Home | History | Annotate | Line # | Download | only in netbt
hci_socket.c revision 1.40.4.1
      1  1.40.4.1    skrll /*	$NetBSD: hci_socket.c,v 1.40.4.1 2015/04/06 15:18:22 skrll Exp $	*/
      2       1.1  gdamore 
      3       1.1  gdamore /*-
      4       1.1  gdamore  * Copyright (c) 2005 Iain Hibbert.
      5       1.1  gdamore  * Copyright (c) 2006 Itronix Inc.
      6       1.1  gdamore  * All rights reserved.
      7       1.1  gdamore  *
      8       1.1  gdamore  * Redistribution and use in source and binary forms, with or without
      9       1.1  gdamore  * modification, are permitted provided that the following conditions
     10       1.1  gdamore  * are met:
     11       1.1  gdamore  * 1. Redistributions of source code must retain the above copyright
     12       1.1  gdamore  *    notice, this list of conditions and the following disclaimer.
     13       1.1  gdamore  * 2. Redistributions in binary form must reproduce the above copyright
     14       1.1  gdamore  *    notice, this list of conditions and the following disclaimer in the
     15       1.1  gdamore  *    documentation and/or other materials provided with the distribution.
     16       1.1  gdamore  * 3. The name of Itronix Inc. may not be used to endorse
     17       1.1  gdamore  *    or promote products derived from this software without specific
     18       1.1  gdamore  *    prior written permission.
     19       1.1  gdamore  *
     20       1.1  gdamore  * THIS SOFTWARE IS PROVIDED BY ITRONIX INC. ``AS IS'' AND
     21       1.1  gdamore  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
     22       1.1  gdamore  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
     23       1.1  gdamore  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL ITRONIX INC. BE LIABLE FOR ANY
     24       1.1  gdamore  * DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
     25       1.1  gdamore  * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
     26       1.1  gdamore  * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
     27       1.1  gdamore  * ON ANY THEORY OF LIABILITY, WHETHER IN
     28       1.1  gdamore  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
     29       1.1  gdamore  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
     30       1.1  gdamore  * POSSIBILITY OF SUCH DAMAGE.
     31       1.1  gdamore  */
     32       1.1  gdamore 
     33       1.1  gdamore #include <sys/cdefs.h>
     34  1.40.4.1    skrll __KERNEL_RCSID(0, "$NetBSD: hci_socket.c,v 1.40.4.1 2015/04/06 15:18:22 skrll Exp $");
     35       1.1  gdamore 
     36      1.10   plunky /* load symbolic names */
     37       1.1  gdamore #ifdef BLUETOOTH_DEBUG
     38      1.10   plunky #define PRUREQUESTS
     39       1.1  gdamore #define PRCOREQUESTS
     40       1.1  gdamore #endif
     41       1.1  gdamore 
     42       1.1  gdamore #include <sys/param.h>
     43       1.1  gdamore #include <sys/domain.h>
     44       1.1  gdamore #include <sys/kauth.h>
     45       1.1  gdamore #include <sys/kernel.h>
     46      1.22    rmind #include <sys/kmem.h>
     47       1.1  gdamore #include <sys/mbuf.h>
     48       1.1  gdamore #include <sys/proc.h>
     49       1.1  gdamore #include <sys/protosw.h>
     50       1.1  gdamore #include <sys/socket.h>
     51       1.1  gdamore #include <sys/socketvar.h>
     52       1.1  gdamore #include <sys/systm.h>
     53       1.1  gdamore 
     54       1.1  gdamore #include <netbt/bluetooth.h>
     55       1.1  gdamore #include <netbt/hci.h>
     56       1.1  gdamore 
     57       1.1  gdamore /*******************************************************************************
     58       1.1  gdamore  *
     59       1.1  gdamore  * HCI SOCK_RAW Sockets - for control of Bluetooth Devices
     60       1.1  gdamore  *
     61       1.1  gdamore  */
     62       1.1  gdamore 
     63       1.1  gdamore /*
     64       1.1  gdamore  * the raw HCI protocol control block
     65       1.1  gdamore  */
     66       1.1  gdamore struct hci_pcb {
     67       1.1  gdamore 	struct socket		*hp_socket;	/* socket */
     68      1.18   plunky 	kauth_cred_t		hp_cred;	/* owner credential */
     69       1.1  gdamore 	unsigned int		hp_flags;	/* flags */
     70       1.1  gdamore 	bdaddr_t		hp_laddr;	/* local address */
     71       1.1  gdamore 	bdaddr_t		hp_raddr;	/* remote address */
     72       1.1  gdamore 	struct hci_filter	hp_efilter;	/* user event filter */
     73       1.1  gdamore 	struct hci_filter	hp_pfilter;	/* user packet filter */
     74       1.1  gdamore 	LIST_ENTRY(hci_pcb)	hp_next;	/* next HCI pcb */
     75       1.1  gdamore };
     76       1.1  gdamore 
     77       1.1  gdamore /* hp_flags */
     78       1.1  gdamore #define HCI_DIRECTION		(1<<1)	/* direction control messages */
     79       1.1  gdamore #define HCI_PROMISCUOUS		(1<<2)	/* listen to all units */
     80       1.1  gdamore 
     81       1.1  gdamore LIST_HEAD(hci_pcb_list, hci_pcb) hci_pcb = LIST_HEAD_INITIALIZER(hci_pcb);
     82       1.1  gdamore 
     83       1.1  gdamore /* sysctl defaults */
     84       1.1  gdamore int hci_sendspace = HCI_CMD_PKT_SIZE;
     85       1.1  gdamore int hci_recvspace = 4096;
     86       1.1  gdamore 
     87      1.18   plunky /* unprivileged commands opcode table */
     88      1.13   plunky static const struct {
     89      1.13   plunky 	uint16_t	opcode;
     90      1.13   plunky 	uint8_t		offs;	/* 0 - 63 */
     91      1.13   plunky 	uint8_t		mask;	/* bit 0 - 7 */
     92      1.18   plunky 	uint8_t		length;	/* approved length */
     93      1.13   plunky } hci_cmds[] = {
     94      1.13   plunky 	{ HCI_CMD_INQUIRY,
     95      1.13   plunky 	  0,  0x01, sizeof(hci_inquiry_cp) },
     96      1.13   plunky 	{ HCI_CMD_REMOTE_NAME_REQ,
     97      1.13   plunky 	  2,  0x08, sizeof(hci_remote_name_req_cp) },
     98      1.13   plunky 	{ HCI_CMD_READ_REMOTE_FEATURES,
     99      1.13   plunky 	  2,  0x20, sizeof(hci_read_remote_features_cp) },
    100      1.13   plunky 	{ HCI_CMD_READ_REMOTE_EXTENDED_FEATURES,
    101      1.13   plunky 	  2,  0x40, sizeof(hci_read_remote_extended_features_cp) },
    102      1.13   plunky 	{ HCI_CMD_READ_REMOTE_VER_INFO,
