xref: /freebsd/sys/netinet/sctputil.c (revision 0e13104de6223fb6ee0c5699d0eea37384b98c11)
1f8829a4aSRandall Stewart /*-
2830d754dSRandall Stewart  * Copyright (c) 2001-2008, by Cisco Systems, Inc. All rights reserved.
3f8829a4aSRandall Stewart  *
4f8829a4aSRandall Stewart  * Redistribution and use in source and binary forms, with or without
5f8829a4aSRandall Stewart  * modification, are permitted provided that the following conditions are met:
6f8829a4aSRandall Stewart  *
7f8829a4aSRandall Stewart  * a) Redistributions of source code must retain the above copyright notice,
8f8829a4aSRandall Stewart  *   this list of conditions and the following disclaimer.
9f8829a4aSRandall Stewart  *
10f8829a4aSRandall Stewart  * b) Redistributions in binary form must reproduce the above copyright
11f8829a4aSRandall Stewart  *    notice, this list of conditions and the following disclaimer in
12f8829a4aSRandall Stewart  *   the documentation and/or other materials provided with the distribution.
13f8829a4aSRandall Stewart  *
14f8829a4aSRandall Stewart  * c) Neither the name of Cisco Systems, Inc. nor the names of its
15f8829a4aSRandall Stewart  *    contributors may be used to endorse or promote products derived
16f8829a4aSRandall Stewart  *    from this software without specific prior written permission.
17f8829a4aSRandall Stewart  *
18f8829a4aSRandall Stewart  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
19f8829a4aSRandall Stewart  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
20f8829a4aSRandall Stewart  * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
21f8829a4aSRandall Stewart  * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
22f8829a4aSRandall Stewart  * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
23f8829a4aSRandall Stewart  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
24f8829a4aSRandall Stewart  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
25f8829a4aSRandall Stewart  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
26f8829a4aSRandall Stewart  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
27f8829a4aSRandall Stewart  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
28f8829a4aSRandall Stewart  * THE POSSIBILITY OF SUCH DAMAGE.
29f8829a4aSRandall Stewart  */
30f8829a4aSRandall Stewart 
31f8829a4aSRandall Stewart /* $KAME: sctputil.c,v 1.37 2005/03/07 23:26:09 itojun Exp $	 */
32f8829a4aSRandall Stewart 
33f8829a4aSRandall Stewart #include <sys/cdefs.h>
34f8829a4aSRandall Stewart __FBSDID("$FreeBSD$");
35f8829a4aSRandall Stewart 
36f8829a4aSRandall Stewart #include <netinet/sctp_os.h>
37f8829a4aSRandall Stewart #include <netinet/sctp_pcb.h>
38f8829a4aSRandall Stewart #include <netinet/sctputil.h>
39f8829a4aSRandall Stewart #include <netinet/sctp_var.h>
4042551e99SRandall Stewart #include <netinet/sctp_sysctl.h>
41f8829a4aSRandall Stewart #ifdef INET6
42f8829a4aSRandall Stewart #endif
43f8829a4aSRandall Stewart #include <netinet/sctp_header.h>
44f8829a4aSRandall Stewart #include <netinet/sctp_output.h>
45f8829a4aSRandall Stewart #include <netinet/sctp_uio.h>
46f8829a4aSRandall Stewart #include <netinet/sctp_timer.h>
47f8829a4aSRandall Stewart #include <netinet/sctp_indata.h>/* for sctp_deliver_data() */
48f8829a4aSRandall Stewart #include <netinet/sctp_auth.h>
49f8829a4aSRandall Stewart #include <netinet/sctp_asconf.h>
50b54d3a6cSRandall Stewart #include <netinet/sctp_cc_functions.h>
51f8829a4aSRandall Stewart 
52f8829a4aSRandall Stewart #define NUMBER_OF_MTU_SIZES 18
53f8829a4aSRandall Stewart 
54f8829a4aSRandall Stewart 
55b9e7085aSRandall Stewart #ifndef KTR_SCTP
56b9e7085aSRandall Stewart #define KTR_SCTP KTR_SUBSYS
5780fefe0aSRandall Stewart #endif
58f8829a4aSRandall Stewart 
59f8829a4aSRandall Stewart void
60f8829a4aSRandall Stewart sctp_sblog(struct sockbuf *sb,
61f8829a4aSRandall Stewart     struct sctp_tcb *stcb, int from, int incr)
62f8829a4aSRandall Stewart {
6380fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
64f8829a4aSRandall Stewart 
6580fefe0aSRandall Stewart 	sctp_clog.x.sb.stcb = stcb;
6680fefe0aSRandall Stewart 	sctp_clog.x.sb.so_sbcc = sb->sb_cc;
67f8829a4aSRandall Stewart 	if (stcb)
6880fefe0aSRandall Stewart 		sctp_clog.x.sb.stcb_sbcc = stcb->asoc.sb_cc;
69f8829a4aSRandall Stewart 	else
7080fefe0aSRandall Stewart 		sctp_clog.x.sb.stcb_sbcc = 0;
7180fefe0aSRandall Stewart 	sctp_clog.x.sb.incr = incr;
72c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
7380fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_SB,
7480fefe0aSRandall Stewart 	    from,
7580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
7680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
7780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
7880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
79f8829a4aSRandall Stewart }
80f8829a4aSRandall Stewart 
81f8829a4aSRandall Stewart void
82f8829a4aSRandall Stewart sctp_log_closing(struct sctp_inpcb *inp, struct sctp_tcb *stcb, int16_t loc)
83f8829a4aSRandall Stewart {
8480fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
85f8829a4aSRandall Stewart 
8680fefe0aSRandall Stewart 	sctp_clog.x.close.inp = (void *)inp;
8780fefe0aSRandall Stewart 	sctp_clog.x.close.sctp_flags = inp->sctp_flags;
88f8829a4aSRandall Stewart 	if (stcb) {
8980fefe0aSRandall Stewart 		sctp_clog.x.close.stcb = (void *)stcb;
9080fefe0aSRandall Stewart 		sctp_clog.x.close.state = (uint16_t) stcb->asoc.state;
91f8829a4aSRandall Stewart 	} else {
9280fefe0aSRandall Stewart 		sctp_clog.x.close.stcb = 0;
9380fefe0aSRandall Stewart 		sctp_clog.x.close.state = 0;
94f8829a4aSRandall Stewart 	}
9580fefe0aSRandall Stewart 	sctp_clog.x.close.loc = loc;
96c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
9780fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_CLOSE,
9880fefe0aSRandall Stewart 	    0,
9980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
10080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
10180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
10280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
103f8829a4aSRandall Stewart }
104f8829a4aSRandall Stewart 
105f8829a4aSRandall Stewart 
106f8829a4aSRandall Stewart void
107f8829a4aSRandall Stewart rto_logging(struct sctp_nets *net, int from)
108f8829a4aSRandall Stewart {
10980fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
110f8829a4aSRandall Stewart 
111bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
11280fefe0aSRandall Stewart 	sctp_clog.x.rto.net = (void *)net;
11380fefe0aSRandall Stewart 	sctp_clog.x.rto.rtt = net->prev_rtt;
114c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
11580fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RTT,
11680fefe0aSRandall Stewart 	    from,
11780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
11880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
11980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
12080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
12180fefe0aSRandall Stewart 
122f8829a4aSRandall Stewart }
123f8829a4aSRandall Stewart 
124f8829a4aSRandall Stewart void
1256a91f103SRandall Stewart sctp_log_strm_del_alt(struct sctp_tcb *stcb, uint32_t tsn, uint16_t sseq, uint16_t stream, int from)
126f8829a4aSRandall Stewart {
12780fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
128f8829a4aSRandall Stewart 
12980fefe0aSRandall Stewart 	sctp_clog.x.strlog.stcb = stcb;
13080fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_tsn = tsn;
13180fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_sseq = sseq;
13280fefe0aSRandall Stewart 	sctp_clog.x.strlog.e_tsn = 0;
13380fefe0aSRandall Stewart 	sctp_clog.x.strlog.e_sseq = 0;
13480fefe0aSRandall Stewart 	sctp_clog.x.strlog.strm = stream;
135c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
13680fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_STRM,
13780fefe0aSRandall Stewart 	    from,
13880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
13980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
14080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
14180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
14280fefe0aSRandall Stewart 
143f8829a4aSRandall Stewart }
144f8829a4aSRandall Stewart 
145f8829a4aSRandall Stewart void
146f8829a4aSRandall Stewart sctp_log_nagle_event(struct sctp_tcb *stcb, int action)
147f8829a4aSRandall Stewart {
14880fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
149f8829a4aSRandall Stewart 
15080fefe0aSRandall Stewart 	sctp_clog.x.nagle.stcb = (void *)stcb;
15180fefe0aSRandall Stewart 	sctp_clog.x.nagle.total_flight = stcb->asoc.total_flight;
15280fefe0aSRandall Stewart 	sctp_clog.x.nagle.total_in_queue = stcb->asoc.total_output_queue_size;
15380fefe0aSRandall Stewart 	sctp_clog.x.nagle.count_in_queue = stcb->asoc.chunks_on_out_queue;
15480fefe0aSRandall Stewart 	sctp_clog.x.nagle.count_in_flight = stcb->asoc.total_flight_count;
155c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
15680fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_NAGLE,
15780fefe0aSRandall Stewart 	    action,
15880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
15980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
16080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
16180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
162f8829a4aSRandall Stewart }
163f8829a4aSRandall Stewart 
164f8829a4aSRandall Stewart 
165f8829a4aSRandall Stewart void
166f8829a4aSRandall Stewart sctp_log_sack(uint32_t old_cumack, uint32_t cumack, uint32_t tsn, uint16_t gaps, uint16_t dups, int from)
167f8829a4aSRandall Stewart {
16880fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
169f8829a4aSRandall Stewart 
17080fefe0aSRandall Stewart 	sctp_clog.x.sack.cumack = cumack;
17180fefe0aSRandall Stewart 	sctp_clog.x.sack.oldcumack = old_cumack;
17280fefe0aSRandall Stewart 	sctp_clog.x.sack.tsn = tsn;
17380fefe0aSRandall Stewart 	sctp_clog.x.sack.numGaps = gaps;
17480fefe0aSRandall Stewart 	sctp_clog.x.sack.numDups = dups;
175c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
17680fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_SACK,
17780fefe0aSRandall Stewart 	    from,
17880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
17980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
18080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
18180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
182f8829a4aSRandall Stewart }
183f8829a4aSRandall Stewart 
184f8829a4aSRandall Stewart void
185f8829a4aSRandall Stewart sctp_log_map(uint32_t map, uint32_t cum, uint32_t high, int from)
186f8829a4aSRandall Stewart {
18780fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
188f8829a4aSRandall Stewart 
189bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
19080fefe0aSRandall Stewart 	sctp_clog.x.map.base = map;
19180fefe0aSRandall Stewart 	sctp_clog.x.map.cum = cum;
19280fefe0aSRandall Stewart 	sctp_clog.x.map.high = high;
193c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
19480fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MAP,
19580fefe0aSRandall Stewart 	    from,
19680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
19780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
19880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
19980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
200f8829a4aSRandall Stewart }
201f8829a4aSRandall Stewart 
202f8829a4aSRandall Stewart void
203f8829a4aSRandall Stewart sctp_log_fr(uint32_t biggest_tsn, uint32_t biggest_new_tsn, uint32_t tsn,
204f8829a4aSRandall Stewart     int from)
205f8829a4aSRandall Stewart {
20680fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
207f8829a4aSRandall Stewart 
208bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
20980fefe0aSRandall Stewart 	sctp_clog.x.fr.largest_tsn = biggest_tsn;
21080fefe0aSRandall Stewart 	sctp_clog.x.fr.largest_new_tsn = biggest_new_tsn;
21180fefe0aSRandall Stewart 	sctp_clog.x.fr.tsn = tsn;
212c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
21380fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_FR,
21480fefe0aSRandall Stewart 	    from,
21580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
21680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
21780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
21880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
21980fefe0aSRandall Stewart 
220f8829a4aSRandall Stewart }
221f8829a4aSRandall Stewart 
222f8829a4aSRandall Stewart 
223f8829a4aSRandall Stewart void
224f8829a4aSRandall Stewart sctp_log_mb(struct mbuf *m, int from)
225f8829a4aSRandall Stewart {
22680fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
227f8829a4aSRandall Stewart 
22880fefe0aSRandall Stewart 	sctp_clog.x.mb.mp = m;
22980fefe0aSRandall Stewart 	sctp_clog.x.mb.mbuf_flags = (uint8_t) (SCTP_BUF_GET_FLAGS(m));
23080fefe0aSRandall Stewart 	sctp_clog.x.mb.size = (uint16_t) (SCTP_BUF_LEN(m));
23180fefe0aSRandall Stewart 	sctp_clog.x.mb.data = SCTP_BUF_AT(m, 0);
232139bc87fSRandall Stewart 	if (SCTP_BUF_IS_EXTENDED(m)) {
23380fefe0aSRandall Stewart 		sctp_clog.x.mb.ext = SCTP_BUF_EXTEND_BASE(m);
23480fefe0aSRandall Stewart 		sctp_clog.x.mb.refcnt = (uint8_t) (SCTP_BUF_EXTEND_REFCNT(m));
235f8829a4aSRandall Stewart 	} else {
23680fefe0aSRandall Stewart 		sctp_clog.x.mb.ext = 0;
23780fefe0aSRandall Stewart 		sctp_clog.x.mb.refcnt = 0;
238f8829a4aSRandall Stewart 	}
239c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
24080fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MBUF,
24180fefe0aSRandall Stewart 	    from,
24280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
24380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
24480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
24580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
246f8829a4aSRandall Stewart }
247f8829a4aSRandall Stewart 
248f8829a4aSRandall Stewart 
249f8829a4aSRandall Stewart void
250f8829a4aSRandall Stewart sctp_log_strm_del(struct sctp_queued_to_read *control, struct sctp_queued_to_read *poschk,
251f8829a4aSRandall Stewart     int from)
252f8829a4aSRandall Stewart {
25380fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
254f8829a4aSRandall Stewart 
255f8829a4aSRandall Stewart 	if (control == NULL) {
256ad81507eSRandall Stewart 		SCTP_PRINTF("Gak log of NULL?\n");
257f8829a4aSRandall Stewart 		return;
258f8829a4aSRandall Stewart 	}
25980fefe0aSRandall Stewart 	sctp_clog.x.strlog.stcb = control->stcb;
26080fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_tsn = control->sinfo_tsn;
26180fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_sseq = control->sinfo_ssn;
26280fefe0aSRandall Stewart 	sctp_clog.x.strlog.strm = control->sinfo_stream;
263f8829a4aSRandall Stewart 	if (poschk != NULL) {
26480fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_tsn = poschk->sinfo_tsn;
26580fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_sseq = poschk->sinfo_ssn;
266f8829a4aSRandall Stewart 	} else {
26780fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_tsn = 0;
26880fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_sseq = 0;
269f8829a4aSRandall Stewart 	}
270c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
27180fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_STRM,
27280fefe0aSRandall Stewart 	    from,
27380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
27480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
27580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
27680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
27780fefe0aSRandall Stewart 
278f8829a4aSRandall Stewart }
279f8829a4aSRandall Stewart 
280f8829a4aSRandall Stewart void
281f8829a4aSRandall Stewart sctp_log_cwnd(struct sctp_tcb *stcb, struct sctp_nets *net, int augment, uint8_t from)
282f8829a4aSRandall Stewart {
28380fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
284f8829a4aSRandall Stewart 
28580fefe0aSRandall Stewart 	sctp_clog.x.cwnd.net = net;
286f8829a4aSRandall Stewart 	if (stcb->asoc.send_queue_cnt > 255)
28780fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = 255;
288f8829a4aSRandall Stewart 	else
28980fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = stcb->asoc.send_queue_cnt;
290f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt > 255)
29180fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = 255;
292f8829a4aSRandall Stewart 	else
29380fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = stcb->asoc.stream_queue_cnt;
294f8829a4aSRandall Stewart 
295f8829a4aSRandall Stewart 	if (net) {
29680fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cwnd_new_value = net->cwnd;
29780fefe0aSRandall Stewart 		sctp_clog.x.cwnd.inflight = net->flight_size;
29880fefe0aSRandall Stewart 		sctp_clog.x.cwnd.pseudo_cumack = net->pseudo_cumack;
29980fefe0aSRandall Stewart 		sctp_clog.x.cwnd.meets_pseudo_cumack = net->new_pseudo_cumack;
30080fefe0aSRandall Stewart 		sctp_clog.x.cwnd.need_new_pseudo_cumack = net->find_pseudo_cumack;
301f8829a4aSRandall Stewart 	}
302f8829a4aSRandall Stewart 	if (SCTP_CWNDLOG_PRESEND == from) {
30380fefe0aSRandall Stewart 		sctp_clog.x.cwnd.meets_pseudo_cumack = stcb->asoc.peers_rwnd;
304f8829a4aSRandall Stewart 	}
30580fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_augment = augment;
306c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
30780fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_CWND,
30880fefe0aSRandall Stewart 	    from,
30980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
31080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
31180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
31280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
31380fefe0aSRandall Stewart 
314f8829a4aSRandall Stewart }
315f8829a4aSRandall Stewart 
316f8829a4aSRandall Stewart void
317f8829a4aSRandall Stewart sctp_log_lock(struct sctp_inpcb *inp, struct sctp_tcb *stcb, uint8_t from)
318f8829a4aSRandall Stewart {
31980fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
320f8829a4aSRandall Stewart 
321bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
32203b0b021SRandall Stewart 	if (inp) {
32380fefe0aSRandall Stewart 		sctp_clog.x.lock.sock = (void *)inp->sctp_socket;
32403b0b021SRandall Stewart 
32503b0b021SRandall Stewart 	} else {
32680fefe0aSRandall Stewart 		sctp_clog.x.lock.sock = (void *)NULL;
32703b0b021SRandall Stewart 	}
32880fefe0aSRandall Stewart 	sctp_clog.x.lock.inp = (void *)inp;
329f8829a4aSRandall Stewart 	if (stcb) {
33080fefe0aSRandall Stewart 		sctp_clog.x.lock.tcb_lock = mtx_owned(&stcb->tcb_mtx);
331f8829a4aSRandall Stewart 	} else {
33280fefe0aSRandall Stewart 		sctp_clog.x.lock.tcb_lock = SCTP_LOCK_UNKNOWN;
333f8829a4aSRandall Stewart 	}
334f8829a4aSRandall Stewart 	if (inp) {
33580fefe0aSRandall Stewart 		sctp_clog.x.lock.inp_lock = mtx_owned(&inp->inp_mtx);
33680fefe0aSRandall Stewart 		sctp_clog.x.lock.create_lock = mtx_owned(&inp->inp_create_mtx);
337f8829a4aSRandall Stewart 	} else {
33880fefe0aSRandall Stewart 		sctp_clog.x.lock.inp_lock = SCTP_LOCK_UNKNOWN;
33980fefe0aSRandall Stewart 		sctp_clog.x.lock.create_lock = SCTP_LOCK_UNKNOWN;
340f8829a4aSRandall Stewart 	}
341b3f1ea41SRandall Stewart 	sctp_clog.x.lock.info_lock = rw_wowned(&SCTP_BASE_INFO(ipi_ep_mtx));
342f8829a4aSRandall Stewart 	if (inp->sctp_socket) {
34380fefe0aSRandall Stewart 		sctp_clog.x.lock.sock_lock = mtx_owned(&(inp->sctp_socket->so_rcv.sb_mtx));
34480fefe0aSRandall Stewart 		sctp_clog.x.lock.sockrcvbuf_lock = mtx_owned(&(inp->sctp_socket->so_rcv.sb_mtx));
34580fefe0aSRandall Stewart 		sctp_clog.x.lock.socksndbuf_lock = mtx_owned(&(inp->sctp_socket->so_snd.sb_mtx));
346f8829a4aSRandall Stewart 	} else {
34780fefe0aSRandall Stewart 		sctp_clog.x.lock.sock_lock = SCTP_LOCK_UNKNOWN;
34880fefe0aSRandall Stewart 		sctp_clog.x.lock.sockrcvbuf_lock = SCTP_LOCK_UNKNOWN;
34980fefe0aSRandall Stewart 		sctp_clog.x.lock.socksndbuf_lock = SCTP_LOCK_UNKNOWN;
350f8829a4aSRandall Stewart 	}
351c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
35280fefe0aSRandall Stewart 	    SCTP_LOG_LOCK_EVENT,
35380fefe0aSRandall Stewart 	    from,
35480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
35580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
35680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
35780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
35880fefe0aSRandall Stewart 
359f8829a4aSRandall Stewart }
360f8829a4aSRandall Stewart 
361f8829a4aSRandall Stewart void
362f8829a4aSRandall Stewart sctp_log_maxburst(struct sctp_tcb *stcb, struct sctp_nets *net, int error, int burst, uint8_t from)
363f8829a4aSRandall Stewart {
36480fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
365f8829a4aSRandall Stewart 
366bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
36780fefe0aSRandall Stewart 	sctp_clog.x.cwnd.net = net;
36880fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_new_value = error;
36980fefe0aSRandall Stewart 	sctp_clog.x.cwnd.inflight = net->flight_size;
37080fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_augment = burst;
371f8829a4aSRandall Stewart 	if (stcb->asoc.send_queue_cnt > 255)
37280fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = 255;
373f8829a4aSRandall Stewart 	else
37480fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = stcb->asoc.send_queue_cnt;
375f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt > 255)
37680fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = 255;
377f8829a4aSRandall Stewart 	else
37880fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = stcb->asoc.stream_queue_cnt;
379c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
38080fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MAXBURST,
38180fefe0aSRandall Stewart 	    from,
38280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
38380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
38480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
38580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
38680fefe0aSRandall Stewart 
387f8829a4aSRandall Stewart }
388f8829a4aSRandall Stewart 
389f8829a4aSRandall Stewart void
390f8829a4aSRandall Stewart sctp_log_rwnd(uint8_t from, uint32_t peers_rwnd, uint32_t snd_size, uint32_t overhead)
391f8829a4aSRandall Stewart {
39280fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
393f8829a4aSRandall Stewart 
39480fefe0aSRandall Stewart 	sctp_clog.x.rwnd.rwnd = peers_rwnd;
39580fefe0aSRandall Stewart 	sctp_clog.x.rwnd.send_size = snd_size;
39680fefe0aSRandall Stewart 	sctp_clog.x.rwnd.overhead = overhead;
39780fefe0aSRandall Stewart 	sctp_clog.x.rwnd.new_rwnd = 0;
398c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
39980fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RWND,
40080fefe0aSRandall Stewart 	    from,
40180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
40280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
40380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
40480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
405f8829a4aSRandall Stewart }
406f8829a4aSRandall Stewart 
407f8829a4aSRandall Stewart void
408f8829a4aSRandall Stewart sctp_log_rwnd_set(uint8_t from, uint32_t peers_rwnd, uint32_t flight_size, uint32_t overhead, uint32_t a_rwndval)
409f8829a4aSRandall Stewart {
41080fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
411f8829a4aSRandall Stewart 
41280fefe0aSRandall Stewart 	sctp_clog.x.rwnd.rwnd = peers_rwnd;
41380fefe0aSRandall Stewart 	sctp_clog.x.rwnd.send_size = flight_size;
41480fefe0aSRandall Stewart 	sctp_clog.x.rwnd.overhead = overhead;
41580fefe0aSRandall Stewart 	sctp_clog.x.rwnd.new_rwnd = a_rwndval;
416c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
41780fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RWND,
41880fefe0aSRandall Stewart 	    from,
41980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
42080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
42180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
42280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
423f8829a4aSRandall Stewart }
424f8829a4aSRandall Stewart 
425f8829a4aSRandall Stewart void
426f8829a4aSRandall Stewart sctp_log_mbcnt(uint8_t from, uint32_t total_oq, uint32_t book, uint32_t total_mbcnt_q, uint32_t mbcnt)
427f8829a4aSRandall Stewart {
42880fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
429f8829a4aSRandall Stewart 
43080fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.total_queue_size = total_oq;
43180fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.size_change = book;
43280fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.total_queue_mb_size = total_mbcnt_q;
43380fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.mbcnt_change = mbcnt;
434c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
43580fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MBCNT,
43680fefe0aSRandall Stewart 	    from,
43780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
43880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
43980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
44080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
44180fefe0aSRandall Stewart 
442f8829a4aSRandall Stewart }
443f8829a4aSRandall Stewart 
444f8829a4aSRandall Stewart void
445f8829a4aSRandall Stewart sctp_misc_ints(uint8_t from, uint32_t a, uint32_t b, uint32_t c, uint32_t d)
446f8829a4aSRandall Stewart {
447c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
44880fefe0aSRandall Stewart 	    SCTP_LOG_MISC_EVENT,
44980fefe0aSRandall Stewart 	    from,
45080fefe0aSRandall Stewart 	    a, b, c, d);
451f8829a4aSRandall Stewart }
452f8829a4aSRandall Stewart 
453f8829a4aSRandall Stewart void
454f8829a4aSRandall Stewart sctp_wakeup_log(struct sctp_tcb *stcb, uint32_t cumtsn, uint32_t wake_cnt, int from)
455f8829a4aSRandall Stewart {
45680fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
457f8829a4aSRandall Stewart 
45880fefe0aSRandall Stewart 	sctp_clog.x.wake.stcb = (void *)stcb;
45980fefe0aSRandall Stewart 	sctp_clog.x.wake.wake_cnt = wake_cnt;
46080fefe0aSRandall Stewart 	sctp_clog.x.wake.flight = stcb->asoc.total_flight_count;
46180fefe0aSRandall Stewart 	sctp_clog.x.wake.send_q = stcb->asoc.send_queue_cnt;
46280fefe0aSRandall Stewart 	sctp_clog.x.wake.sent_q = stcb->asoc.sent_queue_cnt;
463f8829a4aSRandall Stewart 
464f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt < 0xff)
46580fefe0aSRandall Stewart 		sctp_clog.x.wake.stream_qcnt = (uint8_t) stcb->asoc.stream_queue_cnt;
466f8829a4aSRandall Stewart 	else
46780fefe0aSRandall Stewart 		sctp_clog.x.wake.stream_qcnt = 0xff;
468f8829a4aSRandall Stewart 
469f8829a4aSRandall Stewart 	if (stcb->asoc.chunks_on_out_queue < 0xff)
47080fefe0aSRandall Stewart 		sctp_clog.x.wake.chunks_on_oque = (uint8_t) stcb->asoc.chunks_on_out_queue;
471f8829a4aSRandall Stewart 	else
47280fefe0aSRandall Stewart 		sctp_clog.x.wake.chunks_on_oque = 0xff;
473f8829a4aSRandall Stewart 
47480fefe0aSRandall Stewart 	sctp_clog.x.wake.sctpflags = 0;
475f8829a4aSRandall Stewart 	/* set in the defered mode stuff */
476f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_DONT_WAKE)
47780fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 1;
478f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_WAKEOUTPUT)
47980fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 2;
480f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_WAKEINPUT)
48180fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 4;
482f8829a4aSRandall Stewart 	/* what about the sb */
483f8829a4aSRandall Stewart 	if (stcb->sctp_socket) {
484f8829a4aSRandall Stewart 		struct socket *so = stcb->sctp_socket;
485f8829a4aSRandall Stewart 
48680fefe0aSRandall Stewart 		sctp_clog.x.wake.sbflags = (uint8_t) ((so->so_snd.sb_flags & 0x00ff));
487f8829a4aSRandall Stewart 	} else {
48880fefe0aSRandall Stewart 		sctp_clog.x.wake.sbflags = 0xff;
489f8829a4aSRandall Stewart 	}
490c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
49180fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_WAKE,
49280fefe0aSRandall Stewart 	    from,
49380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
49480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
49580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
49680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
49780fefe0aSRandall Stewart 
498f8829a4aSRandall Stewart }
499f8829a4aSRandall Stewart 
500f8829a4aSRandall Stewart void
501f8829a4aSRandall Stewart sctp_log_block(uint8_t from, struct socket *so, struct sctp_association *asoc, int sendlen)
502f8829a4aSRandall Stewart {
50380fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
504f8829a4aSRandall Stewart 
50580fefe0aSRandall Stewart 	sctp_clog.x.blk.onsb = asoc->total_output_queue_size;
50680fefe0aSRandall Stewart 	sctp_clog.x.blk.send_sent_qcnt = (uint16_t) (asoc->send_queue_cnt + asoc->sent_queue_cnt);
50780fefe0aSRandall Stewart 	sctp_clog.x.blk.peer_rwnd = asoc->peers_rwnd;
50880fefe0aSRandall Stewart 	sctp_clog.x.blk.stream_qcnt = (uint16_t) asoc->stream_queue_cnt;
50980fefe0aSRandall Stewart 	sctp_clog.x.blk.chunks_on_oque = (uint16_t) asoc->chunks_on_out_queue;
51080fefe0aSRandall Stewart 	sctp_clog.x.blk.flight_size = (uint16_t) (asoc->total_flight / 1024);
51180fefe0aSRandall Stewart 	sctp_clog.x.blk.sndlen = sendlen;
512c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
51380fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_BLOCK,
51480fefe0aSRandall Stewart 	    from,
51580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
51680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
51780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
51880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
51980fefe0aSRandall Stewart 
520f8829a4aSRandall Stewart }
521f8829a4aSRandall Stewart 
522f8829a4aSRandall Stewart int
52342551e99SRandall Stewart sctp_fill_stat_log(void *optval, size_t *optsize)
524f8829a4aSRandall Stewart {
52580fefe0aSRandall Stewart 	/* May need to fix this if ktrdump does not work */
526f8829a4aSRandall Stewart 	return (0);
527f8829a4aSRandall Stewart }
528f8829a4aSRandall Stewart 
529f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
530f8829a4aSRandall Stewart uint8_t sctp_audit_data[SCTP_AUDIT_SIZE][2];
531f8829a4aSRandall Stewart static int sctp_audit_indx = 0;
532f8829a4aSRandall Stewart 
533f8829a4aSRandall Stewart static
534f8829a4aSRandall Stewart void
535f8829a4aSRandall Stewart sctp_print_audit_report(void)
536f8829a4aSRandall Stewart {
537f8829a4aSRandall Stewart 	int i;
538f8829a4aSRandall Stewart 	int cnt;
539f8829a4aSRandall Stewart 
540f8829a4aSRandall Stewart 	cnt = 0;
541f8829a4aSRandall Stewart 	for (i = sctp_audit_indx; i < SCTP_AUDIT_SIZE; i++) {
542f8829a4aSRandall Stewart 		if ((sctp_audit_data[i][0] == 0xe0) &&
543f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
544f8829a4aSRandall Stewart 			cnt = 0;
545ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
546f8829a4aSRandall Stewart 		} else if (sctp_audit_data[i][0] == 0xf0) {
547f8829a4aSRandall Stewart 			cnt = 0;
548ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
549f8829a4aSRandall Stewart 		} else if ((sctp_audit_data[i][0] == 0xc0) &&
550f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
551ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
552f8829a4aSRandall Stewart 			cnt = 0;
553f8829a4aSRandall Stewart 		}
554ad81507eSRandall Stewart 		SCTP_PRINTF("%2.2x%2.2x ", (uint32_t) sctp_audit_data[i][0],
555f8829a4aSRandall Stewart 		    (uint32_t) sctp_audit_data[i][1]);
556f8829a4aSRandall Stewart 		cnt++;
557f8829a4aSRandall Stewart 		if ((cnt % 14) == 0)
558ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
559f8829a4aSRandall Stewart 	}
560f8829a4aSRandall Stewart 	for (i = 0; i < sctp_audit_indx; i++) {
561f8829a4aSRandall Stewart 		if ((sctp_audit_data[i][0] == 0xe0) &&
562f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
563f8829a4aSRandall Stewart 			cnt = 0;
564ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
565f8829a4aSRandall Stewart 		} else if (sctp_audit_data[i][0] == 0xf0) {
566f8829a4aSRandall Stewart 			cnt = 0;
567ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
568f8829a4aSRandall Stewart 		} else if ((sctp_audit_data[i][0] == 0xc0) &&
569f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
570ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
571f8829a4aSRandall Stewart 			cnt = 0;
572f8829a4aSRandall Stewart 		}
573ad81507eSRandall Stewart 		SCTP_PRINTF("%2.2x%2.2x ", (uint32_t) sctp_audit_data[i][0],
574f8829a4aSRandall Stewart 		    (uint32_t) sctp_audit_data[i][1]);
575f8829a4aSRandall Stewart 		cnt++;
576f8829a4aSRandall Stewart 		if ((cnt % 14) == 0)
577ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
578f8829a4aSRandall Stewart 	}
579ad81507eSRandall Stewart 	SCTP_PRINTF("\n");
580f8829a4aSRandall Stewart }
581f8829a4aSRandall Stewart 
582f8829a4aSRandall Stewart void
583f8829a4aSRandall Stewart sctp_auditing(int from, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
584f8829a4aSRandall Stewart     struct sctp_nets *net)
585f8829a4aSRandall Stewart {
586f8829a4aSRandall Stewart 	int resend_cnt, tot_out, rep, tot_book_cnt;
587f8829a4aSRandall Stewart 	struct sctp_nets *lnet;
588f8829a4aSRandall Stewart 	struct sctp_tmit_chunk *chk;
589f8829a4aSRandall Stewart 
590f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = 0xAA;
591f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] = 0x000000ff & from;
592f8829a4aSRandall Stewart 	sctp_audit_indx++;
593f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
594f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
595f8829a4aSRandall Stewart 	}
596f8829a4aSRandall Stewart 	if (inp == NULL) {
597f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
598f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0x01;
599f8829a4aSRandall Stewart 		sctp_audit_indx++;
600f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
601f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
602f8829a4aSRandall Stewart 		}
603f8829a4aSRandall Stewart 		return;
604f8829a4aSRandall Stewart 	}
605f8829a4aSRandall Stewart 	if (stcb == NULL) {
606f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
607f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0x02;
608f8829a4aSRandall Stewart 		sctp_audit_indx++;
609f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
610f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
611f8829a4aSRandall Stewart 		}
612f8829a4aSRandall Stewart 		return;
613f8829a4aSRandall Stewart 	}
614f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = 0xA1;
615f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] =
616f8829a4aSRandall Stewart 	    (0x000000ff & stcb->asoc.sent_queue_retran_cnt);
617f8829a4aSRandall Stewart 	sctp_audit_indx++;
618f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
619f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
620f8829a4aSRandall Stewart 	}
621f8829a4aSRandall Stewart 	rep = 0;
622f8829a4aSRandall Stewart 	tot_book_cnt = 0;
623f8829a4aSRandall Stewart 	resend_cnt = tot_out = 0;
624f8829a4aSRandall Stewart 	TAILQ_FOREACH(chk, &stcb->asoc.sent_queue, sctp_next) {
625f8829a4aSRandall Stewart 		if (chk->sent == SCTP_DATAGRAM_RESEND) {
626f8829a4aSRandall Stewart 			resend_cnt++;
627f8829a4aSRandall Stewart 		} else if (chk->sent < SCTP_DATAGRAM_RESEND) {
628f8829a4aSRandall Stewart 			tot_out += chk->book_size;
629f8829a4aSRandall Stewart 			tot_book_cnt++;
630f8829a4aSRandall Stewart 		}
631f8829a4aSRandall Stewart 	}
632f8829a4aSRandall Stewart 	if (resend_cnt != stcb->asoc.sent_queue_retran_cnt) {
633f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
634f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA1;
635f8829a4aSRandall Stewart 		sctp_audit_indx++;
636f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
637f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
638f8829a4aSRandall Stewart 		}
639ad81507eSRandall Stewart 		SCTP_PRINTF("resend_cnt:%d asoc-tot:%d\n",
640f8829a4aSRandall Stewart 		    resend_cnt, stcb->asoc.sent_queue_retran_cnt);
641f8829a4aSRandall Stewart 		rep = 1;
642f8829a4aSRandall Stewart 		stcb->asoc.sent_queue_retran_cnt = resend_cnt;
643f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xA2;
644f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] =
645f8829a4aSRandall Stewart 		    (0x000000ff & stcb->asoc.sent_queue_retran_cnt);
646f8829a4aSRandall Stewart 		sctp_audit_indx++;
647f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
648f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
649f8829a4aSRandall Stewart 		}
650f8829a4aSRandall Stewart 	}
651f8829a4aSRandall Stewart 	if (tot_out != stcb->asoc.total_flight) {
652f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
653f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA2;
654f8829a4aSRandall Stewart 		sctp_audit_indx++;
655f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
656f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
657f8829a4aSRandall Stewart 		}
658f8829a4aSRandall Stewart 		rep = 1;
659ad81507eSRandall Stewart 		SCTP_PRINTF("tot_flt:%d asoc_tot:%d\n", tot_out,
660f8829a4aSRandall Stewart 		    (int)stcb->asoc.total_flight);
661f8829a4aSRandall Stewart 		stcb->asoc.total_flight = tot_out;
662f8829a4aSRandall Stewart 	}
663f8829a4aSRandall Stewart 	if (tot_book_cnt != stcb->asoc.total_flight_count) {
664f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
665f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA5;
666f8829a4aSRandall Stewart 		sctp_audit_indx++;
667f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
668f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
669f8829a4aSRandall Stewart 		}
670f8829a4aSRandall Stewart 		rep = 1;
671ad81507eSRandall Stewart 		SCTP_PRINTF("tot_flt_book:%d\n", tot_book);
672f8829a4aSRandall Stewart 
673f8829a4aSRandall Stewart 		stcb->asoc.total_flight_count = tot_book_cnt;
674f8829a4aSRandall Stewart 	}
675f8829a4aSRandall Stewart 	tot_out = 0;
676f8829a4aSRandall Stewart 	TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
677f8829a4aSRandall Stewart 		tot_out += lnet->flight_size;
678f8829a4aSRandall Stewart 	}
679f8829a4aSRandall Stewart 	if (tot_out != stcb->asoc.total_flight) {
680f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
681f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA3;
682f8829a4aSRandall Stewart 		sctp_audit_indx++;
683f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
684f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
685f8829a4aSRandall Stewart 		}
686f8829a4aSRandall Stewart 		rep = 1;
687ad81507eSRandall Stewart 		SCTP_PRINTF("real flight:%d net total was %d\n",
688f8829a4aSRandall Stewart 		    stcb->asoc.total_flight, tot_out);
689f8829a4aSRandall Stewart 		/* now corrective action */
690f8829a4aSRandall Stewart 		TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
691f8829a4aSRandall Stewart 
692f8829a4aSRandall Stewart 			tot_out = 0;
693f8829a4aSRandall Stewart 			TAILQ_FOREACH(chk, &stcb->asoc.sent_queue, sctp_next) {
694f8829a4aSRandall Stewart 				if ((chk->whoTo == lnet) &&
695f8829a4aSRandall Stewart 				    (chk->sent < SCTP_DATAGRAM_RESEND)) {
696f8829a4aSRandall Stewart 					tot_out += chk->book_size;
697f8829a4aSRandall Stewart 				}
698f8829a4aSRandall Stewart 			}
699f8829a4aSRandall Stewart 			if (lnet->flight_size != tot_out) {
700ad81507eSRandall Stewart 				SCTP_PRINTF("net:%x flight was %d corrected to %d\n",
701ad81507eSRandall Stewart 				    (uint32_t) lnet, lnet->flight_size,
702ad81507eSRandall Stewart 				    tot_out);
703f8829a4aSRandall Stewart 				lnet->flight_size = tot_out;
704f8829a4aSRandall Stewart 			}
705f8829a4aSRandall Stewart 		}
706f8829a4aSRandall Stewart 	}
707f8829a4aSRandall Stewart 	if (rep) {
708f8829a4aSRandall Stewart 		sctp_print_audit_report();
709f8829a4aSRandall Stewart 	}
710f8829a4aSRandall Stewart }
711f8829a4aSRandall Stewart 
712f8829a4aSRandall Stewart void
713f8829a4aSRandall Stewart sctp_audit_log(uint8_t ev, uint8_t fd)
714f8829a4aSRandall Stewart {
715f8829a4aSRandall Stewart 
716f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = ev;
717f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] = fd;
718f8829a4aSRandall Stewart 	sctp_audit_indx++;
719f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
720f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
721f8829a4aSRandall Stewart 	}
722f8829a4aSRandall Stewart }
723f8829a4aSRandall Stewart 
724f8829a4aSRandall Stewart #endif
725f8829a4aSRandall Stewart 
726f8829a4aSRandall Stewart /*
727f8829a4aSRandall Stewart  * a list of sizes based on typical mtu's, used only if next hop size not
728f8829a4aSRandall Stewart  * returned.
729f8829a4aSRandall Stewart  */
730f8829a4aSRandall Stewart static int sctp_mtu_sizes[] = {
731f8829a4aSRandall Stewart 	68,
732f8829a4aSRandall Stewart 	296,
733f8829a4aSRandall Stewart 	508,
734f8829a4aSRandall Stewart 	512,
735f8829a4aSRandall Stewart 	544,
736f8829a4aSRandall Stewart 	576,
737f8829a4aSRandall Stewart 	1006,
738f8829a4aSRandall Stewart 	1492,
739f8829a4aSRandall Stewart 	1500,
740f8829a4aSRandall Stewart 	1536,
741f8829a4aSRandall Stewart 	2002,
742f8829a4aSRandall Stewart 	2048,
743f8829a4aSRandall Stewart 	4352,
744f8829a4aSRandall Stewart 	4464,
745f8829a4aSRandall Stewart 	8166,
746f8829a4aSRandall Stewart 	17914,
747f8829a4aSRandall Stewart 	32000,
748f8829a4aSRandall Stewart 	65535
749f8829a4aSRandall Stewart };
750f8829a4aSRandall Stewart 
751f8829a4aSRandall Stewart void
752f8829a4aSRandall Stewart sctp_stop_timers_for_shutdown(struct sctp_tcb *stcb)
753f8829a4aSRandall Stewart {
754f8829a4aSRandall Stewart 	struct sctp_association *asoc;
755f8829a4aSRandall Stewart 	struct sctp_nets *net;
756f8829a4aSRandall Stewart 
757f8829a4aSRandall Stewart 	asoc = &stcb->asoc;
758f8829a4aSRandall Stewart 
7596e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&asoc->hb_timer.timer);
7606e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&asoc->dack_timer.timer);
7616e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&asoc->strreset_timer.timer);
7626e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&asoc->asconf_timer.timer);
7636e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&asoc->autoclose_timer.timer);
7646e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&asoc->delayed_event_timer.timer);
765f8829a4aSRandall Stewart 	TAILQ_FOREACH(net, &asoc->nets, sctp_next) {
7666e55db54SRandall Stewart 		(void)SCTP_OS_TIMER_STOP(&net->fr_timer.timer);
7676e55db54SRandall Stewart 		(void)SCTP_OS_TIMER_STOP(&net->pmtu_timer.timer);
768f8829a4aSRandall Stewart 	}
769f8829a4aSRandall Stewart }
770f8829a4aSRandall Stewart 
771f8829a4aSRandall Stewart int
772f8829a4aSRandall Stewart find_next_best_mtu(int totsz)
773f8829a4aSRandall Stewart {
774f8829a4aSRandall Stewart 	int i, perfer;
775f8829a4aSRandall Stewart 
776f8829a4aSRandall Stewart 	/*
777f8829a4aSRandall Stewart 	 * if we are in here we must find the next best fit based on the
778f8829a4aSRandall Stewart 	 * size of the dg that failed to be sent.
779f8829a4aSRandall Stewart 	 */
780f8829a4aSRandall Stewart 	perfer = 0;
781f8829a4aSRandall Stewart 	for (i = 0; i < NUMBER_OF_MTU_SIZES; i++) {
782f8829a4aSRandall Stewart 		if (totsz < sctp_mtu_sizes[i]) {
783f8829a4aSRandall Stewart 			perfer = i - 1;
784f8829a4aSRandall Stewart 			if (perfer < 0)
785f8829a4aSRandall Stewart 				perfer = 0;
786f8829a4aSRandall Stewart 			break;
787f8829a4aSRandall Stewart 		}
788f8829a4aSRandall Stewart 	}
789f8829a4aSRandall Stewart 	return (sctp_mtu_sizes[perfer]);
790f8829a4aSRandall Stewart }
791f8829a4aSRandall Stewart 
792f8829a4aSRandall Stewart void
793f8829a4aSRandall Stewart sctp_fill_random_store(struct sctp_pcb *m)
794f8829a4aSRandall Stewart {
795f8829a4aSRandall Stewart 	/*
796f8829a4aSRandall Stewart 	 * Here we use the MD5/SHA-1 to hash with our good randomNumbers and
797f8829a4aSRandall Stewart 	 * our counter. The result becomes our good random numbers and we
798f8829a4aSRandall Stewart 	 * then setup to give these out. Note that we do no locking to
799f8829a4aSRandall Stewart 	 * protect this. This is ok, since if competing folks call this we
80017205eccSRandall Stewart 	 * will get more gobbled gook in the random store which is what we
801f8829a4aSRandall Stewart 	 * want. There is a danger that two guys will use the same random
802f8829a4aSRandall Stewart 	 * numbers, but thats ok too since that is random as well :->
803f8829a4aSRandall Stewart 	 */
804f8829a4aSRandall Stewart 	m->store_at = 0;
805ad81507eSRandall Stewart 	(void)sctp_hmac(SCTP_HMAC, (uint8_t *) m->random_numbers,
806f8829a4aSRandall Stewart 	    sizeof(m->random_numbers), (uint8_t *) & m->random_counter,
807f8829a4aSRandall Stewart 	    sizeof(m->random_counter), (uint8_t *) m->random_store);
808f8829a4aSRandall Stewart 	m->random_counter++;
809f8829a4aSRandall Stewart }
810f8829a4aSRandall Stewart 
811f8829a4aSRandall Stewart uint32_t
812851b7298SRandall Stewart sctp_select_initial_TSN(struct sctp_pcb *inp)
813f8829a4aSRandall Stewart {
814f8829a4aSRandall Stewart 	/*
815f8829a4aSRandall Stewart 	 * A true implementation should use random selection process to get
816f8829a4aSRandall Stewart 	 * the initial stream sequence number, using RFC1750 as a good
817f8829a4aSRandall Stewart 	 * guideline
818f8829a4aSRandall Stewart 	 */
819139bc87fSRandall Stewart 	uint32_t x, *xp;
820f8829a4aSRandall Stewart 	uint8_t *p;
821851b7298SRandall Stewart 	int store_at, new_store;
822f8829a4aSRandall Stewart 
823851b7298SRandall Stewart 	if (inp->initial_sequence_debug != 0) {
824f8829a4aSRandall Stewart 		uint32_t ret;
825f8829a4aSRandall Stewart 
826851b7298SRandall Stewart 		ret = inp->initial_sequence_debug;
827851b7298SRandall Stewart 		inp->initial_sequence_debug++;
828f8829a4aSRandall Stewart 		return (ret);
829f8829a4aSRandall Stewart 	}
830851b7298SRandall Stewart retry:
831851b7298SRandall Stewart 	store_at = inp->store_at;
832851b7298SRandall Stewart 	new_store = store_at + sizeof(uint32_t);
833851b7298SRandall Stewart 	if (new_store >= (SCTP_SIGNATURE_SIZE - 3)) {
834851b7298SRandall Stewart 		new_store = 0;
835f8829a4aSRandall Stewart 	}
836851b7298SRandall Stewart 	if (!atomic_cmpset_int(&inp->store_at, store_at, new_store)) {
837851b7298SRandall Stewart 		goto retry;
838851b7298SRandall Stewart 	}
839851b7298SRandall Stewart 	if (new_store == 0) {
840851b7298SRandall Stewart 		/* Refill the random store */
841851b7298SRandall Stewart 		sctp_fill_random_store(inp);
842851b7298SRandall Stewart 	}
843851b7298SRandall Stewart 	p = &inp->random_store[store_at];
844139bc87fSRandall Stewart 	xp = (uint32_t *) p;
845f8829a4aSRandall Stewart 	x = *xp;
846f8829a4aSRandall Stewart 	return (x);
847f8829a4aSRandall Stewart }
848f8829a4aSRandall Stewart 
849f8829a4aSRandall Stewart uint32_t
850830d754dSRandall Stewart sctp_select_a_tag(struct sctp_inpcb *inp, uint16_t lport, uint16_t rport, int save_in_twait)
851f8829a4aSRandall Stewart {
8527291848aSMichael Tuexen 	uint32_t x, not_done;
853f8829a4aSRandall Stewart 	struct timeval now;
854f8829a4aSRandall Stewart 
8556e55db54SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&now);
856f8829a4aSRandall Stewart 	not_done = 1;
857f8829a4aSRandall Stewart 	while (not_done) {
858851b7298SRandall Stewart 		x = sctp_select_initial_TSN(&inp->sctp_ep);
859f8829a4aSRandall Stewart 		if (x == 0) {
860f8829a4aSRandall Stewart 			/* we never use 0 */
861f8829a4aSRandall Stewart 			continue;
862f8829a4aSRandall Stewart 		}
863830d754dSRandall Stewart 		if (sctp_is_vtag_good(inp, x, lport, rport, &now, save_in_twait)) {
864f8829a4aSRandall Stewart 			not_done = 0;
865f8829a4aSRandall Stewart 		}
866f8829a4aSRandall Stewart 	}
867f8829a4aSRandall Stewart 	return (x);
868f8829a4aSRandall Stewart }
869f8829a4aSRandall Stewart 
870f8829a4aSRandall Stewart int
8710696e120SRandall Stewart sctp_init_asoc(struct sctp_inpcb *m, struct sctp_tcb *stcb,
87242551e99SRandall Stewart     int for_a_init, uint32_t override_tag, uint32_t vrf_id)
873f8829a4aSRandall Stewart {
8740696e120SRandall Stewart 	struct sctp_association *asoc;
8750696e120SRandall Stewart 
876f8829a4aSRandall Stewart 	/*
877f8829a4aSRandall Stewart 	 * Anything set to zero is taken care of by the allocation routine's
878f8829a4aSRandall Stewart 	 * bzero
879f8829a4aSRandall Stewart 	 */
880f8829a4aSRandall Stewart 
881f8829a4aSRandall Stewart 	/*
882f8829a4aSRandall Stewart 	 * Up front select what scoping to apply on addresses I tell my peer
883f8829a4aSRandall Stewart 	 * Not sure what to do with these right now, we will need to come up
884f8829a4aSRandall Stewart 	 * with a way to set them. We may need to pass them through from the
885f8829a4aSRandall Stewart 	 * caller in the sctp_aloc_assoc() function.
