xref: /freebsd/sys/netinet/sctputil.c (revision 1e81a4e7e89bb1870bec84e42284ad10505e957c)
1f8829a4aSRandall Stewart /*-
251369649SPedro F. Giffuni  * SPDX-License-Identifier: BSD-3-Clause
351369649SPedro F. Giffuni  *
4830d754dSRandall Stewart  * Copyright (c) 2001-2008, by Cisco Systems, Inc. All rights reserved.
5807aad63SMichael Tuexen  * Copyright (c) 2008-2012, by Randall Stewart. All rights reserved.
6807aad63SMichael Tuexen  * Copyright (c) 2008-2012, by Michael Tuexen. All rights reserved.
7f8829a4aSRandall Stewart  *
8f8829a4aSRandall Stewart  * Redistribution and use in source and binary forms, with or without
9f8829a4aSRandall Stewart  * modification, are permitted provided that the following conditions are met:
10f8829a4aSRandall Stewart  *
11f8829a4aSRandall Stewart  * a) Redistributions of source code must retain the above copyright notice,
12f8829a4aSRandall Stewart  *    this list of conditions and the following disclaimer.
13f8829a4aSRandall Stewart  *
14f8829a4aSRandall Stewart  * b) Redistributions in binary form must reproduce the above copyright
15f8829a4aSRandall Stewart  *    notice, this list of conditions and the following disclaimer in
16f8829a4aSRandall Stewart  *    the documentation and/or other materials provided with the distribution.
17f8829a4aSRandall Stewart  *
18f8829a4aSRandall Stewart  * c) Neither the name of Cisco Systems, Inc. nor the names of its
19f8829a4aSRandall Stewart  *    contributors may be used to endorse or promote products derived
20f8829a4aSRandall Stewart  *    from this software without specific prior written permission.
21f8829a4aSRandall Stewart  *
22f8829a4aSRandall Stewart  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
23f8829a4aSRandall Stewart  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
24f8829a4aSRandall Stewart  * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25f8829a4aSRandall Stewart  * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
26f8829a4aSRandall Stewart  * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
27f8829a4aSRandall Stewart  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
28f8829a4aSRandall Stewart  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
29f8829a4aSRandall Stewart  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
30f8829a4aSRandall Stewart  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
31f8829a4aSRandall Stewart  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
32f8829a4aSRandall Stewart  * THE POSSIBILITY OF SUCH DAMAGE.
33f8829a4aSRandall Stewart  */
34f8829a4aSRandall Stewart 
35f8829a4aSRandall Stewart #include <netinet/sctp_os.h>
36f8829a4aSRandall Stewart #include <netinet/sctp_pcb.h>
37f8829a4aSRandall Stewart #include <netinet/sctputil.h>
38f8829a4aSRandall Stewart #include <netinet/sctp_var.h>
3942551e99SRandall Stewart #include <netinet/sctp_sysctl.h>
40f8829a4aSRandall Stewart #ifdef INET6
413a51a264SMichael Tuexen #include <netinet6/sctp6_var.h>
42f8829a4aSRandall Stewart #endif
43f8829a4aSRandall Stewart #include <netinet/sctp_header.h>
44f8829a4aSRandall Stewart #include <netinet/sctp_output.h>
45f8829a4aSRandall Stewart #include <netinet/sctp_uio.h>
46f8829a4aSRandall Stewart #include <netinet/sctp_timer.h>
4746bf534cSMichael Tuexen #include <netinet/sctp_indata.h>
48f8829a4aSRandall Stewart #include <netinet/sctp_auth.h>
49f8829a4aSRandall Stewart #include <netinet/sctp_asconf.h>
50f7517433SRandall Stewart #include <netinet/sctp_bsd_addr.h>
51776cd558SMichael Tuexen #include <netinet/sctp_kdtrace.h>
5210e0318aSMichael Tuexen #if defined(INET6) || defined(INET)
5310e0318aSMichael Tuexen #include <netinet/tcp_var.h>
5410e0318aSMichael Tuexen #endif
553a51a264SMichael Tuexen #include <netinet/udp.h>
563a51a264SMichael Tuexen #include <netinet/udp_var.h>
573a51a264SMichael Tuexen #include <sys/proc.h>
58fd7af143SMichael Tuexen #ifdef INET6
59fd7af143SMichael Tuexen #include <netinet/icmp6.h>
60fd7af143SMichael Tuexen #endif
61f8829a4aSRandall Stewart 
62b9e7085aSRandall Stewart #ifndef KTR_SCTP
63b9e7085aSRandall Stewart #define KTR_SCTP KTR_SUBSYS
6480fefe0aSRandall Stewart #endif
65f8829a4aSRandall Stewart 
66ed654363SMichael Tuexen extern const struct sctp_cc_functions sctp_cc_functions[];
67ed654363SMichael Tuexen extern const struct sctp_ss_functions sctp_ss_functions[];
680e9a9c10SMichael Tuexen 
69f8829a4aSRandall Stewart void
70dcb68fbaSMichael Tuexen sctp_sblog(struct sockbuf *sb, struct sctp_tcb *stcb, int from, int incr)
71f8829a4aSRandall Stewart {
72c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
73c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
74f8829a4aSRandall Stewart 
7580fefe0aSRandall Stewart 	sctp_clog.x.sb.stcb = stcb;
76edc5b6eaSMichael Tuexen 	sctp_clog.x.sb.so_sbcc = SCTP_SBAVAIL(sb);
77f8829a4aSRandall Stewart 	if (stcb)
784e88d37aSMichael Tuexen 		sctp_clog.x.sb.stcb_sbcc = stcb->asoc.sb_cc;
79f8829a4aSRandall Stewart 	else
8080fefe0aSRandall Stewart 		sctp_clog.x.sb.stcb_sbcc = 0;
8180fefe0aSRandall Stewart 	sctp_clog.x.sb.incr = incr;
82c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
8380fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_SB,
8480fefe0aSRandall Stewart 	    from,
8580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
8680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
8780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
8880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
89c692df45SMichael Tuexen #endif
90f8829a4aSRandall Stewart }
91f8829a4aSRandall Stewart 
92f8829a4aSRandall Stewart void
93f8829a4aSRandall Stewart sctp_log_closing(struct sctp_inpcb *inp, struct sctp_tcb *stcb, int16_t loc)
94f8829a4aSRandall Stewart {
95c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
96c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
97f8829a4aSRandall Stewart 
9880fefe0aSRandall Stewart 	sctp_clog.x.close.inp = (void *)inp;
9980fefe0aSRandall Stewart 	sctp_clog.x.close.sctp_flags = inp->sctp_flags;
100f8829a4aSRandall Stewart 	if (stcb) {
10180fefe0aSRandall Stewart 		sctp_clog.x.close.stcb = (void *)stcb;
10280fefe0aSRandall Stewart 		sctp_clog.x.close.state = (uint16_t)stcb->asoc.state;
103f8829a4aSRandall Stewart 	} else {
10480fefe0aSRandall Stewart 		sctp_clog.x.close.stcb = 0;
10580fefe0aSRandall Stewart 		sctp_clog.x.close.state = 0;
106f8829a4aSRandall Stewart 	}
10780fefe0aSRandall Stewart 	sctp_clog.x.close.loc = loc;
108c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
10980fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_CLOSE,
11080fefe0aSRandall Stewart 	    0,
11180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
11280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
11380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
11480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
115c692df45SMichael Tuexen #endif
116f8829a4aSRandall Stewart }
117f8829a4aSRandall Stewart 
118f8829a4aSRandall Stewart void
119f8829a4aSRandall Stewart rto_logging(struct sctp_nets *net, int from)
120f8829a4aSRandall Stewart {
121c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
122c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
123f8829a4aSRandall Stewart 
124bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
12580fefe0aSRandall Stewart 	sctp_clog.x.rto.net = (void *)net;
126be1d9176SMichael Tuexen 	sctp_clog.x.rto.rtt = net->rtt / 1000;
127c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
12880fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RTT,
12980fefe0aSRandall Stewart 	    from,
13080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
13180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
13280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
13380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
134c692df45SMichael Tuexen #endif
135f8829a4aSRandall Stewart }
136f8829a4aSRandall Stewart 
137f8829a4aSRandall Stewart void
1386a91f103SRandall Stewart sctp_log_strm_del_alt(struct sctp_tcb *stcb, uint32_t tsn, uint16_t sseq, uint16_t stream, int from)
139f8829a4aSRandall Stewart {
140c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
141c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
142f8829a4aSRandall Stewart 
14380fefe0aSRandall Stewart 	sctp_clog.x.strlog.stcb = stcb;
14480fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_tsn = tsn;
14580fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_sseq = sseq;
14680fefe0aSRandall Stewart 	sctp_clog.x.strlog.e_tsn = 0;
14780fefe0aSRandall Stewart 	sctp_clog.x.strlog.e_sseq = 0;
14880fefe0aSRandall Stewart 	sctp_clog.x.strlog.strm = stream;
149c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
15080fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_STRM,
15180fefe0aSRandall Stewart 	    from,
15280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
15380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
15480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
15580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
156c692df45SMichael Tuexen #endif
157f8829a4aSRandall Stewart }
158f8829a4aSRandall Stewart 
159f8829a4aSRandall Stewart void
160f8829a4aSRandall Stewart sctp_log_nagle_event(struct sctp_tcb *stcb, int action)
161f8829a4aSRandall Stewart {
162c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
163c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
164f8829a4aSRandall Stewart 
16580fefe0aSRandall Stewart 	sctp_clog.x.nagle.stcb = (void *)stcb;
16680fefe0aSRandall Stewart 	sctp_clog.x.nagle.total_flight = stcb->asoc.total_flight;
16780fefe0aSRandall Stewart 	sctp_clog.x.nagle.total_in_queue = stcb->asoc.total_output_queue_size;
16880fefe0aSRandall Stewart 	sctp_clog.x.nagle.count_in_queue = stcb->asoc.chunks_on_out_queue;
16980fefe0aSRandall Stewart 	sctp_clog.x.nagle.count_in_flight = stcb->asoc.total_flight_count;
170c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
17180fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_NAGLE,
17280fefe0aSRandall Stewart 	    action,
17380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
17480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
17580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
17680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
177c692df45SMichael Tuexen #endif
178f8829a4aSRandall Stewart }
179f8829a4aSRandall Stewart 
180f8829a4aSRandall Stewart void
181f8829a4aSRandall Stewart sctp_log_sack(uint32_t old_cumack, uint32_t cumack, uint32_t tsn, uint16_t gaps, uint16_t dups, int from)
182f8829a4aSRandall Stewart {
183c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
184c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
185f8829a4aSRandall Stewart 
18680fefe0aSRandall Stewart 	sctp_clog.x.sack.cumack = cumack;
18780fefe0aSRandall Stewart 	sctp_clog.x.sack.oldcumack = old_cumack;
18880fefe0aSRandall Stewart 	sctp_clog.x.sack.tsn = tsn;
18980fefe0aSRandall Stewart 	sctp_clog.x.sack.numGaps = gaps;
19080fefe0aSRandall Stewart 	sctp_clog.x.sack.numDups = dups;
191c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
19280fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_SACK,
19380fefe0aSRandall Stewart 	    from,
19480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
19580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
19680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
19780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
198c692df45SMichael Tuexen #endif
199f8829a4aSRandall Stewart }
200f8829a4aSRandall Stewart 
201f8829a4aSRandall Stewart void
202f8829a4aSRandall Stewart sctp_log_map(uint32_t map, uint32_t cum, uint32_t high, int from)
203f8829a4aSRandall Stewart {
204c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
205c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
206f8829a4aSRandall Stewart 
207bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
20880fefe0aSRandall Stewart 	sctp_clog.x.map.base = map;
20980fefe0aSRandall Stewart 	sctp_clog.x.map.cum = cum;
21080fefe0aSRandall Stewart 	sctp_clog.x.map.high = high;
211c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
21280fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MAP,
21380fefe0aSRandall Stewart 	    from,
21480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
21580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
21680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
21780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
218c692df45SMichael Tuexen #endif
219f8829a4aSRandall Stewart }
220f8829a4aSRandall Stewart 
221f8829a4aSRandall Stewart void
222dcb68fbaSMichael Tuexen sctp_log_fr(uint32_t biggest_tsn, uint32_t biggest_new_tsn, uint32_t tsn, int from)
223f8829a4aSRandall Stewart {
224c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
225c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
226f8829a4aSRandall Stewart 
227bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
22880fefe0aSRandall Stewart 	sctp_clog.x.fr.largest_tsn = biggest_tsn;
22980fefe0aSRandall Stewart 	sctp_clog.x.fr.largest_new_tsn = biggest_new_tsn;
23080fefe0aSRandall Stewart 	sctp_clog.x.fr.tsn = tsn;
231c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
23280fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_FR,
23380fefe0aSRandall Stewart 	    from,
23480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
23580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
23680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
23780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
238c692df45SMichael Tuexen #endif
239f8829a4aSRandall Stewart }
240f8829a4aSRandall Stewart 
2414be807c4SMichael Tuexen #ifdef SCTP_MBUF_LOGGING
242f8829a4aSRandall Stewart void
243f8829a4aSRandall Stewart sctp_log_mb(struct mbuf *m, int from)
244f8829a4aSRandall Stewart {
245c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
246c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
247f8829a4aSRandall Stewart 
24880fefe0aSRandall Stewart 	sctp_clog.x.mb.mp = m;
24980fefe0aSRandall Stewart 	sctp_clog.x.mb.mbuf_flags = (uint8_t)(SCTP_BUF_GET_FLAGS(m));
25080fefe0aSRandall Stewart 	sctp_clog.x.mb.size = (uint16_t)(SCTP_BUF_LEN(m));
25180fefe0aSRandall Stewart 	sctp_clog.x.mb.data = SCTP_BUF_AT(m, 0);
252139bc87fSRandall Stewart 	if (SCTP_BUF_IS_EXTENDED(m)) {
25380fefe0aSRandall Stewart 		sctp_clog.x.mb.ext = SCTP_BUF_EXTEND_BASE(m);
25480fefe0aSRandall Stewart 		sctp_clog.x.mb.refcnt = (uint8_t)(SCTP_BUF_EXTEND_REFCNT(m));
255f8829a4aSRandall Stewart 	} else {
25680fefe0aSRandall Stewart 		sctp_clog.x.mb.ext = 0;
25780fefe0aSRandall Stewart 		sctp_clog.x.mb.refcnt = 0;
258f8829a4aSRandall Stewart 	}
259c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
26080fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MBUF,
26180fefe0aSRandall Stewart 	    from,
26280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
26380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
26480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
26580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
266c692df45SMichael Tuexen #endif
267f8829a4aSRandall Stewart }
268f8829a4aSRandall Stewart 
269f8829a4aSRandall Stewart void
2704be807c4SMichael Tuexen sctp_log_mbc(struct mbuf *m, int from)
2714be807c4SMichael Tuexen {
2724be807c4SMichael Tuexen 	struct mbuf *mat;
2734be807c4SMichael Tuexen 
2744be807c4SMichael Tuexen 	for (mat = m; mat; mat = SCTP_BUF_NEXT(mat)) {
2754be807c4SMichael Tuexen 		sctp_log_mb(mat, from);
2764be807c4SMichael Tuexen 	}
2774be807c4SMichael Tuexen }
2784be807c4SMichael Tuexen #endif
2794be807c4SMichael Tuexen 
2804be807c4SMichael Tuexen void
281dcb68fbaSMichael Tuexen sctp_log_strm_del(struct sctp_queued_to_read *control, struct sctp_queued_to_read *poschk, int from)
282f8829a4aSRandall Stewart {
283c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
284c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
285f8829a4aSRandall Stewart 
286f8829a4aSRandall Stewart 	if (control == NULL) {
287ad81507eSRandall Stewart 		SCTP_PRINTF("Gak log of NULL?\n");
288f8829a4aSRandall Stewart 		return;
289f8829a4aSRandall Stewart 	}
29080fefe0aSRandall Stewart 	sctp_clog.x.strlog.stcb = control->stcb;
29180fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_tsn = control->sinfo_tsn;
29249656eefSMichael Tuexen 	sctp_clog.x.strlog.n_sseq = (uint16_t)control->mid;
29380fefe0aSRandall Stewart 	sctp_clog.x.strlog.strm = control->sinfo_stream;
294f8829a4aSRandall Stewart 	if (poschk != NULL) {
29580fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_tsn = poschk->sinfo_tsn;
29649656eefSMichael Tuexen 		sctp_clog.x.strlog.e_sseq = (uint16_t)poschk->mid;
297f8829a4aSRandall Stewart 	} else {
29880fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_tsn = 0;
29980fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_sseq = 0;
300f8829a4aSRandall Stewart 	}
301c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
30280fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_STRM,
30380fefe0aSRandall Stewart 	    from,
30480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
30580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
30680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
30780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
308c692df45SMichael Tuexen #endif
309f8829a4aSRandall Stewart }
310f8829a4aSRandall Stewart 
311f8829a4aSRandall Stewart void
312f8829a4aSRandall Stewart sctp_log_cwnd(struct sctp_tcb *stcb, struct sctp_nets *net, int augment, uint8_t from)
313f8829a4aSRandall Stewart {
314c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
315c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
316f8829a4aSRandall Stewart 
31780fefe0aSRandall Stewart 	sctp_clog.x.cwnd.net = net;
318f8829a4aSRandall Stewart 	if (stcb->asoc.send_queue_cnt > 255)
31980fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = 255;
320f8829a4aSRandall Stewart 	else
32180fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = stcb->asoc.send_queue_cnt;
322f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt > 255)
32380fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = 255;
324f8829a4aSRandall Stewart 	else
32580fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = stcb->asoc.stream_queue_cnt;
326f8829a4aSRandall Stewart 
327f8829a4aSRandall Stewart 	if (net) {
32880fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cwnd_new_value = net->cwnd;
32980fefe0aSRandall Stewart 		sctp_clog.x.cwnd.inflight = net->flight_size;
33080fefe0aSRandall Stewart 		sctp_clog.x.cwnd.pseudo_cumack = net->pseudo_cumack;
33180fefe0aSRandall Stewart 		sctp_clog.x.cwnd.meets_pseudo_cumack = net->new_pseudo_cumack;
33280fefe0aSRandall Stewart 		sctp_clog.x.cwnd.need_new_pseudo_cumack = net->find_pseudo_cumack;
333f8829a4aSRandall Stewart 	}
334f8829a4aSRandall Stewart 	if (SCTP_CWNDLOG_PRESEND == from) {
33580fefe0aSRandall Stewart 		sctp_clog.x.cwnd.meets_pseudo_cumack = stcb->asoc.peers_rwnd;
336f8829a4aSRandall Stewart 	}
33780fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_augment = augment;
338c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
33980fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_CWND,
34080fefe0aSRandall Stewart 	    from,
34180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
34280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
34380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
34480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
345c692df45SMichael Tuexen #endif
346f8829a4aSRandall Stewart }
347f8829a4aSRandall Stewart 
348f8829a4aSRandall Stewart void
349f8829a4aSRandall Stewart sctp_log_lock(struct sctp_inpcb *inp, struct sctp_tcb *stcb, uint8_t from)
350f8829a4aSRandall Stewart {
351c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
352c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
353f8829a4aSRandall Stewart 
354bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
35503b0b021SRandall Stewart 	if (inp) {
35680fefe0aSRandall Stewart 		sctp_clog.x.lock.sock = (void *)inp->sctp_socket;
35703b0b021SRandall Stewart 
35803b0b021SRandall Stewart 	} else {
35980fefe0aSRandall Stewart 		sctp_clog.x.lock.sock = (void *)NULL;
36003b0b021SRandall Stewart 	}
36180fefe0aSRandall Stewart 	sctp_clog.x.lock.inp = (void *)inp;
362f8829a4aSRandall Stewart 	if (stcb) {
36380fefe0aSRandall Stewart 		sctp_clog.x.lock.tcb_lock = mtx_owned(&stcb->tcb_mtx);
364f8829a4aSRandall Stewart 	} else {
36580fefe0aSRandall Stewart 		sctp_clog.x.lock.tcb_lock = SCTP_LOCK_UNKNOWN;
366f8829a4aSRandall Stewart 	}
367f8829a4aSRandall Stewart 	if (inp) {
36880fefe0aSRandall Stewart 		sctp_clog.x.lock.inp_lock = mtx_owned(&inp->inp_mtx);
36980fefe0aSRandall Stewart 		sctp_clog.x.lock.create_lock = mtx_owned(&inp->inp_create_mtx);
370f8829a4aSRandall Stewart 	} else {
37180fefe0aSRandall Stewart 		sctp_clog.x.lock.inp_lock = SCTP_LOCK_UNKNOWN;
37280fefe0aSRandall Stewart 		sctp_clog.x.lock.create_lock = SCTP_LOCK_UNKNOWN;
373f8829a4aSRandall Stewart 	}
374b3f1ea41SRandall Stewart 	sctp_clog.x.lock.info_lock = rw_wowned(&SCTP_BASE_INFO(ipi_ep_mtx));
37552129fcdSRandall Stewart 	if (inp && (inp->sctp_socket)) {
376a1002174SMark Johnston 		sctp_clog.x.lock.sock_lock = mtx_owned(SOCK_MTX(inp->sctp_socket));
377a1002174SMark Johnston 		sctp_clog.x.lock.sockrcvbuf_lock = mtx_owned(SOCKBUF_MTX(&inp->sctp_socket->so_rcv));
378a1002174SMark Johnston 		sctp_clog.x.lock.socksndbuf_lock = mtx_owned(SOCKBUF_MTX(&inp->sctp_socket->so_snd));
379f8829a4aSRandall Stewart 	} else {
38080fefe0aSRandall Stewart 		sctp_clog.x.lock.sock_lock = SCTP_LOCK_UNKNOWN;
38180fefe0aSRandall Stewart 		sctp_clog.x.lock.sockrcvbuf_lock = SCTP_LOCK_UNKNOWN;
38280fefe0aSRandall Stewart 		sctp_clog.x.lock.socksndbuf_lock = SCTP_LOCK_UNKNOWN;
383f8829a4aSRandall Stewart 	}
384c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
38580fefe0aSRandall Stewart 	    SCTP_LOG_LOCK_EVENT,
38680fefe0aSRandall Stewart 	    from,
38780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
38880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
38980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
39080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
391c692df45SMichael Tuexen #endif
392f8829a4aSRandall Stewart }
393f8829a4aSRandall Stewart 
394f8829a4aSRandall Stewart void
395f8829a4aSRandall Stewart sctp_log_maxburst(struct sctp_tcb *stcb, struct sctp_nets *net, int error, int burst, uint8_t from)
396f8829a4aSRandall Stewart {
397c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
398c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
399f8829a4aSRandall Stewart 
400bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
40180fefe0aSRandall Stewart 	sctp_clog.x.cwnd.net = net;
40280fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_new_value = error;
40380fefe0aSRandall Stewart 	sctp_clog.x.cwnd.inflight = net->flight_size;
40480fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_augment = burst;
405f8829a4aSRandall Stewart 	if (stcb->asoc.send_queue_cnt > 255)
40680fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = 255;
407f8829a4aSRandall Stewart 	else
40880fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = stcb->asoc.send_queue_cnt;
409f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt > 255)
41080fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = 255;
411f8829a4aSRandall Stewart 	else
41280fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = stcb->asoc.stream_queue_cnt;
413c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
41480fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MAXBURST,
41580fefe0aSRandall Stewart 	    from,
41680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
41780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
41880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
41980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
420c692df45SMichael Tuexen #endif
421f8829a4aSRandall Stewart }
422f8829a4aSRandall Stewart 
423f8829a4aSRandall Stewart void
424f8829a4aSRandall Stewart sctp_log_rwnd(uint8_t from, uint32_t peers_rwnd, uint32_t snd_size, uint32_t overhead)
425f8829a4aSRandall Stewart {
426c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
427c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
428f8829a4aSRandall Stewart 
42980fefe0aSRandall Stewart 	sctp_clog.x.rwnd.rwnd = peers_rwnd;
43080fefe0aSRandall Stewart 	sctp_clog.x.rwnd.send_size = snd_size;
43180fefe0aSRandall Stewart 	sctp_clog.x.rwnd.overhead = overhead;
43280fefe0aSRandall Stewart 	sctp_clog.x.rwnd.new_rwnd = 0;
433c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
43480fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RWND,
43580fefe0aSRandall Stewart 	    from,
43680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
43780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
43880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
43980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
440c692df45SMichael Tuexen #endif
441f8829a4aSRandall Stewart }
442f8829a4aSRandall Stewart 
443f8829a4aSRandall Stewart void
444f8829a4aSRandall Stewart sctp_log_rwnd_set(uint8_t from, uint32_t peers_rwnd, uint32_t flight_size, uint32_t overhead, uint32_t a_rwndval)
445f8829a4aSRandall Stewart {
446c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
447c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
448f8829a4aSRandall Stewart 
44980fefe0aSRandall Stewart 	sctp_clog.x.rwnd.rwnd = peers_rwnd;
45080fefe0aSRandall Stewart 	sctp_clog.x.rwnd.send_size = flight_size;
45180fefe0aSRandall Stewart 	sctp_clog.x.rwnd.overhead = overhead;
45280fefe0aSRandall Stewart 	sctp_clog.x.rwnd.new_rwnd = a_rwndval;
453c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
45480fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RWND,
45580fefe0aSRandall Stewart 	    from,
45680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
45780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
45880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
45980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
460c692df45SMichael Tuexen #endif
461f8829a4aSRandall Stewart }
462f8829a4aSRandall Stewart 
4634be807c4SMichael Tuexen #ifdef SCTP_MBCNT_LOGGING
4644be807c4SMichael Tuexen static void
465f8829a4aSRandall Stewart sctp_log_mbcnt(uint8_t from, uint32_t total_oq, uint32_t book, uint32_t total_mbcnt_q, uint32_t mbcnt)
466f8829a4aSRandall Stewart {
467c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
468c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
469f8829a4aSRandall Stewart 
47080fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.total_queue_size = total_oq;
47180fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.size_change = book;
47280fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.total_queue_mb_size = total_mbcnt_q;
47380fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.mbcnt_change = mbcnt;
474c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
47580fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MBCNT,
47680fefe0aSRandall Stewart 	    from,
47780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
47880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
47980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
48080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
481c692df45SMichael Tuexen #endif
482f8829a4aSRandall Stewart }
4834be807c4SMichael Tuexen #endif
4844be807c4SMichael Tuexen 
485f8829a4aSRandall Stewart void
486f8829a4aSRandall Stewart sctp_misc_ints(uint8_t from, uint32_t a, uint32_t b, uint32_t c, uint32_t d)
487f8829a4aSRandall Stewart {
488c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
489c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
49080fefe0aSRandall Stewart 	    SCTP_LOG_MISC_EVENT,
49180fefe0aSRandall Stewart 	    from,
49280fefe0aSRandall Stewart 	    a, b, c, d);
493c692df45SMichael Tuexen #endif
494f8829a4aSRandall Stewart }
495f8829a4aSRandall Stewart 
496f8829a4aSRandall Stewart void
4977215cc1bSMichael Tuexen sctp_wakeup_log(struct sctp_tcb *stcb, uint32_t wake_cnt, int from)
498f8829a4aSRandall Stewart {
499c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
500c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
501f8829a4aSRandall Stewart 
50280fefe0aSRandall Stewart 	sctp_clog.x.wake.stcb = (void *)stcb;
50380fefe0aSRandall Stewart 	sctp_clog.x.wake.wake_cnt = wake_cnt;
50480fefe0aSRandall Stewart 	sctp_clog.x.wake.flight = stcb->asoc.total_flight_count;
50580fefe0aSRandall Stewart 	sctp_clog.x.wake.send_q = stcb->asoc.send_queue_cnt;
50680fefe0aSRandall Stewart 	sctp_clog.x.wake.sent_q = stcb->asoc.sent_queue_cnt;
507f8829a4aSRandall Stewart 
508f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt < 0xff)
50980fefe0aSRandall Stewart 		sctp_clog.x.wake.stream_qcnt = (uint8_t)stcb->asoc.stream_queue_cnt;
510f8829a4aSRandall Stewart 	else
51180fefe0aSRandall Stewart 		sctp_clog.x.wake.stream_qcnt = 0xff;
512f8829a4aSRandall Stewart 
513f8829a4aSRandall Stewart 	if (stcb->asoc.chunks_on_out_queue < 0xff)
51480fefe0aSRandall Stewart 		sctp_clog.x.wake.chunks_on_oque = (uint8_t)stcb->asoc.chunks_on_out_queue;
515f8829a4aSRandall Stewart 	else
51680fefe0aSRandall Stewart 		sctp_clog.x.wake.chunks_on_oque = 0xff;
517f8829a4aSRandall Stewart 
51880fefe0aSRandall Stewart 	sctp_clog.x.wake.sctpflags = 0;
519f8829a4aSRandall Stewart 	/* set in the defered mode stuff */
520f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_DONT_WAKE)
52180fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 1;
522f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_WAKEOUTPUT)
52380fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 2;
524f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_WAKEINPUT)
52580fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 4;
526f8829a4aSRandall Stewart 	/* what about the sb */
527f8829a4aSRandall Stewart 	if (stcb->sctp_socket) {
528f8829a4aSRandall Stewart 		struct socket *so = stcb->sctp_socket;
529f8829a4aSRandall Stewart 
53080fefe0aSRandall Stewart 		sctp_clog.x.wake.sbflags = (uint8_t)((so->so_snd.sb_flags & 0x00ff));
531f8829a4aSRandall Stewart 	} else {
53280fefe0aSRandall Stewart 		sctp_clog.x.wake.sbflags = 0xff;
533f8829a4aSRandall Stewart 	}
534c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
53580fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_WAKE,
53680fefe0aSRandall Stewart 	    from,
53780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
53880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
53980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
54080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
541c692df45SMichael Tuexen #endif
542f8829a4aSRandall Stewart }
543f8829a4aSRandall Stewart 
544f8829a4aSRandall Stewart void
54558e6eeefSMichael Tuexen sctp_log_block(uint8_t from, struct sctp_association *asoc, ssize_t sendlen)
546f8829a4aSRandall Stewart {
547c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
548c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
549f8829a4aSRandall Stewart 
55080fefe0aSRandall Stewart 	sctp_clog.x.blk.onsb = asoc->total_output_queue_size;
55180fefe0aSRandall Stewart 	sctp_clog.x.blk.send_sent_qcnt = (uint16_t)(asoc->send_queue_cnt + asoc->sent_queue_cnt);
55280fefe0aSRandall Stewart 	sctp_clog.x.blk.peer_rwnd = asoc->peers_rwnd;
55380fefe0aSRandall Stewart 	sctp_clog.x.blk.stream_qcnt = (uint16_t)asoc->stream_queue_cnt;
55480fefe0aSRandall Stewart 	sctp_clog.x.blk.chunks_on_oque = (uint16_t)asoc->chunks_on_out_queue;
55580fefe0aSRandall Stewart 	sctp_clog.x.blk.flight_size = (uint16_t)(asoc->total_flight / 1024);
5569a8e3088SMichael Tuexen 	sctp_clog.x.blk.sndlen = (uint32_t)sendlen;
557c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
55880fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_BLOCK,
55980fefe0aSRandall Stewart 	    from,
56080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
56180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
56280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
56380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
564c692df45SMichael Tuexen #endif
565f8829a4aSRandall Stewart }
566f8829a4aSRandall Stewart 
567f8829a4aSRandall Stewart int
5687215cc1bSMichael Tuexen sctp_fill_stat_log(void *optval SCTP_UNUSED, size_t *optsize SCTP_UNUSED)
569f8829a4aSRandall Stewart {
57080fefe0aSRandall Stewart 	/* May need to fix this if ktrdump does not work */
571f8829a4aSRandall Stewart 	return (0);
572f8829a4aSRandall Stewart }
573f8829a4aSRandall Stewart 
574f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
575f8829a4aSRandall Stewart uint8_t sctp_audit_data[SCTP_AUDIT_SIZE][2];
576f8829a4aSRandall Stewart static int sctp_audit_indx = 0;
577f8829a4aSRandall Stewart 
578f8829a4aSRandall Stewart static
579f8829a4aSRandall Stewart void
580f8829a4aSRandall Stewart sctp_print_audit_report(void)
581f8829a4aSRandall Stewart {
582f8829a4aSRandall Stewart 	int i;
583f8829a4aSRandall Stewart 	int cnt;
584f8829a4aSRandall Stewart 
585f8829a4aSRandall Stewart 	cnt = 0;
586f8829a4aSRandall Stewart 	for (i = sctp_audit_indx; i < SCTP_AUDIT_SIZE; i++) {
587f8829a4aSRandall Stewart 		if ((sctp_audit_data[i][0] == 0xe0) &&
588f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
589f8829a4aSRandall Stewart 			cnt = 0;
590ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
591f8829a4aSRandall Stewart 		} else if (sctp_audit_data[i][0] == 0xf0) {
592f8829a4aSRandall Stewart 			cnt = 0;
593ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
594f8829a4aSRandall Stewart 		} else if ((sctp_audit_data[i][0] == 0xc0) &&
595f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
596ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
597f8829a4aSRandall Stewart 			cnt = 0;
598f8829a4aSRandall Stewart 		}
599ad81507eSRandall Stewart 		SCTP_PRINTF("%2.2x%2.2x ", (uint32_t)sctp_audit_data[i][0],
600f8829a4aSRandall Stewart 		    (uint32_t)sctp_audit_data[i][1]);
601f8829a4aSRandall Stewart 		cnt++;
602f8829a4aSRandall Stewart 		if ((cnt % 14) == 0)
603ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
604f8829a4aSRandall Stewart 	}
605f8829a4aSRandall Stewart 	for (i = 0; i < sctp_audit_indx; i++) {
606f8829a4aSRandall Stewart 		if ((sctp_audit_data[i][0] == 0xe0) &&
607f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
608f8829a4aSRandall Stewart 			cnt = 0;
609ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
610f8829a4aSRandall Stewart 		} else if (sctp_audit_data[i][0] == 0xf0) {
611f8829a4aSRandall Stewart 			cnt = 0;
612ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
613f8829a4aSRandall Stewart 		} else if ((sctp_audit_data[i][0] == 0xc0) &&
614f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
615ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
616f8829a4aSRandall Stewart 			cnt = 0;
617f8829a4aSRandall Stewart 		}
618ad81507eSRandall Stewart 		SCTP_PRINTF("%2.2x%2.2x ", (uint32_t)sctp_audit_data[i][0],
619f8829a4aSRandall Stewart 		    (uint32_t)sctp_audit_data[i][1]);
620f8829a4aSRandall Stewart 		cnt++;
621f8829a4aSRandall Stewart 		if ((cnt % 14) == 0)
622ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
623f8829a4aSRandall Stewart 	}
624ad81507eSRandall Stewart 	SCTP_PRINTF("\n");
625f8829a4aSRandall Stewart }
626f8829a4aSRandall Stewart 
627f8829a4aSRandall Stewart void
628f8829a4aSRandall Stewart sctp_auditing(int from, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
629f8829a4aSRandall Stewart     struct sctp_nets *net)
630f8829a4aSRandall Stewart {
631f8829a4aSRandall Stewart 	int resend_cnt, tot_out, rep, tot_book_cnt;
632f8829a4aSRandall Stewart 	struct sctp_nets *lnet;
633f8829a4aSRandall Stewart 	struct sctp_tmit_chunk *chk;
634f8829a4aSRandall Stewart 
635f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = 0xAA;
636f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] = 0x000000ff & from;
637f8829a4aSRandall Stewart 	sctp_audit_indx++;
638f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
639f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
640f8829a4aSRandall Stewart 	}
641f8829a4aSRandall Stewart 	if (inp == NULL) {
642f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
643f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0x01;
644f8829a4aSRandall Stewart 		sctp_audit_indx++;
645f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
646f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
647f8829a4aSRandall Stewart 		}
648f8829a4aSRandall Stewart 		return;
649f8829a4aSRandall Stewart 	}
650f8829a4aSRandall Stewart 	if (stcb == NULL) {
651f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
652f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0x02;
653f8829a4aSRandall Stewart 		sctp_audit_indx++;
654f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
655f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
656f8829a4aSRandall Stewart 		}
657f8829a4aSRandall Stewart 		return;
658f8829a4aSRandall Stewart 	}
659f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = 0xA1;
660f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] =
661f8829a4aSRandall Stewart 	    (0x000000ff & stcb->asoc.sent_queue_retran_cnt);
662f8829a4aSRandall Stewart 	sctp_audit_indx++;
663f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
664f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
665f8829a4aSRandall Stewart 	}
666f8829a4aSRandall Stewart 	rep = 0;
667f8829a4aSRandall Stewart 	tot_book_cnt = 0;
668f8829a4aSRandall Stewart 	resend_cnt = tot_out = 0;
669f8829a4aSRandall Stewart 	TAILQ_FOREACH(chk, &stcb->asoc.sent_queue, sctp_next) {
670f8829a4aSRandall Stewart 		if (chk->sent == SCTP_DATAGRAM_RESEND) {
671f8829a4aSRandall Stewart 			resend_cnt++;
672f8829a4aSRandall Stewart 		} else if (chk->sent < SCTP_DATAGRAM_RESEND) {
673f8829a4aSRandall Stewart 			tot_out += chk->book_size;
674f8829a4aSRandall Stewart 			tot_book_cnt++;
675f8829a4aSRandall Stewart 		}
676f8829a4aSRandall Stewart 	}
677f8829a4aSRandall Stewart 	if (resend_cnt != stcb->asoc.sent_queue_retran_cnt) {
678f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
679f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA1;
680f8829a4aSRandall Stewart 		sctp_audit_indx++;
681f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
682f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
683f8829a4aSRandall Stewart 		}
684ad81507eSRandall Stewart 		SCTP_PRINTF("resend_cnt:%d asoc-tot:%d\n",
685f8829a4aSRandall Stewart 		    resend_cnt, stcb->asoc.sent_queue_retran_cnt);
686f8829a4aSRandall Stewart 		rep = 1;
687f8829a4aSRandall Stewart 		stcb->asoc.sent_queue_retran_cnt = resend_cnt;
688f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xA2;
689f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] =
690f8829a4aSRandall Stewart 		    (0x000000ff & stcb->asoc.sent_queue_retran_cnt);
691f8829a4aSRandall Stewart 		sctp_audit_indx++;
692f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
693f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
694f8829a4aSRandall Stewart 		}
695f8829a4aSRandall Stewart 	}
696f8829a4aSRandall Stewart 	if (tot_out != stcb->asoc.total_flight) {
697f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
698f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA2;
699f8829a4aSRandall Stewart 		sctp_audit_indx++;
700f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
701f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
702f8829a4aSRandall Stewart 		}
703f8829a4aSRandall Stewart 		rep = 1;
704ad81507eSRandall Stewart 		SCTP_PRINTF("tot_flt:%d asoc_tot:%d\n", tot_out,
705f8829a4aSRandall Stewart 		    (int)stcb->asoc.total_flight);
706f8829a4aSRandall Stewart 		stcb->asoc.total_flight = tot_out;
707f8829a4aSRandall Stewart 	}
708f8829a4aSRandall Stewart 	if (tot_book_cnt != stcb->asoc.total_flight_count) {
709f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
710f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA5;
711f8829a4aSRandall Stewart 		sctp_audit_indx++;
712f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
713f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
714f8829a4aSRandall Stewart 		}
715f8829a4aSRandall Stewart 		rep = 1;
716f31e6c7fSMichael Tuexen 		SCTP_PRINTF("tot_flt_book:%d\n", tot_book_cnt);
717f8829a4aSRandall Stewart 
718f8829a4aSRandall Stewart 		stcb->asoc.total_flight_count = tot_book_cnt;
719f8829a4aSRandall Stewart 	}
720f8829a4aSRandall Stewart 	tot_out = 0;
721f8829a4aSRandall Stewart 	TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
722f8829a4aSRandall Stewart 		tot_out += lnet->flight_size;
723f8829a4aSRandall Stewart 	}
724f8829a4aSRandall Stewart 	if (tot_out != stcb->asoc.total_flight) {
725f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
726f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA3;
727f8829a4aSRandall Stewart 		sctp_audit_indx++;
728f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
729f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
730f8829a4aSRandall Stewart 		}
731f8829a4aSRandall Stewart 		rep = 1;
732ad81507eSRandall Stewart 		SCTP_PRINTF("real flight:%d net total was %d\n",
733f8829a4aSRandall Stewart 		    stcb->asoc.total_flight, tot_out);
734f8829a4aSRandall Stewart 		/* now corrective action */
735f8829a4aSRandall Stewart 		TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
736f8829a4aSRandall Stewart 			tot_out = 0;
737f8829a4aSRandall Stewart 			TAILQ_FOREACH(chk, &stcb->asoc.sent_queue, sctp_next) {
738f8829a4aSRandall Stewart 				if ((chk->whoTo == lnet) &&
739f8829a4aSRandall Stewart 				    (chk->sent < SCTP_DATAGRAM_RESEND)) {
740f8829a4aSRandall Stewart 					tot_out += chk->book_size;
741f8829a4aSRandall Stewart 				}
742f8829a4aSRandall Stewart 			}
743f8829a4aSRandall Stewart 			if (lnet->flight_size != tot_out) {
744f31e6c7fSMichael Tuexen 				SCTP_PRINTF("net:%p flight was %d corrected to %d\n",
745dd294dceSMichael Tuexen 				    (void *)lnet, lnet->flight_size,
746ad81507eSRandall Stewart 				    tot_out);
747f8829a4aSRandall Stewart 				lnet->flight_size = tot_out;
748f8829a4aSRandall Stewart 			}
749f8829a4aSRandall Stewart 		}
750f8829a4aSRandall Stewart 	}
751f8829a4aSRandall Stewart 	if (rep) {
752f8829a4aSRandall Stewart 		sctp_print_audit_report();
753f8829a4aSRandall Stewart 	}
754f8829a4aSRandall Stewart }
755f8829a4aSRandall Stewart 
756f8829a4aSRandall Stewart void
757f8829a4aSRandall Stewart sctp_audit_log(uint8_t ev, uint8_t fd)
758f8829a4aSRandall Stewart {
759f8829a4aSRandall Stewart 
760f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = ev;
761f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] = fd;
762f8829a4aSRandall Stewart 	sctp_audit_indx++;
763f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
764f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
765f8829a4aSRandall Stewart 	}
766f8829a4aSRandall Stewart }
767f8829a4aSRandall Stewart 
768f8829a4aSRandall Stewart #endif
769f8829a4aSRandall Stewart 
770f8829a4aSRandall Stewart /*
77125ec3553SMichael Tuexen  * The conversion from time to ticks and vice versa is done by rounding
77225ec3553SMichael Tuexen  * upwards. This way we can test in the code the time to be positive and
77325ec3553SMichael Tuexen  * know that this corresponds to a positive number of ticks.
77425ec3553SMichael Tuexen  */
77525ec3553SMichael Tuexen 
77625ec3553SMichael Tuexen uint32_t
77725ec3553SMichael Tuexen sctp_msecs_to_ticks(uint32_t msecs)
77825ec3553SMichael Tuexen {
77925ec3553SMichael Tuexen 	uint64_t temp;
78025ec3553SMichael Tuexen 	uint32_t ticks;
78125ec3553SMichael Tuexen 
78225ec3553SMichael Tuexen 	if (hz == 1000) {
78325ec3553SMichael Tuexen 		ticks = msecs;
78425ec3553SMichael Tuexen 	} else {
78525ec3553SMichael Tuexen 		temp = (((uint64_t)msecs * hz) + 999) / 1000;
78625ec3553SMichael Tuexen 		if (temp > UINT32_MAX) {
78725ec3553SMichael Tuexen 			ticks = UINT32_MAX;
78825ec3553SMichael Tuexen 		} else {
78925ec3553SMichael Tuexen 			ticks = (uint32_t)temp;
79025ec3553SMichael Tuexen 		}
79125ec3553SMichael Tuexen 	}
79225ec3553SMichael Tuexen 	return (ticks);
79325ec3553SMichael Tuexen }
79425ec3553SMichael Tuexen 
79525ec3553SMichael Tuexen uint32_t
79625ec3553SMichael Tuexen sctp_ticks_to_msecs(uint32_t ticks)
79725ec3553SMichael Tuexen {
79825ec3553SMichael Tuexen 	uint64_t temp;
79925ec3553SMichael Tuexen 	uint32_t msecs;
80025ec3553SMichael Tuexen 
80125ec3553SMichael Tuexen 	if (hz == 1000) {
80225ec3553SMichael Tuexen 		msecs = ticks;
80325ec3553SMichael Tuexen 	} else {
80425ec3553SMichael Tuexen 		temp = (((uint64_t)ticks * 1000) + (hz - 1)) / hz;
80525ec3553SMichael Tuexen 		if (temp > UINT32_MAX) {
80625ec3553SMichael Tuexen 			msecs = UINT32_MAX;
80725ec3553SMichael Tuexen 		} else {
80825ec3553SMichael Tuexen 			msecs = (uint32_t)temp;
80925ec3553SMichael Tuexen 		}
81025ec3553SMichael Tuexen 	}
81125ec3553SMichael Tuexen 	return (msecs);
81225ec3553SMichael Tuexen }
81325ec3553SMichael Tuexen 
81425ec3553SMichael Tuexen uint32_t
81525ec3553SMichael Tuexen sctp_secs_to_ticks(uint32_t secs)
81625ec3553SMichael Tuexen {
81725ec3553SMichael Tuexen 	uint64_t temp;
81825ec3553SMichael Tuexen 	uint32_t ticks;
81925ec3553SMichael Tuexen 
82025ec3553SMichael Tuexen 	temp = (uint64_t)secs * hz;
82125ec3553SMichael Tuexen 	if (temp > UINT32_MAX) {
82225ec3553SMichael Tuexen 		ticks = UINT32_MAX;
82325ec3553SMichael Tuexen 	} else {
82425ec3553SMichael Tuexen 		ticks = (uint32_t)temp;
82525ec3553SMichael Tuexen 	}
82625ec3553SMichael Tuexen 	return (ticks);
82725ec3553SMichael Tuexen }
82825ec3553SMichael Tuexen 
82925ec3553SMichael Tuexen uint32_t
83025ec3553SMichael Tuexen sctp_ticks_to_secs(uint32_t ticks)
83125ec3553SMichael Tuexen {
83225ec3553SMichael Tuexen 	uint64_t temp;
83325ec3553SMichael Tuexen 	uint32_t secs;
83425ec3553SMichael Tuexen 
83525ec3553SMichael Tuexen 	temp = ((uint64_t)ticks + (hz - 1)) / hz;
83625ec3553SMichael Tuexen 	if (temp > UINT32_MAX) {
83725ec3553SMichael Tuexen 		secs = UINT32_MAX;
83825ec3553SMichael Tuexen 	} else {
83925ec3553SMichael Tuexen 		secs = (uint32_t)temp;
84025ec3553SMichael Tuexen 	}
84125ec3553SMichael Tuexen 	return (secs);
84225ec3553SMichael Tuexen }
84325ec3553SMichael Tuexen 
84425ec3553SMichael Tuexen /*
84512af6654SMichael Tuexen  * sctp_stop_timers_for_shutdown() should be called
84612af6654SMichael Tuexen  * when entering the SHUTDOWN_SENT or SHUTDOWN_ACK_SENT
84712af6654SMichael Tuexen  * state to make sure that all timers are stopped.
84812af6654SMichael Tuexen  */
84912af6654SMichael Tuexen void
85012af6654SMichael Tuexen sctp_stop_timers_for_shutdown(struct sctp_tcb *stcb)
85112af6654SMichael Tuexen {
8525555400aSMichael Tuexen 	struct sctp_inpcb *inp;
85312af6654SMichael Tuexen 	struct sctp_nets *net;
85412af6654SMichael Tuexen 
8555555400aSMichael Tuexen 	inp = stcb->sctp_ep;
85612af6654SMichael Tuexen 
8575555400aSMichael Tuexen 	sctp_timer_stop(SCTP_TIMER_TYPE_RECV, inp, stcb, NULL,
8585555400aSMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_12);
8595555400aSMichael Tuexen 	sctp_timer_stop(SCTP_TIMER_TYPE_STRRESET, inp, stcb, NULL,
8605555400aSMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_13);
8615555400aSMichael Tuexen 	sctp_timer_stop(SCTP_TIMER_TYPE_ASCONF, inp, stcb, NULL,
8625555400aSMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_14);
8635555400aSMichael Tuexen 	sctp_timer_stop(SCTP_TIMER_TYPE_AUTOCLOSE, inp, stcb, NULL,
8645555400aSMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_15);
8655555400aSMichael Tuexen 	TAILQ_FOREACH(net, &stcb->asoc.nets, sctp_next) {
8665555400aSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_PATHMTURAISE, inp, stcb, net,
8675555400aSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_16);
8685555400aSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_HEARTBEAT, inp, stcb, net,
8695555400aSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_17);
8705555400aSMichael Tuexen 	}
8715555400aSMichael Tuexen }
8725555400aSMichael Tuexen 
8735555400aSMichael Tuexen void
8748803350dSMichael Tuexen sctp_stop_association_timers(struct sctp_tcb *stcb, bool stop_assoc_kill_timer)
8755555400aSMichael Tuexen {
8765555400aSMichael Tuexen 	struct sctp_inpcb *inp;
8775555400aSMichael Tuexen 	struct sctp_nets *net;
8785555400aSMichael Tuexen 
8795555400aSMichael Tuexen 	inp = stcb->sctp_ep;
8805555400aSMichael Tuexen 	sctp_timer_stop(SCTP_TIMER_TYPE_RECV, inp, stcb, NULL,
8815555400aSMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_18);
8825555400aSMichael Tuexen 	sctp_timer_stop(SCTP_TIMER_TYPE_STRRESET, inp, stcb, NULL,
8835555400aSMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_19);
8848803350dSMichael Tuexen 	if (stop_assoc_kill_timer) {
8855555400aSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_ASOCKILL, inp, stcb, NULL,
8865555400aSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_20);
8875555400aSMichael Tuexen 	}
8885555400aSMichael Tuexen 	sctp_timer_stop(SCTP_TIMER_TYPE_ASCONF, inp, stcb, NULL,
8895555400aSMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_21);
8905555400aSMichael Tuexen 	sctp_timer_stop(SCTP_TIMER_TYPE_AUTOCLOSE, inp, stcb, NULL,
8915555400aSMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_22);
8925555400aSMichael Tuexen 	sctp_timer_stop(SCTP_TIMER_TYPE_SHUTDOWNGUARD, inp, stcb, NULL,
8935555400aSMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_23);
8945555400aSMichael Tuexen 	/* Mobility adaptation */
8955555400aSMichael Tuexen 	sctp_timer_stop(SCTP_TIMER_TYPE_PRIM_DELETED, inp, stcb, NULL,
8965555400aSMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_24);
8975555400aSMichael Tuexen 	TAILQ_FOREACH(net, &stcb->asoc.nets, sctp_next) {
8985555400aSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_SEND, inp, stcb, net,
8995555400aSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_25);
9005555400aSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_INIT, inp, stcb, net,
9015555400aSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_26);
9025555400aSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_SHUTDOWN, inp, stcb, net,
9035555400aSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_27);
9045555400aSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_COOKIE, inp, stcb, net,
9055555400aSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_28);
9065555400aSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_SHUTDOWNACK, inp, stcb, net,
9075555400aSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_29);
9085555400aSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_PATHMTURAISE, inp, stcb, net,
9095555400aSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_30);
9105555400aSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_HEARTBEAT, inp, stcb, net,
9115555400aSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_31);
91212af6654SMichael Tuexen 	}
91312af6654SMichael Tuexen }
91412af6654SMichael Tuexen 
91512af6654SMichael Tuexen /*
916589c42c2SMichael Tuexen  * A list of sizes based on typical mtu's, used only if next hop size not
917589c42c2SMichael Tuexen  * returned. These values MUST be multiples of 4 and MUST be ordered.
918f8829a4aSRandall Stewart  */
919437fc91aSMichael Tuexen static uint32_t sctp_mtu_sizes[] = {
920f8829a4aSRandall Stewart 	68,
921f8829a4aSRandall Stewart 	296,
922f8829a4aSRandall Stewart 	508,
923f8829a4aSRandall Stewart 	512,
924f8829a4aSRandall Stewart 	544,
925f8829a4aSRandall Stewart 	576,
926589c42c2SMichael Tuexen 	1004,
927f8829a4aSRandall Stewart 	1492,
928f8829a4aSRandall Stewart 	1500,
929f8829a4aSRandall Stewart 	1536,
930589c42c2SMichael Tuexen 	2000,
931f8829a4aSRandall Stewart 	2048,
932f8829a4aSRandall Stewart 	4352,
933f8829a4aSRandall Stewart 	4464,
93442078d5aSMichael Tuexen 	8168,
935589c42c2SMichael Tuexen 	17912,
936f8829a4aSRandall Stewart 	32000,
937589c42c2SMichael Tuexen 	65532
938f8829a4aSRandall Stewart };
939f8829a4aSRandall Stewart 
940f8829a4aSRandall Stewart /*
941589c42c2SMichael Tuexen  * Return the largest MTU in sctp_mtu_sizes smaller than val.
942589c42c2SMichael Tuexen  * If val is smaller than the minimum, just return the largest
943589c42c2SMichael Tuexen  * multiple of 4 smaller or equal to val.
944589c42c2SMichael Tuexen  * Ensure that the result is a multiple of 4.
945f8829a4aSRandall Stewart  */
946437fc91aSMichael Tuexen uint32_t
947b0471b4bSMichael Tuexen sctp_get_prev_mtu(uint32_t val)
948b0471b4bSMichael Tuexen {
949437fc91aSMichael Tuexen 	uint32_t i;
950437fc91aSMichael Tuexen 
951eef8d4a9SMichael Tuexen 	val &= 0xfffffffc;
952437fc91aSMichael Tuexen 	if (val <= sctp_mtu_sizes[0]) {
953437fc91aSMichael Tuexen 		return (val);
954437fc91aSMichael Tuexen 	}
955437fc91aSMichael Tuexen 	for (i = 1; i < (sizeof(sctp_mtu_sizes) / sizeof(uint32_t)); i++) {
956437fc91aSMichael Tuexen 		if (val <= sctp_mtu_sizes[i]) {
957f8829a4aSRandall Stewart 			break;
958f8829a4aSRandall Stewart 		}
959f8829a4aSRandall Stewart 	}
960589c42c2SMichael Tuexen 	KASSERT((sctp_mtu_sizes[i - 1] & 0x00000003) == 0,
961589c42c2SMichael Tuexen 	    ("sctp_mtu_sizes[%u] not a multiple of 4", i - 1));
962437fc91aSMichael Tuexen 	return (sctp_mtu_sizes[i - 1]);
963437fc91aSMichael Tuexen }
964437fc91aSMichael Tuexen 
965437fc91aSMichael Tuexen /*
966589c42c2SMichael Tuexen  * Return the smallest MTU in sctp_mtu_sizes larger than val.
967589c42c2SMichael Tuexen  * If val is larger than the maximum, just return the largest multiple of 4 smaller
968589c42c2SMichael Tuexen  * or equal to val.
969589c42c2SMichael Tuexen  * Ensure that the result is a multiple of 4.
970437fc91aSMichael Tuexen  */
971437fc91aSMichael Tuexen uint32_t
972b0471b4bSMichael Tuexen sctp_get_next_mtu(uint32_t val)
973b0471b4bSMichael Tuexen {
974437fc91aSMichael Tuexen 	/* select another MTU that is just bigger than this one */
975437fc91aSMichael Tuexen 	uint32_t i;
976437fc91aSMichael Tuexen 
977eef8d4a9SMichael Tuexen 	val &= 0xfffffffc;
978437fc91aSMichael Tuexen 	for (i = 0; i < (sizeof(sctp_mtu_sizes) / sizeof(uint32_t)); i++) {
979437fc91aSMichael Tuexen 		if (val < sctp_mtu_sizes[i]) {
980589c42c2SMichael Tuexen 			KASSERT((sctp_mtu_sizes[i] & 0x00000003) == 0,
981589c42c2SMichael Tuexen 			    ("sctp_mtu_sizes[%u] not a multiple of 4", i));
982437fc91aSMichael Tuexen 			return (sctp_mtu_sizes[i]);
983437fc91aSMichael Tuexen 		}
984437fc91aSMichael Tuexen 	}
985437fc91aSMichael Tuexen 	return (val);
986f8829a4aSRandall Stewart }
987f8829a4aSRandall Stewart 
988f8829a4aSRandall Stewart void
989f8829a4aSRandall Stewart sctp_fill_random_store(struct sctp_pcb *m)
990f8829a4aSRandall Stewart {
991f8829a4aSRandall Stewart 	/*
992f8829a4aSRandall Stewart 	 * Here we use the MD5/SHA-1 to hash with our good randomNumbers and
993f8829a4aSRandall Stewart 	 * our counter. The result becomes our good random numbers and we
994f8829a4aSRandall Stewart 	 * then setup to give these out. Note that we do no locking to
995f8829a4aSRandall Stewart 	 * protect this. This is ok, since if competing folks call this we
99617205eccSRandall Stewart 	 * will get more gobbled gook in the random store which is what we
997f8829a4aSRandall Stewart 	 * want. There is a danger that two guys will use the same random
998f8829a4aSRandall Stewart 	 * numbers, but thats ok too since that is random as well :->
999f8829a4aSRandall Stewart 	 */
1000f8829a4aSRandall Stewart 	m->store_at = 0;
1001ad81507eSRandall Stewart 	(void)sctp_hmac(SCTP_HMAC, (uint8_t *)m->random_numbers,
1002f8829a4aSRandall Stewart 	    sizeof(m->random_numbers), (uint8_t *)&m->random_counter,
1003f8829a4aSRandall Stewart 	    sizeof(m->random_counter), (uint8_t *)m->random_store);
1004f8829a4aSRandall Stewart 	m->random_counter++;
1005f8829a4aSRandall Stewart }
1006f8829a4aSRandall Stewart 
1007f8829a4aSRandall Stewart uint32_t
1008b0471b4bSMichael Tuexen sctp_select_initial_TSN(struct sctp_pcb *inp)
1009b0471b4bSMichael Tuexen {
1010f8829a4aSRandall Stewart 	/*
1011f8829a4aSRandall Stewart 	 * A true implementation should use random selection process to get
1012f8829a4aSRandall Stewart 	 * the initial stream sequence number, using RFC1750 as a good
1013f8829a4aSRandall Stewart 	 * guideline
1014f8829a4aSRandall Stewart 	 */
1015139bc87fSRandall Stewart 	uint32_t x, *xp;
1016f8829a4aSRandall Stewart 	uint8_t *p;
1017851b7298SRandall Stewart 	int store_at, new_store;
1018f8829a4aSRandall Stewart 
1019851b7298SRandall Stewart 	if (inp->initial_sequence_debug != 0) {
1020f8829a4aSRandall Stewart 		uint32_t ret;
1021f8829a4aSRandall Stewart 
1022851b7298SRandall Stewart 		ret = inp->initial_sequence_debug;
1023851b7298SRandall Stewart 		inp->initial_sequence_debug++;
1024f8829a4aSRandall Stewart 		return (ret);
1025f8829a4aSRandall Stewart 	}
1026851b7298SRandall Stewart retry:
1027851b7298SRandall Stewart 	store_at = inp->store_at;
1028851b7298SRandall Stewart 	new_store = store_at + sizeof(uint32_t);
1029851b7298SRandall Stewart 	if (new_store >= (SCTP_SIGNATURE_SIZE - 3)) {
1030851b7298SRandall Stewart 		new_store = 0;
1031f8829a4aSRandall Stewart 	}
1032851b7298SRandall Stewart 	if (!atomic_cmpset_int(&inp->store_at, store_at, new_store)) {
1033851b7298SRandall Stewart 		goto retry;
1034851b7298SRandall Stewart 	}
1035851b7298SRandall Stewart 	if (new_store == 0) {
1036851b7298SRandall Stewart 		/* Refill the random store */
1037851b7298SRandall Stewart 		sctp_fill_random_store(inp);
1038851b7298SRandall Stewart 	}
1039851b7298SRandall Stewart 	p = &inp->random_store[store_at];
1040139bc87fSRandall Stewart 	xp = (uint32_t *)p;
1041f8829a4aSRandall Stewart 	x = *xp;
1042f8829a4aSRandall Stewart 	return (x);
1043f8829a4aSRandall Stewart }
1044f8829a4aSRandall Stewart 
1045f8829a4aSRandall Stewart uint32_t
1046b0471b4bSMichael Tuexen sctp_select_a_tag(struct sctp_inpcb *inp, uint16_t lport, uint16_t rport, int check)
1047b0471b4bSMichael Tuexen {
10487215cc1bSMichael Tuexen 	uint32_t x;
1049f8829a4aSRandall Stewart 	struct timeval now;
1050f8829a4aSRandall Stewart 
10517215cc1bSMichael Tuexen 	if (check) {
10526e55db54SRandall Stewart 		(void)SCTP_GETTIME_TIMEVAL(&now);
10537215cc1bSMichael Tuexen 	}
10547215cc1bSMichael Tuexen 	for (;;) {
1055851b7298SRandall Stewart 		x = sctp_select_initial_TSN(&inp->sctp_ep);
1056f8829a4aSRandall Stewart 		if (x == 0) {
1057f8829a4aSRandall Stewart 			/* we never use 0 */
1058f8829a4aSRandall Stewart 			continue;
1059f8829a4aSRandall Stewart 		}
10607215cc1bSMichael Tuexen 		if (!check || sctp_is_vtag_good(x, lport, rport, &now)) {
10617215cc1bSMichael Tuexen 			break;
1062f8829a4aSRandall Stewart 		}
1063f8829a4aSRandall Stewart 	}
1064f8829a4aSRandall Stewart 	return (x);
1065f8829a4aSRandall Stewart }
1066f8829a4aSRandall Stewart 
1067e92c2a8dSMichael Tuexen int32_t
1068b0471b4bSMichael Tuexen sctp_map_assoc_state(int kernel_state)
1069b0471b4bSMichael Tuexen {
1070e92c2a8dSMichael Tuexen 	int32_t user_state;
1071e92c2a8dSMichael Tuexen 
1072e92c2a8dSMichael Tuexen 	if (kernel_state & SCTP_STATE_WAS_ABORTED) {
1073e92c2a8dSMichael Tuexen 		user_state = SCTP_CLOSED;
1074e92c2a8dSMichael Tuexen 	} else if (kernel_state & SCTP_STATE_SHUTDOWN_PENDING) {
1075e92c2a8dSMichael Tuexen 		user_state = SCTP_SHUTDOWN_PENDING;
1076e92c2a8dSMichael Tuexen 	} else {
1077e92c2a8dSMichael Tuexen 		switch (kernel_state & SCTP_STATE_MASK) {
1078e92c2a8dSMichael Tuexen 		case SCTP_STATE_EMPTY:
1079e92c2a8dSMichael Tuexen 			user_state = SCTP_CLOSED;
1080e92c2a8dSMichael Tuexen 			break;
1081e92c2a8dSMichael Tuexen 		case SCTP_STATE_INUSE:
1082e92c2a8dSMichael Tuexen 			user_state = SCTP_CLOSED;
1083e92c2a8dSMichael Tuexen 			break;
1084e92c2a8dSMichael Tuexen 		case SCTP_STATE_COOKIE_WAIT:
1085e92c2a8dSMichael Tuexen 			user_state = SCTP_COOKIE_WAIT;
1086e92c2a8dSMichael Tuexen 			break;
1087e92c2a8dSMichael Tuexen 		case SCTP_STATE_COOKIE_ECHOED:
1088e92c2a8dSMichael Tuexen 			user_state = SCTP_COOKIE_ECHOED;
1089e92c2a8dSMichael Tuexen 			break;
1090e92c2a8dSMichael Tuexen 		case SCTP_STATE_OPEN:
1091e92c2a8dSMichael Tuexen 			user_state = SCTP_ESTABLISHED;
1092e92c2a8dSMichael Tuexen 			break;
1093e92c2a8dSMichael Tuexen 		case SCTP_STATE_SHUTDOWN_SENT:
1094e92c2a8dSMichael Tuexen 			user_state = SCTP_SHUTDOWN_SENT;
1095e92c2a8dSMichael Tuexen 			break;
1096e92c2a8dSMichael Tuexen 		case SCTP_STATE_SHUTDOWN_RECEIVED:
1097e92c2a8dSMichael Tuexen 			user_state = SCTP_SHUTDOWN_RECEIVED;
1098e92c2a8dSMichael Tuexen 			break;
1099e92c2a8dSMichael Tuexen 		case SCTP_STATE_SHUTDOWN_ACK_SENT:
1100e92c2a8dSMichael Tuexen 			user_state = SCTP_SHUTDOWN_ACK_SENT;
1101e92c2a8dSMichael Tuexen 			break;
1102e92c2a8dSMichael Tuexen 		default:
1103e92c2a8dSMichael Tuexen 			user_state = SCTP_CLOSED;
1104e92c2a8dSMichael Tuexen 			break;
1105e92c2a8dSMichael Tuexen 		}
1106e92c2a8dSMichael Tuexen 	}
1107e92c2a8dSMichael Tuexen 	return (user_state);
1108e92c2a8dSMichael Tuexen }
1109e92c2a8dSMichael Tuexen 
1110f8829a4aSRandall Stewart int
1111a1cb341bSMichael Tuexen sctp_init_asoc(struct sctp_inpcb *inp, struct sctp_tcb *stcb,
1112c7f048abSMichael Tuexen     uint32_t override_tag, uint32_t initial_tsn, uint32_t vrf_id,
1113c7f048abSMichael Tuexen     uint16_t o_strms)
1114f8829a4aSRandall Stewart {
11150696e120SRandall Stewart 	struct sctp_association *asoc;
11160696e120SRandall Stewart 
1117f8829a4aSRandall Stewart 	/*
1118f8829a4aSRandall Stewart 	 * Anything set to zero is taken care of by the allocation routine's
1119f8829a4aSRandall Stewart 	 * bzero
1120f8829a4aSRandall Stewart 	 */
1121f8829a4aSRandall Stewart 
1122f8829a4aSRandall Stewart 	/*
1123f8829a4aSRandall Stewart 	 * Up front select what scoping to apply on addresses I tell my peer
1124f8829a4aSRandall Stewart 	 * Not sure what to do with these right now, we will need to come up
1125f8829a4aSRandall Stewart 	 * with a way to set them. We may need to pass them through from the
1126f8829a4aSRandall Stewart 	 * caller in the sctp_aloc_assoc() function.