    103      1.13   plunky 	  2,  0x80, sizeof(hci_read_remote_ver_info_cp) },
    104      1.13   plunky 	{ HCI_CMD_READ_CLOCK_OFFSET,
    105      1.13   plunky 	  3,  0x01, sizeof(hci_read_clock_offset_cp) },
    106      1.13   plunky 	{ HCI_CMD_READ_LMP_HANDLE,
    107      1.13   plunky 	  3,  0x02, sizeof(hci_read_lmp_handle_cp) },
    108      1.13   plunky 	{ HCI_CMD_ROLE_DISCOVERY,
    109      1.13   plunky 	  4,  0x80, sizeof(hci_role_discovery_cp) },
    110      1.13   plunky 	{ HCI_CMD_READ_LINK_POLICY_SETTINGS,
    111      1.13   plunky 	  5,  0x02, sizeof(hci_read_link_policy_settings_cp) },
    112      1.13   plunky 	{ HCI_CMD_READ_DEFAULT_LINK_POLICY_SETTINGS,
    113      1.13   plunky 	  5,  0x08, 0 },
    114      1.13   plunky 	{ HCI_CMD_READ_PIN_TYPE,
    115      1.13   plunky 	  6,  0x04, 0 },
    116      1.13   plunky 	{ HCI_CMD_READ_LOCAL_NAME,
    117      1.13   plunky 	  7,  0x02, 0 },
    118      1.13   plunky 	{ HCI_CMD_READ_CON_ACCEPT_TIMEOUT,
    119      1.13   plunky 	  7,  0x04, 0 },
    120      1.13   plunky 	{ HCI_CMD_READ_PAGE_TIMEOUT,
    121      1.13   plunky 	  7,  0x10, 0 },
    122      1.13   plunky 	{ HCI_CMD_READ_SCAN_ENABLE,
    123      1.13   plunky 	  7,  0x40, 0 },
    124      1.13   plunky 	{ HCI_CMD_READ_PAGE_SCAN_ACTIVITY,
    125      1.13   plunky 	  8,  0x01, 0 },
    126      1.13   plunky 	{ HCI_CMD_READ_INQUIRY_SCAN_ACTIVITY,
    127      1.13   plunky 	  8,  0x04, 0 },
    128      1.13   plunky 	{ HCI_CMD_READ_AUTH_ENABLE,
    129      1.13   plunky 	  8,  0x10, 0 },
    130      1.13   plunky 	{ HCI_CMD_READ_ENCRYPTION_MODE,
    131      1.13   plunky 	  8,  0x40, 0 },
    132      1.13   plunky 	{ HCI_CMD_READ_UNIT_CLASS,
    133      1.13   plunky 	  9,  0x01, 0 },
    134      1.13   plunky 	{ HCI_CMD_READ_VOICE_SETTING,
    135      1.13   plunky 	  9,  0x04, 0 },
    136      1.13   plunky 	{ HCI_CMD_READ_AUTO_FLUSH_TIMEOUT,
    137      1.13   plunky 	  9,  0x10, sizeof(hci_read_auto_flush_timeout_cp) },
    138      1.13   plunky 	{ HCI_CMD_READ_NUM_BROADCAST_RETRANS,
    139      1.13   plunky 	  9,  0x40, 0 },
    140      1.13   plunky 	{ HCI_CMD_READ_HOLD_MODE_ACTIVITY,
    141      1.13   plunky 	  10, 0x01, 0 },
    142      1.13   plunky 	{ HCI_CMD_READ_XMIT_LEVEL,
    143      1.13   plunky 	  10, 0x04, sizeof(hci_read_xmit_level_cp) },
    144      1.13   plunky 	{ HCI_CMD_READ_SCO_FLOW_CONTROL,
    145      1.13   plunky 	  10, 0x08, 0 },
    146      1.13   plunky 	{ HCI_CMD_READ_LINK_SUPERVISION_TIMEOUT,
    147      1.13   plunky 	  11, 0x01, sizeof(hci_read_link_supervision_timeout_cp) },
    148      1.13   plunky 	{ HCI_CMD_READ_NUM_SUPPORTED_IAC,
    149      1.13   plunky 	  11, 0x04, 0 },
    150      1.13   plunky 	{ HCI_CMD_READ_IAC_LAP,
    151      1.13   plunky 	  11, 0x08, 0 },
    152      1.13   plunky 	{ HCI_CMD_READ_PAGE_SCAN_PERIOD,
    153      1.13   plunky 	  11, 0x20, 0 },
    154      1.13   plunky 	{ HCI_CMD_READ_PAGE_SCAN,
    155      1.13   plunky 	  11, 0x80, 0 },
    156      1.13   plunky 	{ HCI_CMD_READ_INQUIRY_SCAN_TYPE,
    157      1.13   plunky 	  12, 0x10, 0 },
    158      1.13   plunky 	{ HCI_CMD_READ_INQUIRY_MODE,
    159      1.13   plunky 	  12, 0x40, 0 },
    160      1.13   plunky 	{ HCI_CMD_READ_PAGE_SCAN_TYPE,
    161      1.13   plunky 	  13, 0x01, 0 },
    162      1.13   plunky 	{ HCI_CMD_READ_AFH_ASSESSMENT,
    163      1.13   plunky 	  13, 0x04, 0 },
    164      1.13   plunky 	{ HCI_CMD_READ_LOCAL_VER,
    165      1.13   plunky 	  14, 0x08, 0 },
    166      1.13   plunky 	{ HCI_CMD_READ_LOCAL_COMMANDS,
    167      1.13   plunky 	  14, 0x10, 0 },
    168      1.13   plunky 	{ HCI_CMD_READ_LOCAL_FEATURES,
    169      1.13   plunky 	  14, 0x20, 0 },
    170      1.13   plunky 	{ HCI_CMD_READ_LOCAL_EXTENDED_FEATURES,
    171      1.13   plunky 	  14, 0x40, sizeof(hci_read_local_extended_features_cp) },
    172      1.13   plunky 	{ HCI_CMD_READ_BUFFER_SIZE,
    173      1.13   plunky 	  14, 0x80, 0 },
    174      1.13   plunky 	{ HCI_CMD_READ_COUNTRY_CODE,
    175      1.13   plunky 	  15, 0x01, 0 },
    176      1.13   plunky 	{ HCI_CMD_READ_BDADDR,
    177      1.13   plunky 	  15, 0x02, 0 },
    178      1.13   plunky 	{ HCI_CMD_READ_FAILED_CONTACT_CNTR,
    179      1.13   plunky 	  15, 0x04, sizeof(hci_read_failed_contact_cntr_cp) },
    180      1.13   plunky 	{ HCI_CMD_READ_LINK_QUALITY,
    181      1.13   plunky 	  15, 0x10, sizeof(hci_read_link_quality_cp) },
    182      1.13   plunky 	{ HCI_CMD_READ_RSSI,
    183      1.13   plunky 	  15, 0x20, sizeof(hci_read_rssi_cp) },
    184      1.13   plunky 	{ HCI_CMD_READ_AFH_CHANNEL_MAP,
    185      1.13   plunky 	  15, 0x40, sizeof(hci_read_afh_channel_map_cp) },
    186      1.13   plunky 	{ HCI_CMD_READ_CLOCK,
    187      1.13   plunky 	  15, 0x80, sizeof(hci_read_clock_cp) },
    188      1.13   plunky 	{ HCI_CMD_READ_LOOPBACK_MODE,
    189      1.13   plunky 	  16, 0x01, 0 },
    190      1.14   plunky 	{ HCI_CMD_READ_EXTENDED_INQUIRY_RSP,
    191      1.14   plunky 	  17, 0x01, 0 },
    192      1.14   plunky 	{ HCI_CMD_READ_SIMPLE_PAIRING_MODE,
    193      1.14   plunky 	  17, 0x20, 0 },
    194      1.14   plunky 	{ HCI_CMD_READ_INQUIRY_RSP_XMIT_POWER,
    195      1.14   plunky 	  18, 0x01, 0 },
    196      1.14   plunky 	{ HCI_CMD_READ_DEFAULT_ERRDATA_REPORTING,
    197      1.14   plunky 	  18, 0x04, 0 },
    198      1.13   plunky };
    199      1.13   plunky 
    200       1.1  gdamore /*
    201      1.18   plunky  * supply a basic device send/recv policy
    202       1.1  gdamore  */
    203       1.4   plunky static int
    204      1.18   plunky hci_device_cb(kauth_cred_t cred, kauth_action_t action, void *cookie,
    205      1.18   plunky     void *arg0, void *arg1, void *arg2, void *arg3)
    206       1.1  gdamore {
    207      1.18   plunky 	int i, result;
    208      1.18   plunky 
    209      1.18   plunky 	result = KAUTH_RESULT_DEFER;
    210      1.18   plunky 
    211      1.18   plunky 	switch (action) {
    212      1.19   plunky 	case KAUTH_DEVICE_BLUETOOTH_SEND: {
    213      1.18   plunky 		struct hci_unit *unit = (struct hci_unit *)arg0;
    214      1.18   plunky 		hci_cmd_hdr_t *hdr = (hci_cmd_hdr_t *)arg1;
    215      1.18   plunky 
    216      1.18   plunky 		/*
