xref: /freebsd/sys/netinet/sctp_sysctl.c (revision 8f5f6680efa28135bf37f3def2aa71f35bd30333)
1 /*-
2  * SPDX-License-Identifier: BSD-3-Clause
3  *
4  * Copyright (c) 2007, by Cisco Systems, Inc. All rights reserved.
5  * Copyright (c) 2008-2012, by Randall Stewart. All rights reserved.
6  * Copyright (c) 2008-2012, by Michael Tuexen. All rights reserved.
7  *
8  * Redistribution and use in source and binary forms, with or without
9  * modification, are permitted provided that the following conditions are met:
10  *
11  * a) Redistributions of source code must retain the above copyright notice,
12  *    this list of conditions and the following disclaimer.
13  *
14  * b) Redistributions in binary form must reproduce the above copyright
15  *    notice, this list of conditions and the following disclaimer in
16  *    the documentation and/or other materials provided with the distribution.
17  *
18  * c) Neither the name of Cisco Systems, Inc. nor the names of its
19  *    contributors may be used to endorse or promote products derived
20  *    from this software without specific prior written permission.
21  *
22  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
23  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
24  * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25  * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
26  * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
27  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
28  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
29  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
30  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
31  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
32  * THE POSSIBILITY OF SUCH DAMAGE.
33  */
34 
35 #include <netinet/sctp_os.h>
36 #include <netinet/sctp.h>
37 #include <netinet/sctp_constants.h>
38 #include <netinet/sctp_sysctl.h>
39 #include <netinet/sctp_pcb.h>
40 #include <netinet/sctputil.h>
41 #include <netinet/sctp_output.h>
42 #include <sys/smp.h>
43 #include <sys/sysctl.h>
44 
45 FEATURE(sctp, "Stream Control Transmission Protocol");
46 
47 /*
48  * sysctl tunable variables
49  */
50 
51 void
sctp_init_sysctls(void)52 sctp_init_sysctls(void)
53 {
54 	SCTP_BASE_SYSCTL(sctp_sendspace) = SCTPCTL_MAXDGRAM_DEFAULT;
55 	SCTP_BASE_SYSCTL(sctp_recvspace) = SCTPCTL_RECVSPACE_DEFAULT;
56 	SCTP_BASE_SYSCTL(sctp_auto_asconf) = SCTPCTL_AUTOASCONF_DEFAULT;
57 	SCTP_BASE_SYSCTL(sctp_multiple_asconfs) = SCTPCTL_MULTIPLEASCONFS_DEFAULT;
58 	SCTP_BASE_SYSCTL(sctp_ecn_enable) = SCTPCTL_ECN_ENABLE_DEFAULT;
59 	SCTP_BASE_SYSCTL(sctp_pr_enable) = SCTPCTL_PR_ENABLE_DEFAULT;
60 	SCTP_BASE_SYSCTL(sctp_auth_enable) = SCTPCTL_AUTH_ENABLE_DEFAULT;
61 	SCTP_BASE_SYSCTL(sctp_asconf_enable) = SCTPCTL_ASCONF_ENABLE_DEFAULT;
62 	SCTP_BASE_SYSCTL(sctp_reconfig_enable) = SCTPCTL_RECONFIG_ENABLE_DEFAULT;
63 	SCTP_BASE_SYSCTL(sctp_nrsack_enable) = SCTPCTL_NRSACK_ENABLE_DEFAULT;
64 	SCTP_BASE_SYSCTL(sctp_pktdrop_enable) = SCTPCTL_PKTDROP_ENABLE_DEFAULT;
65 	SCTP_BASE_SYSCTL(sctp_peer_chunk_oh) = SCTPCTL_PEER_CHKOH_DEFAULT;
66 	SCTP_BASE_SYSCTL(sctp_max_burst_default) = SCTPCTL_MAXBURST_DEFAULT;
67 	SCTP_BASE_SYSCTL(sctp_fr_max_burst_default) = SCTPCTL_FRMAXBURST_DEFAULT;
68 	SCTP_BASE_SYSCTL(sctp_max_chunks_on_queue) = SCTPCTL_MAXCHUNKS_DEFAULT;
69 	SCTP_BASE_SYSCTL(sctp_hashtblsize) = SCTPCTL_TCBHASHSIZE_DEFAULT;
70 	SCTP_BASE_SYSCTL(sctp_pcbtblsize) = SCTPCTL_PCBHASHSIZE_DEFAULT;
71 	SCTP_BASE_SYSCTL(sctp_min_split_point) = SCTPCTL_MIN_SPLIT_POINT_DEFAULT;
72 	SCTP_BASE_SYSCTL(sctp_chunkscale) = SCTPCTL_CHUNKSCALE_DEFAULT;
73 	SCTP_BASE_SYSCTL(sctp_delayed_sack_time_default) = SCTPCTL_DELAYED_SACK_TIME_DEFAULT;
74 	SCTP_BASE_SYSCTL(sctp_sack_freq_default) = SCTPCTL_SACK_FREQ_DEFAULT;
75 	SCTP_BASE_SYSCTL(sctp_system_free_resc_limit) = SCTPCTL_SYS_RESOURCE_DEFAULT;
76 	SCTP_BASE_SYSCTL(sctp_asoc_free_resc_limit) = SCTPCTL_ASOC_RESOURCE_DEFAULT;
77 	SCTP_BASE_SYSCTL(sctp_heartbeat_interval_default) = SCTPCTL_HEARTBEAT_INTERVAL_DEFAULT;
78 	SCTP_BASE_SYSCTL(sctp_pmtu_raise_time_default) = SCTPCTL_PMTU_RAISE_TIME_DEFAULT;
79 	SCTP_BASE_SYSCTL(sctp_shutdown_guard_time_default) = SCTPCTL_SHUTDOWN_GUARD_TIME_DEFAULT;
80 	SCTP_BASE_SYSCTL(sctp_secret_lifetime_default) = SCTPCTL_SECRET_LIFETIME_DEFAULT;
81 	SCTP_BASE_SYSCTL(sctp_rto_max_default) = SCTPCTL_RTO_MAX_DEFAULT;
82 	SCTP_BASE_SYSCTL(sctp_rto_min_default) = SCTPCTL_RTO_MIN_DEFAULT;
83 	SCTP_BASE_SYSCTL(sctp_rto_initial_default) = SCTPCTL_RTO_INITIAL_DEFAULT;
84 	SCTP_BASE_SYSCTL(sctp_init_rto_max_default) = SCTPCTL_INIT_RTO_MAX_DEFAULT;
85 	SCTP_BASE_SYSCTL(sctp_valid_cookie_life_default) = SCTPCTL_VALID_COOKIE_LIFE_DEFAULT;
86 	SCTP_BASE_SYSCTL(sctp_init_rtx_max_default) = SCTPCTL_INIT_RTX_MAX_DEFAULT;
87 	SCTP_BASE_SYSCTL(sctp_assoc_rtx_max_default) = SCTPCTL_ASSOC_RTX_MAX_DEFAULT;
88 	SCTP_BASE_SYSCTL(sctp_path_rtx_max_default) = SCTPCTL_PATH_RTX_MAX_DEFAULT;
89 	SCTP_BASE_SYSCTL(sctp_path_pf_threshold) = SCTPCTL_PATH_PF_THRESHOLD_DEFAULT;
90 	SCTP_BASE_SYSCTL(sctp_add_more_threshold) = SCTPCTL_ADD_MORE_ON_OUTPUT_DEFAULT;
91 	SCTP_BASE_SYSCTL(sctp_nr_incoming_streams_default) = SCTPCTL_INCOMING_STREAMS_DEFAULT;
92 	SCTP_BASE_SYSCTL(sctp_nr_outgoing_streams_default) = SCTPCTL_OUTGOING_STREAMS_DEFAULT;
93 	SCTP_BASE_SYSCTL(sctp_cmt_on_off) = SCTPCTL_CMT_ON_OFF_DEFAULT;
94 	SCTP_BASE_SYSCTL(sctp_cmt_use_dac) = SCTPCTL_CMT_USE_DAC_DEFAULT;
95 	SCTP_BASE_SYSCTL(sctp_use_cwnd_based_maxburst) = SCTPCTL_CWND_MAXBURST_DEFAULT;
96 	SCTP_BASE_SYSCTL(sctp_nat_friendly) = SCTPCTL_NAT_FRIENDLY_DEFAULT;
97 	SCTP_BASE_SYSCTL(sctp_L2_abc_variable) = SCTPCTL_ABC_L_VAR_DEFAULT;
98 	SCTP_BASE_SYSCTL(sctp_mbuf_threshold_count) = SCTPCTL_MAX_CHAINED_MBUFS_DEFAULT;
99 	SCTP_BASE_SYSCTL(sctp_do_drain) = SCTPCTL_DO_SCTP_DRAIN_DEFAULT;
100 	SCTP_BASE_SYSCTL(sctp_hb_maxburst) = SCTPCTL_HB_MAX_BURST_DEFAULT;
