Bluetooth: Add reading of page scan parameters
[firefly-linux-kernel-4.4.55.git] / net / bluetooth / hci_event.c
1 /*
2    BlueZ - Bluetooth protocol stack for Linux
3    Copyright (c) 2000-2001, 2010, Code Aurora Forum. All rights reserved.
4
5    Written 2000,2001 by Maxim Krasnyansky <maxk@qualcomm.com>
6
7    This program is free software; you can redistribute it and/or modify
8    it under the terms of the GNU General Public License version 2 as
9    published by the Free Software Foundation;
10
11    THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
12    OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
13    FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS.
14    IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY
15    CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES
16    WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17    ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
18    OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
19
20    ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS,
21    COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS
22    SOFTWARE IS DISCLAIMED.
23 */
24
25 /* Bluetooth HCI event handling. */
26
27 #include <asm/unaligned.h>
28
29 #include <net/bluetooth/bluetooth.h>
30 #include <net/bluetooth/hci_core.h>
31 #include <net/bluetooth/mgmt.h>
32 #include <net/bluetooth/a2mp.h>
33 #include <net/bluetooth/amp.h>
34
35 /* Handle HCI Event packets */
36
37 static void hci_cc_inquiry_cancel(struct hci_dev *hdev, struct sk_buff *skb)
38 {
39         __u8 status = *((__u8 *) skb->data);
40
41         BT_DBG("%s status 0x%2.2x", hdev->name, status);
42
43         if (status) {
44                 hci_dev_lock(hdev);
45                 mgmt_stop_discovery_failed(hdev, status);
46                 hci_dev_unlock(hdev);
47                 return;
48         }
49
50         clear_bit(HCI_INQUIRY, &hdev->flags);
51
52         hci_dev_lock(hdev);
53         hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
54         hci_dev_unlock(hdev);
55
56         hci_req_cmd_complete(hdev, HCI_OP_INQUIRY, status);
57
58         hci_conn_check_pending(hdev);
59 }
60
61 static void hci_cc_periodic_inq(struct hci_dev *hdev, struct sk_buff *skb)
62 {
63         __u8 status = *((__u8 *) skb->data);
64
65         BT_DBG("%s status 0x%2.2x", hdev->name, status);
66
67         if (status)
68                 return;
69
70         set_bit(HCI_PERIODIC_INQ, &hdev->dev_flags);
71 }
72
73 static void hci_cc_exit_periodic_inq(struct hci_dev *hdev, struct sk_buff *skb)
74 {
75         __u8 status = *((__u8 *) skb->data);
76
77         BT_DBG("%s status 0x%2.2x", hdev->name, status);
78
79         if (status)
80                 return;
81
82         clear_bit(HCI_PERIODIC_INQ, &hdev->dev_flags);
83
84         hci_conn_check_pending(hdev);
85 }
86
87 static void hci_cc_remote_name_req_cancel(struct hci_dev *hdev,
88                                           struct sk_buff *skb)
89 {
90         BT_DBG("%s", hdev->name);
91 }
92
93 static void hci_cc_role_discovery(struct hci_dev *hdev, struct sk_buff *skb)
94 {
95         struct hci_rp_role_discovery *rp = (void *) skb->data;
96         struct hci_conn *conn;
97
98         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
99
100         if (rp->status)
101                 return;
102
103         hci_dev_lock(hdev);
104
105         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(rp->handle));
106         if (conn) {
107                 if (rp->role)
108                         conn->link_mode &= ~HCI_LM_MASTER;
109                 else
110                         conn->link_mode |= HCI_LM_MASTER;
111         }
112
113         hci_dev_unlock(hdev);
114 }
115
116 static void hci_cc_read_link_policy(struct hci_dev *hdev, struct sk_buff *skb)
117 {
118         struct hci_rp_read_link_policy *rp = (void *) skb->data;
119         struct hci_conn *conn;
120
121         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
122
123         if (rp->status)
124                 return;
125
126         hci_dev_lock(hdev);
127
128         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(rp->handle));
129         if (conn)
130                 conn->link_policy = __le16_to_cpu(rp->policy);
131
132         hci_dev_unlock(hdev);
133 }
134
135 static void hci_cc_write_link_policy(struct hci_dev *hdev, struct sk_buff *skb)
136 {
137         struct hci_rp_write_link_policy *rp = (void *) skb->data;
138         struct hci_conn *conn;
139         void *sent;
140
141         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
142
143         if (rp->status)
144                 return;
145
146         sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_LINK_POLICY);
147         if (!sent)
148                 return;
149
150         hci_dev_lock(hdev);
151
152         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(rp->handle));
153         if (conn)
154                 conn->link_policy = get_unaligned_le16(sent + 2);
155
156         hci_dev_unlock(hdev);
157 }
158
159 static void hci_cc_read_def_link_policy(struct hci_dev *hdev,
160                                         struct sk_buff *skb)
161 {
162         struct hci_rp_read_def_link_policy *rp = (void *) skb->data;
163
164         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
165
166         if (rp->status)
167                 return;
168
169         hdev->link_policy = __le16_to_cpu(rp->policy);
170 }
171
172 static void hci_cc_write_def_link_policy(struct hci_dev *hdev,
173                                          struct sk_buff *skb)
174 {
175         __u8 status = *((__u8 *) skb->data);
176         void *sent;
177
178         BT_DBG("%s status 0x%2.2x", hdev->name, status);
179
180         sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_DEF_LINK_POLICY);
181         if (!sent)
182                 return;
183
184         if (!status)
185                 hdev->link_policy = get_unaligned_le16(sent);
186 }
187
188 static void hci_cc_reset(struct hci_dev *hdev, struct sk_buff *skb)
189 {
190         __u8 status = *((__u8 *) skb->data);
191
192         BT_DBG("%s status 0x%2.2x", hdev->name, status);
193
194         clear_bit(HCI_RESET, &hdev->flags);
195
196         /* Reset all non-persistent flags */
197         hdev->dev_flags &= ~HCI_PERSISTENT_MASK;
198
199         hdev->discovery.state = DISCOVERY_STOPPED;
200         hdev->inq_tx_power = HCI_TX_POWER_INVALID;
201         hdev->adv_tx_power = HCI_TX_POWER_INVALID;
202
203         memset(hdev->adv_data, 0, sizeof(hdev->adv_data));
204         hdev->adv_data_len = 0;
205 }
206
207 static void hci_cc_write_local_name(struct hci_dev *hdev, struct sk_buff *skb)
208 {
209         __u8 status = *((__u8 *) skb->data);
210         void *sent;
211
212         BT_DBG("%s status 0x%2.2x", hdev->name, status);
213
214         sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_LOCAL_NAME);
215         if (!sent)
216                 return;
217
218         hci_dev_lock(hdev);
219
220         if (test_bit(HCI_MGMT, &hdev->dev_flags))
221                 mgmt_set_local_name_complete(hdev, sent, status);
222         else if (!status)
223                 memcpy(hdev->dev_name, sent, HCI_MAX_NAME_LENGTH);
224
225         hci_dev_unlock(hdev);
226 }
227
228 static void hci_cc_read_local_name(struct hci_dev *hdev, struct sk_buff *skb)
229 {
230         struct hci_rp_read_local_name *rp = (void *) skb->data;
231
232         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
233
234         if (rp->status)
235                 return;
236
237         if (test_bit(HCI_SETUP, &hdev->dev_flags))
238                 memcpy(hdev->dev_name, rp->name, HCI_MAX_NAME_LENGTH);
239 }
240
241 static void hci_cc_write_auth_enable(struct hci_dev *hdev, struct sk_buff *skb)
242 {
243         __u8 status = *((__u8 *) skb->data);
244         void *sent;
245
246         BT_DBG("%s status 0x%2.2x", hdev->name, status);
247
248         sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_AUTH_ENABLE);
249         if (!sent)
250                 return;
251
252         if (!status) {
253                 __u8 param = *((__u8 *) sent);
254
255                 if (param == AUTH_ENABLED)
256                         set_bit(HCI_AUTH, &hdev->flags);
257                 else
258                         clear_bit(HCI_AUTH, &hdev->flags);
259         }
260
261         if (test_bit(HCI_MGMT, &hdev->dev_flags))
262                 mgmt_auth_enable_complete(hdev, status);
263 }
264
265 static void hci_cc_write_encrypt_mode(struct hci_dev *hdev, struct sk_buff *skb)
266 {
267         __u8 status = *((__u8 *) skb->data);
268         void *sent;
269
270         BT_DBG("%s status 0x%2.2x", hdev->name, status);
271
272         sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_ENCRYPT_MODE);
273         if (!sent)
274                 return;
275
276         if (!status) {
277                 __u8 param = *((__u8 *) sent);
278
279                 if (param)
280                         set_bit(HCI_ENCRYPT, &hdev->flags);
281                 else
282                         clear_bit(HCI_ENCRYPT, &hdev->flags);
283         }
284 }
285
286 static void hci_cc_write_scan_enable(struct hci_dev *hdev, struct sk_buff *skb)
287 {
288         __u8 param, status = *((__u8 *) skb->data);
289         int old_pscan, old_iscan;
290         void *sent;
291
292         BT_DBG("%s status 0x%2.2x", hdev->name, status);
293
294         sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_SCAN_ENABLE);
295         if (!sent)
296                 return;
297
298         param = *((__u8 *) sent);
299
300         hci_dev_lock(hdev);
301
302         if (status) {
303                 mgmt_write_scan_failed(hdev, param, status);
304                 hdev->discov_timeout = 0;
305                 goto done;
306         }
307
308         old_pscan = test_and_clear_bit(HCI_PSCAN, &hdev->flags);
309         old_iscan = test_and_clear_bit(HCI_ISCAN, &hdev->flags);
310
311         if (param & SCAN_INQUIRY) {
312                 set_bit(HCI_ISCAN, &hdev->flags);
313                 if (!old_iscan)
314                         mgmt_discoverable(hdev, 1);
315                 if (hdev->discov_timeout > 0) {
316                         int to = msecs_to_jiffies(hdev->discov_timeout * 1000);
317                         queue_delayed_work(hdev->workqueue, &hdev->discov_off,
318                                            to);
319                 }
320         } else if (old_iscan)
321                 mgmt_discoverable(hdev, 0);
322
323         if (param & SCAN_PAGE) {
324                 set_bit(HCI_PSCAN, &hdev->flags);
325                 if (!old_pscan)
326                         mgmt_connectable(hdev, 1);
327         } else if (old_pscan)
328                 mgmt_connectable(hdev, 0);
329
330 done:
331         hci_dev_unlock(hdev);
332 }
333
334 static void hci_cc_read_class_of_dev(struct hci_dev *hdev, struct sk_buff *skb)
335 {
336         struct hci_rp_read_class_of_dev *rp = (void *) skb->data;
337
338         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
339
340         if (rp->status)
341                 return;
342
343         memcpy(hdev->dev_class, rp->dev_class, 3);
344
345         BT_DBG("%s class 0x%.2x%.2x%.2x", hdev->name,
346                hdev->dev_class[2], hdev->dev_class[1], hdev->dev_class[0]);
347 }
348
349 static void hci_cc_write_class_of_dev(struct hci_dev *hdev, struct sk_buff *skb)
350 {
351         __u8 status = *((__u8 *) skb->data);
352         void *sent;
353
354         BT_DBG("%s status 0x%2.2x", hdev->name, status);
355
356         sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_CLASS_OF_DEV);
357         if (!sent)
358                 return;
359
360         hci_dev_lock(hdev);
361
362         if (status == 0)
363                 memcpy(hdev->dev_class, sent, 3);
364
365         if (test_bit(HCI_MGMT, &hdev->dev_flags))
366                 mgmt_set_class_of_dev_complete(hdev, sent, status);
367
368         hci_dev_unlock(hdev);
369 }
370
371 static void hci_cc_read_voice_setting(struct hci_dev *hdev, struct sk_buff *skb)
372 {
373         struct hci_rp_read_voice_setting *rp = (void *) skb->data;
374         __u16 setting;
375
376         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
377
378         if (rp->status)
379                 return;
380
381         setting = __le16_to_cpu(rp->voice_setting);
382
383         if (hdev->voice_setting == setting)
384                 return;
385
386         hdev->voice_setting = setting;
387
388         BT_DBG("%s voice setting 0x%4.4x", hdev->name, setting);
389
390         if (hdev->notify)
391                 hdev->notify(hdev, HCI_NOTIFY_VOICE_SETTING);
392 }
393
394 static void hci_cc_write_voice_setting(struct hci_dev *hdev,
395                                        struct sk_buff *skb)
396 {
397         __u8 status = *((__u8 *) skb->data);
398         __u16 setting;
399         void *sent;
400
401         BT_DBG("%s status 0x%2.2x", hdev->name, status);
402
403         if (status)
404                 return;
405
406         sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_VOICE_SETTING);
407         if (!sent)
408                 return;
409
410         setting = get_unaligned_le16(sent);
411
412         if (hdev->voice_setting == setting)
413                 return;
414
415         hdev->voice_setting = setting;
416
417         BT_DBG("%s voice setting 0x%4.4x", hdev->name, setting);
418
419         if (hdev->notify)
420                 hdev->notify(hdev, HCI_NOTIFY_VOICE_SETTING);
421 }
422
423 static void hci_cc_write_ssp_mode(struct hci_dev *hdev, struct sk_buff *skb)
424 {
425         __u8 status = *((__u8 *) skb->data);
426         struct hci_cp_write_ssp_mode *sent;
427
428         BT_DBG("%s status 0x%2.2x", hdev->name, status);
429
430         sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_SSP_MODE);
431         if (!sent)
432                 return;
433
434         if (!status) {
435                 if (sent->mode)
436                         hdev->host_features[0] |= LMP_HOST_SSP;
437                 else
438                         hdev->host_features[0] &= ~LMP_HOST_SSP;
439         }
440
441         if (test_bit(HCI_MGMT, &hdev->dev_flags))
442                 mgmt_ssp_enable_complete(hdev, sent->mode, status);
443         else if (!status) {
444                 if (sent->mode)
445                         set_bit(HCI_SSP_ENABLED, &hdev->dev_flags);
446                 else
447                         clear_bit(HCI_SSP_ENABLED, &hdev->dev_flags);
448         }
449 }
450
451 static void hci_cc_read_local_version(struct hci_dev *hdev, struct sk_buff *skb)
452 {
453         struct hci_rp_read_local_version *rp = (void *) skb->data;
454
455         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
456
457         if (rp->status)
458                 return;
459
460         hdev->hci_ver = rp->hci_ver;
461         hdev->hci_rev = __le16_to_cpu(rp->hci_rev);
462         hdev->lmp_ver = rp->lmp_ver;
463         hdev->manufacturer = __le16_to_cpu(rp->manufacturer);
464         hdev->lmp_subver = __le16_to_cpu(rp->lmp_subver);
465
466         BT_DBG("%s manufacturer 0x%4.4x hci ver %d:%d", hdev->name,
467                hdev->manufacturer, hdev->hci_ver, hdev->hci_rev);
468 }
469
470 static void hci_cc_read_local_commands(struct hci_dev *hdev,
471                                        struct sk_buff *skb)
472 {
473         struct hci_rp_read_local_commands *rp = (void *) skb->data;
474
475         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
476
477         if (!rp->status)
478                 memcpy(hdev->commands, rp->commands, sizeof(hdev->commands));
479 }
480
481 static void hci_cc_read_local_features(struct hci_dev *hdev,
482                                        struct sk_buff *skb)
483 {
484         struct hci_rp_read_local_features *rp = (void *) skb->data;
485
486         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
487
488         if (rp->status)
489                 return;
490
491         memcpy(hdev->features, rp->features, 8);
492
493         /* Adjust default settings according to features
494          * supported by device. */
495
496         if (hdev->features[0] & LMP_3SLOT)
497                 hdev->pkt_type |= (HCI_DM3 | HCI_DH3);
498
499         if (hdev->features[0] & LMP_5SLOT)
500                 hdev->pkt_type |= (HCI_DM5 | HCI_DH5);
501
502         if (hdev->features[1] & LMP_HV2) {
503                 hdev->pkt_type  |= (HCI_HV2);
504                 hdev->esco_type |= (ESCO_HV2);
505         }
506
507         if (hdev->features[1] & LMP_HV3) {
508                 hdev->pkt_type  |= (HCI_HV3);
509                 hdev->esco_type |= (ESCO_HV3);
510         }
511
512         if (lmp_esco_capable(hdev))
513                 hdev->esco_type |= (ESCO_EV3);
514
515         if (hdev->features[4] & LMP_EV4)
516                 hdev->esco_type |= (ESCO_EV4);
517
518         if (hdev->features[4] & LMP_EV5)
519                 hdev->esco_type |= (ESCO_EV5);
520
521         if (hdev->features[5] & LMP_EDR_ESCO_2M)