    217      1.18   plunky 		 * Allow sending unprivileged commands if the packet size
    218      1.18   plunky 		 * is correct and the unit claims to support it
    219      1.18   plunky 		 */
    220      1.18   plunky 
    221      1.19   plunky 		if (hdr->type != HCI_CMD_PKT)
    222      1.19   plunky 			break;
    223      1.19   plunky 
    224      1.18   plunky 		for (i = 0; i < __arraycount(hci_cmds); i++) {
    225      1.18   plunky 			if (hdr->opcode == hci_cmds[i].opcode
    226      1.18   plunky 			    && hdr->length == hci_cmds[i].length
    227      1.18   plunky 			    && (unit->hci_cmds[hci_cmds[i].offs] & hci_cmds[i].mask)) {
    228      1.18   plunky 				result = KAUTH_RESULT_ALLOW;
    229      1.18   plunky 				break;
    230      1.18   plunky 			}
    231      1.18   plunky 		}
    232      1.18   plunky 
    233      1.18   plunky 		break;
    234      1.18   plunky 		}
    235      1.18   plunky 
    236      1.19   plunky 	case KAUTH_DEVICE_BLUETOOTH_RECV:
    237      1.19   plunky 		switch((uint8_t)(uintptr_t)arg0) {
    238      1.19   plunky 		case HCI_CMD_PKT: {
    239      1.19   plunky 			uint16_t opcode = (uint16_t)(uintptr_t)arg1;
    240      1.19   plunky 
    241      1.19   plunky 			/*
    242      1.19   plunky 			 * Allow to see any unprivileged command packet
    243      1.19   plunky 			 */
    244      1.19   plunky 
    245      1.19   plunky 			for (i = 0; i < __arraycount(hci_cmds); i++) {
    246      1.19   plunky 				if (opcode == hci_cmds[i].opcode) {
    247      1.19   plunky 					result = KAUTH_RESULT_ALLOW;
    248      1.19   plunky 					break;
    249      1.19   plunky 				}
    250      1.19   plunky 			}
    251      1.19   plunky 
    252      1.19   plunky 			break;
    253      1.19   plunky 			}
    254      1.19   plunky 
    255      1.19   plunky 		case HCI_EVENT_PKT: {
    256      1.19   plunky 			uint8_t event = (uint8_t)(uintptr_t)arg1;
    257      1.18   plunky 
    258      1.19   plunky 			/*
    259      1.19   plunky 			 * Allow to receive most events
    260      1.19   plunky 			 */
    261      1.19   plunky 
    262      1.19   plunky 			switch (event) {
    263      1.19   plunky 			case HCI_EVENT_RETURN_LINK_KEYS:
    264      1.19   plunky 			case HCI_EVENT_LINK_KEY_NOTIFICATION:
    265      1.19   plunky 			case HCI_EVENT_USER_CONFIRM_REQ:
    266      1.19   plunky 			case HCI_EVENT_USER_PASSKEY_NOTIFICATION:
    267      1.19   plunky 			case HCI_EVENT_VENDOR:
    268      1.19   plunky 				break;
    269      1.18   plunky 
    270      1.19   plunky 			default:
    271      1.18   plunky 				result = KAUTH_RESULT_ALLOW;
    272      1.18   plunky 				break;
    273      1.18   plunky 			}
    274      1.18   plunky 
    275      1.19   plunky 		    	break;
    276      1.19   plunky 			}
    277      1.18   plunky 
    278      1.19   plunky 		case HCI_ACL_DATA_PKT:
    279      1.19   plunky 		case HCI_SCO_DATA_PKT: {
    280      1.19   plunky 			/* uint16_t handle = (uint16_t)(uintptr_t)arg1; */
    281      1.19   plunky 			/*
    282      1.19   plunky 			 * don't normally allow receiving data packets
    283      1.19   plunky 			 */
    284      1.18   plunky 			break;
    285      1.19   plunky 			}
    286      1.18   plunky 
    287      1.18   plunky 		default:
    288      1.18   plunky 			break;
    289      1.18   plunky 		}
    290      1.13   plunky 
    291      1.18   plunky 		break;
    292      1.18   plunky 
    293      1.18   plunky 	default:
    294      1.13   plunky 		break;
    295       1.4   plunky 	}
    296       1.1  gdamore 
    297      1.18   plunky 	return result;
    298       1.1  gdamore }
    299       1.1  gdamore 
    300      1.18   plunky /*
    301      1.18   plunky  * HCI protocol init routine,
    302      1.18   plunky  * - set up a kauth listener to provide basic packet access policy
    303      1.18   plunky  */
    304      1.18   plunky void
    305      1.18   plunky hci_init(void)
    306       1.1  gdamore {
    307       1.1  gdamore 
    308      1.18   plunky 	if (kauth_listen_scope(KAUTH_SCOPE_DEVICE, hci_device_cb, NULL) == NULL)
    309      1.18   plunky 		panic("Bluetooth HCI: cannot listen on device scope");
    310       1.1  gdamore }
    311       1.1  gdamore 
    312       1.1  gdamore /*
    313       1.1  gdamore  * When command packet reaches the device, we can drop
    314       1.1  gdamore  * it from the socket buffer (called from hci_output_acl)
    315       1.1  gdamore  */
    316       1.1  gdamore void
    317       1.1  gdamore hci_drop(void *arg)
    318       1.1  gdamore {
    319       1.1  gdamore 	struct socket *so = arg;
    320       1.1  gdamore 
    321       1.1  gdamore 	sbdroprecord(&so->so_snd);
    322       1.1  gdamore 	sowwakeup(so);
    323       1.1  gdamore }
    324       1.1  gdamore 
    325       1.1  gdamore /*
    326       1.1  gdamore  * HCI socket is going away and has some pending packets. We let them
    327       1.1  gdamore  * go by design, but remove the context pointer as it will be invalid
    328       1.1  gdamore  * and we no longer need to be notified.
    329       1.1  gdamore  */
    330       1.1  gdamore static void
    331       1.1  gdamore hci_cmdwait_flush(struct socket *so)
    332       1.1  gdamore {
    333       1.1  gdamore 	struct hci_unit *unit;
    334       1.1  gdamore 	struct socket *ctx;
    335       1.1  gdamore 	struct mbuf *m;
    336       1.1  gdamore 
    337       1.1  gdamore 	DPRINTF("flushing %p\n", so);
    338       1.1  gdamore 
    339       1.1  gdamore 	SIMPLEQ_FOREACH(unit, &hci_unit_list, hci_next) {
    340       1.1  gdamore 		m = MBUFQ_FIRST(&unit->hci_cmdwait);
    341       1.1  gdamore 		while (m != NULL) {
    342       1.1  gdamore 			ctx = M_GETCTX(m, struct socket *);
    343       1.1  gdamore 			if (ctx == so)
    344       1.1  gdamore 				M_SETCTX(m, NULL);
    345       1.1  gdamore 
    346       1.1  gdamore 			m = MBUFQ_NEXT(m);
    347       1.1  gdamore 		}
    348       1.1  gdamore 	}
    349       1.1  gdamore }
    350       1.1  gdamore 
    351       1.1  gdamore /*
    352       1.1  gdamore  * HCI send packet
    353       1.1  gdamore  *     This came from userland, so check it out.
