xref: /freebsd/sys/netinet/sctputil.c (revision a99b67833a59fc0fa47cb4f0d73b1a0a14b26112)
1f8829a4aSRandall Stewart /*-
2830d754dSRandall Stewart  * Copyright (c) 2001-2008, by Cisco Systems, Inc. All rights reserved.
3f8829a4aSRandall Stewart  *
4f8829a4aSRandall Stewart  * Redistribution and use in source and binary forms, with or without
5f8829a4aSRandall Stewart  * modification, are permitted provided that the following conditions are met:
6f8829a4aSRandall Stewart  *
7f8829a4aSRandall Stewart  * a) Redistributions of source code must retain the above copyright notice,
8f8829a4aSRandall Stewart  *   this list of conditions and the following disclaimer.
9f8829a4aSRandall Stewart  *
10f8829a4aSRandall Stewart  * b) Redistributions in binary form must reproduce the above copyright
11f8829a4aSRandall Stewart  *    notice, this list of conditions and the following disclaimer in
12f8829a4aSRandall Stewart  *   the documentation and/or other materials provided with the distribution.
13f8829a4aSRandall Stewart  *
14f8829a4aSRandall Stewart  * c) Neither the name of Cisco Systems, Inc. nor the names of its
15f8829a4aSRandall Stewart  *    contributors may be used to endorse or promote products derived
16f8829a4aSRandall Stewart  *    from this software without specific prior written permission.
17f8829a4aSRandall Stewart  *
18f8829a4aSRandall Stewart  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
19f8829a4aSRandall Stewart  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
20f8829a4aSRandall Stewart  * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
21f8829a4aSRandall Stewart  * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
22f8829a4aSRandall Stewart  * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
23f8829a4aSRandall Stewart  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
24f8829a4aSRandall Stewart  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
25f8829a4aSRandall Stewart  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
26f8829a4aSRandall Stewart  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
27f8829a4aSRandall Stewart  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
28f8829a4aSRandall Stewart  * THE POSSIBILITY OF SUCH DAMAGE.
29f8829a4aSRandall Stewart  */
30f8829a4aSRandall Stewart 
31f8829a4aSRandall Stewart /* $KAME: sctputil.c,v 1.37 2005/03/07 23:26:09 itojun Exp $	 */
32f8829a4aSRandall Stewart 
33f8829a4aSRandall Stewart #include <sys/cdefs.h>
34f8829a4aSRandall Stewart __FBSDID("$FreeBSD$");
35f8829a4aSRandall Stewart 
36f8829a4aSRandall Stewart #include <netinet/sctp_os.h>
37f8829a4aSRandall Stewart #include <netinet/sctp_pcb.h>
38f8829a4aSRandall Stewart #include <netinet/sctputil.h>
39f8829a4aSRandall Stewart #include <netinet/sctp_var.h>
4042551e99SRandall Stewart #include <netinet/sctp_sysctl.h>
41f8829a4aSRandall Stewart #ifdef INET6
42f8829a4aSRandall Stewart #endif
43f8829a4aSRandall Stewart #include <netinet/sctp_header.h>
44f8829a4aSRandall Stewart #include <netinet/sctp_output.h>
45f8829a4aSRandall Stewart #include <netinet/sctp_uio.h>
46f8829a4aSRandall Stewart #include <netinet/sctp_timer.h>
47f8829a4aSRandall Stewart #include <netinet/sctp_indata.h>/* for sctp_deliver_data() */
48f8829a4aSRandall Stewart #include <netinet/sctp_auth.h>
49f8829a4aSRandall Stewart #include <netinet/sctp_asconf.h>
50b54d3a6cSRandall Stewart #include <netinet/sctp_cc_functions.h>
51f8829a4aSRandall Stewart 
52f8829a4aSRandall Stewart #define NUMBER_OF_MTU_SIZES 18
53f8829a4aSRandall Stewart 
54f8829a4aSRandall Stewart 
55a99b6783SRandall Stewart #if defined(__Windows__) && !defined(SCTP_LOCAL_TRACE_BUF)
56a99b6783SRandall Stewart #include "eventrace_netinet.h"
57a99b6783SRandall Stewart #include "sctputil.tmh"		/* this is the file that will be auto
58a99b6783SRandall Stewart 				 * generated */
59a99b6783SRandall Stewart #else
60b9e7085aSRandall Stewart #ifndef KTR_SCTP
61b9e7085aSRandall Stewart #define KTR_SCTP KTR_SUBSYS
6280fefe0aSRandall Stewart #endif
63a99b6783SRandall Stewart #endif
64f8829a4aSRandall Stewart 
65f8829a4aSRandall Stewart void
66f8829a4aSRandall Stewart sctp_sblog(struct sockbuf *sb,
67f8829a4aSRandall Stewart     struct sctp_tcb *stcb, int from, int incr)
68f8829a4aSRandall Stewart {
6980fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
70f8829a4aSRandall Stewart 
7180fefe0aSRandall Stewart 	sctp_clog.x.sb.stcb = stcb;
7280fefe0aSRandall Stewart 	sctp_clog.x.sb.so_sbcc = sb->sb_cc;
73f8829a4aSRandall Stewart 	if (stcb)
7480fefe0aSRandall Stewart 		sctp_clog.x.sb.stcb_sbcc = stcb->asoc.sb_cc;
75f8829a4aSRandall Stewart 	else
7680fefe0aSRandall Stewart 		sctp_clog.x.sb.stcb_sbcc = 0;
7780fefe0aSRandall Stewart 	sctp_clog.x.sb.incr = incr;
78c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
7980fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_SB,
8080fefe0aSRandall Stewart 	    from,
8180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
8280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
8380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
8480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
85f8829a4aSRandall Stewart }
86f8829a4aSRandall Stewart 
87f8829a4aSRandall Stewart void
88f8829a4aSRandall Stewart sctp_log_closing(struct sctp_inpcb *inp, struct sctp_tcb *stcb, int16_t loc)
89f8829a4aSRandall Stewart {
9080fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
91f8829a4aSRandall Stewart 
9280fefe0aSRandall Stewart 	sctp_clog.x.close.inp = (void *)inp;
9380fefe0aSRandall Stewart 	sctp_clog.x.close.sctp_flags = inp->sctp_flags;
94f8829a4aSRandall Stewart 	if (stcb) {
9580fefe0aSRandall Stewart 		sctp_clog.x.close.stcb = (void *)stcb;
9680fefe0aSRandall Stewart 		sctp_clog.x.close.state = (uint16_t) stcb->asoc.state;
97f8829a4aSRandall Stewart 	} else {
9880fefe0aSRandall Stewart 		sctp_clog.x.close.stcb = 0;
9980fefe0aSRandall Stewart 		sctp_clog.x.close.state = 0;
100f8829a4aSRandall Stewart 	}
10180fefe0aSRandall Stewart 	sctp_clog.x.close.loc = loc;
102c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
10380fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_CLOSE,
10480fefe0aSRandall Stewart 	    0,
10580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
10680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
10780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
10880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
109f8829a4aSRandall Stewart }
110f8829a4aSRandall Stewart 
111f8829a4aSRandall Stewart 
112f8829a4aSRandall Stewart void
113f8829a4aSRandall Stewart rto_logging(struct sctp_nets *net, int from)
114f8829a4aSRandall Stewart {
11580fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
116f8829a4aSRandall Stewart 
117bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
11880fefe0aSRandall Stewart 	sctp_clog.x.rto.net = (void *)net;
11980fefe0aSRandall Stewart 	sctp_clog.x.rto.rtt = net->prev_rtt;
120c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
12180fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RTT,
12280fefe0aSRandall Stewart 	    from,
12380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
12480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
12580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
12680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
12780fefe0aSRandall Stewart 
128f8829a4aSRandall Stewart }
129f8829a4aSRandall Stewart 
130f8829a4aSRandall Stewart void
1316a91f103SRandall Stewart sctp_log_strm_del_alt(struct sctp_tcb *stcb, uint32_t tsn, uint16_t sseq, uint16_t stream, int from)
132f8829a4aSRandall Stewart {
13380fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
134f8829a4aSRandall Stewart 
13580fefe0aSRandall Stewart 	sctp_clog.x.strlog.stcb = stcb;
13680fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_tsn = tsn;
13780fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_sseq = sseq;
13880fefe0aSRandall Stewart 	sctp_clog.x.strlog.e_tsn = 0;
13980fefe0aSRandall Stewart 	sctp_clog.x.strlog.e_sseq = 0;
14080fefe0aSRandall Stewart 	sctp_clog.x.strlog.strm = stream;
141c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
14280fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_STRM,
14380fefe0aSRandall Stewart 	    from,
14480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
14580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
14680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
14780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
14880fefe0aSRandall Stewart 
149f8829a4aSRandall Stewart }
