xref: /freebsd/sys/netinet/sctp_sysctl.c (revision e45764721aedfa6460e1767664864bda9457c10e)
1 /*-
2  * Copyright (c) 2007, by Cisco Systems, Inc. All rights reserved.
3  * Copyright (c) 2008-2012, by Randall Stewart. All rights reserved.
4  * Copyright (c) 2008-2012, by Michael Tuexen. All rights reserved.
5  *
6  * Redistribution and use in source and binary forms, with or without
7  * modification, are permitted provided that the following conditions are met:
8  *
9  * a) Redistributions of source code must retain the above copyright notice,
10  *    this list of conditions and the following disclaimer.
11  *
12  * b) Redistributions in binary form must reproduce the above copyright
13  *    notice, this list of conditions and the following disclaimer in
14  *    the documentation and/or other materials provided with the distribution.
15  *
16  * c) Neither the name of Cisco Systems, Inc. nor the names of its
17  *    contributors may be used to endorse or promote products derived
18  *    from this software without specific prior written permission.
19  *
20  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
21  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
22  * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
23  * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
24  * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
25  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
26  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
27  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
28  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
29  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
30  * THE POSSIBILITY OF SUCH DAMAGE.
31  */
32 
33 #include <sys/cdefs.h>
34 __FBSDID("$FreeBSD$");
35 
36 #include <netinet/sctp_os.h>
37 #include <netinet/sctp.h>
38 #include <netinet/sctp_constants.h>
39 #include <netinet/sctp_sysctl.h>
40 #include <netinet/sctp_pcb.h>
41 #include <netinet/sctputil.h>
42 #include <netinet/sctp_output.h>
43 #include <sys/smp.h>
44 
45 /*
46  * sysctl tunable variables
47  */
48 
49 void
50 sctp_init_sysctls()
51 {
52 	SCTP_BASE_SYSCTL(sctp_sendspace) = SCTPCTL_MAXDGRAM_DEFAULT;
53 	SCTP_BASE_SYSCTL(sctp_recvspace) = SCTPCTL_RECVSPACE_DEFAULT;
54 	SCTP_BASE_SYSCTL(sctp_auto_asconf) = SCTPCTL_AUTOASCONF_DEFAULT;
55 	SCTP_BASE_SYSCTL(sctp_multiple_asconfs) = SCTPCTL_MULTIPLEASCONFS_DEFAULT;
56 	SCTP_BASE_SYSCTL(sctp_ecn_enable) = SCTPCTL_ECN_ENABLE_DEFAULT;
57 	SCTP_BASE_SYSCTL(sctp_pr_enable) = SCTPCTL_PR_ENABLE_DEFAULT;
58 	SCTP_BASE_SYSCTL(sctp_auth_disable) = SCTPCTL_AUTH_DISABLE_DEFAULT;
59 	SCTP_BASE_SYSCTL(sctp_asconf_enable) = SCTPCTL_ASCONF_ENABLE_DEFAULT;
60 	SCTP_BASE_SYSCTL(sctp_reconfig_enable) = SCTPCTL_RECONFIG_ENABLE_DEFAULT;
61 	SCTP_BASE_SYSCTL(sctp_nrsack_enable) = SCTPCTL_NRSACK_ENABLE_DEFAULT;
62 	SCTP_BASE_SYSCTL(sctp_pktdrop_enable) = SCTPCTL_PKTDROP_ENABLE_DEFAULT;
63 	SCTP_BASE_SYSCTL(sctp_strict_sacks) = SCTPCTL_STRICT_SACKS_DEFAULT;
64 	SCTP_BASE_SYSCTL(sctp_peer_chunk_oh) = SCTPCTL_PEER_CHKOH_DEFAULT;
65 	SCTP_BASE_SYSCTL(sctp_max_burst_default) = SCTPCTL_MAXBURST_DEFAULT;
66 	SCTP_BASE_SYSCTL(sctp_fr_max_burst_default) = SCTPCTL_FRMAXBURST_DEFAULT;
67 	SCTP_BASE_SYSCTL(sctp_max_chunks_on_queue) = SCTPCTL_MAXCHUNKS_DEFAULT;
68 	SCTP_BASE_SYSCTL(sctp_hashtblsize) = SCTPCTL_TCBHASHSIZE_DEFAULT;
69 	SCTP_BASE_SYSCTL(sctp_pcbtblsize) = SCTPCTL_PCBHASHSIZE_DEFAULT;
70 	SCTP_BASE_SYSCTL(sctp_min_split_point) = SCTPCTL_MIN_SPLIT_POINT_DEFAULT;
71 	SCTP_BASE_SYSCTL(sctp_chunkscale) = SCTPCTL_CHUNKSCALE_DEFAULT;
72 	SCTP_BASE_SYSCTL(sctp_delayed_sack_time_default) = SCTPCTL_DELAYED_SACK_TIME_DEFAULT;
73 	SCTP_BASE_SYSCTL(sctp_sack_freq_default) = SCTPCTL_SACK_FREQ_DEFAULT;
74 	SCTP_BASE_SYSCTL(sctp_system_free_resc_limit) = SCTPCTL_SYS_RESOURCE_DEFAULT;
75 	SCTP_BASE_SYSCTL(sctp_asoc_free_resc_limit) = SCTPCTL_ASOC_RESOURCE_DEFAULT;
76 	SCTP_BASE_SYSCTL(sctp_heartbeat_interval_default) = SCTPCTL_HEARTBEAT_INTERVAL_DEFAULT;
77 	SCTP_BASE_SYSCTL(sctp_pmtu_raise_time_default) = SCTPCTL_PMTU_RAISE_TIME_DEFAULT;
78 	SCTP_BASE_SYSCTL(sctp_shutdown_guard_time_default) = SCTPCTL_SHUTDOWN_GUARD_TIME_DEFAULT;
79 	SCTP_BASE_SYSCTL(sctp_secret_lifetime_default) = SCTPCTL_SECRET_LIFETIME_DEFAULT;
80 	SCTP_BASE_SYSCTL(sctp_rto_max_default) = SCTPCTL_RTO_MAX_DEFAULT;
81 	SCTP_BASE_SYSCTL(sctp_rto_min_default) = SCTPCTL_RTO_MIN_DEFAULT;
82 	SCTP_BASE_SYSCTL(sctp_rto_initial_default) = SCTPCTL_RTO_INITIAL_DEFAULT;
83 	SCTP_BASE_SYSCTL(sctp_init_rto_max_default) = SCTPCTL_INIT_RTO_MAX_DEFAULT;
84 	SCTP_BASE_SYSCTL(sctp_valid_cookie_life_default) = SCTPCTL_VALID_COOKIE_LIFE_DEFAULT;
85 	SCTP_BASE_SYSCTL(sctp_init_rtx_max_default) = SCTPCTL_INIT_RTX_MAX_DEFAULT;
86 	SCTP_BASE_SYSCTL(sctp_assoc_rtx_max_default) = SCTPCTL_ASSOC_RTX_MAX_DEFAULT;
87 	SCTP_BASE_SYSCTL(sctp_path_rtx_max_default) = SCTPCTL_PATH_RTX_MAX_DEFAULT;
88 	SCTP_BASE_SYSCTL(sctp_path_pf_threshold) = SCTPCTL_PATH_PF_THRESHOLD_DEFAULT;
89 	SCTP_BASE_SYSCTL(sctp_add_more_threshold) = SCTPCTL_ADD_MORE_ON_OUTPUT_DEFAULT;
90 	SCTP_BASE_SYSCTL(sctp_nr_incoming_streams_default) = SCTPCTL_INCOMING_STREAMS_DEFAULT;
91 	SCTP_BASE_SYSCTL(sctp_nr_outgoing_streams_default) = SCTPCTL_OUTGOING_STREAMS_DEFAULT;
92 	SCTP_BASE_SYSCTL(sctp_cmt_on_off) = SCTPCTL_CMT_ON_OFF_DEFAULT;
93 	SCTP_BASE_SYSCTL(sctp_cmt_use_dac) = SCTPCTL_CMT_USE_DAC_DEFAULT;
94 	SCTP_BASE_SYSCTL(sctp_use_cwnd_based_maxburst) = SCTPCTL_CWND_MAXBURST_DEFAULT;
95 	SCTP_BASE_SYSCTL(sctp_nat_friendly) = SCTPCTL_NAT_FRIENDLY_DEFAULT;
96 	SCTP_BASE_SYSCTL(sctp_L2_abc_variable) = SCTPCTL_ABC_L_VAR_DEFAULT;
97 	SCTP_BASE_SYSCTL(sctp_mbuf_threshold_count) = SCTPCTL_MAX_CHAINED_MBUFS_DEFAULT;
98 	SCTP_BASE_SYSCTL(sctp_do_drain) = SCTPCTL_DO_SCTP_DRAIN_DEFAULT;
99 	SCTP_BASE_SYSCTL(sctp_hb_maxburst) = SCTPCTL_HB_MAX_BURST_DEFAULT;
100 	SCTP_BASE_SYSCTL(sctp_abort_if_one_2_one_hits_limit) = SCTPCTL_ABORT_AT_LIMIT_DEFAULT;
101 	SCTP_BASE_SYSCTL(sctp_strict_data_order) = SCTPCTL_STRICT_DATA_ORDER_DEFAULT;
102 	SCTP_BASE_SYSCTL(sctp_min_residual) = SCTPCTL_MIN_RESIDUAL_DEFAULT;
103 	SCTP_BASE_SYSCTL(sctp_max_retran_chunk) = SCTPCTL_MAX_RETRAN_CHUNK_DEFAULT;
104 	SCTP_BASE_SYSCTL(sctp_logging_level) = SCTPCTL_LOGGING_LEVEL_DEFAULT;
105 	/* JRS - Variable for default congestion control module */
106 	SCTP_BASE_SYSCTL(sctp_default_cc_module) = SCTPCTL_DEFAULT_CC_MODULE_DEFAULT;
107 	/* RS - Variable for default stream scheduling module */
108 	SCTP_BASE_SYSCTL(sctp_default_ss_module) = SCTPCTL_DEFAULT_SS_MODULE_DEFAULT;
109 	SCTP_BASE_SYSCTL(sctp_default_frag_interleave) = SCTPCTL_DEFAULT_FRAG_INTERLEAVE_DEFAULT;
110 	SCTP_BASE_SYSCTL(sctp_mobility_base) = SCTPCTL_MOBILITY_BASE_DEFAULT;
111 	SCTP_BASE_SYSCTL(sctp_mobility_fasthandoff) = SCTPCTL_MOBILITY_FASTHANDOFF_DEFAULT;