101 	SCTP_BASE_SYSCTL(sctp_abort_if_one_2_one_hits_limit) = SCTPCTL_ABORT_AT_LIMIT_DEFAULT;
102 	SCTP_BASE_SYSCTL(sctp_min_residual) = SCTPCTL_MIN_RESIDUAL_DEFAULT;
103 	SCTP_BASE_SYSCTL(sctp_max_retran_chunk) = SCTPCTL_MAX_RETRAN_CHUNK_DEFAULT;
104 	SCTP_BASE_SYSCTL(sctp_logging_level) = SCTPCTL_LOGGING_LEVEL_DEFAULT;
105 	SCTP_BASE_SYSCTL(sctp_default_cc_module) = SCTPCTL_DEFAULT_CC_MODULE_DEFAULT;
106 	SCTP_BASE_SYSCTL(sctp_default_ss_module) = SCTPCTL_DEFAULT_SS_MODULE_DEFAULT;
107 	SCTP_BASE_SYSCTL(sctp_default_frag_interleave) = SCTPCTL_DEFAULT_FRAG_INTERLEAVE_DEFAULT;
108 	SCTP_BASE_SYSCTL(sctp_mobility_base) = SCTPCTL_MOBILITY_BASE_DEFAULT;
109 	SCTP_BASE_SYSCTL(sctp_mobility_fasthandoff) = SCTPCTL_MOBILITY_FASTHANDOFF_DEFAULT;
110 	SCTP_BASE_SYSCTL(sctp_vtag_time_wait) = SCTPCTL_TIME_WAIT_DEFAULT;
111 	SCTP_BASE_SYSCTL(sctp_buffer_splitting) = SCTPCTL_BUFFER_SPLITTING_DEFAULT;
112 	SCTP_BASE_SYSCTL(sctp_initial_cwnd) = SCTPCTL_INITIAL_CWND_DEFAULT;
113 	SCTP_BASE_SYSCTL(sctp_rttvar_bw) = SCTPCTL_RTTVAR_BW_DEFAULT;
114 	SCTP_BASE_SYSCTL(sctp_rttvar_rtt) = SCTPCTL_RTTVAR_RTT_DEFAULT;
115 	SCTP_BASE_SYSCTL(sctp_rttvar_eqret) = SCTPCTL_RTTVAR_EQRET_DEFAULT;
116 	SCTP_BASE_SYSCTL(sctp_steady_step) = SCTPCTL_RTTVAR_STEADYS_DEFAULT;
117 	SCTP_BASE_SYSCTL(sctp_use_dccc_ecn) = SCTPCTL_RTTVAR_DCCCECN_DEFAULT;
118 	SCTP_BASE_SYSCTL(sctp_blackhole) = SCTPCTL_BLACKHOLE_DEFAULT;
119 	SCTP_BASE_SYSCTL(sctp_sendall_limit) = SCTPCTL_SENDALL_LIMIT_DEFAULT;
120 	SCTP_BASE_SYSCTL(sctp_diag_info_code) = SCTPCTL_DIAG_INFO_CODE_DEFAULT;
121 	SCTP_BASE_SYSCTL(sctp_ootb_with_zero_cksum) = SCTPCTL_OOTB_WITH_ZERO_CKSUM_DEFAULT;
122 #if defined(SCTP_LOCAL_TRACE_BUF)
123 	memset(&SCTP_BASE_SYSCTL(sctp_log), 0, sizeof(struct sctp_log));
124 #endif
125 	SCTP_BASE_SYSCTL(sctp_udp_tunneling_port) = SCTPCTL_UDP_TUNNELING_PORT_DEFAULT;
126 	SCTP_BASE_SYSCTL(sctp_enable_sack_immediately) = SCTPCTL_SACK_IMMEDIATELY_ENABLE_DEFAULT;
127 	SCTP_BASE_SYSCTL(sctp_inits_include_nat_friendly) = SCTPCTL_NAT_FRIENDLY_INITS_DEFAULT;
128 #if defined(SCTP_DEBUG)
129 	SCTP_BASE_SYSCTL(sctp_debug_on) = SCTPCTL_DEBUG_DEFAULT;
130 #endif
131 }
132 
133 /* It returns an upper limit. No filtering is done here */
134 static unsigned int
sctp_sysctl_number_of_addresses(struct sctp_inpcb * inp)135 sctp_sysctl_number_of_addresses(struct sctp_inpcb *inp)
136 {
137 	unsigned int cnt;
138 	struct sctp_vrf *vrf;
139 	struct sctp_ifn *sctp_ifn;
140 	struct sctp_ifa *sctp_ifa;
141 	struct sctp_laddr *laddr;
142 
143 	cnt = 0;
144 	/* neither Mac OS X nor FreeBSD support multiple routing functions */
145 	if ((vrf = sctp_find_vrf(inp->def_vrf_id)) == NULL) {
146 		return (0);
147 	}
148 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
149 		LIST_FOREACH(sctp_ifn, &vrf->ifnlist, next_ifn) {
150 			LIST_FOREACH(sctp_ifa, &sctp_ifn->ifalist, next_ifa) {
151 				switch (sctp_ifa->address.sa.sa_family) {
152 #ifdef INET
153 				case AF_INET:
154 #endif
155 #ifdef INET6
156 				case AF_INET6:
157 #endif
158 					cnt++;
159 					break;
160 				default:
161 					break;
162 				}
163 			}
164 		}
165 	} else {
166 		LIST_FOREACH(laddr, &inp->sctp_addr_list, sctp_nxt_addr) {
167 			switch (laddr->ifa->address.sa.sa_family) {
168 #ifdef INET
169 			case AF_INET:
170 #endif
171 #ifdef INET6
172 			case AF_INET6:
173 #endif
174 				cnt++;
175 				break;
176 			default:
177 				break;
178 			}
179 		}
180 	}
181 	return (cnt);
182 }
183 
184 static int
sctp_sysctl_copy_out_local_addresses(struct sctp_inpcb * inp,struct sctp_tcb * stcb,struct sysctl_req * req)185 sctp_sysctl_copy_out_local_addresses(struct sctp_inpcb *inp, struct sctp_tcb *stcb, struct sysctl_req *req)
186 {
187 	struct sctp_ifn *sctp_ifn;
188 	struct sctp_ifa *sctp_ifa;
189 	int loopback_scope;
190 #ifdef INET
191 	int ipv4_local_scope;
192 	int ipv4_addr_legal;
193 #endif
194 #ifdef INET6
195 	int local_scope, site_scope;
196 	int ipv6_addr_legal;
197 #endif
198 	struct sctp_vrf *vrf;
199 	struct xsctp_laddr xladdr;
200 	struct sctp_laddr *laddr;
201 	int error;
202 
203 	/* Turn on all the appropriate scope */
204 	if (stcb != NULL) {
205 		/* use association specific values */
206 		loopback_scope = stcb->asoc.scope.loopback_scope;
207 #ifdef INET
208 		ipv4_local_scope = stcb->asoc.scope.ipv4_local_scope;
209 		ipv4_addr_legal = stcb->asoc.scope.ipv4_addr_legal;
210 #endif
211 #ifdef INET6
212 		local_scope = stcb->asoc.scope.local_scope;
213 		site_scope = stcb->asoc.scope.site_scope;
214 		ipv6_addr_legal = stcb->asoc.scope.ipv6_addr_legal;
215 #endif
216 	} else {
217 		/* Use generic values for endpoints. */
218 		loopback_scope = 1;
219 #ifdef INET
220 		ipv4_local_scope = 1;
221 #endif
222 #ifdef INET6
223 		local_scope = 1;
224 		site_scope = 1;
225 #endif
226 		if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) {
227 #ifdef INET6
228 			ipv6_addr_legal = 1;
229 #endif
230 #ifdef INET
231 			if (SCTP_IPV6_V6ONLY(inp)) {
232 				ipv4_addr_legal = 0;
233 			} else {
234 				ipv4_addr_legal = 1;
235 			}
236 #endif
237 		} else {
238 #ifdef INET6
239 			ipv6_addr_legal = 0;
240 #endif
241 #ifdef INET
242 			ipv4_addr_legal = 1;
243 #endif
244 		}
245 	}
246 
247 	/* Neither Mac OS X nor FreeBSD support multiple routing functions. */
248 	if ((vrf = sctp_find_vrf(inp->def_vrf_id)) == NULL) {
249 		SCTP_INP_RUNLOCK(inp);
250 		SCTP_INP_INFO_RUNLOCK();
251 		return (ENOENT);
252 	}
253 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
254 		LIST_FOREACH(sctp_ifn, &vrf->ifnlist, next_ifn) {
255 			if ((loopback_scope == 0) && SCTP_IFN_IS_IFT_LOOP(sctp_ifn)) {
256 				/* Skip loopback if loopback_scope not set. */
257 				continue;
258 			}
259 			LIST_FOREACH(sctp_ifa, &sctp_ifn->ifalist, next_ifa) {
260 				if (stcb != NULL) {
261 					/*
262 					 * Ignore if blacklisted at
263 					 * association level.