886f8829a4aSRandall Stewart 	 */
887f8829a4aSRandall Stewart 	int i;
888f8829a4aSRandall Stewart 
8890696e120SRandall Stewart 	asoc = &stcb->asoc;
890f8829a4aSRandall Stewart 	/* init all variables to a known value. */
891c4739e2fSRandall Stewart 	SCTP_SET_STATE(&stcb->asoc, SCTP_STATE_INUSE);
892f8829a4aSRandall Stewart 	asoc->max_burst = m->sctp_ep.max_burst;
893f8829a4aSRandall Stewart 	asoc->heart_beat_delay = TICKS_TO_MSEC(m->sctp_ep.sctp_timeoutticks[SCTP_TIMER_HEARTBEAT]);
894f8829a4aSRandall Stewart 	asoc->cookie_life = m->sctp_ep.def_cookie_life;
895b3f1ea41SRandall Stewart 	asoc->sctp_cmt_on_off = (uint8_t) SCTP_BASE_SYSCTL(sctp_cmt_on_off);
896830d754dSRandall Stewart 	/* EY Init nr_sack variable */
897830d754dSRandall Stewart 	asoc->sctp_nr_sack_on_off = (uint8_t) SCTP_BASE_SYSCTL(sctp_nr_sack_on_off);
898b54d3a6cSRandall Stewart 	/* JRS 5/21/07 - Init CMT PF variables */
899b3f1ea41SRandall Stewart 	asoc->sctp_cmt_pf = (uint8_t) SCTP_BASE_SYSCTL(sctp_cmt_pf);
900d61a0ae0SRandall Stewart 	asoc->sctp_frag_point = m->sctp_frag_point;
90142551e99SRandall Stewart #ifdef INET
902f8829a4aSRandall Stewart 	asoc->default_tos = m->ip_inp.inp.inp_ip_tos;
903f8829a4aSRandall Stewart #else
904f8829a4aSRandall Stewart 	asoc->default_tos = 0;
905f8829a4aSRandall Stewart #endif
906f8829a4aSRandall Stewart 
90742551e99SRandall Stewart #ifdef INET6
908f8829a4aSRandall Stewart 	asoc->default_flowlabel = ((struct in6pcb *)m)->in6p_flowinfo;
909f8829a4aSRandall Stewart #else
910f8829a4aSRandall Stewart 	asoc->default_flowlabel = 0;
911f8829a4aSRandall Stewart #endif
9129f22f500SRandall Stewart 	asoc->sb_send_resv = 0;
913f8829a4aSRandall Stewart 	if (override_tag) {
914f8829a4aSRandall Stewart 		asoc->my_vtag = override_tag;
915f8829a4aSRandall Stewart 	} else {
916830d754dSRandall Stewart 		asoc->my_vtag = sctp_select_a_tag(m, stcb->sctp_ep->sctp_lport, stcb->rport, 1);
917f8829a4aSRandall Stewart 	}
918de0e935bSRandall Stewart 	/* Get the nonce tags */
919830d754dSRandall Stewart 	asoc->my_vtag_nonce = sctp_select_a_tag(m, stcb->sctp_ep->sctp_lport, stcb->rport, 0);
920830d754dSRandall Stewart 	asoc->peer_vtag_nonce = sctp_select_a_tag(m, stcb->sctp_ep->sctp_lport, stcb->rport, 0);
92142551e99SRandall Stewart 	asoc->vrf_id = vrf_id;
922de0e935bSRandall Stewart 
923f8829a4aSRandall Stewart 	if (sctp_is_feature_on(m, SCTP_PCB_FLAGS_DONOT_HEARTBEAT))
924f8829a4aSRandall Stewart 		asoc->hb_is_disabled = 1;
925f8829a4aSRandall Stewart 	else
926f8829a4aSRandall Stewart 		asoc->hb_is_disabled = 0;
927f8829a4aSRandall Stewart 
92818e198d3SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
92918e198d3SRandall Stewart 	asoc->tsn_in_at = 0;
93018e198d3SRandall Stewart 	asoc->tsn_out_at = 0;
93118e198d3SRandall Stewart 	asoc->tsn_in_wrapped = 0;
93218e198d3SRandall Stewart 	asoc->tsn_out_wrapped = 0;
93318e198d3SRandall Stewart 	asoc->cumack_log_at = 0;
934b201f536SRandall Stewart 	asoc->cumack_log_atsnt = 0;
93518e198d3SRandall Stewart #endif
93618e198d3SRandall Stewart #ifdef SCTP_FS_SPEC_LOG
93718e198d3SRandall Stewart 	asoc->fs_index = 0;
93818e198d3SRandall Stewart #endif
939f8829a4aSRandall Stewart 	asoc->refcnt = 0;
940f8829a4aSRandall Stewart 	asoc->assoc_up_sent = 0;
941f8829a4aSRandall Stewart 	asoc->asconf_seq_out = asoc->str_reset_seq_out = asoc->init_seq_number = asoc->sending_seq =
942f8829a4aSRandall Stewart 	    sctp_select_initial_TSN(&m->sctp_ep);
943c54a18d2SRandall Stewart 	asoc->asconf_seq_out_acked = asoc->asconf_seq_out - 1;
944f8829a4aSRandall Stewart 	/* we are optimisitic here */
945f8829a4aSRandall Stewart 	asoc->peer_supports_pktdrop = 1;
946830d754dSRandall Stewart 	asoc->peer_supports_nat = 0;
947f8829a4aSRandall Stewart 	asoc->sent_queue_retran_cnt = 0;
948f8829a4aSRandall Stewart 
949f8829a4aSRandall Stewart 	/* for CMT */
9508933fa13SRandall Stewart 	asoc->last_net_cmt_send_started = NULL;
951f8829a4aSRandall Stewart 
952f8829a4aSRandall Stewart 	/* This will need to be adjusted */
953f8829a4aSRandall Stewart 	asoc->last_cwr_tsn = asoc->init_seq_number - 1;
954f8829a4aSRandall Stewart 	asoc->last_acked_seq = asoc->init_seq_number - 1;
955f8829a4aSRandall Stewart 	asoc->advanced_peer_ack_point = asoc->last_acked_seq;
956f8829a4aSRandall Stewart 	asoc->asconf_seq_in = asoc->last_acked_seq;
957f8829a4aSRandall Stewart 
958f8829a4aSRandall Stewart 	/* here we are different, we hold the next one we expect */
959f8829a4aSRandall Stewart 	asoc->str_reset_seq_in = asoc->last_acked_seq + 1;
960f8829a4aSRandall Stewart 
961f8829a4aSRandall Stewart 	asoc->initial_init_rto_max = m->sctp_ep.initial_init_rto_max;
962f8829a4aSRandall Stewart 	asoc->initial_rto = m->sctp_ep.initial_rto;
963f8829a4aSRandall Stewart 
964f8829a4aSRandall Stewart 	asoc->max_init_times = m->sctp_ep.max_init_times;
965f8829a4aSRandall Stewart 	asoc->max_send_times = m->sctp_ep.max_send_times;
966f8829a4aSRandall Stewart 	asoc->def_net_failure = m->sctp_ep.def_net_failure;
967f8829a4aSRandall Stewart 	asoc->free_chunk_cnt = 0;
968f8829a4aSRandall Stewart 
969f8829a4aSRandall Stewart 	asoc->iam_blocking = 0;
970f8829a4aSRandall Stewart 	/* ECN Nonce initialization */
971f8829a4aSRandall Stewart 	asoc->context = m->sctp_context;
972f8829a4aSRandall Stewart 	asoc->def_send = m->def_send;
973f8829a4aSRandall Stewart 	asoc->ecn_nonce_allowed = 0;
974f8829a4aSRandall Stewart 	asoc->receiver_nonce_sum = 1;
975f8829a4aSRandall Stewart 	asoc->nonce_sum_expect_base = 1;
976f8829a4aSRandall Stewart 	asoc->nonce_sum_check = 1;
977f8829a4aSRandall Stewart 	asoc->nonce_resync_tsn = 0;
978f8829a4aSRandall Stewart 	asoc->nonce_wait_for_ecne = 0;
979f8829a4aSRandall Stewart 	asoc->nonce_wait_tsn = 0;
980f8829a4aSRandall Stewart 	asoc->delayed_ack = TICKS_TO_MSEC(m->sctp_ep.sctp_timeoutticks[SCTP_TIMER_RECV]);
98142551e99SRandall Stewart 	asoc->sack_freq = m->sctp_ep.sctp_sack_freq;
982f8829a4aSRandall Stewart 	asoc->pr_sctp_cnt = 0;
983f8829a4aSRandall Stewart 	asoc->total_output_queue_size = 0;
984f8829a4aSRandall Stewart 
985f8829a4aSRandall Stewart 	if (m->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) {
986f8829a4aSRandall Stewart 		struct in6pcb *inp6;
987f8829a4aSRandall Stewart 
988f8829a4aSRandall Stewart 		/* Its a V6 socket */
989f8829a4aSRandall Stewart 		inp6 = (struct in6pcb *)m;
990f8829a4aSRandall Stewart 		asoc->ipv6_addr_legal = 1;
991f8829a4aSRandall Stewart 		/* Now look at the binding flag to see if V4 will be legal */
99244b7479bSRandall Stewart 		if (SCTP_IPV6_V6ONLY(inp6) == 0) {
993f8829a4aSRandall Stewart 			asoc->ipv4_addr_legal = 1;
994f8829a4aSRandall Stewart 		} else {
995f8829a4aSRandall Stewart 			/* V4 addresses are NOT legal on the association */
996f8829a4aSRandall Stewart 			asoc->ipv4_addr_legal = 0;
997f8829a4aSRandall Stewart 		}
998f8829a4aSRandall Stewart 	} else {
999f8829a4aSRandall Stewart 		/* Its a V4 socket, no - V6 */
1000f8829a4aSRandall Stewart 		asoc->ipv4_addr_legal = 1;
1001f8829a4aSRandall Stewart 		asoc->ipv6_addr_legal = 0;
1002f8829a4aSRandall Stewart 	}
1003f8829a4aSRandall Stewart 
100462c1ff9cSRandall Stewart 	asoc->my_rwnd = max(SCTP_SB_LIMIT_RCV(m->sctp_socket), SCTP_MINIMAL_RWND);
100562c1ff9cSRandall Stewart 	asoc->peers_rwnd = SCTP_SB_LIMIT_RCV(m->sctp_socket);
1006f8829a4aSRandall Stewart 
1007f8829a4aSRandall Stewart 	asoc->smallest_mtu = m->sctp_frag_point;
100817205eccSRandall Stewart #ifdef SCTP_PRINT_FOR_B_AND_M
1009ad81507eSRandall Stewart 	SCTP_PRINTF("smallest_mtu init'd with asoc to :%d\n",
101017205eccSRandall Stewart 	    asoc->smallest_mtu);
101117205eccSRandall Stewart #endif
1012f8829a4aSRandall Stewart 	asoc->minrto = m->sctp_ep.sctp_minrto;
1013f8829a4aSRandall Stewart 	asoc->maxrto = m->sctp_ep.sctp_maxrto;
1014f8829a4aSRandall Stewart 
1015f8829a4aSRandall Stewart 	asoc->locked_on_sending = NULL;
1016f8829a4aSRandall Stewart 	asoc->stream_locked_on = 0;
1017f8829a4aSRandall Stewart 	asoc->ecn_echo_cnt_onq = 0;
1018f8829a4aSRandall Stewart 	asoc->stream_locked = 0;
1019f8829a4aSRandall Stewart 
102042551e99SRandall Stewart 	asoc->send_sack = 1;
102142551e99SRandall Stewart 
102242551e99SRandall Stewart 	LIST_INIT(&asoc->sctp_restricted_addrs);
102342551e99SRandall Stewart 
1024f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->nets);
1025f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->pending_reply_queue);
10262afb3e84SRandall Stewart 	TAILQ_INIT(&asoc->asconf_ack_sent);
1027f8829a4aSRandall Stewart 	/* Setup to fill the hb random cache at first HB */
1028f8829a4aSRandall Stewart 	asoc->hb_random_idx = 4;
1029f8829a4aSRandall Stewart 
1030f8829a4aSRandall Stewart 	asoc->sctp_autoclose_ticks = m->sctp_ep.auto_close_time;
1031f8829a4aSRandall Stewart 
1032f8829a4aSRandall Stewart 	/*
1033b54d3a6cSRandall Stewart 	 * JRS - Pick the default congestion control module based on the
1034b54d3a6cSRandall Stewart 	 * sysctl.
1035b54d3a6cSRandall Stewart 	 */
1036b54d3a6cSRandall Stewart 	switch (m->sctp_ep.sctp_default_cc_module) {
1037b54d3a6cSRandall Stewart 		/* JRS - Standard TCP congestion control */
1038b54d3a6cSRandall Stewart 	case SCTP_CC_RFC2581:
1039b54d3a6cSRandall Stewart 		{
1040b54d3a6cSRandall Stewart 			stcb->asoc.congestion_control_module = SCTP_CC_RFC2581;
1041b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_set_initial_cc_param = &sctp_set_initial_cc_param;
1042b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_sack = &sctp_cwnd_update_after_sack;
1043b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr = &sctp_cwnd_update_after_fr;
1044b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_timeout = &sctp_cwnd_update_after_timeout;
1045b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_ecn_echo = &sctp_cwnd_update_after_ecn_echo;
1046b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_packet_dropped = &sctp_cwnd_update_after_packet_dropped;
1047b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_output = &sctp_cwnd_update_after_output;
1048b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr_timer = &sctp_cwnd_update_after_fr_timer;
1049b54d3a6cSRandall Stewart 			break;
1050b54d3a6cSRandall Stewart 		}
1051b54d3a6cSRandall Stewart 		/* JRS - High Speed TCP congestion control (Floyd) */
1052b54d3a6cSRandall Stewart 	case SCTP_CC_HSTCP:
1053b54d3a6cSRandall Stewart 		{
1054b54d3a6cSRandall Stewart 			stcb->asoc.congestion_control_module = SCTP_CC_HSTCP;
1055b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_set_initial_cc_param = &sctp_set_initial_cc_param;
1056b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_sack = &sctp_hs_cwnd_update_after_sack;
1057b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr = &sctp_hs_cwnd_update_after_fr;
1058b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_timeout = &sctp_cwnd_update_after_timeout;
1059b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_ecn_echo = &sctp_cwnd_update_after_ecn_echo;
1060b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_packet_dropped = &sctp_cwnd_update_after_packet_dropped;
1061b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_output = &sctp_cwnd_update_after_output;
1062b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr_timer = &sctp_cwnd_update_after_fr_timer;
1063b54d3a6cSRandall Stewart 			break;
1064b54d3a6cSRandall Stewart 		}
1065b54d3a6cSRandall Stewart 		/* JRS - HTCP congestion control */
1066b54d3a6cSRandall Stewart 	case SCTP_CC_HTCP:
1067b54d3a6cSRandall Stewart 		{
1068b54d3a6cSRandall Stewart 			stcb->asoc.congestion_control_module = SCTP_CC_HTCP;
1069b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_set_initial_cc_param = &sctp_htcp_set_initial_cc_param;
1070b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_sack = &sctp_htcp_cwnd_update_after_sack;
1071b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr = &sctp_htcp_cwnd_update_after_fr;
1072b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_timeout = &sctp_htcp_cwnd_update_after_timeout;
1073b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_ecn_echo = &sctp_htcp_cwnd_update_after_ecn_echo;
1074b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_packet_dropped = &sctp_cwnd_update_after_packet_dropped;
1075b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_output = &sctp_cwnd_update_after_output;
1076b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr_timer = &sctp_htcp_cwnd_update_after_fr_timer;
1077b54d3a6cSRandall Stewart 			break;
1078b54d3a6cSRandall Stewart 		}
1079b54d3a6cSRandall Stewart 		/* JRS - By default, use RFC2581 */
1080b54d3a6cSRandall Stewart 	default:
1081b54d3a6cSRandall Stewart 		{
1082b54d3a6cSRandall Stewart 			stcb->asoc.congestion_control_module = SCTP_CC_RFC2581;
1083b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_set_initial_cc_param = &sctp_set_initial_cc_param;
1084b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_sack = &sctp_cwnd_update_after_sack;
1085b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr = &sctp_cwnd_update_after_fr;
1086b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_timeout = &sctp_cwnd_update_after_timeout;
1087b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_ecn_echo = &sctp_cwnd_update_after_ecn_echo;
1088b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_packet_dropped = &sctp_cwnd_update_after_packet_dropped;
1089b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_output = &sctp_cwnd_update_after_output;
1090b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr_timer = &sctp_cwnd_update_after_fr_timer;
1091b54d3a6cSRandall Stewart 			break;
1092b54d3a6cSRandall Stewart 		}
1093b54d3a6cSRandall Stewart 	}
1094b54d3a6cSRandall Stewart 
1095b54d3a6cSRandall Stewart 	/*
1096f8829a4aSRandall Stewart 	 * Now the stream parameters, here we allocate space for all streams
1097f8829a4aSRandall Stewart 	 * that we request by default.
1098f8829a4aSRandall Stewart 	 */
1099ea44232bSRandall Stewart 	asoc->strm_realoutsize = asoc->streamoutcnt = asoc->pre_open_streams =
1100f8829a4aSRandall Stewart 	    m->sctp_ep.pre_open_stream_count;
1101f8829a4aSRandall Stewart 	SCTP_MALLOC(asoc->strmout, struct sctp_stream_out *,
1102f8829a4aSRandall Stewart 	    asoc->streamoutcnt * sizeof(struct sctp_stream_out),
1103207304d4SRandall Stewart 	    SCTP_M_STRMO);
1104f8829a4aSRandall Stewart 	if (asoc->strmout == NULL) {
1105f8829a4aSRandall Stewart 		/* big trouble no memory */
1106c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
1107f8829a4aSRandall Stewart 		return (ENOMEM);
1108f8829a4aSRandall Stewart 	}
1109f8829a4aSRandall Stewart 	for (i = 0; i < asoc->streamoutcnt; i++) {
1110f8829a4aSRandall Stewart 		/*
1111f8829a4aSRandall Stewart 		 * inbound side must be set to 0xffff, also NOTE when we get
1112f8829a4aSRandall Stewart 		 * the INIT-ACK back (for INIT sender) we MUST reduce the
1113f8829a4aSRandall Stewart 		 * count (streamoutcnt) but first check if we sent to any of
1114f8829a4aSRandall Stewart 		 * the upper streams that were dropped (if some were). Those
1115f8829a4aSRandall Stewart 		 * that were dropped must be notified to the upper layer as
1116f8829a4aSRandall Stewart 		 * failed to send.
1117f8829a4aSRandall Stewart 		 */
1118f8829a4aSRandall Stewart 		asoc->strmout[i].next_sequence_sent = 0x0;
1119f8829a4aSRandall Stewart 		TAILQ_INIT(&asoc->strmout[i].outqueue);
1120f8829a4aSRandall Stewart 		asoc->strmout[i].stream_no = i;
1121f8829a4aSRandall Stewart 		asoc->strmout[i].last_msg_incomplete = 0;
1122f8829a4aSRandall Stewart 		asoc->strmout[i].next_spoke.tqe_next = 0;
1123f8829a4aSRandall Stewart 		asoc->strmout[i].next_spoke.tqe_prev = 0;
1124f8829a4aSRandall Stewart 	}
1125f8829a4aSRandall Stewart 	/* Now the mapping array */
1126f8829a4aSRandall Stewart 	asoc->mapping_array_size = SCTP_INITIAL_MAPPING_ARRAY;
1127f8829a4aSRandall Stewart 	SCTP_MALLOC(asoc->mapping_array, uint8_t *, asoc->mapping_array_size,
1128207304d4SRandall Stewart 	    SCTP_M_MAP);
1129f8829a4aSRandall Stewart 	if (asoc->mapping_array == NULL) {
1130207304d4SRandall Stewart 		SCTP_FREE(asoc->strmout, SCTP_M_STRMO);
1131c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
1132f8829a4aSRandall Stewart 		return (ENOMEM);
1133f8829a4aSRandall Stewart 	}
1134f8829a4aSRandall Stewart 	memset(asoc->mapping_array, 0, asoc->mapping_array_size);
1135830d754dSRandall Stewart 	/* EY  - initialize the nr_mapping_array just like mapping array */
1136830d754dSRandall Stewart 	asoc->nr_mapping_array_size = SCTP_INITIAL_NR_MAPPING_ARRAY;
1137830d754dSRandall Stewart 	SCTP_MALLOC(asoc->nr_mapping_array, uint8_t *, asoc->nr_mapping_array_size,
1138830d754dSRandall Stewart 	    SCTP_M_MAP);
1139bf1be571SRandall Stewart 	if (asoc->nr_mapping_array == NULL) {
1140bf1be571SRandall Stewart 		SCTP_FREE(asoc->strmout, SCTP_M_STRMO);
1141bf1be571SRandall Stewart 		SCTP_FREE(asoc->mapping_array, SCTP_M_MAP);
1142bf1be571SRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
1143bf1be571SRandall Stewart 		return (ENOMEM);
1144bf1be571SRandall Stewart 	}
1145830d754dSRandall Stewart 	memset(asoc->nr_mapping_array, 0, asoc->nr_mapping_array_size);
1146830d754dSRandall Stewart 
1147f8829a4aSRandall Stewart 	/* Now the init of the other outqueues */
1148f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->free_chunks);
1149f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->out_wheel);
1150f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->control_send_queue);
1151c54a18d2SRandall Stewart 	TAILQ_INIT(&asoc->asconf_send_queue);
1152f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->send_queue);
1153f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->sent_queue);
1154f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->reasmqueue);
1155f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->resetHead);
1156f8829a4aSRandall Stewart 	asoc->max_inbound_streams = m->sctp_ep.max_open_streams_intome;
1157f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->asconf_queue);
1158f8829a4aSRandall Stewart 	/* authentication fields */
1159f8829a4aSRandall Stewart 	asoc->authinfo.random = NULL;
1160830d754dSRandall Stewart 	asoc->authinfo.active_keyid = 0;
1161f8829a4aSRandall Stewart 	asoc->authinfo.assoc_key = NULL;
1162f8829a4aSRandall Stewart 	asoc->authinfo.assoc_keyid = 0;
1163f8829a4aSRandall Stewart 	asoc->authinfo.recv_key = NULL;
1164f8829a4aSRandall Stewart 	asoc->authinfo.recv_keyid = 0;
1165f8829a4aSRandall Stewart 	LIST_INIT(&asoc->shared_keys);
1166f42a358aSRandall Stewart 	asoc->marked_retrans = 0;
1167f42a358aSRandall Stewart 	asoc->timoinit = 0;
1168f42a358aSRandall Stewart 	asoc->timodata = 0;
1169f42a358aSRandall Stewart 	asoc->timosack = 0;
1170f42a358aSRandall Stewart 	asoc->timoshutdown = 0;
1171f42a358aSRandall Stewart 	asoc->timoheartbeat = 0;
1172f42a358aSRandall Stewart 	asoc->timocookie = 0;
1173f42a358aSRandall Stewart 	asoc->timoshutdownack = 0;
11746e55db54SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&asoc->start_time);
11756e55db54SRandall Stewart 	asoc->discontinuity_time = asoc->start_time;
1176eacc51c5SRandall Stewart 	/*
1177eacc51c5SRandall Stewart 	 * sa_ignore MEMLEAK {memory is put in the assoc mapping array and
1178eacc51c5SRandall Stewart 	 * freed later whe the association is freed.
1179eacc51c5SRandall Stewart 	 */
1180f8829a4aSRandall Stewart 	return (0);
1181f8829a4aSRandall Stewart }
1182f8829a4aSRandall Stewart 
11830e13104dSRandall Stewart void
11840e13104dSRandall Stewart sctp_print_mapping_array(struct sctp_association *asoc)
11850e13104dSRandall Stewart {
11860e13104dSRandall Stewart 	int i;
11870e13104dSRandall Stewart 
11880e13104dSRandall Stewart 	printf("Mapping size:%d baseTSN:%8.8x cumAck:%8.8x highestTSN:%8.8x\n",
11890e13104dSRandall Stewart 	    asoc->mapping_array_size,
11900e13104dSRandall Stewart 	    asoc->mapping_array_base_tsn,
11910e13104dSRandall Stewart 	    asoc->cumulative_tsn,
11920e13104dSRandall Stewart 	    asoc->highest_tsn_inside_map
11930e13104dSRandall Stewart 	    );
11940e13104dSRandall Stewart 	for (i = 0; i < asoc->mapping_array_size; i++) {
11950e13104dSRandall Stewart 		printf("%8.8x ", asoc->mapping_array[i]);
11960e13104dSRandall Stewart 		if (((i + 1) % 8) == 0)
11970e13104dSRandall Stewart 			printf("\n");
11980e13104dSRandall Stewart 	}
11990e13104dSRandall Stewart 	printf("\n");
12000e13104dSRandall Stewart }
12010e13104dSRandall Stewart 
1202f8829a4aSRandall Stewart int
12030696e120SRandall Stewart sctp_expand_mapping_array(struct sctp_association *asoc, uint32_t needed)
1204f8829a4aSRandall Stewart {
1205f8829a4aSRandall Stewart 	/* mapping array needs to grow */
1206f8829a4aSRandall Stewart 	uint8_t *new_array;
12070696e120SRandall Stewart 	uint32_t new_size;
1208f8829a4aSRandall Stewart 
12090e13104dSRandall Stewart 
12100696e120SRandall Stewart 	new_size = asoc->mapping_array_size + ((needed + 7) / 8 + SCTP_MAPPING_ARRAY_INCR);
12110e13104dSRandall Stewart 
1212207304d4SRandall Stewart 	SCTP_MALLOC(new_array, uint8_t *, new_size, SCTP_M_MAP);
1213f8829a4aSRandall Stewart 	if (new_array == NULL) {
1214f8829a4aSRandall Stewart 		/* can't get more, forget it */
1215ad81507eSRandall Stewart 		SCTP_PRINTF("No memory for expansion of SCTP mapping array %d\n",
1216f8829a4aSRandall Stewart 		    new_size);
1217f8829a4aSRandall Stewart 		return (-1);
1218f8829a4aSRandall Stewart 	}
1219f8829a4aSRandall Stewart 	memset(new_array, 0, new_size);
1220f8829a4aSRandall Stewart 	memcpy(new_array, asoc->mapping_array, asoc->mapping_array_size);
1221207304d4SRandall Stewart 	SCTP_FREE(asoc->mapping_array, SCTP_M_MAP);
1222f8829a4aSRandall Stewart 	asoc->mapping_array = new_array;
1223f8829a4aSRandall Stewart 	asoc->mapping_array_size = new_size;
1224830d754dSRandall Stewart 	new_size = asoc->nr_mapping_array_size + ((needed + 7) / 8 + SCTP_NR_MAPPING_ARRAY_INCR);
1225830d754dSRandall Stewart 	SCTP_MALLOC(new_array, uint8_t *, new_size, SCTP_M_MAP);
1226830d754dSRandall Stewart 	if (new_array == NULL) {
1227830d754dSRandall Stewart 		/* can't get more, forget it */
1228830d754dSRandall Stewart 		SCTP_PRINTF("No memory for expansion of SCTP mapping array %d\n",
1229830d754dSRandall Stewart 		    new_size);
1230830d754dSRandall Stewart 		return (-1);
1231830d754dSRandall Stewart 	}
1232830d754dSRandall Stewart 	memset(new_array, 0, new_size);
1233830d754dSRandall Stewart 	memcpy(new_array, asoc->nr_mapping_array, asoc->nr_mapping_array_size);
1234830d754dSRandall Stewart 	SCTP_FREE(asoc->nr_mapping_array, SCTP_M_MAP);
1235830d754dSRandall Stewart 	asoc->nr_mapping_array = new_array;
1236830d754dSRandall Stewart 	asoc->nr_mapping_array_size = new_size;
1237830d754dSRandall Stewart 	return (0);
1238830d754dSRandall Stewart }
1239830d754dSRandall Stewart 
12408933fa13SRandall Stewart 
124142551e99SRandall Stewart #if defined(SCTP_USE_THREAD_BASED_ITERATOR)
124242551e99SRandall Stewart static void
124342551e99SRandall Stewart sctp_iterator_work(struct sctp_iterator *it)
124442551e99SRandall Stewart {
124542551e99SRandall Stewart 	int iteration_count = 0;
124642551e99SRandall Stewart 	int inp_skip = 0;
124742551e99SRandall Stewart 
124842551e99SRandall Stewart 	SCTP_ITERATOR_LOCK();
1249ad81507eSRandall Stewart 	if (it->inp) {
125042551e99SRandall Stewart 		SCTP_INP_DECR_REF(it->inp);
1251ad81507eSRandall Stewart 	}
125242551e99SRandall Stewart 	if (it->inp == NULL) {
125342551e99SRandall Stewart 		/* iterator is complete */
125442551e99SRandall Stewart done_with_iterator:
125542551e99SRandall Stewart 		SCTP_ITERATOR_UNLOCK();
125642551e99SRandall Stewart 		if (it->function_atend != NULL) {
125742551e99SRandall Stewart 			(*it->function_atend) (it->pointer, it->val);
125842551e99SRandall Stewart 		}
1259207304d4SRandall Stewart 		SCTP_FREE(it, SCTP_M_ITER);
126042551e99SRandall Stewart 		return;
126142551e99SRandall Stewart 	}
126242551e99SRandall Stewart select_a_new_ep:
126342551e99SRandall Stewart 	SCTP_INP_WLOCK(it->inp);
126442551e99SRandall Stewart 	while (((it->pcb_flags) &&
126542551e99SRandall Stewart 	    ((it->inp->sctp_flags & it->pcb_flags) != it->pcb_flags)) ||
126642551e99SRandall Stewart 	    ((it->pcb_features) &&
126742551e99SRandall Stewart 	    ((it->inp->sctp_features & it->pcb_features) != it->pcb_features))) {
126842551e99SRandall Stewart 		/* endpoint flags or features don't match, so keep looking */
126942551e99SRandall Stewart 		if (it->iterator_flags & SCTP_ITERATOR_DO_SINGLE_INP) {
127042551e99SRandall Stewart 			SCTP_INP_WUNLOCK(it->inp);
127142551e99SRandall Stewart 			goto done_with_iterator;
127242551e99SRandall Stewart 		}
127342551e99SRandall Stewart 		SCTP_INP_WUNLOCK(it->inp);
127442551e99SRandall Stewart 		it->inp = LIST_NEXT(it->inp, sctp_list);
127542551e99SRandall Stewart 		if (it->inp == NULL) {
127642551e99SRandall Stewart 			goto done_with_iterator;
127742551e99SRandall Stewart 		}
127842551e99SRandall Stewart 		SCTP_INP_WLOCK(it->inp);
127942551e99SRandall Stewart 	}
128042551e99SRandall Stewart 
128142551e99SRandall Stewart 	SCTP_INP_WUNLOCK(it->inp);
128242551e99SRandall Stewart 	SCTP_INP_RLOCK(it->inp);
128342551e99SRandall Stewart 
128442551e99SRandall Stewart 	/* now go through each assoc which is in the desired state */
128542551e99SRandall Stewart 	if (it->done_current_ep == 0) {
128642551e99SRandall Stewart 		if (it->function_inp != NULL)
128742551e99SRandall Stewart 			inp_skip = (*it->function_inp) (it->inp, it->pointer, it->val);
128842551e99SRandall Stewart 		it->done_current_ep = 1;
128942551e99SRandall Stewart 	}
129042551e99SRandall Stewart 	if (it->stcb == NULL) {
129142551e99SRandall Stewart 		/* run the per instance function */
129242551e99SRandall Stewart 		it->stcb = LIST_FIRST(&it->inp->sctp_asoc_list);
129342551e99SRandall Stewart 	}
129442551e99SRandall Stewart 	if ((inp_skip) || it->stcb == NULL) {
129542551e99SRandall Stewart 		if (it->function_inp_end != NULL) {
129642551e99SRandall Stewart 			inp_skip = (*it->function_inp_end) (it->inp,
129742551e99SRandall Stewart 			    it->pointer,
129842551e99SRandall Stewart 			    it->val);
129942551e99SRandall Stewart 		}
130042551e99SRandall Stewart 		SCTP_INP_RUNLOCK(it->inp);
130142551e99SRandall Stewart 		goto no_stcb;
130242551e99SRandall Stewart 	}
130342551e99SRandall Stewart 	while (it->stcb) {
130442551e99SRandall Stewart 		SCTP_TCB_LOCK(it->stcb);
130542551e99SRandall Stewart 		if (it->asoc_state && ((it->stcb->asoc.state & it->asoc_state) != it->asoc_state)) {
130642551e99SRandall Stewart 			/* not in the right state... keep looking */
130742551e99SRandall Stewart 			SCTP_TCB_UNLOCK(it->stcb);
130842551e99SRandall Stewart 			goto next_assoc;
130942551e99SRandall Stewart 		}
131042551e99SRandall Stewart 		/* see if we have limited out the iterator loop */
131142551e99SRandall Stewart 		iteration_count++;
131242551e99SRandall Stewart 		if (iteration_count > SCTP_ITERATOR_MAX_AT_ONCE) {
131342551e99SRandall Stewart 			/* Pause to let others grab the lock */
131442551e99SRandall Stewart 			atomic_add_int(&it->stcb->asoc.refcnt, 1);
131542551e99SRandall Stewart 			SCTP_TCB_UNLOCK(it->stcb);
1316c4739e2fSRandall Stewart 
1317c4739e2fSRandall Stewart 			SCTP_INP_INCR_REF(it->inp);
131842551e99SRandall Stewart 			SCTP_INP_RUNLOCK(it->inp);
131942551e99SRandall Stewart 			SCTP_ITERATOR_UNLOCK();
132042551e99SRandall Stewart 			SCTP_ITERATOR_LOCK();
132142551e99SRandall Stewart 			SCTP_INP_RLOCK(it->inp);
1322c4739e2fSRandall Stewart 
1323c4739e2fSRandall Stewart 			SCTP_INP_DECR_REF(it->inp);
132442551e99SRandall Stewart 			SCTP_TCB_LOCK(it->stcb);
132542551e99SRandall Stewart 			atomic_add_int(&it->stcb->asoc.refcnt, -1);
132642551e99SRandall Stewart 			iteration_count = 0;
132742551e99SRandall Stewart 		}
132842551e99SRandall Stewart 		/* run function on this one */
132942551e99SRandall Stewart 		(*it->function_assoc) (it->inp, it->stcb, it->pointer, it->val);
133042551e99SRandall Stewart 
133142551e99SRandall Stewart 		/*
133242551e99SRandall Stewart 		 * we lie here, it really needs to have its own type but
133342551e99SRandall Stewart 		 * first I must verify that this won't effect things :-0
133442551e99SRandall Stewart 		 */
133542551e99SRandall Stewart 		if (it->no_chunk_output == 0)
1336ceaad40aSRandall Stewart 			sctp_chunk_output(it->inp, it->stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
133742551e99SRandall Stewart 
133842551e99SRandall Stewart 		SCTP_TCB_UNLOCK(it->stcb);
133942551e99SRandall Stewart next_assoc:
134042551e99SRandall Stewart 		it->stcb = LIST_NEXT(it->stcb, sctp_tcblist);
134142551e99SRandall Stewart 		if (it->stcb == NULL) {
134242551e99SRandall Stewart 			/* Run last function */
134342551e99SRandall Stewart 			if (it->function_inp_end != NULL) {
134442551e99SRandall Stewart 				inp_skip = (*it->function_inp_end) (it->inp,
134542551e99SRandall Stewart 				    it->pointer,
134642551e99SRandall Stewart 				    it->val);
134742551e99SRandall Stewart 			}
134842551e99SRandall Stewart 		}
134942551e99SRandall Stewart 	}
135042551e99SRandall Stewart 	SCTP_INP_RUNLOCK(it->inp);
135142551e99SRandall Stewart no_stcb:
135242551e99SRandall Stewart 	/* done with all assocs on this endpoint, move on to next endpoint */
135342551e99SRandall Stewart 	it->done_current_ep = 0;
135442551e99SRandall Stewart 	SCTP_INP_WLOCK(it->inp);
135542551e99SRandall Stewart 	SCTP_INP_WUNLOCK(it->inp);
135642551e99SRandall Stewart 	if (it->iterator_flags & SCTP_ITERATOR_DO_SINGLE_INP) {
135742551e99SRandall Stewart 		it->inp = NULL;
135842551e99SRandall Stewart 	} else {
135942551e99SRandall Stewart 		SCTP_INP_INFO_RLOCK();
136042551e99SRandall Stewart 		it->inp = LIST_NEXT(it->inp, sctp_list);
136142551e99SRandall Stewart 		SCTP_INP_INFO_RUNLOCK();
136242551e99SRandall Stewart 	}
136342551e99SRandall Stewart 	if (it->inp == NULL) {
136442551e99SRandall Stewart 		goto done_with_iterator;
136542551e99SRandall Stewart 	}
136642551e99SRandall Stewart 	goto select_a_new_ep;
136742551e99SRandall Stewart }
136842551e99SRandall Stewart 
136942551e99SRandall Stewart void
137042551e99SRandall Stewart sctp_iterator_worker(void)
137142551e99SRandall Stewart {
137242551e99SRandall Stewart 	struct sctp_iterator *it = NULL;
137342551e99SRandall Stewart 
137442551e99SRandall Stewart 	/* This function is called with the WQ lock in place */
137542551e99SRandall Stewart 
1376b3f1ea41SRandall Stewart 	SCTP_BASE_INFO(iterator_running) = 1;
137742551e99SRandall Stewart again:
1378b3f1ea41SRandall Stewart 	it = TAILQ_FIRST(&SCTP_BASE_INFO(iteratorhead));
137942551e99SRandall Stewart 	while (it) {
138042551e99SRandall Stewart 		/* now lets work on this one */
1381b3f1ea41SRandall Stewart 		TAILQ_REMOVE(&SCTP_BASE_INFO(iteratorhead), it, sctp_nxt_itr);
138242551e99SRandall Stewart 		SCTP_IPI_ITERATOR_WQ_UNLOCK();
138342551e99SRandall Stewart 		sctp_iterator_work(it);
138442551e99SRandall Stewart 		SCTP_IPI_ITERATOR_WQ_LOCK();
13853c503c28SRandall Stewart 		/* sa_ignore FREED_MEMORY */
1386b3f1ea41SRandall Stewart 		it = TAILQ_FIRST(&SCTP_BASE_INFO(iteratorhead));
138742551e99SRandall Stewart 	}
1388b3f1ea41SRandall Stewart 	if (TAILQ_FIRST(&SCTP_BASE_INFO(iteratorhead))) {
138942551e99SRandall Stewart 		goto again;
139042551e99SRandall Stewart 	}
1391b3f1ea41SRandall Stewart 	SCTP_BASE_INFO(iterator_running) = 0;
139242551e99SRandall Stewart 	return;
139342551e99SRandall Stewart }
139442551e99SRandall Stewart 
139542551e99SRandall Stewart #endif
139642551e99SRandall Stewart 
1397f8829a4aSRandall Stewart 
1398f8829a4aSRandall Stewart static void
1399f8829a4aSRandall Stewart sctp_handle_addr_wq(void)
1400f8829a4aSRandall Stewart {
1401f8829a4aSRandall Stewart 	/* deal with the ADDR wq from the rtsock calls */
1402f8829a4aSRandall Stewart 	struct sctp_laddr *wi;
140342551e99SRandall Stewart 	struct sctp_asconf_iterator *asc;
1404f8829a4aSRandall Stewart 
140542551e99SRandall Stewart 	SCTP_MALLOC(asc, struct sctp_asconf_iterator *,
1406207304d4SRandall Stewart 	    sizeof(struct sctp_asconf_iterator), SCTP_M_ASC_IT);
140742551e99SRandall Stewart 	if (asc == NULL) {
140842551e99SRandall Stewart 		/* Try later, no memory */
1409f8829a4aSRandall Stewart 		sctp_timer_start(SCTP_TIMER_TYPE_ADDR_WQ,
1410f8829a4aSRandall Stewart 		    (struct sctp_inpcb *)NULL,
1411f8829a4aSRandall Stewart 		    (struct sctp_tcb *)NULL,
1412f8829a4aSRandall Stewart 		    (struct sctp_nets *)NULL);
141342551e99SRandall Stewart 		return;
1414f8829a4aSRandall Stewart 	}
141542551e99SRandall Stewart 	LIST_INIT(&asc->list_of_work);
141642551e99SRandall Stewart 	asc->cnt = 0;
141742551e99SRandall Stewart 	SCTP_IPI_ITERATOR_WQ_LOCK();
1418b3f1ea41SRandall Stewart 	wi = LIST_FIRST(&SCTP_BASE_INFO(addr_wq));
141942551e99SRandall Stewart 	while (wi != NULL) {
142042551e99SRandall Stewart 		LIST_REMOVE(wi, sctp_nxt_addr);
142142551e99SRandall Stewart 		LIST_INSERT_HEAD(&asc->list_of_work, wi, sctp_nxt_addr);
142242551e99SRandall Stewart 		asc->cnt++;
1423b3f1ea41SRandall Stewart 		wi = LIST_FIRST(&SCTP_BASE_INFO(addr_wq));
1424f8829a4aSRandall Stewart 	}
142542551e99SRandall Stewart 	SCTP_IPI_ITERATOR_WQ_UNLOCK();
142642551e99SRandall Stewart 	if (asc->cnt == 0) {
1427207304d4SRandall Stewart 		SCTP_FREE(asc, SCTP_M_ASC_IT);
142842551e99SRandall Stewart 	} else {
14291b649582SRandall Stewart 		(void)sctp_initiate_iterator(sctp_asconf_iterator_ep,
14301b649582SRandall Stewart 		    sctp_asconf_iterator_stcb,
143142551e99SRandall Stewart 		    NULL,	/* No ep end for boundall */
143242551e99SRandall Stewart 		    SCTP_PCB_FLAGS_BOUNDALL,
143342551e99SRandall Stewart 		    SCTP_PCB_ANY_FEATURES,
14341b649582SRandall Stewart 		    SCTP_ASOC_ANY_STATE,
14351b649582SRandall Stewart 		    (void *)asc, 0,
14361b649582SRandall Stewart 		    sctp_asconf_iterator_end, NULL, 0);
143742551e99SRandall Stewart 	}
1438f8829a4aSRandall Stewart }
1439f8829a4aSRandall Stewart 
1440b54d3a6cSRandall Stewart int retcode = 0;
1441b54d3a6cSRandall Stewart int cur_oerr = 0;
1442b54d3a6cSRandall Stewart 
1443f8829a4aSRandall Stewart void
1444f8829a4aSRandall Stewart sctp_timeout_handler(void *t)
1445f8829a4aSRandall Stewart {
1446f8829a4aSRandall Stewart 	struct sctp_inpcb *inp;
1447f8829a4aSRandall Stewart 	struct sctp_tcb *stcb;
1448f8829a4aSRandall Stewart 	struct sctp_nets *net;
1449f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
1450ceaad40aSRandall Stewart 
1451ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
1452ceaad40aSRandall Stewart 	struct socket *so;
1453ceaad40aSRandall Stewart 
1454ceaad40aSRandall Stewart #endif
1455d61374e1SRandall Stewart 	int did_output, type;
1456f8829a4aSRandall Stewart 	struct sctp_iterator *it = NULL;
1457f8829a4aSRandall Stewart 
1458f8829a4aSRandall Stewart 	tmr = (struct sctp_timer *)t;
1459f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)tmr->ep;
1460f8829a4aSRandall Stewart 	stcb = (struct sctp_tcb *)tmr->tcb;
1461f8829a4aSRandall Stewart 	net = (struct sctp_nets *)tmr->net;
14628518270eSMichael Tuexen 	CURVNET_SET((struct vnet *)tmr->vnet);
1463f8829a4aSRandall Stewart 	did_output = 1;
1464f8829a4aSRandall Stewart 
1465f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1466f8829a4aSRandall Stewart 	sctp_audit_log(0xF0, (uint8_t) tmr->type);
1467f8829a4aSRandall Stewart 	sctp_auditing(3, inp, stcb, net);
1468f8829a4aSRandall Stewart #endif
1469f8829a4aSRandall Stewart 
1470f8829a4aSRandall Stewart 	/* sanity checks... */
1471f8829a4aSRandall Stewart 	if (tmr->self != (void *)tmr) {
1472f8829a4aSRandall Stewart 		/*
1473ad81507eSRandall Stewart 		 * SCTP_PRINTF("Stale SCTP timer fired (%p), ignoring...\n",
1474f8829a4aSRandall Stewart 		 * tmr);
1475f8829a4aSRandall Stewart 		 */
14768518270eSMichael Tuexen 		CURVNET_RESTORE();
1477f8829a4aSRandall Stewart 		return;
1478f8829a4aSRandall Stewart 	}
1479a5d547adSRandall Stewart 	tmr->stopped_from = 0xa001;
1480f8829a4aSRandall Stewart 	if (!SCTP_IS_TIMER_TYPE_VALID(tmr->type)) {
1481f8829a4aSRandall Stewart 		/*
1482ad81507eSRandall Stewart 		 * SCTP_PRINTF("SCTP timer fired with invalid type: 0x%x\n",
1483f8829a4aSRandall Stewart 		 * tmr->type);
1484f8829a4aSRandall Stewart 		 */
14858518270eSMichael Tuexen 		CURVNET_RESTORE();
1486f8829a4aSRandall Stewart 		return;
1487f8829a4aSRandall Stewart 	}
1488a5d547adSRandall Stewart 	tmr->stopped_from = 0xa002;
1489f8829a4aSRandall Stewart 	if ((tmr->type != SCTP_TIMER_TYPE_ADDR_WQ) && (inp == NULL)) {
14908518270eSMichael Tuexen 		CURVNET_RESTORE();
1491f8829a4aSRandall Stewart 		return;
1492f8829a4aSRandall Stewart 	}
1493f8829a4aSRandall Stewart 	/* if this is an iterator timeout, get the struct and clear inp */
1494a5d547adSRandall Stewart 	tmr->stopped_from = 0xa003;
1495f8829a4aSRandall Stewart 	if (tmr->type == SCTP_TIMER_TYPE_ITERATOR) {
1496f8829a4aSRandall Stewart 		it = (struct sctp_iterator *)inp;
1497f8829a4aSRandall Stewart 		inp = NULL;
1498f8829a4aSRandall Stewart 	}
1499d61374e1SRandall Stewart 	type = tmr->type;
1500f8829a4aSRandall Stewart 	if (inp) {
1501f8829a4aSRandall Stewart 		SCTP_INP_INCR_REF(inp);
1502f8829a4aSRandall Stewart 		if ((inp->sctp_socket == 0) &&
1503f8829a4aSRandall Stewart 		    ((tmr->type != SCTP_TIMER_TYPE_INPKILL) &&
1504810ec536SMichael Tuexen 		    (tmr->type != SCTP_TIMER_TYPE_INIT) &&
1505a1e13272SRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_SEND) &&
1506a1e13272SRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_RECV) &&
1507a1e13272SRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_HEARTBEAT) &&
1508f8829a4aSRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_SHUTDOWN) &&
1509f8829a4aSRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_SHUTDOWNACK) &&
1510f8829a4aSRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_SHUTDOWNGUARD) &&
1511f8829a4aSRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_ASOCKILL))
1512f8829a4aSRandall Stewart 		    ) {
1513f8829a4aSRandall Stewart 			SCTP_INP_DECR_REF(inp);
15148518270eSMichael Tuexen 			CURVNET_RESTORE();
1515f8829a4aSRandall Stewart 			return;
1516f8829a4aSRandall Stewart 		}
1517f8829a4aSRandall Stewart 	}
1518a5d547adSRandall Stewart 	tmr->stopped_from = 0xa004;
1519f8829a4aSRandall Stewart 	if (stcb) {
1520c105859eSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
1521f8829a4aSRandall Stewart 		if (stcb->asoc.state == 0) {
1522c105859eSRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, -1);
1523f8829a4aSRandall Stewart 			if (inp) {
1524f8829a4aSRandall Stewart 				SCTP_INP_DECR_REF(inp);
1525f8829a4aSRandall Stewart 			}
15268518270eSMichael Tuexen 			CURVNET_RESTORE();
1527f8829a4aSRandall Stewart 			return;
1528f8829a4aSRandall Stewart 		}
1529f8829a4aSRandall Stewart 	}
1530a5d547adSRandall Stewart 	tmr->stopped_from = 0xa005;
1531ad81507eSRandall Stewart 	SCTPDBG(SCTP_DEBUG_TIMER1, "Timer type %d goes off\n", tmr->type);
1532139bc87fSRandall Stewart 	if (!SCTP_OS_TIMER_ACTIVE(&tmr->timer)) {
1533f8829a4aSRandall Stewart 		if (inp) {
1534f8829a4aSRandall Stewart 			SCTP_INP_DECR_REF(inp);
1535f8829a4aSRandall Stewart 		}
1536207304d4SRandall Stewart 		if (stcb) {
1537207304d4SRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, -1);
1538207304d4SRandall Stewart 		}
15398518270eSMichael Tuexen 		CURVNET_RESTORE();
1540f8829a4aSRandall Stewart 		return;
1541f8829a4aSRandall Stewart 	}
1542a5d547adSRandall Stewart 	tmr->stopped_from = 0xa006;
1543a5d547adSRandall Stewart 
1544f8829a4aSRandall Stewart 	if (stcb) {
1545f8829a4aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
154650cec919SRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, -1);
1547b54d3a6cSRandall Stewart 		if ((tmr->type != SCTP_TIMER_TYPE_ASOCKILL) &&
1548b54d3a6cSRandall Stewart 		    ((stcb->asoc.state == 0) ||
1549b54d3a6cSRandall Stewart 		    (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED))) {
1550b54d3a6cSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
1551b54d3a6cSRandall Stewart 			if (inp) {
1552b54d3a6cSRandall Stewart 				SCTP_INP_DECR_REF(inp);
1553b54d3a6cSRandall Stewart 			}
15548518270eSMichael Tuexen 			CURVNET_RESTORE();
1555b54d3a6cSRandall Stewart 			return;
1556b54d3a6cSRandall Stewart 		}
1557f8829a4aSRandall Stewart 	}
155844b7479bSRandall Stewart 	/* record in stopped what t-o occured */
155944b7479bSRandall Stewart 	tmr->stopped_from = tmr->type;
156044b7479bSRandall Stewart 
1561f8829a4aSRandall Stewart 	/* mark as being serviced now */
156244b7479bSRandall Stewart 	if (SCTP_OS_TIMER_PENDING(&tmr->timer)) {
156344b7479bSRandall Stewart 		/*
156444b7479bSRandall Stewart 		 * Callout has been rescheduled.
156544b7479bSRandall Stewart 		 */
156644b7479bSRandall Stewart 		goto get_out;
156744b7479bSRandall Stewart 	}
156844b7479bSRandall Stewart 	if (!SCTP_OS_TIMER_ACTIVE(&tmr->timer)) {
156944b7479bSRandall Stewart 		/*
157044b7479bSRandall Stewart 		 * Not active, so no action.
157144b7479bSRandall Stewart 		 */
157244b7479bSRandall Stewart 		goto get_out;
157344b7479bSRandall Stewart 	}
1574139bc87fSRandall Stewart 	SCTP_OS_TIMER_DEACTIVATE(&tmr->timer);
1575f8829a4aSRandall Stewart 
1576f8829a4aSRandall Stewart 	/* call the handler for the appropriate timer type */
1577f8829a4aSRandall Stewart 	switch (tmr->type) {
1578d61a0ae0SRandall Stewart 	case SCTP_TIMER_TYPE_ZERO_COPY:
1579eacc51c5SRandall Stewart 		if (inp == NULL) {
1580eacc51c5SRandall Stewart 			break;
1581eacc51c5SRandall Stewart 		}
1582d61a0ae0SRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_ZERO_COPY_ACTIVE)) {
1583d61a0ae0SRandall Stewart 			SCTP_ZERO_COPY_EVENT(inp, inp->sctp_socket);
1584d61a0ae0SRandall Stewart 		}
1585d61a0ae0SRandall Stewart 		break;
1586ad21a364SRandall Stewart 	case SCTP_TIMER_TYPE_ZCOPY_SENDQ:
1587eacc51c5SRandall Stewart 		if (inp == NULL) {
1588eacc51c5SRandall Stewart 			break;
1589eacc51c5SRandall Stewart 		}
1590ad21a364SRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_ZERO_COPY_ACTIVE)) {
1591ad21a364SRandall Stewart 			SCTP_ZERO_COPY_SENDQ_EVENT(inp, inp->sctp_socket);
1592ad21a364SRandall Stewart 		}
1593ad21a364SRandall Stewart 		break;
1594f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ADDR_WQ:
1595f8829a4aSRandall Stewart 		sctp_handle_addr_wq();
1596f8829a4aSRandall Stewart 		break;
1597f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ITERATOR:
1598f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoiterator);
1599f8829a4aSRandall Stewart 		sctp_iterator_timer(it);
1600f8829a4aSRandall Stewart 		break;
1601f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
1602ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1603ad81507eSRandall Stewart 			break;
1604ad81507eSRandall Stewart 		}
1605f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timodata);
1606f42a358aSRandall Stewart 		stcb->asoc.timodata++;
1607f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up--;
1608f8829a4aSRandall Stewart 		if (stcb->asoc.num_send_timers_up < 0) {
1609f8829a4aSRandall Stewart 			stcb->asoc.num_send_timers_up = 0;
1610f8829a4aSRandall Stewart 		}
1611b54d3a6cSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
1612b54d3a6cSRandall Stewart 		cur_oerr = stcb->asoc.overall_error_count;
1613b54d3a6cSRandall Stewart 		retcode = sctp_t3rxt_timer(inp, stcb, net);
1614b54d3a6cSRandall Stewart 		if (retcode) {
1615f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1616f8829a4aSRandall Stewart 
1617f8829a4aSRandall Stewart 			goto out_decr;
1618f8829a4aSRandall Stewart 		}
1619b54d3a6cSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
1620f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1621f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1622f8829a4aSRandall Stewart #endif
1623ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
1624f8829a4aSRandall Stewart 		if ((stcb->asoc.num_send_timers_up == 0) &&
1625f8829a4aSRandall Stewart 		    (stcb->asoc.sent_queue_cnt > 0)
1626f8829a4aSRandall Stewart 		    ) {
1627f8829a4aSRandall Stewart 			struct sctp_tmit_chunk *chk;
1628f8829a4aSRandall Stewart 
1629f8829a4aSRandall Stewart 			/*
1630f8829a4aSRandall Stewart 			 * safeguard. If there on some on the sent queue
1631f8829a4aSRandall Stewart 			 * somewhere but no timers running something is
1632f8829a4aSRandall Stewart 			 * wrong... so we start a timer on the first chunk
1633f8829a4aSRandall Stewart 			 * on the send queue on whatever net it is sent to.
1634f8829a4aSRandall Stewart 			 */
1635f8829a4aSRandall Stewart 			chk = TAILQ_FIRST(&stcb->asoc.sent_queue);
1636f8829a4aSRandall Stewart 			sctp_timer_start(SCTP_TIMER_TYPE_SEND, inp, stcb,
1637f8829a4aSRandall Stewart 			    chk->whoTo);
1638f8829a4aSRandall Stewart 		}
1639f8829a4aSRandall Stewart 		break;
1640f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
1641ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1642ad81507eSRandall Stewart 			break;
1643ad81507eSRandall Stewart 		}
1644f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoinit);
1645f42a358aSRandall Stewart 		stcb->asoc.timoinit++;
1646f8829a4aSRandall Stewart 		if (sctp_t1init_timer(inp, stcb, net)) {
1647f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1648f8829a4aSRandall Stewart 			goto out_decr;
1649f8829a4aSRandall Stewart 		}
1650f8829a4aSRandall Stewart 		/* We do output but not here */
1651f8829a4aSRandall Stewart 		did_output = 0;
1652f8829a4aSRandall Stewart 		break;
1653f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
1654ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1655ad81507eSRandall Stewart 			break;
1656c4739e2fSRandall Stewart 		} {
1657c4739e2fSRandall Stewart 			int abort_flag;
1658c4739e2fSRandall Stewart 
1659f8829a4aSRandall Stewart 			SCTP_STAT_INCR(sctps_timosack);
1660f42a358aSRandall Stewart 			stcb->asoc.timosack++;
1661c4739e2fSRandall Stewart 			if (stcb->asoc.cumulative_tsn != stcb->asoc.highest_tsn_inside_map)
1662c4739e2fSRandall Stewart 				sctp_sack_check(stcb, 0, 0, &abort_flag);
1663830d754dSRandall Stewart 
1664830d754dSRandall Stewart 			/*
1665830d754dSRandall Stewart 			 * EY if nr_sacks used then send an nr-sack , a sack
1666830d754dSRandall Stewart 			 * otherwise
1667830d754dSRandall Stewart 			 */
1668830d754dSRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_nr_sack_on_off) && stcb->asoc.peer_supports_nr_sack)
1669830d754dSRandall Stewart 				sctp_send_nr_sack(stcb);
1670830d754dSRandall Stewart 			else
1671f8829a4aSRandall Stewart 				sctp_send_sack(stcb);
1672c4739e2fSRandall Stewart 		}
1673f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1674f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1675f8829a4aSRandall Stewart #endif
1676ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SACK_TMR, SCTP_SO_NOT_LOCKED);
1677f8829a4aSRandall Stewart 		break;
1678f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
1679ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1680ad81507eSRandall Stewart 			break;
1681ad81507eSRandall Stewart 		}
1682f8829a4aSRandall Stewart 		if (sctp_shutdown_timer(inp, stcb, net)) {
1683f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1684f8829a4aSRandall Stewart 			goto out_decr;
1685f8829a4aSRandall Stewart 		}
1686f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoshutdown);
1687f42a358aSRandall Stewart 		stcb->asoc.timoshutdown++;
1688f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1689f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1690f8829a4aSRandall Stewart #endif
1691ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SHUT_TMR, SCTP_SO_NOT_LOCKED);
1692f8829a4aSRandall Stewart 		break;
1693f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
1694f8829a4aSRandall Stewart 		{
16954c9179adSRandall Stewart 			struct sctp_nets *lnet;
1696f8829a4aSRandall Stewart 			int cnt_of_unconf = 0;
1697f8829a4aSRandall Stewart 
1698ad81507eSRandall Stewart 			if ((stcb == NULL) || (inp == NULL)) {
1699ad81507eSRandall Stewart 				break;
1700ad81507eSRandall Stewart 			}
1701f8829a4aSRandall Stewart 			SCTP_STAT_INCR(sctps_timoheartbeat);
1702f42a358aSRandall Stewart 			stcb->asoc.timoheartbeat++;
17034c9179adSRandall Stewart 			TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
17044c9179adSRandall Stewart 				if ((lnet->dest_state & SCTP_ADDR_UNCONFIRMED) &&
17054c9179adSRandall Stewart 				    (lnet->dest_state & SCTP_ADDR_REACHABLE)) {
1706f8829a4aSRandall Stewart 					cnt_of_unconf++;
1707f8829a4aSRandall Stewart 				}
1708f8829a4aSRandall Stewart 			}
1709f8829a4aSRandall Stewart 			if (cnt_of_unconf == 0) {
17104c9179adSRandall Stewart 				if (sctp_heartbeat_timer(inp, stcb, lnet,
17114c9179adSRandall Stewart 				    cnt_of_unconf)) {
1712f8829a4aSRandall Stewart 					/* no need to unlock on tcb its gone */
1713f8829a4aSRandall Stewart 					goto out_decr;
1714f8829a4aSRandall Stewart 				}
1715f8829a4aSRandall Stewart 			}
1716f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
17174c9179adSRandall Stewart 			sctp_auditing(4, inp, stcb, lnet);
1718f8829a4aSRandall Stewart #endif
17194c9179adSRandall Stewart 			sctp_timer_start(SCTP_TIMER_TYPE_HEARTBEAT,
17204c9179adSRandall Stewart 			    stcb->sctp_ep, stcb, lnet);
1721ceaad40aSRandall Stewart 			sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_HB_TMR, SCTP_SO_NOT_LOCKED);
1722f8829a4aSRandall Stewart 		}
1723f8829a4aSRandall Stewart 		break;
1724f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
1725ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1726ad81507eSRandall Stewart 			break;
1727ad81507eSRandall Stewart 		}
1728f8829a4aSRandall Stewart 		if (sctp_cookie_timer(inp, stcb, net)) {
1729f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1730f8829a4aSRandall Stewart 			goto out_decr;
1731f8829a4aSRandall Stewart 		}
1732f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timocookie);
1733f42a358aSRandall Stewart 		stcb->asoc.timocookie++;
1734f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1735f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1736f8829a4aSRandall Stewart #endif
1737f8829a4aSRandall Stewart 		/*
1738f8829a4aSRandall Stewart 		 * We consider T3 and Cookie timer pretty much the same with
1739f8829a4aSRandall Stewart 		 * respect to where from in chunk_output.