1127f8829a4aSRandall Stewart 	 */
1128f8829a4aSRandall Stewart 	int i;
1129f0396ad1SMichael Tuexen #if defined(SCTP_DETAILED_STR_STATS)
1130f0396ad1SMichael Tuexen 	int j;
1131f0396ad1SMichael Tuexen #endif
1132f0396ad1SMichael Tuexen 
11330696e120SRandall Stewart 	asoc = &stcb->asoc;
1134f8829a4aSRandall Stewart 	/* init all variables to a known value. */
1135839d21d6SMichael Tuexen 	SCTP_SET_STATE(stcb, SCTP_STATE_INUSE);
1136a1cb341bSMichael Tuexen 	asoc->max_burst = inp->sctp_ep.max_burst;
1137a1cb341bSMichael Tuexen 	asoc->fr_max_burst = inp->sctp_ep.fr_max_burst;
113825ec3553SMichael Tuexen 	asoc->heart_beat_delay = sctp_ticks_to_msecs(inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_HEARTBEAT]);
1139a1cb341bSMichael Tuexen 	asoc->cookie_life = inp->sctp_ep.def_cookie_life;
1140a1cb341bSMichael Tuexen 	asoc->sctp_cmt_on_off = inp->sctp_cmt_on_off;
1141f342355aSMichael Tuexen 	asoc->ecn_supported = inp->ecn_supported;
1142dd973b0eSMichael Tuexen 	asoc->prsctp_supported = inp->prsctp_supported;
1143c79bec9cSMichael Tuexen 	asoc->auth_supported = inp->auth_supported;
1144c79bec9cSMichael Tuexen 	asoc->asconf_supported = inp->asconf_supported;
1145317e00efSMichael Tuexen 	asoc->reconfig_supported = inp->reconfig_supported;
1146caea9879SMichael Tuexen 	asoc->nrsack_supported = inp->nrsack_supported;
1147cb9b8e6fSMichael Tuexen 	asoc->pktdrop_supported = inp->pktdrop_supported;
114844249214SRandall Stewart 	asoc->idata_supported = inp->idata_supported;
114952640d61SMichael Tuexen 	asoc->rcv_edmid = inp->rcv_edmid;
115052640d61SMichael Tuexen 	asoc->snd_edmid = SCTP_EDMID_NONE;
1151ca85e948SMichael Tuexen 	asoc->sctp_cmt_pf = (uint8_t)0;
1152a1cb341bSMichael Tuexen 	asoc->sctp_frag_point = inp->sctp_frag_point;
1153a1cb341bSMichael Tuexen 	asoc->sctp_features = inp->sctp_features;
1154a1cb341bSMichael Tuexen 	asoc->default_dscp = inp->sctp_ep.default_dscp;
115559b6d5beSMichael Tuexen 	asoc->max_cwnd = inp->max_cwnd;
115642551e99SRandall Stewart #ifdef INET6
1157a1cb341bSMichael Tuexen 	if (inp->sctp_ep.default_flowlabel) {
1158a1cb341bSMichael Tuexen 		asoc->default_flowlabel = inp->sctp_ep.default_flowlabel;
115958bdb691SMichael Tuexen 	} else {
1160a1cb341bSMichael Tuexen 		if (inp->ip_inp.inp.inp_flags & IN6P_AUTOFLOWLABEL) {
1161a1cb341bSMichael Tuexen 			asoc->default_flowlabel = sctp_select_initial_TSN(&inp->sctp_ep);
116258bdb691SMichael Tuexen 			asoc->default_flowlabel &= 0x000fffff;
116358bdb691SMichael Tuexen 			asoc->default_flowlabel |= 0x80000000;
116458bdb691SMichael Tuexen 		} else {
1165f8829a4aSRandall Stewart 			asoc->default_flowlabel = 0;
116658bdb691SMichael Tuexen 		}
116758bdb691SMichael Tuexen 	}
1168f8829a4aSRandall Stewart #endif
11699f22f500SRandall Stewart 	asoc->sb_send_resv = 0;
1170f8829a4aSRandall Stewart 	if (override_tag) {
1171f8829a4aSRandall Stewart 		asoc->my_vtag = override_tag;
1172f8829a4aSRandall Stewart 	} else {
1173a1cb341bSMichael Tuexen 		asoc->my_vtag = sctp_select_a_tag(inp, stcb->sctp_ep->sctp_lport, stcb->rport, 1);
1174f8829a4aSRandall Stewart 	}
1175de0e935bSRandall Stewart 	/* Get the nonce tags */
1176a1cb341bSMichael Tuexen 	asoc->my_vtag_nonce = sctp_select_a_tag(inp, stcb->sctp_ep->sctp_lport, stcb->rport, 0);
1177a1cb341bSMichael Tuexen 	asoc->peer_vtag_nonce = sctp_select_a_tag(inp, stcb->sctp_ep->sctp_lport, stcb->rport, 0);
117842551e99SRandall Stewart 	asoc->vrf_id = vrf_id;
1179de0e935bSRandall Stewart 
118018e198d3SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
118118e198d3SRandall Stewart 	asoc->tsn_in_at = 0;
118218e198d3SRandall Stewart 	asoc->tsn_out_at = 0;
118318e198d3SRandall Stewart 	asoc->tsn_in_wrapped = 0;
118418e198d3SRandall Stewart 	asoc->tsn_out_wrapped = 0;
118518e198d3SRandall Stewart 	asoc->cumack_log_at = 0;
1186b201f536SRandall Stewart 	asoc->cumack_log_atsnt = 0;
118718e198d3SRandall Stewart #endif
118818e198d3SRandall Stewart #ifdef SCTP_FS_SPEC_LOG
118918e198d3SRandall Stewart 	asoc->fs_index = 0;
119018e198d3SRandall Stewart #endif
1191f8829a4aSRandall Stewart 	asoc->refcnt = 0;
1192f8829a4aSRandall Stewart 	asoc->assoc_up_sent = 0;
1193c7f048abSMichael Tuexen 	if (override_tag) {
1194c7f048abSMichael Tuexen 		asoc->init_seq_number = initial_tsn;
1195c7f048abSMichael Tuexen 	} else {
1196c7f048abSMichael Tuexen 		asoc->init_seq_number = sctp_select_initial_TSN(&inp->sctp_ep);
1197c7f048abSMichael Tuexen 	}
1198c7f048abSMichael Tuexen 	asoc->asconf_seq_out = asoc->init_seq_number;
1199c7f048abSMichael Tuexen 	asoc->str_reset_seq_out = asoc->init_seq_number;
1200c7f048abSMichael Tuexen 	asoc->sending_seq = asoc->init_seq_number;
1201c7f048abSMichael Tuexen 	asoc->asconf_seq_out_acked = asoc->init_seq_number - 1;
1202e7e65008SMichael Tuexen 	/* we are optimistic here */
1203830d754dSRandall Stewart 	asoc->peer_supports_nat = 0;
1204f8829a4aSRandall Stewart 	asoc->sent_queue_retran_cnt = 0;
1205f8829a4aSRandall Stewart 
1206f8829a4aSRandall Stewart 	/* for CMT */
12078933fa13SRandall Stewart 	asoc->last_net_cmt_send_started = NULL;
1208f8829a4aSRandall Stewart 
1209f8829a4aSRandall Stewart 	asoc->last_acked_seq = asoc->init_seq_number - 1;
1210c7f048abSMichael Tuexen 	asoc->advanced_peer_ack_point = asoc->init_seq_number - 1;
1211c7f048abSMichael Tuexen 	asoc->asconf_seq_in = asoc->init_seq_number - 1;
1212f8829a4aSRandall Stewart 
1213f8829a4aSRandall Stewart 	/* here we are different, we hold the next one we expect */
1214c7f048abSMichael Tuexen 	asoc->str_reset_seq_in = asoc->init_seq_number;
1215f8829a4aSRandall Stewart 
1216a1cb341bSMichael Tuexen 	asoc->initial_init_rto_max = inp->sctp_ep.initial_init_rto_max;
1217a1cb341bSMichael Tuexen 	asoc->initial_rto = inp->sctp_ep.initial_rto;
1218f8829a4aSRandall Stewart 
121928a6addeSMichael Tuexen 	asoc->default_mtu = inp->sctp_ep.default_mtu;
1220a1cb341bSMichael Tuexen 	asoc->max_init_times = inp->sctp_ep.max_init_times;
1221a1cb341bSMichael Tuexen 	asoc->max_send_times = inp->sctp_ep.max_send_times;
1222a1cb341bSMichael Tuexen 	asoc->def_net_failure = inp->sctp_ep.def_net_failure;
1223a1cb341bSMichael Tuexen 	asoc->def_net_pf_threshold = inp->sctp_ep.def_net_pf_threshold;
1224f8829a4aSRandall Stewart 	asoc->free_chunk_cnt = 0;
1225f8829a4aSRandall Stewart 
1226f8829a4aSRandall Stewart 	asoc->iam_blocking = 0;
1227a1cb341bSMichael Tuexen 	asoc->context = inp->sctp_context;
1228a1cb341bSMichael Tuexen 	asoc->local_strreset_support = inp->local_strreset_support;
1229a1cb341bSMichael Tuexen 	asoc->def_send = inp->def_send;
123025ec3553SMichael Tuexen 	asoc->delayed_ack = sctp_ticks_to_msecs(inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_RECV]);
1231a1cb341bSMichael Tuexen 	asoc->sack_freq = inp->sctp_ep.sctp_sack_freq;
1232f8829a4aSRandall Stewart 	asoc->pr_sctp_cnt = 0;
1233f8829a4aSRandall Stewart 	asoc->total_output_queue_size = 0;
1234f8829a4aSRandall Stewart 
1235a1cb341bSMichael Tuexen 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) {
1236a1cb341bSMichael Tuexen 		asoc->scope.ipv6_addr_legal = 1;
1237a1cb341bSMichael Tuexen 		if (SCTP_IPV6_V6ONLY(inp) == 0) {
1238a1cb341bSMichael Tuexen 			asoc->scope.ipv4_addr_legal = 1;
1239f8829a4aSRandall Stewart 		} else {
1240a1cb341bSMichael Tuexen 			asoc->scope.ipv4_addr_legal = 0;
1241f8829a4aSRandall Stewart 		}
1242f8829a4aSRandall Stewart 	} else {
1243a1cb341bSMichael Tuexen 		asoc->scope.ipv6_addr_legal = 0;
1244a1cb341bSMichael Tuexen 		asoc->scope.ipv4_addr_legal = 1;
1245f8829a4aSRandall Stewart 	}
1246f8829a4aSRandall Stewart 
1247a1cb341bSMichael Tuexen 	asoc->my_rwnd = max(SCTP_SB_LIMIT_RCV(inp->sctp_socket), SCTP_MINIMAL_RWND);
1248a1cb341bSMichael Tuexen 	asoc->peers_rwnd = SCTP_SB_LIMIT_RCV(inp->sctp_socket);
1249f8829a4aSRandall Stewart 
1250989453daSMichael Tuexen 	asoc->smallest_mtu = 0;
1251a1cb341bSMichael Tuexen 	asoc->minrto = inp->sctp_ep.sctp_minrto;
1252a1cb341bSMichael Tuexen 	asoc->maxrto = inp->sctp_ep.sctp_maxrto;
1253f8829a4aSRandall Stewart 
1254f8829a4aSRandall Stewart 	asoc->stream_locked_on = 0;
1255f8829a4aSRandall Stewart 	asoc->ecn_echo_cnt_onq = 0;
1256f8829a4aSRandall Stewart 	asoc->stream_locked = 0;
1257f8829a4aSRandall Stewart 
125842551e99SRandall Stewart 	asoc->send_sack = 1;
125942551e99SRandall Stewart 
126042551e99SRandall Stewart 	LIST_INIT(&asoc->sctp_restricted_addrs);
126142551e99SRandall Stewart 
1262f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->nets);
1263f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->pending_reply_queue);
12642afb3e84SRandall Stewart 	TAILQ_INIT(&asoc->asconf_ack_sent);
1265f8829a4aSRandall Stewart 	/* Setup to fill the hb random cache at first HB */
1266f8829a4aSRandall Stewart 	asoc->hb_random_idx = 4;
1267f8829a4aSRandall Stewart 
1268a1cb341bSMichael Tuexen 	asoc->sctp_autoclose_ticks = inp->sctp_ep.auto_close_time;
1269f8829a4aSRandall Stewart 
1270a1cb341bSMichael Tuexen 	stcb->asoc.congestion_control_module = inp->sctp_ep.sctp_default_cc_module;
1271a1cb341bSMichael Tuexen 	stcb->asoc.cc_functions = sctp_cc_functions[inp->sctp_ep.sctp_default_cc_module];
1272b54d3a6cSRandall Stewart 
1273a1cb341bSMichael Tuexen 	stcb->asoc.stream_scheduling_module = inp->sctp_ep.sctp_default_ss_module;
1274a1cb341bSMichael Tuexen 	stcb->asoc.ss_functions = sctp_ss_functions[inp->sctp_ep.sctp_default_ss_module];
1275f7a77f6fSMichael Tuexen 
1276b54d3a6cSRandall Stewart 	/*
1277f8829a4aSRandall Stewart 	 * Now the stream parameters, here we allocate space for all streams
1278f8829a4aSRandall Stewart 	 * that we request by default.
1279f8829a4aSRandall Stewart 	 */
1280ea44232bSRandall Stewart 	asoc->strm_realoutsize = asoc->streamoutcnt = asoc->pre_open_streams =
1281c979034bSMichael Tuexen 	    o_strms;
1282f8829a4aSRandall Stewart 	SCTP_MALLOC(asoc->strmout, struct sctp_stream_out *,
1283f8829a4aSRandall Stewart 	    asoc->streamoutcnt * sizeof(struct sctp_stream_out),
1284207304d4SRandall Stewart 	    SCTP_M_STRMO);
1285f8829a4aSRandall Stewart 	if (asoc->strmout == NULL) {
1286f8829a4aSRandall Stewart 		/* big trouble no memory */
1287c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
1288f8829a4aSRandall Stewart 		return (ENOMEM);
1289f8829a4aSRandall Stewart 	}
12905ac91821SMichael Tuexen 	SCTP_TCB_LOCK(stcb);
1291f8829a4aSRandall Stewart 	for (i = 0; i < asoc->streamoutcnt; i++) {
1292f8829a4aSRandall Stewart 		/*
1293f8829a4aSRandall Stewart 		 * inbound side must be set to 0xffff, also NOTE when we get
1294f8829a4aSRandall Stewart 		 * the INIT-ACK back (for INIT sender) we MUST reduce the
1295f8829a4aSRandall Stewart 		 * count (streamoutcnt) but first check if we sent to any of
1296f8829a4aSRandall Stewart 		 * the upper streams that were dropped (if some were). Those
1297f8829a4aSRandall Stewart 		 * that were dropped must be notified to the upper layer as
1298f8829a4aSRandall Stewart 		 * failed to send.
1299f8829a4aSRandall Stewart 		 */
1300f8829a4aSRandall Stewart 		TAILQ_INIT(&asoc->strmout[i].outqueue);
13017a051c0aSMichael Tuexen 		asoc->ss_functions.sctp_ss_init_stream(stcb, &asoc->strmout[i], NULL);
1302325c8c46SMichael Tuexen 		asoc->strmout[i].chunks_on_queues = 0;
1303f0396ad1SMichael Tuexen #if defined(SCTP_DETAILED_STR_STATS)
1304f0396ad1SMichael Tuexen 		for (j = 0; j < SCTP_PR_SCTP_MAX + 1; j++) {
1305f0396ad1SMichael Tuexen 			asoc->strmout[i].abandoned_sent[j] = 0;
1306f0396ad1SMichael Tuexen 			asoc->strmout[i].abandoned_unsent[j] = 0;
1307f0396ad1SMichael Tuexen 		}
1308f0396ad1SMichael Tuexen #else
1309f0396ad1SMichael Tuexen 		asoc->strmout[i].abandoned_sent[0] = 0;
1310f0396ad1SMichael Tuexen 		asoc->strmout[i].abandoned_unsent[0] = 0;
1311f0396ad1SMichael Tuexen #endif
13127a051c0aSMichael Tuexen 		asoc->strmout[i].next_mid_ordered = 0;
13137a051c0aSMichael Tuexen 		asoc->strmout[i].next_mid_unordered = 0;
131449656eefSMichael Tuexen 		asoc->strmout[i].sid = i;
1315f8829a4aSRandall Stewart 		asoc->strmout[i].last_msg_incomplete = 0;
13167cca1775SRandall Stewart 		asoc->strmout[i].state = SCTP_STREAM_OPENING;
1317f8829a4aSRandall Stewart 	}
1318762ae0ecSMichael Tuexen 	asoc->ss_functions.sctp_ss_init(stcb, asoc);
13195ac91821SMichael Tuexen 	SCTP_TCB_UNLOCK(stcb);
1320f7a77f6fSMichael Tuexen 
1321f8829a4aSRandall Stewart 	/* Now the mapping array */
1322f8829a4aSRandall Stewart 	asoc->mapping_array_size = SCTP_INITIAL_MAPPING_ARRAY;
1323f8829a4aSRandall Stewart 	SCTP_MALLOC(asoc->mapping_array, uint8_t *, asoc->mapping_array_size,
1324207304d4SRandall Stewart 	    SCTP_M_MAP);
1325f8829a4aSRandall Stewart 	if (asoc->mapping_array == NULL) {
1326207304d4SRandall Stewart 		SCTP_FREE(asoc->strmout, SCTP_M_STRMO);
1327c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
1328f8829a4aSRandall Stewart 		return (ENOMEM);
1329f8829a4aSRandall Stewart 	}
1330f8829a4aSRandall Stewart 	memset(asoc->mapping_array, 0, asoc->mapping_array_size);
1331b5c16493SMichael Tuexen 	SCTP_MALLOC(asoc->nr_mapping_array, uint8_t *, asoc->mapping_array_size,
1332830d754dSRandall Stewart 	    SCTP_M_MAP);
1333bf1be571SRandall Stewart 	if (asoc->nr_mapping_array == NULL) {
1334bf1be571SRandall Stewart 		SCTP_FREE(asoc->strmout, SCTP_M_STRMO);
1335bf1be571SRandall Stewart 		SCTP_FREE(asoc->mapping_array, SCTP_M_MAP);
1336bf1be571SRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
1337bf1be571SRandall Stewart 		return (ENOMEM);
1338bf1be571SRandall Stewart 	}
1339b5c16493SMichael Tuexen 	memset(asoc->nr_mapping_array, 0, asoc->mapping_array_size);
1340830d754dSRandall Stewart 
1341f8829a4aSRandall Stewart 	/* Now the init of the other outqueues */
1342f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->free_chunks);
1343f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->control_send_queue);
1344c54a18d2SRandall Stewart 	TAILQ_INIT(&asoc->asconf_send_queue);
1345f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->send_queue);
1346f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->sent_queue);
1347f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->resetHead);
1348a1cb341bSMichael Tuexen 	asoc->max_inbound_streams = inp->sctp_ep.max_open_streams_intome;
1349f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->asconf_queue);
1350f8829a4aSRandall Stewart 	/* authentication fields */
1351f8829a4aSRandall Stewart 	asoc->authinfo.random = NULL;
1352830d754dSRandall Stewart 	asoc->authinfo.active_keyid = 0;
1353f8829a4aSRandall Stewart 	asoc->authinfo.assoc_key = NULL;
1354f8829a4aSRandall Stewart 	asoc->authinfo.assoc_keyid = 0;
1355f8829a4aSRandall Stewart 	asoc->authinfo.recv_key = NULL;
1356f8829a4aSRandall Stewart 	asoc->authinfo.recv_keyid = 0;
1357f8829a4aSRandall Stewart 	LIST_INIT(&asoc->shared_keys);
1358f42a358aSRandall Stewart 	asoc->marked_retrans = 0;
1359a1cb341bSMichael Tuexen 	asoc->port = inp->sctp_ep.port;
1360f42a358aSRandall Stewart 	asoc->timoinit = 0;
1361f42a358aSRandall Stewart 	asoc->timodata = 0;
1362f42a358aSRandall Stewart 	asoc->timosack = 0;
1363f42a358aSRandall Stewart 	asoc->timoshutdown = 0;
1364f42a358aSRandall Stewart 	asoc->timoheartbeat = 0;
1365f42a358aSRandall Stewart 	asoc->timocookie = 0;
1366f42a358aSRandall Stewart 	asoc->timoshutdownack = 0;
13676e55db54SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&asoc->start_time);
13686e55db54SRandall Stewart 	asoc->discontinuity_time = asoc->start_time;
1369f0396ad1SMichael Tuexen 	for (i = 0; i < SCTP_PR_SCTP_MAX + 1; i++) {
1370f0396ad1SMichael Tuexen 		asoc->abandoned_unsent[i] = 0;
1371f0396ad1SMichael Tuexen 		asoc->abandoned_sent[i] = 0;
1372f0396ad1SMichael Tuexen 	}
1373eacc51c5SRandall Stewart 	/*
1374eacc51c5SRandall Stewart 	 * sa_ignore MEMLEAK {memory is put in the assoc mapping array and
137577acdc25SRandall Stewart 	 * freed later when the association is freed.
1376eacc51c5SRandall Stewart 	 */
1377f8829a4aSRandall Stewart 	return (0);
1378f8829a4aSRandall Stewart }
1379f8829a4aSRandall Stewart 
13800e13104dSRandall Stewart void
13810e13104dSRandall Stewart sctp_print_mapping_array(struct sctp_association *asoc)
13820e13104dSRandall Stewart {
1383aed5947cSMichael Tuexen 	unsigned int i, limit;
13840e13104dSRandall Stewart 
1385cd3fd531SMichael Tuexen 	SCTP_PRINTF("Mapping array size: %d, baseTSN: %8.8x, cumAck: %8.8x, highestTSN: (%8.8x, %8.8x).\n",
13860e13104dSRandall Stewart 	    asoc->mapping_array_size,
13870e13104dSRandall Stewart 	    asoc->mapping_array_base_tsn,
13880e13104dSRandall Stewart 	    asoc->cumulative_tsn,
1389aed5947cSMichael Tuexen 	    asoc->highest_tsn_inside_map,
1390aed5947cSMichael Tuexen 	    asoc->highest_tsn_inside_nr_map);
1391aed5947cSMichael Tuexen 	for (limit = asoc->mapping_array_size; limit > 1; limit--) {
139260990c0cSMichael Tuexen 		if (asoc->mapping_array[limit - 1] != 0) {
139377acdc25SRandall Stewart 			break;
139477acdc25SRandall Stewart 		}
139577acdc25SRandall Stewart 	}
1396cd3fd531SMichael Tuexen 	SCTP_PRINTF("Renegable mapping array (last %d entries are zero):\n", asoc->mapping_array_size - limit);
139777acdc25SRandall Stewart 	for (i = 0; i < limit; i++) {
1398cd3fd531SMichael Tuexen 		SCTP_PRINTF("%2.2x%c", asoc->mapping_array[i], ((i + 1) % 16) ? ' ' : '\n');
139977acdc25SRandall Stewart 	}
1400aed5947cSMichael Tuexen 	if (limit % 16)
1401cd3fd531SMichael Tuexen 		SCTP_PRINTF("\n");
1402aed5947cSMichael Tuexen 	for (limit = asoc->mapping_array_size; limit > 1; limit--) {
1403aed5947cSMichael Tuexen 		if (asoc->nr_mapping_array[limit - 1]) {
140477acdc25SRandall Stewart 			break;
140577acdc25SRandall Stewart 		}
140677acdc25SRandall Stewart 	}
1407cd3fd531SMichael Tuexen 	SCTP_PRINTF("Non renegable mapping array (last %d entries are zero):\n", asoc->mapping_array_size - limit);
140877acdc25SRandall Stewart 	for (i = 0; i < limit; i++) {
1409cd3fd531SMichael Tuexen 		SCTP_PRINTF("%2.2x%c", asoc->nr_mapping_array[i], ((i + 1) % 16) ? ' ' : '\n');
14100e13104dSRandall Stewart 	}
1411aed5947cSMichael Tuexen 	if (limit % 16)
1412cd3fd531SMichael Tuexen 		SCTP_PRINTF("\n");
14130e13104dSRandall Stewart }
14140e13104dSRandall Stewart 
1415f8829a4aSRandall Stewart int
14160696e120SRandall Stewart sctp_expand_mapping_array(struct sctp_association *asoc, uint32_t needed)
1417f8829a4aSRandall Stewart {
1418f8829a4aSRandall Stewart 	/* mapping array needs to grow */
1419b5c16493SMichael Tuexen 	uint8_t *new_array1, *new_array2;
14200696e120SRandall Stewart 	uint32_t new_size;
1421f8829a4aSRandall Stewart 
14220696e120SRandall Stewart 	new_size = asoc->mapping_array_size + ((needed + 7) / 8 + SCTP_MAPPING_ARRAY_INCR);
1423b5c16493SMichael Tuexen 	SCTP_MALLOC(new_array1, uint8_t *, new_size, SCTP_M_MAP);
1424b5c16493SMichael Tuexen 	SCTP_MALLOC(new_array2, uint8_t *, new_size, SCTP_M_MAP);
1425b5c16493SMichael Tuexen 	if ((new_array1 == NULL) || (new_array2 == NULL)) {
1426f8829a4aSRandall Stewart 		/* can't get more, forget it */
1427b5c16493SMichael Tuexen 		SCTP_PRINTF("No memory for expansion of SCTP mapping array %d\n", new_size);
1428b5c16493SMichael Tuexen 		if (new_array1) {
1429b5c16493SMichael Tuexen 			SCTP_FREE(new_array1, SCTP_M_MAP);
1430b5c16493SMichael Tuexen 		}
1431b5c16493SMichael Tuexen 		if (new_array2) {
1432b5c16493SMichael Tuexen 			SCTP_FREE(new_array2, SCTP_M_MAP);
1433b5c16493SMichael Tuexen 		}
1434f8829a4aSRandall Stewart 		return (-1);
1435f8829a4aSRandall Stewart 	}
1436b5c16493SMichael Tuexen 	memset(new_array1, 0, new_size);
1437b5c16493SMichael Tuexen 	memset(new_array2, 0, new_size);
1438b5c16493SMichael Tuexen 	memcpy(new_array1, asoc->mapping_array, asoc->mapping_array_size);
1439b5c16493SMichael Tuexen 	memcpy(new_array2, asoc->nr_mapping_array, asoc->mapping_array_size);
1440207304d4SRandall Stewart 	SCTP_FREE(asoc->mapping_array, SCTP_M_MAP);
1441830d754dSRandall Stewart 	SCTP_FREE(asoc->nr_mapping_array, SCTP_M_MAP);
1442b5c16493SMichael Tuexen 	asoc->mapping_array = new_array1;
1443b5c16493SMichael Tuexen 	asoc->nr_mapping_array = new_array2;
1444b5c16493SMichael Tuexen 	asoc->mapping_array_size = new_size;
1445830d754dSRandall Stewart 	return (0);
1446830d754dSRandall Stewart }
1447830d754dSRandall Stewart 
144842551e99SRandall Stewart static void
144942551e99SRandall Stewart sctp_iterator_work(struct sctp_iterator *it)
145042551e99SRandall Stewart {
1451868b51f2SMichael Tuexen 	struct epoch_tracker et;
1452868b51f2SMichael Tuexen 	struct sctp_inpcb *tinp;
145342551e99SRandall Stewart 	int iteration_count = 0;
145442551e99SRandall Stewart 	int inp_skip = 0;
1455ec4c19fcSRandall Stewart 	int first_in = 1;
145642551e99SRandall Stewart 
1457868b51f2SMichael Tuexen 	NET_EPOCH_ENTER(et);
1458ec4c19fcSRandall Stewart 	SCTP_INP_INFO_RLOCK();
145942551e99SRandall Stewart 	SCTP_ITERATOR_LOCK();
1460dcb436c9SMichael Tuexen 	sctp_it_ctl.cur_it = it;
1461ad81507eSRandall Stewart 	if (it->inp) {
1462ec4c19fcSRandall Stewart 		SCTP_INP_RLOCK(it->inp);
146342551e99SRandall Stewart 		SCTP_INP_DECR_REF(it->inp);
1464ad81507eSRandall Stewart 	}
146542551e99SRandall Stewart 	if (it->inp == NULL) {
146642551e99SRandall Stewart 		/* iterator is complete */
146742551e99SRandall Stewart done_with_iterator:
1468dcb436c9SMichael Tuexen 		sctp_it_ctl.cur_it = NULL;
146942551e99SRandall Stewart 		SCTP_ITERATOR_UNLOCK();
1470ec4c19fcSRandall Stewart 		SCTP_INP_INFO_RUNLOCK();
147142551e99SRandall Stewart 		if (it->function_atend != NULL) {
147242551e99SRandall Stewart 			(*it->function_atend) (it->pointer, it->val);
147342551e99SRandall Stewart 		}
1474207304d4SRandall Stewart 		SCTP_FREE(it, SCTP_M_ITER);
1475868b51f2SMichael Tuexen 		NET_EPOCH_EXIT(et);
147642551e99SRandall Stewart 		return;
147742551e99SRandall Stewart 	}
147842551e99SRandall Stewart select_a_new_ep:
1479ec4c19fcSRandall Stewart 	if (first_in) {
1480ec4c19fcSRandall Stewart 		first_in = 0;
1481ec4c19fcSRandall Stewart 	} else {
1482f7517433SRandall Stewart 		SCTP_INP_RLOCK(it->inp);
1483ec4c19fcSRandall Stewart 	}
148442551e99SRandall Stewart 	while (((it->pcb_flags) &&
148542551e99SRandall Stewart 	    ((it->inp->sctp_flags & it->pcb_flags) != it->pcb_flags)) ||
148642551e99SRandall Stewart 	    ((it->pcb_features) &&
148742551e99SRandall Stewart 	    ((it->inp->sctp_features & it->pcb_features) != it->pcb_features))) {
148842551e99SRandall Stewart 		/* endpoint flags or features don't match, so keep looking */
148942551e99SRandall Stewart 		if (it->iterator_flags & SCTP_ITERATOR_DO_SINGLE_INP) {
1490f7517433SRandall Stewart 			SCTP_INP_RUNLOCK(it->inp);
149142551e99SRandall Stewart 			goto done_with_iterator;
149242551e99SRandall Stewart 		}
1493ec4c19fcSRandall Stewart 		tinp = it->inp;
149442551e99SRandall Stewart 		it->inp = LIST_NEXT(it->inp, sctp_list);
149583ed5080SMichael Tuexen 		it->stcb = NULL;
1496ec4c19fcSRandall Stewart 		SCTP_INP_RUNLOCK(tinp);
149742551e99SRandall Stewart 		if (it->inp == NULL) {
149842551e99SRandall Stewart 			goto done_with_iterator;
149942551e99SRandall Stewart 		}
150042551e99SRandall Stewart 		SCTP_INP_RLOCK(it->inp);
1501f7517433SRandall Stewart 	}
150242551e99SRandall Stewart 	/* now go through each assoc which is in the desired state */
150342551e99SRandall Stewart 	if (it->done_current_ep == 0) {
150442551e99SRandall Stewart 		if (it->function_inp != NULL)
150542551e99SRandall Stewart 			inp_skip = (*it->function_inp) (it->inp, it->pointer, it->val);
150642551e99SRandall Stewart 		it->done_current_ep = 1;
150742551e99SRandall Stewart 	}
150842551e99SRandall Stewart 	if (it->stcb == NULL) {
150942551e99SRandall Stewart 		/* run the per instance function */
151042551e99SRandall Stewart 		it->stcb = LIST_FIRST(&it->inp->sctp_asoc_list);
151142551e99SRandall Stewart 	}
151242551e99SRandall Stewart 	if ((inp_skip) || it->stcb == NULL) {
151342551e99SRandall Stewart 		if (it->function_inp_end != NULL) {
151442551e99SRandall Stewart 			inp_skip = (*it->function_inp_end) (it->inp,
151542551e99SRandall Stewart 			    it->pointer,
151642551e99SRandall Stewart 			    it->val);
151742551e99SRandall Stewart 		}
151842551e99SRandall Stewart 		SCTP_INP_RUNLOCK(it->inp);
151942551e99SRandall Stewart 		goto no_stcb;
152042551e99SRandall Stewart 	}
152109063626SMichael Tuexen 	while (it->stcb != NULL) {
152242551e99SRandall Stewart 		SCTP_TCB_LOCK(it->stcb);
152342551e99SRandall Stewart 		if (it->asoc_state && ((it->stcb->asoc.state & it->asoc_state) != it->asoc_state)) {
152442551e99SRandall Stewart 			/* not in the right state... keep looking */
152542551e99SRandall Stewart 			SCTP_TCB_UNLOCK(it->stcb);
152642551e99SRandall Stewart 			goto next_assoc;
152742551e99SRandall Stewart 		}
152842551e99SRandall Stewart 		/* see if we have limited out the iterator loop */
152942551e99SRandall Stewart 		iteration_count++;
153042551e99SRandall Stewart 		if (iteration_count > SCTP_ITERATOR_MAX_AT_ONCE) {
153142551e99SRandall Stewart 			/* Pause to let others grab the lock */
153242551e99SRandall Stewart 			atomic_add_int(&it->stcb->asoc.refcnt, 1);
153342551e99SRandall Stewart 			SCTP_TCB_UNLOCK(it->stcb);
1534c4739e2fSRandall Stewart 			SCTP_INP_INCR_REF(it->inp);
153542551e99SRandall Stewart 			SCTP_INP_RUNLOCK(it->inp);
153642551e99SRandall Stewart 			SCTP_ITERATOR_UNLOCK();
1537ec4c19fcSRandall Stewart 			SCTP_INP_INFO_RUNLOCK();
1538ec4c19fcSRandall Stewart 			SCTP_INP_INFO_RLOCK();
153942551e99SRandall Stewart 			SCTP_ITERATOR_LOCK();
1540f7517433SRandall Stewart 			if (sctp_it_ctl.iterator_flags) {
1541f7517433SRandall Stewart 				/* We won't be staying here */
1542f7517433SRandall Stewart 				SCTP_INP_DECR_REF(it->inp);
15433c1ba6f3SMichael Tuexen 				atomic_subtract_int(&it->stcb->asoc.refcnt, 1);
1544f7517433SRandall Stewart 				if (sctp_it_ctl.iterator_flags &
1545f7517433SRandall Stewart 				    SCTP_ITERATOR_STOP_CUR_IT) {
1546f7517433SRandall Stewart 					sctp_it_ctl.iterator_flags &= ~SCTP_ITERATOR_STOP_CUR_IT;
1547f7517433SRandall Stewart 					goto done_with_iterator;
1548f7517433SRandall Stewart 				}
1549f7517433SRandall Stewart 				if (sctp_it_ctl.iterator_flags &
1550f7517433SRandall Stewart 				    SCTP_ITERATOR_STOP_CUR_INP) {
1551f7517433SRandall Stewart 					sctp_it_ctl.iterator_flags &= ~SCTP_ITERATOR_STOP_CUR_INP;
1552f7517433SRandall Stewart 					goto no_stcb;
1553f7517433SRandall Stewart 				}
1554f7517433SRandall Stewart 				/* If we reach here huh? */
1555cd3fd531SMichael Tuexen 				SCTP_PRINTF("Unknown it ctl flag %x\n",
1556f7517433SRandall Stewart 				    sctp_it_ctl.iterator_flags);
1557f7517433SRandall Stewart 				sctp_it_ctl.iterator_flags = 0;
1558f7517433SRandall Stewart 			}
155942551e99SRandall Stewart 			SCTP_INP_RLOCK(it->inp);
1560c4739e2fSRandall Stewart 			SCTP_INP_DECR_REF(it->inp);
156142551e99SRandall Stewart 			SCTP_TCB_LOCK(it->stcb);
15623c1ba6f3SMichael Tuexen 			atomic_subtract_int(&it->stcb->asoc.refcnt, 1);
156342551e99SRandall Stewart 			iteration_count = 0;
156442551e99SRandall Stewart 		}
156583ed5080SMichael Tuexen 		KASSERT(it->inp == it->stcb->sctp_ep,
156683ed5080SMichael Tuexen 		    ("%s: stcb %p does not belong to inp %p, but inp %p",
156783ed5080SMichael Tuexen 		    __func__, it->stcb, it->inp, it->stcb->sctp_ep));
156809063626SMichael Tuexen 		SCTP_INP_RLOCK_ASSERT(it->inp);
156909063626SMichael Tuexen 		SCTP_TCB_LOCK_ASSERT(it->stcb);
15700053ed28SMichael Tuexen 
157142551e99SRandall Stewart 		/* run function on this one */
157242551e99SRandall Stewart 		(*it->function_assoc) (it->inp, it->stcb, it->pointer, it->val);
157309063626SMichael Tuexen 		SCTP_INP_RLOCK_ASSERT(it->inp);
157409063626SMichael Tuexen 		SCTP_TCB_LOCK_ASSERT(it->stcb);
157542551e99SRandall Stewart 
157642551e99SRandall Stewart 		/*
157742551e99SRandall Stewart 		 * we lie here, it really needs to have its own type but
157842551e99SRandall Stewart 		 * first I must verify that this won't effect things :-0
157942551e99SRandall Stewart 		 */
158009063626SMichael Tuexen 		if (it->no_chunk_output == 0) {
1581ceaad40aSRandall Stewart 			sctp_chunk_output(it->inp, it->stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
158209063626SMichael Tuexen 			SCTP_INP_RLOCK_ASSERT(it->inp);
158309063626SMichael Tuexen 			SCTP_TCB_LOCK_ASSERT(it->stcb);
158409063626SMichael Tuexen 		}
158542551e99SRandall Stewart 
158642551e99SRandall Stewart 		SCTP_TCB_UNLOCK(it->stcb);
158742551e99SRandall Stewart next_assoc:
158842551e99SRandall Stewart 		it->stcb = LIST_NEXT(it->stcb, sctp_tcblist);
158942551e99SRandall Stewart 		if (it->stcb == NULL) {
159042551e99SRandall Stewart 			/* Run last function */
159142551e99SRandall Stewart 			if (it->function_inp_end != NULL) {
159242551e99SRandall Stewart 				inp_skip = (*it->function_inp_end) (it->inp,
159342551e99SRandall Stewart 				    it->pointer,
159442551e99SRandall Stewart 				    it->val);
159542551e99SRandall Stewart 			}
159642551e99SRandall Stewart 		}
159742551e99SRandall Stewart 	}
159842551e99SRandall Stewart 	SCTP_INP_RUNLOCK(it->inp);
159942551e99SRandall Stewart no_stcb:
160042551e99SRandall Stewart 	/* done with all assocs on this endpoint, move on to next endpoint */
160142551e99SRandall Stewart 	it->done_current_ep = 0;
160242551e99SRandall Stewart 	if (it->iterator_flags & SCTP_ITERATOR_DO_SINGLE_INP) {
160342551e99SRandall Stewart 		it->inp = NULL;
160442551e99SRandall Stewart 	} else {
160542551e99SRandall Stewart 		it->inp = LIST_NEXT(it->inp, sctp_list);
160642551e99SRandall Stewart 	}
160783ed5080SMichael Tuexen 	it->stcb = NULL;
160842551e99SRandall Stewart 	if (it->inp == NULL) {
160942551e99SRandall Stewart 		goto done_with_iterator;
161042551e99SRandall Stewart 	}
161142551e99SRandall Stewart 	goto select_a_new_ep;
161242551e99SRandall Stewart }
161342551e99SRandall Stewart 
161442551e99SRandall Stewart void
161542551e99SRandall Stewart sctp_iterator_worker(void)
161642551e99SRandall Stewart {
1617397b1c94SMichael Tuexen 	struct sctp_iterator *it;
161842551e99SRandall Stewart 
161942551e99SRandall Stewart 	/* This function is called with the WQ lock in place */
1620f7517433SRandall Stewart 	sctp_it_ctl.iterator_running = 1;
1621397b1c94SMichael Tuexen 	while ((it = TAILQ_FIRST(&sctp_it_ctl.iteratorhead)) != NULL) {
162242551e99SRandall Stewart 		/* now lets work on this one */
1623f7517433SRandall Stewart 		TAILQ_REMOVE(&sctp_it_ctl.iteratorhead, it, sctp_nxt_itr);
162442551e99SRandall Stewart 		SCTP_IPI_ITERATOR_WQ_UNLOCK();
1625f7517433SRandall Stewart 		CURVNET_SET(it->vn);
162642551e99SRandall Stewart 		sctp_iterator_work(it);
1627f7517433SRandall Stewart 		CURVNET_RESTORE();
162842551e99SRandall Stewart 		SCTP_IPI_ITERATOR_WQ_LOCK();
16293c503c28SRandall Stewart 		/* sa_ignore FREED_MEMORY */
163042551e99SRandall Stewart 	}
1631f7517433SRandall Stewart 	sctp_it_ctl.iterator_running = 0;
163242551e99SRandall Stewart 	return;
163342551e99SRandall Stewart }
163442551e99SRandall Stewart 
1635f8829a4aSRandall Stewart static void
1636f8829a4aSRandall Stewart sctp_handle_addr_wq(void)
1637f8829a4aSRandall Stewart {
1638f8829a4aSRandall Stewart 	/* deal with the ADDR wq from the rtsock calls */
16394a9ef3f8SMichael Tuexen 	struct sctp_laddr *wi, *nwi;
164042551e99SRandall Stewart 	struct sctp_asconf_iterator *asc;
1641f8829a4aSRandall Stewart 
164242551e99SRandall Stewart 	SCTP_MALLOC(asc, struct sctp_asconf_iterator *,
1643207304d4SRandall Stewart 	    sizeof(struct sctp_asconf_iterator), SCTP_M_ASC_IT);
164442551e99SRandall Stewart 	if (asc == NULL) {
164542551e99SRandall Stewart 		/* Try later, no memory */
1646f8829a4aSRandall Stewart 		sctp_timer_start(SCTP_TIMER_TYPE_ADDR_WQ,
1647f8829a4aSRandall Stewart 		    (struct sctp_inpcb *)NULL,
1648f8829a4aSRandall Stewart 		    (struct sctp_tcb *)NULL,
1649f8829a4aSRandall Stewart 		    (struct sctp_nets *)NULL);
165042551e99SRandall Stewart 		return;
1651f8829a4aSRandall Stewart 	}
165242551e99SRandall Stewart 	LIST_INIT(&asc->list_of_work);
165342551e99SRandall Stewart 	asc->cnt = 0;
1654f7517433SRandall Stewart 
16554a9ef3f8SMichael Tuexen 	LIST_FOREACH_SAFE(wi, &SCTP_BASE_INFO(addr_wq), sctp_nxt_addr, nwi) {
165642551e99SRandall Stewart 		LIST_REMOVE(wi, sctp_nxt_addr);
165742551e99SRandall Stewart 		LIST_INSERT_HEAD(&asc->list_of_work, wi, sctp_nxt_addr);
165842551e99SRandall Stewart 		asc->cnt++;
1659f8829a4aSRandall Stewart 	}
1660f7517433SRandall Stewart 
166142551e99SRandall Stewart 	if (asc->cnt == 0) {
1662207304d4SRandall Stewart 		SCTP_FREE(asc, SCTP_M_ASC_IT);
166342551e99SRandall Stewart 	} else {
16642b1c7de4SMichael Tuexen 		int ret;
16652b1c7de4SMichael Tuexen 
16662b1c7de4SMichael Tuexen 		ret = sctp_initiate_iterator(sctp_asconf_iterator_ep,
16671b649582SRandall Stewart 		    sctp_asconf_iterator_stcb,
166842551e99SRandall Stewart 		    NULL,	/* No ep end for boundall */
166942551e99SRandall Stewart 		    SCTP_PCB_FLAGS_BOUNDALL,
167042551e99SRandall Stewart 		    SCTP_PCB_ANY_FEATURES,
16711b649582SRandall Stewart 		    SCTP_ASOC_ANY_STATE,
16721b649582SRandall Stewart 		    (void *)asc, 0,
16731b649582SRandall Stewart 		    sctp_asconf_iterator_end, NULL, 0);
16742b1c7de4SMichael Tuexen 		if (ret) {
16752b1c7de4SMichael Tuexen 			SCTP_PRINTF("Failed to initiate iterator for handle_addr_wq\n");
1676b7b84c0eSMichael Tuexen 			/*
1677b7b84c0eSMichael Tuexen 			 * Freeing if we are stopping or put back on the
1678b7b84c0eSMichael Tuexen 			 * addr_wq.
1679b7b84c0eSMichael Tuexen 			 */
16802b1c7de4SMichael Tuexen 			if (SCTP_BASE_VAR(sctp_pcb_initialized) == 0) {
16812b1c7de4SMichael Tuexen 				sctp_asconf_iterator_end(asc, 0);
16822b1c7de4SMichael Tuexen 			} else {
16832b1c7de4SMichael Tuexen 				LIST_FOREACH(wi, &asc->list_of_work, sctp_nxt_addr) {
16842b1c7de4SMichael Tuexen 					LIST_INSERT_HEAD(&SCTP_BASE_INFO(addr_wq), wi, sctp_nxt_addr);
16852b1c7de4SMichael Tuexen 				}
16862b1c7de4SMichael Tuexen 				SCTP_FREE(asc, SCTP_M_ASC_IT);
16872b1c7de4SMichael Tuexen 			}
16882b1c7de4SMichael Tuexen 		}
168942551e99SRandall Stewart 	}
1690f8829a4aSRandall Stewart }
1691f8829a4aSRandall Stewart 
1692a412576eSMichael Tuexen /*-
1693a412576eSMichael Tuexen  * The following table shows which pointers for the inp, stcb, or net are
1694a412576eSMichael Tuexen  * stored for each timer after it was started.
1695a412576eSMichael Tuexen  *
1696a412576eSMichael Tuexen  *|Name                         |Timer                        |inp |stcb|net |
1697a412576eSMichael Tuexen  *|-----------------------------|-----------------------------|----|----|----|
1698a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_SEND         |net->rxt_timer               |Yes |Yes |Yes |
1699a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_INIT         |net->rxt_timer               |Yes |Yes |Yes |
1700a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_RECV         |stcb->asoc.dack_timer        |Yes |Yes |No  |
1701a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_SHUTDOWN     |net->rxt_timer               |Yes |Yes |Yes |
1702a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_HEARTBEAT    |net->hb_timer                |Yes |Yes |Yes |
1703a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_COOKIE       |net->rxt_timer               |Yes |Yes |Yes |
1704a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_NEWCOOKIE    |inp->sctp_ep.signature_change|Yes |No  |No  |
1705a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_PATHMTURAISE |net->pmtu_timer              |Yes |Yes |Yes |
1706a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_SHUTDOWNACK  |net->rxt_timer               |Yes |Yes |Yes |
1707a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_ASCONF       |stcb->asoc.asconf_timer      |Yes |Yes |Yes |
1708a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_SHUTDOWNGUARD|stcb->asoc.shut_guard_timer  |Yes |Yes |No  |
1709a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_AUTOCLOSE    |stcb->asoc.autoclose_timer   |Yes |Yes |No  |
1710a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_STRRESET     |stcb->asoc.strreset_timer    |Yes |Yes |No  |
1711a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_INPKILL      |inp->sctp_ep.signature_change|Yes |No  |No  |
1712a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_ASOCKILL     |stcb->asoc.strreset_timer    |Yes |Yes |No  |
1713a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_ADDR_WQ      |SCTP_BASE_INFO(addr_wq_timer)|No  |No  |No  |
1714a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_PRIM_DELETED |stcb->asoc.delete_prim_timer |Yes |Yes |No  |
1715a412576eSMichael Tuexen  */
1716a412576eSMichael Tuexen 
1717f8829a4aSRandall Stewart void
1718f8829a4aSRandall Stewart sctp_timeout_handler(void *t)
1719f8829a4aSRandall Stewart {
1720868b51f2SMichael Tuexen 	struct epoch_tracker et;
1721a412576eSMichael Tuexen 	struct timeval tv;
1722f8829a4aSRandall Stewart 	struct sctp_inpcb *inp;
1723f8829a4aSRandall Stewart 	struct sctp_tcb *stcb;
1724f8829a4aSRandall Stewart 	struct sctp_nets *net;
1725f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
1726267dbe63SMichael Tuexen 	struct mbuf *op_err;
1727fa89f692SMichael Tuexen 	int type;
1728a412576eSMichael Tuexen 	int i, secret;
17298745f898SMichael Tuexen 	bool did_output, released_asoc_reference;
1730f8829a4aSRandall Stewart 
17318745f898SMichael Tuexen 	/*
17328745f898SMichael Tuexen 	 * If inp, stcb or net are not NULL, then references to these were
17338745f898SMichael Tuexen 	 * added when the timer was started, and must be released before
17348745f898SMichael Tuexen 	 * this function returns.
17358745f898SMichael Tuexen 	 */
1736f8829a4aSRandall Stewart 	tmr = (struct sctp_timer *)t;
1737f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)tmr->ep;
1738f8829a4aSRandall Stewart 	stcb = (struct sctp_tcb *)tmr->tcb;
1739f8829a4aSRandall Stewart 	net = (struct sctp_nets *)tmr->net;
17408518270eSMichael Tuexen 	CURVNET_SET((struct vnet *)tmr->vnet);
174104996cb7SMichael Tuexen 	NET_EPOCH_ENTER(et);
17428745f898SMichael Tuexen 	released_asoc_reference = false;
1743f8829a4aSRandall Stewart 
1744f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1745f8829a4aSRandall Stewart 	sctp_audit_log(0xF0, (uint8_t)tmr->type);
1746f8829a4aSRandall Stewart 	sctp_auditing(3, inp, stcb, net);
1747f8829a4aSRandall Stewart #endif
1748f8829a4aSRandall Stewart 
1749f8829a4aSRandall Stewart 	/* sanity checks... */
17502d87bacdSMichael Tuexen 	KASSERT(tmr->self == NULL || tmr->self == tmr,
1751f4cb790aSMichael Tuexen 	    ("sctp_timeout_handler: tmr->self corrupted"));
1752f4cb790aSMichael Tuexen 	KASSERT(SCTP_IS_TIMER_TYPE_VALID(tmr->type),
1753f4cb790aSMichael Tuexen 	    ("sctp_timeout_handler: invalid timer type %d", tmr->type));
1754a412576eSMichael Tuexen 	type = tmr->type;
1755f4cb790aSMichael Tuexen 	KASSERT(stcb == NULL || stcb->sctp_ep == inp,
1756f4cb790aSMichael Tuexen 	    ("sctp_timeout_handler of type %d: inp = %p, stcb->sctp_ep %p",
1757f4cb790aSMichael Tuexen 	    type, stcb, stcb->sctp_ep));
17587c63520cSMichael Tuexen 	tmr->stopped_from = 0xa001;
17598745f898SMichael Tuexen 	if ((stcb != NULL) && (stcb->asoc.state == SCTP_STATE_EMPTY)) {
1760a412576eSMichael Tuexen 		SCTPDBG(SCTP_DEBUG_TIMER2,
176123e3c088SMichael Tuexen 		    "Timer type %d handler exiting due to CLOSED association.\n",
1762a412576eSMichael Tuexen 		    type);
17638745f898SMichael Tuexen 		goto out_decr;
1764f8829a4aSRandall Stewart 	}
17657c63520cSMichael Tuexen 	tmr->stopped_from = 0xa002;
176637686ccfSMichael Tuexen 	SCTPDBG(SCTP_DEBUG_TIMER2, "Timer type %d goes off.\n", type);
1767139bc87fSRandall Stewart 	if (!SCTP_OS_TIMER_ACTIVE(&tmr->timer)) {
1768a412576eSMichael Tuexen 		SCTPDBG(SCTP_DEBUG_TIMER2,
176923e3c088SMichael Tuexen 		    "Timer type %d handler exiting due to not being active.\n",
1770a412576eSMichael Tuexen 		    type);
17718745f898SMichael Tuexen 		goto out_decr;
1772f8829a4aSRandall Stewart 	}
1773a5d547adSRandall Stewart 
17747c63520cSMichael Tuexen 	tmr->stopped_from = 0xa003;
1775f8829a4aSRandall Stewart 	if (stcb) {
1776f8829a4aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
17778745f898SMichael Tuexen 		/*
17788745f898SMichael Tuexen 		 * Release reference so that association can be freed if
17798745f898SMichael Tuexen 		 * necessary below. This is safe now that we have acquired
17808745f898SMichael Tuexen 		 * the lock.
17818745f898SMichael Tuexen 		 */
17823c1ba6f3SMichael Tuexen 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
17838745f898SMichael Tuexen 		released_asoc_reference = true;
1784fa89f692SMichael Tuexen 		if ((type != SCTP_TIMER_TYPE_ASOCKILL) &&
17858745f898SMichael Tuexen 		    ((stcb->asoc.state == SCTP_STATE_EMPTY) ||
1786b54d3a6cSRandall Stewart 		    (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED))) {
1787a412576eSMichael Tuexen 			SCTPDBG(SCTP_DEBUG_TIMER2,
178823e3c088SMichael Tuexen 			    "Timer type %d handler exiting due to CLOSED association.\n",
1789a412576eSMichael Tuexen 			    type);
17908745f898SMichael Tuexen 			goto out;
1791b54d3a6cSRandall Stewart 		}
17922c62ba73SMichael Tuexen 	} else if (inp != NULL) {
17932c62ba73SMichael Tuexen 		SCTP_INP_WLOCK(inp);
17942c62ba73SMichael Tuexen 	} else {
17952c62ba73SMichael Tuexen 		SCTP_WQ_ADDR_LOCK();
1796f8829a4aSRandall Stewart 	}
179744b7479bSRandall Stewart 
179837686ccfSMichael Tuexen 	/* Record in stopped_from which timeout occurred. */
179937686ccfSMichael Tuexen 	tmr->stopped_from = type;
1800f8829a4aSRandall Stewart 	/* mark as being serviced now */
180144b7479bSRandall Stewart 	if (SCTP_OS_TIMER_PENDING(&tmr->timer)) {
180244b7479bSRandall Stewart 		/*
180344b7479bSRandall Stewart 		 * Callout has been rescheduled.
180444b7479bSRandall Stewart 		 */
18058745f898SMichael Tuexen 		goto out;
180644b7479bSRandall Stewart 	}
180744b7479bSRandall Stewart 	if (!SCTP_OS_TIMER_ACTIVE(&tmr->timer)) {
180844b7479bSRandall Stewart 		/*
180944b7479bSRandall Stewart 		 * Not active, so no action.
181044b7479bSRandall Stewart 		 */
18118745f898SMichael Tuexen 		goto out;
181244b7479bSRandall Stewart 	}
1813139bc87fSRandall Stewart 	SCTP_OS_TIMER_DEACTIVATE(&tmr->timer);
1814f8829a4aSRandall Stewart 
1815f8829a4aSRandall Stewart 	/* call the handler for the appropriate timer type */
1816fa89f692SMichael Tuexen 	switch (type) {
1817f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
1818a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net != NULL,
1819a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
1820a412576eSMichael Tuexen 		    type, inp, stcb, net));
1821f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timodata);
1822f42a358aSRandall Stewart 		stcb->asoc.timodata++;
1823f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up--;
1824f8829a4aSRandall Stewart 		if (stcb->asoc.num_send_timers_up < 0) {
1825f8829a4aSRandall Stewart 			stcb->asoc.num_send_timers_up = 0;
1826f8829a4aSRandall Stewart 		}
1827b54d3a6cSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
182860990c0cSMichael Tuexen 		if (sctp_t3rxt_timer(inp, stcb, net)) {
1829f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1830f8829a4aSRandall Stewart 
1831f8829a4aSRandall Stewart 			goto out_decr;
1832f8829a4aSRandall Stewart 		}
1833b54d3a6cSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
1834f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1835f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1836f8829a4aSRandall Stewart #endif
1837ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
18388745f898SMichael Tuexen 		did_output = true;
1839f8829a4aSRandall Stewart 		if ((stcb->asoc.num_send_timers_up == 0) &&
18404a9ef3f8SMichael Tuexen 		    (stcb->asoc.sent_queue_cnt > 0)) {
1841f8829a4aSRandall Stewart 			struct sctp_tmit_chunk *chk;
1842f8829a4aSRandall Stewart 
1843f8829a4aSRandall Stewart 			/*
1844efd5e692SMichael Tuexen 			 * Safeguard. If there on some on the sent queue
1845f8829a4aSRandall Stewart 			 * somewhere but no timers running something is
1846f8829a4aSRandall Stewart 			 * wrong... so we start a timer on the first chunk
1847f8829a4aSRandall Stewart 			 * on the send queue on whatever net it is sent to.
1848f8829a4aSRandall Stewart 			 */
1849efd5e692SMichael Tuexen 			TAILQ_FOREACH(chk, &stcb->asoc.sent_queue, sctp_next) {
1850efd5e692SMichael Tuexen 				if (chk->whoTo != NULL) {
1851efd5e692SMichael Tuexen 					break;
1852efd5e692SMichael Tuexen 				}
1853efd5e692SMichael Tuexen 			}
1854efd5e692SMichael Tuexen 			if (chk != NULL) {
1855efd5e692SMichael Tuexen 				sctp_timer_start(SCTP_TIMER_TYPE_SEND, stcb->sctp_ep, stcb, chk->whoTo);
1856efd5e692SMichael Tuexen 			}
1857f8829a4aSRandall Stewart 		}
1858f8829a4aSRandall Stewart 		break;
1859f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
1860a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net != NULL,
1861a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
1862a412576eSMichael Tuexen 		    type, inp, stcb, net));
1863f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoinit);
1864f42a358aSRandall Stewart 		stcb->asoc.timoinit++;
1865f8829a4aSRandall Stewart 		if (sctp_t1init_timer(inp, stcb, net)) {
1866f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1867f8829a4aSRandall Stewart 			goto out_decr;
1868f8829a4aSRandall Stewart 		}
18698745f898SMichael Tuexen 		did_output = false;
1870f8829a4aSRandall Stewart 		break;
1871f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
1872a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net == NULL,
1873a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
1874a412576eSMichael Tuexen 		    type, inp, stcb, net));
1875f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timosack);
1876f42a358aSRandall Stewart 		stcb->asoc.timosack++;
1877689e6a5fSMichael Tuexen 		sctp_send_sack(stcb, SCTP_SO_NOT_LOCKED);
1878f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1879a412576eSMichael Tuexen 		sctp_auditing(4, inp, stcb, NULL);
1880f8829a4aSRandall Stewart #endif
1881ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SACK_TMR, SCTP_SO_NOT_LOCKED);
18828745f898SMichael Tuexen 		did_output = true;
1883f8829a4aSRandall Stewart 		break;
1884f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
1885a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net != NULL,
1886a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
1887a412576eSMichael Tuexen 		    type, inp, stcb, net));
1888a412576eSMichael Tuexen 		SCTP_STAT_INCR(sctps_timoshutdown);
1889a412576eSMichael Tuexen 		stcb->asoc.timoshutdown++;
1890f8829a4aSRandall Stewart 		if (sctp_shutdown_timer(inp, stcb, net)) {
1891f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1892f8829a4aSRandall Stewart 			goto out_decr;
1893f8829a4aSRandall Stewart 		}
1894f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1895f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1896f8829a4aSRandall Stewart #endif
1897ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SHUT_TMR, SCTP_SO_NOT_LOCKED);
18988745f898SMichael Tuexen 		did_output = true;
1899f8829a4aSRandall Stewart 		break;
1900f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
1901a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net != NULL,
1902a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
1903a412576eSMichael Tuexen 		    type, inp, stcb, net));
1904f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoheartbeat);
1905f42a358aSRandall Stewart 		stcb->asoc.timoheartbeat++;
1906ca85e948SMichael Tuexen 		if (sctp_heartbeat_timer(inp, stcb, net)) {
1907f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1908f8829a4aSRandall Stewart 			goto out_decr;
1909f8829a4aSRandall Stewart 		}
1910f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1911ca85e948SMichael Tuexen 		sctp_auditing(4, inp, stcb, net);
1912f8829a4aSRandall Stewart #endif
19139b2a35b3SMichael Tuexen 		if ((net->dest_state & SCTP_ADDR_NOHB) == 0) {
1914629749b6SMichael Tuexen 			sctp_timer_start(SCTP_TIMER_TYPE_HEARTBEAT, inp, stcb, net);
1915ceaad40aSRandall Stewart 			sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_HB_TMR, SCTP_SO_NOT_LOCKED);
19168745f898SMichael Tuexen 			did_output = true;
19178745f898SMichael Tuexen 		} else {
19188745f898SMichael Tuexen 			did_output = false;
1919f8829a4aSRandall Stewart 		}
1920f8829a4aSRandall Stewart 		break;
1921f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
1922a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net != NULL,
1923a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
1924a412576eSMichael Tuexen 		    type, inp, stcb, net));
1925a412576eSMichael Tuexen 		SCTP_STAT_INCR(sctps_timocookie);
1926a412576eSMichael Tuexen 		stcb->asoc.timocookie++;
1927f8829a4aSRandall Stewart 		if (sctp_cookie_timer(inp, stcb, net)) {
1928f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1929f8829a4aSRandall Stewart 			goto out_decr;
1930f8829a4aSRandall Stewart 		}
1931f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1932f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1933f8829a4aSRandall Stewart #endif
1934f8829a4aSRandall Stewart 		/*
1935f8829a4aSRandall Stewart 		 * We consider T3 and Cookie timer pretty much the same with
1936f8829a4aSRandall Stewart 		 * respect to where from in chunk_output.