264 					 */
265 					if (sctp_is_addr_restricted(stcb, sctp_ifa)) {
266 						continue;
267 					}
268 				} else {
269 					if (sctp_ifa->localifa_flags & SCTP_ADDR_IFA_UNUSEABLE) {
270 						continue;
271 					}
272 				}
273 				switch (sctp_ifa->address.sa.sa_family) {
274 #ifdef INET
275 				case AF_INET:
276 					if (ipv4_addr_legal) {
277 						struct sockaddr_in *sin;
278 
279 						sin = &sctp_ifa->address.sin;
280 						if (sin->sin_addr.s_addr == 0) {
281 							continue;
282 						}
283 						if (prison_check_ip4(inp->ip_inp.inp.inp_cred,
284 						    &sin->sin_addr) != 0) {
285 							continue;
286 						}
287 						if ((ipv4_local_scope == 0) && (IN4_ISPRIVATE_ADDRESS(&sin->sin_addr))) {
288 							continue;
289 						}
290 					} else {
291 						continue;
292 					}
293 					break;
294 #endif
295 #ifdef INET6
296 				case AF_INET6:
297 					if (ipv6_addr_legal) {
298 						struct sockaddr_in6 *sin6;
299 
300 						sin6 = &sctp_ifa->address.sin6;
301 						if (IN6_IS_ADDR_UNSPECIFIED(&sin6->sin6_addr)) {
302 							continue;
303 						}
304 						if (prison_check_ip6(inp->ip_inp.inp.inp_cred,
305 						    &sin6->sin6_addr) != 0) {
306 							continue;
307 						}
308 						if (IN6_IS_ADDR_LINKLOCAL(&sin6->sin6_addr)) {
309 							if (local_scope == 0) {
310 								continue;
311 							}
312 						}
313 						if ((site_scope == 0) && (IN6_IS_ADDR_SITELOCAL(&sin6->sin6_addr))) {
314 							continue;
315 						}
316 					} else {
317 						continue;
318 					}
319 					break;
320 #endif
321 				default:
322 					continue;
323 				}
324 				memset((void *)&xladdr, 0, sizeof(struct xsctp_laddr));
325 				memcpy((void *)&xladdr.address, (const void *)&sctp_ifa->address, sizeof(union sctp_sockstore));
326 				SCTP_INP_RUNLOCK(inp);
327 				SCTP_INP_INFO_RUNLOCK();
328 				error = SYSCTL_OUT(req, &xladdr, sizeof(struct xsctp_laddr));
329 				if (error != 0) {
330 					return (error);
331 				} else {
332 					SCTP_INP_INFO_RLOCK();
333 					SCTP_INP_RLOCK(inp);
334 				}
335 			}
336 		}
337 	} else {
338 		LIST_FOREACH(laddr, &inp->sctp_addr_list, sctp_nxt_addr) {
339 			/* ignore if blacklisted at association level */
340 			if (stcb != NULL && sctp_is_addr_restricted(stcb, laddr->ifa))
341 				continue;
342 			memset((void *)&xladdr, 0, sizeof(struct xsctp_laddr));
343 			memcpy((void *)&xladdr.address, (const void *)&laddr->ifa->address, sizeof(union sctp_sockstore));
344 			xladdr.start_time.tv_sec = (uint32_t)laddr->start_time.tv_sec;
345 			xladdr.start_time.tv_usec = (uint32_t)laddr->start_time.tv_usec;
346 			SCTP_INP_RUNLOCK(inp);
347 			SCTP_INP_INFO_RUNLOCK();
348 			error = SYSCTL_OUT(req, &xladdr, sizeof(struct xsctp_laddr));
349 			if (error != 0) {
350 				return (error);
351 			} else {
352 				SCTP_INP_INFO_RLOCK();
353 				SCTP_INP_RLOCK(inp);
354 			}
355 		}
356 	}
357 	memset((void *)&xladdr, 0, sizeof(struct xsctp_laddr));
358 	xladdr.last = 1;
359 	SCTP_INP_RUNLOCK(inp);
360 	SCTP_INP_INFO_RUNLOCK();
361 	error = SYSCTL_OUT(req, &xladdr, sizeof(struct xsctp_laddr));
362 
363 	if (error != 0) {
364 		return (error);
365 	} else {
366 		SCTP_INP_INFO_RLOCK();
367 		SCTP_INP_RLOCK(inp);
368 		return (0);
369 	}
370 }
371 
372 /*
373  * sysctl functions
374  */
375 static int
sctp_sysctl_handle_assoclist(SYSCTL_HANDLER_ARGS)376 sctp_sysctl_handle_assoclist(SYSCTL_HANDLER_ARGS)
377 {
378 	unsigned int number_of_endpoints;
379 	unsigned int number_of_local_addresses;
380 	unsigned int number_of_associations;
381 	unsigned int number_of_remote_addresses;
382 	unsigned int n;
383 	int error;
384 	struct sctp_inpcb *inp;
385 	struct sctp_tcb *stcb;
386 	struct sctp_nets *net;
387 	struct xsctp_inpcb xinpcb;
388 	struct xsctp_tcb xstcb;
389 	struct xsctp_raddr xraddr;
390 	struct socket *so;
391 
392 	number_of_endpoints = 0;
393 	number_of_local_addresses = 0;
394 	number_of_associations = 0;
395 	number_of_remote_addresses = 0;
396 
397 	SCTP_INP_INFO_RLOCK();
398 	if (req->oldptr == NULL) {
399 		LIST_FOREACH(inp, &SCTP_BASE_INFO(listhead), sctp_list) {
400 			SCTP_INP_RLOCK(inp);
401 			number_of_endpoints++;
402 			number_of_local_addresses += sctp_sysctl_number_of_addresses(inp);
403 			LIST_FOREACH(stcb, &inp->sctp_asoc_list, sctp_tcblist) {
404 				number_of_associations++;
405 				number_of_local_addresses += sctp_sysctl_number_of_addresses(inp);
406 				TAILQ_FOREACH(net, &stcb->asoc.nets, sctp_next) {
407 					number_of_remote_addresses++;
408 				}
409 			}
410 			SCTP_INP_RUNLOCK(inp);
411 		}
412 		SCTP_INP_INFO_RUNLOCK();
413 		n = (number_of_endpoints + 1) * sizeof(struct xsctp_inpcb) +
414 		    (number_of_local_addresses + number_of_endpoints + number_of_associations) * sizeof(struct xsctp_laddr) +
415 		    (number_of_associations + number_of_endpoints) * sizeof(struct xsctp_tcb) +
416 		    (number_of_remote_addresses + number_of_associations) * sizeof(struct xsctp_raddr);
417 
418 		/* request some more memory than needed */
419 		req->oldidx = (n + n / 8);
420 		return (0);
421 	}
422 	if (req->newptr != NULL) {
423 		SCTP_INP_INFO_RUNLOCK();
424 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTP_SYSCTL, EPERM);
425 		return (EPERM);
426 	}
427 	memset(&xinpcb, 0, sizeof(xinpcb));
428 	memset(&xstcb, 0, sizeof(xstcb));
429 	memset(&xraddr, 0, sizeof(xraddr));
430 	LIST_FOREACH(inp, &SCTP_BASE_INFO(listhead), sctp_list) {
431 		SCTP_INP_RLOCK(inp);
432 		if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) {
433 			/* if its allgone it is being freed - skip it  */
434 			goto skip;
435 		}
436 		xinpcb.last = 0;
437 		xinpcb.local_port = ntohs(inp->sctp_lport);
438 		xinpcb.flags = inp->sctp_flags;
439 		xinpcb.features = inp->sctp_features;
440 		xinpcb.total_sends = inp->total_sends;
441 		xinpcb.total_recvs = inp->total_recvs;
442 		xinpcb.total_nospaces = inp->total_nospaces;
443 		xinpcb.fragmentation_point = inp->sctp_frag_point;
444 		xinpcb.socket = (uintptr_t)inp->sctp_socket;
445 		so = inp->sctp_socket;
446 		if ((so == NULL) ||
447 		    (!SCTP_IS_LISTENING(inp)) ||
448 		    (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE)) {
449 			xinpcb.qlen = 0;
450 			xinpcb.maxqlen = 0;
451 		} else {
452 			xinpcb.qlen = so->sol_qlen;
453 			xinpcb.qlen_old = so->sol_qlen > USHRT_MAX ?