522                 hdev->esco_type |= (ESCO_2EV3);
523
524         if (hdev->features[5] & LMP_EDR_ESCO_3M)
525                 hdev->esco_type |= (ESCO_3EV3);
526
527         if (hdev->features[5] & LMP_EDR_3S_ESCO)
528                 hdev->esco_type |= (ESCO_2EV5 | ESCO_3EV5);
529
530         BT_DBG("%s features 0x%.2x%.2x%.2x%.2x%.2x%.2x%.2x%.2x", hdev->name,
531                hdev->features[0], hdev->features[1],
532                hdev->features[2], hdev->features[3],
533                hdev->features[4], hdev->features[5],
534                hdev->features[6], hdev->features[7]);
535 }
536
537 static void hci_cc_read_local_ext_features(struct hci_dev *hdev,
538                                            struct sk_buff *skb)
539 {
540         struct hci_rp_read_local_ext_features *rp = (void *) skb->data;
541
542         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
543
544         if (rp->status)
545                 return;
546
547         switch (rp->page) {
548         case 0:
549                 memcpy(hdev->features, rp->features, 8);
550                 break;
551         case 1:
552                 memcpy(hdev->host_features, rp->features, 8);
553                 break;
554         }
555 }
556
557 static void hci_cc_read_flow_control_mode(struct hci_dev *hdev,
558                                           struct sk_buff *skb)
559 {
560         struct hci_rp_read_flow_control_mode *rp = (void *) skb->data;
561
562         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
563
564         if (!rp->status)
565                 hdev->flow_ctl_mode = rp->mode;
566 }
567
568 static void hci_cc_read_buffer_size(struct hci_dev *hdev, struct sk_buff *skb)
569 {
570         struct hci_rp_read_buffer_size *rp = (void *) skb->data;
571
572         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
573
574         if (rp->status)
575                 return;
576
577         hdev->acl_mtu  = __le16_to_cpu(rp->acl_mtu);
578         hdev->sco_mtu  = rp->sco_mtu;
579         hdev->acl_pkts = __le16_to_cpu(rp->acl_max_pkt);
580         hdev->sco_pkts = __le16_to_cpu(rp->sco_max_pkt);
581
582         if (test_bit(HCI_QUIRK_FIXUP_BUFFER_SIZE, &hdev->quirks)) {
583                 hdev->sco_mtu  = 64;
584                 hdev->sco_pkts = 8;
585         }
586
587         hdev->acl_cnt = hdev->acl_pkts;
588         hdev->sco_cnt = hdev->sco_pkts;
589
590         BT_DBG("%s acl mtu %d:%d sco mtu %d:%d", hdev->name, hdev->acl_mtu,
591                hdev->acl_pkts, hdev->sco_mtu, hdev->sco_pkts);
592 }
593
594 static void hci_cc_read_bd_addr(struct hci_dev *hdev, struct sk_buff *skb)
595 {
596         struct hci_rp_read_bd_addr *rp = (void *) skb->data;
597
598         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
599
600         if (!rp->status)
601                 bacpy(&hdev->bdaddr, &rp->bdaddr);
602 }
603
604 static void hci_cc_read_page_scan_activity(struct hci_dev *hdev,
605                                            struct sk_buff *skb)
606 {
607         struct hci_rp_read_page_scan_activity *rp = (void *) skb->data;
608
609         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
610
611         if (test_bit(HCI_INIT, &hdev->flags) && !rp->status) {
612                 hdev->page_scan_interval = __le16_to_cpu(rp->interval);
613                 hdev->page_scan_window = __le16_to_cpu(rp->window);
614         }
615 }
616
617 static void hci_cc_read_page_scan_type(struct hci_dev *hdev,
618                                            struct sk_buff *skb)
619 {
620         struct hci_rp_read_page_scan_type *rp = (void *) skb->data;
621
622         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
623
624         if (test_bit(HCI_INIT, &hdev->flags) && !rp->status)
625                 hdev->page_scan_type = rp->type;
626 }
627
628 static void hci_cc_read_data_block_size(struct hci_dev *hdev,
629                                         struct sk_buff *skb)
630 {
631         struct hci_rp_read_data_block_size *rp = (void *) skb->data;
632
633         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
634
635         if (rp->status)
636                 return;
637
638         hdev->block_mtu = __le16_to_cpu(rp->max_acl_len);
639         hdev->block_len = __le16_to_cpu(rp->block_len);
640         hdev->num_blocks = __le16_to_cpu(rp->num_blocks);
641
642         hdev->block_cnt = hdev->num_blocks;
643
644         BT_DBG("%s blk mtu %d cnt %d len %d", hdev->name, hdev->block_mtu,
645                hdev->block_cnt, hdev->block_len);
646 }
647
648 static void hci_cc_read_local_amp_info(struct hci_dev *hdev,
649                                        struct sk_buff *skb)
650 {
651         struct hci_rp_read_local_amp_info *rp = (void *) skb->data;
652
653         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
654
655         if (rp->status)
656                 goto a2mp_rsp;
657
658         hdev->amp_status = rp->amp_status;
659         hdev->amp_total_bw = __le32_to_cpu(rp->total_bw);
660         hdev->amp_max_bw = __le32_to_cpu(rp->max_bw);
661         hdev->amp_min_latency = __le32_to_cpu(rp->min_latency);
662         hdev->amp_max_pdu = __le32_to_cpu(rp->max_pdu);
663         hdev->amp_type = rp->amp_type;
664         hdev->amp_pal_cap = __le16_to_cpu(rp->pal_cap);
665         hdev->amp_assoc_size = __le16_to_cpu(rp->max_assoc_size);
666         hdev->amp_be_flush_to = __le32_to_cpu(rp->be_flush_to);
667         hdev->amp_max_flush_to = __le32_to_cpu(rp->max_flush_to);
668
669 a2mp_rsp:
670         a2mp_send_getinfo_rsp(hdev);
671 }
672
673 static void hci_cc_read_local_amp_assoc(struct hci_dev *hdev,
674                                         struct sk_buff *skb)
675 {
676         struct hci_rp_read_local_amp_assoc *rp = (void *) skb->data;
677         struct amp_assoc *assoc = &hdev->loc_assoc;
678         size_t rem_len, frag_len;
679
680         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
681
682         if (rp->status)
683                 goto a2mp_rsp;
684
685         frag_len = skb->len - sizeof(*rp);
686         rem_len = __le16_to_cpu(rp->rem_len);
687
688         if (rem_len > frag_len) {
689                 BT_DBG("frag_len %zu rem_len %zu", frag_len, rem_len);
690
691                 memcpy(assoc->data + assoc->offset, rp->frag, frag_len);
692                 assoc->offset += frag_len;
693
694                 /* Read other fragments */
695                 amp_read_loc_assoc_frag(hdev, rp->phy_handle);
696
697                 return;
698         }
699
700         memcpy(assoc->data + assoc->offset, rp->frag, rem_len);
701         assoc->len = assoc->offset + rem_len;
702         assoc->offset = 0;
703
704 a2mp_rsp:
705         /* Send A2MP Rsp when all fragments are received */
706         a2mp_send_getampassoc_rsp(hdev, rp->status);
707         a2mp_send_create_phy_link_req(hdev, rp->status);
708 }
709
710 static void hci_cc_read_inq_rsp_tx_power(struct hci_dev *hdev,
711                                          struct sk_buff *skb)
712 {
713         struct hci_rp_read_inq_rsp_tx_power *rp = (void *) skb->data;
714
715         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
716
717         if (!rp->status)
718                 hdev->inq_tx_power = rp->tx_power;
719 }
720
721 static void hci_cc_pin_code_reply(struct hci_dev *hdev, struct sk_buff *skb)
722 {
723         struct hci_rp_pin_code_reply *rp = (void *) skb->data;
724         struct hci_cp_pin_code_reply *cp;
725         struct hci_conn *conn;
726
727         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
728
729         hci_dev_lock(hdev);
730
731         if (test_bit(HCI_MGMT, &hdev->dev_flags))
732                 mgmt_pin_code_reply_complete(hdev, &rp->bdaddr, rp->status);
733
734         if (rp->status)
735                 goto unlock;
736
737         cp = hci_sent_cmd_data(hdev, HCI_OP_PIN_CODE_REPLY);
738         if (!cp)
739                 goto unlock;
740
741         conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &cp->bdaddr);
742         if (conn)
743                 conn->pin_length = cp->pin_len;
744
745 unlock:
746         hci_dev_unlock(hdev);
747 }
748
749 static void hci_cc_pin_code_neg_reply(struct hci_dev *hdev, struct sk_buff *skb)
750 {
751         struct hci_rp_pin_code_neg_reply *rp = (void *) skb->data;
752
753         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
754
755         hci_dev_lock(hdev);
756
757         if (test_bit(HCI_MGMT, &hdev->dev_flags))
758                 mgmt_pin_code_neg_reply_complete(hdev, &rp->bdaddr,
759                                                  rp->status);
760
761         hci_dev_unlock(hdev);
762 }
763
764 static void hci_cc_le_read_buffer_size(struct hci_dev *hdev,
765                                        struct sk_buff *skb)
766 {
767         struct hci_rp_le_read_buffer_size *rp = (void *) skb->data;
768
769         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
770
771         if (rp->status)
772                 return;
773
774         hdev->le_mtu = __le16_to_cpu(rp->le_mtu);
775         hdev->le_pkts = rp->le_max_pkt;
776
777         hdev->le_cnt = hdev->le_pkts;
778
779         BT_DBG("%s le mtu %d:%d", hdev->name, hdev->le_mtu, hdev->le_pkts);
780 }
781
782 static void hci_cc_le_read_local_features(struct hci_dev *hdev,
783                                           struct sk_buff *skb)
784 {
785         struct hci_rp_le_read_local_features *rp = (void *) skb->data;
786
787         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
788
789         if (!rp->status)
790                 memcpy(hdev->le_features, rp->features, 8);
791 }
792
793 static void hci_cc_le_read_adv_tx_power(struct hci_dev *hdev,
794                                         struct sk_buff *skb)
795 {
796         struct hci_rp_le_read_adv_tx_power *rp = (void *) skb->data;
797
798         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
799
800         if (!rp->status)
801                 hdev->adv_tx_power = rp->tx_power;
802 }
803
804 static void hci_cc_user_confirm_reply(struct hci_dev *hdev, struct sk_buff *skb)
805 {
806         struct hci_rp_user_confirm_reply *rp = (void *) skb->data;
807
808         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
809
810         hci_dev_lock(hdev);
811
812         if (test_bit(HCI_MGMT, &hdev->dev_flags))
813                 mgmt_user_confirm_reply_complete(hdev, &rp->bdaddr, ACL_LINK, 0,
814                                                  rp->status);
815
816         hci_dev_unlock(hdev);
817 }
818
819 static void hci_cc_user_confirm_neg_reply(struct hci_dev *hdev,
820                                           struct sk_buff *skb)
821 {
822         struct hci_rp_user_confirm_reply *rp = (void *) skb->data;
823
824         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
825
826         hci_dev_lock(hdev);
827
828         if (test_bit(HCI_MGMT, &hdev->dev_flags))
829                 mgmt_user_confirm_neg_reply_complete(hdev, &rp->bdaddr,
830                                                      ACL_LINK, 0, rp->status);
831
832         hci_dev_unlock(hdev);
833 }
834
835 static void hci_cc_user_passkey_reply(struct hci_dev *hdev, struct sk_buff *skb)
836 {
837         struct hci_rp_user_confirm_reply *rp = (void *) skb->data;
838
839         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
840
841         hci_dev_lock(hdev);
842
843         if (test_bit(HCI_MGMT, &hdev->dev_flags))
844                 mgmt_user_passkey_reply_complete(hdev, &rp->bdaddr, ACL_LINK,
845                                                  0, rp->status);
846
847         hci_dev_unlock(hdev);
848 }
849
850 static void hci_cc_user_passkey_neg_reply(struct hci_dev *hdev,
851                                           struct sk_buff *skb)
852 {
853         struct hci_rp_user_confirm_reply *rp = (void *) skb->data;
854
855         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
856
857         hci_dev_lock(hdev);
858
859         if (test_bit(HCI_MGMT, &hdev->dev_flags))
860                 mgmt_user_passkey_neg_reply_complete(hdev, &rp->bdaddr,
861                                                      ACL_LINK, 0, rp->status);
862
863         hci_dev_unlock(hdev);
864 }
865
866 static void hci_cc_read_local_oob_data_reply(struct hci_dev *hdev,
867                                              struct sk_buff *skb)
868 {
869         struct hci_rp_read_local_oob_data *rp = (void *) skb->data;
870
871         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
872
873         hci_dev_lock(hdev);
874         mgmt_read_local_oob_data_reply_complete(hdev, rp->hash,
875                                                 rp->randomizer, rp->status);
876         hci_dev_unlock(hdev);
877 }
878
879 static void hci_cc_le_set_adv_enable(struct hci_dev *hdev, struct sk_buff *skb)
880 {
881         __u8 *sent, status = *((__u8 *) skb->data);
882
883         BT_DBG("%s status 0x%2.2x", hdev->name, status);
884
885         sent = hci_sent_cmd_data(hdev, HCI_OP_LE_SET_ADV_ENABLE);
886         if (!sent)
887                 return;
888
889         hci_dev_lock(hdev);
890
891         if (!status) {
892                 if (*sent)
893                         set_bit(HCI_LE_PERIPHERAL, &hdev->dev_flags);
894                 else
895                         clear_bit(HCI_LE_PERIPHERAL, &hdev->dev_flags);
896         }
897
898         if (!test_bit(HCI_INIT, &hdev->flags)) {
899                 struct hci_request req;
900
901                 hci_req_init(&req, hdev);
902                 hci_update_ad(&req);
903                 hci_req_run(&req, NULL);
904         }
905
906         hci_dev_unlock(hdev);
907 }
908
909 static void hci_cc_le_set_scan_param(struct hci_dev *hdev, struct sk_buff *skb)
910 {
911         __u8 status = *((__u8 *) skb->data);
912
913         BT_DBG("%s status 0x%2.2x", hdev->name, status);
914
915         if (status) {
916                 hci_dev_lock(hdev);
917                 mgmt_start_discovery_failed(hdev, status);
918                 hci_dev_unlock(hdev);
919                 return;
920         }
921 }
922
923 static void hci_cc_le_set_scan_enable(struct hci_dev *hdev,
924                                       struct sk_buff *skb)
925 {
926         struct hci_cp_le_set_scan_enable *cp;
927         __u8 status = *((__u8 *) skb->data);
928
929         BT_DBG("%s status 0x%2.2x", hdev->name, status);
930
931         cp = hci_sent_cmd_data(hdev, HCI_OP_LE_SET_SCAN_ENABLE);
932         if (!cp)
933                 return;
934
935         switch (cp->enable) {
936         case LE_SCANNING_ENABLED:
937                 if (status) {
938                         hci_dev_lock(hdev);
939                         mgmt_start_discovery_failed(hdev, status);
940                         hci_dev_unlock(hdev);
941                         return;
942                 }
943
944                 set_bit(HCI_LE_SCAN, &hdev->dev_flags);
945
946                 hci_dev_lock(hdev);
947                 hci_discovery_set_state(hdev, DISCOVERY_FINDING);
948                 hci_dev_unlock(hdev);
949                 break;
950
951         case LE_SCANNING_DISABLED:
952                 if (status) {
953                         hci_dev_lock(hdev);
954                         mgmt_stop_discovery_failed(hdev, status);
955                         hci_dev_unlock(hdev);
956                         return;
957                 }
958
959                 clear_bit(HCI_LE_SCAN, &hdev->dev_flags);
960
961                 if (hdev->discovery.type == DISCOV_TYPE_INTERLEAVED &&
962                     hdev->discovery.state == DISCOVERY_FINDING) {
963                         mgmt_interleaved_discovery(hdev);
964                 } else {
965                         hci_dev_lock(hdev);
966                         hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
967                         hci_dev_unlock(hdev);
968                 }
969
970                 break;
971
972         default:
973                 BT_ERR("Used reserved LE_Scan_Enable param %d", cp->enable);
974                 break;
975         }
976 }
977
978 static void hci_cc_le_read_white_list_size(struct hci_dev *hdev,
979                                            struct sk_buff *skb)
980 {
981         struct hci_rp_le_read_white_list_size *rp = (void *) skb->data;
982
983         BT_DBG("%s status 0x%2.2x size %u", hdev->name, rp->status, rp->size);
984
985         if (!rp->status)
986                 hdev->le_white_list_size = rp->size;
987 }
988
989 static void hci_cc_le_read_supported_states(struct hci_dev *hdev,
990                                             struct sk_buff *skb)
991 {
992         struct hci_rp_le_read_supported_states *rp = (void *) skb->data;
993
994         BT_DBG("%s status 0x%2.2x", hdev->name, rp->status);
995
996         if (!rp->status)
997                 memcpy(hdev->le_states, rp->le_states, 8);
998 }
999
1000 static void hci_cc_write_le_host_supported(struct hci_dev *hdev,
1001                                            struct sk_buff *skb)
1002 {
1003         struct hci_cp_write_le_host_supported *sent;
1004         __u8 status = *((__u8 *) skb->data);