1740f8829a4aSRandall Stewart 		 */
1741ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
1742f8829a4aSRandall Stewart 		break;
1743f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
1744f8829a4aSRandall Stewart 		{
1745f8829a4aSRandall Stewart 			struct timeval tv;
1746f8829a4aSRandall Stewart 			int i, secret;
1747f8829a4aSRandall Stewart 
1748ad81507eSRandall Stewart 			if (inp == NULL) {
1749ad81507eSRandall Stewart 				break;
1750ad81507eSRandall Stewart 			}
1751f8829a4aSRandall Stewart 			SCTP_STAT_INCR(sctps_timosecret);
17526e55db54SRandall Stewart 			(void)SCTP_GETTIME_TIMEVAL(&tv);
1753f8829a4aSRandall Stewart 			SCTP_INP_WLOCK(inp);
1754f8829a4aSRandall Stewart 			inp->sctp_ep.time_of_secret_change = tv.tv_sec;
1755f8829a4aSRandall Stewart 			inp->sctp_ep.last_secret_number =
1756f8829a4aSRandall Stewart 			    inp->sctp_ep.current_secret_number;
1757f8829a4aSRandall Stewart 			inp->sctp_ep.current_secret_number++;
1758f8829a4aSRandall Stewart 			if (inp->sctp_ep.current_secret_number >=
1759f8829a4aSRandall Stewart 			    SCTP_HOW_MANY_SECRETS) {
1760f8829a4aSRandall Stewart 				inp->sctp_ep.current_secret_number = 0;
1761f8829a4aSRandall Stewart 			}
1762f8829a4aSRandall Stewart 			secret = (int)inp->sctp_ep.current_secret_number;
1763f8829a4aSRandall Stewart 			for (i = 0; i < SCTP_NUMBER_OF_SECRETS; i++) {
1764f8829a4aSRandall Stewart 				inp->sctp_ep.secret_key[secret][i] =
1765f8829a4aSRandall Stewart 				    sctp_select_initial_TSN(&inp->sctp_ep);
1766f8829a4aSRandall Stewart 			}
1767f8829a4aSRandall Stewart 			SCTP_INP_WUNLOCK(inp);
1768f8829a4aSRandall Stewart 			sctp_timer_start(SCTP_TIMER_TYPE_NEWCOOKIE, inp, stcb, net);
1769f8829a4aSRandall Stewart 		}
1770f8829a4aSRandall Stewart 		did_output = 0;
1771f8829a4aSRandall Stewart 		break;
1772f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
1773ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1774ad81507eSRandall Stewart 			break;
1775ad81507eSRandall Stewart 		}
1776f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timopathmtu);
1777f8829a4aSRandall Stewart 		sctp_pathmtu_timer(inp, stcb, net);
1778f8829a4aSRandall Stewart 		did_output = 0;
1779f8829a4aSRandall Stewart 		break;
1780f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
1781ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1782ad81507eSRandall Stewart 			break;
1783ad81507eSRandall Stewart 		}
1784f8829a4aSRandall Stewart 		if (sctp_shutdownack_timer(inp, stcb, net)) {
1785f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1786f8829a4aSRandall Stewart 			goto out_decr;
1787f8829a4aSRandall Stewart 		}
1788f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoshutdownack);
1789f42a358aSRandall Stewart 		stcb->asoc.timoshutdownack++;
1790f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1791f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1792f8829a4aSRandall Stewart #endif
1793ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SHUT_ACK_TMR, SCTP_SO_NOT_LOCKED);
1794f8829a4aSRandall Stewart 		break;
1795f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
1796ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1797ad81507eSRandall Stewart 			break;
1798ad81507eSRandall Stewart 		}
1799f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoshutdownguard);
1800f8829a4aSRandall Stewart 		sctp_abort_an_association(inp, stcb,
1801ceaad40aSRandall Stewart 		    SCTP_SHUTDOWN_GUARD_EXPIRES, NULL, SCTP_SO_NOT_LOCKED);
1802f8829a4aSRandall Stewart 		/* no need to unlock on tcb its gone */
1803f8829a4aSRandall Stewart 		goto out_decr;
1804f8829a4aSRandall Stewart 
1805f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_STRRESET:
1806ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1807ad81507eSRandall Stewart 			break;
1808ad81507eSRandall Stewart 		}
1809f8829a4aSRandall Stewart 		if (sctp_strreset_timer(inp, stcb, net)) {
1810f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1811f8829a4aSRandall Stewart 			goto out_decr;
1812f8829a4aSRandall Stewart 		}
1813f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timostrmrst);
1814ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_STRRST_TMR, SCTP_SO_NOT_LOCKED);
1815f8829a4aSRandall Stewart 		break;
1816f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_EARLYFR:
1817f8829a4aSRandall Stewart 		/* Need to do FR of things for net */
1818ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1819ad81507eSRandall Stewart 			break;
1820ad81507eSRandall Stewart 		}
1821f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoearlyfr);
1822f8829a4aSRandall Stewart 		sctp_early_fr_timer(inp, stcb, net);
1823f8829a4aSRandall Stewart 		break;
1824f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASCONF:
1825ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1826ad81507eSRandall Stewart 			break;
1827ad81507eSRandall Stewart 		}
1828f8829a4aSRandall Stewart 		if (sctp_asconf_timer(inp, stcb, net)) {
1829f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1830f8829a4aSRandall Stewart 			goto out_decr;
1831f8829a4aSRandall Stewart 		}
1832f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoasconf);
1833f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1834f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1835f8829a4aSRandall Stewart #endif
1836ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_ASCONF_TMR, SCTP_SO_NOT_LOCKED);
1837f8829a4aSRandall Stewart 		break;
1838851b7298SRandall Stewart 	case SCTP_TIMER_TYPE_PRIM_DELETED:
1839851b7298SRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1840851b7298SRandall Stewart 			break;
1841851b7298SRandall Stewart 		}
184204ee05e8SRandall Stewart 		sctp_delete_prim_timer(inp, stcb, net);
1843851b7298SRandall Stewart 		SCTP_STAT_INCR(sctps_timodelprim);
1844851b7298SRandall Stewart 		break;
1845f8829a4aSRandall Stewart 
1846f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_AUTOCLOSE:
1847ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1848ad81507eSRandall Stewart 			break;
1849ad81507eSRandall Stewart 		}
1850f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoautoclose);
1851f8829a4aSRandall Stewart 		sctp_autoclose_timer(inp, stcb, net);
1852ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_AUTOCLOSE_TMR, SCTP_SO_NOT_LOCKED);
1853f8829a4aSRandall Stewart 		did_output = 0;
1854f8829a4aSRandall Stewart 		break;
1855f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASOCKILL:
1856ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1857ad81507eSRandall Stewart 			break;
1858ad81507eSRandall Stewart 		}
1859f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoassockill);
1860f8829a4aSRandall Stewart 		/* Can we free it yet? */
1861f8829a4aSRandall Stewart 		SCTP_INP_DECR_REF(inp);
1862a5d547adSRandall Stewart 		sctp_timer_stop(SCTP_TIMER_TYPE_ASOCKILL, inp, stcb, NULL, SCTP_FROM_SCTPUTIL + SCTP_LOC_1);
1863ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
1864ceaad40aSRandall Stewart 		so = SCTP_INP_SO(inp);
1865ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
1866ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
1867ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
1868ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
1869ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
1870ceaad40aSRandall Stewart #endif
1871c4739e2fSRandall Stewart 		(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC, SCTP_FROM_SCTPUTIL + SCTP_LOC_2);
1872ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
1873ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
1874ceaad40aSRandall Stewart #endif
1875f8829a4aSRandall Stewart 		/*
1876f8829a4aSRandall Stewart 		 * free asoc, always unlocks (or destroy's) so prevent
1877f8829a4aSRandall Stewart 		 * duplicate unlock or unlock of a free mtx :-0
1878f8829a4aSRandall Stewart 		 */
1879f8829a4aSRandall Stewart 		stcb = NULL;
1880f8829a4aSRandall Stewart 		goto out_no_decr;
1881f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INPKILL:
1882f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoinpkill);
1883ad81507eSRandall Stewart 		if (inp == NULL) {
1884ad81507eSRandall Stewart 			break;
1885ad81507eSRandall Stewart 		}
1886f8829a4aSRandall Stewart 		/*
1887f8829a4aSRandall Stewart 		 * special case, take away our increment since WE are the
1888f8829a4aSRandall Stewart 		 * killer
1889f8829a4aSRandall Stewart 		 */
1890f8829a4aSRandall Stewart 		SCTP_INP_DECR_REF(inp);
1891a5d547adSRandall Stewart 		sctp_timer_stop(SCTP_TIMER_TYPE_INPKILL, inp, NULL, NULL, SCTP_FROM_SCTPUTIL + SCTP_LOC_3);
1892b0552ae2SRandall Stewart 		sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
1893b0552ae2SRandall Stewart 		    SCTP_CALLED_DIRECTLY_NOCMPSET);
1894d61374e1SRandall Stewart 		inp = NULL;
1895f8829a4aSRandall Stewart 		goto out_no_decr;
1896f8829a4aSRandall Stewart 	default:
1897ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_TIMER1, "sctp_timeout_handler:unknown timer %d\n",
1898f8829a4aSRandall Stewart 		    tmr->type);
1899f8829a4aSRandall Stewart 		break;
1900f8829a4aSRandall Stewart 	};
1901f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1902f8829a4aSRandall Stewart 	sctp_audit_log(0xF1, (uint8_t) tmr->type);
1903f8829a4aSRandall Stewart 	if (inp)
1904f8829a4aSRandall Stewart 		sctp_auditing(5, inp, stcb, net);
1905f8829a4aSRandall Stewart #endif
1906f8829a4aSRandall Stewart 	if ((did_output) && stcb) {
1907f8829a4aSRandall Stewart 		/*
1908f8829a4aSRandall Stewart 		 * Now we need to clean up the control chunk chain if an
1909f8829a4aSRandall Stewart 		 * ECNE is on it. It must be marked as UNSENT again so next
1910f8829a4aSRandall Stewart 		 * call will continue to send it until such time that we get
1911f8829a4aSRandall Stewart 		 * a CWR, to remove it. It is, however, less likely that we
1912f8829a4aSRandall Stewart 		 * will find a ecn echo on the chain though.
1913f8829a4aSRandall Stewart 		 */
1914f8829a4aSRandall Stewart 		sctp_fix_ecn_echo(&stcb->asoc);
1915f8829a4aSRandall Stewart 	}
191644b7479bSRandall Stewart get_out:
1917f8829a4aSRandall Stewart 	if (stcb) {
1918f8829a4aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
1919f8829a4aSRandall Stewart 	}
1920f8829a4aSRandall Stewart out_decr:
1921f8829a4aSRandall Stewart 	if (inp) {
1922f8829a4aSRandall Stewart 		SCTP_INP_DECR_REF(inp);
1923f8829a4aSRandall Stewart 	}
1924f8829a4aSRandall Stewart out_no_decr:
1925ad81507eSRandall Stewart 	SCTPDBG(SCTP_DEBUG_TIMER1, "Timer now complete (type %d)\n",
1926d61374e1SRandall Stewart 	    type);
19278518270eSMichael Tuexen 	CURVNET_RESTORE();
1928f8829a4aSRandall Stewart }
1929f8829a4aSRandall Stewart 
1930ad81507eSRandall Stewart void
1931f8829a4aSRandall Stewart sctp_timer_start(int t_type, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
1932f8829a4aSRandall Stewart     struct sctp_nets *net)
1933f8829a4aSRandall Stewart {
1934f8829a4aSRandall Stewart 	int to_ticks;
1935f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
1936f8829a4aSRandall Stewart 
1937139bc87fSRandall Stewart 	if ((t_type != SCTP_TIMER_TYPE_ADDR_WQ) && (inp == NULL))
1938ad81507eSRandall Stewart 		return;
1939f8829a4aSRandall Stewart 
1940f8829a4aSRandall Stewart 	to_ticks = 0;
1941f8829a4aSRandall Stewart 
1942f8829a4aSRandall Stewart 	tmr = NULL;
1943f8829a4aSRandall Stewart 	if (stcb) {
1944f8829a4aSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
1945f8829a4aSRandall Stewart 	}
1946f8829a4aSRandall Stewart 	switch (t_type) {
1947d61a0ae0SRandall Stewart 	case SCTP_TIMER_TYPE_ZERO_COPY:
1948d61a0ae0SRandall Stewart 		tmr = &inp->sctp_ep.zero_copy_timer;
1949d61a0ae0SRandall Stewart 		to_ticks = SCTP_ZERO_COPY_TICK_DELAY;
1950d61a0ae0SRandall Stewart 		break;
1951ad21a364SRandall Stewart 	case SCTP_TIMER_TYPE_ZCOPY_SENDQ:
1952ad21a364SRandall Stewart 		tmr = &inp->sctp_ep.zero_copy_sendq_timer;
1953ad21a364SRandall Stewart 		to_ticks = SCTP_ZERO_COPY_SENDQ_TICK_DELAY;
1954ad21a364SRandall Stewart 		break;
1955f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ADDR_WQ:
1956f8829a4aSRandall Stewart 		/* Only 1 tick away :-) */
1957b3f1ea41SRandall Stewart 		tmr = &SCTP_BASE_INFO(addr_wq_timer);
195842551e99SRandall Stewart 		to_ticks = SCTP_ADDRESS_TICK_DELAY;
1959f8829a4aSRandall Stewart 		break;
1960f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ITERATOR:
1961f8829a4aSRandall Stewart 		{
1962f8829a4aSRandall Stewart 			struct sctp_iterator *it;
1963f8829a4aSRandall Stewart 
1964f8829a4aSRandall Stewart 			it = (struct sctp_iterator *)inp;
1965f8829a4aSRandall Stewart 			tmr = &it->tmr;
1966f8829a4aSRandall Stewart 			to_ticks = SCTP_ITERATOR_TICKS;
1967f8829a4aSRandall Stewart 		}
1968f8829a4aSRandall Stewart 		break;
1969f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
1970f8829a4aSRandall Stewart 		/* Here we use the RTO timer */
1971f8829a4aSRandall Stewart 		{
1972f8829a4aSRandall Stewart 			int rto_val;
1973f8829a4aSRandall Stewart 
1974f8829a4aSRandall Stewart 			if ((stcb == NULL) || (net == NULL)) {
1975ad81507eSRandall Stewart 				return;
1976f8829a4aSRandall Stewart 			}
1977f8829a4aSRandall Stewart 			tmr = &net->rxt_timer;
1978f8829a4aSRandall Stewart 			if (net->RTO == 0) {
1979f8829a4aSRandall Stewart 				rto_val = stcb->asoc.initial_rto;
1980f8829a4aSRandall Stewart 			} else {
1981f8829a4aSRandall Stewart 				rto_val = net->RTO;
1982f8829a4aSRandall Stewart 			}
1983f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(rto_val);
1984f8829a4aSRandall Stewart 		}
1985f8829a4aSRandall Stewart 		break;
1986f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
1987f8829a4aSRandall Stewart 		/*
1988f8829a4aSRandall Stewart 		 * Here we use the INIT timer default usually about 1
1989f8829a4aSRandall Stewart 		 * minute.
1990f8829a4aSRandall Stewart 		 */
1991f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
1992ad81507eSRandall Stewart 			return;
1993f8829a4aSRandall Stewart 		}
1994f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
1995f8829a4aSRandall Stewart 		if (net->RTO == 0) {
1996f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
1997f8829a4aSRandall Stewart 		} else {
1998f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
1999f8829a4aSRandall Stewart 		}
2000f8829a4aSRandall Stewart 		break;
2001f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
2002f8829a4aSRandall Stewart 		/*
2003f8829a4aSRandall Stewart 		 * Here we use the Delayed-Ack timer value from the inp
2004f8829a4aSRandall Stewart 		 * ususually about 200ms.
2005f8829a4aSRandall Stewart 		 */
2006f8829a4aSRandall Stewart 		if (stcb == NULL) {
2007ad81507eSRandall Stewart 			return;
2008f8829a4aSRandall Stewart 		}
2009f8829a4aSRandall Stewart 		tmr = &stcb->asoc.dack_timer;
2010f8829a4aSRandall Stewart 		to_ticks = MSEC_TO_TICKS(stcb->asoc.delayed_ack);
2011f8829a4aSRandall Stewart 		break;
2012f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
2013f8829a4aSRandall Stewart 		/* Here we use the RTO of the destination. */
2014f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2015ad81507eSRandall Stewart 			return;
2016f8829a4aSRandall Stewart 		}
2017f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2018f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2019f8829a4aSRandall Stewart 		} else {
2020f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2021f8829a4aSRandall Stewart 		}
2022f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2023f8829a4aSRandall Stewart 		break;
2024f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
2025f8829a4aSRandall Stewart 		/*
2026f8829a4aSRandall Stewart 		 * the net is used here so that we can add in the RTO. Even
2027f8829a4aSRandall Stewart 		 * though we use a different timer. We also add the HB timer
2028f8829a4aSRandall Stewart 		 * PLUS a random jitter.
2029f8829a4aSRandall Stewart 		 */
2030ad81507eSRandall Stewart 		if ((inp == NULL) || (stcb == NULL)) {
2031ad81507eSRandall Stewart 			return;
2032ad81507eSRandall Stewart 		} else {
2033f8829a4aSRandall Stewart 			uint32_t rndval;
2034f8829a4aSRandall Stewart 			uint8_t this_random;
2035f8829a4aSRandall Stewart 			int cnt_of_unconf = 0;
2036f8829a4aSRandall Stewart 			struct sctp_nets *lnet;
2037f8829a4aSRandall Stewart 
2038f8829a4aSRandall Stewart 			TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
2039f8829a4aSRandall Stewart 				if ((lnet->dest_state & SCTP_ADDR_UNCONFIRMED) &&
2040f8829a4aSRandall Stewart 				    (lnet->dest_state & SCTP_ADDR_REACHABLE)) {
2041f8829a4aSRandall Stewart 					cnt_of_unconf++;
2042f8829a4aSRandall Stewart 				}
2043f8829a4aSRandall Stewart 			}
2044f8829a4aSRandall Stewart 			if (cnt_of_unconf) {
20453c503c28SRandall Stewart 				net = lnet = NULL;
2046ad81507eSRandall Stewart 				(void)sctp_heartbeat_timer(inp, stcb, lnet, cnt_of_unconf);
2047f8829a4aSRandall Stewart 			}
2048f8829a4aSRandall Stewart 			if (stcb->asoc.hb_random_idx > 3) {
2049f8829a4aSRandall Stewart 				rndval = sctp_select_initial_TSN(&inp->sctp_ep);
2050f8829a4aSRandall Stewart 				memcpy(stcb->asoc.hb_random_values, &rndval,
2051f8829a4aSRandall Stewart 				    sizeof(stcb->asoc.hb_random_values));
2052f8829a4aSRandall Stewart 				stcb->asoc.hb_random_idx = 0;
205342551e99SRandall Stewart 			}
2054f8829a4aSRandall Stewart 			this_random = stcb->asoc.hb_random_values[stcb->asoc.hb_random_idx];
2055f8829a4aSRandall Stewart 			stcb->asoc.hb_random_idx++;
2056f8829a4aSRandall Stewart 			stcb->asoc.hb_ect_randombit = 0;
2057f8829a4aSRandall Stewart 			/*
2058f8829a4aSRandall Stewart 			 * this_random will be 0 - 256 ms RTO is in ms.
2059f8829a4aSRandall Stewart 			 */
2060f8829a4aSRandall Stewart 			if ((stcb->asoc.hb_is_disabled) &&
2061f8829a4aSRandall Stewart 			    (cnt_of_unconf == 0)) {
2062ad81507eSRandall Stewart 				return;
2063f8829a4aSRandall Stewart 			}
2064f8829a4aSRandall Stewart 			if (net) {
2065f8829a4aSRandall Stewart 				int delay;
2066f8829a4aSRandall Stewart 
2067f8829a4aSRandall Stewart 				delay = stcb->asoc.heart_beat_delay;
2068f8829a4aSRandall Stewart 				TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
2069f8829a4aSRandall Stewart 					if ((lnet->dest_state & SCTP_ADDR_UNCONFIRMED) &&
2070f8829a4aSRandall Stewart 					    ((lnet->dest_state & SCTP_ADDR_OUT_OF_SCOPE) == 0) &&
2071f8829a4aSRandall Stewart 					    (lnet->dest_state & SCTP_ADDR_REACHABLE)) {
2072f8829a4aSRandall Stewart 						delay = 0;
2073f8829a4aSRandall Stewart 					}
2074f8829a4aSRandall Stewart 				}
2075f8829a4aSRandall Stewart 				if (net->RTO == 0) {
2076f8829a4aSRandall Stewart 					/* Never been checked */
2077f8829a4aSRandall Stewart 					to_ticks = this_random + stcb->asoc.initial_rto + delay;
2078f8829a4aSRandall Stewart 				} else {
2079f8829a4aSRandall Stewart 					/* set rto_val to the ms */
2080f8829a4aSRandall Stewart 					to_ticks = delay + net->RTO + this_random;
2081f8829a4aSRandall Stewart 				}
2082f8829a4aSRandall Stewart 			} else {
2083f8829a4aSRandall Stewart 				if (cnt_of_unconf) {
2084f8829a4aSRandall Stewart 					to_ticks = this_random + stcb->asoc.initial_rto;
2085f8829a4aSRandall Stewart 				} else {
2086f8829a4aSRandall Stewart 					to_ticks = stcb->asoc.heart_beat_delay + this_random + stcb->asoc.initial_rto;
2087f8829a4aSRandall Stewart 				}
2088f8829a4aSRandall Stewart 			}
2089f8829a4aSRandall Stewart 			/*
2090f8829a4aSRandall Stewart 			 * Now we must convert the to_ticks that are now in
2091f8829a4aSRandall Stewart 			 * ms to ticks.
2092f8829a4aSRandall Stewart 			 */
2093f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(to_ticks);
2094f8829a4aSRandall Stewart 			tmr = &stcb->asoc.hb_timer;
2095f8829a4aSRandall Stewart 		}
2096f8829a4aSRandall Stewart 		break;
2097f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
2098f8829a4aSRandall Stewart 		/*
2099f8829a4aSRandall Stewart 		 * Here we can use the RTO timer from the network since one
2100f8829a4aSRandall Stewart 		 * RTT was compelete. If a retran happened then we will be
2101f8829a4aSRandall Stewart 		 * using the RTO initial value.
2102f8829a4aSRandall Stewart 		 */
2103f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2104ad81507eSRandall Stewart 			return;
2105f8829a4aSRandall Stewart 		}
2106f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2107f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2108f8829a4aSRandall Stewart 		} else {
2109f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2110f8829a4aSRandall Stewart 		}
2111f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2112f8829a4aSRandall Stewart 		break;
2113f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
2114f8829a4aSRandall Stewart 		/*
2115f8829a4aSRandall Stewart 		 * nothing needed but the endpoint here ususually about 60
2116f8829a4aSRandall Stewart 		 * minutes.
2117f8829a4aSRandall Stewart 		 */
2118ad81507eSRandall Stewart 		if (inp == NULL) {
2119ad81507eSRandall Stewart 			return;
2120ad81507eSRandall Stewart 		}
2121f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2122f8829a4aSRandall Stewart 		to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_SIGNATURE];
2123f8829a4aSRandall Stewart 		break;
2124f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASOCKILL:
2125f8829a4aSRandall Stewart 		if (stcb == NULL) {
2126ad81507eSRandall Stewart 			return;
2127f8829a4aSRandall Stewart 		}
2128f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2129f8829a4aSRandall Stewart 		to_ticks = MSEC_TO_TICKS(SCTP_ASOC_KILL_TIMEOUT);
2130f8829a4aSRandall Stewart 		break;
2131f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INPKILL:
2132f8829a4aSRandall Stewart 		/*
2133f8829a4aSRandall Stewart 		 * The inp is setup to die. We re-use the signature_chage
2134f8829a4aSRandall Stewart 		 * timer since that has stopped and we are in the GONE
2135f8829a4aSRandall Stewart 		 * state.
2136f8829a4aSRandall Stewart 		 */
2137ad81507eSRandall Stewart 		if (inp == NULL) {
2138ad81507eSRandall Stewart 			return;
2139ad81507eSRandall Stewart 		}
2140f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2141f8829a4aSRandall Stewart 		to_ticks = MSEC_TO_TICKS(SCTP_INP_KILL_TIMEOUT);
2142f8829a4aSRandall Stewart 		break;
2143f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
2144f8829a4aSRandall Stewart 		/*
2145f8829a4aSRandall Stewart 		 * Here we use the value found in the EP for PMTU ususually
2146f8829a4aSRandall Stewart 		 * about 10 minutes.
2147f8829a4aSRandall Stewart 		 */
2148ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
2149ad81507eSRandall Stewart 			return;
2150f8829a4aSRandall Stewart 		}
2151f8829a4aSRandall Stewart 		if (net == NULL) {
2152ad81507eSRandall Stewart 			return;
2153f8829a4aSRandall Stewart 		}
2154f8829a4aSRandall Stewart 		to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_PMTU];
2155f8829a4aSRandall Stewart 		tmr = &net->pmtu_timer;
2156f8829a4aSRandall Stewart 		break;
2157f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
2158f8829a4aSRandall Stewart 		/* Here we use the RTO of the destination */
2159f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2160ad81507eSRandall Stewart 			return;
2161f8829a4aSRandall Stewart 		}
2162f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2163f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2164f8829a4aSRandall Stewart 		} else {
2165f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2166f8829a4aSRandall Stewart 		}
2167f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2168f8829a4aSRandall Stewart 		break;
2169f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
2170f8829a4aSRandall Stewart 		/*
2171f8829a4aSRandall Stewart 		 * Here we use the endpoints shutdown guard timer usually
2172f8829a4aSRandall Stewart 		 * about 3 minutes.
2173f8829a4aSRandall Stewart 		 */
2174ad81507eSRandall Stewart 		if ((inp == NULL) || (stcb == NULL)) {
2175ad81507eSRandall Stewart 			return;
2176f8829a4aSRandall Stewart 		}
2177f8829a4aSRandall Stewart 		to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_MAXSHUTDOWN];
2178f8829a4aSRandall Stewart 		tmr = &stcb->asoc.shut_guard_timer;
2179f8829a4aSRandall Stewart 		break;
2180f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_STRRESET:
2181f8829a4aSRandall Stewart 		/*
21821b649582SRandall Stewart 		 * Here the timer comes from the stcb but its value is from
21831b649582SRandall Stewart 		 * the net's RTO.
2184f8829a4aSRandall Stewart 		 */
2185f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2186ad81507eSRandall Stewart 			return;
2187f8829a4aSRandall Stewart 		}
2188f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2189f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2190f8829a4aSRandall Stewart 		} else {
2191f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2192f8829a4aSRandall Stewart 		}
2193f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2194f8829a4aSRandall Stewart 		break;
2195f8829a4aSRandall Stewart 
2196f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_EARLYFR:
2197f8829a4aSRandall Stewart 		{
2198f8829a4aSRandall Stewart 			unsigned int msec;
2199f8829a4aSRandall Stewart 
2200f8829a4aSRandall Stewart 			if ((stcb == NULL) || (net == NULL)) {
2201ad81507eSRandall Stewart 				return;
2202f8829a4aSRandall Stewart 			}
2203f8829a4aSRandall Stewart 			if (net->flight_size > net->cwnd) {
2204f8829a4aSRandall Stewart 				/* no need to start */
2205ad81507eSRandall Stewart 				return;
2206f8829a4aSRandall Stewart 			}
2207f8829a4aSRandall Stewart 			SCTP_STAT_INCR(sctps_earlyfrstart);
2208f8829a4aSRandall Stewart 			if (net->lastsa == 0) {
2209f8829a4aSRandall Stewart 				/* Hmm no rtt estimate yet? */
2210f8829a4aSRandall Stewart 				msec = stcb->asoc.initial_rto >> 2;
2211f8829a4aSRandall Stewart 			} else {
2212f8829a4aSRandall Stewart 				msec = ((net->lastsa >> 2) + net->lastsv) >> 1;
2213f8829a4aSRandall Stewart 			}
2214b3f1ea41SRandall Stewart 			if (msec < SCTP_BASE_SYSCTL(sctp_early_fr_msec)) {
2215b3f1ea41SRandall Stewart 				msec = SCTP_BASE_SYSCTL(sctp_early_fr_msec);
2216f8829a4aSRandall Stewart 				if (msec < SCTP_MINFR_MSEC_FLOOR) {
2217f8829a4aSRandall Stewart 					msec = SCTP_MINFR_MSEC_FLOOR;
2218f8829a4aSRandall Stewart 				}
2219f8829a4aSRandall Stewart 			}
2220f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(msec);
2221f8829a4aSRandall Stewart 			tmr = &net->fr_timer;
2222f8829a4aSRandall Stewart 		}
2223f8829a4aSRandall Stewart 		break;
2224f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASCONF:
2225f8829a4aSRandall Stewart 		/*
22261b649582SRandall Stewart 		 * Here the timer comes from the stcb but its value is from
22271b649582SRandall Stewart 		 * the net's RTO.
2228f8829a4aSRandall Stewart 		 */
2229f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2230ad81507eSRandall Stewart 			return;
2231f8829a4aSRandall Stewart 		}
2232f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2233f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2234f8829a4aSRandall Stewart 		} else {
2235f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2236f8829a4aSRandall Stewart 		}
2237f8829a4aSRandall Stewart 		tmr = &stcb->asoc.asconf_timer;
2238f8829a4aSRandall Stewart 		break;
2239851b7298SRandall Stewart 	case SCTP_TIMER_TYPE_PRIM_DELETED:
2240851b7298SRandall Stewart 		if ((stcb == NULL) || (net != NULL)) {
2241851b7298SRandall Stewart 			return;
2242851b7298SRandall Stewart 		}
2243851b7298SRandall Stewart 		to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2244851b7298SRandall Stewart 		tmr = &stcb->asoc.delete_prim_timer;
2245851b7298SRandall Stewart 		break;
2246f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_AUTOCLOSE:
2247f8829a4aSRandall Stewart 		if (stcb == NULL) {
2248ad81507eSRandall Stewart 			return;
2249f8829a4aSRandall Stewart 		}
2250f8829a4aSRandall Stewart 		if (stcb->asoc.sctp_autoclose_ticks == 0) {
2251f8829a4aSRandall Stewart 			/*
2252f8829a4aSRandall Stewart 			 * Really an error since stcb is NOT set to
2253f8829a4aSRandall Stewart 			 * autoclose
2254f8829a4aSRandall Stewart 			 */
2255ad81507eSRandall Stewart 			return;
2256f8829a4aSRandall Stewart 		}
2257f8829a4aSRandall Stewart 		to_ticks = stcb->asoc.sctp_autoclose_ticks;
2258f8829a4aSRandall Stewart 		tmr = &stcb->asoc.autoclose_timer;
2259f8829a4aSRandall Stewart 		break;
2260f8829a4aSRandall Stewart 	default:
2261ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_TIMER1, "%s: Unknown timer type %d\n",
2262ad81507eSRandall Stewart 		    __FUNCTION__, t_type);
2263ad81507eSRandall Stewart 		return;
2264f8829a4aSRandall Stewart 		break;
2265f8829a4aSRandall Stewart 	};
2266f8829a4aSRandall Stewart 	if ((to_ticks <= 0) || (tmr == NULL)) {
2267ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_TIMER1, "%s: %d:software error to_ticks:%d tmr:%p not set ??\n",
2268ad81507eSRandall Stewart 		    __FUNCTION__, t_type, to_ticks, tmr);
2269ad81507eSRandall Stewart 		return;
2270f8829a4aSRandall Stewart 	}
2271139bc87fSRandall Stewart 	if (SCTP_OS_TIMER_PENDING(&tmr->timer)) {
2272f8829a4aSRandall Stewart 		/*
2273f8829a4aSRandall Stewart 		 * we do NOT allow you to have it already running. if it is
2274f8829a4aSRandall Stewart 		 * we leave the current one up unchanged
2275f8829a4aSRandall Stewart 		 */
2276ad81507eSRandall Stewart 		return;
2277f8829a4aSRandall Stewart 	}
2278f8829a4aSRandall Stewart 	/* At this point we can proceed */
2279f8829a4aSRandall Stewart 	if (t_type == SCTP_TIMER_TYPE_SEND) {
2280f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up++;
2281f8829a4aSRandall Stewart 	}
2282a5d547adSRandall Stewart 	tmr->stopped_from = 0;
2283f8829a4aSRandall Stewart 	tmr->type = t_type;
2284f8829a4aSRandall Stewart 	tmr->ep = (void *)inp;
2285f8829a4aSRandall Stewart 	tmr->tcb = (void *)stcb;
2286f8829a4aSRandall Stewart 	tmr->net = (void *)net;
2287f8829a4aSRandall Stewart 	tmr->self = (void *)tmr;
22888518270eSMichael Tuexen 	tmr->vnet = (void *)curvnet;
2289c4739e2fSRandall Stewart 	tmr->ticks = sctp_get_tick_count();
2290ad81507eSRandall Stewart 	(void)SCTP_OS_TIMER_START(&tmr->timer, to_ticks, sctp_timeout_handler, tmr);
2291ad81507eSRandall Stewart 	return;
2292f8829a4aSRandall Stewart }
2293f8829a4aSRandall Stewart 
22946e55db54SRandall Stewart void
2295f8829a4aSRandall Stewart sctp_timer_stop(int t_type, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
2296a5d547adSRandall Stewart     struct sctp_nets *net, uint32_t from)
2297f8829a4aSRandall Stewart {
2298f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
2299f8829a4aSRandall Stewart 
2300f8829a4aSRandall Stewart 	if ((t_type != SCTP_TIMER_TYPE_ADDR_WQ) &&
2301f8829a4aSRandall Stewart 	    (inp == NULL))
23026e55db54SRandall Stewart 		return;
2303f8829a4aSRandall Stewart 
2304f8829a4aSRandall Stewart 	tmr = NULL;
2305f8829a4aSRandall Stewart 	if (stcb) {
2306f8829a4aSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
2307f8829a4aSRandall Stewart 	}
2308f8829a4aSRandall Stewart 	switch (t_type) {
2309d61a0ae0SRandall Stewart 	case SCTP_TIMER_TYPE_ZERO_COPY:
2310d61a0ae0SRandall Stewart 		tmr = &inp->sctp_ep.zero_copy_timer;
2311d61a0ae0SRandall Stewart 		break;
2312ad21a364SRandall Stewart 	case SCTP_TIMER_TYPE_ZCOPY_SENDQ:
2313ad21a364SRandall Stewart 		tmr = &inp->sctp_ep.zero_copy_sendq_timer;
2314ad21a364SRandall Stewart 		break;
2315f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ADDR_WQ:
2316b3f1ea41SRandall Stewart 		tmr = &SCTP_BASE_INFO(addr_wq_timer);
2317f8829a4aSRandall Stewart 		break;
2318f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_EARLYFR:
2319f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23206e55db54SRandall Stewart 			return;
2321f8829a4aSRandall Stewart 		}
2322f8829a4aSRandall Stewart 		tmr = &net->fr_timer;
2323f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_earlyfrstop);
2324f8829a4aSRandall Stewart 		break;
2325f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ITERATOR:
2326f8829a4aSRandall Stewart 		{
2327f8829a4aSRandall Stewart 			struct sctp_iterator *it;
2328f8829a4aSRandall Stewart 
2329f8829a4aSRandall Stewart 			it = (struct sctp_iterator *)inp;
2330f8829a4aSRandall Stewart 			tmr = &it->tmr;
2331f8829a4aSRandall Stewart 		}
2332f8829a4aSRandall Stewart 		break;
2333f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
2334f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23356e55db54SRandall Stewart 			return;
2336f8829a4aSRandall Stewart 		}
2337f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2338f8829a4aSRandall Stewart 		break;
2339f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
2340f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23416e55db54SRandall Stewart 			return;
2342f8829a4aSRandall Stewart 		}
2343f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2344f8829a4aSRandall Stewart 		break;
2345f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
2346f8829a4aSRandall Stewart 		if (stcb == NULL) {
23476e55db54SRandall Stewart 			return;
2348f8829a4aSRandall Stewart 		}
2349f8829a4aSRandall Stewart 		tmr = &stcb->asoc.dack_timer;
2350f8829a4aSRandall Stewart 		break;
2351f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
2352f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23536e55db54SRandall Stewart 			return;
2354f8829a4aSRandall Stewart 		}
2355f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2356f8829a4aSRandall Stewart 		break;
2357f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
2358f8829a4aSRandall Stewart 		if (stcb == NULL) {
23596e55db54SRandall Stewart 			return;
2360f8829a4aSRandall Stewart 		}
2361f8829a4aSRandall Stewart 		tmr = &stcb->asoc.hb_timer;
2362f8829a4aSRandall Stewart 		break;
2363f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
2364f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23656e55db54SRandall Stewart 			return;
2366f8829a4aSRandall Stewart 		}
2367f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2368f8829a4aSRandall Stewart 		break;
2369f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
2370f8829a4aSRandall Stewart 		/* nothing needed but the endpoint here */
2371f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2372f8829a4aSRandall Stewart 		/*
2373f8829a4aSRandall Stewart 		 * We re-use the newcookie timer for the INP kill timer. We
2374f8829a4aSRandall Stewart 		 * must assure that we do not kill it by accident.
2375f8829a4aSRandall Stewart 		 */
2376f8829a4aSRandall Stewart 		break;
2377f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASOCKILL:
2378f8829a4aSRandall Stewart 		/*
2379f8829a4aSRandall Stewart 		 * Stop the asoc kill timer.
2380f8829a4aSRandall Stewart 		 */
2381f8829a4aSRandall Stewart 		if (stcb == NULL) {
23826e55db54SRandall Stewart 			return;
2383f8829a4aSRandall Stewart 		}
2384f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2385f8829a4aSRandall Stewart 		break;
2386f8829a4aSRandall Stewart 
2387f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INPKILL:
2388f8829a4aSRandall Stewart 		/*
2389f8829a4aSRandall Stewart 		 * The inp is setup to die. We re-use the signature_chage
2390f8829a4aSRandall Stewart 		 * timer since that has stopped and we are in the GONE
2391f8829a4aSRandall Stewart 		 * state.
2392f8829a4aSRandall Stewart 		 */
2393f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2394f8829a4aSRandall Stewart 		break;
2395f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
2396f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23976e55db54SRandall Stewart 			return;
2398f8829a4aSRandall Stewart 		}
2399f8829a4aSRandall Stewart 		tmr = &net->pmtu_timer;
2400f8829a4aSRandall Stewart 		break;
2401f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
2402f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
24036e55db54SRandall Stewart 			return;
2404f8829a4aSRandall Stewart 		}
2405f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2406f8829a4aSRandall Stewart 		break;
2407f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
2408f8829a4aSRandall Stewart 		if (stcb == NULL) {
24096e55db54SRandall Stewart 			return;
2410f8829a4aSRandall Stewart 		}
2411f8829a4aSRandall Stewart 		tmr = &stcb->asoc.shut_guard_timer;
2412f8829a4aSRandall Stewart 		break;
2413f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_STRRESET:
2414f8829a4aSRandall Stewart 		if (stcb == NULL) {
24156e55db54SRandall Stewart 			return;
2416f8829a4aSRandall Stewart 		}
2417f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2418f8829a4aSRandall Stewart 		break;
2419f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASCONF:
2420f8829a4aSRandall Stewart 		if (stcb == NULL) {
24216e55db54SRandall Stewart 			return;
2422f8829a4aSRandall Stewart 		}
2423f8829a4aSRandall Stewart 		tmr = &stcb->asoc.asconf_timer;
2424f8829a4aSRandall Stewart 		break;
2425851b7298SRandall Stewart 	case SCTP_TIMER_TYPE_PRIM_DELETED:
2426851b7298SRandall Stewart 		if (stcb == NULL) {
2427851b7298SRandall Stewart 			return;
2428851b7298SRandall Stewart 		}
2429851b7298SRandall Stewart 		tmr = &stcb->asoc.delete_prim_timer;
2430851b7298SRandall Stewart 		break;
2431f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_AUTOCLOSE:
2432f8829a4aSRandall Stewart 		if (stcb == NULL) {
24336e55db54SRandall Stewart 			return;
2434f8829a4aSRandall Stewart 		}
2435f8829a4aSRandall Stewart 		tmr = &stcb->asoc.autoclose_timer;
2436f8829a4aSRandall Stewart 		break;
2437f8829a4aSRandall Stewart 	default:
2438ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_TIMER1, "%s: Unknown timer type %d\n",
2439ad81507eSRandall Stewart 		    __FUNCTION__, t_type);
2440f8829a4aSRandall Stewart 		break;
2441f8829a4aSRandall Stewart 	};
2442f8829a4aSRandall Stewart 	if (tmr == NULL) {
24436e55db54SRandall Stewart 		return;
2444f8829a4aSRandall Stewart 	}
2445f8829a4aSRandall Stewart 	if ((tmr->type != t_type) && tmr->type) {
2446f8829a4aSRandall Stewart 		/*
2447f8829a4aSRandall Stewart 		 * Ok we have a timer that is under joint use. Cookie timer
2448f8829a4aSRandall Stewart 		 * per chance with the SEND timer. We therefore are NOT
2449f8829a4aSRandall Stewart 		 * running the timer that the caller wants stopped.  So just
2450f8829a4aSRandall Stewart 		 * return.
2451f8829a4aSRandall Stewart 		 */
24526e55db54SRandall Stewart 		return;
2453f8829a4aSRandall Stewart 	}
2454ad81507eSRandall Stewart 	if ((t_type == SCTP_TIMER_TYPE_SEND) && (stcb != NULL)) {
2455f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up--;
2456f8829a4aSRandall Stewart 		if (stcb->asoc.num_send_timers_up < 0) {
2457f8829a4aSRandall Stewart 			stcb->asoc.num_send_timers_up = 0;
2458f8829a4aSRandall Stewart 		}
2459f8829a4aSRandall Stewart 	}
2460f8829a4aSRandall Stewart 	tmr->self = NULL;
2461a5d547adSRandall Stewart 	tmr->stopped_from = from;
24626e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&tmr->timer);
24636e55db54SRandall Stewart 	return;
2464f8829a4aSRandall Stewart }
2465f8829a4aSRandall Stewart 
2466f8829a4aSRandall Stewart uint32_t
2467f8829a4aSRandall Stewart sctp_calculate_len(struct mbuf *m)
2468f8829a4aSRandall Stewart {
2469f8829a4aSRandall Stewart 	uint32_t tlen = 0;
2470f8829a4aSRandall Stewart 	struct mbuf *at;
2471f8829a4aSRandall Stewart 
2472f8829a4aSRandall Stewart 	at = m;
2473f8829a4aSRandall Stewart 	while (at) {
2474139bc87fSRandall Stewart 		tlen += SCTP_BUF_LEN(at);
2475139bc87fSRandall Stewart 		at = SCTP_BUF_NEXT(at);
2476f8829a4aSRandall Stewart 	}
2477f8829a4aSRandall Stewart 	return (tlen);
2478f8829a4aSRandall Stewart }
2479f8829a4aSRandall Stewart 
2480f8829a4aSRandall Stewart void
2481f8829a4aSRandall Stewart sctp_mtu_size_reset(struct sctp_inpcb *inp,
248244b7479bSRandall Stewart     struct sctp_association *asoc, uint32_t mtu)
2483f8829a4aSRandall Stewart {
2484f8829a4aSRandall Stewart 	/*
2485f8829a4aSRandall Stewart 	 * Reset the P-MTU size on this association, this involves changing
2486f8829a4aSRandall Stewart 	 * the asoc MTU, going through ANY chunk+overhead larger than mtu to
2487f8829a4aSRandall Stewart 	 * allow the DF flag to be cleared.
2488f8829a4aSRandall Stewart 	 */
2489f8829a4aSRandall Stewart 	struct sctp_tmit_chunk *chk;
2490f8829a4aSRandall Stewart 	unsigned int eff_mtu, ovh;
2491f8829a4aSRandall Stewart 
249217205eccSRandall Stewart #ifdef SCTP_PRINT_FOR_B_AND_M
2493ad81507eSRandall Stewart 	SCTP_PRINTF("sctp_mtu_size_reset(%p, asoc:%p mtu:%d\n",
249417205eccSRandall Stewart 	    inp, asoc, mtu);
249517205eccSRandall Stewart #endif
2496f8829a4aSRandall Stewart 	asoc->smallest_mtu = mtu;
2497f8829a4aSRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) {
2498f8829a4aSRandall Stewart 		ovh = SCTP_MIN_OVERHEAD;
2499f8829a4aSRandall Stewart 	} else {
2500f8829a4aSRandall Stewart 		ovh = SCTP_MIN_V4_OVERHEAD;
2501f8829a4aSRandall Stewart 	}
2502f8829a4aSRandall Stewart 	eff_mtu = mtu - ovh;
2503f8829a4aSRandall Stewart 	TAILQ_FOREACH(chk, &asoc->send_queue, sctp_next) {
2504f8829a4aSRandall Stewart 
2505f8829a4aSRandall Stewart 		if (chk->send_size > eff_mtu) {
2506f8829a4aSRandall Stewart 			chk->flags |= CHUNK_FLAGS_FRAGMENT_OK;
2507f8829a4aSRandall Stewart 		}
2508f8829a4aSRandall Stewart 	}
2509f8829a4aSRandall Stewart 	TAILQ_FOREACH(chk, &asoc->sent_queue, sctp_next) {
2510f8829a4aSRandall Stewart 		if (chk->send_size > eff_mtu) {
2511f8829a4aSRandall Stewart 			chk->flags |= CHUNK_FLAGS_FRAGMENT_OK;
2512f8829a4aSRandall Stewart 		}
2513f8829a4aSRandall Stewart 	}
2514f8829a4aSRandall Stewart }
2515f8829a4aSRandall Stewart 
2516f8829a4aSRandall Stewart 
2517f8829a4aSRandall Stewart /*
2518f8829a4aSRandall Stewart  * given an association and starting time of the current RTT period return
2519f42a358aSRandall Stewart  * RTO in number of msecs net should point to the current network
2520f8829a4aSRandall Stewart  */
2521f8829a4aSRandall Stewart uint32_t
2522f8829a4aSRandall Stewart sctp_calculate_rto(struct sctp_tcb *stcb,
2523f8829a4aSRandall Stewart     struct sctp_association *asoc,
2524f8829a4aSRandall Stewart     struct sctp_nets *net,
252518e198d3SRandall Stewart     struct timeval *told,
252618e198d3SRandall Stewart     int safe)
2527f8829a4aSRandall Stewart {
252818e198d3SRandall Stewart 	/*-
2529f8829a4aSRandall Stewart 	 * given an association and the starting time of the current RTT
2530f42a358aSRandall Stewart 	 * period (in value1/value2) return RTO in number of msecs.
2531f8829a4aSRandall Stewart 	 */
2532f8829a4aSRandall Stewart 	int calc_time = 0;
2533f8829a4aSRandall Stewart 	int o_calctime;
25345e54f665SRandall Stewart 	uint32_t new_rto = 0;
2535f8829a4aSRandall Stewart 	int first_measure = 0;
253618e198d3SRandall Stewart 	struct timeval now, then, *old;
2537f8829a4aSRandall Stewart 
253818e198d3SRandall Stewart 	/* Copy it out for sparc64 */
253918e198d3SRandall Stewart 	if (safe == sctp_align_unsafe_makecopy) {
254018e198d3SRandall Stewart 		old = &then;
254118e198d3SRandall Stewart 		memcpy(&then, told, sizeof(struct timeval));
254218e198d3SRandall Stewart 	} else if (safe == sctp_align_safe_nocopy) {
254318e198d3SRandall Stewart 		old = told;
254418e198d3SRandall Stewart 	} else {
254518e198d3SRandall Stewart 		/* error */
254618e198d3SRandall Stewart 		SCTP_PRINTF("Huh, bad rto calc call\n");
254718e198d3SRandall Stewart 		return (0);
254818e198d3SRandall Stewart 	}
2549f8829a4aSRandall Stewart 	/************************/
2550f8829a4aSRandall Stewart 	/* 1. calculate new RTT */
2551f8829a4aSRandall Stewart 	/************************/
2552f8829a4aSRandall Stewart 	/* get the current time */
25536e55db54SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&now);
2554f8829a4aSRandall Stewart 	/* compute the RTT value */
2555f8829a4aSRandall Stewart 	if ((u_long)now.tv_sec > (u_long)old->tv_sec) {
2556f8829a4aSRandall Stewart 		calc_time = ((u_long)now.tv_sec - (u_long)old->tv_sec) * 1000;
2557f8829a4aSRandall Stewart 		if ((u_long)now.tv_usec > (u_long)old->tv_usec) {
2558f8829a4aSRandall Stewart 			calc_time += (((u_long)now.tv_usec -
2559f8829a4aSRandall Stewart 			    (u_long)old->tv_usec) / 1000);
2560f8829a4aSRandall Stewart 		} else if ((u_long)now.tv_usec < (u_long)old->tv_usec) {
2561f8829a4aSRandall Stewart 			/* Borrow 1,000ms from current calculation */
2562f8829a4aSRandall Stewart 			calc_time -= 1000;
2563f8829a4aSRandall Stewart 			/* Add in the slop over */
2564f8829a4aSRandall Stewart 			calc_time += ((int)now.tv_usec / 1000);
2565f8829a4aSRandall Stewart 			/* Add in the pre-second ms's */
2566f8829a4aSRandall Stewart 			calc_time += (((int)1000000 - (int)old->tv_usec) / 1000);
2567f8829a4aSRandall Stewart 		}
2568f8829a4aSRandall Stewart 	} else if ((u_long)now.tv_sec == (u_long)old->tv_sec) {
2569f8829a4aSRandall Stewart 		if ((u_long)now.tv_usec > (u_long)old->tv_usec) {
2570f8829a4aSRandall Stewart 			calc_time = ((u_long)now.tv_usec -
2571f8829a4aSRandall Stewart 			    (u_long)old->tv_usec) / 1000;
2572f8829a4aSRandall Stewart 		} else if ((u_long)now.tv_usec < (u_long)old->tv_usec) {
2573f8829a4aSRandall Stewart 			/* impossible .. garbage in nothing out */
25745e54f665SRandall Stewart 			goto calc_rto;
2575a5d547adSRandall Stewart 		} else if ((u_long)now.tv_usec == (u_long)old->tv_usec) {
2576a5d547adSRandall Stewart 			/*
2577a5d547adSRandall Stewart 			 * We have to have 1 usec :-D this must be the
2578a5d547adSRandall Stewart 			 * loopback.
2579a5d547adSRandall Stewart 			 */
2580a5d547adSRandall Stewart 			calc_time = 1;
2581f8829a4aSRandall Stewart 		} else {
2582f8829a4aSRandall Stewart 			/* impossible .. garbage in nothing out */
25835e54f665SRandall Stewart 			goto calc_rto;
2584f8829a4aSRandall Stewart 		}
2585f8829a4aSRandall Stewart 	} else {
2586f8829a4aSRandall Stewart 		/* Clock wrapped? */
25875e54f665SRandall Stewart 		goto calc_rto;
2588f8829a4aSRandall Stewart 	}
2589f8829a4aSRandall Stewart 	/***************************/
2590f8829a4aSRandall Stewart 	/* 2. update RTTVAR & SRTT */
2591f8829a4aSRandall Stewart 	/***************************/
25928933fa13SRandall Stewart 	net->rtt = o_calctime = calc_time;
2593f8829a4aSRandall Stewart 	/* this is Van Jacobson's integer version */
25949a972525SRandall Stewart 	if (net->RTO_measured) {
2595108df27cSRandall Stewart 		calc_time -= (net->lastsa >> SCTP_RTT_SHIFT);	/* take away 1/8th when
2596108df27cSRandall Stewart 								 * shift=3 */
2597b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RTTVAR_LOGGING_ENABLE) {
2598f8829a4aSRandall Stewart 			rto_logging(net, SCTP_LOG_RTTVAR);
259980fefe0aSRandall Stewart 		}
2600f8829a4aSRandall Stewart 		net->prev_rtt = o_calctime;
2601108df27cSRandall Stewart 		net->lastsa += calc_time;	/* add 7/8th into sa when
2602108df27cSRandall Stewart 						 * shift=3 */
2603f8829a4aSRandall Stewart 		if (calc_time < 0) {
2604f8829a4aSRandall Stewart 			calc_time = -calc_time;
2605f8829a4aSRandall Stewart 		}
2606108df27cSRandall Stewart 		calc_time -= (net->lastsv >> SCTP_RTT_VAR_SHIFT);	/* take away 1/4 when
2607108df27cSRandall Stewart 									 * VAR shift=2 */
2608f8829a4aSRandall Stewart 		net->lastsv += calc_time;
2609f8829a4aSRandall Stewart 		if (net->lastsv == 0) {
2610f8829a4aSRandall Stewart 			net->lastsv = SCTP_CLOCK_GRANULARITY;
2611f8829a4aSRandall Stewart 		}
2612f8829a4aSRandall Stewart 	} else {
2613f8829a4aSRandall Stewart 		/* First RTO measurment */
26149a972525SRandall Stewart 		net->RTO_measured = 1;
2615108df27cSRandall Stewart 		net->lastsa = calc_time << SCTP_RTT_SHIFT;	/* Multiply by 8 when
2616108df27cSRandall Stewart 								 * shift=3 */
2617108df27cSRandall Stewart 		net->lastsv = calc_time;
2618108df27cSRandall Stewart 		if (net->lastsv == 0) {
2619108df27cSRandall Stewart 			net->lastsv = SCTP_CLOCK_GRANULARITY;
2620108df27cSRandall Stewart 		}
2621f8829a4aSRandall Stewart 		first_measure = 1;
2622f8829a4aSRandall Stewart 		net->prev_rtt = o_calctime;
2623b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RTTVAR_LOGGING_ENABLE) {
2624f8829a4aSRandall Stewart 			rto_logging(net, SCTP_LOG_INITIAL_RTT);
262580fefe0aSRandall Stewart 		}
2626f8829a4aSRandall Stewart 	}
26275e54f665SRandall Stewart calc_rto:
2628108df27cSRandall Stewart 	new_rto = (net->lastsa >> SCTP_RTT_SHIFT) + net->lastsv;
2629f8829a4aSRandall Stewart 	if ((new_rto > SCTP_SAT_NETWORK_MIN) &&
2630f8829a4aSRandall Stewart 	    (stcb->asoc.sat_network_lockout == 0)) {
2631f8829a4aSRandall Stewart 		stcb->asoc.sat_network = 1;
2632f8829a4aSRandall Stewart 	} else if ((!first_measure) && stcb->asoc.sat_network) {
2633f8829a4aSRandall Stewart 		stcb->asoc.sat_network = 0;
2634f8829a4aSRandall Stewart 		stcb->asoc.sat_network_lockout = 1;
2635f8829a4aSRandall Stewart 	}
2636f8829a4aSRandall Stewart 	/* bound it, per C6/C7 in Section 5.3.1 */
2637f8829a4aSRandall Stewart 	if (new_rto < stcb->asoc.minrto) {
2638f8829a4aSRandall Stewart 		new_rto = stcb->asoc.minrto;
2639f8829a4aSRandall Stewart 	}
2640f8829a4aSRandall Stewart 	if (new_rto > stcb->asoc.maxrto) {
2641f8829a4aSRandall Stewart 		new_rto = stcb->asoc.maxrto;
2642f8829a4aSRandall Stewart 	}
26435e54f665SRandall Stewart 	/* we are now returning the RTO */
26445e54f665SRandall Stewart 	return (new_rto);
2645f8829a4aSRandall Stewart }
2646f8829a4aSRandall Stewart 
2647f8829a4aSRandall Stewart /*
2648f8829a4aSRandall Stewart  * return a pointer to a contiguous piece of data from the given mbuf chain
2649f8829a4aSRandall Stewart  * starting at 'off' for 'len' bytes.  If the desired piece spans more than
2650f8829a4aSRandall Stewart  * one mbuf, a copy is made at 'ptr'. caller must ensure that the buffer size
2651f8829a4aSRandall Stewart  * is >= 'len' returns NULL if there there isn't 'len' bytes in the chain.
