xref: /freebsd/sys/netinet/sctputil.c (revision 34ae6a1a442881681a9c63e93a189b9191db50ed)
1f8829a4aSRandall Stewart /*-
251369649SPedro F. Giffuni  * SPDX-License-Identifier: BSD-3-Clause
351369649SPedro F. Giffuni  *
4830d754dSRandall Stewart  * Copyright (c) 2001-2008, by Cisco Systems, Inc. All rights reserved.
5807aad63SMichael Tuexen  * Copyright (c) 2008-2012, by Randall Stewart. All rights reserved.
6807aad63SMichael Tuexen  * Copyright (c) 2008-2012, by Michael Tuexen. All rights reserved.
7f8829a4aSRandall Stewart  *
8f8829a4aSRandall Stewart  * Redistribution and use in source and binary forms, with or without
9f8829a4aSRandall Stewart  * modification, are permitted provided that the following conditions are met:
10f8829a4aSRandall Stewart  *
11f8829a4aSRandall Stewart  * a) Redistributions of source code must retain the above copyright notice,
12f8829a4aSRandall Stewart  *    this list of conditions and the following disclaimer.
13f8829a4aSRandall Stewart  *
14f8829a4aSRandall Stewart  * b) Redistributions in binary form must reproduce the above copyright
15f8829a4aSRandall Stewart  *    notice, this list of conditions and the following disclaimer in
16f8829a4aSRandall Stewart  *    the documentation and/or other materials provided with the distribution.
17f8829a4aSRandall Stewart  *
18f8829a4aSRandall Stewart  * c) Neither the name of Cisco Systems, Inc. nor the names of its
19f8829a4aSRandall Stewart  *    contributors may be used to endorse or promote products derived
20f8829a4aSRandall Stewart  *    from this software without specific prior written permission.
21f8829a4aSRandall Stewart  *
22f8829a4aSRandall Stewart  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
23f8829a4aSRandall Stewart  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
24f8829a4aSRandall Stewart  * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25f8829a4aSRandall Stewart  * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
26f8829a4aSRandall Stewart  * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
27f8829a4aSRandall Stewart  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
28f8829a4aSRandall Stewart  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
29f8829a4aSRandall Stewart  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
30f8829a4aSRandall Stewart  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
31f8829a4aSRandall Stewart  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
32f8829a4aSRandall Stewart  * THE POSSIBILITY OF SUCH DAMAGE.
33f8829a4aSRandall Stewart  */
34f8829a4aSRandall Stewart 
35f8829a4aSRandall Stewart #include <sys/cdefs.h>
36f8829a4aSRandall Stewart __FBSDID("$FreeBSD$");
37f8829a4aSRandall Stewart 
38f8829a4aSRandall Stewart #include <netinet/sctp_os.h>
39f8829a4aSRandall Stewart #include <netinet/sctp_pcb.h>
40f8829a4aSRandall Stewart #include <netinet/sctputil.h>
41f8829a4aSRandall Stewart #include <netinet/sctp_var.h>
4242551e99SRandall Stewart #include <netinet/sctp_sysctl.h>
43f8829a4aSRandall Stewart #ifdef INET6
443a51a264SMichael Tuexen #include <netinet6/sctp6_var.h>
45f8829a4aSRandall Stewart #endif
46f8829a4aSRandall Stewart #include <netinet/sctp_header.h>
47f8829a4aSRandall Stewart #include <netinet/sctp_output.h>
48f8829a4aSRandall Stewart #include <netinet/sctp_uio.h>
49f8829a4aSRandall Stewart #include <netinet/sctp_timer.h>
5046bf534cSMichael Tuexen #include <netinet/sctp_indata.h>
51f8829a4aSRandall Stewart #include <netinet/sctp_auth.h>
52f8829a4aSRandall Stewart #include <netinet/sctp_asconf.h>
53f7517433SRandall Stewart #include <netinet/sctp_bsd_addr.h>
54776cd558SMichael Tuexen #include <netinet/sctp_kdtrace.h>
5510e0318aSMichael Tuexen #if defined(INET6) || defined(INET)
5610e0318aSMichael Tuexen #include <netinet/tcp_var.h>
5710e0318aSMichael Tuexen #endif
583a51a264SMichael Tuexen #include <netinet/udp.h>
593a51a264SMichael Tuexen #include <netinet/udp_var.h>
603a51a264SMichael Tuexen #include <sys/proc.h>
61fd7af143SMichael Tuexen #ifdef INET6
62fd7af143SMichael Tuexen #include <netinet/icmp6.h>
63fd7af143SMichael Tuexen #endif
64f8829a4aSRandall Stewart 
65b9e7085aSRandall Stewart #ifndef KTR_SCTP
66b9e7085aSRandall Stewart #define KTR_SCTP KTR_SUBSYS
6780fefe0aSRandall Stewart #endif
68f8829a4aSRandall Stewart 
69ed654363SMichael Tuexen extern const struct sctp_cc_functions sctp_cc_functions[];
70ed654363SMichael Tuexen extern const struct sctp_ss_functions sctp_ss_functions[];
710e9a9c10SMichael Tuexen 
72f8829a4aSRandall Stewart void
73dcb68fbaSMichael Tuexen sctp_sblog(struct sockbuf *sb, struct sctp_tcb *stcb, int from, int incr)
74f8829a4aSRandall Stewart {
75c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
76c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
77f8829a4aSRandall Stewart 
7880fefe0aSRandall Stewart 	sctp_clog.x.sb.stcb = stcb;
794e88d37aSMichael Tuexen 	sctp_clog.x.sb.so_sbcc = sb->sb_cc;
80f8829a4aSRandall Stewart 	if (stcb)
814e88d37aSMichael Tuexen 		sctp_clog.x.sb.stcb_sbcc = stcb->asoc.sb_cc;
82f8829a4aSRandall Stewart 	else
8380fefe0aSRandall Stewart 		sctp_clog.x.sb.stcb_sbcc = 0;
8480fefe0aSRandall Stewart 	sctp_clog.x.sb.incr = incr;
85c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
8680fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_SB,
8780fefe0aSRandall Stewart 	    from,
8880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
8980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
9080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
9180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
92c692df45SMichael Tuexen #endif
93f8829a4aSRandall Stewart }
94f8829a4aSRandall Stewart 
95f8829a4aSRandall Stewart void
96f8829a4aSRandall Stewart sctp_log_closing(struct sctp_inpcb *inp, struct sctp_tcb *stcb, int16_t loc)
97f8829a4aSRandall Stewart {
98c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
99c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
100f8829a4aSRandall Stewart 
10180fefe0aSRandall Stewart 	sctp_clog.x.close.inp = (void *)inp;
10280fefe0aSRandall Stewart 	sctp_clog.x.close.sctp_flags = inp->sctp_flags;
103f8829a4aSRandall Stewart 	if (stcb) {
10480fefe0aSRandall Stewart 		sctp_clog.x.close.stcb = (void *)stcb;
10580fefe0aSRandall Stewart 		sctp_clog.x.close.state = (uint16_t)stcb->asoc.state;
106f8829a4aSRandall Stewart 	} else {
10780fefe0aSRandall Stewart 		sctp_clog.x.close.stcb = 0;
10880fefe0aSRandall Stewart 		sctp_clog.x.close.state = 0;
109f8829a4aSRandall Stewart 	}
11080fefe0aSRandall Stewart 	sctp_clog.x.close.loc = loc;
111c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
11280fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_CLOSE,
11380fefe0aSRandall Stewart 	    0,
11480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
11580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
11680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
11780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
118c692df45SMichael Tuexen #endif
119f8829a4aSRandall Stewart }
120f8829a4aSRandall Stewart 
121f8829a4aSRandall Stewart void
122f8829a4aSRandall Stewart rto_logging(struct sctp_nets *net, int from)
123f8829a4aSRandall Stewart {
124c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
125c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
126f8829a4aSRandall Stewart 
127bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
12880fefe0aSRandall Stewart 	sctp_clog.x.rto.net = (void *)net;
129be1d9176SMichael Tuexen 	sctp_clog.x.rto.rtt = net->rtt / 1000;
130c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
13180fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RTT,
13280fefe0aSRandall Stewart 	    from,
13380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
13480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
13580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
13680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
137c692df45SMichael Tuexen #endif
138f8829a4aSRandall Stewart }
139f8829a4aSRandall Stewart 
140f8829a4aSRandall Stewart void
1416a91f103SRandall Stewart sctp_log_strm_del_alt(struct sctp_tcb *stcb, uint32_t tsn, uint16_t sseq, uint16_t stream, int from)
142f8829a4aSRandall Stewart {
143c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
144c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
145f8829a4aSRandall Stewart 
14680fefe0aSRandall Stewart 	sctp_clog.x.strlog.stcb = stcb;
14780fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_tsn = tsn;
14880fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_sseq = sseq;
14980fefe0aSRandall Stewart 	sctp_clog.x.strlog.e_tsn = 0;
15080fefe0aSRandall Stewart 	sctp_clog.x.strlog.e_sseq = 0;
15180fefe0aSRandall Stewart 	sctp_clog.x.strlog.strm = stream;
152c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
15380fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_STRM,
15480fefe0aSRandall Stewart 	    from,
15580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
15680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
15780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
15880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
159c692df45SMichael Tuexen #endif
160f8829a4aSRandall Stewart }
161f8829a4aSRandall Stewart 
162f8829a4aSRandall Stewart void
163f8829a4aSRandall Stewart sctp_log_nagle_event(struct sctp_tcb *stcb, int action)
164f8829a4aSRandall Stewart {
165c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
166c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
167f8829a4aSRandall Stewart 
16880fefe0aSRandall Stewart 	sctp_clog.x.nagle.stcb = (void *)stcb;
16980fefe0aSRandall Stewart 	sctp_clog.x.nagle.total_flight = stcb->asoc.total_flight;
17080fefe0aSRandall Stewart 	sctp_clog.x.nagle.total_in_queue = stcb->asoc.total_output_queue_size;
17180fefe0aSRandall Stewart 	sctp_clog.x.nagle.count_in_queue = stcb->asoc.chunks_on_out_queue;
17280fefe0aSRandall Stewart 	sctp_clog.x.nagle.count_in_flight = stcb->asoc.total_flight_count;
173c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
17480fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_NAGLE,
17580fefe0aSRandall Stewart 	    action,
17680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
17780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
17880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
17980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
180c692df45SMichael Tuexen #endif
181f8829a4aSRandall Stewart }
182f8829a4aSRandall Stewart 
183f8829a4aSRandall Stewart void
184f8829a4aSRandall Stewart sctp_log_sack(uint32_t old_cumack, uint32_t cumack, uint32_t tsn, uint16_t gaps, uint16_t dups, int from)
185f8829a4aSRandall Stewart {
186c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
187c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
188f8829a4aSRandall Stewart 
18980fefe0aSRandall Stewart 	sctp_clog.x.sack.cumack = cumack;
19080fefe0aSRandall Stewart 	sctp_clog.x.sack.oldcumack = old_cumack;
19180fefe0aSRandall Stewart 	sctp_clog.x.sack.tsn = tsn;
19280fefe0aSRandall Stewart 	sctp_clog.x.sack.numGaps = gaps;
19380fefe0aSRandall Stewart 	sctp_clog.x.sack.numDups = dups;
194c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
19580fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_SACK,
19680fefe0aSRandall Stewart 	    from,
19780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
19880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
19980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
20080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
201c692df45SMichael Tuexen #endif
202f8829a4aSRandall Stewart }
203f8829a4aSRandall Stewart 
204f8829a4aSRandall Stewart void
205f8829a4aSRandall Stewart sctp_log_map(uint32_t map, uint32_t cum, uint32_t high, int from)
206f8829a4aSRandall Stewart {
207c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
208c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
209f8829a4aSRandall Stewart 
210bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
21180fefe0aSRandall Stewart 	sctp_clog.x.map.base = map;
21280fefe0aSRandall Stewart 	sctp_clog.x.map.cum = cum;
21380fefe0aSRandall Stewart 	sctp_clog.x.map.high = high;
214c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
21580fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MAP,
21680fefe0aSRandall Stewart 	    from,
21780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
21880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
21980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
22080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
221c692df45SMichael Tuexen #endif
222f8829a4aSRandall Stewart }
223f8829a4aSRandall Stewart 
224f8829a4aSRandall Stewart void
225dcb68fbaSMichael Tuexen sctp_log_fr(uint32_t biggest_tsn, uint32_t biggest_new_tsn, uint32_t tsn, int from)
226f8829a4aSRandall Stewart {
227c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
228c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
229f8829a4aSRandall Stewart 
230bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
23180fefe0aSRandall Stewart 	sctp_clog.x.fr.largest_tsn = biggest_tsn;
23280fefe0aSRandall Stewart 	sctp_clog.x.fr.largest_new_tsn = biggest_new_tsn;
23380fefe0aSRandall Stewart 	sctp_clog.x.fr.tsn = tsn;
234c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
23580fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_FR,
23680fefe0aSRandall Stewart 	    from,
23780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
23880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
23980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
24080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
241c692df45SMichael Tuexen #endif
242f8829a4aSRandall Stewart }
243f8829a4aSRandall Stewart 
2444be807c4SMichael Tuexen #ifdef SCTP_MBUF_LOGGING
245f8829a4aSRandall Stewart void
246f8829a4aSRandall Stewart sctp_log_mb(struct mbuf *m, int from)
247f8829a4aSRandall Stewart {
248c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
249c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
250f8829a4aSRandall Stewart 
25180fefe0aSRandall Stewart 	sctp_clog.x.mb.mp = m;
25280fefe0aSRandall Stewart 	sctp_clog.x.mb.mbuf_flags = (uint8_t)(SCTP_BUF_GET_FLAGS(m));
25380fefe0aSRandall Stewart 	sctp_clog.x.mb.size = (uint16_t)(SCTP_BUF_LEN(m));
25480fefe0aSRandall Stewart 	sctp_clog.x.mb.data = SCTP_BUF_AT(m, 0);
255139bc87fSRandall Stewart 	if (SCTP_BUF_IS_EXTENDED(m)) {
25680fefe0aSRandall Stewart 		sctp_clog.x.mb.ext = SCTP_BUF_EXTEND_BASE(m);
25780fefe0aSRandall Stewart 		sctp_clog.x.mb.refcnt = (uint8_t)(SCTP_BUF_EXTEND_REFCNT(m));
258f8829a4aSRandall Stewart 	} else {
25980fefe0aSRandall Stewart 		sctp_clog.x.mb.ext = 0;
26080fefe0aSRandall Stewart 		sctp_clog.x.mb.refcnt = 0;
261f8829a4aSRandall Stewart 	}
262c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
26380fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MBUF,
26480fefe0aSRandall Stewart 	    from,
26580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
26680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
26780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
26880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
269c692df45SMichael Tuexen #endif
270f8829a4aSRandall Stewart }
271f8829a4aSRandall Stewart 
272f8829a4aSRandall Stewart void
2734be807c4SMichael Tuexen sctp_log_mbc(struct mbuf *m, int from)
2744be807c4SMichael Tuexen {
2754be807c4SMichael Tuexen 	struct mbuf *mat;
2764be807c4SMichael Tuexen 
2774be807c4SMichael Tuexen 	for (mat = m; mat; mat = SCTP_BUF_NEXT(mat)) {
2784be807c4SMichael Tuexen 		sctp_log_mb(mat, from);
2794be807c4SMichael Tuexen 	}
2804be807c4SMichael Tuexen }
2814be807c4SMichael Tuexen #endif
2824be807c4SMichael Tuexen 
2834be807c4SMichael Tuexen void
284dcb68fbaSMichael Tuexen sctp_log_strm_del(struct sctp_queued_to_read *control, struct sctp_queued_to_read *poschk, int from)
285f8829a4aSRandall Stewart {
286c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
287c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
288f8829a4aSRandall Stewart 
289f8829a4aSRandall Stewart 	if (control == NULL) {
290ad81507eSRandall Stewart 		SCTP_PRINTF("Gak log of NULL?\n");
291f8829a4aSRandall Stewart 		return;
292f8829a4aSRandall Stewart 	}
29380fefe0aSRandall Stewart 	sctp_clog.x.strlog.stcb = control->stcb;
29480fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_tsn = control->sinfo_tsn;
29549656eefSMichael Tuexen 	sctp_clog.x.strlog.n_sseq = (uint16_t)control->mid;
29680fefe0aSRandall Stewart 	sctp_clog.x.strlog.strm = control->sinfo_stream;
297f8829a4aSRandall Stewart 	if (poschk != NULL) {
29880fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_tsn = poschk->sinfo_tsn;
29949656eefSMichael Tuexen 		sctp_clog.x.strlog.e_sseq = (uint16_t)poschk->mid;
300f8829a4aSRandall Stewart 	} else {
30180fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_tsn = 0;
30280fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_sseq = 0;
303f8829a4aSRandall Stewart 	}
304c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
30580fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_STRM,
30680fefe0aSRandall Stewart 	    from,
30780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
30880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
30980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
31080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
311c692df45SMichael Tuexen #endif
312f8829a4aSRandall Stewart }
313f8829a4aSRandall Stewart 
314f8829a4aSRandall Stewart void
315f8829a4aSRandall Stewart sctp_log_cwnd(struct sctp_tcb *stcb, struct sctp_nets *net, int augment, uint8_t from)
316f8829a4aSRandall Stewart {
317c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
318c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
319f8829a4aSRandall Stewart 
32080fefe0aSRandall Stewart 	sctp_clog.x.cwnd.net = net;
321f8829a4aSRandall Stewart 	if (stcb->asoc.send_queue_cnt > 255)
32280fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = 255;
323f8829a4aSRandall Stewart 	else
32480fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = stcb->asoc.send_queue_cnt;
325f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt > 255)
32680fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = 255;
327f8829a4aSRandall Stewart 	else
32880fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = stcb->asoc.stream_queue_cnt;
329f8829a4aSRandall Stewart 
330f8829a4aSRandall Stewart 	if (net) {
33180fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cwnd_new_value = net->cwnd;
33280fefe0aSRandall Stewart 		sctp_clog.x.cwnd.inflight = net->flight_size;
33380fefe0aSRandall Stewart 		sctp_clog.x.cwnd.pseudo_cumack = net->pseudo_cumack;
33480fefe0aSRandall Stewart 		sctp_clog.x.cwnd.meets_pseudo_cumack = net->new_pseudo_cumack;
33580fefe0aSRandall Stewart 		sctp_clog.x.cwnd.need_new_pseudo_cumack = net->find_pseudo_cumack;
336f8829a4aSRandall Stewart 	}
337f8829a4aSRandall Stewart 	if (SCTP_CWNDLOG_PRESEND == from) {
33880fefe0aSRandall Stewart 		sctp_clog.x.cwnd.meets_pseudo_cumack = stcb->asoc.peers_rwnd;
339f8829a4aSRandall Stewart 	}
34080fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_augment = augment;
341c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
34280fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_CWND,
34380fefe0aSRandall Stewart 	    from,
34480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
34580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
34680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
34780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
348c692df45SMichael Tuexen #endif
349f8829a4aSRandall Stewart }
350f8829a4aSRandall Stewart 
351f8829a4aSRandall Stewart void
352f8829a4aSRandall Stewart sctp_log_lock(struct sctp_inpcb *inp, struct sctp_tcb *stcb, uint8_t from)
353f8829a4aSRandall Stewart {
354c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
355c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
356f8829a4aSRandall Stewart 
357bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
35803b0b021SRandall Stewart 	if (inp) {
35980fefe0aSRandall Stewart 		sctp_clog.x.lock.sock = (void *)inp->sctp_socket;
36003b0b021SRandall Stewart 
36103b0b021SRandall Stewart 	} else {
36280fefe0aSRandall Stewart 		sctp_clog.x.lock.sock = (void *)NULL;
36303b0b021SRandall Stewart 	}
36480fefe0aSRandall Stewart 	sctp_clog.x.lock.inp = (void *)inp;
365f8829a4aSRandall Stewart 	if (stcb) {
36680fefe0aSRandall Stewart 		sctp_clog.x.lock.tcb_lock = mtx_owned(&stcb->tcb_mtx);
367f8829a4aSRandall Stewart 	} else {
36880fefe0aSRandall Stewart 		sctp_clog.x.lock.tcb_lock = SCTP_LOCK_UNKNOWN;
369f8829a4aSRandall Stewart 	}
370f8829a4aSRandall Stewart 	if (inp) {
37180fefe0aSRandall Stewart 		sctp_clog.x.lock.inp_lock = mtx_owned(&inp->inp_mtx);
37280fefe0aSRandall Stewart 		sctp_clog.x.lock.create_lock = mtx_owned(&inp->inp_create_mtx);
373f8829a4aSRandall Stewart 	} else {
37480fefe0aSRandall Stewart 		sctp_clog.x.lock.inp_lock = SCTP_LOCK_UNKNOWN;
37580fefe0aSRandall Stewart 		sctp_clog.x.lock.create_lock = SCTP_LOCK_UNKNOWN;
376f8829a4aSRandall Stewart 	}
377b3f1ea41SRandall Stewart 	sctp_clog.x.lock.info_lock = rw_wowned(&SCTP_BASE_INFO(ipi_ep_mtx));
37852129fcdSRandall Stewart 	if (inp && (inp->sctp_socket)) {
379a1002174SMark Johnston 		sctp_clog.x.lock.sock_lock = mtx_owned(SOCK_MTX(inp->sctp_socket));
380a1002174SMark Johnston 		sctp_clog.x.lock.sockrcvbuf_lock = mtx_owned(SOCKBUF_MTX(&inp->sctp_socket->so_rcv));
381a1002174SMark Johnston 		sctp_clog.x.lock.socksndbuf_lock = mtx_owned(SOCKBUF_MTX(&inp->sctp_socket->so_snd));
382f8829a4aSRandall Stewart 	} else {
38380fefe0aSRandall Stewart 		sctp_clog.x.lock.sock_lock = SCTP_LOCK_UNKNOWN;
38480fefe0aSRandall Stewart 		sctp_clog.x.lock.sockrcvbuf_lock = SCTP_LOCK_UNKNOWN;
38580fefe0aSRandall Stewart 		sctp_clog.x.lock.socksndbuf_lock = SCTP_LOCK_UNKNOWN;
386f8829a4aSRandall Stewart 	}
387c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
38880fefe0aSRandall Stewart 	    SCTP_LOG_LOCK_EVENT,
38980fefe0aSRandall Stewart 	    from,
39080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
39180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
39280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
39380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
394c692df45SMichael Tuexen #endif
395f8829a4aSRandall Stewart }
396f8829a4aSRandall Stewart 
397f8829a4aSRandall Stewart void
398f8829a4aSRandall Stewart sctp_log_maxburst(struct sctp_tcb *stcb, struct sctp_nets *net, int error, int burst, uint8_t from)
399f8829a4aSRandall Stewart {
400c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
401c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
402f8829a4aSRandall Stewart 
403bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
40480fefe0aSRandall Stewart 	sctp_clog.x.cwnd.net = net;
40580fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_new_value = error;
40680fefe0aSRandall Stewart 	sctp_clog.x.cwnd.inflight = net->flight_size;
40780fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_augment = burst;
408f8829a4aSRandall Stewart 	if (stcb->asoc.send_queue_cnt > 255)
40980fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = 255;
410f8829a4aSRandall Stewart 	else
41180fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = stcb->asoc.send_queue_cnt;
412f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt > 255)
41380fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = 255;
414f8829a4aSRandall Stewart 	else
41580fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = stcb->asoc.stream_queue_cnt;
416c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
41780fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MAXBURST,
41880fefe0aSRandall Stewart 	    from,
41980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
42080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
42180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
42280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
423c692df45SMichael Tuexen #endif
424f8829a4aSRandall Stewart }
425f8829a4aSRandall Stewart 
426f8829a4aSRandall Stewart void
427f8829a4aSRandall Stewart sctp_log_rwnd(uint8_t from, uint32_t peers_rwnd, uint32_t snd_size, uint32_t overhead)
428f8829a4aSRandall Stewart {
429c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
430c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
431f8829a4aSRandall Stewart 
43280fefe0aSRandall Stewart 	sctp_clog.x.rwnd.rwnd = peers_rwnd;
43380fefe0aSRandall Stewart 	sctp_clog.x.rwnd.send_size = snd_size;
43480fefe0aSRandall Stewart 	sctp_clog.x.rwnd.overhead = overhead;
43580fefe0aSRandall Stewart 	sctp_clog.x.rwnd.new_rwnd = 0;
436c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
43780fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RWND,
43880fefe0aSRandall Stewart 	    from,
43980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
44080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
44180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
44280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
443c692df45SMichael Tuexen #endif
444f8829a4aSRandall Stewart }
445f8829a4aSRandall Stewart 
446f8829a4aSRandall Stewart void
447f8829a4aSRandall Stewart sctp_log_rwnd_set(uint8_t from, uint32_t peers_rwnd, uint32_t flight_size, uint32_t overhead, uint32_t a_rwndval)
448f8829a4aSRandall Stewart {
449c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
450c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
451f8829a4aSRandall Stewart 
45280fefe0aSRandall Stewart 	sctp_clog.x.rwnd.rwnd = peers_rwnd;
45380fefe0aSRandall Stewart 	sctp_clog.x.rwnd.send_size = flight_size;
45480fefe0aSRandall Stewart 	sctp_clog.x.rwnd.overhead = overhead;
45580fefe0aSRandall Stewart 	sctp_clog.x.rwnd.new_rwnd = a_rwndval;
456c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
45780fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RWND,
45880fefe0aSRandall Stewart 	    from,
45980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
46080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
46180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
46280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
463c692df45SMichael Tuexen #endif
464f8829a4aSRandall Stewart }
465f8829a4aSRandall Stewart 
4664be807c4SMichael Tuexen #ifdef SCTP_MBCNT_LOGGING
4674be807c4SMichael Tuexen static void
468f8829a4aSRandall Stewart sctp_log_mbcnt(uint8_t from, uint32_t total_oq, uint32_t book, uint32_t total_mbcnt_q, uint32_t mbcnt)
469f8829a4aSRandall Stewart {
470c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
471c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
472f8829a4aSRandall Stewart 
47380fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.total_queue_size = total_oq;
47480fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.size_change = book;
47580fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.total_queue_mb_size = total_mbcnt_q;
47680fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.mbcnt_change = mbcnt;
477c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
47880fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MBCNT,
47980fefe0aSRandall Stewart 	    from,
48080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
48180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
48280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
48380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
484c692df45SMichael Tuexen #endif
485f8829a4aSRandall Stewart }
4864be807c4SMichael Tuexen #endif
4874be807c4SMichael Tuexen 
488f8829a4aSRandall Stewart void
489f8829a4aSRandall Stewart sctp_misc_ints(uint8_t from, uint32_t a, uint32_t b, uint32_t c, uint32_t d)
490f8829a4aSRandall Stewart {
491c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
492c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
49380fefe0aSRandall Stewart 	    SCTP_LOG_MISC_EVENT,
49480fefe0aSRandall Stewart 	    from,
49580fefe0aSRandall Stewart 	    a, b, c, d);
496c692df45SMichael Tuexen #endif
497f8829a4aSRandall Stewart }
498f8829a4aSRandall Stewart 
499f8829a4aSRandall Stewart void
5007215cc1bSMichael Tuexen sctp_wakeup_log(struct sctp_tcb *stcb, uint32_t wake_cnt, int from)
501f8829a4aSRandall Stewart {
502c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
503c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
504f8829a4aSRandall Stewart 
50580fefe0aSRandall Stewart 	sctp_clog.x.wake.stcb = (void *)stcb;
50680fefe0aSRandall Stewart 	sctp_clog.x.wake.wake_cnt = wake_cnt;
50780fefe0aSRandall Stewart 	sctp_clog.x.wake.flight = stcb->asoc.total_flight_count;
50880fefe0aSRandall Stewart 	sctp_clog.x.wake.send_q = stcb->asoc.send_queue_cnt;
50980fefe0aSRandall Stewart 	sctp_clog.x.wake.sent_q = stcb->asoc.sent_queue_cnt;
510f8829a4aSRandall Stewart 
511f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt < 0xff)
51280fefe0aSRandall Stewart 		sctp_clog.x.wake.stream_qcnt = (uint8_t)stcb->asoc.stream_queue_cnt;
513f8829a4aSRandall Stewart 	else
51480fefe0aSRandall Stewart 		sctp_clog.x.wake.stream_qcnt = 0xff;
515f8829a4aSRandall Stewart 
516f8829a4aSRandall Stewart 	if (stcb->asoc.chunks_on_out_queue < 0xff)
51780fefe0aSRandall Stewart 		sctp_clog.x.wake.chunks_on_oque = (uint8_t)stcb->asoc.chunks_on_out_queue;
518f8829a4aSRandall Stewart 	else
51980fefe0aSRandall Stewart 		sctp_clog.x.wake.chunks_on_oque = 0xff;
520f8829a4aSRandall Stewart 
52180fefe0aSRandall Stewart 	sctp_clog.x.wake.sctpflags = 0;
522f8829a4aSRandall Stewart 	/* set in the defered mode stuff */
523f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_DONT_WAKE)
52480fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 1;
525f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_WAKEOUTPUT)
52680fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 2;
527f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_WAKEINPUT)
52880fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 4;
529f8829a4aSRandall Stewart 	/* what about the sb */
530f8829a4aSRandall Stewart 	if (stcb->sctp_socket) {
531f8829a4aSRandall Stewart 		struct socket *so = stcb->sctp_socket;
532f8829a4aSRandall Stewart 
53380fefe0aSRandall Stewart 		sctp_clog.x.wake.sbflags = (uint8_t)((so->so_snd.sb_flags & 0x00ff));
534f8829a4aSRandall Stewart 	} else {
53580fefe0aSRandall Stewart 		sctp_clog.x.wake.sbflags = 0xff;
536f8829a4aSRandall Stewart 	}
537c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
53880fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_WAKE,
53980fefe0aSRandall Stewart 	    from,
54080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
54180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
54280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
54380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
544c692df45SMichael Tuexen #endif
545f8829a4aSRandall Stewart }
546f8829a4aSRandall Stewart 
547f8829a4aSRandall Stewart void
54858e6eeefSMichael Tuexen sctp_log_block(uint8_t from, struct sctp_association *asoc, ssize_t sendlen)
549f8829a4aSRandall Stewart {
550c692df45SMichael Tuexen #if defined(SCTP_LOCAL_TRACE_BUF)
551c692df45SMichael Tuexen 	struct sctp_cwnd_log sctp_clog;
552f8829a4aSRandall Stewart 
55380fefe0aSRandall Stewart 	sctp_clog.x.blk.onsb = asoc->total_output_queue_size;
55480fefe0aSRandall Stewart 	sctp_clog.x.blk.send_sent_qcnt = (uint16_t)(asoc->send_queue_cnt + asoc->sent_queue_cnt);
55580fefe0aSRandall Stewart 	sctp_clog.x.blk.peer_rwnd = asoc->peers_rwnd;
55680fefe0aSRandall Stewart 	sctp_clog.x.blk.stream_qcnt = (uint16_t)asoc->stream_queue_cnt;
55780fefe0aSRandall Stewart 	sctp_clog.x.blk.chunks_on_oque = (uint16_t)asoc->chunks_on_out_queue;
55880fefe0aSRandall Stewart 	sctp_clog.x.blk.flight_size = (uint16_t)(asoc->total_flight / 1024);
5599a8e3088SMichael Tuexen 	sctp_clog.x.blk.sndlen = (uint32_t)sendlen;
560c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
56180fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_BLOCK,
56280fefe0aSRandall Stewart 	    from,
56380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
56480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
56580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
56680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
567c692df45SMichael Tuexen #endif
568f8829a4aSRandall Stewart }
569f8829a4aSRandall Stewart 
570f8829a4aSRandall Stewart int
5717215cc1bSMichael Tuexen sctp_fill_stat_log(void *optval SCTP_UNUSED, size_t *optsize SCTP_UNUSED)
572f8829a4aSRandall Stewart {
57380fefe0aSRandall Stewart 	/* May need to fix this if ktrdump does not work */
574f8829a4aSRandall Stewart 	return (0);
575f8829a4aSRandall Stewart }
576f8829a4aSRandall Stewart 
577f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
578f8829a4aSRandall Stewart uint8_t sctp_audit_data[SCTP_AUDIT_SIZE][2];
579f8829a4aSRandall Stewart static int sctp_audit_indx = 0;
580f8829a4aSRandall Stewart 
581f8829a4aSRandall Stewart static
582f8829a4aSRandall Stewart void
583f8829a4aSRandall Stewart sctp_print_audit_report(void)
584f8829a4aSRandall Stewart {
585f8829a4aSRandall Stewart 	int i;
586f8829a4aSRandall Stewart 	int cnt;
587f8829a4aSRandall Stewart 
588f8829a4aSRandall Stewart 	cnt = 0;
589f8829a4aSRandall Stewart 	for (i = sctp_audit_indx; i < SCTP_AUDIT_SIZE; i++) {
590f8829a4aSRandall Stewart 		if ((sctp_audit_data[i][0] == 0xe0) &&
591f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
592f8829a4aSRandall Stewart 			cnt = 0;
593ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
594f8829a4aSRandall Stewart 		} else if (sctp_audit_data[i][0] == 0xf0) {
595f8829a4aSRandall Stewart 			cnt = 0;
596ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
597f8829a4aSRandall Stewart 		} else if ((sctp_audit_data[i][0] == 0xc0) &&
598f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
599ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
600f8829a4aSRandall Stewart 			cnt = 0;
601f8829a4aSRandall Stewart 		}
602ad81507eSRandall Stewart 		SCTP_PRINTF("%2.2x%2.2x ", (uint32_t)sctp_audit_data[i][0],
603f8829a4aSRandall Stewart 		    (uint32_t)sctp_audit_data[i][1]);
604f8829a4aSRandall Stewart 		cnt++;
605f8829a4aSRandall Stewart 		if ((cnt % 14) == 0)
606ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
607f8829a4aSRandall Stewart 	}
608f8829a4aSRandall Stewart 	for (i = 0; i < sctp_audit_indx; i++) {
609f8829a4aSRandall Stewart 		if ((sctp_audit_data[i][0] == 0xe0) &&
610f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
611f8829a4aSRandall Stewart 			cnt = 0;
612ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
613f8829a4aSRandall Stewart 		} else if (sctp_audit_data[i][0] == 0xf0) {
614f8829a4aSRandall Stewart 			cnt = 0;
615ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
616f8829a4aSRandall Stewart 		} else if ((sctp_audit_data[i][0] == 0xc0) &&
617f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
618ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
619f8829a4aSRandall Stewart 			cnt = 0;
620f8829a4aSRandall Stewart 		}
621ad81507eSRandall Stewart 		SCTP_PRINTF("%2.2x%2.2x ", (uint32_t)sctp_audit_data[i][0],
622f8829a4aSRandall Stewart 		    (uint32_t)sctp_audit_data[i][1]);
623f8829a4aSRandall Stewart 		cnt++;
624f8829a4aSRandall Stewart 		if ((cnt % 14) == 0)
625ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
626f8829a4aSRandall Stewart 	}
627ad81507eSRandall Stewart 	SCTP_PRINTF("\n");
628f8829a4aSRandall Stewart }
629f8829a4aSRandall Stewart 
630f8829a4aSRandall Stewart void
631f8829a4aSRandall Stewart sctp_auditing(int from, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
632f8829a4aSRandall Stewart     struct sctp_nets *net)
633f8829a4aSRandall Stewart {
634f8829a4aSRandall Stewart 	int resend_cnt, tot_out, rep, tot_book_cnt;
635f8829a4aSRandall Stewart 	struct sctp_nets *lnet;
636f8829a4aSRandall Stewart 	struct sctp_tmit_chunk *chk;
637f8829a4aSRandall Stewart 
638f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = 0xAA;
639f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] = 0x000000ff & from;
640f8829a4aSRandall Stewart 	sctp_audit_indx++;
641f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
642f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
643f8829a4aSRandall Stewart 	}
644f8829a4aSRandall Stewart 	if (inp == NULL) {
645f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
646f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0x01;
647f8829a4aSRandall Stewart 		sctp_audit_indx++;
648f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
649f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
650f8829a4aSRandall Stewart 		}
651f8829a4aSRandall Stewart 		return;
652f8829a4aSRandall Stewart 	}
653f8829a4aSRandall Stewart 	if (stcb == NULL) {
654f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
655f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0x02;
656f8829a4aSRandall Stewart 		sctp_audit_indx++;
657f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
658f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
659f8829a4aSRandall Stewart 		}
660f8829a4aSRandall Stewart 		return;
661f8829a4aSRandall Stewart 	}
662f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = 0xA1;
663f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] =
664f8829a4aSRandall Stewart 	    (0x000000ff & stcb->asoc.sent_queue_retran_cnt);
665f8829a4aSRandall Stewart 	sctp_audit_indx++;
666f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
667f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
668f8829a4aSRandall Stewart 	}
669f8829a4aSRandall Stewart 	rep = 0;
670f8829a4aSRandall Stewart 	tot_book_cnt = 0;
671f8829a4aSRandall Stewart 	resend_cnt = tot_out = 0;
672f8829a4aSRandall Stewart 	TAILQ_FOREACH(chk, &stcb->asoc.sent_queue, sctp_next) {
673f8829a4aSRandall Stewart 		if (chk->sent == SCTP_DATAGRAM_RESEND) {
674f8829a4aSRandall Stewart 			resend_cnt++;
675f8829a4aSRandall Stewart 		} else if (chk->sent < SCTP_DATAGRAM_RESEND) {
676f8829a4aSRandall Stewart 			tot_out += chk->book_size;
677f8829a4aSRandall Stewart 			tot_book_cnt++;
678f8829a4aSRandall Stewart 		}
679f8829a4aSRandall Stewart 	}
680f8829a4aSRandall Stewart 	if (resend_cnt != stcb->asoc.sent_queue_retran_cnt) {
681f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
682f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA1;
683f8829a4aSRandall Stewart 		sctp_audit_indx++;
684f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
685f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
686f8829a4aSRandall Stewart 		}
687ad81507eSRandall Stewart 		SCTP_PRINTF("resend_cnt:%d asoc-tot:%d\n",
688f8829a4aSRandall Stewart 		    resend_cnt, stcb->asoc.sent_queue_retran_cnt);
689f8829a4aSRandall Stewart 		rep = 1;
690f8829a4aSRandall Stewart 		stcb->asoc.sent_queue_retran_cnt = resend_cnt;
691f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xA2;
692f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] =
693f8829a4aSRandall Stewart 		    (0x000000ff & stcb->asoc.sent_queue_retran_cnt);
694f8829a4aSRandall Stewart 		sctp_audit_indx++;
695f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
696f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
697f8829a4aSRandall Stewart 		}
698f8829a4aSRandall Stewart 	}
699f8829a4aSRandall Stewart 	if (tot_out != stcb->asoc.total_flight) {
700f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
701f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA2;
702f8829a4aSRandall Stewart 		sctp_audit_indx++;
703f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
704f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
705f8829a4aSRandall Stewart 		}
706f8829a4aSRandall Stewart 		rep = 1;
707ad81507eSRandall Stewart 		SCTP_PRINTF("tot_flt:%d asoc_tot:%d\n", tot_out,
708f8829a4aSRandall Stewart 		    (int)stcb->asoc.total_flight);
709f8829a4aSRandall Stewart 		stcb->asoc.total_flight = tot_out;
710f8829a4aSRandall Stewart 	}
711f8829a4aSRandall Stewart 	if (tot_book_cnt != stcb->asoc.total_flight_count) {
712f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
713f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA5;
714f8829a4aSRandall Stewart 		sctp_audit_indx++;
715f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
716f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
717f8829a4aSRandall Stewart 		}
718f8829a4aSRandall Stewart 		rep = 1;
719f31e6c7fSMichael Tuexen 		SCTP_PRINTF("tot_flt_book:%d\n", tot_book_cnt);
720f8829a4aSRandall Stewart 
721f8829a4aSRandall Stewart 		stcb->asoc.total_flight_count = tot_book_cnt;
722f8829a4aSRandall Stewart 	}
723f8829a4aSRandall Stewart 	tot_out = 0;
724f8829a4aSRandall Stewart 	TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
725f8829a4aSRandall Stewart 		tot_out += lnet->flight_size;
726f8829a4aSRandall Stewart 	}
727f8829a4aSRandall Stewart 	if (tot_out != stcb->asoc.total_flight) {
728f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
729f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA3;
730f8829a4aSRandall Stewart 		sctp_audit_indx++;
731f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
732f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
733f8829a4aSRandall Stewart 		}
734f8829a4aSRandall Stewart 		rep = 1;
735ad81507eSRandall Stewart 		SCTP_PRINTF("real flight:%d net total was %d\n",
736f8829a4aSRandall Stewart 		    stcb->asoc.total_flight, tot_out);
737f8829a4aSRandall Stewart 		/* now corrective action */
738f8829a4aSRandall Stewart 		TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
739f8829a4aSRandall Stewart 			tot_out = 0;
740f8829a4aSRandall Stewart 			TAILQ_FOREACH(chk, &stcb->asoc.sent_queue, sctp_next) {
741f8829a4aSRandall Stewart 				if ((chk->whoTo == lnet) &&
742f8829a4aSRandall Stewart 				    (chk->sent < SCTP_DATAGRAM_RESEND)) {
743f8829a4aSRandall Stewart 					tot_out += chk->book_size;
744f8829a4aSRandall Stewart 				}
745f8829a4aSRandall Stewart 			}
746f8829a4aSRandall Stewart 			if (lnet->flight_size != tot_out) {
747f31e6c7fSMichael Tuexen 				SCTP_PRINTF("net:%p flight was %d corrected to %d\n",
748dd294dceSMichael Tuexen 				    (void *)lnet, lnet->flight_size,
749ad81507eSRandall Stewart 				    tot_out);
750f8829a4aSRandall Stewart 				lnet->flight_size = tot_out;
751f8829a4aSRandall Stewart 			}
752f8829a4aSRandall Stewart 		}
753f8829a4aSRandall Stewart 	}
754f8829a4aSRandall Stewart 	if (rep) {
755f8829a4aSRandall Stewart 		sctp_print_audit_report();
756f8829a4aSRandall Stewart 	}
757f8829a4aSRandall Stewart }
758f8829a4aSRandall Stewart 
759f8829a4aSRandall Stewart void
760f8829a4aSRandall Stewart sctp_audit_log(uint8_t ev, uint8_t fd)
761f8829a4aSRandall Stewart {
762f8829a4aSRandall Stewart 
763f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = ev;
764f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] = fd;
765f8829a4aSRandall Stewart 	sctp_audit_indx++;
766f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
767f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
768f8829a4aSRandall Stewart 	}
769f8829a4aSRandall Stewart }
770f8829a4aSRandall Stewart 
771f8829a4aSRandall Stewart #endif
772f8829a4aSRandall Stewart 
773f8829a4aSRandall Stewart /*
77425ec3553SMichael Tuexen  * The conversion from time to ticks and vice versa is done by rounding
77525ec3553SMichael Tuexen  * upwards. This way we can test in the code the time to be positive and
77625ec3553SMichael Tuexen  * know that this corresponds to a positive number of ticks.
77725ec3553SMichael Tuexen  */
77825ec3553SMichael Tuexen 
77925ec3553SMichael Tuexen uint32_t
78025ec3553SMichael Tuexen sctp_msecs_to_ticks(uint32_t msecs)
78125ec3553SMichael Tuexen {
78225ec3553SMichael Tuexen 	uint64_t temp;
78325ec3553SMichael Tuexen 	uint32_t ticks;
78425ec3553SMichael Tuexen 
78525ec3553SMichael Tuexen 	if (hz == 1000) {
78625ec3553SMichael Tuexen 		ticks = msecs;
78725ec3553SMichael Tuexen 	} else {
78825ec3553SMichael Tuexen 		temp = (((uint64_t)msecs * hz) + 999) / 1000;
78925ec3553SMichael Tuexen 		if (temp > UINT32_MAX) {
79025ec3553SMichael Tuexen 			ticks = UINT32_MAX;
79125ec3553SMichael Tuexen 		} else {
79225ec3553SMichael Tuexen 			ticks = (uint32_t)temp;
79325ec3553SMichael Tuexen 		}
79425ec3553SMichael Tuexen 	}
79525ec3553SMichael Tuexen 	return (ticks);
79625ec3553SMichael Tuexen }
79725ec3553SMichael Tuexen 
79825ec3553SMichael Tuexen uint32_t
79925ec3553SMichael Tuexen sctp_ticks_to_msecs(uint32_t ticks)
80025ec3553SMichael Tuexen {
80125ec3553SMichael Tuexen 	uint64_t temp;
80225ec3553SMichael Tuexen 	uint32_t msecs;
80325ec3553SMichael Tuexen 
80425ec3553SMichael Tuexen 	if (hz == 1000) {
80525ec3553SMichael Tuexen 		msecs = ticks;
80625ec3553SMichael Tuexen 	} else {
80725ec3553SMichael Tuexen 		temp = (((uint64_t)ticks * 1000) + (hz - 1)) / hz;
80825ec3553SMichael Tuexen 		if (temp > UINT32_MAX) {
80925ec3553SMichael Tuexen 			msecs = UINT32_MAX;
81025ec3553SMichael Tuexen 		} else {
81125ec3553SMichael Tuexen 			msecs = (uint32_t)temp;
81225ec3553SMichael Tuexen 		}
81325ec3553SMichael Tuexen 	}
81425ec3553SMichael Tuexen 	return (msecs);
81525ec3553SMichael Tuexen }
81625ec3553SMichael Tuexen 
81725ec3553SMichael Tuexen uint32_t
81825ec3553SMichael Tuexen sctp_secs_to_ticks(uint32_t secs)
81925ec3553SMichael Tuexen {
82025ec3553SMichael Tuexen 	uint64_t temp;
82125ec3553SMichael Tuexen 	uint32_t ticks;
82225ec3553SMichael Tuexen 
82325ec3553SMichael Tuexen 	temp = (uint64_t)secs * hz;
82425ec3553SMichael Tuexen 	if (temp > UINT32_MAX) {
82525ec3553SMichael Tuexen 		ticks = UINT32_MAX;
82625ec3553SMichael Tuexen 	} else {
82725ec3553SMichael Tuexen 		ticks = (uint32_t)temp;
82825ec3553SMichael Tuexen 	}
82925ec3553SMichael Tuexen 	return (ticks);
83025ec3553SMichael Tuexen }
83125ec3553SMichael Tuexen 
83225ec3553SMichael Tuexen uint32_t
83325ec3553SMichael Tuexen sctp_ticks_to_secs(uint32_t ticks)
83425ec3553SMichael Tuexen {
83525ec3553SMichael Tuexen 	uint64_t temp;
83625ec3553SMichael Tuexen 	uint32_t secs;
83725ec3553SMichael Tuexen 
83825ec3553SMichael Tuexen 	temp = ((uint64_t)ticks + (hz - 1)) / hz;
83925ec3553SMichael Tuexen 	if (temp > UINT32_MAX) {
84025ec3553SMichael Tuexen 		secs = UINT32_MAX;
84125ec3553SMichael Tuexen 	} else {
84225ec3553SMichael Tuexen 		secs = (uint32_t)temp;
84325ec3553SMichael Tuexen 	}
84425ec3553SMichael Tuexen 	return (secs);
84525ec3553SMichael Tuexen }
84625ec3553SMichael Tuexen 
84725ec3553SMichael Tuexen /*
84812af6654SMichael Tuexen  * sctp_stop_timers_for_shutdown() should be called
84912af6654SMichael Tuexen  * when entering the SHUTDOWN_SENT or SHUTDOWN_ACK_SENT
85012af6654SMichael Tuexen  * state to make sure that all timers are stopped.
85112af6654SMichael Tuexen  */
85212af6654SMichael Tuexen void
85312af6654SMichael Tuexen sctp_stop_timers_for_shutdown(struct sctp_tcb *stcb)
85412af6654SMichael Tuexen {
8555555400aSMichael Tuexen 	struct sctp_inpcb *inp;
85612af6654SMichael Tuexen 	struct sctp_nets *net;
85712af6654SMichael Tuexen 
8585555400aSMichael Tuexen 	inp = stcb->sctp_ep;
85912af6654SMichael Tuexen 
8605555400aSMichael Tuexen 	sctp_timer_stop(SCTP_TIMER_TYPE_RECV, inp, stcb, NULL,
8615555400aSMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_12);
8625555400aSMichael Tuexen 	sctp_timer_stop(SCTP_TIMER_TYPE_STRRESET, inp, stcb, NULL,
8635555400aSMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_13);
8645555400aSMichael Tuexen 	sctp_timer_stop(SCTP_TIMER_TYPE_ASCONF, inp, stcb, NULL,
8655555400aSMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_14);
8665555400aSMichael Tuexen 	sctp_timer_stop(SCTP_TIMER_TYPE_AUTOCLOSE, inp, stcb, NULL,
8675555400aSMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_15);
8685555400aSMichael Tuexen 	TAILQ_FOREACH(net, &stcb->asoc.nets, sctp_next) {
8695555400aSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_PATHMTURAISE, inp, stcb, net,
8705555400aSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_16);
8715555400aSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_HEARTBEAT, inp, stcb, net,
8725555400aSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_17);
8735555400aSMichael Tuexen 	}
8745555400aSMichael Tuexen }
8755555400aSMichael Tuexen 
8765555400aSMichael Tuexen void
8778803350dSMichael Tuexen sctp_stop_association_timers(struct sctp_tcb *stcb, bool stop_assoc_kill_timer)
8785555400aSMichael Tuexen {
8795555400aSMichael Tuexen 	struct sctp_inpcb *inp;
8805555400aSMichael Tuexen 	struct sctp_nets *net;
8815555400aSMichael Tuexen 
8825555400aSMichael Tuexen 	inp = stcb->sctp_ep;
8835555400aSMichael Tuexen 	sctp_timer_stop(SCTP_TIMER_TYPE_RECV, inp, stcb, NULL,
8845555400aSMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_18);
8855555400aSMichael Tuexen 	sctp_timer_stop(SCTP_TIMER_TYPE_STRRESET, inp, stcb, NULL,
8865555400aSMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_19);
8878803350dSMichael Tuexen 	if (stop_assoc_kill_timer) {
8885555400aSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_ASOCKILL, inp, stcb, NULL,
8895555400aSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_20);
8905555400aSMichael Tuexen 	}
8915555400aSMichael Tuexen 	sctp_timer_stop(SCTP_TIMER_TYPE_ASCONF, inp, stcb, NULL,
8925555400aSMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_21);
8935555400aSMichael Tuexen 	sctp_timer_stop(SCTP_TIMER_TYPE_AUTOCLOSE, inp, stcb, NULL,
8945555400aSMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_22);
8955555400aSMichael Tuexen 	sctp_timer_stop(SCTP_TIMER_TYPE_SHUTDOWNGUARD, inp, stcb, NULL,
8965555400aSMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_23);
8975555400aSMichael Tuexen 	/* Mobility adaptation */
8985555400aSMichael Tuexen 	sctp_timer_stop(SCTP_TIMER_TYPE_PRIM_DELETED, inp, stcb, NULL,
8995555400aSMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_24);
9005555400aSMichael Tuexen 	TAILQ_FOREACH(net, &stcb->asoc.nets, sctp_next) {
9015555400aSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_SEND, inp, stcb, net,
9025555400aSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_25);
9035555400aSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_INIT, inp, stcb, net,
9045555400aSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_26);
9055555400aSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_SHUTDOWN, inp, stcb, net,
9065555400aSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_27);
9075555400aSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_COOKIE, inp, stcb, net,
9085555400aSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_28);
9095555400aSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_SHUTDOWNACK, inp, stcb, net,
9105555400aSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_29);
9115555400aSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_PATHMTURAISE, inp, stcb, net,
9125555400aSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_30);
9135555400aSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_HEARTBEAT, inp, stcb, net,
9145555400aSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_31);
91512af6654SMichael Tuexen 	}
91612af6654SMichael Tuexen }
91712af6654SMichael Tuexen 
91812af6654SMichael Tuexen /*
919589c42c2SMichael Tuexen  * A list of sizes based on typical mtu's, used only if next hop size not
920589c42c2SMichael Tuexen  * returned. These values MUST be multiples of 4 and MUST be ordered.
921f8829a4aSRandall Stewart  */
922437fc91aSMichael Tuexen static uint32_t sctp_mtu_sizes[] = {
923f8829a4aSRandall Stewart 	68,
924f8829a4aSRandall Stewart 	296,
925f8829a4aSRandall Stewart 	508,
926f8829a4aSRandall Stewart 	512,
927f8829a4aSRandall Stewart 	544,
928f8829a4aSRandall Stewart 	576,
929589c42c2SMichael Tuexen 	1004,
930f8829a4aSRandall Stewart 	1492,
931f8829a4aSRandall Stewart 	1500,
932f8829a4aSRandall Stewart 	1536,
933589c42c2SMichael Tuexen 	2000,
934f8829a4aSRandall Stewart 	2048,
935f8829a4aSRandall Stewart 	4352,
936f8829a4aSRandall Stewart 	4464,
93742078d5aSMichael Tuexen 	8168,
938589c42c2SMichael Tuexen 	17912,
939f8829a4aSRandall Stewart 	32000,
940589c42c2SMichael Tuexen 	65532
941f8829a4aSRandall Stewart };
942f8829a4aSRandall Stewart 
943f8829a4aSRandall Stewart /*
944589c42c2SMichael Tuexen  * Return the largest MTU in sctp_mtu_sizes smaller than val.
945589c42c2SMichael Tuexen  * If val is smaller than the minimum, just return the largest
946589c42c2SMichael Tuexen  * multiple of 4 smaller or equal to val.
947589c42c2SMichael Tuexen  * Ensure that the result is a multiple of 4.
948f8829a4aSRandall Stewart  */
949437fc91aSMichael Tuexen uint32_t
950b0471b4bSMichael Tuexen sctp_get_prev_mtu(uint32_t val)
951b0471b4bSMichael Tuexen {
952437fc91aSMichael Tuexen 	uint32_t i;
953437fc91aSMichael Tuexen 
954eef8d4a9SMichael Tuexen 	val &= 0xfffffffc;
955437fc91aSMichael Tuexen 	if (val <= sctp_mtu_sizes[0]) {
956437fc91aSMichael Tuexen 		return (val);
957437fc91aSMichael Tuexen 	}
958437fc91aSMichael Tuexen 	for (i = 1; i < (sizeof(sctp_mtu_sizes) / sizeof(uint32_t)); i++) {
959437fc91aSMichael Tuexen 		if (val <= sctp_mtu_sizes[i]) {
960f8829a4aSRandall Stewart 			break;
961f8829a4aSRandall Stewart 		}
962f8829a4aSRandall Stewart 	}
963589c42c2SMichael Tuexen 	KASSERT((sctp_mtu_sizes[i - 1] & 0x00000003) == 0,
964589c42c2SMichael Tuexen 	    ("sctp_mtu_sizes[%u] not a multiple of 4", i - 1));
965437fc91aSMichael Tuexen 	return (sctp_mtu_sizes[i - 1]);
966437fc91aSMichael Tuexen }
967437fc91aSMichael Tuexen 
968437fc91aSMichael Tuexen /*
969589c42c2SMichael Tuexen  * Return the smallest MTU in sctp_mtu_sizes larger than val.
970589c42c2SMichael Tuexen  * If val is larger than the maximum, just return the largest multiple of 4 smaller
971589c42c2SMichael Tuexen  * or equal to val.
972589c42c2SMichael Tuexen  * Ensure that the result is a multiple of 4.
973437fc91aSMichael Tuexen  */
974437fc91aSMichael Tuexen uint32_t
975b0471b4bSMichael Tuexen sctp_get_next_mtu(uint32_t val)
976b0471b4bSMichael Tuexen {
977437fc91aSMichael Tuexen 	/* select another MTU that is just bigger than this one */
978437fc91aSMichael Tuexen 	uint32_t i;
979437fc91aSMichael Tuexen 
980eef8d4a9SMichael Tuexen 	val &= 0xfffffffc;
981437fc91aSMichael Tuexen 	for (i = 0; i < (sizeof(sctp_mtu_sizes) / sizeof(uint32_t)); i++) {
982437fc91aSMichael Tuexen 		if (val < sctp_mtu_sizes[i]) {
983589c42c2SMichael Tuexen 			KASSERT((sctp_mtu_sizes[i] & 0x00000003) == 0,
984589c42c2SMichael Tuexen 			    ("sctp_mtu_sizes[%u] not a multiple of 4", i));
985437fc91aSMichael Tuexen 			return (sctp_mtu_sizes[i]);
986437fc91aSMichael Tuexen 		}
987437fc91aSMichael Tuexen 	}
988437fc91aSMichael Tuexen 	return (val);
989f8829a4aSRandall Stewart }
990f8829a4aSRandall Stewart 
991f8829a4aSRandall Stewart void
992f8829a4aSRandall Stewart sctp_fill_random_store(struct sctp_pcb *m)
993f8829a4aSRandall Stewart {
994f8829a4aSRandall Stewart 	/*
995f8829a4aSRandall Stewart 	 * Here we use the MD5/SHA-1 to hash with our good randomNumbers and
996f8829a4aSRandall Stewart 	 * our counter. The result becomes our good random numbers and we
997f8829a4aSRandall Stewart 	 * then setup to give these out. Note that we do no locking to
998f8829a4aSRandall Stewart 	 * protect this. This is ok, since if competing folks call this we
99917205eccSRandall Stewart 	 * will get more gobbled gook in the random store which is what we
1000f8829a4aSRandall Stewart 	 * want. There is a danger that two guys will use the same random
1001f8829a4aSRandall Stewart 	 * numbers, but thats ok too since that is random as well :->
1002f8829a4aSRandall Stewart 	 */
1003f8829a4aSRandall Stewart 	m->store_at = 0;
1004ad81507eSRandall Stewart 	(void)sctp_hmac(SCTP_HMAC, (uint8_t *)m->random_numbers,
1005f8829a4aSRandall Stewart 	    sizeof(m->random_numbers), (uint8_t *)&m->random_counter,
1006f8829a4aSRandall Stewart 	    sizeof(m->random_counter), (uint8_t *)m->random_store);
1007f8829a4aSRandall Stewart 	m->random_counter++;
1008f8829a4aSRandall Stewart }
1009f8829a4aSRandall Stewart 
1010f8829a4aSRandall Stewart uint32_t
1011b0471b4bSMichael Tuexen sctp_select_initial_TSN(struct sctp_pcb *inp)
1012b0471b4bSMichael Tuexen {
1013f8829a4aSRandall Stewart 	/*
1014f8829a4aSRandall Stewart 	 * A true implementation should use random selection process to get
1015f8829a4aSRandall Stewart 	 * the initial stream sequence number, using RFC1750 as a good
1016f8829a4aSRandall Stewart 	 * guideline
1017f8829a4aSRandall Stewart 	 */
1018139bc87fSRandall Stewart 	uint32_t x, *xp;
1019f8829a4aSRandall Stewart 	uint8_t *p;
1020851b7298SRandall Stewart 	int store_at, new_store;
1021f8829a4aSRandall Stewart 
1022851b7298SRandall Stewart 	if (inp->initial_sequence_debug != 0) {
1023f8829a4aSRandall Stewart 		uint32_t ret;
1024f8829a4aSRandall Stewart 
1025851b7298SRandall Stewart 		ret = inp->initial_sequence_debug;
1026851b7298SRandall Stewart 		inp->initial_sequence_debug++;
1027f8829a4aSRandall Stewart 		return (ret);
1028f8829a4aSRandall Stewart 	}
1029851b7298SRandall Stewart retry:
1030851b7298SRandall Stewart 	store_at = inp->store_at;
1031851b7298SRandall Stewart 	new_store = store_at + sizeof(uint32_t);
1032851b7298SRandall Stewart 	if (new_store >= (SCTP_SIGNATURE_SIZE - 3)) {
1033851b7298SRandall Stewart 		new_store = 0;
1034f8829a4aSRandall Stewart 	}
1035851b7298SRandall Stewart 	if (!atomic_cmpset_int(&inp->store_at, store_at, new_store)) {
1036851b7298SRandall Stewart 		goto retry;
1037851b7298SRandall Stewart 	}
1038851b7298SRandall Stewart 	if (new_store == 0) {
1039851b7298SRandall Stewart 		/* Refill the random store */
1040851b7298SRandall Stewart 		sctp_fill_random_store(inp);
1041851b7298SRandall Stewart 	}
1042851b7298SRandall Stewart 	p = &inp->random_store[store_at];
1043139bc87fSRandall Stewart 	xp = (uint32_t *)p;
1044f8829a4aSRandall Stewart 	x = *xp;
1045f8829a4aSRandall Stewart 	return (x);
1046f8829a4aSRandall Stewart }
1047f8829a4aSRandall Stewart 
1048f8829a4aSRandall Stewart uint32_t
1049b0471b4bSMichael Tuexen sctp_select_a_tag(struct sctp_inpcb *inp, uint16_t lport, uint16_t rport, int check)
1050b0471b4bSMichael Tuexen {
10517215cc1bSMichael Tuexen 	uint32_t x;
1052f8829a4aSRandall Stewart 	struct timeval now;
1053f8829a4aSRandall Stewart 
10547215cc1bSMichael Tuexen 	if (check) {
10556e55db54SRandall Stewart 		(void)SCTP_GETTIME_TIMEVAL(&now);
10567215cc1bSMichael Tuexen 	}
10577215cc1bSMichael Tuexen 	for (;;) {
1058851b7298SRandall Stewart 		x = sctp_select_initial_TSN(&inp->sctp_ep);
1059f8829a4aSRandall Stewart 		if (x == 0) {
1060f8829a4aSRandall Stewart 			/* we never use 0 */
1061f8829a4aSRandall Stewart 			continue;
1062f8829a4aSRandall Stewart 		}
10637215cc1bSMichael Tuexen 		if (!check || sctp_is_vtag_good(x, lport, rport, &now)) {
10647215cc1bSMichael Tuexen 			break;
1065f8829a4aSRandall Stewart 		}
1066f8829a4aSRandall Stewart 	}
1067f8829a4aSRandall Stewart 	return (x);
1068f8829a4aSRandall Stewart }
1069f8829a4aSRandall Stewart 
1070e92c2a8dSMichael Tuexen int32_t
1071b0471b4bSMichael Tuexen sctp_map_assoc_state(int kernel_state)
1072b0471b4bSMichael Tuexen {
1073e92c2a8dSMichael Tuexen 	int32_t user_state;
1074e92c2a8dSMichael Tuexen 
1075e92c2a8dSMichael Tuexen 	if (kernel_state & SCTP_STATE_WAS_ABORTED) {
1076e92c2a8dSMichael Tuexen 		user_state = SCTP_CLOSED;
1077e92c2a8dSMichael Tuexen 	} else if (kernel_state & SCTP_STATE_SHUTDOWN_PENDING) {
1078e92c2a8dSMichael Tuexen 		user_state = SCTP_SHUTDOWN_PENDING;
1079e92c2a8dSMichael Tuexen 	} else {
1080e92c2a8dSMichael Tuexen 		switch (kernel_state & SCTP_STATE_MASK) {
1081e92c2a8dSMichael Tuexen 		case SCTP_STATE_EMPTY:
1082e92c2a8dSMichael Tuexen 			user_state = SCTP_CLOSED;
1083e92c2a8dSMichael Tuexen 			break;
1084e92c2a8dSMichael Tuexen 		case SCTP_STATE_INUSE:
1085e92c2a8dSMichael Tuexen 			user_state = SCTP_CLOSED;
1086e92c2a8dSMichael Tuexen 			break;
1087e92c2a8dSMichael Tuexen 		case SCTP_STATE_COOKIE_WAIT:
1088e92c2a8dSMichael Tuexen 			user_state = SCTP_COOKIE_WAIT;
1089e92c2a8dSMichael Tuexen 			break;
1090e92c2a8dSMichael Tuexen 		case SCTP_STATE_COOKIE_ECHOED:
1091e92c2a8dSMichael Tuexen 			user_state = SCTP_COOKIE_ECHOED;
1092e92c2a8dSMichael Tuexen 			break;
1093e92c2a8dSMichael Tuexen 		case SCTP_STATE_OPEN:
1094e92c2a8dSMichael Tuexen 			user_state = SCTP_ESTABLISHED;
1095e92c2a8dSMichael Tuexen 			break;
1096e92c2a8dSMichael Tuexen 		case SCTP_STATE_SHUTDOWN_SENT:
1097e92c2a8dSMichael Tuexen 			user_state = SCTP_SHUTDOWN_SENT;
1098e92c2a8dSMichael Tuexen 			break;
1099e92c2a8dSMichael Tuexen 		case SCTP_STATE_SHUTDOWN_RECEIVED:
1100e92c2a8dSMichael Tuexen 			user_state = SCTP_SHUTDOWN_RECEIVED;
1101e92c2a8dSMichael Tuexen 			break;
1102e92c2a8dSMichael Tuexen 		case SCTP_STATE_SHUTDOWN_ACK_SENT:
1103e92c2a8dSMichael Tuexen 			user_state = SCTP_SHUTDOWN_ACK_SENT;
1104e92c2a8dSMichael Tuexen 			break;
1105e92c2a8dSMichael Tuexen 		default:
1106e92c2a8dSMichael Tuexen 			user_state = SCTP_CLOSED;
1107e92c2a8dSMichael Tuexen 			break;
1108e92c2a8dSMichael Tuexen 		}
1109e92c2a8dSMichael Tuexen 	}
1110e92c2a8dSMichael Tuexen 	return (user_state);
1111e92c2a8dSMichael Tuexen }
1112e92c2a8dSMichael Tuexen 
1113f8829a4aSRandall Stewart int
1114a1cb341bSMichael Tuexen sctp_init_asoc(struct sctp_inpcb *inp, struct sctp_tcb *stcb,
1115c7f048abSMichael Tuexen     uint32_t override_tag, uint32_t initial_tsn, uint32_t vrf_id,
1116c7f048abSMichael Tuexen     uint16_t o_strms)
1117f8829a4aSRandall Stewart {
11180696e120SRandall Stewart 	struct sctp_association *asoc;
11190696e120SRandall Stewart 
1120f8829a4aSRandall Stewart 	/*
1121f8829a4aSRandall Stewart 	 * Anything set to zero is taken care of by the allocation routine's
1122f8829a4aSRandall Stewart 	 * bzero
1123f8829a4aSRandall Stewart 	 */
1124f8829a4aSRandall Stewart 
1125f8829a4aSRandall Stewart 	/*
1126f8829a4aSRandall Stewart 	 * Up front select what scoping to apply on addresses I tell my peer
1127f8829a4aSRandall Stewart 	 * Not sure what to do with these right now, we will need to come up
1128f8829a4aSRandall Stewart 	 * with a way to set them. We may need to pass them through from the
1129f8829a4aSRandall Stewart 	 * caller in the sctp_aloc_assoc() function.