454 			    USHRT_MAX : (uint16_t)so->sol_qlen;
455 			xinpcb.maxqlen = so->sol_qlimit;
456 			xinpcb.maxqlen_old = so->sol_qlimit > USHRT_MAX ?
457 			    USHRT_MAX : (uint16_t)so->sol_qlimit;
458 		}
459 		SCTP_INP_INCR_REF(inp);
460 		SCTP_INP_RUNLOCK(inp);
461 		SCTP_INP_INFO_RUNLOCK();
462 		error = SYSCTL_OUT(req, &xinpcb, sizeof(struct xsctp_inpcb));
463 		if (error) {
464 			SCTP_INP_DECR_REF(inp);
465 			return (error);
466 		}
467 		SCTP_INP_INFO_RLOCK();
468 		SCTP_INP_RLOCK(inp);
469 		error = sctp_sysctl_copy_out_local_addresses(inp, NULL, req);
470 		if (error) {
471 			SCTP_INP_DECR_REF(inp);
472 			return (error);
473 		}
474 		LIST_FOREACH(stcb, &inp->sctp_asoc_list, sctp_tcblist) {
475 			SCTP_TCB_LOCK(stcb);
476 			atomic_add_int(&stcb->asoc.refcnt, 1);
477 			SCTP_TCB_UNLOCK(stcb);
478 			xstcb.last = 0;
479 			xstcb.local_port = ntohs(inp->sctp_lport);
480 			xstcb.remote_port = ntohs(stcb->rport);
481 			if (stcb->asoc.primary_destination != NULL)
482 				xstcb.primary_addr = stcb->asoc.primary_destination->ro._l_addr;
483 			xstcb.heartbeat_interval = stcb->asoc.heart_beat_delay;
484 			xstcb.state = (uint32_t)sctp_map_assoc_state(stcb->asoc.state);
485 			xstcb.assoc_id = sctp_get_associd(stcb);
486 			xstcb.peers_rwnd = stcb->asoc.peers_rwnd;
487 			xstcb.in_streams = stcb->asoc.streamincnt;
488 			xstcb.out_streams = stcb->asoc.streamoutcnt;
489 			xstcb.max_nr_retrans = stcb->asoc.overall_error_count;
490 			xstcb.primary_process = 0;	/* not really supported
491 							 * yet */
492 			xstcb.T1_expireries = stcb->asoc.timoinit + stcb->asoc.timocookie;
493 			xstcb.T2_expireries = stcb->asoc.timoshutdown + stcb->asoc.timoshutdownack;
494 			xstcb.retransmitted_tsns = stcb->asoc.marked_retrans;
495 			xstcb.start_time.tv_sec = (uint32_t)stcb->asoc.start_time.tv_sec;
496 			xstcb.start_time.tv_usec = (uint32_t)stcb->asoc.start_time.tv_usec;
497 			xstcb.discontinuity_time.tv_sec = (uint32_t)stcb->asoc.discontinuity_time.tv_sec;
498 			xstcb.discontinuity_time.tv_usec = (uint32_t)stcb->asoc.discontinuity_time.tv_usec;
499 			xstcb.total_sends = stcb->total_sends;
500 			xstcb.total_recvs = stcb->total_recvs;
501 			xstcb.local_tag = stcb->asoc.my_vtag;
502 			xstcb.remote_tag = stcb->asoc.peer_vtag;
503 			xstcb.initial_tsn = stcb->asoc.init_seq_number;
504 			xstcb.highest_tsn = stcb->asoc.sending_seq - 1;
505 			xstcb.cumulative_tsn = stcb->asoc.last_acked_seq;
506 			xstcb.cumulative_tsn_ack = stcb->asoc.cumulative_tsn;
507 			xstcb.mtu = stcb->asoc.smallest_mtu;
508 			xstcb.refcnt = stcb->asoc.refcnt;
509 			SCTP_INP_RUNLOCK(inp);
510 			SCTP_INP_INFO_RUNLOCK();
511 			error = SYSCTL_OUT(req, &xstcb, sizeof(struct xsctp_tcb));
512 			if (error) {
513 				SCTP_INP_DECR_REF(inp);
514 				atomic_subtract_int(&stcb->asoc.refcnt, 1);
515 				return (error);
516 			}
517 			SCTP_INP_INFO_RLOCK();
518 			SCTP_INP_RLOCK(inp);
519 			error = sctp_sysctl_copy_out_local_addresses(inp, stcb, req);
520 			if (error) {
521 				SCTP_INP_DECR_REF(inp);
522 				atomic_subtract_int(&stcb->asoc.refcnt, 1);
523 				return (error);
524 			}
525 			TAILQ_FOREACH(net, &stcb->asoc.nets, sctp_next) {
526 				xraddr.last = 0;
527 				xraddr.address = net->ro._l_addr;
528 				xraddr.active = ((net->dest_state & SCTP_ADDR_REACHABLE) == SCTP_ADDR_REACHABLE);
529 				xraddr.confirmed = ((net->dest_state & SCTP_ADDR_UNCONFIRMED) == 0);
530 				xraddr.heartbeat_enabled = ((net->dest_state & SCTP_ADDR_NOHB) == 0);
531 				xraddr.potentially_failed = ((net->dest_state & SCTP_ADDR_PF) == SCTP_ADDR_PF);
532 				xraddr.rto = net->RTO;
533 				xraddr.max_path_rtx = net->failure_threshold;
534 				xraddr.rtx = net->marked_retrans;
535 				xraddr.error_counter = net->error_count;
536 				xraddr.cwnd = net->cwnd;
537 				xraddr.flight_size = net->flight_size;
538 				xraddr.mtu = net->mtu;
539 				xraddr.rtt = net->rtt / 1000;
540 				xraddr.heartbeat_interval = net->heart_beat_delay;
541 				xraddr.ssthresh = net->ssthresh;
542 				xraddr.encaps_port = net->port;
543 				if (net->dest_state & SCTP_ADDR_UNCONFIRMED) {
544 					xraddr.state = SCTP_UNCONFIRMED;
545 				} else if (net->dest_state & SCTP_ADDR_REACHABLE) {
546 					xraddr.state = SCTP_ACTIVE;
547 				} else {
548 					xraddr.state = SCTP_INACTIVE;
549 				}
550 				xraddr.start_time.tv_sec = (uint32_t)net->start_time.tv_sec;
551 				xraddr.start_time.tv_usec = (uint32_t)net->start_time.tv_usec;
552 				SCTP_INP_RUNLOCK(inp);
553 				SCTP_INP_INFO_RUNLOCK();
554 				error = SYSCTL_OUT(req, &xraddr, sizeof(struct xsctp_raddr));
555 				if (error) {
556 					SCTP_INP_DECR_REF(inp);
557 					atomic_subtract_int(&stcb->asoc.refcnt, 1);
558 					return (error);
559 				}
560 				SCTP_INP_INFO_RLOCK();
561 				SCTP_INP_RLOCK(inp);
562 			}
563 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
564 			memset((void *)&xraddr, 0, sizeof(struct xsctp_raddr));
565 			xraddr.last = 1;
566 			SCTP_INP_RUNLOCK(inp);
567 			SCTP_INP_INFO_RUNLOCK();
568 			error = SYSCTL_OUT(req, &xraddr, sizeof(struct xsctp_raddr));
569 			if (error) {
570 				SCTP_INP_DECR_REF(inp);
571 				return (error);
572 			}