150f8829a4aSRandall Stewart 
151f8829a4aSRandall Stewart void
152f8829a4aSRandall Stewart sctp_log_nagle_event(struct sctp_tcb *stcb, int action)
153f8829a4aSRandall Stewart {
15480fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
155f8829a4aSRandall Stewart 
15680fefe0aSRandall Stewart 	sctp_clog.x.nagle.stcb = (void *)stcb;
15780fefe0aSRandall Stewart 	sctp_clog.x.nagle.total_flight = stcb->asoc.total_flight;
15880fefe0aSRandall Stewart 	sctp_clog.x.nagle.total_in_queue = stcb->asoc.total_output_queue_size;
15980fefe0aSRandall Stewart 	sctp_clog.x.nagle.count_in_queue = stcb->asoc.chunks_on_out_queue;
16080fefe0aSRandall Stewart 	sctp_clog.x.nagle.count_in_flight = stcb->asoc.total_flight_count;
161c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
16280fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_NAGLE,
16380fefe0aSRandall Stewart 	    action,
16480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
16580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
16680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
16780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
168f8829a4aSRandall Stewart }
169f8829a4aSRandall Stewart 
170f8829a4aSRandall Stewart 
171f8829a4aSRandall Stewart void
172f8829a4aSRandall Stewart sctp_log_sack(uint32_t old_cumack, uint32_t cumack, uint32_t tsn, uint16_t gaps, uint16_t dups, int from)
173f8829a4aSRandall Stewart {
17480fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
175f8829a4aSRandall Stewart 
17680fefe0aSRandall Stewart 	sctp_clog.x.sack.cumack = cumack;
17780fefe0aSRandall Stewart 	sctp_clog.x.sack.oldcumack = old_cumack;
17880fefe0aSRandall Stewart 	sctp_clog.x.sack.tsn = tsn;
17980fefe0aSRandall Stewart 	sctp_clog.x.sack.numGaps = gaps;
18080fefe0aSRandall Stewart 	sctp_clog.x.sack.numDups = dups;
181c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
18280fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_SACK,
18380fefe0aSRandall Stewart 	    from,
18480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
18580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
18680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
18780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
188f8829a4aSRandall Stewart }
189f8829a4aSRandall Stewart 
190f8829a4aSRandall Stewart void
191f8829a4aSRandall Stewart sctp_log_map(uint32_t map, uint32_t cum, uint32_t high, int from)
192f8829a4aSRandall Stewart {
19380fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
194f8829a4aSRandall Stewart 
195bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
19680fefe0aSRandall Stewart 	sctp_clog.x.map.base = map;
19780fefe0aSRandall Stewart 	sctp_clog.x.map.cum = cum;
19880fefe0aSRandall Stewart 	sctp_clog.x.map.high = high;
199c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
20080fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MAP,
20180fefe0aSRandall Stewart 	    from,
20280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
20380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
20480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
20580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
206f8829a4aSRandall Stewart }
207f8829a4aSRandall Stewart 
208f8829a4aSRandall Stewart void
209f8829a4aSRandall Stewart sctp_log_fr(uint32_t biggest_tsn, uint32_t biggest_new_tsn, uint32_t tsn,
210f8829a4aSRandall Stewart     int from)
211f8829a4aSRandall Stewart {
21280fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
213f8829a4aSRandall Stewart 
214bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
21580fefe0aSRandall Stewart 	sctp_clog.x.fr.largest_tsn = biggest_tsn;
21680fefe0aSRandall Stewart 	sctp_clog.x.fr.largest_new_tsn = biggest_new_tsn;
21780fefe0aSRandall Stewart 	sctp_clog.x.fr.tsn = tsn;
218c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
21980fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_FR,
22080fefe0aSRandall Stewart 	    from,
22180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
22280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
22380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
22480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
22580fefe0aSRandall Stewart 
226f8829a4aSRandall Stewart }
227f8829a4aSRandall Stewart 
228f8829a4aSRandall Stewart 
229f8829a4aSRandall Stewart void
230f8829a4aSRandall Stewart sctp_log_mb(struct mbuf *m, int from)
231f8829a4aSRandall Stewart {
23280fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
233f8829a4aSRandall Stewart 
23480fefe0aSRandall Stewart 	sctp_clog.x.mb.mp = m;
23580fefe0aSRandall Stewart 	sctp_clog.x.mb.mbuf_flags = (uint8_t) (SCTP_BUF_GET_FLAGS(m));
23680fefe0aSRandall Stewart 	sctp_clog.x.mb.size = (uint16_t) (SCTP_BUF_LEN(m));
23780fefe0aSRandall Stewart 	sctp_clog.x.mb.data = SCTP_BUF_AT(m, 0);
238139bc87fSRandall Stewart 	if (SCTP_BUF_IS_EXTENDED(m)) {
23980fefe0aSRandall Stewart 		sctp_clog.x.mb.ext = SCTP_BUF_EXTEND_BASE(m);
24080fefe0aSRandall Stewart 		sctp_clog.x.mb.refcnt = (uint8_t) (SCTP_BUF_EXTEND_REFCNT(m));
241f8829a4aSRandall Stewart 	} else {
24280fefe0aSRandall Stewart 		sctp_clog.x.mb.ext = 0;
24380fefe0aSRandall Stewart 		sctp_clog.x.mb.refcnt = 0;
244f8829a4aSRandall Stewart 	}
245c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
24680fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MBUF,
24780fefe0aSRandall Stewart 	    from,
24880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
24980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
25080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
25180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
252f8829a4aSRandall Stewart }
253f8829a4aSRandall Stewart 
254f8829a4aSRandall Stewart 
255f8829a4aSRandall Stewart void
256f8829a4aSRandall Stewart sctp_log_strm_del(struct sctp_queued_to_read *control, struct sctp_queued_to_read *poschk,
257f8829a4aSRandall Stewart     int from)
258f8829a4aSRandall Stewart {
25980fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
260f8829a4aSRandall Stewart 
261f8829a4aSRandall Stewart 	if (control == NULL) {
262ad81507eSRandall Stewart 		SCTP_PRINTF("Gak log of NULL?\n");
263f8829a4aSRandall Stewart 		return;
264f8829a4aSRandall Stewart 	}
26580fefe0aSRandall Stewart 	sctp_clog.x.strlog.stcb = control->stcb;
26680fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_tsn = control->sinfo_tsn;
26780fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_sseq = control->sinfo_ssn;
26880fefe0aSRandall Stewart 	sctp_clog.x.strlog.strm = control->sinfo_stream;
269f8829a4aSRandall Stewart 	if (poschk != NULL) {
27080fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_tsn = poschk->sinfo_tsn;
27180fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_sseq = poschk->sinfo_ssn;
272f8829a4aSRandall Stewart 	} else {
27380fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_tsn = 0;
27480fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_sseq = 0;
275f8829a4aSRandall Stewart 	}
276c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
27780fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_STRM,
27880fefe0aSRandall Stewart 	    from,
27980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
28080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
28180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
28280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
28380fefe0aSRandall Stewart 
284f8829a4aSRandall Stewart }
285f8829a4aSRandall Stewart 
286f8829a4aSRandall Stewart void
287f8829a4aSRandall Stewart sctp_log_cwnd(struct sctp_tcb *stcb, struct sctp_nets *net, int augment, uint8_t from)
288f8829a4aSRandall Stewart {
28980fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
290f8829a4aSRandall Stewart 
29180fefe0aSRandall Stewart 	sctp_clog.x.cwnd.net = net;
292f8829a4aSRandall Stewart 	if (stcb->asoc.send_queue_cnt > 255)
29380fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = 255;
294f8829a4aSRandall Stewart 	else
29580fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = stcb->asoc.send_queue_cnt;
296f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt > 255)
29780fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = 255;
298f8829a4aSRandall Stewart 	else
29980fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = stcb->asoc.stream_queue_cnt;
300f8829a4aSRandall Stewart 
301f8829a4aSRandall Stewart 	if (net) {
30280fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cwnd_new_value = net->cwnd;
30380fefe0aSRandall Stewart 		sctp_clog.x.cwnd.inflight = net->flight_size;
30480fefe0aSRandall Stewart 		sctp_clog.x.cwnd.pseudo_cumack = net->pseudo_cumack;
