xref: /netbsd-src/lib/libbluetooth/bt_dev.c (revision b1c86f5f087524e68db12794ee9c3e3da1ab17a0)
1 /*	$NetBSD: bt_dev.c,v 1.1 2009/08/03 15:59:42 plunky Exp $	*/
2 
3 /*-
4  * Copyright (c) 2009 Iain Hibbert
5  * Copyright (c) 2009 Maksim Yevmenkin <m_evmenkin@yahoo.com>
6  * All rights reserved.
7  *
8  * Redistribution and use in source and binary forms, with or without
9  * modification, are permitted provided that the following conditions
10  * are met:
11  * 1. Redistributions of source code must retain the above copyright
12  *    notice, this list of conditions and the following disclaimer.
13  * 2. Redistributions in binary form must reproduce the above copyright
14  *    notice, this list of conditions and the following disclaimer in the
15  *    documentation and/or other materials provided with the distribution.
16  *
17  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
18  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
19  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
20  * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
21  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
22  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
23  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
24  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
25  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
26  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
27  * SUCH DAMAGE.
28  */
29 
30 /*-
31  * Copyright (c) 2006 Itronix Inc.
32  * All rights reserved.
33  *
34  * Written by Iain Hibbert for Itronix Inc.
35  *
36  * Redistribution and use in source and binary forms, with or without
37  * modification, are permitted provided that the following conditions
38  * are met:
39  * 1. Redistributions of source code must retain the above copyright
40  *    notice, this list of conditions and the following disclaimer.
41  * 2. Redistributions in binary form must reproduce the above copyright
42  *    notice, this list of conditions and the following disclaimer in the
43  *    documentation and/or other materials provided with the distribution.
44  * 3. The name of Itronix Inc. may not be used to endorse
45  *    or promote products derived from this software without specific
46  *    prior written permission.
47  *
48  * THIS SOFTWARE IS PROVIDED BY ITRONIX INC. ``AS IS'' AND
49  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
50  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
51  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL ITRONIX INC. BE LIABLE FOR ANY
52  * DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
53  * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
54  * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
55  * ON ANY THEORY OF LIABILITY, WHETHER IN
56  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
57  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
58  * POSSIBILITY OF SUCH DAMAGE.
59  */
60 
61 #include <sys/cdefs.h>
62 __RCSID("$NetBSD: bt_dev.c,v 1.1 2009/08/03 15:59:42 plunky Exp $");
63 
64 #include <sys/event.h>
65 #include <sys/ioctl.h>
66 #include <sys/param.h>
67 #include <sys/time.h>
68 #include <sys/uio.h>
69 
70 #include <bluetooth.h>
71 #include <errno.h>
72 #include <stdlib.h>
73 #include <string.h>
74 #include <unistd.h>