573 			SCTP_INP_INFO_RLOCK();
574 			SCTP_INP_RLOCK(inp);
575 		}
576 		SCTP_INP_DECR_REF(inp);
577 		SCTP_INP_RUNLOCK(inp);
578 		SCTP_INP_INFO_RUNLOCK();
579 		memset((void *)&xstcb, 0, sizeof(struct xsctp_tcb));
580 		xstcb.last = 1;
581 		error = SYSCTL_OUT(req, &xstcb, sizeof(struct xsctp_tcb));
582 		if (error) {
583 			return (error);
584 		}
585 skip:
586 		SCTP_INP_INFO_RLOCK();
587 	}
588 	SCTP_INP_INFO_RUNLOCK();
589 
590 	memset((void *)&xinpcb, 0, sizeof(struct xsctp_inpcb));
591 	xinpcb.last = 1;
592 	error = SYSCTL_OUT(req, &xinpcb, sizeof(struct xsctp_inpcb));
593 	return (error);
594 }
595 
596 static int
sctp_sysctl_handle_udp_tunneling(SYSCTL_HANDLER_ARGS)597 sctp_sysctl_handle_udp_tunneling(SYSCTL_HANDLER_ARGS)
598 {
599 	int error;
600 	uint32_t old, new;
601 
602 	SCTP_INP_INFO_RLOCK();
603 	old = SCTP_BASE_SYSCTL(sctp_udp_tunneling_port);
604 	SCTP_INP_INFO_RUNLOCK();
605 	new = old;
606 	error = sysctl_handle_int(oidp, &new, 0, req);
607 	if ((error == 0) &&
608 	    (req->newptr != NULL)) {
609 #if (SCTPCTL_UDP_TUNNELING_PORT_MIN == 0)
610 		if (new > SCTPCTL_UDP_TUNNELING_PORT_MAX) {
611 #else
612 		if ((new < SCTPCTL_UDP_TUNNELING_PORT_MIN) ||
613 		    (new > SCTPCTL_UDP_TUNNELING_PORT_MAX)) {
614 #endif
615 			error = EINVAL;
616 		} else {
617 			SCTP_INP_INFO_WLOCK();
618 			SCTP_BASE_SYSCTL(sctp_udp_tunneling_port) = new;
619 			if (old != 0) {
620 				sctp_over_udp_stop();
621 			}
622 			if (new != 0) {
623 				error = sctp_over_udp_start();
624 			}
625 			SCTP_INP_INFO_WUNLOCK();
626 		}
627 	}
628 	return (error);
629 }
630 
631 static int
632 sctp_sysctl_handle_auth(SYSCTL_HANDLER_ARGS)
633 {
634 	int error;
635 	uint32_t new;
636 
637 	new = SCTP_BASE_SYSCTL(sctp_auth_enable);
638 	error = sysctl_handle_int(oidp, &new, 0, req);
639 	if ((error == 0) &&
640 	    (req->newptr != NULL)) {
641 #if (SCTPCTL_AUTH_ENABLE_MIN == 0)
642 		if ((new > SCTPCTL_AUTH_ENABLE_MAX) ||
643 		    ((new == 0) && (SCTP_BASE_SYSCTL(sctp_asconf_enable) == 1))) {
644 #else
645 		if ((new < SCTPCTL_AUTH_ENABLE_MIN) ||
646 		    (new > SCTPCTL_AUTH_ENABLE_MAX) ||
647 		    ((new == 0) && (SCTP_BASE_SYSCTL(sctp_asconf_enable) == 1))) {
648 #endif
649 			error = EINVAL;
650 		} else {
651 			SCTP_BASE_SYSCTL(sctp_auth_enable) = new;
652 		}
653 	}
654 	return (error);
655 }
656 
657 static int
658 sctp_sysctl_handle_asconf(SYSCTL_HANDLER_ARGS)
659 {
660 	int error;
661 	uint32_t new;
662 
663 	new = SCTP_BASE_SYSCTL(sctp_asconf_enable);
664 	error = sysctl_handle_int(oidp, &new, 0, req);
665 	if ((error == 0) &&
666 	    (req->newptr != NULL)) {
667 #if (SCTPCTL_ASCONF_ENABLE_MIN == 0)
668 		if ((new > SCTPCTL_ASCONF_ENABLE_MAX) ||
669 		    ((new == 1) && (SCTP_BASE_SYSCTL(sctp_auth_enable) == 0))) {
670 #else
671 		if ((new < SCTPCTL_ASCONF_ENABLE_MIN) ||
672 		    (new > SCTPCTL_ASCONF_ENABLE_MAX) ||
673 		    ((new == 1) && (SCTP_BASE_SYSCTL(sctp_auth_enable) == 0))) {
674 #endif
675 			error = EINVAL;
676 		} else {
677 			SCTP_BASE_SYSCTL(sctp_asconf_enable) = new;
678 		}
679 	}
680 	return (error);
681 }
682 
683 static int
684 sctp_sysctl_handle_stats(SYSCTL_HANDLER_ARGS)
685 {
686 	int error;
687 #if defined(SMP) && defined(SCTP_USE_PERCPU_STAT)
688 	struct sctpstat *sarry;
689 	struct sctpstat sb;
690 	int cpu;
691 #endif
692 	struct sctpstat sb_temp;
693 
694 	if ((req->newptr != NULL) &&
695 	    (req->newlen != sizeof(struct sctpstat))) {
696 		return (EINVAL);
697 	}
698 	memset(&sb_temp, 0, sizeof(struct sctpstat));
699 
700 	if (req->newptr != NULL) {
701 		error = SYSCTL_IN(req, &sb_temp, sizeof(struct sctpstat));
702 		if (error != 0) {
703 			return (error);
704 		}
705 	}
706 #if defined(SMP) && defined(SCTP_USE_PERCPU_STAT)
707 	memset(&sb, 0, sizeof(sb));
708 	for (cpu = 0; cpu < mp_maxid; cpu++) {
709 		sarry = &SCTP_BASE_STATS[cpu];
710 		if (sarry->sctps_discontinuitytime.tv_sec > sb.sctps_discontinuitytime.tv_sec) {
711 			sb.sctps_discontinuitytime.tv_sec = sarry->sctps_discontinuitytime.tv_sec;
712 			sb.sctps_discontinuitytime.tv_usec = sarry->sctps_discontinuitytime.tv_usec;
713 		}
714 		sb.sctps_currestab += sarry->sctps_currestab;
715 		sb.sctps_activeestab += sarry->sctps_activeestab;
716 		sb.sctps_restartestab += sarry->sctps_restartestab;
717 		sb.sctps_collisionestab += sarry->sctps_collisionestab;
718 		sb.sctps_passiveestab += sarry->sctps_passiveestab;
719 		sb.sctps_aborted += sarry->sctps_aborted;
720 		sb.sctps_shutdown += sarry->sctps_shutdown;
721 		sb.sctps_outoftheblue += sarry->sctps_outoftheblue;
722 		sb.sctps_checksumerrors += sarry->sctps_checksumerrors;
723 		sb.sctps_outcontrolchunks += sarry->sctps_outcontrolchunks;
724 		sb.sctps_outorderchunks += sarry->sctps_outorderchunks;
725 		sb.sctps_outunorderchunks += sarry->sctps_outunorderchunks;
726 		sb.sctps_incontrolchunks += sarry->sctps_incontrolchunks;
727 		sb.sctps_inorderchunks += sarry->sctps_inorderchunks;
728 		sb.sctps_inunorderchunks += sarry->sctps_inunorderchunks;
729 		sb.sctps_fragusrmsgs += sarry->sctps_fragusrmsgs;
730 		sb.sctps_reasmusrmsgs += sarry->sctps_reasmusrmsgs;