1005
1006         BT_DBG("%s status 0x%2.2x", hdev->name, status);
1007
1008         sent = hci_sent_cmd_data(hdev, HCI_OP_WRITE_LE_HOST_SUPPORTED);
1009         if (!sent)
1010                 return;
1011
1012         if (!status) {
1013                 if (sent->le)
1014                         hdev->host_features[0] |= LMP_HOST_LE;
1015                 else
1016                         hdev->host_features[0] &= ~LMP_HOST_LE;
1017
1018                 if (sent->simul)
1019                         hdev->host_features[0] |= LMP_HOST_LE_BREDR;
1020                 else
1021                         hdev->host_features[0] &= ~LMP_HOST_LE_BREDR;
1022         }
1023
1024         if (test_bit(HCI_MGMT, &hdev->dev_flags) &&
1025             !test_bit(HCI_INIT, &hdev->flags))
1026                 mgmt_le_enable_complete(hdev, sent->le, status);
1027 }
1028
1029 static void hci_cc_write_remote_amp_assoc(struct hci_dev *hdev,
1030                                           struct sk_buff *skb)
1031 {
1032         struct hci_rp_write_remote_amp_assoc *rp = (void *) skb->data;
1033
1034         BT_DBG("%s status 0x%2.2x phy_handle 0x%2.2x",
1035                hdev->name, rp->status, rp->phy_handle);
1036
1037         if (rp->status)
1038                 return;
1039
1040         amp_write_rem_assoc_continue(hdev, rp->phy_handle);
1041 }
1042
1043 static void hci_cs_inquiry(struct hci_dev *hdev, __u8 status)
1044 {
1045         BT_DBG("%s status 0x%2.2x", hdev->name, status);
1046
1047         if (status) {
1048                 hci_conn_check_pending(hdev);
1049                 hci_dev_lock(hdev);
1050                 if (test_bit(HCI_MGMT, &hdev->dev_flags))
1051                         mgmt_start_discovery_failed(hdev, status);
1052                 hci_dev_unlock(hdev);
1053                 return;
1054         }
1055
1056         set_bit(HCI_INQUIRY, &hdev->flags);
1057
1058         hci_dev_lock(hdev);
1059         hci_discovery_set_state(hdev, DISCOVERY_FINDING);
1060         hci_dev_unlock(hdev);
1061 }
1062
1063 static void hci_cs_create_conn(struct hci_dev *hdev, __u8 status)
1064 {
1065         struct hci_cp_create_conn *cp;
1066         struct hci_conn *conn;
1067
1068         BT_DBG("%s status 0x%2.2x", hdev->name, status);
1069
1070         cp = hci_sent_cmd_data(hdev, HCI_OP_CREATE_CONN);
1071         if (!cp)
1072                 return;
1073
1074         hci_dev_lock(hdev);
1075
1076         conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &cp->bdaddr);
1077
1078         BT_DBG("%s bdaddr %pMR hcon %p", hdev->name, &cp->bdaddr, conn);
1079
1080         if (status) {
1081                 if (conn && conn->state == BT_CONNECT) {
1082                         if (status != 0x0c || conn->attempt > 2) {
1083                                 conn->state = BT_CLOSED;
1084                                 hci_proto_connect_cfm(conn, status);
1085                                 hci_conn_del(conn);
1086                         } else
1087                                 conn->state = BT_CONNECT2;
1088                 }
1089         } else {
1090                 if (!conn) {
1091                         conn = hci_conn_add(hdev, ACL_LINK, &cp->bdaddr);
1092                         if (conn) {
1093                                 conn->out = true;
1094                                 conn->link_mode |= HCI_LM_MASTER;
1095                         } else
1096                                 BT_ERR("No memory for new connection");
1097                 }
1098         }
1099
1100         hci_dev_unlock(hdev);
1101 }
1102
1103 static void hci_cs_add_sco(struct hci_dev *hdev, __u8 status)
1104 {
1105         struct hci_cp_add_sco *cp;
1106         struct hci_conn *acl, *sco;
1107         __u16 handle;
1108
1109         BT_DBG("%s status 0x%2.2x", hdev->name, status);
1110
1111         if (!status)
1112                 return;
1113
1114         cp = hci_sent_cmd_data(hdev, HCI_OP_ADD_SCO);
1115         if (!cp)
1116                 return;
1117
1118         handle = __le16_to_cpu(cp->handle);
1119
1120         BT_DBG("%s handle 0x%4.4x", hdev->name, handle);
1121
1122         hci_dev_lock(hdev);
1123
1124         acl = hci_conn_hash_lookup_handle(hdev, handle);
1125         if (acl) {
1126                 sco = acl->link;
1127                 if (sco) {
1128                         sco->state = BT_CLOSED;
1129
1130                         hci_proto_connect_cfm(sco, status);
1131                         hci_conn_del(sco);
1132                 }
1133         }
1134
1135         hci_dev_unlock(hdev);
1136 }
1137
1138 static void hci_cs_auth_requested(struct hci_dev *hdev, __u8 status)
1139 {
1140         struct hci_cp_auth_requested *cp;
1141         struct hci_conn *conn;
1142
1143         BT_DBG("%s status 0x%2.2x", hdev->name, status);
1144
1145         if (!status)
1146                 return;
1147
1148         cp = hci_sent_cmd_data(hdev, HCI_OP_AUTH_REQUESTED);
1149         if (!cp)
1150                 return;
1151
1152         hci_dev_lock(hdev);
1153
1154         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
1155         if (conn) {
1156                 if (conn->state == BT_CONFIG) {
1157                         hci_proto_connect_cfm(conn, status);
1158                         hci_conn_put(conn);
1159                 }
1160         }
1161
1162         hci_dev_unlock(hdev);
1163 }
1164
1165 static void hci_cs_set_conn_encrypt(struct hci_dev *hdev, __u8 status)
1166 {
1167         struct hci_cp_set_conn_encrypt *cp;
1168         struct hci_conn *conn;
1169
1170         BT_DBG("%s status 0x%2.2x", hdev->name, status);
1171
1172         if (!status)
1173                 return;
1174
1175         cp = hci_sent_cmd_data(hdev, HCI_OP_SET_CONN_ENCRYPT);
1176         if (!cp)
1177                 return;
1178
1179         hci_dev_lock(hdev);
1180
1181         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
1182         if (conn) {
1183                 if (conn->state == BT_CONFIG) {
1184                         hci_proto_connect_cfm(conn, status);
1185                         hci_conn_put(conn);
1186                 }
1187         }
1188
1189         hci_dev_unlock(hdev);
1190 }
1191
1192 static int hci_outgoing_auth_needed(struct hci_dev *hdev,
1193                                     struct hci_conn *conn)
1194 {
1195         if (conn->state != BT_CONFIG || !conn->out)
1196                 return 0;
1197
1198         if (conn->pending_sec_level == BT_SECURITY_SDP)
1199                 return 0;
1200
1201         /* Only request authentication for SSP connections or non-SSP
1202          * devices with sec_level HIGH or if MITM protection is requested */
1203         if (!hci_conn_ssp_enabled(conn) && !(conn->auth_type & 0x01) &&
1204             conn->pending_sec_level != BT_SECURITY_HIGH)
1205                 return 0;
1206
1207         return 1;
1208 }
1209
1210 static int hci_resolve_name(struct hci_dev *hdev,
1211                                    struct inquiry_entry *e)
1212 {
1213         struct hci_cp_remote_name_req cp;
1214
1215         memset(&cp, 0, sizeof(cp));
1216
1217         bacpy(&cp.bdaddr, &e->data.bdaddr);
1218         cp.pscan_rep_mode = e->data.pscan_rep_mode;
1219         cp.pscan_mode = e->data.pscan_mode;
1220         cp.clock_offset = e->data.clock_offset;
1221
1222         return hci_send_cmd(hdev, HCI_OP_REMOTE_NAME_REQ, sizeof(cp), &cp);
1223 }
1224
1225 static bool hci_resolve_next_name(struct hci_dev *hdev)
1226 {
1227         struct discovery_state *discov = &hdev->discovery;
1228         struct inquiry_entry *e;
1229
1230         if (list_empty(&discov->resolve))
1231                 return false;
1232
1233         e = hci_inquiry_cache_lookup_resolve(hdev, BDADDR_ANY, NAME_NEEDED);
1234         if (!e)
1235                 return false;
1236
1237         if (hci_resolve_name(hdev, e) == 0) {
1238                 e->name_state = NAME_PENDING;
1239                 return true;
1240         }
1241
1242         return false;
1243 }
1244
1245 static void hci_check_pending_name(struct hci_dev *hdev, struct hci_conn *conn,
1246                                    bdaddr_t *bdaddr, u8 *name, u8 name_len)
1247 {
1248         struct discovery_state *discov = &hdev->discovery;
1249         struct inquiry_entry *e;
1250
1251         if (conn && !test_and_set_bit(HCI_CONN_MGMT_CONNECTED, &conn->flags))
1252                 mgmt_device_connected(hdev, bdaddr, ACL_LINK, 0x00, 0, name,
1253                                       name_len, conn->dev_class);
1254
1255         if (discov->state == DISCOVERY_STOPPED)
1256                 return;
1257
1258         if (discov->state == DISCOVERY_STOPPING)
1259                 goto discov_complete;
1260
1261         if (discov->state != DISCOVERY_RESOLVING)
1262                 return;
1263
1264         e = hci_inquiry_cache_lookup_resolve(hdev, bdaddr, NAME_PENDING);
1265         /* If the device was not found in a list of found devices names of which
1266          * are pending. there is no need to continue resolving a next name as it
1267          * will be done upon receiving another Remote Name Request Complete
1268          * Event */
1269         if (!e)
1270                 return;
1271
1272         list_del(&e->list);
1273         if (name) {
1274                 e->name_state = NAME_KNOWN;
1275                 mgmt_remote_name(hdev, bdaddr, ACL_LINK, 0x00,
1276                                  e->data.rssi, name, name_len);
1277         } else {
1278                 e->name_state = NAME_NOT_KNOWN;
1279         }
1280
1281         if (hci_resolve_next_name(hdev))
1282                 return;
1283
1284 discov_complete:
1285         hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
1286 }
1287
1288 static void hci_cs_remote_name_req(struct hci_dev *hdev, __u8 status)
1289 {
1290         struct hci_cp_remote_name_req *cp;
1291         struct hci_conn *conn;
1292
1293         BT_DBG("%s status 0x%2.2x", hdev->name, status);
1294
1295         /* If successful wait for the name req complete event before
1296          * checking for the need to do authentication */
1297         if (!status)
1298                 return;
1299
1300         cp = hci_sent_cmd_data(hdev, HCI_OP_REMOTE_NAME_REQ);
1301         if (!cp)
1302                 return;
1303
1304         hci_dev_lock(hdev);
1305
1306         conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &cp->bdaddr);
1307
1308         if (test_bit(HCI_MGMT, &hdev->dev_flags))
1309                 hci_check_pending_name(hdev, conn, &cp->bdaddr, NULL, 0);
1310
1311         if (!conn)
1312                 goto unlock;
1313
1314         if (!hci_outgoing_auth_needed(hdev, conn))
1315                 goto unlock;
1316
1317         if (!test_and_set_bit(HCI_CONN_AUTH_PEND, &conn->flags)) {
1318                 struct hci_cp_auth_requested cp;
1319                 cp.handle = __cpu_to_le16(conn->handle);
1320                 hci_send_cmd(hdev, HCI_OP_AUTH_REQUESTED, sizeof(cp), &cp);
1321         }
1322
1323 unlock:
1324         hci_dev_unlock(hdev);
1325 }
1326
1327 static void hci_cs_read_remote_features(struct hci_dev *hdev, __u8 status)
1328 {
1329         struct hci_cp_read_remote_features *cp;
1330         struct hci_conn *conn;
1331
1332         BT_DBG("%s status 0x%2.2x", hdev->name, status);
1333
1334         if (!status)
1335                 return;
1336
1337         cp = hci_sent_cmd_data(hdev, HCI_OP_READ_REMOTE_FEATURES);
1338         if (!cp)
1339                 return;
1340
1341         hci_dev_lock(hdev);
1342
1343         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
1344         if (conn) {
1345                 if (conn->state == BT_CONFIG) {
1346                         hci_proto_connect_cfm(conn, status);
1347                         hci_conn_put(conn);
1348                 }
1349         }
1350
1351         hci_dev_unlock(hdev);
1352 }
1353
1354 static void hci_cs_read_remote_ext_features(struct hci_dev *hdev, __u8 status)
1355 {
1356         struct hci_cp_read_remote_ext_features *cp;
1357         struct hci_conn *conn;
1358
1359         BT_DBG("%s status 0x%2.2x", hdev->name, status);
1360
1361         if (!status)
1362                 return;
1363
1364         cp = hci_sent_cmd_data(hdev, HCI_OP_READ_REMOTE_EXT_FEATURES);
1365         if (!cp)
1366                 return;
1367
1368         hci_dev_lock(hdev);
1369
1370         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
1371         if (conn) {
1372                 if (conn->state == BT_CONFIG) {
1373                         hci_proto_connect_cfm(conn, status);
1374                         hci_conn_put(conn);
1375                 }
1376         }
1377
1378         hci_dev_unlock(hdev);
1379 }
1380
1381 static void hci_cs_setup_sync_conn(struct hci_dev *hdev, __u8 status)
1382 {
1383         struct hci_cp_setup_sync_conn *cp;
1384         struct hci_conn *acl, *sco;
1385         __u16 handle;
1386
1387         BT_DBG("%s status 0x%2.2x", hdev->name, status);
1388
1389         if (!status)
1390                 return;
1391
1392         cp = hci_sent_cmd_data(hdev, HCI_OP_SETUP_SYNC_CONN);
1393         if (!cp)
1394                 return;
1395
1396         handle = __le16_to_cpu(cp->handle);
1397
1398         BT_DBG("%s handle 0x%4.4x", hdev->name, handle);
1399
1400         hci_dev_lock(hdev);
1401
1402         acl = hci_conn_hash_lookup_handle(hdev, handle);
1403         if (acl) {
1404                 sco = acl->link;
1405                 if (sco) {
1406                         sco->state = BT_CLOSED;
1407
1408                         hci_proto_connect_cfm(sco, status);
1409                         hci_conn_del(sco);
1410                 }
1411         }
1412
1413         hci_dev_unlock(hdev);
1414 }
1415
1416 static void hci_cs_sniff_mode(struct hci_dev *hdev, __u8 status)
1417 {
1418         struct hci_cp_sniff_mode *cp;
1419         struct hci_conn *conn;
1420
1421         BT_DBG("%s status 0x%2.2x", hdev->name, status);
1422
1423         if (!status)
1424                 return;
1425
1426         cp = hci_sent_cmd_data(hdev, HCI_OP_SNIFF_MODE);
1427         if (!cp)
1428                 return;
1429
1430         hci_dev_lock(hdev);
1431
1432         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
1433         if (conn) {
1434                 clear_bit(HCI_CONN_MODE_CHANGE_PEND, &conn->flags);
1435
1436                 if (test_and_clear_bit(HCI_CONN_SCO_SETUP_PEND, &conn->flags))
1437                         hci_sco_setup(conn, status);
1438         }
1439
1440         hci_dev_unlock(hdev);
1441 }
1442
1443 static void hci_cs_exit_sniff_mode(struct hci_dev *hdev, __u8 status)
1444 {
1445         struct hci_cp_exit_sniff_mode *cp;
1446         struct hci_conn *conn;
1447
1448         BT_DBG("%s status 0x%2.2x", hdev->name, status);
1449
1450         if (!status)
1451                 return;
1452
1453         cp = hci_sent_cmd_data(hdev, HCI_OP_EXIT_SNIFF_MODE);
1454         if (!cp)
1455                 return;
1456
1457         hci_dev_lock(hdev);
1458
1459         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
1460         if (conn) {
1461                 clear_bit(HCI_CONN_MODE_CHANGE_PEND, &conn->flags);
1462
1463                 if (test_and_clear_bit(HCI_CONN_SCO_SETUP_PEND, &conn->flags))
1464                         hci_sco_setup(conn, status);
1465         }
1466
1467         hci_dev_unlock(hdev);
1468 }
1469
1470 static void hci_cs_disconnect(struct hci_dev *hdev, u8 status)
1471 {
1472         struct hci_cp_disconnect *cp;
1473         struct hci_conn *conn;
1474
1475         if (!status)
1476                 return;
1477
1478         cp = hci_sent_cmd_data(hdev, HCI_OP_DISCONNECT);
1479         if (!cp)
1480                 return;
1481
1482         hci_dev_lock(hdev);
1483
1484         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(cp->handle));
1485         if (conn)
1486                 mgmt_disconnect_failed(hdev, &conn->dst, conn->type,
1487                                        conn->dst_type, status);
1488
1489         hci_dev_unlock(hdev);
1490 }
1491
1492 static void hci_cs_le_create_conn(struct hci_dev *hdev, __u8 status)
1493 {
1494         struct hci_conn *conn;
1495
1496         BT_DBG("%s status 0x%2.2x", hdev->name, status);
1497
1498         if (status) {
1499                 hci_dev_lock(hdev);
1500
1501                 conn = hci_conn_hash_lookup_state(hdev, LE_LINK, BT_CONNECT);
1502                 if (!conn) {
1503                         hci_dev_unlock(hdev);
1504                         return;
1505                 }
1506
1507                 BT_DBG("%s bdaddr %pMR conn %p", hdev->name, &conn->dst, conn);
1508
1509                 conn->state = BT_CLOSED;
1510                 mgmt_connect_failed(hdev, &conn->dst, conn->type,
1511                                     conn->dst_type, status);
1512                 hci_proto_connect_cfm(conn, status);
1513                 hci_conn_del(conn);
1514
1515                 hci_dev_unlock(hdev);
1516         }
1517 }
1518
1519 static void hci_cs_create_phylink(struct hci_dev *hdev, u8 status)
1520 {