1937f8829a4aSRandall Stewart 		 */
1938ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
19398745f898SMichael Tuexen 		did_output = true;
1940f8829a4aSRandall Stewart 		break;
1941f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
1942a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb == NULL && net == NULL,
1943a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
1944a412576eSMichael Tuexen 		    type, inp, stcb, net));
1945f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timosecret);
19466e55db54SRandall Stewart 		(void)SCTP_GETTIME_TIMEVAL(&tv);
1947aab1d593SMichael Tuexen 		inp->sctp_ep.time_of_secret_change = (unsigned int)tv.tv_sec;
1948f8829a4aSRandall Stewart 		inp->sctp_ep.last_secret_number =
1949f8829a4aSRandall Stewart 		    inp->sctp_ep.current_secret_number;
1950f8829a4aSRandall Stewart 		inp->sctp_ep.current_secret_number++;
1951f8829a4aSRandall Stewart 		if (inp->sctp_ep.current_secret_number >=
1952f8829a4aSRandall Stewart 		    SCTP_HOW_MANY_SECRETS) {
1953f8829a4aSRandall Stewart 			inp->sctp_ep.current_secret_number = 0;
1954f8829a4aSRandall Stewart 		}
1955f8829a4aSRandall Stewart 		secret = (int)inp->sctp_ep.current_secret_number;
1956f8829a4aSRandall Stewart 		for (i = 0; i < SCTP_NUMBER_OF_SECRETS; i++) {
1957f8829a4aSRandall Stewart 			inp->sctp_ep.secret_key[secret][i] =
1958f8829a4aSRandall Stewart 			    sctp_select_initial_TSN(&inp->sctp_ep);
1959f8829a4aSRandall Stewart 		}
19606fb7b4fbSMichael Tuexen 		sctp_timer_start(SCTP_TIMER_TYPE_NEWCOOKIE, inp, NULL, NULL);
19618745f898SMichael Tuexen 		did_output = false;
1962f8829a4aSRandall Stewart 		break;
1963f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
1964a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net != NULL,
1965a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
1966a412576eSMichael Tuexen 		    type, inp, stcb, net));
1967f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timopathmtu);
1968f8829a4aSRandall Stewart 		sctp_pathmtu_timer(inp, stcb, net);
19698745f898SMichael Tuexen 		did_output = false;
1970f8829a4aSRandall Stewart 		break;
1971f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
1972a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net != NULL,
1973a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
1974a412576eSMichael Tuexen 		    type, inp, stcb, net));
1975f8829a4aSRandall Stewart 		if (sctp_shutdownack_timer(inp, stcb, net)) {
1976f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1977f8829a4aSRandall Stewart 			goto out_decr;
1978f8829a4aSRandall Stewart 		}
1979f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoshutdownack);
1980f42a358aSRandall Stewart 		stcb->asoc.timoshutdownack++;
1981f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1982f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1983f8829a4aSRandall Stewart #endif
1984ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SHUT_ACK_TMR, SCTP_SO_NOT_LOCKED);
19858745f898SMichael Tuexen 		did_output = true;
1986f8829a4aSRandall Stewart 		break;
1987f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASCONF:
1988a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net != NULL,
1989a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
1990a412576eSMichael Tuexen 		    type, inp, stcb, net));
1991a412576eSMichael Tuexen 		SCTP_STAT_INCR(sctps_timoasconf);
1992f8829a4aSRandall Stewart 		if (sctp_asconf_timer(inp, stcb, net)) {
1993f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1994f8829a4aSRandall Stewart 			goto out_decr;
1995f8829a4aSRandall Stewart 		}
1996f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1997f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1998f8829a4aSRandall Stewart #endif
1999ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_ASCONF_TMR, SCTP_SO_NOT_LOCKED);
20008745f898SMichael Tuexen 		did_output = true;
2001f8829a4aSRandall Stewart 		break;
20020554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
2003a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net == NULL,
2004a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
2005a412576eSMichael Tuexen 		    type, inp, stcb, net));
20060554e01dSMichael Tuexen 		SCTP_STAT_INCR(sctps_timoshutdownguard);
20070554e01dSMichael Tuexen 		op_err = sctp_generate_cause(SCTP_BASE_SYSCTL(sctp_diag_info_code),
20080554e01dSMichael Tuexen 		    "Shutdown guard timer expired");
2009105b68b4SMichael Tuexen 		sctp_abort_an_association(inp, stcb, op_err, true, SCTP_SO_NOT_LOCKED);
20100554e01dSMichael Tuexen 		/* no need to unlock on tcb its gone */
20110554e01dSMichael Tuexen 		goto out_decr;
2012f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_AUTOCLOSE:
2013a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net == NULL,
2014a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
2015a412576eSMichael Tuexen 		    type, inp, stcb, net));
2016f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoautoclose);
2017a57fb68bSMichael Tuexen 		sctp_autoclose_timer(inp, stcb);
2018ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_AUTOCLOSE_TMR, SCTP_SO_NOT_LOCKED);
20198745f898SMichael Tuexen 		did_output = true;
2020f8829a4aSRandall Stewart 		break;
20210554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_STRRESET:
2022a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net == NULL,
2023a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
2024a412576eSMichael Tuexen 		    type, inp, stcb, net));
2025a412576eSMichael Tuexen 		SCTP_STAT_INCR(sctps_timostrmrst);
2026e95b3d7fSMichael Tuexen 		if (sctp_strreset_timer(inp, stcb)) {
20270554e01dSMichael Tuexen 			/* no need to unlock on tcb its gone */
20280554e01dSMichael Tuexen 			goto out_decr;
20290554e01dSMichael Tuexen 		}
20300554e01dSMichael Tuexen 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_STRRST_TMR, SCTP_SO_NOT_LOCKED);
20318745f898SMichael Tuexen 		did_output = true;
20320554e01dSMichael Tuexen 		break;
20330554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_INPKILL:
2034a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb == NULL && net == NULL,
2035a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
2036a412576eSMichael Tuexen 		    type, inp, stcb, net));
20370554e01dSMichael Tuexen 		SCTP_STAT_INCR(sctps_timoinpkill);
20380554e01dSMichael Tuexen 		/*
20390554e01dSMichael Tuexen 		 * special case, take away our increment since WE are the
20400554e01dSMichael Tuexen 		 * killer
20410554e01dSMichael Tuexen 		 */
20420554e01dSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_INPKILL, inp, NULL, NULL,
20430554e01dSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_3);
2044a412576eSMichael Tuexen 		SCTP_INP_DECR_REF(inp);
2045a412576eSMichael Tuexen 		SCTP_INP_WUNLOCK(inp);
20460554e01dSMichael Tuexen 		sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
20470554e01dSMichael Tuexen 		    SCTP_CALLED_FROM_INPKILL_TIMER);
20480554e01dSMichael Tuexen 		inp = NULL;
2049bdd4630cSMichael Tuexen 		goto out_decr;
2050f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASOCKILL:
2051a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net == NULL,
2052a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
2053a412576eSMichael Tuexen 		    type, inp, stcb, net));
2054f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoassockill);
2055f8829a4aSRandall Stewart 		/* Can we free it yet? */
2056ba785902SMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_ASOCKILL, inp, stcb, NULL,
2057ba785902SMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_1);
2058ba785902SMichael Tuexen 		(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
2059ba785902SMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_2);
2060f8829a4aSRandall Stewart 		/*
2061f8829a4aSRandall Stewart 		 * free asoc, always unlocks (or destroy's) so prevent
2062f8829a4aSRandall Stewart 		 * duplicate unlock or unlock of a free mtx :-0
2063f8829a4aSRandall Stewart 		 */
2064f8829a4aSRandall Stewart 		stcb = NULL;
2065bdd4630cSMichael Tuexen 		goto out_decr;
20660554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_ADDR_WQ:
2067a412576eSMichael Tuexen 		KASSERT(inp == NULL && stcb == NULL && net == NULL,
2068a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
2069a412576eSMichael Tuexen 		    type, inp, stcb, net));
20700554e01dSMichael Tuexen 		sctp_handle_addr_wq();
20718745f898SMichael Tuexen 		did_output = true;
20720554e01dSMichael Tuexen 		break;
20730554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_PRIM_DELETED:
2074a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net == NULL,
2075a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
2076a412576eSMichael Tuexen 		    type, inp, stcb, net));
20770554e01dSMichael Tuexen 		SCTP_STAT_INCR(sctps_timodelprim);
2078a412576eSMichael Tuexen 		sctp_delete_prim_timer(inp, stcb);
20798745f898SMichael Tuexen 		did_output = false;
20800554e01dSMichael Tuexen 		break;
2081f8829a4aSRandall Stewart 	default:
20827522682eSMichael Tuexen #ifdef INVARIANTS
2083a412576eSMichael Tuexen 		panic("Unknown timer type %d", type);
20847522682eSMichael Tuexen #else
20858745f898SMichael Tuexen 		goto out;
20867522682eSMichael Tuexen #endif
208760990c0cSMichael Tuexen 	}
2088f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
2089fa89f692SMichael Tuexen 	sctp_audit_log(0xF1, (uint8_t)type);
20908745f898SMichael Tuexen 	if (inp != NULL)
2091f8829a4aSRandall Stewart 		sctp_auditing(5, inp, stcb, net);
2092f8829a4aSRandall Stewart #endif
20938745f898SMichael Tuexen 	if (did_output && (stcb != NULL)) {
2094f8829a4aSRandall Stewart 		/*
2095f8829a4aSRandall Stewart 		 * Now we need to clean up the control chunk chain if an
2096f8829a4aSRandall Stewart 		 * ECNE is on it. It must be marked as UNSENT again so next
2097f8829a4aSRandall Stewart 		 * call will continue to send it until such time that we get
2098f8829a4aSRandall Stewart 		 * a CWR, to remove it. It is, however, less likely that we
2099f8829a4aSRandall Stewart 		 * will find a ecn echo on the chain though.
2100f8829a4aSRandall Stewart 		 */
2101f8829a4aSRandall Stewart 		sctp_fix_ecn_echo(&stcb->asoc);
2102f8829a4aSRandall Stewart 	}
21038745f898SMichael Tuexen out:
21048745f898SMichael Tuexen 	if (stcb != NULL) {
2105f8829a4aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
21062c62ba73SMichael Tuexen 	} else if (inp != NULL) {
21072c62ba73SMichael Tuexen 		SCTP_INP_WUNLOCK(inp);
21082c62ba73SMichael Tuexen 	} else {
21092c62ba73SMichael Tuexen 		SCTP_WQ_ADDR_UNLOCK();
2110f8829a4aSRandall Stewart 	}
21112c62ba73SMichael Tuexen 
2112f8829a4aSRandall Stewart out_decr:
21138745f898SMichael Tuexen 	/* These reference counts were incremented in sctp_timer_start(). */
21148745f898SMichael Tuexen 	if (inp != NULL) {
2115f8829a4aSRandall Stewart 		SCTP_INP_DECR_REF(inp);
2116f8829a4aSRandall Stewart 	}
21178745f898SMichael Tuexen 	if ((stcb != NULL) && !released_asoc_reference) {
21183c1ba6f3SMichael Tuexen 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
21198745f898SMichael Tuexen 	}
21208745f898SMichael Tuexen 	if (net != NULL) {
21218745f898SMichael Tuexen 		sctp_free_remote_addr(net);
21228745f898SMichael Tuexen 	}
212323e3c088SMichael Tuexen 	SCTPDBG(SCTP_DEBUG_TIMER2, "Timer type %d handler finished.\n", type);
21248518270eSMichael Tuexen 	CURVNET_RESTORE();
2125868b51f2SMichael Tuexen 	NET_EPOCH_EXIT(et);
2126f8829a4aSRandall Stewart }
2127f8829a4aSRandall Stewart 
2128a412576eSMichael Tuexen /*-
2129a412576eSMichael Tuexen  * The following table shows which parameters must be provided
2130a412576eSMichael Tuexen  * when calling sctp_timer_start(). For parameters not being
2131a412576eSMichael Tuexen  * provided, NULL must be used.
2132a412576eSMichael Tuexen  *
2133a412576eSMichael Tuexen  * |Name                         |inp |stcb|net |
2134a412576eSMichael Tuexen  * |-----------------------------|----|----|----|
2135a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_SEND         |Yes |Yes |Yes |
2136a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_INIT         |Yes |Yes |Yes |
2137a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_RECV         |Yes |Yes |No  |
2138a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_SHUTDOWN     |Yes |Yes |Yes |
2139a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_HEARTBEAT    |Yes |Yes |Yes |
2140a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_COOKIE       |Yes |Yes |Yes |
2141a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_NEWCOOKIE    |Yes |No  |No  |
2142a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_PATHMTURAISE |Yes |Yes |Yes |
2143a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_SHUTDOWNACK  |Yes |Yes |Yes |
2144a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_ASCONF       |Yes |Yes |Yes |
2145a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_SHUTDOWNGUARD|Yes |Yes |No  |
2146a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_AUTOCLOSE    |Yes |Yes |No  |
2147a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_STRRESET     |Yes |Yes |Yes |
2148a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_INPKILL      |Yes |No  |No  |
2149a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_ASOCKILL     |Yes |Yes |No  |
2150a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_ADDR_WQ      |No  |No  |No  |
2151a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_PRIM_DELETED |Yes |Yes |No  |
2152a412576eSMichael Tuexen  *
2153a412576eSMichael Tuexen  */
2154a412576eSMichael Tuexen 
2155ad81507eSRandall Stewart void
2156f8829a4aSRandall Stewart sctp_timer_start(int t_type, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
2157f8829a4aSRandall Stewart     struct sctp_nets *net)
2158f8829a4aSRandall Stewart {
2159f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
2160a412576eSMichael Tuexen 	uint32_t to_ticks;
2161a412576eSMichael Tuexen 	uint32_t rndval, jitter;
2162f8829a4aSRandall Stewart 
2163f4cb790aSMichael Tuexen 	KASSERT(stcb == NULL || stcb->sctp_ep == inp,
2164f4cb790aSMichael Tuexen 	    ("sctp_timer_start of type %d: inp = %p, stcb->sctp_ep %p",
2165f4cb790aSMichael Tuexen 	    t_type, stcb, stcb->sctp_ep));
2166f8829a4aSRandall Stewart 	tmr = NULL;
2167a412576eSMichael Tuexen 	if (stcb != NULL) {
2168f8829a4aSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
2169a412576eSMichael Tuexen 	} else if (inp != NULL) {
2170a412576eSMichael Tuexen 		SCTP_INP_WLOCK_ASSERT(inp);
2171a412576eSMichael Tuexen 	} else {
2172a412576eSMichael Tuexen 		SCTP_WQ_ADDR_LOCK_ASSERT();
2173a412576eSMichael Tuexen 	}
2174a412576eSMichael Tuexen 	if (stcb != NULL) {
2175a412576eSMichael Tuexen 		/*
2176a412576eSMichael Tuexen 		 * Don't restart timer on association that's about to be
2177a412576eSMichael Tuexen 		 * killed.
2178a412576eSMichael Tuexen 		 */
2179a412576eSMichael Tuexen 		if ((stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) &&
2180a412576eSMichael Tuexen 		    (t_type != SCTP_TIMER_TYPE_ASOCKILL)) {
2181a412576eSMichael Tuexen 			SCTPDBG(SCTP_DEBUG_TIMER2,
218237686ccfSMichael Tuexen 			    "Timer type %d not started: inp=%p, stcb=%p, net=%p (stcb deleted).\n",
2183a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2184a412576eSMichael Tuexen 			return;
2185f8829a4aSRandall Stewart 		}
21869803f01cSMichael Tuexen 		/* Don't restart timer on net that's been removed. */
21879803f01cSMichael Tuexen 		if (net != NULL && (net->dest_state & SCTP_ADDR_BEING_DELETED)) {
2188a412576eSMichael Tuexen 			SCTPDBG(SCTP_DEBUG_TIMER2,
218937686ccfSMichael Tuexen 			    "Timer type %d not started: inp=%p, stcb=%p, net=%p (net deleted).\n",
2190a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
21919803f01cSMichael Tuexen 			return;
21929803f01cSMichael Tuexen 		}
2193a412576eSMichael Tuexen 	}
2194f8829a4aSRandall Stewart 	switch (t_type) {
2195f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
2196a412576eSMichael Tuexen 		/* Here we use the RTO timer. */
2197a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2198a412576eSMichael Tuexen #ifdef INVARIANTS
2199a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2200a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2201a412576eSMichael Tuexen #else
2202ad81507eSRandall Stewart 			return;
2203a412576eSMichael Tuexen #endif
2204f8829a4aSRandall Stewart 		}
2205f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2206f8829a4aSRandall Stewart 		if (net->RTO == 0) {
220725ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(stcb->asoc.initial_rto);
2208f8829a4aSRandall Stewart 		} else {
220925ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(net->RTO);
2210f8829a4aSRandall Stewart 		}
2211f8829a4aSRandall Stewart 		break;
2212f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
2213f8829a4aSRandall Stewart 		/*
2214f8829a4aSRandall Stewart 		 * Here we use the INIT timer default usually about 1
2215a412576eSMichael Tuexen 		 * second.
2216f8829a4aSRandall Stewart 		 */
2217a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2218a412576eSMichael Tuexen #ifdef INVARIANTS
2219a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2220a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2221a412576eSMichael Tuexen #else
2222ad81507eSRandall Stewart 			return;
2223a412576eSMichael Tuexen #endif
2224f8829a4aSRandall Stewart 		}
2225f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2226f8829a4aSRandall Stewart 		if (net->RTO == 0) {
222725ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(stcb->asoc.initial_rto);
2228f8829a4aSRandall Stewart 		} else {
222925ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(net->RTO);
2230f8829a4aSRandall Stewart 		}
2231f8829a4aSRandall Stewart 		break;
2232f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
2233f8829a4aSRandall Stewart 		/*
2234a412576eSMichael Tuexen 		 * Here we use the Delayed-Ack timer value from the inp,
2235e7e65008SMichael Tuexen 		 * usually about 200ms.
2236f8829a4aSRandall Stewart 		 */
2237a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2238a412576eSMichael Tuexen #ifdef INVARIANTS
2239a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2240a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2241a412576eSMichael Tuexen #else
2242ad81507eSRandall Stewart 			return;
2243a412576eSMichael Tuexen #endif
2244f8829a4aSRandall Stewart 		}
2245f8829a4aSRandall Stewart 		tmr = &stcb->asoc.dack_timer;
224625ec3553SMichael Tuexen 		to_ticks = sctp_msecs_to_ticks(stcb->asoc.delayed_ack);
2247f8829a4aSRandall Stewart 		break;
2248f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
2249f8829a4aSRandall Stewart 		/* Here we use the RTO of the destination. */
2250a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2251a412576eSMichael Tuexen #ifdef INVARIANTS
2252a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2253a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2254a412576eSMichael Tuexen #else
2255ad81507eSRandall Stewart 			return;
2256a412576eSMichael Tuexen #endif
2257f8829a4aSRandall Stewart 		}
2258a412576eSMichael Tuexen 		tmr = &net->rxt_timer;
2259f8829a4aSRandall Stewart 		if (net->RTO == 0) {
226025ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(stcb->asoc.initial_rto);
2261f8829a4aSRandall Stewart 		} else {
226225ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(net->RTO);
2263f8829a4aSRandall Stewart 		}
2264f8829a4aSRandall Stewart 		break;
2265f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
2266f8829a4aSRandall Stewart 		/*
2267a412576eSMichael Tuexen 		 * The net is used here so that we can add in the RTO. Even
2268f8829a4aSRandall Stewart 		 * though we use a different timer. We also add the HB timer
2269f8829a4aSRandall Stewart 		 * PLUS a random jitter.
2270f8829a4aSRandall Stewart 		 */
2271a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2272a412576eSMichael Tuexen #ifdef INVARIANTS
2273a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2274a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2275a412576eSMichael Tuexen #else
2276ad81507eSRandall Stewart 			return;
2277a412576eSMichael Tuexen #endif
2278a412576eSMichael Tuexen 		}
2279ca85e948SMichael Tuexen 		if ((net->dest_state & SCTP_ADDR_NOHB) &&
22809b2a35b3SMichael Tuexen 		    ((net->dest_state & SCTP_ADDR_UNCONFIRMED) == 0)) {
2281a412576eSMichael Tuexen 			SCTPDBG(SCTP_DEBUG_TIMER2,
228237686ccfSMichael Tuexen 			    "Timer type %d not started: inp=%p, stcb=%p, net=%p.\n",
2283a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2284ad81507eSRandall Stewart 			return;
2285f8829a4aSRandall Stewart 		}
2286a412576eSMichael Tuexen 		tmr = &net->hb_timer;
2287f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2288ca85e948SMichael Tuexen 			to_ticks = stcb->asoc.initial_rto;
2289f8829a4aSRandall Stewart 		} else {
2290ca85e948SMichael Tuexen 			to_ticks = net->RTO;
2291f8829a4aSRandall Stewart 		}
2292ca85e948SMichael Tuexen 		rndval = sctp_select_initial_TSN(&inp->sctp_ep);
2293ca85e948SMichael Tuexen 		jitter = rndval % to_ticks;
2294d995cc7eSMichael Tuexen 		if (to_ticks > 1) {
229570e95f0bSMichael Tuexen 			to_ticks >>= 1;
2296d995cc7eSMichael Tuexen 		}
229770e95f0bSMichael Tuexen 		if (jitter < (UINT32_MAX - to_ticks)) {
229870e95f0bSMichael Tuexen 			to_ticks += jitter;
2299f8829a4aSRandall Stewart 		} else {
230070e95f0bSMichael Tuexen 			to_ticks = UINT32_MAX;
2301f8829a4aSRandall Stewart 		}
23029312ba23SMichael Tuexen 		if (!((net->dest_state & SCTP_ADDR_UNCONFIRMED) &&
23039312ba23SMichael Tuexen 		    (net->dest_state & SCTP_ADDR_REACHABLE)) &&
23049b2a35b3SMichael Tuexen 		    ((net->dest_state & SCTP_ADDR_PF) == 0)) {
230570e95f0bSMichael Tuexen 			if (net->heart_beat_delay < (UINT32_MAX - to_ticks)) {
2306ca85e948SMichael Tuexen 				to_ticks += net->heart_beat_delay;
230770e95f0bSMichael Tuexen 			} else {
230870e95f0bSMichael Tuexen 				to_ticks = UINT32_MAX;
230970e95f0bSMichael Tuexen 			}
2310f8829a4aSRandall Stewart 		}
2311f8829a4aSRandall Stewart 		/*
2312a412576eSMichael Tuexen 		 * Now we must convert the to_ticks that are now in ms to
2313a412576eSMichael Tuexen 		 * ticks.
2314f8829a4aSRandall Stewart 		 */
231525ec3553SMichael Tuexen 		to_ticks = sctp_msecs_to_ticks(to_ticks);
2316f8829a4aSRandall Stewart 		break;
2317f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
2318f8829a4aSRandall Stewart 		/*
2319f8829a4aSRandall Stewart 		 * Here we can use the RTO timer from the network since one
2320a412576eSMichael Tuexen 		 * RTT was complete. If a retransmission happened then we
2321a412576eSMichael Tuexen 		 * will be using the RTO initial value.
2322f8829a4aSRandall Stewart 		 */
2323a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2324a412576eSMichael Tuexen #ifdef INVARIANTS
2325a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2326a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2327a412576eSMichael Tuexen #else
2328ad81507eSRandall Stewart 			return;
2329a412576eSMichael Tuexen #endif
2330f8829a4aSRandall Stewart 		}
2331a412576eSMichael Tuexen 		tmr = &net->rxt_timer;
2332f8829a4aSRandall Stewart 		if (net->RTO == 0) {
233325ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(stcb->asoc.initial_rto);
2334f8829a4aSRandall Stewart 		} else {
233525ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(net->RTO);
2336f8829a4aSRandall Stewart 		}
2337f8829a4aSRandall Stewart 		break;
2338f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
2339f8829a4aSRandall Stewart 		/*
2340e7e65008SMichael Tuexen 		 * Nothing needed but the endpoint here usually about 60
2341f8829a4aSRandall Stewart 		 * minutes.
2342f8829a4aSRandall Stewart 		 */
2343a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb != NULL) || (net != NULL)) {
2344a412576eSMichael Tuexen #ifdef INVARIANTS
2345a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2346a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2347a412576eSMichael Tuexen #else
2348a412576eSMichael Tuexen 			return;
2349a412576eSMichael Tuexen #endif
2350a412576eSMichael Tuexen 		}
2351f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2352f8829a4aSRandall Stewart 		to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_SIGNATURE];
2353f8829a4aSRandall Stewart 		break;
2354f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
2355f8829a4aSRandall Stewart 		/*
2356e7e65008SMichael Tuexen 		 * Here we use the value found in the EP for PMTUD, usually
2357e7e65008SMichael Tuexen 		 * about 10 minutes.
2358f8829a4aSRandall Stewart 		 */
2359a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2360a412576eSMichael Tuexen #ifdef INVARIANTS
2361a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2362a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2363a412576eSMichael Tuexen #else
2364ad81507eSRandall Stewart 			return;
2365a412576eSMichael Tuexen #endif
2366f8829a4aSRandall Stewart 		}
236780c79bbeSMichael Tuexen 		if (net->dest_state & SCTP_ADDR_NO_PMTUD) {
2368a412576eSMichael Tuexen 			SCTPDBG(SCTP_DEBUG_TIMER2,
236937686ccfSMichael Tuexen 			    "Timer type %d not started: inp=%p, stcb=%p, net=%p.\n",
2370a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
237180c79bbeSMichael Tuexen 			return;
237280c79bbeSMichael Tuexen 		}
2373f8829a4aSRandall Stewart 		tmr = &net->pmtu_timer;
2374a412576eSMichael Tuexen 		to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_PMTU];
2375f8829a4aSRandall Stewart 		break;
2376f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
2377a412576eSMichael Tuexen 		/* Here we use the RTO of the destination. */
2378a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2379a412576eSMichael Tuexen #ifdef INVARIANTS
2380a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2381a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2382a412576eSMichael Tuexen #else
2383ad81507eSRandall Stewart 			return;
2384a412576eSMichael Tuexen #endif
2385f8829a4aSRandall Stewart 		}
2386a412576eSMichael Tuexen 		tmr = &net->rxt_timer;
2387f8829a4aSRandall Stewart 		if (net->RTO == 0) {
238825ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(stcb->asoc.initial_rto);
2389f8829a4aSRandall Stewart 		} else {
239025ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(net->RTO);
2391f8829a4aSRandall Stewart 		}
2392f8829a4aSRandall Stewart 		break;
23930554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_ASCONF:
23940554e01dSMichael Tuexen 		/*
23950554e01dSMichael Tuexen 		 * Here the timer comes from the stcb but its value is from
23960554e01dSMichael Tuexen 		 * the net's RTO.
23970554e01dSMichael Tuexen 		 */
2398a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2399a412576eSMichael Tuexen #ifdef INVARIANTS
2400a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2401a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2402a412576eSMichael Tuexen #else
24030554e01dSMichael Tuexen 			return;
2404a412576eSMichael Tuexen #endif
24050554e01dSMichael Tuexen 		}
2406a412576eSMichael Tuexen 		tmr = &stcb->asoc.asconf_timer;
24070554e01dSMichael Tuexen 		if (net->RTO == 0) {
240825ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(stcb->asoc.initial_rto);
24090554e01dSMichael Tuexen 		} else {
241025ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(net->RTO);
24110554e01dSMichael Tuexen 		}
24120554e01dSMichael Tuexen 		break;
2413f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
2414f8829a4aSRandall Stewart 		/*
2415f8829a4aSRandall Stewart 		 * Here we use the endpoints shutdown guard timer usually
2416f8829a4aSRandall Stewart 		 * about 3 minutes.
2417f8829a4aSRandall Stewart 		 */
2418a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2419a412576eSMichael Tuexen #ifdef INVARIANTS
2420a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2421a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2422a412576eSMichael Tuexen #else
2423ad81507eSRandall Stewart 			return;
2424a412576eSMichael Tuexen #endif
2425f8829a4aSRandall Stewart 		}
2426a412576eSMichael Tuexen 		tmr = &stcb->asoc.shut_guard_timer;
24272e2d6794SMichael Tuexen 		if (inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_MAXSHUTDOWN] == 0) {
242825ec3553SMichael Tuexen 			if (stcb->asoc.maxrto < UINT32_MAX / 5) {
242925ec3553SMichael Tuexen 				to_ticks = sctp_msecs_to_ticks(5 * stcb->asoc.maxrto);
243025ec3553SMichael Tuexen 			} else {
243125ec3553SMichael Tuexen 				to_ticks = sctp_msecs_to_ticks(UINT32_MAX);
243225ec3553SMichael Tuexen 			}
24332e2d6794SMichael Tuexen 		} else {
2434f8829a4aSRandall Stewart 			to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_MAXSHUTDOWN];
24352e2d6794SMichael Tuexen 		}
2436f8829a4aSRandall Stewart 		break;
24370554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_AUTOCLOSE:
2438a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2439a412576eSMichael Tuexen #ifdef INVARIANTS
2440a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2441a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2442a412576eSMichael Tuexen #else
24430554e01dSMichael Tuexen 			return;
2444a412576eSMichael Tuexen #endif
24450554e01dSMichael Tuexen 		}
24460554e01dSMichael Tuexen 		tmr = &stcb->asoc.autoclose_timer;
2447a412576eSMichael Tuexen 		to_ticks = stcb->asoc.sctp_autoclose_ticks;
24480554e01dSMichael Tuexen 		break;
2449f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_STRRESET:
2450f8829a4aSRandall Stewart 		/*
24511b649582SRandall Stewart 		 * Here the timer comes from the stcb but its value is from
24521b649582SRandall Stewart 		 * the net's RTO.
2453f8829a4aSRandall Stewart 		 */
2454a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2455a412576eSMichael Tuexen #ifdef INVARIANTS
2456a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2457a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2458a412576eSMichael Tuexen #else
2459ad81507eSRandall Stewart 			return;
2460a412576eSMichael Tuexen #endif
2461f8829a4aSRandall Stewart 		}
2462a412576eSMichael Tuexen 		tmr = &stcb->asoc.strreset_timer;
2463f8829a4aSRandall Stewart 		if (net->RTO == 0) {
246425ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(stcb->asoc.initial_rto);
2465f8829a4aSRandall Stewart 		} else {
246625ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(net->RTO);
2467f8829a4aSRandall Stewart 		}
2468f8829a4aSRandall Stewart 		break;
24690554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_INPKILL:
2470f8829a4aSRandall Stewart 		/*
2471e7e65008SMichael Tuexen 		 * The inp is setup to die. We re-use the signature_change
24720554e01dSMichael Tuexen 		 * timer since that has stopped and we are in the GONE
24730554e01dSMichael Tuexen 		 * state.
2474f8829a4aSRandall Stewart 		 */
2475a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb != NULL) || (net != NULL)) {
2476a412576eSMichael Tuexen #ifdef INVARIANTS
2477a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2478a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2479a412576eSMichael Tuexen #else
2480a412576eSMichael Tuexen 			return;
2481a412576eSMichael Tuexen #endif
2482a412576eSMichael Tuexen 		}
24830554e01dSMichael Tuexen 		tmr = &inp->sctp_ep.signature_change;
248425ec3553SMichael Tuexen 		to_ticks = sctp_msecs_to_ticks(SCTP_INP_KILL_TIMEOUT);
24850554e01dSMichael Tuexen 		break;
24860554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_ASOCKILL:
2487a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2488a412576eSMichael Tuexen #ifdef INVARIANTS
2489a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2490a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2491a412576eSMichael Tuexen #else
2492ad81507eSRandall Stewart 			return;
2493a412576eSMichael Tuexen #endif
2494f8829a4aSRandall Stewart 		}
24950554e01dSMichael Tuexen 		tmr = &stcb->asoc.strreset_timer;
249625ec3553SMichael Tuexen 		to_ticks = sctp_msecs_to_ticks(SCTP_ASOC_KILL_TIMEOUT);
24970554e01dSMichael Tuexen 		break;
24980554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_ADDR_WQ:
2499a412576eSMichael Tuexen 		if ((inp != NULL) || (stcb != NULL) || (net != NULL)) {
2500a412576eSMichael Tuexen #ifdef INVARIANTS
2501a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2502a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2503a412576eSMichael Tuexen #else
2504a412576eSMichael Tuexen 			return;
2505a412576eSMichael Tuexen #endif
2506a412576eSMichael Tuexen 		}
25070554e01dSMichael Tuexen 		/* Only 1 tick away :-) */
25080554e01dSMichael Tuexen 		tmr = &SCTP_BASE_INFO(addr_wq_timer);
25090554e01dSMichael Tuexen 		to_ticks = SCTP_ADDRESS_TICK_DELAY;
2510f8829a4aSRandall Stewart 		break;
2511851b7298SRandall Stewart 	case SCTP_TIMER_TYPE_PRIM_DELETED:
2512a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2513a412576eSMichael Tuexen #ifdef INVARIANTS
2514a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2515a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2516a412576eSMichael Tuexen #else
2517851b7298SRandall Stewart 			return;
2518a412576eSMichael Tuexen #endif
2519851b7298SRandall Stewart 		}
2520851b7298SRandall Stewart 		tmr = &stcb->asoc.delete_prim_timer;
252125ec3553SMichael Tuexen 		to_ticks = sctp_msecs_to_ticks(stcb->asoc.initial_rto);
2522851b7298SRandall Stewart 		break;
2523f8829a4aSRandall Stewart 	default:
25247522682eSMichael Tuexen #ifdef INVARIANTS
2525a412576eSMichael Tuexen 		panic("Unknown timer type %d", t_type);
25267522682eSMichael Tuexen #else
25277522682eSMichael Tuexen 		return;
25287522682eSMichael Tuexen #endif
252960990c0cSMichael Tuexen 	}
2530a412576eSMichael Tuexen 	KASSERT(tmr != NULL, ("tmr is NULL for timer type %d", t_type));
2531a412576eSMichael Tuexen 	KASSERT(to_ticks > 0, ("to_ticks == 0 for timer type %d", t_type));
2532139bc87fSRandall Stewart 	if (SCTP_OS_TIMER_PENDING(&tmr->timer)) {
2533f8829a4aSRandall Stewart 		/*
2534a412576eSMichael Tuexen 		 * We do NOT allow you to have it already running. If it is,
2535a412576eSMichael Tuexen 		 * we leave the current one up unchanged.
2536f8829a4aSRandall Stewart 		 */
2537a412576eSMichael Tuexen 		SCTPDBG(SCTP_DEBUG_TIMER2,
253837686ccfSMichael Tuexen 		    "Timer type %d already running: inp=%p, stcb=%p, net=%p.\n",
2539a412576eSMichael Tuexen 		    t_type, inp, stcb, net);
2540ad81507eSRandall Stewart 		return;
2541f8829a4aSRandall Stewart 	}
2542a412576eSMichael Tuexen 	/* At this point we can proceed. */
2543f8829a4aSRandall Stewart 	if (t_type == SCTP_TIMER_TYPE_SEND) {
2544f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up++;
2545f8829a4aSRandall Stewart 	}
2546a5d547adSRandall Stewart 	tmr->stopped_from = 0;
2547f8829a4aSRandall Stewart 	tmr->type = t_type;
2548f8829a4aSRandall Stewart 	tmr->ep = (void *)inp;
2549f8829a4aSRandall Stewart 	tmr->tcb = (void *)stcb;
2550a412576eSMichael Tuexen 	if (t_type == SCTP_TIMER_TYPE_STRRESET) {
2551a412576eSMichael Tuexen 		tmr->net = NULL;
2552a412576eSMichael Tuexen 	} else {
2553f8829a4aSRandall Stewart 		tmr->net = (void *)net;
2554a412576eSMichael Tuexen 	}
2555f8829a4aSRandall Stewart 	tmr->self = (void *)tmr;
25568518270eSMichael Tuexen 	tmr->vnet = (void *)curvnet;
2557c4739e2fSRandall Stewart 	tmr->ticks = sctp_get_tick_count();
2558a412576eSMichael Tuexen 	if (SCTP_OS_TIMER_START(&tmr->timer, to_ticks, sctp_timeout_handler, tmr) == 0) {
2559a412576eSMichael Tuexen 		SCTPDBG(SCTP_DEBUG_TIMER2,
256037686ccfSMichael Tuexen 		    "Timer type %d started: ticks=%u, inp=%p, stcb=%p, net=%p.\n",
2561a412576eSMichael Tuexen 		    t_type, to_ticks, inp, stcb, net);
25628745f898SMichael Tuexen 		/*
25638745f898SMichael Tuexen 		 * If this is a newly scheduled callout, as opposed to a
25648745f898SMichael Tuexen 		 * rescheduled one, increment relevant reference counts.
25658745f898SMichael Tuexen 		 */
25668745f898SMichael Tuexen 		if (tmr->ep != NULL) {
25678745f898SMichael Tuexen 			SCTP_INP_INCR_REF(inp);
25688745f898SMichael Tuexen 		}
25698745f898SMichael Tuexen 		if (tmr->tcb != NULL) {
25708745f898SMichael Tuexen 			atomic_add_int(&stcb->asoc.refcnt, 1);
25718745f898SMichael Tuexen 		}
25728745f898SMichael Tuexen 		if (tmr->net != NULL) {
25738745f898SMichael Tuexen 			atomic_add_int(&net->ref_count, 1);
25748745f898SMichael Tuexen 		}
2575a412576eSMichael Tuexen 	} else {
2576a412576eSMichael Tuexen 		/*
2577a412576eSMichael Tuexen 		 * This should not happen, since we checked for pending
2578a412576eSMichael Tuexen 		 * above.
2579a412576eSMichael Tuexen 		 */
2580a412576eSMichael Tuexen 		SCTPDBG(SCTP_DEBUG_TIMER2,
258137686ccfSMichael Tuexen 		    "Timer type %d restarted: ticks=%u, inp=%p, stcb=%p, net=%p.\n",
2582a412576eSMichael Tuexen 		    t_type, to_ticks, inp, stcb, net);
2583a412576eSMichael Tuexen 	}
2584ad81507eSRandall Stewart 	return;
2585f8829a4aSRandall Stewart }
2586f8829a4aSRandall Stewart 
2587a412576eSMichael Tuexen /*-
2588a412576eSMichael Tuexen  * The following table shows which parameters must be provided
2589a412576eSMichael Tuexen  * when calling sctp_timer_stop(). For parameters not being
2590a412576eSMichael Tuexen  * provided, NULL must be used.
2591a412576eSMichael Tuexen  *
2592a412576eSMichael Tuexen  * |Name                         |inp |stcb|net |
2593a412576eSMichael Tuexen  * |-----------------------------|----|----|----|
2594a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_SEND         |Yes |Yes |Yes |
2595a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_INIT         |Yes |Yes |Yes |
2596a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_RECV         |Yes |Yes |No  |
2597a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_SHUTDOWN     |Yes |Yes |Yes |
2598a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_HEARTBEAT    |Yes |Yes |Yes |
2599a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_COOKIE       |Yes |Yes |Yes |
2600a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_NEWCOOKIE    |Yes |No  |No  |
2601a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_PATHMTURAISE |Yes |Yes |Yes |
2602a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_SHUTDOWNACK  |Yes |Yes |Yes |
2603a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_ASCONF       |Yes |Yes |No  |
2604a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_SHUTDOWNGUARD|Yes |Yes |No  |
2605a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_AUTOCLOSE    |Yes |Yes |No  |
2606a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_STRRESET     |Yes |Yes |No  |
2607a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_INPKILL      |Yes |No  |No  |
2608a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_ASOCKILL     |Yes |Yes |No  |
2609a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_ADDR_WQ      |No  |No  |No  |
2610a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_PRIM_DELETED |Yes |Yes |No  |
2611a412576eSMichael Tuexen  *
2612a412576eSMichael Tuexen  */
2613a412576eSMichael Tuexen 
26146e55db54SRandall Stewart void
2615f8829a4aSRandall Stewart sctp_timer_stop(int t_type, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
2616a5d547adSRandall Stewart     struct sctp_nets *net, uint32_t from)
2617f8829a4aSRandall Stewart {
2618f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
2619f8829a4aSRandall Stewart 
2620f4cb790aSMichael Tuexen 	KASSERT(stcb == NULL || stcb->sctp_ep == inp,
2621f4cb790aSMichael Tuexen 	    ("sctp_timer_stop of type %d: inp = %p, stcb->sctp_ep %p",
2622f4cb790aSMichael Tuexen 	    t_type, stcb, stcb->sctp_ep));
2623a412576eSMichael Tuexen 	if (stcb != NULL) {
2624f8829a4aSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
2625a412576eSMichael Tuexen 	} else if (inp != NULL) {
2626a412576eSMichael Tuexen 		SCTP_INP_WLOCK_ASSERT(inp);
2627a412576eSMichael Tuexen 	} else {
2628a412576eSMichael Tuexen 		SCTP_WQ_ADDR_LOCK_ASSERT();
2629f8829a4aSRandall Stewart 	}
2630a412576eSMichael Tuexen 	tmr = NULL;
2631f8829a4aSRandall Stewart 	switch (t_type) {
2632f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
2633a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2634a412576eSMichael Tuexen #ifdef INVARIANTS
2635a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2636a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2637a412576eSMichael Tuexen #else
26386e55db54SRandall Stewart 			return;
2639a412576eSMichael Tuexen #endif
2640f8829a4aSRandall Stewart 		}
2641f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2642f8829a4aSRandall Stewart 		break;
2643f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
2644a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2645a412576eSMichael Tuexen #ifdef INVARIANTS
2646a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2647a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2648a412576eSMichael Tuexen #else
26496e55db54SRandall Stewart 			return;
2650a412576eSMichael Tuexen #endif
2651f8829a4aSRandall Stewart 		}
2652f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2653f8829a4aSRandall Stewart 		break;
2654f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
2655a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2656a412576eSMichael Tuexen #ifdef INVARIANTS
2657a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2658a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2659a412576eSMichael Tuexen #else
26606e55db54SRandall Stewart 			return;
2661a412576eSMichael Tuexen #endif
2662f8829a4aSRandall Stewart 		}
2663f8829a4aSRandall Stewart 		tmr = &stcb->asoc.dack_timer;
2664f8829a4aSRandall Stewart 		break;
2665f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
2666a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2667a412576eSMichael Tuexen #ifdef INVARIANTS
2668a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2669a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2670a412576eSMichael Tuexen #else
26716e55db54SRandall Stewart 			return;
2672a412576eSMichael Tuexen #endif
2673f8829a4aSRandall Stewart 		}
2674f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2675f8829a4aSRandall Stewart 		break;
2676f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
2677a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2678a412576eSMichael Tuexen #ifdef INVARIANTS
2679a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2680a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2681a412576eSMichael Tuexen #else
26826e55db54SRandall Stewart 			return;
2683a412576eSMichael Tuexen #endif
2684f8829a4aSRandall Stewart 		}
2685ca85e948SMichael Tuexen 		tmr = &net->hb_timer;
2686f8829a4aSRandall Stewart 		break;
2687f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
2688a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2689a412576eSMichael Tuexen #ifdef INVARIANTS
2690a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2691a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2692a412576eSMichael Tuexen #else
26936e55db54SRandall Stewart 			return;
2694a412576eSMichael Tuexen #endif
2695f8829a4aSRandall Stewart 		}
2696f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2697f8829a4aSRandall Stewart 		break;
2698f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
2699a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb != NULL) || (net != NULL)) {
2700a412576eSMichael Tuexen #ifdef INVARIANTS
2701a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2702a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2703a412576eSMichael Tuexen #else
2704a412576eSMichael Tuexen 			return;
2705a412576eSMichael Tuexen #endif
2706a412576eSMichael Tuexen 		}
2707f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2708f8829a4aSRandall Stewart 		break;
2709f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
2710a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2711a412576eSMichael Tuexen #ifdef INVARIANTS
2712a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2713a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2714a412576eSMichael Tuexen #else
27156e55db54SRandall Stewart 			return;
2716a412576eSMichael Tuexen #endif
2717f8829a4aSRandall Stewart 		}
2718f8829a4aSRandall Stewart 		tmr = &net->pmtu_timer;
2719f8829a4aSRandall Stewart 		break;
2720f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
2721a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2722a412576eSMichael Tuexen #ifdef INVARIANTS
2723a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2724a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2725a412576eSMichael Tuexen #else
27266e55db54SRandall Stewart 			return;
2727a412576eSMichael Tuexen #endif
2728f8829a4aSRandall Stewart 		}
2729f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2730f8829a4aSRandall Stewart 		break;
27310554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_ASCONF:
2732a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2733a412576eSMichael Tuexen #ifdef INVARIANTS
2734a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2735a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2736a412576eSMichael Tuexen #else
27370554e01dSMichael Tuexen 			return;
2738a412576eSMichael Tuexen #endif
27390554e01dSMichael Tuexen 		}
27400554e01dSMichael Tuexen 		tmr = &stcb->asoc.asconf_timer;
27410554e01dSMichael Tuexen 		break;
2742f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
2743a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2744a412576eSMichael Tuexen #ifdef INVARIANTS
2745a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2746a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2747a412576eSMichael Tuexen #else
27486e55db54SRandall Stewart 			return;
2749a412576eSMichael Tuexen #endif
2750f8829a4aSRandall Stewart 		}
2751f8829a4aSRandall Stewart 		tmr = &stcb->asoc.shut_guard_timer;
2752f8829a4aSRandall Stewart 		break;
27530554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_AUTOCLOSE:
2754a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2755a412576eSMichael Tuexen #ifdef INVARIANTS
2756a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2757a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2758a412576eSMichael Tuexen #else
27590554e01dSMichael Tuexen 			return;
2760a412576eSMichael Tuexen #endif
27610554e01dSMichael Tuexen 		}
27620554e01dSMichael Tuexen 		tmr = &stcb->asoc.autoclose_timer;
27630554e01dSMichael Tuexen 		break;
2764f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_STRRESET:
2765a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2766a412576eSMichael Tuexen #ifdef INVARIANTS
2767a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2768a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2769a412576eSMichael Tuexen #else
27706e55db54SRandall Stewart 			return;
2771a412576eSMichael Tuexen #endif
2772f8829a4aSRandall Stewart 		}
2773f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2774f8829a4aSRandall Stewart 		break;
27750554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_INPKILL:
27760554e01dSMichael Tuexen 		/*
2777e7e65008SMichael Tuexen 		 * The inp is setup to die. We re-use the signature_change
27780554e01dSMichael Tuexen 		 * timer since that has stopped and we are in the GONE
27790554e01dSMichael Tuexen 		 * state.
27800554e01dSMichael Tuexen 		 */
2781a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb != NULL) || (net != NULL)) {
2782a412576eSMichael Tuexen #ifdef INVARIANTS
2783a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2784a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2785a412576eSMichael Tuexen #else
2786a412576eSMichael Tuexen 			return;
2787a412576eSMichael Tuexen #endif
2788a412576eSMichael Tuexen 		}
27890554e01dSMichael Tuexen 		tmr = &inp->sctp_ep.signature_change;
27900554e01dSMichael Tuexen 		break;
27910554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_ASOCKILL:
2792a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2793a412576eSMichael Tuexen #ifdef INVARIANTS
2794a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2795a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2796a412576eSMichael Tuexen #else
27976e55db54SRandall Stewart 			return;
2798a412576eSMichael Tuexen #endif
2799f8829a4aSRandall Stewart 		}
28000554e01dSMichael Tuexen 		tmr = &stcb->asoc.strreset_timer;
28010554e01dSMichael Tuexen 		break;
28020554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_ADDR_WQ:
2803a412576eSMichael Tuexen 		if ((inp != NULL) || (stcb != NULL) || (net != NULL)) {
2804a412576eSMichael Tuexen #ifdef INVARIANTS
2805a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2806a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2807a412576eSMichael Tuexen #else
2808a412576eSMichael Tuexen 			return;
2809a412576eSMichael Tuexen #endif
2810a412576eSMichael Tuexen 		}
28110554e01dSMichael Tuexen 		tmr = &SCTP_BASE_INFO(addr_wq_timer);
2812f8829a4aSRandall Stewart 		break;
2813851b7298SRandall Stewart 	case SCTP_TIMER_TYPE_PRIM_DELETED:
2814a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2815a412576eSMichael Tuexen #ifdef INVARIANTS
2816a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2817a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2818a412576eSMichael Tuexen #else
2819851b7298SRandall Stewart 			return;
2820a412576eSMichael Tuexen #endif
2821851b7298SRandall Stewart 		}
2822851b7298SRandall Stewart 		tmr = &stcb->asoc.delete_prim_timer;
2823851b7298SRandall Stewart 		break;
2824f8829a4aSRandall Stewart 	default:
28257522682eSMichael Tuexen #ifdef INVARIANTS
2826a412576eSMichael Tuexen 		panic("Unknown timer type %d", t_type);
28277522682eSMichael Tuexen #else
28287522682eSMichael Tuexen 		return;
28297522682eSMichael Tuexen #endif
283060990c0cSMichael Tuexen 	}
2831a412576eSMichael Tuexen 	KASSERT(tmr != NULL, ("tmr is NULL for timer type %d", t_type));
2832a412576eSMichael Tuexen 	if ((tmr->type != SCTP_TIMER_TYPE_NONE) &&
2833a412576eSMichael Tuexen 	    (tmr->type != t_type)) {
2834f8829a4aSRandall Stewart 		/*
2835f8829a4aSRandall Stewart 		 * Ok we have a timer that is under joint use. Cookie timer
2836f8829a4aSRandall Stewart 		 * per chance with the SEND timer. We therefore are NOT
2837f8829a4aSRandall Stewart 		 * running the timer that the caller wants stopped.  So just
2838f8829a4aSRandall Stewart 		 * return.
2839f8829a4aSRandall Stewart 		 */
2840a412576eSMichael Tuexen 		SCTPDBG(SCTP_DEBUG_TIMER2,
284137686ccfSMichael Tuexen 		    "Shared timer type %d not running: inp=%p, stcb=%p, net=%p.\n",
2842a412576eSMichael Tuexen 		    t_type, inp, stcb, net);
28436e55db54SRandall Stewart 		return;
2844f8829a4aSRandall Stewart 	}
2845ad81507eSRandall Stewart 	if ((t_type == SCTP_TIMER_TYPE_SEND) && (stcb != NULL)) {
2846f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up--;
2847f8829a4aSRandall Stewart 		if (stcb->asoc.num_send_timers_up < 0) {
2848f8829a4aSRandall Stewart 			stcb->asoc.num_send_timers_up = 0;
2849f8829a4aSRandall Stewart 		}
2850f8829a4aSRandall Stewart 	}
2851f8829a4aSRandall Stewart 	tmr->self = NULL;
2852a5d547adSRandall Stewart 	tmr->stopped_from = from;
2853a412576eSMichael Tuexen 	if (SCTP_OS_TIMER_STOP(&tmr->timer) == 1) {
2854a412576eSMichael Tuexen 		KASSERT(tmr->ep == inp,
2855a412576eSMichael Tuexen 		    ("sctp_timer_stop of type %d: inp = %p, tmr->inp = %p",
2856a412576eSMichael Tuexen 		    t_type, inp, tmr->ep));
2857a412576eSMichael Tuexen 		KASSERT(tmr->tcb == stcb,
2858a412576eSMichael Tuexen 		    ("sctp_timer_stop of type %d: stcb = %p, tmr->stcb = %p",
2859a412576eSMichael Tuexen 		    t_type, stcb, tmr->tcb));
2860a412576eSMichael Tuexen 		KASSERT(((t_type == SCTP_TIMER_TYPE_ASCONF) && (tmr->net != NULL)) ||
2861a412576eSMichael Tuexen 		    ((t_type != SCTP_TIMER_TYPE_ASCONF) && (tmr->net == net)),
2862a412576eSMichael Tuexen 		    ("sctp_timer_stop of type %d: net = %p, tmr->net = %p",
2863a412576eSMichael Tuexen 		    t_type, net, tmr->net));
2864a412576eSMichael Tuexen 		SCTPDBG(SCTP_DEBUG_TIMER2,
286537686ccfSMichael Tuexen 		    "Timer type %d stopped: inp=%p, stcb=%p, net=%p.\n",
2866a412576eSMichael Tuexen 		    t_type, inp, stcb, net);
28678745f898SMichael Tuexen 		/*
28688745f898SMichael Tuexen 		 * If the timer was actually stopped, decrement reference
28698745f898SMichael Tuexen 		 * counts that were incremented in sctp_timer_start().
28708745f898SMichael Tuexen 		 */
28718745f898SMichael Tuexen 		if (tmr->ep != NULL) {
2872a412576eSMichael Tuexen 			tmr->ep = NULL;
2873868868f1SMichael Tuexen 			SCTP_INP_DECR_REF(inp);
28748745f898SMichael Tuexen 		}
28758745f898SMichael Tuexen 		if (tmr->tcb != NULL) {
2876a412576eSMichael Tuexen 			tmr->tcb = NULL;
2877868868f1SMichael Tuexen 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
28788745f898SMichael Tuexen 		}
28798745f898SMichael Tuexen 		if (tmr->net != NULL) {
2880868868f1SMichael Tuexen 			struct sctp_nets *tmr_net;
2881868868f1SMichael Tuexen 
28828745f898SMichael Tuexen 			/*
28838745f898SMichael Tuexen 			 * Can't use net, since it doesn't work for
28848745f898SMichael Tuexen 			 * SCTP_TIMER_TYPE_ASCONF.
28858745f898SMichael Tuexen 			 */
2886868868f1SMichael Tuexen 			tmr_net = tmr->net;
2887a412576eSMichael Tuexen 			tmr->net = NULL;
288889c6aba7SMichael Tuexen 			sctp_free_remote_addr(tmr_net);
28898745f898SMichael Tuexen 		}
2890a412576eSMichael Tuexen 	} else {
2891a412576eSMichael Tuexen 		SCTPDBG(SCTP_DEBUG_TIMER2,
289237686ccfSMichael Tuexen 		    "Timer type %d not stopped: inp=%p, stcb=%p, net=%p.\n",
2893a412576eSMichael Tuexen 		    t_type, inp, stcb, net);
2894a412576eSMichael Tuexen 	}
28956e55db54SRandall Stewart 	return;
2896f8829a4aSRandall Stewart }
2897f8829a4aSRandall Stewart 
2898f8829a4aSRandall Stewart uint32_t
2899b0471b4bSMichael Tuexen sctp_calculate_len(struct mbuf *m)
2900b0471b4bSMichael Tuexen {
2901f8829a4aSRandall Stewart 	struct mbuf *at;
290234ae6a1aSMichael Tuexen 	uint32_t tlen;
2903f8829a4aSRandall Stewart 
290434ae6a1aSMichael Tuexen 	tlen = 0;
290534ae6a1aSMichael Tuexen 	for (at = m; at != NULL; at = SCTP_BUF_NEXT(at)) {
2906139bc87fSRandall Stewart 		tlen += SCTP_BUF_LEN(at);
2907f8829a4aSRandall Stewart 	}
2908f8829a4aSRandall Stewart 	return (tlen);
2909f8829a4aSRandall Stewart }
2910f8829a4aSRandall Stewart 
2911f8829a4aSRandall Stewart /*
291244f2a327SMichael Tuexen  * Given an association and starting time of the current RTT period, update
291344f2a327SMichael Tuexen  * RTO in number of msecs. net should point to the current network.
291444f2a327SMichael Tuexen  * Return 1, if an RTO update was performed, return 0 if no update was
291544f2a327SMichael Tuexen  * performed due to invalid starting point.
2916f8829a4aSRandall Stewart  */
2917899288aeSRandall Stewart 
291844f2a327SMichael Tuexen int
2919f8829a4aSRandall Stewart sctp_calculate_rto(struct sctp_tcb *stcb,
2920f8829a4aSRandall Stewart     struct sctp_association *asoc,
2921f8829a4aSRandall Stewart     struct sctp_nets *net,
29228c8e10b7SMichael Tuexen     struct timeval *old,
2923b0471b4bSMichael Tuexen     int rtt_from_sack)
2924b0471b4bSMichael Tuexen {
292544f2a327SMichael Tuexen 	struct timeval now;
292644f2a327SMichael Tuexen 	uint64_t rtt_us;	/* RTT in us */
2927be1d9176SMichael Tuexen 	int32_t rtt;		/* RTT in ms */
2928be1d9176SMichael Tuexen 	uint32_t new_rto;
2929f8829a4aSRandall Stewart 	int first_measure = 0;
2930f8829a4aSRandall Stewart 
2931f8829a4aSRandall Stewart 	/************************/
2932f8829a4aSRandall Stewart 	/* 1. calculate new RTT */
2933f8829a4aSRandall Stewart 	/************************/
2934f8829a4aSRandall Stewart 	/* get the current time */
2935299108c5SRandall Stewart 	if (stcb->asoc.use_precise_time) {
2936299108c5SRandall Stewart 		(void)SCTP_GETPTIME_TIMEVAL(&now);
2937299108c5SRandall Stewart 	} else {
29386e55db54SRandall Stewart 		(void)SCTP_GETTIME_TIMEVAL(&now);
2939299108c5SRandall Stewart 	}
294044f2a327SMichael Tuexen 	if ((old->tv_sec > now.tv_sec) ||
294188116b7eSMichael Tuexen 	    ((old->tv_sec == now.tv_sec) && (old->tv_usec > now.tv_usec))) {
294244f2a327SMichael Tuexen 		/* The starting point is in the future. */
294344f2a327SMichael Tuexen 		return (0);
294444f2a327SMichael Tuexen 	}
2945be1d9176SMichael Tuexen 	timevalsub(&now, old);
294644f2a327SMichael Tuexen 	rtt_us = (uint64_t)1000000 * (uint64_t)now.tv_sec + (uint64_t)now.tv_usec;
294744f2a327SMichael Tuexen 	if (rtt_us > SCTP_RTO_UPPER_BOUND * 1000) {
294844f2a327SMichael Tuexen 		/* The RTT is larger than a sane value. */
294944f2a327SMichael Tuexen 		return (0);
295044f2a327SMichael Tuexen 	}
2951be1d9176SMichael Tuexen 	/* store the current RTT in us */
295244f2a327SMichael Tuexen 	net->rtt = rtt_us;
2953b60b0fe6SMichael Tuexen 	/* compute rtt in ms */
2954b60b0fe6SMichael Tuexen 	rtt = (int32_t)(net->rtt / 1000);
2955f79aab18SRandall Stewart 	if ((asoc->cc_functions.sctp_rtt_calculated) && (rtt_from_sack == SCTP_RTT_FROM_DATA)) {
2956b7b84c0eSMichael Tuexen 		/*
2957b7b84c0eSMichael Tuexen 		 * Tell the CC module that a new update has just occurred
2958b7b84c0eSMichael Tuexen 		 * from a sack
2959b7b84c0eSMichael Tuexen 		 */
2960f79aab18SRandall Stewart 		(*asoc->cc_functions.sctp_rtt_calculated) (stcb, net, &now);
2961f79aab18SRandall Stewart 	}
2962f79aab18SRandall Stewart 	/*
2963f79aab18SRandall Stewart 	 * Do we need to determine the lan? We do this only on sacks i.e.
2964f79aab18SRandall Stewart 	 * RTT being determined from data not non-data (HB/INIT->INITACK).
2965f79aab18SRandall Stewart 	 */
2966f79aab18SRandall Stewart 	if ((rtt_from_sack == SCTP_RTT_FROM_DATA) &&
2967be1d9176SMichael Tuexen 	    (net->lan_type == SCTP_LAN_UNKNOWN)) {
2968be1d9176SMichael Tuexen 		if (net->rtt > SCTP_LOCAL_LAN_RTT) {
2969899288aeSRandall Stewart 			net->lan_type = SCTP_LAN_INTERNET;
2970899288aeSRandall Stewart 		} else {
2971899288aeSRandall Stewart 			net->lan_type = SCTP_LAN_LOCAL;
2972899288aeSRandall Stewart 		}
2973899288aeSRandall Stewart 	}
29740053ed28SMichael Tuexen 
2975f8829a4aSRandall Stewart 	/***************************/
2976f8829a4aSRandall Stewart 	/* 2. update RTTVAR & SRTT */
2977f8829a4aSRandall Stewart 	/***************************/
2978be1d9176SMichael Tuexen 	/*-
2979be1d9176SMichael Tuexen 	 * Compute the scaled average lastsa and the
2980be1d9176SMichael Tuexen 	 * scaled variance lastsv as described in van Jacobson
2981be1d9176SMichael Tuexen 	 * Paper "Congestion Avoidance and Control", Annex A.
2982be1d9176SMichael Tuexen 	 *
2983be1d9176SMichael Tuexen 	 * (net->lastsa >> SCTP_RTT_SHIFT) is the srtt
298444f2a327SMichael Tuexen 	 * (net->lastsv >> SCTP_RTT_VAR_SHIFT) is the rttvar
2985be1d9176SMichael Tuexen 	 */
29869a972525SRandall Stewart 	if (net->RTO_measured) {
2987be1d9176SMichael Tuexen 		rtt -= (net->lastsa >> SCTP_RTT_SHIFT);
2988be1d9176SMichael Tuexen 		net->lastsa += rtt;
2989be1d9176SMichael Tuexen 		if (rtt < 0) {
2990be1d9176SMichael Tuexen 			rtt = -rtt;
2991be1d9176SMichael Tuexen 		}
2992be1d9176SMichael Tuexen 		rtt -= (net->lastsv >> SCTP_RTT_VAR_SHIFT);
2993be1d9176SMichael Tuexen 		net->lastsv += rtt;
2994b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RTTVAR_LOGGING_ENABLE) {
2995f8829a4aSRandall Stewart 			rto_logging(net, SCTP_LOG_RTTVAR);
299680fefe0aSRandall Stewart 		}
2997f8829a4aSRandall Stewart 	} else {
2998e7e65008SMichael Tuexen 		/* First RTO measurement */
29999a972525SRandall Stewart 		net->RTO_measured = 1;
3000f8829a4aSRandall Stewart 		first_measure = 1;
3001be1d9176SMichael Tuexen 		net->lastsa = rtt << SCTP_RTT_SHIFT;
3002be1d9176SMichael Tuexen 		net->lastsv = (rtt / 2) << SCTP_RTT_VAR_SHIFT;
3003b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RTTVAR_LOGGING_ENABLE) {
3004f8829a4aSRandall Stewart 			rto_logging(net, SCTP_LOG_INITIAL_RTT);
300580fefe0aSRandall Stewart 		}
3006f8829a4aSRandall Stewart 	}
3007be1d9176SMichael Tuexen 	if (net->lastsv == 0) {
3008be1d9176SMichael Tuexen 		net->lastsv = SCTP_CLOCK_GRANULARITY;
3009be1d9176SMichael Tuexen 	}
3010108df27cSRandall Stewart 	new_rto = (net->lastsa >> SCTP_RTT_SHIFT) + net->lastsv;
3011f8829a4aSRandall Stewart 	if ((new_rto > SCTP_SAT_NETWORK_MIN) &&
3012f8829a4aSRandall Stewart 	    (stcb->asoc.sat_network_lockout == 0)) {
3013f8829a4aSRandall Stewart 		stcb->asoc.sat_network = 1;
3014f8829a4aSRandall Stewart 	} else if ((!first_measure) && stcb->asoc.sat_network) {
3015f8829a4aSRandall Stewart 		stcb->asoc.sat_network = 0;
3016f8829a4aSRandall Stewart 		stcb->asoc.sat_network_lockout = 1;
3017f8829a4aSRandall Stewart 	}
3018f8829a4aSRandall Stewart 	/* bound it, per C6/C7 in Section 5.3.1 */
3019f8829a4aSRandall Stewart 	if (new_rto < stcb->asoc.minrto) {
3020f8829a4aSRandall Stewart 		new_rto = stcb->asoc.minrto;
3021f8829a4aSRandall Stewart 	}
3022f8829a4aSRandall Stewart 	if (new_rto > stcb->asoc.maxrto) {
3023f8829a4aSRandall Stewart 		new_rto = stcb->asoc.maxrto;
3024f8829a4aSRandall Stewart 	}
302544f2a327SMichael Tuexen 	net->RTO = new_rto;
302644f2a327SMichael Tuexen 	return (1);
3027f8829a4aSRandall Stewart }
3028f8829a4aSRandall Stewart 
3029f8829a4aSRandall Stewart /*
3030f8829a4aSRandall Stewart  * return a pointer to a contiguous piece of data from the given mbuf chain
3031f8829a4aSRandall Stewart  * starting at 'off' for 'len' bytes.  If the desired piece spans more than
3032f8829a4aSRandall Stewart  * one mbuf, a copy is made at 'ptr'. caller must ensure that the buffer size
3033f8829a4aSRandall Stewart  * is >= 'len' returns NULL if there there isn't 'len' bytes in the chain.
3034f8829a4aSRandall Stewart  */
303572fb6fdbSRandall Stewart caddr_t
3036f8829a4aSRandall Stewart sctp_m_getptr(struct mbuf *m, int off, int len, uint8_t *in_ptr)
3037f8829a4aSRandall Stewart {
3038f8829a4aSRandall Stewart 	uint32_t count;
3039f8829a4aSRandall Stewart 	uint8_t *ptr;
3040f8829a4aSRandall Stewart 
3041f8829a4aSRandall Stewart 	ptr = in_ptr;
3042f8829a4aSRandall Stewart 	if ((off < 0) || (len <= 0))
3043f8829a4aSRandall Stewart 		return (NULL);
3044f8829a4aSRandall Stewart 
3045f8829a4aSRandall Stewart 	/* find the desired start location */
3046f8829a4aSRandall Stewart 	while ((m != NULL) && (off > 0)) {
3047139bc87fSRandall Stewart 		if (off < SCTP_BUF_LEN(m))
3048f8829a4aSRandall Stewart 			break;
3049139bc87fSRandall Stewart 		off -= SCTP_BUF_LEN(m);
3050139bc87fSRandall Stewart 		m = SCTP_BUF_NEXT(m);
3051f8829a4aSRandall Stewart 	}
3052f8829a4aSRandall Stewart 	if (m == NULL)
3053f8829a4aSRandall Stewart 		return (NULL);
3054f8829a4aSRandall Stewart 
3055f8829a4aSRandall Stewart 	/* is the current mbuf large enough (eg. contiguous)? */
3056139bc87fSRandall Stewart 	if ((SCTP_BUF_LEN(m) - off) >= len) {
3057f8829a4aSRandall Stewart 		return (mtod(m, caddr_t)+off);
3058f8829a4aSRandall Stewart 	} else {
3059f8829a4aSRandall Stewart 		/* else, it spans more than one mbuf, so save a temp copy... */
3060f8829a4aSRandall Stewart 		while ((m != NULL) && (len > 0)) {
3061139bc87fSRandall Stewart 			count = min(SCTP_BUF_LEN(m) - off, len);
30625ba7f91fSMichael Tuexen 			memcpy(ptr, mtod(m, caddr_t)+off, count);
3063f8829a4aSRandall Stewart 			len -= count;
3064f8829a4aSRandall Stewart 			ptr += count;
3065f8829a4aSRandall Stewart 			off = 0;
3066139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
3067f8829a4aSRandall Stewart 		}
3068f8829a4aSRandall Stewart 		if ((m == NULL) && (len > 0))
3069f8829a4aSRandall Stewart 			return (NULL);
3070f8829a4aSRandall Stewart 		else
3071f8829a4aSRandall Stewart 			return ((caddr_t)in_ptr);
3072f8829a4aSRandall Stewart 	}
3073f8829a4aSRandall Stewart }
3074f8829a4aSRandall Stewart 
3075f8829a4aSRandall Stewart struct sctp_paramhdr *
3076f8829a4aSRandall Stewart sctp_get_next_param(struct mbuf *m,
3077f8829a4aSRandall Stewart     int offset,
3078f8829a4aSRandall Stewart     struct sctp_paramhdr *pull,
3079f8829a4aSRandall Stewart     int pull_limit)
3080f8829a4aSRandall Stewart {
3081f8829a4aSRandall Stewart 	/* This just provides a typed signature to Peter's Pull routine */
3082f8829a4aSRandall Stewart 	return ((struct sctp_paramhdr *)sctp_m_getptr(m, offset, pull_limit,
3083f8829a4aSRandall Stewart 	    (uint8_t *)pull));
3084f8829a4aSRandall Stewart }
3085f8829a4aSRandall Stewart 
3086ce11b842SMichael Tuexen struct mbuf *
3087f8829a4aSRandall Stewart sctp_add_pad_tombuf(struct mbuf *m, int padlen)
3088f8829a4aSRandall Stewart {
3089ce11b842SMichael Tuexen 	struct mbuf *m_last;
3090ce11b842SMichael Tuexen 	caddr_t dp;
3091f8829a4aSRandall Stewart 
3092f8829a4aSRandall Stewart 	if (padlen > 3) {
3093ce11b842SMichael Tuexen 		return (NULL);
3094f8829a4aSRandall Stewart 	}
309541eee555SRandall Stewart 	if (padlen <= M_TRAILINGSPACE(m)) {
3096f8829a4aSRandall Stewart 		/*
3097f8829a4aSRandall Stewart 		 * The easy way. We hope the majority of the time we hit
3098f8829a4aSRandall Stewart 		 * here :)
3099f8829a4aSRandall Stewart 		 */
3100ce11b842SMichael Tuexen 		m_last = m;
3101f8829a4aSRandall Stewart 	} else {
3102ce11b842SMichael Tuexen 		/* Hard way we must grow the mbuf chain */
3103ce11b842SMichael Tuexen 		m_last = sctp_get_mbuf_for_msg(padlen, 0, M_NOWAIT, 1, MT_DATA);
3104ce11b842SMichael Tuexen 		if (m_last == NULL) {
3105ce11b842SMichael Tuexen 			return (NULL);
3106f8829a4aSRandall Stewart 		}
3107ce11b842SMichael Tuexen 		SCTP_BUF_LEN(m_last) = 0;
3108ce11b842SMichael Tuexen 		SCTP_BUF_NEXT(m_last) = NULL;
3109ce11b842SMichael Tuexen 		SCTP_BUF_NEXT(m) = m_last;
3110f8829a4aSRandall Stewart 	}
3111ce11b842SMichael Tuexen 	dp = mtod(m_last, caddr_t)+SCTP_BUF_LEN(m_last);
3112ce11b842SMichael Tuexen 	SCTP_BUF_LEN(m_last) += padlen;
3113ce11b842SMichael Tuexen 	memset(dp, 0, padlen);
3114ce11b842SMichael Tuexen 	return (m_last);
3115f8829a4aSRandall Stewart }
3116f8829a4aSRandall Stewart 
3117ce11b842SMichael Tuexen struct mbuf *
3118f8829a4aSRandall Stewart sctp_pad_lastmbuf(struct mbuf *m, int padval, struct mbuf *last_mbuf)
3119f8829a4aSRandall Stewart {
3120f8829a4aSRandall Stewart 	/* find the last mbuf in chain and pad it */
3121f8829a4aSRandall Stewart 	struct mbuf *m_at;
3122f8829a4aSRandall Stewart 
3123ce11b842SMichael Tuexen 	if (last_mbuf != NULL) {
3124f8829a4aSRandall Stewart 		return (sctp_add_pad_tombuf(last_mbuf, padval));
3125f8829a4aSRandall Stewart 	} else {
312617267b32SMichael Tuexen 		for (m_at = m; m_at; m_at = SCTP_BUF_NEXT(m_at)) {
3127139bc87fSRandall Stewart 			if (SCTP_BUF_NEXT(m_at) == NULL) {
3128f8829a4aSRandall Stewart 				return (sctp_add_pad_tombuf(m_at, padval));
3129f8829a4aSRandall Stewart 			}
3130f8829a4aSRandall Stewart 		}
3131f8829a4aSRandall Stewart 	}
3132ce11b842SMichael Tuexen 	return (NULL);
3133f8829a4aSRandall Stewart }
3134f8829a4aSRandall Stewart 
3135f8829a4aSRandall Stewart static void
3136c5b5675dSMichael Tuexen sctp_notify_assoc_change(uint16_t state, struct sctp_tcb *stcb,
3137105b68b4SMichael Tuexen     uint16_t error, struct sctp_abort_chunk *abort,
3138105b68b4SMichael Tuexen     bool from_peer, bool timedout, int so_locked)
3139f8829a4aSRandall Stewart {
3140f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3141f8829a4aSRandall Stewart 	struct sctp_assoc_change *sac;
3142f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
31433ac76647SMichael Tuexen 	struct sctp_inpcb *inp;
31449a8e3088SMichael Tuexen 	unsigned int notif_len;
3145e06b67c7SMichael Tuexen 	unsigned int i;
31463ac76647SMichael Tuexen 	uint16_t abort_len;
3147ceaad40aSRandall Stewart 
3148105b68b4SMichael Tuexen 	KASSERT(abort == NULL || from_peer,
3149ce64352aSMichael Tuexen 	    ("sctp_notify_assoc_change: ABORT chunk provided for local termination"));
3150105b68b4SMichael Tuexen 	KASSERT(!from_peer || !timedout,
3151105b68b4SMichael Tuexen 	    ("sctp_notify_assoc_change: timeouts can only be local"));
3152f9425b3aSMichael Tuexen 	KASSERT(stcb != NULL, ("stcb == NULL"));
3153f9425b3aSMichael Tuexen 	SCTP_TCB_LOCK_ASSERT(stcb);
31543ac76647SMichael Tuexen 	inp = stcb->sctp_ep;
3155f9425b3aSMichael Tuexen 	SCTP_INP_READ_LOCK_ASSERT(inp);
3156f9425b3aSMichael Tuexen 
31573ac76647SMichael Tuexen 	if (sctp_stcb_is_feature_on(inp, stcb, SCTP_PCB_FLAGS_RECVASSOCEVNT)) {
31589a8e3088SMichael Tuexen 		notif_len = (unsigned int)sizeof(struct sctp_assoc_change);
3159a2b42326SMichael Tuexen 		if (abort != NULL) {
3160c9eb4473SMichael Tuexen 			abort_len = ntohs(abort->ch.chunk_length);
31619669e724SMichael Tuexen 			/*
31629669e724SMichael Tuexen 			 * Only SCTP_CHUNK_BUFFER_SIZE are guaranteed to be
316345d41de5SMichael Tuexen 			 * contiguous.