731 		sb.sctps_outpackets += sarry->sctps_outpackets;
732 		sb.sctps_inpackets += sarry->sctps_inpackets;
733 		sb.sctps_recvpackets += sarry->sctps_recvpackets;
734 		sb.sctps_recvdatagrams += sarry->sctps_recvdatagrams;
735 		sb.sctps_recvpktwithdata += sarry->sctps_recvpktwithdata;
736 		sb.sctps_recvsacks += sarry->sctps_recvsacks;
737 		sb.sctps_recvdata += sarry->sctps_recvdata;
738 		sb.sctps_recvdupdata += sarry->sctps_recvdupdata;
739 		sb.sctps_recvheartbeat += sarry->sctps_recvheartbeat;
740 		sb.sctps_recvheartbeatack += sarry->sctps_recvheartbeatack;
741 		sb.sctps_recvecne += sarry->sctps_recvecne;
742 		sb.sctps_recvauth += sarry->sctps_recvauth;
743 		sb.sctps_recvauthmissing += sarry->sctps_recvauthmissing;
744 		sb.sctps_recvivalhmacid += sarry->sctps_recvivalhmacid;
745 		sb.sctps_recvivalkeyid += sarry->sctps_recvivalkeyid;
746 		sb.sctps_recvauthfailed += sarry->sctps_recvauthfailed;
747 		sb.sctps_recvexpress += sarry->sctps_recvexpress;
748 		sb.sctps_recvexpressm += sarry->sctps_recvexpressm;
749 		sb.sctps_recvswcrc += sarry->sctps_recvswcrc;
750 		sb.sctps_recvhwcrc += sarry->sctps_recvhwcrc;
751 		sb.sctps_sendpackets += sarry->sctps_sendpackets;
752 		sb.sctps_sendsacks += sarry->sctps_sendsacks;
753 		sb.sctps_senddata += sarry->sctps_senddata;
754 		sb.sctps_sendretransdata += sarry->sctps_sendretransdata;
755 		sb.sctps_sendfastretrans += sarry->sctps_sendfastretrans;
756 		sb.sctps_sendmultfastretrans += sarry->sctps_sendmultfastretrans;
757 		sb.sctps_sendheartbeat += sarry->sctps_sendheartbeat;
758 		sb.sctps_sendecne += sarry->sctps_sendecne;
759 		sb.sctps_sendauth += sarry->sctps_sendauth;
760 		sb.sctps_senderrors += sarry->sctps_senderrors;
761 		sb.sctps_sendswcrc += sarry->sctps_sendswcrc;
762 		sb.sctps_sendhwcrc += sarry->sctps_sendhwcrc;
763 		sb.sctps_pdrpfmbox += sarry->sctps_pdrpfmbox;
764 		sb.sctps_pdrpfehos += sarry->sctps_pdrpfehos;
765 		sb.sctps_pdrpmbda += sarry->sctps_pdrpmbda;
766 		sb.sctps_pdrpmbct += sarry->sctps_pdrpmbct;
767 		sb.sctps_pdrpbwrpt += sarry->sctps_pdrpbwrpt;
768 		sb.sctps_pdrpcrupt += sarry->sctps_pdrpcrupt;
769 		sb.sctps_pdrpnedat += sarry->sctps_pdrpnedat;
770 		sb.sctps_pdrppdbrk += sarry->sctps_pdrppdbrk;
771 		sb.sctps_pdrptsnnf += sarry->sctps_pdrptsnnf;
772 		sb.sctps_pdrpdnfnd += sarry->sctps_pdrpdnfnd;
773 		sb.sctps_pdrpdiwnp += sarry->sctps_pdrpdiwnp;
774 		sb.sctps_pdrpdizrw += sarry->sctps_pdrpdizrw;
775 		sb.sctps_pdrpbadd += sarry->sctps_pdrpbadd;
776 		sb.sctps_pdrpmark += sarry->sctps_pdrpmark;
777 		sb.sctps_timoiterator += sarry->sctps_timoiterator;
778 		sb.sctps_timodata += sarry->sctps_timodata;
779 		sb.sctps_timowindowprobe += sarry->sctps_timowindowprobe;
780 		sb.sctps_timoinit += sarry->sctps_timoinit;
781 		sb.sctps_timosack += sarry->sctps_timosack;
782 		sb.sctps_timoshutdown += sarry->sctps_timoshutdown;
783 		sb.sctps_timoheartbeat += sarry->sctps_timoheartbeat;
784 		sb.sctps_timocookie += sarry->sctps_timocookie;
785 		sb.sctps_timosecret += sarry->sctps_timosecret;
786 		sb.sctps_timopathmtu += sarry->sctps_timopathmtu;
787 		sb.sctps_timoshutdownack += sarry->sctps_timoshutdownack;
788 		sb.sctps_timoshutdownguard += sarry->sctps_timoshutdownguard;
789 		sb.sctps_timostrmrst += sarry->sctps_timostrmrst;
790 		sb.sctps_timoearlyfr += sarry->sctps_timoearlyfr;
791 		sb.sctps_timoasconf += sarry->sctps_timoasconf;
792 		sb.sctps_timodelprim += sarry->sctps_timodelprim;
793 		sb.sctps_timoautoclose += sarry->sctps_timoautoclose;
794 		sb.sctps_timoassockill += sarry->sctps_timoassockill;
795 		sb.sctps_timoinpkill += sarry->sctps_timoinpkill;
796 		sb.sctps_hdrops += sarry->sctps_hdrops;
797 		sb.sctps_badsum += sarry->sctps_badsum;
798 		sb.sctps_noport += sarry->sctps_noport;
799 		sb.sctps_badvtag += sarry->sctps_badvtag;
800 		sb.sctps_badsid += sarry->sctps_badsid;
801 		sb.sctps_nomem += sarry->sctps_nomem;
802 		sb.sctps_fastretransinrtt += sarry->sctps_fastretransinrtt;
803 		sb.sctps_markedretrans += sarry->sctps_markedretrans;
804 		sb.sctps_naglesent += sarry->sctps_naglesent;
805 		sb.sctps_naglequeued += sarry->sctps_naglequeued;
806 		sb.sctps_maxburstqueued += sarry->sctps_maxburstqueued;
807 		sb.sctps_ifnomemqueued += sarry->sctps_ifnomemqueued;
808 		sb.sctps_windowprobed += sarry->sctps_windowprobed;
809 		sb.sctps_lowlevelerr += sarry->sctps_lowlevelerr;
810 		sb.sctps_lowlevelerrusr += sarry->sctps_lowlevelerrusr;
811 		sb.sctps_datadropchklmt += sarry->sctps_datadropchklmt;
812 		sb.sctps_datadroprwnd += sarry->sctps_datadroprwnd;
813 		sb.sctps_ecnereducedcwnd += sarry->sctps_ecnereducedcwnd;
814 		sb.sctps_vtagexpress += sarry->sctps_vtagexpress;
815 		sb.sctps_vtagbogus += sarry->sctps_vtagbogus;
816 		sb.sctps_primary_randry += sarry->sctps_primary_randry;
817 		sb.sctps_cmt_randry += sarry->sctps_cmt_randry;
818 		sb.sctps_slowpath_sack += sarry->sctps_slowpath_sack;
819 		sb.sctps_wu_sacks_sent += sarry->sctps_wu_sacks_sent;
820 		sb.sctps_sends_with_flags += sarry->sctps_sends_with_flags;
821 		sb.sctps_sends_with_unord += sarry->sctps_sends_with_unord;
822 		sb.sctps_sends_with_eof += sarry->sctps_sends_with_eof;