1130f8829a4aSRandall Stewart 	 */
1131f8829a4aSRandall Stewart 	int i;
1132f0396ad1SMichael Tuexen #if defined(SCTP_DETAILED_STR_STATS)
1133f0396ad1SMichael Tuexen 	int j;
1134f0396ad1SMichael Tuexen #endif
1135f0396ad1SMichael Tuexen 
11360696e120SRandall Stewart 	asoc = &stcb->asoc;
1137f8829a4aSRandall Stewart 	/* init all variables to a known value. */
1138839d21d6SMichael Tuexen 	SCTP_SET_STATE(stcb, SCTP_STATE_INUSE);
1139a1cb341bSMichael Tuexen 	asoc->max_burst = inp->sctp_ep.max_burst;
1140a1cb341bSMichael Tuexen 	asoc->fr_max_burst = inp->sctp_ep.fr_max_burst;
114125ec3553SMichael Tuexen 	asoc->heart_beat_delay = sctp_ticks_to_msecs(inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_HEARTBEAT]);
1142a1cb341bSMichael Tuexen 	asoc->cookie_life = inp->sctp_ep.def_cookie_life;
1143a1cb341bSMichael Tuexen 	asoc->sctp_cmt_on_off = inp->sctp_cmt_on_off;
1144f342355aSMichael Tuexen 	asoc->ecn_supported = inp->ecn_supported;
1145dd973b0eSMichael Tuexen 	asoc->prsctp_supported = inp->prsctp_supported;
1146c79bec9cSMichael Tuexen 	asoc->auth_supported = inp->auth_supported;
1147c79bec9cSMichael Tuexen 	asoc->asconf_supported = inp->asconf_supported;
1148317e00efSMichael Tuexen 	asoc->reconfig_supported = inp->reconfig_supported;
1149caea9879SMichael Tuexen 	asoc->nrsack_supported = inp->nrsack_supported;
1150cb9b8e6fSMichael Tuexen 	asoc->pktdrop_supported = inp->pktdrop_supported;
115144249214SRandall Stewart 	asoc->idata_supported = inp->idata_supported;
1152ca85e948SMichael Tuexen 	asoc->sctp_cmt_pf = (uint8_t)0;
1153a1cb341bSMichael Tuexen 	asoc->sctp_frag_point = inp->sctp_frag_point;
1154a1cb341bSMichael Tuexen 	asoc->sctp_features = inp->sctp_features;
1155a1cb341bSMichael Tuexen 	asoc->default_dscp = inp->sctp_ep.default_dscp;
115659b6d5beSMichael Tuexen 	asoc->max_cwnd = inp->max_cwnd;
115742551e99SRandall Stewart #ifdef INET6
1158a1cb341bSMichael Tuexen 	if (inp->sctp_ep.default_flowlabel) {
1159a1cb341bSMichael Tuexen 		asoc->default_flowlabel = inp->sctp_ep.default_flowlabel;
116058bdb691SMichael Tuexen 	} else {
1161a1cb341bSMichael Tuexen 		if (inp->ip_inp.inp.inp_flags & IN6P_AUTOFLOWLABEL) {
1162a1cb341bSMichael Tuexen 			asoc->default_flowlabel = sctp_select_initial_TSN(&inp->sctp_ep);
116358bdb691SMichael Tuexen 			asoc->default_flowlabel &= 0x000fffff;
116458bdb691SMichael Tuexen 			asoc->default_flowlabel |= 0x80000000;
116558bdb691SMichael Tuexen 		} else {
1166f8829a4aSRandall Stewart 			asoc->default_flowlabel = 0;
116758bdb691SMichael Tuexen 		}
116858bdb691SMichael Tuexen 	}
1169f8829a4aSRandall Stewart #endif
11709f22f500SRandall Stewart 	asoc->sb_send_resv = 0;
1171f8829a4aSRandall Stewart 	if (override_tag) {
1172f8829a4aSRandall Stewart 		asoc->my_vtag = override_tag;
1173f8829a4aSRandall Stewart 	} else {
1174a1cb341bSMichael Tuexen 		asoc->my_vtag = sctp_select_a_tag(inp, stcb->sctp_ep->sctp_lport, stcb->rport, 1);
1175f8829a4aSRandall Stewart 	}
1176de0e935bSRandall Stewart 	/* Get the nonce tags */
1177a1cb341bSMichael Tuexen 	asoc->my_vtag_nonce = sctp_select_a_tag(inp, stcb->sctp_ep->sctp_lport, stcb->rport, 0);
1178a1cb341bSMichael Tuexen 	asoc->peer_vtag_nonce = sctp_select_a_tag(inp, stcb->sctp_ep->sctp_lport, stcb->rport, 0);
117942551e99SRandall Stewart 	asoc->vrf_id = vrf_id;
1180de0e935bSRandall Stewart 
118118e198d3SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
118218e198d3SRandall Stewart 	asoc->tsn_in_at = 0;
118318e198d3SRandall Stewart 	asoc->tsn_out_at = 0;
118418e198d3SRandall Stewart 	asoc->tsn_in_wrapped = 0;
118518e198d3SRandall Stewart 	asoc->tsn_out_wrapped = 0;
118618e198d3SRandall Stewart 	asoc->cumack_log_at = 0;
1187b201f536SRandall Stewart 	asoc->cumack_log_atsnt = 0;
118818e198d3SRandall Stewart #endif
118918e198d3SRandall Stewart #ifdef SCTP_FS_SPEC_LOG
119018e198d3SRandall Stewart 	asoc->fs_index = 0;
119118e198d3SRandall Stewart #endif
1192f8829a4aSRandall Stewart 	asoc->refcnt = 0;
1193f8829a4aSRandall Stewart 	asoc->assoc_up_sent = 0;
1194c7f048abSMichael Tuexen 	if (override_tag) {
1195c7f048abSMichael Tuexen 		asoc->init_seq_number = initial_tsn;
1196c7f048abSMichael Tuexen 	} else {
1197c7f048abSMichael Tuexen 		asoc->init_seq_number = sctp_select_initial_TSN(&inp->sctp_ep);
1198c7f048abSMichael Tuexen 	}
1199c7f048abSMichael Tuexen 	asoc->asconf_seq_out = asoc->init_seq_number;
1200c7f048abSMichael Tuexen 	asoc->str_reset_seq_out = asoc->init_seq_number;
1201c7f048abSMichael Tuexen 	asoc->sending_seq = asoc->init_seq_number;
1202c7f048abSMichael Tuexen 	asoc->asconf_seq_out_acked = asoc->init_seq_number - 1;
1203f8829a4aSRandall Stewart 	/* we are optimisitic here */
1204830d754dSRandall Stewart 	asoc->peer_supports_nat = 0;
1205f8829a4aSRandall Stewart 	asoc->sent_queue_retran_cnt = 0;
1206f8829a4aSRandall Stewart 
1207f8829a4aSRandall Stewart 	/* for CMT */
12088933fa13SRandall Stewart 	asoc->last_net_cmt_send_started = NULL;
1209f8829a4aSRandall Stewart 
1210f8829a4aSRandall Stewart 	asoc->last_acked_seq = asoc->init_seq_number - 1;
1211c7f048abSMichael Tuexen 	asoc->advanced_peer_ack_point = asoc->init_seq_number - 1;
1212c7f048abSMichael Tuexen 	asoc->asconf_seq_in = asoc->init_seq_number - 1;
1213f8829a4aSRandall Stewart 
1214f8829a4aSRandall Stewart 	/* here we are different, we hold the next one we expect */
1215c7f048abSMichael Tuexen 	asoc->str_reset_seq_in = asoc->init_seq_number;
1216f8829a4aSRandall Stewart 
1217a1cb341bSMichael Tuexen 	asoc->initial_init_rto_max = inp->sctp_ep.initial_init_rto_max;
1218a1cb341bSMichael Tuexen 	asoc->initial_rto = inp->sctp_ep.initial_rto;
1219f8829a4aSRandall Stewart 
122028a6addeSMichael Tuexen 	asoc->default_mtu = inp->sctp_ep.default_mtu;
1221a1cb341bSMichael Tuexen 	asoc->max_init_times = inp->sctp_ep.max_init_times;
1222a1cb341bSMichael Tuexen 	asoc->max_send_times = inp->sctp_ep.max_send_times;
1223a1cb341bSMichael Tuexen 	asoc->def_net_failure = inp->sctp_ep.def_net_failure;
1224a1cb341bSMichael Tuexen 	asoc->def_net_pf_threshold = inp->sctp_ep.def_net_pf_threshold;
1225f8829a4aSRandall Stewart 	asoc->free_chunk_cnt = 0;
1226f8829a4aSRandall Stewart 
1227f8829a4aSRandall Stewart 	asoc->iam_blocking = 0;
1228a1cb341bSMichael Tuexen 	asoc->context = inp->sctp_context;
1229a1cb341bSMichael Tuexen 	asoc->local_strreset_support = inp->local_strreset_support;
1230a1cb341bSMichael Tuexen 	asoc->def_send = inp->def_send;
123125ec3553SMichael Tuexen 	asoc->delayed_ack = sctp_ticks_to_msecs(inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_RECV]);
1232a1cb341bSMichael Tuexen 	asoc->sack_freq = inp->sctp_ep.sctp_sack_freq;
1233f8829a4aSRandall Stewart 	asoc->pr_sctp_cnt = 0;
1234f8829a4aSRandall Stewart 	asoc->total_output_queue_size = 0;
1235f8829a4aSRandall Stewart 
1236a1cb341bSMichael Tuexen 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) {
1237a1cb341bSMichael Tuexen 		asoc->scope.ipv6_addr_legal = 1;
1238a1cb341bSMichael Tuexen 		if (SCTP_IPV6_V6ONLY(inp) == 0) {
1239a1cb341bSMichael Tuexen 			asoc->scope.ipv4_addr_legal = 1;
1240f8829a4aSRandall Stewart 		} else {
1241a1cb341bSMichael Tuexen 			asoc->scope.ipv4_addr_legal = 0;
1242f8829a4aSRandall Stewart 		}
1243f8829a4aSRandall Stewart 	} else {
1244a1cb341bSMichael Tuexen 		asoc->scope.ipv6_addr_legal = 0;
1245a1cb341bSMichael Tuexen 		asoc->scope.ipv4_addr_legal = 1;
1246f8829a4aSRandall Stewart 	}
1247f8829a4aSRandall Stewart 
1248a1cb341bSMichael Tuexen 	asoc->my_rwnd = max(SCTP_SB_LIMIT_RCV(inp->sctp_socket), SCTP_MINIMAL_RWND);
1249a1cb341bSMichael Tuexen 	asoc->peers_rwnd = SCTP_SB_LIMIT_RCV(inp->sctp_socket);
1250f8829a4aSRandall Stewart 
1251a1cb341bSMichael Tuexen 	asoc->smallest_mtu = inp->sctp_frag_point;
1252a1cb341bSMichael Tuexen 	asoc->minrto = inp->sctp_ep.sctp_minrto;
1253a1cb341bSMichael Tuexen 	asoc->maxrto = inp->sctp_ep.sctp_maxrto;
1254f8829a4aSRandall Stewart 
1255f8829a4aSRandall Stewart 	asoc->stream_locked_on = 0;
1256f8829a4aSRandall Stewart 	asoc->ecn_echo_cnt_onq = 0;
1257f8829a4aSRandall Stewart 	asoc->stream_locked = 0;
1258f8829a4aSRandall Stewart 
125942551e99SRandall Stewart 	asoc->send_sack = 1;
126042551e99SRandall Stewart 
126142551e99SRandall Stewart 	LIST_INIT(&asoc->sctp_restricted_addrs);
126242551e99SRandall Stewart 
1263f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->nets);
1264f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->pending_reply_queue);
12652afb3e84SRandall Stewart 	TAILQ_INIT(&asoc->asconf_ack_sent);
1266f8829a4aSRandall Stewart 	/* Setup to fill the hb random cache at first HB */
1267f8829a4aSRandall Stewart 	asoc->hb_random_idx = 4;
1268f8829a4aSRandall Stewart 
1269a1cb341bSMichael Tuexen 	asoc->sctp_autoclose_ticks = inp->sctp_ep.auto_close_time;
1270f8829a4aSRandall Stewart 
1271a1cb341bSMichael Tuexen 	stcb->asoc.congestion_control_module = inp->sctp_ep.sctp_default_cc_module;
1272a1cb341bSMichael Tuexen 	stcb->asoc.cc_functions = sctp_cc_functions[inp->sctp_ep.sctp_default_cc_module];
1273b54d3a6cSRandall Stewart 
1274a1cb341bSMichael Tuexen 	stcb->asoc.stream_scheduling_module = inp->sctp_ep.sctp_default_ss_module;
1275a1cb341bSMichael Tuexen 	stcb->asoc.ss_functions = sctp_ss_functions[inp->sctp_ep.sctp_default_ss_module];
1276f7a77f6fSMichael Tuexen 
1277b54d3a6cSRandall Stewart 	/*
1278f8829a4aSRandall Stewart 	 * Now the stream parameters, here we allocate space for all streams
1279f8829a4aSRandall Stewart 	 * that we request by default.
1280f8829a4aSRandall Stewart 	 */
1281ea44232bSRandall Stewart 	asoc->strm_realoutsize = asoc->streamoutcnt = asoc->pre_open_streams =
1282c979034bSMichael Tuexen 	    o_strms;
1283f8829a4aSRandall Stewart 	SCTP_MALLOC(asoc->strmout, struct sctp_stream_out *,
1284f8829a4aSRandall Stewart 	    asoc->streamoutcnt * sizeof(struct sctp_stream_out),
1285207304d4SRandall Stewart 	    SCTP_M_STRMO);
1286f8829a4aSRandall Stewart 	if (asoc->strmout == NULL) {
1287f8829a4aSRandall Stewart 		/* big trouble no memory */
1288c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
1289f8829a4aSRandall Stewart 		return (ENOMEM);
1290f8829a4aSRandall Stewart 	}
12910b79a76fSMichael Tuexen 	SCTP_TCB_SEND_LOCK(stcb);
1292f8829a4aSRandall Stewart 	for (i = 0; i < asoc->streamoutcnt; i++) {
1293f8829a4aSRandall Stewart 		/*
1294f8829a4aSRandall Stewart 		 * inbound side must be set to 0xffff, also NOTE when we get
1295f8829a4aSRandall Stewart 		 * the INIT-ACK back (for INIT sender) we MUST reduce the
1296f8829a4aSRandall Stewart 		 * count (streamoutcnt) but first check if we sent to any of
1297f8829a4aSRandall Stewart 		 * the upper streams that were dropped (if some were). Those
1298f8829a4aSRandall Stewart 		 * that were dropped must be notified to the upper layer as
1299f8829a4aSRandall Stewart 		 * failed to send.
1300f8829a4aSRandall Stewart 		 */
1301f8829a4aSRandall Stewart 		TAILQ_INIT(&asoc->strmout[i].outqueue);
13027a051c0aSMichael Tuexen 		asoc->ss_functions.sctp_ss_init_stream(stcb, &asoc->strmout[i], NULL);
1303325c8c46SMichael Tuexen 		asoc->strmout[i].chunks_on_queues = 0;
1304f0396ad1SMichael Tuexen #if defined(SCTP_DETAILED_STR_STATS)
1305f0396ad1SMichael Tuexen 		for (j = 0; j < SCTP_PR_SCTP_MAX + 1; j++) {
1306f0396ad1SMichael Tuexen 			asoc->strmout[i].abandoned_sent[j] = 0;
1307f0396ad1SMichael Tuexen 			asoc->strmout[i].abandoned_unsent[j] = 0;
1308f0396ad1SMichael Tuexen 		}
1309f0396ad1SMichael Tuexen #else
1310f0396ad1SMichael Tuexen 		asoc->strmout[i].abandoned_sent[0] = 0;
1311f0396ad1SMichael Tuexen 		asoc->strmout[i].abandoned_unsent[0] = 0;
1312f0396ad1SMichael Tuexen #endif
13137a051c0aSMichael Tuexen 		asoc->strmout[i].next_mid_ordered = 0;
13147a051c0aSMichael Tuexen 		asoc->strmout[i].next_mid_unordered = 0;
131549656eefSMichael Tuexen 		asoc->strmout[i].sid = i;
1316f8829a4aSRandall Stewart 		asoc->strmout[i].last_msg_incomplete = 0;
13177cca1775SRandall Stewart 		asoc->strmout[i].state = SCTP_STREAM_OPENING;
1318f8829a4aSRandall Stewart 	}
1319762ae0ecSMichael Tuexen 	asoc->ss_functions.sctp_ss_init(stcb, asoc);
13200b79a76fSMichael Tuexen 	SCTP_TCB_SEND_UNLOCK(stcb);
1321f7a77f6fSMichael Tuexen 
1322f8829a4aSRandall Stewart 	/* Now the mapping array */
1323f8829a4aSRandall Stewart 	asoc->mapping_array_size = SCTP_INITIAL_MAPPING_ARRAY;
1324f8829a4aSRandall Stewart 	SCTP_MALLOC(asoc->mapping_array, uint8_t *, asoc->mapping_array_size,
1325207304d4SRandall Stewart 	    SCTP_M_MAP);
1326f8829a4aSRandall Stewart 	if (asoc->mapping_array == NULL) {
1327207304d4SRandall Stewart 		SCTP_FREE(asoc->strmout, SCTP_M_STRMO);
1328c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
1329f8829a4aSRandall Stewart 		return (ENOMEM);
1330f8829a4aSRandall Stewart 	}
1331f8829a4aSRandall Stewart 	memset(asoc->mapping_array, 0, asoc->mapping_array_size);
1332b5c16493SMichael Tuexen 	SCTP_MALLOC(asoc->nr_mapping_array, uint8_t *, asoc->mapping_array_size,
1333830d754dSRandall Stewart 	    SCTP_M_MAP);
1334bf1be571SRandall Stewart 	if (asoc->nr_mapping_array == NULL) {
1335bf1be571SRandall Stewart 		SCTP_FREE(asoc->strmout, SCTP_M_STRMO);
1336bf1be571SRandall Stewart 		SCTP_FREE(asoc->mapping_array, SCTP_M_MAP);
1337bf1be571SRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
1338bf1be571SRandall Stewart 		return (ENOMEM);
1339bf1be571SRandall Stewart 	}
1340b5c16493SMichael Tuexen 	memset(asoc->nr_mapping_array, 0, asoc->mapping_array_size);
1341830d754dSRandall Stewart 
1342f8829a4aSRandall Stewart 	/* Now the init of the other outqueues */
1343f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->free_chunks);
1344f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->control_send_queue);
1345c54a18d2SRandall Stewart 	TAILQ_INIT(&asoc->asconf_send_queue);
1346f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->send_queue);
1347f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->sent_queue);
1348f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->resetHead);
1349a1cb341bSMichael Tuexen 	asoc->max_inbound_streams = inp->sctp_ep.max_open_streams_intome;
1350f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->asconf_queue);
1351f8829a4aSRandall Stewart 	/* authentication fields */
1352f8829a4aSRandall Stewart 	asoc->authinfo.random = NULL;
1353830d754dSRandall Stewart 	asoc->authinfo.active_keyid = 0;
1354f8829a4aSRandall Stewart 	asoc->authinfo.assoc_key = NULL;
1355f8829a4aSRandall Stewart 	asoc->authinfo.assoc_keyid = 0;
1356f8829a4aSRandall Stewart 	asoc->authinfo.recv_key = NULL;
1357f8829a4aSRandall Stewart 	asoc->authinfo.recv_keyid = 0;
1358f8829a4aSRandall Stewart 	LIST_INIT(&asoc->shared_keys);
1359f42a358aSRandall Stewart 	asoc->marked_retrans = 0;
1360a1cb341bSMichael Tuexen 	asoc->port = inp->sctp_ep.port;
1361f42a358aSRandall Stewart 	asoc->timoinit = 0;
1362f42a358aSRandall Stewart 	asoc->timodata = 0;
1363f42a358aSRandall Stewart 	asoc->timosack = 0;
1364f42a358aSRandall Stewart 	asoc->timoshutdown = 0;
1365f42a358aSRandall Stewart 	asoc->timoheartbeat = 0;
1366f42a358aSRandall Stewart 	asoc->timocookie = 0;
1367f42a358aSRandall Stewart 	asoc->timoshutdownack = 0;
13686e55db54SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&asoc->start_time);
13696e55db54SRandall Stewart 	asoc->discontinuity_time = asoc->start_time;
1370f0396ad1SMichael Tuexen 	for (i = 0; i < SCTP_PR_SCTP_MAX + 1; i++) {
1371f0396ad1SMichael Tuexen 		asoc->abandoned_unsent[i] = 0;
1372f0396ad1SMichael Tuexen 		asoc->abandoned_sent[i] = 0;
1373f0396ad1SMichael Tuexen 	}
1374eacc51c5SRandall Stewart 	/*
1375eacc51c5SRandall Stewart 	 * sa_ignore MEMLEAK {memory is put in the assoc mapping array and
137677acdc25SRandall Stewart 	 * freed later when the association is freed.
1377eacc51c5SRandall Stewart 	 */
1378f8829a4aSRandall Stewart 	return (0);
1379f8829a4aSRandall Stewart }
1380f8829a4aSRandall Stewart 
13810e13104dSRandall Stewart void
13820e13104dSRandall Stewart sctp_print_mapping_array(struct sctp_association *asoc)
13830e13104dSRandall Stewart {
1384aed5947cSMichael Tuexen 	unsigned int i, limit;
13850e13104dSRandall Stewart 
1386cd3fd531SMichael Tuexen 	SCTP_PRINTF("Mapping array size: %d, baseTSN: %8.8x, cumAck: %8.8x, highestTSN: (%8.8x, %8.8x).\n",
13870e13104dSRandall Stewart 	    asoc->mapping_array_size,
13880e13104dSRandall Stewart 	    asoc->mapping_array_base_tsn,
13890e13104dSRandall Stewart 	    asoc->cumulative_tsn,
1390aed5947cSMichael Tuexen 	    asoc->highest_tsn_inside_map,
1391aed5947cSMichael Tuexen 	    asoc->highest_tsn_inside_nr_map);
1392aed5947cSMichael Tuexen 	for (limit = asoc->mapping_array_size; limit > 1; limit--) {
139360990c0cSMichael Tuexen 		if (asoc->mapping_array[limit - 1] != 0) {
139477acdc25SRandall Stewart 			break;
139577acdc25SRandall Stewart 		}
139677acdc25SRandall Stewart 	}
1397cd3fd531SMichael Tuexen 	SCTP_PRINTF("Renegable mapping array (last %d entries are zero):\n", asoc->mapping_array_size - limit);
139877acdc25SRandall Stewart 	for (i = 0; i < limit; i++) {
1399cd3fd531SMichael Tuexen 		SCTP_PRINTF("%2.2x%c", asoc->mapping_array[i], ((i + 1) % 16) ? ' ' : '\n');
140077acdc25SRandall Stewart 	}
1401aed5947cSMichael Tuexen 	if (limit % 16)
1402cd3fd531SMichael Tuexen 		SCTP_PRINTF("\n");
1403aed5947cSMichael Tuexen 	for (limit = asoc->mapping_array_size; limit > 1; limit--) {
1404aed5947cSMichael Tuexen 		if (asoc->nr_mapping_array[limit - 1]) {
140577acdc25SRandall Stewart 			break;
140677acdc25SRandall Stewart 		}
140777acdc25SRandall Stewart 	}
1408cd3fd531SMichael Tuexen 	SCTP_PRINTF("Non renegable mapping array (last %d entries are zero):\n", asoc->mapping_array_size - limit);
140977acdc25SRandall Stewart 	for (i = 0; i < limit; i++) {
1410cd3fd531SMichael Tuexen 		SCTP_PRINTF("%2.2x%c", asoc->nr_mapping_array[i], ((i + 1) % 16) ? ' ' : '\n');
14110e13104dSRandall Stewart 	}
1412aed5947cSMichael Tuexen 	if (limit % 16)
1413cd3fd531SMichael Tuexen 		SCTP_PRINTF("\n");
14140e13104dSRandall Stewart }
14150e13104dSRandall Stewart 
1416f8829a4aSRandall Stewart int
14170696e120SRandall Stewart sctp_expand_mapping_array(struct sctp_association *asoc, uint32_t needed)
1418f8829a4aSRandall Stewart {
1419f8829a4aSRandall Stewart 	/* mapping array needs to grow */
1420b5c16493SMichael Tuexen 	uint8_t *new_array1, *new_array2;
14210696e120SRandall Stewart 	uint32_t new_size;
1422f8829a4aSRandall Stewart 
14230696e120SRandall Stewart 	new_size = asoc->mapping_array_size + ((needed + 7) / 8 + SCTP_MAPPING_ARRAY_INCR);
1424b5c16493SMichael Tuexen 	SCTP_MALLOC(new_array1, uint8_t *, new_size, SCTP_M_MAP);
1425b5c16493SMichael Tuexen 	SCTP_MALLOC(new_array2, uint8_t *, new_size, SCTP_M_MAP);
1426b5c16493SMichael Tuexen 	if ((new_array1 == NULL) || (new_array2 == NULL)) {
1427f8829a4aSRandall Stewart 		/* can't get more, forget it */
1428b5c16493SMichael Tuexen 		SCTP_PRINTF("No memory for expansion of SCTP mapping array %d\n", new_size);
1429b5c16493SMichael Tuexen 		if (new_array1) {
1430b5c16493SMichael Tuexen 			SCTP_FREE(new_array1, SCTP_M_MAP);
1431b5c16493SMichael Tuexen 		}
1432b5c16493SMichael Tuexen 		if (new_array2) {
1433b5c16493SMichael Tuexen 			SCTP_FREE(new_array2, SCTP_M_MAP);
1434b5c16493SMichael Tuexen 		}
1435f8829a4aSRandall Stewart 		return (-1);
1436f8829a4aSRandall Stewart 	}
1437b5c16493SMichael Tuexen 	memset(new_array1, 0, new_size);
1438b5c16493SMichael Tuexen 	memset(new_array2, 0, new_size);
1439b5c16493SMichael Tuexen 	memcpy(new_array1, asoc->mapping_array, asoc->mapping_array_size);
1440b5c16493SMichael Tuexen 	memcpy(new_array2, asoc->nr_mapping_array, asoc->mapping_array_size);
1441207304d4SRandall Stewart 	SCTP_FREE(asoc->mapping_array, SCTP_M_MAP);
1442830d754dSRandall Stewart 	SCTP_FREE(asoc->nr_mapping_array, SCTP_M_MAP);
1443b5c16493SMichael Tuexen 	asoc->mapping_array = new_array1;
1444b5c16493SMichael Tuexen 	asoc->nr_mapping_array = new_array2;
1445b5c16493SMichael Tuexen 	asoc->mapping_array_size = new_size;
1446830d754dSRandall Stewart 	return (0);
1447830d754dSRandall Stewart }
1448830d754dSRandall Stewart 
144942551e99SRandall Stewart static void
145042551e99SRandall Stewart sctp_iterator_work(struct sctp_iterator *it)
145142551e99SRandall Stewart {
1452868b51f2SMichael Tuexen 	struct epoch_tracker et;
1453868b51f2SMichael Tuexen 	struct sctp_inpcb *tinp;
145442551e99SRandall Stewart 	int iteration_count = 0;
145542551e99SRandall Stewart 	int inp_skip = 0;
1456ec4c19fcSRandall Stewart 	int first_in = 1;
145742551e99SRandall Stewart 
1458868b51f2SMichael Tuexen 	NET_EPOCH_ENTER(et);
1459ec4c19fcSRandall Stewart 	SCTP_INP_INFO_RLOCK();
146042551e99SRandall Stewart 	SCTP_ITERATOR_LOCK();
1461dcb436c9SMichael Tuexen 	sctp_it_ctl.cur_it = it;
1462ad81507eSRandall Stewart 	if (it->inp) {
1463ec4c19fcSRandall Stewart 		SCTP_INP_RLOCK(it->inp);
146442551e99SRandall Stewart 		SCTP_INP_DECR_REF(it->inp);
1465ad81507eSRandall Stewart 	}
146642551e99SRandall Stewart 	if (it->inp == NULL) {
146742551e99SRandall Stewart 		/* iterator is complete */
146842551e99SRandall Stewart done_with_iterator:
1469dcb436c9SMichael Tuexen 		sctp_it_ctl.cur_it = NULL;
147042551e99SRandall Stewart 		SCTP_ITERATOR_UNLOCK();
1471ec4c19fcSRandall Stewart 		SCTP_INP_INFO_RUNLOCK();
147242551e99SRandall Stewart 		if (it->function_atend != NULL) {
147342551e99SRandall Stewart 			(*it->function_atend) (it->pointer, it->val);
147442551e99SRandall Stewart 		}
1475207304d4SRandall Stewart 		SCTP_FREE(it, SCTP_M_ITER);
1476868b51f2SMichael Tuexen 		NET_EPOCH_EXIT(et);
147742551e99SRandall Stewart 		return;
147842551e99SRandall Stewart 	}
147942551e99SRandall Stewart select_a_new_ep:
1480ec4c19fcSRandall Stewart 	if (first_in) {
1481ec4c19fcSRandall Stewart 		first_in = 0;
1482ec4c19fcSRandall Stewart 	} else {
1483f7517433SRandall Stewart 		SCTP_INP_RLOCK(it->inp);
1484ec4c19fcSRandall Stewart 	}
148542551e99SRandall Stewart 	while (((it->pcb_flags) &&
148642551e99SRandall Stewart 	    ((it->inp->sctp_flags & it->pcb_flags) != it->pcb_flags)) ||
148742551e99SRandall Stewart 	    ((it->pcb_features) &&
148842551e99SRandall Stewart 	    ((it->inp->sctp_features & it->pcb_features) != it->pcb_features))) {
148942551e99SRandall Stewart 		/* endpoint flags or features don't match, so keep looking */
149042551e99SRandall Stewart 		if (it->iterator_flags & SCTP_ITERATOR_DO_SINGLE_INP) {
1491f7517433SRandall Stewart 			SCTP_INP_RUNLOCK(it->inp);
149242551e99SRandall Stewart 			goto done_with_iterator;
149342551e99SRandall Stewart 		}
1494ec4c19fcSRandall Stewart 		tinp = it->inp;
149542551e99SRandall Stewart 		it->inp = LIST_NEXT(it->inp, sctp_list);
149683ed5080SMichael Tuexen 		it->stcb = NULL;
1497ec4c19fcSRandall Stewart 		SCTP_INP_RUNLOCK(tinp);
149842551e99SRandall Stewart 		if (it->inp == NULL) {
149942551e99SRandall Stewart 			goto done_with_iterator;
150042551e99SRandall Stewart 		}
150142551e99SRandall Stewart 		SCTP_INP_RLOCK(it->inp);
1502f7517433SRandall Stewart 	}
150342551e99SRandall Stewart 	/* now go through each assoc which is in the desired state */
150442551e99SRandall Stewart 	if (it->done_current_ep == 0) {
150542551e99SRandall Stewart 		if (it->function_inp != NULL)
150642551e99SRandall Stewart 			inp_skip = (*it->function_inp) (it->inp, it->pointer, it->val);
150742551e99SRandall Stewart 		it->done_current_ep = 1;
150842551e99SRandall Stewart 	}
150942551e99SRandall Stewart 	if (it->stcb == NULL) {
151042551e99SRandall Stewart 		/* run the per instance function */
151142551e99SRandall Stewart 		it->stcb = LIST_FIRST(&it->inp->sctp_asoc_list);
151242551e99SRandall Stewart 	}
151342551e99SRandall Stewart 	if ((inp_skip) || it->stcb == NULL) {
151442551e99SRandall Stewart 		if (it->function_inp_end != NULL) {
151542551e99SRandall Stewart 			inp_skip = (*it->function_inp_end) (it->inp,
151642551e99SRandall Stewart 			    it->pointer,
151742551e99SRandall Stewart 			    it->val);
151842551e99SRandall Stewart 		}
151942551e99SRandall Stewart 		SCTP_INP_RUNLOCK(it->inp);
152042551e99SRandall Stewart 		goto no_stcb;
152142551e99SRandall Stewart 	}
152209063626SMichael Tuexen 	while (it->stcb != NULL) {
152342551e99SRandall Stewart 		SCTP_TCB_LOCK(it->stcb);
152442551e99SRandall Stewart 		if (it->asoc_state && ((it->stcb->asoc.state & it->asoc_state) != it->asoc_state)) {
152542551e99SRandall Stewart 			/* not in the right state... keep looking */
152642551e99SRandall Stewart 			SCTP_TCB_UNLOCK(it->stcb);
152742551e99SRandall Stewart 			goto next_assoc;
152842551e99SRandall Stewart 		}
152942551e99SRandall Stewart 		/* see if we have limited out the iterator loop */
153042551e99SRandall Stewart 		iteration_count++;
153142551e99SRandall Stewart 		if (iteration_count > SCTP_ITERATOR_MAX_AT_ONCE) {
153242551e99SRandall Stewart 			/* Pause to let others grab the lock */
153342551e99SRandall Stewart 			atomic_add_int(&it->stcb->asoc.refcnt, 1);
153442551e99SRandall Stewart 			SCTP_TCB_UNLOCK(it->stcb);
1535c4739e2fSRandall Stewart 			SCTP_INP_INCR_REF(it->inp);
153642551e99SRandall Stewart 			SCTP_INP_RUNLOCK(it->inp);
153742551e99SRandall Stewart 			SCTP_ITERATOR_UNLOCK();
1538ec4c19fcSRandall Stewart 			SCTP_INP_INFO_RUNLOCK();
1539ec4c19fcSRandall Stewart 			SCTP_INP_INFO_RLOCK();
154042551e99SRandall Stewart 			SCTP_ITERATOR_LOCK();
1541f7517433SRandall Stewart 			if (sctp_it_ctl.iterator_flags) {
1542f7517433SRandall Stewart 				/* We won't be staying here */
1543f7517433SRandall Stewart 				SCTP_INP_DECR_REF(it->inp);
15443c1ba6f3SMichael Tuexen 				atomic_subtract_int(&it->stcb->asoc.refcnt, 1);
1545f7517433SRandall Stewart 				if (sctp_it_ctl.iterator_flags &
1546f7517433SRandall Stewart 				    SCTP_ITERATOR_STOP_CUR_IT) {
1547f7517433SRandall Stewart 					sctp_it_ctl.iterator_flags &= ~SCTP_ITERATOR_STOP_CUR_IT;
1548f7517433SRandall Stewart 					goto done_with_iterator;
1549f7517433SRandall Stewart 				}
1550f7517433SRandall Stewart 				if (sctp_it_ctl.iterator_flags &
1551f7517433SRandall Stewart 				    SCTP_ITERATOR_STOP_CUR_INP) {
1552f7517433SRandall Stewart 					sctp_it_ctl.iterator_flags &= ~SCTP_ITERATOR_STOP_CUR_INP;
1553f7517433SRandall Stewart 					goto no_stcb;
1554f7517433SRandall Stewart 				}
1555f7517433SRandall Stewart 				/* If we reach here huh? */
1556cd3fd531SMichael Tuexen 				SCTP_PRINTF("Unknown it ctl flag %x\n",
1557f7517433SRandall Stewart 				    sctp_it_ctl.iterator_flags);
1558f7517433SRandall Stewart 				sctp_it_ctl.iterator_flags = 0;
1559f7517433SRandall Stewart 			}
156042551e99SRandall Stewart 			SCTP_INP_RLOCK(it->inp);
1561c4739e2fSRandall Stewart 			SCTP_INP_DECR_REF(it->inp);
156242551e99SRandall Stewart 			SCTP_TCB_LOCK(it->stcb);
15633c1ba6f3SMichael Tuexen 			atomic_subtract_int(&it->stcb->asoc.refcnt, 1);
156442551e99SRandall Stewart 			iteration_count = 0;
156542551e99SRandall Stewart 		}
156683ed5080SMichael Tuexen 		KASSERT(it->inp == it->stcb->sctp_ep,
156783ed5080SMichael Tuexen 		    ("%s: stcb %p does not belong to inp %p, but inp %p",
156883ed5080SMichael Tuexen 		    __func__, it->stcb, it->inp, it->stcb->sctp_ep));
156909063626SMichael Tuexen 		SCTP_INP_RLOCK_ASSERT(it->inp);
157009063626SMichael Tuexen 		SCTP_TCB_LOCK_ASSERT(it->stcb);
15710053ed28SMichael Tuexen 
157242551e99SRandall Stewart 		/* run function on this one */
157342551e99SRandall Stewart 		(*it->function_assoc) (it->inp, it->stcb, it->pointer, it->val);
157409063626SMichael Tuexen 		SCTP_INP_RLOCK_ASSERT(it->inp);
157509063626SMichael Tuexen 		SCTP_TCB_LOCK_ASSERT(it->stcb);
157642551e99SRandall Stewart 
157742551e99SRandall Stewart 		/*
157842551e99SRandall Stewart 		 * we lie here, it really needs to have its own type but
157942551e99SRandall Stewart 		 * first I must verify that this won't effect things :-0
158042551e99SRandall Stewart 		 */
158109063626SMichael Tuexen 		if (it->no_chunk_output == 0) {
1582ceaad40aSRandall Stewart 			sctp_chunk_output(it->inp, it->stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
158309063626SMichael Tuexen 			SCTP_INP_RLOCK_ASSERT(it->inp);
158409063626SMichael Tuexen 			SCTP_TCB_LOCK_ASSERT(it->stcb);
158509063626SMichael Tuexen 		}
158642551e99SRandall Stewart 
158742551e99SRandall Stewart 		SCTP_TCB_UNLOCK(it->stcb);
158842551e99SRandall Stewart next_assoc:
158942551e99SRandall Stewart 		it->stcb = LIST_NEXT(it->stcb, sctp_tcblist);
159042551e99SRandall Stewart 		if (it->stcb == NULL) {
159142551e99SRandall Stewart 			/* Run last function */
159242551e99SRandall Stewart 			if (it->function_inp_end != NULL) {
159342551e99SRandall Stewart 				inp_skip = (*it->function_inp_end) (it->inp,
159442551e99SRandall Stewart 				    it->pointer,
159542551e99SRandall Stewart 				    it->val);
159642551e99SRandall Stewart 			}
159742551e99SRandall Stewart 		}
159842551e99SRandall Stewart 	}
159942551e99SRandall Stewart 	SCTP_INP_RUNLOCK(it->inp);
160042551e99SRandall Stewart no_stcb:
160142551e99SRandall Stewart 	/* done with all assocs on this endpoint, move on to next endpoint */
160242551e99SRandall Stewart 	it->done_current_ep = 0;
160342551e99SRandall Stewart 	if (it->iterator_flags & SCTP_ITERATOR_DO_SINGLE_INP) {
160442551e99SRandall Stewart 		it->inp = NULL;
160542551e99SRandall Stewart 	} else {
160642551e99SRandall Stewart 		it->inp = LIST_NEXT(it->inp, sctp_list);
160742551e99SRandall Stewart 	}
160883ed5080SMichael Tuexen 	it->stcb = NULL;
160942551e99SRandall Stewart 	if (it->inp == NULL) {
161042551e99SRandall Stewart 		goto done_with_iterator;
161142551e99SRandall Stewart 	}
161242551e99SRandall Stewart 	goto select_a_new_ep;
161342551e99SRandall Stewart }
161442551e99SRandall Stewart 
161542551e99SRandall Stewart void
161642551e99SRandall Stewart sctp_iterator_worker(void)
161742551e99SRandall Stewart {
1618397b1c94SMichael Tuexen 	struct sctp_iterator *it;
161942551e99SRandall Stewart 
162042551e99SRandall Stewart 	/* This function is called with the WQ lock in place */
1621f7517433SRandall Stewart 	sctp_it_ctl.iterator_running = 1;
1622397b1c94SMichael Tuexen 	while ((it = TAILQ_FIRST(&sctp_it_ctl.iteratorhead)) != NULL) {
162342551e99SRandall Stewart 		/* now lets work on this one */
1624f7517433SRandall Stewart 		TAILQ_REMOVE(&sctp_it_ctl.iteratorhead, it, sctp_nxt_itr);
162542551e99SRandall Stewart 		SCTP_IPI_ITERATOR_WQ_UNLOCK();
1626f7517433SRandall Stewart 		CURVNET_SET(it->vn);
162742551e99SRandall Stewart 		sctp_iterator_work(it);
1628f7517433SRandall Stewart 		CURVNET_RESTORE();
162942551e99SRandall Stewart 		SCTP_IPI_ITERATOR_WQ_LOCK();
16303c503c28SRandall Stewart 		/* sa_ignore FREED_MEMORY */
163142551e99SRandall Stewart 	}
1632f7517433SRandall Stewart 	sctp_it_ctl.iterator_running = 0;
163342551e99SRandall Stewart 	return;
163442551e99SRandall Stewart }
163542551e99SRandall Stewart 
1636f8829a4aSRandall Stewart static void
1637f8829a4aSRandall Stewart sctp_handle_addr_wq(void)
1638f8829a4aSRandall Stewart {
1639f8829a4aSRandall Stewart 	/* deal with the ADDR wq from the rtsock calls */
16404a9ef3f8SMichael Tuexen 	struct sctp_laddr *wi, *nwi;
164142551e99SRandall Stewart 	struct sctp_asconf_iterator *asc;
1642f8829a4aSRandall Stewart 
164342551e99SRandall Stewart 	SCTP_MALLOC(asc, struct sctp_asconf_iterator *,
1644207304d4SRandall Stewart 	    sizeof(struct sctp_asconf_iterator), SCTP_M_ASC_IT);
164542551e99SRandall Stewart 	if (asc == NULL) {
164642551e99SRandall Stewart 		/* Try later, no memory */
1647f8829a4aSRandall Stewart 		sctp_timer_start(SCTP_TIMER_TYPE_ADDR_WQ,
1648f8829a4aSRandall Stewart 		    (struct sctp_inpcb *)NULL,
1649f8829a4aSRandall Stewart 		    (struct sctp_tcb *)NULL,
1650f8829a4aSRandall Stewart 		    (struct sctp_nets *)NULL);
165142551e99SRandall Stewart 		return;
1652f8829a4aSRandall Stewart 	}
165342551e99SRandall Stewart 	LIST_INIT(&asc->list_of_work);
165442551e99SRandall Stewart 	asc->cnt = 0;
1655f7517433SRandall Stewart 
16564a9ef3f8SMichael Tuexen 	LIST_FOREACH_SAFE(wi, &SCTP_BASE_INFO(addr_wq), sctp_nxt_addr, nwi) {
165742551e99SRandall Stewart 		LIST_REMOVE(wi, sctp_nxt_addr);
165842551e99SRandall Stewart 		LIST_INSERT_HEAD(&asc->list_of_work, wi, sctp_nxt_addr);
165942551e99SRandall Stewart 		asc->cnt++;
1660f8829a4aSRandall Stewart 	}
1661f7517433SRandall Stewart 
166242551e99SRandall Stewart 	if (asc->cnt == 0) {
1663207304d4SRandall Stewart 		SCTP_FREE(asc, SCTP_M_ASC_IT);
166442551e99SRandall Stewart 	} else {
16652b1c7de4SMichael Tuexen 		int ret;
16662b1c7de4SMichael Tuexen 
16672b1c7de4SMichael Tuexen 		ret = sctp_initiate_iterator(sctp_asconf_iterator_ep,
16681b649582SRandall Stewart 		    sctp_asconf_iterator_stcb,
166942551e99SRandall Stewart 		    NULL,	/* No ep end for boundall */
167042551e99SRandall Stewart 		    SCTP_PCB_FLAGS_BOUNDALL,
167142551e99SRandall Stewart 		    SCTP_PCB_ANY_FEATURES,
16721b649582SRandall Stewart 		    SCTP_ASOC_ANY_STATE,
16731b649582SRandall Stewart 		    (void *)asc, 0,
16741b649582SRandall Stewart 		    sctp_asconf_iterator_end, NULL, 0);
16752b1c7de4SMichael Tuexen 		if (ret) {
16762b1c7de4SMichael Tuexen 			SCTP_PRINTF("Failed to initiate iterator for handle_addr_wq\n");
1677b7b84c0eSMichael Tuexen 			/*
1678b7b84c0eSMichael Tuexen 			 * Freeing if we are stopping or put back on the
1679b7b84c0eSMichael Tuexen 			 * addr_wq.
1680b7b84c0eSMichael Tuexen 			 */
16812b1c7de4SMichael Tuexen 			if (SCTP_BASE_VAR(sctp_pcb_initialized) == 0) {
16822b1c7de4SMichael Tuexen 				sctp_asconf_iterator_end(asc, 0);
16832b1c7de4SMichael Tuexen 			} else {
16842b1c7de4SMichael Tuexen 				LIST_FOREACH(wi, &asc->list_of_work, sctp_nxt_addr) {
16852b1c7de4SMichael Tuexen 					LIST_INSERT_HEAD(&SCTP_BASE_INFO(addr_wq), wi, sctp_nxt_addr);
16862b1c7de4SMichael Tuexen 				}
16872b1c7de4SMichael Tuexen 				SCTP_FREE(asc, SCTP_M_ASC_IT);
16882b1c7de4SMichael Tuexen 			}
16892b1c7de4SMichael Tuexen 		}
169042551e99SRandall Stewart 	}
1691f8829a4aSRandall Stewart }
1692f8829a4aSRandall Stewart 
1693a412576eSMichael Tuexen /*-
1694a412576eSMichael Tuexen  * The following table shows which pointers for the inp, stcb, or net are
1695a412576eSMichael Tuexen  * stored for each timer after it was started.
1696a412576eSMichael Tuexen  *
1697a412576eSMichael Tuexen  *|Name                         |Timer                        |inp |stcb|net |
1698a412576eSMichael Tuexen  *|-----------------------------|-----------------------------|----|----|----|
1699a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_SEND         |net->rxt_timer               |Yes |Yes |Yes |
1700a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_INIT         |net->rxt_timer               |Yes |Yes |Yes |
1701a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_RECV         |stcb->asoc.dack_timer        |Yes |Yes |No  |
1702a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_SHUTDOWN     |net->rxt_timer               |Yes |Yes |Yes |
1703a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_HEARTBEAT    |net->hb_timer                |Yes |Yes |Yes |
1704a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_COOKIE       |net->rxt_timer               |Yes |Yes |Yes |
1705a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_NEWCOOKIE    |inp->sctp_ep.signature_change|Yes |No  |No  |
1706a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_PATHMTURAISE |net->pmtu_timer              |Yes |Yes |Yes |
1707a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_SHUTDOWNACK  |net->rxt_timer               |Yes |Yes |Yes |
1708a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_ASCONF       |stcb->asoc.asconf_timer      |Yes |Yes |Yes |
1709a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_SHUTDOWNGUARD|stcb->asoc.shut_guard_timer  |Yes |Yes |No  |
1710a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_AUTOCLOSE    |stcb->asoc.autoclose_timer   |Yes |Yes |No  |
1711a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_STRRESET     |stcb->asoc.strreset_timer    |Yes |Yes |No  |
1712a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_INPKILL      |inp->sctp_ep.signature_change|Yes |No  |No  |
1713a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_ASOCKILL     |stcb->asoc.strreset_timer    |Yes |Yes |No  |
1714a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_ADDR_WQ      |SCTP_BASE_INFO(addr_wq_timer)|No  |No  |No  |
1715a412576eSMichael Tuexen  *|SCTP_TIMER_TYPE_PRIM_DELETED |stcb->asoc.delete_prim_timer |Yes |Yes |No  |
1716a412576eSMichael Tuexen  */
1717a412576eSMichael Tuexen 
1718f8829a4aSRandall Stewart void
1719f8829a4aSRandall Stewart sctp_timeout_handler(void *t)
1720f8829a4aSRandall Stewart {
1721868b51f2SMichael Tuexen 	struct epoch_tracker et;
1722a412576eSMichael Tuexen 	struct timeval tv;
1723f8829a4aSRandall Stewart 	struct sctp_inpcb *inp;
1724f8829a4aSRandall Stewart 	struct sctp_tcb *stcb;
1725f8829a4aSRandall Stewart 	struct sctp_nets *net;
1726f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
1727267dbe63SMichael Tuexen 	struct mbuf *op_err;
1728fa89f692SMichael Tuexen 	int type;
1729a412576eSMichael Tuexen 	int i, secret;
17308745f898SMichael Tuexen 	bool did_output, released_asoc_reference;
1731f8829a4aSRandall Stewart 
17328745f898SMichael Tuexen 	/*
17338745f898SMichael Tuexen 	 * If inp, stcb or net are not NULL, then references to these were
17348745f898SMichael Tuexen 	 * added when the timer was started, and must be released before
17358745f898SMichael Tuexen 	 * this function returns.
17368745f898SMichael Tuexen 	 */
1737f8829a4aSRandall Stewart 	tmr = (struct sctp_timer *)t;
1738f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)tmr->ep;
1739f8829a4aSRandall Stewart 	stcb = (struct sctp_tcb *)tmr->tcb;
1740f8829a4aSRandall Stewart 	net = (struct sctp_nets *)tmr->net;
17418518270eSMichael Tuexen 	CURVNET_SET((struct vnet *)tmr->vnet);
174204996cb7SMichael Tuexen 	NET_EPOCH_ENTER(et);
17438745f898SMichael Tuexen 	released_asoc_reference = false;
1744f8829a4aSRandall Stewart 
1745f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1746f8829a4aSRandall Stewart 	sctp_audit_log(0xF0, (uint8_t)tmr->type);
1747f8829a4aSRandall Stewart 	sctp_auditing(3, inp, stcb, net);
1748f8829a4aSRandall Stewart #endif
1749f8829a4aSRandall Stewart 
1750f8829a4aSRandall Stewart 	/* sanity checks... */
17512d87bacdSMichael Tuexen 	KASSERT(tmr->self == NULL || tmr->self == tmr,
1752f4cb790aSMichael Tuexen 	    ("sctp_timeout_handler: tmr->self corrupted"));
1753f4cb790aSMichael Tuexen 	KASSERT(SCTP_IS_TIMER_TYPE_VALID(tmr->type),
1754f4cb790aSMichael Tuexen 	    ("sctp_timeout_handler: invalid timer type %d", tmr->type));
1755a412576eSMichael Tuexen 	type = tmr->type;
1756f4cb790aSMichael Tuexen 	KASSERT(stcb == NULL || stcb->sctp_ep == inp,
1757f4cb790aSMichael Tuexen 	    ("sctp_timeout_handler of type %d: inp = %p, stcb->sctp_ep %p",
1758f4cb790aSMichael Tuexen 	    type, stcb, stcb->sctp_ep));
17597c63520cSMichael Tuexen 	tmr->stopped_from = 0xa001;
17608745f898SMichael Tuexen 	if ((stcb != NULL) && (stcb->asoc.state == SCTP_STATE_EMPTY)) {
1761a412576eSMichael Tuexen 		SCTPDBG(SCTP_DEBUG_TIMER2,
176223e3c088SMichael Tuexen 		    "Timer type %d handler exiting due to CLOSED association.\n",
1763a412576eSMichael Tuexen 		    type);
17648745f898SMichael Tuexen 		goto out_decr;
1765f8829a4aSRandall Stewart 	}
17667c63520cSMichael Tuexen 	tmr->stopped_from = 0xa002;
176737686ccfSMichael Tuexen 	SCTPDBG(SCTP_DEBUG_TIMER2, "Timer type %d goes off.\n", type);
1768139bc87fSRandall Stewart 	if (!SCTP_OS_TIMER_ACTIVE(&tmr->timer)) {
1769a412576eSMichael Tuexen 		SCTPDBG(SCTP_DEBUG_TIMER2,
177023e3c088SMichael Tuexen 		    "Timer type %d handler exiting due to not being active.\n",
1771a412576eSMichael Tuexen 		    type);
17728745f898SMichael Tuexen 		goto out_decr;
1773f8829a4aSRandall Stewart 	}
1774a5d547adSRandall Stewart 
17757c63520cSMichael Tuexen 	tmr->stopped_from = 0xa003;
1776f8829a4aSRandall Stewart 	if (stcb) {
1777f8829a4aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
17788745f898SMichael Tuexen 		/*
17798745f898SMichael Tuexen 		 * Release reference so that association can be freed if
17808745f898SMichael Tuexen 		 * necessary below. This is safe now that we have acquired
17818745f898SMichael Tuexen 		 * the lock.
17828745f898SMichael Tuexen 		 */
17833c1ba6f3SMichael Tuexen 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
17848745f898SMichael Tuexen 		released_asoc_reference = true;
1785fa89f692SMichael Tuexen 		if ((type != SCTP_TIMER_TYPE_ASOCKILL) &&
17868745f898SMichael Tuexen 		    ((stcb->asoc.state == SCTP_STATE_EMPTY) ||
1787b54d3a6cSRandall Stewart 		    (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED))) {
1788a412576eSMichael Tuexen 			SCTPDBG(SCTP_DEBUG_TIMER2,
178923e3c088SMichael Tuexen 			    "Timer type %d handler exiting due to CLOSED association.\n",
1790a412576eSMichael Tuexen 			    type);
17918745f898SMichael Tuexen 			goto out;
1792b54d3a6cSRandall Stewart 		}
17932c62ba73SMichael Tuexen 	} else if (inp != NULL) {
17942c62ba73SMichael Tuexen 		SCTP_INP_WLOCK(inp);
17952c62ba73SMichael Tuexen 	} else {
17962c62ba73SMichael Tuexen 		SCTP_WQ_ADDR_LOCK();
1797f8829a4aSRandall Stewart 	}
179844b7479bSRandall Stewart 
179937686ccfSMichael Tuexen 	/* Record in stopped_from which timeout occurred. */
180037686ccfSMichael Tuexen 	tmr->stopped_from = type;
1801f8829a4aSRandall Stewart 	/* mark as being serviced now */
180244b7479bSRandall Stewart 	if (SCTP_OS_TIMER_PENDING(&tmr->timer)) {
180344b7479bSRandall Stewart 		/*
180444b7479bSRandall Stewart 		 * Callout has been rescheduled.
180544b7479bSRandall Stewart 		 */
18068745f898SMichael Tuexen 		goto out;
180744b7479bSRandall Stewart 	}
180844b7479bSRandall Stewart 	if (!SCTP_OS_TIMER_ACTIVE(&tmr->timer)) {
180944b7479bSRandall Stewart 		/*
181044b7479bSRandall Stewart 		 * Not active, so no action.
181144b7479bSRandall Stewart 		 */
18128745f898SMichael Tuexen 		goto out;
181344b7479bSRandall Stewart 	}
1814139bc87fSRandall Stewart 	SCTP_OS_TIMER_DEACTIVATE(&tmr->timer);
1815f8829a4aSRandall Stewart 
1816f8829a4aSRandall Stewart 	/* call the handler for the appropriate timer type */
1817fa89f692SMichael Tuexen 	switch (type) {
1818f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
1819a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net != NULL,
1820a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
1821a412576eSMichael Tuexen 		    type, inp, stcb, net));
1822f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timodata);
1823f42a358aSRandall Stewart 		stcb->asoc.timodata++;
1824f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up--;
1825f8829a4aSRandall Stewart 		if (stcb->asoc.num_send_timers_up < 0) {
1826f8829a4aSRandall Stewart 			stcb->asoc.num_send_timers_up = 0;
1827f8829a4aSRandall Stewart 		}
1828b54d3a6cSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
182960990c0cSMichael Tuexen 		if (sctp_t3rxt_timer(inp, stcb, net)) {
1830f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1831f8829a4aSRandall Stewart 
1832f8829a4aSRandall Stewart 			goto out_decr;
1833f8829a4aSRandall Stewart 		}
1834b54d3a6cSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
1835f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1836f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1837f8829a4aSRandall Stewart #endif
1838ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
18398745f898SMichael Tuexen 		did_output = true;
1840f8829a4aSRandall Stewart 		if ((stcb->asoc.num_send_timers_up == 0) &&
18414a9ef3f8SMichael Tuexen 		    (stcb->asoc.sent_queue_cnt > 0)) {
1842f8829a4aSRandall Stewart 			struct sctp_tmit_chunk *chk;
1843f8829a4aSRandall Stewart 
1844f8829a4aSRandall Stewart 			/*
1845efd5e692SMichael Tuexen 			 * Safeguard. If there on some on the sent queue
1846f8829a4aSRandall Stewart 			 * somewhere but no timers running something is
1847f8829a4aSRandall Stewart 			 * wrong... so we start a timer on the first chunk
1848f8829a4aSRandall Stewart 			 * on the send queue on whatever net it is sent to.
1849f8829a4aSRandall Stewart 			 */
1850efd5e692SMichael Tuexen 			TAILQ_FOREACH(chk, &stcb->asoc.sent_queue, sctp_next) {
1851efd5e692SMichael Tuexen 				if (chk->whoTo != NULL) {
1852efd5e692SMichael Tuexen 					break;
1853efd5e692SMichael Tuexen 				}
1854efd5e692SMichael Tuexen 			}
1855efd5e692SMichael Tuexen 			if (chk != NULL) {
1856efd5e692SMichael Tuexen 				sctp_timer_start(SCTP_TIMER_TYPE_SEND, stcb->sctp_ep, stcb, chk->whoTo);
1857efd5e692SMichael Tuexen 			}
1858f8829a4aSRandall Stewart 		}
1859f8829a4aSRandall Stewart 		break;
1860f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
1861a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net != NULL,
1862a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
1863a412576eSMichael Tuexen 		    type, inp, stcb, net));
1864f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoinit);
1865f42a358aSRandall Stewart 		stcb->asoc.timoinit++;
1866f8829a4aSRandall Stewart 		if (sctp_t1init_timer(inp, stcb, net)) {
1867f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1868f8829a4aSRandall Stewart 			goto out_decr;
1869f8829a4aSRandall Stewart 		}
18708745f898SMichael Tuexen 		did_output = false;
1871f8829a4aSRandall Stewart 		break;
1872f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
1873a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net == NULL,
1874a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
1875a412576eSMichael Tuexen 		    type, inp, stcb, net));
1876f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timosack);
1877f42a358aSRandall Stewart 		stcb->asoc.timosack++;
1878689e6a5fSMichael Tuexen 		sctp_send_sack(stcb, SCTP_SO_NOT_LOCKED);
1879f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1880a412576eSMichael Tuexen 		sctp_auditing(4, inp, stcb, NULL);
1881f8829a4aSRandall Stewart #endif
1882ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SACK_TMR, SCTP_SO_NOT_LOCKED);
18838745f898SMichael Tuexen 		did_output = true;
1884f8829a4aSRandall Stewart 		break;
1885f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
1886a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net != NULL,
1887a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
1888a412576eSMichael Tuexen 		    type, inp, stcb, net));
1889a412576eSMichael Tuexen 		SCTP_STAT_INCR(sctps_timoshutdown);
1890a412576eSMichael Tuexen 		stcb->asoc.timoshutdown++;
1891f8829a4aSRandall Stewart 		if (sctp_shutdown_timer(inp, stcb, net)) {
1892f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1893f8829a4aSRandall Stewart 			goto out_decr;
1894f8829a4aSRandall Stewart 		}
1895f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1896f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1897f8829a4aSRandall Stewart #endif
1898ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SHUT_TMR, SCTP_SO_NOT_LOCKED);
18998745f898SMichael Tuexen 		did_output = true;
1900f8829a4aSRandall Stewart 		break;
1901f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
1902a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net != NULL,
1903a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
1904a412576eSMichael Tuexen 		    type, inp, stcb, net));
1905f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoheartbeat);
1906f42a358aSRandall Stewart 		stcb->asoc.timoheartbeat++;
1907ca85e948SMichael Tuexen 		if (sctp_heartbeat_timer(inp, stcb, net)) {
1908f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1909f8829a4aSRandall Stewart 			goto out_decr;
1910f8829a4aSRandall Stewart 		}
1911f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1912ca85e948SMichael Tuexen 		sctp_auditing(4, inp, stcb, net);
1913f8829a4aSRandall Stewart #endif
1914ca85e948SMichael Tuexen 		if (!(net->dest_state & SCTP_ADDR_NOHB)) {
1915629749b6SMichael Tuexen 			sctp_timer_start(SCTP_TIMER_TYPE_HEARTBEAT, inp, stcb, net);
1916ceaad40aSRandall Stewart 			sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_HB_TMR, SCTP_SO_NOT_LOCKED);
19178745f898SMichael Tuexen 			did_output = true;
19188745f898SMichael Tuexen 		} else {
19198745f898SMichael Tuexen 			did_output = false;
1920f8829a4aSRandall Stewart 		}
1921f8829a4aSRandall Stewart 		break;
1922f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
1923a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net != NULL,
1924a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
1925a412576eSMichael Tuexen 		    type, inp, stcb, net));
1926a412576eSMichael Tuexen 		SCTP_STAT_INCR(sctps_timocookie);
1927a412576eSMichael Tuexen 		stcb->asoc.timocookie++;
1928f8829a4aSRandall Stewart 		if (sctp_cookie_timer(inp, stcb, net)) {
1929f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1930f8829a4aSRandall Stewart 			goto out_decr;
1931f8829a4aSRandall Stewart 		}
1932f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1933f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1934f8829a4aSRandall Stewart #endif
1935f8829a4aSRandall Stewart 		/*
1936f8829a4aSRandall Stewart 		 * We consider T3 and Cookie timer pretty much the same with
1937f8829a4aSRandall Stewart 		 * respect to where from in chunk_output.