31649669e724SMichael Tuexen 			 */
31659669e724SMichael Tuexen 			if (abort_len > SCTP_CHUNK_BUFFER_SIZE) {
31669669e724SMichael Tuexen 				abort_len = SCTP_CHUNK_BUFFER_SIZE;
31679669e724SMichael Tuexen 			}
3168a2b42326SMichael Tuexen 		} else {
3169a2b42326SMichael Tuexen 			abort_len = 0;
3170c5b5675dSMichael Tuexen 		}
3171a2b42326SMichael Tuexen 		if ((state == SCTP_COMM_UP) || (state == SCTP_RESTART)) {
3172a2b42326SMichael Tuexen 			notif_len += SCTP_ASSOC_SUPPORTS_MAX;
3173a2b42326SMichael Tuexen 		} else if ((state == SCTP_COMM_LOST) || (state == SCTP_CANT_STR_ASSOC)) {
3174a2b42326SMichael Tuexen 			notif_len += abort_len;
3175a2b42326SMichael Tuexen 		}
3176eb1b1807SGleb Smirnoff 		m_notify = sctp_get_mbuf_for_msg(notif_len, 0, M_NOWAIT, 1, MT_DATA);
3177a2b42326SMichael Tuexen 		if (m_notify == NULL) {
3178a2b42326SMichael Tuexen 			/* Retry with smaller value. */
31799a8e3088SMichael Tuexen 			notif_len = (unsigned int)sizeof(struct sctp_assoc_change);
3180eb1b1807SGleb Smirnoff 			m_notify = sctp_get_mbuf_for_msg(notif_len, 0, M_NOWAIT, 1, MT_DATA);
3181a2b42326SMichael Tuexen 			if (m_notify == NULL) {
318258411b08SMichael Tuexen 				goto set_error;
3183a2b42326SMichael Tuexen 			}
3184a2b42326SMichael Tuexen 		}
3185a2b42326SMichael Tuexen 		SCTP_BUF_NEXT(m_notify) = NULL;
3186f8829a4aSRandall Stewart 		sac = mtod(m_notify, struct sctp_assoc_change *);
3187e432298aSXin LI 		memset(sac, 0, notif_len);
3188f8829a4aSRandall Stewart 		sac->sac_type = SCTP_ASSOC_CHANGE;
3189f8829a4aSRandall Stewart 		sac->sac_flags = 0;
3190f8829a4aSRandall Stewart 		sac->sac_length = sizeof(struct sctp_assoc_change);
3191c5b5675dSMichael Tuexen 		sac->sac_state = state;
3192f8829a4aSRandall Stewart 		sac->sac_error = error;
3193ce64352aSMichael Tuexen 		if (state == SCTP_CANT_STR_ASSOC) {
3194ce64352aSMichael Tuexen 			sac->sac_outbound_streams = 0;
3195ce64352aSMichael Tuexen 			sac->sac_inbound_streams = 0;
3196ce64352aSMichael Tuexen 		} else {
3197f8829a4aSRandall Stewart 			sac->sac_outbound_streams = stcb->asoc.streamoutcnt;
3198f8829a4aSRandall Stewart 			sac->sac_inbound_streams = stcb->asoc.streamincnt;
3199ce64352aSMichael Tuexen 		}
3200f8829a4aSRandall Stewart 		sac->sac_assoc_id = sctp_get_associd(stcb);
3201a2b42326SMichael Tuexen 		if (notif_len > sizeof(struct sctp_assoc_change)) {
3202c5b5675dSMichael Tuexen 			if ((state == SCTP_COMM_UP) || (state == SCTP_RESTART)) {
3203e06b67c7SMichael Tuexen 				i = 0;
3204c79bec9cSMichael Tuexen 				if (stcb->asoc.prsctp_supported == 1) {
3205e06b67c7SMichael Tuexen 					sac->sac_info[i++] = SCTP_ASSOC_SUPPORTS_PR;
3206e06b67c7SMichael Tuexen 				}
3207c79bec9cSMichael Tuexen 				if (stcb->asoc.auth_supported == 1) {
3208e06b67c7SMichael Tuexen 					sac->sac_info[i++] = SCTP_ASSOC_SUPPORTS_AUTH;
3209e06b67c7SMichael Tuexen 				}
3210c79bec9cSMichael Tuexen 				if (stcb->asoc.asconf_supported == 1) {
3211e06b67c7SMichael Tuexen 					sac->sac_info[i++] = SCTP_ASSOC_SUPPORTS_ASCONF;
3212e06b67c7SMichael Tuexen 				}
321344249214SRandall Stewart 				if (stcb->asoc.idata_supported == 1) {
321444249214SRandall Stewart 					sac->sac_info[i++] = SCTP_ASSOC_SUPPORTS_INTERLEAVING;
321544249214SRandall Stewart 				}
3216e06b67c7SMichael Tuexen 				sac->sac_info[i++] = SCTP_ASSOC_SUPPORTS_MULTIBUF;
3217c79bec9cSMichael Tuexen 				if (stcb->asoc.reconfig_supported == 1) {
3218e06b67c7SMichael Tuexen 					sac->sac_info[i++] = SCTP_ASSOC_SUPPORTS_RE_CONFIG;
3219e06b67c7SMichael Tuexen 				}
3220e06b67c7SMichael Tuexen 				sac->sac_length += i;
3221a2b42326SMichael Tuexen 			} else if ((state == SCTP_COMM_LOST) || (state == SCTP_CANT_STR_ASSOC)) {
3222a2b42326SMichael Tuexen 				memcpy(sac->sac_info, abort, abort_len);
3223a2b42326SMichael Tuexen 				sac->sac_length += abort_len;
3224a2b42326SMichael Tuexen 			}
3225c5b5675dSMichael Tuexen 		}
3226e06b67c7SMichael Tuexen 		SCTP_BUF_LEN(m_notify) = sac->sac_length;
3227f8829a4aSRandall Stewart 		control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
32287215cc1bSMichael Tuexen 		    0, 0, stcb->asoc.context, 0, 0, 0,
3229f8829a4aSRandall Stewart 		    m_notify);
323058411b08SMichael Tuexen 		if (control != NULL) {
3231139bc87fSRandall Stewart 			control->length = SCTP_BUF_LEN(m_notify);
323228cd0699SMichael Tuexen 			control->spec_flags = M_NOTIFICATION;
3233f8829a4aSRandall Stewart 			/* not that we need this */
3234f8829a4aSRandall Stewart 			control->tail_mbuf = m_notify;
32353ac76647SMichael Tuexen 			sctp_add_to_readq(inp, stcb, control,
32363ac76647SMichael Tuexen 			    &stcb->sctp_socket->so_rcv, 1,
3237f9425b3aSMichael Tuexen 			    SCTP_READ_LOCK_HELD, so_locked);
323858411b08SMichael Tuexen 		} else {
323958411b08SMichael Tuexen 			sctp_m_freem(m_notify);
324058411b08SMichael Tuexen 		}
324158411b08SMichael Tuexen 	}
324258411b08SMichael Tuexen 	/*
324358411b08SMichael Tuexen 	 * For 1-to-1 style sockets, we send up and error when an ABORT
324458411b08SMichael Tuexen 	 * comes in.
324558411b08SMichael Tuexen 	 */
324658411b08SMichael Tuexen set_error:
32473ac76647SMichael Tuexen 	if (((inp->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
32483ac76647SMichael Tuexen 	    (inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) &&
324958411b08SMichael Tuexen 	    ((state == SCTP_COMM_LOST) || (state == SCTP_CANT_STR_ASSOC))) {
3250e045904fSMichael Tuexen 		SOCK_LOCK(stcb->sctp_socket);
3251410a3b1eSMichael Tuexen 		if (from_peer) {
3252839d21d6SMichael Tuexen 			if (SCTP_GET_STATE(stcb) == SCTP_STATE_COOKIE_WAIT) {
325358411b08SMichael Tuexen 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ECONNREFUSED);
325458411b08SMichael Tuexen 				stcb->sctp_socket->so_error = ECONNREFUSED;
325558411b08SMichael Tuexen 			} else {
325658411b08SMichael Tuexen 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ECONNRESET);
325758411b08SMichael Tuexen 				stcb->sctp_socket->so_error = ECONNRESET;
325858411b08SMichael Tuexen 			}
3259410a3b1eSMichael Tuexen 		} else {
3260105b68b4SMichael Tuexen 			if (timedout) {
3261553bb068SMichael Tuexen 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ETIMEDOUT);
3262553bb068SMichael Tuexen 				stcb->sctp_socket->so_error = ETIMEDOUT;
3263553bb068SMichael Tuexen 			} else {
3264410a3b1eSMichael Tuexen 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ECONNABORTED);
3265410a3b1eSMichael Tuexen 				stcb->sctp_socket->so_error = ECONNABORTED;
3266410a3b1eSMichael Tuexen 			}
326758411b08SMichael Tuexen 		}
32683acfe1e1SGleb Smirnoff 		SOCK_UNLOCK(stcb->sctp_socket);
3269553bb068SMichael Tuexen 	}
327058411b08SMichael Tuexen 	/* Wake ANY sleepers */
32713ac76647SMichael Tuexen 	if (((inp->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
32723ac76647SMichael Tuexen 	    (inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) &&
327358411b08SMichael Tuexen 	    ((state == SCTP_COMM_LOST) || (state == SCTP_CANT_STR_ASSOC))) {
32743acfe1e1SGleb Smirnoff 		socantrcvmore(stcb->sctp_socket);
327558411b08SMichael Tuexen 	}
327658411b08SMichael Tuexen 	sorwakeup(stcb->sctp_socket);
327758411b08SMichael Tuexen 	sowwakeup(stcb->sctp_socket);
3278f8829a4aSRandall Stewart }
3279f8829a4aSRandall Stewart 
3280f8829a4aSRandall Stewart static void
3281f8829a4aSRandall Stewart sctp_notify_peer_addr_change(struct sctp_tcb *stcb, uint32_t state,
328228397ac1SMichael Tuexen     struct sockaddr *sa, uint32_t error, int so_locked)
3283f8829a4aSRandall Stewart {
3284f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3285f8829a4aSRandall Stewart 	struct sctp_paddr_change *spc;
3286f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3287f8829a4aSRandall Stewart 
3288f9425b3aSMichael Tuexen 	KASSERT(stcb != NULL, ("stcb == NULL"));
3289f9425b3aSMichael Tuexen 	SCTP_TCB_LOCK_ASSERT(stcb);
3290f9425b3aSMichael Tuexen 	SCTP_INP_READ_LOCK_ASSERT(stcb->sctp_ep);
3291f9425b3aSMichael Tuexen 
3292f9425b3aSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVPADDREVNT)) {
3293f8829a4aSRandall Stewart 		/* event not enabled */
3294f8829a4aSRandall Stewart 		return;
3295830d754dSRandall Stewart 	}
3296f9425b3aSMichael Tuexen 
3297eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_paddr_change), 0, M_NOWAIT, 1, MT_DATA);
3298f8829a4aSRandall Stewart 	if (m_notify == NULL)
3299f8829a4aSRandall Stewart 		return;
3300139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3301f8829a4aSRandall Stewart 	spc = mtod(m_notify, struct sctp_paddr_change *);
330256711f94SMichael Tuexen 	memset(spc, 0, sizeof(struct sctp_paddr_change));
3303f8829a4aSRandall Stewart 	spc->spc_type = SCTP_PEER_ADDR_CHANGE;
3304f8829a4aSRandall Stewart 	spc->spc_flags = 0;
3305f8829a4aSRandall Stewart 	spc->spc_length = sizeof(struct sctp_paddr_change);
33065e2c2d87SRandall Stewart 	switch (sa->sa_family) {
3307ea5eba11SMichael Tuexen #ifdef INET
33085e2c2d87SRandall Stewart 	case AF_INET:
3309d59107f7SMichael Tuexen #ifdef INET6
3310d59107f7SMichael Tuexen 		if (sctp_is_feature_on(stcb->sctp_ep, SCTP_PCB_FLAGS_NEEDS_MAPPED_V4)) {
3311d59107f7SMichael Tuexen 			in6_sin_2_v4mapsin6((struct sockaddr_in *)sa,
3312d59107f7SMichael Tuexen 			    (struct sockaddr_in6 *)&spc->spc_aaddr);
3313d59107f7SMichael Tuexen 		} else {
3314f8829a4aSRandall Stewart 			memcpy(&spc->spc_aaddr, sa, sizeof(struct sockaddr_in));
3315d59107f7SMichael Tuexen 		}
3316d59107f7SMichael Tuexen #else
3317d59107f7SMichael Tuexen 		memcpy(&spc->spc_aaddr, sa, sizeof(struct sockaddr_in));
3318d59107f7SMichael Tuexen #endif
33195e2c2d87SRandall Stewart 		break;
3320ea5eba11SMichael Tuexen #endif
33215e2c2d87SRandall Stewart #ifdef INET6
33225e2c2d87SRandall Stewart 	case AF_INET6:
33235e2c2d87SRandall Stewart 		{
3324f42a358aSRandall Stewart 			struct sockaddr_in6 *sin6;
3325f42a358aSRandall Stewart 
3326f8829a4aSRandall Stewart 			memcpy(&spc->spc_aaddr, sa, sizeof(struct sockaddr_in6));
3327f42a358aSRandall Stewart 
3328f42a358aSRandall Stewart 			sin6 = (struct sockaddr_in6 *)&spc->spc_aaddr;
3329f42a358aSRandall Stewart 			if (IN6_IS_SCOPE_LINKLOCAL(&sin6->sin6_addr)) {
333042551e99SRandall Stewart 				if (sin6->sin6_scope_id == 0) {
333142551e99SRandall Stewart 					/* recover scope_id for user */
3332f42a358aSRandall Stewart 					(void)sa6_recoverscope(sin6);
333342551e99SRandall Stewart 				} else {
333442551e99SRandall Stewart 					/* clear embedded scope_id for user */
333542551e99SRandall Stewart 					in6_clearscope(&sin6->sin6_addr);
333642551e99SRandall Stewart 				}
3337f42a358aSRandall Stewart 			}
33385e2c2d87SRandall Stewart 			break;
33395e2c2d87SRandall Stewart 		}
33405e2c2d87SRandall Stewart #endif
33415e2c2d87SRandall Stewart 	default:
33425e2c2d87SRandall Stewart 		/* TSNH */
33435e2c2d87SRandall Stewart 		break;
3344f8829a4aSRandall Stewart 	}
3345f8829a4aSRandall Stewart 	spc->spc_state = state;
3346f8829a4aSRandall Stewart 	spc->spc_error = error;
3347f8829a4aSRandall Stewart 	spc->spc_assoc_id = sctp_get_associd(stcb);
3348f8829a4aSRandall Stewart 
3349139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_paddr_change);
3350139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3351f8829a4aSRandall Stewart 
3352f8829a4aSRandall Stewart 	/* append to socket */
3353f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
33547215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3355f8829a4aSRandall Stewart 	    m_notify);
3356f8829a4aSRandall Stewart 	if (control == NULL) {
3357f8829a4aSRandall Stewart 		/* no memory */
3358f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3359f8829a4aSRandall Stewart 		return;
3360f8829a4aSRandall Stewart 	}
3361139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3362139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3363f8829a4aSRandall Stewart 	/* not that we need this */
3364f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
33653ac76647SMichael Tuexen 	sctp_add_to_readq(stcb->sctp_ep, stcb, control,
3366cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1,
3367f9425b3aSMichael Tuexen 	    SCTP_READ_LOCK_HELD, so_locked);
3368f8829a4aSRandall Stewart }
3369f8829a4aSRandall Stewart 
3370f8829a4aSRandall Stewart static void
33711edc9dbaSMichael Tuexen sctp_notify_send_failed(struct sctp_tcb *stcb, uint8_t sent, uint32_t error,
337228397ac1SMichael Tuexen     struct sctp_tmit_chunk *chk, int so_locked)
3373f8829a4aSRandall Stewart {
3374830d754dSRandall Stewart 	struct mbuf *m_notify;
3375f8829a4aSRandall Stewart 	struct sctp_send_failed *ssf;
33769935403aSMichael Tuexen 	struct sctp_send_failed_event *ssfe;
3377f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3378ab337314SMichael Tuexen 	struct sctp_chunkhdr *chkhdr;
3379ab337314SMichael Tuexen 	int notifhdr_len, chk_len, chkhdr_len, padding_len, payload_len;
3380f8829a4aSRandall Stewart 
3381f9425b3aSMichael Tuexen 	KASSERT(stcb != NULL, ("stcb == NULL"));
3382f9425b3aSMichael Tuexen 	SCTP_TCB_LOCK_ASSERT(stcb);
3383f9425b3aSMichael Tuexen 	SCTP_INP_READ_LOCK_ASSERT(stcb->sctp_ep);
3384f9425b3aSMichael Tuexen 
3385f9425b3aSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVSENDFAILEVNT) &&
3386f9425b3aSMichael Tuexen 	    sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVNSENDFAILEVNT)) {
3387f8829a4aSRandall Stewart 		/* event not enabled */
3388f8829a4aSRandall Stewart 		return;
3389830d754dSRandall Stewart 	}
33900053ed28SMichael Tuexen 
33919935403aSMichael Tuexen 	if (sctp_stcb_is_feature_on(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVNSENDFAILEVNT)) {
3392ab337314SMichael Tuexen 		notifhdr_len = sizeof(struct sctp_send_failed_event);
33939935403aSMichael Tuexen 	} else {
3394ab337314SMichael Tuexen 		notifhdr_len = sizeof(struct sctp_send_failed);
33959935403aSMichael Tuexen 	}
3396ab337314SMichael Tuexen 	m_notify = sctp_get_mbuf_for_msg(notifhdr_len, 0, M_NOWAIT, 1, MT_DATA);
3397f8829a4aSRandall Stewart 	if (m_notify == NULL)
3398f8829a4aSRandall Stewart 		/* no space left */
3399f8829a4aSRandall Stewart 		return;
3400ab337314SMichael Tuexen 	SCTP_BUF_LEN(m_notify) = notifhdr_len;
3401ab337314SMichael Tuexen 	if (stcb->asoc.idata_supported) {
3402ab337314SMichael Tuexen 		chkhdr_len = sizeof(struct sctp_idata_chunk);
3403ab337314SMichael Tuexen 	} else {
3404ab337314SMichael Tuexen 		chkhdr_len = sizeof(struct sctp_data_chunk);
3405ab337314SMichael Tuexen 	}
3406ab337314SMichael Tuexen 	/* Use some defaults in case we can't access the chunk header */
3407ab337314SMichael Tuexen 	if (chk->send_size >= chkhdr_len) {
3408ab337314SMichael Tuexen 		payload_len = chk->send_size - chkhdr_len;
3409ab337314SMichael Tuexen 	} else {
3410ab337314SMichael Tuexen 		payload_len = 0;
3411ab337314SMichael Tuexen 	}
3412ab337314SMichael Tuexen 	padding_len = 0;
3413ab337314SMichael Tuexen 	if (chk->data != NULL) {
3414ab337314SMichael Tuexen 		chkhdr = mtod(chk->data, struct sctp_chunkhdr *);
3415ab337314SMichael Tuexen 		if (chkhdr != NULL) {
3416ab337314SMichael Tuexen 			chk_len = ntohs(chkhdr->chunk_length);
3417ab337314SMichael Tuexen 			if ((chk_len >= chkhdr_len) &&
3418ab337314SMichael Tuexen 			    (chk->send_size >= chk_len) &&
3419ab337314SMichael Tuexen 			    (chk->send_size - chk_len < 4)) {
3420ab337314SMichael Tuexen 				padding_len = chk->send_size - chk_len;
3421ab337314SMichael Tuexen 				payload_len = chk->send_size - chkhdr_len - padding_len;
3422ab337314SMichael Tuexen 			}
3423ab337314SMichael Tuexen 		}
3424ab337314SMichael Tuexen 	}
34259935403aSMichael Tuexen 	if (sctp_stcb_is_feature_on(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVNSENDFAILEVNT)) {
34269935403aSMichael Tuexen 		ssfe = mtod(m_notify, struct sctp_send_failed_event *);
3427ab337314SMichael Tuexen 		memset(ssfe, 0, notifhdr_len);
34289935403aSMichael Tuexen 		ssfe->ssfe_type = SCTP_SEND_FAILED_EVENT;
34291edc9dbaSMichael Tuexen 		if (sent) {
34309935403aSMichael Tuexen 			ssfe->ssfe_flags = SCTP_DATA_SENT;
34311edc9dbaSMichael Tuexen 		} else {
34321edc9dbaSMichael Tuexen 			ssfe->ssfe_flags = SCTP_DATA_UNSENT;
34331edc9dbaSMichael Tuexen 		}
3434ab337314SMichael Tuexen 		ssfe->ssfe_length = (uint32_t)(notifhdr_len + payload_len);
34359935403aSMichael Tuexen 		ssfe->ssfe_error = error;
34369935403aSMichael Tuexen 		/* not exactly what the user sent in, but should be close :) */
343749656eefSMichael Tuexen 		ssfe->ssfe_info.snd_sid = chk->rec.data.sid;
34389935403aSMichael Tuexen 		ssfe->ssfe_info.snd_flags = chk->rec.data.rcv_flags;
343949656eefSMichael Tuexen 		ssfe->ssfe_info.snd_ppid = chk->rec.data.ppid;
34409935403aSMichael Tuexen 		ssfe->ssfe_info.snd_context = chk->rec.data.context;
34419935403aSMichael Tuexen 		ssfe->ssfe_info.snd_assoc_id = sctp_get_associd(stcb);
34429935403aSMichael Tuexen 		ssfe->ssfe_assoc_id = sctp_get_associd(stcb);
34439935403aSMichael Tuexen 	} else {
3444f8829a4aSRandall Stewart 		ssf = mtod(m_notify, struct sctp_send_failed *);
3445ab337314SMichael Tuexen 		memset(ssf, 0, notifhdr_len);
3446f8829a4aSRandall Stewart 		ssf->ssf_type = SCTP_SEND_FAILED;
34471edc9dbaSMichael Tuexen 		if (sent) {
3448f8829a4aSRandall Stewart 			ssf->ssf_flags = SCTP_DATA_SENT;
34491edc9dbaSMichael Tuexen 		} else {
34501edc9dbaSMichael Tuexen 			ssf->ssf_flags = SCTP_DATA_UNSENT;
34511edc9dbaSMichael Tuexen 		}
3452ab337314SMichael Tuexen 		ssf->ssf_length = (uint32_t)(notifhdr_len + payload_len);
3453f8829a4aSRandall Stewart 		ssf->ssf_error = error;
3454f8829a4aSRandall Stewart 		/* not exactly what the user sent in, but should be close :) */
345549656eefSMichael Tuexen 		ssf->ssf_info.sinfo_stream = chk->rec.data.sid;
345649656eefSMichael Tuexen 		ssf->ssf_info.sinfo_ssn = (uint16_t)chk->rec.data.mid;
3457f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_flags = chk->rec.data.rcv_flags;
345849656eefSMichael Tuexen 		ssf->ssf_info.sinfo_ppid = chk->rec.data.ppid;
3459f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_context = chk->rec.data.context;
3460f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_assoc_id = sctp_get_associd(stcb);
3461f8829a4aSRandall Stewart 		ssf->ssf_assoc_id = sctp_get_associd(stcb);
34629935403aSMichael Tuexen 	}
3463ab337314SMichael Tuexen 	if (chk->data != NULL) {
3464ab337314SMichael Tuexen 		/* Trim off the sctp chunk header (it should be there) */
3465ab337314SMichael Tuexen 		if (chk->send_size == chkhdr_len + payload_len + padding_len) {
3466ab337314SMichael Tuexen 			m_adj(chk->data, chkhdr_len);
3467ab337314SMichael Tuexen 			m_adj(chk->data, -padding_len);
3468830d754dSRandall Stewart 			sctp_mbuf_crush(chk->data);
3469ab337314SMichael Tuexen 			chk->send_size -= (chkhdr_len + padding_len);
3470830d754dSRandall Stewart 		}
3471830d754dSRandall Stewart 	}
3472810ec536SMichael Tuexen 	SCTP_BUF_NEXT(m_notify) = chk->data;
3473f8829a4aSRandall Stewart 	/* Steal off the mbuf */
3474f8829a4aSRandall Stewart 	chk->data = NULL;
3475f8829a4aSRandall Stewart 	/*
3476f8829a4aSRandall Stewart 	 * For this case, we check the actual socket buffer, since the assoc
3477f8829a4aSRandall Stewart 	 * is going away we don't want to overfill the socket buffer for a
3478f8829a4aSRandall Stewart 	 * non-reader
3479f8829a4aSRandall Stewart 	 */
3480139bc87fSRandall Stewart 	if (sctp_sbspace_failedmsgs(&stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3481f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3482f8829a4aSRandall Stewart 		return;
3483f8829a4aSRandall Stewart 	}
3484f8829a4aSRandall Stewart 	/* append to socket */
3485f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
34867215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3487f8829a4aSRandall Stewart 	    m_notify);
3488f8829a4aSRandall Stewart 	if (control == NULL) {
3489f8829a4aSRandall Stewart 		/* no memory */
3490f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3491f8829a4aSRandall Stewart 		return;
3492f8829a4aSRandall Stewart 	}
349328cd0699SMichael Tuexen 	control->length = SCTP_BUF_LEN(m_notify);
3494139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
349528cd0699SMichael Tuexen 	/* not that we need this */
349628cd0699SMichael Tuexen 	control->tail_mbuf = m_notify;
34973ac76647SMichael Tuexen 	sctp_add_to_readq(stcb->sctp_ep, stcb, control,
3498cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1,
3499f9425b3aSMichael Tuexen 	    SCTP_READ_LOCK_HELD, so_locked);
3500f8829a4aSRandall Stewart }
3501f8829a4aSRandall Stewart 
3502f8829a4aSRandall Stewart static void
3503f8829a4aSRandall Stewart sctp_notify_send_failed2(struct sctp_tcb *stcb, uint32_t error,
350428397ac1SMichael Tuexen     struct sctp_stream_queue_pending *sp, int so_locked)
3505f8829a4aSRandall Stewart {
3506f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3507f8829a4aSRandall Stewart 	struct sctp_send_failed *ssf;
35089935403aSMichael Tuexen 	struct sctp_send_failed_event *ssfe;
3509f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3510ab337314SMichael Tuexen 	int notifhdr_len;
3511f8829a4aSRandall Stewart 
3512f9425b3aSMichael Tuexen 	KASSERT(stcb != NULL, ("stcb == NULL"));
3513f9425b3aSMichael Tuexen 	SCTP_TCB_LOCK_ASSERT(stcb);
3514f9425b3aSMichael Tuexen 	SCTP_INP_READ_LOCK_ASSERT(stcb->sctp_ep);
3515f9425b3aSMichael Tuexen 
3516f9425b3aSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVSENDFAILEVNT) &&
3517f9425b3aSMichael Tuexen 	    sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVNSENDFAILEVNT)) {
3518f8829a4aSRandall Stewart 		/* event not enabled */
3519f8829a4aSRandall Stewart 		return;
3520830d754dSRandall Stewart 	}
3521f9425b3aSMichael Tuexen 
35229935403aSMichael Tuexen 	if (sctp_stcb_is_feature_on(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVNSENDFAILEVNT)) {
3523ab337314SMichael Tuexen 		notifhdr_len = sizeof(struct sctp_send_failed_event);
35249935403aSMichael Tuexen 	} else {
3525ab337314SMichael Tuexen 		notifhdr_len = sizeof(struct sctp_send_failed);
35269935403aSMichael Tuexen 	}
3527ab337314SMichael Tuexen 	m_notify = sctp_get_mbuf_for_msg(notifhdr_len, 0, M_NOWAIT, 1, MT_DATA);
35289935403aSMichael Tuexen 	if (m_notify == NULL) {
3529f8829a4aSRandall Stewart 		/* no space left */
3530f8829a4aSRandall Stewart 		return;
35319935403aSMichael Tuexen 	}
3532ab337314SMichael Tuexen 	SCTP_BUF_LEN(m_notify) = notifhdr_len;
35339935403aSMichael Tuexen 	if (sctp_stcb_is_feature_on(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVNSENDFAILEVNT)) {
35349935403aSMichael Tuexen 		ssfe = mtod(m_notify, struct sctp_send_failed_event *);
3535ab337314SMichael Tuexen 		memset(ssfe, 0, notifhdr_len);
3536ad83c8a5SMichael Tuexen 		ssfe->ssfe_type = SCTP_SEND_FAILED_EVENT;
35379935403aSMichael Tuexen 		ssfe->ssfe_flags = SCTP_DATA_UNSENT;
3538ab337314SMichael Tuexen 		ssfe->ssfe_length = (uint32_t)(notifhdr_len + sp->length);
35399935403aSMichael Tuexen 		ssfe->ssfe_error = error;
35409935403aSMichael Tuexen 		/* not exactly what the user sent in, but should be close :) */
354149656eefSMichael Tuexen 		ssfe->ssfe_info.snd_sid = sp->sid;
35429935403aSMichael Tuexen 		if (sp->some_taken) {
35439935403aSMichael Tuexen 			ssfe->ssfe_info.snd_flags = SCTP_DATA_LAST_FRAG;
35449935403aSMichael Tuexen 		} else {
35459935403aSMichael Tuexen 			ssfe->ssfe_info.snd_flags = SCTP_DATA_NOT_FRAG;
35469935403aSMichael Tuexen 		}
35479935403aSMichael Tuexen 		ssfe->ssfe_info.snd_ppid = sp->ppid;
35489935403aSMichael Tuexen 		ssfe->ssfe_info.snd_context = sp->context;
35499935403aSMichael Tuexen 		ssfe->ssfe_info.snd_assoc_id = sctp_get_associd(stcb);
35509935403aSMichael Tuexen 		ssfe->ssfe_assoc_id = sctp_get_associd(stcb);
35519935403aSMichael Tuexen 	} else {
3552f8829a4aSRandall Stewart 		ssf = mtod(m_notify, struct sctp_send_failed *);
3553ab337314SMichael Tuexen 		memset(ssf, 0, notifhdr_len);
3554f8829a4aSRandall Stewart 		ssf->ssf_type = SCTP_SEND_FAILED;
3555f8829a4aSRandall Stewart 		ssf->ssf_flags = SCTP_DATA_UNSENT;
3556ab337314SMichael Tuexen 		ssf->ssf_length = (uint32_t)(notifhdr_len + sp->length);
3557f8829a4aSRandall Stewart 		ssf->ssf_error = error;
3558f8829a4aSRandall Stewart 		/* not exactly what the user sent in, but should be close :) */
355949656eefSMichael Tuexen 		ssf->ssf_info.sinfo_stream = sp->sid;
3560f3b05218SMichael Tuexen 		ssf->ssf_info.sinfo_ssn = 0;
3561fc14de76SRandall Stewart 		if (sp->some_taken) {
3562fc14de76SRandall Stewart 			ssf->ssf_info.sinfo_flags = SCTP_DATA_LAST_FRAG;
3563fc14de76SRandall Stewart 		} else {
3564fc14de76SRandall Stewart 			ssf->ssf_info.sinfo_flags = SCTP_DATA_NOT_FRAG;
3565fc14de76SRandall Stewart 		}
3566f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_ppid = sp->ppid;
3567f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_context = sp->context;
3568f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_assoc_id = sctp_get_associd(stcb);
3569f8829a4aSRandall Stewart 		ssf->ssf_assoc_id = sctp_get_associd(stcb);
35709935403aSMichael Tuexen 	}
35719935403aSMichael Tuexen 	SCTP_BUF_NEXT(m_notify) = sp->data;
3572f8829a4aSRandall Stewart 
3573f8829a4aSRandall Stewart 	/* Steal off the mbuf */
3574f8829a4aSRandall Stewart 	sp->data = NULL;
3575f8829a4aSRandall Stewart 	/*
3576f8829a4aSRandall Stewart 	 * For this case, we check the actual socket buffer, since the assoc
3577f8829a4aSRandall Stewart 	 * is going away we don't want to overfill the socket buffer for a
3578f8829a4aSRandall Stewart 	 * non-reader
3579f8829a4aSRandall Stewart 	 */
3580139bc87fSRandall Stewart 	if (sctp_sbspace_failedmsgs(&stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3581f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3582f8829a4aSRandall Stewart 		return;
3583f8829a4aSRandall Stewart 	}
3584f8829a4aSRandall Stewart 	/* append to socket */
3585f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
35867215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3587f8829a4aSRandall Stewart 	    m_notify);
3588f8829a4aSRandall Stewart 	if (control == NULL) {
3589f8829a4aSRandall Stewart 		/* no memory */
3590f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3591f8829a4aSRandall Stewart 		return;
3592f8829a4aSRandall Stewart 	}
359328cd0699SMichael Tuexen 	control->length = SCTP_BUF_LEN(m_notify);
3594139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
359528cd0699SMichael Tuexen 	/* not that we need this */
359628cd0699SMichael Tuexen 	control->tail_mbuf = m_notify;
35973ac76647SMichael Tuexen 	sctp_add_to_readq(stcb->sctp_ep, stcb, control,
35983ac76647SMichael Tuexen 	    &stcb->sctp_socket->so_rcv, 1,
3599f9425b3aSMichael Tuexen 	    SCTP_READ_LOCK_HELD, so_locked);
3600f8829a4aSRandall Stewart }
3601f8829a4aSRandall Stewart 
3602f8829a4aSRandall Stewart static void
36033ac76647SMichael Tuexen sctp_notify_adaptation_layer(struct sctp_tcb *stcb, int so_locked)
3604f8829a4aSRandall Stewart {
3605f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3606f8829a4aSRandall Stewart 	struct sctp_adaptation_event *sai;
3607f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3608f8829a4aSRandall Stewart 
3609f9425b3aSMichael Tuexen 	KASSERT(stcb != NULL, ("stcb == NULL"));
3610f9425b3aSMichael Tuexen 	SCTP_TCB_LOCK_ASSERT(stcb);
3611f9425b3aSMichael Tuexen 	SCTP_INP_READ_LOCK_ASSERT(stcb->sctp_ep);
3612f9425b3aSMichael Tuexen 
3613f9425b3aSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_ADAPTATIONEVNT)) {
3614f8829a4aSRandall Stewart 		/* event not enabled */
3615f8829a4aSRandall Stewart 		return;
3616830d754dSRandall Stewart 	}
36170053ed28SMichael Tuexen 
3618eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_adaption_event), 0, M_NOWAIT, 1, MT_DATA);
3619f8829a4aSRandall Stewart 	if (m_notify == NULL)
3620f8829a4aSRandall Stewart 		/* no space left */
3621f8829a4aSRandall Stewart 		return;
3622139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3623f8829a4aSRandall Stewart 	sai = mtod(m_notify, struct sctp_adaptation_event *);
3624e432298aSXin LI 	memset(sai, 0, sizeof(struct sctp_adaptation_event));
3625f8829a4aSRandall Stewart 	sai->sai_type = SCTP_ADAPTATION_INDICATION;
3626f8829a4aSRandall Stewart 	sai->sai_flags = 0;
3627f8829a4aSRandall Stewart 	sai->sai_length = sizeof(struct sctp_adaptation_event);
36282afb3e84SRandall Stewart 	sai->sai_adaptation_ind = stcb->asoc.peers_adaptation;
3629f8829a4aSRandall Stewart 	sai->sai_assoc_id = sctp_get_associd(stcb);
3630f8829a4aSRandall Stewart 
3631139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_adaptation_event);
3632139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3633f8829a4aSRandall Stewart 
3634f8829a4aSRandall Stewart 	/* append to socket */
3635f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
36367215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3637f8829a4aSRandall Stewart 	    m_notify);
3638f8829a4aSRandall Stewart 	if (control == NULL) {
3639f8829a4aSRandall Stewart 		/* no memory */
3640f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3641f8829a4aSRandall Stewart 		return;
3642f8829a4aSRandall Stewart 	}
3643139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3644139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3645f8829a4aSRandall Stewart 	/* not that we need this */
3646f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
36473ac76647SMichael Tuexen 	sctp_add_to_readq(stcb->sctp_ep, stcb, control,
36483ac76647SMichael Tuexen 	    &stcb->sctp_socket->so_rcv, 1,
3649f9425b3aSMichael Tuexen 	    SCTP_READ_LOCK_HELD, so_locked);
3650f8829a4aSRandall Stewart }
3651f8829a4aSRandall Stewart 
3652810ec536SMichael Tuexen static void
36532dad8a55SRandall Stewart sctp_notify_partial_delivery_indication(struct sctp_tcb *stcb, uint32_t error,
3654749a7fb5SMichael Tuexen     struct sctp_queued_to_read *aborted_control,
3655749a7fb5SMichael Tuexen     int so_locked)
3656f8829a4aSRandall Stewart {
3657f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3658f8829a4aSRandall Stewart 	struct sctp_pdapi_event *pdapi;
3659f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
366003b0b021SRandall Stewart 	struct sockbuf *sb;
3661f8829a4aSRandall Stewart 
3662f9425b3aSMichael Tuexen 	KASSERT(aborted_control != NULL, ("aborted_control is NULL"));
3663f9425b3aSMichael Tuexen 	KASSERT(stcb != NULL, ("stcb == NULL"));
3664f9425b3aSMichael Tuexen 	SCTP_TCB_LOCK_ASSERT(stcb);
3665f9425b3aSMichael Tuexen 	SCTP_INP_READ_LOCK_ASSERT(stcb->sctp_ep);
3666f9425b3aSMichael Tuexen 
3667f9425b3aSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_PDAPIEVNT)) {
3668f8829a4aSRandall Stewart 		/* event not enabled */
3669f8829a4aSRandall Stewart 		return;
3670830d754dSRandall Stewart 	}
36710053ed28SMichael Tuexen 
3672eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_pdapi_event), 0, M_NOWAIT, 1, MT_DATA);
3673f8829a4aSRandall Stewart 	if (m_notify == NULL)
3674f8829a4aSRandall Stewart 		/* no space left */
3675f8829a4aSRandall Stewart 		return;
3676139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3677f8829a4aSRandall Stewart 	pdapi = mtod(m_notify, struct sctp_pdapi_event *);
3678e432298aSXin LI 	memset(pdapi, 0, sizeof(struct sctp_pdapi_event));
3679f8829a4aSRandall Stewart 	pdapi->pdapi_type = SCTP_PARTIAL_DELIVERY_EVENT;
3680f8829a4aSRandall Stewart 	pdapi->pdapi_flags = 0;
3681f8829a4aSRandall Stewart 	pdapi->pdapi_length = sizeof(struct sctp_pdapi_event);
3682f8829a4aSRandall Stewart 	pdapi->pdapi_indication = error;
3683749a7fb5SMichael Tuexen 	pdapi->pdapi_stream = aborted_control->sinfo_stream;
3684749a7fb5SMichael Tuexen 	pdapi->pdapi_seq = (uint16_t)aborted_control->mid;
3685f8829a4aSRandall Stewart 	pdapi->pdapi_assoc_id = sctp_get_associd(stcb);
3686f8829a4aSRandall Stewart 
3687139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_pdapi_event);
3688139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3689f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
36907215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3691f8829a4aSRandall Stewart 	    m_notify);
3692f8829a4aSRandall Stewart 	if (control == NULL) {
3693f8829a4aSRandall Stewart 		/* no memory */
3694f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3695f8829a4aSRandall Stewart 		return;
3696f8829a4aSRandall Stewart 	}
3697139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
369828cd0699SMichael Tuexen 	control->spec_flags = M_NOTIFICATION;
3699f8829a4aSRandall Stewart 	/* not that we need this */
3700f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
370103b0b021SRandall Stewart 	sb = &stcb->sctp_socket->so_rcv;
3702b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
3703139bc87fSRandall Stewart 		sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m_notify));
370480fefe0aSRandall Stewart 	}
370503b0b021SRandall Stewart 	sctp_sballoc(stcb, sb, m_notify);
3706b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
370703b0b021SRandall Stewart 		sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
370880fefe0aSRandall Stewart 	}
370903b0b021SRandall Stewart 	control->end_added = 1;
3710749a7fb5SMichael Tuexen 	TAILQ_INSERT_AFTER(&stcb->sctp_ep->read_queue, aborted_control, control, next);
371103b0b021SRandall Stewart 	if (stcb->sctp_ep && stcb->sctp_socket) {
371203b0b021SRandall Stewart 		/* This should always be the case */
371303b0b021SRandall Stewart 		sctp_sorwakeup(stcb->sctp_ep, stcb->sctp_socket);
3714f8829a4aSRandall Stewart 	}
3715f8829a4aSRandall Stewart }
3716f8829a4aSRandall Stewart 
3717f8829a4aSRandall Stewart static void
37183ac76647SMichael Tuexen sctp_notify_shutdown_event(struct sctp_tcb *stcb, int so_locked)
3719f8829a4aSRandall Stewart {
3720f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3721f8829a4aSRandall Stewart 	struct sctp_shutdown_event *sse;
3722f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3723f8829a4aSRandall Stewart 
3724f9425b3aSMichael Tuexen 	KASSERT(stcb != NULL, ("stcb == NULL"));
3725f9425b3aSMichael Tuexen 	SCTP_TCB_LOCK_ASSERT(stcb);
3726f9425b3aSMichael Tuexen 	SCTP_INP_READ_LOCK_ASSERT(stcb->sctp_ep);
3727f9425b3aSMichael Tuexen 
3728f8829a4aSRandall Stewart 	/*
3729f8829a4aSRandall Stewart 	 * For TCP model AND UDP connected sockets we will send an error up
3730f8829a4aSRandall Stewart 	 * when an SHUTDOWN completes
3731f8829a4aSRandall Stewart 	 */
3732f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
3733f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
3734f8829a4aSRandall Stewart 		/* mark socket closed for read/write and wakeup! */
3735f8829a4aSRandall Stewart 		socantsendmore(stcb->sctp_socket);
3736f8829a4aSRandall Stewart 	}
3737f9425b3aSMichael Tuexen 
3738e2e7c62eSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVSHUTDOWNEVNT)) {
3739f8829a4aSRandall Stewart 		/* event not enabled */
3740f8829a4aSRandall Stewart 		return;
3741830d754dSRandall Stewart 	}
37420053ed28SMichael Tuexen 
3743eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_shutdown_event), 0, M_NOWAIT, 1, MT_DATA);
3744f8829a4aSRandall Stewart 	if (m_notify == NULL)
3745f8829a4aSRandall Stewart 		/* no space left */
3746f8829a4aSRandall Stewart 		return;
3747f8829a4aSRandall Stewart 	sse = mtod(m_notify, struct sctp_shutdown_event *);
3748e432298aSXin LI 	memset(sse, 0, sizeof(struct sctp_shutdown_event));
3749f8829a4aSRandall Stewart 	sse->sse_type = SCTP_SHUTDOWN_EVENT;
3750f8829a4aSRandall Stewart 	sse->sse_flags = 0;
3751f8829a4aSRandall Stewart 	sse->sse_length = sizeof(struct sctp_shutdown_event);
3752f8829a4aSRandall Stewart 	sse->sse_assoc_id = sctp_get_associd(stcb);
3753f8829a4aSRandall Stewart 
3754139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_shutdown_event);
3755139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3756f8829a4aSRandall Stewart 
3757f8829a4aSRandall Stewart 	/* append to socket */
3758f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
37597215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3760f8829a4aSRandall Stewart 	    m_notify);
3761f8829a4aSRandall Stewart 	if (control == NULL) {
3762f8829a4aSRandall Stewart 		/* no memory */
3763f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3764f8829a4aSRandall Stewart 		return;
3765f8829a4aSRandall Stewart 	}
3766139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
376728cd0699SMichael Tuexen 	control->spec_flags = M_NOTIFICATION;
3768f8829a4aSRandall Stewart 	/* not that we need this */
3769f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
37703ac76647SMichael Tuexen 	sctp_add_to_readq(stcb->sctp_ep, stcb, control,
37713ac76647SMichael Tuexen 	    &stcb->sctp_socket->so_rcv, 1,
3772f9425b3aSMichael Tuexen 	    SCTP_READ_LOCK_HELD, so_locked);
3773f8829a4aSRandall Stewart }
3774f8829a4aSRandall Stewart 
3775f8829a4aSRandall Stewart static void
37763ac76647SMichael Tuexen sctp_notify_sender_dry_event(struct sctp_tcb *stcb, int so_locked)
3777830d754dSRandall Stewart {
3778830d754dSRandall Stewart 	struct mbuf *m_notify;
3779830d754dSRandall Stewart 	struct sctp_sender_dry_event *event;
3780830d754dSRandall Stewart 	struct sctp_queued_to_read *control;
3781830d754dSRandall Stewart 
3782f9425b3aSMichael Tuexen 	KASSERT(stcb != NULL, ("stcb == NULL"));
3783f9425b3aSMichael Tuexen 	SCTP_TCB_LOCK_ASSERT(stcb);
3784f9425b3aSMichael Tuexen 	SCTP_INP_READ_LOCK_ASSERT(stcb->sctp_ep);
3785f9425b3aSMichael Tuexen 
3786f9425b3aSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_DRYEVNT)) {
3787830d754dSRandall Stewart 		/* event not enabled */
3788830d754dSRandall Stewart 		return;
3789830d754dSRandall Stewart 	}
37900053ed28SMichael Tuexen 
3791eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_sender_dry_event), 0, M_NOWAIT, 1, MT_DATA);
3792830d754dSRandall Stewart 	if (m_notify == NULL) {
3793830d754dSRandall Stewart 		/* no space left */
3794830d754dSRandall Stewart 		return;
3795830d754dSRandall Stewart 	}
3796830d754dSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3797830d754dSRandall Stewart 	event = mtod(m_notify, struct sctp_sender_dry_event *);
3798e432298aSXin LI 	memset(event, 0, sizeof(struct sctp_sender_dry_event));
3799830d754dSRandall Stewart 	event->sender_dry_type = SCTP_SENDER_DRY_EVENT;
3800830d754dSRandall Stewart 	event->sender_dry_flags = 0;
3801830d754dSRandall Stewart 	event->sender_dry_length = sizeof(struct sctp_sender_dry_event);
3802830d754dSRandall Stewart 	event->sender_dry_assoc_id = sctp_get_associd(stcb);
3803830d754dSRandall Stewart 
3804830d754dSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_sender_dry_event);
3805830d754dSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3806830d754dSRandall Stewart 
3807830d754dSRandall Stewart 	/* append to socket */
3808830d754dSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
38097215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
38107215cc1bSMichael Tuexen 	    m_notify);
3811830d754dSRandall Stewart 	if (control == NULL) {
3812830d754dSRandall Stewart 		/* no memory */
3813830d754dSRandall Stewart 		sctp_m_freem(m_notify);
3814830d754dSRandall Stewart 		return;
3815830d754dSRandall Stewart 	}
3816830d754dSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3817830d754dSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3818830d754dSRandall Stewart 	/* not that we need this */
3819830d754dSRandall Stewart 	control->tail_mbuf = m_notify;
3820830d754dSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb, control,
38213ac76647SMichael Tuexen 	    &stcb->sctp_socket->so_rcv, 1,
3822f9425b3aSMichael Tuexen 	    SCTP_READ_LOCK_HELD, so_locked);
3823830d754dSRandall Stewart }
3824830d754dSRandall Stewart 
38253ac76647SMichael Tuexen static void
38263ac76647SMichael Tuexen sctp_notify_stream_reset_add(struct sctp_tcb *stcb, int flag, int so_locked)
3827ea44232bSRandall Stewart {
3828ea44232bSRandall Stewart 	struct mbuf *m_notify;
3829ea44232bSRandall Stewart 	struct sctp_queued_to_read *control;
3830c4e848b7SRandall Stewart 	struct sctp_stream_change_event *stradd;
3831ea44232bSRandall Stewart 
3832f9425b3aSMichael Tuexen 	KASSERT(stcb != NULL, ("stcb == NULL"));
3833f9425b3aSMichael Tuexen 	SCTP_TCB_LOCK_ASSERT(stcb);
3834f9425b3aSMichael Tuexen 	SCTP_INP_READ_LOCK_ASSERT(stcb->sctp_ep);
3835f9425b3aSMichael Tuexen 
38367b2f1a7fSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_STREAM_CHANGEEVNT)) {
3837ea44232bSRandall Stewart 		/* event not enabled */
3838ea44232bSRandall Stewart 		return;
3839ea44232bSRandall Stewart 	}
38407b2f1a7fSMichael Tuexen 
3841c4e848b7SRandall Stewart 	if ((stcb->asoc.peer_req_out) && flag) {
3842c4e848b7SRandall Stewart 		/* Peer made the request, don't tell the local user */
3843c4e848b7SRandall Stewart 		stcb->asoc.peer_req_out = 0;
3844c4e848b7SRandall Stewart 		return;
3845c4e848b7SRandall Stewart 	}
3846c4e848b7SRandall Stewart 	stcb->asoc.peer_req_out = 0;
3847e432298aSXin LI 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_stream_change_event), 0, M_NOWAIT, 1, MT_DATA);
3848ea44232bSRandall Stewart 	if (m_notify == NULL)
3849ea44232bSRandall Stewart 		/* no space left */
3850ea44232bSRandall Stewart 		return;
3851ea44232bSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3852c4e848b7SRandall Stewart 	stradd = mtod(m_notify, struct sctp_stream_change_event *);
3853e432298aSXin LI 	memset(stradd, 0, sizeof(struct sctp_stream_change_event));
3854c4e848b7SRandall Stewart 	stradd->strchange_type = SCTP_STREAM_CHANGE_EVENT;
3855c4e848b7SRandall Stewart 	stradd->strchange_flags = flag;
3856e432298aSXin LI 	stradd->strchange_length = sizeof(struct sctp_stream_change_event);
3857c4e848b7SRandall Stewart 	stradd->strchange_assoc_id = sctp_get_associd(stcb);
38583ac76647SMichael Tuexen 	stradd->strchange_instrms = stcb->asoc.streamincnt;
38593ac76647SMichael Tuexen 	stradd->strchange_outstrms = stcb->asoc.streamoutcnt;
3860e432298aSXin LI 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_stream_change_event);
3861ea44232bSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3862ea44232bSRandall Stewart 	if (sctp_sbspace(&stcb->asoc, &stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3863ea44232bSRandall Stewart 		/* no space */
3864ea44232bSRandall Stewart 		sctp_m_freem(m_notify);
3865ea44232bSRandall Stewart 		return;
3866ea44232bSRandall Stewart 	}
3867ea44232bSRandall Stewart 	/* append to socket */
3868ea44232bSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
38697215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3870ea44232bSRandall Stewart 	    m_notify);
3871ea44232bSRandall Stewart 	if (control == NULL) {
3872ea44232bSRandall Stewart 		/* no memory */
3873ea44232bSRandall Stewart 		sctp_m_freem(m_notify);
3874ea44232bSRandall Stewart 		return;
3875ea44232bSRandall Stewart 	}
3876ea44232bSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
387728cd0699SMichael Tuexen 	control->spec_flags = M_NOTIFICATION;
3878ea44232bSRandall Stewart 	/* not that we need this */
3879ea44232bSRandall Stewart 	control->tail_mbuf = m_notify;
38803ac76647SMichael Tuexen 	sctp_add_to_readq(stcb->sctp_ep, stcb, control,
38813ac76647SMichael Tuexen 	    &stcb->sctp_socket->so_rcv, 1,
3882f9425b3aSMichael Tuexen 	    SCTP_READ_LOCK_HELD, so_locked);
3883ea44232bSRandall Stewart }
3884ea44232bSRandall Stewart 
38853ac76647SMichael Tuexen static void
38863ac76647SMichael Tuexen sctp_notify_stream_reset_tsn(struct sctp_tcb *stcb, int flag, int so_locked)
3887c4e848b7SRandall Stewart {
3888c4e848b7SRandall Stewart 	struct mbuf *m_notify;
3889c4e848b7SRandall Stewart 	struct sctp_queued_to_read *control;
3890c4e848b7SRandall Stewart 	struct sctp_assoc_reset_event *strasoc;
3891c4e848b7SRandall Stewart 
3892f9425b3aSMichael Tuexen 	KASSERT(stcb != NULL, ("stcb == NULL"));
3893f9425b3aSMichael Tuexen 	SCTP_TCB_LOCK_ASSERT(stcb);
3894f9425b3aSMichael Tuexen 	SCTP_INP_READ_LOCK_ASSERT(stcb->sctp_ep);
3895f9425b3aSMichael Tuexen 
38967b2f1a7fSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_ASSOC_RESETEVNT)) {
3897c4e848b7SRandall Stewart 		/* event not enabled */
3898c4e848b7SRandall Stewart 		return;
3899c4e848b7SRandall Stewart 	}
39007b2f1a7fSMichael Tuexen 
3901e432298aSXin LI 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_assoc_reset_event), 0, M_NOWAIT, 1, MT_DATA);
3902c4e848b7SRandall Stewart 	if (m_notify == NULL)
3903c4e848b7SRandall Stewart 		/* no space left */
3904c4e848b7SRandall Stewart 		return;
3905c4e848b7SRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3906c4e848b7SRandall Stewart 	strasoc = mtod(m_notify, struct sctp_assoc_reset_event *);
3907e432298aSXin LI 	memset(strasoc, 0, sizeof(struct sctp_assoc_reset_event));
3908c4e848b7SRandall Stewart 	strasoc->assocreset_type = SCTP_ASSOC_RESET_EVENT;
3909c4e848b7SRandall Stewart 	strasoc->assocreset_flags = flag;
3910e432298aSXin LI 	strasoc->assocreset_length = sizeof(struct sctp_assoc_reset_event);
3911c4e848b7SRandall Stewart 	strasoc->assocreset_assoc_id = sctp_get_associd(stcb);
39123ac76647SMichael Tuexen 	strasoc->assocreset_local_tsn = stcb->asoc.sending_seq;
39133ac76647SMichael Tuexen 	strasoc->assocreset_remote_tsn = stcb->asoc.mapping_array_base_tsn + 1;
3914e432298aSXin LI 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_assoc_reset_event);
3915c4e848b7SRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3916c4e848b7SRandall Stewart 	if (sctp_sbspace(&stcb->asoc, &stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3917c4e848b7SRandall Stewart 		/* no space */
3918c4e848b7SRandall Stewart 		sctp_m_freem(m_notify);
3919c4e848b7SRandall Stewart 		return;
3920c4e848b7SRandall Stewart 	}
3921c4e848b7SRandall Stewart 	/* append to socket */
3922c4e848b7SRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3923c4e848b7SRandall Stewart 	    0, 0, stcb->asoc.context, 0, 0, 0,
3924c4e848b7SRandall Stewart 	    m_notify);
3925c4e848b7SRandall Stewart 	if (control == NULL) {
3926c4e848b7SRandall Stewart 		/* no memory */
3927c4e848b7SRandall Stewart 		sctp_m_freem(m_notify);
3928c4e848b7SRandall Stewart 		return;
3929c4e848b7SRandall Stewart 	}
3930c4e848b7SRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
393128cd0699SMichael Tuexen 	control->spec_flags = M_NOTIFICATION;
3932c4e848b7SRandall Stewart 	/* not that we need this */
3933c4e848b7SRandall Stewart 	control->tail_mbuf = m_notify;
39343ac76647SMichael Tuexen 	sctp_add_to_readq(stcb->sctp_ep, stcb, control,
39353ac76647SMichael Tuexen 	    &stcb->sctp_socket->so_rcv, 1,
3936f9425b3aSMichael Tuexen 	    SCTP_READ_LOCK_HELD, so_locked);
3937c4e848b7SRandall Stewart }
3938c4e848b7SRandall Stewart 
3939830d754dSRandall Stewart static void
3940f8829a4aSRandall Stewart sctp_notify_stream_reset(struct sctp_tcb *stcb,
39413ac76647SMichael Tuexen     int number_entries, uint16_t *list, int flag, int so_locked)
3942f8829a4aSRandall Stewart {
3943f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3944f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3945f8829a4aSRandall Stewart 	struct sctp_stream_reset_event *strreset;
3946f8829a4aSRandall Stewart 	int len;
3947f8829a4aSRandall Stewart 
3948f9425b3aSMichael Tuexen 	KASSERT(stcb != NULL, ("stcb == NULL"));
3949f9425b3aSMichael Tuexen 	SCTP_TCB_LOCK_ASSERT(stcb);
3950f9425b3aSMichael Tuexen 	SCTP_INP_READ_LOCK_ASSERT(stcb->sctp_ep);
3951f9425b3aSMichael Tuexen 
3952f9425b3aSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_STREAM_RESETEVNT)) {
3953f8829a4aSRandall Stewart 		/* event not enabled */
3954f8829a4aSRandall Stewart 		return;
3955830d754dSRandall Stewart 	}
39560053ed28SMichael Tuexen 
3957eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(MCLBYTES, 0, M_NOWAIT, 1, MT_DATA);
3958f8829a4aSRandall Stewart 	if (m_notify == NULL)
3959f8829a4aSRandall Stewart 		/* no space left */
3960f8829a4aSRandall Stewart 		return;
3961139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3962f8829a4aSRandall Stewart 	len = sizeof(struct sctp_stream_reset_event) + (number_entries * sizeof(uint16_t));
3963f8829a4aSRandall Stewart 	if (len > M_TRAILINGSPACE(m_notify)) {
3964f8829a4aSRandall Stewart 		/* never enough room */
3965f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3966f8829a4aSRandall Stewart 		return;
3967f8829a4aSRandall Stewart 	}
3968f8829a4aSRandall Stewart 	strreset = mtod(m_notify, struct sctp_stream_reset_event *);
3969e432298aSXin LI 	memset(strreset, 0, len);
3970f8829a4aSRandall Stewart 	strreset->strreset_type = SCTP_STREAM_RESET_EVENT;
3971c4e848b7SRandall Stewart 	strreset->strreset_flags = flag;
3972f8829a4aSRandall Stewart 	strreset->strreset_length = len;
3973f8829a4aSRandall Stewart 	strreset->strreset_assoc_id = sctp_get_associd(stcb);
3974f8829a4aSRandall Stewart 	if (number_entries) {
3975f8829a4aSRandall Stewart 		int i;
3976f8829a4aSRandall Stewart 
3977f8829a4aSRandall Stewart 		for (i = 0; i < number_entries; i++) {
3978c4e848b7SRandall Stewart 			strreset->strreset_stream_list[i] = ntohs(list[i]);
3979f8829a4aSRandall Stewart 		}
3980f8829a4aSRandall Stewart 	}
3981139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = len;
3982139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3983139bc87fSRandall Stewart 	if (sctp_sbspace(&stcb->asoc, &stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3984f8829a4aSRandall Stewart 		/* no space */
3985f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3986f8829a4aSRandall Stewart 		return;
3987f8829a4aSRandall Stewart 	}
3988f8829a4aSRandall Stewart 	/* append to socket */
3989f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
39907215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3991f8829a4aSRandall Stewart 	    m_notify);
3992f8829a4aSRandall Stewart 	if (control == NULL) {
3993f8829a4aSRandall Stewart 		/* no memory */
3994f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3995f8829a4aSRandall Stewart 		return;
3996f8829a4aSRandall Stewart 	}
3997139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
399828cd0699SMichael Tuexen 	control->spec_flags = M_NOTIFICATION;
3999f8829a4aSRandall Stewart 	/* not that we need this */
4000f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
40013ac76647SMichael Tuexen 	sctp_add_to_readq(stcb->sctp_ep, stcb, control,
40023ac76647SMichael Tuexen 	    &stcb->sctp_socket->so_rcv, 1,
4003f9425b3aSMichael Tuexen 	    SCTP_READ_LOCK_HELD, so_locked);
4004f8829a4aSRandall Stewart }
4005f8829a4aSRandall Stewart 
4006389b1b11SMichael Tuexen static void
40073ac76647SMichael Tuexen sctp_notify_remote_error(struct sctp_tcb *stcb, uint16_t error,
40083ac76647SMichael Tuexen     struct sctp_error_chunk *chunk, int so_locked)
4009389b1b11SMichael Tuexen {
4010389b1b11SMichael Tuexen 	struct mbuf *m_notify;
4011389b1b11SMichael Tuexen 	struct sctp_remote_error *sre;
4012389b1b11SMichael Tuexen 	struct sctp_queued_to_read *control;
40139a8e3088SMichael Tuexen 	unsigned int notif_len;
40149a8e3088SMichael Tuexen 	uint16_t chunk_len;
4015389b1b11SMichael Tuexen 
4016f9425b3aSMichael Tuexen 	KASSERT(stcb != NULL, ("stcb == NULL"));
4017f9425b3aSMichael Tuexen 	SCTP_TCB_LOCK_ASSERT(stcb);
4018f9425b3aSMichael Tuexen 	SCTP_INP_READ_LOCK_ASSERT(stcb->sctp_ep);
4019f9425b3aSMichael Tuexen 
4020f9425b3aSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVPEERERR)) {
4021389b1b11SMichael Tuexen 		return;
4022389b1b11SMichael Tuexen 	}
4023f9425b3aSMichael Tuexen 
4024389b1b11SMichael Tuexen 	if (chunk != NULL) {
4025c9eb4473SMichael Tuexen 		chunk_len = ntohs(chunk->ch.chunk_length);
40269669e724SMichael Tuexen 		/*
40279669e724SMichael Tuexen 		 * Only SCTP_CHUNK_BUFFER_SIZE are guaranteed to be
402845d41de5SMichael Tuexen 		 * contiguous.