    354       1.1  gdamore  */
    355       1.1  gdamore static int
    356      1.38      rtr hci_send_pcb(struct hci_pcb *pcb, struct mbuf *m, bdaddr_t *addr)
    357       1.1  gdamore {
    358       1.1  gdamore 	struct hci_unit *unit;
    359       1.1  gdamore 	struct mbuf *m0;
    360       1.1  gdamore 	hci_cmd_hdr_t hdr;
    361       1.1  gdamore 	int err;
    362       1.1  gdamore 
    363       1.9   plunky 	KASSERT(m != NULL);
    364       1.9   plunky 	KASSERT(addr != NULL);
    365       1.1  gdamore 
    366       1.1  gdamore 	/* wants at least a header to start with */
    367       1.1  gdamore 	if (m->m_pkthdr.len < sizeof(hdr)) {
    368       1.1  gdamore 		err = EMSGSIZE;
    369       1.1  gdamore 		goto bad;
    370       1.1  gdamore 	}
    371       1.1  gdamore 	m_copydata(m, 0, sizeof(hdr), &hdr);
    372      1.13   plunky 	hdr.opcode = le16toh(hdr.opcode);
    373       1.1  gdamore 
    374       1.1  gdamore 	/* only allows CMD packets to be sent */
    375       1.1  gdamore 	if (hdr.type != HCI_CMD_PKT) {
    376       1.1  gdamore 		err = EINVAL;
    377       1.1  gdamore 		goto bad;
    378       1.1  gdamore 	}
    379       1.1  gdamore 
    380       1.1  gdamore 	/* validates packet length */
    381       1.1  gdamore 	if (m->m_pkthdr.len != sizeof(hdr) + hdr.length) {
    382       1.1  gdamore 		err = EMSGSIZE;
    383       1.1  gdamore 		goto bad;
    384       1.1  gdamore 	}
    385       1.1  gdamore 
    386       1.1  gdamore 	/* finds destination */
    387       1.1  gdamore 	unit = hci_unit_lookup(addr);
    388       1.1  gdamore 	if (unit == NULL) {
    389       1.1  gdamore 		err = ENETDOWN;
    390       1.1  gdamore 		goto bad;
    391       1.1  gdamore 	}
    392       1.1  gdamore 
    393      1.13   plunky 	/* security checks for unprivileged users */
    394      1.18   plunky 	if (pcb->hp_cred != NULL
    395      1.18   plunky 	    && kauth_authorize_device(pcb->hp_cred,
    396      1.19   plunky 	    KAUTH_DEVICE_BLUETOOTH_SEND,
    397      1.18   plunky 	    unit, &hdr, NULL, NULL) != 0) {
    398      1.13   plunky 		err = EPERM;
    399      1.13   plunky 		goto bad;
    400      1.13   plunky 	}
    401      1.13   plunky 
    402       1.1  gdamore 	/* makess a copy for precious to keep */
    403       1.1  gdamore 	m0 = m_copypacket(m, M_DONTWAIT);
    404       1.1  gdamore 	if (m0 == NULL) {
    405       1.1  gdamore 		err = ENOMEM;
    406       1.1  gdamore 		goto bad;
    407       1.1  gdamore 	}
    408       1.1  gdamore 	sbappendrecord(&pcb->hp_socket->so_snd, m0);
    409       1.1  gdamore 	M_SETCTX(m, pcb->hp_socket);	/* enable drop callback */
    410       1.1  gdamore 
    411      1.12   plunky 	DPRINTFN(2, "(%s) opcode (%03x|%04x)\n", device_xname(unit->hci_dev),
    412      1.13   plunky 		HCI_OGF(hdr.opcode), HCI_OCF(hdr.opcode));
    413       1.1  gdamore 
    414       1.1  gdamore 	/* Sendss it */
    415       1.1  gdamore 	if (unit->hci_num_cmd_pkts == 0)
    416       1.1  gdamore 		MBUFQ_ENQUEUE(&unit->hci_cmdwait, m);
    417       1.1  gdamore 	else
    418       1.1  gdamore 		hci_output_cmd(unit, m);
    419       1.1  gdamore 
    420       1.1  gdamore 	return 0;
    421       1.1  gdamore 
    422       1.1  gdamore bad:
    423       1.1  gdamore 	DPRINTF("packet (%d bytes) not sent (error %d)\n",
    424       1.1  gdamore 			m->m_pkthdr.len, err);
    425       1.1  gdamore 	if (m) m_freem(m);
    426       1.1  gdamore 	return err;
    427       1.1  gdamore }
    428       1.1  gdamore 
    429      1.22    rmind static int
    430      1.23    rmind hci_attach(struct socket *so, int proto)
    431      1.22    rmind {
    432      1.22    rmind 	struct hci_pcb *pcb;
    433      1.22    rmind 	int error;
    434      1.22    rmind 
    435      1.22    rmind 	KASSERT(so->so_pcb == NULL);
    436      1.22    rmind 
    437      1.22    rmind 	if (so->so_lock == NULL) {
    438      1.22    rmind 		mutex_obj_hold(bt_lock);
    439      1.22    rmind 		so->so_lock = bt_lock;
    440      1.22    rmind 		solock(so);
    441      1.22    rmind 	}
    442      1.22    rmind 	KASSERT(solocked(so));
    443      1.22    rmind 
    444      1.22    rmind 	error = soreserve(so, hci_sendspace, hci_recvspace);
    445      1.22    rmind 	if (error) {
    446      1.22    rmind 		return error;
    447      1.22    rmind 	}
    448      1.22    rmind 
    449      1.22    rmind 	pcb = kmem_zalloc(sizeof(struct hci_pcb), KM_SLEEP);
    450      1.22    rmind 	pcb->hp_cred = kauth_cred_dup(curlwp->l_cred);
    451      1.22    rmind 	pcb->hp_socket = so;
    452      1.22    rmind 
    453      1.22    rmind 	/*
    454      1.22    rmind 	 * Set default user filter. By default, socket only passes
    455      1.22    rmind 	 * Command_Complete and Command_Status Events.