30580fefe0aSRandall Stewart 		sctp_clog.x.cwnd.meets_pseudo_cumack = net->new_pseudo_cumack;
30680fefe0aSRandall Stewart 		sctp_clog.x.cwnd.need_new_pseudo_cumack = net->find_pseudo_cumack;
307f8829a4aSRandall Stewart 	}
308f8829a4aSRandall Stewart 	if (SCTP_CWNDLOG_PRESEND == from) {
30980fefe0aSRandall Stewart 		sctp_clog.x.cwnd.meets_pseudo_cumack = stcb->asoc.peers_rwnd;
310f8829a4aSRandall Stewart 	}
31180fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_augment = augment;
312c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
31380fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_CWND,
31480fefe0aSRandall Stewart 	    from,
31580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
31680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
31780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
31880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
31980fefe0aSRandall Stewart 
320f8829a4aSRandall Stewart }
321f8829a4aSRandall Stewart 
322f8829a4aSRandall Stewart void
323f8829a4aSRandall Stewart sctp_log_lock(struct sctp_inpcb *inp, struct sctp_tcb *stcb, uint8_t from)
324f8829a4aSRandall Stewart {
32580fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
326f8829a4aSRandall Stewart 
327bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
32803b0b021SRandall Stewart 	if (inp) {
32980fefe0aSRandall Stewart 		sctp_clog.x.lock.sock = (void *)inp->sctp_socket;
33003b0b021SRandall Stewart 
33103b0b021SRandall Stewart 	} else {
33280fefe0aSRandall Stewart 		sctp_clog.x.lock.sock = (void *)NULL;
33303b0b021SRandall Stewart 	}
33480fefe0aSRandall Stewart 	sctp_clog.x.lock.inp = (void *)inp;
335f8829a4aSRandall Stewart 	if (stcb) {
33680fefe0aSRandall Stewart 		sctp_clog.x.lock.tcb_lock = mtx_owned(&stcb->tcb_mtx);
337f8829a4aSRandall Stewart 	} else {
33880fefe0aSRandall Stewart 		sctp_clog.x.lock.tcb_lock = SCTP_LOCK_UNKNOWN;
339f8829a4aSRandall Stewart 	}
340f8829a4aSRandall Stewart 	if (inp) {
34180fefe0aSRandall Stewart 		sctp_clog.x.lock.inp_lock = mtx_owned(&inp->inp_mtx);
34280fefe0aSRandall Stewart 		sctp_clog.x.lock.create_lock = mtx_owned(&inp->inp_create_mtx);
343f8829a4aSRandall Stewart 	} else {
34480fefe0aSRandall Stewart 		sctp_clog.x.lock.inp_lock = SCTP_LOCK_UNKNOWN;
34580fefe0aSRandall Stewart 		sctp_clog.x.lock.create_lock = SCTP_LOCK_UNKNOWN;
346f8829a4aSRandall Stewart 	}
347b3f1ea41SRandall Stewart 	sctp_clog.x.lock.info_lock = rw_wowned(&SCTP_BASE_INFO(ipi_ep_mtx));
348f8829a4aSRandall Stewart 	if (inp->sctp_socket) {
34980fefe0aSRandall Stewart 		sctp_clog.x.lock.sock_lock = mtx_owned(&(inp->sctp_socket->so_rcv.sb_mtx));
35080fefe0aSRandall Stewart 		sctp_clog.x.lock.sockrcvbuf_lock = mtx_owned(&(inp->sctp_socket->so_rcv.sb_mtx));
35180fefe0aSRandall Stewart 		sctp_clog.x.lock.socksndbuf_lock = mtx_owned(&(inp->sctp_socket->so_snd.sb_mtx));
352f8829a4aSRandall Stewart 	} else {
35380fefe0aSRandall Stewart 		sctp_clog.x.lock.sock_lock = SCTP_LOCK_UNKNOWN;
35480fefe0aSRandall Stewart 		sctp_clog.x.lock.sockrcvbuf_lock = SCTP_LOCK_UNKNOWN;
35580fefe0aSRandall Stewart 		sctp_clog.x.lock.socksndbuf_lock = SCTP_LOCK_UNKNOWN;
356f8829a4aSRandall Stewart 	}
357c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
35880fefe0aSRandall Stewart 	    SCTP_LOG_LOCK_EVENT,
35980fefe0aSRandall Stewart 	    from,
36080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
36180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
36280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
36380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
36480fefe0aSRandall Stewart 
365f8829a4aSRandall Stewart }
366f8829a4aSRandall Stewart 
367f8829a4aSRandall Stewart void
368f8829a4aSRandall Stewart sctp_log_maxburst(struct sctp_tcb *stcb, struct sctp_nets *net, int error, int burst, uint8_t from)
369f8829a4aSRandall Stewart {
37080fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
371f8829a4aSRandall Stewart 
372bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
37380fefe0aSRandall Stewart 	sctp_clog.x.cwnd.net = net;
37480fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_new_value = error;
37580fefe0aSRandall Stewart 	sctp_clog.x.cwnd.inflight = net->flight_size;
37680fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_augment = burst;
377f8829a4aSRandall Stewart 	if (stcb->asoc.send_queue_cnt > 255)
37880fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = 255;
379f8829a4aSRandall Stewart 	else
38080fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = stcb->asoc.send_queue_cnt;
381f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt > 255)
38280fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = 255;
383f8829a4aSRandall Stewart 	else
38480fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = stcb->asoc.stream_queue_cnt;
385c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
38680fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MAXBURST,
38780fefe0aSRandall Stewart 	    from,
38880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
38980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
39080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
39180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
39280fefe0aSRandall Stewart 
393f8829a4aSRandall Stewart }
394f8829a4aSRandall Stewart 
395f8829a4aSRandall Stewart void
396f8829a4aSRandall Stewart sctp_log_rwnd(uint8_t from, uint32_t peers_rwnd, uint32_t snd_size, uint32_t overhead)
397f8829a4aSRandall Stewart {
39880fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
399f8829a4aSRandall Stewart 
40080fefe0aSRandall Stewart 	sctp_clog.x.rwnd.rwnd = peers_rwnd;
40180fefe0aSRandall Stewart 	sctp_clog.x.rwnd.send_size = snd_size;
40280fefe0aSRandall Stewart 	sctp_clog.x.rwnd.overhead = overhead;
40380fefe0aSRandall Stewart 	sctp_clog.x.rwnd.new_rwnd = 0;
404c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
40580fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RWND,
40680fefe0aSRandall Stewart 	    from,
40780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
40880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
40980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
41080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
411f8829a4aSRandall Stewart }
412f8829a4aSRandall Stewart 
413f8829a4aSRandall Stewart void
414f8829a4aSRandall Stewart sctp_log_rwnd_set(uint8_t from, uint32_t peers_rwnd, uint32_t flight_size, uint32_t overhead, uint32_t a_rwndval)
415f8829a4aSRandall Stewart {
41680fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
417f8829a4aSRandall Stewart 
41880fefe0aSRandall Stewart 	sctp_clog.x.rwnd.rwnd = peers_rwnd;
41980fefe0aSRandall Stewart 	sctp_clog.x.rwnd.send_size = flight_size;
42080fefe0aSRandall Stewart 	sctp_clog.x.rwnd.overhead = overhead;
42180fefe0aSRandall Stewart 	sctp_clog.x.rwnd.new_rwnd = a_rwndval;
422c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
42380fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RWND,
42480fefe0aSRandall Stewart 	    from,
42580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
42680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
42780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
42880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
429f8829a4aSRandall Stewart }
430f8829a4aSRandall Stewart 
431f8829a4aSRandall Stewart void
432f8829a4aSRandall Stewart sctp_log_mbcnt(uint8_t from, uint32_t total_oq, uint32_t book, uint32_t total_mbcnt_q, uint32_t mbcnt)
433f8829a4aSRandall Stewart {
43480fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
435f8829a4aSRandall Stewart 
43680fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.total_queue_size = total_oq;
43780fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.size_change = book;
43880fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.total_queue_mb_size = total_mbcnt_q;
43980fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.mbcnt_change = mbcnt;
440c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
44180fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MBCNT,
44280fefe0aSRandall Stewart 	    from,
44380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
44480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
44580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
44680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
44780fefe0aSRandall Stewart 
448f8829a4aSRandall Stewart }
449f8829a4aSRandall Stewart 
450f8829a4aSRandall Stewart void
451f8829a4aSRandall Stewart sctp_misc_ints(uint8_t from, uint32_t a, uint32_t b, uint32_t c, uint32_t d)