1938f8829a4aSRandall Stewart 		 */
1939ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
19408745f898SMichael Tuexen 		did_output = true;
1941f8829a4aSRandall Stewart 		break;
1942f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
1943a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb == NULL && net == NULL,
1944a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
1945a412576eSMichael Tuexen 		    type, inp, stcb, net));
1946f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timosecret);
19476e55db54SRandall Stewart 		(void)SCTP_GETTIME_TIMEVAL(&tv);
1948aab1d593SMichael Tuexen 		inp->sctp_ep.time_of_secret_change = (unsigned int)tv.tv_sec;
1949f8829a4aSRandall Stewart 		inp->sctp_ep.last_secret_number =
1950f8829a4aSRandall Stewart 		    inp->sctp_ep.current_secret_number;
1951f8829a4aSRandall Stewart 		inp->sctp_ep.current_secret_number++;
1952f8829a4aSRandall Stewart 		if (inp->sctp_ep.current_secret_number >=
1953f8829a4aSRandall Stewart 		    SCTP_HOW_MANY_SECRETS) {
1954f8829a4aSRandall Stewart 			inp->sctp_ep.current_secret_number = 0;
1955f8829a4aSRandall Stewart 		}
1956f8829a4aSRandall Stewart 		secret = (int)inp->sctp_ep.current_secret_number;
1957f8829a4aSRandall Stewart 		for (i = 0; i < SCTP_NUMBER_OF_SECRETS; i++) {
1958f8829a4aSRandall Stewart 			inp->sctp_ep.secret_key[secret][i] =
1959f8829a4aSRandall Stewart 			    sctp_select_initial_TSN(&inp->sctp_ep);
1960f8829a4aSRandall Stewart 		}
19616fb7b4fbSMichael Tuexen 		sctp_timer_start(SCTP_TIMER_TYPE_NEWCOOKIE, inp, NULL, NULL);
19628745f898SMichael Tuexen 		did_output = false;
1963f8829a4aSRandall Stewart 		break;
1964f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
1965a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net != NULL,
1966a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
1967a412576eSMichael Tuexen 		    type, inp, stcb, net));
1968f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timopathmtu);
1969f8829a4aSRandall Stewart 		sctp_pathmtu_timer(inp, stcb, net);
19708745f898SMichael Tuexen 		did_output = false;
1971f8829a4aSRandall Stewart 		break;
1972f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
1973a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net != NULL,
1974a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
1975a412576eSMichael Tuexen 		    type, inp, stcb, net));
1976f8829a4aSRandall Stewart 		if (sctp_shutdownack_timer(inp, stcb, net)) {
1977f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1978f8829a4aSRandall Stewart 			goto out_decr;
1979f8829a4aSRandall Stewart 		}
1980f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoshutdownack);
1981f42a358aSRandall Stewart 		stcb->asoc.timoshutdownack++;
1982f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1983f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1984f8829a4aSRandall Stewart #endif
1985ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SHUT_ACK_TMR, SCTP_SO_NOT_LOCKED);
19868745f898SMichael Tuexen 		did_output = true;
1987f8829a4aSRandall Stewart 		break;
1988f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASCONF:
1989a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net != NULL,
1990a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
1991a412576eSMichael Tuexen 		    type, inp, stcb, net));
1992a412576eSMichael Tuexen 		SCTP_STAT_INCR(sctps_timoasconf);
1993f8829a4aSRandall Stewart 		if (sctp_asconf_timer(inp, stcb, net)) {
1994f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1995f8829a4aSRandall Stewart 			goto out_decr;
1996f8829a4aSRandall Stewart 		}
1997f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1998f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1999f8829a4aSRandall Stewart #endif
2000ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_ASCONF_TMR, SCTP_SO_NOT_LOCKED);
20018745f898SMichael Tuexen 		did_output = true;
2002f8829a4aSRandall Stewart 		break;
20030554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
2004a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net == NULL,
2005a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
2006a412576eSMichael Tuexen 		    type, inp, stcb, net));
20070554e01dSMichael Tuexen 		SCTP_STAT_INCR(sctps_timoshutdownguard);
20080554e01dSMichael Tuexen 		op_err = sctp_generate_cause(SCTP_BASE_SYSCTL(sctp_diag_info_code),
20090554e01dSMichael Tuexen 		    "Shutdown guard timer expired");
2010105b68b4SMichael Tuexen 		sctp_abort_an_association(inp, stcb, op_err, true, SCTP_SO_NOT_LOCKED);
20110554e01dSMichael Tuexen 		/* no need to unlock on tcb its gone */
20120554e01dSMichael Tuexen 		goto out_decr;
2013f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_AUTOCLOSE:
2014a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net == NULL,
2015a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
2016a412576eSMichael Tuexen 		    type, inp, stcb, net));
2017f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoautoclose);
2018a57fb68bSMichael Tuexen 		sctp_autoclose_timer(inp, stcb);
2019ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_AUTOCLOSE_TMR, SCTP_SO_NOT_LOCKED);
20208745f898SMichael Tuexen 		did_output = true;
2021f8829a4aSRandall Stewart 		break;
20220554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_STRRESET:
2023a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net == NULL,
2024a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
2025a412576eSMichael Tuexen 		    type, inp, stcb, net));
2026a412576eSMichael Tuexen 		SCTP_STAT_INCR(sctps_timostrmrst);
2027e95b3d7fSMichael Tuexen 		if (sctp_strreset_timer(inp, stcb)) {
20280554e01dSMichael Tuexen 			/* no need to unlock on tcb its gone */
20290554e01dSMichael Tuexen 			goto out_decr;
20300554e01dSMichael Tuexen 		}
20310554e01dSMichael Tuexen 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_STRRST_TMR, SCTP_SO_NOT_LOCKED);
20328745f898SMichael Tuexen 		did_output = true;
20330554e01dSMichael Tuexen 		break;
20340554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_INPKILL:
2035a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb == NULL && net == NULL,
2036a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
2037a412576eSMichael Tuexen 		    type, inp, stcb, net));
20380554e01dSMichael Tuexen 		SCTP_STAT_INCR(sctps_timoinpkill);
20390554e01dSMichael Tuexen 		/*
20400554e01dSMichael Tuexen 		 * special case, take away our increment since WE are the
20410554e01dSMichael Tuexen 		 * killer
20420554e01dSMichael Tuexen 		 */
20430554e01dSMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_INPKILL, inp, NULL, NULL,
20440554e01dSMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_3);
2045a412576eSMichael Tuexen 		SCTP_INP_DECR_REF(inp);
2046a412576eSMichael Tuexen 		SCTP_INP_WUNLOCK(inp);
20470554e01dSMichael Tuexen 		sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
20480554e01dSMichael Tuexen 		    SCTP_CALLED_FROM_INPKILL_TIMER);
20490554e01dSMichael Tuexen 		inp = NULL;
2050bdd4630cSMichael Tuexen 		goto out_decr;
2051f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASOCKILL:
2052a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net == NULL,
2053a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
2054a412576eSMichael Tuexen 		    type, inp, stcb, net));
2055f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoassockill);
2056f8829a4aSRandall Stewart 		/* Can we free it yet? */
2057ba785902SMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_ASOCKILL, inp, stcb, NULL,
2058ba785902SMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_1);
2059ba785902SMichael Tuexen 		(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
2060ba785902SMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_2);
2061f8829a4aSRandall Stewart 		/*
2062f8829a4aSRandall Stewart 		 * free asoc, always unlocks (or destroy's) so prevent
2063f8829a4aSRandall Stewart 		 * duplicate unlock or unlock of a free mtx :-0
2064f8829a4aSRandall Stewart 		 */
2065f8829a4aSRandall Stewart 		stcb = NULL;
2066bdd4630cSMichael Tuexen 		goto out_decr;
20670554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_ADDR_WQ:
2068a412576eSMichael Tuexen 		KASSERT(inp == NULL && stcb == NULL && net == NULL,
2069a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
2070a412576eSMichael Tuexen 		    type, inp, stcb, net));
20710554e01dSMichael Tuexen 		sctp_handle_addr_wq();
20728745f898SMichael Tuexen 		did_output = true;
20730554e01dSMichael Tuexen 		break;
20740554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_PRIM_DELETED:
2075a412576eSMichael Tuexen 		KASSERT(inp != NULL && stcb != NULL && net == NULL,
2076a412576eSMichael Tuexen 		    ("timeout of type %d: inp = %p, stcb = %p, net = %p",
2077a412576eSMichael Tuexen 		    type, inp, stcb, net));
20780554e01dSMichael Tuexen 		SCTP_STAT_INCR(sctps_timodelprim);
2079a412576eSMichael Tuexen 		sctp_delete_prim_timer(inp, stcb);
20808745f898SMichael Tuexen 		did_output = false;
20810554e01dSMichael Tuexen 		break;
2082f8829a4aSRandall Stewart 	default:
20837522682eSMichael Tuexen #ifdef INVARIANTS
2084a412576eSMichael Tuexen 		panic("Unknown timer type %d", type);
20857522682eSMichael Tuexen #else
20868745f898SMichael Tuexen 		goto out;
20877522682eSMichael Tuexen #endif
208860990c0cSMichael Tuexen 	}
2089f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
2090fa89f692SMichael Tuexen 	sctp_audit_log(0xF1, (uint8_t)type);
20918745f898SMichael Tuexen 	if (inp != NULL)
2092f8829a4aSRandall Stewart 		sctp_auditing(5, inp, stcb, net);
2093f8829a4aSRandall Stewart #endif
20948745f898SMichael Tuexen 	if (did_output && (stcb != NULL)) {
2095f8829a4aSRandall Stewart 		/*
2096f8829a4aSRandall Stewart 		 * Now we need to clean up the control chunk chain if an
2097f8829a4aSRandall Stewart 		 * ECNE is on it. It must be marked as UNSENT again so next
2098f8829a4aSRandall Stewart 		 * call will continue to send it until such time that we get
2099f8829a4aSRandall Stewart 		 * a CWR, to remove it. It is, however, less likely that we
2100f8829a4aSRandall Stewart 		 * will find a ecn echo on the chain though.
2101f8829a4aSRandall Stewart 		 */
2102f8829a4aSRandall Stewart 		sctp_fix_ecn_echo(&stcb->asoc);
2103f8829a4aSRandall Stewart 	}
21048745f898SMichael Tuexen out:
21058745f898SMichael Tuexen 	if (stcb != NULL) {
2106f8829a4aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
21072c62ba73SMichael Tuexen 	} else if (inp != NULL) {
21082c62ba73SMichael Tuexen 		SCTP_INP_WUNLOCK(inp);
21092c62ba73SMichael Tuexen 	} else {
21102c62ba73SMichael Tuexen 		SCTP_WQ_ADDR_UNLOCK();
2111f8829a4aSRandall Stewart 	}
21122c62ba73SMichael Tuexen 
2113f8829a4aSRandall Stewart out_decr:
21148745f898SMichael Tuexen 	/* These reference counts were incremented in sctp_timer_start(). */
21158745f898SMichael Tuexen 	if (inp != NULL) {
2116f8829a4aSRandall Stewart 		SCTP_INP_DECR_REF(inp);
2117f8829a4aSRandall Stewart 	}
21188745f898SMichael Tuexen 	if ((stcb != NULL) && !released_asoc_reference) {
21193c1ba6f3SMichael Tuexen 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
21208745f898SMichael Tuexen 	}
21218745f898SMichael Tuexen 	if (net != NULL) {
21228745f898SMichael Tuexen 		sctp_free_remote_addr(net);
21238745f898SMichael Tuexen 	}
212423e3c088SMichael Tuexen 	SCTPDBG(SCTP_DEBUG_TIMER2, "Timer type %d handler finished.\n", type);
21258518270eSMichael Tuexen 	CURVNET_RESTORE();
2126868b51f2SMichael Tuexen 	NET_EPOCH_EXIT(et);
2127f8829a4aSRandall Stewart }
2128f8829a4aSRandall Stewart 
2129a412576eSMichael Tuexen /*-
2130a412576eSMichael Tuexen  * The following table shows which parameters must be provided
2131a412576eSMichael Tuexen  * when calling sctp_timer_start(). For parameters not being
2132a412576eSMichael Tuexen  * provided, NULL must be used.
2133a412576eSMichael Tuexen  *
2134a412576eSMichael Tuexen  * |Name                         |inp |stcb|net |
2135a412576eSMichael Tuexen  * |-----------------------------|----|----|----|
2136a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_SEND         |Yes |Yes |Yes |
2137a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_INIT         |Yes |Yes |Yes |
2138a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_RECV         |Yes |Yes |No  |
2139a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_SHUTDOWN     |Yes |Yes |Yes |
2140a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_HEARTBEAT    |Yes |Yes |Yes |
2141a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_COOKIE       |Yes |Yes |Yes |
2142a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_NEWCOOKIE    |Yes |No  |No  |
2143a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_PATHMTURAISE |Yes |Yes |Yes |
2144a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_SHUTDOWNACK  |Yes |Yes |Yes |
2145a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_ASCONF       |Yes |Yes |Yes |
2146a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_SHUTDOWNGUARD|Yes |Yes |No  |
2147a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_AUTOCLOSE    |Yes |Yes |No  |
2148a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_STRRESET     |Yes |Yes |Yes |
2149a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_INPKILL      |Yes |No  |No  |
2150a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_ASOCKILL     |Yes |Yes |No  |
2151a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_ADDR_WQ      |No  |No  |No  |
2152a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_PRIM_DELETED |Yes |Yes |No  |
2153a412576eSMichael Tuexen  *
2154a412576eSMichael Tuexen  */
2155a412576eSMichael Tuexen 
2156ad81507eSRandall Stewart void
2157f8829a4aSRandall Stewart sctp_timer_start(int t_type, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
2158f8829a4aSRandall Stewart     struct sctp_nets *net)
2159f8829a4aSRandall Stewart {
2160f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
2161a412576eSMichael Tuexen 	uint32_t to_ticks;
2162a412576eSMichael Tuexen 	uint32_t rndval, jitter;
2163f8829a4aSRandall Stewart 
2164f4cb790aSMichael Tuexen 	KASSERT(stcb == NULL || stcb->sctp_ep == inp,
2165f4cb790aSMichael Tuexen 	    ("sctp_timer_start of type %d: inp = %p, stcb->sctp_ep %p",
2166f4cb790aSMichael Tuexen 	    t_type, stcb, stcb->sctp_ep));
2167f8829a4aSRandall Stewart 	tmr = NULL;
2168a412576eSMichael Tuexen 	if (stcb != NULL) {
2169f8829a4aSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
2170a412576eSMichael Tuexen 	} else if (inp != NULL) {
2171a412576eSMichael Tuexen 		SCTP_INP_WLOCK_ASSERT(inp);
2172a412576eSMichael Tuexen 	} else {
2173a412576eSMichael Tuexen 		SCTP_WQ_ADDR_LOCK_ASSERT();
2174a412576eSMichael Tuexen 	}
2175a412576eSMichael Tuexen 	if (stcb != NULL) {
2176a412576eSMichael Tuexen 		/*
2177a412576eSMichael Tuexen 		 * Don't restart timer on association that's about to be
2178a412576eSMichael Tuexen 		 * killed.
2179a412576eSMichael Tuexen 		 */
2180a412576eSMichael Tuexen 		if ((stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) &&
2181a412576eSMichael Tuexen 		    (t_type != SCTP_TIMER_TYPE_ASOCKILL)) {
2182a412576eSMichael Tuexen 			SCTPDBG(SCTP_DEBUG_TIMER2,
218337686ccfSMichael Tuexen 			    "Timer type %d not started: inp=%p, stcb=%p, net=%p (stcb deleted).\n",
2184a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2185a412576eSMichael Tuexen 			return;
2186f8829a4aSRandall Stewart 		}
21879803f01cSMichael Tuexen 		/* Don't restart timer on net that's been removed. */
21889803f01cSMichael Tuexen 		if (net != NULL && (net->dest_state & SCTP_ADDR_BEING_DELETED)) {
2189a412576eSMichael Tuexen 			SCTPDBG(SCTP_DEBUG_TIMER2,
219037686ccfSMichael Tuexen 			    "Timer type %d not started: inp=%p, stcb=%p, net=%p (net deleted).\n",
2191a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
21929803f01cSMichael Tuexen 			return;
21939803f01cSMichael Tuexen 		}
2194a412576eSMichael Tuexen 	}
2195f8829a4aSRandall Stewart 	switch (t_type) {
2196f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
2197a412576eSMichael Tuexen 		/* Here we use the RTO timer. */
2198a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2199a412576eSMichael Tuexen #ifdef INVARIANTS
2200a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2201a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2202a412576eSMichael Tuexen #else
2203ad81507eSRandall Stewart 			return;
2204a412576eSMichael Tuexen #endif
2205f8829a4aSRandall Stewart 		}
2206f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2207f8829a4aSRandall Stewart 		if (net->RTO == 0) {
220825ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(stcb->asoc.initial_rto);
2209f8829a4aSRandall Stewart 		} else {
221025ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(net->RTO);
2211f8829a4aSRandall Stewart 		}
2212f8829a4aSRandall Stewart 		break;
2213f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
2214f8829a4aSRandall Stewart 		/*
2215f8829a4aSRandall Stewart 		 * Here we use the INIT timer default usually about 1
2216a412576eSMichael Tuexen 		 * second.
2217f8829a4aSRandall Stewart 		 */
2218a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2219a412576eSMichael Tuexen #ifdef INVARIANTS
2220a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2221a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2222a412576eSMichael Tuexen #else
2223ad81507eSRandall Stewart 			return;
2224a412576eSMichael Tuexen #endif
2225f8829a4aSRandall Stewart 		}
2226f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2227f8829a4aSRandall Stewart 		if (net->RTO == 0) {
222825ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(stcb->asoc.initial_rto);
2229f8829a4aSRandall Stewart 		} else {
223025ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(net->RTO);
2231f8829a4aSRandall Stewart 		}
2232f8829a4aSRandall Stewart 		break;
2233f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
2234f8829a4aSRandall Stewart 		/*
2235a412576eSMichael Tuexen 		 * Here we use the Delayed-Ack timer value from the inp,
2236f8829a4aSRandall Stewart 		 * ususually about 200ms.
2237f8829a4aSRandall Stewart 		 */
2238a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2239a412576eSMichael Tuexen #ifdef INVARIANTS
2240a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2241a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2242a412576eSMichael Tuexen #else
2243ad81507eSRandall Stewart 			return;
2244a412576eSMichael Tuexen #endif
2245f8829a4aSRandall Stewart 		}
2246f8829a4aSRandall Stewart 		tmr = &stcb->asoc.dack_timer;
224725ec3553SMichael Tuexen 		to_ticks = sctp_msecs_to_ticks(stcb->asoc.delayed_ack);
2248f8829a4aSRandall Stewart 		break;
2249f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
2250f8829a4aSRandall Stewart 		/* Here we use the RTO of the destination. */
2251a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2252a412576eSMichael Tuexen #ifdef INVARIANTS
2253a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2254a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2255a412576eSMichael Tuexen #else
2256ad81507eSRandall Stewart 			return;
2257a412576eSMichael Tuexen #endif
2258f8829a4aSRandall Stewart 		}
2259a412576eSMichael Tuexen 		tmr = &net->rxt_timer;
2260f8829a4aSRandall Stewart 		if (net->RTO == 0) {
226125ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(stcb->asoc.initial_rto);
2262f8829a4aSRandall Stewart 		} else {
226325ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(net->RTO);
2264f8829a4aSRandall Stewart 		}
2265f8829a4aSRandall Stewart 		break;
2266f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
2267f8829a4aSRandall Stewart 		/*
2268a412576eSMichael Tuexen 		 * The net is used here so that we can add in the RTO. Even
2269f8829a4aSRandall Stewart 		 * though we use a different timer. We also add the HB timer
2270f8829a4aSRandall Stewart 		 * PLUS a random jitter.
2271f8829a4aSRandall Stewart 		 */
2272a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2273a412576eSMichael Tuexen #ifdef INVARIANTS
2274a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2275a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2276a412576eSMichael Tuexen #else
2277ad81507eSRandall Stewart 			return;
2278a412576eSMichael Tuexen #endif
2279a412576eSMichael Tuexen 		}
2280ca85e948SMichael Tuexen 		if ((net->dest_state & SCTP_ADDR_NOHB) &&
2281ca85e948SMichael Tuexen 		    !(net->dest_state & SCTP_ADDR_UNCONFIRMED)) {
2282a412576eSMichael Tuexen 			SCTPDBG(SCTP_DEBUG_TIMER2,
228337686ccfSMichael Tuexen 			    "Timer type %d not started: inp=%p, stcb=%p, net=%p.\n",
2284a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2285ad81507eSRandall Stewart 			return;
2286f8829a4aSRandall Stewart 		}
2287a412576eSMichael Tuexen 		tmr = &net->hb_timer;
2288f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2289ca85e948SMichael Tuexen 			to_ticks = stcb->asoc.initial_rto;
2290f8829a4aSRandall Stewart 		} else {
2291ca85e948SMichael Tuexen 			to_ticks = net->RTO;
2292f8829a4aSRandall Stewart 		}
2293ca85e948SMichael Tuexen 		rndval = sctp_select_initial_TSN(&inp->sctp_ep);
2294ca85e948SMichael Tuexen 		jitter = rndval % to_ticks;
2295d995cc7eSMichael Tuexen 		if (to_ticks > 1) {
229670e95f0bSMichael Tuexen 			to_ticks >>= 1;
2297d995cc7eSMichael Tuexen 		}
229870e95f0bSMichael Tuexen 		if (jitter < (UINT32_MAX - to_ticks)) {
229970e95f0bSMichael Tuexen 			to_ticks += jitter;
2300f8829a4aSRandall Stewart 		} else {
230170e95f0bSMichael Tuexen 			to_ticks = UINT32_MAX;
2302f8829a4aSRandall Stewart 		}
2303ca85e948SMichael Tuexen 		if (!(net->dest_state & SCTP_ADDR_UNCONFIRMED) &&
2304ca85e948SMichael Tuexen 		    !(net->dest_state & SCTP_ADDR_PF)) {
230570e95f0bSMichael Tuexen 			if (net->heart_beat_delay < (UINT32_MAX - to_ticks)) {
2306ca85e948SMichael Tuexen 				to_ticks += net->heart_beat_delay;
230770e95f0bSMichael Tuexen 			} else {
230870e95f0bSMichael Tuexen 				to_ticks = UINT32_MAX;
230970e95f0bSMichael Tuexen 			}
2310f8829a4aSRandall Stewart 		}
2311f8829a4aSRandall Stewart 		/*
2312a412576eSMichael Tuexen 		 * Now we must convert the to_ticks that are now in ms to
2313a412576eSMichael Tuexen 		 * ticks.
2314f8829a4aSRandall Stewart 		 */
231525ec3553SMichael Tuexen 		to_ticks = sctp_msecs_to_ticks(to_ticks);
2316f8829a4aSRandall Stewart 		break;
2317f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
2318f8829a4aSRandall Stewart 		/*
2319f8829a4aSRandall Stewart 		 * Here we can use the RTO timer from the network since one
2320a412576eSMichael Tuexen 		 * RTT was complete. If a retransmission happened then we
2321a412576eSMichael Tuexen 		 * will be using the RTO initial value.
2322f8829a4aSRandall Stewart 		 */
2323a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2324a412576eSMichael Tuexen #ifdef INVARIANTS
2325a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2326a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2327a412576eSMichael Tuexen #else
2328ad81507eSRandall Stewart 			return;
2329a412576eSMichael Tuexen #endif
2330f8829a4aSRandall Stewart 		}
2331a412576eSMichael Tuexen 		tmr = &net->rxt_timer;
2332f8829a4aSRandall Stewart 		if (net->RTO == 0) {
233325ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(stcb->asoc.initial_rto);
2334f8829a4aSRandall Stewart 		} else {
233525ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(net->RTO);
2336f8829a4aSRandall Stewart 		}
2337f8829a4aSRandall Stewart 		break;
2338f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
2339f8829a4aSRandall Stewart 		/*
2340a412576eSMichael Tuexen 		 * Nothing needed but the endpoint here ususually about 60
2341f8829a4aSRandall Stewart 		 * minutes.
2342f8829a4aSRandall Stewart 		 */
2343a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb != NULL) || (net != NULL)) {
2344a412576eSMichael Tuexen #ifdef INVARIANTS
2345a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2346a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2347a412576eSMichael Tuexen #else
2348a412576eSMichael Tuexen 			return;
2349a412576eSMichael Tuexen #endif
2350a412576eSMichael Tuexen 		}
2351f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2352f8829a4aSRandall Stewart 		to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_SIGNATURE];
2353f8829a4aSRandall Stewart 		break;
2354f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
2355f8829a4aSRandall Stewart 		/*
2356a412576eSMichael Tuexen 		 * Here we use the value found in the EP for PMTUD,
2357a412576eSMichael Tuexen 		 * ususually about 10 minutes.
2358f8829a4aSRandall Stewart 		 */
2359a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2360a412576eSMichael Tuexen #ifdef INVARIANTS
2361a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2362a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2363a412576eSMichael Tuexen #else
2364ad81507eSRandall Stewart 			return;
2365a412576eSMichael Tuexen #endif
2366f8829a4aSRandall Stewart 		}
236780c79bbeSMichael Tuexen 		if (net->dest_state & SCTP_ADDR_NO_PMTUD) {
2368a412576eSMichael Tuexen 			SCTPDBG(SCTP_DEBUG_TIMER2,
236937686ccfSMichael Tuexen 			    "Timer type %d not started: inp=%p, stcb=%p, net=%p.\n",
2370a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
237180c79bbeSMichael Tuexen 			return;
237280c79bbeSMichael Tuexen 		}
2373f8829a4aSRandall Stewart 		tmr = &net->pmtu_timer;
2374a412576eSMichael Tuexen 		to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_PMTU];
2375f8829a4aSRandall Stewart 		break;
2376f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
2377a412576eSMichael Tuexen 		/* Here we use the RTO of the destination. */
2378a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2379a412576eSMichael Tuexen #ifdef INVARIANTS
2380a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2381a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2382a412576eSMichael Tuexen #else
2383ad81507eSRandall Stewart 			return;
2384a412576eSMichael Tuexen #endif
2385f8829a4aSRandall Stewart 		}
2386a412576eSMichael Tuexen 		tmr = &net->rxt_timer;
2387f8829a4aSRandall Stewart 		if (net->RTO == 0) {
238825ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(stcb->asoc.initial_rto);
2389f8829a4aSRandall Stewart 		} else {
239025ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(net->RTO);
2391f8829a4aSRandall Stewart 		}
2392f8829a4aSRandall Stewart 		break;
23930554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_ASCONF:
23940554e01dSMichael Tuexen 		/*
23950554e01dSMichael Tuexen 		 * Here the timer comes from the stcb but its value is from
23960554e01dSMichael Tuexen 		 * the net's RTO.
23970554e01dSMichael Tuexen 		 */
2398a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2399a412576eSMichael Tuexen #ifdef INVARIANTS
2400a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2401a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2402a412576eSMichael Tuexen #else
24030554e01dSMichael Tuexen 			return;
2404a412576eSMichael Tuexen #endif
24050554e01dSMichael Tuexen 		}
2406a412576eSMichael Tuexen 		tmr = &stcb->asoc.asconf_timer;
24070554e01dSMichael Tuexen 		if (net->RTO == 0) {
240825ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(stcb->asoc.initial_rto);
24090554e01dSMichael Tuexen 		} else {
241025ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(net->RTO);
24110554e01dSMichael Tuexen 		}
24120554e01dSMichael Tuexen 		break;
2413f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
2414f8829a4aSRandall Stewart 		/*
2415f8829a4aSRandall Stewart 		 * Here we use the endpoints shutdown guard timer usually
2416f8829a4aSRandall Stewart 		 * about 3 minutes.
2417f8829a4aSRandall Stewart 		 */
2418a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2419a412576eSMichael Tuexen #ifdef INVARIANTS
2420a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2421a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2422a412576eSMichael Tuexen #else
2423ad81507eSRandall Stewart 			return;
2424a412576eSMichael Tuexen #endif
2425f8829a4aSRandall Stewart 		}
2426a412576eSMichael Tuexen 		tmr = &stcb->asoc.shut_guard_timer;
24272e2d6794SMichael Tuexen 		if (inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_MAXSHUTDOWN] == 0) {
242825ec3553SMichael Tuexen 			if (stcb->asoc.maxrto < UINT32_MAX / 5) {
242925ec3553SMichael Tuexen 				to_ticks = sctp_msecs_to_ticks(5 * stcb->asoc.maxrto);
243025ec3553SMichael Tuexen 			} else {
243125ec3553SMichael Tuexen 				to_ticks = sctp_msecs_to_ticks(UINT32_MAX);
243225ec3553SMichael Tuexen 			}
24332e2d6794SMichael Tuexen 		} else {
2434f8829a4aSRandall Stewart 			to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_MAXSHUTDOWN];
24352e2d6794SMichael Tuexen 		}
2436f8829a4aSRandall Stewart 		break;
24370554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_AUTOCLOSE:
2438a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2439a412576eSMichael Tuexen #ifdef INVARIANTS
2440a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2441a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2442a412576eSMichael Tuexen #else
24430554e01dSMichael Tuexen 			return;
2444a412576eSMichael Tuexen #endif
24450554e01dSMichael Tuexen 		}
24460554e01dSMichael Tuexen 		tmr = &stcb->asoc.autoclose_timer;
2447a412576eSMichael Tuexen 		to_ticks = stcb->asoc.sctp_autoclose_ticks;
24480554e01dSMichael Tuexen 		break;
2449f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_STRRESET:
2450f8829a4aSRandall Stewart 		/*
24511b649582SRandall Stewart 		 * Here the timer comes from the stcb but its value is from
24521b649582SRandall Stewart 		 * the net's RTO.
2453f8829a4aSRandall Stewart 		 */
2454a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2455a412576eSMichael Tuexen #ifdef INVARIANTS
2456a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2457a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2458a412576eSMichael Tuexen #else
2459ad81507eSRandall Stewart 			return;
2460a412576eSMichael Tuexen #endif
2461f8829a4aSRandall Stewart 		}
2462a412576eSMichael Tuexen 		tmr = &stcb->asoc.strreset_timer;
2463f8829a4aSRandall Stewart 		if (net->RTO == 0) {
246425ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(stcb->asoc.initial_rto);
2465f8829a4aSRandall Stewart 		} else {
246625ec3553SMichael Tuexen 			to_ticks = sctp_msecs_to_ticks(net->RTO);
2467f8829a4aSRandall Stewart 		}
2468f8829a4aSRandall Stewart 		break;
24690554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_INPKILL:
2470f8829a4aSRandall Stewart 		/*
24710554e01dSMichael Tuexen 		 * The inp is setup to die. We re-use the signature_chage
24720554e01dSMichael Tuexen 		 * timer since that has stopped and we are in the GONE
24730554e01dSMichael Tuexen 		 * state.
2474f8829a4aSRandall Stewart 		 */
2475a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb != NULL) || (net != NULL)) {
2476a412576eSMichael Tuexen #ifdef INVARIANTS
2477a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2478a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2479a412576eSMichael Tuexen #else
2480a412576eSMichael Tuexen 			return;
2481a412576eSMichael Tuexen #endif
2482a412576eSMichael Tuexen 		}
24830554e01dSMichael Tuexen 		tmr = &inp->sctp_ep.signature_change;
248425ec3553SMichael Tuexen 		to_ticks = sctp_msecs_to_ticks(SCTP_INP_KILL_TIMEOUT);
24850554e01dSMichael Tuexen 		break;
24860554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_ASOCKILL:
2487a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2488a412576eSMichael Tuexen #ifdef INVARIANTS
2489a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2490a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2491a412576eSMichael Tuexen #else
2492ad81507eSRandall Stewart 			return;
2493a412576eSMichael Tuexen #endif
2494f8829a4aSRandall Stewart 		}
24950554e01dSMichael Tuexen 		tmr = &stcb->asoc.strreset_timer;
249625ec3553SMichael Tuexen 		to_ticks = sctp_msecs_to_ticks(SCTP_ASOC_KILL_TIMEOUT);
24970554e01dSMichael Tuexen 		break;
24980554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_ADDR_WQ:
2499a412576eSMichael Tuexen 		if ((inp != NULL) || (stcb != NULL) || (net != NULL)) {
2500a412576eSMichael Tuexen #ifdef INVARIANTS
2501a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2502a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2503a412576eSMichael Tuexen #else
2504a412576eSMichael Tuexen 			return;
2505a412576eSMichael Tuexen #endif
2506a412576eSMichael Tuexen 		}
25070554e01dSMichael Tuexen 		/* Only 1 tick away :-) */
25080554e01dSMichael Tuexen 		tmr = &SCTP_BASE_INFO(addr_wq_timer);
25090554e01dSMichael Tuexen 		to_ticks = SCTP_ADDRESS_TICK_DELAY;
2510f8829a4aSRandall Stewart 		break;
2511851b7298SRandall Stewart 	case SCTP_TIMER_TYPE_PRIM_DELETED:
2512a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2513a412576eSMichael Tuexen #ifdef INVARIANTS
2514a412576eSMichael Tuexen 			panic("sctp_timer_start of type %d: inp = %p, stcb = %p, net = %p",
2515a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2516a412576eSMichael Tuexen #else
2517851b7298SRandall Stewart 			return;
2518a412576eSMichael Tuexen #endif
2519851b7298SRandall Stewart 		}
2520851b7298SRandall Stewart 		tmr = &stcb->asoc.delete_prim_timer;
252125ec3553SMichael Tuexen 		to_ticks = sctp_msecs_to_ticks(stcb->asoc.initial_rto);
2522851b7298SRandall Stewart 		break;
2523f8829a4aSRandall Stewart 	default:
25247522682eSMichael Tuexen #ifdef INVARIANTS
2525a412576eSMichael Tuexen 		panic("Unknown timer type %d", t_type);
25267522682eSMichael Tuexen #else
25277522682eSMichael Tuexen 		return;
25287522682eSMichael Tuexen #endif
252960990c0cSMichael Tuexen 	}
2530a412576eSMichael Tuexen 	KASSERT(tmr != NULL, ("tmr is NULL for timer type %d", t_type));
2531a412576eSMichael Tuexen 	KASSERT(to_ticks > 0, ("to_ticks == 0 for timer type %d", t_type));
2532139bc87fSRandall Stewart 	if (SCTP_OS_TIMER_PENDING(&tmr->timer)) {
2533f8829a4aSRandall Stewart 		/*
2534a412576eSMichael Tuexen 		 * We do NOT allow you to have it already running. If it is,
2535a412576eSMichael Tuexen 		 * we leave the current one up unchanged.
2536f8829a4aSRandall Stewart 		 */
2537a412576eSMichael Tuexen 		SCTPDBG(SCTP_DEBUG_TIMER2,
253837686ccfSMichael Tuexen 		    "Timer type %d already running: inp=%p, stcb=%p, net=%p.\n",
2539a412576eSMichael Tuexen 		    t_type, inp, stcb, net);
2540ad81507eSRandall Stewart 		return;
2541f8829a4aSRandall Stewart 	}
2542a412576eSMichael Tuexen 	/* At this point we can proceed. */
2543f8829a4aSRandall Stewart 	if (t_type == SCTP_TIMER_TYPE_SEND) {
2544f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up++;
2545f8829a4aSRandall Stewart 	}
2546a5d547adSRandall Stewart 	tmr->stopped_from = 0;
2547f8829a4aSRandall Stewart 	tmr->type = t_type;
2548f8829a4aSRandall Stewart 	tmr->ep = (void *)inp;
2549f8829a4aSRandall Stewart 	tmr->tcb = (void *)stcb;
2550a412576eSMichael Tuexen 	if (t_type == SCTP_TIMER_TYPE_STRRESET) {
2551a412576eSMichael Tuexen 		tmr->net = NULL;
2552a412576eSMichael Tuexen 	} else {
2553f8829a4aSRandall Stewart 		tmr->net = (void *)net;
2554a412576eSMichael Tuexen 	}
2555f8829a4aSRandall Stewart 	tmr->self = (void *)tmr;
25568518270eSMichael Tuexen 	tmr->vnet = (void *)curvnet;
2557c4739e2fSRandall Stewart 	tmr->ticks = sctp_get_tick_count();
2558a412576eSMichael Tuexen 	if (SCTP_OS_TIMER_START(&tmr->timer, to_ticks, sctp_timeout_handler, tmr) == 0) {
2559a412576eSMichael Tuexen 		SCTPDBG(SCTP_DEBUG_TIMER2,
256037686ccfSMichael Tuexen 		    "Timer type %d started: ticks=%u, inp=%p, stcb=%p, net=%p.\n",
2561a412576eSMichael Tuexen 		    t_type, to_ticks, inp, stcb, net);
25628745f898SMichael Tuexen 		/*
25638745f898SMichael Tuexen 		 * If this is a newly scheduled callout, as opposed to a
25648745f898SMichael Tuexen 		 * rescheduled one, increment relevant reference counts.
25658745f898SMichael Tuexen 		 */
25668745f898SMichael Tuexen 		if (tmr->ep != NULL) {
25678745f898SMichael Tuexen 			SCTP_INP_INCR_REF(inp);
25688745f898SMichael Tuexen 		}
25698745f898SMichael Tuexen 		if (tmr->tcb != NULL) {
25708745f898SMichael Tuexen 			atomic_add_int(&stcb->asoc.refcnt, 1);
25718745f898SMichael Tuexen 		}
25728745f898SMichael Tuexen 		if (tmr->net != NULL) {
25738745f898SMichael Tuexen 			atomic_add_int(&net->ref_count, 1);
25748745f898SMichael Tuexen 		}
2575a412576eSMichael Tuexen 	} else {
2576a412576eSMichael Tuexen 		/*
2577a412576eSMichael Tuexen 		 * This should not happen, since we checked for pending
2578a412576eSMichael Tuexen 		 * above.
2579a412576eSMichael Tuexen 		 */
2580a412576eSMichael Tuexen 		SCTPDBG(SCTP_DEBUG_TIMER2,
258137686ccfSMichael Tuexen 		    "Timer type %d restarted: ticks=%u, inp=%p, stcb=%p, net=%p.\n",
2582a412576eSMichael Tuexen 		    t_type, to_ticks, inp, stcb, net);
2583a412576eSMichael Tuexen 	}
2584ad81507eSRandall Stewart 	return;
2585f8829a4aSRandall Stewart }
2586f8829a4aSRandall Stewart 
2587a412576eSMichael Tuexen /*-
2588a412576eSMichael Tuexen  * The following table shows which parameters must be provided
2589a412576eSMichael Tuexen  * when calling sctp_timer_stop(). For parameters not being
2590a412576eSMichael Tuexen  * provided, NULL must be used.
2591a412576eSMichael Tuexen  *
2592a412576eSMichael Tuexen  * |Name                         |inp |stcb|net |
2593a412576eSMichael Tuexen  * |-----------------------------|----|----|----|
2594a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_SEND         |Yes |Yes |Yes |
2595a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_INIT         |Yes |Yes |Yes |
2596a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_RECV         |Yes |Yes |No  |
2597a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_SHUTDOWN     |Yes |Yes |Yes |
2598a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_HEARTBEAT    |Yes |Yes |Yes |
2599a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_COOKIE       |Yes |Yes |Yes |
2600a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_NEWCOOKIE    |Yes |No  |No  |
2601a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_PATHMTURAISE |Yes |Yes |Yes |
2602a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_SHUTDOWNACK  |Yes |Yes |Yes |
2603a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_ASCONF       |Yes |Yes |No  |
2604a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_SHUTDOWNGUARD|Yes |Yes |No  |
2605a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_AUTOCLOSE    |Yes |Yes |No  |
2606a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_STRRESET     |Yes |Yes |No  |
2607a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_INPKILL      |Yes |No  |No  |
2608a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_ASOCKILL     |Yes |Yes |No  |
2609a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_ADDR_WQ      |No  |No  |No  |
2610a412576eSMichael Tuexen  * |SCTP_TIMER_TYPE_PRIM_DELETED |Yes |Yes |No  |
2611a412576eSMichael Tuexen  *
2612a412576eSMichael Tuexen  */
2613a412576eSMichael Tuexen 
26146e55db54SRandall Stewart void
2615f8829a4aSRandall Stewart sctp_timer_stop(int t_type, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
2616a5d547adSRandall Stewart     struct sctp_nets *net, uint32_t from)
2617f8829a4aSRandall Stewart {
2618f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
2619f8829a4aSRandall Stewart 
2620f4cb790aSMichael Tuexen 	KASSERT(stcb == NULL || stcb->sctp_ep == inp,
2621f4cb790aSMichael Tuexen 	    ("sctp_timer_stop of type %d: inp = %p, stcb->sctp_ep %p",
2622f4cb790aSMichael Tuexen 	    t_type, stcb, stcb->sctp_ep));
2623a412576eSMichael Tuexen 	if (stcb != NULL) {
2624f8829a4aSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
2625a412576eSMichael Tuexen 	} else if (inp != NULL) {
2626a412576eSMichael Tuexen 		SCTP_INP_WLOCK_ASSERT(inp);
2627a412576eSMichael Tuexen 	} else {
2628a412576eSMichael Tuexen 		SCTP_WQ_ADDR_LOCK_ASSERT();
2629f8829a4aSRandall Stewart 	}
2630a412576eSMichael Tuexen 	tmr = NULL;
2631f8829a4aSRandall Stewart 	switch (t_type) {
2632f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
2633a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2634a412576eSMichael Tuexen #ifdef INVARIANTS
2635a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2636a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2637a412576eSMichael Tuexen #else
26386e55db54SRandall Stewart 			return;
2639a412576eSMichael Tuexen #endif
2640f8829a4aSRandall Stewart 		}
2641f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2642f8829a4aSRandall Stewart 		break;
2643f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
2644a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2645a412576eSMichael Tuexen #ifdef INVARIANTS
2646a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2647a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2648a412576eSMichael Tuexen #else
26496e55db54SRandall Stewart 			return;
2650a412576eSMichael Tuexen #endif
2651f8829a4aSRandall Stewart 		}
2652f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2653f8829a4aSRandall Stewart 		break;
2654f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
2655a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2656a412576eSMichael Tuexen #ifdef INVARIANTS
2657a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2658a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2659a412576eSMichael Tuexen #else
26606e55db54SRandall Stewart 			return;
2661a412576eSMichael Tuexen #endif
2662f8829a4aSRandall Stewart 		}
2663f8829a4aSRandall Stewart 		tmr = &stcb->asoc.dack_timer;
2664f8829a4aSRandall Stewart 		break;
2665f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
2666a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2667a412576eSMichael Tuexen #ifdef INVARIANTS
2668a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2669a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2670a412576eSMichael Tuexen #else
26716e55db54SRandall Stewart 			return;
2672a412576eSMichael Tuexen #endif
2673f8829a4aSRandall Stewart 		}
2674f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2675f8829a4aSRandall Stewart 		break;
2676f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
2677a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2678a412576eSMichael Tuexen #ifdef INVARIANTS
2679a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2680a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2681a412576eSMichael Tuexen #else
26826e55db54SRandall Stewart 			return;
2683a412576eSMichael Tuexen #endif
2684f8829a4aSRandall Stewart 		}
2685ca85e948SMichael Tuexen 		tmr = &net->hb_timer;
2686f8829a4aSRandall Stewart 		break;
2687f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
2688a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2689a412576eSMichael Tuexen #ifdef INVARIANTS
2690a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2691a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2692a412576eSMichael Tuexen #else
26936e55db54SRandall Stewart 			return;
2694a412576eSMichael Tuexen #endif
2695f8829a4aSRandall Stewart 		}
2696f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2697f8829a4aSRandall Stewart 		break;
2698f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
2699a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb != NULL) || (net != NULL)) {
2700a412576eSMichael Tuexen #ifdef INVARIANTS
2701a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2702a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2703a412576eSMichael Tuexen #else
2704a412576eSMichael Tuexen 			return;
2705a412576eSMichael Tuexen #endif
2706a412576eSMichael Tuexen 		}
2707f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2708f8829a4aSRandall Stewart 		break;
2709f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
2710a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2711a412576eSMichael Tuexen #ifdef INVARIANTS
2712a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2713a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2714a412576eSMichael Tuexen #else
27156e55db54SRandall Stewart 			return;
2716a412576eSMichael Tuexen #endif
2717f8829a4aSRandall Stewart 		}
2718f8829a4aSRandall Stewart 		tmr = &net->pmtu_timer;
2719f8829a4aSRandall Stewart 		break;
2720f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
2721a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net == NULL)) {
2722a412576eSMichael Tuexen #ifdef INVARIANTS
2723a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2724a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2725a412576eSMichael Tuexen #else
27266e55db54SRandall Stewart 			return;
2727a412576eSMichael Tuexen #endif
2728f8829a4aSRandall Stewart 		}
2729f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2730f8829a4aSRandall Stewart 		break;
27310554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_ASCONF:
2732a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2733a412576eSMichael Tuexen #ifdef INVARIANTS
2734a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2735a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2736a412576eSMichael Tuexen #else
27370554e01dSMichael Tuexen 			return;
2738a412576eSMichael Tuexen #endif
27390554e01dSMichael Tuexen 		}
27400554e01dSMichael Tuexen 		tmr = &stcb->asoc.asconf_timer;
27410554e01dSMichael Tuexen 		break;
2742f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
2743a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2744a412576eSMichael Tuexen #ifdef INVARIANTS
2745a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2746a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2747a412576eSMichael Tuexen #else
27486e55db54SRandall Stewart 			return;
2749a412576eSMichael Tuexen #endif
2750f8829a4aSRandall Stewart 		}
2751f8829a4aSRandall Stewart 		tmr = &stcb->asoc.shut_guard_timer;
2752f8829a4aSRandall Stewart 		break;
27530554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_AUTOCLOSE:
2754a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2755a412576eSMichael Tuexen #ifdef INVARIANTS
2756a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2757a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2758a412576eSMichael Tuexen #else
27590554e01dSMichael Tuexen 			return;
2760a412576eSMichael Tuexen #endif
27610554e01dSMichael Tuexen 		}
27620554e01dSMichael Tuexen 		tmr = &stcb->asoc.autoclose_timer;
27630554e01dSMichael Tuexen 		break;
2764f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_STRRESET:
2765a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2766a412576eSMichael Tuexen #ifdef INVARIANTS
2767a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2768a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2769a412576eSMichael Tuexen #else
27706e55db54SRandall Stewart 			return;
2771a412576eSMichael Tuexen #endif
2772f8829a4aSRandall Stewart 		}
2773f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2774f8829a4aSRandall Stewart 		break;
27750554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_INPKILL:
27760554e01dSMichael Tuexen 		/*
27770554e01dSMichael Tuexen 		 * The inp is setup to die. We re-use the signature_chage
27780554e01dSMichael Tuexen 		 * timer since that has stopped and we are in the GONE
27790554e01dSMichael Tuexen 		 * state.
27800554e01dSMichael Tuexen 		 */
2781a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb != NULL) || (net != NULL)) {
2782a412576eSMichael Tuexen #ifdef INVARIANTS
2783a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2784a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2785a412576eSMichael Tuexen #else
2786a412576eSMichael Tuexen 			return;
2787a412576eSMichael Tuexen #endif
2788a412576eSMichael Tuexen 		}
27890554e01dSMichael Tuexen 		tmr = &inp->sctp_ep.signature_change;
27900554e01dSMichael Tuexen 		break;
27910554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_ASOCKILL:
2792a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2793a412576eSMichael Tuexen #ifdef INVARIANTS
2794a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2795a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2796a412576eSMichael Tuexen #else
27976e55db54SRandall Stewart 			return;
2798a412576eSMichael Tuexen #endif
2799f8829a4aSRandall Stewart 		}
28000554e01dSMichael Tuexen 		tmr = &stcb->asoc.strreset_timer;
28010554e01dSMichael Tuexen 		break;
28020554e01dSMichael Tuexen 	case SCTP_TIMER_TYPE_ADDR_WQ:
2803a412576eSMichael Tuexen 		if ((inp != NULL) || (stcb != NULL) || (net != NULL)) {
2804a412576eSMichael Tuexen #ifdef INVARIANTS
2805a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2806a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2807a412576eSMichael Tuexen #else
2808a412576eSMichael Tuexen 			return;
2809a412576eSMichael Tuexen #endif
2810a412576eSMichael Tuexen 		}
28110554e01dSMichael Tuexen 		tmr = &SCTP_BASE_INFO(addr_wq_timer);
2812f8829a4aSRandall Stewart 		break;
2813851b7298SRandall Stewart 	case SCTP_TIMER_TYPE_PRIM_DELETED:
2814a412576eSMichael Tuexen 		if ((inp == NULL) || (stcb == NULL) || (net != NULL)) {
2815a412576eSMichael Tuexen #ifdef INVARIANTS
2816a412576eSMichael Tuexen 			panic("sctp_timer_stop of type %d: inp = %p, stcb = %p, net = %p",
2817a412576eSMichael Tuexen 			    t_type, inp, stcb, net);
2818a412576eSMichael Tuexen #else
2819851b7298SRandall Stewart 			return;
2820a412576eSMichael Tuexen #endif
2821851b7298SRandall Stewart 		}
2822851b7298SRandall Stewart 		tmr = &stcb->asoc.delete_prim_timer;
2823851b7298SRandall Stewart 		break;
2824f8829a4aSRandall Stewart 	default:
28257522682eSMichael Tuexen #ifdef INVARIANTS
2826a412576eSMichael Tuexen 		panic("Unknown timer type %d", t_type);
28277522682eSMichael Tuexen #else
28287522682eSMichael Tuexen 		return;
28297522682eSMichael Tuexen #endif
283060990c0cSMichael Tuexen 	}
2831a412576eSMichael Tuexen 	KASSERT(tmr != NULL, ("tmr is NULL for timer type %d", t_type));
2832a412576eSMichael Tuexen 	if ((tmr->type != SCTP_TIMER_TYPE_NONE) &&
2833a412576eSMichael Tuexen 	    (tmr->type != t_type)) {
2834f8829a4aSRandall Stewart 		/*
2835f8829a4aSRandall Stewart 		 * Ok we have a timer that is under joint use. Cookie timer
2836f8829a4aSRandall Stewart 		 * per chance with the SEND timer. We therefore are NOT
2837f8829a4aSRandall Stewart 		 * running the timer that the caller wants stopped.  So just
2838f8829a4aSRandall Stewart 		 * return.
2839f8829a4aSRandall Stewart 		 */
2840a412576eSMichael Tuexen 		SCTPDBG(SCTP_DEBUG_TIMER2,
284137686ccfSMichael Tuexen 		    "Shared timer type %d not running: inp=%p, stcb=%p, net=%p.\n",
2842a412576eSMichael Tuexen 		    t_type, inp, stcb, net);
28436e55db54SRandall Stewart 		return;
2844f8829a4aSRandall Stewart 	}
2845ad81507eSRandall Stewart 	if ((t_type == SCTP_TIMER_TYPE_SEND) && (stcb != NULL)) {
2846f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up--;
2847f8829a4aSRandall Stewart 		if (stcb->asoc.num_send_timers_up < 0) {
2848f8829a4aSRandall Stewart 			stcb->asoc.num_send_timers_up = 0;
2849f8829a4aSRandall Stewart 		}
2850f8829a4aSRandall Stewart 	}
2851f8829a4aSRandall Stewart 	tmr->self = NULL;
2852a5d547adSRandall Stewart 	tmr->stopped_from = from;
2853a412576eSMichael Tuexen 	if (SCTP_OS_TIMER_STOP(&tmr->timer) == 1) {
2854a412576eSMichael Tuexen 		KASSERT(tmr->ep == inp,
2855a412576eSMichael Tuexen 		    ("sctp_timer_stop of type %d: inp = %p, tmr->inp = %p",
2856a412576eSMichael Tuexen 		    t_type, inp, tmr->ep));
2857a412576eSMichael Tuexen 		KASSERT(tmr->tcb == stcb,
2858a412576eSMichael Tuexen 		    ("sctp_timer_stop of type %d: stcb = %p, tmr->stcb = %p",
2859a412576eSMichael Tuexen 		    t_type, stcb, tmr->tcb));
2860a412576eSMichael Tuexen 		KASSERT(((t_type == SCTP_TIMER_TYPE_ASCONF) && (tmr->net != NULL)) ||
2861a412576eSMichael Tuexen 		    ((t_type != SCTP_TIMER_TYPE_ASCONF) && (tmr->net == net)),
2862a412576eSMichael Tuexen 		    ("sctp_timer_stop of type %d: net = %p, tmr->net = %p",
2863a412576eSMichael Tuexen 		    t_type, net, tmr->net));
2864a412576eSMichael Tuexen 		SCTPDBG(SCTP_DEBUG_TIMER2,
286537686ccfSMichael Tuexen 		    "Timer type %d stopped: inp=%p, stcb=%p, net=%p.\n",
2866a412576eSMichael Tuexen 		    t_type, inp, stcb, net);
28678745f898SMichael Tuexen 		/*
28688745f898SMichael Tuexen 		 * If the timer was actually stopped, decrement reference
28698745f898SMichael Tuexen 		 * counts that were incremented in sctp_timer_start().
28708745f898SMichael Tuexen 		 */
28718745f898SMichael Tuexen 		if (tmr->ep != NULL) {
28728745f898SMichael Tuexen 			SCTP_INP_DECR_REF(inp);
2873a412576eSMichael Tuexen 			tmr->ep = NULL;
28748745f898SMichael Tuexen 		}
28758745f898SMichael Tuexen 		if (tmr->tcb != NULL) {
28763c1ba6f3SMichael Tuexen 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
2877a412576eSMichael Tuexen 			tmr->tcb = NULL;
28788745f898SMichael Tuexen 		}
28798745f898SMichael Tuexen 		if (tmr->net != NULL) {
28808745f898SMichael Tuexen 			/*
28818745f898SMichael Tuexen 			 * Can't use net, since it doesn't work for
28828745f898SMichael Tuexen 			 * SCTP_TIMER_TYPE_ASCONF.
28838745f898SMichael Tuexen 			 */
28848745f898SMichael Tuexen 			sctp_free_remote_addr((struct sctp_nets *)tmr->net);
2885a412576eSMichael Tuexen 			tmr->net = NULL;
28868745f898SMichael Tuexen 		}
2887a412576eSMichael Tuexen 	} else {
2888a412576eSMichael Tuexen 		SCTPDBG(SCTP_DEBUG_TIMER2,
288937686ccfSMichael Tuexen 		    "Timer type %d not stopped: inp=%p, stcb=%p, net=%p.\n",
2890a412576eSMichael Tuexen 		    t_type, inp, stcb, net);
2891a412576eSMichael Tuexen 	}
28926e55db54SRandall Stewart 	return;
2893f8829a4aSRandall Stewart }
2894f8829a4aSRandall Stewart 
2895f8829a4aSRandall Stewart uint32_t
2896b0471b4bSMichael Tuexen sctp_calculate_len(struct mbuf *m)
2897b0471b4bSMichael Tuexen {
2898f8829a4aSRandall Stewart 	struct mbuf *at;
2899*34ae6a1aSMichael Tuexen 	uint32_t tlen;
2900f8829a4aSRandall Stewart 
2901*34ae6a1aSMichael Tuexen 	tlen = 0;
2902*34ae6a1aSMichael Tuexen 	for (at = m; at != NULL; at = SCTP_BUF_NEXT(at)) {
2903139bc87fSRandall Stewart 		tlen += SCTP_BUF_LEN(at);
2904f8829a4aSRandall Stewart 	}
2905f8829a4aSRandall Stewart 	return (tlen);
2906f8829a4aSRandall Stewart }
2907f8829a4aSRandall Stewart 
2908f8829a4aSRandall Stewart void
2909f8829a4aSRandall Stewart sctp_mtu_size_reset(struct sctp_inpcb *inp,
291044b7479bSRandall Stewart     struct sctp_association *asoc, uint32_t mtu)
2911f8829a4aSRandall Stewart {
2912f8829a4aSRandall Stewart 	/*
2913f8829a4aSRandall Stewart 	 * Reset the P-MTU size on this association, this involves changing
2914f8829a4aSRandall Stewart 	 * the asoc MTU, going through ANY chunk+overhead larger than mtu to
2915f8829a4aSRandall Stewart 	 * allow the DF flag to be cleared.
2916f8829a4aSRandall Stewart 	 */
2917f8829a4aSRandall Stewart 	struct sctp_tmit_chunk *chk;
2918f8829a4aSRandall Stewart 	unsigned int eff_mtu, ovh;
2919f8829a4aSRandall Stewart 
2920f8829a4aSRandall Stewart 	asoc->smallest_mtu = mtu;
2921f8829a4aSRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) {
2922f8829a4aSRandall Stewart 		ovh = SCTP_MIN_OVERHEAD;
2923f8829a4aSRandall Stewart 	} else {
2924f8829a4aSRandall Stewart 		ovh = SCTP_MIN_V4_OVERHEAD;
2925f8829a4aSRandall Stewart 	}
2926f8829a4aSRandall Stewart 	eff_mtu = mtu - ovh;
2927f8829a4aSRandall Stewart 	TAILQ_FOREACH(chk, &asoc->send_queue, sctp_next) {
2928f8829a4aSRandall Stewart 		if (chk->send_size > eff_mtu) {
2929f8829a4aSRandall Stewart 			chk->flags |= CHUNK_FLAGS_FRAGMENT_OK;
2930f8829a4aSRandall Stewart 		}
2931f8829a4aSRandall Stewart 	}
2932f8829a4aSRandall Stewart 	TAILQ_FOREACH(chk, &asoc->sent_queue, sctp_next) {
2933f8829a4aSRandall Stewart 		if (chk->send_size > eff_mtu) {
2934f8829a4aSRandall Stewart 			chk->flags |= CHUNK_FLAGS_FRAGMENT_OK;
2935f8829a4aSRandall Stewart 		}
2936f8829a4aSRandall Stewart 	}
2937f8829a4aSRandall Stewart }
2938f8829a4aSRandall Stewart 
2939f8829a4aSRandall Stewart /*
294044f2a327SMichael Tuexen  * Given an association and starting time of the current RTT period, update
294144f2a327SMichael Tuexen  * RTO in number of msecs. net should point to the current network.
294244f2a327SMichael Tuexen  * Return 1, if an RTO update was performed, return 0 if no update was
294344f2a327SMichael Tuexen  * performed due to invalid starting point.
2944f8829a4aSRandall Stewart  */
2945899288aeSRandall Stewart 
294644f2a327SMichael Tuexen int
2947f8829a4aSRandall Stewart sctp_calculate_rto(struct sctp_tcb *stcb,
2948f8829a4aSRandall Stewart     struct sctp_association *asoc,
2949f8829a4aSRandall Stewart     struct sctp_nets *net,
29508c8e10b7SMichael Tuexen     struct timeval *old,
2951b0471b4bSMichael Tuexen     int rtt_from_sack)
2952b0471b4bSMichael Tuexen {
295344f2a327SMichael Tuexen 	struct timeval now;
295444f2a327SMichael Tuexen 	uint64_t rtt_us;	/* RTT in us */
2955be1d9176SMichael Tuexen 	int32_t rtt;		/* RTT in ms */
2956be1d9176SMichael Tuexen 	uint32_t new_rto;
2957f8829a4aSRandall Stewart 	int first_measure = 0;
2958f8829a4aSRandall Stewart 
2959f8829a4aSRandall Stewart 	/************************/
2960f8829a4aSRandall Stewart 	/* 1. calculate new RTT */
2961f8829a4aSRandall Stewart 	/************************/
2962f8829a4aSRandall Stewart 	/* get the current time */
2963299108c5SRandall Stewart 	if (stcb->asoc.use_precise_time) {
2964299108c5SRandall Stewart 		(void)SCTP_GETPTIME_TIMEVAL(&now);
2965299108c5SRandall Stewart 	} else {
29666e55db54SRandall Stewart 		(void)SCTP_GETTIME_TIMEVAL(&now);
2967299108c5SRandall Stewart 	}
296844f2a327SMichael Tuexen 	if ((old->tv_sec > now.tv_sec) ||
296988116b7eSMichael Tuexen 	    ((old->tv_sec == now.tv_sec) && (old->tv_usec > now.tv_usec))) {
297044f2a327SMichael Tuexen 		/* The starting point is in the future. */
297144f2a327SMichael Tuexen 		return (0);
297244f2a327SMichael Tuexen 	}
2973be1d9176SMichael Tuexen 	timevalsub(&now, old);
297444f2a327SMichael Tuexen 	rtt_us = (uint64_t)1000000 * (uint64_t)now.tv_sec + (uint64_t)now.tv_usec;
297544f2a327SMichael Tuexen 	if (rtt_us > SCTP_RTO_UPPER_BOUND * 1000) {
297644f2a327SMichael Tuexen 		/* The RTT is larger than a sane value. */
297744f2a327SMichael Tuexen 		return (0);
297844f2a327SMichael Tuexen 	}
2979be1d9176SMichael Tuexen 	/* store the current RTT in us */
298044f2a327SMichael Tuexen 	net->rtt = rtt_us;
2981b60b0fe6SMichael Tuexen 	/* compute rtt in ms */
2982b60b0fe6SMichael Tuexen 	rtt = (int32_t)(net->rtt / 1000);
2983f79aab18SRandall Stewart 	if ((asoc->cc_functions.sctp_rtt_calculated) && (rtt_from_sack == SCTP_RTT_FROM_DATA)) {
2984b7b84c0eSMichael Tuexen 		/*
2985b7b84c0eSMichael Tuexen 		 * Tell the CC module that a new update has just occurred
2986b7b84c0eSMichael Tuexen 		 * from a sack
2987b7b84c0eSMichael Tuexen 		 */
2988f79aab18SRandall Stewart 		(*asoc->cc_functions.sctp_rtt_calculated) (stcb, net, &now);
2989f79aab18SRandall Stewart 	}
2990f79aab18SRandall Stewart 	/*
2991f79aab18SRandall Stewart 	 * Do we need to determine the lan? We do this only on sacks i.e.
2992f79aab18SRandall Stewart 	 * RTT being determined from data not non-data (HB/INIT->INITACK).
2993f79aab18SRandall Stewart 	 */
2994f79aab18SRandall Stewart 	if ((rtt_from_sack == SCTP_RTT_FROM_DATA) &&
2995be1d9176SMichael Tuexen 	    (net->lan_type == SCTP_LAN_UNKNOWN)) {
2996be1d9176SMichael Tuexen 		if (net->rtt > SCTP_LOCAL_LAN_RTT) {
2997899288aeSRandall Stewart 			net->lan_type = SCTP_LAN_INTERNET;
2998899288aeSRandall Stewart 		} else {
2999899288aeSRandall Stewart 			net->lan_type = SCTP_LAN_LOCAL;
3000899288aeSRandall Stewart 		}
3001899288aeSRandall Stewart 	}
30020053ed28SMichael Tuexen 
3003f8829a4aSRandall Stewart 	/***************************/
3004f8829a4aSRandall Stewart 	/* 2. update RTTVAR & SRTT */
3005f8829a4aSRandall Stewart 	/***************************/
3006be1d9176SMichael Tuexen 	/*-
3007be1d9176SMichael Tuexen 	 * Compute the scaled average lastsa and the
3008be1d9176SMichael Tuexen 	 * scaled variance lastsv as described in van Jacobson
3009be1d9176SMichael Tuexen 	 * Paper "Congestion Avoidance and Control", Annex A.
3010be1d9176SMichael Tuexen 	 *
3011be1d9176SMichael Tuexen 	 * (net->lastsa >> SCTP_RTT_SHIFT) is the srtt
301244f2a327SMichael Tuexen 	 * (net->lastsv >> SCTP_RTT_VAR_SHIFT) is the rttvar
3013be1d9176SMichael Tuexen 	 */
30149a972525SRandall Stewart 	if (net->RTO_measured) {
3015be1d9176SMichael Tuexen 		rtt -= (net->lastsa >> SCTP_RTT_SHIFT);
3016be1d9176SMichael Tuexen 		net->lastsa += rtt;
3017be1d9176SMichael Tuexen 		if (rtt < 0) {
3018be1d9176SMichael Tuexen 			rtt = -rtt;
3019be1d9176SMichael Tuexen 		}
3020be1d9176SMichael Tuexen 		rtt -= (net->lastsv >> SCTP_RTT_VAR_SHIFT);
3021be1d9176SMichael Tuexen 		net->lastsv += rtt;
3022b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RTTVAR_LOGGING_ENABLE) {
3023f8829a4aSRandall Stewart 			rto_logging(net, SCTP_LOG_RTTVAR);
302480fefe0aSRandall Stewart 		}
3025f8829a4aSRandall Stewart 	} else {
3026f8829a4aSRandall Stewart 		/* First RTO measurment */
30279a972525SRandall Stewart 		net->RTO_measured = 1;
3028f8829a4aSRandall Stewart 		first_measure = 1;
3029be1d9176SMichael Tuexen 		net->lastsa = rtt << SCTP_RTT_SHIFT;
3030be1d9176SMichael Tuexen 		net->lastsv = (rtt / 2) << SCTP_RTT_VAR_SHIFT;
3031b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RTTVAR_LOGGING_ENABLE) {
3032f8829a4aSRandall Stewart 			rto_logging(net, SCTP_LOG_INITIAL_RTT);
303380fefe0aSRandall Stewart 		}
3034f8829a4aSRandall Stewart 	}
3035be1d9176SMichael Tuexen 	if (net->lastsv == 0) {
3036be1d9176SMichael Tuexen 		net->lastsv = SCTP_CLOCK_GRANULARITY;
3037be1d9176SMichael Tuexen 	}
3038108df27cSRandall Stewart 	new_rto = (net->lastsa >> SCTP_RTT_SHIFT) + net->lastsv;
3039f8829a4aSRandall Stewart 	if ((new_rto > SCTP_SAT_NETWORK_MIN) &&
3040f8829a4aSRandall Stewart 	    (stcb->asoc.sat_network_lockout == 0)) {
3041f8829a4aSRandall Stewart 		stcb->asoc.sat_network = 1;
3042f8829a4aSRandall Stewart 	} else if ((!first_measure) && stcb->asoc.sat_network) {
3043f8829a4aSRandall Stewart 		stcb->asoc.sat_network = 0;
3044f8829a4aSRandall Stewart 		stcb->asoc.sat_network_lockout = 1;
3045f8829a4aSRandall Stewart 	}
3046f8829a4aSRandall Stewart 	/* bound it, per C6/C7 in Section 5.3.1 */
3047f8829a4aSRandall Stewart 	if (new_rto < stcb->asoc.minrto) {
3048f8829a4aSRandall Stewart 		new_rto = stcb->asoc.minrto;
3049f8829a4aSRandall Stewart 	}
3050f8829a4aSRandall Stewart 	if (new_rto > stcb->asoc.maxrto) {
3051f8829a4aSRandall Stewart 		new_rto = stcb->asoc.maxrto;
3052f8829a4aSRandall Stewart 	}
305344f2a327SMichael Tuexen 	net->RTO = new_rto;
305444f2a327SMichael Tuexen 	return (1);
3055f8829a4aSRandall Stewart }
3056f8829a4aSRandall Stewart 
3057f8829a4aSRandall Stewart /*
3058f8829a4aSRandall Stewart  * return a pointer to a contiguous piece of data from the given mbuf chain
3059f8829a4aSRandall Stewart  * starting at 'off' for 'len' bytes.  If the desired piece spans more than
3060f8829a4aSRandall Stewart  * one mbuf, a copy is made at 'ptr'. caller must ensure that the buffer size
3061f8829a4aSRandall Stewart  * is >= 'len' returns NULL if there there isn't 'len' bytes in the chain.