2652f8829a4aSRandall Stewart  */
265372fb6fdbSRandall Stewart caddr_t
2654f8829a4aSRandall Stewart sctp_m_getptr(struct mbuf *m, int off, int len, uint8_t * in_ptr)
2655f8829a4aSRandall Stewart {
2656f8829a4aSRandall Stewart 	uint32_t count;
2657f8829a4aSRandall Stewart 	uint8_t *ptr;
2658f8829a4aSRandall Stewart 
2659f8829a4aSRandall Stewart 	ptr = in_ptr;
2660f8829a4aSRandall Stewart 	if ((off < 0) || (len <= 0))
2661f8829a4aSRandall Stewart 		return (NULL);
2662f8829a4aSRandall Stewart 
2663f8829a4aSRandall Stewart 	/* find the desired start location */
2664f8829a4aSRandall Stewart 	while ((m != NULL) && (off > 0)) {
2665139bc87fSRandall Stewart 		if (off < SCTP_BUF_LEN(m))
2666f8829a4aSRandall Stewart 			break;
2667139bc87fSRandall Stewart 		off -= SCTP_BUF_LEN(m);
2668139bc87fSRandall Stewart 		m = SCTP_BUF_NEXT(m);
2669f8829a4aSRandall Stewart 	}
2670f8829a4aSRandall Stewart 	if (m == NULL)
2671f8829a4aSRandall Stewart 		return (NULL);
2672f8829a4aSRandall Stewart 
2673f8829a4aSRandall Stewart 	/* is the current mbuf large enough (eg. contiguous)? */
2674139bc87fSRandall Stewart 	if ((SCTP_BUF_LEN(m) - off) >= len) {
2675f8829a4aSRandall Stewart 		return (mtod(m, caddr_t)+off);
2676f8829a4aSRandall Stewart 	} else {
2677f8829a4aSRandall Stewart 		/* else, it spans more than one mbuf, so save a temp copy... */
2678f8829a4aSRandall Stewart 		while ((m != NULL) && (len > 0)) {
2679139bc87fSRandall Stewart 			count = min(SCTP_BUF_LEN(m) - off, len);
2680f8829a4aSRandall Stewart 			bcopy(mtod(m, caddr_t)+off, ptr, count);
2681f8829a4aSRandall Stewart 			len -= count;
2682f8829a4aSRandall Stewart 			ptr += count;
2683f8829a4aSRandall Stewart 			off = 0;
2684139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
2685f8829a4aSRandall Stewart 		}
2686f8829a4aSRandall Stewart 		if ((m == NULL) && (len > 0))
2687f8829a4aSRandall Stewart 			return (NULL);
2688f8829a4aSRandall Stewart 		else
2689f8829a4aSRandall Stewart 			return ((caddr_t)in_ptr);
2690f8829a4aSRandall Stewart 	}
2691f8829a4aSRandall Stewart }
2692f8829a4aSRandall Stewart 
2693f8829a4aSRandall Stewart 
269444b7479bSRandall Stewart 
2695f8829a4aSRandall Stewart struct sctp_paramhdr *
2696f8829a4aSRandall Stewart sctp_get_next_param(struct mbuf *m,
2697f8829a4aSRandall Stewart     int offset,
2698f8829a4aSRandall Stewart     struct sctp_paramhdr *pull,
2699f8829a4aSRandall Stewart     int pull_limit)
2700f8829a4aSRandall Stewart {
2701f8829a4aSRandall Stewart 	/* This just provides a typed signature to Peter's Pull routine */
2702f8829a4aSRandall Stewart 	return ((struct sctp_paramhdr *)sctp_m_getptr(m, offset, pull_limit,
2703f8829a4aSRandall Stewart 	    (uint8_t *) pull));
2704f8829a4aSRandall Stewart }
2705f8829a4aSRandall Stewart 
2706f8829a4aSRandall Stewart 
2707f8829a4aSRandall Stewart int
2708f8829a4aSRandall Stewart sctp_add_pad_tombuf(struct mbuf *m, int padlen)
2709f8829a4aSRandall Stewart {
2710f8829a4aSRandall Stewart 	/*
2711f8829a4aSRandall Stewart 	 * add padlen bytes of 0 filled padding to the end of the mbuf. If
2712f8829a4aSRandall Stewart 	 * padlen is > 3 this routine will fail.
2713f8829a4aSRandall Stewart 	 */
2714f8829a4aSRandall Stewart 	uint8_t *dp;
2715f8829a4aSRandall Stewart 	int i;
2716f8829a4aSRandall Stewart 
2717f8829a4aSRandall Stewart 	if (padlen > 3) {
2718c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET_PKT(m, NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOBUFS);
2719f8829a4aSRandall Stewart 		return (ENOBUFS);
2720f8829a4aSRandall Stewart 	}
272141eee555SRandall Stewart 	if (padlen <= M_TRAILINGSPACE(m)) {
2722f8829a4aSRandall Stewart 		/*
2723f8829a4aSRandall Stewart 		 * The easy way. We hope the majority of the time we hit
2724f8829a4aSRandall Stewart 		 * here :)
2725f8829a4aSRandall Stewart 		 */
2726139bc87fSRandall Stewart 		dp = (uint8_t *) (mtod(m, caddr_t)+SCTP_BUF_LEN(m));
2727139bc87fSRandall Stewart 		SCTP_BUF_LEN(m) += padlen;
2728f8829a4aSRandall Stewart 	} else {
2729f8829a4aSRandall Stewart 		/* Hard way we must grow the mbuf */
2730f8829a4aSRandall Stewart 		struct mbuf *tmp;
2731f8829a4aSRandall Stewart 
2732f8829a4aSRandall Stewart 		tmp = sctp_get_mbuf_for_msg(padlen, 0, M_DONTWAIT, 1, MT_DATA);
2733f8829a4aSRandall Stewart 		if (tmp == NULL) {
2734f8829a4aSRandall Stewart 			/* Out of space GAK! we are in big trouble. */
2735c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET_PKT(m, NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
2736f8829a4aSRandall Stewart 			return (ENOSPC);
2737f8829a4aSRandall Stewart 		}
2738f8829a4aSRandall Stewart 		/* setup and insert in middle */
2739139bc87fSRandall Stewart 		SCTP_BUF_LEN(tmp) = padlen;
274041eee555SRandall Stewart 		SCTP_BUF_NEXT(tmp) = NULL;
2741139bc87fSRandall Stewart 		SCTP_BUF_NEXT(m) = tmp;
2742f8829a4aSRandall Stewart 		dp = mtod(tmp, uint8_t *);
2743f8829a4aSRandall Stewart 	}
2744f8829a4aSRandall Stewart 	/* zero out the pad */
2745f8829a4aSRandall Stewart 	for (i = 0; i < padlen; i++) {
2746f8829a4aSRandall Stewart 		*dp = 0;
2747f8829a4aSRandall Stewart 		dp++;
2748f8829a4aSRandall Stewart 	}
2749f8829a4aSRandall Stewart 	return (0);
2750f8829a4aSRandall Stewart }
2751f8829a4aSRandall Stewart 
2752f8829a4aSRandall Stewart int
2753f8829a4aSRandall Stewart sctp_pad_lastmbuf(struct mbuf *m, int padval, struct mbuf *last_mbuf)
2754f8829a4aSRandall Stewart {
2755f8829a4aSRandall Stewart 	/* find the last mbuf in chain and pad it */
2756f8829a4aSRandall Stewart 	struct mbuf *m_at;
2757f8829a4aSRandall Stewart 
2758f8829a4aSRandall Stewart 	m_at = m;
2759f8829a4aSRandall Stewart 	if (last_mbuf) {
2760f8829a4aSRandall Stewart 		return (sctp_add_pad_tombuf(last_mbuf, padval));
2761f8829a4aSRandall Stewart 	} else {
2762f8829a4aSRandall Stewart 		while (m_at) {
2763139bc87fSRandall Stewart 			if (SCTP_BUF_NEXT(m_at) == NULL) {
2764f8829a4aSRandall Stewart 				return (sctp_add_pad_tombuf(m_at, padval));
2765f8829a4aSRandall Stewart 			}
2766139bc87fSRandall Stewart 			m_at = SCTP_BUF_NEXT(m_at);
2767f8829a4aSRandall Stewart 		}
2768f8829a4aSRandall Stewart 	}
2769c4739e2fSRandall Stewart 	SCTP_LTRACE_ERR_RET_PKT(m, NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EFAULT);
2770f8829a4aSRandall Stewart 	return (EFAULT);
2771f8829a4aSRandall Stewart }
2772f8829a4aSRandall Stewart 
2773f8829a4aSRandall Stewart static void
2774f8829a4aSRandall Stewart sctp_notify_assoc_change(uint32_t event, struct sctp_tcb *stcb,
2775ceaad40aSRandall Stewart     uint32_t error, void *data, int so_locked
2776ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
2777ceaad40aSRandall Stewart     SCTP_UNUSED
2778ceaad40aSRandall Stewart #endif
2779ceaad40aSRandall Stewart )
2780f8829a4aSRandall Stewart {
2781f8829a4aSRandall Stewart 	struct mbuf *m_notify;
2782f8829a4aSRandall Stewart 	struct sctp_assoc_change *sac;
2783f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
2784f8829a4aSRandall Stewart 
2785ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2786ceaad40aSRandall Stewart 	struct socket *so;
2787ceaad40aSRandall Stewart 
2788ceaad40aSRandall Stewart #endif
2789ceaad40aSRandall Stewart 
2790f8829a4aSRandall Stewart 	/*
2791f8829a4aSRandall Stewart 	 * For TCP model AND UDP connected sockets we will send an error up
2792f8829a4aSRandall Stewart 	 * when an ABORT comes in.
2793f8829a4aSRandall Stewart 	 */
2794f8829a4aSRandall Stewart 	if (((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
2795f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) &&
27963c503c28SRandall Stewart 	    ((event == SCTP_COMM_LOST) || (event == SCTP_CANT_STR_ASSOC))) {
2797c4739e2fSRandall Stewart 		if (SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_COOKIE_WAIT) {
2798c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ECONNREFUSED);
279944b7479bSRandall Stewart 			stcb->sctp_socket->so_error = ECONNREFUSED;
2800c4739e2fSRandall Stewart 		} else {
2801c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ECONNRESET);
2802f8829a4aSRandall Stewart 			stcb->sctp_socket->so_error = ECONNRESET;
2803c4739e2fSRandall Stewart 		}
2804f8829a4aSRandall Stewart 		/* Wake ANY sleepers */
2805ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2806ceaad40aSRandall Stewart 		so = SCTP_INP_SO(stcb->sctp_ep);
2807ceaad40aSRandall Stewart 		if (!so_locked) {
2808ceaad40aSRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, 1);
2809ceaad40aSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
2810ceaad40aSRandall Stewart 			SCTP_SOCKET_LOCK(so, 1);
2811ceaad40aSRandall Stewart 			SCTP_TCB_LOCK(stcb);
2812ceaad40aSRandall Stewart 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
2813ceaad40aSRandall Stewart 			if (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET) {
2814ceaad40aSRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
2815ceaad40aSRandall Stewart 				return;
2816ceaad40aSRandall Stewart 			}
2817ceaad40aSRandall Stewart 		}
2818ceaad40aSRandall Stewart #endif
2819f8829a4aSRandall Stewart 		sorwakeup(stcb->sctp_socket);
2820f8829a4aSRandall Stewart 		sowwakeup(stcb->sctp_socket);
2821ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2822ceaad40aSRandall Stewart 		if (!so_locked) {
2823ceaad40aSRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
2824ceaad40aSRandall Stewart 		}
2825ceaad40aSRandall Stewart #endif
2826f8829a4aSRandall Stewart 	}
2827f8829a4aSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_RECVASSOCEVNT)) {
2828f8829a4aSRandall Stewart 		/* event not enabled */
2829f8829a4aSRandall Stewart 		return;
2830f8829a4aSRandall Stewart 	}
2831139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_assoc_change), 0, M_DONTWAIT, 1, MT_DATA);
2832f8829a4aSRandall Stewart 	if (m_notify == NULL)
2833f8829a4aSRandall Stewart 		/* no space left */
2834f8829a4aSRandall Stewart 		return;
2835139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
2836f8829a4aSRandall Stewart 
2837f8829a4aSRandall Stewart 	sac = mtod(m_notify, struct sctp_assoc_change *);
2838f8829a4aSRandall Stewart 	sac->sac_type = SCTP_ASSOC_CHANGE;
2839f8829a4aSRandall Stewart 	sac->sac_flags = 0;
2840f8829a4aSRandall Stewart 	sac->sac_length = sizeof(struct sctp_assoc_change);
2841f8829a4aSRandall Stewart 	sac->sac_state = event;
2842f8829a4aSRandall Stewart 	sac->sac_error = error;
2843f8829a4aSRandall Stewart 	/* XXX verify these stream counts */
2844f8829a4aSRandall Stewart 	sac->sac_outbound_streams = stcb->asoc.streamoutcnt;
2845f8829a4aSRandall Stewart 	sac->sac_inbound_streams = stcb->asoc.streamincnt;
2846f8829a4aSRandall Stewart 	sac->sac_assoc_id = sctp_get_associd(stcb);
2847139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_assoc_change);
2848139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
2849f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
2850f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
2851f8829a4aSRandall Stewart 	    m_notify);
2852f8829a4aSRandall Stewart 	if (control == NULL) {
2853f8829a4aSRandall Stewart 		/* no memory */
2854f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
2855f8829a4aSRandall Stewart 		return;
2856f8829a4aSRandall Stewart 	}
2857139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
2858f8829a4aSRandall Stewart 	/* not that we need this */
2859f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
2860139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
2861f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
2862f8829a4aSRandall Stewart 	    control,
2863cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD,
2864cfde3ff7SRandall Stewart 	    so_locked);
2865f8829a4aSRandall Stewart 	if (event == SCTP_COMM_LOST) {
2866f8829a4aSRandall Stewart 		/* Wake up any sleeper */
2867ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2868ceaad40aSRandall Stewart 		so = SCTP_INP_SO(stcb->sctp_ep);
2869ceaad40aSRandall Stewart 		if (!so_locked) {
2870ceaad40aSRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, 1);
2871ceaad40aSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
2872ceaad40aSRandall Stewart 			SCTP_SOCKET_LOCK(so, 1);
2873ceaad40aSRandall Stewart 			SCTP_TCB_LOCK(stcb);
2874ceaad40aSRandall Stewart 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
2875ceaad40aSRandall Stewart 			if (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET) {
2876ceaad40aSRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
2877ceaad40aSRandall Stewart 				return;
2878ceaad40aSRandall Stewart 			}
2879ceaad40aSRandall Stewart 		}
2880ceaad40aSRandall Stewart #endif
2881f8829a4aSRandall Stewart 		sctp_sowwakeup(stcb->sctp_ep, stcb->sctp_socket);
2882ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2883ceaad40aSRandall Stewart 		if (!so_locked) {
2884ceaad40aSRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
2885ceaad40aSRandall Stewart 		}
2886ceaad40aSRandall Stewart #endif
2887f8829a4aSRandall Stewart 	}
2888f8829a4aSRandall Stewart }
2889f8829a4aSRandall Stewart 
2890f8829a4aSRandall Stewart static void
2891f8829a4aSRandall Stewart sctp_notify_peer_addr_change(struct sctp_tcb *stcb, uint32_t state,
2892f8829a4aSRandall Stewart     struct sockaddr *sa, uint32_t error)
2893f8829a4aSRandall Stewart {
2894f8829a4aSRandall Stewart 	struct mbuf *m_notify;
2895f8829a4aSRandall Stewart 	struct sctp_paddr_change *spc;
2896f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
2897f8829a4aSRandall Stewart 
2898830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_RECVPADDREVNT)) {
2899f8829a4aSRandall Stewart 		/* event not enabled */
2900f8829a4aSRandall Stewart 		return;
2901830d754dSRandall Stewart 	}
2902139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_paddr_change), 0, M_DONTWAIT, 1, MT_DATA);
2903f8829a4aSRandall Stewart 	if (m_notify == NULL)
2904f8829a4aSRandall Stewart 		return;
2905139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
2906f8829a4aSRandall Stewart 	spc = mtod(m_notify, struct sctp_paddr_change *);
2907f8829a4aSRandall Stewart 	spc->spc_type = SCTP_PEER_ADDR_CHANGE;
2908f8829a4aSRandall Stewart 	spc->spc_flags = 0;
2909f8829a4aSRandall Stewart 	spc->spc_length = sizeof(struct sctp_paddr_change);
29105e2c2d87SRandall Stewart 	switch (sa->sa_family) {
29115e2c2d87SRandall Stewart 	case AF_INET:
2912f8829a4aSRandall Stewart 		memcpy(&spc->spc_aaddr, sa, sizeof(struct sockaddr_in));
29135e2c2d87SRandall Stewart 		break;
29145e2c2d87SRandall Stewart #ifdef INET6
29155e2c2d87SRandall Stewart 	case AF_INET6:
29165e2c2d87SRandall Stewart 		{
2917f42a358aSRandall Stewart 			struct sockaddr_in6 *sin6;
2918f42a358aSRandall Stewart 
2919f8829a4aSRandall Stewart 			memcpy(&spc->spc_aaddr, sa, sizeof(struct sockaddr_in6));
2920f42a358aSRandall Stewart 
2921f42a358aSRandall Stewart 			sin6 = (struct sockaddr_in6 *)&spc->spc_aaddr;
2922f42a358aSRandall Stewart 			if (IN6_IS_SCOPE_LINKLOCAL(&sin6->sin6_addr)) {
292342551e99SRandall Stewart 				if (sin6->sin6_scope_id == 0) {
292442551e99SRandall Stewart 					/* recover scope_id for user */
2925f42a358aSRandall Stewart 					(void)sa6_recoverscope(sin6);
292642551e99SRandall Stewart 				} else {
292742551e99SRandall Stewart 					/* clear embedded scope_id for user */
292842551e99SRandall Stewart 					in6_clearscope(&sin6->sin6_addr);
292942551e99SRandall Stewart 				}
2930f42a358aSRandall Stewart 			}
29315e2c2d87SRandall Stewart 			break;
29325e2c2d87SRandall Stewart 		}
29335e2c2d87SRandall Stewart #endif
29345e2c2d87SRandall Stewart 	default:
29355e2c2d87SRandall Stewart 		/* TSNH */
29365e2c2d87SRandall Stewart 		break;
2937f8829a4aSRandall Stewart 	}
2938f8829a4aSRandall Stewart 	spc->spc_state = state;
2939f8829a4aSRandall Stewart 	spc->spc_error = error;
2940f8829a4aSRandall Stewart 	spc->spc_assoc_id = sctp_get_associd(stcb);
2941f8829a4aSRandall Stewart 
2942139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_paddr_change);
2943139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
2944f8829a4aSRandall Stewart 
2945f8829a4aSRandall Stewart 	/* append to socket */
2946f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
2947f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
2948f8829a4aSRandall Stewart 	    m_notify);
2949f8829a4aSRandall Stewart 	if (control == NULL) {
2950f8829a4aSRandall Stewart 		/* no memory */
2951f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
2952f8829a4aSRandall Stewart 		return;
2953f8829a4aSRandall Stewart 	}
2954139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
2955139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
2956f8829a4aSRandall Stewart 	/* not that we need this */
2957f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
2958f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
2959f8829a4aSRandall Stewart 	    control,
2960cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1,
2961cfde3ff7SRandall Stewart 	    SCTP_READ_LOCK_NOT_HELD,
2962cfde3ff7SRandall Stewart 	    SCTP_SO_NOT_LOCKED);
2963f8829a4aSRandall Stewart }
2964f8829a4aSRandall Stewart 
2965f8829a4aSRandall Stewart 
2966f8829a4aSRandall Stewart static void
2967f8829a4aSRandall Stewart sctp_notify_send_failed(struct sctp_tcb *stcb, uint32_t error,
2968ceaad40aSRandall Stewart     struct sctp_tmit_chunk *chk, int so_locked
2969ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
2970ceaad40aSRandall Stewart     SCTP_UNUSED
2971ceaad40aSRandall Stewart #endif
2972ceaad40aSRandall Stewart )
2973f8829a4aSRandall Stewart {
2974830d754dSRandall Stewart 	struct mbuf *m_notify;
2975f8829a4aSRandall Stewart 	struct sctp_send_failed *ssf;
2976f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
2977f8829a4aSRandall Stewart 	int length;
2978f8829a4aSRandall Stewart 
2979830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_RECVSENDFAILEVNT)) {
2980f8829a4aSRandall Stewart 		/* event not enabled */
2981f8829a4aSRandall Stewart 		return;
2982830d754dSRandall Stewart 	}
2983139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_send_failed), 0, M_DONTWAIT, 1, MT_DATA);
2984f8829a4aSRandall Stewart 	if (m_notify == NULL)
2985f8829a4aSRandall Stewart 		/* no space left */
2986f8829a4aSRandall Stewart 		return;
2987fc14de76SRandall Stewart 	length = sizeof(struct sctp_send_failed) + chk->send_size;
2988fc14de76SRandall Stewart 	length -= sizeof(struct sctp_data_chunk);
2989139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
2990f8829a4aSRandall Stewart 	ssf = mtod(m_notify, struct sctp_send_failed *);
2991f8829a4aSRandall Stewart 	ssf->ssf_type = SCTP_SEND_FAILED;
2992f8829a4aSRandall Stewart 	if (error == SCTP_NOTIFY_DATAGRAM_UNSENT)
2993f8829a4aSRandall Stewart 		ssf->ssf_flags = SCTP_DATA_UNSENT;
2994f8829a4aSRandall Stewart 	else
2995f8829a4aSRandall Stewart 		ssf->ssf_flags = SCTP_DATA_SENT;
2996f8829a4aSRandall Stewart 	ssf->ssf_length = length;
2997f8829a4aSRandall Stewart 	ssf->ssf_error = error;
2998f8829a4aSRandall Stewart 	/* not exactly what the user sent in, but should be close :) */
2999d00aff5dSRandall Stewart 	bzero(&ssf->ssf_info, sizeof(ssf->ssf_info));
3000f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_stream = chk->rec.data.stream_number;
3001f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_ssn = chk->rec.data.stream_seq;
3002f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_flags = chk->rec.data.rcv_flags;
3003f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_ppid = chk->rec.data.payloadtype;
3004f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_context = chk->rec.data.context;
3005f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_assoc_id = sctp_get_associd(stcb);
3006f8829a4aSRandall Stewart 	ssf->ssf_assoc_id = sctp_get_associd(stcb);
3007fc14de76SRandall Stewart 
3008830d754dSRandall Stewart 	if (chk->data) {
3009830d754dSRandall Stewart 		/*
3010830d754dSRandall Stewart 		 * trim off the sctp chunk header(it should be there)
3011830d754dSRandall Stewart 		 */
3012830d754dSRandall Stewart 		if (chk->send_size >= sizeof(struct sctp_data_chunk)) {
3013830d754dSRandall Stewart 			m_adj(chk->data, sizeof(struct sctp_data_chunk));
3014830d754dSRandall Stewart 			sctp_mbuf_crush(chk->data);
3015830d754dSRandall Stewart 			chk->send_size -= sizeof(struct sctp_data_chunk);
3016830d754dSRandall Stewart 		}
3017830d754dSRandall Stewart 	}
3018810ec536SMichael Tuexen 	SCTP_BUF_NEXT(m_notify) = chk->data;
3019810ec536SMichael Tuexen 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_send_failed);
3020f8829a4aSRandall Stewart 	/* Steal off the mbuf */
3021f8829a4aSRandall Stewart 	chk->data = NULL;
3022f8829a4aSRandall Stewart 	/*
3023f8829a4aSRandall Stewart 	 * For this case, we check the actual socket buffer, since the assoc
3024f8829a4aSRandall Stewart 	 * is going away we don't want to overfill the socket buffer for a
3025f8829a4aSRandall Stewart 	 * non-reader
3026f8829a4aSRandall Stewart 	 */
3027139bc87fSRandall Stewart 	if (sctp_sbspace_failedmsgs(&stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3028f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3029f8829a4aSRandall Stewart 		return;
3030f8829a4aSRandall Stewart 	}
3031f8829a4aSRandall Stewart 	/* append to socket */
3032f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3033f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3034f8829a4aSRandall Stewart 	    m_notify);
3035f8829a4aSRandall Stewart 	if (control == NULL) {
3036f8829a4aSRandall Stewart 		/* no memory */
3037f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3038f8829a4aSRandall Stewart 		return;
3039f8829a4aSRandall Stewart 	}
3040139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3041f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3042f8829a4aSRandall Stewart 	    control,
3043cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1,
3044cfde3ff7SRandall Stewart 	    SCTP_READ_LOCK_NOT_HELD,
3045cfde3ff7SRandall Stewart 	    so_locked);
3046f8829a4aSRandall Stewart }
3047f8829a4aSRandall Stewart 
3048f8829a4aSRandall Stewart 
3049f8829a4aSRandall Stewart static void
3050f8829a4aSRandall Stewart sctp_notify_send_failed2(struct sctp_tcb *stcb, uint32_t error,
3051ceaad40aSRandall Stewart     struct sctp_stream_queue_pending *sp, int so_locked
3052ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3053ceaad40aSRandall Stewart     SCTP_UNUSED
3054ceaad40aSRandall Stewart #endif
3055ceaad40aSRandall Stewart )
3056f8829a4aSRandall Stewart {
3057f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3058f8829a4aSRandall Stewart 	struct sctp_send_failed *ssf;
3059f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3060f8829a4aSRandall Stewart 	int length;
3061f8829a4aSRandall Stewart 
3062830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_RECVSENDFAILEVNT)) {
3063f8829a4aSRandall Stewart 		/* event not enabled */
3064f8829a4aSRandall Stewart 		return;
3065830d754dSRandall Stewart 	}
3066f8829a4aSRandall Stewart 	length = sizeof(struct sctp_send_failed) + sp->length;
3067d00aff5dSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_send_failed), 0, M_DONTWAIT, 1, MT_DATA);
3068f8829a4aSRandall Stewart 	if (m_notify == NULL)
3069f8829a4aSRandall Stewart 		/* no space left */
3070f8829a4aSRandall Stewart 		return;
3071139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3072f8829a4aSRandall Stewart 	ssf = mtod(m_notify, struct sctp_send_failed *);
3073f8829a4aSRandall Stewart 	ssf->ssf_type = SCTP_SEND_FAILED;
3074f8829a4aSRandall Stewart 	if (error == SCTP_NOTIFY_DATAGRAM_UNSENT)
3075f8829a4aSRandall Stewart 		ssf->ssf_flags = SCTP_DATA_UNSENT;
3076f8829a4aSRandall Stewart 	else
3077f8829a4aSRandall Stewart 		ssf->ssf_flags = SCTP_DATA_SENT;
3078f8829a4aSRandall Stewart 	ssf->ssf_length = length;
3079f8829a4aSRandall Stewart 	ssf->ssf_error = error;
3080f8829a4aSRandall Stewart 	/* not exactly what the user sent in, but should be close :) */
3081d00aff5dSRandall Stewart 	bzero(&ssf->ssf_info, sizeof(ssf->ssf_info));
3082f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_stream = sp->stream;
3083f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_ssn = sp->strseq;
3084fc14de76SRandall Stewart 	if (sp->some_taken) {
3085fc14de76SRandall Stewart 		ssf->ssf_info.sinfo_flags = SCTP_DATA_LAST_FRAG;
3086fc14de76SRandall Stewart 	} else {
3087fc14de76SRandall Stewart 		ssf->ssf_info.sinfo_flags = SCTP_DATA_NOT_FRAG;
3088fc14de76SRandall Stewart 	}
3089f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_ppid = sp->ppid;
3090f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_context = sp->context;
3091f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_assoc_id = sctp_get_associd(stcb);
3092f8829a4aSRandall Stewart 	ssf->ssf_assoc_id = sctp_get_associd(stcb);
3093139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = sp->data;
3094139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_send_failed);
3095f8829a4aSRandall Stewart 
3096f8829a4aSRandall Stewart 	/* Steal off the mbuf */
3097f8829a4aSRandall Stewart 	sp->data = NULL;
3098f8829a4aSRandall Stewart 	/*
3099f8829a4aSRandall Stewart 	 * For this case, we check the actual socket buffer, since the assoc
3100f8829a4aSRandall Stewart 	 * is going away we don't want to overfill the socket buffer for a
3101f8829a4aSRandall Stewart 	 * non-reader
3102f8829a4aSRandall Stewart 	 */
3103139bc87fSRandall Stewart 	if (sctp_sbspace_failedmsgs(&stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3104f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3105f8829a4aSRandall Stewart 		return;
3106f8829a4aSRandall Stewart 	}
3107f8829a4aSRandall Stewart 	/* append to socket */
3108f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3109f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3110f8829a4aSRandall Stewart 	    m_notify);
3111f8829a4aSRandall Stewart 	if (control == NULL) {
3112f8829a4aSRandall Stewart 		/* no memory */
3113f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3114f8829a4aSRandall Stewart 		return;
3115f8829a4aSRandall Stewart 	}
3116139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3117f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3118f8829a4aSRandall Stewart 	    control,
3119cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, so_locked);
3120f8829a4aSRandall Stewart }
3121f8829a4aSRandall Stewart 
3122f8829a4aSRandall Stewart 
3123f8829a4aSRandall Stewart 
3124f8829a4aSRandall Stewart static void
3125f8829a4aSRandall Stewart sctp_notify_adaptation_layer(struct sctp_tcb *stcb,
3126f8829a4aSRandall Stewart     uint32_t error)
3127f8829a4aSRandall Stewart {
3128f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3129f8829a4aSRandall Stewart 	struct sctp_adaptation_event *sai;
3130f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3131f8829a4aSRandall Stewart 
3132830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_ADAPTATIONEVNT)) {
3133f8829a4aSRandall Stewart 		/* event not enabled */
3134f8829a4aSRandall Stewart 		return;
3135830d754dSRandall Stewart 	}
3136139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_adaption_event), 0, M_DONTWAIT, 1, MT_DATA);
3137f8829a4aSRandall Stewart 	if (m_notify == NULL)
3138f8829a4aSRandall Stewart 		/* no space left */
3139f8829a4aSRandall Stewart 		return;
3140139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3141f8829a4aSRandall Stewart 	sai = mtod(m_notify, struct sctp_adaptation_event *);
3142f8829a4aSRandall Stewart 	sai->sai_type = SCTP_ADAPTATION_INDICATION;
3143f8829a4aSRandall Stewart 	sai->sai_flags = 0;
3144f8829a4aSRandall Stewart 	sai->sai_length = sizeof(struct sctp_adaptation_event);
31452afb3e84SRandall Stewart 	sai->sai_adaptation_ind = stcb->asoc.peers_adaptation;
3146f8829a4aSRandall Stewart 	sai->sai_assoc_id = sctp_get_associd(stcb);
3147f8829a4aSRandall Stewart 
3148139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_adaptation_event);
3149139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3150f8829a4aSRandall Stewart 
3151f8829a4aSRandall Stewart 	/* append to socket */
3152f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3153f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3154f8829a4aSRandall Stewart 	    m_notify);
3155f8829a4aSRandall Stewart 	if (control == NULL) {
3156f8829a4aSRandall Stewart 		/* no memory */
3157f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3158f8829a4aSRandall Stewart 		return;
3159f8829a4aSRandall Stewart 	}
3160139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3161139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3162f8829a4aSRandall Stewart 	/* not that we need this */
3163f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
3164f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3165f8829a4aSRandall Stewart 	    control,
3166cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, SCTP_SO_NOT_LOCKED);
3167f8829a4aSRandall Stewart }
3168f8829a4aSRandall Stewart 
316903b0b021SRandall Stewart /* This always must be called with the read-queue LOCKED in the INP */
3170810ec536SMichael Tuexen static void
31712dad8a55SRandall Stewart sctp_notify_partial_delivery_indication(struct sctp_tcb *stcb, uint32_t error,
3172810ec536SMichael Tuexen     uint32_t val, int so_locked
3173810ec536SMichael Tuexen #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3174810ec536SMichael Tuexen     SCTP_UNUSED
3175810ec536SMichael Tuexen #endif
3176810ec536SMichael Tuexen )
3177f8829a4aSRandall Stewart {
3178f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3179f8829a4aSRandall Stewart 	struct sctp_pdapi_event *pdapi;
3180f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
318103b0b021SRandall Stewart 	struct sockbuf *sb;
3182f8829a4aSRandall Stewart 
3183830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_PDAPIEVNT)) {
3184f8829a4aSRandall Stewart 		/* event not enabled */
3185f8829a4aSRandall Stewart 		return;
3186830d754dSRandall Stewart 	}
3187139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_pdapi_event), 0, M_DONTWAIT, 1, MT_DATA);
3188f8829a4aSRandall Stewart 	if (m_notify == NULL)
3189f8829a4aSRandall Stewart 		/* no space left */
3190f8829a4aSRandall Stewart 		return;
3191139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3192f8829a4aSRandall Stewart 	pdapi = mtod(m_notify, struct sctp_pdapi_event *);
3193f8829a4aSRandall Stewart 	pdapi->pdapi_type = SCTP_PARTIAL_DELIVERY_EVENT;
3194f8829a4aSRandall Stewart 	pdapi->pdapi_flags = 0;
3195f8829a4aSRandall Stewart 	pdapi->pdapi_length = sizeof(struct sctp_pdapi_event);
3196f8829a4aSRandall Stewart 	pdapi->pdapi_indication = error;
31979a6142d8SRandall Stewart 	pdapi->pdapi_stream = (val >> 16);
31989a6142d8SRandall Stewart 	pdapi->pdapi_seq = (val & 0x0000ffff);
3199f8829a4aSRandall Stewart 	pdapi->pdapi_assoc_id = sctp_get_associd(stcb);
3200f8829a4aSRandall Stewart 
3201139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_pdapi_event);
3202139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3203f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3204f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3205f8829a4aSRandall Stewart 	    m_notify);
3206f8829a4aSRandall Stewart 	if (control == NULL) {
3207f8829a4aSRandall Stewart 		/* no memory */
3208f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3209f8829a4aSRandall Stewart 		return;
3210f8829a4aSRandall Stewart 	}
3211139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3212139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3213f8829a4aSRandall Stewart 	/* not that we need this */
3214f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
321503b0b021SRandall Stewart 	control->held_length = 0;
321603b0b021SRandall Stewart 	control->length = 0;
321703b0b021SRandall Stewart 	sb = &stcb->sctp_socket->so_rcv;
3218b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
3219139bc87fSRandall Stewart 		sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m_notify));
322080fefe0aSRandall Stewart 	}
322103b0b021SRandall Stewart 	sctp_sballoc(stcb, sb, m_notify);
3222b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
322303b0b021SRandall Stewart 		sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
322480fefe0aSRandall Stewart 	}
3225139bc87fSRandall Stewart 	atomic_add_int(&control->length, SCTP_BUF_LEN(m_notify));
322603b0b021SRandall Stewart 	control->end_added = 1;
322703b0b021SRandall Stewart 	if (stcb->asoc.control_pdapi)
322803b0b021SRandall Stewart 		TAILQ_INSERT_AFTER(&stcb->sctp_ep->read_queue, stcb->asoc.control_pdapi, control, next);
322903b0b021SRandall Stewart 	else {
323003b0b021SRandall Stewart 		/* we really should not see this case */
323103b0b021SRandall Stewart 		TAILQ_INSERT_TAIL(&stcb->sctp_ep->read_queue, control, next);
323203b0b021SRandall Stewart 	}
323303b0b021SRandall Stewart 	if (stcb->sctp_ep && stcb->sctp_socket) {
323403b0b021SRandall Stewart 		/* This should always be the case */
3235810ec536SMichael Tuexen #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3236810ec536SMichael Tuexen 		struct socket *so;
3237810ec536SMichael Tuexen 
3238810ec536SMichael Tuexen 		so = SCTP_INP_SO(stcb->sctp_ep);
3239810ec536SMichael Tuexen 		if (!so_locked) {
3240810ec536SMichael Tuexen 			atomic_add_int(&stcb->asoc.refcnt, 1);
3241810ec536SMichael Tuexen 			SCTP_TCB_UNLOCK(stcb);
3242810ec536SMichael Tuexen 			SCTP_SOCKET_LOCK(so, 1);
3243810ec536SMichael Tuexen 			SCTP_TCB_LOCK(stcb);
3244810ec536SMichael Tuexen 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
3245810ec536SMichael Tuexen 			if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
3246810ec536SMichael Tuexen 				SCTP_SOCKET_UNLOCK(so, 1);
3247810ec536SMichael Tuexen 				return;
3248810ec536SMichael Tuexen 			}
3249810ec536SMichael Tuexen 		}
3250810ec536SMichael Tuexen #endif
325103b0b021SRandall Stewart 		sctp_sorwakeup(stcb->sctp_ep, stcb->sctp_socket);
3252810ec536SMichael Tuexen #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3253810ec536SMichael Tuexen 		if (!so_locked) {
3254810ec536SMichael Tuexen 			SCTP_SOCKET_UNLOCK(so, 1);
3255810ec536SMichael Tuexen 		}
3256810ec536SMichael Tuexen #endif
3257f8829a4aSRandall Stewart 	}
3258f8829a4aSRandall Stewart }
3259f8829a4aSRandall Stewart 
3260f8829a4aSRandall Stewart static void
3261f8829a4aSRandall Stewart sctp_notify_shutdown_event(struct sctp_tcb *stcb)
3262f8829a4aSRandall Stewart {
3263f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3264f8829a4aSRandall Stewart 	struct sctp_shutdown_event *sse;
3265f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3266f8829a4aSRandall Stewart 
3267f8829a4aSRandall Stewart 	/*
3268f8829a4aSRandall Stewart 	 * For TCP model AND UDP connected sockets we will send an error up
3269f8829a4aSRandall Stewart 	 * when an SHUTDOWN completes
3270f8829a4aSRandall Stewart 	 */
3271f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
3272f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
3273f8829a4aSRandall Stewart 		/* mark socket closed for read/write and wakeup! */
3274ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3275ceaad40aSRandall Stewart 		struct socket *so;
3276ceaad40aSRandall Stewart 
3277ceaad40aSRandall Stewart 		so = SCTP_INP_SO(stcb->sctp_ep);
3278ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
3279ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
3280ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
3281ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
3282ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
3283ceaad40aSRandall Stewart 		if (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET) {
3284ceaad40aSRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
3285ceaad40aSRandall Stewart 			return;
3286ceaad40aSRandall Stewart 		}
3287ceaad40aSRandall Stewart #endif
3288f8829a4aSRandall Stewart 		socantsendmore(stcb->sctp_socket);
3289ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3290ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
3291ceaad40aSRandall Stewart #endif
3292f8829a4aSRandall Stewart 	}
3293830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_RECVSHUTDOWNEVNT)) {
3294f8829a4aSRandall Stewart 		/* event not enabled */
3295f8829a4aSRandall Stewart 		return;
3296830d754dSRandall Stewart 	}
3297139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_shutdown_event), 0, M_DONTWAIT, 1, MT_DATA);
3298f8829a4aSRandall Stewart 	if (m_notify == NULL)
3299f8829a4aSRandall Stewart 		/* no space left */
3300f8829a4aSRandall Stewart 		return;
3301f8829a4aSRandall Stewart 	sse = mtod(m_notify, struct sctp_shutdown_event *);
3302f8829a4aSRandall Stewart 	sse->sse_type = SCTP_SHUTDOWN_EVENT;
3303f8829a4aSRandall Stewart 	sse->sse_flags = 0;
3304f8829a4aSRandall Stewart 	sse->sse_length = sizeof(struct sctp_shutdown_event);
3305f8829a4aSRandall Stewart 	sse->sse_assoc_id = sctp_get_associd(stcb);
3306f8829a4aSRandall Stewart 
3307139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_shutdown_event);
3308139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3309f8829a4aSRandall Stewart 
3310f8829a4aSRandall Stewart 	/* append to socket */
3311f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3312f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3313f8829a4aSRandall Stewart 	    m_notify);
3314f8829a4aSRandall Stewart 	if (control == NULL) {
3315f8829a4aSRandall Stewart 		/* no memory */
3316f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3317f8829a4aSRandall Stewart 		return;
3318f8829a4aSRandall Stewart 	}
3319139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3320139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3321f8829a4aSRandall Stewart 	/* not that we need this */
3322f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
3323f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3324f8829a4aSRandall Stewart 	    control,
3325cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, SCTP_SO_NOT_LOCKED);
3326f8829a4aSRandall Stewart }
3327f8829a4aSRandall Stewart 
3328f8829a4aSRandall Stewart static void
3329830d754dSRandall Stewart sctp_notify_sender_dry_event(struct sctp_tcb *stcb,
3330830d754dSRandall Stewart     int so_locked
3331830d754dSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3332830d754dSRandall Stewart     SCTP_UNUSED
3333830d754dSRandall Stewart #endif
3334830d754dSRandall Stewart )
3335830d754dSRandall Stewart {
3336830d754dSRandall Stewart 	struct mbuf *m_notify;
3337830d754dSRandall Stewart 	struct sctp_sender_dry_event *event;
3338830d754dSRandall Stewart 	struct sctp_queued_to_read *control;
3339830d754dSRandall Stewart 
3340830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_DRYEVNT)) {
3341830d754dSRandall Stewart 		/* event not enabled */
3342830d754dSRandall Stewart 		return;
3343830d754dSRandall Stewart 	}
3344830d754dSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_sender_dry_event), 0, M_DONTWAIT, 1, MT_DATA);
3345830d754dSRandall Stewart 	if (m_notify == NULL) {
3346830d754dSRandall Stewart 		/* no space left */
3347830d754dSRandall Stewart 		return;
3348830d754dSRandall Stewart 	}
3349830d754dSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3350830d754dSRandall Stewart 	event = mtod(m_notify, struct sctp_sender_dry_event *);
3351830d754dSRandall Stewart 	event->sender_dry_type = SCTP_SENDER_DRY_EVENT;
3352830d754dSRandall Stewart 	event->sender_dry_flags = 0;
3353830d754dSRandall Stewart 	event->sender_dry_length = sizeof(struct sctp_sender_dry_event);
3354830d754dSRandall Stewart 	event->sender_dry_assoc_id = sctp_get_associd(stcb);
3355830d754dSRandall Stewart 
3356830d754dSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_sender_dry_event);
3357830d754dSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3358830d754dSRandall Stewart 
3359830d754dSRandall Stewart 	/* append to socket */
3360830d754dSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3361830d754dSRandall Stewart 	    0, 0, 0, 0, 0, 0, m_notify);
3362830d754dSRandall Stewart 	if (control == NULL) {
3363830d754dSRandall Stewart 		/* no memory */
3364830d754dSRandall Stewart 		sctp_m_freem(m_notify);
3365830d754dSRandall Stewart 		return;
3366830d754dSRandall Stewart 	}
3367830d754dSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3368830d754dSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3369830d754dSRandall Stewart 	/* not that we need this */
3370830d754dSRandall Stewart 	control->tail_mbuf = m_notify;
3371830d754dSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb, control,
3372cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, so_locked);
3373830d754dSRandall Stewart }
3374830d754dSRandall Stewart 
3375ea44232bSRandall Stewart 
3376ea44232bSRandall Stewart static void
3377ea44232bSRandall Stewart sctp_notify_stream_reset_add(struct sctp_tcb *stcb, int number_entries, int flag)
3378ea44232bSRandall Stewart {
3379ea44232bSRandall Stewart 	struct mbuf *m_notify;
3380ea44232bSRandall Stewart 	struct sctp_queued_to_read *control;
3381ea44232bSRandall Stewart 	struct sctp_stream_reset_event *strreset;
3382ea44232bSRandall Stewart 	int len;
3383ea44232bSRandall Stewart 
3384ea44232bSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_STREAM_RESETEVNT)) {
3385ea44232bSRandall Stewart 		/* event not enabled */
3386ea44232bSRandall Stewart 		return;
3387ea44232bSRandall Stewart 	}
3388ea44232bSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(MCLBYTES, 0, M_DONTWAIT, 1, MT_DATA);
3389ea44232bSRandall Stewart 	if (m_notify == NULL)
3390ea44232bSRandall Stewart 		/* no space left */
3391ea44232bSRandall Stewart 		return;
3392ea44232bSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3393ea44232bSRandall Stewart 	len = sizeof(struct sctp_stream_reset_event) + (number_entries * sizeof(uint16_t));
3394ea44232bSRandall Stewart 	if (len > M_TRAILINGSPACE(m_notify)) {
3395ea44232bSRandall Stewart 		/* never enough room */
3396ea44232bSRandall Stewart 		sctp_m_freem(m_notify);
3397ea44232bSRandall Stewart 		return;
3398ea44232bSRandall Stewart 	}
3399ea44232bSRandall Stewart 	strreset = mtod(m_notify, struct sctp_stream_reset_event *);
3400ea44232bSRandall Stewart 	strreset->strreset_type = SCTP_STREAM_RESET_EVENT;
3401ea44232bSRandall Stewart 	strreset->strreset_flags = SCTP_STRRESET_ADD_STREAM | flag;
3402ea44232bSRandall Stewart 	strreset->strreset_length = len;
3403ea44232bSRandall Stewart 	strreset->strreset_assoc_id = sctp_get_associd(stcb);
3404ea44232bSRandall Stewart 	strreset->strreset_list[0] = number_entries;
3405ea44232bSRandall Stewart 
3406ea44232bSRandall Stewart 	SCTP_BUF_LEN(m_notify) = len;
3407ea44232bSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3408ea44232bSRandall Stewart 	if (sctp_sbspace(&stcb->asoc, &stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3409ea44232bSRandall Stewart 		/* no space */
3410ea44232bSRandall Stewart 		sctp_m_freem(m_notify);
3411ea44232bSRandall Stewart 		return;
3412ea44232bSRandall Stewart 	}
3413ea44232bSRandall Stewart 	/* append to socket */
3414ea44232bSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3415ea44232bSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3416ea44232bSRandall Stewart 	    m_notify);
3417ea44232bSRandall Stewart 	if (control == NULL) {
3418ea44232bSRandall Stewart 		/* no memory */
3419ea44232bSRandall Stewart 		sctp_m_freem(m_notify);
3420ea44232bSRandall Stewart 		return;
3421ea44232bSRandall Stewart 	}
3422ea44232bSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3423ea44232bSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3424ea44232bSRandall Stewart 	/* not that we need this */
3425ea44232bSRandall Stewart 	control->tail_mbuf = m_notify;
3426ea44232bSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3427ea44232bSRandall Stewart 	    control,
3428cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, SCTP_SO_NOT_LOCKED);
3429ea44232bSRandall Stewart }
3430ea44232bSRandall Stewart 
3431ea44232bSRandall Stewart 
3432830d754dSRandall Stewart static void
3433f8829a4aSRandall Stewart sctp_notify_stream_reset(struct sctp_tcb *stcb,
3434f8829a4aSRandall Stewart     int number_entries, uint16_t * list, int flag)
3435f8829a4aSRandall Stewart {
3436f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3437f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3438f8829a4aSRandall Stewart 	struct sctp_stream_reset_event *strreset;
3439f8829a4aSRandall Stewart 	int len;
3440f8829a4aSRandall Stewart 
3441830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_STREAM_RESETEVNT)) {
3442f8829a4aSRandall Stewart 		/* event not enabled */
3443f8829a4aSRandall Stewart 		return;
3444830d754dSRandall Stewart 	}
3445139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(MCLBYTES, 0, M_DONTWAIT, 1, MT_DATA);
3446f8829a4aSRandall Stewart 	if (m_notify == NULL)
3447f8829a4aSRandall Stewart 		/* no space left */
3448f8829a4aSRandall Stewart 		return;
3449139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3450f8829a4aSRandall Stewart 	len = sizeof(struct sctp_stream_reset_event) + (number_entries * sizeof(uint16_t));
3451f8829a4aSRandall Stewart 	if (len > M_TRAILINGSPACE(m_notify)) {
3452f8829a4aSRandall Stewart 		/* never enough room */
3453f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3454f8829a4aSRandall Stewart 		return;
3455f8829a4aSRandall Stewart 	}
3456f8829a4aSRandall Stewart 	strreset = mtod(m_notify, struct sctp_stream_reset_event *);
3457f8829a4aSRandall Stewart 	strreset->strreset_type = SCTP_STREAM_RESET_EVENT;
3458f8829a4aSRandall Stewart 	if (number_entries == 0) {
3459f8829a4aSRandall Stewart 		strreset->strreset_flags = flag | SCTP_STRRESET_ALL_STREAMS;
3460f8829a4aSRandall Stewart 	} else {
3461f8829a4aSRandall Stewart 		strreset->strreset_flags = flag | SCTP_STRRESET_STREAM_LIST;
3462f8829a4aSRandall Stewart 	}
3463f8829a4aSRandall Stewart 	strreset->strreset_length = len;
3464f8829a4aSRandall Stewart 	strreset->strreset_assoc_id = sctp_get_associd(stcb);
3465f8829a4aSRandall Stewart 	if (number_entries) {
3466f8829a4aSRandall Stewart 		int i;
3467f8829a4aSRandall Stewart 
3468f8829a4aSRandall Stewart 		for (i = 0; i < number_entries; i++) {
3469f8829a4aSRandall Stewart 			strreset->strreset_list[i] = ntohs(list[i]);
3470f8829a4aSRandall Stewart 		}
3471f8829a4aSRandall Stewart 	}
3472139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = len;
3473139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3474139bc87fSRandall Stewart 	if (sctp_sbspace(&stcb->asoc, &stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3475f8829a4aSRandall Stewart 		/* no space */
3476f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3477f8829a4aSRandall Stewart 		return;
3478f8829a4aSRandall Stewart 	}
3479f8829a4aSRandall Stewart 	/* append to socket */
3480f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3481f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3482f8829a4aSRandall Stewart 	    m_notify);
3483f8829a4aSRandall Stewart 	if (control == NULL) {
3484f8829a4aSRandall Stewart 		/* no memory */
3485f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3486f8829a4aSRandall Stewart 		return;
3487f8829a4aSRandall Stewart 	}
3488139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3489139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3490f8829a4aSRandall Stewart 	/* not that we need this */
3491f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
3492f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3493f8829a4aSRandall Stewart 	    control,
3494cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, SCTP_SO_NOT_LOCKED);
3495f8829a4aSRandall Stewart }
3496f8829a4aSRandall Stewart 
3497f8829a4aSRandall Stewart 
3498f8829a4aSRandall Stewart void
3499f8829a4aSRandall Stewart sctp_ulp_notify(uint32_t notification, struct sctp_tcb *stcb,
3500ceaad40aSRandall Stewart     uint32_t error, void *data, int so_locked
3501ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3502ceaad40aSRandall Stewart     SCTP_UNUSED
3503ceaad40aSRandall Stewart #endif
3504ceaad40aSRandall Stewart )
3505f8829a4aSRandall Stewart {
3506830d754dSRandall Stewart 	if ((stcb == NULL) ||
3507830d754dSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
3508f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
3509830d754dSRandall Stewart 	    (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET)) {
3510830d754dSRandall Stewart 		/* If the socket is gone we are out of here */
3511f8829a4aSRandall Stewart 		return;
3512f8829a4aSRandall Stewart 	}
3513a99b6783SRandall Stewart 	if (stcb->sctp_socket->so_rcv.sb_state & SBS_CANTRCVMORE) {
3514a99b6783SRandall Stewart 		return;
3515a99b6783SRandall Stewart 	}
351617205eccSRandall Stewart 	if (stcb && ((stcb->asoc.state & SCTP_STATE_COOKIE_WAIT) ||
351717205eccSRandall Stewart 	    (stcb->asoc.state & SCTP_STATE_COOKIE_ECHOED))) {
351817205eccSRandall Stewart 		if ((notification == SCTP_NOTIFY_INTERFACE_DOWN) ||
351917205eccSRandall Stewart 		    (notification == SCTP_NOTIFY_INTERFACE_UP) ||
352017205eccSRandall Stewart 		    (notification == SCTP_NOTIFY_INTERFACE_CONFIRMED)) {
352117205eccSRandall Stewart 			/* Don't report these in front states */
352217205eccSRandall Stewart 			return;
352317205eccSRandall Stewart 		}
352417205eccSRandall Stewart 	}
3525f8829a4aSRandall Stewart 	switch (notification) {
3526f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_UP:
3527f8829a4aSRandall Stewart 		if (stcb->asoc.assoc_up_sent == 0) {
3528ceaad40aSRandall Stewart 			sctp_notify_assoc_change(SCTP_COMM_UP, stcb, error, NULL, so_locked);
3529f8829a4aSRandall Stewart 			stcb->asoc.assoc_up_sent = 1;
3530f8829a4aSRandall Stewart 		}
35312afb3e84SRandall Stewart 		if (stcb->asoc.adaptation_needed && (stcb->asoc.adaptation_sent == 0)) {
35322afb3e84SRandall Stewart 			sctp_notify_adaptation_layer(stcb, error);
35332afb3e84SRandall Stewart 		}
3534830d754dSRandall Stewart 		if (stcb->asoc.peer_supports_auth == 0) {
3535830d754dSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_NO_PEER_AUTH, stcb, 0,
3536830d754dSRandall Stewart 			    NULL, so_locked);
3537830d754dSRandall Stewart 		}
3538f8829a4aSRandall Stewart 		break;
3539f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_DOWN:
3540ceaad40aSRandall Stewart 		sctp_notify_assoc_change(SCTP_SHUTDOWN_COMP, stcb, error, NULL, so_locked);
3541f8829a4aSRandall Stewart 		break;
3542f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_DOWN:
3543f8829a4aSRandall Stewart 		{
3544f8829a4aSRandall Stewart 			struct sctp_nets *net;
3545f8829a4aSRandall Stewart 
3546f8829a4aSRandall Stewart 			net = (struct sctp_nets *)data;
3547f8829a4aSRandall Stewart 			sctp_notify_peer_addr_change(stcb, SCTP_ADDR_UNREACHABLE,
3548f8829a4aSRandall Stewart 			    (struct sockaddr *)&net->ro._l_addr, error);
3549f8829a4aSRandall Stewart 			break;
3550f8829a4aSRandall Stewart 		}
3551f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_UP:
3552f8829a4aSRandall Stewart 		{