75 
76 int
77 bt_devaddr(const char *name, bdaddr_t *addr)
78 {
79 	struct btreq btr;
80 	bdaddr_t bdaddr;
81 	int s, rv;
82 
83 	if (name == NULL) {
84 		errno = EINVAL;
85 		return 0;
86 	}
87 
88 	if (addr == NULL)
89 		addr = &bdaddr;
90 
91 	if (bt_aton(name, addr))
92 		return bt_devname(NULL, addr);
93 
94 	memset(&btr, 0, sizeof(btr));
95 	strncpy(btr.btr_name, name, HCI_DEVNAME_SIZE);
96 
97 	s = socket(PF_BLUETOOTH, SOCK_RAW, BTPROTO_HCI);
98 	if (s == -1)
99 		return 0;
100 
101 	rv = ioctl(s, SIOCGBTINFO, &btr);
102 	close(s);
103 
104 	if (rv == -1)
105 		return 0;
106 
107 	if ((btr.btr_flags & BTF_UP) == 0) {
108 		errno = ENXIO;
109 		return 0;
110 	}
111 
112 	bdaddr_copy(addr, &btr.btr_bdaddr);
113 	return 1;
114 }
115 
116 int
117 bt_devname(char *name, const bdaddr_t *bdaddr)
118 {
119 	struct btreq btr;
120 	int s, rv;
121 
122 	if (bdaddr == NULL) {
123 		errno = EINVAL;
124 		return 0;
125 	}
126 
127 	memset(&btr, 0, sizeof(btr));
128 	bdaddr_copy(&btr.btr_bdaddr, bdaddr);
129 
130 	s = socket(PF_BLUETOOTH, SOCK_RAW, BTPROTO_HCI);
131 	if (s == -1)
132 		return 0;
133 
134 	rv = ioctl(s, SIOCGBTINFOA, &btr);
135 	close(s);
136 
137 	if (rv == -1)
138 		return 0;
139 
140 	if ((btr.btr_flags & BTF_UP) == 0) {
141 		errno = ENXIO;
142 		return 0;
143 	}
144 
145 	if (name != NULL)
146 		strlcpy(name, btr.btr_name, HCI_DEVNAME_SIZE);
147 
148 	return 1;
149 }
150 
151 int
152 bt_devopen(const char *name, int options)
153 {
154 	struct sockaddr_bt	sa;
155 	int			opt, s;
156 
157 	memset(&sa, 0, sizeof(sa));
158 	sa.bt_len = sizeof(sa);
159 	sa.bt_family = AF_BLUETOOTH;
160 
161 	if (name != NULL && !bt_devaddr(name, &sa.bt_bdaddr))
162 		return -1;
163 
164 	s = socket(PF_BLUETOOTH, SOCK_RAW, BTPROTO_HCI);
165 	if (s == -1)
166 		return -1;
167 
168 	opt = 1;
169 
170 	if ((options & BTOPT_DIRECTION) && setsockopt(s, BTPROTO_HCI,
171 	    SO_HCI_DIRECTION, &opt, sizeof(opt)) == -1) {
172 		close(s);
173 		return -1;
174 	}
175 
176 	if ((options & BTOPT_TIMESTAMP) && setsockopt(s, SOL_SOCKET,
177 	    SO_TIMESTAMP, &opt, sizeof(opt)) == -1) {
178 		close(s);
179 		return -1;
180 	}
181 
182 	if (bind(s, (struct sockaddr *)&sa, sizeof(sa)) == -1) {
183 		close(s);
184 		return -1;
185 	}
186 
187 	if (name != NULL
188 	    && connect(s, (struct sockaddr *)&sa, sizeof(sa)) == -1) {
189 		close(s);
190 		return -1;
191 	}
192 
193 	return s;
194 }
195 
196 ssize_t
197 bt_devsend(int s, uint16_t opcode, void *param, size_t plen)
198 {
199 	hci_cmd_hdr_t	hdr;
200 	struct iovec	iov[2];
201 	ssize_t		n;
202 
203 	if (plen > UINT8_MAX
204 	    || (plen == 0 && param != NULL)
205 	    || (plen != 0 && param == NULL)) {
206 		errno = EINVAL;
207 		return -1;
208 	}
209 
210 	hdr.type = HCI_CMD_PKT;
211 	hdr.opcode = htole16(opcode);
212 	hdr.length = (uint8_t)plen;
213 
214 	iov[0].iov_base = &hdr;
215 	iov[0].iov_len = sizeof(hdr);
216 
217 	iov[1].iov_base = param;
218 	iov[1].iov_len = plen;
219 
220 	while ((n = writev(s, iov, __arraycount(iov))) == -1) {
221 		if (errno == EINTR)
222 			continue;
223 
224 		return -1;
225 	}
226 
227 	return n;
228 }
229 
230 ssize_t
231 bt_devrecv(int s, void *buf, size_t size, time_t to)
232 {
233 	struct kevent	ev;
234 	struct timespec ts;
235 	uint8_t		*p;
236 	ssize_t		n;