3062f8829a4aSRandall Stewart  */
306372fb6fdbSRandall Stewart caddr_t
3064f8829a4aSRandall Stewart sctp_m_getptr(struct mbuf *m, int off, int len, uint8_t *in_ptr)
3065f8829a4aSRandall Stewart {
3066f8829a4aSRandall Stewart 	uint32_t count;
3067f8829a4aSRandall Stewart 	uint8_t *ptr;
3068f8829a4aSRandall Stewart 
3069f8829a4aSRandall Stewart 	ptr = in_ptr;
3070f8829a4aSRandall Stewart 	if ((off < 0) || (len <= 0))
3071f8829a4aSRandall Stewart 		return (NULL);
3072f8829a4aSRandall Stewart 
3073f8829a4aSRandall Stewart 	/* find the desired start location */
3074f8829a4aSRandall Stewart 	while ((m != NULL) && (off > 0)) {
3075139bc87fSRandall Stewart 		if (off < SCTP_BUF_LEN(m))
3076f8829a4aSRandall Stewart 			break;
3077139bc87fSRandall Stewart 		off -= SCTP_BUF_LEN(m);
3078139bc87fSRandall Stewart 		m = SCTP_BUF_NEXT(m);
3079f8829a4aSRandall Stewart 	}
3080f8829a4aSRandall Stewart 	if (m == NULL)
3081f8829a4aSRandall Stewart 		return (NULL);
3082f8829a4aSRandall Stewart 
3083f8829a4aSRandall Stewart 	/* is the current mbuf large enough (eg. contiguous)? */
3084139bc87fSRandall Stewart 	if ((SCTP_BUF_LEN(m) - off) >= len) {
3085f8829a4aSRandall Stewart 		return (mtod(m, caddr_t)+off);
3086f8829a4aSRandall Stewart 	} else {
3087f8829a4aSRandall Stewart 		/* else, it spans more than one mbuf, so save a temp copy... */
3088f8829a4aSRandall Stewart 		while ((m != NULL) && (len > 0)) {
3089139bc87fSRandall Stewart 			count = min(SCTP_BUF_LEN(m) - off, len);
30905ba7f91fSMichael Tuexen 			memcpy(ptr, mtod(m, caddr_t)+off, count);
3091f8829a4aSRandall Stewart 			len -= count;
3092f8829a4aSRandall Stewart 			ptr += count;
3093f8829a4aSRandall Stewart 			off = 0;
3094139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
3095f8829a4aSRandall Stewart 		}
3096f8829a4aSRandall Stewart 		if ((m == NULL) && (len > 0))
3097f8829a4aSRandall Stewart 			return (NULL);
3098f8829a4aSRandall Stewart 		else
3099f8829a4aSRandall Stewart 			return ((caddr_t)in_ptr);
3100f8829a4aSRandall Stewart 	}
3101f8829a4aSRandall Stewart }
3102f8829a4aSRandall Stewart 
3103f8829a4aSRandall Stewart struct sctp_paramhdr *
3104f8829a4aSRandall Stewart sctp_get_next_param(struct mbuf *m,
3105f8829a4aSRandall Stewart     int offset,
3106f8829a4aSRandall Stewart     struct sctp_paramhdr *pull,
3107f8829a4aSRandall Stewart     int pull_limit)
3108f8829a4aSRandall Stewart {
3109f8829a4aSRandall Stewart 	/* This just provides a typed signature to Peter's Pull routine */
3110f8829a4aSRandall Stewart 	return ((struct sctp_paramhdr *)sctp_m_getptr(m, offset, pull_limit,
3111f8829a4aSRandall Stewart 	    (uint8_t *)pull));
3112f8829a4aSRandall Stewart }
3113f8829a4aSRandall Stewart 
3114ce11b842SMichael Tuexen struct mbuf *
3115f8829a4aSRandall Stewart sctp_add_pad_tombuf(struct mbuf *m, int padlen)
3116f8829a4aSRandall Stewart {
3117ce11b842SMichael Tuexen 	struct mbuf *m_last;
3118ce11b842SMichael Tuexen 	caddr_t dp;
3119f8829a4aSRandall Stewart 
3120f8829a4aSRandall Stewart 	if (padlen > 3) {
3121ce11b842SMichael Tuexen 		return (NULL);
3122f8829a4aSRandall Stewart 	}
312341eee555SRandall Stewart 	if (padlen <= M_TRAILINGSPACE(m)) {
3124f8829a4aSRandall Stewart 		/*
3125f8829a4aSRandall Stewart 		 * The easy way. We hope the majority of the time we hit
3126f8829a4aSRandall Stewart 		 * here :)
3127f8829a4aSRandall Stewart 		 */
3128ce11b842SMichael Tuexen 		m_last = m;
3129f8829a4aSRandall Stewart 	} else {
3130ce11b842SMichael Tuexen 		/* Hard way we must grow the mbuf chain */
3131ce11b842SMichael Tuexen 		m_last = sctp_get_mbuf_for_msg(padlen, 0, M_NOWAIT, 1, MT_DATA);
3132ce11b842SMichael Tuexen 		if (m_last == NULL) {
3133ce11b842SMichael Tuexen 			return (NULL);
3134f8829a4aSRandall Stewart 		}
3135ce11b842SMichael Tuexen 		SCTP_BUF_LEN(m_last) = 0;
3136ce11b842SMichael Tuexen 		SCTP_BUF_NEXT(m_last) = NULL;
3137ce11b842SMichael Tuexen 		SCTP_BUF_NEXT(m) = m_last;
3138f8829a4aSRandall Stewart 	}
3139ce11b842SMichael Tuexen 	dp = mtod(m_last, caddr_t)+SCTP_BUF_LEN(m_last);
3140ce11b842SMichael Tuexen 	SCTP_BUF_LEN(m_last) += padlen;
3141ce11b842SMichael Tuexen 	memset(dp, 0, padlen);
3142ce11b842SMichael Tuexen 	return (m_last);
3143f8829a4aSRandall Stewart }
3144f8829a4aSRandall Stewart 
3145ce11b842SMichael Tuexen struct mbuf *
3146f8829a4aSRandall Stewart sctp_pad_lastmbuf(struct mbuf *m, int padval, struct mbuf *last_mbuf)
3147f8829a4aSRandall Stewart {
3148f8829a4aSRandall Stewart 	/* find the last mbuf in chain and pad it */
3149f8829a4aSRandall Stewart 	struct mbuf *m_at;
3150f8829a4aSRandall Stewart 
3151ce11b842SMichael Tuexen 	if (last_mbuf != NULL) {
3152f8829a4aSRandall Stewart 		return (sctp_add_pad_tombuf(last_mbuf, padval));
3153f8829a4aSRandall Stewart 	} else {
315417267b32SMichael Tuexen 		for (m_at = m; m_at; m_at = SCTP_BUF_NEXT(m_at)) {
3155139bc87fSRandall Stewart 			if (SCTP_BUF_NEXT(m_at) == NULL) {
3156f8829a4aSRandall Stewart 				return (sctp_add_pad_tombuf(m_at, padval));
3157f8829a4aSRandall Stewart 			}
3158f8829a4aSRandall Stewart 		}
3159f8829a4aSRandall Stewart 	}
3160ce11b842SMichael Tuexen 	return (NULL);
3161f8829a4aSRandall Stewart }
3162f8829a4aSRandall Stewart 
3163f8829a4aSRandall Stewart static void
3164c5b5675dSMichael Tuexen sctp_notify_assoc_change(uint16_t state, struct sctp_tcb *stcb,
3165105b68b4SMichael Tuexen     uint16_t error, struct sctp_abort_chunk *abort,
3166105b68b4SMichael Tuexen     bool from_peer, bool timedout, int so_locked)
3167f8829a4aSRandall Stewart {
3168f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3169f8829a4aSRandall Stewart 	struct sctp_assoc_change *sac;
3170f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
31719a8e3088SMichael Tuexen 	unsigned int notif_len;
31729a8e3088SMichael Tuexen 	uint16_t abort_len;
3173e06b67c7SMichael Tuexen 	unsigned int i;
3174ceaad40aSRandall Stewart 
3175105b68b4SMichael Tuexen 	KASSERT(abort == NULL || from_peer,
3176ce64352aSMichael Tuexen 	    ("sctp_notify_assoc_change: ABORT chunk provided for local termination"));
3177105b68b4SMichael Tuexen 	KASSERT(!from_peer || !timedout,
3178105b68b4SMichael Tuexen 	    ("sctp_notify_assoc_change: timeouts can only be local"));
317959713bbfSMichael Tuexen 	if (stcb == NULL) {
318059713bbfSMichael Tuexen 		return;
318159713bbfSMichael Tuexen 	}
318258411b08SMichael Tuexen 	if (sctp_stcb_is_feature_on(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVASSOCEVNT)) {
31839a8e3088SMichael Tuexen 		notif_len = (unsigned int)sizeof(struct sctp_assoc_change);
3184a2b42326SMichael Tuexen 		if (abort != NULL) {
3185c9eb4473SMichael Tuexen 			abort_len = ntohs(abort->ch.chunk_length);
31869669e724SMichael Tuexen 			/*
31879669e724SMichael Tuexen 			 * Only SCTP_CHUNK_BUFFER_SIZE are guaranteed to be
318845d41de5SMichael Tuexen 			 * contiguous.
31899669e724SMichael Tuexen 			 */
31909669e724SMichael Tuexen 			if (abort_len > SCTP_CHUNK_BUFFER_SIZE) {
31919669e724SMichael Tuexen 				abort_len = SCTP_CHUNK_BUFFER_SIZE;
31929669e724SMichael Tuexen 			}
3193a2b42326SMichael Tuexen 		} else {
3194a2b42326SMichael Tuexen 			abort_len = 0;
3195c5b5675dSMichael Tuexen 		}
3196a2b42326SMichael Tuexen 		if ((state == SCTP_COMM_UP) || (state == SCTP_RESTART)) {
3197a2b42326SMichael Tuexen 			notif_len += SCTP_ASSOC_SUPPORTS_MAX;
3198a2b42326SMichael Tuexen 		} else if ((state == SCTP_COMM_LOST) || (state == SCTP_CANT_STR_ASSOC)) {
3199a2b42326SMichael Tuexen 			notif_len += abort_len;
3200a2b42326SMichael Tuexen 		}
3201eb1b1807SGleb Smirnoff 		m_notify = sctp_get_mbuf_for_msg(notif_len, 0, M_NOWAIT, 1, MT_DATA);
3202a2b42326SMichael Tuexen 		if (m_notify == NULL) {
3203a2b42326SMichael Tuexen 			/* Retry with smaller value. */
32049a8e3088SMichael Tuexen 			notif_len = (unsigned int)sizeof(struct sctp_assoc_change);
3205eb1b1807SGleb Smirnoff 			m_notify = sctp_get_mbuf_for_msg(notif_len, 0, M_NOWAIT, 1, MT_DATA);
3206a2b42326SMichael Tuexen 			if (m_notify == NULL) {
320758411b08SMichael Tuexen 				goto set_error;
3208a2b42326SMichael Tuexen 			}
3209a2b42326SMichael Tuexen 		}
3210a2b42326SMichael Tuexen 		SCTP_BUF_NEXT(m_notify) = NULL;
3211f8829a4aSRandall Stewart 		sac = mtod(m_notify, struct sctp_assoc_change *);
3212e432298aSXin LI 		memset(sac, 0, notif_len);
3213f8829a4aSRandall Stewart 		sac->sac_type = SCTP_ASSOC_CHANGE;
3214f8829a4aSRandall Stewart 		sac->sac_flags = 0;
3215f8829a4aSRandall Stewart 		sac->sac_length = sizeof(struct sctp_assoc_change);
3216c5b5675dSMichael Tuexen 		sac->sac_state = state;
3217f8829a4aSRandall Stewart 		sac->sac_error = error;
3218ce64352aSMichael Tuexen 		if (state == SCTP_CANT_STR_ASSOC) {
3219ce64352aSMichael Tuexen 			sac->sac_outbound_streams = 0;
3220ce64352aSMichael Tuexen 			sac->sac_inbound_streams = 0;
3221ce64352aSMichael Tuexen 		} else {
3222f8829a4aSRandall Stewart 			sac->sac_outbound_streams = stcb->asoc.streamoutcnt;
3223f8829a4aSRandall Stewart 			sac->sac_inbound_streams = stcb->asoc.streamincnt;
3224ce64352aSMichael Tuexen 		}
3225f8829a4aSRandall Stewart 		sac->sac_assoc_id = sctp_get_associd(stcb);
3226a2b42326SMichael Tuexen 		if (notif_len > sizeof(struct sctp_assoc_change)) {
3227c5b5675dSMichael Tuexen 			if ((state == SCTP_COMM_UP) || (state == SCTP_RESTART)) {
3228e06b67c7SMichael Tuexen 				i = 0;
3229c79bec9cSMichael Tuexen 				if (stcb->asoc.prsctp_supported == 1) {
3230e06b67c7SMichael Tuexen 					sac->sac_info[i++] = SCTP_ASSOC_SUPPORTS_PR;
3231e06b67c7SMichael Tuexen 				}
3232c79bec9cSMichael Tuexen 				if (stcb->asoc.auth_supported == 1) {
3233e06b67c7SMichael Tuexen 					sac->sac_info[i++] = SCTP_ASSOC_SUPPORTS_AUTH;
3234e06b67c7SMichael Tuexen 				}
3235c79bec9cSMichael Tuexen 				if (stcb->asoc.asconf_supported == 1) {
3236e06b67c7SMichael Tuexen 					sac->sac_info[i++] = SCTP_ASSOC_SUPPORTS_ASCONF;
3237e06b67c7SMichael Tuexen 				}
323844249214SRandall Stewart 				if (stcb->asoc.idata_supported == 1) {
323944249214SRandall Stewart 					sac->sac_info[i++] = SCTP_ASSOC_SUPPORTS_INTERLEAVING;
324044249214SRandall Stewart 				}
3241e06b67c7SMichael Tuexen 				sac->sac_info[i++] = SCTP_ASSOC_SUPPORTS_MULTIBUF;
3242c79bec9cSMichael Tuexen 				if (stcb->asoc.reconfig_supported == 1) {
3243e06b67c7SMichael Tuexen 					sac->sac_info[i++] = SCTP_ASSOC_SUPPORTS_RE_CONFIG;
3244e06b67c7SMichael Tuexen 				}
3245e06b67c7SMichael Tuexen 				sac->sac_length += i;
3246a2b42326SMichael Tuexen 			} else if ((state == SCTP_COMM_LOST) || (state == SCTP_CANT_STR_ASSOC)) {
3247a2b42326SMichael Tuexen 				memcpy(sac->sac_info, abort, abort_len);
3248a2b42326SMichael Tuexen 				sac->sac_length += abort_len;
3249a2b42326SMichael Tuexen 			}
3250c5b5675dSMichael Tuexen 		}
3251e06b67c7SMichael Tuexen 		SCTP_BUF_LEN(m_notify) = sac->sac_length;
3252f8829a4aSRandall Stewart 		control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
32537215cc1bSMichael Tuexen 		    0, 0, stcb->asoc.context, 0, 0, 0,
3254f8829a4aSRandall Stewart 		    m_notify);
325558411b08SMichael Tuexen 		if (control != NULL) {
3256139bc87fSRandall Stewart 			control->length = SCTP_BUF_LEN(m_notify);
325728cd0699SMichael Tuexen 			control->spec_flags = M_NOTIFICATION;
3258f8829a4aSRandall Stewart 			/* not that we need this */
3259f8829a4aSRandall Stewart 			control->tail_mbuf = m_notify;
3260f8829a4aSRandall Stewart 			sctp_add_to_readq(stcb->sctp_ep, stcb,
3261f8829a4aSRandall Stewart 			    control,
3262cfde3ff7SRandall Stewart 			    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD,
3263cfde3ff7SRandall Stewart 			    so_locked);
326458411b08SMichael Tuexen 		} else {
326558411b08SMichael Tuexen 			sctp_m_freem(m_notify);
326658411b08SMichael Tuexen 		}
326758411b08SMichael Tuexen 	}
326858411b08SMichael Tuexen 	/*
326958411b08SMichael Tuexen 	 * For 1-to-1 style sockets, we send up and error when an ABORT
327058411b08SMichael Tuexen 	 * comes in.
327158411b08SMichael Tuexen 	 */
327258411b08SMichael Tuexen set_error:
327358411b08SMichael Tuexen 	if (((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
327458411b08SMichael Tuexen 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) &&
327558411b08SMichael Tuexen 	    ((state == SCTP_COMM_LOST) || (state == SCTP_CANT_STR_ASSOC))) {
3276e045904fSMichael Tuexen 		SOCK_LOCK(stcb->sctp_socket);
3277410a3b1eSMichael Tuexen 		if (from_peer) {
3278839d21d6SMichael Tuexen 			if (SCTP_GET_STATE(stcb) == SCTP_STATE_COOKIE_WAIT) {
327958411b08SMichael Tuexen 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ECONNREFUSED);
328058411b08SMichael Tuexen 				stcb->sctp_socket->so_error = ECONNREFUSED;
328158411b08SMichael Tuexen 			} else {
328258411b08SMichael Tuexen 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ECONNRESET);
328358411b08SMichael Tuexen 				stcb->sctp_socket->so_error = ECONNRESET;
328458411b08SMichael Tuexen 			}
3285410a3b1eSMichael Tuexen 		} else {
3286105b68b4SMichael Tuexen 			if (timedout) {
3287553bb068SMichael Tuexen 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ETIMEDOUT);
3288553bb068SMichael Tuexen 				stcb->sctp_socket->so_error = ETIMEDOUT;
3289553bb068SMichael Tuexen 			} else {
3290410a3b1eSMichael Tuexen 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ECONNABORTED);
3291410a3b1eSMichael Tuexen 				stcb->sctp_socket->so_error = ECONNABORTED;
3292410a3b1eSMichael Tuexen 			}
329358411b08SMichael Tuexen 		}
32943acfe1e1SGleb Smirnoff 		SOCK_UNLOCK(stcb->sctp_socket);
3295553bb068SMichael Tuexen 	}
329658411b08SMichael Tuexen 	/* Wake ANY sleepers */
329758411b08SMichael Tuexen 	if (((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
329858411b08SMichael Tuexen 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) &&
329958411b08SMichael Tuexen 	    ((state == SCTP_COMM_LOST) || (state == SCTP_CANT_STR_ASSOC))) {
33003acfe1e1SGleb Smirnoff 		socantrcvmore(stcb->sctp_socket);
330158411b08SMichael Tuexen 	}
330258411b08SMichael Tuexen 	sorwakeup(stcb->sctp_socket);
330358411b08SMichael Tuexen 	sowwakeup(stcb->sctp_socket);
3304f8829a4aSRandall Stewart }
3305f8829a4aSRandall Stewart 
3306f8829a4aSRandall Stewart static void
3307f8829a4aSRandall Stewart sctp_notify_peer_addr_change(struct sctp_tcb *stcb, uint32_t state,
330828397ac1SMichael Tuexen     struct sockaddr *sa, uint32_t error, int so_locked)
3309f8829a4aSRandall Stewart {
3310f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3311f8829a4aSRandall Stewart 	struct sctp_paddr_change *spc;
3312f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3313f8829a4aSRandall Stewart 
331460990c0cSMichael Tuexen 	if ((stcb == NULL) ||
331560990c0cSMichael Tuexen 	    sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVPADDREVNT)) {
3316f8829a4aSRandall Stewart 		/* event not enabled */
3317f8829a4aSRandall Stewart 		return;
3318830d754dSRandall Stewart 	}
3319eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_paddr_change), 0, M_NOWAIT, 1, MT_DATA);
3320f8829a4aSRandall Stewart 	if (m_notify == NULL)
3321f8829a4aSRandall Stewart 		return;
3322139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3323f8829a4aSRandall Stewart 	spc = mtod(m_notify, struct sctp_paddr_change *);
332456711f94SMichael Tuexen 	memset(spc, 0, sizeof(struct sctp_paddr_change));
3325f8829a4aSRandall Stewart 	spc->spc_type = SCTP_PEER_ADDR_CHANGE;
3326f8829a4aSRandall Stewart 	spc->spc_flags = 0;
3327f8829a4aSRandall Stewart 	spc->spc_length = sizeof(struct sctp_paddr_change);
33285e2c2d87SRandall Stewart 	switch (sa->sa_family) {
3329ea5eba11SMichael Tuexen #ifdef INET
33305e2c2d87SRandall Stewart 	case AF_INET:
3331d59107f7SMichael Tuexen #ifdef INET6
3332d59107f7SMichael Tuexen 		if (sctp_is_feature_on(stcb->sctp_ep, SCTP_PCB_FLAGS_NEEDS_MAPPED_V4)) {
3333d59107f7SMichael Tuexen 			in6_sin_2_v4mapsin6((struct sockaddr_in *)sa,
3334d59107f7SMichael Tuexen 			    (struct sockaddr_in6 *)&spc->spc_aaddr);
3335d59107f7SMichael Tuexen 		} else {
3336f8829a4aSRandall Stewart 			memcpy(&spc->spc_aaddr, sa, sizeof(struct sockaddr_in));
3337d59107f7SMichael Tuexen 		}
3338d59107f7SMichael Tuexen #else
3339d59107f7SMichael Tuexen 		memcpy(&spc->spc_aaddr, sa, sizeof(struct sockaddr_in));
3340d59107f7SMichael Tuexen #endif
33415e2c2d87SRandall Stewart 		break;
3342ea5eba11SMichael Tuexen #endif
33435e2c2d87SRandall Stewart #ifdef INET6
33445e2c2d87SRandall Stewart 	case AF_INET6:
33455e2c2d87SRandall Stewart 		{
3346f42a358aSRandall Stewart 			struct sockaddr_in6 *sin6;
3347f42a358aSRandall Stewart 
3348f8829a4aSRandall Stewart 			memcpy(&spc->spc_aaddr, sa, sizeof(struct sockaddr_in6));
3349f42a358aSRandall Stewart 
3350f42a358aSRandall Stewart 			sin6 = (struct sockaddr_in6 *)&spc->spc_aaddr;
3351f42a358aSRandall Stewart 			if (IN6_IS_SCOPE_LINKLOCAL(&sin6->sin6_addr)) {
335242551e99SRandall Stewart 				if (sin6->sin6_scope_id == 0) {
335342551e99SRandall Stewart 					/* recover scope_id for user */
3354f42a358aSRandall Stewart 					(void)sa6_recoverscope(sin6);
335542551e99SRandall Stewart 				} else {
335642551e99SRandall Stewart 					/* clear embedded scope_id for user */
335742551e99SRandall Stewart 					in6_clearscope(&sin6->sin6_addr);
335842551e99SRandall Stewart 				}
3359f42a358aSRandall Stewart 			}
33605e2c2d87SRandall Stewart 			break;
33615e2c2d87SRandall Stewart 		}
33625e2c2d87SRandall Stewart #endif
33635e2c2d87SRandall Stewart 	default:
33645e2c2d87SRandall Stewart 		/* TSNH */
33655e2c2d87SRandall Stewart 		break;
3366f8829a4aSRandall Stewart 	}
3367f8829a4aSRandall Stewart 	spc->spc_state = state;
3368f8829a4aSRandall Stewart 	spc->spc_error = error;
3369f8829a4aSRandall Stewart 	spc->spc_assoc_id = sctp_get_associd(stcb);
3370f8829a4aSRandall Stewart 
3371139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_paddr_change);
3372139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3373f8829a4aSRandall Stewart 
3374f8829a4aSRandall Stewart 	/* append to socket */
3375f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
33767215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3377f8829a4aSRandall Stewart 	    m_notify);
3378f8829a4aSRandall Stewart 	if (control == NULL) {
3379f8829a4aSRandall Stewart 		/* no memory */
3380f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3381f8829a4aSRandall Stewart 		return;
3382f8829a4aSRandall Stewart 	}
3383139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3384139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3385f8829a4aSRandall Stewart 	/* not that we need this */
3386f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
3387f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3388f8829a4aSRandall Stewart 	    control,
3389cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1,
3390cfde3ff7SRandall Stewart 	    SCTP_READ_LOCK_NOT_HELD,
33913cb3567dSMichael Tuexen 	    so_locked);
3392f8829a4aSRandall Stewart }
3393f8829a4aSRandall Stewart 
3394f8829a4aSRandall Stewart static void
33951edc9dbaSMichael Tuexen sctp_notify_send_failed(struct sctp_tcb *stcb, uint8_t sent, uint32_t error,
339628397ac1SMichael Tuexen     struct sctp_tmit_chunk *chk, int so_locked)
3397f8829a4aSRandall Stewart {
3398830d754dSRandall Stewart 	struct mbuf *m_notify;
3399f8829a4aSRandall Stewart 	struct sctp_send_failed *ssf;
34009935403aSMichael Tuexen 	struct sctp_send_failed_event *ssfe;
3401f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3402ab337314SMichael Tuexen 	struct sctp_chunkhdr *chkhdr;
3403ab337314SMichael Tuexen 	int notifhdr_len, chk_len, chkhdr_len, padding_len, payload_len;
3404f8829a4aSRandall Stewart 
340560990c0cSMichael Tuexen 	if ((stcb == NULL) ||
34069935403aSMichael Tuexen 	    (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVSENDFAILEVNT) &&
34079935403aSMichael Tuexen 	    sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVNSENDFAILEVNT))) {
3408f8829a4aSRandall Stewart 		/* event not enabled */
3409f8829a4aSRandall Stewart 		return;
3410830d754dSRandall Stewart 	}
34110053ed28SMichael Tuexen 
34129935403aSMichael Tuexen 	if (sctp_stcb_is_feature_on(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVNSENDFAILEVNT)) {
3413ab337314SMichael Tuexen 		notifhdr_len = sizeof(struct sctp_send_failed_event);
34149935403aSMichael Tuexen 	} else {
3415ab337314SMichael Tuexen 		notifhdr_len = sizeof(struct sctp_send_failed);
34169935403aSMichael Tuexen 	}
3417ab337314SMichael Tuexen 	m_notify = sctp_get_mbuf_for_msg(notifhdr_len, 0, M_NOWAIT, 1, MT_DATA);
3418f8829a4aSRandall Stewart 	if (m_notify == NULL)
3419f8829a4aSRandall Stewart 		/* no space left */
3420f8829a4aSRandall Stewart 		return;
3421ab337314SMichael Tuexen 	SCTP_BUF_LEN(m_notify) = notifhdr_len;
3422ab337314SMichael Tuexen 	if (stcb->asoc.idata_supported) {
3423ab337314SMichael Tuexen 		chkhdr_len = sizeof(struct sctp_idata_chunk);
3424ab337314SMichael Tuexen 	} else {
3425ab337314SMichael Tuexen 		chkhdr_len = sizeof(struct sctp_data_chunk);
3426ab337314SMichael Tuexen 	}
3427ab337314SMichael Tuexen 	/* Use some defaults in case we can't access the chunk header */
3428ab337314SMichael Tuexen 	if (chk->send_size >= chkhdr_len) {
3429ab337314SMichael Tuexen 		payload_len = chk->send_size - chkhdr_len;
3430ab337314SMichael Tuexen 	} else {
3431ab337314SMichael Tuexen 		payload_len = 0;
3432ab337314SMichael Tuexen 	}
3433ab337314SMichael Tuexen 	padding_len = 0;
3434ab337314SMichael Tuexen 	if (chk->data != NULL) {
3435ab337314SMichael Tuexen 		chkhdr = mtod(chk->data, struct sctp_chunkhdr *);
3436ab337314SMichael Tuexen 		if (chkhdr != NULL) {
3437ab337314SMichael Tuexen 			chk_len = ntohs(chkhdr->chunk_length);
3438ab337314SMichael Tuexen 			if ((chk_len >= chkhdr_len) &&
3439ab337314SMichael Tuexen 			    (chk->send_size >= chk_len) &&
3440ab337314SMichael Tuexen 			    (chk->send_size - chk_len < 4)) {
3441ab337314SMichael Tuexen 				padding_len = chk->send_size - chk_len;
3442ab337314SMichael Tuexen 				payload_len = chk->send_size - chkhdr_len - padding_len;
3443ab337314SMichael Tuexen 			}
3444ab337314SMichael Tuexen 		}
3445ab337314SMichael Tuexen 	}
34469935403aSMichael Tuexen 	if (sctp_stcb_is_feature_on(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVNSENDFAILEVNT)) {
34479935403aSMichael Tuexen 		ssfe = mtod(m_notify, struct sctp_send_failed_event *);
3448ab337314SMichael Tuexen 		memset(ssfe, 0, notifhdr_len);
34499935403aSMichael Tuexen 		ssfe->ssfe_type = SCTP_SEND_FAILED_EVENT;
34501edc9dbaSMichael Tuexen 		if (sent) {
34519935403aSMichael Tuexen 			ssfe->ssfe_flags = SCTP_DATA_SENT;
34521edc9dbaSMichael Tuexen 		} else {
34531edc9dbaSMichael Tuexen 			ssfe->ssfe_flags = SCTP_DATA_UNSENT;
34541edc9dbaSMichael Tuexen 		}
3455ab337314SMichael Tuexen 		ssfe->ssfe_length = (uint32_t)(notifhdr_len + payload_len);
34569935403aSMichael Tuexen 		ssfe->ssfe_error = error;
34579935403aSMichael Tuexen 		/* not exactly what the user sent in, but should be close :) */
345849656eefSMichael Tuexen 		ssfe->ssfe_info.snd_sid = chk->rec.data.sid;
34599935403aSMichael Tuexen 		ssfe->ssfe_info.snd_flags = chk->rec.data.rcv_flags;
346049656eefSMichael Tuexen 		ssfe->ssfe_info.snd_ppid = chk->rec.data.ppid;
34619935403aSMichael Tuexen 		ssfe->ssfe_info.snd_context = chk->rec.data.context;
34629935403aSMichael Tuexen 		ssfe->ssfe_info.snd_assoc_id = sctp_get_associd(stcb);
34639935403aSMichael Tuexen 		ssfe->ssfe_assoc_id = sctp_get_associd(stcb);
34649935403aSMichael Tuexen 	} else {
3465f8829a4aSRandall Stewart 		ssf = mtod(m_notify, struct sctp_send_failed *);
3466ab337314SMichael Tuexen 		memset(ssf, 0, notifhdr_len);
3467f8829a4aSRandall Stewart 		ssf->ssf_type = SCTP_SEND_FAILED;
34681edc9dbaSMichael Tuexen 		if (sent) {
3469f8829a4aSRandall Stewart 			ssf->ssf_flags = SCTP_DATA_SENT;
34701edc9dbaSMichael Tuexen 		} else {
34711edc9dbaSMichael Tuexen 			ssf->ssf_flags = SCTP_DATA_UNSENT;
34721edc9dbaSMichael Tuexen 		}
3473ab337314SMichael Tuexen 		ssf->ssf_length = (uint32_t)(notifhdr_len + payload_len);
3474f8829a4aSRandall Stewart 		ssf->ssf_error = error;
3475f8829a4aSRandall Stewart 		/* not exactly what the user sent in, but should be close :) */
347649656eefSMichael Tuexen 		ssf->ssf_info.sinfo_stream = chk->rec.data.sid;
347749656eefSMichael Tuexen 		ssf->ssf_info.sinfo_ssn = (uint16_t)chk->rec.data.mid;
3478f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_flags = chk->rec.data.rcv_flags;
347949656eefSMichael Tuexen 		ssf->ssf_info.sinfo_ppid = chk->rec.data.ppid;
3480f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_context = chk->rec.data.context;
3481f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_assoc_id = sctp_get_associd(stcb);
3482f8829a4aSRandall Stewart 		ssf->ssf_assoc_id = sctp_get_associd(stcb);
34839935403aSMichael Tuexen 	}
3484ab337314SMichael Tuexen 	if (chk->data != NULL) {
3485ab337314SMichael Tuexen 		/* Trim off the sctp chunk header (it should be there) */
3486ab337314SMichael Tuexen 		if (chk->send_size == chkhdr_len + payload_len + padding_len) {
3487ab337314SMichael Tuexen 			m_adj(chk->data, chkhdr_len);
3488ab337314SMichael Tuexen 			m_adj(chk->data, -padding_len);
3489830d754dSRandall Stewart 			sctp_mbuf_crush(chk->data);
3490ab337314SMichael Tuexen 			chk->send_size -= (chkhdr_len + padding_len);
3491830d754dSRandall Stewart 		}
3492830d754dSRandall Stewart 	}
3493810ec536SMichael Tuexen 	SCTP_BUF_NEXT(m_notify) = chk->data;
3494f8829a4aSRandall Stewart 	/* Steal off the mbuf */
3495f8829a4aSRandall Stewart 	chk->data = NULL;
3496f8829a4aSRandall Stewart 	/*
3497f8829a4aSRandall Stewart 	 * For this case, we check the actual socket buffer, since the assoc
3498f8829a4aSRandall Stewart 	 * is going away we don't want to overfill the socket buffer for a
3499f8829a4aSRandall Stewart 	 * non-reader
3500f8829a4aSRandall Stewart 	 */
3501139bc87fSRandall Stewart 	if (sctp_sbspace_failedmsgs(&stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3502f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3503f8829a4aSRandall Stewart 		return;
3504f8829a4aSRandall Stewart 	}
3505f8829a4aSRandall Stewart 	/* append to socket */
3506f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
35077215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3508f8829a4aSRandall Stewart 	    m_notify);
3509f8829a4aSRandall Stewart 	if (control == NULL) {
3510f8829a4aSRandall Stewart 		/* no memory */
3511f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3512f8829a4aSRandall Stewart 		return;
3513f8829a4aSRandall Stewart 	}
351428cd0699SMichael Tuexen 	control->length = SCTP_BUF_LEN(m_notify);
3515139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
351628cd0699SMichael Tuexen 	/* not that we need this */
351728cd0699SMichael Tuexen 	control->tail_mbuf = m_notify;
3518f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3519f8829a4aSRandall Stewart 	    control,
3520cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1,
3521cfde3ff7SRandall Stewart 	    SCTP_READ_LOCK_NOT_HELD,
3522cfde3ff7SRandall Stewart 	    so_locked);
3523f8829a4aSRandall Stewart }
3524f8829a4aSRandall Stewart 
3525f8829a4aSRandall Stewart static void
3526f8829a4aSRandall Stewart sctp_notify_send_failed2(struct sctp_tcb *stcb, uint32_t error,
352728397ac1SMichael Tuexen     struct sctp_stream_queue_pending *sp, int so_locked)
3528f8829a4aSRandall Stewart {
3529f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3530f8829a4aSRandall Stewart 	struct sctp_send_failed *ssf;
35319935403aSMichael Tuexen 	struct sctp_send_failed_event *ssfe;
3532f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3533ab337314SMichael Tuexen 	int notifhdr_len;
3534f8829a4aSRandall Stewart 
353560990c0cSMichael Tuexen 	if ((stcb == NULL) ||
35369935403aSMichael Tuexen 	    (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVSENDFAILEVNT) &&
35379935403aSMichael Tuexen 	    sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVNSENDFAILEVNT))) {
3538f8829a4aSRandall Stewart 		/* event not enabled */
3539f8829a4aSRandall Stewart 		return;
3540830d754dSRandall Stewart 	}
35419935403aSMichael Tuexen 	if (sctp_stcb_is_feature_on(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVNSENDFAILEVNT)) {
3542ab337314SMichael Tuexen 		notifhdr_len = sizeof(struct sctp_send_failed_event);
35439935403aSMichael Tuexen 	} else {
3544ab337314SMichael Tuexen 		notifhdr_len = sizeof(struct sctp_send_failed);
35459935403aSMichael Tuexen 	}
3546ab337314SMichael Tuexen 	m_notify = sctp_get_mbuf_for_msg(notifhdr_len, 0, M_NOWAIT, 1, MT_DATA);
35479935403aSMichael Tuexen 	if (m_notify == NULL) {
3548f8829a4aSRandall Stewart 		/* no space left */
3549f8829a4aSRandall Stewart 		return;
35509935403aSMichael Tuexen 	}
3551ab337314SMichael Tuexen 	SCTP_BUF_LEN(m_notify) = notifhdr_len;
35529935403aSMichael Tuexen 	if (sctp_stcb_is_feature_on(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVNSENDFAILEVNT)) {
35539935403aSMichael Tuexen 		ssfe = mtod(m_notify, struct sctp_send_failed_event *);
3554ab337314SMichael Tuexen 		memset(ssfe, 0, notifhdr_len);
3555ad83c8a5SMichael Tuexen 		ssfe->ssfe_type = SCTP_SEND_FAILED_EVENT;
35569935403aSMichael Tuexen 		ssfe->ssfe_flags = SCTP_DATA_UNSENT;
3557ab337314SMichael Tuexen 		ssfe->ssfe_length = (uint32_t)(notifhdr_len + sp->length);
35589935403aSMichael Tuexen 		ssfe->ssfe_error = error;
35599935403aSMichael Tuexen 		/* not exactly what the user sent in, but should be close :) */
356049656eefSMichael Tuexen 		ssfe->ssfe_info.snd_sid = sp->sid;
35619935403aSMichael Tuexen 		if (sp->some_taken) {
35629935403aSMichael Tuexen 			ssfe->ssfe_info.snd_flags = SCTP_DATA_LAST_FRAG;
35639935403aSMichael Tuexen 		} else {
35649935403aSMichael Tuexen 			ssfe->ssfe_info.snd_flags = SCTP_DATA_NOT_FRAG;
35659935403aSMichael Tuexen 		}
35669935403aSMichael Tuexen 		ssfe->ssfe_info.snd_ppid = sp->ppid;
35679935403aSMichael Tuexen 		ssfe->ssfe_info.snd_context = sp->context;
35689935403aSMichael Tuexen 		ssfe->ssfe_info.snd_assoc_id = sctp_get_associd(stcb);
35699935403aSMichael Tuexen 		ssfe->ssfe_assoc_id = sctp_get_associd(stcb);
35709935403aSMichael Tuexen 	} else {
3571f8829a4aSRandall Stewart 		ssf = mtod(m_notify, struct sctp_send_failed *);
3572ab337314SMichael Tuexen 		memset(ssf, 0, notifhdr_len);
3573f8829a4aSRandall Stewart 		ssf->ssf_type = SCTP_SEND_FAILED;
3574f8829a4aSRandall Stewart 		ssf->ssf_flags = SCTP_DATA_UNSENT;
3575ab337314SMichael Tuexen 		ssf->ssf_length = (uint32_t)(notifhdr_len + sp->length);
3576f8829a4aSRandall Stewart 		ssf->ssf_error = error;
3577f8829a4aSRandall Stewart 		/* not exactly what the user sent in, but should be close :) */
357849656eefSMichael Tuexen 		ssf->ssf_info.sinfo_stream = sp->sid;
3579f3b05218SMichael Tuexen 		ssf->ssf_info.sinfo_ssn = 0;
3580fc14de76SRandall Stewart 		if (sp->some_taken) {
3581fc14de76SRandall Stewart 			ssf->ssf_info.sinfo_flags = SCTP_DATA_LAST_FRAG;
3582fc14de76SRandall Stewart 		} else {
3583fc14de76SRandall Stewart 			ssf->ssf_info.sinfo_flags = SCTP_DATA_NOT_FRAG;
3584fc14de76SRandall Stewart 		}
3585f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_ppid = sp->ppid;
3586f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_context = sp->context;
3587f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_assoc_id = sctp_get_associd(stcb);
3588f8829a4aSRandall Stewart 		ssf->ssf_assoc_id = sctp_get_associd(stcb);
35899935403aSMichael Tuexen 	}
35909935403aSMichael Tuexen 	SCTP_BUF_NEXT(m_notify) = sp->data;
3591f8829a4aSRandall Stewart 
3592f8829a4aSRandall Stewart 	/* Steal off the mbuf */
3593f8829a4aSRandall Stewart 	sp->data = NULL;
3594f8829a4aSRandall Stewart 	/*
3595f8829a4aSRandall Stewart 	 * For this case, we check the actual socket buffer, since the assoc
3596f8829a4aSRandall Stewart 	 * is going away we don't want to overfill the socket buffer for a
3597f8829a4aSRandall Stewart 	 * non-reader
3598f8829a4aSRandall Stewart 	 */
3599139bc87fSRandall Stewart 	if (sctp_sbspace_failedmsgs(&stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3600f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3601f8829a4aSRandall Stewart 		return;
3602f8829a4aSRandall Stewart 	}
3603f8829a4aSRandall Stewart 	/* append to socket */
3604f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
36057215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3606f8829a4aSRandall Stewart 	    m_notify);
3607f8829a4aSRandall Stewart 	if (control == NULL) {
3608f8829a4aSRandall Stewart 		/* no memory */
3609f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3610f8829a4aSRandall Stewart 		return;
3611f8829a4aSRandall Stewart 	}
361228cd0699SMichael Tuexen 	control->length = SCTP_BUF_LEN(m_notify);
3613139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
361428cd0699SMichael Tuexen 	/* not that we need this */
361528cd0699SMichael Tuexen 	control->tail_mbuf = m_notify;
3616f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3617f8829a4aSRandall Stewart 	    control,
3618cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, so_locked);
3619f8829a4aSRandall Stewart }
3620f8829a4aSRandall Stewart 
3621f8829a4aSRandall Stewart static void
36227215cc1bSMichael Tuexen sctp_notify_adaptation_layer(struct sctp_tcb *stcb)
3623f8829a4aSRandall Stewart {
3624f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3625f8829a4aSRandall Stewart 	struct sctp_adaptation_event *sai;
3626f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3627f8829a4aSRandall Stewart 
362860990c0cSMichael Tuexen 	if ((stcb == NULL) ||
362960990c0cSMichael Tuexen 	    sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_ADAPTATIONEVNT)) {
3630f8829a4aSRandall Stewart 		/* event not enabled */
3631f8829a4aSRandall Stewart 		return;
3632830d754dSRandall Stewart 	}
36330053ed28SMichael Tuexen 
3634eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_adaption_event), 0, M_NOWAIT, 1, MT_DATA);
3635f8829a4aSRandall Stewart 	if (m_notify == NULL)
3636f8829a4aSRandall Stewart 		/* no space left */
3637f8829a4aSRandall Stewart 		return;
3638139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3639f8829a4aSRandall Stewart 	sai = mtod(m_notify, struct sctp_adaptation_event *);
3640e432298aSXin LI 	memset(sai, 0, sizeof(struct sctp_adaptation_event));
3641f8829a4aSRandall Stewart 	sai->sai_type = SCTP_ADAPTATION_INDICATION;
3642f8829a4aSRandall Stewart 	sai->sai_flags = 0;
3643f8829a4aSRandall Stewart 	sai->sai_length = sizeof(struct sctp_adaptation_event);
36442afb3e84SRandall Stewart 	sai->sai_adaptation_ind = stcb->asoc.peers_adaptation;
3645f8829a4aSRandall Stewart 	sai->sai_assoc_id = sctp_get_associd(stcb);
3646f8829a4aSRandall Stewart 
3647139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_adaptation_event);
3648139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3649f8829a4aSRandall Stewart 
3650f8829a4aSRandall Stewart 	/* append to socket */
3651f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
36527215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3653f8829a4aSRandall Stewart 	    m_notify);
3654f8829a4aSRandall Stewart 	if (control == NULL) {
3655f8829a4aSRandall Stewart 		/* no memory */
3656f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3657f8829a4aSRandall Stewart 		return;
3658f8829a4aSRandall Stewart 	}
3659139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3660139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3661f8829a4aSRandall Stewart 	/* not that we need this */
3662f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
3663f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3664f8829a4aSRandall Stewart 	    control,
3665cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, SCTP_SO_NOT_LOCKED);
3666f8829a4aSRandall Stewart }
3667f8829a4aSRandall Stewart 
366803b0b021SRandall Stewart /* This always must be called with the read-queue LOCKED in the INP */
3669810ec536SMichael Tuexen static void
36702dad8a55SRandall Stewart sctp_notify_partial_delivery_indication(struct sctp_tcb *stcb, uint32_t error,
367128397ac1SMichael Tuexen     uint32_t val, int so_locked)
3672f8829a4aSRandall Stewart {
3673f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3674f8829a4aSRandall Stewart 	struct sctp_pdapi_event *pdapi;
3675f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
367603b0b021SRandall Stewart 	struct sockbuf *sb;
3677f8829a4aSRandall Stewart 
367860990c0cSMichael Tuexen 	if ((stcb == NULL) ||
367960990c0cSMichael Tuexen 	    sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_PDAPIEVNT)) {
3680f8829a4aSRandall Stewart 		/* event not enabled */
3681f8829a4aSRandall Stewart 		return;
3682830d754dSRandall Stewart 	}
3683cd1386abSMichael Tuexen 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_CANT_READ) {
3684cd1386abSMichael Tuexen 		return;
3685cd1386abSMichael Tuexen 	}
36860053ed28SMichael Tuexen 
3687eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_pdapi_event), 0, M_NOWAIT, 1, MT_DATA);
3688f8829a4aSRandall Stewart 	if (m_notify == NULL)
3689f8829a4aSRandall Stewart 		/* no space left */
3690f8829a4aSRandall Stewart 		return;
3691139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3692f8829a4aSRandall Stewart 	pdapi = mtod(m_notify, struct sctp_pdapi_event *);
3693e432298aSXin LI 	memset(pdapi, 0, sizeof(struct sctp_pdapi_event));
3694f8829a4aSRandall Stewart 	pdapi->pdapi_type = SCTP_PARTIAL_DELIVERY_EVENT;
3695f8829a4aSRandall Stewart 	pdapi->pdapi_flags = 0;
3696f8829a4aSRandall Stewart 	pdapi->pdapi_length = sizeof(struct sctp_pdapi_event);
3697f8829a4aSRandall Stewart 	pdapi->pdapi_indication = error;
36989a6142d8SRandall Stewart 	pdapi->pdapi_stream = (val >> 16);
36999a6142d8SRandall Stewart 	pdapi->pdapi_seq = (val & 0x0000ffff);
3700f8829a4aSRandall Stewart 	pdapi->pdapi_assoc_id = sctp_get_associd(stcb);
3701f8829a4aSRandall Stewart 
3702139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_pdapi_event);
3703139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3704f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
37057215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3706f8829a4aSRandall Stewart 	    m_notify);
3707f8829a4aSRandall Stewart 	if (control == NULL) {
3708f8829a4aSRandall Stewart 		/* no memory */
3709f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3710f8829a4aSRandall Stewart 		return;
3711f8829a4aSRandall Stewart 	}
3712139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
371328cd0699SMichael Tuexen 	control->spec_flags = M_NOTIFICATION;
3714f8829a4aSRandall Stewart 	/* not that we need this */
3715f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
371603b0b021SRandall Stewart 	sb = &stcb->sctp_socket->so_rcv;
3717b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
3718139bc87fSRandall Stewart 		sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m_notify));
371980fefe0aSRandall Stewart 	}
372003b0b021SRandall Stewart 	sctp_sballoc(stcb, sb, m_notify);
3721b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
372203b0b021SRandall Stewart 		sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
372380fefe0aSRandall Stewart 	}
372403b0b021SRandall Stewart 	control->end_added = 1;
372503b0b021SRandall Stewart 	if (stcb->asoc.control_pdapi)
372603b0b021SRandall Stewart 		TAILQ_INSERT_AFTER(&stcb->sctp_ep->read_queue, stcb->asoc.control_pdapi, control, next);
372703b0b021SRandall Stewart 	else {
372803b0b021SRandall Stewart 		/* we really should not see this case */
372903b0b021SRandall Stewart 		TAILQ_INSERT_TAIL(&stcb->sctp_ep->read_queue, control, next);
373003b0b021SRandall Stewart 	}
373103b0b021SRandall Stewart 	if (stcb->sctp_ep && stcb->sctp_socket) {
373203b0b021SRandall Stewart 		/* This should always be the case */
373303b0b021SRandall Stewart 		sctp_sorwakeup(stcb->sctp_ep, stcb->sctp_socket);
3734f8829a4aSRandall Stewart 	}
3735f8829a4aSRandall Stewart }
3736f8829a4aSRandall Stewart 
3737f8829a4aSRandall Stewart static void
3738f8829a4aSRandall Stewart sctp_notify_shutdown_event(struct sctp_tcb *stcb)
3739f8829a4aSRandall Stewart {
3740f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3741f8829a4aSRandall Stewart 	struct sctp_shutdown_event *sse;
3742f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3743f8829a4aSRandall Stewart 
3744f8829a4aSRandall Stewart 	/*
3745f8829a4aSRandall Stewart 	 * For TCP model AND UDP connected sockets we will send an error up
3746f8829a4aSRandall Stewart 	 * when an SHUTDOWN completes
3747f8829a4aSRandall Stewart 	 */
3748f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
3749f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
3750f8829a4aSRandall Stewart 		/* mark socket closed for read/write and wakeup! */
3751f8829a4aSRandall Stewart 		socantsendmore(stcb->sctp_socket);
3752f8829a4aSRandall Stewart 	}
3753e2e7c62eSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVSHUTDOWNEVNT)) {
3754f8829a4aSRandall Stewart 		/* event not enabled */
3755f8829a4aSRandall Stewart 		return;
3756830d754dSRandall Stewart 	}
37570053ed28SMichael Tuexen 
3758eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_shutdown_event), 0, M_NOWAIT, 1, MT_DATA);
3759f8829a4aSRandall Stewart 	if (m_notify == NULL)
3760f8829a4aSRandall Stewart 		/* no space left */
3761f8829a4aSRandall Stewart 		return;
3762f8829a4aSRandall Stewart 	sse = mtod(m_notify, struct sctp_shutdown_event *);
3763e432298aSXin LI 	memset(sse, 0, sizeof(struct sctp_shutdown_event));
3764f8829a4aSRandall Stewart 	sse->sse_type = SCTP_SHUTDOWN_EVENT;
3765f8829a4aSRandall Stewart 	sse->sse_flags = 0;
3766f8829a4aSRandall Stewart 	sse->sse_length = sizeof(struct sctp_shutdown_event);
3767f8829a4aSRandall Stewart 	sse->sse_assoc_id = sctp_get_associd(stcb);
3768f8829a4aSRandall Stewart 
3769139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_shutdown_event);
3770139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3771f8829a4aSRandall Stewart 
3772f8829a4aSRandall Stewart 	/* append to socket */
3773f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
37747215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3775f8829a4aSRandall Stewart 	    m_notify);
3776f8829a4aSRandall Stewart 	if (control == NULL) {
3777f8829a4aSRandall Stewart 		/* no memory */
3778f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3779f8829a4aSRandall Stewart 		return;
3780f8829a4aSRandall Stewart 	}
3781139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
378228cd0699SMichael Tuexen 	control->spec_flags = M_NOTIFICATION;
3783f8829a4aSRandall Stewart 	/* not that we need this */
3784f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
3785f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3786f8829a4aSRandall Stewart 	    control,
3787cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, SCTP_SO_NOT_LOCKED);
3788f8829a4aSRandall Stewart }
3789f8829a4aSRandall Stewart 
3790f8829a4aSRandall Stewart static void
3791830d754dSRandall Stewart sctp_notify_sender_dry_event(struct sctp_tcb *stcb,
379228397ac1SMichael Tuexen     int so_locked)
3793830d754dSRandall Stewart {
3794830d754dSRandall Stewart 	struct mbuf *m_notify;
3795830d754dSRandall Stewart 	struct sctp_sender_dry_event *event;
3796830d754dSRandall Stewart 	struct sctp_queued_to_read *control;
3797830d754dSRandall Stewart 
379860990c0cSMichael Tuexen 	if ((stcb == NULL) ||
379960990c0cSMichael Tuexen 	    sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_DRYEVNT)) {
3800830d754dSRandall Stewart 		/* event not enabled */
3801830d754dSRandall Stewart 		return;
3802830d754dSRandall Stewart 	}
38030053ed28SMichael Tuexen 
3804eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_sender_dry_event), 0, M_NOWAIT, 1, MT_DATA);
3805830d754dSRandall Stewart 	if (m_notify == NULL) {
3806830d754dSRandall Stewart 		/* no space left */
3807830d754dSRandall Stewart 		return;
3808830d754dSRandall Stewart 	}
3809830d754dSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3810830d754dSRandall Stewart 	event = mtod(m_notify, struct sctp_sender_dry_event *);
3811e432298aSXin LI 	memset(event, 0, sizeof(struct sctp_sender_dry_event));
3812830d754dSRandall Stewart 	event->sender_dry_type = SCTP_SENDER_DRY_EVENT;
3813830d754dSRandall Stewart 	event->sender_dry_flags = 0;
3814830d754dSRandall Stewart 	event->sender_dry_length = sizeof(struct sctp_sender_dry_event);
3815830d754dSRandall Stewart 	event->sender_dry_assoc_id = sctp_get_associd(stcb);
3816830d754dSRandall Stewart 
3817830d754dSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_sender_dry_event);
3818830d754dSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3819830d754dSRandall Stewart 
3820830d754dSRandall Stewart 	/* append to socket */
3821830d754dSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
38227215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
38237215cc1bSMichael Tuexen 	    m_notify);
3824830d754dSRandall Stewart 	if (control == NULL) {
3825830d754dSRandall Stewart 		/* no memory */
3826830d754dSRandall Stewart 		sctp_m_freem(m_notify);
3827830d754dSRandall Stewart 		return;
3828830d754dSRandall Stewart 	}
3829830d754dSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3830830d754dSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3831830d754dSRandall Stewart 	/* not that we need this */
3832830d754dSRandall Stewart 	control->tail_mbuf = m_notify;
3833830d754dSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb, control,
3834cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, so_locked);
3835830d754dSRandall Stewart }
3836830d754dSRandall Stewart 
3837c4e848b7SRandall Stewart void
3838c4e848b7SRandall Stewart sctp_notify_stream_reset_add(struct sctp_tcb *stcb, uint16_t numberin, uint16_t numberout, int flag)
3839ea44232bSRandall Stewart {
3840ea44232bSRandall Stewart 	struct mbuf *m_notify;
3841ea44232bSRandall Stewart 	struct sctp_queued_to_read *control;
3842c4e848b7SRandall Stewart 	struct sctp_stream_change_event *stradd;
3843ea44232bSRandall Stewart 
38448c501e51SMichael Tuexen 	if ((stcb == NULL) ||
38458c501e51SMichael Tuexen 	    (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_STREAM_CHANGEEVNT))) {
3846ea44232bSRandall Stewart 		/* event not enabled */
3847ea44232bSRandall Stewart 		return;
3848ea44232bSRandall Stewart 	}
3849c4e848b7SRandall Stewart 	if ((stcb->asoc.peer_req_out) && flag) {
3850c4e848b7SRandall Stewart 		/* Peer made the request, don't tell the local user */
3851c4e848b7SRandall Stewart 		stcb->asoc.peer_req_out = 0;
3852c4e848b7SRandall Stewart 		return;
3853c4e848b7SRandall Stewart 	}
3854c4e848b7SRandall Stewart 	stcb->asoc.peer_req_out = 0;
3855e432298aSXin LI 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_stream_change_event), 0, M_NOWAIT, 1, MT_DATA);
3856ea44232bSRandall Stewart 	if (m_notify == NULL)
3857ea44232bSRandall Stewart 		/* no space left */
3858ea44232bSRandall Stewart 		return;
3859ea44232bSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3860c4e848b7SRandall Stewart 	stradd = mtod(m_notify, struct sctp_stream_change_event *);
3861e432298aSXin LI 	memset(stradd, 0, sizeof(struct sctp_stream_change_event));
3862c4e848b7SRandall Stewart 	stradd->strchange_type = SCTP_STREAM_CHANGE_EVENT;
3863c4e848b7SRandall Stewart 	stradd->strchange_flags = flag;
3864e432298aSXin LI 	stradd->strchange_length = sizeof(struct sctp_stream_change_event);
3865c4e848b7SRandall Stewart 	stradd->strchange_assoc_id = sctp_get_associd(stcb);
3866c4e848b7SRandall Stewart 	stradd->strchange_instrms = numberin;
3867c4e848b7SRandall Stewart 	stradd->strchange_outstrms = numberout;
3868e432298aSXin LI 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_stream_change_event);
3869ea44232bSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3870ea44232bSRandall Stewart 	if (sctp_sbspace(&stcb->asoc, &stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3871ea44232bSRandall Stewart 		/* no space */
3872ea44232bSRandall Stewart 		sctp_m_freem(m_notify);
3873ea44232bSRandall Stewart 		return;
3874ea44232bSRandall Stewart 	}
3875ea44232bSRandall Stewart 	/* append to socket */
3876ea44232bSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
38777215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3878ea44232bSRandall Stewart 	    m_notify);
3879ea44232bSRandall Stewart 	if (control == NULL) {
3880ea44232bSRandall Stewart 		/* no memory */
3881ea44232bSRandall Stewart 		sctp_m_freem(m_notify);
3882ea44232bSRandall Stewart 		return;
3883ea44232bSRandall Stewart 	}
3884ea44232bSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
388528cd0699SMichael Tuexen 	control->spec_flags = M_NOTIFICATION;
3886ea44232bSRandall Stewart 	/* not that we need this */
3887ea44232bSRandall Stewart 	control->tail_mbuf = m_notify;
3888ea44232bSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3889ea44232bSRandall Stewart 	    control,
3890cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, SCTP_SO_NOT_LOCKED);
3891ea44232bSRandall Stewart }
3892ea44232bSRandall Stewart 
3893c4e848b7SRandall Stewart void
3894c4e848b7SRandall Stewart sctp_notify_stream_reset_tsn(struct sctp_tcb *stcb, uint32_t sending_tsn, uint32_t recv_tsn, int flag)
3895c4e848b7SRandall Stewart {
3896c4e848b7SRandall Stewart 	struct mbuf *m_notify;
3897c4e848b7SRandall Stewart 	struct sctp_queued_to_read *control;
3898c4e848b7SRandall Stewart 	struct sctp_assoc_reset_event *strasoc;
3899c4e848b7SRandall Stewart 
39008c501e51SMichael Tuexen 	if ((stcb == NULL) ||
39018c501e51SMichael Tuexen 	    (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_ASSOC_RESETEVNT))) {
3902c4e848b7SRandall Stewart 		/* event not enabled */
3903c4e848b7SRandall Stewart 		return;
3904c4e848b7SRandall Stewart 	}
3905e432298aSXin LI 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_assoc_reset_event), 0, M_NOWAIT, 1, MT_DATA);
3906c4e848b7SRandall Stewart 	if (m_notify == NULL)
3907c4e848b7SRandall Stewart 		/* no space left */
3908c4e848b7SRandall Stewart 		return;
3909c4e848b7SRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3910c4e848b7SRandall Stewart 	strasoc = mtod(m_notify, struct sctp_assoc_reset_event *);
3911e432298aSXin LI 	memset(strasoc, 0, sizeof(struct sctp_assoc_reset_event));
3912c4e848b7SRandall Stewart 	strasoc->assocreset_type = SCTP_ASSOC_RESET_EVENT;
3913c4e848b7SRandall Stewart 	strasoc->assocreset_flags = flag;
3914e432298aSXin LI 	strasoc->assocreset_length = sizeof(struct sctp_assoc_reset_event);
3915c4e848b7SRandall Stewart 	strasoc->assocreset_assoc_id = sctp_get_associd(stcb);
3916c4e848b7SRandall Stewart 	strasoc->assocreset_local_tsn = sending_tsn;
3917c4e848b7SRandall Stewart 	strasoc->assocreset_remote_tsn = recv_tsn;
3918e432298aSXin LI 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_assoc_reset_event);
3919c4e848b7SRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3920c4e848b7SRandall Stewart 	if (sctp_sbspace(&stcb->asoc, &stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3921c4e848b7SRandall Stewart 		/* no space */
3922c4e848b7SRandall Stewart 		sctp_m_freem(m_notify);
3923c4e848b7SRandall Stewart 		return;
3924c4e848b7SRandall Stewart 	}
3925c4e848b7SRandall Stewart 	/* append to socket */
3926c4e848b7SRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3927c4e848b7SRandall Stewart 	    0, 0, stcb->asoc.context, 0, 0, 0,
3928c4e848b7SRandall Stewart 	    m_notify);
3929c4e848b7SRandall Stewart 	if (control == NULL) {
3930c4e848b7SRandall Stewart 		/* no memory */
3931c4e848b7SRandall Stewart 		sctp_m_freem(m_notify);
3932c4e848b7SRandall Stewart 		return;
3933c4e848b7SRandall Stewart 	}
3934c4e848b7SRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
393528cd0699SMichael Tuexen 	control->spec_flags = M_NOTIFICATION;
3936c4e848b7SRandall Stewart 	/* not that we need this */
3937c4e848b7SRandall Stewart 	control->tail_mbuf = m_notify;
3938c4e848b7SRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3939c4e848b7SRandall Stewart 	    control,
3940c4e848b7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, SCTP_SO_NOT_LOCKED);
3941c4e848b7SRandall Stewart }
3942c4e848b7SRandall Stewart 
3943830d754dSRandall Stewart static void
3944f8829a4aSRandall Stewart sctp_notify_stream_reset(struct sctp_tcb *stcb,
3945f8829a4aSRandall Stewart     int number_entries, uint16_t *list, int flag)
3946f8829a4aSRandall Stewart {
3947f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3948f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3949f8829a4aSRandall Stewart 	struct sctp_stream_reset_event *strreset;
3950f8829a4aSRandall Stewart 	int len;
3951f8829a4aSRandall Stewart 
39528c501e51SMichael Tuexen 	if ((stcb == NULL) ||
39538c501e51SMichael Tuexen 	    (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_STREAM_RESETEVNT))) {
3954f8829a4aSRandall Stewart 		/* event not enabled */
3955f8829a4aSRandall Stewart 		return;
3956830d754dSRandall Stewart 	}
39570053ed28SMichael Tuexen 
3958eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(MCLBYTES, 0, M_NOWAIT, 1, MT_DATA);
3959f8829a4aSRandall Stewart 	if (m_notify == NULL)
3960f8829a4aSRandall Stewart 		/* no space left */
3961f8829a4aSRandall Stewart 		return;
3962139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3963f8829a4aSRandall Stewart 	len = sizeof(struct sctp_stream_reset_event) + (number_entries * sizeof(uint16_t));
3964f8829a4aSRandall Stewart 	if (len > M_TRAILINGSPACE(m_notify)) {
3965f8829a4aSRandall Stewart 		/* never enough room */
3966f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3967f8829a4aSRandall Stewart 		return;
3968f8829a4aSRandall Stewart 	}
3969f8829a4aSRandall Stewart 	strreset = mtod(m_notify, struct sctp_stream_reset_event *);
3970e432298aSXin LI 	memset(strreset, 0, len);
3971f8829a4aSRandall Stewart 	strreset->strreset_type = SCTP_STREAM_RESET_EVENT;
3972c4e848b7SRandall Stewart 	strreset->strreset_flags = flag;
3973f8829a4aSRandall Stewart 	strreset->strreset_length = len;
3974f8829a4aSRandall Stewart 	strreset->strreset_assoc_id = sctp_get_associd(stcb);
3975f8829a4aSRandall Stewart 	if (number_entries) {
3976f8829a4aSRandall Stewart 		int i;
3977f8829a4aSRandall Stewart 
3978f8829a4aSRandall Stewart 		for (i = 0; i < number_entries; i++) {
3979c4e848b7SRandall Stewart 			strreset->strreset_stream_list[i] = ntohs(list[i]);
3980f8829a4aSRandall Stewart 		}
3981f8829a4aSRandall Stewart 	}
3982139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = len;
3983139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3984139bc87fSRandall Stewart 	if (sctp_sbspace(&stcb->asoc, &stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3985f8829a4aSRandall Stewart 		/* no space */
3986f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3987f8829a4aSRandall Stewart 		return;
3988f8829a4aSRandall Stewart 	}
3989f8829a4aSRandall Stewart 	/* append to socket */
3990f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
39917215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3992f8829a4aSRandall Stewart 	    m_notify);
3993f8829a4aSRandall Stewart 	if (control == NULL) {
3994f8829a4aSRandall Stewart 		/* no memory */
3995f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3996f8829a4aSRandall Stewart 		return;
3997f8829a4aSRandall Stewart 	}
3998139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
399928cd0699SMichael Tuexen 	control->spec_flags = M_NOTIFICATION;
4000f8829a4aSRandall Stewart 	/* not that we need this */
4001f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
4002f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
4003f8829a4aSRandall Stewart 	    control,
4004cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, SCTP_SO_NOT_LOCKED);
4005f8829a4aSRandall Stewart }
4006f8829a4aSRandall Stewart 
4007389b1b11SMichael Tuexen static void
4008389b1b11SMichael Tuexen sctp_notify_remote_error(struct sctp_tcb *stcb, uint16_t error, struct sctp_error_chunk *chunk)
4009389b1b11SMichael Tuexen {
4010389b1b11SMichael Tuexen 	struct mbuf *m_notify;
4011389b1b11SMichael Tuexen 	struct sctp_remote_error *sre;
4012389b1b11SMichael Tuexen 	struct sctp_queued_to_read *control;
40139a8e3088SMichael Tuexen 	unsigned int notif_len;
40149a8e3088SMichael Tuexen 	uint16_t chunk_len;
4015389b1b11SMichael Tuexen 
4016389b1b11SMichael Tuexen 	if ((stcb == NULL) ||
4017389b1b11SMichael Tuexen 	    sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVPEERERR)) {
4018389b1b11SMichael Tuexen 		return;
4019389b1b11SMichael Tuexen 	}
4020389b1b11SMichael Tuexen 	if (chunk != NULL) {
4021c9eb4473SMichael Tuexen 		chunk_len = ntohs(chunk->ch.chunk_length);
40229669e724SMichael Tuexen 		/*
40239669e724SMichael Tuexen 		 * Only SCTP_CHUNK_BUFFER_SIZE are guaranteed to be
402445d41de5SMichael Tuexen 		 * contiguous.