3553f8829a4aSRandall Stewart 			struct sctp_nets *net;
3554f8829a4aSRandall Stewart 
3555f8829a4aSRandall Stewart 			net = (struct sctp_nets *)data;
3556f8829a4aSRandall Stewart 			sctp_notify_peer_addr_change(stcb, SCTP_ADDR_AVAILABLE,
3557f8829a4aSRandall Stewart 			    (struct sockaddr *)&net->ro._l_addr, error);
3558f8829a4aSRandall Stewart 			break;
3559f8829a4aSRandall Stewart 		}
3560f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_CONFIRMED:
3561f8829a4aSRandall Stewart 		{
3562f8829a4aSRandall Stewart 			struct sctp_nets *net;
3563f8829a4aSRandall Stewart 
3564f8829a4aSRandall Stewart 			net = (struct sctp_nets *)data;
3565f8829a4aSRandall Stewart 			sctp_notify_peer_addr_change(stcb, SCTP_ADDR_CONFIRMED,
3566f8829a4aSRandall Stewart 			    (struct sockaddr *)&net->ro._l_addr, error);
3567f8829a4aSRandall Stewart 			break;
3568f8829a4aSRandall Stewart 		}
3569f8829a4aSRandall Stewart 	case SCTP_NOTIFY_SPECIAL_SP_FAIL:
3570f8829a4aSRandall Stewart 		sctp_notify_send_failed2(stcb, error,
3571ceaad40aSRandall Stewart 		    (struct sctp_stream_queue_pending *)data, so_locked);
3572f8829a4aSRandall Stewart 		break;
3573f8829a4aSRandall Stewart 	case SCTP_NOTIFY_DG_FAIL:
3574f8829a4aSRandall Stewart 		sctp_notify_send_failed(stcb, error,
3575ceaad40aSRandall Stewart 		    (struct sctp_tmit_chunk *)data, so_locked);
3576f8829a4aSRandall Stewart 		break;
3577f8829a4aSRandall Stewart 	case SCTP_NOTIFY_PARTIAL_DELVIERY_INDICATION:
35789a6142d8SRandall Stewart 		{
35799a6142d8SRandall Stewart 			uint32_t val;
35809a6142d8SRandall Stewart 
35819a6142d8SRandall Stewart 			val = *((uint32_t *) data);
35829a6142d8SRandall Stewart 
3583810ec536SMichael Tuexen 			sctp_notify_partial_delivery_indication(stcb, error, val, so_locked);
3584f8829a4aSRandall Stewart 			break;
3585810ec536SMichael Tuexen 		}
3586f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STRDATA_ERR:
3587f8829a4aSRandall Stewart 		break;
3588f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_ABORTED:
3589c105859eSRandall Stewart 		if ((stcb) && (((stcb->asoc.state & SCTP_STATE_MASK) == SCTP_STATE_COOKIE_WAIT) ||
3590c105859eSRandall Stewart 		    ((stcb->asoc.state & SCTP_STATE_MASK) == SCTP_STATE_COOKIE_ECHOED))) {
3591ceaad40aSRandall Stewart 			sctp_notify_assoc_change(SCTP_CANT_STR_ASSOC, stcb, error, NULL, so_locked);
3592c105859eSRandall Stewart 		} else {
3593ceaad40aSRandall Stewart 			sctp_notify_assoc_change(SCTP_COMM_LOST, stcb, error, NULL, so_locked);
3594c105859eSRandall Stewart 		}
3595f8829a4aSRandall Stewart 		break;
3596f8829a4aSRandall Stewart 	case SCTP_NOTIFY_PEER_OPENED_STREAM:
3597f8829a4aSRandall Stewart 		break;
3598f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STREAM_OPENED_OK:
3599f8829a4aSRandall Stewart 		break;
3600f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_RESTART:
3601ceaad40aSRandall Stewart 		sctp_notify_assoc_change(SCTP_RESTART, stcb, error, data, so_locked);
3602830d754dSRandall Stewart 		if (stcb->asoc.peer_supports_auth == 0) {
3603830d754dSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_NO_PEER_AUTH, stcb, 0,
3604830d754dSRandall Stewart 			    NULL, so_locked);
3605830d754dSRandall Stewart 		}
3606f8829a4aSRandall Stewart 		break;
3607f8829a4aSRandall Stewart 	case SCTP_NOTIFY_HB_RESP:
3608f8829a4aSRandall Stewart 		break;
3609ea44232bSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_INSTREAM_ADD_OK:
3610ea44232bSRandall Stewart 		sctp_notify_stream_reset_add(stcb, error, SCTP_STRRESET_INBOUND_STR);
3611ea44232bSRandall Stewart 		break;
3612ea44232bSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_ADD_OK:
3613ea44232bSRandall Stewart 		sctp_notify_stream_reset_add(stcb, error, SCTP_STRRESET_OUTBOUND_STR);
3614ea44232bSRandall Stewart 		break;
3615ea44232bSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_ADD_FAIL:
3616ea44232bSRandall Stewart 		sctp_notify_stream_reset_add(stcb, error, (SCTP_STRRESET_FAILED | SCTP_STRRESET_OUTBOUND_STR));
3617ea44232bSRandall Stewart 		break;
3618ea44232bSRandall Stewart 
3619f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_SEND:
3620f8829a4aSRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data), SCTP_STRRESET_OUTBOUND_STR);
3621f8829a4aSRandall Stewart 		break;
3622f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_RECV:
3623f8829a4aSRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data), SCTP_STRRESET_INBOUND_STR);
3624f8829a4aSRandall Stewart 		break;
3625f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_FAILED_OUT:
3626671d309cSRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data), (SCTP_STRRESET_OUTBOUND_STR | SCTP_STRRESET_FAILED));
3627f8829a4aSRandall Stewart 		break;
3628f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_FAILED_IN:
3629671d309cSRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data), (SCTP_STRRESET_INBOUND_STR | SCTP_STRRESET_FAILED));
3630f8829a4aSRandall Stewart 		break;
3631f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_ADD_IP:
3632f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_ADDED, data,
3633f8829a4aSRandall Stewart 		    error);
3634f8829a4aSRandall Stewart 		break;
3635f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_DELETE_IP:
3636f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_REMOVED, data,
3637f8829a4aSRandall Stewart 		    error);
3638f8829a4aSRandall Stewart 		break;
3639f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_SET_PRIMARY:
3640f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_MADE_PRIM, data,
3641f8829a4aSRandall Stewart 		    error);
3642f8829a4aSRandall Stewart 		break;
3643f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_SUCCESS:
3644f8829a4aSRandall Stewart 		break;
3645f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_FAILED:
3646f8829a4aSRandall Stewart 		break;
3647f8829a4aSRandall Stewart 	case SCTP_NOTIFY_PEER_SHUTDOWN:
3648f8829a4aSRandall Stewart 		sctp_notify_shutdown_event(stcb);
3649f8829a4aSRandall Stewart 		break;
3650f8829a4aSRandall Stewart 	case SCTP_NOTIFY_AUTH_NEW_KEY:
3651f8829a4aSRandall Stewart 		sctp_notify_authentication(stcb, SCTP_AUTH_NEWKEY, error,
3652830d754dSRandall Stewart 		    (uint16_t) (uintptr_t) data,
3653830d754dSRandall Stewart 		    so_locked);
3654f8829a4aSRandall Stewart 		break;
3655830d754dSRandall Stewart 	case SCTP_NOTIFY_AUTH_FREE_KEY:
3656830d754dSRandall Stewart 		sctp_notify_authentication(stcb, SCTP_AUTH_FREE_KEY, error,
3657830d754dSRandall Stewart 		    (uint16_t) (uintptr_t) data,
3658830d754dSRandall Stewart 		    so_locked);
3659f8829a4aSRandall Stewart 		break;
3660830d754dSRandall Stewart 	case SCTP_NOTIFY_NO_PEER_AUTH:
3661830d754dSRandall Stewart 		sctp_notify_authentication(stcb, SCTP_AUTH_NO_AUTH, error,
3662830d754dSRandall Stewart 		    (uint16_t) (uintptr_t) data,
3663830d754dSRandall Stewart 		    so_locked);
3664830d754dSRandall Stewart 		break;
3665830d754dSRandall Stewart 	case SCTP_NOTIFY_SENDER_DRY:
3666830d754dSRandall Stewart 		sctp_notify_sender_dry_event(stcb, so_locked);
3667830d754dSRandall Stewart 		break;
3668f8829a4aSRandall Stewart 	default:
3669ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_UTIL1, "%s: unknown notification %xh (%u)\n",
3670ad81507eSRandall Stewart 		    __FUNCTION__, notification, notification);
3671f8829a4aSRandall Stewart 		break;
3672f8829a4aSRandall Stewart 	}			/* end switch */
3673f8829a4aSRandall Stewart }
3674f8829a4aSRandall Stewart 
3675f8829a4aSRandall Stewart void
3676ceaad40aSRandall Stewart sctp_report_all_outbound(struct sctp_tcb *stcb, int holds_lock, int so_locked
3677ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3678ceaad40aSRandall Stewart     SCTP_UNUSED
3679ceaad40aSRandall Stewart #endif
3680ceaad40aSRandall Stewart )
3681f8829a4aSRandall Stewart {
3682f8829a4aSRandall Stewart 	struct sctp_association *asoc;
3683f8829a4aSRandall Stewart 	struct sctp_stream_out *outs;
3684f8829a4aSRandall Stewart 	struct sctp_tmit_chunk *chk;
3685f8829a4aSRandall Stewart 	struct sctp_stream_queue_pending *sp;
36867f34832bSRandall Stewart 	int i;
3687f8829a4aSRandall Stewart 
3688f8829a4aSRandall Stewart 	asoc = &stcb->asoc;
3689f8829a4aSRandall Stewart 
3690ad81507eSRandall Stewart 	if (stcb == NULL) {
3691ad81507eSRandall Stewart 		return;
3692ad81507eSRandall Stewart 	}
3693f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
3694f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
3695f8829a4aSRandall Stewart 	    (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET)) {
3696f8829a4aSRandall Stewart 		return;
3697f8829a4aSRandall Stewart 	}
3698f8829a4aSRandall Stewart 	/* now through all the gunk freeing chunks */
3699ad81507eSRandall Stewart 	if (holds_lock == 0) {
37007f34832bSRandall Stewart 		SCTP_TCB_SEND_LOCK(stcb);
3701ad81507eSRandall Stewart 	}
3702d00aff5dSRandall Stewart 	/* sent queue SHOULD be empty */
3703d00aff5dSRandall Stewart 	if (!TAILQ_EMPTY(&asoc->sent_queue)) {
3704d00aff5dSRandall Stewart 		chk = TAILQ_FIRST(&asoc->sent_queue);
3705d00aff5dSRandall Stewart 		while (chk) {
3706d00aff5dSRandall Stewart 			TAILQ_REMOVE(&asoc->sent_queue, chk, sctp_next);
3707d00aff5dSRandall Stewart 			asoc->sent_queue_cnt--;
37080c0982b8SRandall Stewart 			if (chk->data != NULL) {
3709d00aff5dSRandall Stewart 				sctp_free_bufspace(stcb, asoc, chk, 1);
3710d00aff5dSRandall Stewart 				sctp_ulp_notify(SCTP_NOTIFY_DG_FAIL, stcb,
3711ceaad40aSRandall Stewart 				    SCTP_NOTIFY_DATAGRAM_SENT, chk, so_locked);
3712810ec536SMichael Tuexen 				if (chk->data) {
3713d00aff5dSRandall Stewart 					sctp_m_freem(chk->data);
3714d00aff5dSRandall Stewart 					chk->data = NULL;
3715d00aff5dSRandall Stewart 				}
3716810ec536SMichael Tuexen 			}
3717d00aff5dSRandall Stewart 			sctp_free_a_chunk(stcb, chk);
3718d00aff5dSRandall Stewart 			/* sa_ignore FREED_MEMORY */
3719d00aff5dSRandall Stewart 			chk = TAILQ_FIRST(&asoc->sent_queue);
3720d00aff5dSRandall Stewart 		}
3721d00aff5dSRandall Stewart 	}
3722d00aff5dSRandall Stewart 	/* pending send queue SHOULD be empty */
3723d00aff5dSRandall Stewart 	if (!TAILQ_EMPTY(&asoc->send_queue)) {
3724d00aff5dSRandall Stewart 		chk = TAILQ_FIRST(&asoc->send_queue);
3725d00aff5dSRandall Stewart 		while (chk) {
3726d00aff5dSRandall Stewart 			TAILQ_REMOVE(&asoc->send_queue, chk, sctp_next);
3727d00aff5dSRandall Stewart 			asoc->send_queue_cnt--;
37280c0982b8SRandall Stewart 			if (chk->data != NULL) {
3729d00aff5dSRandall Stewart 				sctp_free_bufspace(stcb, asoc, chk, 1);
37300c0982b8SRandall Stewart 				sctp_ulp_notify(SCTP_NOTIFY_DG_FAIL, stcb,
37310c0982b8SRandall Stewart 				    SCTP_NOTIFY_DATAGRAM_UNSENT, chk, so_locked);
3732810ec536SMichael Tuexen 				if (chk->data) {
3733d00aff5dSRandall Stewart 					sctp_m_freem(chk->data);
3734d00aff5dSRandall Stewart 					chk->data = NULL;
3735d00aff5dSRandall Stewart 				}
3736810ec536SMichael Tuexen 			}
3737d00aff5dSRandall Stewart 			sctp_free_a_chunk(stcb, chk);
3738d00aff5dSRandall Stewart 			/* sa_ignore FREED_MEMORY */
3739d00aff5dSRandall Stewart 			chk = TAILQ_FIRST(&asoc->send_queue);
3740d00aff5dSRandall Stewart 		}
3741d00aff5dSRandall Stewart 	}
37427f34832bSRandall Stewart 	for (i = 0; i < stcb->asoc.streamoutcnt; i++) {
37437f34832bSRandall Stewart 		/* For each stream */
37447f34832bSRandall Stewart 		outs = &stcb->asoc.strmout[i];
37457f34832bSRandall Stewart 		/* clean up any sends there */
3746f8829a4aSRandall Stewart 		stcb->asoc.locked_on_sending = NULL;
3747f8829a4aSRandall Stewart 		sp = TAILQ_FIRST(&outs->outqueue);
3748f8829a4aSRandall Stewart 		while (sp) {
3749f8829a4aSRandall Stewart 			stcb->asoc.stream_queue_cnt--;
3750f8829a4aSRandall Stewart 			TAILQ_REMOVE(&outs->outqueue, sp, next);
3751f8829a4aSRandall Stewart 			sctp_free_spbufspace(stcb, asoc, sp);
3752f8829a4aSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_SPECIAL_SP_FAIL, stcb,
3753ceaad40aSRandall Stewart 			    SCTP_NOTIFY_DATAGRAM_UNSENT, (void *)sp, so_locked);
3754f8829a4aSRandall Stewart 			if (sp->data) {
3755f8829a4aSRandall Stewart 				sctp_m_freem(sp->data);
3756f8829a4aSRandall Stewart 				sp->data = NULL;
3757f8829a4aSRandall Stewart 			}
3758f8829a4aSRandall Stewart 			if (sp->net)
3759f8829a4aSRandall Stewart 				sctp_free_remote_addr(sp->net);
3760f8829a4aSRandall Stewart 			sp->net = NULL;
3761f8829a4aSRandall Stewart 			/* Free the chunk */
3762f8829a4aSRandall Stewart 			sctp_free_a_strmoq(stcb, sp);
37633c503c28SRandall Stewart 			/* sa_ignore FREED_MEMORY */
3764f8829a4aSRandall Stewart 			sp = TAILQ_FIRST(&outs->outqueue);
3765f8829a4aSRandall Stewart 		}
3766f8829a4aSRandall Stewart 	}
3767f8829a4aSRandall Stewart 
3768ad81507eSRandall Stewart 	if (holds_lock == 0) {
37697f34832bSRandall Stewart 		SCTP_TCB_SEND_UNLOCK(stcb);
3770f8829a4aSRandall Stewart 	}
3771ad81507eSRandall Stewart }
3772f8829a4aSRandall Stewart 
3773f8829a4aSRandall Stewart void
3774ceaad40aSRandall Stewart sctp_abort_notification(struct sctp_tcb *stcb, int error, int so_locked
3775ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3776ceaad40aSRandall Stewart     SCTP_UNUSED
3777ceaad40aSRandall Stewart #endif
3778ceaad40aSRandall Stewart )
3779f8829a4aSRandall Stewart {
3780f8829a4aSRandall Stewart 
3781ad81507eSRandall Stewart 	if (stcb == NULL) {
3782ad81507eSRandall Stewart 		return;
3783ad81507eSRandall Stewart 	}
3784f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
3785f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
3786f8829a4aSRandall Stewart 	    (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET)) {
3787f8829a4aSRandall Stewart 		return;
3788f8829a4aSRandall Stewart 	}
3789f8829a4aSRandall Stewart 	/* Tell them we lost the asoc */
3790ceaad40aSRandall Stewart 	sctp_report_all_outbound(stcb, 1, so_locked);
3791f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL) ||
3792f8829a4aSRandall Stewart 	    ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) &&
3793f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_CONNECTED))) {
3794f8829a4aSRandall Stewart 		stcb->sctp_ep->sctp_flags |= SCTP_PCB_FLAGS_WAS_ABORTED;
3795f8829a4aSRandall Stewart 	}
3796ceaad40aSRandall Stewart 	sctp_ulp_notify(SCTP_NOTIFY_ASSOC_ABORTED, stcb, error, NULL, so_locked);
3797f8829a4aSRandall Stewart }
3798f8829a4aSRandall Stewart 
3799f8829a4aSRandall Stewart void
3800f8829a4aSRandall Stewart sctp_abort_association(struct sctp_inpcb *inp, struct sctp_tcb *stcb,
380117205eccSRandall Stewart     struct mbuf *m, int iphlen, struct sctphdr *sh, struct mbuf *op_err,
3802c54a18d2SRandall Stewart     uint32_t vrf_id, uint16_t port)
3803f8829a4aSRandall Stewart {
3804f8829a4aSRandall Stewart 	uint32_t vtag;
3805f8829a4aSRandall Stewart 
3806ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3807ceaad40aSRandall Stewart 	struct socket *so;
3808ceaad40aSRandall Stewart 
3809ceaad40aSRandall Stewart #endif
3810ceaad40aSRandall Stewart 
3811f8829a4aSRandall Stewart 	vtag = 0;
3812f8829a4aSRandall Stewart 	if (stcb != NULL) {
3813f8829a4aSRandall Stewart 		/* We have a TCB to abort, send notification too */
3814f8829a4aSRandall Stewart 		vtag = stcb->asoc.peer_vtag;
3815ceaad40aSRandall Stewart 		sctp_abort_notification(stcb, 0, SCTP_SO_NOT_LOCKED);
381617205eccSRandall Stewart 		/* get the assoc vrf id and table id */
381717205eccSRandall Stewart 		vrf_id = stcb->asoc.vrf_id;
381863981c2bSRandall Stewart 		stcb->asoc.state |= SCTP_STATE_WAS_ABORTED;
3819f8829a4aSRandall Stewart 	}
3820c54a18d2SRandall Stewart 	sctp_send_abort(m, iphlen, sh, vtag, op_err, vrf_id, port);
3821f8829a4aSRandall Stewart 	if (stcb != NULL) {
3822f8829a4aSRandall Stewart 		/* Ok, now lets free it */
3823ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3824ceaad40aSRandall Stewart 		so = SCTP_INP_SO(inp);
3825ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
3826ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
3827ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
3828ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
3829ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
3830ceaad40aSRandall Stewart #endif
3831c4739e2fSRandall Stewart 		(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC, SCTP_FROM_SCTPUTIL + SCTP_LOC_4);
3832ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3833ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
3834ceaad40aSRandall Stewart #endif
3835f8829a4aSRandall Stewart 	} else {
3836f8829a4aSRandall Stewart 		if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
3837f8829a4aSRandall Stewart 			if (LIST_FIRST(&inp->sctp_asoc_list) == NULL) {
3838b0552ae2SRandall Stewart 				sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
3839b0552ae2SRandall Stewart 				    SCTP_CALLED_DIRECTLY_NOCMPSET);
3840f8829a4aSRandall Stewart 			}
3841f8829a4aSRandall Stewart 		}
3842f8829a4aSRandall Stewart 	}
3843f8829a4aSRandall Stewart }
3844f8829a4aSRandall Stewart 
3845f1f73e57SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
3846f1f73e57SRandall Stewart void
3847f1f73e57SRandall Stewart sctp_print_out_track_log(struct sctp_tcb *stcb)
3848f1f73e57SRandall Stewart {
384918e198d3SRandall Stewart #ifdef NOSIY_PRINTS
3850f1f73e57SRandall Stewart 	int i;
3851f1f73e57SRandall Stewart 
3852ad81507eSRandall Stewart 	SCTP_PRINTF("Last ep reason:%x\n", stcb->sctp_ep->last_abort_code);
3853ad81507eSRandall Stewart 	SCTP_PRINTF("IN bound TSN log-aaa\n");
3854f1f73e57SRandall Stewart 	if ((stcb->asoc.tsn_in_at == 0) && (stcb->asoc.tsn_in_wrapped == 0)) {
3855ad81507eSRandall Stewart 		SCTP_PRINTF("None rcvd\n");
3856f1f73e57SRandall Stewart 		goto none_in;
3857f1f73e57SRandall Stewart 	}
3858f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_in_wrapped) {
3859f1f73e57SRandall Stewart 		for (i = stcb->asoc.tsn_in_at; i < SCTP_TSN_LOG_SIZE; i++) {
3860ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
3861f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].tsn,
3862f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].strm,
3863f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].seq,
3864f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].flgs,
3865f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].sz);
3866f1f73e57SRandall Stewart 		}
3867f1f73e57SRandall Stewart 	}
3868f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_in_at) {
3869f1f73e57SRandall Stewart 		for (i = 0; i < stcb->asoc.tsn_in_at; i++) {
3870ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
3871f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].tsn,
3872f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].strm,
3873f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].seq,
3874f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].flgs,
3875f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].sz);
3876f1f73e57SRandall Stewart 		}
3877f1f73e57SRandall Stewart 	}
3878f1f73e57SRandall Stewart none_in:
3879ad81507eSRandall Stewart 	SCTP_PRINTF("OUT bound TSN log-aaa\n");
3880ad81507eSRandall Stewart 	if ((stcb->asoc.tsn_out_at == 0) &&
3881ad81507eSRandall Stewart 	    (stcb->asoc.tsn_out_wrapped == 0)) {
3882ad81507eSRandall Stewart 		SCTP_PRINTF("None sent\n");
3883f1f73e57SRandall Stewart 	}
3884f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_out_wrapped) {
3885f1f73e57SRandall Stewart 		for (i = stcb->asoc.tsn_out_at; i < SCTP_TSN_LOG_SIZE; i++) {
3886ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
3887f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].tsn,
3888f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].strm,
3889f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].seq,
3890f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].flgs,
3891f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].sz);
3892f1f73e57SRandall Stewart 		}
3893f1f73e57SRandall Stewart 	}
3894f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_out_at) {
3895f1f73e57SRandall Stewart 		for (i = 0; i < stcb->asoc.tsn_out_at; i++) {
3896ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
3897f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].tsn,
3898f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].strm,
3899f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].seq,
3900f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].flgs,
3901f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].sz);
3902f1f73e57SRandall Stewart 		}
3903f1f73e57SRandall Stewart 	}
390418e198d3SRandall Stewart #endif
3905f1f73e57SRandall Stewart }
3906f1f73e57SRandall Stewart 
3907f1f73e57SRandall Stewart #endif
3908f1f73e57SRandall Stewart 
3909f8829a4aSRandall Stewart void
3910f8829a4aSRandall Stewart sctp_abort_an_association(struct sctp_inpcb *inp, struct sctp_tcb *stcb,
3911ceaad40aSRandall Stewart     int error, struct mbuf *op_err,
3912ceaad40aSRandall Stewart     int so_locked
3913ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3914ceaad40aSRandall Stewart     SCTP_UNUSED
3915ceaad40aSRandall Stewart #endif
3916ceaad40aSRandall Stewart )
3917f8829a4aSRandall Stewart {
3918f8829a4aSRandall Stewart 	uint32_t vtag;
3919f8829a4aSRandall Stewart 
3920ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3921ceaad40aSRandall Stewart 	struct socket *so;
3922ceaad40aSRandall Stewart 
3923ceaad40aSRandall Stewart #endif
3924ceaad40aSRandall Stewart 
3925ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3926ceaad40aSRandall Stewart 	so = SCTP_INP_SO(inp);
3927ceaad40aSRandall Stewart #endif
3928f8829a4aSRandall Stewart 	if (stcb == NULL) {
3929f8829a4aSRandall Stewart 		/* Got to have a TCB */
3930f8829a4aSRandall Stewart 		if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
3931f8829a4aSRandall Stewart 			if (LIST_FIRST(&inp->sctp_asoc_list) == NULL) {
3932b0552ae2SRandall Stewart 				sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
3933b0552ae2SRandall Stewart 				    SCTP_CALLED_DIRECTLY_NOCMPSET);
3934f8829a4aSRandall Stewart 			}
3935f8829a4aSRandall Stewart 		}
3936f8829a4aSRandall Stewart 		return;
393763981c2bSRandall Stewart 	} else {
393863981c2bSRandall Stewart 		stcb->asoc.state |= SCTP_STATE_WAS_ABORTED;
3939f8829a4aSRandall Stewart 	}
3940f8829a4aSRandall Stewart 	vtag = stcb->asoc.peer_vtag;
3941f8829a4aSRandall Stewart 	/* notify the ulp */
3942f8829a4aSRandall Stewart 	if ((inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) == 0)
3943ceaad40aSRandall Stewart 		sctp_abort_notification(stcb, error, so_locked);
3944f8829a4aSRandall Stewart 	/* notify the peer */
3945b201f536SRandall Stewart #if defined(SCTP_PANIC_ON_ABORT)
3946b201f536SRandall Stewart 	panic("aborting an association");
3947b201f536SRandall Stewart #endif
3948ceaad40aSRandall Stewart 	sctp_send_abort_tcb(stcb, op_err, so_locked);
3949f8829a4aSRandall Stewart 	SCTP_STAT_INCR_COUNTER32(sctps_aborted);
3950f8829a4aSRandall Stewart 	if ((SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_OPEN) ||
3951f8829a4aSRandall Stewart 	    (SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_SHUTDOWN_RECEIVED)) {
3952f8829a4aSRandall Stewart 		SCTP_STAT_DECR_GAUGE32(sctps_currestab);
3953f8829a4aSRandall Stewart 	}
3954f8829a4aSRandall Stewart 	/* now free the asoc */
3955f1f73e57SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
3956f1f73e57SRandall Stewart 	sctp_print_out_track_log(stcb);
3957f1f73e57SRandall Stewart #endif
3958ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3959ceaad40aSRandall Stewart 	if (!so_locked) {
3960ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
3961ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
3962ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
3963ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
3964ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
3965ceaad40aSRandall Stewart 	}
3966ceaad40aSRandall Stewart #endif
3967c4739e2fSRandall Stewart 	(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC, SCTP_FROM_SCTPUTIL + SCTP_LOC_5);
3968ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3969ceaad40aSRandall Stewart 	if (!so_locked) {
3970ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
3971ceaad40aSRandall Stewart 	}
3972ceaad40aSRandall Stewart #endif
3973f8829a4aSRandall Stewart }
3974f8829a4aSRandall Stewart 
3975f8829a4aSRandall Stewart void
3976f8829a4aSRandall Stewart sctp_handle_ootb(struct mbuf *m, int iphlen, int offset, struct sctphdr *sh,
3977c54a18d2SRandall Stewart     struct sctp_inpcb *inp, struct mbuf *op_err, uint32_t vrf_id, uint16_t port)
3978f8829a4aSRandall Stewart {
3979f8829a4aSRandall Stewart 	struct sctp_chunkhdr *ch, chunk_buf;
3980f8829a4aSRandall Stewart 	unsigned int chk_length;
3981f8829a4aSRandall Stewart 
3982f8829a4aSRandall Stewart 	SCTP_STAT_INCR_COUNTER32(sctps_outoftheblue);
3983f8829a4aSRandall Stewart 	/* Generate a TO address for future reference */
3984f8829a4aSRandall Stewart 	if (inp && (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE)) {
3985f8829a4aSRandall Stewart 		if (LIST_FIRST(&inp->sctp_asoc_list) == NULL) {
3986b0552ae2SRandall Stewart 			sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
3987b0552ae2SRandall Stewart 			    SCTP_CALLED_DIRECTLY_NOCMPSET);
3988f8829a4aSRandall Stewart 		}
3989f8829a4aSRandall Stewart 	}
3990f8829a4aSRandall Stewart 	ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
3991f8829a4aSRandall Stewart 	    sizeof(*ch), (uint8_t *) & chunk_buf);
3992f8829a4aSRandall Stewart 	while (ch != NULL) {
3993f8829a4aSRandall Stewart 		chk_length = ntohs(ch->chunk_length);
3994f8829a4aSRandall Stewart 		if (chk_length < sizeof(*ch)) {
3995f8829a4aSRandall Stewart 			/* break to abort land */
3996f8829a4aSRandall Stewart 			break;
3997f8829a4aSRandall Stewart 		}
3998f8829a4aSRandall Stewart 		switch (ch->chunk_type) {
3999d55b0b1bSRandall Stewart 		case SCTP_COOKIE_ECHO:
4000d55b0b1bSRandall Stewart 			/* We hit here only if the assoc is being freed */
4001d55b0b1bSRandall Stewart 			return;
4002f8829a4aSRandall Stewart 		case SCTP_PACKET_DROPPED:
4003f8829a4aSRandall Stewart 			/* we don't respond to pkt-dropped */
4004f8829a4aSRandall Stewart 			return;
4005f8829a4aSRandall Stewart 		case SCTP_ABORT_ASSOCIATION:
4006f8829a4aSRandall Stewart 			/* we don't respond with an ABORT to an ABORT */
4007f8829a4aSRandall Stewart 			return;
4008f8829a4aSRandall Stewart 		case SCTP_SHUTDOWN_COMPLETE:
4009f8829a4aSRandall Stewart 			/*
4010f8829a4aSRandall Stewart 			 * we ignore it since we are not waiting for it and
4011f8829a4aSRandall Stewart 			 * peer is gone
4012f8829a4aSRandall Stewart 			 */
4013f8829a4aSRandall Stewart 			return;
4014f8829a4aSRandall Stewart 		case SCTP_SHUTDOWN_ACK:
4015c54a18d2SRandall Stewart 			sctp_send_shutdown_complete2(m, iphlen, sh, vrf_id, port);
4016f8829a4aSRandall Stewart 			return;
4017f8829a4aSRandall Stewart 		default:
4018f8829a4aSRandall Stewart 			break;
4019f8829a4aSRandall Stewart 		}
4020f8829a4aSRandall Stewart 		offset += SCTP_SIZE32(chk_length);
4021f8829a4aSRandall Stewart 		ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
4022f8829a4aSRandall Stewart 		    sizeof(*ch), (uint8_t *) & chunk_buf);
4023f8829a4aSRandall Stewart 	}
4024c54a18d2SRandall Stewart 	sctp_send_abort(m, iphlen, sh, 0, op_err, vrf_id, port);
4025f8829a4aSRandall Stewart }
4026f8829a4aSRandall Stewart 
4027f8829a4aSRandall Stewart /*
4028f8829a4aSRandall Stewart  * check the inbound datagram to make sure there is not an abort inside it,
4029f8829a4aSRandall Stewart  * if there is return 1, else return 0.
4030f8829a4aSRandall Stewart  */
4031f8829a4aSRandall Stewart int
4032f8829a4aSRandall Stewart sctp_is_there_an_abort_here(struct mbuf *m, int iphlen, uint32_t * vtagfill)
4033f8829a4aSRandall Stewart {
4034f8829a4aSRandall Stewart 	struct sctp_chunkhdr *ch;
4035f8829a4aSRandall Stewart 	struct sctp_init_chunk *init_chk, chunk_buf;
4036f8829a4aSRandall Stewart 	int offset;
4037f8829a4aSRandall Stewart 	unsigned int chk_length;
4038f8829a4aSRandall Stewart 
4039f8829a4aSRandall Stewart 	offset = iphlen + sizeof(struct sctphdr);
4040f8829a4aSRandall Stewart 	ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset, sizeof(*ch),
4041f8829a4aSRandall Stewart 	    (uint8_t *) & chunk_buf);
4042f8829a4aSRandall Stewart 	while (ch != NULL) {
4043f8829a4aSRandall Stewart 		chk_length = ntohs(ch->chunk_length);
4044f8829a4aSRandall Stewart 		if (chk_length < sizeof(*ch)) {
4045f8829a4aSRandall Stewart 			/* packet is probably corrupt */
4046f8829a4aSRandall Stewart 			break;
4047f8829a4aSRandall Stewart 		}
4048f8829a4aSRandall Stewart 		/* we seem to be ok, is it an abort? */
4049f8829a4aSRandall Stewart 		if (ch->chunk_type == SCTP_ABORT_ASSOCIATION) {
4050f8829a4aSRandall Stewart 			/* yep, tell them */
4051f8829a4aSRandall Stewart 			return (1);
4052f8829a4aSRandall Stewart 		}
4053f8829a4aSRandall Stewart 		if (ch->chunk_type == SCTP_INITIATION) {
4054f8829a4aSRandall Stewart 			/* need to update the Vtag */
4055f8829a4aSRandall Stewart 			init_chk = (struct sctp_init_chunk *)sctp_m_getptr(m,
4056f8829a4aSRandall Stewart 			    offset, sizeof(*init_chk), (uint8_t *) & chunk_buf);
4057f8829a4aSRandall Stewart 			if (init_chk != NULL) {
4058f8829a4aSRandall Stewart 				*vtagfill = ntohl(init_chk->init.initiate_tag);
4059f8829a4aSRandall Stewart 			}
4060f8829a4aSRandall Stewart 		}
4061f8829a4aSRandall Stewart 		/* Nope, move to the next chunk */
4062f8829a4aSRandall Stewart 		offset += SCTP_SIZE32(chk_length);
4063f8829a4aSRandall Stewart 		ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
4064f8829a4aSRandall Stewart 		    sizeof(*ch), (uint8_t *) & chunk_buf);
4065f8829a4aSRandall Stewart 	}
4066f8829a4aSRandall Stewart 	return (0);
4067f8829a4aSRandall Stewart }
4068f8829a4aSRandall Stewart 
4069f8829a4aSRandall Stewart /*
4070f8829a4aSRandall Stewart  * currently (2/02), ifa_addr embeds scope_id's and don't have sin6_scope_id
4071f8829a4aSRandall Stewart  * set (i.e. it's 0) so, create this function to compare link local scopes
4072f8829a4aSRandall Stewart  */
40735e2c2d87SRandall Stewart #ifdef INET6
4074f8829a4aSRandall Stewart uint32_t
4075f8829a4aSRandall Stewart sctp_is_same_scope(struct sockaddr_in6 *addr1, struct sockaddr_in6 *addr2)
4076f8829a4aSRandall Stewart {
4077f8829a4aSRandall Stewart 	struct sockaddr_in6 a, b;
4078f8829a4aSRandall Stewart 
4079f8829a4aSRandall Stewart 	/* save copies */
4080f8829a4aSRandall Stewart 	a = *addr1;
4081f8829a4aSRandall Stewart 	b = *addr2;
4082f8829a4aSRandall Stewart 
4083f8829a4aSRandall Stewart 	if (a.sin6_scope_id == 0)
4084f8829a4aSRandall Stewart 		if (sa6_recoverscope(&a)) {
4085f8829a4aSRandall Stewart 			/* can't get scope, so can't match */
4086f8829a4aSRandall Stewart 			return (0);
4087f8829a4aSRandall Stewart 		}
4088f8829a4aSRandall Stewart 	if (b.sin6_scope_id == 0)
4089f8829a4aSRandall Stewart 		if (sa6_recoverscope(&b)) {
4090f8829a4aSRandall Stewart 			/* can't get scope, so can't match */
4091f8829a4aSRandall Stewart 			return (0);
4092f8829a4aSRandall Stewart 		}
4093f8829a4aSRandall Stewart 	if (a.sin6_scope_id != b.sin6_scope_id)
4094f8829a4aSRandall Stewart 		return (0);
4095f8829a4aSRandall Stewart 
4096f8829a4aSRandall Stewart 	return (1);
4097f8829a4aSRandall Stewart }
4098f8829a4aSRandall Stewart 
4099f8829a4aSRandall Stewart /*
4100f8829a4aSRandall Stewart  * returns a sockaddr_in6 with embedded scope recovered and removed
4101f8829a4aSRandall Stewart  */
4102f8829a4aSRandall Stewart struct sockaddr_in6 *
4103f8829a4aSRandall Stewart sctp_recover_scope(struct sockaddr_in6 *addr, struct sockaddr_in6 *store)
4104f8829a4aSRandall Stewart {
4105f8829a4aSRandall Stewart 	/* check and strip embedded scope junk */
4106f8829a4aSRandall Stewart 	if (addr->sin6_family == AF_INET6) {
4107f8829a4aSRandall Stewart 		if (IN6_IS_SCOPE_LINKLOCAL(&addr->sin6_addr)) {
4108f8829a4aSRandall Stewart 			if (addr->sin6_scope_id == 0) {
4109f8829a4aSRandall Stewart 				*store = *addr;
4110f8829a4aSRandall Stewart 				if (!sa6_recoverscope(store)) {
4111f8829a4aSRandall Stewart 					/* use the recovered scope */
4112f8829a4aSRandall Stewart 					addr = store;
4113f8829a4aSRandall Stewart 				}
4114f42a358aSRandall Stewart 			} else {
4115f8829a4aSRandall Stewart 				/* else, return the original "to" addr */
4116f42a358aSRandall Stewart 				in6_clearscope(&addr->sin6_addr);
4117f8829a4aSRandall Stewart 			}
4118f8829a4aSRandall Stewart 		}
4119f8829a4aSRandall Stewart 	}
4120f8829a4aSRandall Stewart 	return (addr);
4121f8829a4aSRandall Stewart }
4122f8829a4aSRandall Stewart 
41235e2c2d87SRandall Stewart #endif
41245e2c2d87SRandall Stewart 
4125f8829a4aSRandall Stewart /*
4126f8829a4aSRandall Stewart  * are the two addresses the same?  currently a "scopeless" check returns: 1
4127f8829a4aSRandall Stewart  * if same, 0 if not
4128f8829a4aSRandall Stewart  */
412972fb6fdbSRandall Stewart int
4130f8829a4aSRandall Stewart sctp_cmpaddr(struct sockaddr *sa1, struct sockaddr *sa2)
4131f8829a4aSRandall Stewart {
4132f8829a4aSRandall Stewart 
4133f8829a4aSRandall Stewart 	/* must be valid */
4134f8829a4aSRandall Stewart 	if (sa1 == NULL || sa2 == NULL)
4135f8829a4aSRandall Stewart 		return (0);
4136f8829a4aSRandall Stewart 
4137f8829a4aSRandall Stewart 	/* must be the same family */
4138f8829a4aSRandall Stewart 	if (sa1->sa_family != sa2->sa_family)
4139f8829a4aSRandall Stewart 		return (0);
4140f8829a4aSRandall Stewart 
41415e2c2d87SRandall Stewart 	switch (sa1->sa_family) {
41425e2c2d87SRandall Stewart #ifdef INET6
41435e2c2d87SRandall Stewart 	case AF_INET6:
41445e2c2d87SRandall Stewart 		{
4145f8829a4aSRandall Stewart 			/* IPv6 addresses */
4146f8829a4aSRandall Stewart 			struct sockaddr_in6 *sin6_1, *sin6_2;
4147f8829a4aSRandall Stewart 
4148f8829a4aSRandall Stewart 			sin6_1 = (struct sockaddr_in6 *)sa1;
4149f8829a4aSRandall Stewart 			sin6_2 = (struct sockaddr_in6 *)sa2;
4150c54a18d2SRandall Stewart 			return (SCTP6_ARE_ADDR_EQUAL(sin6_1,
4151c54a18d2SRandall Stewart 			    sin6_2));
41525e2c2d87SRandall Stewart 		}
41535e2c2d87SRandall Stewart #endif
41545e2c2d87SRandall Stewart 	case AF_INET:
41555e2c2d87SRandall Stewart 		{
4156f8829a4aSRandall Stewart 			/* IPv4 addresses */
4157f8829a4aSRandall Stewart 			struct sockaddr_in *sin_1, *sin_2;
4158f8829a4aSRandall Stewart 
4159f8829a4aSRandall Stewart 			sin_1 = (struct sockaddr_in *)sa1;
4160f8829a4aSRandall Stewart 			sin_2 = (struct sockaddr_in *)sa2;
4161f8829a4aSRandall Stewart 			return (sin_1->sin_addr.s_addr == sin_2->sin_addr.s_addr);
41625e2c2d87SRandall Stewart 		}
41635e2c2d87SRandall Stewart 	default:
4164f8829a4aSRandall Stewart 		/* we don't do these... */
4165f8829a4aSRandall Stewart 		return (0);
4166f8829a4aSRandall Stewart 	}
4167f8829a4aSRandall Stewart }
4168f8829a4aSRandall Stewart 
4169f8829a4aSRandall Stewart void
4170f8829a4aSRandall Stewart sctp_print_address(struct sockaddr *sa)
4171f8829a4aSRandall Stewart {
41725e2c2d87SRandall Stewart #ifdef INET6
41737d32aa0cSBjoern A. Zeeb 	char ip6buf[INET6_ADDRSTRLEN];
4174f8829a4aSRandall Stewart 
4175ad81507eSRandall Stewart 	ip6buf[0] = 0;
41765e2c2d87SRandall Stewart #endif
41775e2c2d87SRandall Stewart 
41785e2c2d87SRandall Stewart 	switch (sa->sa_family) {
41795e2c2d87SRandall Stewart #ifdef INET6
41805e2c2d87SRandall Stewart 	case AF_INET6:
41815e2c2d87SRandall Stewart 		{
4182ad81507eSRandall Stewart 			struct sockaddr_in6 *sin6;
4183ad81507eSRandall Stewart 
4184f8829a4aSRandall Stewart 			sin6 = (struct sockaddr_in6 *)sa;
4185ad81507eSRandall Stewart 			SCTP_PRINTF("IPv6 address: %s:port:%d scope:%u\n",
41867d32aa0cSBjoern A. Zeeb 			    ip6_sprintf(ip6buf, &sin6->sin6_addr),
41877d32aa0cSBjoern A. Zeeb 			    ntohs(sin6->sin6_port),
4188f8829a4aSRandall Stewart 			    sin6->sin6_scope_id);
41895e2c2d87SRandall Stewart 			break;
41905e2c2d87SRandall Stewart 		}
41915e2c2d87SRandall Stewart #endif
41925e2c2d87SRandall Stewart 	case AF_INET:
41935e2c2d87SRandall Stewart 		{
4194f8829a4aSRandall Stewart 			struct sockaddr_in *sin;
4195f8829a4aSRandall Stewart 			unsigned char *p;
4196f8829a4aSRandall Stewart 
4197f8829a4aSRandall Stewart 			sin = (struct sockaddr_in *)sa;
4198f8829a4aSRandall Stewart 			p = (unsigned char *)&sin->sin_addr;
4199ad81507eSRandall Stewart 			SCTP_PRINTF("IPv4 address: %u.%u.%u.%u:%d\n",
4200f8829a4aSRandall Stewart 			    p[0], p[1], p[2], p[3], ntohs(sin->sin_port));
42015e2c2d87SRandall Stewart 			break;
42025e2c2d87SRandall Stewart 		}
42035e2c2d87SRandall Stewart 	default:
4204ad81507eSRandall Stewart 		SCTP_PRINTF("?\n");
42055e2c2d87SRandall Stewart 		break;
4206f8829a4aSRandall Stewart 	}
4207f8829a4aSRandall Stewart }
4208f8829a4aSRandall Stewart 
4209f8829a4aSRandall Stewart void
4210f8829a4aSRandall Stewart sctp_print_address_pkt(struct ip *iph, struct sctphdr *sh)
4211f8829a4aSRandall Stewart {
42125e2c2d87SRandall Stewart 	switch (iph->ip_v) {
42135e2c2d87SRandall Stewart 		case IPVERSION:
42145e2c2d87SRandall Stewart 		{
4215f8829a4aSRandall Stewart 			struct sockaddr_in lsa, fsa;
4216f8829a4aSRandall Stewart 
4217f8829a4aSRandall Stewart 			bzero(&lsa, sizeof(lsa));
4218f8829a4aSRandall Stewart 			lsa.sin_len = sizeof(lsa);
4219f8829a4aSRandall Stewart 			lsa.sin_family = AF_INET;
4220f8829a4aSRandall Stewart 			lsa.sin_addr = iph->ip_src;
4221f8829a4aSRandall Stewart 			lsa.sin_port = sh->src_port;
4222f8829a4aSRandall Stewart 			bzero(&fsa, sizeof(fsa));
4223f8829a4aSRandall Stewart 			fsa.sin_len = sizeof(fsa);
4224f8829a4aSRandall Stewart 			fsa.sin_family = AF_INET;
4225f8829a4aSRandall Stewart 			fsa.sin_addr = iph->ip_dst;
4226f8829a4aSRandall Stewart 			fsa.sin_port = sh->dest_port;
4227ad81507eSRandall Stewart 			SCTP_PRINTF("src: ");
4228f8829a4aSRandall Stewart 			sctp_print_address((struct sockaddr *)&lsa);
4229ad81507eSRandall Stewart 			SCTP_PRINTF("dest: ");
4230f8829a4aSRandall Stewart 			sctp_print_address((struct sockaddr *)&fsa);
42315e2c2d87SRandall Stewart 			break;
42325e2c2d87SRandall Stewart 		}
42335e2c2d87SRandall Stewart #ifdef INET6
42345e2c2d87SRandall Stewart 	case IPV6_VERSION >> 4:
42355e2c2d87SRandall Stewart 		{
4236f8829a4aSRandall Stewart 			struct ip6_hdr *ip6;
4237f8829a4aSRandall Stewart 			struct sockaddr_in6 lsa6, fsa6;
4238f8829a4aSRandall Stewart 
4239f8829a4aSRandall Stewart 			ip6 = (struct ip6_hdr *)iph;
4240f8829a4aSRandall Stewart 			bzero(&lsa6, sizeof(lsa6));
4241f8829a4aSRandall Stewart 			lsa6.sin6_len = sizeof(lsa6);
4242f8829a4aSRandall Stewart 			lsa6.sin6_family = AF_INET6;
4243f8829a4aSRandall Stewart 			lsa6.sin6_addr = ip6->ip6_src;
4244f8829a4aSRandall Stewart 			lsa6.sin6_port = sh->src_port;
4245f8829a4aSRandall Stewart 			bzero(&fsa6, sizeof(fsa6));
4246f8829a4aSRandall Stewart 			fsa6.sin6_len = sizeof(fsa6);
4247f8829a4aSRandall Stewart 			fsa6.sin6_family = AF_INET6;
4248f8829a4aSRandall Stewart 			fsa6.sin6_addr = ip6->ip6_dst;
4249f8829a4aSRandall Stewart 			fsa6.sin6_port = sh->dest_port;
4250ad81507eSRandall Stewart 			SCTP_PRINTF("src: ");
4251f8829a4aSRandall Stewart 			sctp_print_address((struct sockaddr *)&lsa6);
4252ad81507eSRandall Stewart 			SCTP_PRINTF("dest: ");
4253f8829a4aSRandall Stewart 			sctp_print_address((struct sockaddr *)&fsa6);
42545e2c2d87SRandall Stewart 			break;
42555e2c2d87SRandall Stewart 		}
42565e2c2d87SRandall Stewart #endif
42575e2c2d87SRandall Stewart 	default:
42585e2c2d87SRandall Stewart 		/* TSNH */
42595e2c2d87SRandall Stewart 		break;
4260f8829a4aSRandall Stewart 	}
4261f8829a4aSRandall Stewart }
4262f8829a4aSRandall Stewart 
4263f8829a4aSRandall Stewart void
4264f8829a4aSRandall Stewart sctp_pull_off_control_to_new_inp(struct sctp_inpcb *old_inp,
4265f8829a4aSRandall Stewart     struct sctp_inpcb *new_inp,
4266d06c82f1SRandall Stewart     struct sctp_tcb *stcb,
4267d06c82f1SRandall Stewart     int waitflags)
4268f8829a4aSRandall Stewart {
4269f8829a4aSRandall Stewart 	/*
4270f8829a4aSRandall Stewart 	 * go through our old INP and pull off any control structures that
4271f8829a4aSRandall Stewart 	 * belong to stcb and move then to the new inp.
4272f8829a4aSRandall Stewart 	 */
4273f8829a4aSRandall Stewart 	struct socket *old_so, *new_so;
4274f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control, *nctl;
4275f8829a4aSRandall Stewart 	struct sctp_readhead tmp_queue;
4276f8829a4aSRandall Stewart 	struct mbuf *m;
4277bff64a4dSRandall Stewart 	int error = 0;
4278f8829a4aSRandall Stewart 
4279f8829a4aSRandall Stewart 	old_so = old_inp->sctp_socket;
4280f8829a4aSRandall Stewart 	new_so = new_inp->sctp_socket;
4281f8829a4aSRandall Stewart 	TAILQ_INIT(&tmp_queue);
4282d06c82f1SRandall Stewart 	error = sblock(&old_so->so_rcv, waitflags);
4283f8829a4aSRandall Stewart 	if (error) {
4284f8829a4aSRandall Stewart 		/*
4285f8829a4aSRandall Stewart 		 * Gak, can't get sblock, we have a problem. data will be
4286f8829a4aSRandall Stewart 		 * left stranded.. and we don't dare look at it since the
4287f8829a4aSRandall Stewart 		 * other thread may be reading something. Oh well, its a
4288f8829a4aSRandall Stewart 		 * screwed up app that does a peeloff OR a accept while
4289f8829a4aSRandall Stewart 		 * reading from the main socket... actually its only the
4290f8829a4aSRandall Stewart 		 * peeloff() case, since I think read will fail on a
4291f8829a4aSRandall Stewart 		 * listening socket..
4292f8829a4aSRandall Stewart 		 */
4293f8829a4aSRandall Stewart 		return;
4294f8829a4aSRandall Stewart 	}
4295f8829a4aSRandall Stewart 	/* lock the socket buffers */
4296f8829a4aSRandall Stewart 	SCTP_INP_READ_LOCK(old_inp);
4297f8829a4aSRandall Stewart 	control = TAILQ_FIRST(&old_inp->read_queue);
4298f8829a4aSRandall Stewart 	/* Pull off all for out target stcb */
4299f8829a4aSRandall Stewart 	while (control) {
4300f8829a4aSRandall Stewart 		nctl = TAILQ_NEXT(control, next);
4301f8829a4aSRandall Stewart 		if (control->stcb == stcb) {
4302f8829a4aSRandall Stewart 			/* remove it we want it */
4303f8829a4aSRandall Stewart 			TAILQ_REMOVE(&old_inp->read_queue, control, next);
4304f8829a4aSRandall Stewart 			TAILQ_INSERT_TAIL(&tmp_queue, control, next);
4305f8829a4aSRandall Stewart 			m = control->data;
4306f8829a4aSRandall Stewart 			while (m) {
4307b3f1ea41SRandall Stewart 				if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4308139bc87fSRandall Stewart 					sctp_sblog(&old_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
430980fefe0aSRandall Stewart 				}
4310f8829a4aSRandall Stewart 				sctp_sbfree(control, stcb, &old_so->so_rcv, m);
4311b3f1ea41SRandall Stewart 				if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4312f8829a4aSRandall Stewart 					sctp_sblog(&old_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
431380fefe0aSRandall Stewart 				}
4314139bc87fSRandall Stewart 				m = SCTP_BUF_NEXT(m);
4315f8829a4aSRandall Stewart 			}
4316f8829a4aSRandall Stewart 		}
4317f8829a4aSRandall Stewart 		control = nctl;
4318f8829a4aSRandall Stewart 	}
4319f8829a4aSRandall Stewart 	SCTP_INP_READ_UNLOCK(old_inp);
4320f8829a4aSRandall Stewart 	/* Remove the sb-lock on the old socket */
4321f8829a4aSRandall Stewart 
4322f8829a4aSRandall Stewart 	sbunlock(&old_so->so_rcv);
4323f8829a4aSRandall Stewart 	/* Now we move them over to the new socket buffer */
4324f8829a4aSRandall Stewart 	control = TAILQ_FIRST(&tmp_queue);
4325f8829a4aSRandall Stewart 	SCTP_INP_READ_LOCK(new_inp);
4326f8829a4aSRandall Stewart 	while (control) {
4327f8829a4aSRandall Stewart 		nctl = TAILQ_NEXT(control, next);
4328f8829a4aSRandall Stewart 		TAILQ_INSERT_TAIL(&new_inp->read_queue, control, next);
4329f8829a4aSRandall Stewart 		m = control->data;
4330f8829a4aSRandall Stewart 		while (m) {
4331b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4332139bc87fSRandall Stewart 				sctp_sblog(&new_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m));
433380fefe0aSRandall Stewart 			}
4334f8829a4aSRandall Stewart 			sctp_sballoc(stcb, &new_so->so_rcv, m);
4335b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4336f8829a4aSRandall Stewart 				sctp_sblog(&new_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
433780fefe0aSRandall Stewart 			}
4338139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
4339f8829a4aSRandall Stewart 		}
4340f8829a4aSRandall Stewart 		control = nctl;
4341f8829a4aSRandall Stewart 	}
4342f8829a4aSRandall Stewart 	SCTP_INP_READ_UNLOCK(new_inp);
4343f8829a4aSRandall Stewart }
4344f8829a4aSRandall Stewart 
4345f8829a4aSRandall Stewart void
4346f8829a4aSRandall Stewart sctp_add_to_readq(struct sctp_inpcb *inp,
4347f8829a4aSRandall Stewart     struct sctp_tcb *stcb,
4348f8829a4aSRandall Stewart     struct sctp_queued_to_read *control,
4349f8829a4aSRandall Stewart     struct sockbuf *sb,
4350ceaad40aSRandall Stewart     int end,
4351cfde3ff7SRandall Stewart     int inp_read_lock_held,
4352ceaad40aSRandall Stewart     int so_locked
4353ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
4354ceaad40aSRandall Stewart     SCTP_UNUSED
4355ceaad40aSRandall Stewart #endif
4356ceaad40aSRandall Stewart )
4357f8829a4aSRandall Stewart {
4358f8829a4aSRandall Stewart 	/*
4359f8829a4aSRandall Stewart 	 * Here we must place the control on the end of the socket read
4360f8829a4aSRandall Stewart 	 * queue AND increment sb_cc so that select will work properly on
4361f8829a4aSRandall Stewart 	 * read.
4362f8829a4aSRandall Stewart 	 */
4363f8829a4aSRandall Stewart 	struct mbuf *m, *prev = NULL;
4364f8829a4aSRandall Stewart 
436503b0b021SRandall Stewart 	if (inp == NULL) {
436603b0b021SRandall Stewart 		/* Gak, TSNH!! */
4367a5d547adSRandall Stewart #ifdef INVARIANTS
436803b0b021SRandall Stewart 		panic("Gak, inp NULL on add_to_readq");
436903b0b021SRandall Stewart #endif
437003b0b021SRandall Stewart 		return;
437103b0b021SRandall Stewart 	}
4372cfde3ff7SRandall Stewart 	if (inp_read_lock_held == 0)
4373f8829a4aSRandall Stewart 		SCTP_INP_READ_LOCK(inp);
437442551e99SRandall Stewart 	if (!(control->spec_flags & M_NOTIFICATION)) {
4375a5d547adSRandall Stewart 		atomic_add_int(&inp->total_recvs, 1);
437642551e99SRandall Stewart 		if (!control->do_not_ref_stcb) {
4377a5d547adSRandall Stewart 			atomic_add_int(&stcb->total_recvs, 1);
437842551e99SRandall Stewart 		}
437942551e99SRandall Stewart 	}
4380f8829a4aSRandall Stewart 	m = control->data;
4381f8829a4aSRandall Stewart 	control->held_length = 0;
4382f8829a4aSRandall Stewart 	control->length = 0;
4383f8829a4aSRandall Stewart 	while (m) {
4384139bc87fSRandall Stewart 		if (SCTP_BUF_LEN(m) == 0) {
4385f8829a4aSRandall Stewart 			/* Skip mbufs with NO length */
4386f8829a4aSRandall Stewart 			if (prev == NULL) {
4387f8829a4aSRandall Stewart 				/* First one */
4388f8829a4aSRandall Stewart 				control->data = sctp_m_free(m);
4389f8829a4aSRandall Stewart 				m = control->data;
4390f8829a4aSRandall Stewart 			} else {
4391139bc87fSRandall Stewart 				SCTP_BUF_NEXT(prev) = sctp_m_free(m);
4392139bc87fSRandall Stewart 				m = SCTP_BUF_NEXT(prev);
4393f8829a4aSRandall Stewart 			}
4394f8829a4aSRandall Stewart 			if (m == NULL) {
4395c2ede4b3SMartin Blapp 				control->tail_mbuf = prev;
4396f8829a4aSRandall Stewart 			}
4397f8829a4aSRandall Stewart 			continue;
4398f8829a4aSRandall Stewart 		}
4399f8829a4aSRandall Stewart 		prev = m;
4400b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4401139bc87fSRandall Stewart 			sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m));
440280fefe0aSRandall Stewart 		}
4403f8829a4aSRandall Stewart 		sctp_sballoc(stcb, sb, m);
4404b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4405f8829a4aSRandall Stewart 			sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
440680fefe0aSRandall Stewart 		}
4407139bc87fSRandall Stewart 		atomic_add_int(&control->length, SCTP_BUF_LEN(m));
4408139bc87fSRandall Stewart 		m = SCTP_BUF_NEXT(m);
4409f8829a4aSRandall Stewart 	}
4410f8829a4aSRandall Stewart 	if (prev != NULL) {
4411f8829a4aSRandall Stewart 		control->tail_mbuf = prev;
4412f8829a4aSRandall Stewart 	} else {
4413139bc87fSRandall Stewart 		/* Everything got collapsed out?? */
4414cfde3ff7SRandall Stewart 		if (inp_read_lock_held == 0)
441547a490cbSMichael Tuexen 			SCTP_INP_READ_UNLOCK(inp);
4416f8829a4aSRandall Stewart 		return;
4417f8829a4aSRandall Stewart 	}
4418f8829a4aSRandall Stewart 	if (end) {
4419f8829a4aSRandall Stewart 		control->end_added = 1;
4420f8829a4aSRandall Stewart 	}
4421f8829a4aSRandall Stewart 	TAILQ_INSERT_TAIL(&inp->read_queue, control, next);
4422cfde3ff7SRandall Stewart 	if (inp_read_lock_held == 0)
4423f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
4424f8829a4aSRandall Stewart 	if (inp && inp->sctp_socket) {
442517205eccSRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_ZERO_COPY_ACTIVE)) {
442617205eccSRandall Stewart 			SCTP_ZERO_COPY_EVENT(inp, inp->sctp_socket);
4427ceaad40aSRandall Stewart 		} else {
4428ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4429ceaad40aSRandall Stewart 			struct socket *so;
4430ceaad40aSRandall Stewart 
4431ceaad40aSRandall Stewart 			so = SCTP_INP_SO(inp);
4432ceaad40aSRandall Stewart 			if (!so_locked) {
4433ceaad40aSRandall Stewart 				atomic_add_int(&stcb->asoc.refcnt, 1);
4434ceaad40aSRandall Stewart 				SCTP_TCB_UNLOCK(stcb);
4435ceaad40aSRandall Stewart 				SCTP_SOCKET_LOCK(so, 1);
4436ceaad40aSRandall Stewart 				SCTP_TCB_LOCK(stcb);
4437ceaad40aSRandall Stewart 				atomic_subtract_int(&stcb->asoc.refcnt, 1);
4438ceaad40aSRandall Stewart 				if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
4439ceaad40aSRandall Stewart 					SCTP_SOCKET_UNLOCK(so, 1);
4440ceaad40aSRandall Stewart 					return;
4441ceaad40aSRandall Stewart 				}
4442ceaad40aSRandall Stewart 			}
4443ceaad40aSRandall Stewart #endif
4444f8829a4aSRandall Stewart 			sctp_sorwakeup(inp, inp->sctp_socket);
4445ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4446ceaad40aSRandall Stewart 			if (!so_locked) {
4447ceaad40aSRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
4448ceaad40aSRandall Stewart 			}
4449ceaad40aSRandall Stewart #endif
4450ceaad40aSRandall Stewart 		}
4451f8829a4aSRandall Stewart 	}
4452f8829a4aSRandall Stewart }
4453f8829a4aSRandall Stewart 
4454f8829a4aSRandall Stewart 
4455f8829a4aSRandall Stewart int
4456f8829a4aSRandall Stewart sctp_append_to_readq(struct sctp_inpcb *inp,
4457f8829a4aSRandall Stewart     struct sctp_tcb *stcb,
4458f8829a4aSRandall Stewart     struct sctp_queued_to_read *control,
4459f8829a4aSRandall Stewart     struct mbuf *m,
4460f8829a4aSRandall Stewart     int end,
4461f8829a4aSRandall Stewart     int ctls_cumack,
4462f8829a4aSRandall Stewart     struct sockbuf *sb)
4463f8829a4aSRandall Stewart {
4464f8829a4aSRandall Stewart 	/*
4465f8829a4aSRandall Stewart 	 * A partial delivery API event is underway. OR we are appending on
4466f8829a4aSRandall Stewart 	 * the reassembly queue.