237 	int		kq;
238 
239 	if (buf == NULL || size == 0) {
240 		errno = EINVAL;
241 		return -1;
242 	}
243 
244 	if (to >= 0) {	/* timeout is optional */
245 		kq = kqueue();
246 		if (kq == -1)
247 			return -1;
248 
249 		EV_SET(&ev, s, EVFILT_READ, EV_ADD, 0, 0, 0);
250 
251 		ts.tv_sec = to;
252 		ts.tv_nsec = 0;
253 
254 		while (kevent(kq, &ev, 1, &ev, 1, &ts) == -1) {
255 			if (errno == EINTR)
256 				continue;
257 
258 			close(kq);
259 			return -1;
260 		}
261 
262 		close(kq);
263 
264 		if (ev.data == 0) {
265 			errno = ETIMEDOUT;
266 			return -1;
267 		}
268 	}
269 
270 	while ((n = recv(s, buf, size, 0)) == -1) {
271 		if (errno == EINTR)
272 			continue;
273 
274 		return -1;
275 	}
276 
277 	if (n == 0)
278 		return 0;
279 
280 	p = buf;
281 	switch (p[0]) {	/* validate that they get complete packets */
282 	case HCI_CMD_PKT:
283 		if (sizeof(hci_cmd_hdr_t) > (size_t)n
284 		    || sizeof(hci_cmd_hdr_t) + p[3] != (size_t)n)
285 			break;
286 
287 		return n;
288 
289 	case HCI_ACL_DATA_PKT:
290 		if (sizeof(hci_acldata_hdr_t) > (size_t)n
291 		    || sizeof(hci_acldata_hdr_t) + le16dec(p + 3) != (size_t)n)
292 			break;
293 
294 		return n;
295 
296 	case HCI_SCO_DATA_PKT:
297 		if (sizeof(hci_scodata_hdr_t) > (size_t)n
298 		    || sizeof(hci_scodata_hdr_t) + p[3] != (size_t)n)
299 			break;
300 
301 		return n;
302 
303 	case HCI_EVENT_PKT:
304 		if (sizeof(hci_event_hdr_t) > (size_t)n
305 		    || sizeof(hci_event_hdr_t) + p[2] != (size_t)n)
306 			break;
307 
308 		return n;
309 
310 	default:
311 		break;
312 	}
313 
314 	errno = EIO;
315 	return -1;
316 }
317 
318 /*
319  * Internal handler for bt_devreq(), do the actual request.
320  */
321 static int
322 bt__devreq(int s, struct bt_devreq *req, time_t t_end)
323 {
324 	uint8_t			buf[HCI_EVENT_PKT_SIZE], *p;
325 	hci_event_hdr_t		ev;
326 	hci_command_status_ep	cs;
327 	hci_command_compl_ep	cc;
328 	time_t			to;
329 	ssize_t			n;
330 
331 	n = bt_devsend(s, req->opcode, req->cparam, req->clen);
332 	if (n == -1)
333 		return errno;
334 
335 	for (;;) {
336 		to = t_end - time(NULL);
337 		if (to < 0)
338 			return ETIMEDOUT;
339 
340 		p = buf;
341 		n = bt_devrecv(s, buf, sizeof(buf), to);
342 		if (n == -1)
343 			return errno;
344 
345 		if (sizeof(ev) > (size_t)n || p[0] != HCI_EVENT_PKT)
346 			return EIO;
347 
348 		memcpy(&ev, p, sizeof(ev));
349 		p += sizeof(ev);
350 		n -= sizeof(ev);
351 
352 		if (ev.event == req->event)
353 			break;
354 
355 		if (ev.event == HCI_EVENT_COMMAND_STATUS) {
356 			if (sizeof(cs) > (size_t)n)
357 				return EIO;
358 
359 			memcpy(&cs, p, sizeof(cs));
360 			p += sizeof(cs);
361 			n -= sizeof(cs);
362 
363 			if (le16toh(cs.opcode) == req->opcode) {
364 				if (cs.status != 0)
365 					return EIO;
366 
367 				if (req->event == 0)
368 					break;
369 			}
370 
371 			continue;
372 		}
373 
374 		if (ev.event == HCI_EVENT_COMMAND_COMPL) {
375 			if (sizeof(cc) > (size_t)n)
376 				return EIO;
377 
378 			memcpy(&cc, p, sizeof(cc));
379 			p += sizeof(cc);
380 			n -= sizeof(cc);
381 
382 			if (le16toh(cc.opcode) == req->opcode)
383 				break;
384 
385 			continue;
386 		}
387 	}
388 
389 	/* copy out response data */
390 	if (req->rlen >= (size_t)n) {
391 		req->rlen = n;
392 		memcpy(req->rparam, p, req->rlen);