112 	SCTP_BASE_SYSCTL(sctp_vtag_time_wait) = SCTPCTL_TIME_WAIT_DEFAULT;
113 	SCTP_BASE_SYSCTL(sctp_buffer_splitting) = SCTPCTL_BUFFER_SPLITTING_DEFAULT;
114 	SCTP_BASE_SYSCTL(sctp_initial_cwnd) = SCTPCTL_INITIAL_CWND_DEFAULT;
115 	SCTP_BASE_SYSCTL(sctp_rttvar_bw) = SCTPCTL_RTTVAR_BW_DEFAULT;
116 	SCTP_BASE_SYSCTL(sctp_rttvar_rtt) = SCTPCTL_RTTVAR_RTT_DEFAULT;
117 	SCTP_BASE_SYSCTL(sctp_rttvar_eqret) = SCTPCTL_RTTVAR_EQRET_DEFAULT;
118 	SCTP_BASE_SYSCTL(sctp_steady_step) = SCTPCTL_RTTVAR_STEADYS_DEFAULT;
119 	SCTP_BASE_SYSCTL(sctp_use_dccc_ecn) = SCTPCTL_RTTVAR_DCCCECN_DEFAULT;
120 	SCTP_BASE_SYSCTL(sctp_blackhole) = SCTPCTL_BLACKHOLE_DEFAULT;
121 	SCTP_BASE_SYSCTL(sctp_diag_info_code) = SCTPCTL_DIAG_INFO_CODE_DEFAULT;
122 #if defined(SCTP_LOCAL_TRACE_BUF)
123 	memset(&SCTP_BASE_SYSCTL(sctp_log), 0, sizeof(struct sctp_log));
124 #endif
125 	SCTP_BASE_SYSCTL(sctp_udp_tunneling_port) = SCTPCTL_UDP_TUNNELING_PORT_DEFAULT;
126 	SCTP_BASE_SYSCTL(sctp_enable_sack_immediately) = SCTPCTL_SACK_IMMEDIATELY_ENABLE_DEFAULT;
127 	SCTP_BASE_SYSCTL(sctp_inits_include_nat_friendly) = SCTPCTL_NAT_FRIENDLY_INITS_DEFAULT;
128 #if defined(SCTP_DEBUG)
129 	SCTP_BASE_SYSCTL(sctp_debug_on) = SCTPCTL_DEBUG_DEFAULT;
130 #endif
131 #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
132 	SCTP_BASE_SYSCTL(sctp_output_unlocked) = SCTPCTL_OUTPUT_UNLOCKED_DEFAULT;
133 #endif
134 }
135 
136 
137 /* It returns an upper limit. No filtering is done here */
138 static unsigned int
139 number_of_addresses(struct sctp_inpcb *inp)
140 {
141 	unsigned int cnt;
142 	struct sctp_vrf *vrf;
143 	struct sctp_ifn *sctp_ifn;
144 	struct sctp_ifa *sctp_ifa;
145 	struct sctp_laddr *laddr;
146 
147 	cnt = 0;
148 	/* neither Mac OS X nor FreeBSD support mulitple routing functions */
149 	if ((vrf = sctp_find_vrf(inp->def_vrf_id)) == NULL) {
150 		return (0);
151 	}
152 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
153 		LIST_FOREACH(sctp_ifn, &vrf->ifnlist, next_ifn) {
154 			LIST_FOREACH(sctp_ifa, &sctp_ifn->ifalist, next_ifa) {
155 				switch (sctp_ifa->address.sa.sa_family) {
156 #ifdef INET
157 				case AF_INET:
158 #endif
159 #ifdef INET6
160 				case AF_INET6:
161 #endif
162 					cnt++;
163 					break;
164 				default:
165 					break;
166 				}
167 			}
168 		}
169 	} else {
170 		LIST_FOREACH(laddr, &inp->sctp_addr_list, sctp_nxt_addr) {
171 			switch (laddr->ifa->address.sa.sa_family) {
172 #ifdef INET
173 			case AF_INET:
174 #endif
175 #ifdef INET6
176 			case AF_INET6:
177 #endif
178 				cnt++;
179 				break;
180 			default:
181 				break;
182 			}
183 		}
184 	}
185 	return (cnt);
186 }
187 
188 static int
189 copy_out_local_addresses(struct sctp_inpcb *inp, struct sctp_tcb *stcb, struct sysctl_req *req)
190 {
191 	struct sctp_ifn *sctp_ifn;
192 	struct sctp_ifa *sctp_ifa;
193 	int loopback_scope, ipv4_local_scope, local_scope, site_scope;
194 	int ipv4_addr_legal, ipv6_addr_legal;
195 	struct sctp_vrf *vrf;
196 	struct xsctp_laddr xladdr;
197 	struct sctp_laddr *laddr;
198 	int error;
199 
200 	/* Turn on all the appropriate scope */
201 	if (stcb) {
202 		/* use association specific values */
203 		loopback_scope = stcb->asoc.scope.loopback_scope;
204 		ipv4_local_scope = stcb->asoc.scope.ipv4_local_scope;
205 		local_scope = stcb->asoc.scope.local_scope;
206 		site_scope = stcb->asoc.scope.site_scope;
207 		ipv4_addr_legal = stcb->asoc.scope.ipv4_addr_legal;
208 		ipv6_addr_legal = stcb->asoc.scope.ipv6_addr_legal;
209 	} else {
210 		/* Use generic values for endpoints. */
211 		loopback_scope = 1;
212 		ipv4_local_scope = 1;
213 		local_scope = 1;
214 		site_scope = 1;
215 		if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) {
216 			ipv6_addr_legal = 1;
217 			if (SCTP_IPV6_V6ONLY(inp)) {
218 				ipv4_addr_legal = 0;
219 			} else {
220 				ipv4_addr_legal = 1;
221 			}
222 		} else {
223 			ipv6_addr_legal = 0;
224 			ipv4_addr_legal = 1;
225 		}
226 	}
227 
228 	/* neither Mac OS X nor FreeBSD support mulitple routing functions */
229 	if ((vrf = sctp_find_vrf(inp->def_vrf_id)) == NULL) {
230 		SCTP_INP_RUNLOCK(inp);
231 		SCTP_INP_INFO_RUNLOCK();
232 		return (-1);
233 	}
234 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
235 		LIST_FOREACH(sctp_ifn, &vrf->ifnlist, next_ifn) {
236 			if ((loopback_scope == 0) && SCTP_IFN_IS_IFT_LOOP(sctp_ifn))
237 				/* Skip loopback if loopback_scope not set */
238 				continue;
239 			LIST_FOREACH(sctp_ifa, &sctp_ifn->ifalist, next_ifa) {
240 				if (stcb) {
241 					/*
242 					 * ignore if blacklisted at
243 					 * association level
244 					 */
245 					if (sctp_is_addr_restricted(stcb, sctp_ifa))
246 						continue;
247 				}
248 				switch (sctp_ifa->address.sa.sa_family) {
249 #ifdef INET
250 				case AF_INET:
251 					if (ipv4_addr_legal) {
252 						struct sockaddr_in *sin;
253 
254 						sin = (struct sockaddr_in *)&sctp_ifa->address.sa;
255 						if (sin->sin_addr.s_addr == 0)
256 							continue;
257 						if (prison_check_ip4(inp->ip_inp.inp.inp_cred,
258 						    &sin->sin_addr) != 0) {
259 							continue;
260 						}
261 						if ((ipv4_local_scope == 0) && (IN4_ISPRIVATE_ADDRESS(&sin->sin_addr)))
262 							continue;
263 					} else {
264 						continue;
265 					}
266 					break;
267 #endif
268 #ifdef INET6
269 				case AF_INET6:
270 					if (ipv6_addr_legal) {
271 						struct sockaddr_in6 *sin6;
272 
273 						sin6 = (struct sockaddr_in6 *)&sctp_ifa->address.sa;
274 						if (IN6_IS_ADDR_UNSPECIFIED(&sin6->sin6_addr))
275 							continue;
276 						if (prison_check_ip6(inp->ip_inp.inp.inp_cred,
277 						    &sin6->sin6_addr) != 0) {
278 							continue;
279 						}
280 						if (IN6_IS_ADDR_LINKLOCAL(&sin6->sin6_addr)) {
281 							if (local_scope == 0)
282 								continue;
283 							if (sin6->sin6_scope_id == 0) {
284 								/*
285 								 * bad link
286 								 * local
287 								 * address
288 								 */
289 								if (sa6_recoverscope(sin6) != 0)
290 									continue;
291 							}
292 						}
293 						if ((site_scope == 0) && (IN6_IS_ADDR_SITELOCAL(&sin6->sin6_addr)))
294 							continue;
295 					} else {
296 						continue;
297 					}
298 					break;
299 #endif
300 				default:
301 					continue;
302 				}
303 				memset((void *)&xladdr, 0, sizeof(struct xsctp_laddr));
304 				memcpy((void *)&xladdr.address, (const void *)&sctp_ifa->address, sizeof(union sctp_sockstore));
305 				SCTP_INP_RUNLOCK(inp);
306 				SCTP_INP_INFO_RUNLOCK();
307 				error = SYSCTL_OUT(req, &xladdr, sizeof(struct xsctp_laddr));
308 				if (error) {
309 					return (error);
310 				} else {
311 					SCTP_INP_INFO_RLOCK();
312 					SCTP_INP_RLOCK(inp);
313 				}
314 			}
315 		}
316 	} else {
317 		LIST_FOREACH(laddr, &inp->sctp_addr_list, sctp_nxt_addr) {