    456      1.22    rmind 	 */
    457      1.22    rmind 	hci_filter_set(HCI_EVENT_COMMAND_COMPL, &pcb->hp_efilter);
    458      1.22    rmind 	hci_filter_set(HCI_EVENT_COMMAND_STATUS, &pcb->hp_efilter);
    459      1.22    rmind 	hci_filter_set(HCI_EVENT_PKT, &pcb->hp_pfilter);
    460      1.22    rmind 
    461      1.22    rmind 	LIST_INSERT_HEAD(&hci_pcb, pcb, hp_next);
    462      1.22    rmind 	so->so_pcb = pcb;
    463      1.22    rmind 
    464      1.22    rmind 	return 0;
    465      1.22    rmind }
    466      1.22    rmind 
    467      1.22    rmind static void
    468      1.23    rmind hci_detach(struct socket *so)
    469      1.22    rmind {
    470      1.22    rmind 	struct hci_pcb *pcb;
    471      1.22    rmind 
    472      1.22    rmind 	pcb = (struct hci_pcb *)so->so_pcb;
    473      1.22    rmind 	KASSERT(pcb != NULL);
    474      1.22    rmind 
    475      1.22    rmind 	if (so->so_snd.sb_mb != NULL)
    476      1.22    rmind 		hci_cmdwait_flush(so);
    477      1.22    rmind 
    478      1.22    rmind 	if (pcb->hp_cred != NULL)
    479      1.22    rmind 		kauth_cred_free(pcb->hp_cred);
    480      1.22    rmind 
    481      1.22    rmind 	so->so_pcb = NULL;
    482      1.22    rmind 	LIST_REMOVE(pcb, hp_next);
    483      1.22    rmind 	kmem_free(pcb, sizeof(*pcb));
    484      1.22    rmind }
    485      1.22    rmind 
    486      1.25      rtr static int
    487      1.32      rtr hci_accept(struct socket *so, struct mbuf *nam)
    488      1.32      rtr {
    489      1.32      rtr 	KASSERT(solocked(so));
    490      1.32      rtr 
    491      1.32      rtr 	return EOPNOTSUPP;
    492      1.32      rtr }
    493      1.32      rtr 
    494      1.32      rtr static int
    495  1.40.4.1    skrll hci_bind(struct socket *so, struct sockaddr *nam, struct lwp *l)
    496      1.34      rtr {
    497      1.34      rtr 	struct hci_pcb *pcb = so->so_pcb;
    498  1.40.4.1    skrll 	struct sockaddr_bt *sa = (struct sockaddr_bt *)nam;
    499      1.34      rtr 
    500      1.34      rtr 	KASSERT(solocked(so));
    501      1.34      rtr 	KASSERT(pcb != NULL);
    502      1.34      rtr 	KASSERT(nam != NULL);
    503      1.34      rtr 
    504      1.34      rtr 	if (sa->bt_len != sizeof(struct sockaddr_bt))
    505      1.34      rtr 		return EINVAL;
    506      1.34      rtr 
    507      1.34      rtr 	if (sa->bt_family != AF_BLUETOOTH)
    508      1.34      rtr 		return EAFNOSUPPORT;
    509      1.34      rtr 
    510      1.34      rtr 	bdaddr_copy(&pcb->hp_laddr, &sa->bt_bdaddr);
    511      1.34      rtr 
    512      1.34      rtr 	if (bdaddr_any(&sa->bt_bdaddr))
    513      1.34      rtr 		pcb->hp_flags |= HCI_PROMISCUOUS;
    514      1.34      rtr 	else
    515      1.34      rtr 		pcb->hp_flags &= ~HCI_PROMISCUOUS;
    516      1.34      rtr 
    517      1.34      rtr 	return 0;
    518      1.34      rtr }
    519      1.34      rtr 
    520      1.34      rtr static int
    521      1.37      rtr hci_listen(struct socket *so, struct lwp *l)
    522      1.34      rtr {
    523      1.34      rtr 	KASSERT(solocked(so));
    524      1.34      rtr 
    525      1.34      rtr 	return EOPNOTSUPP;
    526      1.34      rtr }
    527      1.34      rtr 
    528      1.34      rtr static int
    529      1.37      rtr hci_connect(struct socket *so, struct mbuf *nam, struct lwp *l)
    530      1.35      rtr {
    531      1.35      rtr 	struct hci_pcb *pcb = so->so_pcb;
    532      1.35      rtr 	struct sockaddr_bt *sa;
    533      1.35      rtr 
    534      1.35      rtr 	KASSERT(solocked(so));
    535      1.35      rtr 	KASSERT(pcb != NULL);
    536      1.35      rtr 	KASSERT(nam != NULL);
    537      1.35      rtr 
    538      1.35      rtr 	sa = mtod(nam, struct sockaddr_bt *);
    539      1.35      rtr 	if (sa->bt_len != sizeof(struct sockaddr_bt))
    540      1.35      rtr 		return EINVAL;
    541      1.35      rtr 
    542      1.35      rtr 	if (sa->bt_family != AF_BLUETOOTH)
    543      1.35      rtr 		return EAFNOSUPPORT;
    544      1.35      rtr 
    545      1.35      rtr 	if (hci_unit_lookup(&sa->bt_bdaddr) == NULL)
    546      1.35      rtr 		return EADDRNOTAVAIL;
    547      1.35      rtr 
    548      1.35      rtr 	bdaddr_copy(&pcb->hp_raddr, &sa->bt_bdaddr);
    549      1.35      rtr 	soisconnected(so);
    550      1.35      rtr 	return 0;
    551      1.35      rtr }
    552      1.35      rtr 
    553      1.35      rtr static int
    554      1.40      rtr hci_connect2(struct socket *so, struct socket *so2)
    555      1.40      rtr {
    556      1.40      rtr 	KASSERT(solocked(so));
    557      1.40      rtr 
    558      1.40      rtr 	return EOPNOTSUPP;
    559      1.40      rtr }
    560      1.40      rtr 
    561      1.40      rtr static int
    562      1.36      rtr hci_disconnect(struct socket *so)
    563      1.36      rtr {
    564      1.36      rtr 	struct hci_pcb *pcb = so->so_pcb;
    565      1.36      rtr 
    566      1.36      rtr 	KASSERT(solocked(so));
    567      1.36      rtr 	KASSERT(pcb != NULL);
    568      1.36      rtr 
    569      1.36      rtr 	bdaddr_copy(&pcb->hp_raddr, BDADDR_ANY);
    570      1.36      rtr 
    571      1.36      rtr 	/* XXX we cannot call soisdisconnected() here, as it sets
    572      1.36      rtr 	 * SS_CANTRCVMORE and SS_CANTSENDMORE. The problem being,
    573      1.36      rtr 	 * that soisconnected() does not clear these and if you
    574      1.36      rtr 	 * try to reconnect this socket (which is permitted) you
    575      1.36      rtr 	 * get a broken pipe when you try to write any data.
    576      1.36      rtr 	 */
    577      1.36      rtr 	so->so_state &= ~SS_ISCONNECTED;
    578      1.36      rtr 	return 0;
    579      1.36      rtr }
    580      1.36      rtr 
    581      1.36      rtr static int
    582      1.36      rtr hci_shutdown(struct socket *so)
    583      1.36      rtr {
    584      1.36      rtr 	KASSERT(solocked(so));
    585      1.36      rtr 
    586      1.36      rtr 	socantsendmore(so);
    587      1.36      rtr 	return 0;
    588      1.36      rtr }
    589      1.36      rtr 
    590      1.36      rtr static int
    591      1.36      rtr hci_abort(struct socket *so)
    592      1.36      rtr {
    593      1.36      rtr 	KASSERT(solocked(so));
    594      1.36      rtr 
    595      1.36      rtr 	soisdisconnected(so);
    596      1.36      rtr 	hci_detach(so);
    597      1.36      rtr 	return 0;
    598      1.36      rtr }
    599      1.36      rtr 
    600      1.36      rtr static int
    601      1.30      rtr hci_ioctl(struct socket *so, u_long cmd, void *nam, struct ifnet *ifp)
    602      1.25      rtr {
    603      1.25      rtr 	int err;
    604      1.25      rtr 	mutex_enter(bt_lock);
    605      1.26      rtr 	err = hci_ioctl_pcb(cmd, nam);
    606      1.25      rtr 	mutex_exit(bt_lock);