393 	} else if (req->rlen > 0)
394 		return EIO;
395 
396 	return 0;
397 }
398 
399 int
400 bt_devreq(int s, struct bt_devreq *req, time_t to)
401 {
402 	struct bt_devfilter	new, old;
403 	int			error;
404 
405 	if (req == NULL || to < 0
406 	    || (req->rlen == 0 && req->rparam != NULL)
407 	    || (req->rlen != 0 && req->rparam == NULL)) {
408 		errno = EINVAL;
409 		return -1;
410 	}
411 
412 	memset(&new, 0, sizeof(new));
413 	bt_devfilter_pkt_set(&new, HCI_EVENT_PKT);
414 	bt_devfilter_evt_set(&new, HCI_EVENT_COMMAND_COMPL);
415 	bt_devfilter_evt_set(&new, HCI_EVENT_COMMAND_STATUS);
416 
417 	if (req->event != 0)
418 		bt_devfilter_evt_set(&new, req->event);
419 
420 	if (bt_devfilter(s, &new, &old) == -1)
421 		return -1;
422 
423 	error = bt__devreq(s, req, to + time(NULL));
424 
425 	(void)bt_devfilter(s, &old, NULL);
426 
427 	if (error != 0) {
428 		errno = error;
429 		return -1;
430 	}
431 
432 	return 0;
433 }
434 
435 int
436 bt_devfilter(int s, const struct bt_devfilter *new, struct bt_devfilter *old)
437 {
438 	socklen_t	len;
439 
440 	if (new == NULL && old == NULL) {
441 		errno = EINVAL;
442 		return -1;
443 	}
444 
445 	len = sizeof(struct hci_filter);
446 
447 	if (old != NULL) {
448 		if (getsockopt(s, BTPROTO_HCI,
449 		    SO_HCI_PKT_FILTER, &old->packet_mask, &len) == -1
450 		    || len != sizeof(struct hci_filter))
451 			return -1;
452 
453 		if (getsockopt(s, BTPROTO_HCI,
454 		    SO_HCI_EVT_FILTER, &old->event_mask, &len) == -1
455 		    || len != sizeof(struct hci_filter))
456 			return -1;
457 	}
458 
459 	if (new != NULL) {
460 		if (setsockopt(s, BTPROTO_HCI,
461 		    SO_HCI_PKT_FILTER, &new->packet_mask, len) == -1)
462 			return -1;
463 
464 		if (setsockopt(s, BTPROTO_HCI,
465 		    SO_HCI_EVT_FILTER, &new->event_mask, len) == -1)
466 			return -1;
467 	}
468 
469 	return 0;
470 }
471 
472 void
473 bt_devfilter_pkt_set(struct bt_devfilter *filter, uint8_t type)
474 {
475 
476 	hci_filter_set(type, &filter->packet_mask);
477 }
478 
479 void
480 bt_devfilter_pkt_clr(struct bt_devfilter *filter, uint8_t type)
481 {
482 
483 	hci_filter_clr(type, &filter->packet_mask);
484 }
485 
486 int
487 bt_devfilter_pkt_tst(const struct bt_devfilter *filter, uint8_t type)
488 {
489 
490 	return hci_filter_test(type, &filter->packet_mask);
491 }
492 
493 void
494 bt_devfilter_evt_set(struct bt_devfilter *filter, uint8_t event)
495 {
496 
497 	hci_filter_set(event, &filter->event_mask);
498 }
499 
500 void
501 bt_devfilter_evt_clr(struct bt_devfilter *filter, uint8_t event)
502 {
503 
504 	hci_filter_clr(event, &filter->event_mask);
505 }
506 
507 int
508 bt_devfilter_evt_tst(const struct bt_devfilter *filter, uint8_t event)
509 {
510 
511 	return hci_filter_test(event, &filter->event_mask);
512 }
513 
514 /*
515  * Internal function used by bt_devinquiry to find the first
516  * active device.
517  */
518 static int
519 bt__devany_cb(int s, const struct bt_devinfo *info, void *arg)
520 {
521 
522 	if ((info->enabled)) {
523 		strlcpy(arg, info->devname, HCI_DEVNAME_SIZE + 1);
524 		return 1;
525 	}
526 
527 	return 0;
528 }
529 
530 /*
531  * Internal function used by bt_devinquiry to insert inquiry
532  * results to an array. Make sure that a bdaddr only appears
533  * once in the list and always use the latest result.