40259669e724SMichael Tuexen 		 */
40269669e724SMichael Tuexen 		if (chunk_len > SCTP_CHUNK_BUFFER_SIZE) {
40279669e724SMichael Tuexen 			chunk_len = SCTP_CHUNK_BUFFER_SIZE;
40289669e724SMichael Tuexen 		}
4029389b1b11SMichael Tuexen 	} else {
4030389b1b11SMichael Tuexen 		chunk_len = 0;
4031389b1b11SMichael Tuexen 	}
40329a8e3088SMichael Tuexen 	notif_len = (unsigned int)(sizeof(struct sctp_remote_error) + chunk_len);
4033eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(notif_len, 0, M_NOWAIT, 1, MT_DATA);
4034389b1b11SMichael Tuexen 	if (m_notify == NULL) {
4035389b1b11SMichael Tuexen 		/* Retry with smaller value. */
40369a8e3088SMichael Tuexen 		notif_len = (unsigned int)sizeof(struct sctp_remote_error);
4037eb1b1807SGleb Smirnoff 		m_notify = sctp_get_mbuf_for_msg(notif_len, 0, M_NOWAIT, 1, MT_DATA);
4038389b1b11SMichael Tuexen 		if (m_notify == NULL) {
4039389b1b11SMichael Tuexen 			return;
4040389b1b11SMichael Tuexen 		}
4041389b1b11SMichael Tuexen 	}
4042389b1b11SMichael Tuexen 	SCTP_BUF_NEXT(m_notify) = NULL;
4043389b1b11SMichael Tuexen 	sre = mtod(m_notify, struct sctp_remote_error *);
404456711f94SMichael Tuexen 	memset(sre, 0, notif_len);
4045389b1b11SMichael Tuexen 	sre->sre_type = SCTP_REMOTE_ERROR;
4046389b1b11SMichael Tuexen 	sre->sre_flags = 0;
4047389b1b11SMichael Tuexen 	sre->sre_length = sizeof(struct sctp_remote_error);
4048389b1b11SMichael Tuexen 	sre->sre_error = error;
4049389b1b11SMichael Tuexen 	sre->sre_assoc_id = sctp_get_associd(stcb);
4050389b1b11SMichael Tuexen 	if (notif_len > sizeof(struct sctp_remote_error)) {
4051389b1b11SMichael Tuexen 		memcpy(sre->sre_data, chunk, chunk_len);
4052389b1b11SMichael Tuexen 		sre->sre_length += chunk_len;
4053389b1b11SMichael Tuexen 	}
4054389b1b11SMichael Tuexen 	SCTP_BUF_LEN(m_notify) = sre->sre_length;
4055389b1b11SMichael Tuexen 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
4056389b1b11SMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
4057389b1b11SMichael Tuexen 	    m_notify);
4058389b1b11SMichael Tuexen 	if (control != NULL) {
4059389b1b11SMichael Tuexen 		control->length = SCTP_BUF_LEN(m_notify);
406028cd0699SMichael Tuexen 		control->spec_flags = M_NOTIFICATION;
4061389b1b11SMichael Tuexen 		/* not that we need this */
4062389b1b11SMichael Tuexen 		control->tail_mbuf = m_notify;
4063389b1b11SMichael Tuexen 		sctp_add_to_readq(stcb->sctp_ep, stcb,
4064389b1b11SMichael Tuexen 		    control,
4065389b1b11SMichael Tuexen 		    &stcb->sctp_socket->so_rcv, 1,
4066389b1b11SMichael Tuexen 		    SCTP_READ_LOCK_NOT_HELD, SCTP_SO_NOT_LOCKED);
4067389b1b11SMichael Tuexen 	} else {
4068389b1b11SMichael Tuexen 		sctp_m_freem(m_notify);
4069389b1b11SMichael Tuexen 	}
4070389b1b11SMichael Tuexen }
4071389b1b11SMichael Tuexen 
4072f8829a4aSRandall Stewart void
4073f8829a4aSRandall Stewart sctp_ulp_notify(uint32_t notification, struct sctp_tcb *stcb,
407428397ac1SMichael Tuexen     uint32_t error, void *data, int so_locked)
4075f8829a4aSRandall Stewart {
4076830d754dSRandall Stewart 	if ((stcb == NULL) ||
4077830d754dSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
4078f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
4079830d754dSRandall Stewart 	    (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET)) {
4080830d754dSRandall Stewart 		/* If the socket is gone we are out of here */
4081f8829a4aSRandall Stewart 		return;
4082f8829a4aSRandall Stewart 	}
4083a99b6783SRandall Stewart 	if (stcb->sctp_socket->so_rcv.sb_state & SBS_CANTRCVMORE) {
4084a99b6783SRandall Stewart 		return;
4085a99b6783SRandall Stewart 	}
4086839d21d6SMichael Tuexen 	if ((SCTP_GET_STATE(stcb) == SCTP_STATE_COOKIE_WAIT) ||
4087839d21d6SMichael Tuexen 	    (SCTP_GET_STATE(stcb) == SCTP_STATE_COOKIE_ECHOED)) {
408817205eccSRandall Stewart 		if ((notification == SCTP_NOTIFY_INTERFACE_DOWN) ||
408917205eccSRandall Stewart 		    (notification == SCTP_NOTIFY_INTERFACE_UP) ||
409017205eccSRandall Stewart 		    (notification == SCTP_NOTIFY_INTERFACE_CONFIRMED)) {
409117205eccSRandall Stewart 			/* Don't report these in front states */
409217205eccSRandall Stewart 			return;
409317205eccSRandall Stewart 		}
409417205eccSRandall Stewart 	}
4095f8829a4aSRandall Stewart 	switch (notification) {
4096f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_UP:
4097f8829a4aSRandall Stewart 		if (stcb->asoc.assoc_up_sent == 0) {
4098105b68b4SMichael Tuexen 			sctp_notify_assoc_change(SCTP_COMM_UP, stcb, error, NULL, false, false, so_locked);
4099f8829a4aSRandall Stewart 			stcb->asoc.assoc_up_sent = 1;
4100f8829a4aSRandall Stewart 		}
41012afb3e84SRandall Stewart 		if (stcb->asoc.adaptation_needed && (stcb->asoc.adaptation_sent == 0)) {
41027215cc1bSMichael Tuexen 			sctp_notify_adaptation_layer(stcb);
41032afb3e84SRandall Stewart 		}
4104c79bec9cSMichael Tuexen 		if (stcb->asoc.auth_supported == 0) {
4105830d754dSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_NO_PEER_AUTH, stcb, 0,
4106830d754dSRandall Stewart 			    NULL, so_locked);
4107830d754dSRandall Stewart 		}
4108f8829a4aSRandall Stewart 		break;
4109f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_DOWN:
4110105b68b4SMichael Tuexen 		sctp_notify_assoc_change(SCTP_SHUTDOWN_COMP, stcb, error, NULL, false, false, so_locked);
4111f8829a4aSRandall Stewart 		break;
4112f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_DOWN:
4113f8829a4aSRandall Stewart 		{
4114f8829a4aSRandall Stewart 			struct sctp_nets *net;
4115f8829a4aSRandall Stewart 
4116f8829a4aSRandall Stewart 			net = (struct sctp_nets *)data;
4117f8829a4aSRandall Stewart 			sctp_notify_peer_addr_change(stcb, SCTP_ADDR_UNREACHABLE,
41183cb3567dSMichael Tuexen 			    (struct sockaddr *)&net->ro._l_addr, error, so_locked);
4119f8829a4aSRandall Stewart 			break;
4120f8829a4aSRandall Stewart 		}
4121f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_UP:
4122f8829a4aSRandall Stewart 		{
4123f8829a4aSRandall Stewart 			struct sctp_nets *net;
4124f8829a4aSRandall Stewart 
4125f8829a4aSRandall Stewart 			net = (struct sctp_nets *)data;
4126f8829a4aSRandall Stewart 			sctp_notify_peer_addr_change(stcb, SCTP_ADDR_AVAILABLE,
41273cb3567dSMichael Tuexen 			    (struct sockaddr *)&net->ro._l_addr, error, so_locked);
4128f8829a4aSRandall Stewart 			break;
4129f8829a4aSRandall Stewart 		}
4130f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_CONFIRMED:
4131f8829a4aSRandall Stewart 		{
4132f8829a4aSRandall Stewart 			struct sctp_nets *net;
4133f8829a4aSRandall Stewart 
4134f8829a4aSRandall Stewart 			net = (struct sctp_nets *)data;
4135f8829a4aSRandall Stewart 			sctp_notify_peer_addr_change(stcb, SCTP_ADDR_CONFIRMED,
41363cb3567dSMichael Tuexen 			    (struct sockaddr *)&net->ro._l_addr, error, so_locked);
4137f8829a4aSRandall Stewart 			break;
4138f8829a4aSRandall Stewart 		}
4139f8829a4aSRandall Stewart 	case SCTP_NOTIFY_SPECIAL_SP_FAIL:
4140f8829a4aSRandall Stewart 		sctp_notify_send_failed2(stcb, error,
4141ceaad40aSRandall Stewart 		    (struct sctp_stream_queue_pending *)data, so_locked);
4142f8829a4aSRandall Stewart 		break;
41431edc9dbaSMichael Tuexen 	case SCTP_NOTIFY_SENT_DG_FAIL:
41441edc9dbaSMichael Tuexen 		sctp_notify_send_failed(stcb, 1, error,
41451edc9dbaSMichael Tuexen 		    (struct sctp_tmit_chunk *)data, so_locked);
41461edc9dbaSMichael Tuexen 		break;
41471edc9dbaSMichael Tuexen 	case SCTP_NOTIFY_UNSENT_DG_FAIL:
41481edc9dbaSMichael Tuexen 		sctp_notify_send_failed(stcb, 0, error,
4149ceaad40aSRandall Stewart 		    (struct sctp_tmit_chunk *)data, so_locked);
4150f8829a4aSRandall Stewart 		break;
4151f8829a4aSRandall Stewart 	case SCTP_NOTIFY_PARTIAL_DELVIERY_INDICATION:
41529a6142d8SRandall Stewart 		{
41539a6142d8SRandall Stewart 			uint32_t val;
41549a6142d8SRandall Stewart 
41559a6142d8SRandall Stewart 			val = *((uint32_t *)data);
41569a6142d8SRandall Stewart 
4157810ec536SMichael Tuexen 			sctp_notify_partial_delivery_indication(stcb, error, val, so_locked);
4158f8829a4aSRandall Stewart 			break;
4159810ec536SMichael Tuexen 		}
4160410a3b1eSMichael Tuexen 	case SCTP_NOTIFY_ASSOC_LOC_ABORTED:
4161839d21d6SMichael Tuexen 		if ((SCTP_GET_STATE(stcb) == SCTP_STATE_COOKIE_WAIT) ||
4162839d21d6SMichael Tuexen 		    (SCTP_GET_STATE(stcb) == SCTP_STATE_COOKIE_ECHOED)) {
4163105b68b4SMichael Tuexen 			sctp_notify_assoc_change(SCTP_CANT_STR_ASSOC, stcb, error, data, false, false, so_locked);
4164c105859eSRandall Stewart 		} else {
4165105b68b4SMichael Tuexen 			sctp_notify_assoc_change(SCTP_COMM_LOST, stcb, error, data, false, false, so_locked);
4166410a3b1eSMichael Tuexen 		}
4167410a3b1eSMichael Tuexen 		break;
4168410a3b1eSMichael Tuexen 	case SCTP_NOTIFY_ASSOC_REM_ABORTED:
4169839d21d6SMichael Tuexen 		if ((SCTP_GET_STATE(stcb) == SCTP_STATE_COOKIE_WAIT) ||
4170839d21d6SMichael Tuexen 		    (SCTP_GET_STATE(stcb) == SCTP_STATE_COOKIE_ECHOED)) {
4171105b68b4SMichael Tuexen 			sctp_notify_assoc_change(SCTP_CANT_STR_ASSOC, stcb, error, data, true, false, so_locked);
4172410a3b1eSMichael Tuexen 		} else {
4173105b68b4SMichael Tuexen 			sctp_notify_assoc_change(SCTP_COMM_LOST, stcb, error, data, true, false, so_locked);
4174105b68b4SMichael Tuexen 		}
4175105b68b4SMichael Tuexen 		break;
4176105b68b4SMichael Tuexen 	case SCTP_NOTIFY_ASSOC_TIMEDOUT:
4177105b68b4SMichael Tuexen 		if ((SCTP_GET_STATE(stcb) == SCTP_STATE_COOKIE_WAIT) ||
4178105b68b4SMichael Tuexen 		    (SCTP_GET_STATE(stcb) == SCTP_STATE_COOKIE_ECHOED)) {
4179105b68b4SMichael Tuexen 			sctp_notify_assoc_change(SCTP_CANT_STR_ASSOC, stcb, error, data, false, true, so_locked);
4180105b68b4SMichael Tuexen 		} else {
4181105b68b4SMichael Tuexen 			sctp_notify_assoc_change(SCTP_COMM_LOST, stcb, error, data, false, true, so_locked);
4182c105859eSRandall Stewart 		}
4183f8829a4aSRandall Stewart 		break;
4184f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_RESTART:
4185105b68b4SMichael Tuexen 		sctp_notify_assoc_change(SCTP_RESTART, stcb, error, NULL, false, false, so_locked);
4186c79bec9cSMichael Tuexen 		if (stcb->asoc.auth_supported == 0) {
4187830d754dSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_NO_PEER_AUTH, stcb, 0,
4188830d754dSRandall Stewart 			    NULL, so_locked);
4189830d754dSRandall Stewart 		}
4190f8829a4aSRandall Stewart 		break;
4191f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_SEND:
4192d7714577SMichael Tuexen 		sctp_notify_stream_reset(stcb, error, ((uint16_t *)data), SCTP_STREAM_RESET_OUTGOING_SSN);
4193f8829a4aSRandall Stewart 		break;
4194f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_RECV:
4195d7714577SMichael Tuexen 		sctp_notify_stream_reset(stcb, error, ((uint16_t *)data), SCTP_STREAM_RESET_INCOMING);
4196f8829a4aSRandall Stewart 		break;
4197f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_FAILED_OUT:
4198c4e848b7SRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *)data),
4199d7714577SMichael Tuexen 		    (SCTP_STREAM_RESET_OUTGOING_SSN | SCTP_STREAM_RESET_FAILED));
4200f8829a4aSRandall Stewart 		break;
4201d4260646SMichael Tuexen 	case SCTP_NOTIFY_STR_RESET_DENIED_OUT:
4202d4260646SMichael Tuexen 		sctp_notify_stream_reset(stcb, error, ((uint16_t *)data),
4203d4260646SMichael Tuexen 		    (SCTP_STREAM_RESET_OUTGOING_SSN | SCTP_STREAM_RESET_DENIED));
4204d4260646SMichael Tuexen 		break;
4205f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_FAILED_IN:
4206c4e848b7SRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *)data),
4207d7714577SMichael Tuexen 		    (SCTP_STREAM_RESET_INCOMING | SCTP_STREAM_RESET_FAILED));
4208f8829a4aSRandall Stewart 		break;
4209d4260646SMichael Tuexen 	case SCTP_NOTIFY_STR_RESET_DENIED_IN:
4210d4260646SMichael Tuexen 		sctp_notify_stream_reset(stcb, error, ((uint16_t *)data),
4211d4260646SMichael Tuexen 		    (SCTP_STREAM_RESET_INCOMING | SCTP_STREAM_RESET_DENIED));
4212d4260646SMichael Tuexen 		break;
4213f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_ADD_IP:
4214f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_ADDED, data,
42153cb3567dSMichael Tuexen 		    error, so_locked);
4216f8829a4aSRandall Stewart 		break;
4217f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_DELETE_IP:
4218f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_REMOVED, data,
42193cb3567dSMichael Tuexen 		    error, so_locked);
4220f8829a4aSRandall Stewart 		break;
4221f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_SET_PRIMARY:
4222f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_MADE_PRIM, data,
42233cb3567dSMichael Tuexen 		    error, so_locked);
4224f8829a4aSRandall Stewart 		break;
4225f8829a4aSRandall Stewart 	case SCTP_NOTIFY_PEER_SHUTDOWN:
4226f8829a4aSRandall Stewart 		sctp_notify_shutdown_event(stcb);
4227f8829a4aSRandall Stewart 		break;
4228f8829a4aSRandall Stewart 	case SCTP_NOTIFY_AUTH_NEW_KEY:
422978f28045SMichael Tuexen 		sctp_notify_authentication(stcb, SCTP_AUTH_NEW_KEY, error,
4230830d754dSRandall Stewart 		    (uint16_t)(uintptr_t)data,
4231830d754dSRandall Stewart 		    so_locked);
4232f8829a4aSRandall Stewart 		break;
4233830d754dSRandall Stewart 	case SCTP_NOTIFY_AUTH_FREE_KEY:
4234830d754dSRandall Stewart 		sctp_notify_authentication(stcb, SCTP_AUTH_FREE_KEY, error,
4235830d754dSRandall Stewart 		    (uint16_t)(uintptr_t)data,
4236830d754dSRandall Stewart 		    so_locked);
4237f8829a4aSRandall Stewart 		break;
4238830d754dSRandall Stewart 	case SCTP_NOTIFY_NO_PEER_AUTH:
4239830d754dSRandall Stewart 		sctp_notify_authentication(stcb, SCTP_AUTH_NO_AUTH, error,
4240830d754dSRandall Stewart 		    (uint16_t)(uintptr_t)data,
4241830d754dSRandall Stewart 		    so_locked);
4242830d754dSRandall Stewart 		break;
4243830d754dSRandall Stewart 	case SCTP_NOTIFY_SENDER_DRY:
4244830d754dSRandall Stewart 		sctp_notify_sender_dry_event(stcb, so_locked);
4245830d754dSRandall Stewart 		break;
4246389b1b11SMichael Tuexen 	case SCTP_NOTIFY_REMOTE_ERROR:
4247389b1b11SMichael Tuexen 		sctp_notify_remote_error(stcb, error, data);
4248389b1b11SMichael Tuexen 		break;
4249f8829a4aSRandall Stewart 	default:
4250ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_UTIL1, "%s: unknown notification %xh (%u)\n",
42516e9c45e0SMichael Tuexen 		    __func__, notification, notification);
4252f8829a4aSRandall Stewart 		break;
4253f8829a4aSRandall Stewart 	}			/* end switch */
4254f8829a4aSRandall Stewart }
4255f8829a4aSRandall Stewart 
4256f8829a4aSRandall Stewart void
4257f5d30f7fSMichael Tuexen sctp_report_all_outbound(struct sctp_tcb *stcb, uint16_t error, int so_locked)
4258f8829a4aSRandall Stewart {
4259f8829a4aSRandall Stewart 	struct sctp_association *asoc;
4260f8829a4aSRandall Stewart 	struct sctp_stream_out *outs;
42614a9ef3f8SMichael Tuexen 	struct sctp_tmit_chunk *chk, *nchk;
42624a9ef3f8SMichael Tuexen 	struct sctp_stream_queue_pending *sp, *nsp;
42637f34832bSRandall Stewart 	int i;
4264f8829a4aSRandall Stewart 
4265ad81507eSRandall Stewart 	if (stcb == NULL) {
4266ad81507eSRandall Stewart 		return;
4267ad81507eSRandall Stewart 	}
42684a9ef3f8SMichael Tuexen 	asoc = &stcb->asoc;
42694a9ef3f8SMichael Tuexen 	if (asoc->state & SCTP_STATE_ABOUT_TO_BE_FREED) {
4270478fbccbSRandall Stewart 		/* already being freed */
4271478fbccbSRandall Stewart 		return;
4272478fbccbSRandall Stewart 	}
4273f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
4274f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
42754a9ef3f8SMichael Tuexen 	    (asoc->state & SCTP_STATE_CLOSED_SOCKET)) {
4276f8829a4aSRandall Stewart 		return;
4277f8829a4aSRandall Stewart 	}
4278f8829a4aSRandall Stewart 	/* now through all the gunk freeing chunks */
4279d00aff5dSRandall Stewart 	/* sent queue SHOULD be empty */
42804a9ef3f8SMichael Tuexen 	TAILQ_FOREACH_SAFE(chk, &asoc->sent_queue, sctp_next, nchk) {
4281d00aff5dSRandall Stewart 		TAILQ_REMOVE(&asoc->sent_queue, chk, sctp_next);
4282d00aff5dSRandall Stewart 		asoc->sent_queue_cnt--;
4283325c8c46SMichael Tuexen 		if (chk->sent != SCTP_DATAGRAM_NR_ACKED) {
428449656eefSMichael Tuexen 			if (asoc->strmout[chk->rec.data.sid].chunks_on_queues > 0) {
428549656eefSMichael Tuexen 				asoc->strmout[chk->rec.data.sid].chunks_on_queues--;
4286a7ad6026SMichael Tuexen #ifdef INVARIANTS
4287a7ad6026SMichael Tuexen 			} else {
428849656eefSMichael Tuexen 				panic("No chunks on the queues for sid %u.", chk->rec.data.sid);
4289a7ad6026SMichael Tuexen #endif
4290a7ad6026SMichael Tuexen 			}
4291a7ad6026SMichael Tuexen 		}
42920c0982b8SRandall Stewart 		if (chk->data != NULL) {
4293d00aff5dSRandall Stewart 			sctp_free_bufspace(stcb, asoc, chk, 1);
42941edc9dbaSMichael Tuexen 			sctp_ulp_notify(SCTP_NOTIFY_SENT_DG_FAIL, stcb,
42951edc9dbaSMichael Tuexen 			    error, chk, so_locked);
4296810ec536SMichael Tuexen 			if (chk->data) {
4297d00aff5dSRandall Stewart 				sctp_m_freem(chk->data);
4298d00aff5dSRandall Stewart 				chk->data = NULL;
4299d00aff5dSRandall Stewart 			}
4300810ec536SMichael Tuexen 		}
4301689e6a5fSMichael Tuexen 		sctp_free_a_chunk(stcb, chk, so_locked);
4302d00aff5dSRandall Stewart 		/* sa_ignore FREED_MEMORY */
4303d00aff5dSRandall Stewart 	}
4304d00aff5dSRandall Stewart 	/* pending send queue SHOULD be empty */
43054a9ef3f8SMichael Tuexen 	TAILQ_FOREACH_SAFE(chk, &asoc->send_queue, sctp_next, nchk) {
4306d00aff5dSRandall Stewart 		TAILQ_REMOVE(&asoc->send_queue, chk, sctp_next);
4307d00aff5dSRandall Stewart 		asoc->send_queue_cnt--;
430849656eefSMichael Tuexen 		if (asoc->strmout[chk->rec.data.sid].chunks_on_queues > 0) {
430949656eefSMichael Tuexen 			asoc->strmout[chk->rec.data.sid].chunks_on_queues--;
4310a7ad6026SMichael Tuexen #ifdef INVARIANTS
4311a7ad6026SMichael Tuexen 		} else {
431249656eefSMichael Tuexen 			panic("No chunks on the queues for sid %u.", chk->rec.data.sid);
4313a7ad6026SMichael Tuexen #endif
4314a7ad6026SMichael Tuexen 		}
43150c0982b8SRandall Stewart 		if (chk->data != NULL) {
4316d00aff5dSRandall Stewart 			sctp_free_bufspace(stcb, asoc, chk, 1);
43171edc9dbaSMichael Tuexen 			sctp_ulp_notify(SCTP_NOTIFY_UNSENT_DG_FAIL, stcb,
43181edc9dbaSMichael Tuexen 			    error, chk, so_locked);
4319810ec536SMichael Tuexen 			if (chk->data) {
4320d00aff5dSRandall Stewart 				sctp_m_freem(chk->data);
4321d00aff5dSRandall Stewart 				chk->data = NULL;
4322d00aff5dSRandall Stewart 			}
4323810ec536SMichael Tuexen 		}
4324689e6a5fSMichael Tuexen 		sctp_free_a_chunk(stcb, chk, so_locked);
4325d00aff5dSRandall Stewart 		/* sa_ignore FREED_MEMORY */
4326d00aff5dSRandall Stewart 	}
43274a9ef3f8SMichael Tuexen 	for (i = 0; i < asoc->streamoutcnt; i++) {
43287f34832bSRandall Stewart 		/* For each stream */
43294a9ef3f8SMichael Tuexen 		outs = &asoc->strmout[i];
43307f34832bSRandall Stewart 		/* clean up any sends there */
43314a9ef3f8SMichael Tuexen 		TAILQ_FOREACH_SAFE(sp, &outs->outqueue, next, nsp) {
43324d58b0c3SMichael Tuexen 			atomic_subtract_int(&asoc->stream_queue_cnt, 1);
4333f8829a4aSRandall Stewart 			TAILQ_REMOVE(&outs->outqueue, sp, next);
4334762ae0ecSMichael Tuexen 			stcb->asoc.ss_functions.sctp_ss_remove_from_stream(stcb, asoc, outs, sp);
4335f8829a4aSRandall Stewart 			sctp_free_spbufspace(stcb, asoc, sp);
4336478fbccbSRandall Stewart 			if (sp->data) {
4337f8829a4aSRandall Stewart 				sctp_ulp_notify(SCTP_NOTIFY_SPECIAL_SP_FAIL, stcb,
43381edc9dbaSMichael Tuexen 				    error, (void *)sp, so_locked);
4339f8829a4aSRandall Stewart 				if (sp->data) {
4340f8829a4aSRandall Stewart 					sctp_m_freem(sp->data);
4341f8829a4aSRandall Stewart 					sp->data = NULL;
4342d07b2ac6SMichael Tuexen 					sp->tail_mbuf = NULL;
4343d07b2ac6SMichael Tuexen 					sp->length = 0;
4344f8829a4aSRandall Stewart 				}
4345478fbccbSRandall Stewart 			}
43469eea4a2dSMichael Tuexen 			if (sp->net) {
4347f8829a4aSRandall Stewart 				sctp_free_remote_addr(sp->net);
4348f8829a4aSRandall Stewart 				sp->net = NULL;
43499eea4a2dSMichael Tuexen 			}
4350f8829a4aSRandall Stewart 			/* Free the chunk */
4351689e6a5fSMichael Tuexen 			sctp_free_a_strmoq(stcb, sp, so_locked);
43523c503c28SRandall Stewart 			/* sa_ignore FREED_MEMORY */
4353f8829a4aSRandall Stewart 		}
4354f8829a4aSRandall Stewart 	}
4355ad81507eSRandall Stewart }
4356f8829a4aSRandall Stewart 
4357f8829a4aSRandall Stewart void
4358105b68b4SMichael Tuexen sctp_abort_notification(struct sctp_tcb *stcb, bool from_peer, bool timeout,
4359105b68b4SMichael Tuexen     uint16_t error, struct sctp_abort_chunk *abort,
4360105b68b4SMichael Tuexen     int so_locked)
4361f8829a4aSRandall Stewart {
4362ad81507eSRandall Stewart 	if (stcb == NULL) {
4363ad81507eSRandall Stewart 		return;
4364ad81507eSRandall Stewart 	}
4365c55b70ceSMichael Tuexen 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL) ||
4366c55b70ceSMichael Tuexen 	    ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) &&
4367c55b70ceSMichael Tuexen 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_CONNECTED))) {
4368c55b70ceSMichael Tuexen 		stcb->sctp_ep->sctp_flags |= SCTP_PCB_FLAGS_WAS_ABORTED;
4369c55b70ceSMichael Tuexen 	}
4370f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
4371f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
4372f8829a4aSRandall Stewart 	    (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET)) {
4373f8829a4aSRandall Stewart 		return;
4374f8829a4aSRandall Stewart 	}
4375f5d30f7fSMichael Tuexen 	SCTP_TCB_SEND_LOCK(stcb);
4376f5d30f7fSMichael Tuexen 	SCTP_ADD_SUBSTATE(stcb, SCTP_STATE_WAS_ABORTED);
4377f8829a4aSRandall Stewart 	/* Tell them we lost the asoc */
4378f5d30f7fSMichael Tuexen 	sctp_report_all_outbound(stcb, error, so_locked);
4379f5d30f7fSMichael Tuexen 	SCTP_TCB_SEND_UNLOCK(stcb);
4380410a3b1eSMichael Tuexen 	if (from_peer) {
4381410a3b1eSMichael Tuexen 		sctp_ulp_notify(SCTP_NOTIFY_ASSOC_REM_ABORTED, stcb, error, abort, so_locked);
4382410a3b1eSMichael Tuexen 	} else {
4383105b68b4SMichael Tuexen 		if (timeout) {
4384105b68b4SMichael Tuexen 			sctp_ulp_notify(SCTP_NOTIFY_ASSOC_TIMEDOUT, stcb, error, abort, so_locked);
4385105b68b4SMichael Tuexen 		} else {
4386410a3b1eSMichael Tuexen 			sctp_ulp_notify(SCTP_NOTIFY_ASSOC_LOC_ABORTED, stcb, error, abort, so_locked);
4387410a3b1eSMichael Tuexen 		}
4388f8829a4aSRandall Stewart 	}
4389105b68b4SMichael Tuexen }
4390f8829a4aSRandall Stewart 
4391f8829a4aSRandall Stewart void
4392f8829a4aSRandall Stewart sctp_abort_association(struct sctp_inpcb *inp, struct sctp_tcb *stcb,
4393b1754ad1SMichael Tuexen     struct mbuf *m, int iphlen,
4394b1754ad1SMichael Tuexen     struct sockaddr *src, struct sockaddr *dst,
4395b1754ad1SMichael Tuexen     struct sctphdr *sh, struct mbuf *op_err,
4396457b4b88SMichael Tuexen     uint8_t mflowtype, uint32_t mflowid,
4397c54a18d2SRandall Stewart     uint32_t vrf_id, uint16_t port)
4398f8829a4aSRandall Stewart {
439984992a32SMichael Tuexen 	struct sctp_gen_error_cause *cause;
4400f8829a4aSRandall Stewart 	uint32_t vtag;
440184992a32SMichael Tuexen 	uint16_t cause_code;
4402ceaad40aSRandall Stewart 
4403f8829a4aSRandall Stewart 	if (stcb != NULL) {
4404f8829a4aSRandall Stewart 		vtag = stcb->asoc.peer_vtag;
440517205eccSRandall Stewart 		vrf_id = stcb->asoc.vrf_id;
440684992a32SMichael Tuexen 		if (op_err != NULL) {
440784992a32SMichael Tuexen 			/* Read the cause code from the error cause. */
440884992a32SMichael Tuexen 			cause = mtod(op_err, struct sctp_gen_error_cause *);
440984992a32SMichael Tuexen 			cause_code = ntohs(cause->code);
441084992a32SMichael Tuexen 		} else {
441184992a32SMichael Tuexen 			cause_code = 0;
441284992a32SMichael Tuexen 		}
441384992a32SMichael Tuexen 	} else {
441484992a32SMichael Tuexen 		vtag = 0;
4415f8829a4aSRandall Stewart 	}
4416b1754ad1SMichael Tuexen 	sctp_send_abort(m, iphlen, src, dst, sh, vtag, op_err,
4417d089f9b9SMichael Tuexen 	    mflowtype, mflowid, inp->fibnum,
4418f30ac432SMichael Tuexen 	    vrf_id, port);
4419f8829a4aSRandall Stewart 	if (stcb != NULL) {
4420884d8c53SMichael Tuexen 		/* We have a TCB to abort, send notification too */
4421105b68b4SMichael Tuexen 		sctp_abort_notification(stcb, false, false, cause_code, NULL, SCTP_SO_NOT_LOCKED);
4422f8829a4aSRandall Stewart 		/* Ok, now lets free it */
44230271d0cdSMichael Tuexen 		SCTP_STAT_INCR_COUNTER32(sctps_aborted);
4424839d21d6SMichael Tuexen 		if ((SCTP_GET_STATE(stcb) == SCTP_STATE_OPEN) ||
4425839d21d6SMichael Tuexen 		    (SCTP_GET_STATE(stcb) == SCTP_STATE_SHUTDOWN_RECEIVED)) {
44260271d0cdSMichael Tuexen 			SCTP_STAT_DECR_GAUGE32(sctps_currestab);
44270271d0cdSMichael Tuexen 		}
4428ba785902SMichael Tuexen 		(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
4429ba785902SMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_4);
4430f8829a4aSRandall Stewart 	}
4431f8829a4aSRandall Stewart }
4432f1f73e57SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
4433f1f73e57SRandall Stewart void
4434f1f73e57SRandall Stewart sctp_print_out_track_log(struct sctp_tcb *stcb)
4435f1f73e57SRandall Stewart {
443618e198d3SRandall Stewart #ifdef NOSIY_PRINTS
4437f1f73e57SRandall Stewart 	int i;
4438f1f73e57SRandall Stewart 
4439ad81507eSRandall Stewart 	SCTP_PRINTF("Last ep reason:%x\n", stcb->sctp_ep->last_abort_code);
4440ad81507eSRandall Stewart 	SCTP_PRINTF("IN bound TSN log-aaa\n");
4441f1f73e57SRandall Stewart 	if ((stcb->asoc.tsn_in_at == 0) && (stcb->asoc.tsn_in_wrapped == 0)) {
4442ad81507eSRandall Stewart 		SCTP_PRINTF("None rcvd\n");
4443f1f73e57SRandall Stewart 		goto none_in;
4444f1f73e57SRandall Stewart 	}
4445f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_in_wrapped) {
4446f1f73e57SRandall Stewart 		for (i = stcb->asoc.tsn_in_at; i < SCTP_TSN_LOG_SIZE; i++) {
4447ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
4448f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].tsn,
4449f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].strm,
4450f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].seq,
4451f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].flgs,
4452f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].sz);
4453f1f73e57SRandall Stewart 		}
4454f1f73e57SRandall Stewart 	}
4455f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_in_at) {
4456f1f73e57SRandall Stewart 		for (i = 0; i < stcb->asoc.tsn_in_at; i++) {
4457ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
4458f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].tsn,
4459f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].strm,
4460f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].seq,
4461f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].flgs,
4462f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].sz);
4463f1f73e57SRandall Stewart 		}
4464f1f73e57SRandall Stewart 	}
4465f1f73e57SRandall Stewart none_in:
4466ad81507eSRandall Stewart 	SCTP_PRINTF("OUT bound TSN log-aaa\n");
4467ad81507eSRandall Stewart 	if ((stcb->asoc.tsn_out_at == 0) &&
4468ad81507eSRandall Stewart 	    (stcb->asoc.tsn_out_wrapped == 0)) {
4469ad81507eSRandall Stewart 		SCTP_PRINTF("None sent\n");
4470f1f73e57SRandall Stewart 	}
4471f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_out_wrapped) {
4472f1f73e57SRandall Stewart 		for (i = stcb->asoc.tsn_out_at; i < SCTP_TSN_LOG_SIZE; i++) {
4473ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
4474f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].tsn,
4475f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].strm,
4476f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].seq,
4477f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].flgs,
4478f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].sz);
4479f1f73e57SRandall Stewart 		}
4480f1f73e57SRandall Stewart 	}
4481f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_out_at) {
4482f1f73e57SRandall Stewart 		for (i = 0; i < stcb->asoc.tsn_out_at; i++) {
4483ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
4484f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].tsn,
4485f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].strm,
4486f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].seq,
4487f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].flgs,
4488f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].sz);
4489f1f73e57SRandall Stewart 		}
4490f1f73e57SRandall Stewart 	}
449118e198d3SRandall Stewart #endif
4492f1f73e57SRandall Stewart }
4493f1f73e57SRandall Stewart #endif
4494f1f73e57SRandall Stewart 
4495f8829a4aSRandall Stewart void
4496f8829a4aSRandall Stewart sctp_abort_an_association(struct sctp_inpcb *inp, struct sctp_tcb *stcb,
4497105b68b4SMichael Tuexen     struct mbuf *op_err, bool timedout, int so_locked)
4498f8829a4aSRandall Stewart {
449984992a32SMichael Tuexen 	struct sctp_gen_error_cause *cause;
450084992a32SMichael Tuexen 	uint16_t cause_code;
4501ceaad40aSRandall Stewart 
4502f8829a4aSRandall Stewart 	if (stcb == NULL) {
4503f8829a4aSRandall Stewart 		/* Got to have a TCB */
4504f8829a4aSRandall Stewart 		if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
4505fe1831e0SMichael Tuexen 			if (LIST_EMPTY(&inp->sctp_asoc_list)) {
4506b0552ae2SRandall Stewart 				sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
4507b0552ae2SRandall Stewart 				    SCTP_CALLED_DIRECTLY_NOCMPSET);
4508f8829a4aSRandall Stewart 			}
4509f8829a4aSRandall Stewart 		}
4510f8829a4aSRandall Stewart 		return;
4511f8829a4aSRandall Stewart 	}
451284992a32SMichael Tuexen 	if (op_err != NULL) {
451384992a32SMichael Tuexen 		/* Read the cause code from the error cause. */
451484992a32SMichael Tuexen 		cause = mtod(op_err, struct sctp_gen_error_cause *);
451584992a32SMichael Tuexen 		cause_code = ntohs(cause->code);
451684992a32SMichael Tuexen 	} else {
451784992a32SMichael Tuexen 		cause_code = 0;
451884992a32SMichael Tuexen 	}
4519f8829a4aSRandall Stewart 	/* notify the peer */
4520ceaad40aSRandall Stewart 	sctp_send_abort_tcb(stcb, op_err, so_locked);
4521f8829a4aSRandall Stewart 	SCTP_STAT_INCR_COUNTER32(sctps_aborted);
4522839d21d6SMichael Tuexen 	if ((SCTP_GET_STATE(stcb) == SCTP_STATE_OPEN) ||
4523839d21d6SMichael Tuexen 	    (SCTP_GET_STATE(stcb) == SCTP_STATE_SHUTDOWN_RECEIVED)) {
4524f8829a4aSRandall Stewart 		SCTP_STAT_DECR_GAUGE32(sctps_currestab);
4525f8829a4aSRandall Stewart 	}
4526884d8c53SMichael Tuexen 	/* notify the ulp */
4527884d8c53SMichael Tuexen 	if ((inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) == 0) {
4528105b68b4SMichael Tuexen 		sctp_abort_notification(stcb, false, timedout, cause_code, NULL, so_locked);
4529884d8c53SMichael Tuexen 	}
4530f8829a4aSRandall Stewart 	/* now free the asoc */
4531f1f73e57SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
4532f1f73e57SRandall Stewart 	sctp_print_out_track_log(stcb);
4533f1f73e57SRandall Stewart #endif
4534ba785902SMichael Tuexen 	(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
4535ba785902SMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_5);
4536f8829a4aSRandall Stewart }
4537f8829a4aSRandall Stewart 
4538f8829a4aSRandall Stewart void
4539b1754ad1SMichael Tuexen sctp_handle_ootb(struct mbuf *m, int iphlen, int offset,
4540b1754ad1SMichael Tuexen     struct sockaddr *src, struct sockaddr *dst,
4541b1754ad1SMichael Tuexen     struct sctphdr *sh, struct sctp_inpcb *inp,
4542ff1ffd74SMichael Tuexen     struct mbuf *cause,
4543d089f9b9SMichael Tuexen     uint8_t mflowtype, uint32_t mflowid, uint16_t fibnum,
4544f30ac432SMichael Tuexen     uint32_t vrf_id, uint16_t port)
4545f8829a4aSRandall Stewart {
4546f8829a4aSRandall Stewart 	struct sctp_chunkhdr *ch, chunk_buf;
4547f8829a4aSRandall Stewart 	unsigned int chk_length;
4548c58e60beSMichael Tuexen 	int contains_init_chunk;
4549f8829a4aSRandall Stewart 
4550f8829a4aSRandall Stewart 	SCTP_STAT_INCR_COUNTER32(sctps_outoftheblue);
4551f8829a4aSRandall Stewart 	/* Generate a TO address for future reference */
4552f8829a4aSRandall Stewart 	if (inp && (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE)) {
4553fe1831e0SMichael Tuexen 		if (LIST_EMPTY(&inp->sctp_asoc_list)) {
4554b0552ae2SRandall Stewart 			sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
4555b0552ae2SRandall Stewart 			    SCTP_CALLED_DIRECTLY_NOCMPSET);
4556f8829a4aSRandall Stewart 		}
4557f8829a4aSRandall Stewart 	}
4558c58e60beSMichael Tuexen 	contains_init_chunk = 0;
4559f8829a4aSRandall Stewart 	ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
4560f8829a4aSRandall Stewart 	    sizeof(*ch), (uint8_t *)&chunk_buf);
4561f8829a4aSRandall Stewart 	while (ch != NULL) {
4562f8829a4aSRandall Stewart 		chk_length = ntohs(ch->chunk_length);
4563f8829a4aSRandall Stewart 		if (chk_length < sizeof(*ch)) {
4564f8829a4aSRandall Stewart 			/* break to abort land */
4565f8829a4aSRandall Stewart 			break;
4566f8829a4aSRandall Stewart 		}
4567f8829a4aSRandall Stewart 		switch (ch->chunk_type) {
4568c58e60beSMichael Tuexen 		case SCTP_INIT:
4569c58e60beSMichael Tuexen 			contains_init_chunk = 1;
4570c58e60beSMichael Tuexen 			break;
4571f8829a4aSRandall Stewart 		case SCTP_PACKET_DROPPED:
4572f8829a4aSRandall Stewart 			/* we don't respond to pkt-dropped */
4573f8829a4aSRandall Stewart 			return;
4574f8829a4aSRandall Stewart 		case SCTP_ABORT_ASSOCIATION:
4575f8829a4aSRandall Stewart 			/* we don't respond with an ABORT to an ABORT */
4576f8829a4aSRandall Stewart 			return;
4577f8829a4aSRandall Stewart 		case SCTP_SHUTDOWN_COMPLETE:
4578f8829a4aSRandall Stewart 			/*
4579f8829a4aSRandall Stewart 			 * we ignore it since we are not waiting for it and
4580f8829a4aSRandall Stewart 			 * peer is gone
4581f8829a4aSRandall Stewart 			 */
4582f8829a4aSRandall Stewart 			return;
4583f8829a4aSRandall Stewart 		case SCTP_SHUTDOWN_ACK:
4584b1754ad1SMichael Tuexen 			sctp_send_shutdown_complete2(src, dst, sh,
4585d089f9b9SMichael Tuexen 			    mflowtype, mflowid, fibnum,
4586f30ac432SMichael Tuexen 			    vrf_id, port);
4587f8829a4aSRandall Stewart 			return;
4588f8829a4aSRandall Stewart 		default:
4589f8829a4aSRandall Stewart 			break;
4590f8829a4aSRandall Stewart 		}
4591f8829a4aSRandall Stewart 		offset += SCTP_SIZE32(chk_length);
4592f8829a4aSRandall Stewart 		ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
4593f8829a4aSRandall Stewart 		    sizeof(*ch), (uint8_t *)&chunk_buf);
4594f8829a4aSRandall Stewart 	}
4595c58e60beSMichael Tuexen 	if ((SCTP_BASE_SYSCTL(sctp_blackhole) == 0) ||
4596c58e60beSMichael Tuexen 	    ((SCTP_BASE_SYSCTL(sctp_blackhole) == 1) &&
4597c58e60beSMichael Tuexen 	    (contains_init_chunk == 0))) {
4598ff1ffd74SMichael Tuexen 		sctp_send_abort(m, iphlen, src, dst, sh, 0, cause,
4599d089f9b9SMichael Tuexen 		    mflowtype, mflowid, fibnum,
4600f30ac432SMichael Tuexen 		    vrf_id, port);
4601f8829a4aSRandall Stewart 	}
4602c58e60beSMichael Tuexen }
4603f8829a4aSRandall Stewart 
4604f8829a4aSRandall Stewart /*
4605f8829a4aSRandall Stewart  * check the inbound datagram to make sure there is not an abort inside it,
4606f8829a4aSRandall Stewart  * if there is return 1, else return 0.
4607f8829a4aSRandall Stewart  */
4608f8829a4aSRandall Stewart int
4609e010d200SMichael Tuexen sctp_is_there_an_abort_here(struct mbuf *m, int iphlen, uint32_t *vtag)
4610f8829a4aSRandall Stewart {
4611f8829a4aSRandall Stewart 	struct sctp_chunkhdr *ch;
4612f8829a4aSRandall Stewart 	struct sctp_init_chunk *init_chk, chunk_buf;
4613f8829a4aSRandall Stewart 	int offset;
4614f8829a4aSRandall Stewart 	unsigned int chk_length;
4615f8829a4aSRandall Stewart 
4616f8829a4aSRandall Stewart 	offset = iphlen + sizeof(struct sctphdr);
4617f8829a4aSRandall Stewart 	ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset, sizeof(*ch),
4618f8829a4aSRandall Stewart 	    (uint8_t *)&chunk_buf);
4619f8829a4aSRandall Stewart 	while (ch != NULL) {
4620f8829a4aSRandall Stewart 		chk_length = ntohs(ch->chunk_length);
4621f8829a4aSRandall Stewart 		if (chk_length < sizeof(*ch)) {
4622f8829a4aSRandall Stewart 			/* packet is probably corrupt */
4623f8829a4aSRandall Stewart 			break;
4624f8829a4aSRandall Stewart 		}
4625f8829a4aSRandall Stewart 		/* we seem to be ok, is it an abort? */
4626f8829a4aSRandall Stewart 		if (ch->chunk_type == SCTP_ABORT_ASSOCIATION) {
4627f8829a4aSRandall Stewart 			/* yep, tell them */
4628f8829a4aSRandall Stewart 			return (1);
4629f8829a4aSRandall Stewart 		}
4630e010d200SMichael Tuexen 		if ((ch->chunk_type == SCTP_INITIATION) ||
4631e010d200SMichael Tuexen 		    (ch->chunk_type == SCTP_INITIATION_ACK)) {
4632f8829a4aSRandall Stewart 			/* need to update the Vtag */
4633f8829a4aSRandall Stewart 			init_chk = (struct sctp_init_chunk *)sctp_m_getptr(m,
4634e010d200SMichael Tuexen 			    offset, sizeof(struct sctp_init_chunk), (uint8_t *)&chunk_buf);
4635f8829a4aSRandall Stewart 			if (init_chk != NULL) {
4636e010d200SMichael Tuexen 				*vtag = ntohl(init_chk->init.initiate_tag);
4637f8829a4aSRandall Stewart 			}
4638f8829a4aSRandall Stewart 		}
4639f8829a4aSRandall Stewart 		/* Nope, move to the next chunk */
4640f8829a4aSRandall Stewart 		offset += SCTP_SIZE32(chk_length);
4641f8829a4aSRandall Stewart 		ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
4642f8829a4aSRandall Stewart 		    sizeof(*ch), (uint8_t *)&chunk_buf);
4643f8829a4aSRandall Stewart 	}
4644f8829a4aSRandall Stewart 	return (0);
4645f8829a4aSRandall Stewart }
4646f8829a4aSRandall Stewart 
4647f8829a4aSRandall Stewart /*
4648f8829a4aSRandall Stewart  * currently (2/02), ifa_addr embeds scope_id's and don't have sin6_scope_id
4649f8829a4aSRandall Stewart  * set (i.e. it's 0) so, create this function to compare link local scopes
4650f8829a4aSRandall Stewart  */
46515e2c2d87SRandall Stewart #ifdef INET6
4652f8829a4aSRandall Stewart uint32_t
4653b0471b4bSMichael Tuexen sctp_is_same_scope(struct sockaddr_in6 *addr1, struct sockaddr_in6 *addr2)
4654b0471b4bSMichael Tuexen {
4655f8829a4aSRandall Stewart 	struct sockaddr_in6 a, b;
4656f8829a4aSRandall Stewart 
4657f8829a4aSRandall Stewart 	/* save copies */
4658f8829a4aSRandall Stewart 	a = *addr1;
4659f8829a4aSRandall Stewart 	b = *addr2;
4660f8829a4aSRandall Stewart 
4661f8829a4aSRandall Stewart 	if (a.sin6_scope_id == 0)
4662f8829a4aSRandall Stewart 		if (sa6_recoverscope(&a)) {
4663f8829a4aSRandall Stewart 			/* can't get scope, so can't match */
4664f8829a4aSRandall Stewart 			return (0);
4665f8829a4aSRandall Stewart 		}
4666f8829a4aSRandall Stewart 	if (b.sin6_scope_id == 0)
4667f8829a4aSRandall Stewart 		if (sa6_recoverscope(&b)) {
4668f8829a4aSRandall Stewart 			/* can't get scope, so can't match */
4669f8829a4aSRandall Stewart 			return (0);
4670f8829a4aSRandall Stewart 		}
4671f8829a4aSRandall Stewart 	if (a.sin6_scope_id != b.sin6_scope_id)
4672f8829a4aSRandall Stewart 		return (0);
4673f8829a4aSRandall Stewart 
4674f8829a4aSRandall Stewart 	return (1);
4675f8829a4aSRandall Stewart }
4676f8829a4aSRandall Stewart 
4677f8829a4aSRandall Stewart /*
4678f8829a4aSRandall Stewart  * returns a sockaddr_in6 with embedded scope recovered and removed
4679f8829a4aSRandall Stewart  */
4680f8829a4aSRandall Stewart struct sockaddr_in6 *
4681f8829a4aSRandall Stewart sctp_recover_scope(struct sockaddr_in6 *addr, struct sockaddr_in6 *store)
4682f8829a4aSRandall Stewart {
4683f8829a4aSRandall Stewart 	/* check and strip embedded scope junk */
4684f8829a4aSRandall Stewart 	if (addr->sin6_family == AF_INET6) {
4685f8829a4aSRandall Stewart 		if (IN6_IS_SCOPE_LINKLOCAL(&addr->sin6_addr)) {
4686f8829a4aSRandall Stewart 			if (addr->sin6_scope_id == 0) {
4687f8829a4aSRandall Stewart 				*store = *addr;
4688f8829a4aSRandall Stewart 				if (!sa6_recoverscope(store)) {
4689f8829a4aSRandall Stewart 					/* use the recovered scope */
4690f8829a4aSRandall Stewart 					addr = store;
4691f8829a4aSRandall Stewart 				}
4692f42a358aSRandall Stewart 			} else {
4693f8829a4aSRandall Stewart 				/* else, return the original "to" addr */
4694f42a358aSRandall Stewart 				in6_clearscope(&addr->sin6_addr);
4695f8829a4aSRandall Stewart 			}
4696f8829a4aSRandall Stewart 		}
4697f8829a4aSRandall Stewart 	}
4698f8829a4aSRandall Stewart 	return (addr);
4699f8829a4aSRandall Stewart }
47005e2c2d87SRandall Stewart #endif
47015e2c2d87SRandall Stewart 
4702f8829a4aSRandall Stewart /*
4703f8829a4aSRandall Stewart  * are the two addresses the same?  currently a "scopeless" check returns: 1
4704f8829a4aSRandall Stewart  * if same, 0 if not
4705f8829a4aSRandall Stewart  */
470672fb6fdbSRandall Stewart int
4707f8829a4aSRandall Stewart sctp_cmpaddr(struct sockaddr *sa1, struct sockaddr *sa2)
4708f8829a4aSRandall Stewart {
4709f8829a4aSRandall Stewart 
4710f8829a4aSRandall Stewart 	/* must be valid */
4711f8829a4aSRandall Stewart 	if (sa1 == NULL || sa2 == NULL)
4712f8829a4aSRandall Stewart 		return (0);
4713f8829a4aSRandall Stewart 
4714f8829a4aSRandall Stewart 	/* must be the same family */
4715f8829a4aSRandall Stewart 	if (sa1->sa_family != sa2->sa_family)
4716f8829a4aSRandall Stewart 		return (0);
4717f8829a4aSRandall Stewart 
47185e2c2d87SRandall Stewart 	switch (sa1->sa_family) {
47195e2c2d87SRandall Stewart #ifdef INET6
47205e2c2d87SRandall Stewart 	case AF_INET6:
47215e2c2d87SRandall Stewart 		{
4722f8829a4aSRandall Stewart 			/* IPv6 addresses */
4723f8829a4aSRandall Stewart 			struct sockaddr_in6 *sin6_1, *sin6_2;
4724f8829a4aSRandall Stewart 
4725f8829a4aSRandall Stewart 			sin6_1 = (struct sockaddr_in6 *)sa1;
4726f8829a4aSRandall Stewart 			sin6_2 = (struct sockaddr_in6 *)sa2;
4727c54a18d2SRandall Stewart 			return (SCTP6_ARE_ADDR_EQUAL(sin6_1,
4728c54a18d2SRandall Stewart 			    sin6_2));
47295e2c2d87SRandall Stewart 		}
47305e2c2d87SRandall Stewart #endif
4731ea5eba11SMichael Tuexen #ifdef INET
47325e2c2d87SRandall Stewart 	case AF_INET:
47335e2c2d87SRandall Stewart 		{
4734f8829a4aSRandall Stewart 			/* IPv4 addresses */
4735f8829a4aSRandall Stewart 			struct sockaddr_in *sin_1, *sin_2;
4736f8829a4aSRandall Stewart 
4737f8829a4aSRandall Stewart 			sin_1 = (struct sockaddr_in *)sa1;
4738f8829a4aSRandall Stewart 			sin_2 = (struct sockaddr_in *)sa2;
4739f8829a4aSRandall Stewart 			return (sin_1->sin_addr.s_addr == sin_2->sin_addr.s_addr);
47405e2c2d87SRandall Stewart 		}
4741ea5eba11SMichael Tuexen #endif
47425e2c2d87SRandall Stewart 	default:
4743f8829a4aSRandall Stewart 		/* we don't do these... */
4744f8829a4aSRandall Stewart 		return (0);
4745f8829a4aSRandall Stewart 	}
4746f8829a4aSRandall Stewart }
4747f8829a4aSRandall Stewart 
4748f8829a4aSRandall Stewart void
4749f8829a4aSRandall Stewart sctp_print_address(struct sockaddr *sa)
4750f8829a4aSRandall Stewart {
47515e2c2d87SRandall Stewart #ifdef INET6
47527d32aa0cSBjoern A. Zeeb 	char ip6buf[INET6_ADDRSTRLEN];
47535e2c2d87SRandall Stewart #endif
47545e2c2d87SRandall Stewart 
47555e2c2d87SRandall Stewart 	switch (sa->sa_family) {
47565e2c2d87SRandall Stewart #ifdef INET6
47575e2c2d87SRandall Stewart 	case AF_INET6:
47585e2c2d87SRandall Stewart 		{
4759ad81507eSRandall Stewart 			struct sockaddr_in6 *sin6;
4760ad81507eSRandall Stewart 
4761f8829a4aSRandall Stewart 			sin6 = (struct sockaddr_in6 *)sa;
4762ad81507eSRandall Stewart 			SCTP_PRINTF("IPv6 address: %s:port:%d scope:%u\n",
47637d32aa0cSBjoern A. Zeeb 			    ip6_sprintf(ip6buf, &sin6->sin6_addr),
47647d32aa0cSBjoern A. Zeeb 			    ntohs(sin6->sin6_port),
4765f8829a4aSRandall Stewart 			    sin6->sin6_scope_id);
47665e2c2d87SRandall Stewart 			break;
47675e2c2d87SRandall Stewart 		}
47685e2c2d87SRandall Stewart #endif
4769ea5eba11SMichael Tuexen #ifdef INET
47705e2c2d87SRandall Stewart 	case AF_INET:
47715e2c2d87SRandall Stewart 		{
4772f8829a4aSRandall Stewart 			struct sockaddr_in *sin;
4773f8829a4aSRandall Stewart 			unsigned char *p;
4774f8829a4aSRandall Stewart 
4775f8829a4aSRandall Stewart 			sin = (struct sockaddr_in *)sa;
4776f8829a4aSRandall Stewart 			p = (unsigned char *)&sin->sin_addr;
4777ad81507eSRandall Stewart 			SCTP_PRINTF("IPv4 address: %u.%u.%u.%u:%d\n",
4778f8829a4aSRandall Stewart 			    p[0], p[1], p[2], p[3], ntohs(sin->sin_port));
47795e2c2d87SRandall Stewart 			break;
47805e2c2d87SRandall Stewart 		}
4781ea5eba11SMichael Tuexen #endif
47825e2c2d87SRandall Stewart 	default:
4783ad81507eSRandall Stewart 		SCTP_PRINTF("?\n");
47845e2c2d87SRandall Stewart 		break;
4785f8829a4aSRandall Stewart 	}
4786f8829a4aSRandall Stewart }
4787f8829a4aSRandall Stewart 
4788f8829a4aSRandall Stewart void
4789f8829a4aSRandall Stewart sctp_pull_off_control_to_new_inp(struct sctp_inpcb *old_inp,
4790f8829a4aSRandall Stewart     struct sctp_inpcb *new_inp,
4791d06c82f1SRandall Stewart     struct sctp_tcb *stcb,
4792d06c82f1SRandall Stewart     int waitflags)
4793f8829a4aSRandall Stewart {
4794f8829a4aSRandall Stewart 	/*
4795f8829a4aSRandall Stewart 	 * go through our old INP and pull off any control structures that
4796f8829a4aSRandall Stewart 	 * belong to stcb and move then to the new inp.
4797f8829a4aSRandall Stewart 	 */
4798f8829a4aSRandall Stewart 	struct socket *old_so, *new_so;
4799f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control, *nctl;
4800f8829a4aSRandall Stewart 	struct sctp_readhead tmp_queue;
4801f8829a4aSRandall Stewart 	struct mbuf *m;
4802bff64a4dSRandall Stewart 	int error = 0;
4803f8829a4aSRandall Stewart 
4804f8829a4aSRandall Stewart 	old_so = old_inp->sctp_socket;
4805f8829a4aSRandall Stewart 	new_so = new_inp->sctp_socket;
4806f8829a4aSRandall Stewart 	TAILQ_INIT(&tmp_queue);
4807f94acf52SMark Johnston 	error = SOCK_IO_RECV_LOCK(old_so, waitflags);
4808f8829a4aSRandall Stewart 	if (error) {
4809f8829a4aSRandall Stewart 		/*
4810f94acf52SMark Johnston 		 * Gak, can't get I/O lock, we have a problem. data will be
4811f8829a4aSRandall Stewart 		 * left stranded.. and we don't dare look at it since the
4812f8829a4aSRandall Stewart 		 * other thread may be reading something. Oh well, its a
4813f8829a4aSRandall Stewart 		 * screwed up app that does a peeloff OR a accept while
4814f8829a4aSRandall Stewart 		 * reading from the main socket... actually its only the
4815f8829a4aSRandall Stewart 		 * peeloff() case, since I think read will fail on a
4816f8829a4aSRandall Stewart 		 * listening socket..
4817f8829a4aSRandall Stewart 		 */
4818f8829a4aSRandall Stewart 		return;
4819f8829a4aSRandall Stewart 	}
4820f8829a4aSRandall Stewart 	/* lock the socket buffers */
4821f8829a4aSRandall Stewart 	SCTP_INP_READ_LOCK(old_inp);
48224a9ef3f8SMichael Tuexen 	TAILQ_FOREACH_SAFE(control, &old_inp->read_queue, next, nctl) {
4823f8829a4aSRandall Stewart 		/* Pull off all for out target stcb */
4824f8829a4aSRandall Stewart 		if (control->stcb == stcb) {
4825f8829a4aSRandall Stewart 			/* remove it we want it */
4826f8829a4aSRandall Stewart 			TAILQ_REMOVE(&old_inp->read_queue, control, next);
4827f8829a4aSRandall Stewart 			TAILQ_INSERT_TAIL(&tmp_queue, control, next);
4828f8829a4aSRandall Stewart 			m = control->data;
4829f8829a4aSRandall Stewart 			while (m) {
4830b3f1ea41SRandall Stewart 				if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4831139bc87fSRandall Stewart 					sctp_sblog(&old_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
483280fefe0aSRandall Stewart 				}
4833f8829a4aSRandall Stewart 				sctp_sbfree(control, stcb, &old_so->so_rcv, m);
4834b3f1ea41SRandall Stewart 				if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4835f8829a4aSRandall Stewart 					sctp_sblog(&old_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
483680fefe0aSRandall Stewart 				}
4837139bc87fSRandall Stewart 				m = SCTP_BUF_NEXT(m);
4838f8829a4aSRandall Stewart 			}
4839f8829a4aSRandall Stewart 		}
4840f8829a4aSRandall Stewart 	}
4841f8829a4aSRandall Stewart 	SCTP_INP_READ_UNLOCK(old_inp);
4842f94acf52SMark Johnston 	/* Remove the recv-lock on the old socket */
4843f94acf52SMark Johnston 	SOCK_IO_RECV_UNLOCK(old_so);
4844f8829a4aSRandall Stewart 	/* Now we move them over to the new socket buffer */
4845f8829a4aSRandall Stewart 	SCTP_INP_READ_LOCK(new_inp);
48464a9ef3f8SMichael Tuexen 	TAILQ_FOREACH_SAFE(control, &tmp_queue, next, nctl) {
4847f8829a4aSRandall Stewart 		TAILQ_INSERT_TAIL(&new_inp->read_queue, control, next);
4848f8829a4aSRandall Stewart 		m = control->data;
4849f8829a4aSRandall Stewart 		while (m) {
4850b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4851139bc87fSRandall Stewart 				sctp_sblog(&new_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m));
485280fefe0aSRandall Stewart 			}
4853f8829a4aSRandall Stewart 			sctp_sballoc(stcb, &new_so->so_rcv, m);
4854b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4855f8829a4aSRandall Stewart 				sctp_sblog(&new_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
485680fefe0aSRandall Stewart 			}
4857139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
4858f8829a4aSRandall Stewart 		}
4859f8829a4aSRandall Stewart 	}
4860f8829a4aSRandall Stewart 	SCTP_INP_READ_UNLOCK(new_inp);
4861f8829a4aSRandall Stewart }
4862f8829a4aSRandall Stewart 
4863f8829a4aSRandall Stewart void
4864b1deed45SMichael Tuexen sctp_wakeup_the_read_socket(struct sctp_inpcb *inp,
4865b1deed45SMichael Tuexen     struct sctp_tcb *stcb,
4866b1deed45SMichael Tuexen     int so_locked
4867b1deed45SMichael Tuexen     SCTP_UNUSED
4868b1deed45SMichael Tuexen )
486944249214SRandall Stewart {
4870b1deed45SMichael Tuexen 	if ((inp != NULL) && (inp->sctp_socket != NULL)) {
487144249214SRandall Stewart 		sctp_sorwakeup(inp, inp->sctp_socket);
487244249214SRandall Stewart 	}
487344249214SRandall Stewart }
487444249214SRandall Stewart 
487544249214SRandall Stewart void
4876f8829a4aSRandall Stewart sctp_add_to_readq(struct sctp_inpcb *inp,
4877f8829a4aSRandall Stewart     struct sctp_tcb *stcb,
4878f8829a4aSRandall Stewart     struct sctp_queued_to_read *control,
4879f8829a4aSRandall Stewart     struct sockbuf *sb,
4880ceaad40aSRandall Stewart     int end,
4881cfde3ff7SRandall Stewart     int inp_read_lock_held,
488228397ac1SMichael Tuexen     int so_locked)
4883f8829a4aSRandall Stewart {
4884f8829a4aSRandall Stewart 	/*
4885f8829a4aSRandall Stewart 	 * Here we must place the control on the end of the socket read
48864e88d37aSMichael Tuexen 	 * queue AND increment sb_cc so that select will work properly on
4887f8829a4aSRandall Stewart 	 * read.