318 			/* ignore if blacklisted at association level */
319 			if (stcb && sctp_is_addr_restricted(stcb, laddr->ifa))
320 				continue;
321 			memset((void *)&xladdr, 0, sizeof(struct xsctp_laddr));
322 			memcpy((void *)&xladdr.address, (const void *)&laddr->ifa->address, sizeof(union sctp_sockstore));
323 			xladdr.start_time.tv_sec = (uint32_t) laddr->start_time.tv_sec;
324 			xladdr.start_time.tv_usec = (uint32_t) laddr->start_time.tv_usec;
325 			SCTP_INP_RUNLOCK(inp);
326 			SCTP_INP_INFO_RUNLOCK();
327 			error = SYSCTL_OUT(req, &xladdr, sizeof(struct xsctp_laddr));
328 			if (error) {
329 				return (error);
330 			} else {
331 				SCTP_INP_INFO_RLOCK();
332 				SCTP_INP_RLOCK(inp);
333 			}
334 		}
335 	}
336 	memset((void *)&xladdr, 0, sizeof(struct xsctp_laddr));
337 	xladdr.last = 1;
338 	SCTP_INP_RUNLOCK(inp);
339 	SCTP_INP_INFO_RUNLOCK();
340 	error = SYSCTL_OUT(req, &xladdr, sizeof(struct xsctp_laddr));
341 
342 	if (error) {
343 		return (error);
344 	} else {
345 		SCTP_INP_INFO_RLOCK();
346 		SCTP_INP_RLOCK(inp);
347 		return (0);
348 	}
349 }
350 
351 /*
352  * sysctl functions
353  */
354 static int
355 sctp_assoclist(SYSCTL_HANDLER_ARGS)
356 {
357 	unsigned int number_of_endpoints;
358 	unsigned int number_of_local_addresses;
359 	unsigned int number_of_associations;
360 	unsigned int number_of_remote_addresses;
361 	unsigned int n;
362 	int error;
363 	struct sctp_inpcb *inp;
364 	struct sctp_tcb *stcb;
365 	struct sctp_nets *net;
366 	struct xsctp_inpcb xinpcb;
367 	struct xsctp_tcb xstcb;
368 	struct xsctp_raddr xraddr;
369 	struct socket *so;
370 
371 	number_of_endpoints = 0;
372 	number_of_local_addresses = 0;
373 	number_of_associations = 0;
374 	number_of_remote_addresses = 0;
375 
376 	SCTP_INP_INFO_RLOCK();
377 	if (req->oldptr == USER_ADDR_NULL) {
378 		LIST_FOREACH(inp, &SCTP_BASE_INFO(listhead), sctp_list) {
379 			SCTP_INP_RLOCK(inp);
380 			number_of_endpoints++;
381 			number_of_local_addresses += number_of_addresses(inp);
382 			LIST_FOREACH(stcb, &inp->sctp_asoc_list, sctp_tcblist) {
383 				number_of_associations++;
384 				number_of_local_addresses += number_of_addresses(inp);
385 				TAILQ_FOREACH(net, &stcb->asoc.nets, sctp_next) {
386 					number_of_remote_addresses++;
387 				}
388 			}
389 			SCTP_INP_RUNLOCK(inp);
390 		}
391 		SCTP_INP_INFO_RUNLOCK();
392 		n = (number_of_endpoints + 1) * sizeof(struct xsctp_inpcb) +
393 		    (number_of_local_addresses + number_of_endpoints + number_of_associations) * sizeof(struct xsctp_laddr) +
394 		    (number_of_associations + number_of_endpoints) * sizeof(struct xsctp_tcb) +
395 		    (number_of_remote_addresses + number_of_associations) * sizeof(struct xsctp_raddr);
396 
397 		/* request some more memory than needed */
398 		req->oldidx = (n + n / 8);
399 		return (0);
400 	}
401 	if (req->newptr != USER_ADDR_NULL) {
402 		SCTP_INP_INFO_RUNLOCK();
403 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTP_SYSCTL, EPERM);
404 		return (EPERM);
405 	}
406 	LIST_FOREACH(inp, &SCTP_BASE_INFO(listhead), sctp_list) {
407 		SCTP_INP_RLOCK(inp);
408 		if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) {
409 			/* if its allgone it is being freed - skip it  */
410 			goto skip;
411 		}
412 		xinpcb.last = 0;
413 		xinpcb.local_port = ntohs(inp->sctp_lport);
414 		xinpcb.flags = inp->sctp_flags;
415 		xinpcb.features = inp->sctp_features;
416 		xinpcb.total_sends = inp->total_sends;
417 		xinpcb.total_recvs = inp->total_recvs;
418 		xinpcb.total_nospaces = inp->total_nospaces;
419 		xinpcb.fragmentation_point = inp->sctp_frag_point;
420 		so = inp->sctp_socket;
421 		if ((so == NULL) ||
422 		    (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE)) {
423 			xinpcb.qlen = 0;
424 			xinpcb.maxqlen = 0;
425 		} else {
426 			xinpcb.qlen = so->so_qlen;
427 			xinpcb.maxqlen = so->so_qlimit;
428 		}
429 		SCTP_INP_INCR_REF(inp);
430 		SCTP_INP_RUNLOCK(inp);
431 		SCTP_INP_INFO_RUNLOCK();
432 		error = SYSCTL_OUT(req, &xinpcb, sizeof(struct xsctp_inpcb));
433 		if (error) {
434 			SCTP_INP_DECR_REF(inp);
435 			return (error);
436 		}
437 		SCTP_INP_INFO_RLOCK();
438 		SCTP_INP_RLOCK(inp);
439 		error = copy_out_local_addresses(inp, NULL, req);
440 		if (error) {
441 			SCTP_INP_DECR_REF(inp);
442 			return (error);
443 		}
444 		LIST_FOREACH(stcb, &inp->sctp_asoc_list, sctp_tcblist) {
445 			SCTP_TCB_LOCK(stcb);
446 			atomic_add_int(&stcb->asoc.refcnt, 1);
447 			SCTP_TCB_UNLOCK(stcb);
448 			xstcb.last = 0;
449 			xstcb.local_port = ntohs(inp->sctp_lport);
450 			xstcb.remote_port = ntohs(stcb->rport);
451 			if (stcb->asoc.primary_destination != NULL)
452 				xstcb.primary_addr = stcb->asoc.primary_destination->ro._l_addr;
453 			xstcb.heartbeat_interval = stcb->asoc.heart_beat_delay;
454 			xstcb.state = SCTP_GET_STATE(&stcb->asoc);	/* FIXME */
455 			/* 7.0 does not support these */
456 			xstcb.assoc_id = sctp_get_associd(stcb);
457 			xstcb.peers_rwnd = stcb->asoc.peers_rwnd;
458 			xstcb.in_streams = stcb->asoc.streamincnt;
459 			xstcb.out_streams = stcb->asoc.streamoutcnt;
460 			xstcb.max_nr_retrans = stcb->asoc.overall_error_count;
461 			xstcb.primary_process = 0;	/* not really supported
462 							 * yet */
463 			xstcb.T1_expireries = stcb->asoc.timoinit + stcb->asoc.timocookie;
464 			xstcb.T2_expireries = stcb->asoc.timoshutdown + stcb->asoc.timoshutdownack;
465 			xstcb.retransmitted_tsns = stcb->asoc.marked_retrans;
466 			xstcb.start_time.tv_sec = (uint32_t) stcb->asoc.start_time.tv_sec;
467 			xstcb.start_time.tv_usec = (uint32_t) stcb->asoc.start_time.tv_usec;
468 			xstcb.discontinuity_time.tv_sec = (uint32_t) stcb->asoc.discontinuity_time.tv_sec;
469 			xstcb.discontinuity_time.tv_usec = (uint32_t) stcb->asoc.discontinuity_time.tv_usec;
470 			xstcb.total_sends = stcb->total_sends;
471 			xstcb.total_recvs = stcb->total_recvs;
472 			xstcb.local_tag = stcb->asoc.my_vtag;
473 			xstcb.remote_tag = stcb->asoc.peer_vtag;
474 			xstcb.initial_tsn = stcb->asoc.init_seq_number;
475 			xstcb.highest_tsn = stcb->asoc.sending_seq - 1;
476 			xstcb.cumulative_tsn = stcb->asoc.last_acked_seq;
477 			xstcb.cumulative_tsn_ack = stcb->asoc.cumulative_tsn;
478 			xstcb.mtu = stcb->asoc.smallest_mtu;
479 			xstcb.refcnt = stcb->asoc.refcnt;
480 			SCTP_INP_RUNLOCK(inp);
481 			SCTP_INP_INFO_RUNLOCK();
482 			error = SYSCTL_OUT(req, &xstcb, sizeof(struct xsctp_tcb));
483 			if (error) {
484 				SCTP_INP_DECR_REF(inp);
485 				atomic_subtract_int(&stcb->asoc.refcnt, 1);
486 				return (error);
487 			}
488 			SCTP_INP_INFO_RLOCK();
489 			SCTP_INP_RLOCK(inp);
490 			error = copy_out_local_addresses(inp, stcb, req);
491 			if (error) {
492 				SCTP_INP_DECR_REF(inp);
493 				atomic_subtract_int(&stcb->asoc.refcnt, 1);