534  */
535 static void
536 bt__devresult(struct bt_devinquiry *ii, int *count, int max_count,
537     bdaddr_t *ba, uint8_t psrm, uint8_t pspm, uint8_t *cl, uint16_t co,
538     int8_t rssi, uint8_t *data)
539 {
540 	int	n;
541 
542 	for (n = 0; ; n++, ii++) {
543 		if (n == *count) {
544 			if (*count == max_count)
545 				return;
546 
547 			(*count)++;
548 			break;
549 		}
550 
551 		if (bdaddr_same(&ii->bdaddr, ba))
552 			break;
553 	}
554 
555 	bdaddr_copy(&ii->bdaddr, ba);
556 	ii->pscan_rep_mode = psrm;
557 	ii->pscan_period_mode = pspm;
558 	ii->clock_offset = le16toh(co);
559 	ii->rssi = rssi;
560 
561 	if (cl != NULL)
562 		memcpy(ii->dev_class, cl, HCI_CLASS_SIZE);
563 
564 	if (data != NULL)
565 		memcpy(ii->data, data, 240);
566 }
567 
568 int
569 bt_devinquiry(const char *name, time_t to, int max_rsp,
570     struct bt_devinquiry **iip)
571 {
572 	uint8_t			buf[HCI_EVENT_PKT_SIZE], *p;
573 	struct bt_devfilter	f;
574 	hci_event_hdr_t		ev;
575 	hci_command_status_ep	sp;
576 	hci_inquiry_cp		cp;
577 	hci_inquiry_result_ep	ip;
578 	hci_inquiry_response	ir;
579 	hci_rssi_result_ep	rp;
580 	hci_rssi_response	rr;
581 	hci_extended_result_ep	ep;
582 	struct bt_devinquiry	*ii;
583 	int			count, i, s;
584 	time_t			t_end;
585 	ssize_t			n;
586 
587 	if (iip == NULL) {
588 		errno = EINVAL;
589 		return -1;
590 	}
591 
592 	if (name == NULL) {
593 		if (bt_devenum(bt__devany_cb, buf) == -1)
594 			return -1;
595 
596 		name = (const char *)buf;
597 	}
598 
599 	s = bt_devopen(name, 0);
600 	if (s == -1)
601 		return -1;
602 
603 	memset(&f, 0, sizeof(f));
604 	bt_devfilter_pkt_set(&f, HCI_EVENT_PKT);
605 	bt_devfilter_evt_set(&f, HCI_EVENT_COMMAND_STATUS);
606 	bt_devfilter_evt_set(&f, HCI_EVENT_INQUIRY_COMPL);
607 	bt_devfilter_evt_set(&f, HCI_EVENT_INQUIRY_RESULT);
608 	bt_devfilter_evt_set(&f, HCI_EVENT_RSSI_RESULT);
609 	bt_devfilter_evt_set(&f, HCI_EVENT_EXTENDED_RESULT);
610 	if (bt_devfilter(s, &f, NULL) == -1) {
611 		close(s);
612 		return -1;
613 	}
614 
615 	/*
616 	 * silently adjust number of reponses to fit in uint8_t
617 	 */
618 	if (max_rsp < 1)
619 		max_rsp = 8;
620 	else if (max_rsp > UINT8_MAX)
621 		max_rsp = UINT8_MAX;
622 
623 	ii = calloc((size_t)max_rsp, sizeof(struct bt_devinquiry));
624 	if (ii == NULL) {
625 		close(s);
626 		return -1;
627 	}
628 
629 	/*
630 	 * silently adjust timeout value so that inquiry_length
631 	 * falls into the range 0x01->0x30 (unit is 1.28 seconds)
632 	 */
633 	if (to < 1)
634 		to = 5;
635 	else if (to == 1)
636 		to = 2;
637 	else if (to > 62)
638 		to = 62;
639 
640 	/* General Inquiry LAP is 0x9e8b33 */
641 	cp.lap[0] = 0x33;
642 	cp.lap[1] = 0x8b;
643 	cp.lap[2] = 0x9e;
644 	cp.inquiry_length = (uint8_t)(to * 100 / 128);
645 	cp.num_responses = (uint8_t)max_rsp;
646 
647 	if (bt_devsend(s, HCI_CMD_INQUIRY, &cp, sizeof(cp)) == -1)