40299669e724SMichael Tuexen 		 */
40309669e724SMichael Tuexen 		if (chunk_len > SCTP_CHUNK_BUFFER_SIZE) {
40319669e724SMichael Tuexen 			chunk_len = SCTP_CHUNK_BUFFER_SIZE;
40329669e724SMichael Tuexen 		}
4033389b1b11SMichael Tuexen 	} else {
4034389b1b11SMichael Tuexen 		chunk_len = 0;
4035389b1b11SMichael Tuexen 	}
40369a8e3088SMichael Tuexen 	notif_len = (unsigned int)(sizeof(struct sctp_remote_error) + chunk_len);
4037eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(notif_len, 0, M_NOWAIT, 1, MT_DATA);
4038389b1b11SMichael Tuexen 	if (m_notify == NULL) {
4039389b1b11SMichael Tuexen 		/* Retry with smaller value. */
40409a8e3088SMichael Tuexen 		notif_len = (unsigned int)sizeof(struct sctp_remote_error);
4041eb1b1807SGleb Smirnoff 		m_notify = sctp_get_mbuf_for_msg(notif_len, 0, M_NOWAIT, 1, MT_DATA);
4042389b1b11SMichael Tuexen 		if (m_notify == NULL) {
4043389b1b11SMichael Tuexen 			return;
4044389b1b11SMichael Tuexen 		}
4045389b1b11SMichael Tuexen 	}
4046389b1b11SMichael Tuexen 	SCTP_BUF_NEXT(m_notify) = NULL;
4047389b1b11SMichael Tuexen 	sre = mtod(m_notify, struct sctp_remote_error *);
404856711f94SMichael Tuexen 	memset(sre, 0, notif_len);
4049389b1b11SMichael Tuexen 	sre->sre_type = SCTP_REMOTE_ERROR;
4050389b1b11SMichael Tuexen 	sre->sre_flags = 0;
4051389b1b11SMichael Tuexen 	sre->sre_length = sizeof(struct sctp_remote_error);
4052389b1b11SMichael Tuexen 	sre->sre_error = error;
4053389b1b11SMichael Tuexen 	sre->sre_assoc_id = sctp_get_associd(stcb);
4054389b1b11SMichael Tuexen 	if (notif_len > sizeof(struct sctp_remote_error)) {
4055389b1b11SMichael Tuexen 		memcpy(sre->sre_data, chunk, chunk_len);
4056389b1b11SMichael Tuexen 		sre->sre_length += chunk_len;
4057389b1b11SMichael Tuexen 	}
4058389b1b11SMichael Tuexen 	SCTP_BUF_LEN(m_notify) = sre->sre_length;
4059389b1b11SMichael Tuexen 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
4060389b1b11SMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
4061389b1b11SMichael Tuexen 	    m_notify);
4062389b1b11SMichael Tuexen 	if (control != NULL) {
4063389b1b11SMichael Tuexen 		control->length = SCTP_BUF_LEN(m_notify);
406428cd0699SMichael Tuexen 		control->spec_flags = M_NOTIFICATION;
4065389b1b11SMichael Tuexen 		/* not that we need this */
4066389b1b11SMichael Tuexen 		control->tail_mbuf = m_notify;
40673ac76647SMichael Tuexen 		sctp_add_to_readq(stcb->sctp_ep, stcb, control,
4068389b1b11SMichael Tuexen 		    &stcb->sctp_socket->so_rcv, 1,
4069f9425b3aSMichael Tuexen 		    SCTP_READ_LOCK_HELD, so_locked);
4070389b1b11SMichael Tuexen 	} else {
4071389b1b11SMichael Tuexen 		sctp_m_freem(m_notify);
4072389b1b11SMichael Tuexen 	}
4073389b1b11SMichael Tuexen }
4074389b1b11SMichael Tuexen 
4075f8829a4aSRandall Stewart void
4076f8829a4aSRandall Stewart sctp_ulp_notify(uint32_t notification, struct sctp_tcb *stcb,
407728397ac1SMichael Tuexen     uint32_t error, void *data, int so_locked)
4078f8829a4aSRandall Stewart {
4079e40d16adSMichael Tuexen 	struct sctp_inpcb *inp;
4080e40d16adSMichael Tuexen 	struct sctp_nets *net;
4081e40d16adSMichael Tuexen 
4082e40d16adSMichael Tuexen 	KASSERT(stcb != NULL, ("stcb == NULL"));
4083e40d16adSMichael Tuexen 	SCTP_TCB_LOCK_ASSERT(stcb);
4084e40d16adSMichael Tuexen 
4085e40d16adSMichael Tuexen 	inp = stcb->sctp_ep;
4086e40d16adSMichael Tuexen 	if (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET) {
4087a99b6783SRandall Stewart 		return;
4088a99b6783SRandall Stewart 	}
4089839d21d6SMichael Tuexen 	if ((SCTP_GET_STATE(stcb) == SCTP_STATE_COOKIE_WAIT) ||
4090839d21d6SMichael Tuexen 	    (SCTP_GET_STATE(stcb) == SCTP_STATE_COOKIE_ECHOED)) {
409117205eccSRandall Stewart 		if ((notification == SCTP_NOTIFY_INTERFACE_DOWN) ||
409217205eccSRandall Stewart 		    (notification == SCTP_NOTIFY_INTERFACE_UP) ||
409317205eccSRandall Stewart 		    (notification == SCTP_NOTIFY_INTERFACE_CONFIRMED)) {
409417205eccSRandall Stewart 			/* Don't report these in front states */
409517205eccSRandall Stewart 			return;
409617205eccSRandall Stewart 		}
409717205eccSRandall Stewart 	}
4098f9425b3aSMichael Tuexen 	if (notification != SCTP_NOTIFY_PARTIAL_DELVIERY_INDICATION) {
4099f9425b3aSMichael Tuexen 		SCTP_INP_READ_LOCK(inp);
4100f9425b3aSMichael Tuexen 	}
4101f9425b3aSMichael Tuexen 	SCTP_INP_READ_LOCK_ASSERT(inp);
4102f9425b3aSMichael Tuexen 
4103e40d16adSMichael Tuexen 	if ((inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
4104e40d16adSMichael Tuexen 	    (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
4105e40d16adSMichael Tuexen 	    (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_CANT_READ)) {
4106f9425b3aSMichael Tuexen 		SCTP_INP_READ_UNLOCK(inp);
4107e40d16adSMichael Tuexen 		return;
4108e40d16adSMichael Tuexen 	}
4109e40d16adSMichael Tuexen 
4110f8829a4aSRandall Stewart 	switch (notification) {
4111f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_UP:
4112f8829a4aSRandall Stewart 		if (stcb->asoc.assoc_up_sent == 0) {
4113105b68b4SMichael Tuexen 			sctp_notify_assoc_change(SCTP_COMM_UP, stcb, error, NULL, false, false, so_locked);
4114f8829a4aSRandall Stewart 			stcb->asoc.assoc_up_sent = 1;
4115f8829a4aSRandall Stewart 		}
41162afb3e84SRandall Stewart 		if (stcb->asoc.adaptation_needed && (stcb->asoc.adaptation_sent == 0)) {
41173ac76647SMichael Tuexen 			sctp_notify_adaptation_layer(stcb, so_locked);
41182afb3e84SRandall Stewart 		}
4119c79bec9cSMichael Tuexen 		if (stcb->asoc.auth_supported == 0) {
4120*1e81a4e7SMichael Tuexen 			sctp_notify_authentication(stcb, SCTP_AUTH_NO_AUTH, 0, so_locked);
4121830d754dSRandall Stewart 		}
4122f8829a4aSRandall Stewart 		break;
4123f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_DOWN:
4124105b68b4SMichael Tuexen 		sctp_notify_assoc_change(SCTP_SHUTDOWN_COMP, stcb, error, NULL, false, false, so_locked);
4125f8829a4aSRandall Stewart 		break;
4126f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_DOWN:
4127f8829a4aSRandall Stewart 		net = (struct sctp_nets *)data;
4128f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_UNREACHABLE,
4129e40d16adSMichael Tuexen 		    &net->ro._l_addr.sa, error, so_locked);
4130f8829a4aSRandall Stewart 		break;
4131f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_UP:
4132f8829a4aSRandall Stewart 		net = (struct sctp_nets *)data;
4133f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_AVAILABLE,
4134e40d16adSMichael Tuexen 		    &net->ro._l_addr.sa, error, so_locked);
4135f8829a4aSRandall Stewart 		break;
4136f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_CONFIRMED:
4137f8829a4aSRandall Stewart 		net = (struct sctp_nets *)data;
4138f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_CONFIRMED,
4139e40d16adSMichael Tuexen 		    &net->ro._l_addr.sa, error, so_locked);
4140f8829a4aSRandall Stewart 		break;
4141f8829a4aSRandall Stewart 	case SCTP_NOTIFY_SPECIAL_SP_FAIL:
4142f8829a4aSRandall Stewart 		sctp_notify_send_failed2(stcb, error,
4143ceaad40aSRandall Stewart 		    (struct sctp_stream_queue_pending *)data, so_locked);
4144f8829a4aSRandall Stewart 		break;
41451edc9dbaSMichael Tuexen 	case SCTP_NOTIFY_SENT_DG_FAIL:
41461edc9dbaSMichael Tuexen 		sctp_notify_send_failed(stcb, 1, error,
41471edc9dbaSMichael Tuexen 		    (struct sctp_tmit_chunk *)data, so_locked);
41481edc9dbaSMichael Tuexen 		break;
41491edc9dbaSMichael Tuexen 	case SCTP_NOTIFY_UNSENT_DG_FAIL:
41501edc9dbaSMichael Tuexen 		sctp_notify_send_failed(stcb, 0, error,
4151ceaad40aSRandall Stewart 		    (struct sctp_tmit_chunk *)data, so_locked);
4152f8829a4aSRandall Stewart 		break;
4153f8829a4aSRandall Stewart 	case SCTP_NOTIFY_PARTIAL_DELVIERY_INDICATION:
4154749a7fb5SMichael Tuexen 		sctp_notify_partial_delivery_indication(stcb, error,
4155749a7fb5SMichael Tuexen 		    (struct sctp_queued_to_read *)data,
4156749a7fb5SMichael Tuexen 		    so_locked);
4157f8829a4aSRandall Stewart 		break;
4158410a3b1eSMichael Tuexen 	case SCTP_NOTIFY_ASSOC_LOC_ABORTED:
4159839d21d6SMichael Tuexen 		if ((SCTP_GET_STATE(stcb) == SCTP_STATE_COOKIE_WAIT) ||
4160839d21d6SMichael Tuexen 		    (SCTP_GET_STATE(stcb) == SCTP_STATE_COOKIE_ECHOED)) {
4161105b68b4SMichael Tuexen 			sctp_notify_assoc_change(SCTP_CANT_STR_ASSOC, stcb, error, data, false, false, so_locked);
4162c105859eSRandall Stewart 		} else {
4163105b68b4SMichael Tuexen 			sctp_notify_assoc_change(SCTP_COMM_LOST, stcb, error, data, false, false, so_locked);
4164410a3b1eSMichael Tuexen 		}
4165410a3b1eSMichael Tuexen 		break;
4166410a3b1eSMichael Tuexen 	case SCTP_NOTIFY_ASSOC_REM_ABORTED:
4167839d21d6SMichael Tuexen 		if ((SCTP_GET_STATE(stcb) == SCTP_STATE_COOKIE_WAIT) ||
4168839d21d6SMichael Tuexen 		    (SCTP_GET_STATE(stcb) == SCTP_STATE_COOKIE_ECHOED)) {
4169105b68b4SMichael Tuexen 			sctp_notify_assoc_change(SCTP_CANT_STR_ASSOC, stcb, error, data, true, false, so_locked);
4170410a3b1eSMichael Tuexen 		} else {
4171105b68b4SMichael Tuexen 			sctp_notify_assoc_change(SCTP_COMM_LOST, stcb, error, data, true, false, so_locked);
4172105b68b4SMichael Tuexen 		}
4173105b68b4SMichael Tuexen 		break;
4174105b68b4SMichael Tuexen 	case SCTP_NOTIFY_ASSOC_TIMEDOUT:
4175105b68b4SMichael Tuexen 		if ((SCTP_GET_STATE(stcb) == SCTP_STATE_COOKIE_WAIT) ||
4176105b68b4SMichael Tuexen 		    (SCTP_GET_STATE(stcb) == SCTP_STATE_COOKIE_ECHOED)) {
4177105b68b4SMichael Tuexen 			sctp_notify_assoc_change(SCTP_CANT_STR_ASSOC, stcb, error, data, false, true, so_locked);
4178105b68b4SMichael Tuexen 		} else {
4179105b68b4SMichael Tuexen 			sctp_notify_assoc_change(SCTP_COMM_LOST, stcb, error, data, false, true, so_locked);
4180c105859eSRandall Stewart 		}
4181f8829a4aSRandall Stewart 		break;
4182f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_RESTART:
4183105b68b4SMichael Tuexen 		sctp_notify_assoc_change(SCTP_RESTART, stcb, error, NULL, false, false, so_locked);
4184c79bec9cSMichael Tuexen 		if (stcb->asoc.auth_supported == 0) {
4185*1e81a4e7SMichael Tuexen 			sctp_notify_authentication(stcb, SCTP_AUTH_NO_AUTH, 0, so_locked);
4186830d754dSRandall Stewart 		}
4187f8829a4aSRandall Stewart 		break;
4188f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_SEND:
41893ac76647SMichael Tuexen 		sctp_notify_stream_reset(stcb, error, ((uint16_t *)data), SCTP_STREAM_RESET_OUTGOING_SSN, so_locked);
4190f8829a4aSRandall Stewart 		break;
4191f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_RECV:
41923ac76647SMichael Tuexen 		sctp_notify_stream_reset(stcb, error, ((uint16_t *)data), SCTP_STREAM_RESET_INCOMING, so_locked);
4193f8829a4aSRandall Stewart 		break;
4194f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_FAILED_OUT:
4195c4e848b7SRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *)data),
41963ac76647SMichael Tuexen 		    (SCTP_STREAM_RESET_OUTGOING_SSN | SCTP_STREAM_RESET_FAILED), so_locked);
4197f8829a4aSRandall Stewart 		break;
4198d4260646SMichael Tuexen 	case SCTP_NOTIFY_STR_RESET_DENIED_OUT:
4199d4260646SMichael Tuexen 		sctp_notify_stream_reset(stcb, error, ((uint16_t *)data),
42003ac76647SMichael Tuexen 		    (SCTP_STREAM_RESET_OUTGOING_SSN | SCTP_STREAM_RESET_DENIED), so_locked);
4201d4260646SMichael Tuexen 		break;
4202f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_FAILED_IN:
4203c4e848b7SRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *)data),
42043ac76647SMichael Tuexen 		    (SCTP_STREAM_RESET_INCOMING | SCTP_STREAM_RESET_FAILED), so_locked);
4205f8829a4aSRandall Stewart 		break;
4206d4260646SMichael Tuexen 	case SCTP_NOTIFY_STR_RESET_DENIED_IN:
4207d4260646SMichael Tuexen 		sctp_notify_stream_reset(stcb, error, ((uint16_t *)data),
42083ac76647SMichael Tuexen 		    (SCTP_STREAM_RESET_INCOMING | SCTP_STREAM_RESET_DENIED), so_locked);
42093ac76647SMichael Tuexen 		break;
42103ac76647SMichael Tuexen 	case SCTP_NOTIFY_STR_RESET_ADD:
42113ac76647SMichael Tuexen 		sctp_notify_stream_reset_add(stcb, error, so_locked);
42123ac76647SMichael Tuexen 		break;
42133ac76647SMichael Tuexen 	case SCTP_NOTIFY_STR_RESET_TSN:
42143ac76647SMichael Tuexen 		sctp_notify_stream_reset_tsn(stcb, error, so_locked);
4215d4260646SMichael Tuexen 		break;
4216f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_ADD_IP:
4217f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_ADDED, data,
42183cb3567dSMichael Tuexen 		    error, so_locked);
4219f8829a4aSRandall Stewart 		break;
4220f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_DELETE_IP:
4221f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_REMOVED, data,
42223cb3567dSMichael Tuexen 		    error, so_locked);
4223f8829a4aSRandall Stewart 		break;
4224f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_SET_PRIMARY:
4225f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_MADE_PRIM, data,
42263cb3567dSMichael Tuexen 		    error, so_locked);
4227f8829a4aSRandall Stewart 		break;
4228f8829a4aSRandall Stewart 	case SCTP_NOTIFY_PEER_SHUTDOWN:
42293ac76647SMichael Tuexen 		sctp_notify_shutdown_event(stcb, so_locked);
4230f8829a4aSRandall Stewart 		break;
4231f8829a4aSRandall Stewart 	case SCTP_NOTIFY_AUTH_NEW_KEY:
4232cd3770c5SMichael Tuexen 		sctp_notify_authentication(stcb, SCTP_AUTH_NEW_KEY,
4233cd3770c5SMichael Tuexen 		    *(uint16_t *)data, so_locked);
4234f8829a4aSRandall Stewart 		break;
4235830d754dSRandall Stewart 	case SCTP_NOTIFY_AUTH_FREE_KEY:
4236cd3770c5SMichael Tuexen 		sctp_notify_authentication(stcb, SCTP_AUTH_FREE_KEY,
4237cd3770c5SMichael Tuexen 		    *(uint16_t *)data, so_locked);
4238f8829a4aSRandall Stewart 		break;
4239830d754dSRandall Stewart 	case SCTP_NOTIFY_NO_PEER_AUTH:
4240cd3770c5SMichael Tuexen 		sctp_notify_authentication(stcb, SCTP_AUTH_NO_AUTH,
4241cd3770c5SMichael Tuexen 		    0, so_locked);
4242830d754dSRandall Stewart 		break;
4243830d754dSRandall Stewart 	case SCTP_NOTIFY_SENDER_DRY:
4244830d754dSRandall Stewart 		sctp_notify_sender_dry_event(stcb, so_locked);
4245830d754dSRandall Stewart 		break;
4246389b1b11SMichael Tuexen 	case SCTP_NOTIFY_REMOTE_ERROR:
42473ac76647SMichael Tuexen 		sctp_notify_remote_error(stcb, error, data, so_locked);
4248389b1b11SMichael Tuexen 		break;
4249f8829a4aSRandall Stewart 	default:
4250ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_UTIL1, "%s: unknown notification %xh (%u)\n",
42516e9c45e0SMichael Tuexen 		    __func__, notification, notification);
4252f8829a4aSRandall Stewart 		break;
4253e40d16adSMichael Tuexen 	}
4254f9425b3aSMichael Tuexen 	if (notification != SCTP_NOTIFY_PARTIAL_DELVIERY_INDICATION) {
4255f9425b3aSMichael Tuexen 		SCTP_INP_READ_UNLOCK(inp);
4256f9425b3aSMichael Tuexen 	}
4257f8829a4aSRandall Stewart }
4258f8829a4aSRandall Stewart 
4259f8829a4aSRandall Stewart void
4260f5d30f7fSMichael Tuexen sctp_report_all_outbound(struct sctp_tcb *stcb, uint16_t error, int so_locked)
4261f8829a4aSRandall Stewart {
4262f8829a4aSRandall Stewart 	struct sctp_association *asoc;
4263f8829a4aSRandall Stewart 	struct sctp_stream_out *outs;
42644a9ef3f8SMichael Tuexen 	struct sctp_tmit_chunk *chk, *nchk;
42654a9ef3f8SMichael Tuexen 	struct sctp_stream_queue_pending *sp, *nsp;
42667f34832bSRandall Stewart 	int i;
4267f8829a4aSRandall Stewart 
4268ad81507eSRandall Stewart 	if (stcb == NULL) {
4269ad81507eSRandall Stewart 		return;
4270ad81507eSRandall Stewart 	}
42714a9ef3f8SMichael Tuexen 	asoc = &stcb->asoc;
42724a9ef3f8SMichael Tuexen 	if (asoc->state & SCTP_STATE_ABOUT_TO_BE_FREED) {
4273478fbccbSRandall Stewart 		/* already being freed */
4274478fbccbSRandall Stewart 		return;
4275478fbccbSRandall Stewart 	}
4276f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
4277f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
42784a9ef3f8SMichael Tuexen 	    (asoc->state & SCTP_STATE_CLOSED_SOCKET)) {
4279f8829a4aSRandall Stewart 		return;
4280f8829a4aSRandall Stewart 	}
4281f8829a4aSRandall Stewart 	/* now through all the gunk freeing chunks */
4282d00aff5dSRandall Stewart 	/* sent queue SHOULD be empty */
42834a9ef3f8SMichael Tuexen 	TAILQ_FOREACH_SAFE(chk, &asoc->sent_queue, sctp_next, nchk) {
4284d00aff5dSRandall Stewart 		TAILQ_REMOVE(&asoc->sent_queue, chk, sctp_next);
4285d00aff5dSRandall Stewart 		asoc->sent_queue_cnt--;
4286325c8c46SMichael Tuexen 		if (chk->sent != SCTP_DATAGRAM_NR_ACKED) {
428749656eefSMichael Tuexen 			if (asoc->strmout[chk->rec.data.sid].chunks_on_queues > 0) {
428849656eefSMichael Tuexen 				asoc->strmout[chk->rec.data.sid].chunks_on_queues--;
4289a7ad6026SMichael Tuexen #ifdef INVARIANTS
4290a7ad6026SMichael Tuexen 			} else {
429149656eefSMichael Tuexen 				panic("No chunks on the queues for sid %u.", chk->rec.data.sid);
4292a7ad6026SMichael Tuexen #endif
4293a7ad6026SMichael Tuexen 			}
4294a7ad6026SMichael Tuexen 		}
42950c0982b8SRandall Stewart 		if (chk->data != NULL) {
4296d00aff5dSRandall Stewart 			sctp_free_bufspace(stcb, asoc, chk, 1);
42971edc9dbaSMichael Tuexen 			sctp_ulp_notify(SCTP_NOTIFY_SENT_DG_FAIL, stcb,
42981edc9dbaSMichael Tuexen 			    error, chk, so_locked);
4299810ec536SMichael Tuexen 			if (chk->data) {
4300d00aff5dSRandall Stewart 				sctp_m_freem(chk->data);
4301d00aff5dSRandall Stewart 				chk->data = NULL;
4302d00aff5dSRandall Stewart 			}
4303810ec536SMichael Tuexen 		}
4304689e6a5fSMichael Tuexen 		sctp_free_a_chunk(stcb, chk, so_locked);
4305d00aff5dSRandall Stewart 		/* sa_ignore FREED_MEMORY */
4306d00aff5dSRandall Stewart 	}
4307d00aff5dSRandall Stewart 	/* pending send queue SHOULD be empty */
43084a9ef3f8SMichael Tuexen 	TAILQ_FOREACH_SAFE(chk, &asoc->send_queue, sctp_next, nchk) {
4309d00aff5dSRandall Stewart 		TAILQ_REMOVE(&asoc->send_queue, chk, sctp_next);
4310d00aff5dSRandall Stewart 		asoc->send_queue_cnt--;
431149656eefSMichael Tuexen 		if (asoc->strmout[chk->rec.data.sid].chunks_on_queues > 0) {
431249656eefSMichael Tuexen 			asoc->strmout[chk->rec.data.sid].chunks_on_queues--;
4313a7ad6026SMichael Tuexen #ifdef INVARIANTS
4314a7ad6026SMichael Tuexen 		} else {
431549656eefSMichael Tuexen 			panic("No chunks on the queues for sid %u.", chk->rec.data.sid);
4316a7ad6026SMichael Tuexen #endif
4317a7ad6026SMichael Tuexen 		}
43180c0982b8SRandall Stewart 		if (chk->data != NULL) {
4319d00aff5dSRandall Stewart 			sctp_free_bufspace(stcb, asoc, chk, 1);
43201edc9dbaSMichael Tuexen 			sctp_ulp_notify(SCTP_NOTIFY_UNSENT_DG_FAIL, stcb,
43211edc9dbaSMichael Tuexen 			    error, chk, so_locked);
4322810ec536SMichael Tuexen 			if (chk->data) {
4323d00aff5dSRandall Stewart 				sctp_m_freem(chk->data);
4324d00aff5dSRandall Stewart 				chk->data = NULL;
4325d00aff5dSRandall Stewart 			}
4326810ec536SMichael Tuexen 		}
4327689e6a5fSMichael Tuexen 		sctp_free_a_chunk(stcb, chk, so_locked);
4328d00aff5dSRandall Stewart 		/* sa_ignore FREED_MEMORY */
4329d00aff5dSRandall Stewart 	}
43304a9ef3f8SMichael Tuexen 	for (i = 0; i < asoc->streamoutcnt; i++) {
43317f34832bSRandall Stewart 		/* For each stream */
43324a9ef3f8SMichael Tuexen 		outs = &asoc->strmout[i];
43337f34832bSRandall Stewart 		/* clean up any sends there */
43344a9ef3f8SMichael Tuexen 		TAILQ_FOREACH_SAFE(sp, &outs->outqueue, next, nsp) {
43354d58b0c3SMichael Tuexen 			atomic_subtract_int(&asoc->stream_queue_cnt, 1);
4336f8829a4aSRandall Stewart 			TAILQ_REMOVE(&outs->outqueue, sp, next);
4337762ae0ecSMichael Tuexen 			stcb->asoc.ss_functions.sctp_ss_remove_from_stream(stcb, asoc, outs, sp);
4338f8829a4aSRandall Stewart 			sctp_free_spbufspace(stcb, asoc, sp);
4339478fbccbSRandall Stewart 			if (sp->data) {
4340f8829a4aSRandall Stewart 				sctp_ulp_notify(SCTP_NOTIFY_SPECIAL_SP_FAIL, stcb,
43411edc9dbaSMichael Tuexen 				    error, (void *)sp, so_locked);
4342f8829a4aSRandall Stewart 				if (sp->data) {
4343f8829a4aSRandall Stewart 					sctp_m_freem(sp->data);
4344f8829a4aSRandall Stewart 					sp->data = NULL;
4345d07b2ac6SMichael Tuexen 					sp->tail_mbuf = NULL;
4346d07b2ac6SMichael Tuexen 					sp->length = 0;
4347f8829a4aSRandall Stewart 				}
4348478fbccbSRandall Stewart 			}
43499eea4a2dSMichael Tuexen 			if (sp->net) {
4350f8829a4aSRandall Stewart 				sctp_free_remote_addr(sp->net);
4351f8829a4aSRandall Stewart 				sp->net = NULL;
43529eea4a2dSMichael Tuexen 			}
4353f8829a4aSRandall Stewart 			/* Free the chunk */
4354689e6a5fSMichael Tuexen 			sctp_free_a_strmoq(stcb, sp, so_locked);
43553c503c28SRandall Stewart 			/* sa_ignore FREED_MEMORY */
4356f8829a4aSRandall Stewart 		}
4357f8829a4aSRandall Stewart 	}
4358ad81507eSRandall Stewart }
4359f8829a4aSRandall Stewart 
4360f8829a4aSRandall Stewart void
4361105b68b4SMichael Tuexen sctp_abort_notification(struct sctp_tcb *stcb, bool from_peer, bool timeout,
4362105b68b4SMichael Tuexen     uint16_t error, struct sctp_abort_chunk *abort,
4363105b68b4SMichael Tuexen     int so_locked)
4364f8829a4aSRandall Stewart {
4365ad81507eSRandall Stewart 	if (stcb == NULL) {
4366ad81507eSRandall Stewart 		return;
4367ad81507eSRandall Stewart 	}
43685ac91821SMichael Tuexen 	SCTP_TCB_LOCK_ASSERT(stcb);
43695ac91821SMichael Tuexen 
4370c55b70ceSMichael Tuexen 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL) ||
4371c55b70ceSMichael Tuexen 	    ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) &&
4372c55b70ceSMichael Tuexen 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_CONNECTED))) {
4373a5c2009dSMichael Tuexen 		sctp_pcb_add_flags(stcb->sctp_ep, SCTP_PCB_FLAGS_WAS_ABORTED);
4374c55b70ceSMichael Tuexen 	}
4375f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
4376f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
4377f8829a4aSRandall Stewart 	    (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET)) {
4378f8829a4aSRandall Stewart 		return;
4379f8829a4aSRandall Stewart 	}
4380f5d30f7fSMichael Tuexen 	SCTP_ADD_SUBSTATE(stcb, SCTP_STATE_WAS_ABORTED);
4381f8829a4aSRandall Stewart 	/* Tell them we lost the asoc */
4382f5d30f7fSMichael Tuexen 	sctp_report_all_outbound(stcb, error, so_locked);
4383410a3b1eSMichael Tuexen 	if (from_peer) {
4384410a3b1eSMichael Tuexen 		sctp_ulp_notify(SCTP_NOTIFY_ASSOC_REM_ABORTED, stcb, error, abort, so_locked);
4385410a3b1eSMichael Tuexen 	} else {
4386105b68b4SMichael Tuexen 		if (timeout) {
4387105b68b4SMichael Tuexen 			sctp_ulp_notify(SCTP_NOTIFY_ASSOC_TIMEDOUT, stcb, error, abort, so_locked);
4388105b68b4SMichael Tuexen 		} else {
4389410a3b1eSMichael Tuexen 			sctp_ulp_notify(SCTP_NOTIFY_ASSOC_LOC_ABORTED, stcb, error, abort, so_locked);
4390410a3b1eSMichael Tuexen 		}
4391f8829a4aSRandall Stewart 	}
4392105b68b4SMichael Tuexen }
4393f8829a4aSRandall Stewart 
4394f8829a4aSRandall Stewart void
4395f8829a4aSRandall Stewart sctp_abort_association(struct sctp_inpcb *inp, struct sctp_tcb *stcb,
4396b1754ad1SMichael Tuexen     struct mbuf *m, int iphlen,
4397b1754ad1SMichael Tuexen     struct sockaddr *src, struct sockaddr *dst,
4398b1754ad1SMichael Tuexen     struct sctphdr *sh, struct mbuf *op_err,
4399457b4b88SMichael Tuexen     uint8_t mflowtype, uint32_t mflowid,
4400c54a18d2SRandall Stewart     uint32_t vrf_id, uint16_t port)
4401f8829a4aSRandall Stewart {
440284992a32SMichael Tuexen 	struct sctp_gen_error_cause *cause;
4403f8829a4aSRandall Stewart 	uint32_t vtag;
440484992a32SMichael Tuexen 	uint16_t cause_code;
4405ceaad40aSRandall Stewart 
4406f8829a4aSRandall Stewart 	if (stcb != NULL) {
4407f8829a4aSRandall Stewart 		vtag = stcb->asoc.peer_vtag;
440817205eccSRandall Stewart 		vrf_id = stcb->asoc.vrf_id;
440984992a32SMichael Tuexen 		if (op_err != NULL) {
441084992a32SMichael Tuexen 			/* Read the cause code from the error cause. */
441184992a32SMichael Tuexen 			cause = mtod(op_err, struct sctp_gen_error_cause *);
441284992a32SMichael Tuexen 			cause_code = ntohs(cause->code);
441384992a32SMichael Tuexen 		} else {
441484992a32SMichael Tuexen 			cause_code = 0;
441584992a32SMichael Tuexen 		}
441684992a32SMichael Tuexen 	} else {
441784992a32SMichael Tuexen 		vtag = 0;
4418f8829a4aSRandall Stewart 	}
4419b1754ad1SMichael Tuexen 	sctp_send_abort(m, iphlen, src, dst, sh, vtag, op_err,
4420d089f9b9SMichael Tuexen 	    mflowtype, mflowid, inp->fibnum,
4421f30ac432SMichael Tuexen 	    vrf_id, port);
4422f8829a4aSRandall Stewart 	if (stcb != NULL) {
4423884d8c53SMichael Tuexen 		/* We have a TCB to abort, send notification too */
4424105b68b4SMichael Tuexen 		sctp_abort_notification(stcb, false, false, cause_code, NULL, SCTP_SO_NOT_LOCKED);
4425f8829a4aSRandall Stewart 		/* Ok, now lets free it */
44260271d0cdSMichael Tuexen 		SCTP_STAT_INCR_COUNTER32(sctps_aborted);
4427839d21d6SMichael Tuexen 		if ((SCTP_GET_STATE(stcb) == SCTP_STATE_OPEN) ||
4428839d21d6SMichael Tuexen 		    (SCTP_GET_STATE(stcb) == SCTP_STATE_SHUTDOWN_RECEIVED)) {
44290271d0cdSMichael Tuexen 			SCTP_STAT_DECR_GAUGE32(sctps_currestab);
44300271d0cdSMichael Tuexen 		}
4431ba785902SMichael Tuexen 		(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
4432ba785902SMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_4);
4433f8829a4aSRandall Stewart 	}
4434f8829a4aSRandall Stewart }
4435f1f73e57SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
4436f1f73e57SRandall Stewart void
4437f1f73e57SRandall Stewart sctp_print_out_track_log(struct sctp_tcb *stcb)
4438f1f73e57SRandall Stewart {
443918e198d3SRandall Stewart #ifdef NOSIY_PRINTS
4440f1f73e57SRandall Stewart 	int i;
4441f1f73e57SRandall Stewart 
4442ad81507eSRandall Stewart 	SCTP_PRINTF("Last ep reason:%x\n", stcb->sctp_ep->last_abort_code);
4443ad81507eSRandall Stewart 	SCTP_PRINTF("IN bound TSN log-aaa\n");
4444f1f73e57SRandall Stewart 	if ((stcb->asoc.tsn_in_at == 0) && (stcb->asoc.tsn_in_wrapped == 0)) {
4445ad81507eSRandall Stewart 		SCTP_PRINTF("None rcvd\n");
4446f1f73e57SRandall Stewart 		goto none_in;
4447f1f73e57SRandall Stewart 	}
4448f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_in_wrapped) {
4449f1f73e57SRandall Stewart 		for (i = stcb->asoc.tsn_in_at; i < SCTP_TSN_LOG_SIZE; i++) {
4450ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
4451f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].tsn,
4452f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].strm,
4453f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].seq,
4454f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].flgs,
4455f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].sz);
4456f1f73e57SRandall Stewart 		}
4457f1f73e57SRandall Stewart 	}
4458f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_in_at) {
4459f1f73e57SRandall Stewart 		for (i = 0; i < stcb->asoc.tsn_in_at; i++) {
4460ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
4461f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].tsn,
4462f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].strm,
4463f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].seq,
4464f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].flgs,
4465f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].sz);
4466f1f73e57SRandall Stewart 		}
4467f1f73e57SRandall Stewart 	}
4468f1f73e57SRandall Stewart none_in:
4469ad81507eSRandall Stewart 	SCTP_PRINTF("OUT bound TSN log-aaa\n");
4470ad81507eSRandall Stewart 	if ((stcb->asoc.tsn_out_at == 0) &&
4471ad81507eSRandall Stewart 	    (stcb->asoc.tsn_out_wrapped == 0)) {
4472ad81507eSRandall Stewart 		SCTP_PRINTF("None sent\n");
4473f1f73e57SRandall Stewart 	}
4474f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_out_wrapped) {
4475f1f73e57SRandall Stewart 		for (i = stcb->asoc.tsn_out_at; i < SCTP_TSN_LOG_SIZE; i++) {
4476ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
4477f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].tsn,
4478f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].strm,
4479f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].seq,
4480f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].flgs,
4481f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].sz);
4482f1f73e57SRandall Stewart 		}
4483f1f73e57SRandall Stewart 	}
4484f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_out_at) {
4485f1f73e57SRandall Stewart 		for (i = 0; i < stcb->asoc.tsn_out_at; i++) {
4486ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
4487f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].tsn,
4488f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].strm,
4489f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].seq,
4490f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].flgs,
4491f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].sz);
4492f1f73e57SRandall Stewart 		}
4493f1f73e57SRandall Stewart 	}
449418e198d3SRandall Stewart #endif
4495f1f73e57SRandall Stewart }
4496f1f73e57SRandall Stewart #endif
4497f1f73e57SRandall Stewart 
4498f8829a4aSRandall Stewart void
4499f8829a4aSRandall Stewart sctp_abort_an_association(struct sctp_inpcb *inp, struct sctp_tcb *stcb,
4500105b68b4SMichael Tuexen     struct mbuf *op_err, bool timedout, int so_locked)
4501f8829a4aSRandall Stewart {
450284992a32SMichael Tuexen 	struct sctp_gen_error_cause *cause;
450384992a32SMichael Tuexen 	uint16_t cause_code;
4504ceaad40aSRandall Stewart 
4505f8829a4aSRandall Stewart 	if (stcb == NULL) {
4506f8829a4aSRandall Stewart 		/* Got to have a TCB */
4507f8829a4aSRandall Stewart 		if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
4508fe1831e0SMichael Tuexen 			if (LIST_EMPTY(&inp->sctp_asoc_list)) {
4509b0552ae2SRandall Stewart 				sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
4510b0552ae2SRandall Stewart 				    SCTP_CALLED_DIRECTLY_NOCMPSET);
4511f8829a4aSRandall Stewart 			}
4512f8829a4aSRandall Stewart 		}
4513f8829a4aSRandall Stewart 		return;
4514f8829a4aSRandall Stewart 	}
451584992a32SMichael Tuexen 	if (op_err != NULL) {
451684992a32SMichael Tuexen 		/* Read the cause code from the error cause. */
451784992a32SMichael Tuexen 		cause = mtod(op_err, struct sctp_gen_error_cause *);
451884992a32SMichael Tuexen 		cause_code = ntohs(cause->code);
451984992a32SMichael Tuexen 	} else {
452084992a32SMichael Tuexen 		cause_code = 0;
452184992a32SMichael Tuexen 	}
4522f8829a4aSRandall Stewart 	/* notify the peer */
4523ceaad40aSRandall Stewart 	sctp_send_abort_tcb(stcb, op_err, so_locked);
4524f8829a4aSRandall Stewart 	SCTP_STAT_INCR_COUNTER32(sctps_aborted);
4525839d21d6SMichael Tuexen 	if ((SCTP_GET_STATE(stcb) == SCTP_STATE_OPEN) ||
4526839d21d6SMichael Tuexen 	    (SCTP_GET_STATE(stcb) == SCTP_STATE_SHUTDOWN_RECEIVED)) {
4527f8829a4aSRandall Stewart 		SCTP_STAT_DECR_GAUGE32(sctps_currestab);
4528f8829a4aSRandall Stewart 	}
4529884d8c53SMichael Tuexen 	/* notify the ulp */
4530884d8c53SMichael Tuexen 	if ((inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) == 0) {
4531105b68b4SMichael Tuexen 		sctp_abort_notification(stcb, false, timedout, cause_code, NULL, so_locked);
4532884d8c53SMichael Tuexen 	}
4533f8829a4aSRandall Stewart 	/* now free the asoc */
4534f1f73e57SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
4535f1f73e57SRandall Stewart 	sctp_print_out_track_log(stcb);
4536f1f73e57SRandall Stewart #endif
4537ba785902SMichael Tuexen 	(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
4538ba785902SMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_5);
4539f8829a4aSRandall Stewart }
4540f8829a4aSRandall Stewart 
4541f8829a4aSRandall Stewart void
4542b1754ad1SMichael Tuexen sctp_handle_ootb(struct mbuf *m, int iphlen, int offset,
4543b1754ad1SMichael Tuexen     struct sockaddr *src, struct sockaddr *dst,
4544b1754ad1SMichael Tuexen     struct sctphdr *sh, struct sctp_inpcb *inp,
4545ff1ffd74SMichael Tuexen     struct mbuf *cause,
4546d089f9b9SMichael Tuexen     uint8_t mflowtype, uint32_t mflowid, uint16_t fibnum,
4547f30ac432SMichael Tuexen     uint32_t vrf_id, uint16_t port)
4548f8829a4aSRandall Stewart {
4549f8829a4aSRandall Stewart 	struct sctp_chunkhdr *ch, chunk_buf;
4550f8829a4aSRandall Stewart 	unsigned int chk_length;
4551c58e60beSMichael Tuexen 	int contains_init_chunk;
4552f8829a4aSRandall Stewart 
4553f8829a4aSRandall Stewart 	SCTP_STAT_INCR_COUNTER32(sctps_outoftheblue);
4554f8829a4aSRandall Stewart 	/* Generate a TO address for future reference */
4555f8829a4aSRandall Stewart 	if (inp && (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE)) {
4556fe1831e0SMichael Tuexen 		if (LIST_EMPTY(&inp->sctp_asoc_list)) {
4557b0552ae2SRandall Stewart 			sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
4558b0552ae2SRandall Stewart 			    SCTP_CALLED_DIRECTLY_NOCMPSET);
4559f8829a4aSRandall Stewart 		}
4560f8829a4aSRandall Stewart 	}
4561c58e60beSMichael Tuexen 	contains_init_chunk = 0;
4562f8829a4aSRandall Stewart 	ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
4563f8829a4aSRandall Stewart 	    sizeof(*ch), (uint8_t *)&chunk_buf);
4564f8829a4aSRandall Stewart 	while (ch != NULL) {
4565f8829a4aSRandall Stewart 		chk_length = ntohs(ch->chunk_length);
4566f8829a4aSRandall Stewart 		if (chk_length < sizeof(*ch)) {
4567f8829a4aSRandall Stewart 			/* break to abort land */
4568f8829a4aSRandall Stewart 			break;
4569f8829a4aSRandall Stewart 		}
4570f8829a4aSRandall Stewart 		switch (ch->chunk_type) {
4571c58e60beSMichael Tuexen 		case SCTP_INIT:
4572c58e60beSMichael Tuexen 			contains_init_chunk = 1;
4573c58e60beSMichael Tuexen 			break;
4574f8829a4aSRandall Stewart 		case SCTP_PACKET_DROPPED:
4575f8829a4aSRandall Stewart 			/* we don't respond to pkt-dropped */
4576f8829a4aSRandall Stewart 			return;
4577f8829a4aSRandall Stewart 		case SCTP_ABORT_ASSOCIATION:
4578f8829a4aSRandall Stewart 			/* we don't respond with an ABORT to an ABORT */
4579f8829a4aSRandall Stewart 			return;
4580f8829a4aSRandall Stewart 		case SCTP_SHUTDOWN_COMPLETE:
4581f8829a4aSRandall Stewart 			/*
4582f8829a4aSRandall Stewart 			 * we ignore it since we are not waiting for it and
4583f8829a4aSRandall Stewart 			 * peer is gone
4584f8829a4aSRandall Stewart 			 */
4585f8829a4aSRandall Stewart 			return;
4586f8829a4aSRandall Stewart 		case SCTP_SHUTDOWN_ACK:
4587b1754ad1SMichael Tuexen 			sctp_send_shutdown_complete2(src, dst, sh,
4588d089f9b9SMichael Tuexen 			    mflowtype, mflowid, fibnum,
4589f30ac432SMichael Tuexen 			    vrf_id, port);
4590f8829a4aSRandall Stewart 			return;
4591f8829a4aSRandall Stewart 		default:
4592f8829a4aSRandall Stewart 			break;
4593f8829a4aSRandall Stewart 		}
4594f8829a4aSRandall Stewart 		offset += SCTP_SIZE32(chk_length);
4595f8829a4aSRandall Stewart 		ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
4596f8829a4aSRandall Stewart 		    sizeof(*ch), (uint8_t *)&chunk_buf);
4597f8829a4aSRandall Stewart 	}
4598c58e60beSMichael Tuexen 	if ((SCTP_BASE_SYSCTL(sctp_blackhole) == 0) ||
4599c58e60beSMichael Tuexen 	    ((SCTP_BASE_SYSCTL(sctp_blackhole) == 1) &&
4600c58e60beSMichael Tuexen 	    (contains_init_chunk == 0))) {
4601ff1ffd74SMichael Tuexen 		sctp_send_abort(m, iphlen, src, dst, sh, 0, cause,
4602d089f9b9SMichael Tuexen 		    mflowtype, mflowid, fibnum,
4603f30ac432SMichael Tuexen 		    vrf_id, port);
4604f8829a4aSRandall Stewart 	}
4605c58e60beSMichael Tuexen }
4606f8829a4aSRandall Stewart 
4607f8829a4aSRandall Stewart /*
4608f8829a4aSRandall Stewart  * check the inbound datagram to make sure there is not an abort inside it,
4609f8829a4aSRandall Stewart  * if there is return 1, else return 0.
4610f8829a4aSRandall Stewart  */
4611f8829a4aSRandall Stewart int
4612e010d200SMichael Tuexen sctp_is_there_an_abort_here(struct mbuf *m, int iphlen, uint32_t *vtag)
4613f8829a4aSRandall Stewart {
4614f8829a4aSRandall Stewart 	struct sctp_chunkhdr *ch;
4615f8829a4aSRandall Stewart 	struct sctp_init_chunk *init_chk, chunk_buf;
4616f8829a4aSRandall Stewart 	int offset;
4617f8829a4aSRandall Stewart 	unsigned int chk_length;
4618f8829a4aSRandall Stewart 
4619f8829a4aSRandall Stewart 	offset = iphlen + sizeof(struct sctphdr);
4620f8829a4aSRandall Stewart 	ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset, sizeof(*ch),
4621f8829a4aSRandall Stewart 	    (uint8_t *)&chunk_buf);
4622f8829a4aSRandall Stewart 	while (ch != NULL) {
4623f8829a4aSRandall Stewart 		chk_length = ntohs(ch->chunk_length);
4624f8829a4aSRandall Stewart 		if (chk_length < sizeof(*ch)) {
4625f8829a4aSRandall Stewart 			/* packet is probably corrupt */
4626f8829a4aSRandall Stewart 			break;
4627f8829a4aSRandall Stewart 		}
4628f8829a4aSRandall Stewart 		/* we seem to be ok, is it an abort? */
4629f8829a4aSRandall Stewart 		if (ch->chunk_type == SCTP_ABORT_ASSOCIATION) {
4630f8829a4aSRandall Stewart 			/* yep, tell them */
4631f8829a4aSRandall Stewart 			return (1);
4632f8829a4aSRandall Stewart 		}
4633e010d200SMichael Tuexen 		if ((ch->chunk_type == SCTP_INITIATION) ||
4634e010d200SMichael Tuexen 		    (ch->chunk_type == SCTP_INITIATION_ACK)) {
4635f8829a4aSRandall Stewart 			/* need to update the Vtag */
4636f8829a4aSRandall Stewart 			init_chk = (struct sctp_init_chunk *)sctp_m_getptr(m,
4637e010d200SMichael Tuexen 			    offset, sizeof(struct sctp_init_chunk), (uint8_t *)&chunk_buf);
4638f8829a4aSRandall Stewart 			if (init_chk != NULL) {
4639e010d200SMichael Tuexen 				*vtag = ntohl(init_chk->init.initiate_tag);
4640f8829a4aSRandall Stewart 			}
4641f8829a4aSRandall Stewart 		}
4642f8829a4aSRandall Stewart 		/* Nope, move to the next chunk */
4643f8829a4aSRandall Stewart 		offset += SCTP_SIZE32(chk_length);
4644f8829a4aSRandall Stewart 		ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
4645f8829a4aSRandall Stewart 		    sizeof(*ch), (uint8_t *)&chunk_buf);
4646f8829a4aSRandall Stewart 	}
4647f8829a4aSRandall Stewart 	return (0);
4648f8829a4aSRandall Stewart }
4649f8829a4aSRandall Stewart 
4650f8829a4aSRandall Stewart /*
4651f8829a4aSRandall Stewart  * currently (2/02), ifa_addr embeds scope_id's and don't have sin6_scope_id
4652f8829a4aSRandall Stewart  * set (i.e. it's 0) so, create this function to compare link local scopes
4653f8829a4aSRandall Stewart  */
46545e2c2d87SRandall Stewart #ifdef INET6
4655f8829a4aSRandall Stewart uint32_t
4656b0471b4bSMichael Tuexen sctp_is_same_scope(struct sockaddr_in6 *addr1, struct sockaddr_in6 *addr2)
4657b0471b4bSMichael Tuexen {
4658f8829a4aSRandall Stewart 	struct sockaddr_in6 a, b;
4659f8829a4aSRandall Stewart 
4660f8829a4aSRandall Stewart 	/* save copies */
4661f8829a4aSRandall Stewart 	a = *addr1;
4662f8829a4aSRandall Stewart 	b = *addr2;
4663f8829a4aSRandall Stewart 
4664f8829a4aSRandall Stewart 	if (a.sin6_scope_id == 0)
4665f8829a4aSRandall Stewart 		if (sa6_recoverscope(&a)) {
4666f8829a4aSRandall Stewart 			/* can't get scope, so can't match */
4667f8829a4aSRandall Stewart 			return (0);
4668f8829a4aSRandall Stewart 		}
4669f8829a4aSRandall Stewart 	if (b.sin6_scope_id == 0)
4670f8829a4aSRandall Stewart 		if (sa6_recoverscope(&b)) {
4671f8829a4aSRandall Stewart 			/* can't get scope, so can't match */
4672f8829a4aSRandall Stewart 			return (0);
4673f8829a4aSRandall Stewart 		}
4674f8829a4aSRandall Stewart 	if (a.sin6_scope_id != b.sin6_scope_id)
4675f8829a4aSRandall Stewart 		return (0);
4676f8829a4aSRandall Stewart 
4677f8829a4aSRandall Stewart 	return (1);
4678f8829a4aSRandall Stewart }
4679f8829a4aSRandall Stewart 
4680f8829a4aSRandall Stewart /*
4681f8829a4aSRandall Stewart  * returns a sockaddr_in6 with embedded scope recovered and removed
4682f8829a4aSRandall Stewart  */
4683f8829a4aSRandall Stewart struct sockaddr_in6 *
4684f8829a4aSRandall Stewart sctp_recover_scope(struct sockaddr_in6 *addr, struct sockaddr_in6 *store)
4685f8829a4aSRandall Stewart {
4686f8829a4aSRandall Stewart 	/* check and strip embedded scope junk */
4687f8829a4aSRandall Stewart 	if (addr->sin6_family == AF_INET6) {
4688f8829a4aSRandall Stewart 		if (IN6_IS_SCOPE_LINKLOCAL(&addr->sin6_addr)) {
4689f8829a4aSRandall Stewart 			if (addr->sin6_scope_id == 0) {
4690f8829a4aSRandall Stewart 				*store = *addr;
4691f8829a4aSRandall Stewart 				if (!sa6_recoverscope(store)) {
4692f8829a4aSRandall Stewart 					/* use the recovered scope */
4693f8829a4aSRandall Stewart 					addr = store;
4694f8829a4aSRandall Stewart 				}
4695f42a358aSRandall Stewart 			} else {
4696f8829a4aSRandall Stewart 				/* else, return the original "to" addr */
4697f42a358aSRandall Stewart 				in6_clearscope(&addr->sin6_addr);
4698f8829a4aSRandall Stewart 			}
4699f8829a4aSRandall Stewart 		}
4700f8829a4aSRandall Stewart 	}
4701f8829a4aSRandall Stewart 	return (addr);
4702f8829a4aSRandall Stewart }
47035e2c2d87SRandall Stewart #endif
47045e2c2d87SRandall Stewart 
4705f8829a4aSRandall Stewart /*
4706f8829a4aSRandall Stewart  * are the two addresses the same?  currently a "scopeless" check returns: 1
4707f8829a4aSRandall Stewart  * if same, 0 if not
4708f8829a4aSRandall Stewart  */
470972fb6fdbSRandall Stewart int
4710f8829a4aSRandall Stewart sctp_cmpaddr(struct sockaddr *sa1, struct sockaddr *sa2)
4711f8829a4aSRandall Stewart {
4712f8829a4aSRandall Stewart 
4713f8829a4aSRandall Stewart 	/* must be valid */
4714f8829a4aSRandall Stewart 	if (sa1 == NULL || sa2 == NULL)
4715f8829a4aSRandall Stewart 		return (0);
4716f8829a4aSRandall Stewart 
4717f8829a4aSRandall Stewart 	/* must be the same family */
4718f8829a4aSRandall Stewart 	if (sa1->sa_family != sa2->sa_family)
4719f8829a4aSRandall Stewart 		return (0);
4720f8829a4aSRandall Stewart 
47215e2c2d87SRandall Stewart 	switch (sa1->sa_family) {
47225e2c2d87SRandall Stewart #ifdef INET6
47235e2c2d87SRandall Stewart 	case AF_INET6:
47245e2c2d87SRandall Stewart 		{
4725f8829a4aSRandall Stewart 			/* IPv6 addresses */
4726f8829a4aSRandall Stewart 			struct sockaddr_in6 *sin6_1, *sin6_2;
4727f8829a4aSRandall Stewart 
4728f8829a4aSRandall Stewart 			sin6_1 = (struct sockaddr_in6 *)sa1;
4729f8829a4aSRandall Stewart 			sin6_2 = (struct sockaddr_in6 *)sa2;
4730c54a18d2SRandall Stewart 			return (SCTP6_ARE_ADDR_EQUAL(sin6_1,
4731c54a18d2SRandall Stewart 			    sin6_2));
47325e2c2d87SRandall Stewart 		}
47335e2c2d87SRandall Stewart #endif
4734ea5eba11SMichael Tuexen #ifdef INET
47355e2c2d87SRandall Stewart 	case AF_INET:
47365e2c2d87SRandall Stewart 		{
4737f8829a4aSRandall Stewart 			/* IPv4 addresses */
4738f8829a4aSRandall Stewart 			struct sockaddr_in *sin_1, *sin_2;
4739f8829a4aSRandall Stewart 
4740f8829a4aSRandall Stewart 			sin_1 = (struct sockaddr_in *)sa1;
4741f8829a4aSRandall Stewart 			sin_2 = (struct sockaddr_in *)sa2;
4742f8829a4aSRandall Stewart 			return (sin_1->sin_addr.s_addr == sin_2->sin_addr.s_addr);
47435e2c2d87SRandall Stewart 		}
4744ea5eba11SMichael Tuexen #endif
47455e2c2d87SRandall Stewart 	default:
4746f8829a4aSRandall Stewart 		/* we don't do these... */
4747f8829a4aSRandall Stewart 		return (0);
4748f8829a4aSRandall Stewart 	}
4749f8829a4aSRandall Stewart }
4750f8829a4aSRandall Stewart 
4751f8829a4aSRandall Stewart void
4752f8829a4aSRandall Stewart sctp_print_address(struct sockaddr *sa)
4753f8829a4aSRandall Stewart {
47545e2c2d87SRandall Stewart #ifdef INET6
47557d32aa0cSBjoern A. Zeeb 	char ip6buf[INET6_ADDRSTRLEN];
47565e2c2d87SRandall Stewart #endif
47575e2c2d87SRandall Stewart 
47585e2c2d87SRandall Stewart 	switch (sa->sa_family) {
47595e2c2d87SRandall Stewart #ifdef INET6
47605e2c2d87SRandall Stewart 	case AF_INET6:
47615e2c2d87SRandall Stewart 		{
4762ad81507eSRandall Stewart 			struct sockaddr_in6 *sin6;
4763ad81507eSRandall Stewart 
4764f8829a4aSRandall Stewart 			sin6 = (struct sockaddr_in6 *)sa;
4765ad81507eSRandall Stewart 			SCTP_PRINTF("IPv6 address: %s:port:%d scope:%u\n",
47667d32aa0cSBjoern A. Zeeb 			    ip6_sprintf(ip6buf, &sin6->sin6_addr),
47677d32aa0cSBjoern A. Zeeb 			    ntohs(sin6->sin6_port),
4768f8829a4aSRandall Stewart 			    sin6->sin6_scope_id);
47695e2c2d87SRandall Stewart 			break;
47705e2c2d87SRandall Stewart 		}
47715e2c2d87SRandall Stewart #endif
4772ea5eba11SMichael Tuexen #ifdef INET
47735e2c2d87SRandall Stewart 	case AF_INET:
47745e2c2d87SRandall Stewart 		{
4775f8829a4aSRandall Stewart 			struct sockaddr_in *sin;
4776f8829a4aSRandall Stewart 			unsigned char *p;
4777f8829a4aSRandall Stewart 
4778f8829a4aSRandall Stewart 			sin = (struct sockaddr_in *)sa;
4779f8829a4aSRandall Stewart 			p = (unsigned char *)&sin->sin_addr;
4780ad81507eSRandall Stewart 			SCTP_PRINTF("IPv4 address: %u.%u.%u.%u:%d\n",
4781f8829a4aSRandall Stewart 			    p[0], p[1], p[2], p[3], ntohs(sin->sin_port));
47825e2c2d87SRandall Stewart 			break;
47835e2c2d87SRandall Stewart 		}
4784ea5eba11SMichael Tuexen #endif
47855e2c2d87SRandall Stewart 	default:
4786ad81507eSRandall Stewart 		SCTP_PRINTF("?\n");
47875e2c2d87SRandall Stewart 		break;
4788f8829a4aSRandall Stewart 	}
4789f8829a4aSRandall Stewart }
4790f8829a4aSRandall Stewart 
4791f8829a4aSRandall Stewart void
4792f8829a4aSRandall Stewart sctp_pull_off_control_to_new_inp(struct sctp_inpcb *old_inp,
4793f8829a4aSRandall Stewart     struct sctp_inpcb *new_inp,
4794d06c82f1SRandall Stewart     struct sctp_tcb *stcb,
4795d06c82f1SRandall Stewart     int waitflags)
4796f8829a4aSRandall Stewart {
4797f8829a4aSRandall Stewart 	/*
4798f8829a4aSRandall Stewart 	 * go through our old INP and pull off any control structures that
4799f8829a4aSRandall Stewart 	 * belong to stcb and move then to the new inp.
4800f8829a4aSRandall Stewart 	 */
4801f8829a4aSRandall Stewart 	struct socket *old_so, *new_so;
4802f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control, *nctl;
4803f8829a4aSRandall Stewart 	struct sctp_readhead tmp_queue;
4804f8829a4aSRandall Stewart 	struct mbuf *m;
4805bff64a4dSRandall Stewart 	int error = 0;
4806f8829a4aSRandall Stewart 
4807f8829a4aSRandall Stewart 	old_so = old_inp->sctp_socket;
4808f8829a4aSRandall Stewart 	new_so = new_inp->sctp_socket;
4809f8829a4aSRandall Stewart 	TAILQ_INIT(&tmp_queue);
4810f94acf52SMark Johnston 	error = SOCK_IO_RECV_LOCK(old_so, waitflags);
4811f8829a4aSRandall Stewart 	if (error) {
4812f8829a4aSRandall Stewart 		/*
4813f94acf52SMark Johnston 		 * Gak, can't get I/O lock, we have a problem. data will be
4814f8829a4aSRandall Stewart 		 * left stranded.. and we don't dare look at it since the
4815f8829a4aSRandall Stewart 		 * other thread may be reading something. Oh well, its a
4816f8829a4aSRandall Stewart 		 * screwed up app that does a peeloff OR a accept while
4817f8829a4aSRandall Stewart 		 * reading from the main socket... actually its only the
4818f8829a4aSRandall Stewart 		 * peeloff() case, since I think read will fail on a
4819f8829a4aSRandall Stewart 		 * listening socket..
4820f8829a4aSRandall Stewart 		 */
4821f8829a4aSRandall Stewart 		return;
4822f8829a4aSRandall Stewart 	}
4823f8829a4aSRandall Stewart 	/* lock the socket buffers */
4824f8829a4aSRandall Stewart 	SCTP_INP_READ_LOCK(old_inp);
48254a9ef3f8SMichael Tuexen 	TAILQ_FOREACH_SAFE(control, &old_inp->read_queue, next, nctl) {
4826f8829a4aSRandall Stewart 		/* Pull off all for out target stcb */
4827f8829a4aSRandall Stewart 		if (control->stcb == stcb) {
4828f8829a4aSRandall Stewart 			/* remove it we want it */
4829f8829a4aSRandall Stewart 			TAILQ_REMOVE(&old_inp->read_queue, control, next);
4830f8829a4aSRandall Stewart 			TAILQ_INSERT_TAIL(&tmp_queue, control, next);
4831f8829a4aSRandall Stewart 			m = control->data;
4832f8829a4aSRandall Stewart 			while (m) {
4833b3f1ea41SRandall Stewart 				if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4834139bc87fSRandall Stewart 					sctp_sblog(&old_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
483580fefe0aSRandall Stewart 				}
4836f8829a4aSRandall Stewart 				sctp_sbfree(control, stcb, &old_so->so_rcv, m);
4837b3f1ea41SRandall Stewart 				if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4838f8829a4aSRandall Stewart 					sctp_sblog(&old_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
483980fefe0aSRandall Stewart 				}
4840139bc87fSRandall Stewart 				m = SCTP_BUF_NEXT(m);
4841f8829a4aSRandall Stewart 			}
4842f8829a4aSRandall Stewart 		}
4843f8829a4aSRandall Stewart 	}
4844f8829a4aSRandall Stewart 	SCTP_INP_READ_UNLOCK(old_inp);
4845f94acf52SMark Johnston 	/* Remove the recv-lock on the old socket */
4846f94acf52SMark Johnston 	SOCK_IO_RECV_UNLOCK(old_so);
4847f8829a4aSRandall Stewart 	/* Now we move them over to the new socket buffer */
4848f8829a4aSRandall Stewart 	SCTP_INP_READ_LOCK(new_inp);
48494a9ef3f8SMichael Tuexen 	TAILQ_FOREACH_SAFE(control, &tmp_queue, next, nctl) {
4850f8829a4aSRandall Stewart 		TAILQ_INSERT_TAIL(&new_inp->read_queue, control, next);
4851f8829a4aSRandall Stewart 		m = control->data;
4852f8829a4aSRandall Stewart 		while (m) {
4853b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4854139bc87fSRandall Stewart 				sctp_sblog(&new_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m));
485580fefe0aSRandall Stewart 			}
4856f8829a4aSRandall Stewart 			sctp_sballoc(stcb, &new_so->so_rcv, m);
4857b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4858f8829a4aSRandall Stewart 				sctp_sblog(&new_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
485980fefe0aSRandall Stewart 			}
4860139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
4861f8829a4aSRandall Stewart 		}
4862f8829a4aSRandall Stewart 	}
4863f8829a4aSRandall Stewart 	SCTP_INP_READ_UNLOCK(new_inp);
4864f8829a4aSRandall Stewart }
4865f8829a4aSRandall Stewart 
4866f8829a4aSRandall Stewart void
4867b1deed45SMichael Tuexen sctp_wakeup_the_read_socket(struct sctp_inpcb *inp,
4868b1deed45SMichael Tuexen     struct sctp_tcb *stcb,
4869b1deed45SMichael Tuexen     int so_locked
4870b1deed45SMichael Tuexen     SCTP_UNUSED
4871b1deed45SMichael Tuexen )
487244249214SRandall Stewart {
48733dc57df9SMichael Tuexen 	if ((inp != NULL) &&
48743dc57df9SMichael Tuexen 	    (inp->sctp_socket != NULL) &&
4875bbf3bf32SMichael Tuexen 	    (((inp->sctp_flags & (SCTP_PCB_FLAGS_TCPTYPE | SCTP_PCB_FLAGS_IN_TCPPOOL)) == 0) ||
48763dc57df9SMichael Tuexen 	    !SCTP_IS_LISTENING(inp))) {
487744249214SRandall Stewart 		sctp_sorwakeup(inp, inp->sctp_socket);
487844249214SRandall Stewart 	}
487944249214SRandall Stewart }
488044249214SRandall Stewart 
488144249214SRandall Stewart void
4882f8829a4aSRandall Stewart sctp_add_to_readq(struct sctp_inpcb *inp,
4883f8829a4aSRandall Stewart     struct sctp_tcb *stcb,
4884f8829a4aSRandall Stewart     struct sctp_queued_to_read *control,
4885f8829a4aSRandall Stewart     struct sockbuf *sb,
4886ceaad40aSRandall Stewart     int end,
4887cfde3ff7SRandall Stewart     int inp_read_lock_held,
488828397ac1SMichael Tuexen     int so_locked)
4889f8829a4aSRandall Stewart {
4890f8829a4aSRandall Stewart 	/*
4891f8829a4aSRandall Stewart 	 * Here we must place the control on the end of the socket read
48924e88d37aSMichael Tuexen 	 * queue AND increment sb_cc so that select will work properly on
4893f8829a4aSRandall Stewart 	 * read.