1521         struct hci_cp_create_phy_link *cp;
1522
1523         BT_DBG("%s status 0x%2.2x", hdev->name, status);
1524
1525         cp = hci_sent_cmd_data(hdev, HCI_OP_CREATE_PHY_LINK);
1526         if (!cp)
1527                 return;
1528
1529         hci_dev_lock(hdev);
1530
1531         if (status) {
1532                 struct hci_conn *hcon;
1533
1534                 hcon = hci_conn_hash_lookup_handle(hdev, cp->phy_handle);
1535                 if (hcon)
1536                         hci_conn_del(hcon);
1537         } else {
1538                 amp_write_remote_assoc(hdev, cp->phy_handle);
1539         }
1540
1541         hci_dev_unlock(hdev);
1542 }
1543
1544 static void hci_cs_accept_phylink(struct hci_dev *hdev, u8 status)
1545 {
1546         struct hci_cp_accept_phy_link *cp;
1547
1548         BT_DBG("%s status 0x%2.2x", hdev->name, status);
1549
1550         if (status)
1551                 return;
1552
1553         cp = hci_sent_cmd_data(hdev, HCI_OP_ACCEPT_PHY_LINK);
1554         if (!cp)
1555                 return;
1556
1557         amp_write_remote_assoc(hdev, cp->phy_handle);
1558 }
1559
1560 static void hci_inquiry_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
1561 {
1562         __u8 status = *((__u8 *) skb->data);
1563         struct discovery_state *discov = &hdev->discovery;
1564         struct inquiry_entry *e;
1565
1566         BT_DBG("%s status 0x%2.2x", hdev->name, status);
1567
1568         hci_req_cmd_complete(hdev, HCI_OP_INQUIRY, status);
1569
1570         hci_conn_check_pending(hdev);
1571
1572         if (!test_and_clear_bit(HCI_INQUIRY, &hdev->flags))
1573                 return;
1574
1575         if (!test_bit(HCI_MGMT, &hdev->dev_flags))
1576                 return;
1577
1578         hci_dev_lock(hdev);
1579
1580         if (discov->state != DISCOVERY_FINDING)
1581                 goto unlock;
1582
1583         if (list_empty(&discov->resolve)) {
1584                 hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
1585                 goto unlock;
1586         }
1587
1588         e = hci_inquiry_cache_lookup_resolve(hdev, BDADDR_ANY, NAME_NEEDED);
1589         if (e && hci_resolve_name(hdev, e) == 0) {
1590                 e->name_state = NAME_PENDING;
1591                 hci_discovery_set_state(hdev, DISCOVERY_RESOLVING);
1592         } else {
1593                 hci_discovery_set_state(hdev, DISCOVERY_STOPPED);
1594         }
1595
1596 unlock:
1597         hci_dev_unlock(hdev);
1598 }
1599
1600 static void hci_inquiry_result_evt(struct hci_dev *hdev, struct sk_buff *skb)
1601 {
1602         struct inquiry_data data;
1603         struct inquiry_info *info = (void *) (skb->data + 1);
1604         int num_rsp = *((__u8 *) skb->data);
1605
1606         BT_DBG("%s num_rsp %d", hdev->name, num_rsp);
1607
1608         if (!num_rsp)
1609                 return;
1610
1611         if (test_bit(HCI_PERIODIC_INQ, &hdev->dev_flags))
1612                 return;
1613
1614         hci_dev_lock(hdev);
1615
1616         for (; num_rsp; num_rsp--, info++) {
1617                 bool name_known, ssp;
1618
1619                 bacpy(&data.bdaddr, &info->bdaddr);
1620                 data.pscan_rep_mode     = info->pscan_rep_mode;
1621                 data.pscan_period_mode  = info->pscan_period_mode;
1622                 data.pscan_mode         = info->pscan_mode;
1623                 memcpy(data.dev_class, info->dev_class, 3);
1624                 data.clock_offset       = info->clock_offset;
1625                 data.rssi               = 0x00;
1626                 data.ssp_mode           = 0x00;
1627
1628                 name_known = hci_inquiry_cache_update(hdev, &data, false, &ssp);
1629                 mgmt_device_found(hdev, &info->bdaddr, ACL_LINK, 0x00,
1630                                   info->dev_class, 0, !name_known, ssp, NULL,
1631                                   0);
1632         }
1633
1634         hci_dev_unlock(hdev);
1635 }
1636
1637 static void hci_conn_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
1638 {
1639         struct hci_ev_conn_complete *ev = (void *) skb->data;
1640         struct hci_conn *conn;
1641
1642         BT_DBG("%s", hdev->name);
1643
1644         hci_dev_lock(hdev);
1645
1646         conn = hci_conn_hash_lookup_ba(hdev, ev->link_type, &ev->bdaddr);
1647         if (!conn) {
1648                 if (ev->link_type != SCO_LINK)
1649                         goto unlock;
1650
1651                 conn = hci_conn_hash_lookup_ba(hdev, ESCO_LINK, &ev->bdaddr);
1652                 if (!conn)
1653                         goto unlock;
1654
1655                 conn->type = SCO_LINK;
1656         }
1657
1658         if (!ev->status) {
1659                 conn->handle = __le16_to_cpu(ev->handle);
1660
1661                 if (conn->type == ACL_LINK) {
1662                         conn->state = BT_CONFIG;
1663                         hci_conn_hold(conn);
1664
1665                         if (!conn->out && !hci_conn_ssp_enabled(conn) &&
1666                             !hci_find_link_key(hdev, &ev->bdaddr))
1667                                 conn->disc_timeout = HCI_PAIRING_TIMEOUT;
1668                         else
1669                                 conn->disc_timeout = HCI_DISCONN_TIMEOUT;
1670                 } else
1671                         conn->state = BT_CONNECTED;
1672
1673                 hci_conn_hold_device(conn);
1674                 hci_conn_add_sysfs(conn);
1675
1676                 if (test_bit(HCI_AUTH, &hdev->flags))
1677                         conn->link_mode |= HCI_LM_AUTH;
1678
1679                 if (test_bit(HCI_ENCRYPT, &hdev->flags))
1680                         conn->link_mode |= HCI_LM_ENCRYPT;
1681
1682                 /* Get remote features */
1683                 if (conn->type == ACL_LINK) {
1684                         struct hci_cp_read_remote_features cp;
1685                         cp.handle = ev->handle;
1686                         hci_send_cmd(hdev, HCI_OP_READ_REMOTE_FEATURES,
1687                                      sizeof(cp), &cp);
1688                 }
1689
1690                 /* Set packet type for incoming connection */
1691                 if (!conn->out && hdev->hci_ver < BLUETOOTH_VER_2_0) {
1692                         struct hci_cp_change_conn_ptype cp;
1693                         cp.handle = ev->handle;
1694                         cp.pkt_type = cpu_to_le16(conn->pkt_type);
1695                         hci_send_cmd(hdev, HCI_OP_CHANGE_CONN_PTYPE, sizeof(cp),
1696                                      &cp);
1697                 }
1698         } else {
1699                 conn->state = BT_CLOSED;
1700                 if (conn->type == ACL_LINK)
1701                         mgmt_connect_failed(hdev, &ev->bdaddr, conn->type,
1702                                             conn->dst_type, ev->status);
1703         }
1704
1705         if (conn->type == ACL_LINK)
1706                 hci_sco_setup(conn, ev->status);
1707
1708         if (ev->status) {
1709                 hci_proto_connect_cfm(conn, ev->status);
1710                 hci_conn_del(conn);
1711         } else if (ev->link_type != ACL_LINK)
1712                 hci_proto_connect_cfm(conn, ev->status);
1713
1714 unlock:
1715         hci_dev_unlock(hdev);
1716
1717         hci_conn_check_pending(hdev);
1718 }
1719
1720 void hci_conn_accept(struct hci_conn *conn, int mask)
1721 {
1722         struct hci_dev *hdev = conn->hdev;
1723
1724         BT_DBG("conn %p", conn);
1725
1726         conn->state = BT_CONFIG;
1727
1728         if (!lmp_esco_capable(hdev)) {
1729                 struct hci_cp_accept_conn_req cp;
1730
1731                 bacpy(&cp.bdaddr, &conn->dst);
1732
1733                 if (lmp_rswitch_capable(hdev) && (mask & HCI_LM_MASTER))
1734                         cp.role = 0x00; /* Become master */
1735                 else
1736                         cp.role = 0x01; /* Remain slave */
1737
1738                 hci_send_cmd(hdev, HCI_OP_ACCEPT_CONN_REQ, sizeof(cp), &cp);
1739         } else /* lmp_esco_capable(hdev)) */ {
1740                 struct hci_cp_accept_sync_conn_req cp;
1741
1742                 bacpy(&cp.bdaddr, &conn->dst);
1743                 cp.pkt_type = cpu_to_le16(conn->pkt_type);
1744
1745                 cp.tx_bandwidth   = __constant_cpu_to_le32(0x00001f40);
1746                 cp.rx_bandwidth   = __constant_cpu_to_le32(0x00001f40);
1747                 cp.max_latency    = __constant_cpu_to_le16(0xffff);
1748                 cp.content_format = cpu_to_le16(hdev->voice_setting);
1749                 cp.retrans_effort = 0xff;
1750
1751                 hci_send_cmd(hdev, HCI_OP_ACCEPT_SYNC_CONN_REQ,
1752                              sizeof(cp), &cp);
1753         }
1754 }
1755
1756 static void hci_conn_request_evt(struct hci_dev *hdev, struct sk_buff *skb)
1757 {
1758         struct hci_ev_conn_request *ev = (void *) skb->data;
1759         int mask = hdev->link_mode;
1760         __u8 flags = 0;
1761
1762         BT_DBG("%s bdaddr %pMR type 0x%x", hdev->name, &ev->bdaddr,
1763                ev->link_type);
1764
1765         mask |= hci_proto_connect_ind(hdev, &ev->bdaddr, ev->link_type,
1766                                       &flags);
1767
1768         if ((mask & HCI_LM_ACCEPT) &&
1769             !hci_blacklist_lookup(hdev, &ev->bdaddr)) {
1770                 /* Connection accepted */
1771                 struct inquiry_entry *ie;
1772                 struct hci_conn *conn;
1773
1774                 hci_dev_lock(hdev);
1775
1776                 ie = hci_inquiry_cache_lookup(hdev, &ev->bdaddr);
1777                 if (ie)
1778                         memcpy(ie->data.dev_class, ev->dev_class, 3);
1779
1780                 conn = hci_conn_hash_lookup_ba(hdev, ev->link_type,
1781                                                &ev->bdaddr);
1782                 if (!conn) {
1783                         conn = hci_conn_add(hdev, ev->link_type, &ev->bdaddr);
1784                         if (!conn) {
1785                                 BT_ERR("No memory for new connection");
1786                                 hci_dev_unlock(hdev);
1787                                 return;
1788                         }
1789                 }
1790
1791                 memcpy(conn->dev_class, ev->dev_class, 3);
1792
1793                 hci_dev_unlock(hdev);
1794
1795                 if (ev->link_type == ACL_LINK ||
1796                     (!(flags & HCI_PROTO_DEFER) && !lmp_esco_capable(hdev))) {
1797                         struct hci_cp_accept_conn_req cp;
1798                         conn->state = BT_CONNECT;
1799
1800                         bacpy(&cp.bdaddr, &ev->bdaddr);
1801
1802                         if (lmp_rswitch_capable(hdev) && (mask & HCI_LM_MASTER))
1803                                 cp.role = 0x00; /* Become master */
1804                         else
1805                                 cp.role = 0x01; /* Remain slave */
1806
1807                         hci_send_cmd(hdev, HCI_OP_ACCEPT_CONN_REQ, sizeof(cp),
1808                                      &cp);
1809                 } else if (!(flags & HCI_PROTO_DEFER)) {
1810                         struct hci_cp_accept_sync_conn_req cp;
1811                         conn->state = BT_CONNECT;
1812
1813                         bacpy(&cp.bdaddr, &ev->bdaddr);
1814                         cp.pkt_type = cpu_to_le16(conn->pkt_type);
1815
1816                         cp.tx_bandwidth   = __constant_cpu_to_le32(0x00001f40);
1817                         cp.rx_bandwidth   = __constant_cpu_to_le32(0x00001f40);
1818                         cp.max_latency    = __constant_cpu_to_le16(0xffff);
1819                         cp.content_format = cpu_to_le16(hdev->voice_setting);
1820                         cp.retrans_effort = 0xff;
1821
1822                         hci_send_cmd(hdev, HCI_OP_ACCEPT_SYNC_CONN_REQ,
1823                                      sizeof(cp), &cp);
1824                 } else {
1825                         conn->state = BT_CONNECT2;
1826                         hci_proto_connect_cfm(conn, 0);
1827                         hci_conn_put(conn);
1828                 }
1829         } else {
1830                 /* Connection rejected */
1831                 struct hci_cp_reject_conn_req cp;
1832
1833                 bacpy(&cp.bdaddr, &ev->bdaddr);
1834                 cp.reason = HCI_ERROR_REJ_BAD_ADDR;
1835                 hci_send_cmd(hdev, HCI_OP_REJECT_CONN_REQ, sizeof(cp), &cp);
1836         }
1837 }
1838
1839 static u8 hci_to_mgmt_reason(u8 err)
1840 {
1841         switch (err) {
1842         case HCI_ERROR_CONNECTION_TIMEOUT:
1843                 return MGMT_DEV_DISCONN_TIMEOUT;
1844         case HCI_ERROR_REMOTE_USER_TERM:
1845         case HCI_ERROR_REMOTE_LOW_RESOURCES:
1846         case HCI_ERROR_REMOTE_POWER_OFF:
1847                 return MGMT_DEV_DISCONN_REMOTE;
1848         case HCI_ERROR_LOCAL_HOST_TERM:
1849                 return MGMT_DEV_DISCONN_LOCAL_HOST;
1850         default:
1851                 return MGMT_DEV_DISCONN_UNKNOWN;
1852         }
1853 }
1854
1855 static void hci_disconn_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
1856 {
1857         struct hci_ev_disconn_complete *ev = (void *) skb->data;
1858         struct hci_conn *conn;
1859
1860         BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
1861
1862         hci_dev_lock(hdev);
1863
1864         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
1865         if (!conn)
1866                 goto unlock;
1867
1868         if (ev->status == 0)
1869                 conn->state = BT_CLOSED;
1870
1871         if (test_and_clear_bit(HCI_CONN_MGMT_CONNECTED, &conn->flags) &&
1872             (conn->type == ACL_LINK || conn->type == LE_LINK)) {
1873                 if (ev->status) {
1874                         mgmt_disconnect_failed(hdev, &conn->dst, conn->type,
1875                                                conn->dst_type, ev->status);
1876                 } else {
1877                         u8 reason = hci_to_mgmt_reason(ev->reason);
1878
1879                         mgmt_device_disconnected(hdev, &conn->dst, conn->type,
1880                                                  conn->dst_type, reason);
1881                 }
1882         }
1883
1884         if (ev->status == 0) {
1885                 if (conn->type == ACL_LINK && conn->flush_key)
1886                         hci_remove_link_key(hdev, &conn->dst);
1887                 hci_proto_disconn_cfm(conn, ev->reason);
1888                 hci_conn_del(conn);
1889         }
1890
1891 unlock:
1892         hci_dev_unlock(hdev);
1893 }
1894
1895 static void hci_auth_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
1896 {
1897         struct hci_ev_auth_complete *ev = (void *) skb->data;
1898         struct hci_conn *conn;
1899
1900         BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
1901
1902         hci_dev_lock(hdev);
1903
1904         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
1905         if (!conn)
1906                 goto unlock;
1907
1908         if (!ev->status) {
1909                 if (!hci_conn_ssp_enabled(conn) &&
1910                     test_bit(HCI_CONN_REAUTH_PEND, &conn->flags)) {
1911                         BT_INFO("re-auth of legacy device is not possible.");
1912                 } else {
1913                         conn->link_mode |= HCI_LM_AUTH;
1914                         conn->sec_level = conn->pending_sec_level;
1915                 }
1916         } else {
1917                 mgmt_auth_failed(hdev, &conn->dst, conn->type, conn->dst_type,
1918                                  ev->status);
1919         }
1920
1921         clear_bit(HCI_CONN_AUTH_PEND, &conn->flags);
1922         clear_bit(HCI_CONN_REAUTH_PEND, &conn->flags);
1923
1924         if (conn->state == BT_CONFIG) {
1925                 if (!ev->status && hci_conn_ssp_enabled(conn)) {
1926                         struct hci_cp_set_conn_encrypt cp;
1927                         cp.handle  = ev->handle;
1928                         cp.encrypt = 0x01;
1929                         hci_send_cmd(hdev, HCI_OP_SET_CONN_ENCRYPT, sizeof(cp),
1930                                      &cp);
1931                 } else {
1932                         conn->state = BT_CONNECTED;
1933                         hci_proto_connect_cfm(conn, ev->status);
1934                         hci_conn_put(conn);
1935                 }
1936         } else {
1937                 hci_auth_cfm(conn, ev->status);
1938
1939                 hci_conn_hold(conn);
1940                 conn->disc_timeout = HCI_DISCONN_TIMEOUT;
1941                 hci_conn_put(conn);
1942         }
1943
1944         if (test_bit(HCI_CONN_ENCRYPT_PEND, &conn->flags)) {
1945                 if (!ev->status) {
1946                         struct hci_cp_set_conn_encrypt cp;
1947                         cp.handle  = ev->handle;
1948                         cp.encrypt = 0x01;
1949                         hci_send_cmd(hdev, HCI_OP_SET_CONN_ENCRYPT, sizeof(cp),
1950                                      &cp);
1951                 } else {