4467f8829a4aSRandall Stewart 	 *
4468f8829a4aSRandall Stewart 	 * If PDAPI this means we need to add m to the end of the data.
4469f8829a4aSRandall Stewart 	 * Increase the length in the control AND increment the sb_cc.
4470f8829a4aSRandall Stewart 	 * Otherwise sb is NULL and all we need to do is put it at the end
4471f8829a4aSRandall Stewart 	 * of the mbuf chain.
4472f8829a4aSRandall Stewart 	 */
4473f8829a4aSRandall Stewart 	int len = 0;
4474f8829a4aSRandall Stewart 	struct mbuf *mm, *tail = NULL, *prev = NULL;
4475f8829a4aSRandall Stewart 
4476f8829a4aSRandall Stewart 	if (inp) {
4477f8829a4aSRandall Stewart 		SCTP_INP_READ_LOCK(inp);
4478f8829a4aSRandall Stewart 	}
4479f8829a4aSRandall Stewart 	if (control == NULL) {
4480f8829a4aSRandall Stewart get_out:
4481f8829a4aSRandall Stewart 		if (inp) {
4482f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
4483f8829a4aSRandall Stewart 		}
4484f8829a4aSRandall Stewart 		return (-1);
4485f8829a4aSRandall Stewart 	}
4486139bc87fSRandall Stewart 	if (control->end_added) {
4487f8829a4aSRandall Stewart 		/* huh this one is complete? */
4488f8829a4aSRandall Stewart 		goto get_out;
4489f8829a4aSRandall Stewart 	}
4490f8829a4aSRandall Stewart 	mm = m;
4491f8829a4aSRandall Stewart 	if (mm == NULL) {
4492f8829a4aSRandall Stewart 		goto get_out;
4493f8829a4aSRandall Stewart 	}
4494f8829a4aSRandall Stewart 	while (mm) {
4495139bc87fSRandall Stewart 		if (SCTP_BUF_LEN(mm) == 0) {
4496f8829a4aSRandall Stewart 			/* Skip mbufs with NO lenght */
4497f8829a4aSRandall Stewart 			if (prev == NULL) {
4498f8829a4aSRandall Stewart 				/* First one */
4499f8829a4aSRandall Stewart 				m = sctp_m_free(mm);
4500f8829a4aSRandall Stewart 				mm = m;
4501f8829a4aSRandall Stewart 			} else {
4502139bc87fSRandall Stewart 				SCTP_BUF_NEXT(prev) = sctp_m_free(mm);
4503139bc87fSRandall Stewart 				mm = SCTP_BUF_NEXT(prev);
4504f8829a4aSRandall Stewart 			}
4505f8829a4aSRandall Stewart 			continue;
4506f8829a4aSRandall Stewart 		}
4507f8829a4aSRandall Stewart 		prev = mm;
4508139bc87fSRandall Stewart 		len += SCTP_BUF_LEN(mm);
4509f8829a4aSRandall Stewart 		if (sb) {
4510b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4511139bc87fSRandall Stewart 				sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(mm));
451280fefe0aSRandall Stewart 			}
4513f8829a4aSRandall Stewart 			sctp_sballoc(stcb, sb, mm);
4514b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4515f8829a4aSRandall Stewart 				sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
451680fefe0aSRandall Stewart 			}
4517f8829a4aSRandall Stewart 		}
4518139bc87fSRandall Stewart 		mm = SCTP_BUF_NEXT(mm);
4519f8829a4aSRandall Stewart 	}
4520f8829a4aSRandall Stewart 	if (prev) {
4521f8829a4aSRandall Stewart 		tail = prev;
4522f8829a4aSRandall Stewart 	} else {
4523f8829a4aSRandall Stewart 		/* Really there should always be a prev */
4524f8829a4aSRandall Stewart 		if (m == NULL) {
4525f8829a4aSRandall Stewart 			/* Huh nothing left? */
4526a5d547adSRandall Stewart #ifdef INVARIANTS
4527f8829a4aSRandall Stewart 			panic("Nothing left to add?");
4528f8829a4aSRandall Stewart #else
4529f8829a4aSRandall Stewart 			goto get_out;
4530f8829a4aSRandall Stewart #endif
4531f8829a4aSRandall Stewart 		}
4532f8829a4aSRandall Stewart 		tail = m;
4533f8829a4aSRandall Stewart 	}
4534f8829a4aSRandall Stewart 	if (control->tail_mbuf) {
4535f8829a4aSRandall Stewart 		/* append */
4536139bc87fSRandall Stewart 		SCTP_BUF_NEXT(control->tail_mbuf) = m;
4537f8829a4aSRandall Stewart 		control->tail_mbuf = tail;
4538f8829a4aSRandall Stewart 	} else {
4539f8829a4aSRandall Stewart 		/* nothing there */
4540a5d547adSRandall Stewart #ifdef INVARIANTS
4541f8829a4aSRandall Stewart 		if (control->data != NULL) {
4542f8829a4aSRandall Stewart 			panic("This should NOT happen");
4543f8829a4aSRandall Stewart 		}
4544f8829a4aSRandall Stewart #endif
4545f8829a4aSRandall Stewart 		control->data = m;
4546f8829a4aSRandall Stewart 		control->tail_mbuf = tail;
4547f8829a4aSRandall Stewart 	}
454818e198d3SRandall Stewart 	atomic_add_int(&control->length, len);
454918e198d3SRandall Stewart 	if (end) {
455018e198d3SRandall Stewart 		/* message is complete */
455118e198d3SRandall Stewart 		if (stcb && (control == stcb->asoc.control_pdapi)) {
455218e198d3SRandall Stewart 			stcb->asoc.control_pdapi = NULL;
455318e198d3SRandall Stewart 		}
455418e198d3SRandall Stewart 		control->held_length = 0;
455518e198d3SRandall Stewart 		control->end_added = 1;
455618e198d3SRandall Stewart 	}
4557ad81507eSRandall Stewart 	if (stcb == NULL) {
4558ad81507eSRandall Stewart 		control->do_not_ref_stcb = 1;
4559ad81507eSRandall Stewart 	}
4560f8829a4aSRandall Stewart 	/*
4561f8829a4aSRandall Stewart 	 * When we are appending in partial delivery, the cum-ack is used
4562f8829a4aSRandall Stewart 	 * for the actual pd-api highest tsn on this mbuf. The true cum-ack
4563f8829a4aSRandall Stewart 	 * is populated in the outbound sinfo structure from the true cumack
4564f8829a4aSRandall Stewart 	 * if the association exists...
4565f8829a4aSRandall Stewart 	 */
4566f8829a4aSRandall Stewart 	control->sinfo_tsn = control->sinfo_cumtsn = ctls_cumack;
4567f8829a4aSRandall Stewart 	if (inp) {
4568f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
4569f8829a4aSRandall Stewart 	}
4570f8829a4aSRandall Stewart 	if (inp && inp->sctp_socket) {
457117205eccSRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_ZERO_COPY_ACTIVE)) {
457217205eccSRandall Stewart 			SCTP_ZERO_COPY_EVENT(inp, inp->sctp_socket);
4573ceaad40aSRandall Stewart 		} else {
4574ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4575ceaad40aSRandall Stewart 			struct socket *so;
4576ceaad40aSRandall Stewart 
4577ceaad40aSRandall Stewart 			so = SCTP_INP_SO(inp);
4578ceaad40aSRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, 1);
4579ceaad40aSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
4580ceaad40aSRandall Stewart 			SCTP_SOCKET_LOCK(so, 1);
4581ceaad40aSRandall Stewart 			SCTP_TCB_LOCK(stcb);
4582ceaad40aSRandall Stewart 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
4583ceaad40aSRandall Stewart 			if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
4584ceaad40aSRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
4585ceaad40aSRandall Stewart 				return (0);
4586ceaad40aSRandall Stewart 			}
4587ceaad40aSRandall Stewart #endif
4588f8829a4aSRandall Stewart 			sctp_sorwakeup(inp, inp->sctp_socket);
4589ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4590ceaad40aSRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
4591ceaad40aSRandall Stewart #endif
4592ceaad40aSRandall Stewart 		}
4593f8829a4aSRandall Stewart 	}
4594f8829a4aSRandall Stewart 	return (0);
4595f8829a4aSRandall Stewart }
4596f8829a4aSRandall Stewart 
4597f8829a4aSRandall Stewart 
4598f8829a4aSRandall Stewart 
4599f8829a4aSRandall Stewart /*************HOLD THIS COMMENT FOR PATCH FILE OF
4600f8829a4aSRandall Stewart  *************ALTERNATE ROUTING CODE
4601f8829a4aSRandall Stewart  */
4602f8829a4aSRandall Stewart 
4603f8829a4aSRandall Stewart /*************HOLD THIS COMMENT FOR END OF PATCH FILE OF
4604f8829a4aSRandall Stewart  *************ALTERNATE ROUTING CODE
4605f8829a4aSRandall Stewart  */
4606f8829a4aSRandall Stewart 
4607f8829a4aSRandall Stewart struct mbuf *
4608f8829a4aSRandall Stewart sctp_generate_invmanparam(int err)
4609f8829a4aSRandall Stewart {
4610f8829a4aSRandall Stewart 	/* Return a MBUF with a invalid mandatory parameter */
4611f8829a4aSRandall Stewart 	struct mbuf *m;
4612f8829a4aSRandall Stewart 
4613f8829a4aSRandall Stewart 	m = sctp_get_mbuf_for_msg(sizeof(struct sctp_paramhdr), 0, M_DONTWAIT, 1, MT_DATA);
4614f8829a4aSRandall Stewart 	if (m) {
4615f8829a4aSRandall Stewart 		struct sctp_paramhdr *ph;
4616f8829a4aSRandall Stewart 
4617139bc87fSRandall Stewart 		SCTP_BUF_LEN(m) = sizeof(struct sctp_paramhdr);
4618f8829a4aSRandall Stewart 		ph = mtod(m, struct sctp_paramhdr *);
4619f8829a4aSRandall Stewart 		ph->param_length = htons(sizeof(struct sctp_paramhdr));
4620f8829a4aSRandall Stewart 		ph->param_type = htons(err);
4621f8829a4aSRandall Stewart 	}
4622f8829a4aSRandall Stewart 	return (m);
4623f8829a4aSRandall Stewart }
4624f8829a4aSRandall Stewart 
4625f8829a4aSRandall Stewart #ifdef SCTP_MBCNT_LOGGING
4626f8829a4aSRandall Stewart void
4627f8829a4aSRandall Stewart sctp_free_bufspace(struct sctp_tcb *stcb, struct sctp_association *asoc,
4628f8829a4aSRandall Stewart     struct sctp_tmit_chunk *tp1, int chk_cnt)
4629f8829a4aSRandall Stewart {
4630f8829a4aSRandall Stewart 	if (tp1->data == NULL) {
4631f8829a4aSRandall Stewart 		return;
4632f8829a4aSRandall Stewart 	}
4633f8829a4aSRandall Stewart 	asoc->chunks_on_out_queue -= chk_cnt;
4634b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_MBCNT_LOGGING_ENABLE) {
4635f8829a4aSRandall Stewart 		sctp_log_mbcnt(SCTP_LOG_MBCNT_DECREASE,
4636f8829a4aSRandall Stewart 		    asoc->total_output_queue_size,
4637f8829a4aSRandall Stewart 		    tp1->book_size,
4638f8829a4aSRandall Stewart 		    0,
4639f8829a4aSRandall Stewart 		    tp1->mbcnt);
464080fefe0aSRandall Stewart 	}
4641f8829a4aSRandall Stewart 	if (asoc->total_output_queue_size >= tp1->book_size) {
464244b7479bSRandall Stewart 		atomic_add_int(&asoc->total_output_queue_size, -tp1->book_size);
4643f8829a4aSRandall Stewart 	} else {
4644f8829a4aSRandall Stewart 		asoc->total_output_queue_size = 0;
4645f8829a4aSRandall Stewart 	}
4646f8829a4aSRandall Stewart 
4647f8829a4aSRandall Stewart 	if (stcb->sctp_socket && (((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) ||
4648f8829a4aSRandall Stewart 	    ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE)))) {
4649f8829a4aSRandall Stewart 		if (stcb->sctp_socket->so_snd.sb_cc >= tp1->book_size) {
4650f8829a4aSRandall Stewart 			stcb->sctp_socket->so_snd.sb_cc -= tp1->book_size;
4651f8829a4aSRandall Stewart 		} else {
4652f8829a4aSRandall Stewart 			stcb->sctp_socket->so_snd.sb_cc = 0;
4653f8829a4aSRandall Stewart 
4654f8829a4aSRandall Stewart 		}
4655f8829a4aSRandall Stewart 	}
4656f8829a4aSRandall Stewart }
4657f8829a4aSRandall Stewart 
4658f8829a4aSRandall Stewart #endif
4659f8829a4aSRandall Stewart 
4660f8829a4aSRandall Stewart int
4661f8829a4aSRandall Stewart sctp_release_pr_sctp_chunk(struct sctp_tcb *stcb, struct sctp_tmit_chunk *tp1,
46620c0982b8SRandall Stewart     int reason, int so_locked
4663ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
4664ceaad40aSRandall Stewart     SCTP_UNUSED
4665ceaad40aSRandall Stewart #endif
4666ceaad40aSRandall Stewart )
4667f8829a4aSRandall Stewart {
46680c0982b8SRandall Stewart 	struct sctp_stream_out *strq;
46690c0982b8SRandall Stewart 	struct sctp_tmit_chunk *chk = NULL;
46700c0982b8SRandall Stewart 	struct sctp_stream_queue_pending *sp;
46710c0982b8SRandall Stewart 	uint16_t stream = 0, seq = 0;
46720c0982b8SRandall Stewart 	uint8_t foundeom = 0;
4673f8829a4aSRandall Stewart 	int ret_sz = 0;
4674f8829a4aSRandall Stewart 	int notdone;
46750c0982b8SRandall Stewart 	int do_wakeup_routine = 0;
4676f8829a4aSRandall Stewart 
46770c0982b8SRandall Stewart 	stream = tp1->rec.data.stream_number;
46780c0982b8SRandall Stewart 	seq = tp1->rec.data.stream_seq;
4679f8829a4aSRandall Stewart 	do {
4680f8829a4aSRandall Stewart 		ret_sz += tp1->book_size;
46810c0982b8SRandall Stewart 		if (tp1->data != NULL) {
46828933fa13SRandall Stewart 			if (tp1->sent < SCTP_DATAGRAM_RESEND) {
4683830d754dSRandall Stewart 				sctp_flight_size_decrease(tp1);
4684830d754dSRandall Stewart 				sctp_total_flight_decrease(stcb, tp1);
46858933fa13SRandall Stewart 			}
46868933fa13SRandall Stewart 			sctp_free_bufspace(stcb, &stcb->asoc, tp1, 1);
46870c0982b8SRandall Stewart 			stcb->asoc.peers_rwnd += tp1->send_size;
46880c0982b8SRandall Stewart 			stcb->asoc.peers_rwnd += SCTP_BASE_SYSCTL(sctp_peer_chunk_oh);
4689830d754dSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_DG_FAIL, stcb, reason, tp1, so_locked);
46902f99457bSMichael Tuexen 			if (tp1->data) {
4691f8829a4aSRandall Stewart 				sctp_m_freem(tp1->data);
4692f8829a4aSRandall Stewart 				tp1->data = NULL;
46932f99457bSMichael Tuexen 			}
46940c0982b8SRandall Stewart 			do_wakeup_routine = 1;
4695f8829a4aSRandall Stewart 			if (PR_SCTP_BUF_ENABLED(tp1->flags)) {
4696f8829a4aSRandall Stewart 				stcb->asoc.sent_queue_cnt_removeable--;
4697f8829a4aSRandall Stewart 			}
4698f8829a4aSRandall Stewart 		}
46998933fa13SRandall Stewart 		tp1->sent = SCTP_FORWARD_TSN_SKIP;
4700f8829a4aSRandall Stewart 		if ((tp1->rec.data.rcv_flags & SCTP_DATA_NOT_FRAG) ==
4701f8829a4aSRandall Stewart 		    SCTP_DATA_NOT_FRAG) {
4702f8829a4aSRandall Stewart 			/* not frag'ed we ae done   */
4703f8829a4aSRandall Stewart 			notdone = 0;
4704f8829a4aSRandall Stewart 			foundeom = 1;
4705f8829a4aSRandall Stewart 		} else if (tp1->rec.data.rcv_flags & SCTP_DATA_LAST_FRAG) {
4706f8829a4aSRandall Stewart 			/* end of frag, we are done */
4707f8829a4aSRandall Stewart 			notdone = 0;
4708f8829a4aSRandall Stewart 			foundeom = 1;
4709f8829a4aSRandall Stewart 		} else {
4710f8829a4aSRandall Stewart 			/*
4711f8829a4aSRandall Stewart 			 * Its a begin or middle piece, we must mark all of
4712f8829a4aSRandall Stewart 			 * it
4713f8829a4aSRandall Stewart 			 */
4714f8829a4aSRandall Stewart 			notdone = 1;
4715f8829a4aSRandall Stewart 			tp1 = TAILQ_NEXT(tp1, sctp_next);
4716f8829a4aSRandall Stewart 		}
4717f8829a4aSRandall Stewart 	} while (tp1 && notdone);
47180c0982b8SRandall Stewart 	if (foundeom == 0) {
4719f8829a4aSRandall Stewart 		/*
4720f8829a4aSRandall Stewart 		 * The multi-part message was scattered across the send and
4721f8829a4aSRandall Stewart 		 * sent queue.
4722f8829a4aSRandall Stewart 		 */
47230c0982b8SRandall Stewart next_on_sent:
4724f8829a4aSRandall Stewart 		tp1 = TAILQ_FIRST(&stcb->asoc.send_queue);
4725f8829a4aSRandall Stewart 		/*
4726f8829a4aSRandall Stewart 		 * recurse throught the send_queue too, starting at the
4727f8829a4aSRandall Stewart 		 * beginning.
4728f8829a4aSRandall Stewart 		 */
47290c0982b8SRandall Stewart 		if ((tp1) &&
47300c0982b8SRandall Stewart 		    (tp1->rec.data.stream_number == stream) &&
47310c0982b8SRandall Stewart 		    (tp1->rec.data.stream_seq == seq)
47320c0982b8SRandall Stewart 		    ) {
47330c0982b8SRandall Stewart 			/*
47340c0982b8SRandall Stewart 			 * save to chk in case we have some on stream out
47350c0982b8SRandall Stewart 			 * queue. If so and we have an un-transmitted one we
47360c0982b8SRandall Stewart 			 * don't have to fudge the TSN.
47370c0982b8SRandall Stewart 			 */
47380c0982b8SRandall Stewart 			chk = tp1;
47390c0982b8SRandall Stewart 			ret_sz += tp1->book_size;
47400c0982b8SRandall Stewart 			sctp_free_bufspace(stcb, &stcb->asoc, tp1, 1);
47412f99457bSMichael Tuexen 			sctp_ulp_notify(SCTP_NOTIFY_DG_FAIL, stcb, reason, tp1, so_locked);
47422f99457bSMichael Tuexen 			if (tp1->data) {
47430c0982b8SRandall Stewart 				sctp_m_freem(tp1->data);
47442f99457bSMichael Tuexen 				tp1->data = NULL;
47452f99457bSMichael Tuexen 			}
47468933fa13SRandall Stewart 			/* No flight involved here book the size to 0 */
47478933fa13SRandall Stewart 			tp1->book_size = 0;
47480c0982b8SRandall Stewart 			if (tp1->rec.data.rcv_flags & SCTP_DATA_LAST_FRAG) {
47490c0982b8SRandall Stewart 				foundeom = 1;
4750f8829a4aSRandall Stewart 			}
47510c0982b8SRandall Stewart 			do_wakeup_routine = 1;
47520c0982b8SRandall Stewart 			tp1->sent = SCTP_FORWARD_TSN_SKIP;
47530c0982b8SRandall Stewart 			TAILQ_REMOVE(&stcb->asoc.send_queue, tp1, sctp_next);
47540c0982b8SRandall Stewart 			/*
47550c0982b8SRandall Stewart 			 * on to the sent queue so we can wait for it to be
47560c0982b8SRandall Stewart 			 * passed by.
47570c0982b8SRandall Stewart 			 */
47580c0982b8SRandall Stewart 			TAILQ_INSERT_TAIL(&stcb->asoc.sent_queue, tp1,
47590c0982b8SRandall Stewart 			    sctp_next);
47600c0982b8SRandall Stewart 			stcb->asoc.send_queue_cnt--;
47610c0982b8SRandall Stewart 			stcb->asoc.sent_queue_cnt++;
47620c0982b8SRandall Stewart 			goto next_on_sent;
47630c0982b8SRandall Stewart 		}
47640c0982b8SRandall Stewart 	}
47650c0982b8SRandall Stewart 	if (foundeom == 0) {
47660c0982b8SRandall Stewart 		/*
47670c0982b8SRandall Stewart 		 * Still no eom found. That means there is stuff left on the
47680c0982b8SRandall Stewart 		 * stream out queue.. yuck.
47690c0982b8SRandall Stewart 		 */
47700c0982b8SRandall Stewart 		strq = &stcb->asoc.strmout[stream];
47710c0982b8SRandall Stewart 		SCTP_TCB_SEND_LOCK(stcb);
47720c0982b8SRandall Stewart 		sp = TAILQ_FIRST(&strq->outqueue);
47730c0982b8SRandall Stewart 		while (sp->strseq <= seq) {
47740c0982b8SRandall Stewart 			/* Check if its our SEQ */
47750c0982b8SRandall Stewart 			if (sp->strseq == seq) {
47760c0982b8SRandall Stewart 				sp->discard_rest = 1;
47770c0982b8SRandall Stewart 				/*
47780c0982b8SRandall Stewart 				 * We may need to put a chunk on the queue
47790c0982b8SRandall Stewart 				 * that holds the TSN that would have been
47800c0982b8SRandall Stewart 				 * sent with the LAST bit.
47810c0982b8SRandall Stewart 				 */
47820c0982b8SRandall Stewart 				if (chk == NULL) {
47830c0982b8SRandall Stewart 					/* Yep, we have to */
47840c0982b8SRandall Stewart 					sctp_alloc_a_chunk(stcb, chk);
47850c0982b8SRandall Stewart 					if (chk == NULL) {
47860c0982b8SRandall Stewart 						/*
47870c0982b8SRandall Stewart 						 * we are hosed. All we can
47880c0982b8SRandall Stewart 						 * do is nothing.. which
47890c0982b8SRandall Stewart 						 * will cause an abort if
47900c0982b8SRandall Stewart 						 * the peer is paying
47910c0982b8SRandall Stewart 						 * attention.
47920c0982b8SRandall Stewart 						 */
47930c0982b8SRandall Stewart 						goto oh_well;
47940c0982b8SRandall Stewart 					}
47950c0982b8SRandall Stewart 					memset(chk, 0, sizeof(*chk));
47960c0982b8SRandall Stewart 					chk->rec.data.rcv_flags = SCTP_DATA_LAST_FRAG;
47970c0982b8SRandall Stewart 					chk->sent = SCTP_FORWARD_TSN_SKIP;
47980c0982b8SRandall Stewart 					chk->asoc = &stcb->asoc;
47990c0982b8SRandall Stewart 					chk->rec.data.stream_seq = sp->strseq;
48000c0982b8SRandall Stewart 					chk->rec.data.stream_number = sp->stream;
48010c0982b8SRandall Stewart 					chk->rec.data.payloadtype = sp->ppid;
48020c0982b8SRandall Stewart 					chk->rec.data.context = sp->context;
48030c0982b8SRandall Stewart 					chk->flags = sp->act_flags;
48040c0982b8SRandall Stewart 					chk->whoTo = sp->net;
48050c0982b8SRandall Stewart 					atomic_add_int(&chk->whoTo->ref_count, 1);
48060c0982b8SRandall Stewart 					chk->rec.data.TSN_seq = atomic_fetchadd_int(&stcb->asoc.sending_seq, 1);
48070c0982b8SRandall Stewart 					stcb->asoc.pr_sctp_cnt++;
48080c0982b8SRandall Stewart 					chk->pr_sctp_on = 1;
48090c0982b8SRandall Stewart 					TAILQ_INSERT_TAIL(&stcb->asoc.sent_queue, chk, sctp_next);
48100c0982b8SRandall Stewart 					stcb->asoc.sent_queue_cnt++;
48118933fa13SRandall Stewart 					stcb->asoc.pr_sctp_cnt++;
48120c0982b8SRandall Stewart 				} else {
48130c0982b8SRandall Stewart 					chk->rec.data.rcv_flags |= SCTP_DATA_LAST_FRAG;
48140c0982b8SRandall Stewart 				}
48150c0982b8SRandall Stewart 		oh_well:
48160c0982b8SRandall Stewart 				if (sp->data) {
48170c0982b8SRandall Stewart 					/*
48180c0982b8SRandall Stewart 					 * Pull any data to free up the SB
48190c0982b8SRandall Stewart 					 * and allow sender to "add more"
48200c0982b8SRandall Stewart 					 * whilc we will throw away :-)
48210c0982b8SRandall Stewart 					 */
48220c0982b8SRandall Stewart 					sctp_free_spbufspace(stcb, &stcb->asoc,
48230c0982b8SRandall Stewart 					    sp);
48240c0982b8SRandall Stewart 					ret_sz += sp->length;
48250c0982b8SRandall Stewart 					do_wakeup_routine = 1;
48260c0982b8SRandall Stewart 					sp->some_taken = 1;
48270c0982b8SRandall Stewart 					sctp_m_freem(sp->data);
48280c0982b8SRandall Stewart 					sp->length = 0;
48290c0982b8SRandall Stewart 					sp->data = NULL;
48300c0982b8SRandall Stewart 					sp->tail_mbuf = NULL;
48310c0982b8SRandall Stewart 				}
48320c0982b8SRandall Stewart 				break;
48330c0982b8SRandall Stewart 			} else {
48340c0982b8SRandall Stewart 				/* Next one please */
48350c0982b8SRandall Stewart 				sp = TAILQ_NEXT(sp, next);
48360c0982b8SRandall Stewart 			}
48370c0982b8SRandall Stewart 		}		/* End while */
48380c0982b8SRandall Stewart 		SCTP_TCB_SEND_UNLOCK(stcb);
48390c0982b8SRandall Stewart 	}
48400c0982b8SRandall Stewart 	if (do_wakeup_routine) {
48410c0982b8SRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
48428933fa13SRandall Stewart 		struct socket *so;
48438933fa13SRandall Stewart 
48440c0982b8SRandall Stewart 		so = SCTP_INP_SO(stcb->sctp_ep);
48450c0982b8SRandall Stewart 		if (!so_locked) {
48460c0982b8SRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, 1);
48470c0982b8SRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
48480c0982b8SRandall Stewart 			SCTP_SOCKET_LOCK(so, 1);
48490c0982b8SRandall Stewart 			SCTP_TCB_LOCK(stcb);
48500c0982b8SRandall Stewart 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
48510c0982b8SRandall Stewart 			if (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET) {
48520c0982b8SRandall Stewart 				/* assoc was freed while we were unlocked */
48530c0982b8SRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
48540c0982b8SRandall Stewart 				return (ret_sz);
48550c0982b8SRandall Stewart 			}
48560c0982b8SRandall Stewart 		}
48570c0982b8SRandall Stewart #endif
48580c0982b8SRandall Stewart 		sctp_sowwakeup(stcb->sctp_ep, stcb->sctp_socket);
48590c0982b8SRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
48600c0982b8SRandall Stewart 		if (!so_locked) {
48610c0982b8SRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
48620c0982b8SRandall Stewart 		}
48630c0982b8SRandall Stewart #endif
4864f8829a4aSRandall Stewart 	}
4865f8829a4aSRandall Stewart 	return (ret_sz);
4866f8829a4aSRandall Stewart }
4867f8829a4aSRandall Stewart 
4868f8829a4aSRandall Stewart /*
4869f8829a4aSRandall Stewart  * checks to see if the given address, sa, is one that is currently known by
4870f8829a4aSRandall Stewart  * the kernel note: can't distinguish the same address on multiple interfaces
4871f8829a4aSRandall Stewart  * and doesn't handle multiple addresses with different zone/scope id's note:
4872f8829a4aSRandall Stewart  * ifa_ifwithaddr() compares the entire sockaddr struct
4873f8829a4aSRandall Stewart  */
487442551e99SRandall Stewart struct sctp_ifa *
487580fefe0aSRandall Stewart sctp_find_ifa_in_ep(struct sctp_inpcb *inp, struct sockaddr *addr,
487680fefe0aSRandall Stewart     int holds_lock)
4877f8829a4aSRandall Stewart {
487842551e99SRandall Stewart 	struct sctp_laddr *laddr;
4879f8829a4aSRandall Stewart 
4880ad81507eSRandall Stewart 	if (holds_lock == 0) {
488142551e99SRandall Stewart 		SCTP_INP_RLOCK(inp);
4882ad81507eSRandall Stewart 	}
488342551e99SRandall Stewart 	LIST_FOREACH(laddr, &inp->sctp_addr_list, sctp_nxt_addr) {
488442551e99SRandall Stewart 		if (laddr->ifa == NULL)
4885f8829a4aSRandall Stewart 			continue;
488642551e99SRandall Stewart 		if (addr->sa_family != laddr->ifa->address.sa.sa_family)
488742551e99SRandall Stewart 			continue;
488842551e99SRandall Stewart 		if (addr->sa_family == AF_INET) {
488942551e99SRandall Stewart 			if (((struct sockaddr_in *)addr)->sin_addr.s_addr ==
489042551e99SRandall Stewart 			    laddr->ifa->address.sin.sin_addr.s_addr) {
489142551e99SRandall Stewart 				/* found him. */
4892ad81507eSRandall Stewart 				if (holds_lock == 0) {
489342551e99SRandall Stewart 					SCTP_INP_RUNLOCK(inp);
4894ad81507eSRandall Stewart 				}
489542551e99SRandall Stewart 				return (laddr->ifa);
489642551e99SRandall Stewart 				break;
489742551e99SRandall Stewart 			}
48985e2c2d87SRandall Stewart 		}
48995e2c2d87SRandall Stewart #ifdef INET6
49005e2c2d87SRandall Stewart 		if (addr->sa_family == AF_INET6) {
4901c54a18d2SRandall Stewart 			if (SCTP6_ARE_ADDR_EQUAL((struct sockaddr_in6 *)addr,
4902c54a18d2SRandall Stewart 			    &laddr->ifa->address.sin6)) {
490342551e99SRandall Stewart 				/* found him. */
4904ad81507eSRandall Stewart 				if (holds_lock == 0) {
490542551e99SRandall Stewart 					SCTP_INP_RUNLOCK(inp);
4906ad81507eSRandall Stewart 				}
490742551e99SRandall Stewart 				return (laddr->ifa);
490842551e99SRandall Stewart 				break;
490942551e99SRandall Stewart 			}
491042551e99SRandall Stewart 		}
49115e2c2d87SRandall Stewart #endif
491242551e99SRandall Stewart 	}
4913ad81507eSRandall Stewart 	if (holds_lock == 0) {
491442551e99SRandall Stewart 		SCTP_INP_RUNLOCK(inp);
4915ad81507eSRandall Stewart 	}
491642551e99SRandall Stewart 	return (NULL);
491742551e99SRandall Stewart }
4918f8829a4aSRandall Stewart 
49196a27c376SRandall Stewart uint32_t
49206a27c376SRandall Stewart sctp_get_ifa_hash_val(struct sockaddr *addr)
49216a27c376SRandall Stewart {
49226a27c376SRandall Stewart 	if (addr->sa_family == AF_INET) {
49236a27c376SRandall Stewart 		struct sockaddr_in *sin;
49246a27c376SRandall Stewart 
49256a27c376SRandall Stewart 		sin = (struct sockaddr_in *)addr;
49266a27c376SRandall Stewart 		return (sin->sin_addr.s_addr ^ (sin->sin_addr.s_addr >> 16));
49276a27c376SRandall Stewart 	} else if (addr->sa_family == AF_INET6) {
49286a27c376SRandall Stewart 		struct sockaddr_in6 *sin6;
49296a27c376SRandall Stewart 		uint32_t hash_of_addr;
49306a27c376SRandall Stewart 
49316a27c376SRandall Stewart 		sin6 = (struct sockaddr_in6 *)addr;
49326a27c376SRandall Stewart 		hash_of_addr = (sin6->sin6_addr.s6_addr32[0] +
49336a27c376SRandall Stewart 		    sin6->sin6_addr.s6_addr32[1] +
49346a27c376SRandall Stewart 		    sin6->sin6_addr.s6_addr32[2] +
49356a27c376SRandall Stewart 		    sin6->sin6_addr.s6_addr32[3]);
49366a27c376SRandall Stewart 		hash_of_addr = (hash_of_addr ^ (hash_of_addr >> 16));
49376a27c376SRandall Stewart 		return (hash_of_addr);
49386a27c376SRandall Stewart 	}
49396a27c376SRandall Stewart 	return (0);
49406a27c376SRandall Stewart }
49416a27c376SRandall Stewart 
494242551e99SRandall Stewart struct sctp_ifa *
494342551e99SRandall Stewart sctp_find_ifa_by_addr(struct sockaddr *addr, uint32_t vrf_id, int holds_lock)
494442551e99SRandall Stewart {
494542551e99SRandall Stewart 	struct sctp_ifa *sctp_ifap;
494642551e99SRandall Stewart 	struct sctp_vrf *vrf;
49476a27c376SRandall Stewart 	struct sctp_ifalist *hash_head;
49486a27c376SRandall Stewart 	uint32_t hash_of_addr;
494942551e99SRandall Stewart 
495042551e99SRandall Stewart 	if (holds_lock == 0)
4951c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RLOCK();
495242551e99SRandall Stewart 
4953bff64a4dSRandall Stewart 	vrf = sctp_find_vrf(vrf_id);
4954bff64a4dSRandall Stewart 	if (vrf == NULL) {
4955df6e0cc3SRandall Stewart stage_right:
4956bff64a4dSRandall Stewart 		if (holds_lock == 0)
4957c99efcf6SRandall Stewart 			SCTP_IPI_ADDR_RUNLOCK();
4958bff64a4dSRandall Stewart 		return (NULL);
4959bff64a4dSRandall Stewart 	}
4960bff64a4dSRandall Stewart 	hash_of_addr = sctp_get_ifa_hash_val(addr);
4961bff64a4dSRandall Stewart 
496217205eccSRandall Stewart 	hash_head = &vrf->vrf_addr_hash[(hash_of_addr & vrf->vrf_addr_hashmark)];
4963bff64a4dSRandall Stewart 	if (hash_head == NULL) {
4964ad81507eSRandall Stewart 		SCTP_PRINTF("hash_of_addr:%x mask:%x table:%x - ",
4965c99efcf6SRandall Stewart 		    hash_of_addr, (uint32_t) vrf->vrf_addr_hashmark,
4966c99efcf6SRandall Stewart 		    (uint32_t) (hash_of_addr & vrf->vrf_addr_hashmark));
4967bff64a4dSRandall Stewart 		sctp_print_address(addr);
4968ad81507eSRandall Stewart 		SCTP_PRINTF("No such bucket for address\n");
4969bff64a4dSRandall Stewart 		if (holds_lock == 0)
4970c99efcf6SRandall Stewart 			SCTP_IPI_ADDR_RUNLOCK();
4971bff64a4dSRandall Stewart 
4972bff64a4dSRandall Stewart 		return (NULL);
4973bff64a4dSRandall Stewart 	}
49746a27c376SRandall Stewart 	LIST_FOREACH(sctp_ifap, hash_head, next_bucket) {
4975bff64a4dSRandall Stewart 		if (sctp_ifap == NULL) {
4976df6e0cc3SRandall Stewart #ifdef INVARIANTS
4977bff64a4dSRandall Stewart 			panic("Huh LIST_FOREACH corrupt");
4978df6e0cc3SRandall Stewart 			goto stage_right;
4979df6e0cc3SRandall Stewart #else
4980df6e0cc3SRandall Stewart 			SCTP_PRINTF("LIST corrupt of sctp_ifap's?\n");
4981df6e0cc3SRandall Stewart 			goto stage_right;
4982df6e0cc3SRandall Stewart #endif
4983bff64a4dSRandall Stewart 		}
49846a27c376SRandall Stewart 		if (addr->sa_family != sctp_ifap->address.sa.sa_family)
49856a27c376SRandall Stewart 			continue;
49866a27c376SRandall Stewart 		if (addr->sa_family == AF_INET) {
49876a27c376SRandall Stewart 			if (((struct sockaddr_in *)addr)->sin_addr.s_addr ==
49886a27c376SRandall Stewart 			    sctp_ifap->address.sin.sin_addr.s_addr) {
49896a27c376SRandall Stewart 				/* found him. */
499042551e99SRandall Stewart 				if (holds_lock == 0)
4991c99efcf6SRandall Stewart 					SCTP_IPI_ADDR_RUNLOCK();
499242551e99SRandall Stewart 				return (sctp_ifap);
49936a27c376SRandall Stewart 				break;
49946a27c376SRandall Stewart 			}
49955e2c2d87SRandall Stewart 		}
49965e2c2d87SRandall Stewart #ifdef INET6
49975e2c2d87SRandall Stewart 		if (addr->sa_family == AF_INET6) {
4998c54a18d2SRandall Stewart 			if (SCTP6_ARE_ADDR_EQUAL((struct sockaddr_in6 *)addr,
4999c54a18d2SRandall Stewart 			    &sctp_ifap->address.sin6)) {
50006a27c376SRandall Stewart 				/* found him. */
50016a27c376SRandall Stewart 				if (holds_lock == 0)
5002c99efcf6SRandall Stewart 					SCTP_IPI_ADDR_RUNLOCK();
50036a27c376SRandall Stewart 				return (sctp_ifap);
50046a27c376SRandall Stewart 				break;
50056a27c376SRandall Stewart 			}
500642551e99SRandall Stewart 		}
50075e2c2d87SRandall Stewart #endif
500842551e99SRandall Stewart 	}
500942551e99SRandall Stewart 	if (holds_lock == 0)
5010c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RUNLOCK();
5011f8829a4aSRandall Stewart 	return (NULL);
5012f8829a4aSRandall Stewart }
5013f8829a4aSRandall Stewart 
5014f8829a4aSRandall Stewart static void
50154c9179adSRandall Stewart sctp_user_rcvd(struct sctp_tcb *stcb, uint32_t * freed_so_far, int hold_rlock,
5016f8829a4aSRandall Stewart     uint32_t rwnd_req)
5017f8829a4aSRandall Stewart {
5018f8829a4aSRandall Stewart 	/* User pulled some data, do we need a rwnd update? */
5019f8829a4aSRandall Stewart 	int r_unlocked = 0;
5020f8829a4aSRandall Stewart 	uint32_t dif, rwnd;
5021f8829a4aSRandall Stewart 	struct socket *so = NULL;
5022f8829a4aSRandall Stewart 
5023f8829a4aSRandall Stewart 	if (stcb == NULL)
5024f8829a4aSRandall Stewart 		return;
5025f8829a4aSRandall Stewart 
502650cec919SRandall Stewart 	atomic_add_int(&stcb->asoc.refcnt, 1);
5027f8829a4aSRandall Stewart 
502862c1ff9cSRandall Stewart 	if (stcb->asoc.state & (SCTP_STATE_ABOUT_TO_BE_FREED |
502962c1ff9cSRandall Stewart 	    SCTP_STATE_SHUTDOWN_RECEIVED |
50304c9179adSRandall Stewart 	    SCTP_STATE_SHUTDOWN_ACK_SENT)) {
5031f8829a4aSRandall Stewart 		/* Pre-check If we are freeing no update */
5032f8829a4aSRandall Stewart 		goto no_lock;
5033f8829a4aSRandall Stewart 	}
5034f8829a4aSRandall Stewart 	SCTP_INP_INCR_REF(stcb->sctp_ep);
5035f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
5036f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE)) {
5037f8829a4aSRandall Stewart 		goto out;
5038f8829a4aSRandall Stewart 	}
5039f8829a4aSRandall Stewart 	so = stcb->sctp_socket;
5040f8829a4aSRandall Stewart 	if (so == NULL) {
5041f8829a4aSRandall Stewart 		goto out;
5042f8829a4aSRandall Stewart 	}
5043f8829a4aSRandall Stewart 	atomic_add_int(&stcb->freed_by_sorcv_sincelast, *freed_so_far);
5044f8829a4aSRandall Stewart 	/* Have you have freed enough to look */
5045f8829a4aSRandall Stewart 	*freed_so_far = 0;
5046f8829a4aSRandall Stewart 	/* Yep, its worth a look and the lock overhead */
5047f8829a4aSRandall Stewart 
5048f8829a4aSRandall Stewart 	/* Figure out what the rwnd would be */
5049f8829a4aSRandall Stewart 	rwnd = sctp_calc_rwnd(stcb, &stcb->asoc);
5050f8829a4aSRandall Stewart 	if (rwnd >= stcb->asoc.my_last_reported_rwnd) {
5051f8829a4aSRandall Stewart 		dif = rwnd - stcb->asoc.my_last_reported_rwnd;
5052f8829a4aSRandall Stewart 	} else {
5053f8829a4aSRandall Stewart 		dif = 0;
5054f8829a4aSRandall Stewart 	}
5055f8829a4aSRandall Stewart 	if (dif >= rwnd_req) {
5056f8829a4aSRandall Stewart 		if (hold_rlock) {
5057f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(stcb->sctp_ep);
5058f8829a4aSRandall Stewart 			r_unlocked = 1;
5059f8829a4aSRandall Stewart 		}
5060f8829a4aSRandall Stewart 		if (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
5061f8829a4aSRandall Stewart 			/*
5062f8829a4aSRandall Stewart 			 * One last check before we allow the guy possibly
5063f8829a4aSRandall Stewart 			 * to get in. There is a race, where the guy has not
5064f8829a4aSRandall Stewart 			 * reached the gate. In that case
5065f8829a4aSRandall Stewart 			 */
5066f8829a4aSRandall Stewart 			goto out;
5067f8829a4aSRandall Stewart 		}
5068f8829a4aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
5069f8829a4aSRandall Stewart 		if (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
5070f8829a4aSRandall Stewart 			/* No reports here */
5071f8829a4aSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
5072f8829a4aSRandall Stewart 			goto out;
5073f8829a4aSRandall Stewart 		}
5074f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_wu_sacks_sent);
5075830d754dSRandall Stewart 		/*
5076830d754dSRandall Stewart 		 * EY if nr_sacks used then send an nr-sack , a sack
5077830d754dSRandall Stewart 		 * otherwise
5078830d754dSRandall Stewart 		 */
5079830d754dSRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_nr_sack_on_off) && stcb->asoc.peer_supports_nr_sack)
5080830d754dSRandall Stewart 			sctp_send_nr_sack(stcb);
5081830d754dSRandall Stewart 		else
5082f8829a4aSRandall Stewart 			sctp_send_sack(stcb);
5083830d754dSRandall Stewart 
5084f8829a4aSRandall Stewart 		sctp_chunk_output(stcb->sctp_ep, stcb,
5085ceaad40aSRandall Stewart 		    SCTP_OUTPUT_FROM_USR_RCVD, SCTP_SO_LOCKED);
5086f8829a4aSRandall Stewart 		/* make sure no timer is running */
5087a5d547adSRandall Stewart 		sctp_timer_stop(SCTP_TIMER_TYPE_RECV, stcb->sctp_ep, stcb, NULL, SCTP_FROM_SCTPUTIL + SCTP_LOC_6);
5088f8829a4aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
5089f8829a4aSRandall Stewart 	} else {
5090f8829a4aSRandall Stewart 		/* Update how much we have pending */
5091f8829a4aSRandall Stewart 		stcb->freed_by_sorcv_sincelast = dif;
5092f8829a4aSRandall Stewart 	}
5093f8829a4aSRandall Stewart out:
5094f8829a4aSRandall Stewart 	if (so && r_unlocked && hold_rlock) {
5095f8829a4aSRandall Stewart 		SCTP_INP_READ_LOCK(stcb->sctp_ep);
5096f8829a4aSRandall Stewart 	}
5097f8829a4aSRandall Stewart 	SCTP_INP_DECR_REF(stcb->sctp_ep);
5098f8829a4aSRandall Stewart no_lock:
509950cec919SRandall Stewart 	atomic_add_int(&stcb->asoc.refcnt, -1);
5100f8829a4aSRandall Stewart 	return;
5101f8829a4aSRandall Stewart }
5102f8829a4aSRandall Stewart 
5103f8829a4aSRandall Stewart int
5104f8829a4aSRandall Stewart sctp_sorecvmsg(struct socket *so,
5105f8829a4aSRandall Stewart     struct uio *uio,
5106f8829a4aSRandall Stewart     struct mbuf **mp,
5107f8829a4aSRandall Stewart     struct sockaddr *from,
5108f8829a4aSRandall Stewart     int fromlen,
5109f8829a4aSRandall Stewart     int *msg_flags,
5110f8829a4aSRandall Stewart     struct sctp_sndrcvinfo *sinfo,
5111f8829a4aSRandall Stewart     int filling_sinfo)
5112f8829a4aSRandall Stewart {
5113f8829a4aSRandall Stewart 	/*
5114f8829a4aSRandall Stewart 	 * MSG flags we will look at MSG_DONTWAIT - non-blocking IO.
5115f8829a4aSRandall Stewart 	 * MSG_PEEK - Look don't touch :-D (only valid with OUT mbuf copy
5116f8829a4aSRandall Stewart 	 * mp=NULL thus uio is the copy method to userland) MSG_WAITALL - ??
5117f8829a4aSRandall Stewart 	 * On the way out we may send out any combination of:
5118f8829a4aSRandall Stewart 	 * MSG_NOTIFICATION MSG_EOR
5119f8829a4aSRandall Stewart 	 *
5120f8829a4aSRandall Stewart 	 */
5121f8829a4aSRandall Stewart 	struct sctp_inpcb *inp = NULL;
5122f8829a4aSRandall Stewart 	int my_len = 0;
5123f8829a4aSRandall Stewart 	int cp_len = 0, error = 0;
5124f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control = NULL, *ctl = NULL, *nxt = NULL;
5125f8829a4aSRandall Stewart 	struct mbuf *m = NULL, *embuf = NULL;
5126f8829a4aSRandall Stewart 	struct sctp_tcb *stcb = NULL;
5127f8829a4aSRandall Stewart 	int wakeup_read_socket = 0;
5128f8829a4aSRandall Stewart 	int freecnt_applied = 0;
5129f8829a4aSRandall Stewart 	int out_flags = 0, in_flags = 0;
5130f8829a4aSRandall Stewart 	int block_allowed = 1;
51314c9179adSRandall Stewart 	uint32_t freed_so_far = 0;
513281aca91aSRandall Stewart 	uint32_t copied_so_far = 0;
513393164cf9SRandall Stewart 	int in_eeor_mode = 0;
5134f8829a4aSRandall Stewart 	int no_rcv_needed = 0;
5135f8829a4aSRandall Stewart 	uint32_t rwnd_req = 0;
5136f8829a4aSRandall Stewart 	int hold_sblock = 0;
5137f8829a4aSRandall Stewart 	int hold_rlock = 0;
513842551e99SRandall Stewart 	int slen = 0;
51394c9179adSRandall Stewart 	uint32_t held_length = 0;
51407abab911SRobert Watson 	int sockbuf_lock = 0;
5141f8829a4aSRandall Stewart 
514217205eccSRandall Stewart 	if (uio == NULL) {
5143c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
514417205eccSRandall Stewart 		return (EINVAL);
514517205eccSRandall Stewart 	}
5146f8829a4aSRandall Stewart 	if (msg_flags) {
5147f8829a4aSRandall Stewart 		in_flags = *msg_flags;
5148c105859eSRandall Stewart 		if (in_flags & MSG_PEEK)
5149c105859eSRandall Stewart 			SCTP_STAT_INCR(sctps_read_peeks);
5150f8829a4aSRandall Stewart 	} else {
5151f8829a4aSRandall Stewart 		in_flags = 0;
5152f8829a4aSRandall Stewart 	}
5153f8829a4aSRandall Stewart 	slen = uio->uio_resid;
515417205eccSRandall Stewart 
5155f8829a4aSRandall Stewart 	/* Pull in and set up our int flags */
5156f8829a4aSRandall Stewart 	if (in_flags & MSG_OOB) {
5157f8829a4aSRandall Stewart 		/* Out of band's NOT supported */
5158f8829a4aSRandall Stewart 		return (EOPNOTSUPP);
5159f8829a4aSRandall Stewart 	}
5160f8829a4aSRandall Stewart 	if ((in_flags & MSG_PEEK) && (mp != NULL)) {
5161c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
5162f8829a4aSRandall Stewart 		return (EINVAL);
5163f8829a4aSRandall Stewart 	}
5164f8829a4aSRandall Stewart 	if ((in_flags & (MSG_DONTWAIT
5165f8829a4aSRandall Stewart 	    | MSG_NBIO
5166f8829a4aSRandall Stewart 	    )) ||
516742551e99SRandall Stewart 	    SCTP_SO_IS_NBIO(so)) {
5168f8829a4aSRandall Stewart 		block_allowed = 0;
5169f8829a4aSRandall Stewart 	}
5170f8829a4aSRandall Stewart 	/* setup the endpoint */
5171f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)so->so_pcb;
5172f8829a4aSRandall Stewart 	if (inp == NULL) {
5173c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EFAULT);
5174f8829a4aSRandall Stewart 		return (EFAULT);
5175f8829a4aSRandall Stewart 	}
517662c1ff9cSRandall Stewart 	rwnd_req = (SCTP_SB_LIMIT_RCV(so) >> SCTP_RWND_HIWAT_SHIFT);
5177f8829a4aSRandall Stewart 	/* Must be at least a MTU's worth */
5178f8829a4aSRandall Stewart 	if (rwnd_req < SCTP_MIN_RWND)
5179f8829a4aSRandall Stewart 		rwnd_req = SCTP_MIN_RWND;
5180f8829a4aSRandall Stewart 	in_eeor_mode = sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXPLICIT_EOR);
5181b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
5182f8829a4aSRandall Stewart 		sctp_misc_ints(SCTP_SORECV_ENTER,
518317205eccSRandall Stewart 		    rwnd_req, in_eeor_mode, so->so_rcv.sb_cc, uio->uio_resid);
518480fefe0aSRandall Stewart 	}
5185b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
5186f8829a4aSRandall Stewart 		sctp_misc_ints(SCTP_SORECV_ENTERPL,
518717205eccSRandall Stewart 		    rwnd_req, block_allowed, so->so_rcv.sb_cc, uio->uio_resid);
518880fefe0aSRandall Stewart 	}
5189265de5bbSRobert Watson 	error = sblock(&so->so_rcv, (block_allowed ? SBL_WAIT : 0));
51907abab911SRobert Watson 	sockbuf_lock = 1;
5191f8829a4aSRandall Stewart 	if (error) {
5192f8829a4aSRandall Stewart 		goto release_unlocked;
5193f8829a4aSRandall Stewart 	}
5194f8829a4aSRandall Stewart restart:
51957abab911SRobert Watson 
5196f8829a4aSRandall Stewart 
5197f8829a4aSRandall Stewart restart_nosblocks:
5198f8829a4aSRandall Stewart 	if (hold_sblock == 0) {
5199f8829a4aSRandall Stewart 		SOCKBUF_LOCK(&so->so_rcv);
5200f8829a4aSRandall Stewart 		hold_sblock = 1;
5201f8829a4aSRandall Stewart 	}
5202f8829a4aSRandall Stewart 	if ((inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
5203f8829a4aSRandall Stewart 	    (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE)) {
5204f8829a4aSRandall Stewart 		goto out;
5205f8829a4aSRandall Stewart 	}
520644b7479bSRandall Stewart 	if (so->so_rcv.sb_state & SBS_CANTRCVMORE) {
5207f8829a4aSRandall Stewart 		if (so->so_error) {
5208f8829a4aSRandall Stewart 			error = so->so_error;
520944b7479bSRandall Stewart 			if ((in_flags & MSG_PEEK) == 0)
521044b7479bSRandall Stewart 				so->so_error = 0;
52119f22f500SRandall Stewart 			goto out;
5212f8829a4aSRandall Stewart 		} else {
52139f22f500SRandall Stewart 			if (so->so_rcv.sb_cc == 0) {
5214c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOTCONN);
52157924093fSRandall Stewart 				/* indicate EOF */
52167924093fSRandall Stewart 				error = 0;
5217f8829a4aSRandall Stewart 				goto out;
5218f8829a4aSRandall Stewart 			}
52199f22f500SRandall Stewart 		}
52209f22f500SRandall Stewart 	}
5221f8829a4aSRandall Stewart 	if ((so->so_rcv.sb_cc <= held_length) && block_allowed) {
5222f8829a4aSRandall Stewart 		/* we need to wait for data */
5223f8829a4aSRandall Stewart 		if ((so->so_rcv.sb_cc == 0) &&
5224f8829a4aSRandall Stewart 		    ((inp->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
5225f8829a4aSRandall Stewart 		    (inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL))) {
5226f8829a4aSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_CONNECTED) == 0) {
5227f8829a4aSRandall Stewart 				/*
5228f8829a4aSRandall Stewart 				 * For active open side clear flags for
5229f8829a4aSRandall Stewart 				 * re-use passive open is blocked by
5230f8829a4aSRandall Stewart 				 * connect.