648 		goto fail;
649 
650 	count = 0;
651 
652 	for (t_end = time(NULL) + to + 1; to > 0; to = t_end - time(NULL)) {
653 		p = buf;
654 		n = bt_devrecv(s, buf, sizeof(buf), to);
655 		if (n == -1)
656 			goto fail;
657 
658 		if (sizeof(ev) > (size_t)n) {
659 			errno = EIO;
660 			goto fail;
661 		}
662 
663 		memcpy(&ev, p, sizeof(ev));
664 		p += sizeof(ev);
665 		n -= sizeof(ev);
666 
667 		switch (ev.event) {
668 		case HCI_EVENT_COMMAND_STATUS:
669 			if (sizeof(sp) > (size_t)n)
670 				break;
671 
672 			memcpy(&sp, p, sizeof(sp));
673 
674 			if (le16toh(sp.opcode) != HCI_CMD_INQUIRY
675 			    || sp.status == 0)
676 				break;
677 
678 			errno = EIO;
679 			goto fail;
680 
681 		case HCI_EVENT_INQUIRY_COMPL:
682 			close(s);
683 			*iip = ii;
684 			return count;
685 
686 		case HCI_EVENT_INQUIRY_RESULT:
687 			if (sizeof(ip) > (size_t)n)
688 				break;
689 
690 			memcpy(&ip, p, sizeof(ip));
691 			p += sizeof(ip);
692 			n -= sizeof(ip);
693 
694 			if (sizeof(ir) * ip.num_responses != (size_t)n)
695 				break;
696 
697 			for (i = 0; i < ip.num_responses; i++) {
698 				memcpy(&ir, p, sizeof(ir));
699 				p += sizeof(ir);
700 
701 				bt__devresult(ii, &count, max_rsp,
702 					&ir.bdaddr,
703 					ir.page_scan_rep_mode,
704 					ir.page_scan_period_mode,
705 					ir.uclass,
706 					ir.clock_offset,
707 					0,		/* rssi */
708 					NULL);		/* extended data */
709 			}
710 
711 			break;
712 
713 		case HCI_EVENT_RSSI_RESULT:
714 			if (sizeof(rp) > (size_t)n)
715 				break;
716 
717 			memcpy(&rp, p, sizeof(rp));
718 			p += sizeof(rp);
719 			n -= sizeof(rp);
720 
721 			if (sizeof(rr) * rp.num_responses != (size_t)n)
722 				break;
723 
724 			for (i = 0; i < rp.num_responses; i++) {
725 				memcpy(&rr, p, sizeof(rr));
726 				p += sizeof(rr);
727 
728 				bt__devresult(ii, &count, max_rsp,
729 					&rr.bdaddr,
730 					rr.page_scan_rep_mode,
731 					0,	/* page scan period mode */
732 					rr.uclass,
733 					rr.clock_offset,
734 					rr.rssi,
735 					NULL);		/* extended data */
736 			}
737 
738 			break;
739 
740 		case HCI_EVENT_EXTENDED_RESULT:
741 			if (sizeof(ep) != (size_t)n)
742 				break;
743 
744 			memcpy(&ep, p, sizeof(ep));
745 
746 			if (ep.num_responses != 1)
747 				break;
748 
749 			bt__devresult(ii, &count, max_rsp,
750 				&ep.bdaddr,
751 				ep.page_scan_rep_mode,
752 				0,	/* page scan period mode */
753 				ep.uclass,
754 				ep.clock_offset,
755 				ep.rssi,
756 				ep.response);
757 
758 			break;
759 
760 		default:
761 			break;
762 		}
763 	}
764 
765 	errno = ETIMEDOUT;
766 
767 fail:
768 	free(ii);
769 	close(s);
770 	return -1;
771 }
772 
773 /*
774  * Internal version of bt_devinfo. Fill in the devinfo structure
775  * with the socket handle provided. If the device is present and
776  * active, the socket will be left connected to the device.