1952                         clear_bit(HCI_CONN_ENCRYPT_PEND, &conn->flags);
1953                         hci_encrypt_cfm(conn, ev->status, 0x00);
1954                 }
1955         }
1956
1957 unlock:
1958         hci_dev_unlock(hdev);
1959 }
1960
1961 static void hci_remote_name_evt(struct hci_dev *hdev, struct sk_buff *skb)
1962 {
1963         struct hci_ev_remote_name *ev = (void *) skb->data;
1964         struct hci_conn *conn;
1965
1966         BT_DBG("%s", hdev->name);
1967
1968         hci_conn_check_pending(hdev);
1969
1970         hci_dev_lock(hdev);
1971
1972         conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
1973
1974         if (!test_bit(HCI_MGMT, &hdev->dev_flags))
1975                 goto check_auth;
1976
1977         if (ev->status == 0)
1978                 hci_check_pending_name(hdev, conn, &ev->bdaddr, ev->name,
1979                                        strnlen(ev->name, HCI_MAX_NAME_LENGTH));
1980         else
1981                 hci_check_pending_name(hdev, conn, &ev->bdaddr, NULL, 0);
1982
1983 check_auth:
1984         if (!conn)
1985                 goto unlock;
1986
1987         if (!hci_outgoing_auth_needed(hdev, conn))
1988                 goto unlock;
1989
1990         if (!test_and_set_bit(HCI_CONN_AUTH_PEND, &conn->flags)) {
1991                 struct hci_cp_auth_requested cp;
1992                 cp.handle = __cpu_to_le16(conn->handle);
1993                 hci_send_cmd(hdev, HCI_OP_AUTH_REQUESTED, sizeof(cp), &cp);
1994         }
1995
1996 unlock:
1997         hci_dev_unlock(hdev);
1998 }
1999
2000 static void hci_encrypt_change_evt(struct hci_dev *hdev, struct sk_buff *skb)
2001 {
2002         struct hci_ev_encrypt_change *ev = (void *) skb->data;
2003         struct hci_conn *conn;
2004
2005         BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
2006
2007         hci_dev_lock(hdev);
2008
2009         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
2010         if (conn) {
2011                 if (!ev->status) {
2012                         if (ev->encrypt) {
2013                                 /* Encryption implies authentication */
2014                                 conn->link_mode |= HCI_LM_AUTH;
2015                                 conn->link_mode |= HCI_LM_ENCRYPT;
2016                                 conn->sec_level = conn->pending_sec_level;
2017                         } else
2018                                 conn->link_mode &= ~HCI_LM_ENCRYPT;
2019                 }
2020
2021                 clear_bit(HCI_CONN_ENCRYPT_PEND, &conn->flags);
2022
2023                 if (ev->status && conn->state == BT_CONNECTED) {
2024                         hci_disconnect(conn, HCI_ERROR_AUTH_FAILURE);
2025                         hci_conn_put(conn);
2026                         goto unlock;
2027                 }
2028
2029                 if (conn->state == BT_CONFIG) {
2030                         if (!ev->status)
2031                                 conn->state = BT_CONNECTED;
2032
2033                         hci_proto_connect_cfm(conn, ev->status);
2034                         hci_conn_put(conn);
2035                 } else
2036                         hci_encrypt_cfm(conn, ev->status, ev->encrypt);
2037         }
2038
2039 unlock:
2040         hci_dev_unlock(hdev);
2041 }
2042
2043 static void hci_change_link_key_complete_evt(struct hci_dev *hdev,
2044                                              struct sk_buff *skb)
2045 {
2046         struct hci_ev_change_link_key_complete *ev = (void *) skb->data;
2047         struct hci_conn *conn;
2048
2049         BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
2050
2051         hci_dev_lock(hdev);
2052
2053         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
2054         if (conn) {
2055                 if (!ev->status)
2056                         conn->link_mode |= HCI_LM_SECURE;
2057
2058                 clear_bit(HCI_CONN_AUTH_PEND, &conn->flags);
2059
2060                 hci_key_change_cfm(conn, ev->status);
2061         }
2062
2063         hci_dev_unlock(hdev);
2064 }
2065
2066 static void hci_remote_features_evt(struct hci_dev *hdev,
2067                                     struct sk_buff *skb)
2068 {
2069         struct hci_ev_remote_features *ev = (void *) skb->data;
2070         struct hci_conn *conn;
2071
2072         BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
2073
2074         hci_dev_lock(hdev);
2075
2076         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
2077         if (!conn)
2078                 goto unlock;
2079
2080         if (!ev->status)
2081                 memcpy(conn->features, ev->features, 8);
2082
2083         if (conn->state != BT_CONFIG)
2084                 goto unlock;
2085
2086         if (!ev->status && lmp_ssp_capable(hdev) && lmp_ssp_capable(conn)) {
2087                 struct hci_cp_read_remote_ext_features cp;
2088                 cp.handle = ev->handle;
2089                 cp.page = 0x01;
2090                 hci_send_cmd(hdev, HCI_OP_READ_REMOTE_EXT_FEATURES,
2091                              sizeof(cp), &cp);
2092                 goto unlock;
2093         }
2094
2095         if (!ev->status && !test_bit(HCI_CONN_MGMT_CONNECTED, &conn->flags)) {
2096                 struct hci_cp_remote_name_req cp;
2097                 memset(&cp, 0, sizeof(cp));
2098                 bacpy(&cp.bdaddr, &conn->dst);
2099                 cp.pscan_rep_mode = 0x02;
2100                 hci_send_cmd(hdev, HCI_OP_REMOTE_NAME_REQ, sizeof(cp), &cp);
2101         } else if (!test_and_set_bit(HCI_CONN_MGMT_CONNECTED, &conn->flags))
2102                 mgmt_device_connected(hdev, &conn->dst, conn->type,
2103                                       conn->dst_type, 0, NULL, 0,
2104                                       conn->dev_class);
2105
2106         if (!hci_outgoing_auth_needed(hdev, conn)) {
2107                 conn->state = BT_CONNECTED;
2108                 hci_proto_connect_cfm(conn, ev->status);
2109                 hci_conn_put(conn);
2110         }
2111
2112 unlock:
2113         hci_dev_unlock(hdev);
2114 }
2115
2116 static void hci_cmd_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
2117 {
2118         struct hci_ev_cmd_complete *ev = (void *) skb->data;
2119         u8 status = skb->data[sizeof(*ev)];
2120         __u16 opcode;
2121
2122         skb_pull(skb, sizeof(*ev));
2123
2124         opcode = __le16_to_cpu(ev->opcode);
2125
2126         switch (opcode) {
2127         case HCI_OP_INQUIRY_CANCEL:
2128                 hci_cc_inquiry_cancel(hdev, skb);
2129                 break;
2130
2131         case HCI_OP_PERIODIC_INQ:
2132                 hci_cc_periodic_inq(hdev, skb);
2133                 break;
2134
2135         case HCI_OP_EXIT_PERIODIC_INQ:
2136                 hci_cc_exit_periodic_inq(hdev, skb);
2137                 break;
2138
2139         case HCI_OP_REMOTE_NAME_REQ_CANCEL:
2140                 hci_cc_remote_name_req_cancel(hdev, skb);
2141                 break;
2142
2143         case HCI_OP_ROLE_DISCOVERY:
2144                 hci_cc_role_discovery(hdev, skb);
2145                 break;
2146
2147         case HCI_OP_READ_LINK_POLICY:
2148                 hci_cc_read_link_policy(hdev, skb);
2149                 break;
2150
2151         case HCI_OP_WRITE_LINK_POLICY:
2152                 hci_cc_write_link_policy(hdev, skb);
2153                 break;
2154
2155         case HCI_OP_READ_DEF_LINK_POLICY:
2156                 hci_cc_read_def_link_policy(hdev, skb);
2157                 break;
2158
2159         case HCI_OP_WRITE_DEF_LINK_POLICY:
2160                 hci_cc_write_def_link_policy(hdev, skb);
2161                 break;
2162
2163         case HCI_OP_RESET:
2164                 hci_cc_reset(hdev, skb);
2165                 break;
2166
2167         case HCI_OP_WRITE_LOCAL_NAME:
2168                 hci_cc_write_local_name(hdev, skb);
2169                 break;
2170
2171         case HCI_OP_READ_LOCAL_NAME:
2172                 hci_cc_read_local_name(hdev, skb);
2173                 break;
2174
2175         case HCI_OP_WRITE_AUTH_ENABLE:
2176                 hci_cc_write_auth_enable(hdev, skb);
2177                 break;
2178
2179         case HCI_OP_WRITE_ENCRYPT_MODE:
2180                 hci_cc_write_encrypt_mode(hdev, skb);
2181                 break;
2182
2183         case HCI_OP_WRITE_SCAN_ENABLE:
2184                 hci_cc_write_scan_enable(hdev, skb);
2185                 break;
2186
2187         case HCI_OP_READ_CLASS_OF_DEV:
2188                 hci_cc_read_class_of_dev(hdev, skb);
2189                 break;
2190
2191         case HCI_OP_WRITE_CLASS_OF_DEV:
2192                 hci_cc_write_class_of_dev(hdev, skb);
2193                 break;
2194
2195         case HCI_OP_READ_VOICE_SETTING:
2196                 hci_cc_read_voice_setting(hdev, skb);
2197                 break;
2198
2199         case HCI_OP_WRITE_VOICE_SETTING:
2200                 hci_cc_write_voice_setting(hdev, skb);
2201                 break;
2202
2203         case HCI_OP_WRITE_SSP_MODE:
2204                 hci_cc_write_ssp_mode(hdev, skb);
2205                 break;
2206
2207         case HCI_OP_READ_LOCAL_VERSION:
2208                 hci_cc_read_local_version(hdev, skb);
2209                 break;
2210
2211         case HCI_OP_READ_LOCAL_COMMANDS:
2212                 hci_cc_read_local_commands(hdev, skb);
2213                 break;
2214
2215         case HCI_OP_READ_LOCAL_FEATURES:
2216                 hci_cc_read_local_features(hdev, skb);
2217                 break;
2218
2219         case HCI_OP_READ_LOCAL_EXT_FEATURES:
2220                 hci_cc_read_local_ext_features(hdev, skb);
2221                 break;
2222
2223         case HCI_OP_READ_BUFFER_SIZE:
2224                 hci_cc_read_buffer_size(hdev, skb);
2225                 break;
2226
2227         case HCI_OP_READ_BD_ADDR:
2228                 hci_cc_read_bd_addr(hdev, skb);
2229                 break;
2230
2231         case HCI_OP_READ_PAGE_SCAN_ACTIVITY:
2232                 hci_cc_read_page_scan_activity(hdev, skb);
2233                 break;
2234
2235         case HCI_OP_READ_PAGE_SCAN_TYPE:
2236                 hci_cc_read_page_scan_type(hdev, skb);
2237                 break;
2238
2239         case HCI_OP_READ_DATA_BLOCK_SIZE:
2240                 hci_cc_read_data_block_size(hdev, skb);
2241                 break;
2242
2243         case HCI_OP_READ_FLOW_CONTROL_MODE:
2244                 hci_cc_read_flow_control_mode(hdev, skb);
2245                 break;
2246
2247         case HCI_OP_READ_LOCAL_AMP_INFO:
2248                 hci_cc_read_local_amp_info(hdev, skb);
2249                 break;
2250
2251         case HCI_OP_READ_LOCAL_AMP_ASSOC:
2252                 hci_cc_read_local_amp_assoc(hdev, skb);
2253                 break;
2254
2255         case HCI_OP_READ_INQ_RSP_TX_POWER:
2256                 hci_cc_read_inq_rsp_tx_power(hdev, skb);
2257                 break;
2258
2259         case HCI_OP_PIN_CODE_REPLY:
2260                 hci_cc_pin_code_reply(hdev, skb);
2261                 break;
2262
2263         case HCI_OP_PIN_CODE_NEG_REPLY:
2264                 hci_cc_pin_code_neg_reply(hdev, skb);
2265                 break;
2266
2267         case HCI_OP_READ_LOCAL_OOB_DATA:
2268                 hci_cc_read_local_oob_data_reply(hdev, skb);
2269                 break;
2270
2271         case HCI_OP_LE_READ_BUFFER_SIZE:
2272                 hci_cc_le_read_buffer_size(hdev, skb);
2273                 break;
2274
2275         case HCI_OP_LE_READ_LOCAL_FEATURES:
2276                 hci_cc_le_read_local_features(hdev, skb);
2277                 break;
2278
2279         case HCI_OP_LE_READ_ADV_TX_POWER:
2280                 hci_cc_le_read_adv_tx_power(hdev, skb);
2281                 break;
2282
2283         case HCI_OP_USER_CONFIRM_REPLY:
2284                 hci_cc_user_confirm_reply(hdev, skb);
2285                 break;
2286
2287         case HCI_OP_USER_CONFIRM_NEG_REPLY:
2288                 hci_cc_user_confirm_neg_reply(hdev, skb);
2289                 break;
2290
2291         case HCI_OP_USER_PASSKEY_REPLY:
2292                 hci_cc_user_passkey_reply(hdev, skb);
2293                 break;
2294
2295         case HCI_OP_USER_PASSKEY_NEG_REPLY:
2296                 hci_cc_user_passkey_neg_reply(hdev, skb);
2297                 break;
2298
2299         case HCI_OP_LE_SET_SCAN_PARAM:
2300                 hci_cc_le_set_scan_param(hdev, skb);
2301                 break;
2302
2303         case HCI_OP_LE_SET_ADV_ENABLE:
2304                 hci_cc_le_set_adv_enable(hdev, skb);
2305                 break;
2306
2307         case HCI_OP_LE_SET_SCAN_ENABLE:
2308                 hci_cc_le_set_scan_enable(hdev, skb);
2309                 break;
2310
2311         case HCI_OP_LE_READ_WHITE_LIST_SIZE:
2312                 hci_cc_le_read_white_list_size(hdev, skb);
2313                 break;
2314
2315         case HCI_OP_LE_READ_SUPPORTED_STATES:
2316                 hci_cc_le_read_supported_states(hdev, skb);
2317                 break;
2318
2319         case HCI_OP_WRITE_LE_HOST_SUPPORTED:
2320                 hci_cc_write_le_host_supported(hdev, skb);
2321                 break;
2322
2323         case HCI_OP_WRITE_REMOTE_AMP_ASSOC:
2324                 hci_cc_write_remote_amp_assoc(hdev, skb);
2325                 break;
2326
2327         default:
2328                 BT_DBG("%s opcode 0x%4.4x", hdev->name, opcode);
2329                 break;
2330         }
2331
2332         if (opcode != HCI_OP_NOP)
2333                 del_timer(&hdev->cmd_timer);
2334
2335         hci_req_cmd_complete(hdev, opcode, status);
2336
2337         if (ev->ncmd && !test_bit(HCI_RESET, &hdev->flags)) {
2338                 atomic_set(&hdev->cmd_cnt, 1);
2339                 if (!skb_queue_empty(&hdev->cmd_q))
2340                         queue_work(hdev->workqueue, &hdev->cmd_work);
2341         }
2342 }
2343
2344 static void hci_cmd_status_evt(struct hci_dev *hdev, struct sk_buff *skb)
2345 {
2346         struct hci_ev_cmd_status *ev = (void *) skb->data;
2347         __u16 opcode;
2348
2349         skb_pull(skb, sizeof(*ev));
2350
2351         opcode = __le16_to_cpu(ev->opcode);
2352
2353         switch (opcode) {
2354         case HCI_OP_INQUIRY:
2355                 hci_cs_inquiry(hdev, ev->status);
2356                 break;
2357
2358         case HCI_OP_CREATE_CONN:
2359                 hci_cs_create_conn(hdev, ev->status);
2360                 break;
2361
2362         case HCI_OP_ADD_SCO:
2363                 hci_cs_add_sco(hdev, ev->status);
2364                 break;
2365
2366         case HCI_OP_AUTH_REQUESTED:
2367                 hci_cs_auth_requested(hdev, ev->status);
2368                 break;
2369
2370         case HCI_OP_SET_CONN_ENCRYPT:
2371                 hci_cs_set_conn_encrypt(hdev, ev->status);
2372                 break;
2373
2374         case HCI_OP_REMOTE_NAME_REQ:
2375                 hci_cs_remote_name_req(hdev, ev->status);
2376                 break;
2377
2378         case HCI_OP_READ_REMOTE_FEATURES:
2379                 hci_cs_read_remote_features(hdev, ev->status);
2380                 break;
2381
2382         case HCI_OP_READ_REMOTE_EXT_FEATURES:
2383                 hci_cs_read_remote_ext_features(hdev, ev->status);
2384                 break;
2385
2386         case HCI_OP_SETUP_SYNC_CONN:
2387                 hci_cs_setup_sync_conn(hdev, ev->status);
2388                 break;
2389
2390         case HCI_OP_SNIFF_MODE:
2391                 hci_cs_sniff_mode(hdev, ev->status);
2392                 break;
2393
2394         case HCI_OP_EXIT_SNIFF_MODE:
2395                 hci_cs_exit_sniff_mode(hdev, ev->status);
2396                 break;
2397
2398         case HCI_OP_DISCONNECT:
2399                 hci_cs_disconnect(hdev, ev->status);
2400                 break;
2401
2402         case HCI_OP_LE_CREATE_CONN:
2403                 hci_cs_le_create_conn(hdev, ev->status);
2404                 break;
2405
2406         case HCI_OP_CREATE_PHY_LINK:
2407                 hci_cs_create_phylink(hdev, ev->status);
2408                 break;
2409
2410         case HCI_OP_ACCEPT_PHY_LINK:
2411                 hci_cs_accept_phylink(hdev, ev->status);
2412                 break;
2413
2414         default:
2415                 BT_DBG("%s opcode 0x%4.4x", hdev->name, opcode);
2416                 break;
2417         }
2418
2419         if (opcode != HCI_OP_NOP)
2420                 del_timer(&hdev->cmd_timer);
2421
2422         hci_req_cmd_status(hdev, opcode, ev->status);
2423
2424         if (ev->ncmd && !test_bit(HCI_RESET, &hdev->flags)) {
2425                 atomic_set(&hdev->cmd_cnt, 1);
2426                 if (!skb_queue_empty(&hdev->cmd_q))
2427                         queue_work(hdev->workqueue, &hdev->cmd_work);
2428         }
2429 }
2430
2431 static void hci_role_change_evt(struct hci_dev *hdev, struct sk_buff *skb)
2432 {
2433         struct hci_ev_role_change *ev = (void *) skb->data;
2434         struct hci_conn *conn;
2435
2436         BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
2437
2438         hci_dev_lock(hdev);