494 				return (error);
495 			}
496 			TAILQ_FOREACH(net, &stcb->asoc.nets, sctp_next) {
497 				xraddr.last = 0;
498 				xraddr.address = net->ro._l_addr;
499 				xraddr.active = ((net->dest_state & SCTP_ADDR_REACHABLE) == SCTP_ADDR_REACHABLE);
500 				xraddr.confirmed = ((net->dest_state & SCTP_ADDR_UNCONFIRMED) == 0);
501 				xraddr.heartbeat_enabled = ((net->dest_state & SCTP_ADDR_NOHB) == 0);
502 				xraddr.potentially_failed = ((net->dest_state & SCTP_ADDR_PF) == SCTP_ADDR_PF);
503 				xraddr.rto = net->RTO;
504 				xraddr.max_path_rtx = net->failure_threshold;
505 				xraddr.rtx = net->marked_retrans;
506 				xraddr.error_counter = net->error_count;
507 				xraddr.cwnd = net->cwnd;
508 				xraddr.flight_size = net->flight_size;
509 				xraddr.mtu = net->mtu;
510 				xraddr.rtt = net->rtt / 1000;
511 				xraddr.heartbeat_interval = net->heart_beat_delay;
512 				xraddr.start_time.tv_sec = (uint32_t) net->start_time.tv_sec;
513 				xraddr.start_time.tv_usec = (uint32_t) net->start_time.tv_usec;
514 				SCTP_INP_RUNLOCK(inp);
515 				SCTP_INP_INFO_RUNLOCK();
516 				error = SYSCTL_OUT(req, &xraddr, sizeof(struct xsctp_raddr));
517 				if (error) {
518 					SCTP_INP_DECR_REF(inp);
519 					atomic_subtract_int(&stcb->asoc.refcnt, 1);
520 					return (error);
521 				}
522 				SCTP_INP_INFO_RLOCK();
523 				SCTP_INP_RLOCK(inp);
524 			}
525 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
526 			memset((void *)&xraddr, 0, sizeof(struct xsctp_raddr));
527 			xraddr.last = 1;
528 			SCTP_INP_RUNLOCK(inp);
529 			SCTP_INP_INFO_RUNLOCK();
530 			error = SYSCTL_OUT(req, &xraddr, sizeof(struct xsctp_raddr));
531 			if (error) {
532 				SCTP_INP_DECR_REF(inp);
533 				return (error);
534 			}
535 			SCTP_INP_INFO_RLOCK();
536 			SCTP_INP_RLOCK(inp);
537 		}
538 		SCTP_INP_DECR_REF(inp);
539 		SCTP_INP_RUNLOCK(inp);
540 		SCTP_INP_INFO_RUNLOCK();
541 		memset((void *)&xstcb, 0, sizeof(struct xsctp_tcb));
542 		xstcb.last = 1;
543 		error = SYSCTL_OUT(req, &xstcb, sizeof(struct xsctp_tcb));
544 		if (error) {
545 			return (error);
546 		}
547 skip:
548 		SCTP_INP_INFO_RLOCK();
549 	}
550 	SCTP_INP_INFO_RUNLOCK();
551 
552 	memset((void *)&xinpcb, 0, sizeof(struct xsctp_inpcb));
553 	xinpcb.last = 1;
554 	error = SYSCTL_OUT(req, &xinpcb, sizeof(struct xsctp_inpcb));
555 	return (error);
556 }
557 
558 
559 #define RANGECHK(var, min, max) \
560 	if ((var) < (min)) { (var) = (min); } \
561 	else if ((var) > (max)) { (var) = (max); }
562 
563 static int
564 sysctl_sctp_udp_tunneling_check(SYSCTL_HANDLER_ARGS)
565 {
566 	int error;
567 	uint32_t old_sctp_udp_tunneling_port;
568 
569 	SCTP_INP_INFO_RLOCK();
570 	old_sctp_udp_tunneling_port = SCTP_BASE_SYSCTL(sctp_udp_tunneling_port);
571 	SCTP_INP_INFO_RUNLOCK();
572 	error = sysctl_handle_int(oidp, oidp->oid_arg1, oidp->oid_arg2, req);
573 	if (error == 0) {
574 		RANGECHK(SCTP_BASE_SYSCTL(sctp_udp_tunneling_port), SCTPCTL_UDP_TUNNELING_PORT_MIN, SCTPCTL_UDP_TUNNELING_PORT_MAX);
575 		if (old_sctp_udp_tunneling_port == SCTP_BASE_SYSCTL(sctp_udp_tunneling_port)) {
576 			error = 0;
577 			goto out;
578 		}
579 		SCTP_INP_INFO_WLOCK();
580 		if (old_sctp_udp_tunneling_port) {
581 			sctp_over_udp_stop();
582 		}
583 		if (SCTP_BASE_SYSCTL(sctp_udp_tunneling_port)) {
584 			if (sctp_over_udp_start()) {
585 				SCTP_BASE_SYSCTL(sctp_udp_tunneling_port) = 0;
586 			}
587 		}
588 		SCTP_INP_INFO_WUNLOCK();
589 	}
590 out:
591 	return (error);
592 }
593 
594 
595 static int
596 sysctl_sctp_check(SYSCTL_HANDLER_ARGS)
597 {
598 	int error;
599 
600 	error = sysctl_handle_int(oidp, oidp->oid_arg1, oidp->oid_arg2, req);
601 	if (error == 0) {
602 		RANGECHK(SCTP_BASE_SYSCTL(sctp_sendspace), SCTPCTL_MAXDGRAM_MIN, SCTPCTL_MAXDGRAM_MAX);
603 		RANGECHK(SCTP_BASE_SYSCTL(sctp_recvspace), SCTPCTL_RECVSPACE_MIN, SCTPCTL_RECVSPACE_MAX);
604 		RANGECHK(SCTP_BASE_SYSCTL(sctp_auto_asconf), SCTPCTL_AUTOASCONF_MIN, SCTPCTL_AUTOASCONF_MAX);
605 		RANGECHK(SCTP_BASE_SYSCTL(sctp_ecn_enable), SCTPCTL_ECN_ENABLE_MIN, SCTPCTL_ECN_ENABLE_MAX);
606 		RANGECHK(SCTP_BASE_SYSCTL(sctp_pr_enable), SCTPCTL_PR_ENABLE_MIN, SCTPCTL_PR_ENABLE_MAX);
607 		RANGECHK(SCTP_BASE_SYSCTL(sctp_reconfig_enable), SCTPCTL_RECONFIG_ENABLE_MIN, SCTPCTL_RECONFIG_ENABLE_MAX);
608 		RANGECHK(SCTP_BASE_SYSCTL(sctp_nrsack_enable), SCTPCTL_NRSACK_ENABLE_MIN, SCTPCTL_NRSACK_ENABLE_MAX);
609 		RANGECHK(SCTP_BASE_SYSCTL(sctp_pktdrop_enable), SCTPCTL_PKTDROP_ENABLE_MIN, SCTPCTL_PKTDROP_ENABLE_MAX);
610 		RANGECHK(SCTP_BASE_SYSCTL(sctp_strict_sacks), SCTPCTL_STRICT_SACKS_MIN, SCTPCTL_STRICT_SACKS_MAX);
611 		RANGECHK(SCTP_BASE_SYSCTL(sctp_peer_chunk_oh), SCTPCTL_PEER_CHKOH_MIN, SCTPCTL_PEER_CHKOH_MAX);
612 		RANGECHK(SCTP_BASE_SYSCTL(sctp_max_burst_default), SCTPCTL_MAXBURST_MIN, SCTPCTL_MAXBURST_MAX);
613 		RANGECHK(SCTP_BASE_SYSCTL(sctp_fr_max_burst_default), SCTPCTL_FRMAXBURST_MIN, SCTPCTL_FRMAXBURST_MAX);
614 		RANGECHK(SCTP_BASE_SYSCTL(sctp_max_chunks_on_queue), SCTPCTL_MAXCHUNKS_MIN, SCTPCTL_MAXCHUNKS_MAX);
615 		RANGECHK(SCTP_BASE_SYSCTL(sctp_hashtblsize), SCTPCTL_TCBHASHSIZE_MIN, SCTPCTL_TCBHASHSIZE_MAX);
616 		RANGECHK(SCTP_BASE_SYSCTL(sctp_pcbtblsize), SCTPCTL_PCBHASHSIZE_MIN, SCTPCTL_PCBHASHSIZE_MAX);
617 		RANGECHK(SCTP_BASE_SYSCTL(sctp_min_split_point), SCTPCTL_MIN_SPLIT_POINT_MIN, SCTPCTL_MIN_SPLIT_POINT_MAX);
618 		RANGECHK(SCTP_BASE_SYSCTL(sctp_chunkscale), SCTPCTL_CHUNKSCALE_MIN, SCTPCTL_CHUNKSCALE_MAX);
619 		RANGECHK(SCTP_BASE_SYSCTL(sctp_delayed_sack_time_default), SCTPCTL_DELAYED_SACK_TIME_MIN, SCTPCTL_DELAYED_SACK_TIME_MAX);
620 		RANGECHK(SCTP_BASE_SYSCTL(sctp_sack_freq_default), SCTPCTL_SACK_FREQ_MIN, SCTPCTL_SACK_FREQ_MAX);
621 		RANGECHK(SCTP_BASE_SYSCTL(sctp_system_free_resc_limit), SCTPCTL_SYS_RESOURCE_MIN, SCTPCTL_SYS_RESOURCE_MAX);
622 		RANGECHK(SCTP_BASE_SYSCTL(sctp_asoc_free_resc_limit), SCTPCTL_ASOC_RESOURCE_MIN, SCTPCTL_ASOC_RESOURCE_MAX);
623 		RANGECHK(SCTP_BASE_SYSCTL(sctp_heartbeat_interval_default), SCTPCTL_HEARTBEAT_INTERVAL_MIN, SCTPCTL_HEARTBEAT_INTERVAL_MAX);
624 		RANGECHK(SCTP_BASE_SYSCTL(sctp_pmtu_raise_time_default), SCTPCTL_PMTU_RAISE_TIME_MIN, SCTPCTL_PMTU_RAISE_TIME_MAX);
625 		RANGECHK(SCTP_BASE_SYSCTL(sctp_shutdown_guard_time_default), SCTPCTL_SHUTDOWN_GUARD_TIME_MIN, SCTPCTL_SHUTDOWN_GUARD_TIME_MAX);
626 		RANGECHK(SCTP_BASE_SYSCTL(sctp_secret_lifetime_default), SCTPCTL_SECRET_LIFETIME_MIN, SCTPCTL_SECRET_LIFETIME_MAX);
627 		RANGECHK(SCTP_BASE_SYSCTL(sctp_rto_max_default), SCTPCTL_RTO_MAX_MIN, SCTPCTL_RTO_MAX_MAX);
628 		RANGECHK(SCTP_BASE_SYSCTL(sctp_rto_min_default), SCTPCTL_RTO_MIN_MIN, SCTPCTL_RTO_MIN_MAX);
629 		RANGECHK(SCTP_BASE_SYSCTL(sctp_rto_initial_default), SCTPCTL_RTO_INITIAL_MIN, SCTPCTL_RTO_INITIAL_MAX);