4888f8829a4aSRandall Stewart 	 */
4889f8829a4aSRandall Stewart 	struct mbuf *m, *prev = NULL;
4890f8829a4aSRandall Stewart 
489103b0b021SRandall Stewart 	if (inp == NULL) {
489203b0b021SRandall Stewart 		/* Gak, TSNH!! */
4893a5d547adSRandall Stewart #ifdef INVARIANTS
489403b0b021SRandall Stewart 		panic("Gak, inp NULL on add_to_readq");
489503b0b021SRandall Stewart #endif
489603b0b021SRandall Stewart 		return;
489703b0b021SRandall Stewart 	}
4898cfde3ff7SRandall Stewart 	if (inp_read_lock_held == 0)
4899f8829a4aSRandall Stewart 		SCTP_INP_READ_LOCK(inp);
4900cd1386abSMichael Tuexen 	if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_CANT_READ) {
49018a3cfbffSMichael Tuexen 		if (!control->on_strm_q) {
4902cd1386abSMichael Tuexen 			sctp_free_remote_addr(control->whoFrom);
4903cd1386abSMichael Tuexen 			if (control->data) {
4904cd1386abSMichael Tuexen 				sctp_m_freem(control->data);
4905cd1386abSMichael Tuexen 				control->data = NULL;
4906cd1386abSMichael Tuexen 			}
490744249214SRandall Stewart 			sctp_free_a_readq(stcb, control);
49088a3cfbffSMichael Tuexen 		}
4909cd1386abSMichael Tuexen 		if (inp_read_lock_held == 0)
4910cd1386abSMichael Tuexen 			SCTP_INP_READ_UNLOCK(inp);
4911cd1386abSMichael Tuexen 		return;
4912cd1386abSMichael Tuexen 	}
491342551e99SRandall Stewart 	if (!(control->spec_flags & M_NOTIFICATION)) {
4914a5d547adSRandall Stewart 		atomic_add_int(&inp->total_recvs, 1);
491542551e99SRandall Stewart 		if (!control->do_not_ref_stcb) {
4916a5d547adSRandall Stewart 			atomic_add_int(&stcb->total_recvs, 1);
491742551e99SRandall Stewart 		}
491842551e99SRandall Stewart 	}
4919f8829a4aSRandall Stewart 	m = control->data;
4920f8829a4aSRandall Stewart 	control->held_length = 0;
4921f8829a4aSRandall Stewart 	control->length = 0;
4922f8829a4aSRandall Stewart 	while (m) {
4923139bc87fSRandall Stewart 		if (SCTP_BUF_LEN(m) == 0) {
4924f8829a4aSRandall Stewart 			/* Skip mbufs with NO length */
4925f8829a4aSRandall Stewart 			if (prev == NULL) {
4926f8829a4aSRandall Stewart 				/* First one */
4927f8829a4aSRandall Stewart 				control->data = sctp_m_free(m);
4928f8829a4aSRandall Stewart 				m = control->data;
4929f8829a4aSRandall Stewart 			} else {
4930139bc87fSRandall Stewart 				SCTP_BUF_NEXT(prev) = sctp_m_free(m);
4931139bc87fSRandall Stewart 				m = SCTP_BUF_NEXT(prev);
4932f8829a4aSRandall Stewart 			}
4933f8829a4aSRandall Stewart 			if (m == NULL) {
4934c2ede4b3SMartin Blapp 				control->tail_mbuf = prev;
4935f8829a4aSRandall Stewart 			}
4936f8829a4aSRandall Stewart 			continue;
4937f8829a4aSRandall Stewart 		}
4938f8829a4aSRandall Stewart 		prev = m;
4939b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4940139bc87fSRandall Stewart 			sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m));
494180fefe0aSRandall Stewart 		}
4942f8829a4aSRandall Stewart 		sctp_sballoc(stcb, sb, m);
4943b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4944f8829a4aSRandall Stewart 			sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
494580fefe0aSRandall Stewart 		}
4946139bc87fSRandall Stewart 		atomic_add_int(&control->length, SCTP_BUF_LEN(m));
4947139bc87fSRandall Stewart 		m = SCTP_BUF_NEXT(m);
4948f8829a4aSRandall Stewart 	}
4949f8829a4aSRandall Stewart 	if (prev != NULL) {
4950f8829a4aSRandall Stewart 		control->tail_mbuf = prev;
4951f8829a4aSRandall Stewart 	} else {
4952139bc87fSRandall Stewart 		/* Everything got collapsed out?? */
49538a3cfbffSMichael Tuexen 		if (!control->on_strm_q) {
4954cd1386abSMichael Tuexen 			sctp_free_remote_addr(control->whoFrom);
495544249214SRandall Stewart 			sctp_free_a_readq(stcb, control);
49568a3cfbffSMichael Tuexen 		}
4957cfde3ff7SRandall Stewart 		if (inp_read_lock_held == 0)
495847a490cbSMichael Tuexen 			SCTP_INP_READ_UNLOCK(inp);
4959f8829a4aSRandall Stewart 		return;
4960f8829a4aSRandall Stewart 	}
4961f8829a4aSRandall Stewart 	if (end) {
4962f8829a4aSRandall Stewart 		control->end_added = 1;
4963f8829a4aSRandall Stewart 	}
4964f8829a4aSRandall Stewart 	TAILQ_INSERT_TAIL(&inp->read_queue, control, next);
496544249214SRandall Stewart 	control->on_read_q = 1;
4966cfde3ff7SRandall Stewart 	if (inp_read_lock_held == 0)
4967f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
4968f8829a4aSRandall Stewart 	if (inp && inp->sctp_socket) {
4969b1deed45SMichael Tuexen 		sctp_wakeup_the_read_socket(inp, stcb, so_locked);
4970f8829a4aSRandall Stewart 	}
4971f8829a4aSRandall Stewart }
4972f8829a4aSRandall Stewart 
4973f8829a4aSRandall Stewart /*************HOLD THIS COMMENT FOR PATCH FILE OF
4974f8829a4aSRandall Stewart  *************ALTERNATE ROUTING CODE
4975f8829a4aSRandall Stewart  */
4976f8829a4aSRandall Stewart 
4977f8829a4aSRandall Stewart /*************HOLD THIS COMMENT FOR END OF PATCH FILE OF
4978f8829a4aSRandall Stewart  *************ALTERNATE ROUTING CODE
4979f8829a4aSRandall Stewart  */
4980f8829a4aSRandall Stewart 
4981f8829a4aSRandall Stewart struct mbuf *
4982ff1ffd74SMichael Tuexen sctp_generate_cause(uint16_t code, char *info)
4983f8829a4aSRandall Stewart {
4984f8829a4aSRandall Stewart 	struct mbuf *m;
4985ff1ffd74SMichael Tuexen 	struct sctp_gen_error_cause *cause;
49869a8e3088SMichael Tuexen 	size_t info_len;
49879a8e3088SMichael Tuexen 	uint16_t len;
4988f8829a4aSRandall Stewart 
4989ff1ffd74SMichael Tuexen 	if ((code == 0) || (info == NULL)) {
4990ff1ffd74SMichael Tuexen 		return (NULL);
4991ff1ffd74SMichael Tuexen 	}
4992ff1ffd74SMichael Tuexen 	info_len = strlen(info);
49939a8e3088SMichael Tuexen 	if (info_len > (SCTP_MAX_CAUSE_LENGTH - sizeof(struct sctp_paramhdr))) {
49949a8e3088SMichael Tuexen 		return (NULL);
49959a8e3088SMichael Tuexen 	}
49969a8e3088SMichael Tuexen 	len = (uint16_t)(sizeof(struct sctp_paramhdr) + info_len);
4997ff1ffd74SMichael Tuexen 	m = sctp_get_mbuf_for_msg(len, 0, M_NOWAIT, 1, MT_DATA);
4998ff1ffd74SMichael Tuexen 	if (m != NULL) {
4999ff1ffd74SMichael Tuexen 		SCTP_BUF_LEN(m) = len;
5000ff1ffd74SMichael Tuexen 		cause = mtod(m, struct sctp_gen_error_cause *);
5001ff1ffd74SMichael Tuexen 		cause->code = htons(code);
50029a8e3088SMichael Tuexen 		cause->length = htons(len);
5003ff1ffd74SMichael Tuexen 		memcpy(cause->info, info, info_len);
5004f8829a4aSRandall Stewart 	}
5005f8829a4aSRandall Stewart 	return (m);
5006f8829a4aSRandall Stewart }
5007f8829a4aSRandall Stewart 
500832451da4SMichael Tuexen struct mbuf *
500932451da4SMichael Tuexen sctp_generate_no_user_data_cause(uint32_t tsn)
501032451da4SMichael Tuexen {
501132451da4SMichael Tuexen 	struct mbuf *m;
501232451da4SMichael Tuexen 	struct sctp_error_no_user_data *no_user_data_cause;
50139a8e3088SMichael Tuexen 	uint16_t len;
501432451da4SMichael Tuexen 
50159a8e3088SMichael Tuexen 	len = (uint16_t)sizeof(struct sctp_error_no_user_data);
501632451da4SMichael Tuexen 	m = sctp_get_mbuf_for_msg(len, 0, M_NOWAIT, 1, MT_DATA);
501732451da4SMichael Tuexen 	if (m != NULL) {
501832451da4SMichael Tuexen 		SCTP_BUF_LEN(m) = len;
501932451da4SMichael Tuexen 		no_user_data_cause = mtod(m, struct sctp_error_no_user_data *);
502032451da4SMichael Tuexen 		no_user_data_cause->cause.code = htons(SCTP_CAUSE_NO_USER_DATA);
50219a8e3088SMichael Tuexen 		no_user_data_cause->cause.length = htons(len);
50228b9c95f4SMichael Tuexen 		no_user_data_cause->tsn = htonl(tsn);
502332451da4SMichael Tuexen 	}
502432451da4SMichael Tuexen 	return (m);
502532451da4SMichael Tuexen }
502632451da4SMichael Tuexen 
5027f8829a4aSRandall Stewart #ifdef SCTP_MBCNT_LOGGING
5028f8829a4aSRandall Stewart void
5029f8829a4aSRandall Stewart sctp_free_bufspace(struct sctp_tcb *stcb, struct sctp_association *asoc,
5030f8829a4aSRandall Stewart     struct sctp_tmit_chunk *tp1, int chk_cnt)
5031f8829a4aSRandall Stewart {
5032f8829a4aSRandall Stewart 	if (tp1->data == NULL) {
5033f8829a4aSRandall Stewart 		return;
5034f8829a4aSRandall Stewart 	}
5035f8829a4aSRandall Stewart 	asoc->chunks_on_out_queue -= chk_cnt;
5036b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_MBCNT_LOGGING_ENABLE) {
5037f8829a4aSRandall Stewart 		sctp_log_mbcnt(SCTP_LOG_MBCNT_DECREASE,
5038f8829a4aSRandall Stewart 		    asoc->total_output_queue_size,
5039f8829a4aSRandall Stewart 		    tp1->book_size,
5040f8829a4aSRandall Stewart 		    0,
5041f8829a4aSRandall Stewart 		    tp1->mbcnt);
504280fefe0aSRandall Stewart 	}
5043f8829a4aSRandall Stewart 	if (asoc->total_output_queue_size >= tp1->book_size) {
504444b7479bSRandall Stewart 		atomic_add_int(&asoc->total_output_queue_size, -tp1->book_size);
5045f8829a4aSRandall Stewart 	} else {
5046f8829a4aSRandall Stewart 		asoc->total_output_queue_size = 0;
5047f8829a4aSRandall Stewart 	}
5048f8829a4aSRandall Stewart 
5049f8829a4aSRandall Stewart 	if (stcb->sctp_socket && (((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) ||
5050f8829a4aSRandall Stewart 	    ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE)))) {
50514e88d37aSMichael Tuexen 		if (stcb->sctp_socket->so_snd.sb_cc >= tp1->book_size) {
50524e88d37aSMichael Tuexen 			stcb->sctp_socket->so_snd.sb_cc -= tp1->book_size;
5053f8829a4aSRandall Stewart 		} else {
50544e88d37aSMichael Tuexen 			stcb->sctp_socket->so_snd.sb_cc = 0;
5055f8829a4aSRandall Stewart 		}
5056f8829a4aSRandall Stewart 	}
5057f8829a4aSRandall Stewart }
5058f8829a4aSRandall Stewart 
5059f8829a4aSRandall Stewart #endif
5060f8829a4aSRandall Stewart 
5061f8829a4aSRandall Stewart int
5062f8829a4aSRandall Stewart sctp_release_pr_sctp_chunk(struct sctp_tcb *stcb, struct sctp_tmit_chunk *tp1,
506328397ac1SMichael Tuexen     uint8_t sent, int so_locked)
5064f8829a4aSRandall Stewart {
50650c0982b8SRandall Stewart 	struct sctp_stream_out *strq;
50664a9ef3f8SMichael Tuexen 	struct sctp_tmit_chunk *chk = NULL, *tp2;
50670c0982b8SRandall Stewart 	struct sctp_stream_queue_pending *sp;
506849656eefSMichael Tuexen 	uint32_t mid;
506949656eefSMichael Tuexen 	uint16_t sid;
50700c0982b8SRandall Stewart 	uint8_t foundeom = 0;
5071f8829a4aSRandall Stewart 	int ret_sz = 0;
5072f8829a4aSRandall Stewart 	int notdone;
50730c0982b8SRandall Stewart 	int do_wakeup_routine = 0;
5074f8829a4aSRandall Stewart 
507549656eefSMichael Tuexen 	sid = tp1->rec.data.sid;
507649656eefSMichael Tuexen 	mid = tp1->rec.data.mid;
5077f0396ad1SMichael Tuexen 	if (sent || !(tp1->rec.data.rcv_flags & SCTP_DATA_FIRST_FRAG)) {
5078f0396ad1SMichael Tuexen 		stcb->asoc.abandoned_sent[0]++;
5079f0396ad1SMichael Tuexen 		stcb->asoc.abandoned_sent[PR_SCTP_POLICY(tp1->flags)]++;
508049656eefSMichael Tuexen 		stcb->asoc.strmout[sid].abandoned_sent[0]++;
5081f0396ad1SMichael Tuexen #if defined(SCTP_DETAILED_STR_STATS)
5082ad15e154SMichael Tuexen 		stcb->asoc.strmout[sid].abandoned_sent[PR_SCTP_POLICY(tp1->flags)]++;
5083f0396ad1SMichael Tuexen #endif
5084f0396ad1SMichael Tuexen 	} else {
5085f0396ad1SMichael Tuexen 		stcb->asoc.abandoned_unsent[0]++;
5086f0396ad1SMichael Tuexen 		stcb->asoc.abandoned_unsent[PR_SCTP_POLICY(tp1->flags)]++;
508749656eefSMichael Tuexen 		stcb->asoc.strmout[sid].abandoned_unsent[0]++;
5088f0396ad1SMichael Tuexen #if defined(SCTP_DETAILED_STR_STATS)
5089ad15e154SMichael Tuexen 		stcb->asoc.strmout[sid].abandoned_unsent[PR_SCTP_POLICY(tp1->flags)]++;
5090f0396ad1SMichael Tuexen #endif
5091f0396ad1SMichael Tuexen 	}
5092f8829a4aSRandall Stewart 	do {
5093f8829a4aSRandall Stewart 		ret_sz += tp1->book_size;
50940c0982b8SRandall Stewart 		if (tp1->data != NULL) {
50958933fa13SRandall Stewart 			if (tp1->sent < SCTP_DATAGRAM_RESEND) {
5096830d754dSRandall Stewart 				sctp_flight_size_decrease(tp1);
5097830d754dSRandall Stewart 				sctp_total_flight_decrease(stcb, tp1);
50988933fa13SRandall Stewart 			}
50998933fa13SRandall Stewart 			sctp_free_bufspace(stcb, &stcb->asoc, tp1, 1);
51000c0982b8SRandall Stewart 			stcb->asoc.peers_rwnd += tp1->send_size;
51010c0982b8SRandall Stewart 			stcb->asoc.peers_rwnd += SCTP_BASE_SYSCTL(sctp_peer_chunk_oh);
51021edc9dbaSMichael Tuexen 			if (sent) {
51031edc9dbaSMichael Tuexen 				sctp_ulp_notify(SCTP_NOTIFY_SENT_DG_FAIL, stcb, 0, tp1, so_locked);
51041edc9dbaSMichael Tuexen 			} else {
51051edc9dbaSMichael Tuexen 				sctp_ulp_notify(SCTP_NOTIFY_UNSENT_DG_FAIL, stcb, 0, tp1, so_locked);
51061edc9dbaSMichael Tuexen 			}
51072f99457bSMichael Tuexen 			if (tp1->data) {
5108f8829a4aSRandall Stewart 				sctp_m_freem(tp1->data);
5109f8829a4aSRandall Stewart 				tp1->data = NULL;
51102f99457bSMichael Tuexen 			}
51110c0982b8SRandall Stewart 			do_wakeup_routine = 1;
5112f8829a4aSRandall Stewart 			if (PR_SCTP_BUF_ENABLED(tp1->flags)) {
5113f8829a4aSRandall Stewart 				stcb->asoc.sent_queue_cnt_removeable--;
5114f8829a4aSRandall Stewart 			}
5115f8829a4aSRandall Stewart 		}
51168933fa13SRandall Stewart 		tp1->sent = SCTP_FORWARD_TSN_SKIP;
5117f8829a4aSRandall Stewart 		if ((tp1->rec.data.rcv_flags & SCTP_DATA_NOT_FRAG) ==
5118f8829a4aSRandall Stewart 		    SCTP_DATA_NOT_FRAG) {
5119f8829a4aSRandall Stewart 			/* not frag'ed we ae done   */
5120f8829a4aSRandall Stewart 			notdone = 0;
5121f8829a4aSRandall Stewart 			foundeom = 1;
5122f8829a4aSRandall Stewart 		} else if (tp1->rec.data.rcv_flags & SCTP_DATA_LAST_FRAG) {
5123f8829a4aSRandall Stewart 			/* end of frag, we are done */
5124f8829a4aSRandall Stewart 			notdone = 0;
5125f8829a4aSRandall Stewart 			foundeom = 1;
5126f8829a4aSRandall Stewart 		} else {
5127f8829a4aSRandall Stewart 			/*
5128f8829a4aSRandall Stewart 			 * Its a begin or middle piece, we must mark all of
5129f8829a4aSRandall Stewart 			 * it
5130f8829a4aSRandall Stewart 			 */
5131f8829a4aSRandall Stewart 			notdone = 1;
5132f8829a4aSRandall Stewart 			tp1 = TAILQ_NEXT(tp1, sctp_next);
5133f8829a4aSRandall Stewart 		}
5134f8829a4aSRandall Stewart 	} while (tp1 && notdone);
51350c0982b8SRandall Stewart 	if (foundeom == 0) {
5136f8829a4aSRandall Stewart 		/*
5137f8829a4aSRandall Stewart 		 * The multi-part message was scattered across the send and
5138f8829a4aSRandall Stewart 		 * sent queue.
5139f8829a4aSRandall Stewart 		 */
51404a9ef3f8SMichael Tuexen 		TAILQ_FOREACH_SAFE(tp1, &stcb->asoc.send_queue, sctp_next, tp2) {
514149656eefSMichael Tuexen 			if ((tp1->rec.data.sid != sid) ||
514249656eefSMichael Tuexen 			    (!SCTP_MID_EQ(stcb->asoc.idata_supported, tp1->rec.data.mid, mid))) {
51434a9ef3f8SMichael Tuexen 				break;
51444a9ef3f8SMichael Tuexen 			}
51450c0982b8SRandall Stewart 			/*
51460c0982b8SRandall Stewart 			 * save to chk in case we have some on stream out
51470c0982b8SRandall Stewart 			 * queue. If so and we have an un-transmitted one we
51480c0982b8SRandall Stewart 			 * don't have to fudge the TSN.
51490c0982b8SRandall Stewart 			 */
51500c0982b8SRandall Stewart 			chk = tp1;
51510c0982b8SRandall Stewart 			ret_sz += tp1->book_size;
51520c0982b8SRandall Stewart 			sctp_free_bufspace(stcb, &stcb->asoc, tp1, 1);
51531edc9dbaSMichael Tuexen 			if (sent) {
51541edc9dbaSMichael Tuexen 				sctp_ulp_notify(SCTP_NOTIFY_SENT_DG_FAIL, stcb, 0, tp1, so_locked);
51551edc9dbaSMichael Tuexen 			} else {
51561edc9dbaSMichael Tuexen 				sctp_ulp_notify(SCTP_NOTIFY_UNSENT_DG_FAIL, stcb, 0, tp1, so_locked);
51571edc9dbaSMichael Tuexen 			}
51582f99457bSMichael Tuexen 			if (tp1->data) {
51590c0982b8SRandall Stewart 				sctp_m_freem(tp1->data);
51602f99457bSMichael Tuexen 				tp1->data = NULL;
51612f99457bSMichael Tuexen 			}
51628933fa13SRandall Stewart 			/* No flight involved here book the size to 0 */
51638933fa13SRandall Stewart 			tp1->book_size = 0;
51640c0982b8SRandall Stewart 			if (tp1->rec.data.rcv_flags & SCTP_DATA_LAST_FRAG) {
51650c0982b8SRandall Stewart 				foundeom = 1;
5166f8829a4aSRandall Stewart 			}
51670c0982b8SRandall Stewart 			do_wakeup_routine = 1;
51680c0982b8SRandall Stewart 			tp1->sent = SCTP_FORWARD_TSN_SKIP;
51690c0982b8SRandall Stewart 			TAILQ_REMOVE(&stcb->asoc.send_queue, tp1, sctp_next);
5170b7b84c0eSMichael Tuexen 			/*
5171b7b84c0eSMichael Tuexen 			 * on to the sent queue so we can wait for it to be
5172b7b84c0eSMichael Tuexen 			 * passed by.
5173b7b84c0eSMichael Tuexen 			 */
51740c0982b8SRandall Stewart 			TAILQ_INSERT_TAIL(&stcb->asoc.sent_queue, tp1,
51750c0982b8SRandall Stewart 			    sctp_next);
51760c0982b8SRandall Stewart 			stcb->asoc.send_queue_cnt--;
51770c0982b8SRandall Stewart 			stcb->asoc.sent_queue_cnt++;
51780c0982b8SRandall Stewart 		}
51790c0982b8SRandall Stewart 	}
51800c0982b8SRandall Stewart 	if (foundeom == 0) {
51810c0982b8SRandall Stewart 		/*
51820c0982b8SRandall Stewart 		 * Still no eom found. That means there is stuff left on the
51830c0982b8SRandall Stewart 		 * stream out queue.. yuck.
51840c0982b8SRandall Stewart 		 */
51850c0982b8SRandall Stewart 		SCTP_TCB_SEND_LOCK(stcb);
518649656eefSMichael Tuexen 		strq = &stcb->asoc.strmout[sid];
5187f3b05218SMichael Tuexen 		sp = TAILQ_FIRST(&strq->outqueue);
5188f3b05218SMichael Tuexen 		if (sp != NULL) {
51890c0982b8SRandall Stewart 			sp->discard_rest = 1;
51900c0982b8SRandall Stewart 			/*
5191f3b05218SMichael Tuexen 			 * We may need to put a chunk on the queue that
5192f3b05218SMichael Tuexen 			 * holds the TSN that would have been sent with the
5193f3b05218SMichael Tuexen 			 * LAST bit.
51940c0982b8SRandall Stewart 			 */
51950c0982b8SRandall Stewart 			if (chk == NULL) {
51960c0982b8SRandall Stewart 				/* Yep, we have to */
51970c0982b8SRandall Stewart 				sctp_alloc_a_chunk(stcb, chk);
51980c0982b8SRandall Stewart 				if (chk == NULL) {
51990c0982b8SRandall Stewart 					/*
5200f3b05218SMichael Tuexen 					 * we are hosed. All we can do is
5201f3b05218SMichael Tuexen 					 * nothing.. which will cause an
5202f3b05218SMichael Tuexen 					 * abort if the peer is paying
52030c0982b8SRandall Stewart 					 * attention.
52040c0982b8SRandall Stewart 					 */
52050c0982b8SRandall Stewart 					goto oh_well;
52060c0982b8SRandall Stewart 				}
52070c0982b8SRandall Stewart 				memset(chk, 0, sizeof(*chk));
520863d5b568SMichael Tuexen 				chk->rec.data.rcv_flags = 0;
52090c0982b8SRandall Stewart 				chk->sent = SCTP_FORWARD_TSN_SKIP;
52100c0982b8SRandall Stewart 				chk->asoc = &stcb->asoc;
521163d5b568SMichael Tuexen 				if (stcb->asoc.idata_supported == 0) {
521263d5b568SMichael Tuexen 					if (sp->sinfo_flags & SCTP_UNORDERED) {
521349656eefSMichael Tuexen 						chk->rec.data.mid = 0;
521463d5b568SMichael Tuexen 					} else {
521549656eefSMichael Tuexen 						chk->rec.data.mid = strq->next_mid_ordered;
521663d5b568SMichael Tuexen 					}
521763d5b568SMichael Tuexen 				} else {
521863d5b568SMichael Tuexen 					if (sp->sinfo_flags & SCTP_UNORDERED) {
521949656eefSMichael Tuexen 						chk->rec.data.mid = strq->next_mid_unordered;
522063d5b568SMichael Tuexen 					} else {
522149656eefSMichael Tuexen 						chk->rec.data.mid = strq->next_mid_ordered;
522263d5b568SMichael Tuexen 					}
522363d5b568SMichael Tuexen 				}
522449656eefSMichael Tuexen 				chk->rec.data.sid = sp->sid;
522549656eefSMichael Tuexen 				chk->rec.data.ppid = sp->ppid;
52260c0982b8SRandall Stewart 				chk->rec.data.context = sp->context;
52270c0982b8SRandall Stewart 				chk->flags = sp->act_flags;
52287fd5b436SMichael Tuexen 				chk->whoTo = NULL;
522949656eefSMichael Tuexen 				chk->rec.data.tsn = atomic_fetchadd_int(&stcb->asoc.sending_seq, 1);
52307fd5b436SMichael Tuexen 				strq->chunks_on_queues++;
52310c0982b8SRandall Stewart 				TAILQ_INSERT_TAIL(&stcb->asoc.sent_queue, chk, sctp_next);
52320c0982b8SRandall Stewart 				stcb->asoc.sent_queue_cnt++;
52338933fa13SRandall Stewart 				stcb->asoc.pr_sctp_cnt++;
52340c0982b8SRandall Stewart 			}
523563d5b568SMichael Tuexen 			chk->rec.data.rcv_flags |= SCTP_DATA_LAST_FRAG;
5236d1ea5fa9SMichael Tuexen 			if (sp->sinfo_flags & SCTP_UNORDERED) {
5237d1ea5fa9SMichael Tuexen 				chk->rec.data.rcv_flags |= SCTP_DATA_UNORDERED;
5238d1ea5fa9SMichael Tuexen 			}
523963d5b568SMichael Tuexen 			if (stcb->asoc.idata_supported == 0) {
524063d5b568SMichael Tuexen 				if ((sp->sinfo_flags & SCTP_UNORDERED) == 0) {
524163d5b568SMichael Tuexen 					strq->next_mid_ordered++;
524263d5b568SMichael Tuexen 				}
524363d5b568SMichael Tuexen 			} else {
524463d5b568SMichael Tuexen 				if (sp->sinfo_flags & SCTP_UNORDERED) {
524563d5b568SMichael Tuexen 					strq->next_mid_unordered++;
524663d5b568SMichael Tuexen 				} else {
524763d5b568SMichael Tuexen 					strq->next_mid_ordered++;
524863d5b568SMichael Tuexen 				}
524963d5b568SMichael Tuexen 			}
52500c0982b8SRandall Stewart 	oh_well:
52510c0982b8SRandall Stewart 			if (sp->data) {
52520c0982b8SRandall Stewart 				/*
5253f3b05218SMichael Tuexen 				 * Pull any data to free up the SB and allow
5254f3b05218SMichael Tuexen 				 * sender to "add more" while we will throw
5255f3b05218SMichael Tuexen 				 * away :-)
52560c0982b8SRandall Stewart 				 */
5257f3b05218SMichael Tuexen 				sctp_free_spbufspace(stcb, &stcb->asoc, sp);
52580c0982b8SRandall Stewart 				ret_sz += sp->length;
52590c0982b8SRandall Stewart 				do_wakeup_routine = 1;
52600c0982b8SRandall Stewart 				sp->some_taken = 1;
52610c0982b8SRandall Stewart 				sctp_m_freem(sp->data);
52620c0982b8SRandall Stewart 				sp->data = NULL;
52630c0982b8SRandall Stewart 				sp->tail_mbuf = NULL;
5264d07b2ac6SMichael Tuexen 				sp->length = 0;
52650c0982b8SRandall Stewart 			}
52660c0982b8SRandall Stewart 		}
52670c0982b8SRandall Stewart 		SCTP_TCB_SEND_UNLOCK(stcb);
52680c0982b8SRandall Stewart 	}
52690c0982b8SRandall Stewart 	if (do_wakeup_routine) {
52700c0982b8SRandall Stewart 		sctp_sowwakeup(stcb->sctp_ep, stcb->sctp_socket);
5271f8829a4aSRandall Stewart 	}
5272f8829a4aSRandall Stewart 	return (ret_sz);
5273f8829a4aSRandall Stewart }
5274f8829a4aSRandall Stewart 
5275f8829a4aSRandall Stewart /*
5276f8829a4aSRandall Stewart  * checks to see if the given address, sa, is one that is currently known by
5277f8829a4aSRandall Stewart  * the kernel note: can't distinguish the same address on multiple interfaces
5278f8829a4aSRandall Stewart  * and doesn't handle multiple addresses with different zone/scope id's note:
5279f8829a4aSRandall Stewart  * ifa_ifwithaddr() compares the entire sockaddr struct
5280f8829a4aSRandall Stewart  */
528142551e99SRandall Stewart struct sctp_ifa *
528280fefe0aSRandall Stewart sctp_find_ifa_in_ep(struct sctp_inpcb *inp, struct sockaddr *addr,
528380fefe0aSRandall Stewart     int holds_lock)
5284f8829a4aSRandall Stewart {
528542551e99SRandall Stewart 	struct sctp_laddr *laddr;
5286f8829a4aSRandall Stewart 
5287ad81507eSRandall Stewart 	if (holds_lock == 0) {
528842551e99SRandall Stewart 		SCTP_INP_RLOCK(inp);
5289ad81507eSRandall Stewart 	}
52900053ed28SMichael Tuexen 
529142551e99SRandall Stewart 	LIST_FOREACH(laddr, &inp->sctp_addr_list, sctp_nxt_addr) {
529242551e99SRandall Stewart 		if (laddr->ifa == NULL)
5293f8829a4aSRandall Stewart 			continue;
529442551e99SRandall Stewart 		if (addr->sa_family != laddr->ifa->address.sa.sa_family)
529542551e99SRandall Stewart 			continue;
5296e6194c2eSMichael Tuexen #ifdef INET
529742551e99SRandall Stewart 		if (addr->sa_family == AF_INET) {
529842551e99SRandall Stewart 			if (((struct sockaddr_in *)addr)->sin_addr.s_addr ==
529942551e99SRandall Stewart 			    laddr->ifa->address.sin.sin_addr.s_addr) {
530042551e99SRandall Stewart 				/* found him. */
530142551e99SRandall Stewart 				break;
530242551e99SRandall Stewart 			}
53035e2c2d87SRandall Stewart 		}
5304e6194c2eSMichael Tuexen #endif
53055e2c2d87SRandall Stewart #ifdef INET6
53065e2c2d87SRandall Stewart 		if (addr->sa_family == AF_INET6) {
5307c54a18d2SRandall Stewart 			if (SCTP6_ARE_ADDR_EQUAL((struct sockaddr_in6 *)addr,
5308c54a18d2SRandall Stewart 			    &laddr->ifa->address.sin6)) {
530942551e99SRandall Stewart 				/* found him. */
531042551e99SRandall Stewart 				break;
531142551e99SRandall Stewart 			}
531242551e99SRandall Stewart 		}
53135e2c2d87SRandall Stewart #endif
531442551e99SRandall Stewart 	}
5315ad81507eSRandall Stewart 	if (holds_lock == 0) {
531642551e99SRandall Stewart 		SCTP_INP_RUNLOCK(inp);
5317ad81507eSRandall Stewart 	}
53187a3f60e7SMichael Tuexen 	if (laddr != NULL) {
531944710431SMichael Tuexen 		return (laddr->ifa);
53207a3f60e7SMichael Tuexen 	} else {
53217a3f60e7SMichael Tuexen 		return (NULL);
53227a3f60e7SMichael Tuexen 	}
532342551e99SRandall Stewart }
5324f8829a4aSRandall Stewart 
53256a27c376SRandall Stewart uint32_t
5326b0471b4bSMichael Tuexen sctp_get_ifa_hash_val(struct sockaddr *addr)
5327b0471b4bSMichael Tuexen {
5328ea5eba11SMichael Tuexen 	switch (addr->sa_family) {
5329ea5eba11SMichael Tuexen #ifdef INET
5330ea5eba11SMichael Tuexen 	case AF_INET:
5331ea5eba11SMichael Tuexen 		{
53326a27c376SRandall Stewart 			struct sockaddr_in *sin;
53336a27c376SRandall Stewart 
53346a27c376SRandall Stewart 			sin = (struct sockaddr_in *)addr;
53356a27c376SRandall Stewart 			return (sin->sin_addr.s_addr ^ (sin->sin_addr.s_addr >> 16));
5336ea5eba11SMichael Tuexen 		}
5337ea5eba11SMichael Tuexen #endif
5338ea5eba11SMichael Tuexen #ifdef INET6
53392c2e3218SMichael Tuexen 	case AF_INET6:
5340ea5eba11SMichael Tuexen 		{
53416a27c376SRandall Stewart 			struct sockaddr_in6 *sin6;
53426a27c376SRandall Stewart 			uint32_t hash_of_addr;
53436a27c376SRandall Stewart 
53446a27c376SRandall Stewart 			sin6 = (struct sockaddr_in6 *)addr;
53456a27c376SRandall Stewart 			hash_of_addr = (sin6->sin6_addr.s6_addr32[0] +
53466a27c376SRandall Stewart 			    sin6->sin6_addr.s6_addr32[1] +
53476a27c376SRandall Stewart 			    sin6->sin6_addr.s6_addr32[2] +
53486a27c376SRandall Stewart 			    sin6->sin6_addr.s6_addr32[3]);
53496a27c376SRandall Stewart 			hash_of_addr = (hash_of_addr ^ (hash_of_addr >> 16));
53506a27c376SRandall Stewart 			return (hash_of_addr);
53516a27c376SRandall Stewart 		}
5352ea5eba11SMichael Tuexen #endif
5353ea5eba11SMichael Tuexen 	default:
5354ea5eba11SMichael Tuexen 		break;
5355ea5eba11SMichael Tuexen 	}
53566a27c376SRandall Stewart 	return (0);
53576a27c376SRandall Stewart }
53586a27c376SRandall Stewart 
535942551e99SRandall Stewart struct sctp_ifa *
536042551e99SRandall Stewart sctp_find_ifa_by_addr(struct sockaddr *addr, uint32_t vrf_id, int holds_lock)
536142551e99SRandall Stewart {
536242551e99SRandall Stewart 	struct sctp_ifa *sctp_ifap;
536342551e99SRandall Stewart 	struct sctp_vrf *vrf;
53646a27c376SRandall Stewart 	struct sctp_ifalist *hash_head;
53656a27c376SRandall Stewart 	uint32_t hash_of_addr;
536642551e99SRandall Stewart 
53677f0ad227SMichael Tuexen 	if (holds_lock == 0) {
5368c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RLOCK();
53697f0ad227SMichael Tuexen 	} else {
53707f0ad227SMichael Tuexen 		SCTP_IPI_ADDR_LOCK_ASSERT();
53717f0ad227SMichael Tuexen 	}
537242551e99SRandall Stewart 
5373bff64a4dSRandall Stewart 	vrf = sctp_find_vrf(vrf_id);
5374bff64a4dSRandall Stewart 	if (vrf == NULL) {
5375bff64a4dSRandall Stewart 		if (holds_lock == 0)
5376c99efcf6SRandall Stewart 			SCTP_IPI_ADDR_RUNLOCK();
5377bff64a4dSRandall Stewart 		return (NULL);
5378bff64a4dSRandall Stewart 	}
53790053ed28SMichael Tuexen 
5380bff64a4dSRandall Stewart 	hash_of_addr = sctp_get_ifa_hash_val(addr);
5381bff64a4dSRandall Stewart 
538217205eccSRandall Stewart 	hash_head = &vrf->vrf_addr_hash[(hash_of_addr & vrf->vrf_addr_hashmark)];
5383bff64a4dSRandall Stewart 	if (hash_head == NULL) {
5384ad81507eSRandall Stewart 		SCTP_PRINTF("hash_of_addr:%x mask:%x table:%x - ",
5385c99efcf6SRandall Stewart 		    hash_of_addr, (uint32_t)vrf->vrf_addr_hashmark,
5386c99efcf6SRandall Stewart 		    (uint32_t)(hash_of_addr & vrf->vrf_addr_hashmark));
5387bff64a4dSRandall Stewart 		sctp_print_address(addr);
5388ad81507eSRandall Stewart 		SCTP_PRINTF("No such bucket for address\n");
5389bff64a4dSRandall Stewart 		if (holds_lock == 0)
5390c99efcf6SRandall Stewart 			SCTP_IPI_ADDR_RUNLOCK();
5391bff64a4dSRandall Stewart 
5392bff64a4dSRandall Stewart 		return (NULL);
5393bff64a4dSRandall Stewart 	}
53946a27c376SRandall Stewart 	LIST_FOREACH(sctp_ifap, hash_head, next_bucket) {
53956a27c376SRandall Stewart 		if (addr->sa_family != sctp_ifap->address.sa.sa_family)
53966a27c376SRandall Stewart 			continue;
5397e6194c2eSMichael Tuexen #ifdef INET
53986a27c376SRandall Stewart 		if (addr->sa_family == AF_INET) {
53996a27c376SRandall Stewart 			if (((struct sockaddr_in *)addr)->sin_addr.s_addr ==
54006a27c376SRandall Stewart 			    sctp_ifap->address.sin.sin_addr.s_addr) {
54016a27c376SRandall Stewart 				/* found him. */
54026a27c376SRandall Stewart 				break;
54036a27c376SRandall Stewart 			}
54045e2c2d87SRandall Stewart 		}
5405e6194c2eSMichael Tuexen #endif
54065e2c2d87SRandall Stewart #ifdef INET6
54075e2c2d87SRandall Stewart 		if (addr->sa_family == AF_INET6) {
5408c54a18d2SRandall Stewart 			if (SCTP6_ARE_ADDR_EQUAL((struct sockaddr_in6 *)addr,
5409c54a18d2SRandall Stewart 			    &sctp_ifap->address.sin6)) {
54106a27c376SRandall Stewart 				/* found him. */
54116a27c376SRandall Stewart 				break;
54126a27c376SRandall Stewart 			}
541342551e99SRandall Stewart 		}
54145e2c2d87SRandall Stewart #endif
541542551e99SRandall Stewart 	}
541642551e99SRandall Stewart 	if (holds_lock == 0)
5417c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RUNLOCK();
541844710431SMichael Tuexen 	return (sctp_ifap);
5419f8829a4aSRandall Stewart }
5420f8829a4aSRandall Stewart 
5421f8829a4aSRandall Stewart static void
54224c9179adSRandall Stewart sctp_user_rcvd(struct sctp_tcb *stcb, uint32_t *freed_so_far, int hold_rlock,
5423f8829a4aSRandall Stewart     uint32_t rwnd_req)
5424f8829a4aSRandall Stewart {
5425f8829a4aSRandall Stewart 	/* User pulled some data, do we need a rwnd update? */
5426868b51f2SMichael Tuexen 	struct epoch_tracker et;
5427f8829a4aSRandall Stewart 	int r_unlocked = 0;
5428f8829a4aSRandall Stewart 	uint32_t dif, rwnd;
5429f8829a4aSRandall Stewart 	struct socket *so = NULL;
5430f8829a4aSRandall Stewart 
5431f8829a4aSRandall Stewart 	if (stcb == NULL)
5432f8829a4aSRandall Stewart 		return;
5433f8829a4aSRandall Stewart 
543450cec919SRandall Stewart 	atomic_add_int(&stcb->asoc.refcnt, 1);
5435f8829a4aSRandall Stewart 
5436839d21d6SMichael Tuexen 	if ((SCTP_GET_STATE(stcb) == SCTP_STATE_SHUTDOWN_ACK_SENT) ||
543761a21880SMichael Tuexen 	    (stcb->asoc.state & (SCTP_STATE_ABOUT_TO_BE_FREED | SCTP_STATE_SHUTDOWN_RECEIVED))) {
5438f8829a4aSRandall Stewart 		/* Pre-check If we are freeing no update */
5439f8829a4aSRandall Stewart 		goto no_lock;
5440f8829a4aSRandall Stewart 	}
5441f8829a4aSRandall Stewart 	SCTP_INP_INCR_REF(stcb->sctp_ep);
5442f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
5443f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE)) {
5444f8829a4aSRandall Stewart 		goto out;
5445f8829a4aSRandall Stewart 	}
5446f8829a4aSRandall Stewart 	so = stcb->sctp_socket;
5447f8829a4aSRandall Stewart 	if (so == NULL) {
5448f8829a4aSRandall Stewart 		goto out;
5449f8829a4aSRandall Stewart 	}
5450f8829a4aSRandall Stewart 	atomic_add_int(&stcb->freed_by_sorcv_sincelast, *freed_so_far);
5451f8829a4aSRandall Stewart 	/* Have you have freed enough to look */
5452f8829a4aSRandall Stewart 	*freed_so_far = 0;
5453f8829a4aSRandall Stewart 	/* Yep, its worth a look and the lock overhead */
5454f8829a4aSRandall Stewart 
5455f8829a4aSRandall Stewart 	/* Figure out what the rwnd would be */
5456f8829a4aSRandall Stewart 	rwnd = sctp_calc_rwnd(stcb, &stcb->asoc);
5457f8829a4aSRandall Stewart 	if (rwnd >= stcb->asoc.my_last_reported_rwnd) {
5458f8829a4aSRandall Stewart 		dif = rwnd - stcb->asoc.my_last_reported_rwnd;
5459f8829a4aSRandall Stewart 	} else {
5460f8829a4aSRandall Stewart 		dif = 0;
5461f8829a4aSRandall Stewart 	}
5462f8829a4aSRandall Stewart 	if (dif >= rwnd_req) {
5463f8829a4aSRandall Stewart 		if (hold_rlock) {
5464f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(stcb->sctp_ep);
5465f8829a4aSRandall Stewart 			r_unlocked = 1;
5466f8829a4aSRandall Stewart 		}
5467f8829a4aSRandall Stewart 		if (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
5468f8829a4aSRandall Stewart 			/*
5469f8829a4aSRandall Stewart 			 * One last check before we allow the guy possibly
5470f8829a4aSRandall Stewart 			 * to get in. There is a race, where the guy has not
5471f8829a4aSRandall Stewart 			 * reached the gate. In that case
5472f8829a4aSRandall Stewart 			 */
5473f8829a4aSRandall Stewart 			goto out;
5474f8829a4aSRandall Stewart 		}
5475f8829a4aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
5476f8829a4aSRandall Stewart 		if (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
5477f8829a4aSRandall Stewart 			/* No reports here */
5478f8829a4aSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
5479f8829a4aSRandall Stewart 			goto out;
5480f8829a4aSRandall Stewart 		}
5481f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_wu_sacks_sent);
5482868b51f2SMichael Tuexen 		NET_EPOCH_ENTER(et);
5483689e6a5fSMichael Tuexen 		sctp_send_sack(stcb, SCTP_SO_LOCKED);
5484830d754dSRandall Stewart 
5485f8829a4aSRandall Stewart 		sctp_chunk_output(stcb->sctp_ep, stcb,
5486ceaad40aSRandall Stewart 		    SCTP_OUTPUT_FROM_USR_RCVD, SCTP_SO_LOCKED);
5487f8829a4aSRandall Stewart 		/* make sure no timer is running */
5488868b51f2SMichael Tuexen 		NET_EPOCH_EXIT(et);
5489ba785902SMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_RECV, stcb->sctp_ep, stcb, NULL,
5490ba785902SMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_6);
5491f8829a4aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
5492f8829a4aSRandall Stewart 	} else {
5493f8829a4aSRandall Stewart 		/* Update how much we have pending */
5494f8829a4aSRandall Stewart 		stcb->freed_by_sorcv_sincelast = dif;
5495f8829a4aSRandall Stewart 	}
5496f8829a4aSRandall Stewart out:
5497f8829a4aSRandall Stewart 	if (so && r_unlocked && hold_rlock) {
5498f8829a4aSRandall Stewart 		SCTP_INP_READ_LOCK(stcb->sctp_ep);
5499f8829a4aSRandall Stewart 	}
55000053ed28SMichael Tuexen 
5501f8829a4aSRandall Stewart 	SCTP_INP_DECR_REF(stcb->sctp_ep);
5502f8829a4aSRandall Stewart no_lock:
55033c1ba6f3SMichael Tuexen 	atomic_subtract_int(&stcb->asoc.refcnt, 1);
5504f8829a4aSRandall Stewart 	return;
5505f8829a4aSRandall Stewart }
5506f8829a4aSRandall Stewart 
5507f8829a4aSRandall Stewart int
5508f8829a4aSRandall Stewart sctp_sorecvmsg(struct socket *so,
5509f8829a4aSRandall Stewart     struct uio *uio,
5510f8829a4aSRandall Stewart     struct mbuf **mp,
5511f8829a4aSRandall Stewart     struct sockaddr *from,
5512f8829a4aSRandall Stewart     int fromlen,
5513f8829a4aSRandall Stewart     int *msg_flags,
5514f8829a4aSRandall Stewart     struct sctp_sndrcvinfo *sinfo,
5515f8829a4aSRandall Stewart     int filling_sinfo)
5516f8829a4aSRandall Stewart {
5517f8829a4aSRandall Stewart 	/*
5518f8829a4aSRandall Stewart 	 * MSG flags we will look at MSG_DONTWAIT - non-blocking IO.
5519f8829a4aSRandall Stewart 	 * MSG_PEEK - Look don't touch :-D (only valid with OUT mbuf copy
5520f8829a4aSRandall Stewart 	 * mp=NULL thus uio is the copy method to userland) MSG_WAITALL - ??
5521f8829a4aSRandall Stewart 	 * On the way out we may send out any combination of:
5522f8829a4aSRandall Stewart 	 * MSG_NOTIFICATION MSG_EOR
5523f8829a4aSRandall Stewart 	 *
5524f8829a4aSRandall Stewart 	 */
5525f8829a4aSRandall Stewart 	struct sctp_inpcb *inp = NULL;
552658e6eeefSMichael Tuexen 	ssize_t my_len = 0;
552758e6eeefSMichael Tuexen 	ssize_t cp_len = 0;
55280d3cf13dSMichael Tuexen 	int error = 0;
5529f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control = NULL, *ctl = NULL, *nxt = NULL;
553094b0d969SMichael Tuexen 	struct mbuf *m = NULL;
5531f8829a4aSRandall Stewart 	struct sctp_tcb *stcb = NULL;
5532f8829a4aSRandall Stewart 	int wakeup_read_socket = 0;
5533f8829a4aSRandall Stewart 	int freecnt_applied = 0;
5534f8829a4aSRandall Stewart 	int out_flags = 0, in_flags = 0;
5535f8829a4aSRandall Stewart 	int block_allowed = 1;
55364c9179adSRandall Stewart 	uint32_t freed_so_far = 0;
553758e6eeefSMichael Tuexen 	ssize_t copied_so_far = 0;
553893164cf9SRandall Stewart 	int in_eeor_mode = 0;
5539f8829a4aSRandall Stewart 	int no_rcv_needed = 0;
5540f8829a4aSRandall Stewart 	uint32_t rwnd_req = 0;
5541f8829a4aSRandall Stewart 	int hold_sblock = 0;
5542f8829a4aSRandall Stewart 	int hold_rlock = 0;
55439a8e3088SMichael Tuexen 	ssize_t slen = 0;
55444c9179adSRandall Stewart 	uint32_t held_length = 0;
55457abab911SRobert Watson 	int sockbuf_lock = 0;
5546f8829a4aSRandall Stewart 
554717205eccSRandall Stewart 	if (uio == NULL) {
5548c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
554917205eccSRandall Stewart 		return (EINVAL);
555017205eccSRandall Stewart 	}
55510053ed28SMichael Tuexen 
5552f8829a4aSRandall Stewart 	if (msg_flags) {
5553f8829a4aSRandall Stewart 		in_flags = *msg_flags;
5554c105859eSRandall Stewart 		if (in_flags & MSG_PEEK)
5555c105859eSRandall Stewart 			SCTP_STAT_INCR(sctps_read_peeks);
5556f8829a4aSRandall Stewart 	} else {
5557f8829a4aSRandall Stewart 		in_flags = 0;
5558f8829a4aSRandall Stewart 	}
5559f8829a4aSRandall Stewart 	slen = uio->uio_resid;
556017205eccSRandall Stewart 
5561f8829a4aSRandall Stewart 	/* Pull in and set up our int flags */
5562f8829a4aSRandall Stewart 	if (in_flags & MSG_OOB) {
5563f8829a4aSRandall Stewart 		/* Out of band's NOT supported */
5564f8829a4aSRandall Stewart 		return (EOPNOTSUPP);
5565f8829a4aSRandall Stewart 	}
5566f8829a4aSRandall Stewart 	if ((in_flags & MSG_PEEK) && (mp != NULL)) {
5567c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
5568f8829a4aSRandall Stewart 		return (EINVAL);
5569f8829a4aSRandall Stewart 	}
5570f8829a4aSRandall Stewart 	if ((in_flags & (MSG_DONTWAIT
5571f8829a4aSRandall Stewart 	    | MSG_NBIO
5572f8829a4aSRandall Stewart 	    )) ||
557342551e99SRandall Stewart 	    SCTP_SO_IS_NBIO(so)) {
5574f8829a4aSRandall Stewart 		block_allowed = 0;
5575f8829a4aSRandall Stewart 	}
5576f8829a4aSRandall Stewart 	/* setup the endpoint */
5577f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)so->so_pcb;
5578f8829a4aSRandall Stewart 	if (inp == NULL) {
5579c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EFAULT);
5580f8829a4aSRandall Stewart 		return (EFAULT);
5581f8829a4aSRandall Stewart 	}
558262c1ff9cSRandall Stewart 	rwnd_req = (SCTP_SB_LIMIT_RCV(so) >> SCTP_RWND_HIWAT_SHIFT);
5583f8829a4aSRandall Stewart 	/* Must be at least a MTU's worth */
5584f8829a4aSRandall Stewart 	if (rwnd_req < SCTP_MIN_RWND)
5585f8829a4aSRandall Stewart 		rwnd_req = SCTP_MIN_RWND;
5586f8829a4aSRandall Stewart 	in_eeor_mode = sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXPLICIT_EOR);
5587b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
5588f8829a4aSRandall Stewart 		sctp_misc_ints(SCTP_SORECV_ENTER,
55899a8e3088SMichael Tuexen 		    rwnd_req, in_eeor_mode, so->so_rcv.sb_cc, (uint32_t)uio->uio_resid);
559080fefe0aSRandall Stewart 	}
5591b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
5592f8829a4aSRandall Stewart 		sctp_misc_ints(SCTP_SORECV_ENTERPL,
55939a8e3088SMichael Tuexen 		    rwnd_req, block_allowed, so->so_rcv.sb_cc, (uint32_t)uio->uio_resid);
559480fefe0aSRandall Stewart 	}
55950053ed28SMichael Tuexen 
5596e6c19aa9SMark Johnston 	error = SOCK_IO_RECV_LOCK(so, SBLOCKWAIT(in_flags));
5597f8829a4aSRandall Stewart 	if (error) {
5598f8829a4aSRandall Stewart 		goto release_unlocked;
5599f8829a4aSRandall Stewart 	}
56008e1e6e5fSMateusz Guzik 	sockbuf_lock = 1;
5601f8829a4aSRandall Stewart restart:
56027abab911SRobert Watson 
5603f8829a4aSRandall Stewart restart_nosblocks:
5604f8829a4aSRandall Stewart 	if (hold_sblock == 0) {
5605f8829a4aSRandall Stewart 		SOCKBUF_LOCK(&so->so_rcv);
5606f8829a4aSRandall Stewart 		hold_sblock = 1;
5607f8829a4aSRandall Stewart 	}
5608f8829a4aSRandall Stewart 	if ((inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
5609f8829a4aSRandall Stewart 	    (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE)) {
5610f8829a4aSRandall Stewart 		goto out;
5611f8829a4aSRandall Stewart 	}
56124e88d37aSMichael Tuexen 	if ((so->so_rcv.sb_state & SBS_CANTRCVMORE) && (so->so_rcv.sb_cc == 0)) {
5613f8829a4aSRandall Stewart 		if (so->so_error) {
5614f8829a4aSRandall Stewart 			error = so->so_error;
561544b7479bSRandall Stewart 			if ((in_flags & MSG_PEEK) == 0)
561644b7479bSRandall Stewart 				so->so_error = 0;
56179f22f500SRandall Stewart 			goto out;
5618f8829a4aSRandall Stewart 		} else {
56194e88d37aSMichael Tuexen 			if (so->so_rcv.sb_cc == 0) {
56207924093fSRandall Stewart 				/* indicate EOF */
56217924093fSRandall Stewart 				error = 0;
5622f8829a4aSRandall Stewart 				goto out;
5623f8829a4aSRandall Stewart 			}
56249f22f500SRandall Stewart 		}
56259f22f500SRandall Stewart 	}
56269de217ceSMichael Tuexen 	if (so->so_rcv.sb_cc <= held_length) {
56279de217ceSMichael Tuexen 		if (so->so_error) {
56289de217ceSMichael Tuexen 			error = so->so_error;
56299de217ceSMichael Tuexen 			if ((in_flags & MSG_PEEK) == 0) {
56309de217ceSMichael Tuexen 				so->so_error = 0;
56319de217ceSMichael Tuexen 			}
56329de217ceSMichael Tuexen 			goto out;
56339de217ceSMichael Tuexen 		}
56344e88d37aSMichael Tuexen 		if ((so->so_rcv.sb_cc == 0) &&
5635f8829a4aSRandall Stewart 		    ((inp->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
5636f8829a4aSRandall Stewart 		    (inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL))) {
5637f8829a4aSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_CONNECTED) == 0) {
5638f8829a4aSRandall Stewart 				/*
5639f8829a4aSRandall Stewart 				 * For active open side clear flags for
5640f8829a4aSRandall Stewart 				 * re-use passive open is blocked by
5641f8829a4aSRandall Stewart 				 * connect.
5642f8829a4aSRandall Stewart 				 */
5643f8829a4aSRandall Stewart 				if (inp->sctp_flags & SCTP_PCB_FLAGS_WAS_ABORTED) {
5644b7b84c0eSMichael Tuexen 					/*
5645b7b84c0eSMichael Tuexen 					 * You were aborted, passive side
5646b7b84c0eSMichael Tuexen 					 * always hits here
5647b7b84c0eSMichael Tuexen 					 */
5648c4739e2fSRandall Stewart 					SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ECONNRESET);
5649f8829a4aSRandall Stewart 					error = ECONNRESET;
5650f8829a4aSRandall Stewart 				}
5651f8829a4aSRandall Stewart 				so->so_state &= ~(SS_ISCONNECTING |
5652f8829a4aSRandall Stewart 				    SS_ISDISCONNECTING |
5653f8829a4aSRandall Stewart 				    SS_ISCONFIRMING |
5654f8829a4aSRandall Stewart 				    SS_ISCONNECTED);
5655f8829a4aSRandall Stewart 				if (error == 0) {
5656f8829a4aSRandall Stewart 					if ((inp->sctp_flags & SCTP_PCB_FLAGS_WAS_CONNECTED) == 0) {
5657c4739e2fSRandall Stewart 						SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOTCONN);
5658f8829a4aSRandall Stewart 						error = ENOTCONN;
5659f8829a4aSRandall Stewart 					}
5660f8829a4aSRandall Stewart 				}
5661f8829a4aSRandall Stewart 				goto out;
5662f8829a4aSRandall Stewart 			}
5663f8829a4aSRandall Stewart 		}
56649de217ceSMichael Tuexen 		if (block_allowed) {
5665f8829a4aSRandall Stewart 			error = sbwait(&so->so_rcv);
5666f8829a4aSRandall Stewart 			if (error) {
5667f8829a4aSRandall Stewart 				goto out;
5668f8829a4aSRandall Stewart 			}
5669f8829a4aSRandall Stewart 			held_length = 0;
5670f8829a4aSRandall Stewart 			goto restart_nosblocks;
567144b7479bSRandall Stewart 		} else {
5672c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EWOULDBLOCK);
5673f8829a4aSRandall Stewart 			error = EWOULDBLOCK;
5674f8829a4aSRandall Stewart 			goto out;
5675f8829a4aSRandall Stewart 		}
56769de217ceSMichael Tuexen 	}
5677d06c82f1SRandall Stewart 	if (hold_sblock == 1) {
5678d06c82f1SRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
5679d06c82f1SRandall Stewart 		hold_sblock = 0;
5680d06c82f1SRandall Stewart 	}
5681f8829a4aSRandall Stewart 	/* we possibly have data we can read */
56823c503c28SRandall Stewart 	/* sa_ignore FREED_MEMORY */
5683f8829a4aSRandall Stewart 	control = TAILQ_FIRST(&inp->read_queue);
5684f8829a4aSRandall Stewart 	if (control == NULL) {
5685f8829a4aSRandall Stewart 		/*
5686f8829a4aSRandall Stewart 		 * This could be happening since the appender did the
5687f8829a4aSRandall Stewart 		 * increment but as not yet did the tailq insert onto the
5688f8829a4aSRandall Stewart 		 * read_queue
5689f8829a4aSRandall Stewart 		 */
5690f8829a4aSRandall Stewart 		if (hold_rlock == 0) {
5691f8829a4aSRandall Stewart 			SCTP_INP_READ_LOCK(inp);
5692f8829a4aSRandall Stewart 		}
5693f8829a4aSRandall Stewart 		control = TAILQ_FIRST(&inp->read_queue);
56944e88d37aSMichael Tuexen 		if ((control == NULL) && (so->so_rcv.sb_cc != 0)) {
5695a5d547adSRandall Stewart #ifdef INVARIANTS
5696f8829a4aSRandall Stewart 			panic("Huh, its non zero and nothing on control?");
5697f8829a4aSRandall Stewart #endif
56984e88d37aSMichael Tuexen 			so->so_rcv.sb_cc = 0;
5699f8829a4aSRandall Stewart 		}
5700f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
5701f8829a4aSRandall Stewart 		hold_rlock = 0;
5702f8829a4aSRandall Stewart 		goto restart;
5703f8829a4aSRandall Stewart 	}
57040053ed28SMichael Tuexen 
5705f8829a4aSRandall Stewart 	if ((control->length == 0) &&
5706f8829a4aSRandall Stewart 	    (control->do_not_ref_stcb)) {
5707f8829a4aSRandall Stewart 		/*
5708f8829a4aSRandall Stewart 		 * Clean up code for freeing assoc that left behind a
5709f8829a4aSRandall Stewart 		 * pdapi.. maybe a peer in EEOR that just closed after
5710f8829a4aSRandall Stewart 		 * sending and never indicated a EOR.
5711f8829a4aSRandall Stewart 		 */
5712f8829a4aSRandall Stewart 		if (hold_rlock == 0) {
5713f8829a4aSRandall Stewart 			hold_rlock = 1;
5714f8829a4aSRandall Stewart 			SCTP_INP_READ_LOCK(inp);
5715f8829a4aSRandall Stewart 		}
5716f8829a4aSRandall Stewart 		control->held_length = 0;
5717f8829a4aSRandall Stewart 		if (control->data) {
5718f8829a4aSRandall Stewart 			/* Hmm there is data here .. fix */
57194c9179adSRandall Stewart 			struct mbuf *m_tmp;
5720f8829a4aSRandall Stewart 			int cnt = 0;
5721f8829a4aSRandall Stewart 
57224c9179adSRandall Stewart 			m_tmp = control->data;
57234c9179adSRandall Stewart 			while (m_tmp) {
57244c9179adSRandall Stewart 				cnt += SCTP_BUF_LEN(m_tmp);
57254c9179adSRandall Stewart 				if (SCTP_BUF_NEXT(m_tmp) == NULL) {
57264c9179adSRandall Stewart 					control->tail_mbuf = m_tmp;
5727f8829a4aSRandall Stewart 					control->end_added = 1;
5728f8829a4aSRandall Stewart 				}
57294c9179adSRandall Stewart 				m_tmp = SCTP_BUF_NEXT(m_tmp);
5730f8829a4aSRandall Stewart 			}
5731f8829a4aSRandall Stewart 			control->length = cnt;
5732f8829a4aSRandall Stewart 		} else {
5733f8829a4aSRandall Stewart 			/* remove it */
5734f8829a4aSRandall Stewart 			TAILQ_REMOVE(&inp->read_queue, control, next);
5735f8829a4aSRandall Stewart 			/* Add back any hiddend data */
5736f8829a4aSRandall Stewart 			sctp_free_remote_addr(control->whoFrom);
5737f8829a4aSRandall Stewart 			sctp_free_a_readq(stcb, control);
5738f8829a4aSRandall Stewart 		}
5739f8829a4aSRandall Stewart 		if (hold_rlock) {
5740f8829a4aSRandall Stewart 			hold_rlock = 0;
5741f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
5742f8829a4aSRandall Stewart 		}
5743f8829a4aSRandall Stewart 		goto restart;
5744f8829a4aSRandall Stewart 	}
5745810ec536SMichael Tuexen 	if ((control->length == 0) &&
5746810ec536SMichael Tuexen 	    (control->end_added == 1)) {
5747b7b84c0eSMichael Tuexen 		/*
5748b7b84c0eSMichael Tuexen 		 * Do we also need to check for (control->pdapi_aborted ==
5749b7b84c0eSMichael Tuexen 		 * 1)?
5750b7b84c0eSMichael Tuexen 		 */
5751810ec536SMichael Tuexen 		if (hold_rlock == 0) {
5752810ec536SMichael Tuexen 			hold_rlock = 1;
5753810ec536SMichael Tuexen 			SCTP_INP_READ_LOCK(inp);
5754810ec536SMichael Tuexen 		}
5755810ec536SMichael Tuexen 		TAILQ_REMOVE(&inp->read_queue, control, next);
5756810ec536SMichael Tuexen 		if (control->data) {
5757810ec536SMichael Tuexen #ifdef INVARIANTS
5758810ec536SMichael Tuexen 			panic("control->data not null but control->length == 0");
5759810ec536SMichael Tuexen #else
5760810ec536SMichael Tuexen 			SCTP_PRINTF("Strange, data left in the control buffer. Cleaning up.\n");
5761810ec536SMichael Tuexen 			sctp_m_freem(control->data);
5762810ec536SMichael Tuexen 			control->data = NULL;
5763810ec536SMichael Tuexen #endif
5764810ec536SMichael Tuexen 		}
5765810ec536SMichael Tuexen 		if (control->aux_data) {
5766810ec536SMichael Tuexen 			sctp_m_free(control->aux_data);
5767810ec536SMichael Tuexen 			control->aux_data = NULL;
5768810ec536SMichael Tuexen 		}
576998d5fd97SMichael Tuexen #ifdef INVARIANTS
577044249214SRandall Stewart 		if (control->on_strm_q) {
577144249214SRandall Stewart 			panic("About to free ctl:%p so:%p and its in %d",
577244249214SRandall Stewart 			    control, so, control->on_strm_q);
577344249214SRandall Stewart 		}
577498d5fd97SMichael Tuexen #endif
5775810ec536SMichael Tuexen 		sctp_free_remote_addr(control->whoFrom);
5776810ec536SMichael Tuexen 		sctp_free_a_readq(stcb, control);
5777810ec536SMichael Tuexen 		if (hold_rlock) {
5778810ec536SMichael Tuexen 			hold_rlock = 0;
5779810ec536SMichael Tuexen 			SCTP_INP_READ_UNLOCK(inp);
5780810ec536SMichael Tuexen 		}
5781810ec536SMichael Tuexen 		goto restart;
5782810ec536SMichael Tuexen 	}
5783f8829a4aSRandall Stewart 	if (control->length == 0) {
5784f8829a4aSRandall Stewart 		if ((sctp_is_feature_on(inp, SCTP_PCB_FLAGS_FRAG_INTERLEAVE)) &&
5785f8829a4aSRandall Stewart 		    (filling_sinfo)) {
5786f8829a4aSRandall Stewart 			/* find a more suitable one then this */
5787f8829a4aSRandall Stewart 			ctl = TAILQ_NEXT(control, next);
5788f8829a4aSRandall Stewart 			while (ctl) {
57899a6142d8SRandall Stewart 				if ((ctl->stcb != control->stcb) && (ctl->length) &&
57909a6142d8SRandall Stewart 				    (ctl->some_taken ||
57916114cd96SRandall Stewart 				    (ctl->spec_flags & M_NOTIFICATION) ||
57929a6142d8SRandall Stewart 				    ((ctl->do_not_ref_stcb == 0) &&
57939a6142d8SRandall Stewart 				    (ctl->stcb->asoc.strmin[ctl->sinfo_stream].delivery_started == 0)))
57949a6142d8SRandall Stewart 				    ) {
57959a6142d8SRandall Stewart 					/*-
57969a6142d8SRandall Stewart 					 * If we have a different TCB next, and there is data
57979a6142d8SRandall Stewart 					 * present. If we have already taken some (pdapi), OR we can
57989a6142d8SRandall Stewart 					 * ref the tcb and no delivery as started on this stream, we
579917205eccSRandall Stewart 					 * take it. Note we allow a notification on a different
580017205eccSRandall Stewart 					 * assoc to be delivered..
58019a6142d8SRandall Stewart 					 */
58029a6142d8SRandall Stewart 					control = ctl;
58039a6142d8SRandall Stewart 					goto found_one;
58049a6142d8SRandall Stewart 				} else if ((sctp_is_feature_on(inp, SCTP_PCB_FLAGS_INTERLEAVE_STRMS)) &&
58059a6142d8SRandall Stewart 					    (ctl->length) &&
58069a6142d8SRandall Stewart 					    ((ctl->some_taken) ||
58079a6142d8SRandall Stewart 					    ((ctl->do_not_ref_stcb == 0) &&
580817205eccSRandall Stewart 					    ((ctl->spec_flags & M_NOTIFICATION) == 0) &&
5809b5c16493SMichael Tuexen 				    (ctl->stcb->asoc.strmin[ctl->sinfo_stream].delivery_started == 0)))) {
58109a6142d8SRandall Stewart 					/*-
58119a6142d8SRandall Stewart 					 * If we have the same tcb, and there is data present, and we
58129a6142d8SRandall Stewart 					 * have the strm interleave feature present. Then if we have
58139a6142d8SRandall Stewart 					 * taken some (pdapi) or we can refer to tht tcb AND we have
58149a6142d8SRandall Stewart 					 * not started a delivery for this stream, we can take it.
581517205eccSRandall Stewart 					 * Note we do NOT allow a notificaiton on the same assoc to
581617205eccSRandall Stewart 					 * be delivered.
58179a6142d8SRandall Stewart 					 */
5818f8829a4aSRandall Stewart 					control = ctl;
5819f8829a4aSRandall Stewart 					goto found_one;
5820f8829a4aSRandall Stewart 				}
5821f8829a4aSRandall Stewart 				ctl = TAILQ_NEXT(ctl, next);
5822f8829a4aSRandall Stewart 			}
5823f8829a4aSRandall Stewart 		}
5824f8829a4aSRandall Stewart 		/*
5825f8829a4aSRandall Stewart 		 * if we reach here, not suitable replacement is available
58264e88d37aSMichael Tuexen 		 * <or> fragment interleave is NOT on. So stuff the sb_cc
5827f8829a4aSRandall Stewart 		 * into the our held count, and its time to sleep again.