2439
2440         conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
2441         if (conn) {
2442                 if (!ev->status) {
2443                         if (ev->role)
2444                                 conn->link_mode &= ~HCI_LM_MASTER;
2445                         else
2446                                 conn->link_mode |= HCI_LM_MASTER;
2447                 }
2448
2449                 clear_bit(HCI_CONN_RSWITCH_PEND, &conn->flags);
2450
2451                 hci_role_switch_cfm(conn, ev->status, ev->role);
2452         }
2453
2454         hci_dev_unlock(hdev);
2455 }
2456
2457 static void hci_num_comp_pkts_evt(struct hci_dev *hdev, struct sk_buff *skb)
2458 {
2459         struct hci_ev_num_comp_pkts *ev = (void *) skb->data;
2460         int i;
2461
2462         if (hdev->flow_ctl_mode != HCI_FLOW_CTL_MODE_PACKET_BASED) {
2463                 BT_ERR("Wrong event for mode %d", hdev->flow_ctl_mode);
2464                 return;
2465         }
2466
2467         if (skb->len < sizeof(*ev) || skb->len < sizeof(*ev) +
2468             ev->num_hndl * sizeof(struct hci_comp_pkts_info)) {
2469                 BT_DBG("%s bad parameters", hdev->name);
2470                 return;
2471         }
2472
2473         BT_DBG("%s num_hndl %d", hdev->name, ev->num_hndl);
2474
2475         for (i = 0; i < ev->num_hndl; i++) {
2476                 struct hci_comp_pkts_info *info = &ev->handles[i];
2477                 struct hci_conn *conn;
2478                 __u16  handle, count;
2479
2480                 handle = __le16_to_cpu(info->handle);
2481                 count  = __le16_to_cpu(info->count);
2482
2483                 conn = hci_conn_hash_lookup_handle(hdev, handle);
2484                 if (!conn)
2485                         continue;
2486
2487                 conn->sent -= count;
2488
2489                 switch (conn->type) {
2490                 case ACL_LINK:
2491                         hdev->acl_cnt += count;
2492                         if (hdev->acl_cnt > hdev->acl_pkts)
2493                                 hdev->acl_cnt = hdev->acl_pkts;
2494                         break;
2495
2496                 case LE_LINK:
2497                         if (hdev->le_pkts) {
2498                                 hdev->le_cnt += count;
2499                                 if (hdev->le_cnt > hdev->le_pkts)
2500                                         hdev->le_cnt = hdev->le_pkts;
2501                         } else {
2502                                 hdev->acl_cnt += count;
2503                                 if (hdev->acl_cnt > hdev->acl_pkts)
2504                                         hdev->acl_cnt = hdev->acl_pkts;
2505                         }
2506                         break;
2507
2508                 case SCO_LINK:
2509                         hdev->sco_cnt += count;
2510                         if (hdev->sco_cnt > hdev->sco_pkts)
2511                                 hdev->sco_cnt = hdev->sco_pkts;
2512                         break;
2513
2514                 default:
2515                         BT_ERR("Unknown type %d conn %p", conn->type, conn);
2516                         break;
2517                 }
2518         }
2519
2520         queue_work(hdev->workqueue, &hdev->tx_work);
2521 }
2522
2523 static struct hci_conn *__hci_conn_lookup_handle(struct hci_dev *hdev,
2524                                                  __u16 handle)
2525 {
2526         struct hci_chan *chan;
2527
2528         switch (hdev->dev_type) {
2529         case HCI_BREDR:
2530                 return hci_conn_hash_lookup_handle(hdev, handle);
2531         case HCI_AMP:
2532                 chan = hci_chan_lookup_handle(hdev, handle);
2533                 if (chan)
2534                         return chan->conn;
2535                 break;
2536         default:
2537                 BT_ERR("%s unknown dev_type %d", hdev->name, hdev->dev_type);
2538                 break;
2539         }
2540
2541         return NULL;
2542 }
2543
2544 static void hci_num_comp_blocks_evt(struct hci_dev *hdev, struct sk_buff *skb)
2545 {
2546         struct hci_ev_num_comp_blocks *ev = (void *) skb->data;
2547         int i;
2548
2549         if (hdev->flow_ctl_mode != HCI_FLOW_CTL_MODE_BLOCK_BASED) {
2550                 BT_ERR("Wrong event for mode %d", hdev->flow_ctl_mode);
2551                 return;
2552         }
2553
2554         if (skb->len < sizeof(*ev) || skb->len < sizeof(*ev) +
2555             ev->num_hndl * sizeof(struct hci_comp_blocks_info)) {
2556                 BT_DBG("%s bad parameters", hdev->name);
2557                 return;
2558         }
2559
2560         BT_DBG("%s num_blocks %d num_hndl %d", hdev->name, ev->num_blocks,
2561                ev->num_hndl);
2562
2563         for (i = 0; i < ev->num_hndl; i++) {
2564                 struct hci_comp_blocks_info *info = &ev->handles[i];
2565                 struct hci_conn *conn = NULL;
2566                 __u16  handle, block_count;
2567
2568                 handle = __le16_to_cpu(info->handle);
2569                 block_count = __le16_to_cpu(info->blocks);
2570
2571                 conn = __hci_conn_lookup_handle(hdev, handle);
2572                 if (!conn)
2573                         continue;
2574
2575                 conn->sent -= block_count;
2576
2577                 switch (conn->type) {
2578                 case ACL_LINK:
2579                 case AMP_LINK:
2580                         hdev->block_cnt += block_count;
2581                         if (hdev->block_cnt > hdev->num_blocks)
2582                                 hdev->block_cnt = hdev->num_blocks;
2583                         break;
2584
2585                 default:
2586                         BT_ERR("Unknown type %d conn %p", conn->type, conn);
2587                         break;
2588                 }
2589         }
2590
2591         queue_work(hdev->workqueue, &hdev->tx_work);
2592 }
2593
2594 static void hci_mode_change_evt(struct hci_dev *hdev, struct sk_buff *skb)
2595 {
2596         struct hci_ev_mode_change *ev = (void *) skb->data;
2597         struct hci_conn *conn;
2598
2599         BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
2600
2601         hci_dev_lock(hdev);
2602
2603         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
2604         if (conn) {
2605                 conn->mode = ev->mode;
2606                 conn->interval = __le16_to_cpu(ev->interval);
2607
2608                 if (!test_and_clear_bit(HCI_CONN_MODE_CHANGE_PEND,
2609                                         &conn->flags)) {
2610                         if (conn->mode == HCI_CM_ACTIVE)
2611                                 set_bit(HCI_CONN_POWER_SAVE, &conn->flags);
2612                         else
2613                                 clear_bit(HCI_CONN_POWER_SAVE, &conn->flags);
2614                 }
2615
2616                 if (test_and_clear_bit(HCI_CONN_SCO_SETUP_PEND, &conn->flags))
2617                         hci_sco_setup(conn, ev->status);
2618         }
2619
2620         hci_dev_unlock(hdev);
2621 }
2622
2623 static void hci_pin_code_request_evt(struct hci_dev *hdev, struct sk_buff *skb)
2624 {
2625         struct hci_ev_pin_code_req *ev = (void *) skb->data;
2626         struct hci_conn *conn;
2627
2628         BT_DBG("%s", hdev->name);
2629
2630         hci_dev_lock(hdev);
2631
2632         conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
2633         if (!conn)
2634                 goto unlock;
2635
2636         if (conn->state == BT_CONNECTED) {
2637                 hci_conn_hold(conn);
2638                 conn->disc_timeout = HCI_PAIRING_TIMEOUT;
2639                 hci_conn_put(conn);
2640         }
2641
2642         if (!test_bit(HCI_PAIRABLE, &hdev->dev_flags))
2643                 hci_send_cmd(hdev, HCI_OP_PIN_CODE_NEG_REPLY,
2644                              sizeof(ev->bdaddr), &ev->bdaddr);
2645         else if (test_bit(HCI_MGMT, &hdev->dev_flags)) {
2646                 u8 secure;
2647
2648                 if (conn->pending_sec_level == BT_SECURITY_HIGH)
2649                         secure = 1;
2650                 else
2651                         secure = 0;
2652
2653                 mgmt_pin_code_request(hdev, &ev->bdaddr, secure);
2654         }
2655
2656 unlock:
2657         hci_dev_unlock(hdev);
2658 }
2659
2660 static void hci_link_key_request_evt(struct hci_dev *hdev, struct sk_buff *skb)
2661 {
2662         struct hci_ev_link_key_req *ev = (void *) skb->data;
2663         struct hci_cp_link_key_reply cp;
2664         struct hci_conn *conn;
2665         struct link_key *key;
2666
2667         BT_DBG("%s", hdev->name);
2668
2669         if (!test_bit(HCI_LINK_KEYS, &hdev->dev_flags))
2670                 return;
2671
2672         hci_dev_lock(hdev);
2673
2674         key = hci_find_link_key(hdev, &ev->bdaddr);
2675         if (!key) {
2676                 BT_DBG("%s link key not found for %pMR", hdev->name,
2677                        &ev->bdaddr);
2678                 goto not_found;
2679         }
2680
2681         BT_DBG("%s found key type %u for %pMR", hdev->name, key->type,
2682                &ev->bdaddr);
2683
2684         if (!test_bit(HCI_DEBUG_KEYS, &hdev->dev_flags) &&
2685             key->type == HCI_LK_DEBUG_COMBINATION) {
2686                 BT_DBG("%s ignoring debug key", hdev->name);
2687                 goto not_found;
2688         }
2689
2690         conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
2691         if (conn) {
2692                 if (key->type == HCI_LK_UNAUTH_COMBINATION &&
2693                     conn->auth_type != 0xff && (conn->auth_type & 0x01)) {
2694                         BT_DBG("%s ignoring unauthenticated key", hdev->name);
2695                         goto not_found;
2696                 }
2697
2698                 if (key->type == HCI_LK_COMBINATION && key->pin_len < 16 &&
2699                     conn->pending_sec_level == BT_SECURITY_HIGH) {
2700                         BT_DBG("%s ignoring key unauthenticated for high security",
2701                                hdev->name);
2702                         goto not_found;
2703                 }
2704
2705                 conn->key_type = key->type;
2706                 conn->pin_length = key->pin_len;
2707         }
2708
2709         bacpy(&cp.bdaddr, &ev->bdaddr);
2710         memcpy(cp.link_key, key->val, HCI_LINK_KEY_SIZE);
2711
2712         hci_send_cmd(hdev, HCI_OP_LINK_KEY_REPLY, sizeof(cp), &cp);
2713
2714         hci_dev_unlock(hdev);
2715
2716         return;
2717
2718 not_found:
2719         hci_send_cmd(hdev, HCI_OP_LINK_KEY_NEG_REPLY, 6, &ev->bdaddr);
2720         hci_dev_unlock(hdev);
2721 }
2722
2723 static void hci_link_key_notify_evt(struct hci_dev *hdev, struct sk_buff *skb)
2724 {
2725         struct hci_ev_link_key_notify *ev = (void *) skb->data;
2726         struct hci_conn *conn;
2727         u8 pin_len = 0;
2728
2729         BT_DBG("%s", hdev->name);
2730
2731         hci_dev_lock(hdev);
2732
2733         conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
2734         if (conn) {
2735                 hci_conn_hold(conn);
2736                 conn->disc_timeout = HCI_DISCONN_TIMEOUT;
2737                 pin_len = conn->pin_length;
2738
2739                 if (ev->key_type != HCI_LK_CHANGED_COMBINATION)
2740                         conn->key_type = ev->key_type;
2741
2742                 hci_conn_put(conn);
2743         }
2744
2745         if (test_bit(HCI_LINK_KEYS, &hdev->dev_flags))
2746                 hci_add_link_key(hdev, conn, 1, &ev->bdaddr, ev->link_key,
2747                                  ev->key_type, pin_len);
2748
2749         hci_dev_unlock(hdev);
2750 }
2751
2752 static void hci_clock_offset_evt(struct hci_dev *hdev, struct sk_buff *skb)
2753 {
2754         struct hci_ev_clock_offset *ev = (void *) skb->data;
2755         struct hci_conn *conn;
2756
2757         BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
2758
2759         hci_dev_lock(hdev);
2760
2761         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
2762         if (conn && !ev->status) {
2763                 struct inquiry_entry *ie;
2764
2765                 ie = hci_inquiry_cache_lookup(hdev, &conn->dst);
2766                 if (ie) {
2767                         ie->data.clock_offset = ev->clock_offset;
2768                         ie->timestamp = jiffies;
2769                 }
2770         }
2771
2772         hci_dev_unlock(hdev);
2773 }
2774
2775 static void hci_pkt_type_change_evt(struct hci_dev *hdev, struct sk_buff *skb)
2776 {
2777         struct hci_ev_pkt_type_change *ev = (void *) skb->data;
2778         struct hci_conn *conn;
2779
2780         BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
2781
2782         hci_dev_lock(hdev);
2783
2784         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
2785         if (conn && !ev->status)
2786                 conn->pkt_type = __le16_to_cpu(ev->pkt_type);
2787
2788         hci_dev_unlock(hdev);
2789 }
2790
2791 static void hci_pscan_rep_mode_evt(struct hci_dev *hdev, struct sk_buff *skb)
2792 {
2793         struct hci_ev_pscan_rep_mode *ev = (void *) skb->data;
2794         struct inquiry_entry *ie;
2795
2796         BT_DBG("%s", hdev->name);
2797
2798         hci_dev_lock(hdev);
2799
2800         ie = hci_inquiry_cache_lookup(hdev, &ev->bdaddr);
2801         if (ie) {
2802                 ie->data.pscan_rep_mode = ev->pscan_rep_mode;
2803                 ie->timestamp = jiffies;
2804         }
2805
2806         hci_dev_unlock(hdev);
2807 }
2808
2809 static void hci_inquiry_result_with_rssi_evt(struct hci_dev *hdev,
2810                                              struct sk_buff *skb)
2811 {
2812         struct inquiry_data data;
2813         int num_rsp = *((__u8 *) skb->data);
2814         bool name_known, ssp;
2815
2816         BT_DBG("%s num_rsp %d", hdev->name, num_rsp);
2817
2818         if (!num_rsp)
2819                 return;
2820
2821         if (test_bit(HCI_PERIODIC_INQ, &hdev->dev_flags))
2822                 return;
2823
2824         hci_dev_lock(hdev);
2825
2826         if ((skb->len - 1) / num_rsp != sizeof(struct inquiry_info_with_rssi)) {
2827                 struct inquiry_info_with_rssi_and_pscan_mode *info;
2828                 info = (void *) (skb->data + 1);
2829
2830                 for (; num_rsp; num_rsp--, info++) {
2831                         bacpy(&data.bdaddr, &info->bdaddr);
2832                         data.pscan_rep_mode     = info->pscan_rep_mode;
2833                         data.pscan_period_mode  = info->pscan_period_mode;
2834                         data.pscan_mode         = info->pscan_mode;
2835                         memcpy(data.dev_class, info->dev_class, 3);
2836                         data.clock_offset       = info->clock_offset;
2837                         data.rssi               = info->rssi;
2838                         data.ssp_mode           = 0x00;
2839
2840                         name_known = hci_inquiry_cache_update(hdev, &data,
2841                                                               false, &ssp);
2842                         mgmt_device_found(hdev, &info->bdaddr, ACL_LINK, 0x00,
2843                                           info->dev_class, info->rssi,
2844                                           !name_known, ssp, NULL, 0);
2845                 }
2846         } else {
2847                 struct inquiry_info_with_rssi *info = (void *) (skb->data + 1);
2848
2849                 for (; num_rsp; num_rsp--, info++) {
2850                         bacpy(&data.bdaddr, &info->bdaddr);
2851                         data.pscan_rep_mode     = info->pscan_rep_mode;
2852                         data.pscan_period_mode  = info->pscan_period_mode;
2853                         data.pscan_mode         = 0x00;
2854                         memcpy(data.dev_class, info->dev_class, 3);
2855                         data.clock_offset       = info->clock_offset;
2856                         data.rssi               = info->rssi;
2857                         data.ssp_mode           = 0x00;
2858                         name_known = hci_inquiry_cache_update(hdev, &data,
2859                                                               false, &ssp);
2860                         mgmt_device_found(hdev, &info->bdaddr, ACL_LINK, 0x00,
2861                                           info->dev_class, info->rssi,
2862                                           !name_known, ssp, NULL, 0);
2863                 }
2864         }
2865
2866         hci_dev_unlock(hdev);
2867 }
2868
2869 static void hci_remote_ext_features_evt(struct hci_dev *hdev,
2870                                         struct sk_buff *skb)
2871 {
2872         struct hci_ev_remote_ext_features *ev = (void *) skb->data;
2873         struct hci_conn *conn;
2874
2875         BT_DBG("%s", hdev->name);
2876
2877         hci_dev_lock(hdev);
2878
2879         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
2880         if (!conn)
2881                 goto unlock;
2882
2883         if (!ev->status && ev->page == 0x01) {
2884                 struct inquiry_entry *ie;