630 		RANGECHK(SCTP_BASE_SYSCTL(sctp_init_rto_max_default), SCTPCTL_INIT_RTO_MAX_MIN, SCTPCTL_INIT_RTO_MAX_MAX);
631 		RANGECHK(SCTP_BASE_SYSCTL(sctp_valid_cookie_life_default), SCTPCTL_VALID_COOKIE_LIFE_MIN, SCTPCTL_VALID_COOKIE_LIFE_MAX);
632 		RANGECHK(SCTP_BASE_SYSCTL(sctp_init_rtx_max_default), SCTPCTL_INIT_RTX_MAX_MIN, SCTPCTL_INIT_RTX_MAX_MAX);
633 		RANGECHK(SCTP_BASE_SYSCTL(sctp_assoc_rtx_max_default), SCTPCTL_ASSOC_RTX_MAX_MIN, SCTPCTL_ASSOC_RTX_MAX_MAX);
634 		RANGECHK(SCTP_BASE_SYSCTL(sctp_path_rtx_max_default), SCTPCTL_PATH_RTX_MAX_MIN, SCTPCTL_PATH_RTX_MAX_MAX);
635 		RANGECHK(SCTP_BASE_SYSCTL(sctp_path_pf_threshold), SCTPCTL_PATH_PF_THRESHOLD_MIN, SCTPCTL_PATH_PF_THRESHOLD_MAX);
636 		RANGECHK(SCTP_BASE_SYSCTL(sctp_add_more_threshold), SCTPCTL_ADD_MORE_ON_OUTPUT_MIN, SCTPCTL_ADD_MORE_ON_OUTPUT_MAX);
637 		RANGECHK(SCTP_BASE_SYSCTL(sctp_nr_incoming_streams_default), SCTPCTL_INCOMING_STREAMS_MIN, SCTPCTL_INCOMING_STREAMS_MAX);
638 		RANGECHK(SCTP_BASE_SYSCTL(sctp_nr_outgoing_streams_default), SCTPCTL_OUTGOING_STREAMS_MIN, SCTPCTL_OUTGOING_STREAMS_MAX);
639 		RANGECHK(SCTP_BASE_SYSCTL(sctp_cmt_on_off), SCTPCTL_CMT_ON_OFF_MIN, SCTPCTL_CMT_ON_OFF_MAX);
640 		RANGECHK(SCTP_BASE_SYSCTL(sctp_cmt_use_dac), SCTPCTL_CMT_USE_DAC_MIN, SCTPCTL_CMT_USE_DAC_MAX);
641 		RANGECHK(SCTP_BASE_SYSCTL(sctp_use_cwnd_based_maxburst), SCTPCTL_CWND_MAXBURST_MIN, SCTPCTL_CWND_MAXBURST_MAX);
642 		RANGECHK(SCTP_BASE_SYSCTL(sctp_nat_friendly), SCTPCTL_NAT_FRIENDLY_MIN, SCTPCTL_NAT_FRIENDLY_MAX);
643 		RANGECHK(SCTP_BASE_SYSCTL(sctp_L2_abc_variable), SCTPCTL_ABC_L_VAR_MIN, SCTPCTL_ABC_L_VAR_MAX);
644 		RANGECHK(SCTP_BASE_SYSCTL(sctp_mbuf_threshold_count), SCTPCTL_MAX_CHAINED_MBUFS_MIN, SCTPCTL_MAX_CHAINED_MBUFS_MAX);
645 		RANGECHK(SCTP_BASE_SYSCTL(sctp_do_drain), SCTPCTL_DO_SCTP_DRAIN_MIN, SCTPCTL_DO_SCTP_DRAIN_MAX);
646 		RANGECHK(SCTP_BASE_SYSCTL(sctp_hb_maxburst), SCTPCTL_HB_MAX_BURST_MIN, SCTPCTL_HB_MAX_BURST_MAX);
647 		RANGECHK(SCTP_BASE_SYSCTL(sctp_abort_if_one_2_one_hits_limit), SCTPCTL_ABORT_AT_LIMIT_MIN, SCTPCTL_ABORT_AT_LIMIT_MAX);
648 		RANGECHK(SCTP_BASE_SYSCTL(sctp_strict_data_order), SCTPCTL_STRICT_DATA_ORDER_MIN, SCTPCTL_STRICT_DATA_ORDER_MAX);
649 		RANGECHK(SCTP_BASE_SYSCTL(sctp_min_residual), SCTPCTL_MIN_RESIDUAL_MIN, SCTPCTL_MIN_RESIDUAL_MAX);
650 		RANGECHK(SCTP_BASE_SYSCTL(sctp_max_retran_chunk), SCTPCTL_MAX_RETRAN_CHUNK_MIN, SCTPCTL_MAX_RETRAN_CHUNK_MAX);
651 		RANGECHK(SCTP_BASE_SYSCTL(sctp_logging_level), SCTPCTL_LOGGING_LEVEL_MIN, SCTPCTL_LOGGING_LEVEL_MAX);
652 		RANGECHK(SCTP_BASE_SYSCTL(sctp_default_cc_module), SCTPCTL_DEFAULT_CC_MODULE_MIN, SCTPCTL_DEFAULT_CC_MODULE_MAX);
653 		RANGECHK(SCTP_BASE_SYSCTL(sctp_default_ss_module), SCTPCTL_DEFAULT_SS_MODULE_MIN, SCTPCTL_DEFAULT_SS_MODULE_MAX);
654 		RANGECHK(SCTP_BASE_SYSCTL(sctp_default_frag_interleave), SCTPCTL_DEFAULT_FRAG_INTERLEAVE_MIN, SCTPCTL_DEFAULT_FRAG_INTERLEAVE_MAX);
655 		RANGECHK(SCTP_BASE_SYSCTL(sctp_vtag_time_wait), SCTPCTL_TIME_WAIT_MIN, SCTPCTL_TIME_WAIT_MAX);
656 		RANGECHK(SCTP_BASE_SYSCTL(sctp_buffer_splitting), SCTPCTL_BUFFER_SPLITTING_MIN, SCTPCTL_BUFFER_SPLITTING_MAX);
657 		RANGECHK(SCTP_BASE_SYSCTL(sctp_initial_cwnd), SCTPCTL_INITIAL_CWND_MIN, SCTPCTL_INITIAL_CWND_MAX);
658 		RANGECHK(SCTP_BASE_SYSCTL(sctp_rttvar_bw), SCTPCTL_RTTVAR_BW_MIN, SCTPCTL_RTTVAR_BW_MAX);
659 		RANGECHK(SCTP_BASE_SYSCTL(sctp_rttvar_rtt), SCTPCTL_RTTVAR_RTT_MIN, SCTPCTL_RTTVAR_RTT_MAX);
660 		RANGECHK(SCTP_BASE_SYSCTL(sctp_rttvar_eqret), SCTPCTL_RTTVAR_EQRET_MIN, SCTPCTL_RTTVAR_EQRET_MAX);
661 		RANGECHK(SCTP_BASE_SYSCTL(sctp_steady_step), SCTPCTL_RTTVAR_STEADYS_MIN, SCTPCTL_RTTVAR_STEADYS_MAX);
662 		RANGECHK(SCTP_BASE_SYSCTL(sctp_use_dccc_ecn), SCTPCTL_RTTVAR_DCCCECN_MIN, SCTPCTL_RTTVAR_DCCCECN_MAX);
663 		RANGECHK(SCTP_BASE_SYSCTL(sctp_mobility_base), SCTPCTL_MOBILITY_BASE_MIN, SCTPCTL_MOBILITY_BASE_MAX);
664 		RANGECHK(SCTP_BASE_SYSCTL(sctp_mobility_fasthandoff), SCTPCTL_MOBILITY_FASTHANDOFF_MIN, SCTPCTL_MOBILITY_FASTHANDOFF_MAX);
665 		RANGECHK(SCTP_BASE_SYSCTL(sctp_enable_sack_immediately), SCTPCTL_SACK_IMMEDIATELY_ENABLE_MIN, SCTPCTL_SACK_IMMEDIATELY_ENABLE_MAX);
666 		RANGECHK(SCTP_BASE_SYSCTL(sctp_inits_include_nat_friendly), SCTPCTL_NAT_FRIENDLY_INITS_MIN, SCTPCTL_NAT_FRIENDLY_INITS_MAX);
667 		RANGECHK(SCTP_BASE_SYSCTL(sctp_blackhole), SCTPCTL_BLACKHOLE_MIN, SCTPCTL_BLACKHOLE_MAX);
668 		RANGECHK(SCTP_BASE_SYSCTL(sctp_diag_info_code), SCTPCTL_DIAG_INFO_CODE_MIN, SCTPCTL_DIAG_INFO_CODE_MAX);
669 
670 #ifdef SCTP_DEBUG
671 		RANGECHK(SCTP_BASE_SYSCTL(sctp_debug_on), SCTPCTL_DEBUG_MIN, SCTPCTL_DEBUG_MAX);
672 #endif
673 #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
674 		RANGECHK(SCTP_BASE_SYSCTL(sctp_output_unlocked), SCTPCTL_OUTPUT_UNLOCKED_MIN, SCTPCTL_OUTPUT_UNLOCKED_MAX);
675 #endif
676 	}
677 	return (error);
678 }
679 
680 static int
681 sysctl_sctp_auth_check(SYSCTL_HANDLER_ARGS)
682 {
683 	int error;
684 
685 	error = sysctl_handle_int(oidp, oidp->oid_arg1, oidp->oid_arg2, req);
686 	if (error == 0) {
687 		if (SCTP_BASE_SYSCTL(sctp_auth_disable) < SCTPCTL_AUTH_DISABLE_MIN) {
688 			SCTP_BASE_SYSCTL(sctp_auth_disable) = SCTPCTL_AUTH_DISABLE_MIN;
689 		}
690 		if (SCTP_BASE_SYSCTL(sctp_auth_disable) > SCTPCTL_AUTH_DISABLE_MAX) {
691 			SCTP_BASE_SYSCTL(sctp_auth_disable) = SCTPCTL_AUTH_DISABLE_MAX;
692 		}
693 		if ((SCTP_BASE_SYSCTL(sctp_auth_disable) == 1) &&
694 		    (SCTP_BASE_SYSCTL(sctp_asconf_enable) == 1)) {
695 			/*
696 			 * You can't disable AUTH with disabling ASCONF
697 			 * first
698 			 */
699 			SCTP_BASE_SYSCTL(sctp_auth_disable) = 0;
700 		}
701 	}
702 	return (error);
703 }
704 
705 static int
706 sysctl_sctp_asconf_check(SYSCTL_HANDLER_ARGS)
707 {
708 	int error;
709 
710 	error = sysctl_handle_int(oidp, oidp->oid_arg1, oidp->oid_arg2, req);
711 	if (error == 0) {
712 		if (SCTP_BASE_SYSCTL(sctp_asconf_enable) < SCTPCTL_ASCONF_ENABLE_MIN) {
713 			SCTP_BASE_SYSCTL(sctp_asconf_enable) = SCTPCTL_ASCONF_ENABLE_MIN;
714 		}
715 		if (SCTP_BASE_SYSCTL(sctp_asconf_enable) > SCTPCTL_ASCONF_ENABLE_MAX) {
716 			SCTP_BASE_SYSCTL(sctp_asconf_enable) = SCTPCTL_ASCONF_ENABLE_MAX;
717 		}
718 		if ((SCTP_BASE_SYSCTL(sctp_asconf_enable) == 1) &&
719 		    (SCTP_BASE_SYSCTL(sctp_auth_disable) == 1)) {
720 			/*
721 			 * You can't enable ASCONF without enabling AUTH
722 			 * first
723 			 */
724 			SCTP_BASE_SYSCTL(sctp_asconf_enable) = 0;
725 		}
726 	}
727 	return (error);
728 }
729 
730 #if defined(__FreeBSD__) && defined(SMP) && defined(SCTP_USE_PERCPU_STAT)
731 static int
732 sysctl_stat_get(SYSCTL_HANDLER_ARGS)
733 {
734 	int cpu, error;
735 	struct sctpstat sb, *sarry, *cpin = NULL;
736 
737 	if ((req->newptr) && (req->newlen == sizeof(struct sctpstat))) {
738 		/*
739 		 * User wants us to clear or at least reset the counters to
740 		 * the specified values.