5828f8829a4aSRandall Stewart 		 */
58294e88d37aSMichael Tuexen 		held_length = so->so_rcv.sb_cc;
58304e88d37aSMichael Tuexen 		control->held_length = so->so_rcv.sb_cc;
5831f8829a4aSRandall Stewart 		goto restart;
5832f8829a4aSRandall Stewart 	}
5833f8829a4aSRandall Stewart 	/* Clear the held length since there is something to read */
5834f8829a4aSRandall Stewart 	control->held_length = 0;
5835f8829a4aSRandall Stewart found_one:
5836f8829a4aSRandall Stewart 	/*
5837f8829a4aSRandall Stewart 	 * If we reach here, control has a some data for us to read off.
5838f8829a4aSRandall Stewart 	 * Note that stcb COULD be NULL.
5839f8829a4aSRandall Stewart 	 */
58409c5ca6f2SMichael Tuexen 	if (hold_rlock == 0) {
58419c5ca6f2SMichael Tuexen 		hold_rlock = 1;
58429c5ca6f2SMichael Tuexen 		SCTP_INP_READ_LOCK(inp);
5843f8829a4aSRandall Stewart 	}
58449c5ca6f2SMichael Tuexen 	control->some_taken++;
5845f8829a4aSRandall Stewart 	stcb = control->stcb;
5846f8829a4aSRandall Stewart 	if (stcb) {
58470696e120SRandall Stewart 		if ((control->do_not_ref_stcb == 0) &&
58480696e120SRandall Stewart 		    (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED)) {
584950cec919SRandall Stewart 			if (freecnt_applied == 0)
5850f8829a4aSRandall Stewart 				stcb = NULL;
5851f8829a4aSRandall Stewart 		} else if (control->do_not_ref_stcb == 0) {
5852f8829a4aSRandall Stewart 			/* you can't free it on me please */
5853f8829a4aSRandall Stewart 			/*
5854f8829a4aSRandall Stewart 			 * The lock on the socket buffer protects us so the
5855f8829a4aSRandall Stewart 			 * free code will stop. But since we used the
5856f8829a4aSRandall Stewart 			 * socketbuf lock and the sender uses the tcb_lock
5857f8829a4aSRandall Stewart 			 * to increment, we need to use the atomic add to
5858f8829a4aSRandall Stewart 			 * the refcnt
5859f8829a4aSRandall Stewart 			 */
5860d55b0b1bSRandall Stewart 			if (freecnt_applied) {
5861d55b0b1bSRandall Stewart #ifdef INVARIANTS
5862207304d4SRandall Stewart 				panic("refcnt already incremented");
5863d55b0b1bSRandall Stewart #else
5864cd3fd531SMichael Tuexen 				SCTP_PRINTF("refcnt already incremented?\n");
5865d55b0b1bSRandall Stewart #endif
5866d55b0b1bSRandall Stewart 			} else {
586750cec919SRandall Stewart 				atomic_add_int(&stcb->asoc.refcnt, 1);
5868f8829a4aSRandall Stewart 				freecnt_applied = 1;
5869d55b0b1bSRandall Stewart 			}
5870f8829a4aSRandall Stewart 			/*
5871f8829a4aSRandall Stewart 			 * Setup to remember how much we have not yet told
5872f8829a4aSRandall Stewart 			 * the peer our rwnd has opened up. Note we grab the
5873f8829a4aSRandall Stewart 			 * value from the tcb from last time. Note too that
58740696e120SRandall Stewart 			 * sack sending clears this when a sack is sent,
5875f8829a4aSRandall Stewart 			 * which is fine. Once we hit the rwnd_req, we then
5876f8829a4aSRandall Stewart 			 * will go to the sctp_user_rcvd() that will not
5877f8829a4aSRandall Stewart 			 * lock until it KNOWs it MUST send a WUP-SACK.
5878f8829a4aSRandall Stewart 			 */
587958e6eeefSMichael Tuexen 			freed_so_far = (uint32_t)stcb->freed_by_sorcv_sincelast;
5880f8829a4aSRandall Stewart 			stcb->freed_by_sorcv_sincelast = 0;
5881f8829a4aSRandall Stewart 		}
5882f8829a4aSRandall Stewart 	}
58836114cd96SRandall Stewart 	if (stcb &&
58846114cd96SRandall Stewart 	    ((control->spec_flags & M_NOTIFICATION) == 0) &&
58856114cd96SRandall Stewart 	    control->do_not_ref_stcb == 0) {
5886d06c82f1SRandall Stewart 		stcb->asoc.strmin[control->sinfo_stream].delivery_started = 1;
5887d06c82f1SRandall Stewart 	}
58880053ed28SMichael Tuexen 
5889f8829a4aSRandall Stewart 	/* First lets get off the sinfo and sockaddr info */
58905f05199cSMichael Tuexen 	if ((sinfo != NULL) && (filling_sinfo != 0)) {
58915f05199cSMichael Tuexen 		sinfo->sinfo_stream = control->sinfo_stream;
589249656eefSMichael Tuexen 		sinfo->sinfo_ssn = (uint16_t)control->mid;
58935f05199cSMichael Tuexen 		sinfo->sinfo_flags = control->sinfo_flags;
58945f05199cSMichael Tuexen 		sinfo->sinfo_ppid = control->sinfo_ppid;
58955f05199cSMichael Tuexen 		sinfo->sinfo_context = control->sinfo_context;
58965f05199cSMichael Tuexen 		sinfo->sinfo_timetolive = control->sinfo_timetolive;
58975f05199cSMichael Tuexen 		sinfo->sinfo_tsn = control->sinfo_tsn;
58985f05199cSMichael Tuexen 		sinfo->sinfo_cumtsn = control->sinfo_cumtsn;
58995f05199cSMichael Tuexen 		sinfo->sinfo_assoc_id = control->sinfo_assoc_id;
5900f8829a4aSRandall Stewart 		nxt = TAILQ_NEXT(control, next);
5901e2e7c62eSMichael Tuexen 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXT_RCVINFO) ||
5902e2e7c62eSMichael Tuexen 		    sctp_is_feature_on(inp, SCTP_PCB_FLAGS_RECVNXTINFO)) {
5903f8829a4aSRandall Stewart 			struct sctp_extrcvinfo *s_extra;
5904f8829a4aSRandall Stewart 
5905f8829a4aSRandall Stewart 			s_extra = (struct sctp_extrcvinfo *)sinfo;
59069a6142d8SRandall Stewart 			if ((nxt) &&
59079a6142d8SRandall Stewart 			    (nxt->length)) {
5908b70b526dSMichael Tuexen 				s_extra->serinfo_next_flags = SCTP_NEXT_MSG_AVAIL;
5909f8829a4aSRandall Stewart 				if (nxt->sinfo_flags & SCTP_UNORDERED) {
5910b70b526dSMichael Tuexen 					s_extra->serinfo_next_flags |= SCTP_NEXT_MSG_IS_UNORDERED;
5911f8829a4aSRandall Stewart 				}
5912f42a358aSRandall Stewart 				if (nxt->spec_flags & M_NOTIFICATION) {
5913b70b526dSMichael Tuexen 					s_extra->serinfo_next_flags |= SCTP_NEXT_MSG_IS_NOTIFICATION;
5914f42a358aSRandall Stewart 				}
5915b70b526dSMichael Tuexen 				s_extra->serinfo_next_aid = nxt->sinfo_assoc_id;
5916b70b526dSMichael Tuexen 				s_extra->serinfo_next_length = nxt->length;
5917b70b526dSMichael Tuexen 				s_extra->serinfo_next_ppid = nxt->sinfo_ppid;
5918b70b526dSMichael Tuexen 				s_extra->serinfo_next_stream = nxt->sinfo_stream;
5919f8829a4aSRandall Stewart 				if (nxt->tail_mbuf != NULL) {
5920139bc87fSRandall Stewart 					if (nxt->end_added) {
5921b70b526dSMichael Tuexen 						s_extra->serinfo_next_flags |= SCTP_NEXT_MSG_ISCOMPLETE;
5922f8829a4aSRandall Stewart 					}
5923f8829a4aSRandall Stewart 				}
5924f8829a4aSRandall Stewart 			} else {
5925f8829a4aSRandall Stewart 				/*
5926f8829a4aSRandall Stewart 				 * we explicitly 0 this, since the memcpy
5927f8829a4aSRandall Stewart 				 * got some other things beyond the older
5928f8829a4aSRandall Stewart 				 * sinfo_ that is on the control's structure
5929f8829a4aSRandall Stewart 				 * :-D
5930f8829a4aSRandall Stewart 				 */
59319a6142d8SRandall Stewart 				nxt = NULL;
5932b70b526dSMichael Tuexen 				s_extra->serinfo_next_flags = SCTP_NO_NEXT_MSG;
5933b70b526dSMichael Tuexen 				s_extra->serinfo_next_aid = 0;
5934b70b526dSMichael Tuexen 				s_extra->serinfo_next_length = 0;
5935b70b526dSMichael Tuexen 				s_extra->serinfo_next_ppid = 0;
5936b70b526dSMichael Tuexen 				s_extra->serinfo_next_stream = 0;
5937f8829a4aSRandall Stewart 			}
5938f8829a4aSRandall Stewart 		}
5939f8829a4aSRandall Stewart 		/*
5940f8829a4aSRandall Stewart 		 * update off the real current cum-ack, if we have an stcb.
5941f8829a4aSRandall Stewart 		 */
59420696e120SRandall Stewart 		if ((control->do_not_ref_stcb == 0) && stcb)
5943f8829a4aSRandall Stewart 			sinfo->sinfo_cumtsn = stcb->asoc.cumulative_tsn;
5944f8829a4aSRandall Stewart 		/*
5945f8829a4aSRandall Stewart 		 * mask off the high bits, we keep the actual chunk bits in
5946f8829a4aSRandall Stewart 		 * there.
5947f8829a4aSRandall Stewart 		 */
5948f8829a4aSRandall Stewart 		sinfo->sinfo_flags &= 0x00ff;
59495f26a41dSRandall Stewart 		if ((control->sinfo_flags >> 8) & SCTP_DATA_UNORDERED) {
59505f26a41dSRandall Stewart 			sinfo->sinfo_flags |= SCTP_UNORDERED;
59515f26a41dSRandall Stewart 		}
5952f8829a4aSRandall Stewart 	}
595318e198d3SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
595418e198d3SRandall Stewart 	{
595518e198d3SRandall Stewart 		int index, newindex;
595618e198d3SRandall Stewart 		struct sctp_pcbtsn_rlog *entry;
595718e198d3SRandall Stewart 
595818e198d3SRandall Stewart 		do {
595918e198d3SRandall Stewart 			index = inp->readlog_index;
596018e198d3SRandall Stewart 			newindex = index + 1;
596118e198d3SRandall Stewart 			if (newindex >= SCTP_READ_LOG_SIZE) {
596218e198d3SRandall Stewart 				newindex = 0;
596318e198d3SRandall Stewart 			}
596418e198d3SRandall Stewart 		} while (atomic_cmpset_int(&inp->readlog_index, index, newindex) == 0);
596518e198d3SRandall Stewart 		entry = &inp->readlog[index];
596618e198d3SRandall Stewart 		entry->vtag = control->sinfo_assoc_id;
596718e198d3SRandall Stewart 		entry->strm = control->sinfo_stream;
596849656eefSMichael Tuexen 		entry->seq = (uint16_t)control->mid;
596918e198d3SRandall Stewart 		entry->sz = control->length;
597018e198d3SRandall Stewart 		entry->flgs = control->sinfo_flags;
597118e198d3SRandall Stewart 	}
597218e198d3SRandall Stewart #endif
5973d59107f7SMichael Tuexen 	if ((fromlen > 0) && (from != NULL)) {
5974d59107f7SMichael Tuexen 		union sctp_sockstore store;
5975d59107f7SMichael Tuexen 		size_t len;
5976d59107f7SMichael Tuexen 
5977b5b6e5c2SMichael Tuexen 		switch (control->whoFrom->ro._l_addr.sa.sa_family) {
5978b5b6e5c2SMichael Tuexen #ifdef INET6
5979b5b6e5c2SMichael Tuexen 		case AF_INET6:
5980d59107f7SMichael Tuexen 			len = sizeof(struct sockaddr_in6);
5981d59107f7SMichael Tuexen 			store.sin6 = control->whoFrom->ro._l_addr.sin6;
5982d59107f7SMichael Tuexen 			store.sin6.sin6_port = control->port_from;
5983b5b6e5c2SMichael Tuexen 			break;
5984f8829a4aSRandall Stewart #endif
5985b5b6e5c2SMichael Tuexen #ifdef INET
5986b5b6e5c2SMichael Tuexen 		case AF_INET:
5987d59107f7SMichael Tuexen #ifdef INET6
5988d59107f7SMichael Tuexen 			if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_NEEDS_MAPPED_V4)) {
5989d59107f7SMichael Tuexen 				len = sizeof(struct sockaddr_in6);
5990d59107f7SMichael Tuexen 				in6_sin_2_v4mapsin6(&control->whoFrom->ro._l_addr.sin,
5991d59107f7SMichael Tuexen 				    &store.sin6);
5992d59107f7SMichael Tuexen 				store.sin6.sin6_port = control->port_from;
5993d59107f7SMichael Tuexen 			} else {
5994d59107f7SMichael Tuexen 				len = sizeof(struct sockaddr_in);
5995d59107f7SMichael Tuexen 				store.sin = control->whoFrom->ro._l_addr.sin;
5996d59107f7SMichael Tuexen 				store.sin.sin_port = control->port_from;
5997d59107f7SMichael Tuexen 			}
5998d59107f7SMichael Tuexen #else
5999d59107f7SMichael Tuexen 			len = sizeof(struct sockaddr_in);
6000d59107f7SMichael Tuexen 			store.sin = control->whoFrom->ro._l_addr.sin;
6001d59107f7SMichael Tuexen 			store.sin.sin_port = control->port_from;
6002d59107f7SMichael Tuexen #endif
6003b5b6e5c2SMichael Tuexen 			break;
6004b5b6e5c2SMichael Tuexen #endif
6005b5b6e5c2SMichael Tuexen 		default:
6006d59107f7SMichael Tuexen 			len = 0;
6007b5b6e5c2SMichael Tuexen 			break;
6008b5b6e5c2SMichael Tuexen 		}
6009d59107f7SMichael Tuexen 		memcpy(from, &store, min((size_t)fromlen, len));
6010e0e00a4dSMichael Tuexen #ifdef INET6
6011f8829a4aSRandall Stewart 		{
6012b5b6e5c2SMichael Tuexen 			struct sockaddr_in6 lsa6, *from6;
6013f8829a4aSRandall Stewart 
6014b5b6e5c2SMichael Tuexen 			from6 = (struct sockaddr_in6 *)from;
6015b5b6e5c2SMichael Tuexen 			sctp_recover_scope_mac(from6, (&lsa6));
6016f8829a4aSRandall Stewart 		}
6017f8829a4aSRandall Stewart #endif
6018f8829a4aSRandall Stewart 	}
60199c5ca6f2SMichael Tuexen 	if (hold_rlock) {
60209c5ca6f2SMichael Tuexen 		SCTP_INP_READ_UNLOCK(inp);
60219c5ca6f2SMichael Tuexen 		hold_rlock = 0;
60229c5ca6f2SMichael Tuexen 	}
60239c5ca6f2SMichael Tuexen 	if (hold_sblock) {
60249c5ca6f2SMichael Tuexen 		SOCKBUF_UNLOCK(&so->so_rcv);
60259c5ca6f2SMichael Tuexen 		hold_sblock = 0;
60269c5ca6f2SMichael Tuexen 	}
6027f8829a4aSRandall Stewart 	/* now copy out what data we can */
6028f8829a4aSRandall Stewart 	if (mp == NULL) {
6029f8829a4aSRandall Stewart 		/* copy out each mbuf in the chain up to length */
6030f8829a4aSRandall Stewart get_more_data:
6031f8829a4aSRandall Stewart 		m = control->data;
6032f8829a4aSRandall Stewart 		while (m) {
6033f8829a4aSRandall Stewart 			/* Move out all we can */
60340d3cf13dSMichael Tuexen 			cp_len = uio->uio_resid;
60350d3cf13dSMichael Tuexen 			my_len = SCTP_BUF_LEN(m);
6036f8829a4aSRandall Stewart 			if (cp_len > my_len) {
6037f8829a4aSRandall Stewart 				/* not enough in this buf */
6038f8829a4aSRandall Stewart 				cp_len = my_len;
6039f8829a4aSRandall Stewart 			}
6040f8829a4aSRandall Stewart 			if (hold_rlock) {
6041f8829a4aSRandall Stewart 				SCTP_INP_READ_UNLOCK(inp);
6042f8829a4aSRandall Stewart 				hold_rlock = 0;
6043f8829a4aSRandall Stewart 			}
6044f8829a4aSRandall Stewart 			if (cp_len > 0)
604558e6eeefSMichael Tuexen 				error = uiomove(mtod(m, char *), (int)cp_len, uio);
6046f8829a4aSRandall Stewart 			/* re-read */
6047f8829a4aSRandall Stewart 			if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
6048f8829a4aSRandall Stewart 				goto release;
6049f8829a4aSRandall Stewart 			}
60500053ed28SMichael Tuexen 
60510696e120SRandall Stewart 			if ((control->do_not_ref_stcb == 0) && stcb &&
6052f8829a4aSRandall Stewart 			    stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
6053f8829a4aSRandall Stewart 				no_rcv_needed = 1;
6054f8829a4aSRandall Stewart 			}
6055f8829a4aSRandall Stewart 			if (error) {
6056f8829a4aSRandall Stewart 				/* error we are out of here */
6057f8829a4aSRandall Stewart 				goto release;
6058f8829a4aSRandall Stewart 			}
6059f8829a4aSRandall Stewart 			SCTP_INP_READ_LOCK(inp);
6060f8829a4aSRandall Stewart 			hold_rlock = 1;
6061139bc87fSRandall Stewart 			if (cp_len == SCTP_BUF_LEN(m)) {
6062139bc87fSRandall Stewart 				if ((SCTP_BUF_NEXT(m) == NULL) &&
6063139bc87fSRandall Stewart 				    (control->end_added)) {
6064f8829a4aSRandall Stewart 					out_flags |= MSG_EOR;
606552129fcdSRandall Stewart 					if ((control->do_not_ref_stcb == 0) &&
606652129fcdSRandall Stewart 					    (control->stcb != NULL) &&
606752129fcdSRandall Stewart 					    ((control->spec_flags & M_NOTIFICATION) == 0))
6068ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
6069f8829a4aSRandall Stewart 				}
6070139bc87fSRandall Stewart 				if (control->spec_flags & M_NOTIFICATION) {
6071f8829a4aSRandall Stewart 					out_flags |= MSG_NOTIFICATION;
6072f8829a4aSRandall Stewart 				}
6073f8829a4aSRandall Stewart 				/* we ate up the mbuf */
6074f8829a4aSRandall Stewart 				if (in_flags & MSG_PEEK) {
6075f8829a4aSRandall Stewart 					/* just looking */
6076139bc87fSRandall Stewart 					m = SCTP_BUF_NEXT(m);
6077f8829a4aSRandall Stewart 					copied_so_far += cp_len;
6078f8829a4aSRandall Stewart 				} else {
6079f8829a4aSRandall Stewart 					/* dispose of the mbuf */
6080b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
6081f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv,
6082139bc87fSRandall Stewart 						    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
608380fefe0aSRandall Stewart 					}
6084f8829a4aSRandall Stewart 					sctp_sbfree(control, stcb, &so->so_rcv, m);
6085b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
6086f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv,
6087f8829a4aSRandall Stewart 						    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
608880fefe0aSRandall Stewart 					}
6089f8829a4aSRandall Stewart 					copied_so_far += cp_len;
609058e6eeefSMichael Tuexen 					freed_so_far += (uint32_t)cp_len;
6091c4739e2fSRandall Stewart 					freed_so_far += MSIZE;
6092aab1d593SMichael Tuexen 					atomic_subtract_int(&control->length, (int)cp_len);
6093f8829a4aSRandall Stewart 					control->data = sctp_m_free(m);
6094f8829a4aSRandall Stewart 					m = control->data;
6095b7b84c0eSMichael Tuexen 					/*
6096b7b84c0eSMichael Tuexen 					 * been through it all, must hold sb
6097b7b84c0eSMichael Tuexen 					 * lock ok to null tail
6098b7b84c0eSMichael Tuexen 					 */
6099f8829a4aSRandall Stewart 					if (control->data == NULL) {
6100a5d547adSRandall Stewart #ifdef INVARIANTS
6101f8829a4aSRandall Stewart 						if ((control->end_added == 0) ||
6102f8829a4aSRandall Stewart 						    (TAILQ_NEXT(control, next) == NULL)) {
6103f8829a4aSRandall Stewart 							/*
6104f8829a4aSRandall Stewart 							 * If the end is not
6105f8829a4aSRandall Stewart 							 * added, OR the
6106f8829a4aSRandall Stewart 							 * next is NOT null
6107f8829a4aSRandall Stewart 							 * we MUST have the
6108f8829a4aSRandall Stewart 							 * lock.
6109f8829a4aSRandall Stewart 							 */
6110f8829a4aSRandall Stewart 							if (mtx_owned(&inp->inp_rdata_mtx) == 0) {
6111f8829a4aSRandall Stewart 								panic("Hmm we don't own the lock?");
6112f8829a4aSRandall Stewart 							}
6113f8829a4aSRandall Stewart 						}
6114f8829a4aSRandall Stewart #endif
6115f8829a4aSRandall Stewart 						control->tail_mbuf = NULL;
6116a5d547adSRandall Stewart #ifdef INVARIANTS
6117f8829a4aSRandall Stewart 						if ((control->end_added) && ((out_flags & MSG_EOR) == 0)) {
6118f8829a4aSRandall Stewart 							panic("end_added, nothing left and no MSG_EOR");
6119f8829a4aSRandall Stewart 						}
6120f8829a4aSRandall Stewart #endif
6121f8829a4aSRandall Stewart 					}
6122f8829a4aSRandall Stewart 				}
6123f8829a4aSRandall Stewart 			} else {
6124f8829a4aSRandall Stewart 				/* Do we need to trim the mbuf? */
6125139bc87fSRandall Stewart 				if (control->spec_flags & M_NOTIFICATION) {
6126f8829a4aSRandall Stewart 					out_flags |= MSG_NOTIFICATION;
6127f8829a4aSRandall Stewart 				}
6128f8829a4aSRandall Stewart 				if ((in_flags & MSG_PEEK) == 0) {
6129139bc87fSRandall Stewart 					SCTP_BUF_RESV_UF(m, cp_len);
613058e6eeefSMichael Tuexen 					SCTP_BUF_LEN(m) -= (int)cp_len;
6131b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
613258e6eeefSMichael Tuexen 						sctp_sblog(&so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, (int)cp_len);
613380fefe0aSRandall Stewart 					}
6134aab1d593SMichael Tuexen 					atomic_subtract_int(&so->so_rcv.sb_cc, (int)cp_len);
61350696e120SRandall Stewart 					if ((control->do_not_ref_stcb == 0) &&
61360696e120SRandall Stewart 					    stcb) {
6137aab1d593SMichael Tuexen 						atomic_subtract_int(&stcb->asoc.sb_cc, (int)cp_len);
6138f8829a4aSRandall Stewart 					}
6139f8829a4aSRandall Stewart 					copied_so_far += cp_len;
614058e6eeefSMichael Tuexen 					freed_so_far += (uint32_t)cp_len;
6141c4739e2fSRandall Stewart 					freed_so_far += MSIZE;
6142b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
6143f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv, control->do_not_ref_stcb ? NULL : stcb,
6144f8829a4aSRandall Stewart 						    SCTP_LOG_SBRESULT, 0);
614580fefe0aSRandall Stewart 					}
6146aab1d593SMichael Tuexen 					atomic_subtract_int(&control->length, (int)cp_len);
6147f8829a4aSRandall Stewart 				} else {
6148f8829a4aSRandall Stewart 					copied_so_far += cp_len;
6149f8829a4aSRandall Stewart 				}
6150f8829a4aSRandall Stewart 			}
6151d61a0ae0SRandall Stewart 			if ((out_flags & MSG_EOR) || (uio->uio_resid == 0)) {
6152f8829a4aSRandall Stewart 				break;
6153f8829a4aSRandall Stewart 			}
6154f8829a4aSRandall Stewart 			if (((stcb) && (in_flags & MSG_PEEK) == 0) &&
6155f8829a4aSRandall Stewart 			    (control->do_not_ref_stcb == 0) &&
6156f8829a4aSRandall Stewart 			    (freed_so_far >= rwnd_req)) {
6157f8829a4aSRandall Stewart 				sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
6158f8829a4aSRandall Stewart 			}
6159f8829a4aSRandall Stewart 		}		/* end while(m) */
6160f8829a4aSRandall Stewart 		/*
6161f8829a4aSRandall Stewart 		 * At this point we have looked at it all and we either have
6162f8829a4aSRandall Stewart 		 * a MSG_EOR/or read all the user wants... <OR>
6163f8829a4aSRandall Stewart 		 * control->length == 0.
6164f8829a4aSRandall Stewart 		 */
6165d61a0ae0SRandall Stewart 		if ((out_flags & MSG_EOR) && ((in_flags & MSG_PEEK) == 0)) {
6166f8829a4aSRandall Stewart 			/* we are done with this control */
6167f8829a4aSRandall Stewart 			if (control->length == 0) {
6168f8829a4aSRandall Stewart 				if (control->data) {
6169a5d547adSRandall Stewart #ifdef INVARIANTS
6170f8829a4aSRandall Stewart 					panic("control->data not null at read eor?");
6171f8829a4aSRandall Stewart #else
6172ad81507eSRandall Stewart 					SCTP_PRINTF("Strange, data left in the control buffer .. invarients would panic?\n");
6173f8829a4aSRandall Stewart 					sctp_m_freem(control->data);
6174f8829a4aSRandall Stewart 					control->data = NULL;
6175f8829a4aSRandall Stewart #endif
6176f8829a4aSRandall Stewart 				}
6177f8829a4aSRandall Stewart 		done_with_control:
6178f8829a4aSRandall Stewart 				if (hold_rlock == 0) {
6179f8829a4aSRandall Stewart 					SCTP_INP_READ_LOCK(inp);
6180f8829a4aSRandall Stewart 					hold_rlock = 1;
6181f8829a4aSRandall Stewart 				}
6182f8829a4aSRandall Stewart 				TAILQ_REMOVE(&inp->read_queue, control, next);
6183f8829a4aSRandall Stewart 				/* Add back any hiddend data */
6184f8829a4aSRandall Stewart 				if (control->held_length) {
6185f8829a4aSRandall Stewart 					held_length = 0;
6186f8829a4aSRandall Stewart 					control->held_length = 0;
6187f8829a4aSRandall Stewart 					wakeup_read_socket = 1;
6188f8829a4aSRandall Stewart 				}
618917205eccSRandall Stewart 				if (control->aux_data) {
619017205eccSRandall Stewart 					sctp_m_free(control->aux_data);
619117205eccSRandall Stewart 					control->aux_data = NULL;
619217205eccSRandall Stewart 				}
6193f8829a4aSRandall Stewart 				no_rcv_needed = control->do_not_ref_stcb;
6194f8829a4aSRandall Stewart 				sctp_free_remote_addr(control->whoFrom);
6195f8829a4aSRandall Stewart 				control->data = NULL;
619698d5fd97SMichael Tuexen #ifdef INVARIANTS
619744249214SRandall Stewart 				if (control->on_strm_q) {
619844249214SRandall Stewart 					panic("About to free ctl:%p so:%p and its in %d",
619944249214SRandall Stewart 					    control, so, control->on_strm_q);
620044249214SRandall Stewart 				}
620198d5fd97SMichael Tuexen #endif
6202f8829a4aSRandall Stewart 				sctp_free_a_readq(stcb, control);
6203f8829a4aSRandall Stewart 				control = NULL;
62040696e120SRandall Stewart 				if ((freed_so_far >= rwnd_req) &&
62050696e120SRandall Stewart 				    (no_rcv_needed == 0))
6206f8829a4aSRandall Stewart 					sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
6207f8829a4aSRandall Stewart 
6208f8829a4aSRandall Stewart 			} else {
6209f8829a4aSRandall Stewart 				/*
6210f8829a4aSRandall Stewart 				 * The user did not read all of this
6211f8829a4aSRandall Stewart 				 * message, turn off the returned MSG_EOR
6212f8829a4aSRandall Stewart 				 * since we are leaving more behind on the
6213f8829a4aSRandall Stewart 				 * control to read.
6214f8829a4aSRandall Stewart 				 */
6215a5d547adSRandall Stewart #ifdef INVARIANTS
62160696e120SRandall Stewart 				if (control->end_added &&
62170696e120SRandall Stewart 				    (control->data == NULL) &&
6218f8829a4aSRandall Stewart 				    (control->tail_mbuf == NULL)) {
6219f8829a4aSRandall Stewart 					panic("Gak, control->length is corrupt?");
6220f8829a4aSRandall Stewart 				}
6221f8829a4aSRandall Stewart #endif
6222f8829a4aSRandall Stewart 				no_rcv_needed = control->do_not_ref_stcb;
6223f8829a4aSRandall Stewart 				out_flags &= ~MSG_EOR;
6224f8829a4aSRandall Stewart 			}
6225f8829a4aSRandall Stewart 		}
6226f8829a4aSRandall Stewart 		if (out_flags & MSG_EOR) {
6227f8829a4aSRandall Stewart 			goto release;
6228f8829a4aSRandall Stewart 		}
6229f8829a4aSRandall Stewart 		if ((uio->uio_resid == 0) ||
623004aab884SMichael Tuexen 		    ((in_eeor_mode) &&
623143ecbff2SMichael Tuexen 		    (copied_so_far >= max(so->so_rcv.sb_lowat, 1)))) {
6232f8829a4aSRandall Stewart 			goto release;
6233f8829a4aSRandall Stewart 		}
6234f8829a4aSRandall Stewart 		/*
6235f8829a4aSRandall Stewart 		 * If I hit here the receiver wants more and this message is
6236f8829a4aSRandall Stewart 		 * NOT done (pd-api). So two questions. Can we block? if not
6237f8829a4aSRandall Stewart 		 * we are done. Did the user NOT set MSG_WAITALL?
6238f8829a4aSRandall Stewart 		 */
6239f8829a4aSRandall Stewart 		if (block_allowed == 0) {
6240f8829a4aSRandall Stewart 			goto release;
6241f8829a4aSRandall Stewart 		}
6242f8829a4aSRandall Stewart 		/*
6243f8829a4aSRandall Stewart 		 * We need to wait for more data a few things: - We don't
6244aab1d593SMichael Tuexen 		 * release the I/O lock so we don't get someone else
6245aab1d593SMichael Tuexen 		 * reading. - We must be sure to account for the case where
6246aab1d593SMichael Tuexen 		 * what is added is NOT to our control when we wakeup.
6247f8829a4aSRandall Stewart 		 */
6248f8829a4aSRandall Stewart 
6249f8829a4aSRandall Stewart 		/*
6250f8829a4aSRandall Stewart 		 * Do we need to tell the transport a rwnd update might be
6251f8829a4aSRandall Stewart 		 * needed before we go to sleep?
6252f8829a4aSRandall Stewart 		 */
6253f8829a4aSRandall Stewart 		if (((stcb) && (in_flags & MSG_PEEK) == 0) &&
6254f8829a4aSRandall Stewart 		    ((freed_so_far >= rwnd_req) &&
6255f8829a4aSRandall Stewart 		    (control->do_not_ref_stcb == 0) &&
6256f8829a4aSRandall Stewart 		    (no_rcv_needed == 0))) {
6257f8829a4aSRandall Stewart 			sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
6258f8829a4aSRandall Stewart 		}
6259f8829a4aSRandall Stewart wait_some_more:
626044b7479bSRandall Stewart 		if (so->so_rcv.sb_state & SBS_CANTRCVMORE) {
6261f8829a4aSRandall Stewart 			goto release;
6262f8829a4aSRandall Stewart 		}
62630053ed28SMichael Tuexen 
6264f8829a4aSRandall Stewart 		if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE)
6265f8829a4aSRandall Stewart 			goto release;
6266f8829a4aSRandall Stewart 
6267f8829a4aSRandall Stewart 		if (hold_rlock == 1) {
6268f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
6269f8829a4aSRandall Stewart 			hold_rlock = 0;
6270f8829a4aSRandall Stewart 		}
6271f8829a4aSRandall Stewart 		if (hold_sblock == 0) {
6272f8829a4aSRandall Stewart 			SOCKBUF_LOCK(&so->so_rcv);
6273f8829a4aSRandall Stewart 			hold_sblock = 1;
6274f8829a4aSRandall Stewart 		}
6275851b7298SRandall Stewart 		if ((copied_so_far) && (control->length == 0) &&
6276b5c16493SMichael Tuexen 		    (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_FRAG_INTERLEAVE))) {
6277851b7298SRandall Stewart 			goto release;
6278851b7298SRandall Stewart 		}
62794e88d37aSMichael Tuexen 		if (so->so_rcv.sb_cc <= control->held_length) {
6280f8829a4aSRandall Stewart 			error = sbwait(&so->so_rcv);
6281f8829a4aSRandall Stewart 			if (error) {
6282f8829a4aSRandall Stewart 				goto release;
6283f8829a4aSRandall Stewart 			}
6284f8829a4aSRandall Stewart 			control->held_length = 0;
6285f8829a4aSRandall Stewart 		}
6286f8829a4aSRandall Stewart 		if (hold_sblock) {
6287f8829a4aSRandall Stewart 			SOCKBUF_UNLOCK(&so->so_rcv);
6288f8829a4aSRandall Stewart 			hold_sblock = 0;
6289f8829a4aSRandall Stewart 		}
6290f8829a4aSRandall Stewart 		if (control->length == 0) {
6291f8829a4aSRandall Stewart 			/* still nothing here */
6292f8829a4aSRandall Stewart 			if (control->end_added == 1) {
6293f8829a4aSRandall Stewart 				/* he aborted, or is done i.e.did a shutdown */
6294f8829a4aSRandall Stewart 				out_flags |= MSG_EOR;
62959a6142d8SRandall Stewart 				if (control->pdapi_aborted) {
62966114cd96SRandall Stewart 					if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
6297ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
62989a6142d8SRandall Stewart 
629903b0b021SRandall Stewart 					out_flags |= MSG_TRUNC;
63009a6142d8SRandall Stewart 				} else {
63016114cd96SRandall Stewart 					if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
6302ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
63039a6142d8SRandall Stewart 				}
6304f8829a4aSRandall Stewart 				goto done_with_control;
6305f8829a4aSRandall Stewart 			}
63064e88d37aSMichael Tuexen 			if (so->so_rcv.sb_cc > held_length) {
63074e88d37aSMichael Tuexen 				control->held_length = so->so_rcv.sb_cc;
6308f8829a4aSRandall Stewart 				held_length = 0;
6309f8829a4aSRandall Stewart 			}
6310f8829a4aSRandall Stewart 			goto wait_some_more;
6311f8829a4aSRandall Stewart 		} else if (control->data == NULL) {
631250cec919SRandall Stewart 			/*
631350cec919SRandall Stewart 			 * we must re-sync since data is probably being
631450cec919SRandall Stewart 			 * added
631550cec919SRandall Stewart 			 */
631650cec919SRandall Stewart 			SCTP_INP_READ_LOCK(inp);
631750cec919SRandall Stewart 			if ((control->length > 0) && (control->data == NULL)) {
6318b7b84c0eSMichael Tuexen 				/*
6319b7b84c0eSMichael Tuexen 				 * big trouble.. we have the lock and its
6320b7b84c0eSMichael Tuexen 				 * corrupt?
6321b7b84c0eSMichael Tuexen 				 */
63229c04b296SRandall Stewart #ifdef INVARIANTS
63239d18771fSRandall Stewart 				panic("Impossible data==NULL length !=0");
63249c04b296SRandall Stewart #endif
63259c04b296SRandall Stewart 				out_flags |= MSG_EOR;
63269c04b296SRandall Stewart 				out_flags |= MSG_TRUNC;
63279c04b296SRandall Stewart 				control->length = 0;
63289c04b296SRandall Stewart 				SCTP_INP_READ_UNLOCK(inp);
63299c04b296SRandall Stewart 				goto done_with_control;
6330f8829a4aSRandall Stewart 			}
633150cec919SRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
633250cec919SRandall Stewart 			/* We will fall around to get more data */
633350cec919SRandall Stewart 		}
6334f8829a4aSRandall Stewart 		goto get_more_data;
6335f8829a4aSRandall Stewart 	} else {
633617205eccSRandall Stewart 		/*-
633717205eccSRandall Stewart 		 * Give caller back the mbuf chain,
633817205eccSRandall Stewart 		 * store in uio_resid the length
6339f8829a4aSRandall Stewart 		 */
634017205eccSRandall Stewart 		wakeup_read_socket = 0;
6341f8829a4aSRandall Stewart 		if ((control->end_added == 0) ||
6342f8829a4aSRandall Stewart 		    (TAILQ_NEXT(control, next) == NULL)) {
6343f8829a4aSRandall Stewart 			/* Need to get rlock */
6344f8829a4aSRandall Stewart 			if (hold_rlock == 0) {
6345f8829a4aSRandall Stewart 				SCTP_INP_READ_LOCK(inp);
6346f8829a4aSRandall Stewart 				hold_rlock = 1;
6347f8829a4aSRandall Stewart 			}
6348f8829a4aSRandall Stewart 		}
6349139bc87fSRandall Stewart 		if (control->end_added) {
6350f8829a4aSRandall Stewart 			out_flags |= MSG_EOR;
635160990c0cSMichael Tuexen 			if ((control->do_not_ref_stcb == 0) &&
635260990c0cSMichael Tuexen 			    (control->stcb != NULL) &&
635360990c0cSMichael Tuexen 			    ((control->spec_flags & M_NOTIFICATION) == 0))
6354ee7f9857SRandall Stewart 				control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
6355f8829a4aSRandall Stewart 		}
6356139bc87fSRandall Stewart 		if (control->spec_flags & M_NOTIFICATION) {
6357f8829a4aSRandall Stewart 			out_flags |= MSG_NOTIFICATION;
6358f8829a4aSRandall Stewart 		}
635917205eccSRandall Stewart 		uio->uio_resid = control->length;
6360f8829a4aSRandall Stewart 		*mp = control->data;
6361f8829a4aSRandall Stewart 		m = control->data;
6362f8829a4aSRandall Stewart 		while (m) {
6363b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
6364f8829a4aSRandall Stewart 				sctp_sblog(&so->so_rcv,
6365139bc87fSRandall Stewart 				    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
636680fefe0aSRandall Stewart 			}
6367f8829a4aSRandall Stewart 			sctp_sbfree(control, stcb, &so->so_rcv, m);
636858e6eeefSMichael Tuexen 			freed_so_far += (uint32_t)SCTP_BUF_LEN(m);
6369c4739e2fSRandall Stewart 			freed_so_far += MSIZE;
6370b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
6371f8829a4aSRandall Stewart 				sctp_sblog(&so->so_rcv,
6372f8829a4aSRandall Stewart 				    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
637380fefe0aSRandall Stewart 			}
6374139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
6375f8829a4aSRandall Stewart 		}
6376f8829a4aSRandall Stewart 		control->data = control->tail_mbuf = NULL;
6377f8829a4aSRandall Stewart 		control->length = 0;
6378f8829a4aSRandall Stewart 		if (out_flags & MSG_EOR) {
6379f8829a4aSRandall Stewart 			/* Done with this control */
6380f8829a4aSRandall Stewart 			goto done_with_control;
6381f8829a4aSRandall Stewart 		}
6382f8829a4aSRandall Stewart 	}
6383f8829a4aSRandall Stewart release:
6384f8829a4aSRandall Stewart 	if (hold_rlock == 1) {
6385f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
6386f8829a4aSRandall Stewart 		hold_rlock = 0;
6387f8829a4aSRandall Stewart 	}
63887abab911SRobert Watson 	if (hold_sblock == 1) {
63897abab911SRobert Watson 		SOCKBUF_UNLOCK(&so->so_rcv);
63907abab911SRobert Watson 		hold_sblock = 0;
6391f8829a4aSRandall Stewart 	}
63920053ed28SMichael Tuexen 
6393f94acf52SMark Johnston 	SOCK_IO_RECV_UNLOCK(so);
63947abab911SRobert Watson 	sockbuf_lock = 0;
6395f8829a4aSRandall Stewart 
6396f8829a4aSRandall Stewart release_unlocked:
6397f8829a4aSRandall Stewart 	if (hold_sblock) {
6398f8829a4aSRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
6399f8829a4aSRandall Stewart 		hold_sblock = 0;
6400f8829a4aSRandall Stewart 	}
6401f8829a4aSRandall Stewart 	if ((stcb) && (in_flags & MSG_PEEK) == 0) {
6402f8829a4aSRandall Stewart 		if ((freed_so_far >= rwnd_req) &&
6403f8829a4aSRandall Stewart 		    (control && (control->do_not_ref_stcb == 0)) &&
6404f8829a4aSRandall Stewart 		    (no_rcv_needed == 0))
6405f8829a4aSRandall Stewart 			sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
6406f8829a4aSRandall Stewart 	}
6407f8829a4aSRandall Stewart out:
64081b9f62a0SRandall Stewart 	if (msg_flags) {
64091b9f62a0SRandall Stewart 		*msg_flags = out_flags;
64101b9f62a0SRandall Stewart 	}
64119a6142d8SRandall Stewart 	if (((out_flags & MSG_EOR) == 0) &&
64129a6142d8SRandall Stewart 	    ((in_flags & MSG_PEEK) == 0) &&
64139a6142d8SRandall Stewart 	    (sinfo) &&
6414e2e7c62eSMichael Tuexen 	    (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXT_RCVINFO) ||
6415e2e7c62eSMichael Tuexen 	    sctp_is_feature_on(inp, SCTP_PCB_FLAGS_RECVNXTINFO))) {
64169a6142d8SRandall Stewart 		struct sctp_extrcvinfo *s_extra;
64179a6142d8SRandall Stewart 
64189a6142d8SRandall Stewart 		s_extra = (struct sctp_extrcvinfo *)sinfo;
6419b70b526dSMichael Tuexen 		s_extra->serinfo_next_flags = SCTP_NO_NEXT_MSG;
64209a6142d8SRandall Stewart 	}
6421f8829a4aSRandall Stewart 	if (hold_rlock == 1) {
6422f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
6423f8829a4aSRandall Stewart 	}
6424f8829a4aSRandall Stewart 	if (hold_sblock) {
6425f8829a4aSRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
6426f8829a4aSRandall Stewart 	}
64277abab911SRobert Watson 	if (sockbuf_lock) {
6428f94acf52SMark Johnston 		SOCK_IO_RECV_UNLOCK(so);
64297abab911SRobert Watson 	}
64300053ed28SMichael Tuexen 
643150cec919SRandall Stewart 	if (freecnt_applied) {
6432f8829a4aSRandall Stewart 		/*
6433f8829a4aSRandall Stewart 		 * The lock on the socket buffer protects us so the free
6434f8829a4aSRandall Stewart 		 * code will stop. But since we used the socketbuf lock and
6435f8829a4aSRandall Stewart 		 * the sender uses the tcb_lock to increment, we need to use
6436f8829a4aSRandall Stewart 		 * the atomic add to the refcnt.
6437f8829a4aSRandall Stewart 		 */
643850cec919SRandall Stewart 		if (stcb == NULL) {
6439df6e0cc3SRandall Stewart #ifdef INVARIANTS
644050cec919SRandall Stewart 			panic("stcb for refcnt has gone NULL?");
6441df6e0cc3SRandall Stewart 			goto stage_left;
6442df6e0cc3SRandall Stewart #else
6443df6e0cc3SRandall Stewart 			goto stage_left;
6444df6e0cc3SRandall Stewart #endif
644550cec919SRandall Stewart 		}
6446f8829a4aSRandall Stewart 		/* Save the value back for next time */
6447f8829a4aSRandall Stewart 		stcb->freed_by_sorcv_sincelast = freed_so_far;
64483c1ba6f3SMichael Tuexen 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
6449f8829a4aSRandall Stewart 	}
6450b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
6451f8829a4aSRandall Stewart 		if (stcb) {
6452f8829a4aSRandall Stewart 			sctp_misc_ints(SCTP_SORECV_DONE,
6453f8829a4aSRandall Stewart 			    freed_so_far,
64549a8e3088SMichael Tuexen 			    (uint32_t)((uio) ? (slen - uio->uio_resid) : slen),
6455f8829a4aSRandall Stewart 			    stcb->asoc.my_rwnd,
64564e88d37aSMichael Tuexen 			    so->so_rcv.sb_cc);
6457f8829a4aSRandall Stewart 		} else {
6458f8829a4aSRandall Stewart 			sctp_misc_ints(SCTP_SORECV_DONE,
6459f8829a4aSRandall Stewart 			    freed_so_far,
64609a8e3088SMichael Tuexen 			    (uint32_t)((uio) ? (slen - uio->uio_resid) : slen),
6461f8829a4aSRandall Stewart 			    0,
64624e88d37aSMichael Tuexen 			    so->so_rcv.sb_cc);
6463f8829a4aSRandall Stewart 		}
646480fefe0aSRandall Stewart 	}
6465df6e0cc3SRandall Stewart stage_left:
6466f8829a4aSRandall Stewart 	if (wakeup_read_socket) {
6467f8829a4aSRandall Stewart 		sctp_sorwakeup(inp, so);
6468f8829a4aSRandall Stewart 	}
6469f8829a4aSRandall Stewart 	return (error);
6470f8829a4aSRandall Stewart }
6471f8829a4aSRandall Stewart 
6472f8829a4aSRandall Stewart #ifdef SCTP_MBUF_LOGGING
6473f8829a4aSRandall Stewart struct mbuf *
6474f8829a4aSRandall Stewart sctp_m_free(struct mbuf *m)
6475f8829a4aSRandall Stewart {
6476b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_MBUF_LOGGING_ENABLE) {
6477f8829a4aSRandall Stewart 		sctp_log_mb(m, SCTP_MBUF_IFREE);
6478f8829a4aSRandall Stewart 	}
6479f8829a4aSRandall Stewart 	return (m_free(m));
6480f8829a4aSRandall Stewart }
6481f8829a4aSRandall Stewart 
6482f8829a4aSRandall Stewart void
6483f8829a4aSRandall Stewart sctp_m_freem(struct mbuf *mb)
6484f8829a4aSRandall Stewart {
6485f8829a4aSRandall Stewart 	while (mb != NULL)
6486f8829a4aSRandall Stewart 		mb = sctp_m_free(mb);
6487f8829a4aSRandall Stewart }
6488f8829a4aSRandall Stewart 
6489f8829a4aSRandall Stewart #endif
6490f8829a4aSRandall Stewart 
649142551e99SRandall Stewart int
649242551e99SRandall Stewart sctp_dynamic_set_primary(struct sockaddr *sa, uint32_t vrf_id)
649342551e99SRandall Stewart {
649442551e99SRandall Stewart 	/*
649542551e99SRandall Stewart 	 * Given a local address. For all associations that holds the
649642551e99SRandall Stewart 	 * address, request a peer-set-primary.
649742551e99SRandall Stewart 	 */
649842551e99SRandall Stewart 	struct sctp_ifa *ifa;
649942551e99SRandall Stewart 	struct sctp_laddr *wi;
650042551e99SRandall Stewart 
65017f0ad227SMichael Tuexen 	ifa = sctp_find_ifa_by_addr(sa, vrf_id, SCTP_ADDR_NOT_LOCKED);
650242551e99SRandall Stewart 	if (ifa == NULL) {
6503c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EADDRNOTAVAIL);
650442551e99SRandall Stewart 		return (EADDRNOTAVAIL);
650542551e99SRandall Stewart 	}
650642551e99SRandall Stewart 	/*
650742551e99SRandall Stewart 	 * Now that we have the ifa we must awaken the iterator with this
650842551e99SRandall Stewart 	 * message.
650942551e99SRandall Stewart 	 */
6510b3f1ea41SRandall Stewart 	wi = SCTP_ZONE_GET(SCTP_BASE_INFO(ipi_zone_laddr), struct sctp_laddr);
651142551e99SRandall Stewart 	if (wi == NULL) {
6512c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
651342551e99SRandall Stewart 		return (ENOMEM);
651442551e99SRandall Stewart 	}
651542551e99SRandall Stewart 	/* Now incr the count and int wi structure */
651642551e99SRandall Stewart 	SCTP_INCR_LADDR_COUNT();
65175ba7f91fSMichael Tuexen 	memset(wi, 0, sizeof(*wi));
6518d61a0ae0SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&wi->start_time);
651942551e99SRandall Stewart 	wi->ifa = ifa;
652042551e99SRandall Stewart 	wi->action = SCTP_SET_PRIM_ADDR;
652142551e99SRandall Stewart 	atomic_add_int(&ifa->refcount, 1);
652242551e99SRandall Stewart 
652342551e99SRandall Stewart 	/* Now add it to the work queue */
6524f7517433SRandall Stewart 	SCTP_WQ_ADDR_LOCK();
652542551e99SRandall Stewart 	/*
652642551e99SRandall Stewart 	 * Should this really be a tailq? As it is we will process the
652742551e99SRandall Stewart 	 * newest first :-0
652842551e99SRandall Stewart 	 */
6529b3f1ea41SRandall Stewart 	LIST_INSERT_HEAD(&SCTP_BASE_INFO(addr_wq), wi, sctp_nxt_addr);
653042551e99SRandall Stewart 	sctp_timer_start(SCTP_TIMER_TYPE_ADDR_WQ,
653142551e99SRandall Stewart 	    (struct sctp_inpcb *)NULL,
653242551e99SRandall Stewart 	    (struct sctp_tcb *)NULL,
653342551e99SRandall Stewart 	    (struct sctp_nets *)NULL);
65342c62ba73SMichael Tuexen 	SCTP_WQ_ADDR_UNLOCK();
653542551e99SRandall Stewart 	return (0);
653642551e99SRandall Stewart }
653742551e99SRandall Stewart 
6538f8829a4aSRandall Stewart int
653917205eccSRandall Stewart sctp_soreceive(struct socket *so,
654017205eccSRandall Stewart     struct sockaddr **psa,
654117205eccSRandall Stewart     struct uio *uio,
654217205eccSRandall Stewart     struct mbuf **mp0,
654317205eccSRandall Stewart     struct mbuf **controlp,
654417205eccSRandall Stewart     int *flagsp)
6545f8829a4aSRandall Stewart {
6546f8829a4aSRandall Stewart 	int error, fromlen;
6547f8829a4aSRandall Stewart 	uint8_t sockbuf[256];
6548f8829a4aSRandall Stewart 	struct sockaddr *from;
6549f8829a4aSRandall Stewart 	struct sctp_extrcvinfo sinfo;
6550f8829a4aSRandall Stewart 	int filling_sinfo = 1;
655146bf534cSMichael Tuexen 	int flags;
6552f8829a4aSRandall Stewart 	struct sctp_inpcb *inp;
6553f8829a4aSRandall Stewart 
6554f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)so->so_pcb;
6555f8829a4aSRandall Stewart 	/* pickup the assoc we are reading from */
6556f8829a4aSRandall Stewart 	if (inp == NULL) {
6557c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6558f8829a4aSRandall Stewart 		return (EINVAL);
6559f8829a4aSRandall Stewart 	}
6560e2e7c62eSMichael Tuexen 	if ((sctp_is_feature_off(inp, SCTP_PCB_FLAGS_RECVDATAIOEVNT) &&
6561e2e7c62eSMichael Tuexen 	    sctp_is_feature_off(inp, SCTP_PCB_FLAGS_RECVRCVINFO) &&
6562e2e7c62eSMichael Tuexen 	    sctp_is_feature_off(inp, SCTP_PCB_FLAGS_RECVNXTINFO)) ||
6563f8829a4aSRandall Stewart 	    (controlp == NULL)) {
6564f8829a4aSRandall Stewart 		/* user does not want the sndrcv ctl */
6565f8829a4aSRandall Stewart 		filling_sinfo = 0;
6566f8829a4aSRandall Stewart 	}
6567f8829a4aSRandall Stewart 	if (psa) {
6568f8829a4aSRandall Stewart 		from = (struct sockaddr *)sockbuf;
6569f8829a4aSRandall Stewart 		fromlen = sizeof(sockbuf);
6570f8829a4aSRandall Stewart 		from->sa_len = 0;
6571f8829a4aSRandall Stewart 	} else {
6572f8829a4aSRandall Stewart 		from = NULL;
6573f8829a4aSRandall Stewart 		fromlen = 0;
6574f8829a4aSRandall Stewart 	}
6575f8829a4aSRandall Stewart 
6576e432298aSXin LI 	if (filling_sinfo) {
6577e432298aSXin LI 		memset(&sinfo, 0, sizeof(struct sctp_extrcvinfo));
6578e432298aSXin LI 	}
657946bf534cSMichael Tuexen 	if (flagsp != NULL) {
658046bf534cSMichael Tuexen 		flags = *flagsp;
658146bf534cSMichael Tuexen 	} else {
658246bf534cSMichael Tuexen 		flags = 0;
658346bf534cSMichael Tuexen 	}
658446bf534cSMichael Tuexen 	error = sctp_sorecvmsg(so, uio, mp0, from, fromlen, &flags,
6585f8829a4aSRandall Stewart 	    (struct sctp_sndrcvinfo *)&sinfo, filling_sinfo);
658646bf534cSMichael Tuexen 	if (flagsp != NULL) {
658746bf534cSMichael Tuexen 		*flagsp = flags;
658846bf534cSMichael Tuexen 	}
6589e432298aSXin LI 	if (controlp != NULL) {
6590f8829a4aSRandall Stewart 		/* copy back the sinfo in a CMSG format */
659146bf534cSMichael Tuexen 		if (filling_sinfo && ((flags & MSG_NOTIFICATION) == 0)) {
6592f8829a4aSRandall Stewart 			*controlp = sctp_build_ctl_nchunk(inp,
6593f8829a4aSRandall Stewart 			    (struct sctp_sndrcvinfo *)&sinfo);
659446bf534cSMichael Tuexen 		} else {
6595f8829a4aSRandall Stewart 			*controlp = NULL;
6596f8829a4aSRandall Stewart 		}
659746bf534cSMichael Tuexen 	}
6598f8829a4aSRandall Stewart 	if (psa) {
6599f8829a4aSRandall Stewart 		/* copy back the address info */
6600f8829a4aSRandall Stewart 		if (from && from->sa_len) {
6601f8829a4aSRandall Stewart 			*psa = sodupsockaddr(from, M_NOWAIT);
6602f8829a4aSRandall Stewart 		} else {
6603f8829a4aSRandall Stewart 			*psa = NULL;
6604f8829a4aSRandall Stewart 		}
6605f8829a4aSRandall Stewart 	}
6606f8829a4aSRandall Stewart 	return (error);
6607f8829a4aSRandall Stewart }
660817205eccSRandall Stewart 
660917205eccSRandall Stewart int
6610d61a0ae0SRandall Stewart sctp_connectx_helper_add(struct sctp_tcb *stcb, struct sockaddr *addr,
6611d61a0ae0SRandall Stewart     int totaddr, int *error)
661217205eccSRandall Stewart {
661317205eccSRandall Stewart 	int added = 0;
661417205eccSRandall Stewart 	int i;
661517205eccSRandall Stewart 	struct sctp_inpcb *inp;
661617205eccSRandall Stewart 	struct sockaddr *sa;
661717205eccSRandall Stewart 	size_t incr = 0;
661892776dfdSMichael Tuexen #ifdef INET
661992776dfdSMichael Tuexen 	struct sockaddr_in *sin;
662092776dfdSMichael Tuexen #endif
662192776dfdSMichael Tuexen #ifdef INET6
662292776dfdSMichael Tuexen 	struct sockaddr_in6 *sin6;
662392776dfdSMichael Tuexen #endif
662492776dfdSMichael Tuexen 
662517205eccSRandall Stewart 	sa = addr;
662617205eccSRandall Stewart 	inp = stcb->sctp_ep;
662717205eccSRandall Stewart 	*error = 0;
662817205eccSRandall Stewart 	for (i = 0; i < totaddr; i++) {
6629ea5eba11SMichael Tuexen 		switch (sa->sa_family) {
6630ea5eba11SMichael Tuexen #ifdef INET
6631ea5eba11SMichael Tuexen 		case AF_INET:
663217205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in);
663392776dfdSMichael Tuexen 			sin = (struct sockaddr_in *)sa;
663492776dfdSMichael Tuexen 			if ((sin->sin_addr.s_addr == INADDR_ANY) ||
663592776dfdSMichael Tuexen 			    (sin->sin_addr.s_addr == INADDR_BROADCAST) ||
663692776dfdSMichael Tuexen 			    IN_MULTICAST(ntohl(sin->sin_addr.s_addr))) {
663792776dfdSMichael Tuexen 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6638ba785902SMichael Tuexen 				(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
6639ba785902SMichael Tuexen 				    SCTP_FROM_SCTPUTIL + SCTP_LOC_7);
664092776dfdSMichael Tuexen 				*error = EINVAL;
664192776dfdSMichael Tuexen 				goto out_now;
664292776dfdSMichael Tuexen 			}
66437154bf4aSMichael Tuexen 			if (sctp_add_remote_addr(stcb, sa, NULL, stcb->asoc.port,
66447154bf4aSMichael Tuexen 			    SCTP_DONOT_SETSCOPE,
66457154bf4aSMichael Tuexen 			    SCTP_ADDR_IS_CONFIRMED)) {
664617205eccSRandall Stewart 				/* assoc gone no un-lock */
6647c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOBUFS);
6648ba785902SMichael Tuexen 				(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
6649ba785902SMichael Tuexen 				    SCTP_FROM_SCTPUTIL + SCTP_LOC_8);
665017205eccSRandall Stewart 				*error = ENOBUFS;
665117205eccSRandall Stewart 				goto out_now;
665217205eccSRandall Stewart 			}
665317205eccSRandall Stewart 			added++;
6654ea5eba11SMichael Tuexen 			break;
6655ea5eba11SMichael Tuexen #endif
6656ea5eba11SMichael Tuexen #ifdef INET6
6657ea5eba11SMichael Tuexen 		case AF_INET6:
665817205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in6);
665992776dfdSMichael Tuexen 			sin6 = (struct sockaddr_in6 *)sa;
666092776dfdSMichael Tuexen 			if (IN6_IS_ADDR_UNSPECIFIED(&sin6->sin6_addr) ||
666192776dfdSMichael Tuexen 			    IN6_IS_ADDR_MULTICAST(&sin6->sin6_addr)) {
666292776dfdSMichael Tuexen 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6663ba785902SMichael Tuexen 				(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
6664ba785902SMichael Tuexen 				    SCTP_FROM_SCTPUTIL + SCTP_LOC_9);
666592776dfdSMichael Tuexen 				*error = EINVAL;
666692776dfdSMichael Tuexen 				goto out_now;
666792776dfdSMichael Tuexen 			}
66687154bf4aSMichael Tuexen 			if (sctp_add_remote_addr(stcb, sa, NULL, stcb->asoc.port,
66697154bf4aSMichael Tuexen 			    SCTP_DONOT_SETSCOPE,
66707154bf4aSMichael Tuexen 			    SCTP_ADDR_IS_CONFIRMED)) {
667117205eccSRandall Stewart 				/* assoc gone no un-lock */
6672c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOBUFS);
6673ba785902SMichael Tuexen 				(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
6674ba785902SMichael Tuexen 				    SCTP_FROM_SCTPUTIL + SCTP_LOC_10);
667517205eccSRandall Stewart 				*error = ENOBUFS;
667617205eccSRandall Stewart 				goto out_now;
667717205eccSRandall Stewart 			}
667817205eccSRandall Stewart 			added++;
6679ea5eba11SMichael Tuexen 			break;
6680ea5eba11SMichael Tuexen #endif
6681ea5eba11SMichael Tuexen 		default:
6682ea5eba11SMichael Tuexen 			break;
668317205eccSRandall Stewart 		}
668417205eccSRandall Stewart 		sa = (struct sockaddr *)((caddr_t)sa + incr);
668517205eccSRandall Stewart 	}
668617205eccSRandall Stewart out_now:
668717205eccSRandall Stewart 	return (added);
668817205eccSRandall Stewart }
668917205eccSRandall Stewart 
6690fc26bf71SMichael Tuexen int
6691d61a0ae0SRandall Stewart sctp_connectx_helper_find(struct sctp_inpcb *inp, struct sockaddr *addr,
6692fc26bf71SMichael Tuexen     unsigned int totaddr,
6693fc26bf71SMichael Tuexen     unsigned int *num_v4, unsigned int *num_v6,
6694fc26bf71SMichael Tuexen     unsigned int limit)
669517205eccSRandall Stewart {
669617205eccSRandall Stewart 	struct sockaddr *sa;
6697fc26bf71SMichael Tuexen 	struct sctp_tcb *stcb;
66989a8e3088SMichael Tuexen 	unsigned int incr, at, i;
669917205eccSRandall Stewart 
6700e1949767SMichael Tuexen 	at = 0;
670117205eccSRandall Stewart 	sa = addr;
6702fc26bf71SMichael Tuexen 	*num_v6 = *num_v4 = 0;
670317205eccSRandall Stewart 	/* account and validate addresses */
6704fc26bf71SMichael Tuexen 	if (totaddr == 0) {
6705fc26bf71SMichael Tuexen 		return (EINVAL);
6706fc26bf71SMichael Tuexen 	}
6707fc26bf71SMichael Tuexen 	for (i = 0; i < totaddr; i++) {
6708fc26bf71SMichael Tuexen 		if (at + sizeof(struct sockaddr) > limit) {
6709fc26bf71SMichael Tuexen 			return (EINVAL);
6710fc26bf71SMichael Tuexen 		}
6711ea5eba11SMichael Tuexen 		switch (sa->sa_family) {
6712ea5eba11SMichael Tuexen #ifdef INET
6713ea5eba11SMichael Tuexen 		case AF_INET:
6714e1949767SMichael Tuexen 			incr = (unsigned int)sizeof(struct sockaddr_in);
6715d61a0ae0SRandall Stewart 			if (sa->sa_len != incr) {
6716fc26bf71SMichael Tuexen 				return (EINVAL);
6717d61a0ae0SRandall Stewart 			}
67189a8e3088SMichael Tuexen 			(*num_v4) += 1;
6719ea5eba11SMichael Tuexen 			break;
6720ea5eba11SMichael Tuexen #endif
6721ea5eba11SMichael Tuexen #ifdef INET6
6722ea5eba11SMichael Tuexen 		case AF_INET6:
6723ea5eba11SMichael Tuexen 			{
672417205eccSRandall Stewart 				struct sockaddr_in6 *sin6;
672517205eccSRandall Stewart 
6726112899c6SMichael Tuexen 				incr = (unsigned int)sizeof(struct sockaddr_in6);
6727112899c6SMichael Tuexen 				if (sa->sa_len != incr) {
6728112899c6SMichael Tuexen 					return (EINVAL);
6729112899c6SMichael Tuexen 				}
673017205eccSRandall Stewart 				sin6 = (struct sockaddr_in6 *)sa;
673117205eccSRandall Stewart 				if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
673217205eccSRandall Stewart 					/* Must be non-mapped for connectx */
6733fc26bf71SMichael Tuexen 					return (EINVAL);
673417205eccSRandall Stewart 				}
67359a8e3088SMichael Tuexen 				(*num_v6) += 1;
6736ea5eba11SMichael Tuexen 				break;
6737ea5eba11SMichael Tuexen 			}
6738ea5eba11SMichael Tuexen #endif
6739ea5eba11SMichael Tuexen 		default:
6740fc26bf71SMichael Tuexen 			return (EINVAL);
674117205eccSRandall Stewart 		}
6742fc26bf71SMichael Tuexen 		if ((at + incr) > limit) {
6743fc26bf71SMichael Tuexen 			return (EINVAL);
6744ea5eba11SMichael Tuexen 		}
6745d61a0ae0SRandall Stewart 		SCTP_INP_INCR_REF(inp);
674617205eccSRandall Stewart 		stcb = sctp_findassociation_ep_addr(&inp, sa, NULL, NULL, NULL);
674717205eccSRandall Stewart 		if (stcb != NULL) {
6748fc26bf71SMichael Tuexen 			SCTP_TCB_UNLOCK(stcb);
6749fc26bf71SMichael Tuexen 			return (EALREADY);
6750d61a0ae0SRandall Stewart 		} else {
6751d61a0ae0SRandall Stewart 			SCTP_INP_DECR_REF(inp);
675217205eccSRandall Stewart 		}
6753fc26bf71SMichael Tuexen 		at += incr;
675417205eccSRandall Stewart 		sa = (struct sockaddr *)((caddr_t)sa + incr);
675517205eccSRandall Stewart 	}
6756fc26bf71SMichael Tuexen 	return (0);
675717205eccSRandall Stewart }
675835918f85SRandall Stewart 
675935918f85SRandall Stewart /*
676035918f85SRandall Stewart  * sctp_bindx(ADD) for one address.
676135918f85SRandall Stewart  * assumes all arguments are valid/checked by caller.