452f8829a4aSRandall Stewart {
453c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
45480fefe0aSRandall Stewart 	    SCTP_LOG_MISC_EVENT,
45580fefe0aSRandall Stewart 	    from,
45680fefe0aSRandall Stewart 	    a, b, c, d);
457f8829a4aSRandall Stewart }
458f8829a4aSRandall Stewart 
459f8829a4aSRandall Stewart void
460f8829a4aSRandall Stewart sctp_wakeup_log(struct sctp_tcb *stcb, uint32_t cumtsn, uint32_t wake_cnt, int from)
461f8829a4aSRandall Stewart {
46280fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
463f8829a4aSRandall Stewart 
46480fefe0aSRandall Stewart 	sctp_clog.x.wake.stcb = (void *)stcb;
46580fefe0aSRandall Stewart 	sctp_clog.x.wake.wake_cnt = wake_cnt;
46680fefe0aSRandall Stewart 	sctp_clog.x.wake.flight = stcb->asoc.total_flight_count;
46780fefe0aSRandall Stewart 	sctp_clog.x.wake.send_q = stcb->asoc.send_queue_cnt;
46880fefe0aSRandall Stewart 	sctp_clog.x.wake.sent_q = stcb->asoc.sent_queue_cnt;
469f8829a4aSRandall Stewart 
470f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt < 0xff)
47180fefe0aSRandall Stewart 		sctp_clog.x.wake.stream_qcnt = (uint8_t) stcb->asoc.stream_queue_cnt;
472f8829a4aSRandall Stewart 	else
47380fefe0aSRandall Stewart 		sctp_clog.x.wake.stream_qcnt = 0xff;
474f8829a4aSRandall Stewart 
475f8829a4aSRandall Stewart 	if (stcb->asoc.chunks_on_out_queue < 0xff)
47680fefe0aSRandall Stewart 		sctp_clog.x.wake.chunks_on_oque = (uint8_t) stcb->asoc.chunks_on_out_queue;
477f8829a4aSRandall Stewart 	else
47880fefe0aSRandall Stewart 		sctp_clog.x.wake.chunks_on_oque = 0xff;
479f8829a4aSRandall Stewart 
48080fefe0aSRandall Stewart 	sctp_clog.x.wake.sctpflags = 0;
481f8829a4aSRandall Stewart 	/* set in the defered mode stuff */
482f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_DONT_WAKE)
48380fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 1;
484f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_WAKEOUTPUT)
48580fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 2;
486f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_WAKEINPUT)
48780fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 4;
488f8829a4aSRandall Stewart 	/* what about the sb */
489f8829a4aSRandall Stewart 	if (stcb->sctp_socket) {
490f8829a4aSRandall Stewart 		struct socket *so = stcb->sctp_socket;
491f8829a4aSRandall Stewart 
49280fefe0aSRandall Stewart 		sctp_clog.x.wake.sbflags = (uint8_t) ((so->so_snd.sb_flags & 0x00ff));
493f8829a4aSRandall Stewart 	} else {
49480fefe0aSRandall Stewart 		sctp_clog.x.wake.sbflags = 0xff;
495f8829a4aSRandall Stewart 	}
496c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
49780fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_WAKE,
49880fefe0aSRandall Stewart 	    from,
49980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
50080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
50180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
50280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
50380fefe0aSRandall Stewart 
504f8829a4aSRandall Stewart }
505f8829a4aSRandall Stewart 
506f8829a4aSRandall Stewart void
507f8829a4aSRandall Stewart sctp_log_block(uint8_t from, struct socket *so, struct sctp_association *asoc, int sendlen)
508f8829a4aSRandall Stewart {
50980fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
510f8829a4aSRandall Stewart 
51180fefe0aSRandall Stewart 	sctp_clog.x.blk.onsb = asoc->total_output_queue_size;
51280fefe0aSRandall Stewart 	sctp_clog.x.blk.send_sent_qcnt = (uint16_t) (asoc->send_queue_cnt + asoc->sent_queue_cnt);
51380fefe0aSRandall Stewart 	sctp_clog.x.blk.peer_rwnd = asoc->peers_rwnd;
51480fefe0aSRandall Stewart 	sctp_clog.x.blk.stream_qcnt = (uint16_t) asoc->stream_queue_cnt;
51580fefe0aSRandall Stewart 	sctp_clog.x.blk.chunks_on_oque = (uint16_t) asoc->chunks_on_out_queue;
51680fefe0aSRandall Stewart 	sctp_clog.x.blk.flight_size = (uint16_t) (asoc->total_flight / 1024);
51780fefe0aSRandall Stewart 	sctp_clog.x.blk.sndlen = sendlen;
518c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
51980fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_BLOCK,
52080fefe0aSRandall Stewart 	    from,
52180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
52280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
52380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
52480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
52580fefe0aSRandall Stewart 
526f8829a4aSRandall Stewart }
527f8829a4aSRandall Stewart 
528f8829a4aSRandall Stewart int
52942551e99SRandall Stewart sctp_fill_stat_log(void *optval, size_t *optsize)
530f8829a4aSRandall Stewart {
53180fefe0aSRandall Stewart 	/* May need to fix this if ktrdump does not work */
532f8829a4aSRandall Stewart 	return (0);
533f8829a4aSRandall Stewart }
534f8829a4aSRandall Stewart 
535f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
536f8829a4aSRandall Stewart uint8_t sctp_audit_data[SCTP_AUDIT_SIZE][2];
537f8829a4aSRandall Stewart static int sctp_audit_indx = 0;
538f8829a4aSRandall Stewart 
539f8829a4aSRandall Stewart static
540f8829a4aSRandall Stewart void
541f8829a4aSRandall Stewart sctp_print_audit_report(void)
542f8829a4aSRandall Stewart {
543f8829a4aSRandall Stewart 	int i;
544f8829a4aSRandall Stewart 	int cnt;
545f8829a4aSRandall Stewart 
546f8829a4aSRandall Stewart 	cnt = 0;
547f8829a4aSRandall Stewart 	for (i = sctp_audit_indx; i < SCTP_AUDIT_SIZE; i++) {
548f8829a4aSRandall Stewart 		if ((sctp_audit_data[i][0] == 0xe0) &&
549f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
550f8829a4aSRandall Stewart 			cnt = 0;
551ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
552f8829a4aSRandall Stewart 		} else if (sctp_audit_data[i][0] == 0xf0) {
553f8829a4aSRandall Stewart 			cnt = 0;
554ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
555f8829a4aSRandall Stewart 		} else if ((sctp_audit_data[i][0] == 0xc0) &&
556f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
557ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
558f8829a4aSRandall Stewart 			cnt = 0;
559f8829a4aSRandall Stewart 		}
560ad81507eSRandall Stewart 		SCTP_PRINTF("%2.2x%2.2x ", (uint32_t) sctp_audit_data[i][0],
561f8829a4aSRandall Stewart 		    (uint32_t) sctp_audit_data[i][1]);
562f8829a4aSRandall Stewart 		cnt++;
563f8829a4aSRandall Stewart 		if ((cnt % 14) == 0)
564ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
565f8829a4aSRandall Stewart 	}
566f8829a4aSRandall Stewart 	for (i = 0; i < sctp_audit_indx; i++) {
567f8829a4aSRandall Stewart 		if ((sctp_audit_data[i][0] == 0xe0) &&
568f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
569f8829a4aSRandall Stewart 			cnt = 0;
570ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
571f8829a4aSRandall Stewart 		} else if (sctp_audit_data[i][0] == 0xf0) {
572f8829a4aSRandall Stewart 			cnt = 0;
573ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
574f8829a4aSRandall Stewart 		} else if ((sctp_audit_data[i][0] == 0xc0) &&
575f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
576ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
577f8829a4aSRandall Stewart 			cnt = 0;
578f8829a4aSRandall Stewart 		}
579ad81507eSRandall Stewart 		SCTP_PRINTF("%2.2x%2.2x ", (uint32_t) sctp_audit_data[i][0],
580f8829a4aSRandall Stewart 		    (uint32_t) sctp_audit_data[i][1]);
581f8829a4aSRandall Stewart 		cnt++;
582f8829a4aSRandall Stewart 		if ((cnt % 14) == 0)
583ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
584f8829a4aSRandall Stewart 	}
585ad81507eSRandall Stewart 	SCTP_PRINTF("\n");
586f8829a4aSRandall Stewart }
587f8829a4aSRandall Stewart 
588f8829a4aSRandall Stewart void
589f8829a4aSRandall Stewart sctp_auditing(int from, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
590f8829a4aSRandall Stewart     struct sctp_nets *net)
591f8829a4aSRandall Stewart {
592f8829a4aSRandall Stewart 	int resend_cnt, tot_out, rep, tot_book_cnt;
593f8829a4aSRandall Stewart 	struct sctp_nets *lnet;
594f8829a4aSRandall Stewart 	struct sctp_tmit_chunk *chk;
595f8829a4aSRandall Stewart 
596f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = 0xAA;
597f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] = 0x000000ff & from;
598f8829a4aSRandall Stewart 	sctp_audit_indx++;
599f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
600f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
601f8829a4aSRandall Stewart 	}
602f8829a4aSRandall Stewart 	if (inp == NULL) {
603f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
604f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0x01;