4894f8829a4aSRandall Stewart 	 */
4895f8829a4aSRandall Stewart 	struct mbuf *m, *prev = NULL;
4896f8829a4aSRandall Stewart 
489703b0b021SRandall Stewart 	if (inp == NULL) {
489803b0b021SRandall Stewart 		/* Gak, TSNH!! */
4899a5d547adSRandall Stewart #ifdef INVARIANTS
490003b0b021SRandall Stewart 		panic("Gak, inp NULL on add_to_readq");
490103b0b021SRandall Stewart #endif
490203b0b021SRandall Stewart 		return;
490303b0b021SRandall Stewart 	}
4904490a0f77SMichael Tuexen 	if (inp_read_lock_held == SCTP_READ_LOCK_NOT_HELD) {
4905f8829a4aSRandall Stewart 		SCTP_INP_READ_LOCK(inp);
4906490a0f77SMichael Tuexen 	}
4907cd1386abSMichael Tuexen 	if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_CANT_READ) {
49088a3cfbffSMichael Tuexen 		if (!control->on_strm_q) {
4909cd1386abSMichael Tuexen 			sctp_free_remote_addr(control->whoFrom);
4910cd1386abSMichael Tuexen 			if (control->data) {
4911cd1386abSMichael Tuexen 				sctp_m_freem(control->data);
4912cd1386abSMichael Tuexen 				control->data = NULL;
4913cd1386abSMichael Tuexen 			}
491444249214SRandall Stewart 			sctp_free_a_readq(stcb, control);
49158a3cfbffSMichael Tuexen 		}
4916490a0f77SMichael Tuexen 		if (inp_read_lock_held == SCTP_READ_LOCK_NOT_HELD) {
4917cd1386abSMichael Tuexen 			SCTP_INP_READ_UNLOCK(inp);
4918490a0f77SMichael Tuexen 		}
4919cd1386abSMichael Tuexen 		return;
4920cd1386abSMichael Tuexen 	}
49219b2a35b3SMichael Tuexen 	if ((control->spec_flags & M_NOTIFICATION) == 0) {
4922a5d547adSRandall Stewart 		atomic_add_int(&inp->total_recvs, 1);
492342551e99SRandall Stewart 		if (!control->do_not_ref_stcb) {
4924a5d547adSRandall Stewart 			atomic_add_int(&stcb->total_recvs, 1);
492542551e99SRandall Stewart 		}
492642551e99SRandall Stewart 	}
4927f8829a4aSRandall Stewart 	m = control->data;
4928f8829a4aSRandall Stewart 	control->held_length = 0;
4929f8829a4aSRandall Stewart 	control->length = 0;
4930490a0f77SMichael Tuexen 	while (m != NULL) {
4931139bc87fSRandall Stewart 		if (SCTP_BUF_LEN(m) == 0) {
4932f8829a4aSRandall Stewart 			/* Skip mbufs with NO length */
4933f8829a4aSRandall Stewart 			if (prev == NULL) {
4934f8829a4aSRandall Stewart 				/* First one */
4935f8829a4aSRandall Stewart 				control->data = sctp_m_free(m);
4936f8829a4aSRandall Stewart 				m = control->data;
4937f8829a4aSRandall Stewart 			} else {
4938139bc87fSRandall Stewart 				SCTP_BUF_NEXT(prev) = sctp_m_free(m);
4939139bc87fSRandall Stewart 				m = SCTP_BUF_NEXT(prev);
4940f8829a4aSRandall Stewart 			}
4941f8829a4aSRandall Stewart 			if (m == NULL) {
4942c2ede4b3SMartin Blapp 				control->tail_mbuf = prev;
4943f8829a4aSRandall Stewart 			}
4944f8829a4aSRandall Stewart 			continue;
4945f8829a4aSRandall Stewart 		}
4946f8829a4aSRandall Stewart 		prev = m;
4947b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4948139bc87fSRandall Stewart 			sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m));
494980fefe0aSRandall Stewart 		}
4950f8829a4aSRandall Stewart 		sctp_sballoc(stcb, sb, m);
4951b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4952f8829a4aSRandall Stewart 			sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
495380fefe0aSRandall Stewart 		}
4954139bc87fSRandall Stewart 		atomic_add_int(&control->length, SCTP_BUF_LEN(m));
4955139bc87fSRandall Stewart 		m = SCTP_BUF_NEXT(m);
4956f8829a4aSRandall Stewart 	}
4957f8829a4aSRandall Stewart 	if (prev != NULL) {
4958f8829a4aSRandall Stewart 		control->tail_mbuf = prev;
4959f8829a4aSRandall Stewart 	} else {
4960139bc87fSRandall Stewart 		/* Everything got collapsed out?? */
49618a3cfbffSMichael Tuexen 		if (!control->on_strm_q) {
4962cd1386abSMichael Tuexen 			sctp_free_remote_addr(control->whoFrom);
496344249214SRandall Stewart 			sctp_free_a_readq(stcb, control);
49648a3cfbffSMichael Tuexen 		}
4965cfde3ff7SRandall Stewart 		if (inp_read_lock_held == 0)
496647a490cbSMichael Tuexen 			SCTP_INP_READ_UNLOCK(inp);
4967f8829a4aSRandall Stewart 		return;
4968f8829a4aSRandall Stewart 	}
4969f8829a4aSRandall Stewart 	if (end) {
4970f8829a4aSRandall Stewart 		control->end_added = 1;
4971f8829a4aSRandall Stewart 	}
4972f8829a4aSRandall Stewart 	TAILQ_INSERT_TAIL(&inp->read_queue, control, next);
497344249214SRandall Stewart 	control->on_read_q = 1;
4974490a0f77SMichael Tuexen 	if ((inp != NULL) && (inp->sctp_socket != NULL)) {
4975b1deed45SMichael Tuexen 		sctp_wakeup_the_read_socket(inp, stcb, so_locked);
4976f8829a4aSRandall Stewart 	}
4977490a0f77SMichael Tuexen 	if (inp_read_lock_held == SCTP_READ_LOCK_NOT_HELD) {
4978490a0f77SMichael Tuexen 		SCTP_INP_READ_UNLOCK(inp);
4979490a0f77SMichael Tuexen 	}
4980f8829a4aSRandall Stewart }
4981f8829a4aSRandall Stewart 
4982f8829a4aSRandall Stewart /*************HOLD THIS COMMENT FOR PATCH FILE OF
4983f8829a4aSRandall Stewart  *************ALTERNATE ROUTING CODE
4984f8829a4aSRandall Stewart  */
4985f8829a4aSRandall Stewart 
4986f8829a4aSRandall Stewart /*************HOLD THIS COMMENT FOR END OF PATCH FILE OF
4987f8829a4aSRandall Stewart  *************ALTERNATE ROUTING CODE
4988f8829a4aSRandall Stewart  */
4989f8829a4aSRandall Stewart 
4990f8829a4aSRandall Stewart struct mbuf *
4991ff1ffd74SMichael Tuexen sctp_generate_cause(uint16_t code, char *info)
4992f8829a4aSRandall Stewart {
4993f8829a4aSRandall Stewart 	struct mbuf *m;
4994ff1ffd74SMichael Tuexen 	struct sctp_gen_error_cause *cause;
49959a8e3088SMichael Tuexen 	size_t info_len;
49969a8e3088SMichael Tuexen 	uint16_t len;
4997f8829a4aSRandall Stewart 
4998ff1ffd74SMichael Tuexen 	if ((code == 0) || (info == NULL)) {
4999ff1ffd74SMichael Tuexen 		return (NULL);
5000ff1ffd74SMichael Tuexen 	}
5001ff1ffd74SMichael Tuexen 	info_len = strlen(info);
50029a8e3088SMichael Tuexen 	if (info_len > (SCTP_MAX_CAUSE_LENGTH - sizeof(struct sctp_paramhdr))) {
50039a8e3088SMichael Tuexen 		return (NULL);
50049a8e3088SMichael Tuexen 	}
50059a8e3088SMichael Tuexen 	len = (uint16_t)(sizeof(struct sctp_paramhdr) + info_len);
5006ff1ffd74SMichael Tuexen 	m = sctp_get_mbuf_for_msg(len, 0, M_NOWAIT, 1, MT_DATA);
5007ff1ffd74SMichael Tuexen 	if (m != NULL) {
5008ff1ffd74SMichael Tuexen 		SCTP_BUF_LEN(m) = len;
5009ff1ffd74SMichael Tuexen 		cause = mtod(m, struct sctp_gen_error_cause *);
5010ff1ffd74SMichael Tuexen 		cause->code = htons(code);
50119a8e3088SMichael Tuexen 		cause->length = htons(len);
5012ff1ffd74SMichael Tuexen 		memcpy(cause->info, info, info_len);
5013f8829a4aSRandall Stewart 	}
5014f8829a4aSRandall Stewart 	return (m);
5015f8829a4aSRandall Stewart }
5016f8829a4aSRandall Stewart 
501732451da4SMichael Tuexen struct mbuf *
501832451da4SMichael Tuexen sctp_generate_no_user_data_cause(uint32_t tsn)
501932451da4SMichael Tuexen {
502032451da4SMichael Tuexen 	struct mbuf *m;
502132451da4SMichael Tuexen 	struct sctp_error_no_user_data *no_user_data_cause;
50229a8e3088SMichael Tuexen 	uint16_t len;
502332451da4SMichael Tuexen 
50249a8e3088SMichael Tuexen 	len = (uint16_t)sizeof(struct sctp_error_no_user_data);
502532451da4SMichael Tuexen 	m = sctp_get_mbuf_for_msg(len, 0, M_NOWAIT, 1, MT_DATA);
502632451da4SMichael Tuexen 	if (m != NULL) {
502732451da4SMichael Tuexen 		SCTP_BUF_LEN(m) = len;
502832451da4SMichael Tuexen 		no_user_data_cause = mtod(m, struct sctp_error_no_user_data *);
502932451da4SMichael Tuexen 		no_user_data_cause->cause.code = htons(SCTP_CAUSE_NO_USER_DATA);
50309a8e3088SMichael Tuexen 		no_user_data_cause->cause.length = htons(len);
50318b9c95f4SMichael Tuexen 		no_user_data_cause->tsn = htonl(tsn);
503232451da4SMichael Tuexen 	}
503332451da4SMichael Tuexen 	return (m);
503432451da4SMichael Tuexen }
503532451da4SMichael Tuexen 
5036f8829a4aSRandall Stewart void
5037f8829a4aSRandall Stewart sctp_free_bufspace(struct sctp_tcb *stcb, struct sctp_association *asoc,
5038f8829a4aSRandall Stewart     struct sctp_tmit_chunk *tp1, int chk_cnt)
5039f8829a4aSRandall Stewart {
5040f8829a4aSRandall Stewart 	if (tp1->data == NULL) {
5041f8829a4aSRandall Stewart 		return;
5042f8829a4aSRandall Stewart 	}
50435cebd830SMichael Tuexen 	atomic_subtract_int(&asoc->chunks_on_out_queue, chk_cnt);
50445cebd830SMichael Tuexen #ifdef SCTP_MBCNT_LOGGING
5045b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_MBCNT_LOGGING_ENABLE) {
5046f8829a4aSRandall Stewart 		sctp_log_mbcnt(SCTP_LOG_MBCNT_DECREASE,
5047f8829a4aSRandall Stewart 		    asoc->total_output_queue_size,
5048f8829a4aSRandall Stewart 		    tp1->book_size,
5049f8829a4aSRandall Stewart 		    0,
5050f8829a4aSRandall Stewart 		    tp1->mbcnt);
505180fefe0aSRandall Stewart 	}
50525cebd830SMichael Tuexen #endif
5053f8829a4aSRandall Stewart 	if (asoc->total_output_queue_size >= tp1->book_size) {
50545cebd830SMichael Tuexen 		atomic_subtract_int(&asoc->total_output_queue_size, tp1->book_size);
5055f8829a4aSRandall Stewart 	} else {
5056f8829a4aSRandall Stewart 		asoc->total_output_queue_size = 0;
5057f8829a4aSRandall Stewart 	}
50585cebd830SMichael Tuexen 	if ((stcb->sctp_socket != NULL) &&
50595cebd830SMichael Tuexen 	    (((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) ||
5060f8829a4aSRandall Stewart 	    ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE)))) {
5061c6207881SMichael Tuexen 		SCTP_SB_DECR(&stcb->sctp_socket->so_snd, tp1->book_size);
5062f8829a4aSRandall Stewart 	}
5063f8829a4aSRandall Stewart }
5064f8829a4aSRandall Stewart 
5065f8829a4aSRandall Stewart int
5066f8829a4aSRandall Stewart sctp_release_pr_sctp_chunk(struct sctp_tcb *stcb, struct sctp_tmit_chunk *tp1,
506728397ac1SMichael Tuexen     uint8_t sent, int so_locked)
5068f8829a4aSRandall Stewart {
50690c0982b8SRandall Stewart 	struct sctp_stream_out *strq;
50704a9ef3f8SMichael Tuexen 	struct sctp_tmit_chunk *chk = NULL, *tp2;
50710c0982b8SRandall Stewart 	struct sctp_stream_queue_pending *sp;
507249656eefSMichael Tuexen 	uint32_t mid;
507349656eefSMichael Tuexen 	uint16_t sid;
50740c0982b8SRandall Stewart 	uint8_t foundeom = 0;
5075f8829a4aSRandall Stewart 	int ret_sz = 0;
5076f8829a4aSRandall Stewart 	int notdone;
50770c0982b8SRandall Stewart 	int do_wakeup_routine = 0;
5078f8829a4aSRandall Stewart 
50795ac91821SMichael Tuexen 	SCTP_TCB_LOCK_ASSERT(stcb);
50805ac91821SMichael Tuexen 
508149656eefSMichael Tuexen 	sid = tp1->rec.data.sid;
508249656eefSMichael Tuexen 	mid = tp1->rec.data.mid;
50839b2a35b3SMichael Tuexen 	if (sent || ((tp1->rec.data.rcv_flags & SCTP_DATA_FIRST_FRAG) == 0)) {
5084f0396ad1SMichael Tuexen 		stcb->asoc.abandoned_sent[0]++;
5085f0396ad1SMichael Tuexen 		stcb->asoc.abandoned_sent[PR_SCTP_POLICY(tp1->flags)]++;
508649656eefSMichael Tuexen 		stcb->asoc.strmout[sid].abandoned_sent[0]++;
5087f0396ad1SMichael Tuexen #if defined(SCTP_DETAILED_STR_STATS)
5088ad15e154SMichael Tuexen 		stcb->asoc.strmout[sid].abandoned_sent[PR_SCTP_POLICY(tp1->flags)]++;
5089f0396ad1SMichael Tuexen #endif
5090f0396ad1SMichael Tuexen 	} else {
5091f0396ad1SMichael Tuexen 		stcb->asoc.abandoned_unsent[0]++;
5092f0396ad1SMichael Tuexen 		stcb->asoc.abandoned_unsent[PR_SCTP_POLICY(tp1->flags)]++;
509349656eefSMichael Tuexen 		stcb->asoc.strmout[sid].abandoned_unsent[0]++;
5094f0396ad1SMichael Tuexen #if defined(SCTP_DETAILED_STR_STATS)
5095ad15e154SMichael Tuexen 		stcb->asoc.strmout[sid].abandoned_unsent[PR_SCTP_POLICY(tp1->flags)]++;
5096f0396ad1SMichael Tuexen #endif
5097f0396ad1SMichael Tuexen 	}
5098f8829a4aSRandall Stewart 	do {
5099f8829a4aSRandall Stewart 		ret_sz += tp1->book_size;
51000c0982b8SRandall Stewart 		if (tp1->data != NULL) {
51018933fa13SRandall Stewart 			if (tp1->sent < SCTP_DATAGRAM_RESEND) {
5102830d754dSRandall Stewart 				sctp_flight_size_decrease(tp1);
5103830d754dSRandall Stewart 				sctp_total_flight_decrease(stcb, tp1);
51048933fa13SRandall Stewart 			}
51058933fa13SRandall Stewart 			sctp_free_bufspace(stcb, &stcb->asoc, tp1, 1);
51060c0982b8SRandall Stewart 			stcb->asoc.peers_rwnd += tp1->send_size;
51070c0982b8SRandall Stewart 			stcb->asoc.peers_rwnd += SCTP_BASE_SYSCTL(sctp_peer_chunk_oh);
51081edc9dbaSMichael Tuexen 			if (sent) {
51091edc9dbaSMichael Tuexen 				sctp_ulp_notify(SCTP_NOTIFY_SENT_DG_FAIL, stcb, 0, tp1, so_locked);
51101edc9dbaSMichael Tuexen 			} else {
51111edc9dbaSMichael Tuexen 				sctp_ulp_notify(SCTP_NOTIFY_UNSENT_DG_FAIL, stcb, 0, tp1, so_locked);
51121edc9dbaSMichael Tuexen 			}
51132f99457bSMichael Tuexen 			if (tp1->data) {
5114f8829a4aSRandall Stewart 				sctp_m_freem(tp1->data);
5115f8829a4aSRandall Stewart 				tp1->data = NULL;
51162f99457bSMichael Tuexen 			}
51170c0982b8SRandall Stewart 			do_wakeup_routine = 1;
5118f8829a4aSRandall Stewart 			if (PR_SCTP_BUF_ENABLED(tp1->flags)) {
5119f8829a4aSRandall Stewart 				stcb->asoc.sent_queue_cnt_removeable--;
5120f8829a4aSRandall Stewart 			}
5121f8829a4aSRandall Stewart 		}
51228933fa13SRandall Stewart 		tp1->sent = SCTP_FORWARD_TSN_SKIP;
5123f8829a4aSRandall Stewart 		if ((tp1->rec.data.rcv_flags & SCTP_DATA_NOT_FRAG) ==
5124f8829a4aSRandall Stewart 		    SCTP_DATA_NOT_FRAG) {
5125f8829a4aSRandall Stewart 			/* not frag'ed we ae done   */
5126f8829a4aSRandall Stewart 			notdone = 0;
5127f8829a4aSRandall Stewart 			foundeom = 1;
5128f8829a4aSRandall Stewart 		} else if (tp1->rec.data.rcv_flags & SCTP_DATA_LAST_FRAG) {
5129f8829a4aSRandall Stewart 			/* end of frag, we are done */
5130f8829a4aSRandall Stewart 			notdone = 0;
5131f8829a4aSRandall Stewart 			foundeom = 1;
5132f8829a4aSRandall Stewart 		} else {
5133f8829a4aSRandall Stewart 			/*
5134f8829a4aSRandall Stewart 			 * Its a begin or middle piece, we must mark all of
5135f8829a4aSRandall Stewart 			 * it
5136f8829a4aSRandall Stewart 			 */
5137f8829a4aSRandall Stewart 			notdone = 1;
5138f8829a4aSRandall Stewart 			tp1 = TAILQ_NEXT(tp1, sctp_next);
5139f8829a4aSRandall Stewart 		}
5140f8829a4aSRandall Stewart 	} while (tp1 && notdone);
51410c0982b8SRandall Stewart 	if (foundeom == 0) {
5142f8829a4aSRandall Stewart 		/*
5143f8829a4aSRandall Stewart 		 * The multi-part message was scattered across the send and
5144f8829a4aSRandall Stewart 		 * sent queue.
5145f8829a4aSRandall Stewart 		 */
51464a9ef3f8SMichael Tuexen 		TAILQ_FOREACH_SAFE(tp1, &stcb->asoc.send_queue, sctp_next, tp2) {
514749656eefSMichael Tuexen 			if ((tp1->rec.data.sid != sid) ||
514849656eefSMichael Tuexen 			    (!SCTP_MID_EQ(stcb->asoc.idata_supported, tp1->rec.data.mid, mid))) {
51494a9ef3f8SMichael Tuexen 				break;
51504a9ef3f8SMichael Tuexen 			}
51510c0982b8SRandall Stewart 			/*
51520c0982b8SRandall Stewart 			 * save to chk in case we have some on stream out
51530c0982b8SRandall Stewart 			 * queue. If so and we have an un-transmitted one we
51540c0982b8SRandall Stewart 			 * don't have to fudge the TSN.
51550c0982b8SRandall Stewart 			 */
51560c0982b8SRandall Stewart 			chk = tp1;
51570c0982b8SRandall Stewart 			ret_sz += tp1->book_size;
51580c0982b8SRandall Stewart 			sctp_free_bufspace(stcb, &stcb->asoc, tp1, 1);
51591edc9dbaSMichael Tuexen 			if (sent) {
51601edc9dbaSMichael Tuexen 				sctp_ulp_notify(SCTP_NOTIFY_SENT_DG_FAIL, stcb, 0, tp1, so_locked);
51611edc9dbaSMichael Tuexen 			} else {
51621edc9dbaSMichael Tuexen 				sctp_ulp_notify(SCTP_NOTIFY_UNSENT_DG_FAIL, stcb, 0, tp1, so_locked);
51631edc9dbaSMichael Tuexen 			}
51642f99457bSMichael Tuexen 			if (tp1->data) {
51650c0982b8SRandall Stewart 				sctp_m_freem(tp1->data);
51662f99457bSMichael Tuexen 				tp1->data = NULL;
51672f99457bSMichael Tuexen 			}
51688933fa13SRandall Stewart 			/* No flight involved here book the size to 0 */
51698933fa13SRandall Stewart 			tp1->book_size = 0;
51700c0982b8SRandall Stewart 			if (tp1->rec.data.rcv_flags & SCTP_DATA_LAST_FRAG) {
51710c0982b8SRandall Stewart 				foundeom = 1;
5172f8829a4aSRandall Stewart 			}
51730c0982b8SRandall Stewart 			do_wakeup_routine = 1;
51740c0982b8SRandall Stewart 			tp1->sent = SCTP_FORWARD_TSN_SKIP;
51750c0982b8SRandall Stewart 			TAILQ_REMOVE(&stcb->asoc.send_queue, tp1, sctp_next);
5176b7b84c0eSMichael Tuexen 			/*
5177b7b84c0eSMichael Tuexen 			 * on to the sent queue so we can wait for it to be
5178b7b84c0eSMichael Tuexen 			 * passed by.
5179b7b84c0eSMichael Tuexen 			 */
51800c0982b8SRandall Stewart 			TAILQ_INSERT_TAIL(&stcb->asoc.sent_queue, tp1,
51810c0982b8SRandall Stewart 			    sctp_next);
51820c0982b8SRandall Stewart 			stcb->asoc.send_queue_cnt--;
51830c0982b8SRandall Stewart 			stcb->asoc.sent_queue_cnt++;
51840c0982b8SRandall Stewart 		}
51850c0982b8SRandall Stewart 	}
51860c0982b8SRandall Stewart 	if (foundeom == 0) {
51870c0982b8SRandall Stewart 		/*
51880c0982b8SRandall Stewart 		 * Still no eom found. That means there is stuff left on the
51890c0982b8SRandall Stewart 		 * stream out queue.. yuck.
51900c0982b8SRandall Stewart 		 */
519149656eefSMichael Tuexen 		strq = &stcb->asoc.strmout[sid];
5192f3b05218SMichael Tuexen 		sp = TAILQ_FIRST(&strq->outqueue);
5193f3b05218SMichael Tuexen 		if (sp != NULL) {
51940c0982b8SRandall Stewart 			sp->discard_rest = 1;
51950c0982b8SRandall Stewart 			/*
5196f3b05218SMichael Tuexen 			 * We may need to put a chunk on the queue that
5197f3b05218SMichael Tuexen 			 * holds the TSN that would have been sent with the
5198f3b05218SMichael Tuexen 			 * LAST bit.
51990c0982b8SRandall Stewart 			 */
52000c0982b8SRandall Stewart 			if (chk == NULL) {
52010c0982b8SRandall Stewart 				/* Yep, we have to */
52020c0982b8SRandall Stewart 				sctp_alloc_a_chunk(stcb, chk);
52030c0982b8SRandall Stewart 				if (chk == NULL) {
52040c0982b8SRandall Stewart 					/*
5205f3b05218SMichael Tuexen 					 * we are hosed. All we can do is
5206f3b05218SMichael Tuexen 					 * nothing.. which will cause an
5207f3b05218SMichael Tuexen 					 * abort if the peer is paying
52080c0982b8SRandall Stewart 					 * attention.
52090c0982b8SRandall Stewart 					 */
52100c0982b8SRandall Stewart 					goto oh_well;
52110c0982b8SRandall Stewart 				}
52120c0982b8SRandall Stewart 				memset(chk, 0, sizeof(*chk));
521363d5b568SMichael Tuexen 				chk->rec.data.rcv_flags = 0;
52140c0982b8SRandall Stewart 				chk->sent = SCTP_FORWARD_TSN_SKIP;
52150c0982b8SRandall Stewart 				chk->asoc = &stcb->asoc;
521663d5b568SMichael Tuexen 				if (stcb->asoc.idata_supported == 0) {
521763d5b568SMichael Tuexen 					if (sp->sinfo_flags & SCTP_UNORDERED) {
521849656eefSMichael Tuexen 						chk->rec.data.mid = 0;
521963d5b568SMichael Tuexen 					} else {
522049656eefSMichael Tuexen 						chk->rec.data.mid = strq->next_mid_ordered;
522163d5b568SMichael Tuexen 					}
522263d5b568SMichael Tuexen 				} else {
522363d5b568SMichael Tuexen 					if (sp->sinfo_flags & SCTP_UNORDERED) {
522449656eefSMichael Tuexen 						chk->rec.data.mid = strq->next_mid_unordered;
522563d5b568SMichael Tuexen 					} else {
522649656eefSMichael Tuexen 						chk->rec.data.mid = strq->next_mid_ordered;
522763d5b568SMichael Tuexen 					}
522863d5b568SMichael Tuexen 				}
522949656eefSMichael Tuexen 				chk->rec.data.sid = sp->sid;
523049656eefSMichael Tuexen 				chk->rec.data.ppid = sp->ppid;
52310c0982b8SRandall Stewart 				chk->rec.data.context = sp->context;
52320c0982b8SRandall Stewart 				chk->flags = sp->act_flags;
52337fd5b436SMichael Tuexen 				chk->whoTo = NULL;
523449656eefSMichael Tuexen 				chk->rec.data.tsn = atomic_fetchadd_int(&stcb->asoc.sending_seq, 1);
52357fd5b436SMichael Tuexen 				strq->chunks_on_queues++;
52360c0982b8SRandall Stewart 				TAILQ_INSERT_TAIL(&stcb->asoc.sent_queue, chk, sctp_next);
52370c0982b8SRandall Stewart 				stcb->asoc.sent_queue_cnt++;
52388933fa13SRandall Stewart 				stcb->asoc.pr_sctp_cnt++;
52390c0982b8SRandall Stewart 			}
524063d5b568SMichael Tuexen 			chk->rec.data.rcv_flags |= SCTP_DATA_LAST_FRAG;
5241d1ea5fa9SMichael Tuexen 			if (sp->sinfo_flags & SCTP_UNORDERED) {
5242d1ea5fa9SMichael Tuexen 				chk->rec.data.rcv_flags |= SCTP_DATA_UNORDERED;
5243d1ea5fa9SMichael Tuexen 			}
524463d5b568SMichael Tuexen 			if (stcb->asoc.idata_supported == 0) {
524563d5b568SMichael Tuexen 				if ((sp->sinfo_flags & SCTP_UNORDERED) == 0) {
524663d5b568SMichael Tuexen 					strq->next_mid_ordered++;
524763d5b568SMichael Tuexen 				}
524863d5b568SMichael Tuexen 			} else {
524963d5b568SMichael Tuexen 				if (sp->sinfo_flags & SCTP_UNORDERED) {
525063d5b568SMichael Tuexen 					strq->next_mid_unordered++;
525163d5b568SMichael Tuexen 				} else {
525263d5b568SMichael Tuexen 					strq->next_mid_ordered++;
525363d5b568SMichael Tuexen 				}
525463d5b568SMichael Tuexen 			}
52550c0982b8SRandall Stewart 	oh_well:
52560c0982b8SRandall Stewart 			if (sp->data) {
52570c0982b8SRandall Stewart 				/*
5258f3b05218SMichael Tuexen 				 * Pull any data to free up the SB and allow
5259f3b05218SMichael Tuexen 				 * sender to "add more" while we will throw
5260f3b05218SMichael Tuexen 				 * away :-)
52610c0982b8SRandall Stewart 				 */
5262f3b05218SMichael Tuexen 				sctp_free_spbufspace(stcb, &stcb->asoc, sp);
52630c0982b8SRandall Stewart 				ret_sz += sp->length;
52640c0982b8SRandall Stewart 				do_wakeup_routine = 1;
52650c0982b8SRandall Stewart 				sp->some_taken = 1;
52660c0982b8SRandall Stewart 				sctp_m_freem(sp->data);
52670c0982b8SRandall Stewart 				sp->data = NULL;
52680c0982b8SRandall Stewart 				sp->tail_mbuf = NULL;
5269d07b2ac6SMichael Tuexen 				sp->length = 0;
52700c0982b8SRandall Stewart 			}
52710c0982b8SRandall Stewart 		}
52720c0982b8SRandall Stewart 	}
52730c0982b8SRandall Stewart 	if (do_wakeup_routine) {
52740c0982b8SRandall Stewart 		sctp_sowwakeup(stcb->sctp_ep, stcb->sctp_socket);
5275f8829a4aSRandall Stewart 	}
5276f8829a4aSRandall Stewart 	return (ret_sz);
5277f8829a4aSRandall Stewart }
5278f8829a4aSRandall Stewart 
5279f8829a4aSRandall Stewart /*
5280f8829a4aSRandall Stewart  * checks to see if the given address, sa, is one that is currently known by
5281f8829a4aSRandall Stewart  * the kernel note: can't distinguish the same address on multiple interfaces
5282f8829a4aSRandall Stewart  * and doesn't handle multiple addresses with different zone/scope id's note:
5283f8829a4aSRandall Stewart  * ifa_ifwithaddr() compares the entire sockaddr struct
5284f8829a4aSRandall Stewart  */
528542551e99SRandall Stewart struct sctp_ifa *
528680fefe0aSRandall Stewart sctp_find_ifa_in_ep(struct sctp_inpcb *inp, struct sockaddr *addr,
528780fefe0aSRandall Stewart     int holds_lock)
5288f8829a4aSRandall Stewart {
528942551e99SRandall Stewart 	struct sctp_laddr *laddr;
5290f8829a4aSRandall Stewart 
5291ad81507eSRandall Stewart 	if (holds_lock == 0) {
529242551e99SRandall Stewart 		SCTP_INP_RLOCK(inp);
5293ad81507eSRandall Stewart 	}
52940053ed28SMichael Tuexen 
529542551e99SRandall Stewart 	LIST_FOREACH(laddr, &inp->sctp_addr_list, sctp_nxt_addr) {
529642551e99SRandall Stewart 		if (laddr->ifa == NULL)
5297f8829a4aSRandall Stewart 			continue;
529842551e99SRandall Stewart 		if (addr->sa_family != laddr->ifa->address.sa.sa_family)
529942551e99SRandall Stewart 			continue;
5300e6194c2eSMichael Tuexen #ifdef INET
530142551e99SRandall Stewart 		if (addr->sa_family == AF_INET) {
530242551e99SRandall Stewart 			if (((struct sockaddr_in *)addr)->sin_addr.s_addr ==
530342551e99SRandall Stewart 			    laddr->ifa->address.sin.sin_addr.s_addr) {
530442551e99SRandall Stewart 				/* found him. */
530542551e99SRandall Stewart 				break;
530642551e99SRandall Stewart 			}
53075e2c2d87SRandall Stewart 		}
5308e6194c2eSMichael Tuexen #endif
53095e2c2d87SRandall Stewart #ifdef INET6
53105e2c2d87SRandall Stewart 		if (addr->sa_family == AF_INET6) {
5311c54a18d2SRandall Stewart 			if (SCTP6_ARE_ADDR_EQUAL((struct sockaddr_in6 *)addr,
5312c54a18d2SRandall Stewart 			    &laddr->ifa->address.sin6)) {
531342551e99SRandall Stewart 				/* found him. */
531442551e99SRandall Stewart 				break;
531542551e99SRandall Stewart 			}
531642551e99SRandall Stewart 		}
53175e2c2d87SRandall Stewart #endif
531842551e99SRandall Stewart 	}
5319ad81507eSRandall Stewart 	if (holds_lock == 0) {
532042551e99SRandall Stewart 		SCTP_INP_RUNLOCK(inp);
5321ad81507eSRandall Stewart 	}
53227a3f60e7SMichael Tuexen 	if (laddr != NULL) {
532344710431SMichael Tuexen 		return (laddr->ifa);
53247a3f60e7SMichael Tuexen 	} else {
53257a3f60e7SMichael Tuexen 		return (NULL);
53267a3f60e7SMichael Tuexen 	}
532742551e99SRandall Stewart }
5328f8829a4aSRandall Stewart 
53296a27c376SRandall Stewart uint32_t
5330b0471b4bSMichael Tuexen sctp_get_ifa_hash_val(struct sockaddr *addr)
5331b0471b4bSMichael Tuexen {
5332ea5eba11SMichael Tuexen 	switch (addr->sa_family) {
5333ea5eba11SMichael Tuexen #ifdef INET
5334ea5eba11SMichael Tuexen 	case AF_INET:
5335ea5eba11SMichael Tuexen 		{
53366a27c376SRandall Stewart 			struct sockaddr_in *sin;
53376a27c376SRandall Stewart 
53386a27c376SRandall Stewart 			sin = (struct sockaddr_in *)addr;
53396a27c376SRandall Stewart 			return (sin->sin_addr.s_addr ^ (sin->sin_addr.s_addr >> 16));
5340ea5eba11SMichael Tuexen 		}
5341ea5eba11SMichael Tuexen #endif
5342ea5eba11SMichael Tuexen #ifdef INET6
53432c2e3218SMichael Tuexen 	case AF_INET6:
5344ea5eba11SMichael Tuexen 		{
53456a27c376SRandall Stewart 			struct sockaddr_in6 *sin6;
53466a27c376SRandall Stewart 			uint32_t hash_of_addr;
53476a27c376SRandall Stewart 
53486a27c376SRandall Stewart 			sin6 = (struct sockaddr_in6 *)addr;
53496a27c376SRandall Stewart 			hash_of_addr = (sin6->sin6_addr.s6_addr32[0] +
53506a27c376SRandall Stewart 			    sin6->sin6_addr.s6_addr32[1] +
53516a27c376SRandall Stewart 			    sin6->sin6_addr.s6_addr32[2] +
53526a27c376SRandall Stewart 			    sin6->sin6_addr.s6_addr32[3]);
53536a27c376SRandall Stewart 			hash_of_addr = (hash_of_addr ^ (hash_of_addr >> 16));
53546a27c376SRandall Stewart 			return (hash_of_addr);
53556a27c376SRandall Stewart 		}
5356ea5eba11SMichael Tuexen #endif
5357ea5eba11SMichael Tuexen 	default:
5358ea5eba11SMichael Tuexen 		break;
5359ea5eba11SMichael Tuexen 	}
53606a27c376SRandall Stewart 	return (0);
53616a27c376SRandall Stewart }
53626a27c376SRandall Stewart 
536342551e99SRandall Stewart struct sctp_ifa *
536442551e99SRandall Stewart sctp_find_ifa_by_addr(struct sockaddr *addr, uint32_t vrf_id, int holds_lock)
536542551e99SRandall Stewart {
536642551e99SRandall Stewart 	struct sctp_ifa *sctp_ifap;
536742551e99SRandall Stewart 	struct sctp_vrf *vrf;
53686a27c376SRandall Stewart 	struct sctp_ifalist *hash_head;
53696a27c376SRandall Stewart 	uint32_t hash_of_addr;
537042551e99SRandall Stewart 
53717f0ad227SMichael Tuexen 	if (holds_lock == 0) {
5372c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RLOCK();
53737f0ad227SMichael Tuexen 	} else {
53747f0ad227SMichael Tuexen 		SCTP_IPI_ADDR_LOCK_ASSERT();
53757f0ad227SMichael Tuexen 	}
537642551e99SRandall Stewart 
5377bff64a4dSRandall Stewart 	vrf = sctp_find_vrf(vrf_id);
5378bff64a4dSRandall Stewart 	if (vrf == NULL) {
5379bff64a4dSRandall Stewart 		if (holds_lock == 0)
5380c99efcf6SRandall Stewart 			SCTP_IPI_ADDR_RUNLOCK();
5381bff64a4dSRandall Stewart 		return (NULL);
5382bff64a4dSRandall Stewart 	}
53830053ed28SMichael Tuexen 
5384bff64a4dSRandall Stewart 	hash_of_addr = sctp_get_ifa_hash_val(addr);
5385bff64a4dSRandall Stewart 
538617205eccSRandall Stewart 	hash_head = &vrf->vrf_addr_hash[(hash_of_addr & vrf->vrf_addr_hashmark)];
5387bff64a4dSRandall Stewart 	if (hash_head == NULL) {
5388ad81507eSRandall Stewart 		SCTP_PRINTF("hash_of_addr:%x mask:%x table:%x - ",
5389c99efcf6SRandall Stewart 		    hash_of_addr, (uint32_t)vrf->vrf_addr_hashmark,
5390c99efcf6SRandall Stewart 		    (uint32_t)(hash_of_addr & vrf->vrf_addr_hashmark));
5391bff64a4dSRandall Stewart 		sctp_print_address(addr);
5392ad81507eSRandall Stewart 		SCTP_PRINTF("No such bucket for address\n");
5393bff64a4dSRandall Stewart 		if (holds_lock == 0)
5394c99efcf6SRandall Stewart 			SCTP_IPI_ADDR_RUNLOCK();
5395bff64a4dSRandall Stewart 
5396bff64a4dSRandall Stewart 		return (NULL);
5397bff64a4dSRandall Stewart 	}
53986a27c376SRandall Stewart 	LIST_FOREACH(sctp_ifap, hash_head, next_bucket) {
53996a27c376SRandall Stewart 		if (addr->sa_family != sctp_ifap->address.sa.sa_family)
54006a27c376SRandall Stewart 			continue;
5401e6194c2eSMichael Tuexen #ifdef INET
54026a27c376SRandall Stewart 		if (addr->sa_family == AF_INET) {
54036a27c376SRandall Stewart 			if (((struct sockaddr_in *)addr)->sin_addr.s_addr ==
54046a27c376SRandall Stewart 			    sctp_ifap->address.sin.sin_addr.s_addr) {
54056a27c376SRandall Stewart 				/* found him. */
54066a27c376SRandall Stewart 				break;
54076a27c376SRandall Stewart 			}
54085e2c2d87SRandall Stewart 		}
5409e6194c2eSMichael Tuexen #endif
54105e2c2d87SRandall Stewart #ifdef INET6
54115e2c2d87SRandall Stewart 		if (addr->sa_family == AF_INET6) {
5412c54a18d2SRandall Stewart 			if (SCTP6_ARE_ADDR_EQUAL((struct sockaddr_in6 *)addr,
5413c54a18d2SRandall Stewart 			    &sctp_ifap->address.sin6)) {
54146a27c376SRandall Stewart 				/* found him. */
54156a27c376SRandall Stewart 				break;
54166a27c376SRandall Stewart 			}
541742551e99SRandall Stewart 		}
54185e2c2d87SRandall Stewart #endif
541942551e99SRandall Stewart 	}
542042551e99SRandall Stewart 	if (holds_lock == 0)
5421c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RUNLOCK();
542244710431SMichael Tuexen 	return (sctp_ifap);
5423f8829a4aSRandall Stewart }
5424f8829a4aSRandall Stewart 
5425f8829a4aSRandall Stewart static void
54264c9179adSRandall Stewart sctp_user_rcvd(struct sctp_tcb *stcb, uint32_t *freed_so_far, int hold_rlock,
5427f8829a4aSRandall Stewart     uint32_t rwnd_req)
5428f8829a4aSRandall Stewart {
5429f8829a4aSRandall Stewart 	/* User pulled some data, do we need a rwnd update? */
5430868b51f2SMichael Tuexen 	struct epoch_tracker et;
5431f8829a4aSRandall Stewart 	int r_unlocked = 0;
5432f8829a4aSRandall Stewart 	uint32_t dif, rwnd;
5433f8829a4aSRandall Stewart 	struct socket *so = NULL;
5434f8829a4aSRandall Stewart 
5435f8829a4aSRandall Stewart 	if (stcb == NULL)
5436f8829a4aSRandall Stewart 		return;
5437f8829a4aSRandall Stewart 
543850cec919SRandall Stewart 	atomic_add_int(&stcb->asoc.refcnt, 1);
5439f8829a4aSRandall Stewart 
5440839d21d6SMichael Tuexen 	if ((SCTP_GET_STATE(stcb) == SCTP_STATE_SHUTDOWN_ACK_SENT) ||
544161a21880SMichael Tuexen 	    (stcb->asoc.state & (SCTP_STATE_ABOUT_TO_BE_FREED | SCTP_STATE_SHUTDOWN_RECEIVED))) {
5442f8829a4aSRandall Stewart 		/* Pre-check If we are freeing no update */
5443f8829a4aSRandall Stewart 		goto no_lock;
5444f8829a4aSRandall Stewart 	}
5445f8829a4aSRandall Stewart 	SCTP_INP_INCR_REF(stcb->sctp_ep);
5446f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
5447f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE)) {
5448f8829a4aSRandall Stewart 		goto out;
5449f8829a4aSRandall Stewart 	}
5450f8829a4aSRandall Stewart 	so = stcb->sctp_socket;
5451f8829a4aSRandall Stewart 	if (so == NULL) {
5452f8829a4aSRandall Stewart 		goto out;
5453f8829a4aSRandall Stewart 	}
5454f8829a4aSRandall Stewart 	atomic_add_int(&stcb->freed_by_sorcv_sincelast, *freed_so_far);
5455f8829a4aSRandall Stewart 	/* Have you have freed enough to look */
5456f8829a4aSRandall Stewart 	*freed_so_far = 0;
5457f8829a4aSRandall Stewart 	/* Yep, its worth a look and the lock overhead */
5458f8829a4aSRandall Stewart 
5459f8829a4aSRandall Stewart 	/* Figure out what the rwnd would be */
5460f8829a4aSRandall Stewart 	rwnd = sctp_calc_rwnd(stcb, &stcb->asoc);
5461f8829a4aSRandall Stewart 	if (rwnd >= stcb->asoc.my_last_reported_rwnd) {
5462f8829a4aSRandall Stewart 		dif = rwnd - stcb->asoc.my_last_reported_rwnd;
5463f8829a4aSRandall Stewart 	} else {
5464f8829a4aSRandall Stewart 		dif = 0;
5465f8829a4aSRandall Stewart 	}
5466f8829a4aSRandall Stewart 	if (dif >= rwnd_req) {
5467f8829a4aSRandall Stewart 		if (hold_rlock) {
5468f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(stcb->sctp_ep);
5469f8829a4aSRandall Stewart 			r_unlocked = 1;
5470f8829a4aSRandall Stewart 		}
5471f8829a4aSRandall Stewart 		if (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
5472f8829a4aSRandall Stewart 			/*
5473f8829a4aSRandall Stewart 			 * One last check before we allow the guy possibly
5474f8829a4aSRandall Stewart 			 * to get in. There is a race, where the guy has not
5475f8829a4aSRandall Stewart 			 * reached the gate. In that case
5476f8829a4aSRandall Stewart 			 */
5477f8829a4aSRandall Stewart 			goto out;
5478f8829a4aSRandall Stewart 		}
5479f8829a4aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
5480f8829a4aSRandall Stewart 		if (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
5481f8829a4aSRandall Stewart 			/* No reports here */
5482f8829a4aSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
5483f8829a4aSRandall Stewart 			goto out;
5484f8829a4aSRandall Stewart 		}
5485f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_wu_sacks_sent);
5486868b51f2SMichael Tuexen 		NET_EPOCH_ENTER(et);
5487689e6a5fSMichael Tuexen 		sctp_send_sack(stcb, SCTP_SO_LOCKED);
5488830d754dSRandall Stewart 
5489f8829a4aSRandall Stewart 		sctp_chunk_output(stcb->sctp_ep, stcb,
5490ceaad40aSRandall Stewart 		    SCTP_OUTPUT_FROM_USR_RCVD, SCTP_SO_LOCKED);
5491f8829a4aSRandall Stewart 		/* make sure no timer is running */
5492868b51f2SMichael Tuexen 		NET_EPOCH_EXIT(et);
5493ba785902SMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_RECV, stcb->sctp_ep, stcb, NULL,
5494ba785902SMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_6);
5495f8829a4aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
5496f8829a4aSRandall Stewart 	} else {
5497f8829a4aSRandall Stewart 		/* Update how much we have pending */
5498f8829a4aSRandall Stewart 		stcb->freed_by_sorcv_sincelast = dif;
5499f8829a4aSRandall Stewart 	}
5500f8829a4aSRandall Stewart out:
5501f8829a4aSRandall Stewart 	if (so && r_unlocked && hold_rlock) {
5502f8829a4aSRandall Stewart 		SCTP_INP_READ_LOCK(stcb->sctp_ep);
5503f8829a4aSRandall Stewart 	}
55040053ed28SMichael Tuexen 
5505f8829a4aSRandall Stewart 	SCTP_INP_DECR_REF(stcb->sctp_ep);
5506f8829a4aSRandall Stewart no_lock:
55073c1ba6f3SMichael Tuexen 	atomic_subtract_int(&stcb->asoc.refcnt, 1);
5508f8829a4aSRandall Stewart 	return;
5509f8829a4aSRandall Stewart }
5510f8829a4aSRandall Stewart 
5511f8829a4aSRandall Stewart int
5512f8829a4aSRandall Stewart sctp_sorecvmsg(struct socket *so,
5513f8829a4aSRandall Stewart     struct uio *uio,
5514f8829a4aSRandall Stewart     struct mbuf **mp,
5515f8829a4aSRandall Stewart     struct sockaddr *from,
5516f8829a4aSRandall Stewart     int fromlen,
5517f8829a4aSRandall Stewart     int *msg_flags,
5518f8829a4aSRandall Stewart     struct sctp_sndrcvinfo *sinfo,
5519f8829a4aSRandall Stewart     int filling_sinfo)
5520f8829a4aSRandall Stewart {
5521f8829a4aSRandall Stewart 	/*
5522f8829a4aSRandall Stewart 	 * MSG flags we will look at MSG_DONTWAIT - non-blocking IO.
5523f8829a4aSRandall Stewart 	 * MSG_PEEK - Look don't touch :-D (only valid with OUT mbuf copy
5524f8829a4aSRandall Stewart 	 * mp=NULL thus uio is the copy method to userland) MSG_WAITALL - ??
5525f8829a4aSRandall Stewart 	 * On the way out we may send out any combination of:
5526f8829a4aSRandall Stewart 	 * MSG_NOTIFICATION MSG_EOR
5527f8829a4aSRandall Stewart 	 *
5528f8829a4aSRandall Stewart 	 */
5529f8829a4aSRandall Stewart 	struct sctp_inpcb *inp = NULL;
553058e6eeefSMichael Tuexen 	ssize_t my_len = 0;
553158e6eeefSMichael Tuexen 	ssize_t cp_len = 0;
55320d3cf13dSMichael Tuexen 	int error = 0;
5533f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control = NULL, *ctl = NULL, *nxt = NULL;
553494b0d969SMichael Tuexen 	struct mbuf *m = NULL;
5535f8829a4aSRandall Stewart 	struct sctp_tcb *stcb = NULL;
5536f8829a4aSRandall Stewart 	int wakeup_read_socket = 0;
5537f8829a4aSRandall Stewart 	int freecnt_applied = 0;
5538f8829a4aSRandall Stewart 	int out_flags = 0, in_flags = 0;
5539f8829a4aSRandall Stewart 	int block_allowed = 1;
55404c9179adSRandall Stewart 	uint32_t freed_so_far = 0;
554158e6eeefSMichael Tuexen 	ssize_t copied_so_far = 0;
554293164cf9SRandall Stewart 	int in_eeor_mode = 0;
5543f8829a4aSRandall Stewart 	int no_rcv_needed = 0;
5544f8829a4aSRandall Stewart 	uint32_t rwnd_req = 0;
5545f8829a4aSRandall Stewart 	int hold_sblock = 0;
5546f8829a4aSRandall Stewart 	int hold_rlock = 0;
55479a8e3088SMichael Tuexen 	ssize_t slen = 0;
55484c9179adSRandall Stewart 	uint32_t held_length = 0;
55497abab911SRobert Watson 	int sockbuf_lock = 0;
5550f8829a4aSRandall Stewart 
555117205eccSRandall Stewart 	if (uio == NULL) {
5552c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
555317205eccSRandall Stewart 		return (EINVAL);
555417205eccSRandall Stewart 	}
55550053ed28SMichael Tuexen 
5556f8829a4aSRandall Stewart 	if (msg_flags) {
5557f8829a4aSRandall Stewart 		in_flags = *msg_flags;
5558c105859eSRandall Stewart 		if (in_flags & MSG_PEEK)
5559c105859eSRandall Stewart 			SCTP_STAT_INCR(sctps_read_peeks);
5560f8829a4aSRandall Stewart 	} else {
5561f8829a4aSRandall Stewart 		in_flags = 0;
5562f8829a4aSRandall Stewart 	}
5563f8829a4aSRandall Stewart 	slen = uio->uio_resid;
556417205eccSRandall Stewart 
5565f8829a4aSRandall Stewart 	/* Pull in and set up our int flags */
5566f8829a4aSRandall Stewart 	if (in_flags & MSG_OOB) {
5567f8829a4aSRandall Stewart 		/* Out of band's NOT supported */
5568f8829a4aSRandall Stewart 		return (EOPNOTSUPP);
5569f8829a4aSRandall Stewart 	}
5570f8829a4aSRandall Stewart 	if ((in_flags & MSG_PEEK) && (mp != NULL)) {
5571c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
5572f8829a4aSRandall Stewart 		return (EINVAL);
5573f8829a4aSRandall Stewart 	}
5574f8829a4aSRandall Stewart 	if ((in_flags & (MSG_DONTWAIT
5575f8829a4aSRandall Stewart 	    | MSG_NBIO
5576f8829a4aSRandall Stewart 	    )) ||
557742551e99SRandall Stewart 	    SCTP_SO_IS_NBIO(so)) {
5578f8829a4aSRandall Stewart 		block_allowed = 0;
5579f8829a4aSRandall Stewart 	}
5580f8829a4aSRandall Stewart 	/* setup the endpoint */
5581f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)so->so_pcb;
5582f8829a4aSRandall Stewart 	if (inp == NULL) {
5583c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EFAULT);
5584f8829a4aSRandall Stewart 		return (EFAULT);
5585f8829a4aSRandall Stewart 	}
558662c1ff9cSRandall Stewart 	rwnd_req = (SCTP_SB_LIMIT_RCV(so) >> SCTP_RWND_HIWAT_SHIFT);
5587f8829a4aSRandall Stewart 	/* Must be at least a MTU's worth */
5588f8829a4aSRandall Stewart 	if (rwnd_req < SCTP_MIN_RWND)
5589f8829a4aSRandall Stewart 		rwnd_req = SCTP_MIN_RWND;
5590f8829a4aSRandall Stewart 	in_eeor_mode = sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXPLICIT_EOR);
5591b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
5592f8829a4aSRandall Stewart 		sctp_misc_ints(SCTP_SORECV_ENTER,
5593edc5b6eaSMichael Tuexen 		    rwnd_req, in_eeor_mode, SCTP_SBAVAIL(&so->so_rcv), (uint32_t)uio->uio_resid);
559480fefe0aSRandall Stewart 	}
5595b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
5596f8829a4aSRandall Stewart 		sctp_misc_ints(SCTP_SORECV_ENTERPL,
5597edc5b6eaSMichael Tuexen 		    rwnd_req, block_allowed, SCTP_SBAVAIL(&so->so_rcv), (uint32_t)uio->uio_resid);
559880fefe0aSRandall Stewart 	}
55990053ed28SMichael Tuexen 
5600e6c19aa9SMark Johnston 	error = SOCK_IO_RECV_LOCK(so, SBLOCKWAIT(in_flags));
5601f8829a4aSRandall Stewart 	if (error) {
5602f8829a4aSRandall Stewart 		goto release_unlocked;
5603f8829a4aSRandall Stewart 	}
56048e1e6e5fSMateusz Guzik 	sockbuf_lock = 1;
5605f8829a4aSRandall Stewart restart:
56067abab911SRobert Watson 
5607f8829a4aSRandall Stewart restart_nosblocks:
5608f8829a4aSRandall Stewart 	if (hold_sblock == 0) {
5609f8829a4aSRandall Stewart 		SOCKBUF_LOCK(&so->so_rcv);
5610f8829a4aSRandall Stewart 		hold_sblock = 1;
5611f8829a4aSRandall Stewart 	}
5612f8829a4aSRandall Stewart 	if ((inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
5613f8829a4aSRandall Stewart 	    (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE)) {
5614f8829a4aSRandall Stewart 		goto out;
5615f8829a4aSRandall Stewart 	}
5616edc5b6eaSMichael Tuexen 	if ((so->so_rcv.sb_state & SBS_CANTRCVMORE) && SCTP_SBAVAIL(&so->so_rcv) == 0) {
5617f8829a4aSRandall Stewart 		if (so->so_error) {
5618f8829a4aSRandall Stewart 			error = so->so_error;
561944b7479bSRandall Stewart 			if ((in_flags & MSG_PEEK) == 0)
562044b7479bSRandall Stewart 				so->so_error = 0;
56219f22f500SRandall Stewart 			goto out;
5622f8829a4aSRandall Stewart 		} else {
5623edc5b6eaSMichael Tuexen 			if (SCTP_SBAVAIL(&so->so_rcv) == 0) {
56247924093fSRandall Stewart 				/* indicate EOF */
56257924093fSRandall Stewart 				error = 0;
5626f8829a4aSRandall Stewart 				goto out;
5627f8829a4aSRandall Stewart 			}
56289f22f500SRandall Stewart 		}
56299f22f500SRandall Stewart 	}
5630edc5b6eaSMichael Tuexen 	if (SCTP_SBAVAIL(&so->so_rcv) <= held_length) {
56319de217ceSMichael Tuexen 		if (so->so_error) {
56329de217ceSMichael Tuexen 			error = so->so_error;
56339de217ceSMichael Tuexen 			if ((in_flags & MSG_PEEK) == 0) {
56349de217ceSMichael Tuexen 				so->so_error = 0;
56359de217ceSMichael Tuexen 			}
56369de217ceSMichael Tuexen 			goto out;
56379de217ceSMichael Tuexen 		}
5638edc5b6eaSMichael Tuexen 		if ((SCTP_SBAVAIL(&so->so_rcv) == 0) &&
5639f8829a4aSRandall Stewart 		    ((inp->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
5640f8829a4aSRandall Stewart 		    (inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL))) {
5641f8829a4aSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_CONNECTED) == 0) {
5642f8829a4aSRandall Stewart 				/*
5643f8829a4aSRandall Stewart 				 * For active open side clear flags for
5644f8829a4aSRandall Stewart 				 * re-use passive open is blocked by
5645f8829a4aSRandall Stewart 				 * connect.
5646f8829a4aSRandall Stewart 				 */
5647f8829a4aSRandall Stewart 				if (inp->sctp_flags & SCTP_PCB_FLAGS_WAS_ABORTED) {
5648b7b84c0eSMichael Tuexen 					/*
5649b7b84c0eSMichael Tuexen 					 * You were aborted, passive side
5650b7b84c0eSMichael Tuexen 					 * always hits here
5651b7b84c0eSMichael Tuexen 					 */
5652c4739e2fSRandall Stewart 					SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ECONNRESET);
5653f8829a4aSRandall Stewart 					error = ECONNRESET;
5654f8829a4aSRandall Stewart 				}
5655f8829a4aSRandall Stewart 				so->so_state &= ~(SS_ISCONNECTING |
5656f8829a4aSRandall Stewart 				    SS_ISDISCONNECTING |
5657f8829a4aSRandall Stewart 				    SS_ISCONFIRMING |
5658f8829a4aSRandall Stewart 				    SS_ISCONNECTED);
5659f8829a4aSRandall Stewart 				if (error == 0) {
5660f8829a4aSRandall Stewart 					if ((inp->sctp_flags & SCTP_PCB_FLAGS_WAS_CONNECTED) == 0) {
5661c4739e2fSRandall Stewart 						SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOTCONN);
5662f8829a4aSRandall Stewart 						error = ENOTCONN;
5663f8829a4aSRandall Stewart 					}
5664f8829a4aSRandall Stewart 				}
5665f8829a4aSRandall Stewart 				goto out;
5666f8829a4aSRandall Stewart 			}
5667f8829a4aSRandall Stewart 		}
56689de217ceSMichael Tuexen 		if (block_allowed) {
566943283184SGleb Smirnoff 			error = sbwait(so, SO_RCV);
5670f8829a4aSRandall Stewart 			if (error) {
5671f8829a4aSRandall Stewart 				goto out;
5672f8829a4aSRandall Stewart 			}
5673f8829a4aSRandall Stewart 			held_length = 0;
5674f8829a4aSRandall Stewart 			goto restart_nosblocks;
567544b7479bSRandall Stewart 		} else {
5676c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EWOULDBLOCK);
5677f8829a4aSRandall Stewart 			error = EWOULDBLOCK;
5678f8829a4aSRandall Stewart 			goto out;
5679f8829a4aSRandall Stewart 		}
56809de217ceSMichael Tuexen 	}
5681d06c82f1SRandall Stewart 	if (hold_sblock == 1) {
5682d06c82f1SRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
5683d06c82f1SRandall Stewart 		hold_sblock = 0;
5684d06c82f1SRandall Stewart 	}
5685f8829a4aSRandall Stewart 	/* we possibly have data we can read */
56863c503c28SRandall Stewart 	/* sa_ignore FREED_MEMORY */
5687f8829a4aSRandall Stewart 	control = TAILQ_FIRST(&inp->read_queue);
5688f8829a4aSRandall Stewart 	if (control == NULL) {
5689f8829a4aSRandall Stewart 		/*
5690f8829a4aSRandall Stewart 		 * This could be happening since the appender did the
5691f8829a4aSRandall Stewart 		 * increment but as not yet did the tailq insert onto the
5692f8829a4aSRandall Stewart 		 * read_queue
5693f8829a4aSRandall Stewart 		 */
5694f8829a4aSRandall Stewart 		if (hold_rlock == 0) {
5695f8829a4aSRandall Stewart 			SCTP_INP_READ_LOCK(inp);
5696f8829a4aSRandall Stewart 		}
5697f8829a4aSRandall Stewart 		control = TAILQ_FIRST(&inp->read_queue);
5698edc5b6eaSMichael Tuexen 		if ((control == NULL) && (SCTP_SBAVAIL(&so->so_rcv) > 0)) {
5699a5d547adSRandall Stewart #ifdef INVARIANTS
5700f8829a4aSRandall Stewart 			panic("Huh, its non zero and nothing on control?");
5701f8829a4aSRandall Stewart #endif
5702f210e4fbSMichael Tuexen 			SCTP_SB_CLEAR(so->so_rcv);
5703f8829a4aSRandall Stewart 		}
5704f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
5705f8829a4aSRandall Stewart 		hold_rlock = 0;
5706f8829a4aSRandall Stewart 		goto restart;
5707f8829a4aSRandall Stewart 	}
57080053ed28SMichael Tuexen 
5709f8829a4aSRandall Stewart 	if ((control->length == 0) &&
5710f8829a4aSRandall Stewart 	    (control->do_not_ref_stcb)) {
5711f8829a4aSRandall Stewart 		/*
5712f8829a4aSRandall Stewart 		 * Clean up code for freeing assoc that left behind a
5713f8829a4aSRandall Stewart 		 * pdapi.. maybe a peer in EEOR that just closed after
5714f8829a4aSRandall Stewart 		 * sending and never indicated a EOR.
5715f8829a4aSRandall Stewart 		 */
5716f8829a4aSRandall Stewart 		if (hold_rlock == 0) {
5717f8829a4aSRandall Stewart 			hold_rlock = 1;
5718f8829a4aSRandall Stewart 			SCTP_INP_READ_LOCK(inp);
5719f8829a4aSRandall Stewart 		}
5720f8829a4aSRandall Stewart 		control->held_length = 0;
5721f8829a4aSRandall Stewart 		if (control->data) {
5722f8829a4aSRandall Stewart 			/* Hmm there is data here .. fix */
57234c9179adSRandall Stewart 			struct mbuf *m_tmp;
5724f8829a4aSRandall Stewart 			int cnt = 0;
5725f8829a4aSRandall Stewart 
57264c9179adSRandall Stewart 			m_tmp = control->data;
57274c9179adSRandall Stewart 			while (m_tmp) {
57284c9179adSRandall Stewart 				cnt += SCTP_BUF_LEN(m_tmp);
57294c9179adSRandall Stewart 				if (SCTP_BUF_NEXT(m_tmp) == NULL) {
57304c9179adSRandall Stewart 					control->tail_mbuf = m_tmp;
5731f8829a4aSRandall Stewart 					control->end_added = 1;
5732f8829a4aSRandall Stewart 				}
57334c9179adSRandall Stewart 				m_tmp = SCTP_BUF_NEXT(m_tmp);
5734f8829a4aSRandall Stewart 			}
5735f8829a4aSRandall Stewart 			control->length = cnt;
5736f8829a4aSRandall Stewart 		} else {
5737f8829a4aSRandall Stewart 			/* remove it */
5738f8829a4aSRandall Stewart 			TAILQ_REMOVE(&inp->read_queue, control, next);
5739e7e65008SMichael Tuexen 			/* Add back any hidden data */
5740f8829a4aSRandall Stewart 			sctp_free_remote_addr(control->whoFrom);
5741f8829a4aSRandall Stewart 			sctp_free_a_readq(stcb, control);
5742f8829a4aSRandall Stewart 		}
5743f8829a4aSRandall Stewart 		if (hold_rlock) {
5744f8829a4aSRandall Stewart 			hold_rlock = 0;
5745f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
5746f8829a4aSRandall Stewart 		}
5747f8829a4aSRandall Stewart 		goto restart;
5748f8829a4aSRandall Stewart 	}
5749810ec536SMichael Tuexen 	if ((control->length == 0) &&
5750810ec536SMichael Tuexen 	    (control->end_added == 1)) {
5751b7b84c0eSMichael Tuexen 		/*
5752b7b84c0eSMichael Tuexen 		 * Do we also need to check for (control->pdapi_aborted ==
5753b7b84c0eSMichael Tuexen 		 * 1)?
5754b7b84c0eSMichael Tuexen 		 */
5755810ec536SMichael Tuexen 		if (hold_rlock == 0) {
5756810ec536SMichael Tuexen 			hold_rlock = 1;
5757810ec536SMichael Tuexen 			SCTP_INP_READ_LOCK(inp);
5758810ec536SMichael Tuexen 		}
5759810ec536SMichael Tuexen 		TAILQ_REMOVE(&inp->read_queue, control, next);
5760810ec536SMichael Tuexen 		if (control->data) {
5761810ec536SMichael Tuexen #ifdef INVARIANTS
5762810ec536SMichael Tuexen 			panic("control->data not null but control->length == 0");
5763810ec536SMichael Tuexen #else
5764810ec536SMichael Tuexen 			SCTP_PRINTF("Strange, data left in the control buffer. Cleaning up.\n");
5765810ec536SMichael Tuexen 			sctp_m_freem(control->data);
5766810ec536SMichael Tuexen 			control->data = NULL;
5767810ec536SMichael Tuexen #endif
5768810ec536SMichael Tuexen 		}
5769810ec536SMichael Tuexen 		if (control->aux_data) {
5770810ec536SMichael Tuexen 			sctp_m_free(control->aux_data);
5771810ec536SMichael Tuexen 			control->aux_data = NULL;
5772810ec536SMichael Tuexen 		}
577398d5fd97SMichael Tuexen #ifdef INVARIANTS
577444249214SRandall Stewart 		if (control->on_strm_q) {
577544249214SRandall Stewart 			panic("About to free ctl:%p so:%p and its in %d",
577644249214SRandall Stewart 			    control, so, control->on_strm_q);
577744249214SRandall Stewart 		}
577898d5fd97SMichael Tuexen #endif
5779810ec536SMichael Tuexen 		sctp_free_remote_addr(control->whoFrom);
5780810ec536SMichael Tuexen 		sctp_free_a_readq(stcb, control);
5781810ec536SMichael Tuexen 		if (hold_rlock) {
5782810ec536SMichael Tuexen 			hold_rlock = 0;
5783810ec536SMichael Tuexen 			SCTP_INP_READ_UNLOCK(inp);
5784810ec536SMichael Tuexen 		}
5785810ec536SMichael Tuexen 		goto restart;
5786810ec536SMichael Tuexen 	}
5787f8829a4aSRandall Stewart 	if (control->length == 0) {
5788f8829a4aSRandall Stewart 		if ((sctp_is_feature_on(inp, SCTP_PCB_FLAGS_FRAG_INTERLEAVE)) &&
5789f8829a4aSRandall Stewart 		    (filling_sinfo)) {
5790f8829a4aSRandall Stewart 			/* find a more suitable one then this */
5791f8829a4aSRandall Stewart 			ctl = TAILQ_NEXT(control, next);
5792f8829a4aSRandall Stewart 			while (ctl) {
57939a6142d8SRandall Stewart 				if ((ctl->stcb != control->stcb) && (ctl->length) &&
57949a6142d8SRandall Stewart 				    (ctl->some_taken ||
57956114cd96SRandall Stewart 				    (ctl->spec_flags & M_NOTIFICATION) ||
57969a6142d8SRandall Stewart 				    ((ctl->do_not_ref_stcb == 0) &&
57979a6142d8SRandall Stewart 				    (ctl->stcb->asoc.strmin[ctl->sinfo_stream].delivery_started == 0)))
57989a6142d8SRandall Stewart 				    ) {
57999a6142d8SRandall Stewart 					/*-
58009a6142d8SRandall Stewart 					 * If we have a different TCB next, and there is data
58019a6142d8SRandall Stewart 					 * present. If we have already taken some (pdapi), OR we can
58029a6142d8SRandall Stewart 					 * ref the tcb and no delivery as started on this stream, we
580317205eccSRandall Stewart 					 * take it. Note we allow a notification on a different
580417205eccSRandall Stewart 					 * assoc to be delivered..
58059a6142d8SRandall Stewart 					 */
58069a6142d8SRandall Stewart 					control = ctl;
58079a6142d8SRandall Stewart 					goto found_one;
58089a6142d8SRandall Stewart 				} else if ((sctp_is_feature_on(inp, SCTP_PCB_FLAGS_INTERLEAVE_STRMS)) &&
58099a6142d8SRandall Stewart 					    (ctl->length) &&
58109a6142d8SRandall Stewart 					    ((ctl->some_taken) ||
58119a6142d8SRandall Stewart 					    ((ctl->do_not_ref_stcb == 0) &&
581217205eccSRandall Stewart 					    ((ctl->spec_flags & M_NOTIFICATION) == 0) &&
5813b5c16493SMichael Tuexen 				    (ctl->stcb->asoc.strmin[ctl->sinfo_stream].delivery_started == 0)))) {
58149a6142d8SRandall Stewart 					/*-
58159a6142d8SRandall Stewart 					 * If we have the same tcb, and there is data present, and we
58169a6142d8SRandall Stewart 					 * have the strm interleave feature present. Then if we have
58179a6142d8SRandall Stewart 					 * taken some (pdapi) or we can refer to tht tcb AND we have
58189a6142d8SRandall Stewart 					 * not started a delivery for this stream, we can take it.
5819e7e65008SMichael Tuexen 					 * Note we do NOT allow a notification on the same assoc to
582017205eccSRandall Stewart 					 * be delivered.