741 		 */
742 		cpin = (struct sctpstat *)req->newptr;
743 	} else if (req->newptr) {
744 		/* Must be a stat structure */
745 		return (EINVAL);
746 	}
747 	memset(&sb, 0, sizeof(sb));
748 	for (cpu = 0; cpu < mp_maxid; cpu++) {
749 		sarry = &SCTP_BASE_STATS[cpu];
750 		if (sarry->sctps_discontinuitytime.tv_sec > sb.sctps_discontinuitytime.tv_sec) {
751 			sb.sctps_discontinuitytime.tv_sec = sarry->sctps_discontinuitytime.tv_sec;
752 			sb.sctps_discontinuitytime.tv_usec = sarry->sctps_discontinuitytime.tv_usec;
753 		}
754 		sb.sctps_currestab += sarry->sctps_currestab;
755 		sb.sctps_activeestab += sarry->sctps_activeestab;
756 		sb.sctps_restartestab += sarry->sctps_restartestab;
757 		sb.sctps_collisionestab += sarry->sctps_collisionestab;
758 		sb.sctps_passiveestab += sarry->sctps_passiveestab;
759 		sb.sctps_aborted += sarry->sctps_aborted;
760 		sb.sctps_shutdown += sarry->sctps_shutdown;
761 		sb.sctps_outoftheblue += sarry->sctps_outoftheblue;
762 		sb.sctps_checksumerrors += sarry->sctps_checksumerrors;
763 		sb.sctps_outcontrolchunks += sarry->sctps_outcontrolchunks;
764 		sb.sctps_outorderchunks += sarry->sctps_outorderchunks;
765 		sb.sctps_outunorderchunks += sarry->sctps_outunorderchunks;
766 		sb.sctps_incontrolchunks += sarry->sctps_incontrolchunks;
767 		sb.sctps_inorderchunks += sarry->sctps_inorderchunks;
768 		sb.sctps_inunorderchunks += sarry->sctps_inunorderchunks;
769 		sb.sctps_fragusrmsgs += sarry->sctps_fragusrmsgs;
770 		sb.sctps_reasmusrmsgs += sarry->sctps_reasmusrmsgs;
771 		sb.sctps_outpackets += sarry->sctps_outpackets;
772 		sb.sctps_inpackets += sarry->sctps_inpackets;
773 		sb.sctps_recvpackets += sarry->sctps_recvpackets;
774 		sb.sctps_recvdatagrams += sarry->sctps_recvdatagrams;
775 		sb.sctps_recvpktwithdata += sarry->sctps_recvpktwithdata;
776 		sb.sctps_recvsacks += sarry->sctps_recvsacks;
777 		sb.sctps_recvdata += sarry->sctps_recvdata;
778 		sb.sctps_recvdupdata += sarry->sctps_recvdupdata;
779 		sb.sctps_recvheartbeat += sarry->sctps_recvheartbeat;
780 		sb.sctps_recvheartbeatack += sarry->sctps_recvheartbeatack;
781 		sb.sctps_recvecne += sarry->sctps_recvecne;
782 		sb.sctps_recvauth += sarry->sctps_recvauth;
783 		sb.sctps_recvauthmissing += sarry->sctps_recvauthmissing;
784 		sb.sctps_recvivalhmacid += sarry->sctps_recvivalhmacid;
785 		sb.sctps_recvivalkeyid += sarry->sctps_recvivalkeyid;
786 		sb.sctps_recvauthfailed += sarry->sctps_recvauthfailed;
787 		sb.sctps_recvexpress += sarry->sctps_recvexpress;
788 		sb.sctps_recvexpressm += sarry->sctps_recvexpressm;
789 		sb.sctps_recvnocrc += sarry->sctps_recvnocrc;
790 		sb.sctps_recvswcrc += sarry->sctps_recvswcrc;
791 		sb.sctps_recvhwcrc += sarry->sctps_recvhwcrc;
792 		sb.sctps_sendpackets += sarry->sctps_sendpackets;
793 		sb.sctps_sendsacks += sarry->sctps_sendsacks;
794 		sb.sctps_senddata += sarry->sctps_senddata;
795 		sb.sctps_sendretransdata += sarry->sctps_sendretransdata;
796 		sb.sctps_sendfastretrans += sarry->sctps_sendfastretrans;
797 		sb.sctps_sendmultfastretrans += sarry->sctps_sendmultfastretrans;
798 		sb.sctps_sendheartbeat += sarry->sctps_sendheartbeat;
799 		sb.sctps_sendecne += sarry->sctps_sendecne;
800 		sb.sctps_sendauth += sarry->sctps_sendauth;
801 		sb.sctps_senderrors += sarry->sctps_senderrors;
802 		sb.sctps_sendnocrc += sarry->sctps_sendnocrc;
803 		sb.sctps_sendswcrc += sarry->sctps_sendswcrc;
804 		sb.sctps_sendhwcrc += sarry->sctps_sendhwcrc;
805 		sb.sctps_pdrpfmbox += sarry->sctps_pdrpfmbox;
806 		sb.sctps_pdrpfehos += sarry->sctps_pdrpfehos;
807 		sb.sctps_pdrpmbda += sarry->sctps_pdrpmbda;
808 		sb.sctps_pdrpmbct += sarry->sctps_pdrpmbct;
809 		sb.sctps_pdrpbwrpt += sarry->sctps_pdrpbwrpt;
810 		sb.sctps_pdrpcrupt += sarry->sctps_pdrpcrupt;
811 		sb.sctps_pdrpnedat += sarry->sctps_pdrpnedat;
812 		sb.sctps_pdrppdbrk += sarry->sctps_pdrppdbrk;
813 		sb.sctps_pdrptsnnf += sarry->sctps_pdrptsnnf;
814 		sb.sctps_pdrpdnfnd += sarry->sctps_pdrpdnfnd;
815 		sb.sctps_pdrpdiwnp += sarry->sctps_pdrpdiwnp;
816 		sb.sctps_pdrpdizrw += sarry->sctps_pdrpdizrw;
817 		sb.sctps_pdrpbadd += sarry->sctps_pdrpbadd;
818 		sb.sctps_pdrpmark += sarry->sctps_pdrpmark;
819 		sb.sctps_timoiterator += sarry->sctps_timoiterator;
820 		sb.sctps_timodata += sarry->sctps_timodata;
821 		sb.sctps_timowindowprobe += sarry->sctps_timowindowprobe;
822 		sb.sctps_timoinit += sarry->sctps_timoinit;
823 		sb.sctps_timosack += sarry->sctps_timosack;
824 		sb.sctps_timoshutdown += sarry->sctps_timoshutdown;
825 		sb.sctps_timoheartbeat += sarry->sctps_timoheartbeat;
826 		sb.sctps_timocookie += sarry->sctps_timocookie;
827 		sb.sctps_timosecret += sarry->sctps_timosecret;
828 		sb.sctps_timopathmtu += sarry->sctps_timopathmtu;
829 		sb.sctps_timoshutdownack += sarry->sctps_timoshutdownack;
830 		sb.sctps_timoshutdownguard += sarry->sctps_timoshutdownguard;
831 		sb.sctps_timostrmrst += sarry->sctps_timostrmrst;
832 		sb.sctps_timoearlyfr += sarry->sctps_timoearlyfr;
833 		sb.sctps_timoasconf += sarry->sctps_timoasconf;
834 		sb.sctps_timodelprim += sarry->sctps_timodelprim;
835 		sb.sctps_timoautoclose += sarry->sctps_timoautoclose;
836 		sb.sctps_timoassockill += sarry->sctps_timoassockill;
837 		sb.sctps_timoinpkill += sarry->sctps_timoinpkill;
838 		sb.sctps_hdrops += sarry->sctps_hdrops;
839 		sb.sctps_badsum += sarry->sctps_badsum;
840 		sb.sctps_noport += sarry->sctps_noport;
841 		sb.sctps_badvtag += sarry->sctps_badvtag;
842 		sb.sctps_badsid += sarry->sctps_badsid;
843 		sb.sctps_nomem += sarry->sctps_nomem;
844 		sb.sctps_fastretransinrtt += sarry->sctps_fastretransinrtt;
845 		sb.sctps_markedretrans += sarry->sctps_markedretrans;
846 		sb.sctps_naglesent += sarry->sctps_naglesent;
847 		sb.sctps_naglequeued += sarry->sctps_naglequeued;
848 		sb.sctps_maxburstqueued += sarry->sctps_maxburstqueued;
849 		sb.sctps_ifnomemqueued += sarry->sctps_ifnomemqueued;
850 		sb.sctps_windowprobed += sarry->sctps_windowprobed;
851 		sb.sctps_lowlevelerr += sarry->sctps_lowlevelerr;
852 		sb.sctps_lowlevelerrusr += sarry->sctps_lowlevelerrusr;
853 		sb.sctps_datadropchklmt += sarry->sctps_datadropchklmt;
854 		sb.sctps_datadroprwnd += sarry->sctps_datadroprwnd;
855 		sb.sctps_ecnereducedcwnd += sarry->sctps_ecnereducedcwnd;
856 		sb.sctps_vtagexpress += sarry->sctps_vtagexpress;
857 		sb.sctps_vtagbogus += sarry->sctps_vtagbogus;
858 		sb.sctps_primary_randry += sarry->sctps_primary_randry;
859 		sb.sctps_cmt_randry += sarry->sctps_cmt_randry;
860 		sb.sctps_slowpath_sack += sarry->sctps_slowpath_sack;
861 		sb.sctps_wu_sacks_sent += sarry->sctps_wu_sacks_sent;
862 		sb.sctps_sends_with_flags += sarry->sctps_sends_with_flags;
863 		sb.sctps_sends_with_unord += sarry->sctps_sends_with_unord;
864 		sb.sctps_sends_with_eof += sarry->sctps_sends_with_eof;
865 		sb.sctps_sends_with_abort += sarry->sctps_sends_with_abort;
866 		sb.sctps_protocol_drain_calls += sarry->sctps_protocol_drain_calls;
867 		sb.sctps_protocol_drains_done += sarry->sctps_protocol_drains_done;
868 		sb.sctps_read_peeks += sarry->sctps_read_peeks;
869 		sb.sctps_cached_chk += sarry->sctps_cached_chk;
870 		sb.sctps_cached_strmoq += sarry->sctps_cached_strmoq;
871 		sb.sctps_left_abandon += sarry->sctps_left_abandon;
872 		sb.sctps_send_burst_avoid += sarry->sctps_send_burst_avoid;
873 		sb.sctps_send_cwnd_avoid += sarry->sctps_send_cwnd_avoid;
874 		sb.sctps_fwdtsn_map_over += sarry->sctps_fwdtsn_map_over;
875 		if (cpin) {
876 			memcpy(sarry, cpin, sizeof(struct sctpstat));
877 		}
878 	}
879 	error = SYSCTL_OUT(req, &sb, sizeof(sb));
880 	return (error);
881 }
882 
883 #endif
884 
885 #if defined(SCTP_LOCAL_TRACE_BUF)
886 static int
887 sysctl_sctp_cleartrace(SYSCTL_HANDLER_ARGS)
888 {
889 	int error = 0;
890 
891 	memset(&SCTP_BASE_SYSCTL(sctp_log), 0, sizeof(struct sctp_log));
892 	return (error);
893 }
894 
895 #endif
896 
897 
898 /*
899  * sysctl definitions
900  */
901 
902 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, sendspace, CTLTYPE_UINT | CTLFLAG_RW,
903     &SCTP_BASE_SYSCTL(sctp_sendspace), 0, sysctl_sctp_check, "IU",
904     SCTPCTL_MAXDGRAM_DESC);
905 
906 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, recvspace, CTLTYPE_UINT | CTLFLAG_RW,
907     &SCTP_BASE_SYSCTL(sctp_recvspace), 0, sysctl_sctp_check, "IU",
908     SCTPCTL_RECVSPACE_DESC);
909 
910 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, auto_asconf, CTLTYPE_UINT | CTLFLAG_RW,