605f8829a4aSRandall Stewart 		sctp_audit_indx++;
606f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
607f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
608f8829a4aSRandall Stewart 		}
609f8829a4aSRandall Stewart 		return;
610f8829a4aSRandall Stewart 	}
611f8829a4aSRandall Stewart 	if (stcb == NULL) {
612f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
613f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0x02;
614f8829a4aSRandall Stewart 		sctp_audit_indx++;
615f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
616f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
617f8829a4aSRandall Stewart 		}
618f8829a4aSRandall Stewart 		return;
619f8829a4aSRandall Stewart 	}
620f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = 0xA1;
621f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] =
622f8829a4aSRandall Stewart 	    (0x000000ff & stcb->asoc.sent_queue_retran_cnt);
623f8829a4aSRandall Stewart 	sctp_audit_indx++;
624f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
625f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
626f8829a4aSRandall Stewart 	}
627f8829a4aSRandall Stewart 	rep = 0;
628f8829a4aSRandall Stewart 	tot_book_cnt = 0;
629f8829a4aSRandall Stewart 	resend_cnt = tot_out = 0;
630f8829a4aSRandall Stewart 	TAILQ_FOREACH(chk, &stcb->asoc.sent_queue, sctp_next) {
631f8829a4aSRandall Stewart 		if (chk->sent == SCTP_DATAGRAM_RESEND) {
632f8829a4aSRandall Stewart 			resend_cnt++;
633f8829a4aSRandall Stewart 		} else if (chk->sent < SCTP_DATAGRAM_RESEND) {
634f8829a4aSRandall Stewart 			tot_out += chk->book_size;
635f8829a4aSRandall Stewart 			tot_book_cnt++;
636f8829a4aSRandall Stewart 		}
637f8829a4aSRandall Stewart 	}
638f8829a4aSRandall Stewart 	if (resend_cnt != stcb->asoc.sent_queue_retran_cnt) {
639f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
640f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA1;
641f8829a4aSRandall Stewart 		sctp_audit_indx++;
642f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
643f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
644f8829a4aSRandall Stewart 		}
645ad81507eSRandall Stewart 		SCTP_PRINTF("resend_cnt:%d asoc-tot:%d\n",
646f8829a4aSRandall Stewart 		    resend_cnt, stcb->asoc.sent_queue_retran_cnt);
647f8829a4aSRandall Stewart 		rep = 1;
648f8829a4aSRandall Stewart 		stcb->asoc.sent_queue_retran_cnt = resend_cnt;
649f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xA2;
650f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] =
651f8829a4aSRandall Stewart 		    (0x000000ff & stcb->asoc.sent_queue_retran_cnt);
652f8829a4aSRandall Stewart 		sctp_audit_indx++;
653f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
654f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
655f8829a4aSRandall Stewart 		}
656f8829a4aSRandall Stewart 	}
657f8829a4aSRandall Stewart 	if (tot_out != stcb->asoc.total_flight) {
658f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
659f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA2;
660f8829a4aSRandall Stewart 		sctp_audit_indx++;
661f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
662f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
663f8829a4aSRandall Stewart 		}
664f8829a4aSRandall Stewart 		rep = 1;
665ad81507eSRandall Stewart 		SCTP_PRINTF("tot_flt:%d asoc_tot:%d\n", tot_out,
666f8829a4aSRandall Stewart 		    (int)stcb->asoc.total_flight);
667f8829a4aSRandall Stewart 		stcb->asoc.total_flight = tot_out;
668f8829a4aSRandall Stewart 	}
669f8829a4aSRandall Stewart 	if (tot_book_cnt != stcb->asoc.total_flight_count) {
670f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
671f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA5;
672f8829a4aSRandall Stewart 		sctp_audit_indx++;
673f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
674f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
675f8829a4aSRandall Stewart 		}
676f8829a4aSRandall Stewart 		rep = 1;
677ad81507eSRandall Stewart 		SCTP_PRINTF("tot_flt_book:%d\n", tot_book);
678f8829a4aSRandall Stewart 
679f8829a4aSRandall Stewart 		stcb->asoc.total_flight_count = tot_book_cnt;
680f8829a4aSRandall Stewart 	}
681f8829a4aSRandall Stewart 	tot_out = 0;
682f8829a4aSRandall Stewart 	TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
683f8829a4aSRandall Stewart 		tot_out += lnet->flight_size;
684f8829a4aSRandall Stewart 	}
685f8829a4aSRandall Stewart 	if (tot_out != stcb->asoc.total_flight) {
686f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
687f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA3;
688f8829a4aSRandall Stewart 		sctp_audit_indx++;
689f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
690f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
691f8829a4aSRandall Stewart 		}
692f8829a4aSRandall Stewart 		rep = 1;
693ad81507eSRandall Stewart 		SCTP_PRINTF("real flight:%d net total was %d\n",
694f8829a4aSRandall Stewart 		    stcb->asoc.total_flight, tot_out);
695f8829a4aSRandall Stewart 		/* now corrective action */
696f8829a4aSRandall Stewart 		TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
697f8829a4aSRandall Stewart 
698f8829a4aSRandall Stewart 			tot_out = 0;
699f8829a4aSRandall Stewart 			TAILQ_FOREACH(chk, &stcb->asoc.sent_queue, sctp_next) {
700f8829a4aSRandall Stewart 				if ((chk->whoTo == lnet) &&
701f8829a4aSRandall Stewart 				    (chk->sent < SCTP_DATAGRAM_RESEND)) {
702f8829a4aSRandall Stewart 					tot_out += chk->book_size;
703f8829a4aSRandall Stewart 				}
704f8829a4aSRandall Stewart 			}
705f8829a4aSRandall Stewart 			if (lnet->flight_size != tot_out) {
706ad81507eSRandall Stewart 				SCTP_PRINTF("net:%x flight was %d corrected to %d\n",
707ad81507eSRandall Stewart 				    (uint32_t) lnet, lnet->flight_size,
708ad81507eSRandall Stewart 				    tot_out);
709f8829a4aSRandall Stewart 				lnet->flight_size = tot_out;
710f8829a4aSRandall Stewart 			}
711f8829a4aSRandall Stewart 		}
712f8829a4aSRandall Stewart 	}
713f8829a4aSRandall Stewart 	if (rep) {
714f8829a4aSRandall Stewart 		sctp_print_audit_report();
715f8829a4aSRandall Stewart 	}
716f8829a4aSRandall Stewart }
717f8829a4aSRandall Stewart 
718f8829a4aSRandall Stewart void
719f8829a4aSRandall Stewart sctp_audit_log(uint8_t ev, uint8_t fd)
720f8829a4aSRandall Stewart {
721f8829a4aSRandall Stewart 
722f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = ev;
723f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] = fd;
724f8829a4aSRandall Stewart 	sctp_audit_indx++;
725f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
726f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
727f8829a4aSRandall Stewart 	}
728f8829a4aSRandall Stewart }
729f8829a4aSRandall Stewart 
730f8829a4aSRandall Stewart #endif
731f8829a4aSRandall Stewart 
732f8829a4aSRandall Stewart /*
733f8829a4aSRandall Stewart  * a list of sizes based on typical mtu's, used only if next hop size not
734f8829a4aSRandall Stewart  * returned.
735f8829a4aSRandall Stewart  */
736f8829a4aSRandall Stewart static int sctp_mtu_sizes[] = {
737f8829a4aSRandall Stewart 	68,
738f8829a4aSRandall Stewart 	296,
739f8829a4aSRandall Stewart 	508,
740f8829a4aSRandall Stewart 	512,
741f8829a4aSRandall Stewart 	544,
742f8829a4aSRandall Stewart 	576,
743f8829a4aSRandall Stewart 	1006,
744f8829a4aSRandall Stewart 	1492,
745f8829a4aSRandall Stewart 	1500,
746f8829a4aSRandall Stewart 	1536,
747f8829a4aSRandall Stewart 	2002,
748f8829a4aSRandall Stewart 	2048,
749f8829a4aSRandall Stewart 	4352,
750f8829a4aSRandall Stewart 	4464,
751f8829a4aSRandall Stewart 	8166,
752f8829a4aSRandall Stewart 	17914,
753f8829a4aSRandall Stewart 	32000,
754f8829a4aSRandall Stewart 	65535
755f8829a4aSRandall Stewart };
756f8829a4aSRandall Stewart 
757f8829a4aSRandall Stewart void
758f8829a4aSRandall Stewart sctp_stop_timers_for_shutdown(struct sctp_tcb *stcb)
759f8829a4aSRandall Stewart {
760f8829a4aSRandall Stewart 	struct sctp_association *asoc;
761f8829a4aSRandall Stewart 	struct sctp_nets *net;
762f8829a4aSRandall Stewart 
763f8829a4aSRandall Stewart 	asoc = &stcb->asoc;
764f8829a4aSRandall Stewart 
7656e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&asoc->hb_timer.timer);
7666e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&asoc->dack_timer.timer);
7676e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&asoc->strreset_timer.timer);
7686e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&asoc->asconf_timer.timer);
7696e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&asoc->autoclose_timer.timer);
7706e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&asoc->delayed_event_timer.timer);