676235918f85SRandall Stewart  */
676335918f85SRandall Stewart void
676435918f85SRandall Stewart sctp_bindx_add_address(struct socket *so, struct sctp_inpcb *inp,
67657621bd5eSMichael Tuexen     struct sockaddr *sa, uint32_t vrf_id, int *error,
67667621bd5eSMichael Tuexen     void *p)
676735918f85SRandall Stewart {
6768d59107f7SMichael Tuexen #if defined(INET) && defined(INET6)
676935918f85SRandall Stewart 	struct sockaddr_in sin;
67705e2c2d87SRandall Stewart #endif
67717621bd5eSMichael Tuexen #ifdef INET6
67727621bd5eSMichael Tuexen 	struct sockaddr_in6 *sin6;
67737621bd5eSMichael Tuexen #endif
67747621bd5eSMichael Tuexen #ifdef INET
67757621bd5eSMichael Tuexen 	struct sockaddr_in *sinp;
67767621bd5eSMichael Tuexen #endif
67777621bd5eSMichael Tuexen 	struct sockaddr *addr_to_use;
67787621bd5eSMichael Tuexen 	struct sctp_inpcb *lep;
67797621bd5eSMichael Tuexen 	uint16_t port;
67805e2c2d87SRandall Stewart 
678135918f85SRandall Stewart 	/* see if we're bound all already! */
678235918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
6783c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
678435918f85SRandall Stewart 		*error = EINVAL;
678535918f85SRandall Stewart 		return;
678635918f85SRandall Stewart 	}
67877621bd5eSMichael Tuexen 	switch (sa->sa_family) {
6788ea5eba11SMichael Tuexen #ifdef INET6
67897621bd5eSMichael Tuexen 	case AF_INET6:
679035918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in6)) {
6791c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
679235918f85SRandall Stewart 			*error = EINVAL;
679335918f85SRandall Stewart 			return;
679435918f85SRandall Stewart 		}
6795db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) == 0) {
6796db4fd95bSRandall Stewart 			/* can only bind v6 on PF_INET6 sockets */
6797c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6798db4fd95bSRandall Stewart 			*error = EINVAL;
6799db4fd95bSRandall Stewart 			return;
6800db4fd95bSRandall Stewart 		}
68017621bd5eSMichael Tuexen 		sin6 = (struct sockaddr_in6 *)sa;
68027621bd5eSMichael Tuexen 		port = sin6->sin6_port;
6803d59107f7SMichael Tuexen #ifdef INET
680435918f85SRandall Stewart 		if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
6805db4fd95bSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6806db4fd95bSRandall Stewart 			    SCTP_IPV6_V6ONLY(inp)) {
6807db4fd95bSRandall Stewart 				/* can't bind v4-mapped on PF_INET sockets */
6808c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6809db4fd95bSRandall Stewart 				*error = EINVAL;
6810db4fd95bSRandall Stewart 				return;
6811db4fd95bSRandall Stewart 			}
681235918f85SRandall Stewart 			in6_sin6_2_sin(&sin, sin6);
68137621bd5eSMichael Tuexen 			addr_to_use = (struct sockaddr *)&sin;
68147621bd5eSMichael Tuexen 		} else {
68157621bd5eSMichael Tuexen 			addr_to_use = sa;
681635918f85SRandall Stewart 		}
68175087b6e7SMichael Tuexen #else
68185087b6e7SMichael Tuexen 		addr_to_use = sa;
6819d59107f7SMichael Tuexen #endif
68207621bd5eSMichael Tuexen 		break;
682135918f85SRandall Stewart #endif
6822ea5eba11SMichael Tuexen #ifdef INET
68237621bd5eSMichael Tuexen 	case AF_INET:
682435918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in)) {
6825c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
682635918f85SRandall Stewart 			*error = EINVAL;
682735918f85SRandall Stewart 			return;
682835918f85SRandall Stewart 		}
6829db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6830db4fd95bSRandall Stewart 		    SCTP_IPV6_V6ONLY(inp)) {
6831db4fd95bSRandall Stewart 			/* can't bind v4 on PF_INET sockets */
6832c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6833db4fd95bSRandall Stewart 			*error = EINVAL;
6834db4fd95bSRandall Stewart 			return;
6835db4fd95bSRandall Stewart 		}
68367621bd5eSMichael Tuexen 		sinp = (struct sockaddr_in *)sa;
68377621bd5eSMichael Tuexen 		port = sinp->sin_port;
68387621bd5eSMichael Tuexen 		addr_to_use = sa;
68397621bd5eSMichael Tuexen 		break;
6840ea5eba11SMichael Tuexen #endif
68417621bd5eSMichael Tuexen 	default:
68427621bd5eSMichael Tuexen 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
68437621bd5eSMichael Tuexen 		*error = EINVAL;
68447621bd5eSMichael Tuexen 		return;
68457621bd5eSMichael Tuexen 	}
684635918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_UNBOUND) {
684735918f85SRandall Stewart 		if (p == NULL) {
684835918f85SRandall Stewart 			/* Can't get proc for Net/Open BSD */
6849c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
685035918f85SRandall Stewart 			*error = EINVAL;
685135918f85SRandall Stewart 			return;
685235918f85SRandall Stewart 		}
68537621bd5eSMichael Tuexen 		*error = sctp_inpcb_bind(so, addr_to_use, NULL, p);
685435918f85SRandall Stewart 		return;
685535918f85SRandall Stewart 	}
68567621bd5eSMichael Tuexen 	/* Validate the incoming port. */
68577621bd5eSMichael Tuexen 	if ((port != 0) && (port != inp->sctp_lport)) {
6858c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
685997c76f10SRandall Stewart 		*error = EINVAL;
686097c76f10SRandall Stewart 		return;
686197c76f10SRandall Stewart 	}
68627621bd5eSMichael Tuexen 	lep = sctp_pcb_findep(addr_to_use, 1, 0, vrf_id);
68637621bd5eSMichael Tuexen 	if (lep == NULL) {
68647621bd5eSMichael Tuexen 		/* add the address */
68657621bd5eSMichael Tuexen 		*error = sctp_addr_mgmt_ep_sa(inp, addr_to_use,
68667a9dbc33SMichael Tuexen 		    SCTP_ADD_IP_ADDRESS, vrf_id);
686735918f85SRandall Stewart 	} else {
68687621bd5eSMichael Tuexen 		if (lep != inp) {
686935918f85SRandall Stewart 			*error = EADDRINUSE;
687035918f85SRandall Stewart 		}
68717621bd5eSMichael Tuexen 		SCTP_INP_DECR_REF(lep);
687235918f85SRandall Stewart 	}
687335918f85SRandall Stewart }
687435918f85SRandall Stewart 
687535918f85SRandall Stewart /*
687635918f85SRandall Stewart  * sctp_bindx(DELETE) for one address.
687735918f85SRandall Stewart  * assumes all arguments are valid/checked by caller.
687835918f85SRandall Stewart  */
687935918f85SRandall Stewart void
68807215cc1bSMichael Tuexen sctp_bindx_delete_address(struct sctp_inpcb *inp,
68817621bd5eSMichael Tuexen     struct sockaddr *sa, uint32_t vrf_id, int *error)
688235918f85SRandall Stewart {
68837621bd5eSMichael Tuexen 	struct sockaddr *addr_to_use;
6884d59107f7SMichael Tuexen #if defined(INET) && defined(INET6)
68857621bd5eSMichael Tuexen 	struct sockaddr_in6 *sin6;
688635918f85SRandall Stewart 	struct sockaddr_in sin;
68875e2c2d87SRandall Stewart #endif
68885e2c2d87SRandall Stewart 
688935918f85SRandall Stewart 	/* see if we're bound all already! */
689035918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
6891c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
689235918f85SRandall Stewart 		*error = EINVAL;
689335918f85SRandall Stewart 		return;
689435918f85SRandall Stewart 	}
68957621bd5eSMichael Tuexen 	switch (sa->sa_family) {
6896e0e00a4dSMichael Tuexen #ifdef INET6
68977621bd5eSMichael Tuexen 	case AF_INET6:
689835918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in6)) {
6899c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
690035918f85SRandall Stewart 			*error = EINVAL;
690135918f85SRandall Stewart 			return;
690235918f85SRandall Stewart 		}
6903db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) == 0) {
6904db4fd95bSRandall Stewart 			/* can only bind v6 on PF_INET6 sockets */
6905c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6906db4fd95bSRandall Stewart 			*error = EINVAL;
6907db4fd95bSRandall Stewart 			return;
6908db4fd95bSRandall Stewart 		}
6909d59107f7SMichael Tuexen #ifdef INET
69107621bd5eSMichael Tuexen 		sin6 = (struct sockaddr_in6 *)sa;
691135918f85SRandall Stewart 		if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
6912db4fd95bSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6913db4fd95bSRandall Stewart 			    SCTP_IPV6_V6ONLY(inp)) {
6914db4fd95bSRandall Stewart 				/* can't bind mapped-v4 on PF_INET sockets */
6915c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6916db4fd95bSRandall Stewart 				*error = EINVAL;
6917db4fd95bSRandall Stewart 				return;
6918db4fd95bSRandall Stewart 			}
691935918f85SRandall Stewart 			in6_sin6_2_sin(&sin, sin6);
69207621bd5eSMichael Tuexen 			addr_to_use = (struct sockaddr *)&sin;
69217621bd5eSMichael Tuexen 		} else {
69227621bd5eSMichael Tuexen 			addr_to_use = sa;
692335918f85SRandall Stewart 		}
6924171edd21SMichael Tuexen #else
6925171edd21SMichael Tuexen 		addr_to_use = sa;
6926d59107f7SMichael Tuexen #endif
69277621bd5eSMichael Tuexen 		break;
692835918f85SRandall Stewart #endif
6929ea5eba11SMichael Tuexen #ifdef INET
69307621bd5eSMichael Tuexen 	case AF_INET:
693135918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in)) {
6932c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
693335918f85SRandall Stewart 			*error = EINVAL;
693435918f85SRandall Stewart 			return;
693535918f85SRandall Stewart 		}
6936db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6937db4fd95bSRandall Stewart 		    SCTP_IPV6_V6ONLY(inp)) {
6938db4fd95bSRandall Stewart 			/* can't bind v4 on PF_INET sockets */
6939c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6940db4fd95bSRandall Stewart 			*error = EINVAL;
6941db4fd95bSRandall Stewart 			return;
6942db4fd95bSRandall Stewart 		}
69437621bd5eSMichael Tuexen 		addr_to_use = sa;
69447621bd5eSMichael Tuexen 		break;
6945ea5eba11SMichael Tuexen #endif
69467621bd5eSMichael Tuexen 	default:
69477621bd5eSMichael Tuexen 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
69487621bd5eSMichael Tuexen 		*error = EINVAL;
69497621bd5eSMichael Tuexen 		return;
695035918f85SRandall Stewart 	}
69517621bd5eSMichael Tuexen 	/* No lock required mgmt_ep_sa does its own locking. */
69527621bd5eSMichael Tuexen 	*error = sctp_addr_mgmt_ep_sa(inp, addr_to_use, SCTP_DEL_IP_ADDRESS,
69537621bd5eSMichael Tuexen 	    vrf_id);
695435918f85SRandall Stewart }
69551b649582SRandall Stewart 
69561b649582SRandall Stewart /*
69571b649582SRandall Stewart  * returns the valid local address count for an assoc, taking into account
69581b649582SRandall Stewart  * all scoping rules
69591b649582SRandall Stewart  */
69601b649582SRandall Stewart int
69611b649582SRandall Stewart sctp_local_addr_count(struct sctp_tcb *stcb)
69621b649582SRandall Stewart {
6963b54ddf22SMichael Tuexen 	int loopback_scope;
6964b54ddf22SMichael Tuexen #if defined(INET)
6965b54ddf22SMichael Tuexen 	int ipv4_local_scope, ipv4_addr_legal;
6966b54ddf22SMichael Tuexen #endif
6967b54ddf22SMichael Tuexen #if defined(INET6)
6968b54ddf22SMichael Tuexen 	int local_scope, site_scope, ipv6_addr_legal;
6969b54ddf22SMichael Tuexen #endif
69701b649582SRandall Stewart 	struct sctp_vrf *vrf;
69711b649582SRandall Stewart 	struct sctp_ifn *sctp_ifn;
69721b649582SRandall Stewart 	struct sctp_ifa *sctp_ifa;
69731b649582SRandall Stewart 	int count = 0;
69741b649582SRandall Stewart 
69751b649582SRandall Stewart 	/* Turn on all the appropriate scopes */
6976a1cb341bSMichael Tuexen 	loopback_scope = stcb->asoc.scope.loopback_scope;
6977b54ddf22SMichael Tuexen #if defined(INET)
6978a1cb341bSMichael Tuexen 	ipv4_local_scope = stcb->asoc.scope.ipv4_local_scope;
6979b54ddf22SMichael Tuexen 	ipv4_addr_legal = stcb->asoc.scope.ipv4_addr_legal;
6980b54ddf22SMichael Tuexen #endif
6981b54ddf22SMichael Tuexen #if defined(INET6)
6982a1cb341bSMichael Tuexen 	local_scope = stcb->asoc.scope.local_scope;
6983a1cb341bSMichael Tuexen 	site_scope = stcb->asoc.scope.site_scope;
6984a1cb341bSMichael Tuexen 	ipv6_addr_legal = stcb->asoc.scope.ipv6_addr_legal;
6985b54ddf22SMichael Tuexen #endif
6986c99efcf6SRandall Stewart 	SCTP_IPI_ADDR_RLOCK();
69871b649582SRandall Stewart 	vrf = sctp_find_vrf(stcb->asoc.vrf_id);
69881b649582SRandall Stewart 	if (vrf == NULL) {
69891b649582SRandall Stewart 		/* no vrf, no addresses */
6990c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RUNLOCK();
69911b649582SRandall Stewart 		return (0);
69921b649582SRandall Stewart 	}
69930053ed28SMichael Tuexen 
69941b649582SRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
69951b649582SRandall Stewart 		/*
69961b649582SRandall Stewart 		 * bound all case: go through all ifns on the vrf
69971b649582SRandall Stewart 		 */
69981b649582SRandall Stewart 		LIST_FOREACH(sctp_ifn, &vrf->ifnlist, next_ifn) {
69991b649582SRandall Stewart 			if ((loopback_scope == 0) &&
70001b649582SRandall Stewart 			    SCTP_IFN_IS_IFT_LOOP(sctp_ifn)) {
70011b649582SRandall Stewart 				continue;
70021b649582SRandall Stewart 			}
70031b649582SRandall Stewart 			LIST_FOREACH(sctp_ifa, &sctp_ifn->ifalist, next_ifa) {
70041b649582SRandall Stewart 				if (sctp_is_addr_restricted(stcb, sctp_ifa))
70051b649582SRandall Stewart 					continue;
70065e2c2d87SRandall Stewart 				switch (sctp_ifa->address.sa.sa_family) {
7007ea5eba11SMichael Tuexen #ifdef INET
70085e2c2d87SRandall Stewart 				case AF_INET:
70095e2c2d87SRandall Stewart 					if (ipv4_addr_legal) {
70101b649582SRandall Stewart 						struct sockaddr_in *sin;
70111b649582SRandall Stewart 
701224aaac8dSMichael Tuexen 						sin = &sctp_ifa->address.sin;
70131b649582SRandall Stewart 						if (sin->sin_addr.s_addr == 0) {
7014b7b84c0eSMichael Tuexen 							/*
7015b7b84c0eSMichael Tuexen 							 * skip unspecified
7016b7b84c0eSMichael Tuexen 							 * addrs
7017b7b84c0eSMichael Tuexen 							 */
70181b649582SRandall Stewart 							continue;
70191b649582SRandall Stewart 						}
70206ba22f19SMichael Tuexen 						if (prison_check_ip4(stcb->sctp_ep->ip_inp.inp.inp_cred,
70216ba22f19SMichael Tuexen 						    &sin->sin_addr) != 0) {
70226ba22f19SMichael Tuexen 							continue;
70236ba22f19SMichael Tuexen 						}
70241b649582SRandall Stewart 						if ((ipv4_local_scope == 0) &&
70251b649582SRandall Stewart 						    (IN4_ISPRIVATE_ADDRESS(&sin->sin_addr))) {
70261b649582SRandall Stewart 							continue;
70271b649582SRandall Stewart 						}
70281b649582SRandall Stewart 						/* count this one */
70291b649582SRandall Stewart 						count++;
70305e2c2d87SRandall Stewart 					} else {
70315e2c2d87SRandall Stewart 						continue;
70325e2c2d87SRandall Stewart 					}
70335e2c2d87SRandall Stewart 					break;
7034ea5eba11SMichael Tuexen #endif
70355e2c2d87SRandall Stewart #ifdef INET6
70365e2c2d87SRandall Stewart 				case AF_INET6:
70375e2c2d87SRandall Stewart 					if (ipv6_addr_legal) {
70381b649582SRandall Stewart 						struct sockaddr_in6 *sin6;
70391b649582SRandall Stewart 
704024aaac8dSMichael Tuexen 						sin6 = &sctp_ifa->address.sin6;
70411b649582SRandall Stewart 						if (IN6_IS_ADDR_UNSPECIFIED(&sin6->sin6_addr)) {
70421b649582SRandall Stewart 							continue;
70431b649582SRandall Stewart 						}
70446ba22f19SMichael Tuexen 						if (prison_check_ip6(stcb->sctp_ep->ip_inp.inp.inp_cred,
70456ba22f19SMichael Tuexen 						    &sin6->sin6_addr) != 0) {
70466ba22f19SMichael Tuexen 							continue;
70476ba22f19SMichael Tuexen 						}
70481b649582SRandall Stewart 						if (IN6_IS_ADDR_LINKLOCAL(&sin6->sin6_addr)) {
70491b649582SRandall Stewart 							if (local_scope == 0)
70501b649582SRandall Stewart 								continue;
70511b649582SRandall Stewart 							if (sin6->sin6_scope_id == 0) {
70521b649582SRandall Stewart 								if (sa6_recoverscope(sin6) != 0)
70531b649582SRandall Stewart 									/*
70545e2c2d87SRandall Stewart 									 *
70555e2c2d87SRandall Stewart 									 * bad
70565b495f17SMichael Tuexen 									 * link
70575e2c2d87SRandall Stewart 									 *
70585b495f17SMichael Tuexen 									 * local
70595e2c2d87SRandall Stewart 									 *
70605b495f17SMichael Tuexen 									 * address
70615b495f17SMichael Tuexen 									 */
70621b649582SRandall Stewart 									continue;
70631b649582SRandall Stewart 							}
70641b649582SRandall Stewart 						}
70651b649582SRandall Stewart 						if ((site_scope == 0) &&
70661b649582SRandall Stewart 						    (IN6_IS_ADDR_SITELOCAL(&sin6->sin6_addr))) {
70671b649582SRandall Stewart 							continue;
70681b649582SRandall Stewart 						}
70691b649582SRandall Stewart 						/* count this one */
70701b649582SRandall Stewart 						count++;
70711b649582SRandall Stewart 					}
70725e2c2d87SRandall Stewart 					break;
70735e2c2d87SRandall Stewart #endif
70745e2c2d87SRandall Stewart 				default:
70755e2c2d87SRandall Stewart 					/* TSNH */
70765e2c2d87SRandall Stewart 					break;
70775e2c2d87SRandall Stewart 				}
70781b649582SRandall Stewart 			}
70791b649582SRandall Stewart 		}
70801b649582SRandall Stewart 	} else {
70811b649582SRandall Stewart 		/*
70821b649582SRandall Stewart 		 * subset bound case
70831b649582SRandall Stewart 		 */
70841b649582SRandall Stewart 		struct sctp_laddr *laddr;
70851b649582SRandall Stewart 
70861b649582SRandall Stewart 		LIST_FOREACH(laddr, &stcb->sctp_ep->sctp_addr_list,
70871b649582SRandall Stewart 		    sctp_nxt_addr) {
70881b649582SRandall Stewart 			if (sctp_is_addr_restricted(stcb, laddr->ifa)) {
70891b649582SRandall Stewart 				continue;
70901b649582SRandall Stewart 			}
70911b649582SRandall Stewart 			/* count this one */
70921b649582SRandall Stewart 			count++;
70931b649582SRandall Stewart 		}
70941b649582SRandall Stewart 	}
7095c99efcf6SRandall Stewart 	SCTP_IPI_ADDR_RUNLOCK();
70961b649582SRandall Stewart 	return (count);
70971b649582SRandall Stewart }
7098c4739e2fSRandall Stewart 
7099c4739e2fSRandall Stewart #if defined(SCTP_LOCAL_TRACE_BUF)
7100c4739e2fSRandall Stewart 
7101c4739e2fSRandall Stewart void
7102b27a6b7dSRandall Stewart sctp_log_trace(uint32_t subsys, const char *str SCTP_UNUSED, uint32_t a, uint32_t b, uint32_t c, uint32_t d, uint32_t e, uint32_t f)
7103c4739e2fSRandall Stewart {
7104b27a6b7dSRandall Stewart 	uint32_t saveindex, newindex;
7105c4739e2fSRandall Stewart 
7106c4739e2fSRandall Stewart 	do {
7107b3f1ea41SRandall Stewart 		saveindex = SCTP_BASE_SYSCTL(sctp_log).index;
7108c4739e2fSRandall Stewart 		if (saveindex >= SCTP_MAX_LOGGING_SIZE) {
7109c4739e2fSRandall Stewart 			newindex = 1;
7110c4739e2fSRandall Stewart 		} else {
7111c4739e2fSRandall Stewart 			newindex = saveindex + 1;
7112c4739e2fSRandall Stewart 		}
7113b3f1ea41SRandall Stewart 	} while (atomic_cmpset_int(&SCTP_BASE_SYSCTL(sctp_log).index, saveindex, newindex) == 0);
7114c4739e2fSRandall Stewart 	if (saveindex >= SCTP_MAX_LOGGING_SIZE) {
7115c4739e2fSRandall Stewart 		saveindex = 0;
7116c4739e2fSRandall Stewart 	}
7117b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].timestamp = SCTP_GET_CYCLECOUNT;
7118b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].subsys = subsys;
7119b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[0] = a;
7120b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[1] = b;
7121b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[2] = c;
7122b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[3] = d;
7123b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[4] = e;
7124b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[5] = f;
7125c4739e2fSRandall Stewart }
7126c4739e2fSRandall Stewart 
7127c4739e2fSRandall Stewart #endif
7128a99b6783SRandall Stewart static void
71297cca1775SRandall Stewart sctp_recv_udp_tunneled_packet(struct mbuf *m, int off, struct inpcb *inp,
713081d3ec17SBryan Venteicher     const struct sockaddr *sa SCTP_UNUSED, void *ctx SCTP_UNUSED)
7131a99b6783SRandall Stewart {
7132a99b6783SRandall Stewart 	struct ip *iph;
71333a51a264SMichael Tuexen #ifdef INET6
71343a51a264SMichael Tuexen 	struct ip6_hdr *ip6;
71353a51a264SMichael Tuexen #endif
7136a99b6783SRandall Stewart 	struct mbuf *sp, *last;
7137a99b6783SRandall Stewart 	struct udphdr *uhdr;
7138285052f0SMichael Tuexen 	uint16_t port;
7139a99b6783SRandall Stewart 
7140a99b6783SRandall Stewart 	if ((m->m_flags & M_PKTHDR) == 0) {
7141a99b6783SRandall Stewart 		/* Can't handle one that is not a pkt hdr */
7142a99b6783SRandall Stewart 		goto out;
7143a99b6783SRandall Stewart 	}
7144285052f0SMichael Tuexen 	/* Pull the src port */
7145a99b6783SRandall Stewart 	iph = mtod(m, struct ip *);
7146a99b6783SRandall Stewart 	uhdr = (struct udphdr *)((caddr_t)iph + off);
7147a99b6783SRandall Stewart 	port = uhdr->uh_sport;
7148285052f0SMichael Tuexen 	/*
7149285052f0SMichael Tuexen 	 * Split out the mbuf chain. Leave the IP header in m, place the
7150285052f0SMichael Tuexen 	 * rest in the sp.
7151285052f0SMichael Tuexen 	 */
7152eb1b1807SGleb Smirnoff 	sp = m_split(m, off, M_NOWAIT);
7153a99b6783SRandall Stewart 	if (sp == NULL) {
7154a99b6783SRandall Stewart 		/* Gak, drop packet, we can't do a split */
7155a99b6783SRandall Stewart 		goto out;
7156a99b6783SRandall Stewart 	}
7157285052f0SMichael Tuexen 	if (sp->m_pkthdr.len < sizeof(struct udphdr) + sizeof(struct sctphdr)) {
7158285052f0SMichael Tuexen 		/* Gak, packet can't have an SCTP header in it - too small */
7159a99b6783SRandall Stewart 		m_freem(sp);
7160a99b6783SRandall Stewart 		goto out;
7161a99b6783SRandall Stewart 	}
7162285052f0SMichael Tuexen 	/* Now pull up the UDP header and SCTP header together */
7163285052f0SMichael Tuexen 	sp = m_pullup(sp, sizeof(struct udphdr) + sizeof(struct sctphdr));
7164a99b6783SRandall Stewart 	if (sp == NULL) {
7165a99b6783SRandall Stewart 		/* Gak pullup failed */
7166a99b6783SRandall Stewart 		goto out;
7167a99b6783SRandall Stewart 	}
7168285052f0SMichael Tuexen 	/* Trim out the UDP header */
7169a99b6783SRandall Stewart 	m_adj(sp, sizeof(struct udphdr));
7170a99b6783SRandall Stewart 
7171a99b6783SRandall Stewart 	/* Now reconstruct the mbuf chain */
7172285052f0SMichael Tuexen 	for (last = m; last->m_next; last = last->m_next);
7173a99b6783SRandall Stewart 	last->m_next = sp;
7174a99b6783SRandall Stewart 	m->m_pkthdr.len += sp->m_pkthdr.len;
717552f175beSMichael Tuexen 	/*
717652f175beSMichael Tuexen 	 * The CSUM_DATA_VALID flags indicates that the HW checked the UDP
717752f175beSMichael Tuexen 	 * checksum and it was valid. Since CSUM_DATA_VALID ==
717852f175beSMichael Tuexen 	 * CSUM_SCTP_VALID this would imply that the HW also verified the
717952f175beSMichael Tuexen 	 * SCTP checksum. Therefore, clear the bit.
718052f175beSMichael Tuexen 	 */
718152f175beSMichael Tuexen 	SCTPDBG(SCTP_DEBUG_CRCOFFLOAD,
718252f175beSMichael Tuexen 	    "sctp_recv_udp_tunneled_packet(): Packet of length %d received on %s with csum_flags 0x%b.\n",
718352f175beSMichael Tuexen 	    m->m_pkthdr.len,
718452f175beSMichael Tuexen 	    if_name(m->m_pkthdr.rcvif),
718552f175beSMichael Tuexen 	    (int)m->m_pkthdr.csum_flags, CSUM_BITS);
718652f175beSMichael Tuexen 	m->m_pkthdr.csum_flags &= ~CSUM_DATA_VALID;
7187a99b6783SRandall Stewart 	iph = mtod(m, struct ip *);
7188a99b6783SRandall Stewart 	switch (iph->ip_v) {
7189e6194c2eSMichael Tuexen #ifdef INET
7190a99b6783SRandall Stewart 	case IPVERSION:
719109c1c856SMichael Tuexen 		iph->ip_len = htons(ntohs(iph->ip_len) - sizeof(struct udphdr));
7192a99b6783SRandall Stewart 		sctp_input_with_port(m, off, port);
7193a99b6783SRandall Stewart 		break;
7194e6194c2eSMichael Tuexen #endif
7195a99b6783SRandall Stewart #ifdef INET6
7196a99b6783SRandall Stewart 	case IPV6_VERSION >> 4:
71973a51a264SMichael Tuexen 		ip6 = mtod(m, struct ip6_hdr *);
71983a51a264SMichael Tuexen 		ip6->ip6_plen = htons(ntohs(ip6->ip6_plen) - sizeof(struct udphdr));
71993a51a264SMichael Tuexen 		sctp6_input_with_port(&m, &off, port);
7200a99b6783SRandall Stewart 		break;
7201a99b6783SRandall Stewart #endif
7202a99b6783SRandall Stewart 	default:
7203285052f0SMichael Tuexen 		goto out;
7204a99b6783SRandall Stewart 		break;
7205a99b6783SRandall Stewart 	}
7206a99b6783SRandall Stewart 	return;
7207a99b6783SRandall Stewart out:
7208a99b6783SRandall Stewart 	m_freem(m);
7209a99b6783SRandall Stewart }
7210c54a18d2SRandall Stewart 
7211fd7af143SMichael Tuexen #ifdef INET
7212fd7af143SMichael Tuexen static void
7213fd7af143SMichael Tuexen sctp_recv_icmp_tunneled_packet(int cmd, struct sockaddr *sa, void *vip, void *ctx SCTP_UNUSED)
7214fd7af143SMichael Tuexen {
7215fd7af143SMichael Tuexen 	struct ip *outer_ip, *inner_ip;
7216fd7af143SMichael Tuexen 	struct sctphdr *sh;
7217fd7af143SMichael Tuexen 	struct icmp *icmp;
7218fd7af143SMichael Tuexen 	struct udphdr *udp;
7219fd7af143SMichael Tuexen 	struct sctp_inpcb *inp;
7220fd7af143SMichael Tuexen 	struct sctp_tcb *stcb;
7221fd7af143SMichael Tuexen 	struct sctp_nets *net;
7222fd7af143SMichael Tuexen 	struct sctp_init_chunk *ch;
7223fd7af143SMichael Tuexen 	struct sockaddr_in src, dst;
7224fd7af143SMichael Tuexen 	uint8_t type, code;
7225fd7af143SMichael Tuexen 
7226fd7af143SMichael Tuexen 	inner_ip = (struct ip *)vip;
7227fd7af143SMichael Tuexen 	icmp = (struct icmp *)((caddr_t)inner_ip -
7228fd7af143SMichael Tuexen 	    (sizeof(struct icmp) - sizeof(struct ip)));
7229fd7af143SMichael Tuexen 	outer_ip = (struct ip *)((caddr_t)icmp - sizeof(struct ip));
7230fd7af143SMichael Tuexen 	if (ntohs(outer_ip->ip_len) <
7231fd7af143SMichael Tuexen 	    sizeof(struct ip) + 8 + (inner_ip->ip_hl << 2) + sizeof(struct udphdr) + 8) {
7232fd7af143SMichael Tuexen 		return;
7233fd7af143SMichael Tuexen 	}
7234fd7af143SMichael Tuexen 	udp = (struct udphdr *)((caddr_t)inner_ip + (inner_ip->ip_hl << 2));
7235fd7af143SMichael Tuexen 	sh = (struct sctphdr *)(udp + 1);
7236fd7af143SMichael Tuexen 	memset(&src, 0, sizeof(struct sockaddr_in));
7237fd7af143SMichael Tuexen 	src.sin_family = AF_INET;
7238fd7af143SMichael Tuexen 	src.sin_len = sizeof(struct sockaddr_in);
7239fd7af143SMichael Tuexen 	src.sin_port = sh->src_port;
7240fd7af143SMichael Tuexen 	src.sin_addr = inner_ip->ip_src;
7241fd7af143SMichael Tuexen 	memset(&dst, 0, sizeof(struct sockaddr_in));
7242fd7af143SMichael Tuexen 	dst.sin_family = AF_INET;
7243fd7af143SMichael Tuexen 	dst.sin_len = sizeof(struct sockaddr_in);
7244fd7af143SMichael Tuexen 	dst.sin_port = sh->dest_port;
7245fd7af143SMichael Tuexen 	dst.sin_addr = inner_ip->ip_dst;
7246fd7af143SMichael Tuexen 	/*
7247fd7af143SMichael Tuexen 	 * 'dst' holds the dest of the packet that failed to be sent. 'src'
7248fd7af143SMichael Tuexen 	 * holds our local endpoint address. Thus we reverse the dst and the
7249fd7af143SMichael Tuexen 	 * src in the lookup.
7250fd7af143SMichael Tuexen 	 */
7251fd7af143SMichael Tuexen 	inp = NULL;
7252fd7af143SMichael Tuexen 	net = NULL;
7253fd7af143SMichael Tuexen 	stcb = sctp_findassociation_addr_sa((struct sockaddr *)&dst,
7254fd7af143SMichael Tuexen 	    (struct sockaddr *)&src,
7255fd7af143SMichael Tuexen 	    &inp, &net, 1,
7256fd7af143SMichael Tuexen 	    SCTP_DEFAULT_VRFID);
7257fd7af143SMichael Tuexen 	if ((stcb != NULL) &&
7258fd7af143SMichael Tuexen 	    (net != NULL) &&
725955b8cd93SMichael Tuexen 	    (inp != NULL)) {
7260fd7af143SMichael Tuexen 		/* Check the UDP port numbers */
7261fd7af143SMichael Tuexen 		if ((udp->uh_dport != net->port) ||
7262fd7af143SMichael Tuexen 		    (udp->uh_sport != htons(SCTP_BASE_SYSCTL(sctp_udp_tunneling_port)))) {
7263fd7af143SMichael Tuexen 			SCTP_TCB_UNLOCK(stcb);
7264fd7af143SMichael Tuexen 			return;
7265fd7af143SMichael Tuexen 		}
7266fd7af143SMichael Tuexen 		/* Check the verification tag */
7267fd7af143SMichael Tuexen 		if (ntohl(sh->v_tag) != 0) {
7268fd7af143SMichael Tuexen 			/*
7269fd7af143SMichael Tuexen 			 * This must be the verification tag used for
7270fd7af143SMichael Tuexen 			 * sending out packets. We don't consider packets
7271fd7af143SMichael Tuexen 			 * reflecting the verification tag.
7272fd7af143SMichael Tuexen 			 */
7273fd7af143SMichael Tuexen 			if (ntohl(sh->v_tag) != stcb->asoc.peer_vtag) {
7274fd7af143SMichael Tuexen 				SCTP_TCB_UNLOCK(stcb);
7275fd7af143SMichael Tuexen 				return;
7276fd7af143SMichael Tuexen 			}
7277fd7af143SMichael Tuexen 		} else {
7278fd7af143SMichael Tuexen 			if (ntohs(outer_ip->ip_len) >=
7279fd7af143SMichael Tuexen 			    sizeof(struct ip) +
7280fd7af143SMichael Tuexen 			    8 + (inner_ip->ip_hl << 2) + 8 + 20) {
7281fd7af143SMichael Tuexen 				/*
7282fd7af143SMichael Tuexen 				 * In this case we can check if we got an
7283fd7af143SMichael Tuexen 				 * INIT chunk and if the initiate tag
7284fd7af143SMichael Tuexen 				 * matches.
7285fd7af143SMichael Tuexen 				 */
7286fd7af143SMichael Tuexen 				ch = (struct sctp_init_chunk *)(sh + 1);
7287fd7af143SMichael Tuexen 				if ((ch->ch.chunk_type != SCTP_INITIATION) ||
7288fd7af143SMichael Tuexen 				    (ntohl(ch->init.initiate_tag) != stcb->asoc.my_vtag)) {
7289fd7af143SMichael Tuexen 					SCTP_TCB_UNLOCK(stcb);
7290fd7af143SMichael Tuexen 					return;
7291fd7af143SMichael Tuexen 				}
7292fd7af143SMichael Tuexen 			} else {
7293fd7af143SMichael Tuexen 				SCTP_TCB_UNLOCK(stcb);
7294fd7af143SMichael Tuexen 				return;
7295fd7af143SMichael Tuexen 			}
7296fd7af143SMichael Tuexen 		}
7297fd7af143SMichael Tuexen 		type = icmp->icmp_type;
7298fd7af143SMichael Tuexen 		code = icmp->icmp_code;
72993c3f9e2aSMichael Tuexen 		if ((type == ICMP_UNREACH) &&
73003c3f9e2aSMichael Tuexen 		    (code == ICMP_UNREACH_PORT)) {
7301fd7af143SMichael Tuexen 			code = ICMP_UNREACH_PROTOCOL;
7302fd7af143SMichael Tuexen 		}
7303fd7af143SMichael Tuexen 		sctp_notify(inp, stcb, net, type, code,
7304fd7af143SMichael Tuexen 		    ntohs(inner_ip->ip_len),
73056ebfa5eeSMichael Tuexen 		    (uint32_t)ntohs(icmp->icmp_nextmtu));
7306fd7af143SMichael Tuexen 	} else {
7307fd7af143SMichael Tuexen 		if ((stcb == NULL) && (inp != NULL)) {
7308fd7af143SMichael Tuexen 			/* reduce ref-count */
7309fd7af143SMichael Tuexen 			SCTP_INP_WLOCK(inp);
7310fd7af143SMichael Tuexen 			SCTP_INP_DECR_REF(inp);
7311fd7af143SMichael Tuexen 			SCTP_INP_WUNLOCK(inp);
7312fd7af143SMichael Tuexen 		}
7313fd7af143SMichael Tuexen 		if (stcb) {
7314fd7af143SMichael Tuexen 			SCTP_TCB_UNLOCK(stcb);
7315fd7af143SMichael Tuexen 		}
7316fd7af143SMichael Tuexen 	}
7317fd7af143SMichael Tuexen 	return;
7318fd7af143SMichael Tuexen }
7319fd7af143SMichael Tuexen #endif
7320fd7af143SMichael Tuexen 
7321fd7af143SMichael Tuexen #ifdef INET6
7322fd7af143SMichael Tuexen static void
7323fd7af143SMichael Tuexen sctp_recv_icmp6_tunneled_packet(int cmd, struct sockaddr *sa, void *d, void *ctx SCTP_UNUSED)
7324fd7af143SMichael Tuexen {
7325fd7af143SMichael Tuexen 	struct ip6ctlparam *ip6cp;
7326fd7af143SMichael Tuexen 	struct sctp_inpcb *inp;
7327fd7af143SMichael Tuexen 	struct sctp_tcb *stcb;
7328fd7af143SMichael Tuexen 	struct sctp_nets *net;
7329fd7af143SMichael Tuexen 	struct sctphdr sh;
7330fd7af143SMichael Tuexen 	struct udphdr udp;
7331fd7af143SMichael Tuexen 	struct sockaddr_in6 src, dst;
7332fd7af143SMichael Tuexen 	uint8_t type, code;
7333fd7af143SMichael Tuexen 
7334fd7af143SMichael Tuexen 	ip6cp = (struct ip6ctlparam *)d;
7335fd7af143SMichael Tuexen 	/*
7336fd7af143SMichael Tuexen 	 * XXX: We assume that when IPV6 is non NULL, M and OFF are valid.
7337fd7af143SMichael Tuexen 	 */
7338fd7af143SMichael Tuexen 	if (ip6cp->ip6c_m == NULL) {
7339fd7af143SMichael Tuexen 		return;
7340fd7af143SMichael Tuexen 	}
7341fd7af143SMichael Tuexen 	/*
7342fd7af143SMichael Tuexen 	 * Check if we can safely examine the ports and the verification tag
7343fd7af143SMichael Tuexen 	 * of the SCTP common header.
7344fd7af143SMichael Tuexen 	 */
7345fd7af143SMichael Tuexen 	if (ip6cp->ip6c_m->m_pkthdr.len <
7346fd7af143SMichael Tuexen 	    ip6cp->ip6c_off + sizeof(struct udphdr) + offsetof(struct sctphdr, checksum)) {
7347fd7af143SMichael Tuexen 		return;
7348fd7af143SMichael Tuexen 	}
7349fd7af143SMichael Tuexen 	/* Copy out the UDP header. */
7350fd7af143SMichael Tuexen 	memset(&udp, 0, sizeof(struct udphdr));
7351fd7af143SMichael Tuexen 	m_copydata(ip6cp->ip6c_m,
7352fd7af143SMichael Tuexen 	    ip6cp->ip6c_off,
7353fd7af143SMichael Tuexen 	    sizeof(struct udphdr),
7354fd7af143SMichael Tuexen 	    (caddr_t)&udp);
7355fd7af143SMichael Tuexen 	/* Copy out the port numbers and the verification tag. */
7356fd7af143SMichael Tuexen 	memset(&sh, 0, sizeof(struct sctphdr));
7357fd7af143SMichael Tuexen 	m_copydata(ip6cp->ip6c_m,
7358fd7af143SMichael Tuexen 	    ip6cp->ip6c_off + sizeof(struct udphdr),
7359fd7af143SMichael Tuexen 	    sizeof(uint16_t) + sizeof(uint16_t) + sizeof(uint32_t),
7360fd7af143SMichael Tuexen 	    (caddr_t)&sh);
7361fd7af143SMichael Tuexen 	memset(&src, 0, sizeof(struct sockaddr_in6));
7362fd7af143SMichael Tuexen 	src.sin6_family = AF_INET6;
7363fd7af143SMichael Tuexen 	src.sin6_len = sizeof(struct sockaddr_in6);
7364fd7af143SMichael Tuexen 	src.sin6_port = sh.src_port;
7365fd7af143SMichael Tuexen 	src.sin6_addr = ip6cp->ip6c_ip6->ip6_src;
7366fd7af143SMichael Tuexen 	if (in6_setscope(&src.sin6_addr, ip6cp->ip6c_m->m_pkthdr.rcvif, NULL) != 0) {
7367fd7af143SMichael Tuexen 		return;
7368fd7af143SMichael Tuexen 	}
7369fd7af143SMichael Tuexen 	memset(&dst, 0, sizeof(struct sockaddr_in6));
7370fd7af143SMichael Tuexen 	dst.sin6_family = AF_INET6;
7371fd7af143SMichael Tuexen 	dst.sin6_len = sizeof(struct sockaddr_in6);
7372fd7af143SMichael Tuexen 	dst.sin6_port = sh.dest_port;
7373fd7af143SMichael Tuexen 	dst.sin6_addr = ip6cp->ip6c_ip6->ip6_dst;
7374fd7af143SMichael Tuexen 	if (in6_setscope(&dst.sin6_addr, ip6cp->ip6c_m->m_pkthdr.rcvif, NULL) != 0) {
7375fd7af143SMichael Tuexen 		return;
7376fd7af143SMichael Tuexen 	}
7377fd7af143SMichael Tuexen 	inp = NULL;
7378fd7af143SMichael Tuexen 	net = NULL;
7379fd7af143SMichael Tuexen 	stcb = sctp_findassociation_addr_sa((struct sockaddr *)&dst,
7380fd7af143SMichael Tuexen 	    (struct sockaddr *)&src,
7381fd7af143SMichael Tuexen 	    &inp, &net, 1, SCTP_DEFAULT_VRFID);
7382fd7af143SMichael Tuexen 	if ((stcb != NULL) &&
7383fd7af143SMichael Tuexen 	    (net != NULL) &&
738455b8cd93SMichael Tuexen 	    (inp != NULL)) {
7385fd7af143SMichael Tuexen 		/* Check the UDP port numbers */
7386fd7af143SMichael Tuexen 		if ((udp.uh_dport != net->port) ||
7387fd7af143SMichael Tuexen 		    (udp.uh_sport != htons(SCTP_BASE_SYSCTL(sctp_udp_tunneling_port)))) {
7388fd7af143SMichael Tuexen 			SCTP_TCB_UNLOCK(stcb);
7389fd7af143SMichael Tuexen 			return;
7390fd7af143SMichael Tuexen 		}
7391fd7af143SMichael Tuexen 		/* Check the verification tag */
7392fd7af143SMichael Tuexen 		if (ntohl(sh.v_tag) != 0) {
7393fd7af143SMichael Tuexen 			/*
7394fd7af143SMichael Tuexen 			 * This must be the verification tag used for
7395fd7af143SMichael Tuexen 			 * sending out packets. We don't consider packets
7396fd7af143SMichael Tuexen 			 * reflecting the verification tag.
7397fd7af143SMichael Tuexen 			 */
7398fd7af143SMichael Tuexen 			if (ntohl(sh.v_tag) != stcb->asoc.peer_vtag) {
7399fd7af143SMichael Tuexen 				SCTP_TCB_UNLOCK(stcb);
7400fd7af143SMichael Tuexen 				return;
7401fd7af143SMichael Tuexen 			}
7402fd7af143SMichael Tuexen 		} else {
7403fd7af143SMichael Tuexen 			if (ip6cp->ip6c_m->m_pkthdr.len >=
7404fd7af143SMichael Tuexen 			    ip6cp->ip6c_off + sizeof(struct udphdr) +
7405fd7af143SMichael Tuexen 			    sizeof(struct sctphdr) +
7406fd7af143SMichael Tuexen 			    sizeof(struct sctp_chunkhdr) +
7407fd7af143SMichael Tuexen 			    offsetof(struct sctp_init, a_rwnd)) {
7408fd7af143SMichael Tuexen 				/*
7409fd7af143SMichael Tuexen 				 * In this case we can check if we got an
7410fd7af143SMichael Tuexen 				 * INIT chunk and if the initiate tag
7411fd7af143SMichael Tuexen 				 * matches.
7412fd7af143SMichael Tuexen 				 */
7413fd7af143SMichael Tuexen 				uint32_t initiate_tag;
7414fd7af143SMichael Tuexen 				uint8_t chunk_type;
7415fd7af143SMichael Tuexen 
7416fd7af143SMichael Tuexen 				m_copydata(ip6cp->ip6c_m,
7417fd7af143SMichael Tuexen 				    ip6cp->ip6c_off +
7418fd7af143SMichael Tuexen 				    sizeof(struct udphdr) +
7419fd7af143SMichael Tuexen 				    sizeof(struct sctphdr),
7420fd7af143SMichael Tuexen 				    sizeof(uint8_t),
7421fd7af143SMichael Tuexen 				    (caddr_t)&chunk_type);
7422fd7af143SMichael Tuexen 				m_copydata(ip6cp->ip6c_m,
7423fd7af143SMichael Tuexen 				    ip6cp->ip6c_off +
7424fd7af143SMichael Tuexen 				    sizeof(struct udphdr) +
7425fd7af143SMichael Tuexen 				    sizeof(struct sctphdr) +
7426fd7af143SMichael Tuexen 				    sizeof(struct sctp_chunkhdr),
7427fd7af143SMichael Tuexen 				    sizeof(uint32_t),
7428fd7af143SMichael Tuexen 				    (caddr_t)&initiate_tag);
7429fd7af143SMichael Tuexen 				if ((chunk_type != SCTP_INITIATION) ||
7430fd7af143SMichael Tuexen 				    (ntohl(initiate_tag) != stcb->asoc.my_vtag)) {
7431fd7af143SMichael Tuexen 					SCTP_TCB_UNLOCK(stcb);
7432fd7af143SMichael Tuexen 					return;
7433fd7af143SMichael Tuexen 				}
7434fd7af143SMichael Tuexen 			} else {
7435fd7af143SMichael Tuexen 				SCTP_TCB_UNLOCK(stcb);
7436fd7af143SMichael Tuexen 				return;
7437fd7af143SMichael Tuexen 			}
7438fd7af143SMichael Tuexen 		}
7439fd7af143SMichael Tuexen 		type = ip6cp->ip6c_icmp6->icmp6_type;
7440fd7af143SMichael Tuexen 		code = ip6cp->ip6c_icmp6->icmp6_code;
7441fd7af143SMichael Tuexen 		if ((type == ICMP6_DST_UNREACH) &&
7442fd7af143SMichael Tuexen 		    (code == ICMP6_DST_UNREACH_NOPORT)) {
7443fd7af143SMichael Tuexen 			type = ICMP6_PARAM_PROB;
7444fd7af143SMichael Tuexen 			code = ICMP6_PARAMPROB_NEXTHEADER;
7445fd7af143SMichael Tuexen 		}
7446fd7af143SMichael Tuexen 		sctp6_notify(inp, stcb, net, type, code,
74476ebfa5eeSMichael Tuexen 		    ntohl(ip6cp->ip6c_icmp6->icmp6_mtu));
7448fd7af143SMichael Tuexen 	} else {
7449fd7af143SMichael Tuexen 		if ((stcb == NULL) && (inp != NULL)) {
7450fd7af143SMichael Tuexen 			/* reduce inp's ref-count */
7451fd7af143SMichael Tuexen 			SCTP_INP_WLOCK(inp);
7452fd7af143SMichael Tuexen 			SCTP_INP_DECR_REF(inp);
7453fd7af143SMichael Tuexen 			SCTP_INP_WUNLOCK(inp);
7454fd7af143SMichael Tuexen 		}
7455fd7af143SMichael Tuexen 		if (stcb) {
7456fd7af143SMichael Tuexen 			SCTP_TCB_UNLOCK(stcb);
7457fd7af143SMichael Tuexen 		}
7458fd7af143SMichael Tuexen 	}
7459fd7af143SMichael Tuexen }
7460fd7af143SMichael Tuexen #endif
7461fd7af143SMichael Tuexen 
7462c54a18d2SRandall Stewart void
7463c54a18d2SRandall Stewart sctp_over_udp_stop(void)
7464c54a18d2SRandall Stewart {
7465a99b6783SRandall Stewart 	/*
7466a99b6783SRandall Stewart 	 * This function assumes sysctl caller holds sctp_sysctl_info_lock()
7467bb91496aSGordon Bergling 	 * for writing!
7468a99b6783SRandall Stewart 	 */
74693a51a264SMichael Tuexen #ifdef INET
74703a51a264SMichael Tuexen 	if (SCTP_BASE_INFO(udp4_tun_socket) != NULL) {
74713a51a264SMichael Tuexen 		soclose(SCTP_BASE_INFO(udp4_tun_socket));
74723a51a264SMichael Tuexen 		SCTP_BASE_INFO(udp4_tun_socket) = NULL;
7473c54a18d2SRandall Stewart 	}
74743a51a264SMichael Tuexen #endif
74753a51a264SMichael Tuexen #ifdef INET6
74763a51a264SMichael Tuexen 	if (SCTP_BASE_INFO(udp6_tun_socket) != NULL) {
74773a51a264SMichael Tuexen 		soclose(SCTP_BASE_INFO(udp6_tun_socket));
74783a51a264SMichael Tuexen 		SCTP_BASE_INFO(udp6_tun_socket) = NULL;
74793a51a264SMichael Tuexen 	}
74803a51a264SMichael Tuexen #endif
7481a99b6783SRandall Stewart }
7482ea5eba11SMichael Tuexen 
7483c54a18d2SRandall Stewart int
7484c54a18d2SRandall Stewart sctp_over_udp_start(void)
7485c54a18d2SRandall Stewart {
7486a99b6783SRandall Stewart 	uint16_t port;
7487a99b6783SRandall Stewart 	int ret;
74883a51a264SMichael Tuexen #ifdef INET
74893a51a264SMichael Tuexen 	struct sockaddr_in sin;
74903a51a264SMichael Tuexen #endif
74913a51a264SMichael Tuexen #ifdef INET6
74923a51a264SMichael Tuexen 	struct sockaddr_in6 sin6;
74933a51a264SMichael Tuexen #endif
7494a99b6783SRandall Stewart 	/*
7495a99b6783SRandall Stewart 	 * This function assumes sysctl caller holds sctp_sysctl_info_lock()
7496bb91496aSGordon Bergling 	 * for writing!
7497a99b6783SRandall Stewart 	 */
7498a99b6783SRandall Stewart 	port = SCTP_BASE_SYSCTL(sctp_udp_tunneling_port);
74993a51a264SMichael Tuexen 	if (ntohs(port) == 0) {
7500a99b6783SRandall Stewart 		/* Must have a port set */
7501a99b6783SRandall Stewart 		return (EINVAL);
7502a99b6783SRandall Stewart 	}
75033a51a264SMichael Tuexen #ifdef INET
75043a51a264SMichael Tuexen 	if (SCTP_BASE_INFO(udp4_tun_socket) != NULL) {
7505a99b6783SRandall Stewart 		/* Already running -- must stop first */
7506a99b6783SRandall Stewart 		return (EALREADY);
7507a99b6783SRandall Stewart 	}
75083a51a264SMichael Tuexen #endif
75093a51a264SMichael Tuexen #ifdef INET6
75103a51a264SMichael Tuexen 	if (SCTP_BASE_INFO(udp6_tun_socket) != NULL) {
75113a51a264SMichael Tuexen 		/* Already running -- must stop first */
75123a51a264SMichael Tuexen 		return (EALREADY);
7513a99b6783SRandall Stewart 	}
75143a51a264SMichael Tuexen #endif
75153a51a264SMichael Tuexen #ifdef INET
75163a51a264SMichael Tuexen 	if ((ret = socreate(PF_INET, &SCTP_BASE_INFO(udp4_tun_socket),
75173a51a264SMichael Tuexen 	    SOCK_DGRAM, IPPROTO_UDP,
75183a51a264SMichael Tuexen 	    curthread->td_ucred, curthread))) {
7519a99b6783SRandall Stewart 		sctp_over_udp_stop();
7520a99b6783SRandall Stewart 		return (ret);
7521a99b6783SRandall Stewart 	}
75223a51a264SMichael Tuexen 	/* Call the special UDP hook. */
75233a51a264SMichael Tuexen 	if ((ret = udp_set_kernel_tunneling(SCTP_BASE_INFO(udp4_tun_socket),
7524fd7af143SMichael Tuexen 	    sctp_recv_udp_tunneled_packet,
7525fd7af143SMichael Tuexen 	    sctp_recv_icmp_tunneled_packet,
7526fd7af143SMichael Tuexen 	    NULL))) {
75273a51a264SMichael Tuexen 		sctp_over_udp_stop();
75283a51a264SMichael Tuexen 		return (ret);
75293a51a264SMichael Tuexen 	}
75303a51a264SMichael Tuexen 	/* Ok, we have a socket, bind it to the port. */
75313a51a264SMichael Tuexen 	memset(&sin, 0, sizeof(struct sockaddr_in));
75323a51a264SMichael Tuexen 	sin.sin_len = sizeof(struct sockaddr_in);
75333a51a264SMichael Tuexen 	sin.sin_family = AF_INET;
75343a51a264SMichael Tuexen 	sin.sin_port = htons(port);
75353a51a264SMichael Tuexen 	if ((ret = sobind(SCTP_BASE_INFO(udp4_tun_socket),
75363a51a264SMichael Tuexen 	    (struct sockaddr *)&sin, curthread))) {
75373a51a264SMichael Tuexen 		sctp_over_udp_stop();
75383a51a264SMichael Tuexen 		return (ret);
75393a51a264SMichael Tuexen 	}
75403a51a264SMichael Tuexen #endif
75413a51a264SMichael Tuexen #ifdef INET6
75423a51a264SMichael Tuexen 	if ((ret = socreate(PF_INET6, &SCTP_BASE_INFO(udp6_tun_socket),
75433a51a264SMichael Tuexen 	    SOCK_DGRAM, IPPROTO_UDP,
75443a51a264SMichael Tuexen 	    curthread->td_ucred, curthread))) {
75453a51a264SMichael Tuexen 		sctp_over_udp_stop();
75463a51a264SMichael Tuexen 		return (ret);
75473a51a264SMichael Tuexen 	}
75483a51a264SMichael Tuexen 	/* Call the special UDP hook. */
75493a51a264SMichael Tuexen 	if ((ret = udp_set_kernel_tunneling(SCTP_BASE_INFO(udp6_tun_socket),
7550fd7af143SMichael Tuexen 	    sctp_recv_udp_tunneled_packet,
7551fd7af143SMichael Tuexen 	    sctp_recv_icmp6_tunneled_packet,
7552fd7af143SMichael Tuexen 	    NULL))) {
75533a51a264SMichael Tuexen 		sctp_over_udp_stop();
75543a51a264SMichael Tuexen 		return (ret);
75553a51a264SMichael Tuexen 	}
75563a51a264SMichael Tuexen 	/* Ok, we have a socket, bind it to the port. */
75573a51a264SMichael Tuexen 	memset(&sin6, 0, sizeof(struct sockaddr_in6));
75583a51a264SMichael Tuexen 	sin6.sin6_len = sizeof(struct sockaddr_in6);
75593a51a264SMichael Tuexen 	sin6.sin6_family = AF_INET6;
75603a51a264SMichael Tuexen 	sin6.sin6_port = htons(port);
75613a51a264SMichael Tuexen 	if ((ret = sobind(SCTP_BASE_INFO(udp6_tun_socket),
75623a51a264SMichael Tuexen 	    (struct sockaddr *)&sin6, curthread))) {
75633a51a264SMichael Tuexen 		sctp_over_udp_stop();
75643a51a264SMichael Tuexen 		return (ret);
75653a51a264SMichael Tuexen 	}
75663a51a264SMichael Tuexen #endif
7567a99b6783SRandall Stewart 	return (0);
7568c54a18d2SRandall Stewart }
756910e0318aSMichael Tuexen 
757010e0318aSMichael Tuexen /*
757110e0318aSMichael Tuexen  * sctp_min_mtu ()returns the minimum of all non-zero arguments.
757210e0318aSMichael Tuexen  * If all arguments are zero, zero is returned.
757310e0318aSMichael Tuexen  */
757410e0318aSMichael Tuexen uint32_t
7575b0471b4bSMichael Tuexen sctp_min_mtu(uint32_t mtu1, uint32_t mtu2, uint32_t mtu3)
7576b0471b4bSMichael Tuexen {
757710e0318aSMichael Tuexen 	if (mtu1 > 0) {
757810e0318aSMichael Tuexen 		if (mtu2 > 0) {
757910e0318aSMichael Tuexen 			if (mtu3 > 0) {
758010e0318aSMichael Tuexen 				return (min(mtu1, min(mtu2, mtu3)));
758110e0318aSMichael Tuexen 			} else {
758210e0318aSMichael Tuexen 				return (min(mtu1, mtu2));
758310e0318aSMichael Tuexen 			}
758410e0318aSMichael Tuexen 		} else {
758510e0318aSMichael Tuexen 			if (mtu3 > 0) {
758610e0318aSMichael Tuexen 				return (min(mtu1, mtu3));
758710e0318aSMichael Tuexen 			} else {
758810e0318aSMichael Tuexen 				return (mtu1);
758910e0318aSMichael Tuexen 			}
759010e0318aSMichael Tuexen 		}
759110e0318aSMichael Tuexen 	} else {
759210e0318aSMichael Tuexen 		if (mtu2 > 0) {
759310e0318aSMichael Tuexen 			if (mtu3 > 0) {
759410e0318aSMichael Tuexen 				return (min(mtu2, mtu3));
759510e0318aSMichael Tuexen 			} else {
759610e0318aSMichael Tuexen 				return (mtu2);
759710e0318aSMichael Tuexen 			}
759810e0318aSMichael Tuexen 		} else {
759910e0318aSMichael Tuexen 			return (mtu3);
760010e0318aSMichael Tuexen 		}
760110e0318aSMichael Tuexen 	}
760210e0318aSMichael Tuexen }
760310e0318aSMichael Tuexen 
760410e0318aSMichael Tuexen void
760510e0318aSMichael Tuexen sctp_hc_set_mtu(union sctp_sockstore *addr, uint16_t fibnum, uint32_t mtu)
760610e0318aSMichael Tuexen {
760710e0318aSMichael Tuexen 	struct in_conninfo inc;
760810e0318aSMichael Tuexen 
760910e0318aSMichael Tuexen 	memset(&inc, 0, sizeof(struct in_conninfo));
761010e0318aSMichael Tuexen 	inc.inc_fibnum = fibnum;
761110e0318aSMichael Tuexen 	switch (addr->sa.sa_family) {
761210e0318aSMichael Tuexen #ifdef INET
761310e0318aSMichael Tuexen 	case AF_INET:
761410e0318aSMichael Tuexen 		inc.inc_faddr = addr->sin.sin_addr;
761510e0318aSMichael Tuexen 		break;
761610e0318aSMichael Tuexen #endif
761710e0318aSMichael Tuexen #ifdef INET6
761810e0318aSMichael Tuexen 	case AF_INET6:
761910e0318aSMichael Tuexen 		inc.inc_flags |= INC_ISIPV6;
762010e0318aSMichael Tuexen 		inc.inc6_faddr = addr->sin6.sin6_addr;
762110e0318aSMichael Tuexen 		break;
762210e0318aSMichael Tuexen #endif
762310e0318aSMichael Tuexen 	default:
762410e0318aSMichael Tuexen 		return;
762510e0318aSMichael Tuexen 	}
762610e0318aSMichael Tuexen 	tcp_hc_updatemtu(&inc, (u_long)mtu);
762710e0318aSMichael Tuexen }
762810e0318aSMichael Tuexen 
762910e0318aSMichael Tuexen uint32_t
7630b0471b4bSMichael Tuexen sctp_hc_get_mtu(union sctp_sockstore *addr, uint16_t fibnum)
7631b0471b4bSMichael Tuexen {
763210e0318aSMichael Tuexen 	struct in_conninfo inc;
763310e0318aSMichael Tuexen 
763410e0318aSMichael Tuexen 	memset(&inc, 0, sizeof(struct in_conninfo));
763510e0318aSMichael Tuexen 	inc.inc_fibnum = fibnum;
763610e0318aSMichael Tuexen 	switch (addr->sa.sa_family) {
763710e0318aSMichael Tuexen #ifdef INET
763810e0318aSMichael Tuexen 	case AF_INET:
763910e0318aSMichael Tuexen 		inc.inc_faddr = addr->sin.sin_addr;
764010e0318aSMichael Tuexen 		break;
764110e0318aSMichael Tuexen #endif
764210e0318aSMichael Tuexen #ifdef INET6
764310e0318aSMichael Tuexen 	case AF_INET6:
764410e0318aSMichael Tuexen 		inc.inc_flags |= INC_ISIPV6;
764510e0318aSMichael Tuexen 		inc.inc6_faddr = addr->sin6.sin6_addr;
764610e0318aSMichael Tuexen 		break;
764710e0318aSMichael Tuexen #endif
764810e0318aSMichael Tuexen 	default:
764910e0318aSMichael Tuexen 		return (0);
765010e0318aSMichael Tuexen 	}
765110e0318aSMichael Tuexen 	return ((uint32_t)tcp_hc_getmtu(&inc));
765210e0318aSMichael Tuexen }
76536ef849e6SMichael Tuexen 
76541a0b0216SMichael Tuexen void
76551a0b0216SMichael Tuexen sctp_set_state(struct sctp_tcb *stcb, int new_state)
76561a0b0216SMichael Tuexen {
76571e88cc8bSMichael Tuexen #if defined(KDTRACE_HOOKS)
76581e88cc8bSMichael Tuexen 	int old_state = stcb->asoc.state;
76591e88cc8bSMichael Tuexen #endif
76601e88cc8bSMichael Tuexen 
76611a0b0216SMichael Tuexen 	KASSERT((new_state & ~SCTP_STATE_MASK) == 0,
76621a0b0216SMichael Tuexen 	    ("sctp_set_state: Can't set substate (new_state = %x)",
76631a0b0216SMichael Tuexen 	    new_state));
76641a0b0216SMichael Tuexen 	stcb->asoc.state = (stcb->asoc.state & ~SCTP_STATE_MASK) | new_state;
76651a0b0216SMichael Tuexen 	if ((new_state == SCTP_STATE_SHUTDOWN_RECEIVED) ||
76661a0b0216SMichael Tuexen 	    (new_state == SCTP_STATE_SHUTDOWN_SENT) ||
76671a0b0216SMichael Tuexen 	    (new_state == SCTP_STATE_SHUTDOWN_ACK_SENT)) {
76681a0b0216SMichael Tuexen 		SCTP_CLEAR_SUBSTATE(stcb, SCTP_STATE_SHUTDOWN_PENDING);
76691a0b0216SMichael Tuexen 	}
76701e88cc8bSMichael Tuexen #if defined(KDTRACE_HOOKS)
76711e88cc8bSMichael Tuexen 	if (((old_state & SCTP_STATE_MASK) != new_state) &&
76721e88cc8bSMichael Tuexen 	    !(((old_state & SCTP_STATE_MASK) == SCTP_STATE_EMPTY) &&
76731e88cc8bSMichael Tuexen 	    (new_state == SCTP_STATE_INUSE))) {
76741e88cc8bSMichael Tuexen 		SCTP_PROBE6(state__change, NULL, stcb, NULL, stcb, NULL, old_state);
76751e88cc8bSMichael Tuexen 	}
76761e88cc8bSMichael Tuexen #endif
76771a0b0216SMichael Tuexen }
76781a0b0216SMichael Tuexen 
76791a0b0216SMichael Tuexen void
76801a0b0216SMichael Tuexen sctp_add_substate(struct sctp_tcb *stcb, int substate)
76811a0b0216SMichael Tuexen {
76821e88cc8bSMichael Tuexen #if defined(KDTRACE_HOOKS)
76831e88cc8bSMichael Tuexen 	int old_state = stcb->asoc.state;
76841e88cc8bSMichael Tuexen #endif
76851e88cc8bSMichael Tuexen 
76861a0b0216SMichael Tuexen 	KASSERT((substate & SCTP_STATE_MASK) == 0,
76871a0b0216SMichael Tuexen 	    ("sctp_add_substate: Can't set state (substate = %x)",
76881a0b0216SMichael Tuexen 	    substate));
76891a0b0216SMichael Tuexen 	stcb->asoc.state |= substate;
76901e88cc8bSMichael Tuexen #if defined(KDTRACE_HOOKS)
76911e88cc8bSMichael Tuexen 	if (((substate & SCTP_STATE_ABOUT_TO_BE_FREED) &&
76921e88cc8bSMichael Tuexen 	    ((old_state & SCTP_STATE_ABOUT_TO_BE_FREED) == 0)) ||
76931e88cc8bSMichael Tuexen 	    ((substate & SCTP_STATE_SHUTDOWN_PENDING) &&
76941e88cc8bSMichael Tuexen 	    ((old_state & SCTP_STATE_SHUTDOWN_PENDING) == 0))) {
76951e88cc8bSMichael Tuexen 		SCTP_PROBE6(state__change, NULL, stcb, NULL, stcb, NULL, old_state);
76961e88cc8bSMichael Tuexen 	}
76971e88cc8bSMichael Tuexen #endif
76981a0b0216SMichael Tuexen }
7699