911     &SCTP_BASE_SYSCTL(sctp_auto_asconf), 0, sysctl_sctp_check, "IU",
912     SCTPCTL_AUTOASCONF_DESC);
913 
914 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, ecn_enable, CTLTYPE_UINT | CTLFLAG_RW,
915     &SCTP_BASE_SYSCTL(sctp_ecn_enable), 0, sysctl_sctp_check, "IU",
916     SCTPCTL_ECN_ENABLE_DESC);
917 
918 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, pr_enable, CTLTYPE_UINT | CTLFLAG_RW,
919     &SCTP_BASE_SYSCTL(sctp_pr_enable), 0, sysctl_sctp_check, "IU",
920     SCTPCTL_PR_ENABLE_DESC);
921 
922 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, auth_disable, CTLTYPE_UINT | CTLFLAG_RW,
923     &SCTP_BASE_SYSCTL(sctp_auth_disable), 0, sysctl_sctp_auth_check, "IU",
924     SCTPCTL_AUTH_DISABLE_DESC);
925 
926 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, asconf_enable, CTLTYPE_UINT | CTLFLAG_RW,
927     &SCTP_BASE_SYSCTL(sctp_asconf_enable), 0, sysctl_sctp_asconf_check, "IU",
928     SCTPCTL_ASCONF_ENABLE_DESC);
929 
930 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, reconfig_enable, CTLTYPE_UINT | CTLFLAG_RW,
931     &SCTP_BASE_SYSCTL(sctp_reconfig_enable), 0, sysctl_sctp_check, "IU",
932     SCTPCTL_RECONFIG_ENABLE_DESC);
933 
934 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, nrsack_enable, CTLTYPE_UINT | CTLFLAG_RW,
935     &SCTP_BASE_SYSCTL(sctp_nrsack_enable), 0, sysctl_sctp_check, "IU",
936     SCTPCTL_NRSACK_ENABLE_DESC);
937 
938 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, pktdrop_enable, CTLTYPE_UINT | CTLFLAG_RW,
939     &SCTP_BASE_SYSCTL(sctp_pktdrop_enable), 0, sysctl_sctp_check, "IU",
940     SCTPCTL_PKTDROP_ENABLE_DESC);
941 
942 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, strict_sacks, CTLTYPE_UINT | CTLFLAG_RW,
943     &SCTP_BASE_SYSCTL(sctp_strict_sacks), 0, sysctl_sctp_check, "IU",
944     SCTPCTL_STRICT_SACKS_DESC);
945 
946 
947 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, peer_chkoh, CTLTYPE_UINT | CTLFLAG_RW,
948     &SCTP_BASE_SYSCTL(sctp_peer_chunk_oh), 0, sysctl_sctp_check, "IU",
949     SCTPCTL_PEER_CHKOH_DESC);
950 
951 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, maxburst, CTLTYPE_UINT | CTLFLAG_RW,
952     &SCTP_BASE_SYSCTL(sctp_max_burst_default), 0, sysctl_sctp_check, "IU",
953     SCTPCTL_MAXBURST_DESC);
954 
955 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, fr_maxburst, CTLTYPE_UINT | CTLFLAG_RW,
956     &SCTP_BASE_SYSCTL(sctp_fr_max_burst_default), 0, sysctl_sctp_check, "IU",
957     SCTPCTL_FRMAXBURST_DESC);
958 
959 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, maxchunks, CTLTYPE_UINT | CTLFLAG_RW,
960     &SCTP_BASE_SYSCTL(sctp_max_chunks_on_queue), 0, sysctl_sctp_check, "IU",
961     SCTPCTL_MAXCHUNKS_DESC);
962 
963 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, tcbhashsize, CTLTYPE_UINT | CTLFLAG_RW,
964     &SCTP_BASE_SYSCTL(sctp_hashtblsize), 0, sysctl_sctp_check, "IU",
965     SCTPCTL_TCBHASHSIZE_DESC);
966 
967 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, pcbhashsize, CTLTYPE_UINT | CTLFLAG_RW,
968     &SCTP_BASE_SYSCTL(sctp_pcbtblsize), 0, sysctl_sctp_check, "IU",
969     SCTPCTL_PCBHASHSIZE_DESC);
970 
971 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, min_split_point, CTLTYPE_UINT | CTLFLAG_RW,
972     &SCTP_BASE_SYSCTL(sctp_min_split_point), 0, sysctl_sctp_check, "IU",
973     SCTPCTL_MIN_SPLIT_POINT_DESC);
974 
975 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, chunkscale, CTLTYPE_UINT | CTLFLAG_RW,
976     &SCTP_BASE_SYSCTL(sctp_chunkscale), 0, sysctl_sctp_check, "IU",
977     SCTPCTL_CHUNKSCALE_DESC);
978 
979 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, delayed_sack_time, CTLTYPE_UINT | CTLFLAG_RW,
980     &SCTP_BASE_SYSCTL(sctp_delayed_sack_time_default), 0, sysctl_sctp_check, "IU",
981     SCTPCTL_DELAYED_SACK_TIME_DESC);
982 
983 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, sack_freq, CTLTYPE_UINT | CTLFLAG_RW,
984     &SCTP_BASE_SYSCTL(sctp_sack_freq_default), 0, sysctl_sctp_check, "IU",
985     SCTPCTL_SACK_FREQ_DESC);
986 
987 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, sys_resource, CTLTYPE_UINT | CTLFLAG_RW,
988     &SCTP_BASE_SYSCTL(sctp_system_free_resc_limit), 0, sysctl_sctp_check, "IU",
989     SCTPCTL_SYS_RESOURCE_DESC);
990 
991 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, asoc_resource, CTLTYPE_UINT | CTLFLAG_RW,
992     &SCTP_BASE_SYSCTL(sctp_asoc_free_resc_limit), 0, sysctl_sctp_check, "IU",
993     SCTPCTL_ASOC_RESOURCE_DESC);
994 
995 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, heartbeat_interval, CTLTYPE_UINT | CTLFLAG_RW,
996     &SCTP_BASE_SYSCTL(sctp_heartbeat_interval_default), 0, sysctl_sctp_check, "IU",
997     SCTPCTL_HEARTBEAT_INTERVAL_DESC);
998 
999 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, pmtu_raise_time, CTLTYPE_UINT | CTLFLAG_RW,
1000     &SCTP_BASE_SYSCTL(sctp_pmtu_raise_time_default), 0, sysctl_sctp_check, "IU",
1001     SCTPCTL_PMTU_RAISE_TIME_DESC);
1002 
1003 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, shutdown_guard_time, CTLTYPE_UINT | CTLFLAG_RW,
1004     &SCTP_BASE_SYSCTL(sctp_shutdown_guard_time_default), 0, sysctl_sctp_check, "IU",
1005     SCTPCTL_SHUTDOWN_GUARD_TIME_DESC);
1006 
1007 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, secret_lifetime, CTLTYPE_UINT | CTLFLAG_RW,
1008     &SCTP_BASE_SYSCTL(sctp_secret_lifetime_default), 0, sysctl_sctp_check, "IU",
1009     SCTPCTL_SECRET_LIFETIME_DESC);
1010 
1011 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, rto_max, CTLTYPE_UINT | CTLFLAG_RW,
1012     &SCTP_BASE_SYSCTL(sctp_rto_max_default), 0, sysctl_sctp_check, "IU",
1013     SCTPCTL_RTO_MAX_DESC);
1014 
1015 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, rto_min, CTLTYPE_UINT | CTLFLAG_RW,
1016     &SCTP_BASE_SYSCTL(sctp_rto_min_default), 0, sysctl_sctp_check, "IU",
1017     SCTPCTL_RTO_MIN_DESC);
1018 
1019 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, rto_initial, CTLTYPE_UINT | CTLFLAG_RW,
1020     &SCTP_BASE_SYSCTL(sctp_rto_initial_default), 0, sysctl_sctp_check, "IU",
1021     SCTPCTL_RTO_INITIAL_DESC);
1022 
1023 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, init_rto_max, CTLTYPE_UINT | CTLFLAG_RW,
1024     &SCTP_BASE_SYSCTL(sctp_init_rto_max_default), 0, sysctl_sctp_check, "IU",
1025     SCTPCTL_INIT_RTO_MAX_DESC);
1026 
1027 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, valid_cookie_life, CTLTYPE_UINT | CTLFLAG_RW,
1028     &SCTP_BASE_SYSCTL(sctp_valid_cookie_life_default), 0, sysctl_sctp_check, "IU",
1029     SCTPCTL_VALID_COOKIE_LIFE_DESC);
1030 
1031 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, init_rtx_max, CTLTYPE_UINT | CTLFLAG_RW,
1032     &SCTP_BASE_SYSCTL(sctp_init_rtx_max_default), 0, sysctl_sctp_check, "IU",
1033     SCTPCTL_INIT_RTX_MAX_DESC);
1034 
1035 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, assoc_rtx_max, CTLTYPE_UINT | CTLFLAG_RW,
1036     &SCTP_BASE_SYSCTL(sctp_assoc_rtx_max_default), 0, sysctl_sctp_check, "IU",
1037     SCTPCTL_ASSOC_RTX_MAX_DESC);
1038 
1039 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, path_rtx_max, CTLTYPE_UINT | CTLFLAG_RW,
1040     &SCTP_BASE_SYSCTL(sctp_path_rtx_max_default), 0, sysctl_sctp_check, "IU",
1041     SCTPCTL_PATH_RTX_MAX_DESC);
1042 
1043 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, path_pf_threshold, CTLTYPE_UINT | CTLFLAG_RW,
1044     &SCTP_BASE_SYSCTL(sctp_path_pf_threshold), 0, sysctl_sctp_check, "IU",
1045     SCTPCTL_PATH_PF_THRESHOLD_DESC);
1046 
1047 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, add_more_on_output, CTLTYPE_UINT | CTLFLAG_RW,
1048     &SCTP_BASE_SYSCTL(sctp_add_more_threshold), 0, sysctl_sctp_check, "IU",
1049     SCTPCTL_ADD_MORE_ON_OUTPUT_DESC);
1050 
1051 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, incoming_streams, CTLTYPE_UINT | CTLFLAG_RW,
1052     &SCTP_BASE_SYSCTL(sctp_nr_incoming_streams_default), 0, sysctl_sctp_check, "IU",
1053     SCTPCTL_INCOMING_STREAMS_DESC);
1054 
1055 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, outgoing_streams, CTLTYPE_UINT | CTLFLAG_RW,
1056     &SCTP_BASE_SYSCTL(sctp_nr_outgoing_streams_default), 0, sysctl_sctp_check, "IU",
1057     SCTPCTL_OUTGOING_STREAMS_DESC);
1058 
1059 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, cmt_on_off, CTLTYPE_UINT | CTLFLAG_RW,
1060     &SCTP_BASE_SYSCTL(sctp_cmt_on_off), 0, sysctl_sctp_check, "IU",
1061     SCTPCTL_CMT_ON_OFF_DESC);
1062 