771f8829a4aSRandall Stewart 	TAILQ_FOREACH(net, &asoc->nets, sctp_next) {
7726e55db54SRandall Stewart 		(void)SCTP_OS_TIMER_STOP(&net->fr_timer.timer);
7736e55db54SRandall Stewart 		(void)SCTP_OS_TIMER_STOP(&net->pmtu_timer.timer);
774f8829a4aSRandall Stewart 	}
775f8829a4aSRandall Stewart }
776f8829a4aSRandall Stewart 
777f8829a4aSRandall Stewart int
778f8829a4aSRandall Stewart find_next_best_mtu(int totsz)
779f8829a4aSRandall Stewart {
780f8829a4aSRandall Stewart 	int i, perfer;
781f8829a4aSRandall Stewart 
782f8829a4aSRandall Stewart 	/*
783f8829a4aSRandall Stewart 	 * if we are in here we must find the next best fit based on the
784f8829a4aSRandall Stewart 	 * size of the dg that failed to be sent.
785f8829a4aSRandall Stewart 	 */
786f8829a4aSRandall Stewart 	perfer = 0;
787f8829a4aSRandall Stewart 	for (i = 0; i < NUMBER_OF_MTU_SIZES; i++) {
788f8829a4aSRandall Stewart 		if (totsz < sctp_mtu_sizes[i]) {
789f8829a4aSRandall Stewart 			perfer = i - 1;
790f8829a4aSRandall Stewart 			if (perfer < 0)
791f8829a4aSRandall Stewart 				perfer = 0;
792f8829a4aSRandall Stewart 			break;
793f8829a4aSRandall Stewart 		}
794f8829a4aSRandall Stewart 	}
795f8829a4aSRandall Stewart 	return (sctp_mtu_sizes[perfer]);
796f8829a4aSRandall Stewart }
797f8829a4aSRandall Stewart 
798f8829a4aSRandall Stewart void
799f8829a4aSRandall Stewart sctp_fill_random_store(struct sctp_pcb *m)
800f8829a4aSRandall Stewart {
801f8829a4aSRandall Stewart 	/*
802f8829a4aSRandall Stewart 	 * Here we use the MD5/SHA-1 to hash with our good randomNumbers and
803f8829a4aSRandall Stewart 	 * our counter. The result becomes our good random numbers and we
804f8829a4aSRandall Stewart 	 * then setup to give these out. Note that we do no locking to
805f8829a4aSRandall Stewart 	 * protect this. This is ok, since if competing folks call this we
80617205eccSRandall Stewart 	 * will get more gobbled gook in the random store which is what we
807f8829a4aSRandall Stewart 	 * want. There is a danger that two guys will use the same random
808f8829a4aSRandall Stewart 	 * numbers, but thats ok too since that is random as well :->
809f8829a4aSRandall Stewart 	 */
810f8829a4aSRandall Stewart 	m->store_at = 0;
811ad81507eSRandall Stewart 	(void)sctp_hmac(SCTP_HMAC, (uint8_t *) m->random_numbers,
812f8829a4aSRandall Stewart 	    sizeof(m->random_numbers), (uint8_t *) & m->random_counter,
813f8829a4aSRandall Stewart 	    sizeof(m->random_counter), (uint8_t *) m->random_store);
814f8829a4aSRandall Stewart 	m->random_counter++;
815f8829a4aSRandall Stewart }
816f8829a4aSRandall Stewart 
817f8829a4aSRandall Stewart uint32_t
818851b7298SRandall Stewart sctp_select_initial_TSN(struct sctp_pcb *inp)
819f8829a4aSRandall Stewart {
820f8829a4aSRandall Stewart 	/*
821f8829a4aSRandall Stewart 	 * A true implementation should use random selection process to get
822f8829a4aSRandall Stewart 	 * the initial stream sequence number, using RFC1750 as a good
823f8829a4aSRandall Stewart 	 * guideline
824f8829a4aSRandall Stewart 	 */
825139bc87fSRandall Stewart 	uint32_t x, *xp;
826f8829a4aSRandall Stewart 	uint8_t *p;
827851b7298SRandall Stewart 	int store_at, new_store;
828f8829a4aSRandall Stewart 
829851b7298SRandall Stewart 	if (inp->initial_sequence_debug != 0) {
830f8829a4aSRandall Stewart 		uint32_t ret;
831f8829a4aSRandall Stewart 
832851b7298SRandall Stewart 		ret = inp->initial_sequence_debug;
833851b7298SRandall Stewart 		inp->initial_sequence_debug++;
834f8829a4aSRandall Stewart 		return (ret);
835f8829a4aSRandall Stewart 	}
836851b7298SRandall Stewart retry:
837851b7298SRandall Stewart 	store_at = inp->store_at;
838851b7298SRandall Stewart 	new_store = store_at + sizeof(uint32_t);
839851b7298SRandall Stewart 	if (new_store >= (SCTP_SIGNATURE_SIZE - 3)) {
840851b7298SRandall Stewart 		new_store = 0;
841f8829a4aSRandall Stewart 	}
842851b7298SRandall Stewart 	if (!atomic_cmpset_int(&inp->store_at, store_at, new_store)) {
843851b7298SRandall Stewart 		goto retry;
844851b7298SRandall Stewart 	}
845851b7298SRandall Stewart 	if (new_store == 0) {
846851b7298SRandall Stewart 		/* Refill the random store */
847851b7298SRandall Stewart 		sctp_fill_random_store(inp);
848851b7298SRandall Stewart 	}
849851b7298SRandall Stewart 	p = &inp->random_store[store_at];
850139bc87fSRandall Stewart 	xp = (uint32_t *) p;
851f8829a4aSRandall Stewart 	x = *xp;
852f8829a4aSRandall Stewart 	return (x);
853f8829a4aSRandall Stewart }
854f8829a4aSRandall Stewart 
855f8829a4aSRandall Stewart uint32_t
856830d754dSRandall Stewart sctp_select_a_tag(struct sctp_inpcb *inp, uint16_t lport, uint16_t rport, int save_in_twait)
857f8829a4aSRandall Stewart {
858f8829a4aSRandall Stewart 	u_long x, not_done;
859f8829a4aSRandall Stewart 	struct timeval now;
860f8829a4aSRandall Stewart 
8616e55db54SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&now);
862f8829a4aSRandall Stewart 	not_done = 1;
863f8829a4aSRandall Stewart 	while (not_done) {
864851b7298SRandall Stewart 		x = sctp_select_initial_TSN(&inp->sctp_ep);
865f8829a4aSRandall Stewart 		if (x == 0) {
866f8829a4aSRandall Stewart 			/* we never use 0 */
867f8829a4aSRandall Stewart 			continue;
868f8829a4aSRandall Stewart 		}
869830d754dSRandall Stewart 		if (sctp_is_vtag_good(inp, x, lport, rport, &now, save_in_twait)) {
870f8829a4aSRandall Stewart 			not_done = 0;
871f8829a4aSRandall Stewart 		}
872f8829a4aSRandall Stewart 	}
873f8829a4aSRandall Stewart 	return (x);
874f8829a4aSRandall Stewart }
875f8829a4aSRandall Stewart 
876f8829a4aSRandall Stewart int
8770696e120SRandall Stewart sctp_init_asoc(struct sctp_inpcb *m, struct sctp_tcb *stcb,
87842551e99SRandall Stewart     int for_a_init, uint32_t override_tag, uint32_t vrf_id)
879f8829a4aSRandall Stewart {
8800696e120SRandall Stewart 	struct sctp_association *asoc;
8810696e120SRandall Stewart 
882f8829a4aSRandall Stewart 	/*
883f8829a4aSRandall Stewart 	 * Anything set to zero is taken care of by the allocation routine's
884f8829a4aSRandall Stewart 	 * bzero
885f8829a4aSRandall Stewart 	 */
886f8829a4aSRandall Stewart 
887f8829a4aSRandall Stewart 	/*
888f8829a4aSRandall Stewart 	 * Up front select what scoping to apply on addresses I tell my peer
889f8829a4aSRandall Stewart 	 * Not sure what to do with these right now, we will need to come up
890f8829a4aSRandall Stewart 	 * with a way to set them. We may need to pass them through from the
891f8829a4aSRandall Stewart 	 * caller in the sctp_aloc_assoc() function.
892f8829a4aSRandall Stewart 	 */
893f8829a4aSRandall Stewart 	int i;
894f8829a4aSRandall Stewart 
8950696e120SRandall Stewart 	asoc = &stcb->asoc;
896f8829a4aSRandall Stewart 	/* init all variables to a known value. */
897c4739e2fSRandall Stewart 	SCTP_SET_STATE(&stcb->asoc, SCTP_STATE_INUSE);
898f8829a4aSRandall Stewart 	asoc->max_burst = m->sctp_ep.max_burst;
899f8829a4aSRandall Stewart 	asoc->heart_beat_delay = TICKS_TO_MSEC(m->sctp_ep.sctp_timeoutticks[SCTP_TIMER_HEARTBEAT]);
900f8829a4aSRandall Stewart 	asoc->cookie_life = m->sctp_ep.def_cookie_life;
901b3f1ea41SRandall Stewart 	asoc->sctp_cmt_on_off = (uint8_t) SCTP_BASE_SYSCTL(sctp_cmt_on_off);
902830d754dSRandall Stewart 	/* EY Init nr_sack variable */
903830d754dSRandall Stewart 	asoc->sctp_nr_sack_on_off = (uint8_t) SCTP_BASE_SYSCTL(sctp_nr_sack_on_off);
904b54d3a6cSRandall Stewart 	/* JRS 5/21/07 - Init CMT PF variables */
905b3f1ea41SRandall Stewart 	asoc->sctp_cmt_pf = (uint8_t) SCTP_BASE_SYSCTL(sctp_cmt_pf);
906d61a0ae0SRandall Stewart 	asoc->sctp_frag_point = m->sctp_frag_point;
90742551e99SRandall Stewart #ifdef INET
908f8829a4aSRandall Stewart 	asoc->default_tos = m->ip_inp.inp.inp_ip_tos;
909f8829a4aSRandall Stewart #else
910f8829a4aSRandall Stewart 	asoc->default_tos = 0;
911f8829a4aSRandall Stewart #endif
912f8829a4aSRandall Stewart 
91342551e99SRandall Stewart #ifdef INET6
914f8829a4aSRandall Stewart 	asoc->default_flowlabel = ((struct in6pcb *)m)->in6p_flowinfo;
915f8829a4aSRandall Stewart #else
916f8829a4aSRandall Stewart 	asoc->default_flowlabel = 0;
917f8829a4aSRandall Stewart #endif
9189f22f500SRandall Stewart 	asoc->sb_send_resv = 0;
919f8829a4aSRandall Stewart 	if (override_tag) {
920830d754dSRandall Stewart #ifdef MICHAELS_EXPERIMENT
921830d754dSRandall Stewart 		if (sctp_is_in_timewait(override_tag, stcb->sctp_ep->sctp_lport, stcb->rport)) {
922fb8fb8f8SRandall Stewart 			/*
923fb8fb8f8SRandall Stewart 			 * It must be in the time-wait hash, we put it there
924fb8fb8f8SRandall Stewart 			 * when we aloc one. If not the peer is playing
925fb8fb8f8SRandall Stewart 			 * games.