5231f8829a4aSRandall Stewart 				 */
5232f8829a4aSRandall Stewart 				if (inp->sctp_flags & SCTP_PCB_FLAGS_WAS_ABORTED) {
5233f8829a4aSRandall Stewart 					/*
5234f8829a4aSRandall Stewart 					 * You were aborted, passive side
5235f8829a4aSRandall Stewart 					 * always hits here
5236f8829a4aSRandall Stewart 					 */
5237c4739e2fSRandall Stewart 					SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ECONNRESET);
5238f8829a4aSRandall Stewart 					error = ECONNRESET;
5239f8829a4aSRandall Stewart 					/*
5240f8829a4aSRandall Stewart 					 * You get this once if you are
5241f8829a4aSRandall Stewart 					 * active open side
5242f8829a4aSRandall Stewart 					 */
5243f8829a4aSRandall Stewart 					if (!(inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
5244f8829a4aSRandall Stewart 						/*
5245f8829a4aSRandall Stewart 						 * Remove flag if on the
5246f8829a4aSRandall Stewart 						 * active open side
5247f8829a4aSRandall Stewart 						 */
5248f8829a4aSRandall Stewart 						inp->sctp_flags &= ~SCTP_PCB_FLAGS_WAS_ABORTED;
5249f8829a4aSRandall Stewart 					}
5250f8829a4aSRandall Stewart 				}
5251f8829a4aSRandall Stewart 				so->so_state &= ~(SS_ISCONNECTING |
5252f8829a4aSRandall Stewart 				    SS_ISDISCONNECTING |
5253f8829a4aSRandall Stewart 				    SS_ISCONFIRMING |
5254f8829a4aSRandall Stewart 				    SS_ISCONNECTED);
5255f8829a4aSRandall Stewart 				if (error == 0) {
5256f8829a4aSRandall Stewart 					if ((inp->sctp_flags & SCTP_PCB_FLAGS_WAS_CONNECTED) == 0) {
5257c4739e2fSRandall Stewart 						SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOTCONN);
5258f8829a4aSRandall Stewart 						error = ENOTCONN;
5259f8829a4aSRandall Stewart 					} else {
5260f8829a4aSRandall Stewart 						inp->sctp_flags &= ~SCTP_PCB_FLAGS_WAS_CONNECTED;
5261f8829a4aSRandall Stewart 					}
5262f8829a4aSRandall Stewart 				}
5263f8829a4aSRandall Stewart 				goto out;
5264f8829a4aSRandall Stewart 			}
5265f8829a4aSRandall Stewart 		}
5266f8829a4aSRandall Stewart 		error = sbwait(&so->so_rcv);
5267f8829a4aSRandall Stewart 		if (error) {
5268f8829a4aSRandall Stewart 			goto out;
5269f8829a4aSRandall Stewart 		}
5270f8829a4aSRandall Stewart 		held_length = 0;
5271f8829a4aSRandall Stewart 		goto restart_nosblocks;
5272f8829a4aSRandall Stewart 	} else if (so->so_rcv.sb_cc == 0) {
527344b7479bSRandall Stewart 		if (so->so_error) {
527444b7479bSRandall Stewart 			error = so->so_error;
527544b7479bSRandall Stewart 			if ((in_flags & MSG_PEEK) == 0)
527644b7479bSRandall Stewart 				so->so_error = 0;
527744b7479bSRandall Stewart 		} else {
527844b7479bSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
527944b7479bSRandall Stewart 			    (inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
528044b7479bSRandall Stewart 				if ((inp->sctp_flags & SCTP_PCB_FLAGS_CONNECTED) == 0) {
528144b7479bSRandall Stewart 					/*
528244b7479bSRandall Stewart 					 * For active open side clear flags
528344b7479bSRandall Stewart 					 * for re-use passive open is
528444b7479bSRandall Stewart 					 * blocked by connect.
528544b7479bSRandall Stewart 					 */
528644b7479bSRandall Stewart 					if (inp->sctp_flags & SCTP_PCB_FLAGS_WAS_ABORTED) {
528744b7479bSRandall Stewart 						/*
528844b7479bSRandall Stewart 						 * You were aborted, passive
528944b7479bSRandall Stewart 						 * side always hits here
529044b7479bSRandall Stewart 						 */
5291c4739e2fSRandall Stewart 						SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ECONNRESET);
529244b7479bSRandall Stewart 						error = ECONNRESET;
529344b7479bSRandall Stewart 						/*
529444b7479bSRandall Stewart 						 * You get this once if you
529544b7479bSRandall Stewart 						 * are active open side
529644b7479bSRandall Stewart 						 */
529744b7479bSRandall Stewart 						if (!(inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
529844b7479bSRandall Stewart 							/*
529944b7479bSRandall Stewart 							 * Remove flag if on
530044b7479bSRandall Stewart 							 * the active open
530144b7479bSRandall Stewart 							 * side
530244b7479bSRandall Stewart 							 */
530344b7479bSRandall Stewart 							inp->sctp_flags &= ~SCTP_PCB_FLAGS_WAS_ABORTED;
530444b7479bSRandall Stewart 						}
530544b7479bSRandall Stewart 					}
530644b7479bSRandall Stewart 					so->so_state &= ~(SS_ISCONNECTING |
530744b7479bSRandall Stewart 					    SS_ISDISCONNECTING |
530844b7479bSRandall Stewart 					    SS_ISCONFIRMING |
530944b7479bSRandall Stewart 					    SS_ISCONNECTED);
531044b7479bSRandall Stewart 					if (error == 0) {
531144b7479bSRandall Stewart 						if ((inp->sctp_flags & SCTP_PCB_FLAGS_WAS_CONNECTED) == 0) {
5312c4739e2fSRandall Stewart 							SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOTCONN);
531344b7479bSRandall Stewart 							error = ENOTCONN;
531444b7479bSRandall Stewart 						} else {
531544b7479bSRandall Stewart 							inp->sctp_flags &= ~SCTP_PCB_FLAGS_WAS_CONNECTED;
531644b7479bSRandall Stewart 						}
531744b7479bSRandall Stewart 					}
531844b7479bSRandall Stewart 					goto out;
531944b7479bSRandall Stewart 				}
532044b7479bSRandall Stewart 			}
5321c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EWOULDBLOCK);
5322f8829a4aSRandall Stewart 			error = EWOULDBLOCK;
532344b7479bSRandall Stewart 		}
5324f8829a4aSRandall Stewart 		goto out;
5325f8829a4aSRandall Stewart 	}
5326d06c82f1SRandall Stewart 	if (hold_sblock == 1) {
5327d06c82f1SRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
5328d06c82f1SRandall Stewart 		hold_sblock = 0;
5329d06c82f1SRandall Stewart 	}
5330f8829a4aSRandall Stewart 	/* we possibly have data we can read */
53313c503c28SRandall Stewart 	/* sa_ignore FREED_MEMORY */
5332f8829a4aSRandall Stewart 	control = TAILQ_FIRST(&inp->read_queue);
5333f8829a4aSRandall Stewart 	if (control == NULL) {
5334f8829a4aSRandall Stewart 		/*
5335f8829a4aSRandall Stewart 		 * This could be happening since the appender did the
5336f8829a4aSRandall Stewart 		 * increment but as not yet did the tailq insert onto the
5337f8829a4aSRandall Stewart 		 * read_queue
5338f8829a4aSRandall Stewart 		 */
5339f8829a4aSRandall Stewart 		if (hold_rlock == 0) {
5340f8829a4aSRandall Stewart 			SCTP_INP_READ_LOCK(inp);
5341f8829a4aSRandall Stewart 			hold_rlock = 1;
5342f8829a4aSRandall Stewart 		}
5343f8829a4aSRandall Stewart 		control = TAILQ_FIRST(&inp->read_queue);
5344f8829a4aSRandall Stewart 		if ((control == NULL) && (so->so_rcv.sb_cc != 0)) {
5345a5d547adSRandall Stewart #ifdef INVARIANTS
5346f8829a4aSRandall Stewart 			panic("Huh, its non zero and nothing on control?");
5347f8829a4aSRandall Stewart #endif
5348f8829a4aSRandall Stewart 			so->so_rcv.sb_cc = 0;
5349f8829a4aSRandall Stewart 		}
5350f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
5351f8829a4aSRandall Stewart 		hold_rlock = 0;
5352f8829a4aSRandall Stewart 		goto restart;
5353f8829a4aSRandall Stewart 	}
5354f8829a4aSRandall Stewart 	if ((control->length == 0) &&
5355f8829a4aSRandall Stewart 	    (control->do_not_ref_stcb)) {
5356f8829a4aSRandall Stewart 		/*
5357f8829a4aSRandall Stewart 		 * Clean up code for freeing assoc that left behind a
5358f8829a4aSRandall Stewart 		 * pdapi.. maybe a peer in EEOR that just closed after
5359f8829a4aSRandall Stewart 		 * sending and never indicated a EOR.
5360f8829a4aSRandall Stewart 		 */
5361f8829a4aSRandall Stewart 		if (hold_rlock == 0) {
5362f8829a4aSRandall Stewart 			hold_rlock = 1;
5363f8829a4aSRandall Stewart 			SCTP_INP_READ_LOCK(inp);
5364f8829a4aSRandall Stewart 		}
5365f8829a4aSRandall Stewart 		control->held_length = 0;
5366f8829a4aSRandall Stewart 		if (control->data) {
5367f8829a4aSRandall Stewart 			/* Hmm there is data here .. fix */
53684c9179adSRandall Stewart 			struct mbuf *m_tmp;
5369f8829a4aSRandall Stewart 			int cnt = 0;
5370f8829a4aSRandall Stewart 
53714c9179adSRandall Stewart 			m_tmp = control->data;
53724c9179adSRandall Stewart 			while (m_tmp) {
53734c9179adSRandall Stewart 				cnt += SCTP_BUF_LEN(m_tmp);
53744c9179adSRandall Stewart 				if (SCTP_BUF_NEXT(m_tmp) == NULL) {
53754c9179adSRandall Stewart 					control->tail_mbuf = m_tmp;
5376f8829a4aSRandall Stewart 					control->end_added = 1;
5377f8829a4aSRandall Stewart 				}
53784c9179adSRandall Stewart 				m_tmp = SCTP_BUF_NEXT(m_tmp);
5379f8829a4aSRandall Stewart 			}
5380f8829a4aSRandall Stewart 			control->length = cnt;
5381f8829a4aSRandall Stewart 		} else {
5382f8829a4aSRandall Stewart 			/* remove it */
5383f8829a4aSRandall Stewart 			TAILQ_REMOVE(&inp->read_queue, control, next);
5384f8829a4aSRandall Stewart 			/* Add back any hiddend data */
5385f8829a4aSRandall Stewart 			sctp_free_remote_addr(control->whoFrom);
5386f8829a4aSRandall Stewart 			sctp_free_a_readq(stcb, control);
5387f8829a4aSRandall Stewart 		}
5388f8829a4aSRandall Stewart 		if (hold_rlock) {
5389f8829a4aSRandall Stewart 			hold_rlock = 0;
5390f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
5391f8829a4aSRandall Stewart 		}
5392f8829a4aSRandall Stewart 		goto restart;
5393f8829a4aSRandall Stewart 	}
5394810ec536SMichael Tuexen 	if ((control->length == 0) &&
5395810ec536SMichael Tuexen 	    (control->end_added == 1)) {
5396810ec536SMichael Tuexen 		/*
5397810ec536SMichael Tuexen 		 * Do we also need to check for (control->pdapi_aborted ==
5398810ec536SMichael Tuexen 		 * 1)?
5399810ec536SMichael Tuexen 		 */
5400810ec536SMichael Tuexen 		if (hold_rlock == 0) {
5401810ec536SMichael Tuexen 			hold_rlock = 1;
5402810ec536SMichael Tuexen 			SCTP_INP_READ_LOCK(inp);
5403810ec536SMichael Tuexen 		}
5404810ec536SMichael Tuexen 		TAILQ_REMOVE(&inp->read_queue, control, next);
5405810ec536SMichael Tuexen 		if (control->data) {
5406810ec536SMichael Tuexen #ifdef INVARIANTS
5407810ec536SMichael Tuexen 			panic("control->data not null but control->length == 0");
5408810ec536SMichael Tuexen #else
5409810ec536SMichael Tuexen 			SCTP_PRINTF("Strange, data left in the control buffer. Cleaning up.\n");
5410810ec536SMichael Tuexen 			sctp_m_freem(control->data);
5411810ec536SMichael Tuexen 			control->data = NULL;
5412810ec536SMichael Tuexen #endif
5413810ec536SMichael Tuexen 		}
5414810ec536SMichael Tuexen 		if (control->aux_data) {
5415810ec536SMichael Tuexen 			sctp_m_free(control->aux_data);
5416810ec536SMichael Tuexen 			control->aux_data = NULL;
5417810ec536SMichael Tuexen 		}
5418810ec536SMichael Tuexen 		sctp_free_remote_addr(control->whoFrom);
5419810ec536SMichael Tuexen 		sctp_free_a_readq(stcb, control);
5420810ec536SMichael Tuexen 		if (hold_rlock) {
5421810ec536SMichael Tuexen 			hold_rlock = 0;
5422810ec536SMichael Tuexen 			SCTP_INP_READ_UNLOCK(inp);
5423810ec536SMichael Tuexen 		}
5424810ec536SMichael Tuexen 		goto restart;
5425810ec536SMichael Tuexen 	}
5426f8829a4aSRandall Stewart 	if (control->length == 0) {
5427f8829a4aSRandall Stewart 		if ((sctp_is_feature_on(inp, SCTP_PCB_FLAGS_FRAG_INTERLEAVE)) &&
5428f8829a4aSRandall Stewart 		    (filling_sinfo)) {
5429f8829a4aSRandall Stewart 			/* find a more suitable one then this */
5430f8829a4aSRandall Stewart 			ctl = TAILQ_NEXT(control, next);
5431f8829a4aSRandall Stewart 			while (ctl) {
54329a6142d8SRandall Stewart 				if ((ctl->stcb != control->stcb) && (ctl->length) &&
54339a6142d8SRandall Stewart 				    (ctl->some_taken ||
54346114cd96SRandall Stewart 				    (ctl->spec_flags & M_NOTIFICATION) ||
54359a6142d8SRandall Stewart 				    ((ctl->do_not_ref_stcb == 0) &&
54369a6142d8SRandall Stewart 				    (ctl->stcb->asoc.strmin[ctl->sinfo_stream].delivery_started == 0)))
54379a6142d8SRandall Stewart 				    ) {
54389a6142d8SRandall Stewart 					/*-
54399a6142d8SRandall Stewart 					 * If we have a different TCB next, and there is data
54409a6142d8SRandall Stewart 					 * present. If we have already taken some (pdapi), OR we can
54419a6142d8SRandall Stewart 					 * ref the tcb and no delivery as started on this stream, we
544217205eccSRandall Stewart 					 * take it. Note we allow a notification on a different
544317205eccSRandall Stewart 					 * assoc to be delivered..
54449a6142d8SRandall Stewart 					 */
54459a6142d8SRandall Stewart 					control = ctl;
54469a6142d8SRandall Stewart 					goto found_one;
54479a6142d8SRandall Stewart 				} else if ((sctp_is_feature_on(inp, SCTP_PCB_FLAGS_INTERLEAVE_STRMS)) &&
54489a6142d8SRandall Stewart 					    (ctl->length) &&
54499a6142d8SRandall Stewart 					    ((ctl->some_taken) ||
54509a6142d8SRandall Stewart 					    ((ctl->do_not_ref_stcb == 0) &&
545117205eccSRandall Stewart 					    ((ctl->spec_flags & M_NOTIFICATION) == 0) &&
54529a6142d8SRandall Stewart 					    (ctl->stcb->asoc.strmin[ctl->sinfo_stream].delivery_started == 0)))
54539a6142d8SRandall Stewart 				    ) {
54549a6142d8SRandall Stewart 					/*-
54559a6142d8SRandall Stewart 					 * If we have the same tcb, and there is data present, and we
54569a6142d8SRandall Stewart 					 * have the strm interleave feature present. Then if we have
54579a6142d8SRandall Stewart 					 * taken some (pdapi) or we can refer to tht tcb AND we have
54589a6142d8SRandall Stewart 					 * not started a delivery for this stream, we can take it.
545917205eccSRandall Stewart 					 * Note we do NOT allow a notificaiton on the same assoc to
546017205eccSRandall Stewart 					 * be delivered.
54619a6142d8SRandall Stewart 					 */
5462f8829a4aSRandall Stewart 					control = ctl;
5463f8829a4aSRandall Stewart 					goto found_one;
5464f8829a4aSRandall Stewart 				}
5465f8829a4aSRandall Stewart 				ctl = TAILQ_NEXT(ctl, next);
5466f8829a4aSRandall Stewart 			}
5467f8829a4aSRandall Stewart 		}
5468f8829a4aSRandall Stewart 		/*
5469f8829a4aSRandall Stewart 		 * if we reach here, not suitable replacement is available
5470f8829a4aSRandall Stewart 		 * <or> fragment interleave is NOT on. So stuff the sb_cc
5471f8829a4aSRandall Stewart 		 * into the our held count, and its time to sleep again.
5472f8829a4aSRandall Stewart 		 */
5473f8829a4aSRandall Stewart 		held_length = so->so_rcv.sb_cc;
5474f8829a4aSRandall Stewart 		control->held_length = so->so_rcv.sb_cc;
5475f8829a4aSRandall Stewart 		goto restart;
5476f8829a4aSRandall Stewart 	}
5477f8829a4aSRandall Stewart 	/* Clear the held length since there is something to read */
5478f8829a4aSRandall Stewart 	control->held_length = 0;
5479f8829a4aSRandall Stewart 	if (hold_rlock) {
5480f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
5481f8829a4aSRandall Stewart 		hold_rlock = 0;
5482f8829a4aSRandall Stewart 	}
5483f8829a4aSRandall Stewart found_one:
5484f8829a4aSRandall Stewart 	/*
5485f8829a4aSRandall Stewart 	 * If we reach here, control has a some data for us to read off.
5486f8829a4aSRandall Stewart 	 * Note that stcb COULD be NULL.
5487f8829a4aSRandall Stewart 	 */
54889c04b296SRandall Stewart 	control->some_taken++;
5489f8829a4aSRandall Stewart 	if (hold_sblock) {
5490f8829a4aSRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
5491f8829a4aSRandall Stewart 		hold_sblock = 0;
5492f8829a4aSRandall Stewart 	}
5493f8829a4aSRandall Stewart 	stcb = control->stcb;
5494f8829a4aSRandall Stewart 	if (stcb) {
54950696e120SRandall Stewart 		if ((control->do_not_ref_stcb == 0) &&
54960696e120SRandall Stewart 		    (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED)) {
549750cec919SRandall Stewart 			if (freecnt_applied == 0)
5498f8829a4aSRandall Stewart 				stcb = NULL;
5499f8829a4aSRandall Stewart 		} else if (control->do_not_ref_stcb == 0) {
5500f8829a4aSRandall Stewart 			/* you can't free it on me please */
5501f8829a4aSRandall Stewart 			/*
5502f8829a4aSRandall Stewart 			 * The lock on the socket buffer protects us so the
5503f8829a4aSRandall Stewart 			 * free code will stop. But since we used the
5504f8829a4aSRandall Stewart 			 * socketbuf lock and the sender uses the tcb_lock
5505f8829a4aSRandall Stewart 			 * to increment, we need to use the atomic add to
5506f8829a4aSRandall Stewart 			 * the refcnt
5507f8829a4aSRandall Stewart 			 */
5508d55b0b1bSRandall Stewart 			if (freecnt_applied) {
5509d55b0b1bSRandall Stewart #ifdef INVARIANTS
5510207304d4SRandall Stewart 				panic("refcnt already incremented");
5511d55b0b1bSRandall Stewart #else
5512d55b0b1bSRandall Stewart 				printf("refcnt already incremented?\n");
5513d55b0b1bSRandall Stewart #endif
5514d55b0b1bSRandall Stewart 			} else {
551550cec919SRandall Stewart 				atomic_add_int(&stcb->asoc.refcnt, 1);
5516f8829a4aSRandall Stewart 				freecnt_applied = 1;
5517d55b0b1bSRandall Stewart 			}
5518f8829a4aSRandall Stewart 			/*
5519f8829a4aSRandall Stewart 			 * Setup to remember how much we have not yet told
5520f8829a4aSRandall Stewart 			 * the peer our rwnd has opened up. Note we grab the
5521f8829a4aSRandall Stewart 			 * value from the tcb from last time. Note too that
55220696e120SRandall Stewart 			 * sack sending clears this when a sack is sent,
5523f8829a4aSRandall Stewart 			 * which is fine. Once we hit the rwnd_req, we then
5524f8829a4aSRandall Stewart 			 * will go to the sctp_user_rcvd() that will not
5525f8829a4aSRandall Stewart 			 * lock until it KNOWs it MUST send a WUP-SACK.
5526f8829a4aSRandall Stewart 			 */
5527f8829a4aSRandall Stewart 			freed_so_far = stcb->freed_by_sorcv_sincelast;
5528f8829a4aSRandall Stewart 			stcb->freed_by_sorcv_sincelast = 0;
5529f8829a4aSRandall Stewart 		}
5530f8829a4aSRandall Stewart 	}
55316114cd96SRandall Stewart 	if (stcb &&
55326114cd96SRandall Stewart 	    ((control->spec_flags & M_NOTIFICATION) == 0) &&
55336114cd96SRandall Stewart 	    control->do_not_ref_stcb == 0) {
5534d06c82f1SRandall Stewart 		stcb->asoc.strmin[control->sinfo_stream].delivery_started = 1;
5535d06c82f1SRandall Stewart 	}
5536f8829a4aSRandall Stewart 	/* First lets get off the sinfo and sockaddr info */
5537f8829a4aSRandall Stewart 	if ((sinfo) && filling_sinfo) {
5538f8829a4aSRandall Stewart 		memcpy(sinfo, control, sizeof(struct sctp_nonpad_sndrcvinfo));
5539f8829a4aSRandall Stewart 		nxt = TAILQ_NEXT(control, next);
5540f8829a4aSRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXT_RCVINFO)) {
5541f8829a4aSRandall Stewart 			struct sctp_extrcvinfo *s_extra;
5542f8829a4aSRandall Stewart 
5543f8829a4aSRandall Stewart 			s_extra = (struct sctp_extrcvinfo *)sinfo;
55449a6142d8SRandall Stewart 			if ((nxt) &&
55459a6142d8SRandall Stewart 			    (nxt->length)) {
55469a6142d8SRandall Stewart 				s_extra->sreinfo_next_flags = SCTP_NEXT_MSG_AVAIL;
5547f8829a4aSRandall Stewart 				if (nxt->sinfo_flags & SCTP_UNORDERED) {
55489a6142d8SRandall Stewart 					s_extra->sreinfo_next_flags |= SCTP_NEXT_MSG_IS_UNORDERED;
5549f8829a4aSRandall Stewart 				}
5550f42a358aSRandall Stewart 				if (nxt->spec_flags & M_NOTIFICATION) {
55519a6142d8SRandall Stewart 					s_extra->sreinfo_next_flags |= SCTP_NEXT_MSG_IS_NOTIFICATION;
5552f42a358aSRandall Stewart 				}
55539a6142d8SRandall Stewart 				s_extra->sreinfo_next_aid = nxt->sinfo_assoc_id;
55549a6142d8SRandall Stewart 				s_extra->sreinfo_next_length = nxt->length;
55559a6142d8SRandall Stewart 				s_extra->sreinfo_next_ppid = nxt->sinfo_ppid;
55569a6142d8SRandall Stewart 				s_extra->sreinfo_next_stream = nxt->sinfo_stream;
5557f8829a4aSRandall Stewart 				if (nxt->tail_mbuf != NULL) {
5558139bc87fSRandall Stewart 					if (nxt->end_added) {
55599a6142d8SRandall Stewart 						s_extra->sreinfo_next_flags |= SCTP_NEXT_MSG_ISCOMPLETE;
5560f8829a4aSRandall Stewart 					}
5561f8829a4aSRandall Stewart 				}
5562f8829a4aSRandall Stewart 			} else {
5563f8829a4aSRandall Stewart 				/*
5564f8829a4aSRandall Stewart 				 * we explicitly 0 this, since the memcpy
5565f8829a4aSRandall Stewart 				 * got some other things beyond the older
5566f8829a4aSRandall Stewart 				 * sinfo_ that is on the control's structure
5567f8829a4aSRandall Stewart 				 * :-D
5568f8829a4aSRandall Stewart 				 */
55699a6142d8SRandall Stewart 				nxt = NULL;
55709a6142d8SRandall Stewart 				s_extra->sreinfo_next_flags = SCTP_NO_NEXT_MSG;
55719a6142d8SRandall Stewart 				s_extra->sreinfo_next_aid = 0;
55729a6142d8SRandall Stewart 				s_extra->sreinfo_next_length = 0;
55739a6142d8SRandall Stewart 				s_extra->sreinfo_next_ppid = 0;
55749a6142d8SRandall Stewart 				s_extra->sreinfo_next_stream = 0;
5575f8829a4aSRandall Stewart 			}
5576f8829a4aSRandall Stewart 		}
5577f8829a4aSRandall Stewart 		/*
5578f8829a4aSRandall Stewart 		 * update off the real current cum-ack, if we have an stcb.
5579f8829a4aSRandall Stewart 		 */
55800696e120SRandall Stewart 		if ((control->do_not_ref_stcb == 0) && stcb)
5581f8829a4aSRandall Stewart 			sinfo->sinfo_cumtsn = stcb->asoc.cumulative_tsn;
5582f8829a4aSRandall Stewart 		/*
5583f8829a4aSRandall Stewart 		 * mask off the high bits, we keep the actual chunk bits in
5584f8829a4aSRandall Stewart 		 * there.
5585f8829a4aSRandall Stewart 		 */
5586f8829a4aSRandall Stewart 		sinfo->sinfo_flags &= 0x00ff;
55875f26a41dSRandall Stewart 		if ((control->sinfo_flags >> 8) & SCTP_DATA_UNORDERED) {
55885f26a41dSRandall Stewart 			sinfo->sinfo_flags |= SCTP_UNORDERED;
55895f26a41dSRandall Stewart 		}
5590f8829a4aSRandall Stewart 	}
559118e198d3SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
559218e198d3SRandall Stewart 	{
559318e198d3SRandall Stewart 		int index, newindex;
559418e198d3SRandall Stewart 		struct sctp_pcbtsn_rlog *entry;
559518e198d3SRandall Stewart 
559618e198d3SRandall Stewart 		do {
559718e198d3SRandall Stewart 			index = inp->readlog_index;
559818e198d3SRandall Stewart 			newindex = index + 1;
559918e198d3SRandall Stewart 			if (newindex >= SCTP_READ_LOG_SIZE) {
560018e198d3SRandall Stewart 				newindex = 0;
560118e198d3SRandall Stewart 			}
560218e198d3SRandall Stewart 		} while (atomic_cmpset_int(&inp->readlog_index, index, newindex) == 0);
560318e198d3SRandall Stewart 		entry = &inp->readlog[index];
560418e198d3SRandall Stewart 		entry->vtag = control->sinfo_assoc_id;
560518e198d3SRandall Stewart 		entry->strm = control->sinfo_stream;
560618e198d3SRandall Stewart 		entry->seq = control->sinfo_ssn;
560718e198d3SRandall Stewart 		entry->sz = control->length;
560818e198d3SRandall Stewart 		entry->flgs = control->sinfo_flags;
560918e198d3SRandall Stewart 	}
561018e198d3SRandall Stewart #endif
5611f8829a4aSRandall Stewart 	if (fromlen && from) {
5612f8829a4aSRandall Stewart 		struct sockaddr *to;
5613f8829a4aSRandall Stewart 
561442551e99SRandall Stewart #ifdef INET
5615baf3da66SRandall Stewart 		cp_len = min((size_t)fromlen, (size_t)control->whoFrom->ro._l_addr.sin.sin_len);
5616f8829a4aSRandall Stewart 		memcpy(from, &control->whoFrom->ro._l_addr, cp_len);
5617f8829a4aSRandall Stewart 		((struct sockaddr_in *)from)->sin_port = control->port_from;
5618f8829a4aSRandall Stewart #else
5619f8829a4aSRandall Stewart 		/* No AF_INET use AF_INET6 */
5620baf3da66SRandall Stewart 		cp_len = min((size_t)fromlen, (size_t)control->whoFrom->ro._l_addr.sin6.sin6_len);
5621f8829a4aSRandall Stewart 		memcpy(from, &control->whoFrom->ro._l_addr, cp_len);
5622f8829a4aSRandall Stewart 		((struct sockaddr_in6 *)from)->sin6_port = control->port_from;
5623f8829a4aSRandall Stewart #endif
5624f8829a4aSRandall Stewart 
5625f8829a4aSRandall Stewart 		to = from;
562642551e99SRandall Stewart #if defined(INET) && defined(INET6)
56275e2c2d87SRandall Stewart 		if ((sctp_is_feature_on(inp, SCTP_PCB_FLAGS_NEEDS_MAPPED_V4)) &&
5628f8829a4aSRandall Stewart 		    (to->sa_family == AF_INET) &&
5629f8829a4aSRandall Stewart 		    ((size_t)fromlen >= sizeof(struct sockaddr_in6))) {
5630f8829a4aSRandall Stewart 			struct sockaddr_in *sin;
5631f8829a4aSRandall Stewart 			struct sockaddr_in6 sin6;
5632f8829a4aSRandall Stewart 
5633f8829a4aSRandall Stewart 			sin = (struct sockaddr_in *)to;
5634f8829a4aSRandall Stewart 			bzero(&sin6, sizeof(sin6));
5635f8829a4aSRandall Stewart 			sin6.sin6_family = AF_INET6;
5636f8829a4aSRandall Stewart 			sin6.sin6_len = sizeof(struct sockaddr_in6);
5637d6af161aSRandall Stewart 			sin6.sin6_addr.s6_addr32[2] = htonl(0xffff);
5638f8829a4aSRandall Stewart 			bcopy(&sin->sin_addr,
5639d6af161aSRandall Stewart 			    &sin6.sin6_addr.s6_addr32[3],
5640d6af161aSRandall Stewart 			    sizeof(sin6.sin6_addr.s6_addr32[3]));
5641f8829a4aSRandall Stewart 			sin6.sin6_port = sin->sin_port;
5642f8829a4aSRandall Stewart 			memcpy(from, (caddr_t)&sin6, sizeof(sin6));
5643f8829a4aSRandall Stewart 		}
5644f8829a4aSRandall Stewart #endif
564542551e99SRandall Stewart #if defined(INET6)
5646f8829a4aSRandall Stewart 		{
5647f8829a4aSRandall Stewart 			struct sockaddr_in6 lsa6, *to6;
5648f8829a4aSRandall Stewart 
5649f8829a4aSRandall Stewart 			to6 = (struct sockaddr_in6 *)to;
5650f8829a4aSRandall Stewart 			sctp_recover_scope_mac(to6, (&lsa6));
5651f8829a4aSRandall Stewart 		}
5652f8829a4aSRandall Stewart #endif
5653f8829a4aSRandall Stewart 	}
5654f8829a4aSRandall Stewart 	/* now copy out what data we can */
5655f8829a4aSRandall Stewart 	if (mp == NULL) {
5656f8829a4aSRandall Stewart 		/* copy out each mbuf in the chain up to length */
5657f8829a4aSRandall Stewart get_more_data:
5658f8829a4aSRandall Stewart 		m = control->data;
5659f8829a4aSRandall Stewart 		while (m) {
5660f8829a4aSRandall Stewart 			/* Move out all we can */
5661f8829a4aSRandall Stewart 			cp_len = (int)uio->uio_resid;
5662139bc87fSRandall Stewart 			my_len = (int)SCTP_BUF_LEN(m);
5663f8829a4aSRandall Stewart 			if (cp_len > my_len) {
5664f8829a4aSRandall Stewart 				/* not enough in this buf */
5665f8829a4aSRandall Stewart 				cp_len = my_len;
5666f8829a4aSRandall Stewart 			}
5667f8829a4aSRandall Stewart 			if (hold_rlock) {
5668f8829a4aSRandall Stewart 				SCTP_INP_READ_UNLOCK(inp);
5669f8829a4aSRandall Stewart 				hold_rlock = 0;
5670f8829a4aSRandall Stewart 			}
5671f8829a4aSRandall Stewart 			if (cp_len > 0)
5672f8829a4aSRandall Stewart 				error = uiomove(mtod(m, char *), cp_len, uio);
5673f8829a4aSRandall Stewart 			/* re-read */
5674f8829a4aSRandall Stewart 			if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
5675f8829a4aSRandall Stewart 				goto release;
5676f8829a4aSRandall Stewart 			}
56770696e120SRandall Stewart 			if ((control->do_not_ref_stcb == 0) && stcb &&
5678f8829a4aSRandall Stewart 			    stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
5679f8829a4aSRandall Stewart 				no_rcv_needed = 1;
5680f8829a4aSRandall Stewart 			}
5681f8829a4aSRandall Stewart 			if (error) {
5682f8829a4aSRandall Stewart 				/* error we are out of here */
5683f8829a4aSRandall Stewart 				goto release;
5684f8829a4aSRandall Stewart 			}
5685139bc87fSRandall Stewart 			if ((SCTP_BUF_NEXT(m) == NULL) &&
5686139bc87fSRandall Stewart 			    (cp_len >= SCTP_BUF_LEN(m)) &&
5687f8829a4aSRandall Stewart 			    ((control->end_added == 0) ||
56880696e120SRandall Stewart 			    (control->end_added &&
56890696e120SRandall Stewart 			    (TAILQ_NEXT(control, next) == NULL)))
5690f8829a4aSRandall Stewart 			    ) {
5691f8829a4aSRandall Stewart 				SCTP_INP_READ_LOCK(inp);
5692f8829a4aSRandall Stewart 				hold_rlock = 1;
5693f8829a4aSRandall Stewart 			}
5694139bc87fSRandall Stewart 			if (cp_len == SCTP_BUF_LEN(m)) {
5695139bc87fSRandall Stewart 				if ((SCTP_BUF_NEXT(m) == NULL) &&
5696139bc87fSRandall Stewart 				    (control->end_added)) {
5697f8829a4aSRandall Stewart 					out_flags |= MSG_EOR;
56986114cd96SRandall Stewart 					if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
5699ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
5700f8829a4aSRandall Stewart 				}
5701139bc87fSRandall Stewart 				if (control->spec_flags & M_NOTIFICATION) {
5702f8829a4aSRandall Stewart 					out_flags |= MSG_NOTIFICATION;
5703f8829a4aSRandall Stewart 				}
5704f8829a4aSRandall Stewart 				/* we ate up the mbuf */
5705f8829a4aSRandall Stewart 				if (in_flags & MSG_PEEK) {
5706f8829a4aSRandall Stewart 					/* just looking */
5707139bc87fSRandall Stewart 					m = SCTP_BUF_NEXT(m);
5708f8829a4aSRandall Stewart 					copied_so_far += cp_len;
5709f8829a4aSRandall Stewart 				} else {
5710f8829a4aSRandall Stewart 					/* dispose of the mbuf */
5711b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5712f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv,
5713139bc87fSRandall Stewart 						    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
571480fefe0aSRandall Stewart 					}
5715f8829a4aSRandall Stewart 					sctp_sbfree(control, stcb, &so->so_rcv, m);
5716b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5717f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv,
5718f8829a4aSRandall Stewart 						    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
571980fefe0aSRandall Stewart 					}
5720f8829a4aSRandall Stewart 					embuf = m;
5721f8829a4aSRandall Stewart 					copied_so_far += cp_len;
5722f8829a4aSRandall Stewart 					freed_so_far += cp_len;
5723c4739e2fSRandall Stewart 					freed_so_far += MSIZE;
572418e198d3SRandall Stewart 					atomic_subtract_int(&control->length, cp_len);
5725f8829a4aSRandall Stewart 					control->data = sctp_m_free(m);
5726f8829a4aSRandall Stewart 					m = control->data;
5727f8829a4aSRandall Stewart 					/*
5728f8829a4aSRandall Stewart 					 * been through it all, must hold sb
5729f8829a4aSRandall Stewart 					 * lock ok to null tail
5730f8829a4aSRandall Stewart 					 */
5731f8829a4aSRandall Stewart 					if (control->data == NULL) {
5732a5d547adSRandall Stewart #ifdef INVARIANTS
5733f8829a4aSRandall Stewart 						if ((control->end_added == 0) ||
5734f8829a4aSRandall Stewart 						    (TAILQ_NEXT(control, next) == NULL)) {
5735f8829a4aSRandall Stewart 							/*
5736f8829a4aSRandall Stewart 							 * If the end is not
5737f8829a4aSRandall Stewart 							 * added, OR the
5738f8829a4aSRandall Stewart 							 * next is NOT null
5739f8829a4aSRandall Stewart 							 * we MUST have the
5740f8829a4aSRandall Stewart 							 * lock.
5741f8829a4aSRandall Stewart 							 */
5742f8829a4aSRandall Stewart 							if (mtx_owned(&inp->inp_rdata_mtx) == 0) {
5743f8829a4aSRandall Stewart 								panic("Hmm we don't own the lock?");
5744f8829a4aSRandall Stewart 							}
5745f8829a4aSRandall Stewart 						}
5746f8829a4aSRandall Stewart #endif
5747f8829a4aSRandall Stewart 						control->tail_mbuf = NULL;
5748a5d547adSRandall Stewart #ifdef INVARIANTS
5749f8829a4aSRandall Stewart 						if ((control->end_added) && ((out_flags & MSG_EOR) == 0)) {
5750f8829a4aSRandall Stewart 							panic("end_added, nothing left and no MSG_EOR");
5751f8829a4aSRandall Stewart 						}
5752f8829a4aSRandall Stewart #endif
5753f8829a4aSRandall Stewart 					}
5754f8829a4aSRandall Stewart 				}
5755f8829a4aSRandall Stewart 			} else {
5756f8829a4aSRandall Stewart 				/* Do we need to trim the mbuf? */
5757139bc87fSRandall Stewart 				if (control->spec_flags & M_NOTIFICATION) {
5758f8829a4aSRandall Stewart 					out_flags |= MSG_NOTIFICATION;
5759f8829a4aSRandall Stewart 				}
5760f8829a4aSRandall Stewart 				if ((in_flags & MSG_PEEK) == 0) {
5761139bc87fSRandall Stewart 					SCTP_BUF_RESV_UF(m, cp_len);
5762139bc87fSRandall Stewart 					SCTP_BUF_LEN(m) -= cp_len;
5763b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5764f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, cp_len);
576580fefe0aSRandall Stewart 					}
5766f8829a4aSRandall Stewart 					atomic_subtract_int(&so->so_rcv.sb_cc, cp_len);
57670696e120SRandall Stewart 					if ((control->do_not_ref_stcb == 0) &&
57680696e120SRandall Stewart 					    stcb) {
5769f8829a4aSRandall Stewart 						atomic_subtract_int(&stcb->asoc.sb_cc, cp_len);
5770f8829a4aSRandall Stewart 					}
5771f8829a4aSRandall Stewart 					copied_so_far += cp_len;
5772f8829a4aSRandall Stewart 					embuf = m;
5773f8829a4aSRandall Stewart 					freed_so_far += cp_len;
5774c4739e2fSRandall Stewart 					freed_so_far += MSIZE;
5775b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5776f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv, control->do_not_ref_stcb ? NULL : stcb,
5777f8829a4aSRandall Stewart 						    SCTP_LOG_SBRESULT, 0);
577880fefe0aSRandall Stewart 					}
577918e198d3SRandall Stewart 					atomic_subtract_int(&control->length, cp_len);
5780f8829a4aSRandall Stewart 				} else {
5781f8829a4aSRandall Stewart 					copied_so_far += cp_len;
5782f8829a4aSRandall Stewart 				}
5783f8829a4aSRandall Stewart 			}
5784d61a0ae0SRandall Stewart 			if ((out_flags & MSG_EOR) || (uio->uio_resid == 0)) {
5785f8829a4aSRandall Stewart 				break;
5786f8829a4aSRandall Stewart 			}
5787f8829a4aSRandall Stewart 			if (((stcb) && (in_flags & MSG_PEEK) == 0) &&
5788f8829a4aSRandall Stewart 			    (control->do_not_ref_stcb == 0) &&
5789f8829a4aSRandall Stewart 			    (freed_so_far >= rwnd_req)) {
5790f8829a4aSRandall Stewart 				sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
5791f8829a4aSRandall Stewart 			}
5792f8829a4aSRandall Stewart 		}		/* end while(m) */
5793f8829a4aSRandall Stewart 		/*
5794f8829a4aSRandall Stewart 		 * At this point we have looked at it all and we either have
5795f8829a4aSRandall Stewart 		 * a MSG_EOR/or read all the user wants... <OR>
5796f8829a4aSRandall Stewart 		 * control->length == 0.
5797f8829a4aSRandall Stewart 		 */
5798d61a0ae0SRandall Stewart 		if ((out_flags & MSG_EOR) && ((in_flags & MSG_PEEK) == 0)) {
5799f8829a4aSRandall Stewart 			/* we are done with this control */
5800f8829a4aSRandall Stewart 			if (control->length == 0) {
5801f8829a4aSRandall Stewart 				if (control->data) {
5802a5d547adSRandall Stewart #ifdef INVARIANTS
5803f8829a4aSRandall Stewart 					panic("control->data not null at read eor?");
5804f8829a4aSRandall Stewart #else
5805ad81507eSRandall Stewart 					SCTP_PRINTF("Strange, data left in the control buffer .. invarients would panic?\n");
5806f8829a4aSRandall Stewart 					sctp_m_freem(control->data);
5807f8829a4aSRandall Stewart 					control->data = NULL;
5808f8829a4aSRandall Stewart #endif
5809f8829a4aSRandall Stewart 				}
5810f8829a4aSRandall Stewart 		done_with_control:
5811f8829a4aSRandall Stewart 				if (TAILQ_NEXT(control, next) == NULL) {
5812f8829a4aSRandall Stewart 					/*
5813f8829a4aSRandall Stewart 					 * If we don't have a next we need a
5814b201f536SRandall Stewart 					 * lock, if there is a next
5815b201f536SRandall Stewart 					 * interrupt is filling ahead of us
5816b201f536SRandall Stewart 					 * and we don't need a lock to
5817b201f536SRandall Stewart 					 * remove this guy (which is the
5818b201f536SRandall Stewart 					 * head of the queue).
5819f8829a4aSRandall Stewart 					 */
5820f8829a4aSRandall Stewart 					if (hold_rlock == 0) {
5821f8829a4aSRandall Stewart 						SCTP_INP_READ_LOCK(inp);
5822f8829a4aSRandall Stewart 						hold_rlock = 1;
5823f8829a4aSRandall Stewart 					}
5824f8829a4aSRandall Stewart 				}
5825f8829a4aSRandall Stewart 				TAILQ_REMOVE(&inp->read_queue, control, next);
5826f8829a4aSRandall Stewart 				/* Add back any hiddend data */
5827f8829a4aSRandall Stewart 				if (control->held_length) {
5828f8829a4aSRandall Stewart 					held_length = 0;
5829f8829a4aSRandall Stewart 					control->held_length = 0;
5830f8829a4aSRandall Stewart 					wakeup_read_socket = 1;
5831f8829a4aSRandall Stewart 				}
583217205eccSRandall Stewart 				if (control->aux_data) {
583317205eccSRandall Stewart 					sctp_m_free(control->aux_data);
583417205eccSRandall Stewart 					control->aux_data = NULL;
583517205eccSRandall Stewart 				}
5836f8829a4aSRandall Stewart 				no_rcv_needed = control->do_not_ref_stcb;
5837f8829a4aSRandall Stewart 				sctp_free_remote_addr(control->whoFrom);
5838f8829a4aSRandall Stewart 				control->data = NULL;
5839f8829a4aSRandall Stewart 				sctp_free_a_readq(stcb, control);
5840f8829a4aSRandall Stewart 				control = NULL;
58410696e120SRandall Stewart 				if ((freed_so_far >= rwnd_req) &&
58420696e120SRandall Stewart 				    (no_rcv_needed == 0))
5843f8829a4aSRandall Stewart 					sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
5844f8829a4aSRandall Stewart 
5845f8829a4aSRandall Stewart 			} else {
5846f8829a4aSRandall Stewart 				/*
5847f8829a4aSRandall Stewart 				 * The user did not read all of this
5848f8829a4aSRandall Stewart 				 * message, turn off the returned MSG_EOR
5849f8829a4aSRandall Stewart 				 * since we are leaving more behind on the
5850f8829a4aSRandall Stewart 				 * control to read.
5851f8829a4aSRandall Stewart 				 */
5852a5d547adSRandall Stewart #ifdef INVARIANTS
58530696e120SRandall Stewart 				if (control->end_added &&
58540696e120SRandall Stewart 				    (control->data == NULL) &&
5855f8829a4aSRandall Stewart 				    (control->tail_mbuf == NULL)) {
5856f8829a4aSRandall Stewart 					panic("Gak, control->length is corrupt?");
5857f8829a4aSRandall Stewart 				}
5858f8829a4aSRandall Stewart #endif
5859f8829a4aSRandall Stewart 				no_rcv_needed = control->do_not_ref_stcb;
5860f8829a4aSRandall Stewart 				out_flags &= ~MSG_EOR;
5861f8829a4aSRandall Stewart 			}
5862f8829a4aSRandall Stewart 		}
5863f8829a4aSRandall Stewart 		if (out_flags & MSG_EOR) {
5864f8829a4aSRandall Stewart 			goto release;
5865f8829a4aSRandall Stewart 		}
5866f8829a4aSRandall Stewart 		if ((uio->uio_resid == 0) ||
5867f8829a4aSRandall Stewart 		    ((in_eeor_mode) && (copied_so_far >= max(so->so_rcv.sb_lowat, 1)))
5868f8829a4aSRandall Stewart 		    ) {
5869f8829a4aSRandall Stewart 			goto release;
5870f8829a4aSRandall Stewart 		}
5871f8829a4aSRandall Stewart 		/*
5872f8829a4aSRandall Stewart 		 * If I hit here the receiver wants more and this message is
5873f8829a4aSRandall Stewart 		 * NOT done (pd-api). So two questions. Can we block? if not
5874f8829a4aSRandall Stewart 		 * we are done. Did the user NOT set MSG_WAITALL?
5875f8829a4aSRandall Stewart 		 */
5876f8829a4aSRandall Stewart 		if (block_allowed == 0) {
5877f8829a4aSRandall Stewart 			goto release;
5878f8829a4aSRandall Stewart 		}
5879f8829a4aSRandall Stewart 		/*
5880f8829a4aSRandall Stewart 		 * We need to wait for more data a few things: - We don't
5881f8829a4aSRandall Stewart 		 * sbunlock() so we don't get someone else reading. - We
5882f8829a4aSRandall Stewart 		 * must be sure to account for the case where what is added
5883f8829a4aSRandall Stewart 		 * is NOT to our control when we wakeup.
5884f8829a4aSRandall Stewart 		 */
5885f8829a4aSRandall Stewart 
5886f8829a4aSRandall Stewart 		/*
5887f8829a4aSRandall Stewart 		 * Do we need to tell the transport a rwnd update might be
5888f8829a4aSRandall Stewart 		 * needed before we go to sleep?
5889f8829a4aSRandall Stewart 		 */
5890f8829a4aSRandall Stewart 		if (((stcb) && (in_flags & MSG_PEEK) == 0) &&
5891f8829a4aSRandall Stewart 		    ((freed_so_far >= rwnd_req) &&
5892f8829a4aSRandall Stewart 		    (control->do_not_ref_stcb == 0) &&
5893f8829a4aSRandall Stewart 		    (no_rcv_needed == 0))) {
5894f8829a4aSRandall Stewart 			sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
5895f8829a4aSRandall Stewart 		}
5896f8829a4aSRandall Stewart wait_some_more:
589744b7479bSRandall Stewart 		if (so->so_rcv.sb_state & SBS_CANTRCVMORE) {
5898f8829a4aSRandall Stewart 			goto release;
5899f8829a4aSRandall Stewart 		}
5900f8829a4aSRandall Stewart 		if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE)
5901f8829a4aSRandall Stewart 			goto release;
5902f8829a4aSRandall Stewart 
5903f8829a4aSRandall Stewart 		if (hold_rlock == 1) {
5904f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
5905f8829a4aSRandall Stewart 			hold_rlock = 0;
5906f8829a4aSRandall Stewart 		}
5907f8829a4aSRandall Stewart 		if (hold_sblock == 0) {
5908f8829a4aSRandall Stewart 			SOCKBUF_LOCK(&so->so_rcv);
5909f8829a4aSRandall Stewart 			hold_sblock = 1;
5910f8829a4aSRandall Stewart 		}
5911851b7298SRandall Stewart 		if ((copied_so_far) && (control->length == 0) &&
5912851b7298SRandall Stewart 		    (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_FRAG_INTERLEAVE))
5913851b7298SRandall Stewart 		    ) {
5914851b7298SRandall Stewart 			goto release;
5915851b7298SRandall Stewart 		}
5916f8829a4aSRandall Stewart 		if (so->so_rcv.sb_cc <= control->held_length) {
5917f8829a4aSRandall Stewart 			error = sbwait(&so->so_rcv);
5918f8829a4aSRandall Stewart 			if (error) {
5919f8829a4aSRandall Stewart 				goto release;
5920f8829a4aSRandall Stewart 			}
5921f8829a4aSRandall Stewart 			control->held_length = 0;
5922f8829a4aSRandall Stewart 		}
5923f8829a4aSRandall Stewart 		if (hold_sblock) {
5924f8829a4aSRandall Stewart 			SOCKBUF_UNLOCK(&so->so_rcv);
5925f8829a4aSRandall Stewart 			hold_sblock = 0;
5926f8829a4aSRandall Stewart 		}
5927f8829a4aSRandall Stewart 		if (control->length == 0) {
5928f8829a4aSRandall Stewart 			/* still nothing here */
5929f8829a4aSRandall Stewart 			if (control->end_added == 1) {
5930f8829a4aSRandall Stewart 				/* he aborted, or is done i.e.did a shutdown */
5931f8829a4aSRandall Stewart 				out_flags |= MSG_EOR;
59329a6142d8SRandall Stewart 				if (control->pdapi_aborted) {
59336114cd96SRandall Stewart 					if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
5934ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
59359a6142d8SRandall Stewart 
593603b0b021SRandall Stewart 					out_flags |= MSG_TRUNC;
59379a6142d8SRandall Stewart 				} else {
59386114cd96SRandall Stewart 					if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
5939ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
59409a6142d8SRandall Stewart 				}
5941f8829a4aSRandall Stewart 				goto done_with_control;
5942f8829a4aSRandall Stewart 			}
5943f8829a4aSRandall Stewart 			if (so->so_rcv.sb_cc > held_length) {
5944f8829a4aSRandall Stewart 				control->held_length = so->so_rcv.sb_cc;
5945f8829a4aSRandall Stewart 				held_length = 0;
5946f8829a4aSRandall Stewart 			}
5947f8829a4aSRandall Stewart 			goto wait_some_more;
5948f8829a4aSRandall Stewart 		} else if (control->data == NULL) {
594950cec919SRandall Stewart 			/*
595050cec919SRandall Stewart 			 * we must re-sync since data is probably being
595150cec919SRandall Stewart 			 * added
595250cec919SRandall Stewart 			 */
595350cec919SRandall Stewart 			SCTP_INP_READ_LOCK(inp);
595450cec919SRandall Stewart 			if ((control->length > 0) && (control->data == NULL)) {
595550cec919SRandall Stewart 				/*
595650cec919SRandall Stewart 				 * big trouble.. we have the lock and its
595750cec919SRandall Stewart 				 * corrupt?
595850cec919SRandall Stewart 				 */
59599c04b296SRandall Stewart #ifdef INVARIANTS
5960f8829a4aSRandall Stewart 				panic("Impossible data==NULL length !=0");
59619c04b296SRandall Stewart #endif
59629c04b296SRandall Stewart 				out_flags |= MSG_EOR;
59639c04b296SRandall Stewart 				out_flags |= MSG_TRUNC;
59649c04b296SRandall Stewart 				control->length = 0;
59659c04b296SRandall Stewart 				SCTP_INP_READ_UNLOCK(inp);
59669c04b296SRandall Stewart 				goto done_with_control;
5967f8829a4aSRandall Stewart 			}
596850cec919SRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
596950cec919SRandall Stewart 			/* We will fall around to get more data */
597050cec919SRandall Stewart 		}
5971f8829a4aSRandall Stewart 		goto get_more_data;
5972f8829a4aSRandall Stewart 	} else {
597317205eccSRandall Stewart 		/*-
597417205eccSRandall Stewart 		 * Give caller back the mbuf chain,
597517205eccSRandall Stewart 		 * store in uio_resid the length
5976f8829a4aSRandall Stewart 		 */
597717205eccSRandall Stewart 		wakeup_read_socket = 0;
5978f8829a4aSRandall Stewart 		if ((control->end_added == 0) ||
5979f8829a4aSRandall Stewart 		    (TAILQ_NEXT(control, next) == NULL)) {
5980f8829a4aSRandall Stewart 			/* Need to get rlock */
5981f8829a4aSRandall Stewart 			if (hold_rlock == 0) {
5982f8829a4aSRandall Stewart 				SCTP_INP_READ_LOCK(inp);
5983f8829a4aSRandall Stewart 				hold_rlock = 1;
5984f8829a4aSRandall Stewart 			}
5985f8829a4aSRandall Stewart 		}
5986139bc87fSRandall Stewart 		if (control->end_added) {
5987f8829a4aSRandall Stewart 			out_flags |= MSG_EOR;
59886114cd96SRandall Stewart 			if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
5989ee7f9857SRandall Stewart 				control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
5990f8829a4aSRandall Stewart 		}
5991139bc87fSRandall Stewart 		if (control->spec_flags & M_NOTIFICATION) {
5992f8829a4aSRandall Stewart 			out_flags |= MSG_NOTIFICATION;
5993f8829a4aSRandall Stewart 		}
599417205eccSRandall Stewart 		uio->uio_resid = control->length;
5995f8829a4aSRandall Stewart 		*mp = control->data;
5996f8829a4aSRandall Stewart 		m = control->data;
5997f8829a4aSRandall Stewart 		while (m) {
5998b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5999f8829a4aSRandall Stewart 				sctp_sblog(&so->so_rcv,
6000139bc87fSRandall Stewart 				    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
600180fefe0aSRandall Stewart 			}
6002f8829a4aSRandall Stewart 			sctp_sbfree(control, stcb, &so->so_rcv, m);
6003139bc87fSRandall Stewart 			freed_so_far += SCTP_BUF_LEN(m);
6004c4739e2fSRandall Stewart 			freed_so_far += MSIZE;
6005b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
6006f8829a4aSRandall Stewart 				sctp_sblog(&so->so_rcv,
6007f8829a4aSRandall Stewart 				    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
600880fefe0aSRandall Stewart 			}
6009139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
6010f8829a4aSRandall Stewart 		}
6011f8829a4aSRandall Stewart 		control->data = control->tail_mbuf = NULL;
6012f8829a4aSRandall Stewart 		control->length = 0;
6013f8829a4aSRandall Stewart 		if (out_flags & MSG_EOR) {
6014f8829a4aSRandall Stewart 			/* Done with this control */
6015f8829a4aSRandall Stewart 			goto done_with_control;
6016f8829a4aSRandall Stewart 		}
6017f8829a4aSRandall Stewart 	}
6018f8829a4aSRandall Stewart release:
6019f8829a4aSRandall Stewart 	if (hold_rlock == 1) {
6020f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
6021f8829a4aSRandall Stewart 		hold_rlock = 0;
6022f8829a4aSRandall Stewart 	}
60237abab911SRobert Watson 	if (hold_sblock == 1) {
60247abab911SRobert Watson 		SOCKBUF_UNLOCK(&so->so_rcv);
60257abab911SRobert Watson 		hold_sblock = 0;
6026f8829a4aSRandall Stewart 	}
6027f8829a4aSRandall Stewart 	sbunlock(&so->so_rcv);
60287abab911SRobert Watson 	sockbuf_lock = 0;
6029f8829a4aSRandall Stewart 
6030f8829a4aSRandall Stewart release_unlocked:
6031f8829a4aSRandall Stewart 	if (hold_sblock) {
6032f8829a4aSRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
6033f8829a4aSRandall Stewart 		hold_sblock = 0;
6034f8829a4aSRandall Stewart 	}
6035f8829a4aSRandall Stewart 	if ((stcb) && (in_flags & MSG_PEEK) == 0) {
6036f8829a4aSRandall Stewart 		if ((freed_so_far >= rwnd_req) &&
6037f8829a4aSRandall Stewart 		    (control && (control->do_not_ref_stcb == 0)) &&
6038f8829a4aSRandall Stewart 		    (no_rcv_needed == 0))
6039f8829a4aSRandall Stewart 			sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
6040f8829a4aSRandall Stewart 	}
6041f8829a4aSRandall Stewart out:
60421b9f62a0SRandall Stewart 	if (msg_flags) {
60431b9f62a0SRandall Stewart 		*msg_flags = out_flags;
60441b9f62a0SRandall Stewart 	}
60459a6142d8SRandall Stewart 	if (((out_flags & MSG_EOR) == 0) &&
60469a6142d8SRandall Stewart 	    ((in_flags & MSG_PEEK) == 0) &&
60479a6142d8SRandall Stewart 	    (sinfo) &&
60489a6142d8SRandall Stewart 	    (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXT_RCVINFO))) {
60499a6142d8SRandall Stewart 		struct sctp_extrcvinfo *s_extra;
60509a6142d8SRandall Stewart 
60519a6142d8SRandall Stewart 		s_extra = (struct sctp_extrcvinfo *)sinfo;
60529a6142d8SRandall Stewart 		s_extra->sreinfo_next_flags = SCTP_NO_NEXT_MSG;
60539a6142d8SRandall Stewart 	}
6054f8829a4aSRandall Stewart 	if (hold_rlock == 1) {
6055f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
6056f8829a4aSRandall Stewart 		hold_rlock = 0;
6057f8829a4aSRandall Stewart 	}
6058f8829a4aSRandall Stewart 	if (hold_sblock) {
6059f8829a4aSRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
6060f8829a4aSRandall Stewart 		hold_sblock = 0;
6061f8829a4aSRandall Stewart 	}
60627abab911SRobert Watson 	if (sockbuf_lock) {
60637abab911SRobert Watson 		sbunlock(&so->so_rcv);
60647abab911SRobert Watson 	}
606550cec919SRandall Stewart 	if (freecnt_applied) {
6066f8829a4aSRandall Stewart 		/*
6067f8829a4aSRandall Stewart 		 * The lock on the socket buffer protects us so the free
6068f8829a4aSRandall Stewart 		 * code will stop. But since we used the socketbuf lock and
6069f8829a4aSRandall Stewart 		 * the sender uses the tcb_lock to increment, we need to use
6070f8829a4aSRandall Stewart 		 * the atomic add to the refcnt.