1063 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, cmt_use_dac, CTLTYPE_UINT | CTLFLAG_RW,
1064     &SCTP_BASE_SYSCTL(sctp_cmt_use_dac), 0, sysctl_sctp_check, "IU",
1065     SCTPCTL_CMT_USE_DAC_DESC);
1066 
1067 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, cwnd_maxburst, CTLTYPE_UINT | CTLFLAG_RW,
1068     &SCTP_BASE_SYSCTL(sctp_use_cwnd_based_maxburst), 0, sysctl_sctp_check, "IU",
1069     SCTPCTL_CWND_MAXBURST_DESC);
1070 
1071 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, nat_friendly, CTLTYPE_UINT | CTLFLAG_RW,
1072     &SCTP_BASE_SYSCTL(sctp_nat_friendly), 0, sysctl_sctp_check, "IU",
1073     SCTPCTL_NAT_FRIENDLY_DESC);
1074 
1075 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, abc_l_var, CTLTYPE_UINT | CTLFLAG_RW,
1076     &SCTP_BASE_SYSCTL(sctp_L2_abc_variable), 0, sysctl_sctp_check, "IU",
1077     SCTPCTL_ABC_L_VAR_DESC);
1078 
1079 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, max_chained_mbufs, CTLTYPE_UINT | CTLFLAG_RW,
1080     &SCTP_BASE_SYSCTL(sctp_mbuf_threshold_count), 0, sysctl_sctp_check, "IU",
1081     SCTPCTL_MAX_CHAINED_MBUFS_DESC);
1082 
1083 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, do_sctp_drain, CTLTYPE_UINT | CTLFLAG_RW,
1084     &SCTP_BASE_SYSCTL(sctp_do_drain), 0, sysctl_sctp_check, "IU",
1085     SCTPCTL_DO_SCTP_DRAIN_DESC);
1086 
1087 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, hb_max_burst, CTLTYPE_UINT | CTLFLAG_RW,
1088     &SCTP_BASE_SYSCTL(sctp_hb_maxburst), 0, sysctl_sctp_check, "IU",
1089     SCTPCTL_HB_MAX_BURST_DESC);
1090 
1091 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, abort_at_limit, CTLTYPE_UINT | CTLFLAG_RW,
1092     &SCTP_BASE_SYSCTL(sctp_abort_if_one_2_one_hits_limit), 0, sysctl_sctp_check, "IU",
1093     SCTPCTL_ABORT_AT_LIMIT_DESC);
1094 
1095 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, strict_data_order, CTLTYPE_UINT | CTLFLAG_RW,
1096     &SCTP_BASE_SYSCTL(sctp_strict_data_order), 0, sysctl_sctp_check, "IU",
1097     SCTPCTL_STRICT_DATA_ORDER_DESC);
1098 
1099 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, min_residual, CTLTYPE_UINT | CTLFLAG_RW,
1100     &SCTP_BASE_SYSCTL(sctp_min_residual), 0, sysctl_sctp_check, "IU",
1101     SCTPCTL_MIN_RESIDUAL_DESC);
1102 
1103 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, max_retran_chunk, CTLTYPE_UINT | CTLFLAG_RW,
1104     &SCTP_BASE_SYSCTL(sctp_max_retran_chunk), 0, sysctl_sctp_check, "IU",
1105     SCTPCTL_MAX_RETRAN_CHUNK_DESC);
1106 
1107 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, log_level, CTLTYPE_UINT | CTLFLAG_RW,
1108     &SCTP_BASE_SYSCTL(sctp_logging_level), 0, sysctl_sctp_check, "IU",
1109     SCTPCTL_LOGGING_LEVEL_DESC);
1110 
1111 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, default_cc_module, CTLTYPE_UINT | CTLFLAG_RW,
1112     &SCTP_BASE_SYSCTL(sctp_default_cc_module), 0, sysctl_sctp_check, "IU",
1113     SCTPCTL_DEFAULT_CC_MODULE_DESC);
1114 
1115 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, default_ss_module, CTLTYPE_UINT | CTLFLAG_RW,
1116     &SCTP_BASE_SYSCTL(sctp_default_ss_module), 0, sysctl_sctp_check, "IU",
1117     SCTPCTL_DEFAULT_SS_MODULE_DESC);
1118 
1119 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, default_frag_interleave, CTLTYPE_UINT | CTLFLAG_RW,
1120     &SCTP_BASE_SYSCTL(sctp_default_frag_interleave), 0, sysctl_sctp_check, "IU",
1121     SCTPCTL_DEFAULT_FRAG_INTERLEAVE_DESC);
1122 
1123 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, mobility_base, CTLTYPE_UINT | CTLFLAG_RW,
1124     &SCTP_BASE_SYSCTL(sctp_mobility_base), 0, sysctl_sctp_check, "IU",
1125     SCTPCTL_MOBILITY_BASE_DESC);
1126 
1127 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, mobility_fasthandoff, CTLTYPE_UINT | CTLFLAG_RW,
1128     &SCTP_BASE_SYSCTL(sctp_mobility_fasthandoff), 0, sysctl_sctp_check, "IU",
1129     SCTPCTL_MOBILITY_FASTHANDOFF_DESC);
1130 
1131 #if defined(SCTP_LOCAL_TRACE_BUF)
1132 SYSCTL_VNET_STRUCT(_net_inet_sctp, OID_AUTO, log, CTLFLAG_RD,
1133     &SCTP_BASE_SYSCTL(sctp_log), sctp_log,
1134     "SCTP logging (struct sctp_log)");
1135 
1136 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, clear_trace, CTLTYPE_UINT | CTLFLAG_RW,
1137     &SCTP_BASE_SYSCTL(sctp_log), 0, sysctl_sctp_cleartrace, "IU",
1138     "Clear SCTP Logging buffer");
1139 #endif
1140 
1141 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, udp_tunneling_port, CTLTYPE_UINT | CTLFLAG_RW,
1142     &SCTP_BASE_SYSCTL(sctp_udp_tunneling_port), 0, sysctl_sctp_udp_tunneling_check, "IU",
1143     SCTPCTL_UDP_TUNNELING_PORT_DESC);
1144 
1145 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, enable_sack_immediately, CTLTYPE_UINT | CTLFLAG_RW,
1146     &SCTP_BASE_SYSCTL(sctp_enable_sack_immediately), 0, sysctl_sctp_check, "IU",
1147     SCTPCTL_SACK_IMMEDIATELY_ENABLE_DESC);
1148 
1149 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, nat_friendly_init, CTLTYPE_UINT | CTLFLAG_RW,
1150     &SCTP_BASE_SYSCTL(sctp_inits_include_nat_friendly), 0, sysctl_sctp_check, "IU",
1151     SCTPCTL_NAT_FRIENDLY_INITS_DESC);
1152 
1153 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, vtag_time_wait, CTLTYPE_UINT | CTLFLAG_RW,
1154     &SCTP_BASE_SYSCTL(sctp_vtag_time_wait), 0, sysctl_sctp_check, "IU",
1155     SCTPCTL_TIME_WAIT_DESC);
1156 
1157 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, buffer_splitting, CTLTYPE_UINT | CTLFLAG_RW,
1158     &SCTP_BASE_SYSCTL(sctp_buffer_splitting), 0, sysctl_sctp_check, "IU",
1159     SCTPCTL_BUFFER_SPLITTING_DESC);
1160 
1161 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, initial_cwnd, CTLTYPE_UINT | CTLFLAG_RW,
1162     &SCTP_BASE_SYSCTL(sctp_initial_cwnd), 0, sysctl_sctp_check, "IU",
1163     SCTPCTL_INITIAL_CWND_DESC);
1164 
1165 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, rttvar_bw, CTLTYPE_UINT | CTLFLAG_RW,
1166     &SCTP_BASE_SYSCTL(sctp_rttvar_bw), 0, sysctl_sctp_check, "IU",
1167     SCTPCTL_RTTVAR_BW_DESC);
1168 
1169 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, rttvar_rtt, CTLTYPE_UINT | CTLFLAG_RW,
1170     &SCTP_BASE_SYSCTL(sctp_rttvar_rtt), 0, sysctl_sctp_check, "IU",
1171     SCTPCTL_RTTVAR_RTT_DESC);
1172 
1173 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, rttvar_eqret, CTLTYPE_UINT | CTLFLAG_RW,
1174     &SCTP_BASE_SYSCTL(sctp_rttvar_eqret), 0, sysctl_sctp_check, "IU",
1175     SCTPCTL_RTTVAR_EQRET_DESC);
1176 
1177 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, rttvar_steady_step, CTLTYPE_UINT | CTLFLAG_RW,
1178     &SCTP_BASE_SYSCTL(sctp_steady_step), 0, sysctl_sctp_check, "IU",
1179     SCTPCTL_RTTVAR_STEADYS_DESC);
1180 
1181 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, use_dcccecn, CTLTYPE_UINT | CTLFLAG_RW,
1182     &SCTP_BASE_SYSCTL(sctp_use_dccc_ecn), 0, sysctl_sctp_check, "IU",
1183     SCTPCTL_RTTVAR_DCCCECN_DESC);
1184 
1185 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, blackhole, CTLTYPE_UINT | CTLFLAG_RW,
1186     &SCTP_BASE_SYSCTL(sctp_blackhole), 0, sysctl_sctp_check, "IU",
1187     SCTPCTL_BLACKHOLE_DESC);
1188 
1189 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, diag_info_code, CTLTYPE_UINT | CTLFLAG_RW,
1190     &SCTP_BASE_SYSCTL(sctp_diag_info_code), 0, sysctl_sctp_check, "IU",
1191     SCTPCTL_DIAG_INFO_CODE_DESC);
1192 
1193 #ifdef SCTP_DEBUG
1194 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, debug, CTLTYPE_UINT | CTLFLAG_RW,
1195     &SCTP_BASE_SYSCTL(sctp_debug_on), 0, sysctl_sctp_check, "IU",
1196     SCTPCTL_DEBUG_DESC);
1197 #endif
1198 
1199 
1200 #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
1201 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, output_unlocked, CTLTYPE_UINT | CTLFLAG_RW,
1202     &SCTP_BASE_SYSCTL(sctp_output_unlocked), 0, sysctl_sctp_check, "IU",
1203     SCTPCTL_OUTPUT_UNLOCKED_DESC);
1204 #endif
1205 
1206 #if defined(__FreeBSD__) && defined(SMP) && defined(SCTP_USE_PERCPU_STAT)
1207 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, stats,
1208     CTLTYPE_STRUCT | CTLFLAG_RW,
1209     0, 0, sysctl_stat_get, "S,sctpstat",
1210     "SCTP statistics (struct sctp_stat)");
1211 #else
1212 SYSCTL_VNET_STRUCT(_net_inet_sctp, OID_AUTO, stats, CTLFLAG_RW,
1213     &SCTP_BASE_STATS_SYSCTL, sctpstat,
1214     "SCTP statistics (struct sctp_stat)");
1215 #endif
1216 
1217 SYSCTL_VNET_PROC(_net_inet_sctp, OID_AUTO, assoclist, CTLTYPE_OPAQUE | CTLFLAG_RD,
1218     0, 0, sctp_assoclist,
1219     "S,xassoc", "List of active SCTP associations");
1220