926fb8fb8f8SRandall Stewart 			 */
927f8829a4aSRandall Stewart 			asoc->my_vtag = override_tag;
928f8829a4aSRandall Stewart 		} else {
929c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
930df6e0cc3SRandall Stewart #ifdef INVARIANTS
931fb8fb8f8SRandall Stewart 			panic("Huh is_in_timewait fails");
932df6e0cc3SRandall Stewart #endif
933f8829a4aSRandall Stewart 			return (ENOMEM);
934f8829a4aSRandall Stewart 		}
935830d754dSRandall Stewart #else
936830d754dSRandall Stewart 		asoc->my_vtag = override_tag;
937830d754dSRandall Stewart #endif
938f8829a4aSRandall Stewart 	} else {
939830d754dSRandall Stewart 		asoc->my_vtag = sctp_select_a_tag(m, stcb->sctp_ep->sctp_lport, stcb->rport, 1);
940f8829a4aSRandall Stewart 	}
941de0e935bSRandall Stewart 	/* Get the nonce tags */
942830d754dSRandall Stewart 	asoc->my_vtag_nonce = sctp_select_a_tag(m, stcb->sctp_ep->sctp_lport, stcb->rport, 0);
943830d754dSRandall Stewart 	asoc->peer_vtag_nonce = sctp_select_a_tag(m, stcb->sctp_ep->sctp_lport, stcb->rport, 0);
94442551e99SRandall Stewart 	asoc->vrf_id = vrf_id;
945de0e935bSRandall Stewart 
946f8829a4aSRandall Stewart 	if (sctp_is_feature_on(m, SCTP_PCB_FLAGS_DONOT_HEARTBEAT))
947f8829a4aSRandall Stewart 		asoc->hb_is_disabled = 1;
948f8829a4aSRandall Stewart 	else
949f8829a4aSRandall Stewart 		asoc->hb_is_disabled = 0;
950f8829a4aSRandall Stewart 
95118e198d3SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
95218e198d3SRandall Stewart 	asoc->tsn_in_at = 0;
95318e198d3SRandall Stewart 	asoc->tsn_out_at = 0;
95418e198d3SRandall Stewart 	asoc->tsn_in_wrapped = 0;
95518e198d3SRandall Stewart 	asoc->tsn_out_wrapped = 0;
95618e198d3SRandall Stewart 	asoc->cumack_log_at = 0;
957b201f536SRandall Stewart 	asoc->cumack_log_atsnt = 0;
95818e198d3SRandall Stewart #endif
95918e198d3SRandall Stewart #ifdef SCTP_FS_SPEC_LOG
96018e198d3SRandall Stewart 	asoc->fs_index = 0;
96118e198d3SRandall Stewart #endif
962f8829a4aSRandall Stewart 	asoc->refcnt = 0;
963f8829a4aSRandall Stewart 	asoc->assoc_up_sent = 0;
964f8829a4aSRandall Stewart 	asoc->asconf_seq_out = asoc->str_reset_seq_out = asoc->init_seq_number = asoc->sending_seq =
965f8829a4aSRandall Stewart 	    sctp_select_initial_TSN(&m->sctp_ep);
966c54a18d2SRandall Stewart 	asoc->asconf_seq_out_acked = asoc->asconf_seq_out - 1;
967f8829a4aSRandall Stewart 	/* we are optimisitic here */
968f8829a4aSRandall Stewart 	asoc->peer_supports_pktdrop = 1;
969830d754dSRandall Stewart 	asoc->peer_supports_nat = 0;
970f8829a4aSRandall Stewart 	asoc->sent_queue_retran_cnt = 0;
971f8829a4aSRandall Stewart 
972f8829a4aSRandall Stewart 	/* for CMT */
973f8829a4aSRandall Stewart 	asoc->last_net_data_came_from = NULL;
974f8829a4aSRandall Stewart 
975f8829a4aSRandall Stewart 	/* This will need to be adjusted */
976f8829a4aSRandall Stewart 	asoc->last_cwr_tsn = asoc->init_seq_number - 1;
977f8829a4aSRandall Stewart 	asoc->last_acked_seq = asoc->init_seq_number - 1;
978f8829a4aSRandall Stewart 	asoc->advanced_peer_ack_point = asoc->last_acked_seq;
979f8829a4aSRandall Stewart 	asoc->asconf_seq_in = asoc->last_acked_seq;
980f8829a4aSRandall Stewart 
981f8829a4aSRandall Stewart 	/* here we are different, we hold the next one we expect */
982f8829a4aSRandall Stewart 	asoc->str_reset_seq_in = asoc->last_acked_seq + 1;
983f8829a4aSRandall Stewart 
984f8829a4aSRandall Stewart 	asoc->initial_init_rto_max = m->sctp_ep.initial_init_rto_max;
985f8829a4aSRandall Stewart 	asoc->initial_rto = m->sctp_ep.initial_rto;
986f8829a4aSRandall Stewart 
987f8829a4aSRandall Stewart 	asoc->max_init_times = m->sctp_ep.max_init_times;
988f8829a4aSRandall Stewart 	asoc->max_send_times = m->sctp_ep.max_send_times;
989f8829a4aSRandall Stewart 	asoc->def_net_failure = m->sctp_ep.def_net_failure;
990f8829a4aSRandall Stewart 	asoc->free_chunk_cnt = 0;
991f8829a4aSRandall Stewart 
992f8829a4aSRandall Stewart 	asoc->iam_blocking = 0;
993f8829a4aSRandall Stewart 	/* ECN Nonce initialization */
994f8829a4aSRandall Stewart 	asoc->context = m->sctp_context;
995f8829a4aSRandall Stewart 	asoc->def_send = m->def_send;
996f8829a4aSRandall Stewart 	asoc->ecn_nonce_allowed = 0;
997f8829a4aSRandall Stewart 	asoc->receiver_nonce_sum = 1;
998f8829a4aSRandall Stewart 	asoc->nonce_sum_expect_base = 1;
999f8829a4aSRandall Stewart 	asoc->nonce_sum_check = 1;
1000f8829a4aSRandall Stewart 	asoc->nonce_resync_tsn = 0;
1001f8829a4aSRandall Stewart 	asoc->nonce_wait_for_ecne = 0;
1002f8829a4aSRandall Stewart 	asoc->nonce_wait_tsn = 0;
1003f8829a4aSRandall Stewart 	asoc->delayed_ack = TICKS_TO_MSEC(m->sctp_ep.sctp_timeoutticks[SCTP_TIMER_RECV]);
100442551e99SRandall Stewart 	asoc->sack_freq = m->sctp_ep.sctp_sack_freq;
1005f8829a4aSRandall Stewart 	asoc->pr_sctp_cnt = 0;
1006f8829a4aSRandall Stewart 	asoc->total_output_queue_size = 0;
1007f8829a4aSRandall Stewart 
1008f8829a4aSRandall Stewart 	if (m->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) {
1009f8829a4aSRandall Stewart 		struct in6pcb *inp6;
1010f8829a4aSRandall Stewart 
1011f8829a4aSRandall Stewart 		/* Its a V6 socket */
1012f8829a4aSRandall Stewart 		inp6 = (struct in6pcb *)m;
1013f8829a4aSRandall Stewart 		asoc->ipv6_addr_legal = 1;
1014f8829a4aSRandall Stewart 		/* Now look at the binding flag to see if V4 will be legal */
101544b7479bSRandall Stewart 		if (SCTP_IPV6_V6ONLY(inp6) == 0) {
1016f8829a4aSRandall Stewart 			asoc->ipv4_addr_legal = 1;
1017f8829a4aSRandall Stewart 		} else {
1018f8829a4aSRandall Stewart 			/* V4 addresses are NOT legal on the association */
1019f8829a4aSRandall Stewart 			asoc->ipv4_addr_legal = 0;
1020f8829a4aSRandall Stewart 		}
1021f8829a4aSRandall Stewart 	} else {
1022f8829a4aSRandall Stewart 		/* Its a V4 socket, no - V6 */
1023f8829a4aSRandall Stewart 		asoc->ipv4_addr_legal = 1;
1024f8829a4aSRandall Stewart 		asoc->ipv6_addr_legal = 0;
1025f8829a4aSRandall Stewart 	}
1026f8829a4aSRandall Stewart 
102762c1ff9cSRandall Stewart 	asoc->my_rwnd = max(SCTP_SB_LIMIT_RCV(m->sctp_socket), SCTP_MINIMAL_RWND);
102862c1ff9cSRandall Stewart 	asoc->peers_rwnd = SCTP_SB_LIMIT_RCV(m->sctp_socket);
1029f8829a4aSRandall Stewart 
1030f8829a4aSRandall Stewart 	asoc->smallest_mtu = m->sctp_frag_point;
103117205eccSRandall Stewart #ifdef SCTP_PRINT_FOR_B_AND_M
1032ad81507eSRandall Stewart 	SCTP_PRINTF("smallest_mtu init'd with asoc to :%d\n",
103317205eccSRandall Stewart 	    asoc->smallest_mtu);
103417205eccSRandall Stewart #endif
1035f8829a4aSRandall Stewart 	asoc->minrto = m->sctp_ep.sctp_minrto;
1036f8829a4aSRandall Stewart 	asoc->maxrto = m->sctp_ep.sctp_maxrto;
1037f8829a4aSRandall Stewart 
1038f8829a4aSRandall Stewart 	asoc->locked_on_sending = NULL;
1039f8829a4aSRandall Stewart 	asoc->stream_locked_on = 0;
1040f8829a4aSRandall Stewart 	asoc->ecn_echo_cnt_onq = 0;
1041f8829a4aSRandall Stewart 	asoc->stream_locked = 0;
1042f8829a4aSRandall Stewart 
104342551e99SRandall Stewart 	asoc->send_sack = 1;
104442551e99SRandall Stewart 
104542551e99SRandall Stewart 	LIST_INIT(&asoc->sctp_restricted_addrs);
104642551e99SRandall Stewart 
1047f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->nets);
1048f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->pending_reply_queue);
10492afb3e84SRandall Stewart 	TAILQ_INIT(&asoc->asconf_ack_sent);
1050f8829a4aSRandall Stewart 	/* Setup to fill the hb random cache at first HB */
1051f8829a4aSRandall Stewart 	asoc->hb_random_idx = 4;
1052f8829a4aSRandall Stewart 
1053f8829a4aSRandall Stewart 	asoc->sctp_autoclose_ticks = m->sctp_ep.auto_close_time;
1054f8829a4aSRandall Stewart 
1055f8829a4aSRandall Stewart 	/*
1056b54d3a6cSRandall Stewart 	 * JRS - Pick the default congestion control module based on the
1057b54d3a6cSRandall Stewart 	 * sysctl.