823 		sb.sctps_sends_with_abort += sarry->sctps_sends_with_abort;
824 		sb.sctps_protocol_drain_calls += sarry->sctps_protocol_drain_calls;
825 		sb.sctps_protocol_drains_done += sarry->sctps_protocol_drains_done;
826 		sb.sctps_read_peeks += sarry->sctps_read_peeks;
827 		sb.sctps_cached_chk += sarry->sctps_cached_chk;
828 		sb.sctps_cached_strmoq += sarry->sctps_cached_strmoq;
829 		sb.sctps_left_abandon += sarry->sctps_left_abandon;
830 		sb.sctps_send_burst_avoid += sarry->sctps_send_burst_avoid;
831 		sb.sctps_send_cwnd_avoid += sarry->sctps_send_cwnd_avoid;
832 		sb.sctps_fwdtsn_map_over += sarry->sctps_fwdtsn_map_over;
833 		sb.sctps_queue_upd_ecne += sarry->sctps_queue_upd_ecne;
834 		sb.sctps_recvzerocrc += sarry->sctps_recvzerocrc;
835 		sb.sctps_sendzerocrc += sarry->sctps_sendzerocrc;
836 		if (req->newptr != NULL) {
837 			memcpy(sarry, &sb_temp, sizeof(struct sctpstat));
838 		}
839 	}
840 	error = SYSCTL_OUT(req, &sb, sizeof(struct sctpstat));
841 #else
842 	error = SYSCTL_OUT(req, &SCTP_BASE_STATS, sizeof(struct sctpstat));
843 	if (error != 0) {
844 		return (error);
845 	}
846 	if (req->newptr != NULL) {
847 		memcpy(&SCTP_BASE_STATS, &sb_temp, sizeof(struct sctpstat));
848 	}
849 #endif
850 	return (error);
851 }
852 
853 #if defined(SCTP_LOCAL_TRACE_BUF)
854 static int
855 sctp_sysctl_handle_trace_log(SYSCTL_HANDLER_ARGS)
856 {
857 	int error;
858 
859 	error = SYSCTL_OUT(req, &SCTP_BASE_SYSCTL(sctp_log), sizeof(struct sctp_log));
860 	return (error);
861 }
862 
863 static int
864 sctp_sysctl_handle_trace_log_clear(SYSCTL_HANDLER_ARGS)
865 {
866 	int error = 0;
867 
868 	memset(&SCTP_BASE_SYSCTL(sctp_log), 0, sizeof(struct sctp_log));
869 	return (error);
870 }
871 #endif
872 
873 #define SCTP_UINT_SYSCTL(mib_name, var_name, prefix)			\
874 	SCTP_UINT_SYSCTL_FLAG(mib_name, var_name, prefix,		\
875 	    CTLFLAG_VNET|CTLTYPE_UINT|CTLFLAG_RW)
876 
877 #define SCTP_UINT_SYSCTL_TUN(mib_name, var_name, prefix)		\
878 	SCTP_UINT_SYSCTL_FLAG(mib_name, var_name, prefix,		\
879 	    CTLFLAG_VNET|CTLTYPE_UINT|CTLFLAG_RWTUN|CTLFLAG_NOFETCH)
880 
881 #define SCTP_UINT_SYSCTL_FLAG(mib_name, var_name, prefix, flags)	\
882 	static int							\
883 	sctp_sysctl_handle_##mib_name(SYSCTL_HANDLER_ARGS)		\
884 	{								\
885 		int error;						\
886 		uint32_t new;						\
887 									\
888 		new = SCTP_BASE_SYSCTL(var_name);			\
889 		error = sysctl_handle_int(oidp, &new, 0, req);		\
890 		if ((error == 0) && (req->newptr != NULL)) {		\
891 			if ((new < prefix##_MIN) ||			\
892 			    (new > prefix##_MAX)) {			\
893 				error = EINVAL;				\
894 			} else {					\
895 				SCTP_BASE_SYSCTL(var_name) = new;	\
896 			}						\
897 		}							\
898 		return (error);						\
899 	}								\
900 	SYSCTL_PROC(_net_inet_sctp, OID_AUTO, mib_name, flags, NULL, 0,	\
901 	    sctp_sysctl_handle_##mib_name, "IU", prefix##_DESC)
902 
903 #define SCTP_UINT_SYSCTL_RDTUN(mib_name, var_name, prefix)		\
904 	SYSCTL_UINT(_net_inet_sctp, OID_AUTO, mib_name,			\
905 	    CTLFLAG_VNET|CTLFLAG_RDTUN|CTLFLAG_NOFETCH,			\
906 	    &VNET_NAME(system_base_info.sctpsysctl.var_name), 0,	\
907 	    prefix##_DESC)
908 
909 /*
910  * sysctl definitions
911  */
912 
913 SCTP_UINT_SYSCTL(sendspace, sctp_sendspace, SCTPCTL_MAXDGRAM);
914 SCTP_UINT_SYSCTL(recvspace, sctp_recvspace, SCTPCTL_RECVSPACE);
915 SCTP_UINT_SYSCTL(auto_asconf, sctp_auto_asconf, SCTPCTL_AUTOASCONF);
916 SCTP_UINT_SYSCTL(ecn_enable, sctp_ecn_enable, SCTPCTL_ECN_ENABLE);
917 SCTP_UINT_SYSCTL(pr_enable, sctp_pr_enable, SCTPCTL_PR_ENABLE);
918 SYSCTL_PROC(_net_inet_sctp, OID_AUTO, auth_enable, CTLFLAG_VNET | CTLTYPE_UINT | CTLFLAG_RW,
919     NULL, 0, sctp_sysctl_handle_auth, "IU", SCTPCTL_AUTH_ENABLE_DESC);
920 SYSCTL_PROC(_net_inet_sctp, OID_AUTO, asconf_enable, CTLFLAG_VNET | CTLTYPE_UINT | CTLFLAG_RW,
921     NULL, 0, sctp_sysctl_handle_asconf, "IU", SCTPCTL_ASCONF_ENABLE_DESC);
922 SCTP_UINT_SYSCTL(reconfig_enable, sctp_reconfig_enable, SCTPCTL_RECONFIG_ENABLE);
923 SCTP_UINT_SYSCTL(nrsack_enable, sctp_nrsack_enable, SCTPCTL_NRSACK_ENABLE);
924 SCTP_UINT_SYSCTL(pktdrop_enable, sctp_pktdrop_enable, SCTPCTL_PKTDROP_ENABLE);
925 SCTP_UINT_SYSCTL(peer_chkoh, sctp_peer_chunk_oh, SCTPCTL_PEER_CHKOH);
926 SCTP_UINT_SYSCTL(maxburst, sctp_max_burst_default, SCTPCTL_MAXBURST);
927 SCTP_UINT_SYSCTL(fr_maxburst, sctp_fr_max_burst_default, SCTPCTL_FRMAXBURST);
928 SCTP_UINT_SYSCTL(maxchunks, sctp_max_chunks_on_queue, SCTPCTL_MAXCHUNKS);
929 SCTP_UINT_SYSCTL_RDTUN(tcbhashsize, sctp_hashtblsize, SCTPCTL_TCBHASHSIZE);
930 SCTP_UINT_SYSCTL_TUN(pcbhashsize, sctp_pcbtblsize, SCTPCTL_PCBHASHSIZE);
931 SCTP_UINT_SYSCTL_RDTUN(chunkscale, sctp_chunkscale, SCTPCTL_CHUNKSCALE);
932 SCTP_UINT_SYSCTL(min_split_point, sctp_min_split_point, SCTPCTL_MIN_SPLIT_POINT);
933 SCTP_UINT_SYSCTL(delayed_sack_time, sctp_delayed_sack_time_default, SCTPCTL_DELAYED_SACK_TIME);
934 SCTP_UINT_SYSCTL(sack_freq, sctp_sack_freq_default, SCTPCTL_SACK_FREQ);
935 SCTP_UINT_SYSCTL(sys_resource, sctp_system_free_resc_limit, SCTPCTL_SYS_RESOURCE);
936 SCTP_UINT_SYSCTL(asoc_resource, sctp_asoc_free_resc_limit, SCTPCTL_ASOC_RESOURCE);