    607      1.25      rtr 	return err;
    608      1.25      rtr }
    609      1.25      rtr 
    610      1.27      rtr static int
    611      1.27      rtr hci_stat(struct socket *so, struct stat *ub)
    612      1.27      rtr {
    613      1.30      rtr 	KASSERT(solocked(so));
    614      1.30      rtr 
    615      1.29      rtr 	return 0;
    616      1.27      rtr }
    617      1.27      rtr 
    618      1.31      rtr static int
    619      1.31      rtr hci_peeraddr(struct socket *so, struct mbuf *nam)
    620      1.31      rtr {
    621      1.31      rtr 	struct hci_pcb *pcb = (struct hci_pcb *)so->so_pcb;
    622      1.31      rtr 	struct sockaddr_bt *sa;
    623      1.31      rtr 
    624      1.31      rtr 	KASSERT(solocked(so));
    625      1.31      rtr 	KASSERT(pcb != NULL);
    626      1.31      rtr 	KASSERT(nam != NULL);
    627      1.31      rtr 
    628      1.31      rtr 	sa = mtod(nam, struct sockaddr_bt *);
    629      1.31      rtr 	memset(sa, 0, sizeof(struct sockaddr_bt));
    630      1.31      rtr 	nam->m_len =
    631      1.31      rtr 	sa->bt_len = sizeof(struct sockaddr_bt);
    632      1.31      rtr 	sa->bt_family = AF_BLUETOOTH;
    633      1.31      rtr 	bdaddr_copy(&sa->bt_bdaddr, &pcb->hp_raddr);
    634      1.31      rtr 	return 0;
    635      1.31      rtr }
    636      1.31      rtr 
    637      1.31      rtr static int
    638      1.31      rtr hci_sockaddr(struct socket *so, struct mbuf *nam)
    639      1.31      rtr {
    640      1.31      rtr 	struct hci_pcb *pcb = (struct hci_pcb *)so->so_pcb;
    641      1.31      rtr 	struct sockaddr_bt *sa;
    642      1.31      rtr 
    643      1.31      rtr 	KASSERT(solocked(so));
    644      1.31      rtr 	KASSERT(pcb != NULL);
    645      1.31      rtr 	KASSERT(nam != NULL);
    646      1.31      rtr 
    647      1.31      rtr 	sa = mtod(nam, struct sockaddr_bt *);
    648      1.31      rtr 	memset(sa, 0, sizeof(struct sockaddr_bt));
    649      1.31      rtr 	nam->m_len =
    650      1.31      rtr 	sa->bt_len = sizeof(struct sockaddr_bt);
    651      1.31      rtr 	sa->bt_family = AF_BLUETOOTH;
    652      1.31      rtr 	bdaddr_copy(&sa->bt_bdaddr, &pcb->hp_laddr);
    653      1.31      rtr 	return 0;
    654      1.31      rtr }
    655      1.31      rtr 
    656      1.33      rtr static int
    657      1.39      rtr hci_rcvd(struct socket *so, int flags, struct lwp *l)
    658      1.39      rtr {
    659      1.39      rtr 	KASSERT(solocked(so));
    660      1.39      rtr 
    661      1.39      rtr 	return EOPNOTSUPP;
    662      1.39      rtr }
    663      1.39      rtr 
    664      1.39      rtr static int
    665      1.33      rtr hci_recvoob(struct socket *so, struct mbuf *m, int flags)
    666      1.33      rtr {
    667      1.33      rtr 	KASSERT(solocked(so));
    668      1.33      rtr 
    669      1.33      rtr 	return EOPNOTSUPP;
    670      1.33      rtr }
    671      1.33      rtr 
    672      1.33      rtr static int
    673      1.38      rtr hci_send(struct socket *so, struct mbuf *m, struct mbuf *nam,
    674      1.38      rtr     struct mbuf *control, struct lwp *l)
    675      1.38      rtr {
    676      1.38      rtr 	struct hci_pcb *pcb = so->so_pcb;
    677      1.38      rtr 	struct sockaddr_bt * sa = NULL;
    678      1.38      rtr 	int err = 0;
    679      1.38      rtr 
    680      1.38      rtr 	KASSERT(solocked(so));
    681      1.38      rtr 	KASSERT(pcb != NULL);
    682      1.38      rtr 
    683      1.38      rtr 	if (control) /* have no use for this */
    684      1.38      rtr 		m_freem(control);
    685      1.38      rtr 
    686      1.38      rtr 	if (nam) {
    687      1.38      rtr 		sa = mtod(nam, struct sockaddr_bt *);
    688      1.38      rtr 
    689      1.38      rtr 		if (sa->bt_len != sizeof(struct sockaddr_bt)) {
    690      1.38      rtr 			err = EINVAL;
    691      1.38      rtr 			goto release;
    692      1.38      rtr 		}
    693      1.38      rtr 
    694      1.38      rtr 		if (sa->bt_family != AF_BLUETOOTH) {
    695      1.38      rtr 			err = EAFNOSUPPORT;
    696      1.38      rtr 			goto release;
    697      1.38      rtr 		}
    698      1.38      rtr 	}
    699      1.38      rtr 
    700      1.38      rtr 	return hci_send_pcb(pcb, m, (sa ? &sa->bt_bdaddr : &pcb->hp_raddr));
    701      1.38      rtr 
    702      1.38      rtr release:
    703      1.38      rtr 	if (m)
    704      1.38      rtr 		m_freem(m);
    705      1.38      rtr 
    706      1.38      rtr 	return err;
    707      1.38      rtr }
    708      1.38      rtr 
    709      1.38      rtr static int
    710      1.33      rtr hci_sendoob(struct socket *so, struct mbuf *m, struct mbuf *control)
    711      1.33      rtr {
    712      1.33      rtr 	KASSERT(solocked(so));
    713      1.33      rtr 
    714      1.33      rtr 	if (m)
    715      1.33      rtr 		m_freem(m);
    716      1.33      rtr 	if (control)
    717      1.33      rtr 		m_freem(control);
    718      1.33      rtr 
    719      1.33      rtr 	return EOPNOTSUPP;
    720      1.33      rtr }
    721      1.33      rtr 
    722      1.40      rtr static int
    723      1.40      rtr hci_purgeif(struct socket *so, struct ifnet *ifp)
    724      1.40      rtr {
    725      1.40      rtr 
    726      1.40      rtr 	return EOPNOTSUPP;
    727      1.40      rtr }
    728      1.40      rtr 
    729       1.1  gdamore /*
    730       1.1  gdamore  * User Request.
    731       1.1  gdamore  * up is socket
    732      1.25      rtr  * m is optional mbuf chain containing message
    733      1.25      rtr  * nam is optional mbuf chain containing an address
    734       1.1  gdamore  * ctl is optional mbuf chain containing socket options
    735       1.1  gdamore  * l is pointer to process requesting action (if any)
    736       1.1  gdamore  *
    737      1.25      rtr  * we are responsible for disposing of m and ctl
    738       1.1  gdamore  */
    739      1.21    rmind static int
    740       1.1  gdamore hci_usrreq(struct socket *up, int req, struct mbuf *m,
    741       1.1  gdamore 		struct mbuf *nam, struct mbuf *ctl, struct lwp *l)
    742       1.1  gdamore {
    743      1.40      rtr 	struct hci_pcb *pcb = up->so_pcb;
    744       1.4   plunky 	int err = 0;
    745       1.1  gdamore 
    746       1.1  gdamore 	DPRINTFN(2, "%s\n", prurequests[req]);
    747      1.22    rmind 	KASSERT(req != PRU_ATTACH);
    748      1.22    rmind 	KASSERT(req != PRU_DETACH);
    749      1.32      rtr 	KASSERT(req != PRU_ACCEPT);
    750      1.34      rtr 	KASSERT(req != PRU_BIND);
    751      1.34      rtr 	KASSERT(req != PRU_LISTEN);
    752      1.35      rtr 	KASSERT(req != PRU_CONNECT);
    753      1.40      rtr 	KASSERT(req != PRU_CONNECT2);
    754      1.36      rtr 	KASSERT(req != PRU_DISCONNECT);
    755      1.36      rtr 	KASSERT(req != PRU_SHUTDOWN);