6071f8829a4aSRandall Stewart 		 */
607250cec919SRandall Stewart 		if (stcb == NULL) {
6073df6e0cc3SRandall Stewart #ifdef INVARIANTS
607450cec919SRandall Stewart 			panic("stcb for refcnt has gone NULL?");
6075df6e0cc3SRandall Stewart 			goto stage_left;
6076df6e0cc3SRandall Stewart #else
6077df6e0cc3SRandall Stewart 			goto stage_left;
6078df6e0cc3SRandall Stewart #endif
607950cec919SRandall Stewart 		}
608050cec919SRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, -1);
6081f8829a4aSRandall Stewart 		freecnt_applied = 0;
6082f8829a4aSRandall Stewart 		/* Save the value back for next time */
6083f8829a4aSRandall Stewart 		stcb->freed_by_sorcv_sincelast = freed_so_far;
6084f8829a4aSRandall Stewart 	}
6085b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
6086f8829a4aSRandall Stewart 		if (stcb) {
6087f8829a4aSRandall Stewart 			sctp_misc_ints(SCTP_SORECV_DONE,
6088f8829a4aSRandall Stewart 			    freed_so_far,
6089f8829a4aSRandall Stewart 			    ((uio) ? (slen - uio->uio_resid) : slen),
6090f8829a4aSRandall Stewart 			    stcb->asoc.my_rwnd,
6091f8829a4aSRandall Stewart 			    so->so_rcv.sb_cc);
6092f8829a4aSRandall Stewart 		} else {
6093f8829a4aSRandall Stewart 			sctp_misc_ints(SCTP_SORECV_DONE,
6094f8829a4aSRandall Stewart 			    freed_so_far,
6095f8829a4aSRandall Stewart 			    ((uio) ? (slen - uio->uio_resid) : slen),
6096f8829a4aSRandall Stewart 			    0,
6097f8829a4aSRandall Stewart 			    so->so_rcv.sb_cc);
6098f8829a4aSRandall Stewart 		}
609980fefe0aSRandall Stewart 	}
6100df6e0cc3SRandall Stewart stage_left:
6101f8829a4aSRandall Stewart 	if (wakeup_read_socket) {
6102f8829a4aSRandall Stewart 		sctp_sorwakeup(inp, so);
6103f8829a4aSRandall Stewart 	}
6104f8829a4aSRandall Stewart 	return (error);
6105f8829a4aSRandall Stewart }
6106f8829a4aSRandall Stewart 
6107f8829a4aSRandall Stewart 
6108f8829a4aSRandall Stewart #ifdef SCTP_MBUF_LOGGING
6109f8829a4aSRandall Stewart struct mbuf *
6110f8829a4aSRandall Stewart sctp_m_free(struct mbuf *m)
6111f8829a4aSRandall Stewart {
6112b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_MBUF_LOGGING_ENABLE) {
6113139bc87fSRandall Stewart 		if (SCTP_BUF_IS_EXTENDED(m)) {
6114f8829a4aSRandall Stewart 			sctp_log_mb(m, SCTP_MBUF_IFREE);
6115f8829a4aSRandall Stewart 		}
611680fefe0aSRandall Stewart 	}
6117f8829a4aSRandall Stewart 	return (m_free(m));
6118f8829a4aSRandall Stewart }
6119f8829a4aSRandall Stewart 
6120f8829a4aSRandall Stewart void
6121f8829a4aSRandall Stewart sctp_m_freem(struct mbuf *mb)
6122f8829a4aSRandall Stewart {
6123f8829a4aSRandall Stewart 	while (mb != NULL)
6124f8829a4aSRandall Stewart 		mb = sctp_m_free(mb);
6125f8829a4aSRandall Stewart }
6126f8829a4aSRandall Stewart 
6127f8829a4aSRandall Stewart #endif
6128f8829a4aSRandall Stewart 
612942551e99SRandall Stewart int
613042551e99SRandall Stewart sctp_dynamic_set_primary(struct sockaddr *sa, uint32_t vrf_id)
613142551e99SRandall Stewart {
613242551e99SRandall Stewart 	/*
613342551e99SRandall Stewart 	 * Given a local address. For all associations that holds the
613442551e99SRandall Stewart 	 * address, request a peer-set-primary.
613542551e99SRandall Stewart 	 */
613642551e99SRandall Stewart 	struct sctp_ifa *ifa;
613742551e99SRandall Stewart 	struct sctp_laddr *wi;
613842551e99SRandall Stewart 
613942551e99SRandall Stewart 	ifa = sctp_find_ifa_by_addr(sa, vrf_id, 0);
614042551e99SRandall Stewart 	if (ifa == NULL) {
6141c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EADDRNOTAVAIL);
614242551e99SRandall Stewart 		return (EADDRNOTAVAIL);
614342551e99SRandall Stewart 	}
614442551e99SRandall Stewart 	/*
614542551e99SRandall Stewart 	 * Now that we have the ifa we must awaken the iterator with this
614642551e99SRandall Stewart 	 * message.
614742551e99SRandall Stewart 	 */
6148b3f1ea41SRandall Stewart 	wi = SCTP_ZONE_GET(SCTP_BASE_INFO(ipi_zone_laddr), struct sctp_laddr);
614942551e99SRandall Stewart 	if (wi == NULL) {
6150c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
615142551e99SRandall Stewart 		return (ENOMEM);
615242551e99SRandall Stewart 	}
615342551e99SRandall Stewart 	/* Now incr the count and int wi structure */
615442551e99SRandall Stewart 	SCTP_INCR_LADDR_COUNT();
615542551e99SRandall Stewart 	bzero(wi, sizeof(*wi));
6156d61a0ae0SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&wi->start_time);
615742551e99SRandall Stewart 	wi->ifa = ifa;
615842551e99SRandall Stewart 	wi->action = SCTP_SET_PRIM_ADDR;
615942551e99SRandall Stewart 	atomic_add_int(&ifa->refcount, 1);
616042551e99SRandall Stewart 
616142551e99SRandall Stewart 	/* Now add it to the work queue */
616242551e99SRandall Stewart 	SCTP_IPI_ITERATOR_WQ_LOCK();
616342551e99SRandall Stewart 	/*
616442551e99SRandall Stewart 	 * Should this really be a tailq? As it is we will process the
616542551e99SRandall Stewart 	 * newest first :-0
616642551e99SRandall Stewart 	 */
6167b3f1ea41SRandall Stewart 	LIST_INSERT_HEAD(&SCTP_BASE_INFO(addr_wq), wi, sctp_nxt_addr);
61687a9b5b20SMichael Tuexen 	SCTP_IPI_ITERATOR_WQ_UNLOCK();
616942551e99SRandall Stewart 	sctp_timer_start(SCTP_TIMER_TYPE_ADDR_WQ,
617042551e99SRandall Stewart 	    (struct sctp_inpcb *)NULL,
617142551e99SRandall Stewart 	    (struct sctp_tcb *)NULL,
617242551e99SRandall Stewart 	    (struct sctp_nets *)NULL);
617342551e99SRandall Stewart 	return (0);
617442551e99SRandall Stewart }
617542551e99SRandall Stewart 
617642551e99SRandall Stewart 
6177f8829a4aSRandall Stewart int
617817205eccSRandall Stewart sctp_soreceive(struct socket *so,
617917205eccSRandall Stewart     struct sockaddr **psa,
618017205eccSRandall Stewart     struct uio *uio,
618117205eccSRandall Stewart     struct mbuf **mp0,
618217205eccSRandall Stewart     struct mbuf **controlp,
618317205eccSRandall Stewart     int *flagsp)
6184f8829a4aSRandall Stewart {
6185f8829a4aSRandall Stewart 	int error, fromlen;
6186f8829a4aSRandall Stewart 	uint8_t sockbuf[256];
6187f8829a4aSRandall Stewart 	struct sockaddr *from;
6188f8829a4aSRandall Stewart 	struct sctp_extrcvinfo sinfo;
6189f8829a4aSRandall Stewart 	int filling_sinfo = 1;
6190f8829a4aSRandall Stewart 	struct sctp_inpcb *inp;
6191f8829a4aSRandall Stewart 
6192f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)so->so_pcb;
6193f8829a4aSRandall Stewart 	/* pickup the assoc we are reading from */
6194f8829a4aSRandall Stewart 	if (inp == NULL) {
6195c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6196f8829a4aSRandall Stewart 		return (EINVAL);
6197f8829a4aSRandall Stewart 	}
6198f8829a4aSRandall Stewart 	if ((sctp_is_feature_off(inp,
6199f8829a4aSRandall Stewart 	    SCTP_PCB_FLAGS_RECVDATAIOEVNT)) ||
6200f8829a4aSRandall Stewart 	    (controlp == NULL)) {
6201f8829a4aSRandall Stewart 		/* user does not want the sndrcv ctl */
6202f8829a4aSRandall Stewart 		filling_sinfo = 0;
6203f8829a4aSRandall Stewart 	}
6204f8829a4aSRandall Stewart 	if (psa) {
6205f8829a4aSRandall Stewart 		from = (struct sockaddr *)sockbuf;
6206f8829a4aSRandall Stewart 		fromlen = sizeof(sockbuf);
6207f8829a4aSRandall Stewart 		from->sa_len = 0;
6208f8829a4aSRandall Stewart 	} else {
6209f8829a4aSRandall Stewart 		from = NULL;
6210f8829a4aSRandall Stewart 		fromlen = 0;
6211f8829a4aSRandall Stewart 	}
6212f8829a4aSRandall Stewart 
6213f8829a4aSRandall Stewart 	error = sctp_sorecvmsg(so, uio, mp0, from, fromlen, flagsp,
6214f8829a4aSRandall Stewart 	    (struct sctp_sndrcvinfo *)&sinfo, filling_sinfo);
6215f8829a4aSRandall Stewart 	if ((controlp) && (filling_sinfo)) {
6216f8829a4aSRandall Stewart 		/* copy back the sinfo in a CMSG format */
6217f8829a4aSRandall Stewart 		if (filling_sinfo)
6218f8829a4aSRandall Stewart 			*controlp = sctp_build_ctl_nchunk(inp,
6219f8829a4aSRandall Stewart 			    (struct sctp_sndrcvinfo *)&sinfo);
6220f8829a4aSRandall Stewart 		else
6221f8829a4aSRandall Stewart 			*controlp = NULL;
6222f8829a4aSRandall Stewart 	}
6223f8829a4aSRandall Stewart 	if (psa) {
6224f8829a4aSRandall Stewart 		/* copy back the address info */
6225f8829a4aSRandall Stewart 		if (from && from->sa_len) {
6226f8829a4aSRandall Stewart 			*psa = sodupsockaddr(from, M_NOWAIT);
6227f8829a4aSRandall Stewart 		} else {
6228f8829a4aSRandall Stewart 			*psa = NULL;
6229f8829a4aSRandall Stewart 		}
6230f8829a4aSRandall Stewart 	}
6231f8829a4aSRandall Stewart 	return (error);
6232f8829a4aSRandall Stewart }
623317205eccSRandall Stewart 
623417205eccSRandall Stewart 
623517205eccSRandall Stewart int
623617205eccSRandall Stewart sctp_l_soreceive(struct socket *so,
623717205eccSRandall Stewart     struct sockaddr **name,
623817205eccSRandall Stewart     struct uio *uio,
623917205eccSRandall Stewart     char **controlp,
624017205eccSRandall Stewart     int *controllen,
624117205eccSRandall Stewart     int *flag)
624217205eccSRandall Stewart {
624317205eccSRandall Stewart 	int error, fromlen;
624417205eccSRandall Stewart 	uint8_t sockbuf[256];
624517205eccSRandall Stewart 	struct sockaddr *from;
624617205eccSRandall Stewart 	struct sctp_extrcvinfo sinfo;
624717205eccSRandall Stewart 	int filling_sinfo = 1;
624817205eccSRandall Stewart 	struct sctp_inpcb *inp;
624917205eccSRandall Stewart 
625017205eccSRandall Stewart 	inp = (struct sctp_inpcb *)so->so_pcb;
625117205eccSRandall Stewart 	/* pickup the assoc we are reading from */
625217205eccSRandall Stewart 	if (inp == NULL) {
6253c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
625417205eccSRandall Stewart 		return (EINVAL);
625517205eccSRandall Stewart 	}
625617205eccSRandall Stewart 	if ((sctp_is_feature_off(inp,
625717205eccSRandall Stewart 	    SCTP_PCB_FLAGS_RECVDATAIOEVNT)) ||
625817205eccSRandall Stewart 	    (controlp == NULL)) {
625917205eccSRandall Stewart 		/* user does not want the sndrcv ctl */
626017205eccSRandall Stewart 		filling_sinfo = 0;
626117205eccSRandall Stewart 	}
626217205eccSRandall Stewart 	if (name) {
626317205eccSRandall Stewart 		from = (struct sockaddr *)sockbuf;
626417205eccSRandall Stewart 		fromlen = sizeof(sockbuf);
626517205eccSRandall Stewart 		from->sa_len = 0;
626617205eccSRandall Stewart 	} else {
626717205eccSRandall Stewart 		from = NULL;
626817205eccSRandall Stewart 		fromlen = 0;
626917205eccSRandall Stewart 	}
627017205eccSRandall Stewart 
627117205eccSRandall Stewart 	error = sctp_sorecvmsg(so, uio,
627217205eccSRandall Stewart 	    (struct mbuf **)NULL,
627317205eccSRandall Stewart 	    from, fromlen, flag,
627417205eccSRandall Stewart 	    (struct sctp_sndrcvinfo *)&sinfo,
627517205eccSRandall Stewart 	    filling_sinfo);
627617205eccSRandall Stewart 	if ((controlp) && (filling_sinfo)) {
627717205eccSRandall Stewart 		/*
627817205eccSRandall Stewart 		 * copy back the sinfo in a CMSG format note that the caller
627917205eccSRandall Stewart 		 * has reponsibility for freeing the memory.
628017205eccSRandall Stewart 		 */
628117205eccSRandall Stewart 		if (filling_sinfo)
628217205eccSRandall Stewart 			*controlp = sctp_build_ctl_cchunk(inp,
628317205eccSRandall Stewart 			    controllen,
628417205eccSRandall Stewart 			    (struct sctp_sndrcvinfo *)&sinfo);
628517205eccSRandall Stewart 	}
628617205eccSRandall Stewart 	if (name) {
628717205eccSRandall Stewart 		/* copy back the address info */
628817205eccSRandall Stewart 		if (from && from->sa_len) {
628917205eccSRandall Stewart 			*name = sodupsockaddr(from, M_WAIT);
629017205eccSRandall Stewart 		} else {
629117205eccSRandall Stewart 			*name = NULL;
629217205eccSRandall Stewart 		}
629317205eccSRandall Stewart 	}
629417205eccSRandall Stewart 	return (error);
629517205eccSRandall Stewart }
629617205eccSRandall Stewart 
629717205eccSRandall Stewart 
629817205eccSRandall Stewart 
629917205eccSRandall Stewart 
630017205eccSRandall Stewart 
630117205eccSRandall Stewart 
630217205eccSRandall Stewart 
630317205eccSRandall Stewart int
6304d61a0ae0SRandall Stewart sctp_connectx_helper_add(struct sctp_tcb *stcb, struct sockaddr *addr,
6305d61a0ae0SRandall Stewart     int totaddr, int *error)
630617205eccSRandall Stewart {
630717205eccSRandall Stewart 	int added = 0;
630817205eccSRandall Stewart 	int i;
630917205eccSRandall Stewart 	struct sctp_inpcb *inp;
631017205eccSRandall Stewart 	struct sockaddr *sa;
631117205eccSRandall Stewart 	size_t incr = 0;
631217205eccSRandall Stewart 
631317205eccSRandall Stewart 	sa = addr;
631417205eccSRandall Stewart 	inp = stcb->sctp_ep;
631517205eccSRandall Stewart 	*error = 0;
631617205eccSRandall Stewart 	for (i = 0; i < totaddr; i++) {
631717205eccSRandall Stewart 		if (sa->sa_family == AF_INET) {
631817205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in);
631917205eccSRandall Stewart 			if (sctp_add_remote_addr(stcb, sa, SCTP_DONOT_SETSCOPE, SCTP_ADDR_IS_CONFIRMED)) {
632017205eccSRandall Stewart 				/* assoc gone no un-lock */
6321c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOBUFS);
6322c4739e2fSRandall Stewart 				(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC, SCTP_FROM_SCTP_USRREQ + SCTP_LOC_7);
632317205eccSRandall Stewart 				*error = ENOBUFS;
632417205eccSRandall Stewart 				goto out_now;
632517205eccSRandall Stewart 			}
632617205eccSRandall Stewart 			added++;
632717205eccSRandall Stewart 		} else if (sa->sa_family == AF_INET6) {
632817205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in6);
632917205eccSRandall Stewart 			if (sctp_add_remote_addr(stcb, sa, SCTP_DONOT_SETSCOPE, SCTP_ADDR_IS_CONFIRMED)) {
633017205eccSRandall Stewart 				/* assoc gone no un-lock */
6331c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOBUFS);
6332c4739e2fSRandall Stewart 				(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC, SCTP_FROM_SCTP_USRREQ + SCTP_LOC_8);
633317205eccSRandall Stewart 				*error = ENOBUFS;
633417205eccSRandall Stewart 				goto out_now;
633517205eccSRandall Stewart 			}
633617205eccSRandall Stewart 			added++;
633717205eccSRandall Stewart 		}
633817205eccSRandall Stewart 		sa = (struct sockaddr *)((caddr_t)sa + incr);
633917205eccSRandall Stewart 	}
634017205eccSRandall Stewart out_now:
634117205eccSRandall Stewart 	return (added);
634217205eccSRandall Stewart }
634317205eccSRandall Stewart 
634417205eccSRandall Stewart struct sctp_tcb *
6345d61a0ae0SRandall Stewart sctp_connectx_helper_find(struct sctp_inpcb *inp, struct sockaddr *addr,
6346d61a0ae0SRandall Stewart     int *totaddr, int *num_v4, int *num_v6, int *error,
6347d61a0ae0SRandall Stewart     int limit, int *bad_addr)
634817205eccSRandall Stewart {
634917205eccSRandall Stewart 	struct sockaddr *sa;
635017205eccSRandall Stewart 	struct sctp_tcb *stcb = NULL;
635117205eccSRandall Stewart 	size_t incr, at, i;
635217205eccSRandall Stewart 
635317205eccSRandall Stewart 	at = incr = 0;
635417205eccSRandall Stewart 	sa = addr;
635517205eccSRandall Stewart 	*error = *num_v6 = *num_v4 = 0;
635617205eccSRandall Stewart 	/* account and validate addresses */
63574c9179adSRandall Stewart 	for (i = 0; i < (size_t)*totaddr; i++) {
635817205eccSRandall Stewart 		if (sa->sa_family == AF_INET) {
635917205eccSRandall Stewart 			(*num_v4) += 1;
636017205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in);
6361d61a0ae0SRandall Stewart 			if (sa->sa_len != incr) {
6362c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6363d61a0ae0SRandall Stewart 				*error = EINVAL;
6364d61a0ae0SRandall Stewart 				*bad_addr = 1;
6365d61a0ae0SRandall Stewart 				return (NULL);
6366d61a0ae0SRandall Stewart 			}
636717205eccSRandall Stewart 		} else if (sa->sa_family == AF_INET6) {
636817205eccSRandall Stewart 			struct sockaddr_in6 *sin6;
636917205eccSRandall Stewart 
637017205eccSRandall Stewart 			sin6 = (struct sockaddr_in6 *)sa;
637117205eccSRandall Stewart 			if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
637217205eccSRandall Stewart 				/* Must be non-mapped for connectx */
6373c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
637417205eccSRandall Stewart 				*error = EINVAL;
6375d61a0ae0SRandall Stewart 				*bad_addr = 1;
637617205eccSRandall Stewart 				return (NULL);
637717205eccSRandall Stewart 			}
637817205eccSRandall Stewart 			(*num_v6) += 1;
637917205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in6);
6380d61a0ae0SRandall Stewart 			if (sa->sa_len != incr) {
6381c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6382d61a0ae0SRandall Stewart 				*error = EINVAL;
6383d61a0ae0SRandall Stewart 				*bad_addr = 1;
6384d61a0ae0SRandall Stewart 				return (NULL);
6385d61a0ae0SRandall Stewart 			}
638617205eccSRandall Stewart 		} else {
638717205eccSRandall Stewart 			*totaddr = i;
638817205eccSRandall Stewart 			/* we are done */
638917205eccSRandall Stewart 			break;
639017205eccSRandall Stewart 		}
6391d61a0ae0SRandall Stewart 		SCTP_INP_INCR_REF(inp);
639217205eccSRandall Stewart 		stcb = sctp_findassociation_ep_addr(&inp, sa, NULL, NULL, NULL);
639317205eccSRandall Stewart 		if (stcb != NULL) {
639417205eccSRandall Stewart 			/* Already have or am bring up an association */
639517205eccSRandall Stewart 			return (stcb);
6396d61a0ae0SRandall Stewart 		} else {
6397d61a0ae0SRandall Stewart 			SCTP_INP_DECR_REF(inp);
639817205eccSRandall Stewart 		}
63994c9179adSRandall Stewart 		if ((at + incr) > (size_t)limit) {
640017205eccSRandall Stewart 			*totaddr = i;
640117205eccSRandall Stewart 			break;
640217205eccSRandall Stewart 		}
640317205eccSRandall Stewart 		sa = (struct sockaddr *)((caddr_t)sa + incr);
640417205eccSRandall Stewart 	}
640517205eccSRandall Stewart 	return ((struct sctp_tcb *)NULL);
640617205eccSRandall Stewart }
640735918f85SRandall Stewart 
640835918f85SRandall Stewart /*
640935918f85SRandall Stewart  * sctp_bindx(ADD) for one address.
641035918f85SRandall Stewart  * assumes all arguments are valid/checked by caller.
641135918f85SRandall Stewart  */
641235918f85SRandall Stewart void
641335918f85SRandall Stewart sctp_bindx_add_address(struct socket *so, struct sctp_inpcb *inp,
641435918f85SRandall Stewart     struct sockaddr *sa, sctp_assoc_t assoc_id,
641535918f85SRandall Stewart     uint32_t vrf_id, int *error, void *p)
641635918f85SRandall Stewart {
641735918f85SRandall Stewart 	struct sockaddr *addr_touse;
64185e2c2d87SRandall Stewart 
64195e2c2d87SRandall Stewart #ifdef INET6
642035918f85SRandall Stewart 	struct sockaddr_in sin;
642135918f85SRandall Stewart 
64225e2c2d87SRandall Stewart #endif
64235e2c2d87SRandall Stewart 
642435918f85SRandall Stewart 	/* see if we're bound all already! */
642535918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
6426c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
642735918f85SRandall Stewart 		*error = EINVAL;
642835918f85SRandall Stewart 		return;
642935918f85SRandall Stewart 	}
643035918f85SRandall Stewart 	addr_touse = sa;
6431fc14de76SRandall Stewart #if defined(INET6) && !defined(__Userspace__)	/* TODO port in6_sin6_2_sin */
643235918f85SRandall Stewart 	if (sa->sa_family == AF_INET6) {
643335918f85SRandall Stewart 		struct sockaddr_in6 *sin6;
643435918f85SRandall Stewart 
643535918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in6)) {
6436c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
643735918f85SRandall Stewart 			*error = EINVAL;
643835918f85SRandall Stewart 			return;
643935918f85SRandall Stewart 		}
6440db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) == 0) {
6441db4fd95bSRandall Stewart 			/* can only bind v6 on PF_INET6 sockets */
6442c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6443db4fd95bSRandall Stewart 			*error = EINVAL;
6444db4fd95bSRandall Stewart 			return;
6445db4fd95bSRandall Stewart 		}
644635918f85SRandall Stewart 		sin6 = (struct sockaddr_in6 *)addr_touse;
644735918f85SRandall Stewart 		if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
6448db4fd95bSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6449db4fd95bSRandall Stewart 			    SCTP_IPV6_V6ONLY(inp)) {
6450db4fd95bSRandall Stewart 				/* can't bind v4-mapped on PF_INET sockets */
6451c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6452db4fd95bSRandall Stewart 				*error = EINVAL;
6453db4fd95bSRandall Stewart 				return;
6454db4fd95bSRandall Stewart 			}
645535918f85SRandall Stewart 			in6_sin6_2_sin(&sin, sin6);
645635918f85SRandall Stewart 			addr_touse = (struct sockaddr *)&sin;
645735918f85SRandall Stewart 		}
645835918f85SRandall Stewart 	}
645935918f85SRandall Stewart #endif
646035918f85SRandall Stewart 	if (sa->sa_family == AF_INET) {
646135918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in)) {
6462c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
646335918f85SRandall Stewart 			*error = EINVAL;
646435918f85SRandall Stewart 			return;
646535918f85SRandall Stewart 		}
6466db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6467db4fd95bSRandall Stewart 		    SCTP_IPV6_V6ONLY(inp)) {
6468db4fd95bSRandall Stewart 			/* can't bind v4 on PF_INET sockets */
6469c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6470db4fd95bSRandall Stewart 			*error = EINVAL;
6471db4fd95bSRandall Stewart 			return;
6472db4fd95bSRandall Stewart 		}
647335918f85SRandall Stewart 	}
647435918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_UNBOUND) {
647535918f85SRandall Stewart 		if (p == NULL) {
647635918f85SRandall Stewart 			/* Can't get proc for Net/Open BSD */
6477c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
647835918f85SRandall Stewart 			*error = EINVAL;
647935918f85SRandall Stewart 			return;
648035918f85SRandall Stewart 		}
64811b649582SRandall Stewart 		*error = sctp_inpcb_bind(so, addr_touse, NULL, p);
648235918f85SRandall Stewart 		return;
648335918f85SRandall Stewart 	}
648435918f85SRandall Stewart 	/*
648535918f85SRandall Stewart 	 * No locks required here since bind and mgmt_ep_sa all do their own
648635918f85SRandall Stewart 	 * locking. If we do something for the FIX: below we may need to
648735918f85SRandall Stewart 	 * lock in that case.
648835918f85SRandall Stewart 	 */
648935918f85SRandall Stewart 	if (assoc_id == 0) {
649035918f85SRandall Stewart 		/* add the address */
649135918f85SRandall Stewart 		struct sctp_inpcb *lep;
649297c76f10SRandall Stewart 		struct sockaddr_in *lsin = (struct sockaddr_in *)addr_touse;
649335918f85SRandall Stewart 
649497c76f10SRandall Stewart 		/* validate the incoming port */
649597c76f10SRandall Stewart 		if ((lsin->sin_port != 0) &&
649697c76f10SRandall Stewart 		    (lsin->sin_port != inp->sctp_lport)) {
6497c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
649897c76f10SRandall Stewart 			*error = EINVAL;
649997c76f10SRandall Stewart 			return;
650097c76f10SRandall Stewart 		} else {
650197c76f10SRandall Stewart 			/* user specified 0 port, set it to existing port */
650297c76f10SRandall Stewart 			lsin->sin_port = inp->sctp_lport;
650397c76f10SRandall Stewart 		}
650497c76f10SRandall Stewart 
650535918f85SRandall Stewart 		lep = sctp_pcb_findep(addr_touse, 1, 0, vrf_id);
650635918f85SRandall Stewart 		if (lep != NULL) {
650735918f85SRandall Stewart 			/*
650835918f85SRandall Stewart 			 * We must decrement the refcount since we have the
650935918f85SRandall Stewart 			 * ep already and are binding. No remove going on
651035918f85SRandall Stewart 			 * here.
651135918f85SRandall Stewart 			 */
65126d9e8f2bSRandall Stewart 			SCTP_INP_DECR_REF(lep);
651335918f85SRandall Stewart 		}
651435918f85SRandall Stewart 		if (lep == inp) {
651535918f85SRandall Stewart 			/* already bound to it.. ok */
651635918f85SRandall Stewart 			return;
651735918f85SRandall Stewart 		} else if (lep == NULL) {
651835918f85SRandall Stewart 			((struct sockaddr_in *)addr_touse)->sin_port = 0;
651935918f85SRandall Stewart 			*error = sctp_addr_mgmt_ep_sa(inp, addr_touse,
652035918f85SRandall Stewart 			    SCTP_ADD_IP_ADDRESS,
652180fefe0aSRandall Stewart 			    vrf_id, NULL);
652235918f85SRandall Stewart 		} else {
652335918f85SRandall Stewart 			*error = EADDRINUSE;
652435918f85SRandall Stewart 		}
652535918f85SRandall Stewart 		if (*error)
652635918f85SRandall Stewart 			return;
652735918f85SRandall Stewart 	} else {
652835918f85SRandall Stewart 		/*
652935918f85SRandall Stewart 		 * FIX: decide whether we allow assoc based bindx
653035918f85SRandall Stewart 		 */
653135918f85SRandall Stewart 	}
653235918f85SRandall Stewart }
653335918f85SRandall Stewart 
653435918f85SRandall Stewart /*
653535918f85SRandall Stewart  * sctp_bindx(DELETE) for one address.
653635918f85SRandall Stewart  * assumes all arguments are valid/checked by caller.
653735918f85SRandall Stewart  */
653835918f85SRandall Stewart void
653935918f85SRandall Stewart sctp_bindx_delete_address(struct socket *so, struct sctp_inpcb *inp,
654035918f85SRandall Stewart     struct sockaddr *sa, sctp_assoc_t assoc_id,
654135918f85SRandall Stewart     uint32_t vrf_id, int *error)
654235918f85SRandall Stewart {
654335918f85SRandall Stewart 	struct sockaddr *addr_touse;
65445e2c2d87SRandall Stewart 
65455e2c2d87SRandall Stewart #ifdef INET6
654635918f85SRandall Stewart 	struct sockaddr_in sin;
654735918f85SRandall Stewart 
65485e2c2d87SRandall Stewart #endif
65495e2c2d87SRandall Stewart 
655035918f85SRandall Stewart 	/* see if we're bound all already! */
655135918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
6552c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
655335918f85SRandall Stewart 		*error = EINVAL;
655435918f85SRandall Stewart 		return;
655535918f85SRandall Stewart 	}
655635918f85SRandall Stewart 	addr_touse = sa;
6557fc14de76SRandall Stewart #if defined(INET6) && !defined(__Userspace__)	/* TODO port in6_sin6_2_sin */
655835918f85SRandall Stewart 	if (sa->sa_family == AF_INET6) {
655935918f85SRandall Stewart 		struct sockaddr_in6 *sin6;
656035918f85SRandall Stewart 
656135918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in6)) {
6562c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
656335918f85SRandall Stewart 			*error = EINVAL;
656435918f85SRandall Stewart 			return;
656535918f85SRandall Stewart 		}
6566db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) == 0) {
6567db4fd95bSRandall Stewart 			/* can only bind v6 on PF_INET6 sockets */
6568c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6569db4fd95bSRandall Stewart 			*error = EINVAL;
6570db4fd95bSRandall Stewart 			return;
6571db4fd95bSRandall Stewart 		}
657235918f85SRandall Stewart 		sin6 = (struct sockaddr_in6 *)addr_touse;
657335918f85SRandall Stewart 		if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
6574db4fd95bSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6575db4fd95bSRandall Stewart 			    SCTP_IPV6_V6ONLY(inp)) {
6576db4fd95bSRandall Stewart 				/* can't bind mapped-v4 on PF_INET sockets */
6577c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6578db4fd95bSRandall Stewart 				*error = EINVAL;
6579db4fd95bSRandall Stewart 				return;
6580db4fd95bSRandall Stewart 			}
658135918f85SRandall Stewart 			in6_sin6_2_sin(&sin, sin6);
658235918f85SRandall Stewart 			addr_touse = (struct sockaddr *)&sin;
658335918f85SRandall Stewart 		}
658435918f85SRandall Stewart 	}
658535918f85SRandall Stewart #endif
658635918f85SRandall Stewart 	if (sa->sa_family == AF_INET) {
658735918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in)) {
6588c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
658935918f85SRandall Stewart 			*error = EINVAL;
659035918f85SRandall Stewart 			return;
659135918f85SRandall Stewart 		}
6592db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6593db4fd95bSRandall Stewart 		    SCTP_IPV6_V6ONLY(inp)) {
6594db4fd95bSRandall Stewart 			/* can't bind v4 on PF_INET sockets */
6595c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6596db4fd95bSRandall Stewart 			*error = EINVAL;
6597db4fd95bSRandall Stewart 			return;
6598db4fd95bSRandall Stewart 		}
659935918f85SRandall Stewart 	}
660035918f85SRandall Stewart 	/*
660135918f85SRandall Stewart 	 * No lock required mgmt_ep_sa does its own locking. If the FIX:
660235918f85SRandall Stewart 	 * below is ever changed we may need to lock before calling
660335918f85SRandall Stewart 	 * association level binding.
660435918f85SRandall Stewart 	 */
660535918f85SRandall Stewart 	if (assoc_id == 0) {
660635918f85SRandall Stewart 		/* delete the address */
660735918f85SRandall Stewart 		*error = sctp_addr_mgmt_ep_sa(inp, addr_touse,
660835918f85SRandall Stewart 		    SCTP_DEL_IP_ADDRESS,
660980fefe0aSRandall Stewart 		    vrf_id, NULL);
661035918f85SRandall Stewart 	} else {
661135918f85SRandall Stewart 		/*
661235918f85SRandall Stewart 		 * FIX: decide whether we allow assoc based bindx
661335918f85SRandall Stewart 		 */
661435918f85SRandall Stewart 	}
661535918f85SRandall Stewart }
66161b649582SRandall Stewart 
66171b649582SRandall Stewart /*
66181b649582SRandall Stewart  * returns the valid local address count for an assoc, taking into account
66191b649582SRandall Stewart  * all scoping rules
66201b649582SRandall Stewart  */
66211b649582SRandall Stewart int
66221b649582SRandall Stewart sctp_local_addr_count(struct sctp_tcb *stcb)
66231b649582SRandall Stewart {
66241b649582SRandall Stewart 	int loopback_scope, ipv4_local_scope, local_scope, site_scope;
66251b649582SRandall Stewart 	int ipv4_addr_legal, ipv6_addr_legal;
66261b649582SRandall Stewart 	struct sctp_vrf *vrf;
66271b649582SRandall Stewart 	struct sctp_ifn *sctp_ifn;
66281b649582SRandall Stewart 	struct sctp_ifa *sctp_ifa;
66291b649582SRandall Stewart 	int count = 0;
66301b649582SRandall Stewart 
66311b649582SRandall Stewart 	/* Turn on all the appropriate scopes */
66321b649582SRandall Stewart 	loopback_scope = stcb->asoc.loopback_scope;
66331b649582SRandall Stewart 	ipv4_local_scope = stcb->asoc.ipv4_local_scope;
66341b649582SRandall Stewart 	local_scope = stcb->asoc.local_scope;
66351b649582SRandall Stewart 	site_scope = stcb->asoc.site_scope;
66361b649582SRandall Stewart 	ipv4_addr_legal = ipv6_addr_legal = 0;
66371b649582SRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) {
66381b649582SRandall Stewart 		ipv6_addr_legal = 1;
66391b649582SRandall Stewart 		if (SCTP_IPV6_V6ONLY(stcb->sctp_ep) == 0) {
66401b649582SRandall Stewart 			ipv4_addr_legal = 1;
66411b649582SRandall Stewart 		}
66421b649582SRandall Stewart 	} else {
66431b649582SRandall Stewart 		ipv4_addr_legal = 1;
66441b649582SRandall Stewart 	}
66451b649582SRandall Stewart 
6646c99efcf6SRandall Stewart 	SCTP_IPI_ADDR_RLOCK();
66471b649582SRandall Stewart 	vrf = sctp_find_vrf(stcb->asoc.vrf_id);
66481b649582SRandall Stewart 	if (vrf == NULL) {
66491b649582SRandall Stewart 		/* no vrf, no addresses */
6650c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RUNLOCK();
66511b649582SRandall Stewart 		return (0);
66521b649582SRandall Stewart 	}
66531b649582SRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
66541b649582SRandall Stewart 		/*
66551b649582SRandall Stewart 		 * bound all case: go through all ifns on the vrf
66561b649582SRandall Stewart 		 */
66571b649582SRandall Stewart 		LIST_FOREACH(sctp_ifn, &vrf->ifnlist, next_ifn) {
66581b649582SRandall Stewart 			if ((loopback_scope == 0) &&
66591b649582SRandall Stewart 			    SCTP_IFN_IS_IFT_LOOP(sctp_ifn)) {
66601b649582SRandall Stewart 				continue;
66611b649582SRandall Stewart 			}
66621b649582SRandall Stewart 			LIST_FOREACH(sctp_ifa, &sctp_ifn->ifalist, next_ifa) {
66631b649582SRandall Stewart 				if (sctp_is_addr_restricted(stcb, sctp_ifa))
66641b649582SRandall Stewart 					continue;
66655e2c2d87SRandall Stewart 				switch (sctp_ifa->address.sa.sa_family) {
66665e2c2d87SRandall Stewart 				case AF_INET:
66675e2c2d87SRandall Stewart 					if (ipv4_addr_legal) {
66681b649582SRandall Stewart 						struct sockaddr_in *sin;
66691b649582SRandall Stewart 
66701b649582SRandall Stewart 						sin = (struct sockaddr_in *)&sctp_ifa->address.sa;
66711b649582SRandall Stewart 						if (sin->sin_addr.s_addr == 0) {
66725e2c2d87SRandall Stewart 							/*
66735e2c2d87SRandall Stewart 							 * skip unspecified
66745e2c2d87SRandall Stewart 							 * addrs
66755e2c2d87SRandall Stewart 							 */
66761b649582SRandall Stewart 							continue;
66771b649582SRandall Stewart 						}
66781b649582SRandall Stewart 						if ((ipv4_local_scope == 0) &&
66791b649582SRandall Stewart 						    (IN4_ISPRIVATE_ADDRESS(&sin->sin_addr))) {
66801b649582SRandall Stewart 							continue;
66811b649582SRandall Stewart 						}
66821b649582SRandall Stewart 						/* count this one */
66831b649582SRandall Stewart 						count++;
66845e2c2d87SRandall Stewart 					} else {
66855e2c2d87SRandall Stewart 						continue;
66865e2c2d87SRandall Stewart 					}
66875e2c2d87SRandall Stewart 					break;
66885e2c2d87SRandall Stewart #ifdef INET6
66895e2c2d87SRandall Stewart 				case AF_INET6:
66905e2c2d87SRandall Stewart 					if (ipv6_addr_legal) {
66911b649582SRandall Stewart 						struct sockaddr_in6 *sin6;
66921b649582SRandall Stewart 
66931b649582SRandall Stewart 						sin6 = (struct sockaddr_in6 *)&sctp_ifa->address.sa;
66941b649582SRandall Stewart 						if (IN6_IS_ADDR_UNSPECIFIED(&sin6->sin6_addr)) {
66951b649582SRandall Stewart 							continue;
66961b649582SRandall Stewart 						}
66971b649582SRandall Stewart 						if (IN6_IS_ADDR_LINKLOCAL(&sin6->sin6_addr)) {
66981b649582SRandall Stewart 							if (local_scope == 0)
66991b649582SRandall Stewart 								continue;
67001b649582SRandall Stewart 							if (sin6->sin6_scope_id == 0) {
67011b649582SRandall Stewart 								if (sa6_recoverscope(sin6) != 0)
67021b649582SRandall Stewart 									/*
67035e2c2d87SRandall Stewart 									 *
67045e2c2d87SRandall Stewart 									 * bad
67055e2c2d87SRandall Stewart 									 *
67065e2c2d87SRandall Stewart 									 * li
67075e2c2d87SRandall Stewart 									 * nk
67085e2c2d87SRandall Stewart 									 *
67095e2c2d87SRandall Stewart 									 * loc
67105e2c2d87SRandall Stewart 									 * al
67115e2c2d87SRandall Stewart 									 *
67125e2c2d87SRandall Stewart 									 * add
67135e2c2d87SRandall Stewart 									 * re
67145e2c2d87SRandall Stewart 									 * ss
67155e2c2d87SRandall Stewart 									 * */
67161b649582SRandall Stewart 									continue;
67171b649582SRandall Stewart 							}
67181b649582SRandall Stewart 						}
67191b649582SRandall Stewart 						if ((site_scope == 0) &&
67201b649582SRandall Stewart 						    (IN6_IS_ADDR_SITELOCAL(&sin6->sin6_addr))) {
67211b649582SRandall Stewart 							continue;
67221b649582SRandall Stewart 						}
67231b649582SRandall Stewart 						/* count this one */
67241b649582SRandall Stewart 						count++;
67251b649582SRandall Stewart 					}
67265e2c2d87SRandall Stewart 					break;
67275e2c2d87SRandall Stewart #endif
67285e2c2d87SRandall Stewart 				default:
67295e2c2d87SRandall Stewart 					/* TSNH */
67305e2c2d87SRandall Stewart 					break;
67315e2c2d87SRandall Stewart 				}
67321b649582SRandall Stewart 			}
67331b649582SRandall Stewart 		}
67341b649582SRandall Stewart 	} else {
67351b649582SRandall Stewart 		/*
67361b649582SRandall Stewart 		 * subset bound case
67371b649582SRandall Stewart 		 */
67381b649582SRandall Stewart 		struct sctp_laddr *laddr;
67391b649582SRandall Stewart 
67401b649582SRandall Stewart 		LIST_FOREACH(laddr, &stcb->sctp_ep->sctp_addr_list,
67411b649582SRandall Stewart 		    sctp_nxt_addr) {
67421b649582SRandall Stewart 			if (sctp_is_addr_restricted(stcb, laddr->ifa)) {
67431b649582SRandall Stewart 				continue;
67441b649582SRandall Stewart 			}
67451b649582SRandall Stewart 			/* count this one */
67461b649582SRandall Stewart 			count++;
67471b649582SRandall Stewart 		}
67481b649582SRandall Stewart 	}
6749c99efcf6SRandall Stewart 	SCTP_IPI_ADDR_RUNLOCK();
67501b649582SRandall Stewart 	return (count);
67511b649582SRandall Stewart }
6752c4739e2fSRandall Stewart 
6753c4739e2fSRandall Stewart #if defined(SCTP_LOCAL_TRACE_BUF)
6754c4739e2fSRandall Stewart 
6755c4739e2fSRandall Stewart void
6756b27a6b7dSRandall Stewart sctp_log_trace(uint32_t subsys, const char *str SCTP_UNUSED, uint32_t a, uint32_t b, uint32_t c, uint32_t d, uint32_t e, uint32_t f)
6757c4739e2fSRandall Stewart {
6758b27a6b7dSRandall Stewart 	uint32_t saveindex, newindex;
6759c4739e2fSRandall Stewart 
6760c4739e2fSRandall Stewart 	do {
6761b3f1ea41SRandall Stewart 		saveindex = SCTP_BASE_SYSCTL(sctp_log).index;
6762c4739e2fSRandall Stewart 		if (saveindex >= SCTP_MAX_LOGGING_SIZE) {
6763c4739e2fSRandall Stewart 			newindex = 1;
6764c4739e2fSRandall Stewart 		} else {
6765c4739e2fSRandall Stewart 			newindex = saveindex + 1;
6766c4739e2fSRandall Stewart 		}
6767b3f1ea41SRandall Stewart 	} while (atomic_cmpset_int(&SCTP_BASE_SYSCTL(sctp_log).index, saveindex, newindex) == 0);
6768c4739e2fSRandall Stewart 	if (saveindex >= SCTP_MAX_LOGGING_SIZE) {
6769c4739e2fSRandall Stewart 		saveindex = 0;
6770c4739e2fSRandall Stewart 	}
6771b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].timestamp = SCTP_GET_CYCLECOUNT;
6772b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].subsys = subsys;
6773b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[0] = a;
6774b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[1] = b;
6775b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[2] = c;
6776b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[3] = d;
6777b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[4] = e;
6778b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[5] = f;
6779c4739e2fSRandall Stewart }
6780c4739e2fSRandall Stewart 
6781c4739e2fSRandall Stewart #endif
6782c54a18d2SRandall Stewart /* We will need to add support
6783c54a18d2SRandall Stewart  * to bind the ports and such here
6784c54a18d2SRandall Stewart  * so we can do UDP tunneling. In
6785c54a18d2SRandall Stewart  * the mean-time, we return error
6786c54a18d2SRandall Stewart  */
6787a99b6783SRandall Stewart #include <netinet/udp.h>
6788a99b6783SRandall Stewart #include <netinet/udp_var.h>
6789a99b6783SRandall Stewart #include <sys/proc.h>
6790a1f2f7a5SRandall Stewart #ifdef INET6
6791a99b6783SRandall Stewart #include <netinet6/sctp6_var.h>
6792a1f2f7a5SRandall Stewart #endif
6793a99b6783SRandall Stewart 
6794a99b6783SRandall Stewart static void
6795a99b6783SRandall Stewart sctp_recv_udp_tunneled_packet(struct mbuf *m, int off, struct inpcb *ignored)
6796a99b6783SRandall Stewart {
6797a99b6783SRandall Stewart 	struct ip *iph;
6798a99b6783SRandall Stewart 	struct mbuf *sp, *last;
6799a99b6783SRandall Stewart 	struct udphdr *uhdr;
6800a99b6783SRandall Stewart 	uint16_t port = 0, len;
6801a99b6783SRandall Stewart 	int header_size = sizeof(struct udphdr) + sizeof(struct sctphdr);
6802a99b6783SRandall Stewart 
6803a99b6783SRandall Stewart 	/*
6804a99b6783SRandall Stewart 	 * Split out the mbuf chain. Leave the IP header in m, place the
6805a99b6783SRandall Stewart 	 * rest in the sp.
6806a99b6783SRandall Stewart 	 */
6807a99b6783SRandall Stewart 	if ((m->m_flags & M_PKTHDR) == 0) {
6808a99b6783SRandall Stewart 		/* Can't handle one that is not a pkt hdr */
6809a99b6783SRandall Stewart 		goto out;
6810a99b6783SRandall Stewart 	}
6811a99b6783SRandall Stewart 	/* pull the src port */
6812a99b6783SRandall Stewart 	iph = mtod(m, struct ip *);
6813a99b6783SRandall Stewart 	uhdr = (struct udphdr *)((caddr_t)iph + off);
6814a99b6783SRandall Stewart 
6815a99b6783SRandall Stewart 	port = uhdr->uh_sport;
6816a99b6783SRandall Stewart 	sp = m_split(m, off, M_DONTWAIT);
6817a99b6783SRandall Stewart 	if (sp == NULL) {
6818a99b6783SRandall Stewart 		/* Gak, drop packet, we can't do a split */
6819a99b6783SRandall Stewart 		goto out;
6820a99b6783SRandall Stewart 	}
6821a99b6783SRandall Stewart 	if (sp->m_pkthdr.len < header_size) {
6822a99b6783SRandall Stewart 		/* Gak, packet can't have an SCTP header in it - to small */
6823a99b6783SRandall Stewart 		m_freem(sp);
6824a99b6783SRandall Stewart 		goto out;
6825a99b6783SRandall Stewart 	}
6826a99b6783SRandall Stewart 	/* ok now pull up the UDP header and SCTP header together */
6827a99b6783SRandall Stewart 	sp = m_pullup(sp, header_size);
6828a99b6783SRandall Stewart 	if (sp == NULL) {
6829a99b6783SRandall Stewart 		/* Gak pullup failed */
6830a99b6783SRandall Stewart 		goto out;
6831a99b6783SRandall Stewart 	}
6832a99b6783SRandall Stewart 	/* trim out the UDP header */
6833a99b6783SRandall Stewart 	m_adj(sp, sizeof(struct udphdr));
6834a99b6783SRandall Stewart 
6835a99b6783SRandall Stewart 	/* Now reconstruct the mbuf chain */
6836a99b6783SRandall Stewart 	/* 1) find last one */
6837a99b6783SRandall Stewart 	last = m;
6838a99b6783SRandall Stewart 	while (last->m_next != NULL) {
6839a99b6783SRandall Stewart 		last = last->m_next;
6840a99b6783SRandall Stewart 	}
6841a99b6783SRandall Stewart 	last->m_next = sp;
6842a99b6783SRandall Stewart 	m->m_pkthdr.len += sp->m_pkthdr.len;
6843a99b6783SRandall Stewart 	last = m;
6844a99b6783SRandall Stewart 	while (last != NULL) {
6845a99b6783SRandall Stewart 		last = last->m_next;
6846a99b6783SRandall Stewart 	}
6847a99b6783SRandall Stewart 	/* Now its ready for sctp_input or sctp6_input */
6848a99b6783SRandall Stewart 	iph = mtod(m, struct ip *);
6849a99b6783SRandall Stewart 	switch (iph->ip_v) {
6850a99b6783SRandall Stewart 	case IPVERSION:
6851a99b6783SRandall Stewart 		{
6852a99b6783SRandall Stewart 			/* its IPv4 */
6853a99b6783SRandall Stewart 			len = SCTP_GET_IPV4_LENGTH(iph);
6854a99b6783SRandall Stewart 			len -= sizeof(struct udphdr);
6855a99b6783SRandall Stewart 			SCTP_GET_IPV4_LENGTH(iph) = len;
6856a99b6783SRandall Stewart 			sctp_input_with_port(m, off, port);
6857a99b6783SRandall Stewart 			break;
6858a99b6783SRandall Stewart 		}
6859a99b6783SRandall Stewart #ifdef INET6
6860a99b6783SRandall Stewart 	case IPV6_VERSION >> 4:
6861a99b6783SRandall Stewart 		{
6862a99b6783SRandall Stewart 			/* its IPv6 - NOT supported */
6863a99b6783SRandall Stewart 			goto out;
6864a99b6783SRandall Stewart 			break;
6865a99b6783SRandall Stewart 
6866a99b6783SRandall Stewart 		}
6867a99b6783SRandall Stewart #endif
6868a99b6783SRandall Stewart 	default:
6869a99b6783SRandall Stewart 		{
6870a99b6783SRandall Stewart 			m_freem(m);
6871a99b6783SRandall Stewart 			break;
6872a99b6783SRandall Stewart 		}
6873a99b6783SRandall Stewart 	}
6874a99b6783SRandall Stewart 	return;
6875a99b6783SRandall Stewart out:
6876a99b6783SRandall Stewart 	m_freem(m);
6877a99b6783SRandall Stewart }
6878c54a18d2SRandall Stewart 
6879c54a18d2SRandall Stewart void
6880c54a18d2SRandall Stewart sctp_over_udp_stop(void)
6881c54a18d2SRandall Stewart {
6882a99b6783SRandall Stewart 	struct socket *sop;
6883a99b6783SRandall Stewart 
6884a99b6783SRandall Stewart 	/*
6885a99b6783SRandall Stewart 	 * This function assumes sysctl caller holds sctp_sysctl_info_lock()
6886a99b6783SRandall Stewart 	 * for writting!
6887a99b6783SRandall Stewart 	 */
6888a99b6783SRandall Stewart 	if (SCTP_BASE_INFO(udp_tun_socket) == NULL) {
6889a99b6783SRandall Stewart 		/* Nothing to do */
6890c54a18d2SRandall Stewart 		return;
6891c54a18d2SRandall Stewart 	}
6892a99b6783SRandall Stewart 	sop = SCTP_BASE_INFO(udp_tun_socket);
6893a99b6783SRandall Stewart 	soclose(sop);
6894a99b6783SRandall Stewart 	SCTP_BASE_INFO(udp_tun_socket) = NULL;
6895a99b6783SRandall Stewart }
6896c54a18d2SRandall Stewart int
6897c54a18d2SRandall Stewart sctp_over_udp_start(void)
6898c54a18d2SRandall Stewart {
6899a99b6783SRandall Stewart 	uint16_t port;
6900a99b6783SRandall Stewart 	int ret;
6901a99b6783SRandall Stewart 	struct sockaddr_in sin;
6902a99b6783SRandall Stewart 	struct socket *sop = NULL;
6903a99b6783SRandall Stewart 	struct thread *th;
6904a99b6783SRandall Stewart 	struct ucred *cred;
6905a99b6783SRandall Stewart 
6906a99b6783SRandall Stewart 	/*
6907a99b6783SRandall Stewart 	 * This function assumes sysctl caller holds sctp_sysctl_info_lock()
6908a99b6783SRandall Stewart 	 * for writting!
6909a99b6783SRandall Stewart 	 */
6910a99b6783SRandall Stewart 	port = SCTP_BASE_SYSCTL(sctp_udp_tunneling_port);
6911a99b6783SRandall Stewart 	if (port == 0) {
6912a99b6783SRandall Stewart 		/* Must have a port set */
6913a99b6783SRandall Stewart 		return (EINVAL);
6914a99b6783SRandall Stewart 	}
6915a99b6783SRandall Stewart 	if (SCTP_BASE_INFO(udp_tun_socket) != NULL) {
6916a99b6783SRandall Stewart 		/* Already running -- must stop first */
6917a99b6783SRandall Stewart 		return (EALREADY);
6918a99b6783SRandall Stewart 	}
6919a99b6783SRandall Stewart 	th = curthread;
6920a99b6783SRandall Stewart 	cred = th->td_ucred;
6921a99b6783SRandall Stewart 	if ((ret = socreate(PF_INET, &sop,
6922a99b6783SRandall Stewart 	    SOCK_DGRAM, IPPROTO_UDP, cred, th))) {
6923a99b6783SRandall Stewart 		return (ret);
6924a99b6783SRandall Stewart 	}
6925a99b6783SRandall Stewart 	SCTP_BASE_INFO(udp_tun_socket) = sop;
6926a99b6783SRandall Stewart 	/* call the special UDP hook */
6927a99b6783SRandall Stewart 	ret = udp_set_kernel_tunneling(sop, sctp_recv_udp_tunneled_packet);
6928a99b6783SRandall Stewart 	if (ret) {
6929a99b6783SRandall Stewart 		goto exit_stage_left;
6930a99b6783SRandall Stewart 	}
6931a99b6783SRandall Stewart 	/* Ok we have a socket, bind it to the port */
6932a99b6783SRandall Stewart 	memset(&sin, 0, sizeof(sin));
6933a99b6783SRandall Stewart 	sin.sin_len = sizeof(sin);
6934a99b6783SRandall Stewart 	sin.sin_family = AF_INET;
6935a99b6783SRandall Stewart 	sin.sin_port = htons(port);
6936a99b6783SRandall Stewart 	ret = sobind(sop, (struct sockaddr *)&sin, th);
6937a99b6783SRandall Stewart 	if (ret) {
6938a99b6783SRandall Stewart 		/* Close up we cant get the port */
6939a99b6783SRandall Stewart exit_stage_left:
6940a99b6783SRandall Stewart 		sctp_over_udp_stop();
6941a99b6783SRandall Stewart 		return (ret);
6942a99b6783SRandall Stewart 	}
6943a99b6783SRandall Stewart 	/*
6944a99b6783SRandall Stewart 	 * Ok we should now get UDP packets directly to our input routine
6945a99b6783SRandall Stewart 	 * sctp_recv_upd_tunneled_packet().
6946a99b6783SRandall Stewart 	 */
6947a99b6783SRandall Stewart 	return (0);
6948c54a18d2SRandall Stewart }
6949