777  */
778 static int
779 bt__devinfo(int s, const char *name, struct bt_devinfo *info)
780 {
781 	struct sockaddr_bt		sa;
782 	struct bt_devreq		req;
783 	struct btreq			btr;
784 	hci_read_buffer_size_rp		bp;
785 	hci_read_local_features_rp	fp;
786 
787 	memset(&btr, 0, sizeof(btr));
788 	strncpy(btr.btr_name, name, HCI_DEVNAME_SIZE);
789 
790 	if (ioctl(s, SIOCGBTINFO, &btr) == -1)
791 		return -1;
792 
793 	memset(info, 0, sizeof(struct bt_devinfo));
794 	memcpy(info->devname, btr.btr_name, HCI_DEVNAME_SIZE);
795 	bdaddr_copy(&info->bdaddr, &btr.btr_bdaddr);
796 	info->enabled = ((btr.btr_flags & BTF_UP) ? 1 : 0);
797 
798 	info->sco_size = btr.btr_sco_mtu;
799 	info->acl_size = btr.btr_acl_mtu;
800 	info->cmd_free = btr.btr_num_cmd;
801 	info->sco_free = btr.btr_num_sco;
802 	info->acl_free = btr.btr_num_acl;
803 
804 	info->link_policy_info = btr.btr_link_policy;
805 	info->packet_type_info = btr.btr_packet_type;
806 
807 	if (ioctl(s, SIOCGBTSTATS, &btr) == -1)
808 		return -1;
809 
810 	info->cmd_sent = btr.btr_stats.cmd_tx;
811 	info->evnt_recv = btr.btr_stats.evt_rx;
812 	info->acl_recv = btr.btr_stats.acl_rx;
813 	info->acl_sent = btr.btr_stats.acl_tx;
814 	info->sco_recv = btr.btr_stats.sco_rx;
815 	info->sco_sent = btr.btr_stats.sco_tx;
816 	info->bytes_recv = btr.btr_stats.byte_rx;
817 	info->bytes_sent = btr.btr_stats.byte_tx;
818 
819 	/* can only get the rest from enabled devices */
820 	if ((info->enabled) == 0)
821 		return 0;
822 
823 	memset(&sa, 0, sizeof(sa));
824 	sa.bt_len = sizeof(sa);
825 	sa.bt_family = AF_BLUETOOTH;
826 	bdaddr_copy(&sa.bt_bdaddr, &info->bdaddr);
827 
828 	if (bind(s, (struct sockaddr *)&sa, sizeof(sa)) == -1
829 	    || connect(s, (struct sockaddr *)&sa, sizeof(sa)) == -1)
830 		return -1;
831 
832 	memset(&req, 0, sizeof(req));
833 	req.opcode = HCI_CMD_READ_BUFFER_SIZE;
834 	req.rparam = &bp;
835 	req.rlen = sizeof(bp);
836 
837 	if (bt_devreq(s, &req, 5) == -1)
838 		return -1;
839 
840 	info->acl_pkts = bp.max_acl_size;
841 	info->sco_pkts = bp.max_sco_size;
842 
843 	memset(&req, 0, sizeof(req));
844 	req.opcode = HCI_CMD_READ_LOCAL_FEATURES;
845 	req.rparam = &fp;
846 	req.rlen = sizeof(fp);
847 
848 	if (bt_devreq(s, &req, 5) == -1)
849 		return -1;
850 
851 	memcpy(info->features, fp.features, HCI_FEATURES_SIZE);
852 
853 	return 0;
854 }
855 
856 int
857 bt_devinfo(const char *name, struct bt_devinfo *info)
858 {
859 	int	rv, s;
860 
861 	if (name == NULL || info == NULL) {
862 		errno = EINVAL;
863 		return -1;
864 	}
865 
866 	s = socket(PF_BLUETOOTH, SOCK_RAW, BTPROTO_HCI);
867 	if (s == -1)
868 		return -1;
869 
870 	rv = bt__devinfo(s, name, info);
871 	close(s);
872 	return rv;
873 }
874 
875 int
876 bt_devenum(bt_devenum_cb_t cb, void *arg)
877 {
878 	struct btreq		btr;
879 	struct bt_devinfo	info;
880 	int			count, fd, rv, s;
881 
882 	s = socket(PF_BLUETOOTH, SOCK_RAW, BTPROTO_HCI);
883 	if (s == -1)
884 		return -1;
885 
886 	memset(&btr, 0, sizeof(btr));
887 	count = 0;
888 
889 	while (ioctl(s, SIOCNBTINFO, &btr) != -1) {
890 		count++;
891 
892 		if (cb == NULL)
893 			continue;
894 
895 		fd = socket(PF_BLUETOOTH, SOCK_RAW, BTPROTO_HCI);
896 		if (fd == -1) {
897 			close(s);
898 			return -1;
899 		}
900 
901 		if (bt__devinfo(fd, btr.btr_name, &info) == -1) {
902 			close(fd);
903 			close(s);
904 			return -1;
905 		}
906 
907 		rv = (*cb)(fd, &info, arg);
908 		close(fd);
909 		if (rv != 0)
910 			break;
911 	}
912 
913 	close(s);
914 	return count;
915 }
916