    756      1.36      rtr 	KASSERT(req != PRU_ABORT);
    757      1.25      rtr 	KASSERT(req != PRU_CONTROL);
    758      1.27      rtr 	KASSERT(req != PRU_SENSE);
    759      1.31      rtr 	KASSERT(req != PRU_PEERADDR);
    760      1.31      rtr 	KASSERT(req != PRU_SOCKADDR);
    761      1.39      rtr 	KASSERT(req != PRU_RCVD);
    762      1.33      rtr 	KASSERT(req != PRU_RCVOOB);
    763      1.38      rtr 	KASSERT(req != PRU_SEND);
    764      1.33      rtr 	KASSERT(req != PRU_SENDOOB);
    765      1.40      rtr 	KASSERT(req != PRU_PURGEIF);
    766       1.1  gdamore 
    767       1.1  gdamore 	/* anything after here *requires* a pcb */
    768       1.1  gdamore 	if (pcb == NULL) {
    769       1.1  gdamore 		err = EINVAL;
    770       1.1  gdamore 		goto release;
    771       1.1  gdamore 	}
    772       1.1  gdamore 
    773       1.1  gdamore 	switch(req) {
    774       1.1  gdamore 	case PRU_FASTTIMO:
    775       1.1  gdamore 	case PRU_SLOWTIMO:
    776       1.1  gdamore 	case PRU_PROTORCV:
    777       1.1  gdamore 	case PRU_PROTOSEND:
    778       1.1  gdamore 		err = EOPNOTSUPP;
    779       1.1  gdamore 		break;
    780       1.1  gdamore 
    781       1.1  gdamore 	default:
    782       1.1  gdamore 		UNKNOWN(req);
    783       1.1  gdamore 		err = EOPNOTSUPP;
    784       1.1  gdamore 		break;
    785       1.1  gdamore 	}
    786       1.1  gdamore 
    787       1.1  gdamore release:
    788       1.2       ad 	if (m)
    789       1.2       ad 		m_freem(m);
    790       1.2       ad 	if (ctl)
    791       1.2       ad 		m_freem(ctl);
    792       1.1  gdamore 	return err;
    793       1.1  gdamore }
    794       1.1  gdamore 
    795       1.1  gdamore /*
    796       1.1  gdamore  * get/set socket options
    797       1.1  gdamore  */
    798       1.1  gdamore int
    799      1.17   plunky hci_ctloutput(int req, struct socket *so, struct sockopt *sopt)
    800       1.1  gdamore {
    801       1.1  gdamore 	struct hci_pcb *pcb = (struct hci_pcb *)so->so_pcb;
    802      1.17   plunky 	int optval, err = 0;
    803       1.1  gdamore 
    804       1.1  gdamore 	DPRINTFN(2, "req %s\n", prcorequests[req]);
    805       1.1  gdamore 
    806       1.1  gdamore 	if (pcb == NULL)
    807       1.1  gdamore 		return EINVAL;
    808       1.1  gdamore 
    809      1.17   plunky 	if (sopt->sopt_level != BTPROTO_HCI)
    810       1.7   plunky 		return ENOPROTOOPT;
    811       1.1  gdamore 
    812       1.1  gdamore 	switch(req) {
    813       1.1  gdamore 	case PRCO_GETOPT:
    814      1.17   plunky 		switch (sopt->sopt_name) {
    815       1.1  gdamore 		case SO_HCI_EVT_FILTER:
    816      1.17   plunky 			err = sockopt_set(sopt, &pcb->hp_efilter,
    817      1.17   plunky 			    sizeof(struct hci_filter));
    818      1.17   plunky 
    819       1.1  gdamore 			break;
    820       1.1  gdamore 
    821       1.1  gdamore 		case SO_HCI_PKT_FILTER:
    822      1.17   plunky 			err = sockopt_set(sopt, &pcb->hp_pfilter,
    823      1.17   plunky 			    sizeof(struct hci_filter));
    824      1.17   plunky 
    825       1.1  gdamore 			break;
    826       1.1  gdamore 
    827       1.1  gdamore 		case SO_HCI_DIRECTION:
    828      1.17   plunky 			err = sockopt_setint(sopt,
    829      1.17   plunky 			    (pcb->hp_flags & HCI_DIRECTION ? 1 : 0));
    830      1.17   plunky 
    831       1.1  gdamore 			break;
    832       1.1  gdamore 
    833       1.1  gdamore 		default:
    834       1.7   plunky 			err = ENOPROTOOPT;
    835       1.1  gdamore 			break;
    836       1.1  gdamore 		}
    837       1.1  gdamore 		break;
    838       1.1  gdamore 
    839       1.1  gdamore 	case PRCO_SETOPT:
    840      1.17   plunky 		switch (sopt->sopt_name) {
    841       1.1  gdamore 		case SO_HCI_EVT_FILTER:	/* set event filter */
    842      1.17   plunky 			err = sockopt_get(sopt, &pcb->hp_efilter,
    843      1.17   plunky 			    sizeof(pcb->hp_efilter));
    844      1.17   plunky 
    845       1.1  gdamore 			break;
    846       1.1  gdamore 
    847       1.1  gdamore 		case SO_HCI_PKT_FILTER:	/* set packet filter */
    848      1.17   plunky 			err = sockopt_get(sopt, &pcb->hp_pfilter,
    849      1.17   plunky 			    sizeof(pcb->hp_pfilter));
    850      1.17   plunky 
    851       1.1  gdamore 			break;
    852       1.1  gdamore 
    853       1.1  gdamore 		case SO_HCI_DIRECTION:	/* request direction ctl messages */
    854      1.17   plunky 			err = sockopt_getint(sopt, &optval);
    855      1.17   plunky 			if (err)
    856      1.17   plunky 				break;
    857      1.17   plunky 
    858      1.17   plunky 			if (optval)
    859       1.1  gdamore 				pcb->hp_flags |= HCI_DIRECTION;
    860       1.1  gdamore 			else
    861       1.1  gdamore 				pcb->hp_flags &= ~HCI_DIRECTION;
    862       1.1  gdamore 			break;
    863       1.1  gdamore 
    864       1.1  gdamore 		default:
    865       1.7   plunky 			err = ENOPROTOOPT;
    866       1.1  gdamore 			break;
    867       1.1  gdamore 		}
    868       1.1  gdamore 		break;
    869       1.1  gdamore 
    870       1.1  gdamore 	default:
    871       1.7   plunky 		err = ENOPROTOOPT;
    872       1.1  gdamore 		break;
    873       1.1  gdamore 	}
    874       1.1  gdamore 
    875       1.1  gdamore 	return err;
    876       1.1  gdamore }
    877       1.1  gdamore 
    878       1.1  gdamore /*
    879       1.1  gdamore  * HCI mbuf tap routine
    880       1.1  gdamore  *
    881       1.1  gdamore  * copy packets to any raw HCI sockets that wish (and are
    882       1.1  gdamore  * permitted) to see them
    883       1.1  gdamore  */
    884       1.1  gdamore void
    885       1.1  gdamore hci_mtap(struct mbuf *m, struct hci_unit *unit)
    886       1.1  gdamore {
    887       1.1  gdamore 	struct hci_pcb *pcb;
    888       1.1  gdamore 	struct mbuf *m0, *ctlmsg, **ctl;
    889       1.1  gdamore 	struct sockaddr_bt sa;
    890       1.1  gdamore 	uint8_t type;
    891       1.1  gdamore 	uint8_t event;
    892      1.19   plunky 	uint16_t arg1;
    893       1.1  gdamore 
    894       1.1  gdamore 	KASSERT(m->m_len >= sizeof(type));
    895       1.1  gdamore 
    896       1.1  gdamore 	type = *mtod(m, uint8_t *);
    897       1.1  gdamore 
    898       1.1  gdamore 	memset(&sa, 0, sizeof(sa));
    899       1.1  gdamore 	sa.bt_len = sizeof(struct sockaddr_bt);
    900       1.1  gdamore 	sa.bt_family = AF_BLUETOOTH;
    901       1.1  gdamore 	bdaddr_copy(&sa.bt_bdaddr, &unit->hci_bdaddr);
    902       1.1  gdamore 
    903       1.1  gdamore 	LIST_FOREACH(pcb, &hci_pcb, hp_next) {
    904       1.1  gdamore 		/*
    905       1.1  gdamore 		 * filter according to source address
    906       1.1  gdamore 		 */
    907       1.1  gdamore 		if ((pcb->hp_flags & HCI_PROMISCUOUS) == 0
    908       1.1  gdamore 		    && bdaddr_same(&pcb->hp_laddr, &sa.bt_bdaddr) == 0)