58219a6142d8SRandall Stewart 					 */
5822f8829a4aSRandall Stewart 					control = ctl;
5823f8829a4aSRandall Stewart 					goto found_one;
5824f8829a4aSRandall Stewart 				}
5825f8829a4aSRandall Stewart 				ctl = TAILQ_NEXT(ctl, next);
5826f8829a4aSRandall Stewart 			}
5827f8829a4aSRandall Stewart 		}
5828f8829a4aSRandall Stewart 		/*
5829f8829a4aSRandall Stewart 		 * if we reach here, not suitable replacement is available
58304e88d37aSMichael Tuexen 		 * <or> fragment interleave is NOT on. So stuff the sb_cc
5831f8829a4aSRandall Stewart 		 * into the our held count, and its time to sleep again.
5832f8829a4aSRandall Stewart 		 */
5833edc5b6eaSMichael Tuexen 		held_length = SCTP_SBAVAIL(&so->so_rcv);
5834edc5b6eaSMichael Tuexen 		control->held_length = SCTP_SBAVAIL(&so->so_rcv);
5835f8829a4aSRandall Stewart 		goto restart;
5836f8829a4aSRandall Stewart 	}
5837f8829a4aSRandall Stewart 	/* Clear the held length since there is something to read */
5838f8829a4aSRandall Stewart 	control->held_length = 0;
5839f8829a4aSRandall Stewart found_one:
5840f8829a4aSRandall Stewart 	/*
5841f8829a4aSRandall Stewart 	 * If we reach here, control has a some data for us to read off.
5842f8829a4aSRandall Stewart 	 * Note that stcb COULD be NULL.
5843f8829a4aSRandall Stewart 	 */
58449c5ca6f2SMichael Tuexen 	if (hold_rlock == 0) {
58459c5ca6f2SMichael Tuexen 		hold_rlock = 1;
58469c5ca6f2SMichael Tuexen 		SCTP_INP_READ_LOCK(inp);
5847f8829a4aSRandall Stewart 	}
58489c5ca6f2SMichael Tuexen 	control->some_taken++;
5849f8829a4aSRandall Stewart 	stcb = control->stcb;
5850f8829a4aSRandall Stewart 	if (stcb) {
58510696e120SRandall Stewart 		if ((control->do_not_ref_stcb == 0) &&
58520696e120SRandall Stewart 		    (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED)) {
585350cec919SRandall Stewart 			if (freecnt_applied == 0)
5854f8829a4aSRandall Stewart 				stcb = NULL;
5855f8829a4aSRandall Stewart 		} else if (control->do_not_ref_stcb == 0) {
5856f8829a4aSRandall Stewart 			/* you can't free it on me please */
5857f8829a4aSRandall Stewart 			/*
5858f8829a4aSRandall Stewart 			 * The lock on the socket buffer protects us so the
5859f8829a4aSRandall Stewart 			 * free code will stop. But since we used the
5860f8829a4aSRandall Stewart 			 * socketbuf lock and the sender uses the tcb_lock
5861f8829a4aSRandall Stewart 			 * to increment, we need to use the atomic add to
5862f8829a4aSRandall Stewart 			 * the refcnt
5863f8829a4aSRandall Stewart 			 */
5864d55b0b1bSRandall Stewart 			if (freecnt_applied) {
5865d55b0b1bSRandall Stewart #ifdef INVARIANTS
5866207304d4SRandall Stewart 				panic("refcnt already incremented");
5867d55b0b1bSRandall Stewart #else
5868cd3fd531SMichael Tuexen 				SCTP_PRINTF("refcnt already incremented?\n");
5869d55b0b1bSRandall Stewart #endif
5870d55b0b1bSRandall Stewart 			} else {
587150cec919SRandall Stewart 				atomic_add_int(&stcb->asoc.refcnt, 1);
5872f8829a4aSRandall Stewart 				freecnt_applied = 1;
5873d55b0b1bSRandall Stewart 			}
5874f8829a4aSRandall Stewart 			/*
5875f8829a4aSRandall Stewart 			 * Setup to remember how much we have not yet told
5876f8829a4aSRandall Stewart 			 * the peer our rwnd has opened up. Note we grab the
5877f8829a4aSRandall Stewart 			 * value from the tcb from last time. Note too that
58780696e120SRandall Stewart 			 * sack sending clears this when a sack is sent,
5879f8829a4aSRandall Stewart 			 * which is fine. Once we hit the rwnd_req, we then
5880f8829a4aSRandall Stewart 			 * will go to the sctp_user_rcvd() that will not
5881f8829a4aSRandall Stewart 			 * lock until it KNOWs it MUST send a WUP-SACK.
5882f8829a4aSRandall Stewart 			 */
588358e6eeefSMichael Tuexen 			freed_so_far = (uint32_t)stcb->freed_by_sorcv_sincelast;
5884f8829a4aSRandall Stewart 			stcb->freed_by_sorcv_sincelast = 0;
5885f8829a4aSRandall Stewart 		}
5886f8829a4aSRandall Stewart 	}
58876114cd96SRandall Stewart 	if (stcb &&
58886114cd96SRandall Stewart 	    ((control->spec_flags & M_NOTIFICATION) == 0) &&
58896114cd96SRandall Stewart 	    control->do_not_ref_stcb == 0) {
5890d06c82f1SRandall Stewart 		stcb->asoc.strmin[control->sinfo_stream].delivery_started = 1;
5891d06c82f1SRandall Stewart 	}
58920053ed28SMichael Tuexen 
5893f8829a4aSRandall Stewart 	/* First lets get off the sinfo and sockaddr info */
58945f05199cSMichael Tuexen 	if ((sinfo != NULL) && (filling_sinfo != 0)) {
58955f05199cSMichael Tuexen 		sinfo->sinfo_stream = control->sinfo_stream;
589649656eefSMichael Tuexen 		sinfo->sinfo_ssn = (uint16_t)control->mid;
58975f05199cSMichael Tuexen 		sinfo->sinfo_flags = control->sinfo_flags;
58985f05199cSMichael Tuexen 		sinfo->sinfo_ppid = control->sinfo_ppid;
58995f05199cSMichael Tuexen 		sinfo->sinfo_context = control->sinfo_context;
59005f05199cSMichael Tuexen 		sinfo->sinfo_timetolive = control->sinfo_timetolive;
59015f05199cSMichael Tuexen 		sinfo->sinfo_tsn = control->sinfo_tsn;
59025f05199cSMichael Tuexen 		sinfo->sinfo_cumtsn = control->sinfo_cumtsn;
59035f05199cSMichael Tuexen 		sinfo->sinfo_assoc_id = control->sinfo_assoc_id;
5904f8829a4aSRandall Stewart 		nxt = TAILQ_NEXT(control, next);
5905e2e7c62eSMichael Tuexen 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXT_RCVINFO) ||
5906e2e7c62eSMichael Tuexen 		    sctp_is_feature_on(inp, SCTP_PCB_FLAGS_RECVNXTINFO)) {
5907f8829a4aSRandall Stewart 			struct sctp_extrcvinfo *s_extra;
5908f8829a4aSRandall Stewart 
5909f8829a4aSRandall Stewart 			s_extra = (struct sctp_extrcvinfo *)sinfo;
59109a6142d8SRandall Stewart 			if ((nxt) &&
59119a6142d8SRandall Stewart 			    (nxt->length)) {
5912b70b526dSMichael Tuexen 				s_extra->serinfo_next_flags = SCTP_NEXT_MSG_AVAIL;
5913f8829a4aSRandall Stewart 				if (nxt->sinfo_flags & SCTP_UNORDERED) {
5914b70b526dSMichael Tuexen 					s_extra->serinfo_next_flags |= SCTP_NEXT_MSG_IS_UNORDERED;
5915f8829a4aSRandall Stewart 				}
5916f42a358aSRandall Stewart 				if (nxt->spec_flags & M_NOTIFICATION) {
5917b70b526dSMichael Tuexen 					s_extra->serinfo_next_flags |= SCTP_NEXT_MSG_IS_NOTIFICATION;
5918f42a358aSRandall Stewart 				}
5919b70b526dSMichael Tuexen 				s_extra->serinfo_next_aid = nxt->sinfo_assoc_id;
5920b70b526dSMichael Tuexen 				s_extra->serinfo_next_length = nxt->length;
5921b70b526dSMichael Tuexen 				s_extra->serinfo_next_ppid = nxt->sinfo_ppid;
5922b70b526dSMichael Tuexen 				s_extra->serinfo_next_stream = nxt->sinfo_stream;
5923f8829a4aSRandall Stewart 				if (nxt->tail_mbuf != NULL) {
5924139bc87fSRandall Stewart 					if (nxt->end_added) {
5925b70b526dSMichael Tuexen 						s_extra->serinfo_next_flags |= SCTP_NEXT_MSG_ISCOMPLETE;
5926f8829a4aSRandall Stewart 					}
5927f8829a4aSRandall Stewart 				}
5928f8829a4aSRandall Stewart 			} else {
5929f8829a4aSRandall Stewart 				/*
5930f8829a4aSRandall Stewart 				 * we explicitly 0 this, since the memcpy
5931f8829a4aSRandall Stewart 				 * got some other things beyond the older
5932f8829a4aSRandall Stewart 				 * sinfo_ that is on the control's structure
5933f8829a4aSRandall Stewart 				 * :-D
5934f8829a4aSRandall Stewart 				 */
59359a6142d8SRandall Stewart 				nxt = NULL;
5936b70b526dSMichael Tuexen 				s_extra->serinfo_next_flags = SCTP_NO_NEXT_MSG;
5937b70b526dSMichael Tuexen 				s_extra->serinfo_next_aid = 0;
5938b70b526dSMichael Tuexen 				s_extra->serinfo_next_length = 0;
5939b70b526dSMichael Tuexen 				s_extra->serinfo_next_ppid = 0;
5940b70b526dSMichael Tuexen 				s_extra->serinfo_next_stream = 0;
5941f8829a4aSRandall Stewart 			}
5942f8829a4aSRandall Stewart 		}
5943f8829a4aSRandall Stewart 		/*
5944f8829a4aSRandall Stewart 		 * update off the real current cum-ack, if we have an stcb.
5945f8829a4aSRandall Stewart 		 */
59460696e120SRandall Stewart 		if ((control->do_not_ref_stcb == 0) && stcb)
5947f8829a4aSRandall Stewart 			sinfo->sinfo_cumtsn = stcb->asoc.cumulative_tsn;
5948f8829a4aSRandall Stewart 		/*
5949f8829a4aSRandall Stewart 		 * mask off the high bits, we keep the actual chunk bits in
5950f8829a4aSRandall Stewart 		 * there.
5951f8829a4aSRandall Stewart 		 */
5952f8829a4aSRandall Stewart 		sinfo->sinfo_flags &= 0x00ff;
59535f26a41dSRandall Stewart 		if ((control->sinfo_flags >> 8) & SCTP_DATA_UNORDERED) {
59545f26a41dSRandall Stewart 			sinfo->sinfo_flags |= SCTP_UNORDERED;
59555f26a41dSRandall Stewart 		}
5956f8829a4aSRandall Stewart 	}
595718e198d3SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
595818e198d3SRandall Stewart 	{
595918e198d3SRandall Stewart 		int index, newindex;
596018e198d3SRandall Stewart 		struct sctp_pcbtsn_rlog *entry;
596118e198d3SRandall Stewart 
596218e198d3SRandall Stewart 		do {
596318e198d3SRandall Stewart 			index = inp->readlog_index;
596418e198d3SRandall Stewart 			newindex = index + 1;
596518e198d3SRandall Stewart 			if (newindex >= SCTP_READ_LOG_SIZE) {
596618e198d3SRandall Stewart 				newindex = 0;
596718e198d3SRandall Stewart 			}
596818e198d3SRandall Stewart 		} while (atomic_cmpset_int(&inp->readlog_index, index, newindex) == 0);
596918e198d3SRandall Stewart 		entry = &inp->readlog[index];
597018e198d3SRandall Stewart 		entry->vtag = control->sinfo_assoc_id;
597118e198d3SRandall Stewart 		entry->strm = control->sinfo_stream;
597249656eefSMichael Tuexen 		entry->seq = (uint16_t)control->mid;
597318e198d3SRandall Stewart 		entry->sz = control->length;
597418e198d3SRandall Stewart 		entry->flgs = control->sinfo_flags;
597518e198d3SRandall Stewart 	}
597618e198d3SRandall Stewart #endif
5977d59107f7SMichael Tuexen 	if ((fromlen > 0) && (from != NULL)) {
5978d59107f7SMichael Tuexen 		union sctp_sockstore store;
5979d59107f7SMichael Tuexen 		size_t len;
5980d59107f7SMichael Tuexen 
5981b5b6e5c2SMichael Tuexen 		switch (control->whoFrom->ro._l_addr.sa.sa_family) {
5982b5b6e5c2SMichael Tuexen #ifdef INET6
5983b5b6e5c2SMichael Tuexen 		case AF_INET6:
5984d59107f7SMichael Tuexen 			len = sizeof(struct sockaddr_in6);
5985d59107f7SMichael Tuexen 			store.sin6 = control->whoFrom->ro._l_addr.sin6;
5986d59107f7SMichael Tuexen 			store.sin6.sin6_port = control->port_from;
5987b5b6e5c2SMichael Tuexen 			break;
5988f8829a4aSRandall Stewart #endif
5989b5b6e5c2SMichael Tuexen #ifdef INET
5990b5b6e5c2SMichael Tuexen 		case AF_INET:
5991d59107f7SMichael Tuexen #ifdef INET6
5992d59107f7SMichael Tuexen 			if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_NEEDS_MAPPED_V4)) {
5993d59107f7SMichael Tuexen 				len = sizeof(struct sockaddr_in6);
5994d59107f7SMichael Tuexen 				in6_sin_2_v4mapsin6(&control->whoFrom->ro._l_addr.sin,
5995d59107f7SMichael Tuexen 				    &store.sin6);
5996d59107f7SMichael Tuexen 				store.sin6.sin6_port = control->port_from;
5997d59107f7SMichael Tuexen 			} else {
5998d59107f7SMichael Tuexen 				len = sizeof(struct sockaddr_in);
5999d59107f7SMichael Tuexen 				store.sin = control->whoFrom->ro._l_addr.sin;
6000d59107f7SMichael Tuexen 				store.sin.sin_port = control->port_from;
6001d59107f7SMichael Tuexen 			}
6002d59107f7SMichael Tuexen #else
6003d59107f7SMichael Tuexen 			len = sizeof(struct sockaddr_in);
6004d59107f7SMichael Tuexen 			store.sin = control->whoFrom->ro._l_addr.sin;
6005d59107f7SMichael Tuexen 			store.sin.sin_port = control->port_from;
6006d59107f7SMichael Tuexen #endif
6007b5b6e5c2SMichael Tuexen 			break;
6008b5b6e5c2SMichael Tuexen #endif
6009b5b6e5c2SMichael Tuexen 		default:
6010d59107f7SMichael Tuexen 			len = 0;
6011b5b6e5c2SMichael Tuexen 			break;
6012b5b6e5c2SMichael Tuexen 		}
6013d59107f7SMichael Tuexen 		memcpy(from, &store, min((size_t)fromlen, len));
6014e0e00a4dSMichael Tuexen #ifdef INET6
6015f8829a4aSRandall Stewart 		{
6016b5b6e5c2SMichael Tuexen 			struct sockaddr_in6 lsa6, *from6;
6017f8829a4aSRandall Stewart 
6018b5b6e5c2SMichael Tuexen 			from6 = (struct sockaddr_in6 *)from;
6019b5b6e5c2SMichael Tuexen 			sctp_recover_scope_mac(from6, (&lsa6));
6020f8829a4aSRandall Stewart 		}
6021f8829a4aSRandall Stewart #endif
6022f8829a4aSRandall Stewart 	}
60239c5ca6f2SMichael Tuexen 	if (hold_rlock) {
60249c5ca6f2SMichael Tuexen 		SCTP_INP_READ_UNLOCK(inp);
60259c5ca6f2SMichael Tuexen 		hold_rlock = 0;
60269c5ca6f2SMichael Tuexen 	}
60279c5ca6f2SMichael Tuexen 	if (hold_sblock) {
60289c5ca6f2SMichael Tuexen 		SOCKBUF_UNLOCK(&so->so_rcv);
60299c5ca6f2SMichael Tuexen 		hold_sblock = 0;
60309c5ca6f2SMichael Tuexen 	}
6031f8829a4aSRandall Stewart 	/* now copy out what data we can */
6032f8829a4aSRandall Stewart 	if (mp == NULL) {
6033f8829a4aSRandall Stewart 		/* copy out each mbuf in the chain up to length */
6034f8829a4aSRandall Stewart get_more_data:
6035f8829a4aSRandall Stewart 		m = control->data;
6036f8829a4aSRandall Stewart 		while (m) {
6037f8829a4aSRandall Stewart 			/* Move out all we can */
60380d3cf13dSMichael Tuexen 			cp_len = uio->uio_resid;
60390d3cf13dSMichael Tuexen 			my_len = SCTP_BUF_LEN(m);
6040f8829a4aSRandall Stewart 			if (cp_len > my_len) {
6041f8829a4aSRandall Stewart 				/* not enough in this buf */
6042f8829a4aSRandall Stewart 				cp_len = my_len;
6043f8829a4aSRandall Stewart 			}
6044f8829a4aSRandall Stewart 			if (hold_rlock) {
6045f8829a4aSRandall Stewart 				SCTP_INP_READ_UNLOCK(inp);
6046f8829a4aSRandall Stewart 				hold_rlock = 0;
6047f8829a4aSRandall Stewart 			}
6048f8829a4aSRandall Stewart 			if (cp_len > 0)
604958e6eeefSMichael Tuexen 				error = uiomove(mtod(m, char *), (int)cp_len, uio);
6050f8829a4aSRandall Stewart 			/* re-read */
6051f8829a4aSRandall Stewart 			if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
6052f8829a4aSRandall Stewart 				goto release;
6053f8829a4aSRandall Stewart 			}
60540053ed28SMichael Tuexen 
60550696e120SRandall Stewart 			if ((control->do_not_ref_stcb == 0) && stcb &&
6056f8829a4aSRandall Stewart 			    stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
6057f8829a4aSRandall Stewart 				no_rcv_needed = 1;
6058f8829a4aSRandall Stewart 			}
6059f8829a4aSRandall Stewart 			if (error) {
6060f8829a4aSRandall Stewart 				/* error we are out of here */
6061f8829a4aSRandall Stewart 				goto release;
6062f8829a4aSRandall Stewart 			}
6063f8829a4aSRandall Stewart 			SCTP_INP_READ_LOCK(inp);
6064f8829a4aSRandall Stewart 			hold_rlock = 1;
6065139bc87fSRandall Stewart 			if (cp_len == SCTP_BUF_LEN(m)) {
6066139bc87fSRandall Stewart 				if ((SCTP_BUF_NEXT(m) == NULL) &&
6067139bc87fSRandall Stewart 				    (control->end_added)) {
6068f8829a4aSRandall Stewart 					out_flags |= MSG_EOR;
606952129fcdSRandall Stewart 					if ((control->do_not_ref_stcb == 0) &&
607052129fcdSRandall Stewart 					    (control->stcb != NULL) &&
607152129fcdSRandall Stewart 					    ((control->spec_flags & M_NOTIFICATION) == 0))
6072ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
6073f8829a4aSRandall Stewart 				}
6074139bc87fSRandall Stewart 				if (control->spec_flags & M_NOTIFICATION) {
6075f8829a4aSRandall Stewart 					out_flags |= MSG_NOTIFICATION;
6076f8829a4aSRandall Stewart 				}
6077f8829a4aSRandall Stewart 				/* we ate up the mbuf */
6078f8829a4aSRandall Stewart 				if (in_flags & MSG_PEEK) {
6079f8829a4aSRandall Stewart 					/* just looking */
6080139bc87fSRandall Stewart 					m = SCTP_BUF_NEXT(m);
6081f8829a4aSRandall Stewart 					copied_so_far += cp_len;
6082f8829a4aSRandall Stewart 				} else {
6083f8829a4aSRandall Stewart 					/* dispose of the mbuf */
6084b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
6085f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv,
6086139bc87fSRandall Stewart 						    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
608780fefe0aSRandall Stewart 					}
6088f8829a4aSRandall Stewart 					sctp_sbfree(control, stcb, &so->so_rcv, m);
6089b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
6090f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv,
6091f8829a4aSRandall Stewart 						    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
609280fefe0aSRandall Stewart 					}
6093f8829a4aSRandall Stewart 					copied_so_far += cp_len;
609458e6eeefSMichael Tuexen 					freed_so_far += (uint32_t)cp_len;
6095c4739e2fSRandall Stewart 					freed_so_far += MSIZE;
6096aab1d593SMichael Tuexen 					atomic_subtract_int(&control->length, (int)cp_len);
6097f8829a4aSRandall Stewart 					control->data = sctp_m_free(m);
6098f8829a4aSRandall Stewart 					m = control->data;
6099b7b84c0eSMichael Tuexen 					/*
6100b7b84c0eSMichael Tuexen 					 * been through it all, must hold sb
6101b7b84c0eSMichael Tuexen 					 * lock ok to null tail
6102b7b84c0eSMichael Tuexen 					 */
6103f8829a4aSRandall Stewart 					if (control->data == NULL) {
6104a5d547adSRandall Stewart #ifdef INVARIANTS
6105f8829a4aSRandall Stewart 						if ((control->end_added == 0) ||
6106f8829a4aSRandall Stewart 						    (TAILQ_NEXT(control, next) == NULL)) {
6107f8829a4aSRandall Stewart 							/*
6108f8829a4aSRandall Stewart 							 * If the end is not
6109f8829a4aSRandall Stewart 							 * added, OR the
6110f8829a4aSRandall Stewart 							 * next is NOT null
6111f8829a4aSRandall Stewart 							 * we MUST have the
6112f8829a4aSRandall Stewart 							 * lock.
6113f8829a4aSRandall Stewart 							 */
6114f8829a4aSRandall Stewart 							if (mtx_owned(&inp->inp_rdata_mtx) == 0) {
6115f8829a4aSRandall Stewart 								panic("Hmm we don't own the lock?");
6116f8829a4aSRandall Stewart 							}
6117f8829a4aSRandall Stewart 						}
6118f8829a4aSRandall Stewart #endif
6119f8829a4aSRandall Stewart 						control->tail_mbuf = NULL;
6120a5d547adSRandall Stewart #ifdef INVARIANTS
6121f8829a4aSRandall Stewart 						if ((control->end_added) && ((out_flags & MSG_EOR) == 0)) {
6122f8829a4aSRandall Stewart 							panic("end_added, nothing left and no MSG_EOR");
6123f8829a4aSRandall Stewart 						}
6124f8829a4aSRandall Stewart #endif
6125f8829a4aSRandall Stewart 					}
6126f8829a4aSRandall Stewart 				}
6127f8829a4aSRandall Stewart 			} else {
6128f8829a4aSRandall Stewart 				/* Do we need to trim the mbuf? */
6129139bc87fSRandall Stewart 				if (control->spec_flags & M_NOTIFICATION) {
6130f8829a4aSRandall Stewart 					out_flags |= MSG_NOTIFICATION;
6131f8829a4aSRandall Stewart 				}
6132f8829a4aSRandall Stewart 				if ((in_flags & MSG_PEEK) == 0) {
6133139bc87fSRandall Stewart 					SCTP_BUF_RESV_UF(m, cp_len);
613458e6eeefSMichael Tuexen 					SCTP_BUF_LEN(m) -= (int)cp_len;
6135b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
613658e6eeefSMichael Tuexen 						sctp_sblog(&so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, (int)cp_len);
613780fefe0aSRandall Stewart 					}
613810b2b306SMichael Tuexen 					SCTP_SB_DECR(&so->so_rcv, cp_len);
61390696e120SRandall Stewart 					if ((control->do_not_ref_stcb == 0) &&
61400696e120SRandall Stewart 					    stcb) {
6141aab1d593SMichael Tuexen 						atomic_subtract_int(&stcb->asoc.sb_cc, (int)cp_len);
6142f8829a4aSRandall Stewart 					}
6143f8829a4aSRandall Stewart 					copied_so_far += cp_len;
614458e6eeefSMichael Tuexen 					freed_so_far += (uint32_t)cp_len;
6145c4739e2fSRandall Stewart 					freed_so_far += MSIZE;
6146b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
6147f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv, control->do_not_ref_stcb ? NULL : stcb,
6148f8829a4aSRandall Stewart 						    SCTP_LOG_SBRESULT, 0);
614980fefe0aSRandall Stewart 					}
6150aab1d593SMichael Tuexen 					atomic_subtract_int(&control->length, (int)cp_len);
6151f8829a4aSRandall Stewart 				} else {
6152f8829a4aSRandall Stewart 					copied_so_far += cp_len;
6153f8829a4aSRandall Stewart 				}
6154f8829a4aSRandall Stewart 			}
6155d61a0ae0SRandall Stewart 			if ((out_flags & MSG_EOR) || (uio->uio_resid == 0)) {
6156f8829a4aSRandall Stewart 				break;
6157f8829a4aSRandall Stewart 			}
6158f8829a4aSRandall Stewart 			if (((stcb) && (in_flags & MSG_PEEK) == 0) &&
6159f8829a4aSRandall Stewart 			    (control->do_not_ref_stcb == 0) &&
6160f8829a4aSRandall Stewart 			    (freed_so_far >= rwnd_req)) {
6161f8829a4aSRandall Stewart 				sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
6162f8829a4aSRandall Stewart 			}
6163f8829a4aSRandall Stewart 		}		/* end while(m) */
6164f8829a4aSRandall Stewart 		/*
6165f8829a4aSRandall Stewart 		 * At this point we have looked at it all and we either have
6166f8829a4aSRandall Stewart 		 * a MSG_EOR/or read all the user wants... <OR>
6167f8829a4aSRandall Stewart 		 * control->length == 0.
6168f8829a4aSRandall Stewart 		 */
6169d61a0ae0SRandall Stewart 		if ((out_flags & MSG_EOR) && ((in_flags & MSG_PEEK) == 0)) {
6170f8829a4aSRandall Stewart 			/* we are done with this control */
6171f8829a4aSRandall Stewart 			if (control->length == 0) {
6172f8829a4aSRandall Stewart 				if (control->data) {
6173a5d547adSRandall Stewart #ifdef INVARIANTS
6174f8829a4aSRandall Stewart 					panic("control->data not null at read eor?");
6175f8829a4aSRandall Stewart #else
6176e7e65008SMichael Tuexen 					SCTP_PRINTF("Strange, data left in the control buffer .. invariants would panic?\n");
6177f8829a4aSRandall Stewart 					sctp_m_freem(control->data);
6178f8829a4aSRandall Stewart 					control->data = NULL;
6179f8829a4aSRandall Stewart #endif
6180f8829a4aSRandall Stewart 				}
6181f8829a4aSRandall Stewart 		done_with_control:
6182f8829a4aSRandall Stewart 				if (hold_rlock == 0) {
6183f8829a4aSRandall Stewart 					SCTP_INP_READ_LOCK(inp);
6184f8829a4aSRandall Stewart 					hold_rlock = 1;
6185f8829a4aSRandall Stewart 				}
6186f8829a4aSRandall Stewart 				TAILQ_REMOVE(&inp->read_queue, control, next);
6187e7e65008SMichael Tuexen 				/* Add back any hidden data */
6188f8829a4aSRandall Stewart 				if (control->held_length) {
6189f8829a4aSRandall Stewart 					held_length = 0;
6190f8829a4aSRandall Stewart 					control->held_length = 0;
6191f8829a4aSRandall Stewart 					wakeup_read_socket = 1;
6192f8829a4aSRandall Stewart 				}
619317205eccSRandall Stewart 				if (control->aux_data) {
619417205eccSRandall Stewart 					sctp_m_free(control->aux_data);
619517205eccSRandall Stewart 					control->aux_data = NULL;
619617205eccSRandall Stewart 				}
6197f8829a4aSRandall Stewart 				no_rcv_needed = control->do_not_ref_stcb;
6198f8829a4aSRandall Stewart 				sctp_free_remote_addr(control->whoFrom);
6199f8829a4aSRandall Stewart 				control->data = NULL;
620098d5fd97SMichael Tuexen #ifdef INVARIANTS
620144249214SRandall Stewart 				if (control->on_strm_q) {
620244249214SRandall Stewart 					panic("About to free ctl:%p so:%p and its in %d",
620344249214SRandall Stewart 					    control, so, control->on_strm_q);
620444249214SRandall Stewart 				}
620598d5fd97SMichael Tuexen #endif
6206f8829a4aSRandall Stewart 				sctp_free_a_readq(stcb, control);
6207f8829a4aSRandall Stewart 				control = NULL;
62080696e120SRandall Stewart 				if ((freed_so_far >= rwnd_req) &&
62090696e120SRandall Stewart 				    (no_rcv_needed == 0))
6210f8829a4aSRandall Stewart 					sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
6211f8829a4aSRandall Stewart 
6212f8829a4aSRandall Stewart 			} else {
6213f8829a4aSRandall Stewart 				/*
6214f8829a4aSRandall Stewart 				 * The user did not read all of this
6215f8829a4aSRandall Stewart 				 * message, turn off the returned MSG_EOR
6216f8829a4aSRandall Stewart 				 * since we are leaving more behind on the
6217f8829a4aSRandall Stewart 				 * control to read.
6218f8829a4aSRandall Stewart 				 */
6219a5d547adSRandall Stewart #ifdef INVARIANTS
62200696e120SRandall Stewart 				if (control->end_added &&
62210696e120SRandall Stewart 				    (control->data == NULL) &&
6222f8829a4aSRandall Stewart 				    (control->tail_mbuf == NULL)) {
6223f8829a4aSRandall Stewart 					panic("Gak, control->length is corrupt?");
6224f8829a4aSRandall Stewart 				}
6225f8829a4aSRandall Stewart #endif
6226f8829a4aSRandall Stewart 				no_rcv_needed = control->do_not_ref_stcb;
6227f8829a4aSRandall Stewart 				out_flags &= ~MSG_EOR;
6228f8829a4aSRandall Stewart 			}
6229f8829a4aSRandall Stewart 		}
6230f8829a4aSRandall Stewart 		if (out_flags & MSG_EOR) {
6231f8829a4aSRandall Stewart 			goto release;
6232f8829a4aSRandall Stewart 		}
6233f8829a4aSRandall Stewart 		if ((uio->uio_resid == 0) ||
623404aab884SMichael Tuexen 		    ((in_eeor_mode) &&
623543ecbff2SMichael Tuexen 		    (copied_so_far >= max(so->so_rcv.sb_lowat, 1)))) {
6236f8829a4aSRandall Stewart 			goto release;
6237f8829a4aSRandall Stewart 		}
6238f8829a4aSRandall Stewart 		/*
6239f8829a4aSRandall Stewart 		 * If I hit here the receiver wants more and this message is
6240f8829a4aSRandall Stewart 		 * NOT done (pd-api). So two questions. Can we block? if not
6241f8829a4aSRandall Stewart 		 * we are done. Did the user NOT set MSG_WAITALL?
6242f8829a4aSRandall Stewart 		 */
6243f8829a4aSRandall Stewart 		if (block_allowed == 0) {
6244f8829a4aSRandall Stewart 			goto release;
6245f8829a4aSRandall Stewart 		}
6246f8829a4aSRandall Stewart 		/*
6247f8829a4aSRandall Stewart 		 * We need to wait for more data a few things: - We don't
6248aab1d593SMichael Tuexen 		 * release the I/O lock so we don't get someone else
6249aab1d593SMichael Tuexen 		 * reading. - We must be sure to account for the case where
6250aab1d593SMichael Tuexen 		 * what is added is NOT to our control when we wakeup.
6251f8829a4aSRandall Stewart 		 */
6252f8829a4aSRandall Stewart 
6253f8829a4aSRandall Stewart 		/*
6254f8829a4aSRandall Stewart 		 * Do we need to tell the transport a rwnd update might be
6255f8829a4aSRandall Stewart 		 * needed before we go to sleep?
6256f8829a4aSRandall Stewart 		 */
6257f8829a4aSRandall Stewart 		if (((stcb) && (in_flags & MSG_PEEK) == 0) &&
6258f8829a4aSRandall Stewart 		    ((freed_so_far >= rwnd_req) &&
6259f8829a4aSRandall Stewart 		    (control->do_not_ref_stcb == 0) &&
6260f8829a4aSRandall Stewart 		    (no_rcv_needed == 0))) {
6261f8829a4aSRandall Stewart 			sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
6262f8829a4aSRandall Stewart 		}
6263f8829a4aSRandall Stewart wait_some_more:
626444b7479bSRandall Stewart 		if (so->so_rcv.sb_state & SBS_CANTRCVMORE) {
6265f8829a4aSRandall Stewart 			goto release;
6266f8829a4aSRandall Stewart 		}
62670053ed28SMichael Tuexen 
6268f8829a4aSRandall Stewart 		if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE)
6269f8829a4aSRandall Stewart 			goto release;
6270f8829a4aSRandall Stewart 
6271f8829a4aSRandall Stewart 		if (hold_rlock == 1) {
6272f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
6273f8829a4aSRandall Stewart 			hold_rlock = 0;
6274f8829a4aSRandall Stewart 		}
6275f8829a4aSRandall Stewart 		if (hold_sblock == 0) {
6276f8829a4aSRandall Stewart 			SOCKBUF_LOCK(&so->so_rcv);
6277f8829a4aSRandall Stewart 			hold_sblock = 1;
6278f8829a4aSRandall Stewart 		}
6279851b7298SRandall Stewart 		if ((copied_so_far) && (control->length == 0) &&
6280b5c16493SMichael Tuexen 		    (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_FRAG_INTERLEAVE))) {
6281851b7298SRandall Stewart 			goto release;
6282851b7298SRandall Stewart 		}
6283edc5b6eaSMichael Tuexen 		if (SCTP_SBAVAIL(&so->so_rcv) <= control->held_length) {
628443283184SGleb Smirnoff 			error = sbwait(so, SO_RCV);
6285f8829a4aSRandall Stewart 			if (error) {
6286f8829a4aSRandall Stewart 				goto release;
6287f8829a4aSRandall Stewart 			}
6288f8829a4aSRandall Stewart 			control->held_length = 0;
6289f8829a4aSRandall Stewart 		}
6290f8829a4aSRandall Stewart 		if (hold_sblock) {
6291f8829a4aSRandall Stewart 			SOCKBUF_UNLOCK(&so->so_rcv);
6292f8829a4aSRandall Stewart 			hold_sblock = 0;
6293f8829a4aSRandall Stewart 		}
6294f8829a4aSRandall Stewart 		if (control->length == 0) {
6295f8829a4aSRandall Stewart 			/* still nothing here */
6296f8829a4aSRandall Stewart 			if (control->end_added == 1) {
6297f8829a4aSRandall Stewart 				/* he aborted, or is done i.e.did a shutdown */
6298f8829a4aSRandall Stewart 				out_flags |= MSG_EOR;
62999a6142d8SRandall Stewart 				if (control->pdapi_aborted) {
63006114cd96SRandall Stewart 					if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
6301ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
63029a6142d8SRandall Stewart 
630303b0b021SRandall Stewart 					out_flags |= MSG_TRUNC;
63049a6142d8SRandall Stewart 				} else {
63056114cd96SRandall Stewart 					if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
6306ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
63079a6142d8SRandall Stewart 				}
6308f8829a4aSRandall Stewart 				goto done_with_control;
6309f8829a4aSRandall Stewart 			}
6310edc5b6eaSMichael Tuexen 			if (SCTP_SBAVAIL(&so->so_rcv) > held_length) {
6311edc5b6eaSMichael Tuexen 				control->held_length = SCTP_SBAVAIL(&so->so_rcv);
6312f8829a4aSRandall Stewart 				held_length = 0;
6313f8829a4aSRandall Stewart 			}
6314f8829a4aSRandall Stewart 			goto wait_some_more;
6315f8829a4aSRandall Stewart 		} else if (control->data == NULL) {
631650cec919SRandall Stewart 			/*
631750cec919SRandall Stewart 			 * we must re-sync since data is probably being
631850cec919SRandall Stewart 			 * added
631950cec919SRandall Stewart 			 */
632050cec919SRandall Stewart 			SCTP_INP_READ_LOCK(inp);
632150cec919SRandall Stewart 			if ((control->length > 0) && (control->data == NULL)) {
6322b7b84c0eSMichael Tuexen 				/*
6323b7b84c0eSMichael Tuexen 				 * big trouble.. we have the lock and its
6324b7b84c0eSMichael Tuexen 				 * corrupt?
6325b7b84c0eSMichael Tuexen 				 */
63269c04b296SRandall Stewart #ifdef INVARIANTS
63279d18771fSRandall Stewart 				panic("Impossible data==NULL length !=0");
63289c04b296SRandall Stewart #endif
63299c04b296SRandall Stewart 				out_flags |= MSG_EOR;
63309c04b296SRandall Stewart 				out_flags |= MSG_TRUNC;
63319c04b296SRandall Stewart 				control->length = 0;
63329c04b296SRandall Stewart 				SCTP_INP_READ_UNLOCK(inp);
63339c04b296SRandall Stewart 				goto done_with_control;
6334f8829a4aSRandall Stewart 			}
633550cec919SRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
633650cec919SRandall Stewart 			/* We will fall around to get more data */
633750cec919SRandall Stewart 		}
6338f8829a4aSRandall Stewart 		goto get_more_data;
6339f8829a4aSRandall Stewart 	} else {
634017205eccSRandall Stewart 		/*-
634117205eccSRandall Stewart 		 * Give caller back the mbuf chain,
634217205eccSRandall Stewart 		 * store in uio_resid the length
6343f8829a4aSRandall Stewart 		 */
634417205eccSRandall Stewart 		wakeup_read_socket = 0;
6345f8829a4aSRandall Stewart 		if ((control->end_added == 0) ||
6346f8829a4aSRandall Stewart 		    (TAILQ_NEXT(control, next) == NULL)) {
6347f8829a4aSRandall Stewart 			/* Need to get rlock */
6348f8829a4aSRandall Stewart 			if (hold_rlock == 0) {
6349f8829a4aSRandall Stewart 				SCTP_INP_READ_LOCK(inp);
6350f8829a4aSRandall Stewart 				hold_rlock = 1;
6351f8829a4aSRandall Stewart 			}
6352f8829a4aSRandall Stewart 		}
6353139bc87fSRandall Stewart 		if (control->end_added) {
6354f8829a4aSRandall Stewart 			out_flags |= MSG_EOR;
635560990c0cSMichael Tuexen 			if ((control->do_not_ref_stcb == 0) &&
635660990c0cSMichael Tuexen 			    (control->stcb != NULL) &&
635760990c0cSMichael Tuexen 			    ((control->spec_flags & M_NOTIFICATION) == 0))
6358ee7f9857SRandall Stewart 				control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
6359f8829a4aSRandall Stewart 		}
6360139bc87fSRandall Stewart 		if (control->spec_flags & M_NOTIFICATION) {
6361f8829a4aSRandall Stewart 			out_flags |= MSG_NOTIFICATION;
6362f8829a4aSRandall Stewart 		}
636317205eccSRandall Stewart 		uio->uio_resid = control->length;
6364f8829a4aSRandall Stewart 		*mp = control->data;
6365f8829a4aSRandall Stewart 		m = control->data;
6366f8829a4aSRandall Stewart 		while (m) {
6367b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
6368f8829a4aSRandall Stewart 				sctp_sblog(&so->so_rcv,
6369139bc87fSRandall Stewart 				    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
637080fefe0aSRandall Stewart 			}
6371f8829a4aSRandall Stewart 			sctp_sbfree(control, stcb, &so->so_rcv, m);
637258e6eeefSMichael Tuexen 			freed_so_far += (uint32_t)SCTP_BUF_LEN(m);
6373c4739e2fSRandall Stewart 			freed_so_far += MSIZE;
6374b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
6375f8829a4aSRandall Stewart 				sctp_sblog(&so->so_rcv,
6376f8829a4aSRandall Stewart 				    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
637780fefe0aSRandall Stewart 			}
6378139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
6379f8829a4aSRandall Stewart 		}
6380f8829a4aSRandall Stewart 		control->data = control->tail_mbuf = NULL;
6381f8829a4aSRandall Stewart 		control->length = 0;
6382f8829a4aSRandall Stewart 		if (out_flags & MSG_EOR) {
6383f8829a4aSRandall Stewart 			/* Done with this control */
6384f8829a4aSRandall Stewart 			goto done_with_control;
6385f8829a4aSRandall Stewart 		}
6386f8829a4aSRandall Stewart 	}
6387f8829a4aSRandall Stewart release:
6388f8829a4aSRandall Stewart 	if (hold_rlock == 1) {
6389f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
6390f8829a4aSRandall Stewart 		hold_rlock = 0;
6391f8829a4aSRandall Stewart 	}
63927abab911SRobert Watson 	if (hold_sblock == 1) {
63937abab911SRobert Watson 		SOCKBUF_UNLOCK(&so->so_rcv);
63947abab911SRobert Watson 		hold_sblock = 0;
6395f8829a4aSRandall Stewart 	}
63960053ed28SMichael Tuexen 
6397f94acf52SMark Johnston 	SOCK_IO_RECV_UNLOCK(so);
63987abab911SRobert Watson 	sockbuf_lock = 0;
6399f8829a4aSRandall Stewart 
6400f8829a4aSRandall Stewart release_unlocked:
6401f8829a4aSRandall Stewart 	if (hold_sblock) {
6402f8829a4aSRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
6403f8829a4aSRandall Stewart 		hold_sblock = 0;
6404f8829a4aSRandall Stewart 	}
6405f8829a4aSRandall Stewart 	if ((stcb) && (in_flags & MSG_PEEK) == 0) {
6406f8829a4aSRandall Stewart 		if ((freed_so_far >= rwnd_req) &&
6407f8829a4aSRandall Stewart 		    (control && (control->do_not_ref_stcb == 0)) &&
6408f8829a4aSRandall Stewart 		    (no_rcv_needed == 0))
6409f8829a4aSRandall Stewart 			sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
6410f8829a4aSRandall Stewart 	}
6411f8829a4aSRandall Stewart out:
64121b9f62a0SRandall Stewart 	if (msg_flags) {
64131b9f62a0SRandall Stewart 		*msg_flags = out_flags;
64141b9f62a0SRandall Stewart 	}
64159a6142d8SRandall Stewart 	if (((out_flags & MSG_EOR) == 0) &&
64169a6142d8SRandall Stewart 	    ((in_flags & MSG_PEEK) == 0) &&
64179a6142d8SRandall Stewart 	    (sinfo) &&
6418e2e7c62eSMichael Tuexen 	    (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXT_RCVINFO) ||
6419e2e7c62eSMichael Tuexen 	    sctp_is_feature_on(inp, SCTP_PCB_FLAGS_RECVNXTINFO))) {
64209a6142d8SRandall Stewart 		struct sctp_extrcvinfo *s_extra;
64219a6142d8SRandall Stewart 
64229a6142d8SRandall Stewart 		s_extra = (struct sctp_extrcvinfo *)sinfo;
6423b70b526dSMichael Tuexen 		s_extra->serinfo_next_flags = SCTP_NO_NEXT_MSG;
64249a6142d8SRandall Stewart 	}
6425f8829a4aSRandall Stewart 	if (hold_rlock == 1) {
6426f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
6427f8829a4aSRandall Stewart 	}
6428f8829a4aSRandall Stewart 	if (hold_sblock) {
6429f8829a4aSRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
6430f8829a4aSRandall Stewart 	}
64317abab911SRobert Watson 	if (sockbuf_lock) {
6432f94acf52SMark Johnston 		SOCK_IO_RECV_UNLOCK(so);
64337abab911SRobert Watson 	}
64340053ed28SMichael Tuexen 
643550cec919SRandall Stewart 	if (freecnt_applied) {
6436f8829a4aSRandall Stewart 		/*
6437f8829a4aSRandall Stewart 		 * The lock on the socket buffer protects us so the free
6438f8829a4aSRandall Stewart 		 * code will stop. But since we used the socketbuf lock and
6439f8829a4aSRandall Stewart 		 * the sender uses the tcb_lock to increment, we need to use
6440f8829a4aSRandall Stewart 		 * the atomic add to the refcnt.
6441f8829a4aSRandall Stewart 		 */
644250cec919SRandall Stewart 		if (stcb == NULL) {
6443df6e0cc3SRandall Stewart #ifdef INVARIANTS
644450cec919SRandall Stewart 			panic("stcb for refcnt has gone NULL?");
6445df6e0cc3SRandall Stewart 			goto stage_left;
6446df6e0cc3SRandall Stewart #else
6447df6e0cc3SRandall Stewart 			goto stage_left;
6448df6e0cc3SRandall Stewart #endif
644950cec919SRandall Stewart 		}
6450f8829a4aSRandall Stewart 		/* Save the value back for next time */
6451f8829a4aSRandall Stewart 		stcb->freed_by_sorcv_sincelast = freed_so_far;
64523c1ba6f3SMichael Tuexen 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
6453f8829a4aSRandall Stewart 	}
6454b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
6455f8829a4aSRandall Stewart 		if (stcb) {
6456f8829a4aSRandall Stewart 			sctp_misc_ints(SCTP_SORECV_DONE,
6457f8829a4aSRandall Stewart 			    freed_so_far,
64589a8e3088SMichael Tuexen 			    (uint32_t)((uio) ? (slen - uio->uio_resid) : slen),
6459f8829a4aSRandall Stewart 			    stcb->asoc.my_rwnd,
6460edc5b6eaSMichael Tuexen 			    SCTP_SBAVAIL(&so->so_rcv));
6461f8829a4aSRandall Stewart 		} else {
6462f8829a4aSRandall Stewart 			sctp_misc_ints(SCTP_SORECV_DONE,
6463f8829a4aSRandall Stewart 			    freed_so_far,
64649a8e3088SMichael Tuexen 			    (uint32_t)((uio) ? (slen - uio->uio_resid) : slen),
6465f8829a4aSRandall Stewart 			    0,
6466edc5b6eaSMichael Tuexen 			    SCTP_SBAVAIL(&so->so_rcv));
6467f8829a4aSRandall Stewart 		}
646880fefe0aSRandall Stewart 	}
6469df6e0cc3SRandall Stewart stage_left:
6470f8829a4aSRandall Stewart 	if (wakeup_read_socket) {
6471f8829a4aSRandall Stewart 		sctp_sorwakeup(inp, so);
6472f8829a4aSRandall Stewart 	}
6473f8829a4aSRandall Stewart 	return (error);
6474f8829a4aSRandall Stewart }
6475f8829a4aSRandall Stewart 
6476f8829a4aSRandall Stewart #ifdef SCTP_MBUF_LOGGING
6477f8829a4aSRandall Stewart struct mbuf *
6478f8829a4aSRandall Stewart sctp_m_free(struct mbuf *m)
6479f8829a4aSRandall Stewart {
6480b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_MBUF_LOGGING_ENABLE) {
6481f8829a4aSRandall Stewart 		sctp_log_mb(m, SCTP_MBUF_IFREE);
6482f8829a4aSRandall Stewart 	}
6483f8829a4aSRandall Stewart 	return (m_free(m));
6484f8829a4aSRandall Stewart }
6485f8829a4aSRandall Stewart 
6486f8829a4aSRandall Stewart void
6487f8829a4aSRandall Stewart sctp_m_freem(struct mbuf *mb)
6488f8829a4aSRandall Stewart {
6489f8829a4aSRandall Stewart 	while (mb != NULL)
6490f8829a4aSRandall Stewart 		mb = sctp_m_free(mb);
6491f8829a4aSRandall Stewart }
6492f8829a4aSRandall Stewart 
6493f8829a4aSRandall Stewart #endif
6494f8829a4aSRandall Stewart 
649542551e99SRandall Stewart int
649642551e99SRandall Stewart sctp_dynamic_set_primary(struct sockaddr *sa, uint32_t vrf_id)
649742551e99SRandall Stewart {
649842551e99SRandall Stewart 	/*
649942551e99SRandall Stewart 	 * Given a local address. For all associations that holds the
650042551e99SRandall Stewart 	 * address, request a peer-set-primary.
650142551e99SRandall Stewart 	 */
650242551e99SRandall Stewart 	struct sctp_ifa *ifa;
650342551e99SRandall Stewart 	struct sctp_laddr *wi;
650442551e99SRandall Stewart 
65057f0ad227SMichael Tuexen 	ifa = sctp_find_ifa_by_addr(sa, vrf_id, SCTP_ADDR_NOT_LOCKED);
650642551e99SRandall Stewart 	if (ifa == NULL) {
6507c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EADDRNOTAVAIL);
650842551e99SRandall Stewart 		return (EADDRNOTAVAIL);
650942551e99SRandall Stewart 	}
651042551e99SRandall Stewart 	/*
651142551e99SRandall Stewart 	 * Now that we have the ifa we must awaken the iterator with this
651242551e99SRandall Stewart 	 * message.
651342551e99SRandall Stewart 	 */
6514b3f1ea41SRandall Stewart 	wi = SCTP_ZONE_GET(SCTP_BASE_INFO(ipi_zone_laddr), struct sctp_laddr);
651542551e99SRandall Stewart 	if (wi == NULL) {
6516c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
651742551e99SRandall Stewart 		return (ENOMEM);
651842551e99SRandall Stewart 	}
651942551e99SRandall Stewart 	/* Now incr the count and int wi structure */
652042551e99SRandall Stewart 	SCTP_INCR_LADDR_COUNT();
65215ba7f91fSMichael Tuexen 	memset(wi, 0, sizeof(*wi));
6522d61a0ae0SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&wi->start_time);
652342551e99SRandall Stewart 	wi->ifa = ifa;
652442551e99SRandall Stewart 	wi->action = SCTP_SET_PRIM_ADDR;
652542551e99SRandall Stewart 	atomic_add_int(&ifa->refcount, 1);
652642551e99SRandall Stewart 
652742551e99SRandall Stewart 	/* Now add it to the work queue */
6528f7517433SRandall Stewart 	SCTP_WQ_ADDR_LOCK();
652942551e99SRandall Stewart 	/*
653042551e99SRandall Stewart 	 * Should this really be a tailq? As it is we will process the
653142551e99SRandall Stewart 	 * newest first :-0
653242551e99SRandall Stewart 	 */
6533b3f1ea41SRandall Stewart 	LIST_INSERT_HEAD(&SCTP_BASE_INFO(addr_wq), wi, sctp_nxt_addr);
653442551e99SRandall Stewart 	sctp_timer_start(SCTP_TIMER_TYPE_ADDR_WQ,
653542551e99SRandall Stewart 	    (struct sctp_inpcb *)NULL,
653642551e99SRandall Stewart 	    (struct sctp_tcb *)NULL,
653742551e99SRandall Stewart 	    (struct sctp_nets *)NULL);
65382c62ba73SMichael Tuexen 	SCTP_WQ_ADDR_UNLOCK();
653942551e99SRandall Stewart 	return (0);
654042551e99SRandall Stewart }
654142551e99SRandall Stewart 
6542f8829a4aSRandall Stewart int
654317205eccSRandall Stewart sctp_soreceive(struct socket *so,
654417205eccSRandall Stewart     struct sockaddr **psa,
654517205eccSRandall Stewart     struct uio *uio,
654617205eccSRandall Stewart     struct mbuf **mp0,
654717205eccSRandall Stewart     struct mbuf **controlp,
654817205eccSRandall Stewart     int *flagsp)
6549f8829a4aSRandall Stewart {
6550f8829a4aSRandall Stewart 	int error, fromlen;
6551f8829a4aSRandall Stewart 	uint8_t sockbuf[256];
6552f8829a4aSRandall Stewart 	struct sockaddr *from;
6553f8829a4aSRandall Stewart 	struct sctp_extrcvinfo sinfo;
6554f8829a4aSRandall Stewart 	int filling_sinfo = 1;
655546bf534cSMichael Tuexen 	int flags;
6556f8829a4aSRandall Stewart 	struct sctp_inpcb *inp;
6557f8829a4aSRandall Stewart 
6558f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)so->so_pcb;
6559f8829a4aSRandall Stewart 	/* pickup the assoc we are reading from */
6560f8829a4aSRandall Stewart 	if (inp == NULL) {
6561c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6562f8829a4aSRandall Stewart 		return (EINVAL);
6563f8829a4aSRandall Stewart 	}
6564e2e7c62eSMichael Tuexen 	if ((sctp_is_feature_off(inp, SCTP_PCB_FLAGS_RECVDATAIOEVNT) &&
6565e2e7c62eSMichael Tuexen 	    sctp_is_feature_off(inp, SCTP_PCB_FLAGS_RECVRCVINFO) &&
6566e2e7c62eSMichael Tuexen 	    sctp_is_feature_off(inp, SCTP_PCB_FLAGS_RECVNXTINFO)) ||
6567f8829a4aSRandall Stewart 	    (controlp == NULL)) {
6568f8829a4aSRandall Stewart 		/* user does not want the sndrcv ctl */
6569f8829a4aSRandall Stewart 		filling_sinfo = 0;
6570f8829a4aSRandall Stewart 	}
6571f8829a4aSRandall Stewart 	if (psa) {
6572f8829a4aSRandall Stewart 		from = (struct sockaddr *)sockbuf;
6573f8829a4aSRandall Stewart 		fromlen = sizeof(sockbuf);
6574f8829a4aSRandall Stewart 		from->sa_len = 0;
6575f8829a4aSRandall Stewart 	} else {
6576f8829a4aSRandall Stewart 		from = NULL;
6577f8829a4aSRandall Stewart 		fromlen = 0;
6578f8829a4aSRandall Stewart 	}
6579f8829a4aSRandall Stewart 
6580e432298aSXin LI 	if (filling_sinfo) {
6581e432298aSXin LI 		memset(&sinfo, 0, sizeof(struct sctp_extrcvinfo));
6582e432298aSXin LI 	}
658346bf534cSMichael Tuexen 	if (flagsp != NULL) {
658446bf534cSMichael Tuexen 		flags = *flagsp;
658546bf534cSMichael Tuexen 	} else {
658646bf534cSMichael Tuexen 		flags = 0;
658746bf534cSMichael Tuexen 	}
658846bf534cSMichael Tuexen 	error = sctp_sorecvmsg(so, uio, mp0, from, fromlen, &flags,
6589f8829a4aSRandall Stewart 	    (struct sctp_sndrcvinfo *)&sinfo, filling_sinfo);
659046bf534cSMichael Tuexen 	if (flagsp != NULL) {
659146bf534cSMichael Tuexen 		*flagsp = flags;
659246bf534cSMichael Tuexen 	}
6593e432298aSXin LI 	if (controlp != NULL) {
6594f8829a4aSRandall Stewart 		/* copy back the sinfo in a CMSG format */
659546bf534cSMichael Tuexen 		if (filling_sinfo && ((flags & MSG_NOTIFICATION) == 0)) {
6596f8829a4aSRandall Stewart 			*controlp = sctp_build_ctl_nchunk(inp,
6597f8829a4aSRandall Stewart 			    (struct sctp_sndrcvinfo *)&sinfo);
659846bf534cSMichael Tuexen 		} else {
6599f8829a4aSRandall Stewart 			*controlp = NULL;
6600f8829a4aSRandall Stewart 		}
660146bf534cSMichael Tuexen 	}
6602f8829a4aSRandall Stewart 	if (psa) {
6603f8829a4aSRandall Stewart 		/* copy back the address info */
6604f8829a4aSRandall Stewart 		if (from && from->sa_len) {
6605f8829a4aSRandall Stewart 			*psa = sodupsockaddr(from, M_NOWAIT);
6606f8829a4aSRandall Stewart 		} else {
6607f8829a4aSRandall Stewart 			*psa = NULL;
6608f8829a4aSRandall Stewart 		}
6609f8829a4aSRandall Stewart 	}
6610f8829a4aSRandall Stewart 	return (error);
6611f8829a4aSRandall Stewart }
661217205eccSRandall Stewart 
661317205eccSRandall Stewart int
6614d61a0ae0SRandall Stewart sctp_connectx_helper_add(struct sctp_tcb *stcb, struct sockaddr *addr,
6615d61a0ae0SRandall Stewart     int totaddr, int *error)
661617205eccSRandall Stewart {
661717205eccSRandall Stewart 	int added = 0;
661817205eccSRandall Stewart 	int i;
661917205eccSRandall Stewart 	struct sctp_inpcb *inp;
662017205eccSRandall Stewart 	struct sockaddr *sa;
662117205eccSRandall Stewart 	size_t incr = 0;
662292776dfdSMichael Tuexen #ifdef INET
662392776dfdSMichael Tuexen 	struct sockaddr_in *sin;
662492776dfdSMichael Tuexen #endif
662592776dfdSMichael Tuexen #ifdef INET6
662692776dfdSMichael Tuexen 	struct sockaddr_in6 *sin6;
662792776dfdSMichael Tuexen #endif
662892776dfdSMichael Tuexen 
662917205eccSRandall Stewart 	sa = addr;
663017205eccSRandall Stewart 	inp = stcb->sctp_ep;
663117205eccSRandall Stewart 	*error = 0;
663217205eccSRandall Stewart 	for (i = 0; i < totaddr; i++) {
6633ea5eba11SMichael Tuexen 		switch (sa->sa_family) {
6634ea5eba11SMichael Tuexen #ifdef INET
6635ea5eba11SMichael Tuexen 		case AF_INET:
663617205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in);
663792776dfdSMichael Tuexen 			sin = (struct sockaddr_in *)sa;
663892776dfdSMichael Tuexen 			if ((sin->sin_addr.s_addr == INADDR_ANY) ||
663992776dfdSMichael Tuexen 			    (sin->sin_addr.s_addr == INADDR_BROADCAST) ||
664092776dfdSMichael Tuexen 			    IN_MULTICAST(ntohl(sin->sin_addr.s_addr))) {
664192776dfdSMichael Tuexen 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6642ba785902SMichael Tuexen 				(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
6643ba785902SMichael Tuexen 				    SCTP_FROM_SCTPUTIL + SCTP_LOC_7);
664492776dfdSMichael Tuexen 				*error = EINVAL;
664592776dfdSMichael Tuexen 				goto out_now;
664692776dfdSMichael Tuexen 			}
66477154bf4aSMichael Tuexen 			if (sctp_add_remote_addr(stcb, sa, NULL, stcb->asoc.port,
66487154bf4aSMichael Tuexen 			    SCTP_DONOT_SETSCOPE,
66497154bf4aSMichael Tuexen 			    SCTP_ADDR_IS_CONFIRMED)) {
665017205eccSRandall Stewart 				/* assoc gone no un-lock */
6651c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOBUFS);
6652ba785902SMichael Tuexen 				(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
6653ba785902SMichael Tuexen 				    SCTP_FROM_SCTPUTIL + SCTP_LOC_8);
665417205eccSRandall Stewart 				*error = ENOBUFS;
665517205eccSRandall Stewart 				goto out_now;
665617205eccSRandall Stewart 			}
665717205eccSRandall Stewart 			added++;
6658ea5eba11SMichael Tuexen 			break;
6659ea5eba11SMichael Tuexen #endif
6660ea5eba11SMichael Tuexen #ifdef INET6
6661ea5eba11SMichael Tuexen 		case AF_INET6:
666217205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in6);
666392776dfdSMichael Tuexen 			sin6 = (struct sockaddr_in6 *)sa;
666492776dfdSMichael Tuexen 			if (IN6_IS_ADDR_UNSPECIFIED(&sin6->sin6_addr) ||
666592776dfdSMichael Tuexen 			    IN6_IS_ADDR_MULTICAST(&sin6->sin6_addr)) {
666692776dfdSMichael Tuexen 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6667ba785902SMichael Tuexen 				(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
6668ba785902SMichael Tuexen 				    SCTP_FROM_SCTPUTIL + SCTP_LOC_9);
666992776dfdSMichael Tuexen 				*error = EINVAL;
667092776dfdSMichael Tuexen 				goto out_now;
667192776dfdSMichael Tuexen 			}
66727154bf4aSMichael Tuexen 			if (sctp_add_remote_addr(stcb, sa, NULL, stcb->asoc.port,
66737154bf4aSMichael Tuexen 			    SCTP_DONOT_SETSCOPE,
66747154bf4aSMichael Tuexen 			    SCTP_ADDR_IS_CONFIRMED)) {
667517205eccSRandall Stewart 				/* assoc gone no un-lock */
6676c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOBUFS);
6677ba785902SMichael Tuexen 				(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
6678ba785902SMichael Tuexen 				    SCTP_FROM_SCTPUTIL + SCTP_LOC_10);
667917205eccSRandall Stewart 				*error = ENOBUFS;
668017205eccSRandall Stewart 				goto out_now;
668117205eccSRandall Stewart 			}
668217205eccSRandall Stewart 			added++;
6683ea5eba11SMichael Tuexen 			break;
6684ea5eba11SMichael Tuexen #endif
6685ea5eba11SMichael Tuexen 		default:
6686ea5eba11SMichael Tuexen 			break;
668717205eccSRandall Stewart 		}
668817205eccSRandall Stewart 		sa = (struct sockaddr *)((caddr_t)sa + incr);
668917205eccSRandall Stewart 	}
669017205eccSRandall Stewart out_now:
669117205eccSRandall Stewart 	return (added);
669217205eccSRandall Stewart }
669317205eccSRandall Stewart 
6694fc26bf71SMichael Tuexen int
6695d61a0ae0SRandall Stewart sctp_connectx_helper_find(struct sctp_inpcb *inp, struct sockaddr *addr,
6696fc26bf71SMichael Tuexen     unsigned int totaddr,
6697fc26bf71SMichael Tuexen     unsigned int *num_v4, unsigned int *num_v6,
6698fc26bf71SMichael Tuexen     unsigned int limit)
669917205eccSRandall Stewart {
670017205eccSRandall Stewart 	struct sockaddr *sa;
6701fc26bf71SMichael Tuexen 	struct sctp_tcb *stcb;
67029a8e3088SMichael Tuexen 	unsigned int incr, at, i;
670317205eccSRandall Stewart 
6704e1949767SMichael Tuexen 	at = 0;
670517205eccSRandall Stewart 	sa = addr;
6706fc26bf71SMichael Tuexen 	*num_v6 = *num_v4 = 0;
670717205eccSRandall Stewart 	/* account and validate addresses */
6708fc26bf71SMichael Tuexen 	if (totaddr == 0) {
6709fc26bf71SMichael Tuexen 		return (EINVAL);
6710fc26bf71SMichael Tuexen 	}
6711fc26bf71SMichael Tuexen 	for (i = 0; i < totaddr; i++) {
6712fc26bf71SMichael Tuexen 		if (at + sizeof(struct sockaddr) > limit) {
6713fc26bf71SMichael Tuexen 			return (EINVAL);
6714fc26bf71SMichael Tuexen 		}
6715ea5eba11SMichael Tuexen 		switch (sa->sa_family) {
6716ea5eba11SMichael Tuexen #ifdef INET
6717ea5eba11SMichael Tuexen 		case AF_INET:
6718e1949767SMichael Tuexen 			incr = (unsigned int)sizeof(struct sockaddr_in);
6719d61a0ae0SRandall Stewart 			if (sa->sa_len != incr) {
6720fc26bf71SMichael Tuexen 				return (EINVAL);
6721d61a0ae0SRandall Stewart 			}
67229a8e3088SMichael Tuexen 			(*num_v4) += 1;
6723ea5eba11SMichael Tuexen 			break;
6724ea5eba11SMichael Tuexen #endif
6725ea5eba11SMichael Tuexen #ifdef INET6
6726ea5eba11SMichael Tuexen 		case AF_INET6:
6727ea5eba11SMichael Tuexen 			{
672817205eccSRandall Stewart 				struct sockaddr_in6 *sin6;
672917205eccSRandall Stewart 
6730112899c6SMichael Tuexen 				incr = (unsigned int)sizeof(struct sockaddr_in6);
6731112899c6SMichael Tuexen 				if (sa->sa_len != incr) {
6732112899c6SMichael Tuexen 					return (EINVAL);
6733112899c6SMichael Tuexen 				}
673417205eccSRandall Stewart 				sin6 = (struct sockaddr_in6 *)sa;
673517205eccSRandall Stewart 				if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
673617205eccSRandall Stewart 					/* Must be non-mapped for connectx */
6737fc26bf71SMichael Tuexen 					return (EINVAL);
673817205eccSRandall Stewart 				}
67399a8e3088SMichael Tuexen 				(*num_v6) += 1;
6740ea5eba11SMichael Tuexen 				break;
6741ea5eba11SMichael Tuexen 			}
6742ea5eba11SMichael Tuexen #endif
6743ea5eba11SMichael Tuexen 		default:
6744fc26bf71SMichael Tuexen 			return (EINVAL);
674517205eccSRandall Stewart 		}
6746fc26bf71SMichael Tuexen 		if ((at + incr) > limit) {
6747fc26bf71SMichael Tuexen 			return (EINVAL);
6748ea5eba11SMichael Tuexen 		}
6749d61a0ae0SRandall Stewart 		SCTP_INP_INCR_REF(inp);
675017205eccSRandall Stewart 		stcb = sctp_findassociation_ep_addr(&inp, sa, NULL, NULL, NULL);
675117205eccSRandall Stewart 		if (stcb != NULL) {
6752fc26bf71SMichael Tuexen 			SCTP_TCB_UNLOCK(stcb);
6753fc26bf71SMichael Tuexen 			return (EALREADY);
6754d61a0ae0SRandall Stewart 		} else {
6755d61a0ae0SRandall Stewart 			SCTP_INP_DECR_REF(inp);
675617205eccSRandall Stewart 		}
6757fc26bf71SMichael Tuexen 		at += incr;
675817205eccSRandall Stewart 		sa = (struct sockaddr *)((caddr_t)sa + incr);
675917205eccSRandall Stewart 	}
6760fc26bf71SMichael Tuexen 	return (0);
676117205eccSRandall Stewart }
676235918f85SRandall Stewart 
676335918f85SRandall Stewart /*
676435918f85SRandall Stewart  * sctp_bindx(ADD) for one address.