2885
2886                 ie = hci_inquiry_cache_lookup(hdev, &conn->dst);
2887                 if (ie)
2888                         ie->data.ssp_mode = (ev->features[0] & LMP_HOST_SSP);
2889
2890                 if (ev->features[0] & LMP_HOST_SSP)
2891                         set_bit(HCI_CONN_SSP_ENABLED, &conn->flags);
2892         }
2893
2894         if (conn->state != BT_CONFIG)
2895                 goto unlock;
2896
2897         if (!ev->status && !test_bit(HCI_CONN_MGMT_CONNECTED, &conn->flags)) {
2898                 struct hci_cp_remote_name_req cp;
2899                 memset(&cp, 0, sizeof(cp));
2900                 bacpy(&cp.bdaddr, &conn->dst);
2901                 cp.pscan_rep_mode = 0x02;
2902                 hci_send_cmd(hdev, HCI_OP_REMOTE_NAME_REQ, sizeof(cp), &cp);
2903         } else if (!test_and_set_bit(HCI_CONN_MGMT_CONNECTED, &conn->flags))
2904                 mgmt_device_connected(hdev, &conn->dst, conn->type,
2905                                       conn->dst_type, 0, NULL, 0,
2906                                       conn->dev_class);
2907
2908         if (!hci_outgoing_auth_needed(hdev, conn)) {
2909                 conn->state = BT_CONNECTED;
2910                 hci_proto_connect_cfm(conn, ev->status);
2911                 hci_conn_put(conn);
2912         }
2913
2914 unlock:
2915         hci_dev_unlock(hdev);
2916 }
2917
2918 static void hci_sync_conn_complete_evt(struct hci_dev *hdev,
2919                                        struct sk_buff *skb)
2920 {
2921         struct hci_ev_sync_conn_complete *ev = (void *) skb->data;
2922         struct hci_conn *conn;
2923
2924         BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
2925
2926         hci_dev_lock(hdev);
2927
2928         conn = hci_conn_hash_lookup_ba(hdev, ev->link_type, &ev->bdaddr);
2929         if (!conn) {
2930                 if (ev->link_type == ESCO_LINK)
2931                         goto unlock;
2932
2933                 conn = hci_conn_hash_lookup_ba(hdev, ESCO_LINK, &ev->bdaddr);
2934                 if (!conn)
2935                         goto unlock;
2936
2937                 conn->type = SCO_LINK;
2938         }
2939
2940         switch (ev->status) {
2941         case 0x00:
2942                 conn->handle = __le16_to_cpu(ev->handle);
2943                 conn->state  = BT_CONNECTED;
2944
2945                 hci_conn_hold_device(conn);
2946                 hci_conn_add_sysfs(conn);
2947                 break;
2948
2949         case 0x11:      /* Unsupported Feature or Parameter Value */
2950         case 0x1c:      /* SCO interval rejected */
2951         case 0x1a:      /* Unsupported Remote Feature */
2952         case 0x1f:      /* Unspecified error */
2953                 if (conn->out && conn->attempt < 2) {
2954                         conn->pkt_type = (hdev->esco_type & SCO_ESCO_MASK) |
2955                                         (hdev->esco_type & EDR_ESCO_MASK);
2956                         hci_setup_sync(conn, conn->link->handle);
2957                         goto unlock;
2958                 }
2959                 /* fall through */
2960
2961         default:
2962                 conn->state = BT_CLOSED;
2963                 break;
2964         }
2965
2966         hci_proto_connect_cfm(conn, ev->status);
2967         if (ev->status)
2968                 hci_conn_del(conn);
2969
2970 unlock:
2971         hci_dev_unlock(hdev);
2972 }
2973
2974 static void hci_extended_inquiry_result_evt(struct hci_dev *hdev,
2975                                             struct sk_buff *skb)
2976 {
2977         struct inquiry_data data;
2978         struct extended_inquiry_info *info = (void *) (skb->data + 1);
2979         int num_rsp = *((__u8 *) skb->data);
2980         size_t eir_len;
2981
2982         BT_DBG("%s num_rsp %d", hdev->name, num_rsp);
2983
2984         if (!num_rsp)
2985                 return;
2986
2987         if (test_bit(HCI_PERIODIC_INQ, &hdev->dev_flags))
2988                 return;
2989
2990         hci_dev_lock(hdev);
2991
2992         for (; num_rsp; num_rsp--, info++) {
2993                 bool name_known, ssp;
2994
2995                 bacpy(&data.bdaddr, &info->bdaddr);
2996                 data.pscan_rep_mode     = info->pscan_rep_mode;
2997                 data.pscan_period_mode  = info->pscan_period_mode;
2998                 data.pscan_mode         = 0x00;
2999                 memcpy(data.dev_class, info->dev_class, 3);
3000                 data.clock_offset       = info->clock_offset;
3001                 data.rssi               = info->rssi;
3002                 data.ssp_mode           = 0x01;
3003
3004                 if (test_bit(HCI_MGMT, &hdev->dev_flags))
3005                         name_known = eir_has_data_type(info->data,
3006                                                        sizeof(info->data),
3007                                                        EIR_NAME_COMPLETE);
3008                 else
3009                         name_known = true;
3010
3011                 name_known = hci_inquiry_cache_update(hdev, &data, name_known,
3012                                                       &ssp);
3013                 eir_len = eir_get_length(info->data, sizeof(info->data));
3014                 mgmt_device_found(hdev, &info->bdaddr, ACL_LINK, 0x00,
3015                                   info->dev_class, info->rssi, !name_known,
3016                                   ssp, info->data, eir_len);
3017         }
3018
3019         hci_dev_unlock(hdev);
3020 }
3021
3022 static void hci_key_refresh_complete_evt(struct hci_dev *hdev,
3023                                          struct sk_buff *skb)
3024 {
3025         struct hci_ev_key_refresh_complete *ev = (void *) skb->data;
3026         struct hci_conn *conn;
3027
3028         BT_DBG("%s status 0x%2.2x handle 0x%4.4x", hdev->name, ev->status,
3029                __le16_to_cpu(ev->handle));
3030
3031         hci_dev_lock(hdev);
3032
3033         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
3034         if (!conn)
3035                 goto unlock;
3036
3037         if (!ev->status)
3038                 conn->sec_level = conn->pending_sec_level;
3039
3040         clear_bit(HCI_CONN_ENCRYPT_PEND, &conn->flags);
3041
3042         if (ev->status && conn->state == BT_CONNECTED) {
3043                 hci_disconnect(conn, HCI_ERROR_AUTH_FAILURE);
3044                 hci_conn_put(conn);
3045                 goto unlock;
3046         }
3047
3048         if (conn->state == BT_CONFIG) {
3049                 if (!ev->status)
3050                         conn->state = BT_CONNECTED;
3051
3052                 hci_proto_connect_cfm(conn, ev->status);
3053                 hci_conn_put(conn);
3054         } else {
3055                 hci_auth_cfm(conn, ev->status);
3056
3057                 hci_conn_hold(conn);
3058                 conn->disc_timeout = HCI_DISCONN_TIMEOUT;
3059                 hci_conn_put(conn);
3060         }
3061
3062 unlock:
3063         hci_dev_unlock(hdev);
3064 }
3065
3066 static u8 hci_get_auth_req(struct hci_conn *conn)
3067 {
3068         /* If remote requests dedicated bonding follow that lead */
3069         if (conn->remote_auth == 0x02 || conn->remote_auth == 0x03) {
3070                 /* If both remote and local IO capabilities allow MITM
3071                  * protection then require it, otherwise don't */
3072                 if (conn->remote_cap == 0x03 || conn->io_capability == 0x03)
3073                         return 0x02;
3074                 else
3075                         return 0x03;
3076         }
3077
3078         /* If remote requests no-bonding follow that lead */
3079         if (conn->remote_auth == 0x00 || conn->remote_auth == 0x01)
3080                 return conn->remote_auth | (conn->auth_type & 0x01);
3081
3082         return conn->auth_type;
3083 }
3084
3085 static void hci_io_capa_request_evt(struct hci_dev *hdev, struct sk_buff *skb)
3086 {
3087         struct hci_ev_io_capa_request *ev = (void *) skb->data;
3088         struct hci_conn *conn;
3089
3090         BT_DBG("%s", hdev->name);
3091
3092         hci_dev_lock(hdev);
3093
3094         conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
3095         if (!conn)
3096                 goto unlock;
3097
3098         hci_conn_hold(conn);
3099
3100         if (!test_bit(HCI_MGMT, &hdev->dev_flags))
3101                 goto unlock;
3102
3103         if (test_bit(HCI_PAIRABLE, &hdev->dev_flags) ||
3104             (conn->remote_auth & ~0x01) == HCI_AT_NO_BONDING) {
3105                 struct hci_cp_io_capability_reply cp;
3106
3107                 bacpy(&cp.bdaddr, &ev->bdaddr);
3108                 /* Change the IO capability from KeyboardDisplay
3109                  * to DisplayYesNo as it is not supported by BT spec. */
3110                 cp.capability = (conn->io_capability == 0x04) ?
3111                                                 0x01 : conn->io_capability;
3112                 conn->auth_type = hci_get_auth_req(conn);
3113                 cp.authentication = conn->auth_type;
3114
3115                 if (hci_find_remote_oob_data(hdev, &conn->dst) &&
3116                     (conn->out || test_bit(HCI_CONN_REMOTE_OOB, &conn->flags)))
3117                         cp.oob_data = 0x01;
3118                 else
3119                         cp.oob_data = 0x00;
3120
3121                 hci_send_cmd(hdev, HCI_OP_IO_CAPABILITY_REPLY,
3122                              sizeof(cp), &cp);
3123         } else {
3124                 struct hci_cp_io_capability_neg_reply cp;
3125
3126                 bacpy(&cp.bdaddr, &ev->bdaddr);
3127                 cp.reason = HCI_ERROR_PAIRING_NOT_ALLOWED;
3128
3129                 hci_send_cmd(hdev, HCI_OP_IO_CAPABILITY_NEG_REPLY,
3130                              sizeof(cp), &cp);
3131         }
3132
3133 unlock:
3134         hci_dev_unlock(hdev);
3135 }
3136
3137 static void hci_io_capa_reply_evt(struct hci_dev *hdev, struct sk_buff *skb)
3138 {
3139         struct hci_ev_io_capa_reply *ev = (void *) skb->data;
3140         struct hci_conn *conn;
3141
3142         BT_DBG("%s", hdev->name);
3143
3144         hci_dev_lock(hdev);
3145
3146         conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
3147         if (!conn)
3148                 goto unlock;
3149
3150         conn->remote_cap = ev->capability;
3151         conn->remote_auth = ev->authentication;
3152         if (ev->oob_data)
3153                 set_bit(HCI_CONN_REMOTE_OOB, &conn->flags);
3154
3155 unlock:
3156         hci_dev_unlock(hdev);
3157 }
3158
3159 static void hci_user_confirm_request_evt(struct hci_dev *hdev,
3160                                          struct sk_buff *skb)
3161 {
3162         struct hci_ev_user_confirm_req *ev = (void *) skb->data;
3163         int loc_mitm, rem_mitm, confirm_hint = 0;
3164         struct hci_conn *conn;
3165
3166         BT_DBG("%s", hdev->name);
3167
3168         hci_dev_lock(hdev);
3169
3170         if (!test_bit(HCI_MGMT, &hdev->dev_flags))
3171                 goto unlock;
3172
3173         conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
3174         if (!conn)
3175                 goto unlock;
3176
3177         loc_mitm = (conn->auth_type & 0x01);
3178         rem_mitm = (conn->remote_auth & 0x01);
3179
3180         /* If we require MITM but the remote device can't provide that
3181          * (it has NoInputNoOutput) then reject the confirmation
3182          * request. The only exception is when we're dedicated bonding
3183          * initiators (connect_cfm_cb set) since then we always have the MITM
3184          * bit set. */
3185         if (!conn->connect_cfm_cb && loc_mitm && conn->remote_cap == 0x03) {
3186                 BT_DBG("Rejecting request: remote device can't provide MITM");
3187                 hci_send_cmd(hdev, HCI_OP_USER_CONFIRM_NEG_REPLY,
3188                              sizeof(ev->bdaddr), &ev->bdaddr);
3189                 goto unlock;
3190         }
3191
3192         /* If no side requires MITM protection; auto-accept */
3193         if ((!loc_mitm || conn->remote_cap == 0x03) &&
3194             (!rem_mitm || conn->io_capability == 0x03)) {
3195
3196                 /* If we're not the initiators request authorization to
3197                  * proceed from user space (mgmt_user_confirm with
3198                  * confirm_hint set to 1). */
3199                 if (!test_bit(HCI_CONN_AUTH_PEND, &conn->flags)) {
3200                         BT_DBG("Confirming auto-accept as acceptor");
3201                         confirm_hint = 1;
3202                         goto confirm;
3203                 }
3204
3205                 BT_DBG("Auto-accept of user confirmation with %ums delay",
3206                        hdev->auto_accept_delay);
3207
3208                 if (hdev->auto_accept_delay > 0) {
3209                         int delay = msecs_to_jiffies(hdev->auto_accept_delay);
3210                         mod_timer(&conn->auto_accept_timer, jiffies + delay);
3211                         goto unlock;
3212                 }
3213
3214                 hci_send_cmd(hdev, HCI_OP_USER_CONFIRM_REPLY,
3215                              sizeof(ev->bdaddr), &ev->bdaddr);
3216                 goto unlock;
3217         }
3218
3219 confirm:
3220         mgmt_user_confirm_request(hdev, &ev->bdaddr, ACL_LINK, 0, ev->passkey,
3221                                   confirm_hint);
3222
3223 unlock:
3224         hci_dev_unlock(hdev);
3225 }
3226
3227 static void hci_user_passkey_request_evt(struct hci_dev *hdev,
3228                                          struct sk_buff *skb)
3229 {
3230         struct hci_ev_user_passkey_req *ev = (void *) skb->data;
3231
3232         BT_DBG("%s", hdev->name);
3233
3234         if (test_bit(HCI_MGMT, &hdev->dev_flags))
3235                 mgmt_user_passkey_request(hdev, &ev->bdaddr, ACL_LINK, 0);
3236 }
3237
3238 static void hci_user_passkey_notify_evt(struct hci_dev *hdev,
3239                                         struct sk_buff *skb)
3240 {
3241         struct hci_ev_user_passkey_notify *ev = (void *) skb->data;
3242         struct hci_conn *conn;
3243
3244         BT_DBG("%s", hdev->name);
3245
3246         conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
3247         if (!conn)
3248                 return;
3249
3250         conn->passkey_notify = __le32_to_cpu(ev->passkey);
3251         conn->passkey_entered = 0;
3252
3253         if (test_bit(HCI_MGMT, &hdev->dev_flags))
3254                 mgmt_user_passkey_notify(hdev, &conn->dst, conn->type,
3255                                          conn->dst_type, conn->passkey_notify,
3256                                          conn->passkey_entered);
3257 }
3258
3259 static void hci_keypress_notify_evt(struct hci_dev *hdev, struct sk_buff *skb)
3260 {
3261         struct hci_ev_keypress_notify *ev = (void *) skb->data;
3262         struct hci_conn *conn;
3263
3264         BT_DBG("%s", hdev->name);
3265
3266         conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
3267         if (!conn)
3268                 return;
3269
3270         switch (ev->type) {
3271         case HCI_KEYPRESS_STARTED:
3272                 conn->passkey_entered = 0;
3273                 return;
3274
3275         case HCI_KEYPRESS_ENTERED:
3276                 conn->passkey_entered++;
3277                 break;
3278
3279         case HCI_KEYPRESS_ERASED:
3280                 conn->passkey_entered--;
3281                 break;
3282
3283         case HCI_KEYPRESS_CLEARED:
3284                 conn->passkey_entered = 0;
3285                 break;
3286
3287         case HCI_KEYPRESS_COMPLETED:
3288                 return;
3289         }
3290
3291         if (test_bit(HCI_MGMT, &hdev->dev_flags))
3292                 mgmt_user_passkey_notify(hdev, &conn->dst, conn->type,
3293                                          conn->dst_type, conn->passkey_notify,
3294                                          conn->passkey_entered);
3295 }
3296
3297 static void hci_simple_pair_complete_evt(struct hci_dev *hdev,
3298                                          struct sk_buff *skb)
3299 {
3300         struct hci_ev_simple_pair_complete *ev = (void *) skb->data;
3301         struct hci_conn *conn;
3302
3303         BT_DBG("%s", hdev->name);
3304
3305         hci_dev_lock(hdev);
3306
3307         conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
3308         if (!conn)
3309                 goto unlock;
3310
3311         /* To avoid duplicate auth_failed events to user space we check
3312          * the HCI_CONN_AUTH_PEND flag which will be set if we
3313          * initiated the authentication. A traditional auth_complete
3314          * event gets always produced as initiator and is also mapped to
3315          * the mgmt_auth_failed event */
3316         if (!test_bit(HCI_CONN_AUTH_PEND, &conn->flags) && ev->status)
3317                 mgmt_auth_failed(hdev, &conn->dst, conn->type, conn->dst_type,
3318                                  ev->status);
3319
3320         hci_conn_put(conn);
3321
3322 unlock:
3323         hci_dev_unlock(hdev);