    909       1.1  gdamore 			continue;
    910       1.1  gdamore 
    911       1.1  gdamore 		/*
    912       1.1  gdamore 		 * filter according to packet type filter
    913       1.1  gdamore 		 */
    914       1.1  gdamore 		if (hci_filter_test(type, &pcb->hp_pfilter) == 0)
    915       1.1  gdamore 			continue;
    916       1.1  gdamore 
    917       1.1  gdamore 		/*
    918       1.1  gdamore 		 * filter according to event/security filters
    919       1.1  gdamore 		 */
    920       1.1  gdamore 		switch(type) {
    921       1.1  gdamore 		case HCI_EVENT_PKT:
    922       1.1  gdamore 			KASSERT(m->m_len >= sizeof(hci_event_hdr_t));
    923       1.1  gdamore 
    924       1.1  gdamore 			event = mtod(m, hci_event_hdr_t *)->event;
    925       1.1  gdamore 
    926       1.1  gdamore 			if (hci_filter_test(event, &pcb->hp_efilter) == 0)
    927       1.1  gdamore 				continue;
    928       1.1  gdamore 
    929      1.19   plunky 			arg1 = event;
    930       1.1  gdamore 			break;
    931       1.1  gdamore 
    932       1.1  gdamore 		case HCI_CMD_PKT:
    933       1.1  gdamore 			KASSERT(m->m_len >= sizeof(hci_cmd_hdr_t));
    934      1.19   plunky 			arg1 = le16toh(mtod(m, hci_cmd_hdr_t *)->opcode);
    935      1.19   plunky 			break;
    936       1.1  gdamore 
    937      1.19   plunky 		case HCI_ACL_DATA_PKT:
    938      1.19   plunky 			KASSERT(m->m_len >= sizeof(hci_acldata_hdr_t));
    939      1.19   plunky 			arg1 = le16toh(mtod(m, hci_acldata_hdr_t *)->con_handle);
    940      1.19   plunky 			arg1 = HCI_CON_HANDLE(arg1);
    941      1.19   plunky 			break;
    942      1.18   plunky 
    943      1.19   plunky 		case HCI_SCO_DATA_PKT:
    944      1.19   plunky 			KASSERT(m->m_len >= sizeof(hci_scodata_hdr_t));
    945      1.19   plunky 			arg1 = le16toh(mtod(m, hci_scodata_hdr_t *)->con_handle);
    946      1.19   plunky 			arg1 = HCI_CON_HANDLE(arg1);
    947       1.1  gdamore 			break;
    948       1.1  gdamore 
    949       1.1  gdamore 		default:
    950      1.19   plunky 			arg1 = 0;
    951       1.1  gdamore 			break;
    952       1.1  gdamore 		}
    953       1.1  gdamore 
    954      1.19   plunky 		if (pcb->hp_cred != NULL
    955      1.19   plunky 		    && kauth_authorize_device(pcb->hp_cred,
    956      1.19   plunky 		    KAUTH_DEVICE_BLUETOOTH_RECV,
    957      1.19   plunky 		    KAUTH_ARG(type), KAUTH_ARG(arg1), NULL, NULL) != 0)
    958      1.19   plunky 			continue;
    959      1.19   plunky 
    960       1.1  gdamore 		/*
    961       1.1  gdamore 		 * create control messages
    962       1.1  gdamore 		 */
    963       1.1  gdamore 		ctlmsg = NULL;
    964       1.1  gdamore 		ctl = &ctlmsg;
    965       1.1  gdamore 		if (pcb->hp_flags & HCI_DIRECTION) {
    966       1.1  gdamore 			int dir = m->m_flags & M_LINK0 ? 1 : 0;
    967       1.1  gdamore 
    968      1.11   plunky 			*ctl = sbcreatecontrol(&dir, sizeof(dir),
    969       1.1  gdamore 			    SCM_HCI_DIRECTION, BTPROTO_HCI);
    970       1.1  gdamore 
    971       1.1  gdamore 			if (*ctl != NULL)
    972       1.1  gdamore 				ctl = &((*ctl)->m_next);
    973       1.1  gdamore 		}
    974      1.20   plunky 		if (pcb->hp_socket->so_options & SO_TIMESTAMP) {
    975      1.20   plunky 			struct timeval tv;
    976      1.20   plunky 
    977      1.20   plunky 			microtime(&tv);
    978      1.20   plunky 			*ctl = sbcreatecontrol(&tv, sizeof(tv),
    979      1.20   plunky 			    SCM_TIMESTAMP, SOL_SOCKET);
    980      1.20   plunky 
    981      1.20   plunky 			if (*ctl != NULL)
    982      1.20   plunky 				ctl = &((*ctl)->m_next);
    983      1.20   plunky 		}
    984       1.1  gdamore 
    985       1.1  gdamore 		/*
    986       1.1  gdamore 		 * copy to socket
    987       1.1  gdamore 		 */
    988       1.1  gdamore 		m0 = m_copypacket(m, M_DONTWAIT);
    989       1.1  gdamore 		if (m0 && sbappendaddr(&pcb->hp_socket->so_rcv,
    990       1.1  gdamore 				(struct sockaddr *)&sa, m0, ctlmsg)) {
    991       1.1  gdamore 			sorwakeup(pcb->hp_socket);
    992       1.1  gdamore 		} else {
    993       1.1  gdamore 			m_freem(ctlmsg);
    994       1.1  gdamore 			m_freem(m0);
    995       1.1  gdamore 		}
    996       1.1  gdamore 	}
    997       1.1  gdamore }
    998      1.21    rmind 
    999      1.24    rmind PR_WRAP_USRREQS(hci)
   1000      1.21    rmind 
   1001      1.24    rmind #define	hci_attach		hci_attach_wrapper
   1002      1.24    rmind #define	hci_detach		hci_detach_wrapper
   1003      1.32      rtr #define	hci_accept		hci_accept_wrapper
   1004      1.34      rtr #define	hci_bind		hci_bind_wrapper
   1005      1.34      rtr #define	hci_listen		hci_listen_wrapper
   1006      1.35      rtr #define	hci_connect		hci_connect_wrapper
   1007      1.40      rtr #define	hci_connect2		hci_connect2_wrapper
   1008      1.36      rtr #define	hci_disconnect		hci_disconnect_wrapper
   1009      1.36      rtr #define	hci_shutdown		hci_shutdown_wrapper
   1010      1.36      rtr #define	hci_abort		hci_abort_wrapper
   1011      1.25      rtr #define	hci_ioctl		hci_ioctl_wrapper
   1012      1.27      rtr #define	hci_stat		hci_stat_wrapper
   1013      1.31      rtr #define	hci_peeraddr		hci_peeraddr_wrapper
   1014      1.31      rtr #define	hci_sockaddr		hci_sockaddr_wrapper
   1015      1.39      rtr #define	hci_rcvd		hci_rcvd_wrapper
   1016      1.33      rtr #define	hci_recvoob		hci_recvoob_wrapper
   1017      1.38      rtr #define	hci_send		hci_send_wrapper
   1018      1.33      rtr #define	hci_sendoob		hci_sendoob_wrapper
   1019      1.40      rtr #define	hci_purgeif		hci_purgeif_wrapper
   1020      1.21    rmind #define	hci_usrreq		hci_usrreq_wrapper
   1021      1.21    rmind 
   1022      1.21    rmind const struct pr_usrreqs hci_usrreqs = {
   1023      1.23    rmind 	.pr_attach	= hci_attach,
   1024      1.23    rmind 	.pr_detach	= hci_detach,
   1025      1.32      rtr 	.pr_accept	= hci_accept,
   1026      1.34      rtr 	.pr_bind	= hci_bind,
   1027      1.34      rtr 	.pr_listen	= hci_listen,
   1028      1.35      rtr 	.pr_connect	= hci_connect,
   1029      1.40      rtr 	.pr_connect2	= hci_connect2,
   1030      1.36      rtr 	.pr_disconnect	= hci_disconnect,
   1031      1.36      rtr 	.pr_shutdown	= hci_shutdown,
   1032      1.36      rtr 	.pr_abort	= hci_abort,
   1033      1.25      rtr 	.pr_ioctl	= hci_ioctl,
   1034      1.27      rtr 	.pr_stat	= hci_stat,
   1035      1.31      rtr 	.pr_peeraddr	= hci_peeraddr,
   1036      1.31      rtr 	.pr_sockaddr	= hci_sockaddr,
   1037      1.39      rtr 	.pr_rcvd	= hci_rcvd,
   1038      1.33      rtr 	.pr_recvoob	= hci_recvoob,
   1039      1.38      rtr 	.pr_send	= hci_send,
   1040      1.33      rtr 	.pr_sendoob	= hci_sendoob,
   1041      1.40      rtr 	.pr_purgeif	= hci_purgeif,
   1042      1.21    rmind 	.pr_generic	= hci_usrreq,
   1043      1.21    rmind };
   1044