676535918f85SRandall Stewart  * assumes all arguments are valid/checked by caller.
676635918f85SRandall Stewart  */
676735918f85SRandall Stewart void
676835918f85SRandall Stewart sctp_bindx_add_address(struct socket *so, struct sctp_inpcb *inp,
67697621bd5eSMichael Tuexen     struct sockaddr *sa, uint32_t vrf_id, int *error,
67707621bd5eSMichael Tuexen     void *p)
677135918f85SRandall Stewart {
6772d59107f7SMichael Tuexen #if defined(INET) && defined(INET6)
677335918f85SRandall Stewart 	struct sockaddr_in sin;
67745e2c2d87SRandall Stewart #endif
67757621bd5eSMichael Tuexen #ifdef INET6
67767621bd5eSMichael Tuexen 	struct sockaddr_in6 *sin6;
67777621bd5eSMichael Tuexen #endif
67787621bd5eSMichael Tuexen #ifdef INET
67797621bd5eSMichael Tuexen 	struct sockaddr_in *sinp;
67807621bd5eSMichael Tuexen #endif
67817621bd5eSMichael Tuexen 	struct sockaddr *addr_to_use;
67827621bd5eSMichael Tuexen 	struct sctp_inpcb *lep;
67837621bd5eSMichael Tuexen 	uint16_t port;
67845e2c2d87SRandall Stewart 
678535918f85SRandall Stewart 	/* see if we're bound all already! */
678635918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
6787c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
678835918f85SRandall Stewart 		*error = EINVAL;
678935918f85SRandall Stewart 		return;
679035918f85SRandall Stewart 	}
67917621bd5eSMichael Tuexen 	switch (sa->sa_family) {
6792ea5eba11SMichael Tuexen #ifdef INET6
67937621bd5eSMichael Tuexen 	case AF_INET6:
679435918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in6)) {
6795c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
679635918f85SRandall Stewart 			*error = EINVAL;
679735918f85SRandall Stewart 			return;
679835918f85SRandall Stewart 		}
6799db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) == 0) {
6800db4fd95bSRandall Stewart 			/* can only bind v6 on PF_INET6 sockets */
6801c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6802db4fd95bSRandall Stewart 			*error = EINVAL;
6803db4fd95bSRandall Stewart 			return;
6804db4fd95bSRandall Stewart 		}
68057621bd5eSMichael Tuexen 		sin6 = (struct sockaddr_in6 *)sa;
68067621bd5eSMichael Tuexen 		port = sin6->sin6_port;
6807d59107f7SMichael Tuexen #ifdef INET
680835918f85SRandall Stewart 		if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
6809db4fd95bSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6810db4fd95bSRandall Stewart 			    SCTP_IPV6_V6ONLY(inp)) {
6811db4fd95bSRandall Stewart 				/* can't bind v4-mapped on PF_INET sockets */
6812c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6813db4fd95bSRandall Stewart 				*error = EINVAL;
6814db4fd95bSRandall Stewart 				return;
6815db4fd95bSRandall Stewart 			}
681635918f85SRandall Stewart 			in6_sin6_2_sin(&sin, sin6);
68177621bd5eSMichael Tuexen 			addr_to_use = (struct sockaddr *)&sin;
68187621bd5eSMichael Tuexen 		} else {
68197621bd5eSMichael Tuexen 			addr_to_use = sa;
682035918f85SRandall Stewart 		}
68215087b6e7SMichael Tuexen #else
68225087b6e7SMichael Tuexen 		addr_to_use = sa;
6823d59107f7SMichael Tuexen #endif
68247621bd5eSMichael Tuexen 		break;
682535918f85SRandall Stewart #endif
6826ea5eba11SMichael Tuexen #ifdef INET
68277621bd5eSMichael Tuexen 	case AF_INET:
682835918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in)) {
6829c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
683035918f85SRandall Stewart 			*error = EINVAL;
683135918f85SRandall Stewart 			return;
683235918f85SRandall Stewart 		}
6833db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6834db4fd95bSRandall Stewart 		    SCTP_IPV6_V6ONLY(inp)) {
6835db4fd95bSRandall Stewart 			/* can't bind v4 on PF_INET sockets */
6836c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6837db4fd95bSRandall Stewart 			*error = EINVAL;
6838db4fd95bSRandall Stewart 			return;
6839db4fd95bSRandall Stewart 		}
68407621bd5eSMichael Tuexen 		sinp = (struct sockaddr_in *)sa;
68417621bd5eSMichael Tuexen 		port = sinp->sin_port;
68427621bd5eSMichael Tuexen 		addr_to_use = sa;
68437621bd5eSMichael Tuexen 		break;
6844ea5eba11SMichael Tuexen #endif
68457621bd5eSMichael Tuexen 	default:
68467621bd5eSMichael Tuexen 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
68477621bd5eSMichael Tuexen 		*error = EINVAL;
68487621bd5eSMichael Tuexen 		return;
68497621bd5eSMichael Tuexen 	}
685035918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_UNBOUND) {
685135918f85SRandall Stewart 		if (p == NULL) {
685235918f85SRandall Stewart 			/* Can't get proc for Net/Open BSD */
6853c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
685435918f85SRandall Stewart 			*error = EINVAL;
685535918f85SRandall Stewart 			return;
685635918f85SRandall Stewart 		}
68577621bd5eSMichael Tuexen 		*error = sctp_inpcb_bind(so, addr_to_use, NULL, p);
685835918f85SRandall Stewart 		return;
685935918f85SRandall Stewart 	}
68607621bd5eSMichael Tuexen 	/* Validate the incoming port. */
68617621bd5eSMichael Tuexen 	if ((port != 0) && (port != inp->sctp_lport)) {
6862c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
686397c76f10SRandall Stewart 		*error = EINVAL;
686497c76f10SRandall Stewart 		return;
686597c76f10SRandall Stewart 	}
68667621bd5eSMichael Tuexen 	lep = sctp_pcb_findep(addr_to_use, 1, 0, vrf_id);
68677621bd5eSMichael Tuexen 	if (lep == NULL) {
68687621bd5eSMichael Tuexen 		/* add the address */
68697621bd5eSMichael Tuexen 		*error = sctp_addr_mgmt_ep_sa(inp, addr_to_use,
68707a9dbc33SMichael Tuexen 		    SCTP_ADD_IP_ADDRESS, vrf_id);
687135918f85SRandall Stewart 	} else {
68727621bd5eSMichael Tuexen 		if (lep != inp) {
687335918f85SRandall Stewart 			*error = EADDRINUSE;
687435918f85SRandall Stewart 		}
68757621bd5eSMichael Tuexen 		SCTP_INP_DECR_REF(lep);
687635918f85SRandall Stewart 	}
687735918f85SRandall Stewart }
687835918f85SRandall Stewart 
687935918f85SRandall Stewart /*
688035918f85SRandall Stewart  * sctp_bindx(DELETE) for one address.
688135918f85SRandall Stewart  * assumes all arguments are valid/checked by caller.
688235918f85SRandall Stewart  */
688335918f85SRandall Stewart void
68847215cc1bSMichael Tuexen sctp_bindx_delete_address(struct sctp_inpcb *inp,
68857621bd5eSMichael Tuexen     struct sockaddr *sa, uint32_t vrf_id, int *error)
688635918f85SRandall Stewart {
68877621bd5eSMichael Tuexen 	struct sockaddr *addr_to_use;
6888d59107f7SMichael Tuexen #if defined(INET) && defined(INET6)
68897621bd5eSMichael Tuexen 	struct sockaddr_in6 *sin6;
689035918f85SRandall Stewart 	struct sockaddr_in sin;
68915e2c2d87SRandall Stewart #endif
68925e2c2d87SRandall Stewart 
689335918f85SRandall Stewart 	/* see if we're bound all already! */
689435918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
6895c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
689635918f85SRandall Stewart 		*error = EINVAL;
689735918f85SRandall Stewart 		return;
689835918f85SRandall Stewart 	}
68997621bd5eSMichael Tuexen 	switch (sa->sa_family) {
6900e0e00a4dSMichael Tuexen #ifdef INET6
69017621bd5eSMichael Tuexen 	case AF_INET6:
690235918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in6)) {
6903c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
690435918f85SRandall Stewart 			*error = EINVAL;
690535918f85SRandall Stewart 			return;
690635918f85SRandall Stewart 		}
6907db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) == 0) {
6908db4fd95bSRandall Stewart 			/* can only bind v6 on PF_INET6 sockets */
6909c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6910db4fd95bSRandall Stewart 			*error = EINVAL;
6911db4fd95bSRandall Stewart 			return;
6912db4fd95bSRandall Stewart 		}
6913d59107f7SMichael Tuexen #ifdef INET
69147621bd5eSMichael Tuexen 		sin6 = (struct sockaddr_in6 *)sa;
691535918f85SRandall Stewart 		if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
6916db4fd95bSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6917db4fd95bSRandall Stewart 			    SCTP_IPV6_V6ONLY(inp)) {
6918db4fd95bSRandall Stewart 				/* can't bind mapped-v4 on PF_INET sockets */
6919c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6920db4fd95bSRandall Stewart 				*error = EINVAL;
6921db4fd95bSRandall Stewart 				return;
6922db4fd95bSRandall Stewart 			}
692335918f85SRandall Stewart 			in6_sin6_2_sin(&sin, sin6);
69247621bd5eSMichael Tuexen 			addr_to_use = (struct sockaddr *)&sin;
69257621bd5eSMichael Tuexen 		} else {
69267621bd5eSMichael Tuexen 			addr_to_use = sa;
692735918f85SRandall Stewart 		}
6928171edd21SMichael Tuexen #else
6929171edd21SMichael Tuexen 		addr_to_use = sa;
6930d59107f7SMichael Tuexen #endif
69317621bd5eSMichael Tuexen 		break;
693235918f85SRandall Stewart #endif
6933ea5eba11SMichael Tuexen #ifdef INET
69347621bd5eSMichael Tuexen 	case AF_INET:
693535918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in)) {
6936c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
693735918f85SRandall Stewart 			*error = EINVAL;
693835918f85SRandall Stewart 			return;
693935918f85SRandall Stewart 		}
6940db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6941db4fd95bSRandall Stewart 		    SCTP_IPV6_V6ONLY(inp)) {
6942db4fd95bSRandall Stewart 			/* can't bind v4 on PF_INET sockets */
6943c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6944db4fd95bSRandall Stewart 			*error = EINVAL;
6945db4fd95bSRandall Stewart 			return;
6946db4fd95bSRandall Stewart 		}
69477621bd5eSMichael Tuexen 		addr_to_use = sa;
69487621bd5eSMichael Tuexen 		break;
6949ea5eba11SMichael Tuexen #endif
69507621bd5eSMichael Tuexen 	default:
69517621bd5eSMichael Tuexen 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
69527621bd5eSMichael Tuexen 		*error = EINVAL;
69537621bd5eSMichael Tuexen 		return;
695435918f85SRandall Stewart 	}
69557621bd5eSMichael Tuexen 	/* No lock required mgmt_ep_sa does its own locking. */
69567621bd5eSMichael Tuexen 	*error = sctp_addr_mgmt_ep_sa(inp, addr_to_use, SCTP_DEL_IP_ADDRESS,
69577621bd5eSMichael Tuexen 	    vrf_id);
695835918f85SRandall Stewart }
69591b649582SRandall Stewart 
69601b649582SRandall Stewart /*
69611b649582SRandall Stewart  * returns the valid local address count for an assoc, taking into account
69621b649582SRandall Stewart  * all scoping rules
69631b649582SRandall Stewart  */
69641b649582SRandall Stewart int
69651b649582SRandall Stewart sctp_local_addr_count(struct sctp_tcb *stcb)
69661b649582SRandall Stewart {
6967b54ddf22SMichael Tuexen 	int loopback_scope;
6968b54ddf22SMichael Tuexen #if defined(INET)
6969b54ddf22SMichael Tuexen 	int ipv4_local_scope, ipv4_addr_legal;
6970b54ddf22SMichael Tuexen #endif
6971b54ddf22SMichael Tuexen #if defined(INET6)
6972b54ddf22SMichael Tuexen 	int local_scope, site_scope, ipv6_addr_legal;
6973b54ddf22SMichael Tuexen #endif
69741b649582SRandall Stewart 	struct sctp_vrf *vrf;
69751b649582SRandall Stewart 	struct sctp_ifn *sctp_ifn;
69761b649582SRandall Stewart 	struct sctp_ifa *sctp_ifa;
69771b649582SRandall Stewart 	int count = 0;
69781b649582SRandall Stewart 
69791b649582SRandall Stewart 	/* Turn on all the appropriate scopes */
6980a1cb341bSMichael Tuexen 	loopback_scope = stcb->asoc.scope.loopback_scope;
6981b54ddf22SMichael Tuexen #if defined(INET)
6982a1cb341bSMichael Tuexen 	ipv4_local_scope = stcb->asoc.scope.ipv4_local_scope;
6983b54ddf22SMichael Tuexen 	ipv4_addr_legal = stcb->asoc.scope.ipv4_addr_legal;
6984b54ddf22SMichael Tuexen #endif
6985b54ddf22SMichael Tuexen #if defined(INET6)
6986a1cb341bSMichael Tuexen 	local_scope = stcb->asoc.scope.local_scope;
6987a1cb341bSMichael Tuexen 	site_scope = stcb->asoc.scope.site_scope;
6988a1cb341bSMichael Tuexen 	ipv6_addr_legal = stcb->asoc.scope.ipv6_addr_legal;
6989b54ddf22SMichael Tuexen #endif
6990c99efcf6SRandall Stewart 	SCTP_IPI_ADDR_RLOCK();
69911b649582SRandall Stewart 	vrf = sctp_find_vrf(stcb->asoc.vrf_id);
69921b649582SRandall Stewart 	if (vrf == NULL) {
69931b649582SRandall Stewart 		/* no vrf, no addresses */
6994c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RUNLOCK();
69951b649582SRandall Stewart 		return (0);
69961b649582SRandall Stewart 	}
69970053ed28SMichael Tuexen 
69981b649582SRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
69991b649582SRandall Stewart 		/*
70001b649582SRandall Stewart 		 * bound all case: go through all ifns on the vrf
70011b649582SRandall Stewart 		 */
70021b649582SRandall Stewart 		LIST_FOREACH(sctp_ifn, &vrf->ifnlist, next_ifn) {
70031b649582SRandall Stewart 			if ((loopback_scope == 0) &&
70041b649582SRandall Stewart 			    SCTP_IFN_IS_IFT_LOOP(sctp_ifn)) {
70051b649582SRandall Stewart 				continue;
70061b649582SRandall Stewart 			}
70071b649582SRandall Stewart 			LIST_FOREACH(sctp_ifa, &sctp_ifn->ifalist, next_ifa) {
70081b649582SRandall Stewart 				if (sctp_is_addr_restricted(stcb, sctp_ifa))
70091b649582SRandall Stewart 					continue;
70105e2c2d87SRandall Stewart 				switch (sctp_ifa->address.sa.sa_family) {
7011ea5eba11SMichael Tuexen #ifdef INET
70125e2c2d87SRandall Stewart 				case AF_INET:
70135e2c2d87SRandall Stewart 					if (ipv4_addr_legal) {
70141b649582SRandall Stewart 						struct sockaddr_in *sin;
70151b649582SRandall Stewart 
701624aaac8dSMichael Tuexen 						sin = &sctp_ifa->address.sin;
70171b649582SRandall Stewart 						if (sin->sin_addr.s_addr == 0) {
7018b7b84c0eSMichael Tuexen 							/*
7019b7b84c0eSMichael Tuexen 							 * skip unspecified
7020b7b84c0eSMichael Tuexen 							 * addrs
7021b7b84c0eSMichael Tuexen 							 */
70221b649582SRandall Stewart 							continue;
70231b649582SRandall Stewart 						}
70246ba22f19SMichael Tuexen 						if (prison_check_ip4(stcb->sctp_ep->ip_inp.inp.inp_cred,
70256ba22f19SMichael Tuexen 						    &sin->sin_addr) != 0) {
70266ba22f19SMichael Tuexen 							continue;
70276ba22f19SMichael Tuexen 						}
70281b649582SRandall Stewart 						if ((ipv4_local_scope == 0) &&
70291b649582SRandall Stewart 						    (IN4_ISPRIVATE_ADDRESS(&sin->sin_addr))) {
70301b649582SRandall Stewart 							continue;
70311b649582SRandall Stewart 						}
70321b649582SRandall Stewart 						/* count this one */
70331b649582SRandall Stewart 						count++;
70345e2c2d87SRandall Stewart 					} else {
70355e2c2d87SRandall Stewart 						continue;
70365e2c2d87SRandall Stewart 					}
70375e2c2d87SRandall Stewart 					break;
7038ea5eba11SMichael Tuexen #endif
70395e2c2d87SRandall Stewart #ifdef INET6
70405e2c2d87SRandall Stewart 				case AF_INET6:
70415e2c2d87SRandall Stewart 					if (ipv6_addr_legal) {
70421b649582SRandall Stewart 						struct sockaddr_in6 *sin6;
70431b649582SRandall Stewart 
704424aaac8dSMichael Tuexen 						sin6 = &sctp_ifa->address.sin6;
70451b649582SRandall Stewart 						if (IN6_IS_ADDR_UNSPECIFIED(&sin6->sin6_addr)) {
70461b649582SRandall Stewart 							continue;
70471b649582SRandall Stewart 						}
70486ba22f19SMichael Tuexen 						if (prison_check_ip6(stcb->sctp_ep->ip_inp.inp.inp_cred,
70496ba22f19SMichael Tuexen 						    &sin6->sin6_addr) != 0) {
70506ba22f19SMichael Tuexen 							continue;
70516ba22f19SMichael Tuexen 						}
70521b649582SRandall Stewart 						if (IN6_IS_ADDR_LINKLOCAL(&sin6->sin6_addr)) {
70531b649582SRandall Stewart 							if (local_scope == 0)
70541b649582SRandall Stewart 								continue;
70551b649582SRandall Stewart 							if (sin6->sin6_scope_id == 0) {
70561b649582SRandall Stewart 								if (sa6_recoverscope(sin6) != 0)
70571b649582SRandall Stewart 									/*
70585e2c2d87SRandall Stewart 									 *
70595e2c2d87SRandall Stewart 									 * bad
70605b495f17SMichael Tuexen 									 * link
70615e2c2d87SRandall Stewart 									 *
70625b495f17SMichael Tuexen 									 * local
70635e2c2d87SRandall Stewart 									 *
70645b495f17SMichael Tuexen 									 * address
70655b495f17SMichael Tuexen 									 */
70661b649582SRandall Stewart 									continue;
70671b649582SRandall Stewart 							}
70681b649582SRandall Stewart 						}
70691b649582SRandall Stewart 						if ((site_scope == 0) &&
70701b649582SRandall Stewart 						    (IN6_IS_ADDR_SITELOCAL(&sin6->sin6_addr))) {
70711b649582SRandall Stewart 							continue;
70721b649582SRandall Stewart 						}
70731b649582SRandall Stewart 						/* count this one */
70741b649582SRandall Stewart 						count++;
70751b649582SRandall Stewart 					}
70765e2c2d87SRandall Stewart 					break;
70775e2c2d87SRandall Stewart #endif
70785e2c2d87SRandall Stewart 				default:
70795e2c2d87SRandall Stewart 					/* TSNH */
70805e2c2d87SRandall Stewart 					break;
70815e2c2d87SRandall Stewart 				}
70821b649582SRandall Stewart 			}
70831b649582SRandall Stewart 		}
70841b649582SRandall Stewart 	} else {
70851b649582SRandall Stewart 		/*
70861b649582SRandall Stewart 		 * subset bound case
70871b649582SRandall Stewart 		 */
70881b649582SRandall Stewart 		struct sctp_laddr *laddr;
70891b649582SRandall Stewart 
70901b649582SRandall Stewart 		LIST_FOREACH(laddr, &stcb->sctp_ep->sctp_addr_list,
70911b649582SRandall Stewart 		    sctp_nxt_addr) {
70921b649582SRandall Stewart 			if (sctp_is_addr_restricted(stcb, laddr->ifa)) {
70931b649582SRandall Stewart 				continue;
70941b649582SRandall Stewart 			}
70951b649582SRandall Stewart 			/* count this one */
70961b649582SRandall Stewart 			count++;
70971b649582SRandall Stewart 		}
70981b649582SRandall Stewart 	}
7099c99efcf6SRandall Stewart 	SCTP_IPI_ADDR_RUNLOCK();
71001b649582SRandall Stewart 	return (count);
71011b649582SRandall Stewart }
7102c4739e2fSRandall Stewart 
7103c4739e2fSRandall Stewart #if defined(SCTP_LOCAL_TRACE_BUF)
7104c4739e2fSRandall Stewart 
7105c4739e2fSRandall Stewart void
7106b27a6b7dSRandall Stewart sctp_log_trace(uint32_t subsys, const char *str SCTP_UNUSED, uint32_t a, uint32_t b, uint32_t c, uint32_t d, uint32_t e, uint32_t f)
7107c4739e2fSRandall Stewart {
7108b27a6b7dSRandall Stewart 	uint32_t saveindex, newindex;
7109c4739e2fSRandall Stewart 
7110c4739e2fSRandall Stewart 	do {
7111b3f1ea41SRandall Stewart 		saveindex = SCTP_BASE_SYSCTL(sctp_log).index;
7112c4739e2fSRandall Stewart 		if (saveindex >= SCTP_MAX_LOGGING_SIZE) {
7113c4739e2fSRandall Stewart 			newindex = 1;
7114c4739e2fSRandall Stewart 		} else {
7115c4739e2fSRandall Stewart 			newindex = saveindex + 1;
7116c4739e2fSRandall Stewart 		}
7117b3f1ea41SRandall Stewart 	} while (atomic_cmpset_int(&SCTP_BASE_SYSCTL(sctp_log).index, saveindex, newindex) == 0);
7118c4739e2fSRandall Stewart 	if (saveindex >= SCTP_MAX_LOGGING_SIZE) {
7119c4739e2fSRandall Stewart 		saveindex = 0;
7120c4739e2fSRandall Stewart 	}
7121b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].timestamp = SCTP_GET_CYCLECOUNT;
7122b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].subsys = subsys;
7123b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[0] = a;
7124b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[1] = b;
7125b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[2] = c;
7126b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[3] = d;
7127b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[4] = e;
7128b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[5] = f;
7129c4739e2fSRandall Stewart }
7130c4739e2fSRandall Stewart 
7131c4739e2fSRandall Stewart #endif
7132742e7210SKristof Provost static bool
71337cca1775SRandall Stewart sctp_recv_udp_tunneled_packet(struct mbuf *m, int off, struct inpcb *inp,
713481d3ec17SBryan Venteicher     const struct sockaddr *sa SCTP_UNUSED, void *ctx SCTP_UNUSED)
7135a99b6783SRandall Stewart {
7136a99b6783SRandall Stewart 	struct ip *iph;
71373a51a264SMichael Tuexen #ifdef INET6
71383a51a264SMichael Tuexen 	struct ip6_hdr *ip6;
71393a51a264SMichael Tuexen #endif
7140a99b6783SRandall Stewart 	struct mbuf *sp, *last;
7141a99b6783SRandall Stewart 	struct udphdr *uhdr;
7142285052f0SMichael Tuexen 	uint16_t port;
7143a99b6783SRandall Stewart 
7144a99b6783SRandall Stewart 	if ((m->m_flags & M_PKTHDR) == 0) {
7145a99b6783SRandall Stewart 		/* Can't handle one that is not a pkt hdr */
7146a99b6783SRandall Stewart 		goto out;
7147a99b6783SRandall Stewart 	}
7148285052f0SMichael Tuexen 	/* Pull the src port */
7149a99b6783SRandall Stewart 	iph = mtod(m, struct ip *);
7150a99b6783SRandall Stewart 	uhdr = (struct udphdr *)((caddr_t)iph + off);
7151a99b6783SRandall Stewart 	port = uhdr->uh_sport;
7152285052f0SMichael Tuexen 	/*
7153285052f0SMichael Tuexen 	 * Split out the mbuf chain. Leave the IP header in m, place the
7154285052f0SMichael Tuexen 	 * rest in the sp.
7155285052f0SMichael Tuexen 	 */
7156eb1b1807SGleb Smirnoff 	sp = m_split(m, off, M_NOWAIT);
7157a99b6783SRandall Stewart 	if (sp == NULL) {
7158a99b6783SRandall Stewart 		/* Gak, drop packet, we can't do a split */
7159a99b6783SRandall Stewart 		goto out;
7160a99b6783SRandall Stewart 	}
7161285052f0SMichael Tuexen 	if (sp->m_pkthdr.len < sizeof(struct udphdr) + sizeof(struct sctphdr)) {
7162285052f0SMichael Tuexen 		/* Gak, packet can't have an SCTP header in it - too small */
7163a99b6783SRandall Stewart 		m_freem(sp);
7164a99b6783SRandall Stewart 		goto out;
7165a99b6783SRandall Stewart 	}
7166285052f0SMichael Tuexen 	/* Now pull up the UDP header and SCTP header together */
7167285052f0SMichael Tuexen 	sp = m_pullup(sp, sizeof(struct udphdr) + sizeof(struct sctphdr));
7168a99b6783SRandall Stewart 	if (sp == NULL) {
7169a99b6783SRandall Stewart 		/* Gak pullup failed */
7170a99b6783SRandall Stewart 		goto out;
7171a99b6783SRandall Stewart 	}
7172285052f0SMichael Tuexen 	/* Trim out the UDP header */
7173a99b6783SRandall Stewart 	m_adj(sp, sizeof(struct udphdr));
7174a99b6783SRandall Stewart 
7175a99b6783SRandall Stewart 	/* Now reconstruct the mbuf chain */
7176285052f0SMichael Tuexen 	for (last = m; last->m_next; last = last->m_next);
7177a99b6783SRandall Stewart 	last->m_next = sp;
7178a99b6783SRandall Stewart 	m->m_pkthdr.len += sp->m_pkthdr.len;
717952f175beSMichael Tuexen 	/*
718052f175beSMichael Tuexen 	 * The CSUM_DATA_VALID flags indicates that the HW checked the UDP
718152f175beSMichael Tuexen 	 * checksum and it was valid. Since CSUM_DATA_VALID ==
718252f175beSMichael Tuexen 	 * CSUM_SCTP_VALID this would imply that the HW also verified the
718352f175beSMichael Tuexen 	 * SCTP checksum. Therefore, clear the bit.
718452f175beSMichael Tuexen 	 */
718552f175beSMichael Tuexen 	SCTPDBG(SCTP_DEBUG_CRCOFFLOAD,
718652f175beSMichael Tuexen 	    "sctp_recv_udp_tunneled_packet(): Packet of length %d received on %s with csum_flags 0x%b.\n",
718752f175beSMichael Tuexen 	    m->m_pkthdr.len,
718852f175beSMichael Tuexen 	    if_name(m->m_pkthdr.rcvif),
718952f175beSMichael Tuexen 	    (int)m->m_pkthdr.csum_flags, CSUM_BITS);
719052f175beSMichael Tuexen 	m->m_pkthdr.csum_flags &= ~CSUM_DATA_VALID;
7191a99b6783SRandall Stewart 	iph = mtod(m, struct ip *);
7192a99b6783SRandall Stewart 	switch (iph->ip_v) {
7193e6194c2eSMichael Tuexen #ifdef INET
7194a99b6783SRandall Stewart 	case IPVERSION:
719509c1c856SMichael Tuexen 		iph->ip_len = htons(ntohs(iph->ip_len) - sizeof(struct udphdr));
7196a99b6783SRandall Stewart 		sctp_input_with_port(m, off, port);
7197a99b6783SRandall Stewart 		break;
7198e6194c2eSMichael Tuexen #endif
7199a99b6783SRandall Stewart #ifdef INET6
7200a99b6783SRandall Stewart 	case IPV6_VERSION >> 4:
72013a51a264SMichael Tuexen 		ip6 = mtod(m, struct ip6_hdr *);
72023a51a264SMichael Tuexen 		ip6->ip6_plen = htons(ntohs(ip6->ip6_plen) - sizeof(struct udphdr));
72033a51a264SMichael Tuexen 		sctp6_input_with_port(&m, &off, port);
7204a99b6783SRandall Stewart 		break;
7205a99b6783SRandall Stewart #endif
7206a99b6783SRandall Stewart 	default:
7207285052f0SMichael Tuexen 		goto out;
7208a99b6783SRandall Stewart 		break;
7209a99b6783SRandall Stewart 	}
7210742e7210SKristof Provost 	return (true);
7211a99b6783SRandall Stewart out:
7212a99b6783SRandall Stewart 	m_freem(m);
7213742e7210SKristof Provost 
7214742e7210SKristof Provost 	return (true);
7215a99b6783SRandall Stewart }
7216c54a18d2SRandall Stewart 
7217fd7af143SMichael Tuexen #ifdef INET
7218fd7af143SMichael Tuexen static void
7219fcb3f813SGleb Smirnoff sctp_recv_icmp_tunneled_packet(udp_tun_icmp_param_t param)
7220fd7af143SMichael Tuexen {
7221fcb3f813SGleb Smirnoff 	struct icmp *icmp = param.icmp;
7222fd7af143SMichael Tuexen 	struct ip *outer_ip, *inner_ip;
7223fd7af143SMichael Tuexen 	struct sctphdr *sh;
7224fd7af143SMichael Tuexen 	struct udphdr *udp;
7225fd7af143SMichael Tuexen 	struct sctp_inpcb *inp;
7226fd7af143SMichael Tuexen 	struct sctp_tcb *stcb;
7227fd7af143SMichael Tuexen 	struct sctp_nets *net;
7228fd7af143SMichael Tuexen 	struct sctp_init_chunk *ch;
7229fd7af143SMichael Tuexen 	struct sockaddr_in src, dst;
7230fd7af143SMichael Tuexen 	uint8_t type, code;
7231fd7af143SMichael Tuexen 
7232fcb3f813SGleb Smirnoff 	inner_ip = &icmp->icmp_ip;
7233fd7af143SMichael Tuexen 	outer_ip = (struct ip *)((caddr_t)icmp - sizeof(struct ip));
7234fd7af143SMichael Tuexen 	if (ntohs(outer_ip->ip_len) <
7235fd7af143SMichael Tuexen 	    sizeof(struct ip) + 8 + (inner_ip->ip_hl << 2) + sizeof(struct udphdr) + 8) {
7236fd7af143SMichael Tuexen 		return;
7237fd7af143SMichael Tuexen 	}
7238fd7af143SMichael Tuexen 	udp = (struct udphdr *)((caddr_t)inner_ip + (inner_ip->ip_hl << 2));
7239fd7af143SMichael Tuexen 	sh = (struct sctphdr *)(udp + 1);
7240fd7af143SMichael Tuexen 	memset(&src, 0, sizeof(struct sockaddr_in));
7241fd7af143SMichael Tuexen 	src.sin_family = AF_INET;
7242fd7af143SMichael Tuexen 	src.sin_len = sizeof(struct sockaddr_in);
7243fd7af143SMichael Tuexen 	src.sin_port = sh->src_port;
7244fd7af143SMichael Tuexen 	src.sin_addr = inner_ip->ip_src;
7245fd7af143SMichael Tuexen 	memset(&dst, 0, sizeof(struct sockaddr_in));
7246fd7af143SMichael Tuexen 	dst.sin_family = AF_INET;
7247fd7af143SMichael Tuexen 	dst.sin_len = sizeof(struct sockaddr_in);
7248fd7af143SMichael Tuexen 	dst.sin_port = sh->dest_port;
7249fd7af143SMichael Tuexen 	dst.sin_addr = inner_ip->ip_dst;
7250fd7af143SMichael Tuexen 	/*
7251fd7af143SMichael Tuexen 	 * 'dst' holds the dest of the packet that failed to be sent. 'src'
7252fd7af143SMichael Tuexen 	 * holds our local endpoint address. Thus we reverse the dst and the
7253fd7af143SMichael Tuexen 	 * src in the lookup.
7254fd7af143SMichael Tuexen 	 */
7255fd7af143SMichael Tuexen 	inp = NULL;
7256fd7af143SMichael Tuexen 	net = NULL;
7257fd7af143SMichael Tuexen 	stcb = sctp_findassociation_addr_sa((struct sockaddr *)&dst,
7258fd7af143SMichael Tuexen 	    (struct sockaddr *)&src,
7259fd7af143SMichael Tuexen 	    &inp, &net, 1,
7260fd7af143SMichael Tuexen 	    SCTP_DEFAULT_VRFID);
7261fd7af143SMichael Tuexen 	if ((stcb != NULL) &&
7262fd7af143SMichael Tuexen 	    (net != NULL) &&
726355b8cd93SMichael Tuexen 	    (inp != NULL)) {
7264fd7af143SMichael Tuexen 		/* Check the UDP port numbers */
7265fd7af143SMichael Tuexen 		if ((udp->uh_dport != net->port) ||
7266fd7af143SMichael Tuexen 		    (udp->uh_sport != htons(SCTP_BASE_SYSCTL(sctp_udp_tunneling_port)))) {
7267fd7af143SMichael Tuexen 			SCTP_TCB_UNLOCK(stcb);
7268fd7af143SMichael Tuexen 			return;
7269fd7af143SMichael Tuexen 		}
7270fd7af143SMichael Tuexen 		/* Check the verification tag */
7271fd7af143SMichael Tuexen 		if (ntohl(sh->v_tag) != 0) {
7272fd7af143SMichael Tuexen 			/*
7273fd7af143SMichael Tuexen 			 * This must be the verification tag used for
7274fd7af143SMichael Tuexen 			 * sending out packets. We don't consider packets
7275fd7af143SMichael Tuexen 			 * reflecting the verification tag.
7276fd7af143SMichael Tuexen 			 */
7277fd7af143SMichael Tuexen 			if (ntohl(sh->v_tag) != stcb->asoc.peer_vtag) {
7278fd7af143SMichael Tuexen 				SCTP_TCB_UNLOCK(stcb);
7279fd7af143SMichael Tuexen 				return;
7280fd7af143SMichael Tuexen 			}
7281fd7af143SMichael Tuexen 		} else {
7282fd7af143SMichael Tuexen 			if (ntohs(outer_ip->ip_len) >=
7283fd7af143SMichael Tuexen 			    sizeof(struct ip) +
7284fd7af143SMichael Tuexen 			    8 + (inner_ip->ip_hl << 2) + 8 + 20) {
7285fd7af143SMichael Tuexen 				/*
7286fd7af143SMichael Tuexen 				 * In this case we can check if we got an
7287fd7af143SMichael Tuexen 				 * INIT chunk and if the initiate tag
7288fd7af143SMichael Tuexen 				 * matches.
7289fd7af143SMichael Tuexen 				 */
7290fd7af143SMichael Tuexen 				ch = (struct sctp_init_chunk *)(sh + 1);
7291fd7af143SMichael Tuexen 				if ((ch->ch.chunk_type != SCTP_INITIATION) ||
7292fd7af143SMichael Tuexen 				    (ntohl(ch->init.initiate_tag) != stcb->asoc.my_vtag)) {
7293fd7af143SMichael Tuexen 					SCTP_TCB_UNLOCK(stcb);
7294fd7af143SMichael Tuexen 					return;
7295fd7af143SMichael Tuexen 				}
7296fd7af143SMichael Tuexen 			} else {
7297fd7af143SMichael Tuexen 				SCTP_TCB_UNLOCK(stcb);
7298fd7af143SMichael Tuexen 				return;
7299fd7af143SMichael Tuexen 			}
7300fd7af143SMichael Tuexen 		}
7301fd7af143SMichael Tuexen 		type = icmp->icmp_type;
7302fd7af143SMichael Tuexen 		code = icmp->icmp_code;
73033c3f9e2aSMichael Tuexen 		if ((type == ICMP_UNREACH) &&
73043c3f9e2aSMichael Tuexen 		    (code == ICMP_UNREACH_PORT)) {
7305fd7af143SMichael Tuexen 			code = ICMP_UNREACH_PROTOCOL;
7306fd7af143SMichael Tuexen 		}
7307fd7af143SMichael Tuexen 		sctp_notify(inp, stcb, net, type, code,
7308fd7af143SMichael Tuexen 		    ntohs(inner_ip->ip_len),
73096ebfa5eeSMichael Tuexen 		    (uint32_t)ntohs(icmp->icmp_nextmtu));
7310fd7af143SMichael Tuexen 	} else {
7311fd7af143SMichael Tuexen 		if ((stcb == NULL) && (inp != NULL)) {
7312fd7af143SMichael Tuexen 			/* reduce ref-count */
7313fd7af143SMichael Tuexen 			SCTP_INP_WLOCK(inp);
7314fd7af143SMichael Tuexen 			SCTP_INP_DECR_REF(inp);
7315fd7af143SMichael Tuexen 			SCTP_INP_WUNLOCK(inp);
7316fd7af143SMichael Tuexen 		}
7317fd7af143SMichael Tuexen 		if (stcb) {
7318fd7af143SMichael Tuexen 			SCTP_TCB_UNLOCK(stcb);
7319fd7af143SMichael Tuexen 		}
7320fd7af143SMichael Tuexen 	}
7321fd7af143SMichael Tuexen 	return;
7322fd7af143SMichael Tuexen }
7323fd7af143SMichael Tuexen #endif
7324fd7af143SMichael Tuexen 
7325fd7af143SMichael Tuexen #ifdef INET6
7326fd7af143SMichael Tuexen static void
7327fcb3f813SGleb Smirnoff sctp_recv_icmp6_tunneled_packet(udp_tun_icmp_param_t param)
7328fd7af143SMichael Tuexen {
7329fcb3f813SGleb Smirnoff 	struct ip6ctlparam *ip6cp = param.ip6cp;
7330fd7af143SMichael Tuexen 	struct sctp_inpcb *inp;
7331fd7af143SMichael Tuexen 	struct sctp_tcb *stcb;
7332fd7af143SMichael Tuexen 	struct sctp_nets *net;
7333fd7af143SMichael Tuexen 	struct sctphdr sh;
7334fd7af143SMichael Tuexen 	struct udphdr udp;
7335fd7af143SMichael Tuexen 	struct sockaddr_in6 src, dst;
7336fd7af143SMichael Tuexen 	uint8_t type, code;
7337fd7af143SMichael Tuexen 
7338fd7af143SMichael Tuexen 	/*
7339fd7af143SMichael Tuexen 	 * XXX: We assume that when IPV6 is non NULL, M and OFF are valid.
7340fd7af143SMichael Tuexen 	 */
7341fd7af143SMichael Tuexen 	if (ip6cp->ip6c_m == NULL) {
7342fd7af143SMichael Tuexen 		return;
7343fd7af143SMichael Tuexen 	}
7344fd7af143SMichael Tuexen 	/*
7345fd7af143SMichael Tuexen 	 * Check if we can safely examine the ports and the verification tag
7346fd7af143SMichael Tuexen 	 * of the SCTP common header.
7347fd7af143SMichael Tuexen 	 */
7348fd7af143SMichael Tuexen 	if (ip6cp->ip6c_m->m_pkthdr.len <
7349fd7af143SMichael Tuexen 	    ip6cp->ip6c_off + sizeof(struct udphdr) + offsetof(struct sctphdr, checksum)) {
7350fd7af143SMichael Tuexen 		return;
7351fd7af143SMichael Tuexen 	}
7352fd7af143SMichael Tuexen 	/* Copy out the UDP header. */
7353fd7af143SMichael Tuexen 	memset(&udp, 0, sizeof(struct udphdr));
7354fd7af143SMichael Tuexen 	m_copydata(ip6cp->ip6c_m,
7355fd7af143SMichael Tuexen 	    ip6cp->ip6c_off,
7356fd7af143SMichael Tuexen 	    sizeof(struct udphdr),
7357fd7af143SMichael Tuexen 	    (caddr_t)&udp);
7358fd7af143SMichael Tuexen 	/* Copy out the port numbers and the verification tag. */
7359fd7af143SMichael Tuexen 	memset(&sh, 0, sizeof(struct sctphdr));
7360fd7af143SMichael Tuexen 	m_copydata(ip6cp->ip6c_m,
7361fd7af143SMichael Tuexen 	    ip6cp->ip6c_off + sizeof(struct udphdr),
7362fd7af143SMichael Tuexen 	    sizeof(uint16_t) + sizeof(uint16_t) + sizeof(uint32_t),
7363fd7af143SMichael Tuexen 	    (caddr_t)&sh);
7364fd7af143SMichael Tuexen 	memset(&src, 0, sizeof(struct sockaddr_in6));
7365fd7af143SMichael Tuexen 	src.sin6_family = AF_INET6;
7366fd7af143SMichael Tuexen 	src.sin6_len = sizeof(struct sockaddr_in6);
7367fd7af143SMichael Tuexen 	src.sin6_port = sh.src_port;
7368fd7af143SMichael Tuexen 	src.sin6_addr = ip6cp->ip6c_ip6->ip6_src;
7369fd7af143SMichael Tuexen 	if (in6_setscope(&src.sin6_addr, ip6cp->ip6c_m->m_pkthdr.rcvif, NULL) != 0) {
7370fd7af143SMichael Tuexen 		return;
7371fd7af143SMichael Tuexen 	}
7372fd7af143SMichael Tuexen 	memset(&dst, 0, sizeof(struct sockaddr_in6));
7373fd7af143SMichael Tuexen 	dst.sin6_family = AF_INET6;
7374fd7af143SMichael Tuexen 	dst.sin6_len = sizeof(struct sockaddr_in6);
7375fd7af143SMichael Tuexen 	dst.sin6_port = sh.dest_port;
7376fd7af143SMichael Tuexen 	dst.sin6_addr = ip6cp->ip6c_ip6->ip6_dst;
7377fd7af143SMichael Tuexen 	if (in6_setscope(&dst.sin6_addr, ip6cp->ip6c_m->m_pkthdr.rcvif, NULL) != 0) {
7378fd7af143SMichael Tuexen 		return;
7379fd7af143SMichael Tuexen 	}
7380fd7af143SMichael Tuexen 	inp = NULL;
7381fd7af143SMichael Tuexen 	net = NULL;
7382fd7af143SMichael Tuexen 	stcb = sctp_findassociation_addr_sa((struct sockaddr *)&dst,
7383fd7af143SMichael Tuexen 	    (struct sockaddr *)&src,
7384fd7af143SMichael Tuexen 	    &inp, &net, 1, SCTP_DEFAULT_VRFID);
7385fd7af143SMichael Tuexen 	if ((stcb != NULL) &&
7386fd7af143SMichael Tuexen 	    (net != NULL) &&
738755b8cd93SMichael Tuexen 	    (inp != NULL)) {
7388fd7af143SMichael Tuexen 		/* Check the UDP port numbers */
7389fd7af143SMichael Tuexen 		if ((udp.uh_dport != net->port) ||
7390fd7af143SMichael Tuexen 		    (udp.uh_sport != htons(SCTP_BASE_SYSCTL(sctp_udp_tunneling_port)))) {
7391fd7af143SMichael Tuexen 			SCTP_TCB_UNLOCK(stcb);
7392fd7af143SMichael Tuexen 			return;
7393fd7af143SMichael Tuexen 		}
7394fd7af143SMichael Tuexen 		/* Check the verification tag */
7395fd7af143SMichael Tuexen 		if (ntohl(sh.v_tag) != 0) {
7396fd7af143SMichael Tuexen 			/*
7397fd7af143SMichael Tuexen 			 * This must be the verification tag used for
7398fd7af143SMichael Tuexen 			 * sending out packets. We don't consider packets
7399fd7af143SMichael Tuexen 			 * reflecting the verification tag.
7400fd7af143SMichael Tuexen 			 */
7401fd7af143SMichael Tuexen 			if (ntohl(sh.v_tag) != stcb->asoc.peer_vtag) {
7402fd7af143SMichael Tuexen 				SCTP_TCB_UNLOCK(stcb);
7403fd7af143SMichael Tuexen 				return;
7404fd7af143SMichael Tuexen 			}
7405fd7af143SMichael Tuexen 		} else {
7406fd7af143SMichael Tuexen 			if (ip6cp->ip6c_m->m_pkthdr.len >=
7407fd7af143SMichael Tuexen 			    ip6cp->ip6c_off + sizeof(struct udphdr) +
7408fd7af143SMichael Tuexen 			    sizeof(struct sctphdr) +
7409fd7af143SMichael Tuexen 			    sizeof(struct sctp_chunkhdr) +
7410fd7af143SMichael Tuexen 			    offsetof(struct sctp_init, a_rwnd)) {
7411fd7af143SMichael Tuexen 				/*
7412fd7af143SMichael Tuexen 				 * In this case we can check if we got an
7413fd7af143SMichael Tuexen 				 * INIT chunk and if the initiate tag
7414fd7af143SMichael Tuexen 				 * matches.
7415fd7af143SMichael Tuexen 				 */
7416fd7af143SMichael Tuexen 				uint32_t initiate_tag;
7417fd7af143SMichael Tuexen 				uint8_t chunk_type;
7418fd7af143SMichael Tuexen 
7419fd7af143SMichael Tuexen 				m_copydata(ip6cp->ip6c_m,
7420fd7af143SMichael Tuexen 				    ip6cp->ip6c_off +
7421fd7af143SMichael Tuexen 				    sizeof(struct udphdr) +
7422fd7af143SMichael Tuexen 				    sizeof(struct sctphdr),
7423fd7af143SMichael Tuexen 				    sizeof(uint8_t),
7424fd7af143SMichael Tuexen 				    (caddr_t)&chunk_type);
7425fd7af143SMichael Tuexen 				m_copydata(ip6cp->ip6c_m,
7426fd7af143SMichael Tuexen 				    ip6cp->ip6c_off +
7427fd7af143SMichael Tuexen 				    sizeof(struct udphdr) +
7428fd7af143SMichael Tuexen 				    sizeof(struct sctphdr) +
7429fd7af143SMichael Tuexen 				    sizeof(struct sctp_chunkhdr),
7430fd7af143SMichael Tuexen 				    sizeof(uint32_t),
7431fd7af143SMichael Tuexen 				    (caddr_t)&initiate_tag);
7432fd7af143SMichael Tuexen 				if ((chunk_type != SCTP_INITIATION) ||
7433fd7af143SMichael Tuexen 				    (ntohl(initiate_tag) != stcb->asoc.my_vtag)) {
7434fd7af143SMichael Tuexen 					SCTP_TCB_UNLOCK(stcb);
7435fd7af143SMichael Tuexen 					return;
7436fd7af143SMichael Tuexen 				}
7437fd7af143SMichael Tuexen 			} else {
7438fd7af143SMichael Tuexen 				SCTP_TCB_UNLOCK(stcb);
7439fd7af143SMichael Tuexen 				return;
7440fd7af143SMichael Tuexen 			}
7441fd7af143SMichael Tuexen 		}
7442fd7af143SMichael Tuexen 		type = ip6cp->ip6c_icmp6->icmp6_type;
7443fd7af143SMichael Tuexen 		code = ip6cp->ip6c_icmp6->icmp6_code;
7444fd7af143SMichael Tuexen 		if ((type == ICMP6_DST_UNREACH) &&
7445fd7af143SMichael Tuexen 		    (code == ICMP6_DST_UNREACH_NOPORT)) {
7446fd7af143SMichael Tuexen 			type = ICMP6_PARAM_PROB;
7447fd7af143SMichael Tuexen 			code = ICMP6_PARAMPROB_NEXTHEADER;
7448fd7af143SMichael Tuexen 		}
7449fd7af143SMichael Tuexen 		sctp6_notify(inp, stcb, net, type, code,
74506ebfa5eeSMichael Tuexen 		    ntohl(ip6cp->ip6c_icmp6->icmp6_mtu));
7451fd7af143SMichael Tuexen 	} else {
7452fd7af143SMichael Tuexen 		if ((stcb == NULL) && (inp != NULL)) {
7453fd7af143SMichael Tuexen 			/* reduce inp's ref-count */
7454fd7af143SMichael Tuexen 			SCTP_INP_WLOCK(inp);
7455fd7af143SMichael Tuexen 			SCTP_INP_DECR_REF(inp);
7456fd7af143SMichael Tuexen 			SCTP_INP_WUNLOCK(inp);
7457fd7af143SMichael Tuexen 		}
7458fd7af143SMichael Tuexen 		if (stcb) {
7459fd7af143SMichael Tuexen 			SCTP_TCB_UNLOCK(stcb);
7460fd7af143SMichael Tuexen 		}
7461fd7af143SMichael Tuexen 	}
7462fd7af143SMichael Tuexen }
7463fd7af143SMichael Tuexen #endif
7464fd7af143SMichael Tuexen 
7465c54a18d2SRandall Stewart void
7466c54a18d2SRandall Stewart sctp_over_udp_stop(void)
7467c54a18d2SRandall Stewart {
7468a99b6783SRandall Stewart 	/*
7469a99b6783SRandall Stewart 	 * This function assumes sysctl caller holds sctp_sysctl_info_lock()
7470bb91496aSGordon Bergling 	 * for writing!
7471a99b6783SRandall Stewart 	 */
74723a51a264SMichael Tuexen #ifdef INET
74733a51a264SMichael Tuexen 	if (SCTP_BASE_INFO(udp4_tun_socket) != NULL) {
74743a51a264SMichael Tuexen 		soclose(SCTP_BASE_INFO(udp4_tun_socket));
74753a51a264SMichael Tuexen 		SCTP_BASE_INFO(udp4_tun_socket) = NULL;
7476c54a18d2SRandall Stewart 	}
74773a51a264SMichael Tuexen #endif
74783a51a264SMichael Tuexen #ifdef INET6
74793a51a264SMichael Tuexen 	if (SCTP_BASE_INFO(udp6_tun_socket) != NULL) {
74803a51a264SMichael Tuexen 		soclose(SCTP_BASE_INFO(udp6_tun_socket));
74813a51a264SMichael Tuexen 		SCTP_BASE_INFO(udp6_tun_socket) = NULL;
74823a51a264SMichael Tuexen 	}
74833a51a264SMichael Tuexen #endif
7484a99b6783SRandall Stewart }
7485ea5eba11SMichael Tuexen 
7486c54a18d2SRandall Stewart int
7487c54a18d2SRandall Stewart sctp_over_udp_start(void)
7488c54a18d2SRandall Stewart {
7489a99b6783SRandall Stewart 	uint16_t port;
7490a99b6783SRandall Stewart 	int ret;
74913a51a264SMichael Tuexen #ifdef INET
74923a51a264SMichael Tuexen 	struct sockaddr_in sin;
74933a51a264SMichael Tuexen #endif
74943a51a264SMichael Tuexen #ifdef INET6
74953a51a264SMichael Tuexen 	struct sockaddr_in6 sin6;
74963a51a264SMichael Tuexen #endif
7497a99b6783SRandall Stewart 	/*
7498a99b6783SRandall Stewart 	 * This function assumes sysctl caller holds sctp_sysctl_info_lock()
7499bb91496aSGordon Bergling 	 * for writing!
7500a99b6783SRandall Stewart 	 */
7501a99b6783SRandall Stewart 	port = SCTP_BASE_SYSCTL(sctp_udp_tunneling_port);
75023a51a264SMichael Tuexen 	if (ntohs(port) == 0) {
7503a99b6783SRandall Stewart 		/* Must have a port set */
7504a99b6783SRandall Stewart 		return (EINVAL);
7505a99b6783SRandall Stewart 	}
75063a51a264SMichael Tuexen #ifdef INET
75073a51a264SMichael Tuexen 	if (SCTP_BASE_INFO(udp4_tun_socket) != NULL) {
7508a99b6783SRandall Stewart 		/* Already running -- must stop first */
7509a99b6783SRandall Stewart 		return (EALREADY);
7510a99b6783SRandall Stewart 	}
75113a51a264SMichael Tuexen #endif
75123a51a264SMichael Tuexen #ifdef INET6
75133a51a264SMichael Tuexen 	if (SCTP_BASE_INFO(udp6_tun_socket) != NULL) {
75143a51a264SMichael Tuexen 		/* Already running -- must stop first */
75153a51a264SMichael Tuexen 		return (EALREADY);
7516a99b6783SRandall Stewart 	}
75173a51a264SMichael Tuexen #endif
75183a51a264SMichael Tuexen #ifdef INET
75193a51a264SMichael Tuexen 	if ((ret = socreate(PF_INET, &SCTP_BASE_INFO(udp4_tun_socket),
75203a51a264SMichael Tuexen 	    SOCK_DGRAM, IPPROTO_UDP,
75213a51a264SMichael Tuexen 	    curthread->td_ucred, curthread))) {
7522a99b6783SRandall Stewart 		sctp_over_udp_stop();
7523a99b6783SRandall Stewart 		return (ret);
7524a99b6783SRandall Stewart 	}
75253a51a264SMichael Tuexen 	/* Call the special UDP hook. */
75263a51a264SMichael Tuexen 	if ((ret = udp_set_kernel_tunneling(SCTP_BASE_INFO(udp4_tun_socket),
7527fd7af143SMichael Tuexen 	    sctp_recv_udp_tunneled_packet,
7528fd7af143SMichael Tuexen 	    sctp_recv_icmp_tunneled_packet,
7529fd7af143SMichael Tuexen 	    NULL))) {
75303a51a264SMichael Tuexen 		sctp_over_udp_stop();
75313a51a264SMichael Tuexen 		return (ret);
75323a51a264SMichael Tuexen 	}
75333a51a264SMichael Tuexen 	/* Ok, we have a socket, bind it to the port. */
75343a51a264SMichael Tuexen 	memset(&sin, 0, sizeof(struct sockaddr_in));
75353a51a264SMichael Tuexen 	sin.sin_len = sizeof(struct sockaddr_in);
75363a51a264SMichael Tuexen 	sin.sin_family = AF_INET;
75373a51a264SMichael Tuexen 	sin.sin_port = htons(port);
75383a51a264SMichael Tuexen 	if ((ret = sobind(SCTP_BASE_INFO(udp4_tun_socket),
75393a51a264SMichael Tuexen 	    (struct sockaddr *)&sin, curthread))) {
75403a51a264SMichael Tuexen 		sctp_over_udp_stop();
75413a51a264SMichael Tuexen 		return (ret);
75423a51a264SMichael Tuexen 	}
75433a51a264SMichael Tuexen #endif
75443a51a264SMichael Tuexen #ifdef INET6
75453a51a264SMichael Tuexen 	if ((ret = socreate(PF_INET6, &SCTP_BASE_INFO(udp6_tun_socket),
75463a51a264SMichael Tuexen 	    SOCK_DGRAM, IPPROTO_UDP,
75473a51a264SMichael Tuexen 	    curthread->td_ucred, curthread))) {
75483a51a264SMichael Tuexen 		sctp_over_udp_stop();
75493a51a264SMichael Tuexen 		return (ret);
75503a51a264SMichael Tuexen 	}
75513a51a264SMichael Tuexen 	/* Call the special UDP hook. */
75523a51a264SMichael Tuexen 	if ((ret = udp_set_kernel_tunneling(SCTP_BASE_INFO(udp6_tun_socket),
7553fd7af143SMichael Tuexen 	    sctp_recv_udp_tunneled_packet,
7554fd7af143SMichael Tuexen 	    sctp_recv_icmp6_tunneled_packet,
7555fd7af143SMichael Tuexen 	    NULL))) {
75563a51a264SMichael Tuexen 		sctp_over_udp_stop();
75573a51a264SMichael Tuexen 		return (ret);
75583a51a264SMichael Tuexen 	}
75593a51a264SMichael Tuexen 	/* Ok, we have a socket, bind it to the port. */
75603a51a264SMichael Tuexen 	memset(&sin6, 0, sizeof(struct sockaddr_in6));
75613a51a264SMichael Tuexen 	sin6.sin6_len = sizeof(struct sockaddr_in6);
75623a51a264SMichael Tuexen 	sin6.sin6_family = AF_INET6;
75633a51a264SMichael Tuexen 	sin6.sin6_port = htons(port);
75643a51a264SMichael Tuexen 	if ((ret = sobind(SCTP_BASE_INFO(udp6_tun_socket),
75653a51a264SMichael Tuexen 	    (struct sockaddr *)&sin6, curthread))) {
75663a51a264SMichael Tuexen 		sctp_over_udp_stop();
75673a51a264SMichael Tuexen 		return (ret);
75683a51a264SMichael Tuexen 	}
75693a51a264SMichael Tuexen #endif
7570a99b6783SRandall Stewart 	return (0);
7571c54a18d2SRandall Stewart }
757210e0318aSMichael Tuexen 
757310e0318aSMichael Tuexen /*
757410e0318aSMichael Tuexen  * sctp_min_mtu ()returns the minimum of all non-zero arguments.
757510e0318aSMichael Tuexen  * If all arguments are zero, zero is returned.
757610e0318aSMichael Tuexen  */
757710e0318aSMichael Tuexen uint32_t
7578b0471b4bSMichael Tuexen sctp_min_mtu(uint32_t mtu1, uint32_t mtu2, uint32_t mtu3)
7579b0471b4bSMichael Tuexen {
758010e0318aSMichael Tuexen 	if (mtu1 > 0) {
758110e0318aSMichael Tuexen 		if (mtu2 > 0) {
758210e0318aSMichael Tuexen 			if (mtu3 > 0) {
758310e0318aSMichael Tuexen 				return (min(mtu1, min(mtu2, mtu3)));
758410e0318aSMichael Tuexen 			} else {
758510e0318aSMichael Tuexen 				return (min(mtu1, mtu2));
758610e0318aSMichael Tuexen 			}
758710e0318aSMichael Tuexen 		} else {
758810e0318aSMichael Tuexen 			if (mtu3 > 0) {
758910e0318aSMichael Tuexen 				return (min(mtu1, mtu3));
759010e0318aSMichael Tuexen 			} else {
759110e0318aSMichael Tuexen 				return (mtu1);
759210e0318aSMichael Tuexen 			}
759310e0318aSMichael Tuexen 		}
759410e0318aSMichael Tuexen 	} else {
759510e0318aSMichael Tuexen 		if (mtu2 > 0) {
759610e0318aSMichael Tuexen 			if (mtu3 > 0) {
759710e0318aSMichael Tuexen 				return (min(mtu2, mtu3));
759810e0318aSMichael Tuexen 			} else {
759910e0318aSMichael Tuexen 				return (mtu2);
760010e0318aSMichael Tuexen 			}
760110e0318aSMichael Tuexen 		} else {
760210e0318aSMichael Tuexen 			return (mtu3);
760310e0318aSMichael Tuexen 		}
760410e0318aSMichael Tuexen 	}
760510e0318aSMichael Tuexen }
760610e0318aSMichael Tuexen 
760710e0318aSMichael Tuexen void
760810e0318aSMichael Tuexen sctp_hc_set_mtu(union sctp_sockstore *addr, uint16_t fibnum, uint32_t mtu)
760910e0318aSMichael Tuexen {
761010e0318aSMichael Tuexen 	struct in_conninfo inc;
761110e0318aSMichael Tuexen 
761210e0318aSMichael Tuexen 	memset(&inc, 0, sizeof(struct in_conninfo));
761310e0318aSMichael Tuexen 	inc.inc_fibnum = fibnum;
761410e0318aSMichael Tuexen 	switch (addr->sa.sa_family) {
761510e0318aSMichael Tuexen #ifdef INET
761610e0318aSMichael Tuexen 	case AF_INET:
761710e0318aSMichael Tuexen 		inc.inc_faddr = addr->sin.sin_addr;
761810e0318aSMichael Tuexen 		break;
761910e0318aSMichael Tuexen #endif
762010e0318aSMichael Tuexen #ifdef INET6
762110e0318aSMichael Tuexen 	case AF_INET6:
762210e0318aSMichael Tuexen 		inc.inc_flags |= INC_ISIPV6;
762310e0318aSMichael Tuexen 		inc.inc6_faddr = addr->sin6.sin6_addr;
762410e0318aSMichael Tuexen 		break;
762510e0318aSMichael Tuexen #endif
762610e0318aSMichael Tuexen 	default:
762710e0318aSMichael Tuexen 		return;
762810e0318aSMichael Tuexen 	}
762910e0318aSMichael Tuexen 	tcp_hc_updatemtu(&inc, (u_long)mtu);
763010e0318aSMichael Tuexen }
763110e0318aSMichael Tuexen 
763210e0318aSMichael Tuexen uint32_t
7633b0471b4bSMichael Tuexen sctp_hc_get_mtu(union sctp_sockstore *addr, uint16_t fibnum)
7634b0471b4bSMichael Tuexen {
763510e0318aSMichael Tuexen 	struct in_conninfo inc;
763610e0318aSMichael Tuexen 
763710e0318aSMichael Tuexen 	memset(&inc, 0, sizeof(struct in_conninfo));
763810e0318aSMichael Tuexen 	inc.inc_fibnum = fibnum;
763910e0318aSMichael Tuexen 	switch (addr->sa.sa_family) {
764010e0318aSMichael Tuexen #ifdef INET
764110e0318aSMichael Tuexen 	case AF_INET:
764210e0318aSMichael Tuexen 		inc.inc_faddr = addr->sin.sin_addr;
764310e0318aSMichael Tuexen 		break;
764410e0318aSMichael Tuexen #endif
764510e0318aSMichael Tuexen #ifdef INET6
764610e0318aSMichael Tuexen 	case AF_INET6:
764710e0318aSMichael Tuexen 		inc.inc_flags |= INC_ISIPV6;
764810e0318aSMichael Tuexen 		inc.inc6_faddr = addr->sin6.sin6_addr;
764910e0318aSMichael Tuexen 		break;
765010e0318aSMichael Tuexen #endif
765110e0318aSMichael Tuexen 	default:
765210e0318aSMichael Tuexen 		return (0);
765310e0318aSMichael Tuexen 	}
765410e0318aSMichael Tuexen 	return ((uint32_t)tcp_hc_getmtu(&inc));
765510e0318aSMichael Tuexen }
76566ef849e6SMichael Tuexen 
76571a0b0216SMichael Tuexen void
76581a0b0216SMichael Tuexen sctp_set_state(struct sctp_tcb *stcb, int new_state)
76591a0b0216SMichael Tuexen {
76601e88cc8bSMichael Tuexen #if defined(KDTRACE_HOOKS)
76611e88cc8bSMichael Tuexen 	int old_state = stcb->asoc.state;
76621e88cc8bSMichael Tuexen #endif
76631e88cc8bSMichael Tuexen 
76641a0b0216SMichael Tuexen 	KASSERT((new_state & ~SCTP_STATE_MASK) == 0,
76651a0b0216SMichael Tuexen 	    ("sctp_set_state: Can't set substate (new_state = %x)",
76661a0b0216SMichael Tuexen 	    new_state));
76671a0b0216SMichael Tuexen 	stcb->asoc.state = (stcb->asoc.state & ~SCTP_STATE_MASK) | new_state;
76681a0b0216SMichael Tuexen 	if ((new_state == SCTP_STATE_SHUTDOWN_RECEIVED) ||
76691a0b0216SMichael Tuexen 	    (new_state == SCTP_STATE_SHUTDOWN_SENT) ||
76701a0b0216SMichael Tuexen 	    (new_state == SCTP_STATE_SHUTDOWN_ACK_SENT)) {
76711a0b0216SMichael Tuexen 		SCTP_CLEAR_SUBSTATE(stcb, SCTP_STATE_SHUTDOWN_PENDING);
76721a0b0216SMichael Tuexen 	}
76731e88cc8bSMichael Tuexen #if defined(KDTRACE_HOOKS)
76741e88cc8bSMichael Tuexen 	if (((old_state & SCTP_STATE_MASK) != new_state) &&
76751e88cc8bSMichael Tuexen 	    !(((old_state & SCTP_STATE_MASK) == SCTP_STATE_EMPTY) &&
76761e88cc8bSMichael Tuexen 	    (new_state == SCTP_STATE_INUSE))) {
76771e88cc8bSMichael Tuexen 		SCTP_PROBE6(state__change, NULL, stcb, NULL, stcb, NULL, old_state);
76781e88cc8bSMichael Tuexen 	}
76791e88cc8bSMichael Tuexen #endif
76801a0b0216SMichael Tuexen }
76811a0b0216SMichael Tuexen 
76821a0b0216SMichael Tuexen void
76831a0b0216SMichael Tuexen sctp_add_substate(struct sctp_tcb *stcb, int substate)
76841a0b0216SMichael Tuexen {
76851e88cc8bSMichael Tuexen #if defined(KDTRACE_HOOKS)
76861e88cc8bSMichael Tuexen 	int old_state = stcb->asoc.state;
76871e88cc8bSMichael Tuexen #endif
76881e88cc8bSMichael Tuexen 
76891a0b0216SMichael Tuexen 	KASSERT((substate & SCTP_STATE_MASK) == 0,
76901a0b0216SMichael Tuexen 	    ("sctp_add_substate: Can't set state (substate = %x)",
76911a0b0216SMichael Tuexen 	    substate));
76921a0b0216SMichael Tuexen 	stcb->asoc.state |= substate;
76931e88cc8bSMichael Tuexen #if defined(KDTRACE_HOOKS)
76941e88cc8bSMichael Tuexen 	if (((substate & SCTP_STATE_ABOUT_TO_BE_FREED) &&
76951e88cc8bSMichael Tuexen 	    ((old_state & SCTP_STATE_ABOUT_TO_BE_FREED) == 0)) ||
76961e88cc8bSMichael Tuexen 	    ((substate & SCTP_STATE_SHUTDOWN_PENDING) &&
76971e88cc8bSMichael Tuexen 	    ((old_state & SCTP_STATE_SHUTDOWN_PENDING) == 0))) {
76981e88cc8bSMichael Tuexen 		SCTP_PROBE6(state__change, NULL, stcb, NULL, stcb, NULL, old_state);
76991e88cc8bSMichael Tuexen 	}
77001e88cc8bSMichael Tuexen #endif
77011a0b0216SMichael Tuexen }
7702