937 SCTP_UINT_SYSCTL(heartbeat_interval, sctp_heartbeat_interval_default, SCTPCTL_HEARTBEAT_INTERVAL);
938 SCTP_UINT_SYSCTL(pmtu_raise_time, sctp_pmtu_raise_time_default, SCTPCTL_PMTU_RAISE_TIME);
939 SCTP_UINT_SYSCTL(shutdown_guard_time, sctp_shutdown_guard_time_default, SCTPCTL_SHUTDOWN_GUARD_TIME);
940 SCTP_UINT_SYSCTL(secret_lifetime, sctp_secret_lifetime_default, SCTPCTL_SECRET_LIFETIME);
941 SCTP_UINT_SYSCTL(rto_max, sctp_rto_max_default, SCTPCTL_RTO_MAX);
942 SCTP_UINT_SYSCTL(rto_min, sctp_rto_min_default, SCTPCTL_RTO_MIN);
943 SCTP_UINT_SYSCTL(rto_initial, sctp_rto_initial_default, SCTPCTL_RTO_INITIAL);
944 SCTP_UINT_SYSCTL(init_rto_max, sctp_init_rto_max_default, SCTPCTL_INIT_RTO_MAX);
945 SCTP_UINT_SYSCTL(valid_cookie_life, sctp_valid_cookie_life_default, SCTPCTL_VALID_COOKIE_LIFE);
946 SCTP_UINT_SYSCTL(init_rtx_max, sctp_init_rtx_max_default, SCTPCTL_INIT_RTX_MAX);
947 SCTP_UINT_SYSCTL(assoc_rtx_max, sctp_assoc_rtx_max_default, SCTPCTL_ASSOC_RTX_MAX);
948 SCTP_UINT_SYSCTL(path_rtx_max, sctp_path_rtx_max_default, SCTPCTL_PATH_RTX_MAX);
949 SCTP_UINT_SYSCTL(path_pf_threshold, sctp_path_pf_threshold, SCTPCTL_PATH_PF_THRESHOLD);
950 SCTP_UINT_SYSCTL(add_more_on_output, sctp_add_more_threshold, SCTPCTL_ADD_MORE_ON_OUTPUT);
951 SCTP_UINT_SYSCTL(incoming_streams, sctp_nr_incoming_streams_default, SCTPCTL_INCOMING_STREAMS);
952 SCTP_UINT_SYSCTL(outgoing_streams, sctp_nr_outgoing_streams_default, SCTPCTL_OUTGOING_STREAMS);
953 SCTP_UINT_SYSCTL(cmt_on_off, sctp_cmt_on_off, SCTPCTL_CMT_ON_OFF);
954 SCTP_UINT_SYSCTL(cmt_use_dac, sctp_cmt_use_dac, SCTPCTL_CMT_USE_DAC);
955 SCTP_UINT_SYSCTL(cwnd_maxburst, sctp_use_cwnd_based_maxburst, SCTPCTL_CWND_MAXBURST);
956 SCTP_UINT_SYSCTL(nat_friendly, sctp_nat_friendly, SCTPCTL_NAT_FRIENDLY);
957 SCTP_UINT_SYSCTL(abc_l_var, sctp_L2_abc_variable, SCTPCTL_ABC_L_VAR);
958 SCTP_UINT_SYSCTL(max_chained_mbufs, sctp_mbuf_threshold_count, SCTPCTL_MAX_CHAINED_MBUFS);
959 SCTP_UINT_SYSCTL(do_sctp_drain, sctp_do_drain, SCTPCTL_DO_SCTP_DRAIN);
960 SCTP_UINT_SYSCTL(hb_max_burst, sctp_hb_maxburst, SCTPCTL_HB_MAX_BURST);
961 SCTP_UINT_SYSCTL(abort_at_limit, sctp_abort_if_one_2_one_hits_limit, SCTPCTL_ABORT_AT_LIMIT);
962 SCTP_UINT_SYSCTL(min_residual, sctp_min_residual, SCTPCTL_MIN_RESIDUAL);
963 SCTP_UINT_SYSCTL(max_retran_chunk, sctp_max_retran_chunk, SCTPCTL_MAX_RETRAN_CHUNK);
964 SCTP_UINT_SYSCTL(log_level, sctp_logging_level, SCTPCTL_LOGGING_LEVEL);
965 SCTP_UINT_SYSCTL(default_cc_module, sctp_default_cc_module, SCTPCTL_DEFAULT_CC_MODULE);
966 SCTP_UINT_SYSCTL(default_ss_module, sctp_default_ss_module, SCTPCTL_DEFAULT_SS_MODULE);
967 SCTP_UINT_SYSCTL(default_frag_interleave, sctp_default_frag_interleave, SCTPCTL_DEFAULT_FRAG_INTERLEAVE);
968 SCTP_UINT_SYSCTL(mobility_base, sctp_mobility_base, SCTPCTL_MOBILITY_BASE);
969 SCTP_UINT_SYSCTL(mobility_fasthandoff, sctp_mobility_fasthandoff, SCTPCTL_MOBILITY_FASTHANDOFF);
970 #if defined(SCTP_LOCAL_TRACE_BUF)
971 SYSCTL_PROC(_net_inet_sctp, OID_AUTO, log, CTLFLAG_VNET | CTLTYPE_STRUCT | CTLFLAG_RD,
972     NULL, 0, sctp_sysctl_handle_trace_log, "S,sctplog", "SCTP logging (struct sctp_log)");
973 SYSCTL_PROC(_net_inet_sctp, OID_AUTO, clear_trace, CTLFLAG_VNET | CTLTYPE_UINT | CTLFLAG_RW,
974     NULL, 0, sctp_sysctl_handle_trace_log_clear, "IU", "Clear SCTP Logging buffer");
975 #endif
976 SYSCTL_PROC(_net_inet_sctp, OID_AUTO, udp_tunneling_port, CTLFLAG_VNET | CTLTYPE_UINT | CTLFLAG_RW,
977     NULL, 0, sctp_sysctl_handle_udp_tunneling, "IU", SCTPCTL_UDP_TUNNELING_PORT_DESC);
978 SCTP_UINT_SYSCTL(enable_sack_immediately, sctp_enable_sack_immediately, SCTPCTL_SACK_IMMEDIATELY_ENABLE);
979 SCTP_UINT_SYSCTL(nat_friendly_init, sctp_inits_include_nat_friendly, SCTPCTL_NAT_FRIENDLY_INITS);
980 SCTP_UINT_SYSCTL(vtag_time_wait, sctp_vtag_time_wait, SCTPCTL_TIME_WAIT);
981 SCTP_UINT_SYSCTL(buffer_splitting, sctp_buffer_splitting, SCTPCTL_BUFFER_SPLITTING);
982 SCTP_UINT_SYSCTL(initial_cwnd, sctp_initial_cwnd, SCTPCTL_INITIAL_CWND);
983 SCTP_UINT_SYSCTL(rttvar_bw, sctp_rttvar_bw, SCTPCTL_RTTVAR_BW);
984 SCTP_UINT_SYSCTL(rttvar_rtt, sctp_rttvar_rtt, SCTPCTL_RTTVAR_RTT);
985 SCTP_UINT_SYSCTL(rttvar_eqret, sctp_rttvar_eqret, SCTPCTL_RTTVAR_EQRET);
986 SCTP_UINT_SYSCTL(rttvar_steady_step, sctp_steady_step, SCTPCTL_RTTVAR_STEADYS);
987 SCTP_UINT_SYSCTL(use_dcccecn, sctp_use_dccc_ecn, SCTPCTL_RTTVAR_DCCCECN);
988 SCTP_UINT_SYSCTL(blackhole, sctp_blackhole, SCTPCTL_BLACKHOLE);
989 SCTP_UINT_SYSCTL(sendall_limit, sctp_sendall_limit, SCTPCTL_SENDALL_LIMIT);
990 SCTP_UINT_SYSCTL(diag_info_code, sctp_diag_info_code, SCTPCTL_DIAG_INFO_CODE);
991 SCTP_UINT_SYSCTL(ootb_with_zero_cksum, sctp_ootb_with_zero_cksum, SCTPCTL_OOTB_WITH_ZERO_CKSUM);
992 #ifdef SCTP_DEBUG
993 SCTP_UINT_SYSCTL(debug, sctp_debug_on, SCTPCTL_DEBUG);
994 #endif
995 SYSCTL_PROC(_net_inet_sctp, OID_AUTO, stats, CTLFLAG_VNET | CTLTYPE_STRUCT | CTLFLAG_RW,
996     NULL, 0, sctp_sysctl_handle_stats, "S,sctpstat", "SCTP statistics (struct sctp_stat)");
997 SYSCTL_PROC(_net_inet_sctp, OID_AUTO, assoclist, CTLFLAG_VNET | CTLTYPE_OPAQUE | CTLFLAG_RD,
998     NULL, 0, sctp_sysctl_handle_assoclist, "S,xassoc", "List of active SCTP associations");
999