3324 }
3325
3326 static void hci_remote_host_features_evt(struct hci_dev *hdev,
3327                                          struct sk_buff *skb)
3328 {
3329         struct hci_ev_remote_host_features *ev = (void *) skb->data;
3330         struct inquiry_entry *ie;
3331
3332         BT_DBG("%s", hdev->name);
3333
3334         hci_dev_lock(hdev);
3335
3336         ie = hci_inquiry_cache_lookup(hdev, &ev->bdaddr);
3337         if (ie)
3338                 ie->data.ssp_mode = (ev->features[0] & LMP_HOST_SSP);
3339
3340         hci_dev_unlock(hdev);
3341 }
3342
3343 static void hci_remote_oob_data_request_evt(struct hci_dev *hdev,
3344                                             struct sk_buff *skb)
3345 {
3346         struct hci_ev_remote_oob_data_request *ev = (void *) skb->data;
3347         struct oob_data *data;
3348
3349         BT_DBG("%s", hdev->name);
3350
3351         hci_dev_lock(hdev);
3352
3353         if (!test_bit(HCI_MGMT, &hdev->dev_flags))
3354                 goto unlock;
3355
3356         data = hci_find_remote_oob_data(hdev, &ev->bdaddr);
3357         if (data) {
3358                 struct hci_cp_remote_oob_data_reply cp;
3359
3360                 bacpy(&cp.bdaddr, &ev->bdaddr);
3361                 memcpy(cp.hash, data->hash, sizeof(cp.hash));
3362                 memcpy(cp.randomizer, data->randomizer, sizeof(cp.randomizer));
3363
3364                 hci_send_cmd(hdev, HCI_OP_REMOTE_OOB_DATA_REPLY, sizeof(cp),
3365                              &cp);
3366         } else {
3367                 struct hci_cp_remote_oob_data_neg_reply cp;
3368
3369                 bacpy(&cp.bdaddr, &ev->bdaddr);
3370                 hci_send_cmd(hdev, HCI_OP_REMOTE_OOB_DATA_NEG_REPLY, sizeof(cp),
3371                              &cp);
3372         }
3373
3374 unlock:
3375         hci_dev_unlock(hdev);
3376 }
3377
3378 static void hci_phy_link_complete_evt(struct hci_dev *hdev,
3379                                       struct sk_buff *skb)
3380 {
3381         struct hci_ev_phy_link_complete *ev = (void *) skb->data;
3382         struct hci_conn *hcon, *bredr_hcon;
3383
3384         BT_DBG("%s handle 0x%2.2x status 0x%2.2x", hdev->name, ev->phy_handle,
3385                ev->status);
3386
3387         hci_dev_lock(hdev);
3388
3389         hcon = hci_conn_hash_lookup_handle(hdev, ev->phy_handle);
3390         if (!hcon) {
3391                 hci_dev_unlock(hdev);
3392                 return;
3393         }
3394
3395         if (ev->status) {
3396                 hci_conn_del(hcon);
3397                 hci_dev_unlock(hdev);
3398                 return;
3399         }
3400
3401         bredr_hcon = hcon->amp_mgr->l2cap_conn->hcon;
3402
3403         hcon->state = BT_CONNECTED;
3404         bacpy(&hcon->dst, &bredr_hcon->dst);
3405
3406         hci_conn_hold(hcon);
3407         hcon->disc_timeout = HCI_DISCONN_TIMEOUT;
3408         hci_conn_put(hcon);
3409
3410         hci_conn_hold_device(hcon);
3411         hci_conn_add_sysfs(hcon);
3412
3413         amp_physical_cfm(bredr_hcon, hcon);
3414
3415         hci_dev_unlock(hdev);
3416 }
3417
3418 static void hci_loglink_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
3419 {
3420         struct hci_ev_logical_link_complete *ev = (void *) skb->data;
3421         struct hci_conn *hcon;
3422         struct hci_chan *hchan;
3423         struct amp_mgr *mgr;
3424
3425         BT_DBG("%s log_handle 0x%4.4x phy_handle 0x%2.2x status 0x%2.2x",
3426                hdev->name, le16_to_cpu(ev->handle), ev->phy_handle,
3427                ev->status);
3428
3429         hcon = hci_conn_hash_lookup_handle(hdev, ev->phy_handle);
3430         if (!hcon)
3431                 return;
3432
3433         /* Create AMP hchan */
3434         hchan = hci_chan_create(hcon);
3435         if (!hchan)
3436                 return;
3437
3438         hchan->handle = le16_to_cpu(ev->handle);
3439
3440         BT_DBG("hcon %p mgr %p hchan %p", hcon, hcon->amp_mgr, hchan);
3441
3442         mgr = hcon->amp_mgr;
3443         if (mgr && mgr->bredr_chan) {
3444                 struct l2cap_chan *bredr_chan = mgr->bredr_chan;
3445
3446                 l2cap_chan_lock(bredr_chan);
3447
3448                 bredr_chan->conn->mtu = hdev->block_mtu;
3449                 l2cap_logical_cfm(bredr_chan, hchan, 0);
3450                 hci_conn_hold(hcon);
3451
3452                 l2cap_chan_unlock(bredr_chan);
3453         }
3454 }
3455
3456 static void hci_disconn_loglink_complete_evt(struct hci_dev *hdev,
3457                                              struct sk_buff *skb)
3458 {
3459         struct hci_ev_disconn_logical_link_complete *ev = (void *) skb->data;
3460         struct hci_chan *hchan;
3461
3462         BT_DBG("%s log handle 0x%4.4x status 0x%2.2x", hdev->name,
3463                le16_to_cpu(ev->handle), ev->status);
3464
3465         if (ev->status)
3466                 return;
3467
3468         hci_dev_lock(hdev);
3469
3470         hchan = hci_chan_lookup_handle(hdev, le16_to_cpu(ev->handle));
3471         if (!hchan)
3472                 goto unlock;
3473
3474         amp_destroy_logical_link(hchan, ev->reason);
3475
3476 unlock:
3477         hci_dev_unlock(hdev);
3478 }
3479
3480 static void hci_disconn_phylink_complete_evt(struct hci_dev *hdev,
3481                                              struct sk_buff *skb)
3482 {
3483         struct hci_ev_disconn_phy_link_complete *ev = (void *) skb->data;
3484         struct hci_conn *hcon;
3485
3486         BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
3487
3488         if (ev->status)
3489                 return;
3490
3491         hci_dev_lock(hdev);
3492
3493         hcon = hci_conn_hash_lookup_handle(hdev, ev->phy_handle);
3494         if (hcon) {
3495                 hcon->state = BT_CLOSED;
3496                 hci_conn_del(hcon);
3497         }
3498
3499         hci_dev_unlock(hdev);
3500 }
3501
3502 static void hci_le_conn_complete_evt(struct hci_dev *hdev, struct sk_buff *skb)
3503 {
3504         struct hci_ev_le_conn_complete *ev = (void *) skb->data;
3505         struct hci_conn *conn;
3506
3507         BT_DBG("%s status 0x%2.2x", hdev->name, ev->status);
3508
3509         hci_dev_lock(hdev);
3510
3511         conn = hci_conn_hash_lookup_state(hdev, LE_LINK, BT_CONNECT);
3512         if (!conn) {
3513                 conn = hci_conn_add(hdev, LE_LINK, &ev->bdaddr);
3514                 if (!conn) {
3515                         BT_ERR("No memory for new connection");
3516                         goto unlock;
3517                 }
3518
3519                 conn->dst_type = ev->bdaddr_type;
3520
3521                 if (ev->role == LE_CONN_ROLE_MASTER) {
3522                         conn->out = true;
3523                         conn->link_mode |= HCI_LM_MASTER;
3524                 }
3525         }
3526
3527         if (ev->status) {
3528                 mgmt_connect_failed(hdev, &conn->dst, conn->type,
3529                                     conn->dst_type, ev->status);
3530                 hci_proto_connect_cfm(conn, ev->status);
3531                 conn->state = BT_CLOSED;
3532                 hci_conn_del(conn);
3533                 goto unlock;
3534         }
3535
3536         if (!test_and_set_bit(HCI_CONN_MGMT_CONNECTED, &conn->flags))
3537                 mgmt_device_connected(hdev, &ev->bdaddr, conn->type,
3538                                       conn->dst_type, 0, NULL, 0, NULL);
3539
3540         conn->sec_level = BT_SECURITY_LOW;
3541         conn->handle = __le16_to_cpu(ev->handle);
3542         conn->state = BT_CONNECTED;
3543
3544         hci_conn_hold_device(conn);
3545         hci_conn_add_sysfs(conn);
3546
3547         hci_proto_connect_cfm(conn, ev->status);
3548
3549 unlock:
3550         hci_dev_unlock(hdev);
3551 }
3552
3553 static void hci_le_adv_report_evt(struct hci_dev *hdev, struct sk_buff *skb)
3554 {
3555         u8 num_reports = skb->data[0];
3556         void *ptr = &skb->data[1];
3557         s8 rssi;
3558
3559         while (num_reports--) {
3560                 struct hci_ev_le_advertising_info *ev = ptr;
3561
3562                 rssi = ev->data[ev->length];
3563                 mgmt_device_found(hdev, &ev->bdaddr, LE_LINK, ev->bdaddr_type,
3564                                   NULL, rssi, 0, 1, ev->data, ev->length);
3565
3566                 ptr += sizeof(*ev) + ev->length + 1;
3567         }
3568 }
3569
3570 static void hci_le_ltk_request_evt(struct hci_dev *hdev, struct sk_buff *skb)
3571 {
3572         struct hci_ev_le_ltk_req *ev = (void *) skb->data;
3573         struct hci_cp_le_ltk_reply cp;
3574         struct hci_cp_le_ltk_neg_reply neg;
3575         struct hci_conn *conn;
3576         struct smp_ltk *ltk;
3577
3578         BT_DBG("%s handle 0x%4.4x", hdev->name, __le16_to_cpu(ev->handle));
3579
3580         hci_dev_lock(hdev);
3581
3582         conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
3583         if (conn == NULL)
3584                 goto not_found;
3585
3586         ltk = hci_find_ltk(hdev, ev->ediv, ev->random);
3587         if (ltk == NULL)
3588                 goto not_found;
3589
3590         memcpy(cp.ltk, ltk->val, sizeof(ltk->val));
3591         cp.handle = cpu_to_le16(conn->handle);
3592
3593         if (ltk->authenticated)
3594                 conn->sec_level = BT_SECURITY_HIGH;
3595
3596         hci_send_cmd(hdev, HCI_OP_LE_LTK_REPLY, sizeof(cp), &cp);
3597
3598         if (ltk->type & HCI_SMP_STK) {
3599                 list_del(&ltk->list);
3600                 kfree(ltk);
3601         }
3602
3603         hci_dev_unlock(hdev);
3604
3605         return;
3606
3607 not_found:
3608         neg.handle = ev->handle;
3609         hci_send_cmd(hdev, HCI_OP_LE_LTK_NEG_REPLY, sizeof(neg), &neg);
3610         hci_dev_unlock(hdev);
3611 }
3612
3613 static void hci_le_meta_evt(struct hci_dev *hdev, struct sk_buff *skb)
3614 {
3615         struct hci_ev_le_meta *le_ev = (void *) skb->data;
3616
3617         skb_pull(skb, sizeof(*le_ev));
3618
3619         switch (le_ev->subevent) {
3620         case HCI_EV_LE_CONN_COMPLETE:
3621                 hci_le_conn_complete_evt(hdev, skb);
3622                 break;
3623
3624         case HCI_EV_LE_ADVERTISING_REPORT:
3625                 hci_le_adv_report_evt(hdev, skb);
3626                 break;
3627
3628         case HCI_EV_LE_LTK_REQ:
3629                 hci_le_ltk_request_evt(hdev, skb);
3630                 break;
3631
3632         default:
3633                 break;
3634         }
3635 }
3636
3637 static void hci_chan_selected_evt(struct hci_dev *hdev, struct sk_buff *skb)
3638 {
3639         struct hci_ev_channel_selected *ev = (void *) skb->data;
3640         struct hci_conn *hcon;
3641
3642         BT_DBG("%s handle 0x%2.2x", hdev->name, ev->phy_handle);
3643
3644         skb_pull(skb, sizeof(*ev));
3645
3646         hcon = hci_conn_hash_lookup_handle(hdev, ev->phy_handle);
3647         if (!hcon)
3648                 return;
3649
3650         amp_read_loc_assoc_final_data(hdev, hcon);
3651 }
3652
3653 void hci_event_packet(struct hci_dev *hdev, struct sk_buff *skb)
3654 {
3655         struct hci_event_hdr *hdr = (void *) skb->data;
3656         __u8 event = hdr->evt;
3657
3658         skb_pull(skb, HCI_EVENT_HDR_SIZE);
3659
3660         switch (event) {
3661         case HCI_EV_INQUIRY_COMPLETE:
3662                 hci_inquiry_complete_evt(hdev, skb);
3663                 break;
3664
3665         case HCI_EV_INQUIRY_RESULT:
3666                 hci_inquiry_result_evt(hdev, skb);
3667                 break;
3668
3669         case HCI_EV_CONN_COMPLETE:
3670                 hci_conn_complete_evt(hdev, skb);
3671                 break;
3672
3673         case HCI_EV_CONN_REQUEST:
3674                 hci_conn_request_evt(hdev, skb);
3675                 break;
3676
3677         case HCI_EV_DISCONN_COMPLETE:
3678                 hci_disconn_complete_evt(hdev, skb);
3679                 break;
3680
3681         case HCI_EV_AUTH_COMPLETE:
3682                 hci_auth_complete_evt(hdev, skb);
3683                 break;
3684
3685         case HCI_EV_REMOTE_NAME:
3686                 hci_remote_name_evt(hdev, skb);
3687                 break;
3688
3689         case HCI_EV_ENCRYPT_CHANGE:
3690                 hci_encrypt_change_evt(hdev, skb);
3691                 break;
3692
3693         case HCI_EV_CHANGE_LINK_KEY_COMPLETE:
3694                 hci_change_link_key_complete_evt(hdev, skb);
3695                 break;
3696
3697         case HCI_EV_REMOTE_FEATURES:
3698                 hci_remote_features_evt(hdev, skb);
3699                 break;
3700
3701         case HCI_EV_CMD_COMPLETE:
3702                 hci_cmd_complete_evt(hdev, skb);
3703                 break;
3704
3705         case HCI_EV_CMD_STATUS:
3706                 hci_cmd_status_evt(hdev, skb);
3707                 break;
3708
3709         case HCI_EV_ROLE_CHANGE:
3710                 hci_role_change_evt(hdev, skb);
3711                 break;
3712
3713         case HCI_EV_NUM_COMP_PKTS:
3714                 hci_num_comp_pkts_evt(hdev, skb);
3715                 break;
3716
3717         case HCI_EV_MODE_CHANGE:
3718                 hci_mode_change_evt(hdev, skb);
3719                 break;
3720
3721         case HCI_EV_PIN_CODE_REQ:
3722                 hci_pin_code_request_evt(hdev, skb);
3723                 break;
3724
3725         case HCI_EV_LINK_KEY_REQ:
3726                 hci_link_key_request_evt(hdev, skb);
3727                 break;
3728
3729         case HCI_EV_LINK_KEY_NOTIFY:
3730                 hci_link_key_notify_evt(hdev, skb);
3731                 break;
3732
3733         case HCI_EV_CLOCK_OFFSET:
3734                 hci_clock_offset_evt(hdev, skb);
3735                 break;
3736
3737         case HCI_EV_PKT_TYPE_CHANGE:
3738                 hci_pkt_type_change_evt(hdev, skb);
3739                 break;
3740
3741         case HCI_EV_PSCAN_REP_MODE:
3742                 hci_pscan_rep_mode_evt(hdev, skb);
3743                 break;
3744
3745         case HCI_EV_INQUIRY_RESULT_WITH_RSSI:
3746                 hci_inquiry_result_with_rssi_evt(hdev, skb);
3747                 break;
3748
3749         case HCI_EV_REMOTE_EXT_FEATURES:
3750                 hci_remote_ext_features_evt(hdev, skb);
3751                 break;
3752
3753         case HCI_EV_SYNC_CONN_COMPLETE:
3754                 hci_sync_conn_complete_evt(hdev, skb);
3755                 break;
3756
3757         case HCI_EV_EXTENDED_INQUIRY_RESULT:
3758                 hci_extended_inquiry_result_evt(hdev, skb);
3759                 break;
3760
3761         case HCI_EV_KEY_REFRESH_COMPLETE:
3762                 hci_key_refresh_complete_evt(hdev, skb);
3763                 break;
3764
3765         case HCI_EV_IO_CAPA_REQUEST:
3766                 hci_io_capa_request_evt(hdev, skb);
3767                 break;
3768
3769         case HCI_EV_IO_CAPA_REPLY:
3770                 hci_io_capa_reply_evt(hdev, skb);
3771                 break;
3772
3773         case HCI_EV_USER_CONFIRM_REQUEST:
3774                 hci_user_confirm_request_evt(hdev, skb);
3775                 break;
3776
3777         case HCI_EV_USER_PASSKEY_REQUEST:
3778                 hci_user_passkey_request_evt(hdev, skb);
3779                 break;
3780
3781         case HCI_EV_USER_PASSKEY_NOTIFY:
3782                 hci_user_passkey_notify_evt(hdev, skb);
3783                 break;
3784
3785         case HCI_EV_KEYPRESS_NOTIFY:
3786                 hci_keypress_notify_evt(hdev, skb);
3787                 break;
3788
3789         case HCI_EV_SIMPLE_PAIR_COMPLETE:
3790                 hci_simple_pair_complete_evt(hdev, skb);
3791                 break;
3792
3793         case HCI_EV_REMOTE_HOST_FEATURES:
3794                 hci_remote_host_features_evt(hdev, skb);
3795                 break;
3796
3797         case HCI_EV_LE_META:
3798                 hci_le_meta_evt(hdev, skb);
3799                 break;
3800
3801         case HCI_EV_CHANNEL_SELECTED:
3802                 hci_chan_selected_evt(hdev, skb);
3803                 break;
3804
3805         case HCI_EV_REMOTE_OOB_DATA_REQUEST:
3806                 hci_remote_oob_data_request_evt(hdev, skb);
3807                 break;
3808
3809         case HCI_EV_PHY_LINK_COMPLETE:
3810                 hci_phy_link_complete_evt(hdev, skb);
3811                 break;
3812
3813         case HCI_EV_LOGICAL_LINK_COMPLETE:
3814                 hci_loglink_complete_evt(hdev, skb);
3815                 break;
3816
3817         case HCI_EV_DISCONN_LOGICAL_LINK_COMPLETE:
3818                 hci_disconn_loglink_complete_evt(hdev, skb);
3819                 break;
3820
3821         case HCI_EV_DISCONN_PHY_LINK_COMPLETE:
3822                 hci_disconn_phylink_complete_evt(hdev, skb);
3823                 break;
3824
3825         case HCI_EV_NUM_COMP_BLOCKS:
3826                 hci_num_comp_blocks_evt(hdev, skb);
3827                 break;
3828
3829         default:
3830                 BT_DBG("%s event 0x%2.2x", hdev->name, event);
3831                 break;
3832         }
3833
3834         kfree_skb(skb);
3835         hdev->stat.evt_rx++;
3836 }