1058b54d3a6cSRandall Stewart 	 */
1059b54d3a6cSRandall Stewart 	switch (m->sctp_ep.sctp_default_cc_module) {
1060b54d3a6cSRandall Stewart 		/* JRS - Standard TCP congestion control */
1061b54d3a6cSRandall Stewart 	case SCTP_CC_RFC2581:
1062b54d3a6cSRandall Stewart 		{
1063b54d3a6cSRandall Stewart 			stcb->asoc.congestion_control_module = SCTP_CC_RFC2581;
1064b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_set_initial_cc_param = &sctp_set_initial_cc_param;
1065b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_sack = &sctp_cwnd_update_after_sack;
1066b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr = &sctp_cwnd_update_after_fr;
1067b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_timeout = &sctp_cwnd_update_after_timeout;
1068b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_ecn_echo = &sctp_cwnd_update_after_ecn_echo;
1069b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_packet_dropped = &sctp_cwnd_update_after_packet_dropped;
1070b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_output = &sctp_cwnd_update_after_output;
1071b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr_timer = &sctp_cwnd_update_after_fr_timer;
1072b54d3a6cSRandall Stewart 			break;
1073b54d3a6cSRandall Stewart 		}
1074b54d3a6cSRandall Stewart 		/* JRS - High Speed TCP congestion control (Floyd) */
1075b54d3a6cSRandall Stewart 	case SCTP_CC_HSTCP:
1076b54d3a6cSRandall Stewart 		{
1077b54d3a6cSRandall Stewart 			stcb->asoc.congestion_control_module = SCTP_CC_HSTCP;
1078b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_set_initial_cc_param = &sctp_set_initial_cc_param;
1079b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_sack = &sctp_hs_cwnd_update_after_sack;
1080b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr = &sctp_hs_cwnd_update_after_fr;
1081b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_timeout = &sctp_cwnd_update_after_timeout;
1082b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_ecn_echo = &sctp_cwnd_update_after_ecn_echo;
1083b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_packet_dropped = &sctp_cwnd_update_after_packet_dropped;
1084b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_output = &sctp_cwnd_update_after_output;
1085b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr_timer = &sctp_cwnd_update_after_fr_timer;
1086b54d3a6cSRandall Stewart 			break;
1087b54d3a6cSRandall Stewart 		}
1088b54d3a6cSRandall Stewart 		/* JRS - HTCP congestion control */
1089b54d3a6cSRandall Stewart 	case SCTP_CC_HTCP:
1090b54d3a6cSRandall Stewart 		{
1091b54d3a6cSRandall Stewart 			stcb->asoc.congestion_control_module = SCTP_CC_HTCP;
1092b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_set_initial_cc_param = &sctp_htcp_set_initial_cc_param;
1093b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_sack = &sctp_htcp_cwnd_update_after_sack;
1094b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr = &sctp_htcp_cwnd_update_after_fr;
1095b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_timeout = &sctp_htcp_cwnd_update_after_timeout;
1096b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_ecn_echo = &sctp_htcp_cwnd_update_after_ecn_echo;
1097b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_packet_dropped = &sctp_cwnd_update_after_packet_dropped;
1098b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_output = &sctp_cwnd_update_after_output;
1099b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr_timer = &sctp_htcp_cwnd_update_after_fr_timer;
1100b54d3a6cSRandall Stewart 			break;
1101b54d3a6cSRandall Stewart 		}
1102b54d3a6cSRandall Stewart 		/* JRS - By default, use RFC2581 */
1103b54d3a6cSRandall Stewart 	default:
1104b54d3a6cSRandall Stewart 		{
1105b54d3a6cSRandall Stewart 			stcb->asoc.congestion_control_module = SCTP_CC_RFC2581;
1106b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_set_initial_cc_param = &sctp_set_initial_cc_param;
1107b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_sack = &sctp_cwnd_update_after_sack;
1108b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr = &sctp_cwnd_update_after_fr;
1109b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_timeout = &sctp_cwnd_update_after_timeout;
1110b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_ecn_echo = &sctp_cwnd_update_after_ecn_echo;
1111b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_packet_dropped = &sctp_cwnd_update_after_packet_dropped;
1112b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_output = &sctp_cwnd_update_after_output;
1113b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr_timer = &sctp_cwnd_update_after_fr_timer;
1114b54d3a6cSRandall Stewart 			break;
1115b54d3a6cSRandall Stewart 		}
1116b54d3a6cSRandall Stewart 	}
1117b54d3a6cSRandall Stewart 
1118b54d3a6cSRandall Stewart 	/*
1119f8829a4aSRandall Stewart 	 * Now the stream parameters, here we allocate space for all streams
1120f8829a4aSRandall Stewart 	 * that we request by default.
1121f8829a4aSRandall Stewart 	 */
1122f8829a4aSRandall Stewart 	asoc->streamoutcnt = asoc->pre_open_streams =
1123f8829a4aSRandall Stewart 	    m->sctp_ep.pre_open_stream_count;
1124f8829a4aSRandall Stewart 	SCTP_MALLOC(asoc->strmout, struct sctp_stream_out *,
1125f8829a4aSRandall Stewart 	    asoc->streamoutcnt * sizeof(struct sctp_stream_out),
1126207304d4SRandall Stewart 	    SCTP_M_STRMO);
1127f8829a4aSRandall Stewart 	if (asoc->strmout == NULL) {
1128f8829a4aSRandall Stewart 		/* big trouble no memory */
1129c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
1130f8829a4aSRandall Stewart 		return (ENOMEM);
1131f8829a4aSRandall Stewart 	}
1132f8829a4aSRandall Stewart 	for (i = 0; i < asoc->streamoutcnt; i++) {
1133f8829a4aSRandall Stewart 		/*
1134f8829a4aSRandall Stewart 		 * inbound side must be set to 0xffff, also NOTE when we get
1135f8829a4aSRandall Stewart 		 * the INIT-ACK back (for INIT sender) we MUST reduce the
1136f8829a4aSRandall Stewart 		 * count (streamoutcnt) but first check if we sent to any of
1137f8829a4aSRandall Stewart 		 * the upper streams that were dropped (if some were). Those
1138f8829a4aSRandall Stewart 		 * that were dropped must be notified to the upper layer as
1139f8829a4aSRandall Stewart 		 * failed to send.
1140f8829a4aSRandall Stewart 		 */
1141f8829a4aSRandall Stewart 		asoc->strmout[i].next_sequence_sent = 0x0;
1142f8829a4aSRandall Stewart 		TAILQ_INIT(&asoc->strmout[i].outqueue);
1143f8829a4aSRandall Stewart 		asoc->strmout[i].stream_no = i;
1144f8829a4aSRandall Stewart 		asoc->strmout[i].last_msg_incomplete = 0;
1145f8829a4aSRandall Stewart 		asoc->strmout[i].next_spoke.tqe_next = 0;
1146f8829a4aSRandall Stewart 		asoc->strmout[i].next_spoke.tqe_prev = 0;
1147f8829a4aSRandall Stewart 	}
1148f8829a4aSRandall Stewart 	/* Now the mapping array */
1149f8829a4aSRandall Stewart 	asoc->mapping_array_size = SCTP_INITIAL_MAPPING_ARRAY;
1150f8829a4aSRandall Stewart 	SCTP_MALLOC(asoc->mapping_array, uint8_t *, asoc->mapping_array_size,
1151207304d4SRandall Stewart 	    SCTP_M_MAP);
1152f8829a4aSRandall Stewart 	if (asoc->mapping_array == NULL) {
1153207304d4SRandall Stewart 		SCTP_FREE(asoc->strmout, SCTP_M_STRMO);
1154c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
1155f8829a4aSRandall Stewart 		return (ENOMEM);
1156f8829a4aSRandall Stewart 	}
1157f8829a4aSRandall Stewart 	memset(asoc->mapping_array, 0, asoc->mapping_array_size);
1158830d754dSRandall Stewart 	/* EY  - initialize the nr_mapping_array just like mapping array */
1159830d754dSRandall Stewart 	asoc->nr_mapping_array_size = SCTP_INITIAL_NR_MAPPING_ARRAY;
1160830d754dSRandall Stewart 	SCTP_MALLOC(asoc->nr_mapping_array, uint8_t *, asoc->nr_mapping_array_size,
1161830d754dSRandall Stewart 	    SCTP_M_MAP);
1162830d754dSRandall Stewart 	/*
1163830d754dSRandall Stewart 	 * if (asoc->nr_mapping_array == NULL) { SCTP_FREE(asoc->strmout,
1164830d754dSRandall Stewart 	 * SCTP_M_STRMO); SCTP_LTRACE_ERR_RET(NULL, stcb, NULL,
1165830d754dSRandall Stewart 	 * SCTP_FROM_SCTPUTIL, ENOMEM); return (ENOMEM); }
1166830d754dSRandall Stewart 	 */
1167830d754dSRandall Stewart 	memset(asoc->nr_mapping_array, 0, asoc->nr_mapping_array_size);
1168830d754dSRandall Stewart 
1169f8829a4aSRandall Stewart 	/* Now the init of the other outqueues */
1170f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->free_chunks);
1171f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->out_wheel);
1172f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->control_send_queue);
1173c54a18d2SRandall Stewart 	TAILQ_INIT(&asoc->asconf_send_queue);
1174f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->send_queue);
1175f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->sent_queue);
1176f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->reasmqueue);
1177f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->resetHead);
1178f8829a4aSRandall Stewart 	asoc->max_inbound_streams = m->sctp_ep.max_open_streams_intome;
1179f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->asconf_queue);
1180f8829a4aSRandall Stewart 	/* authentication fields */
1181f8829a4aSRandall Stewart 	asoc->authinfo.random = NULL;
1182830d754dSRandall Stewart 	asoc->authinfo.active_keyid = 0;
1183f8829a4aSRandall Stewart 	asoc->authinfo.assoc_key = NULL;
1184f8829a4aSRandall Stewart 	asoc->authinfo.assoc_keyid = 0;
1185f8829a4aSRandall Stewart 	asoc->authinfo.recv_key = NULL;
1186f8829a4aSRandall Stewart 	asoc->authinfo.recv_keyid = 0;
1187f8829a4aSRandall Stewart 	LIST_INIT(&asoc->shared_keys);
1188f42a358aSRandall Stewart 	asoc->marked_retrans = 0;
1189f42a358aSRandall Stewart 	asoc->timoinit = 0;
1190f42a358aSRandall Stewart 	asoc->timodata = 0;
1191f42a358aSRandall Stewart 	asoc->timosack = 0;
1192f42a358aSRandall Stewart 	asoc->timoshutdown = 0;
1193f42a358aSRandall Stewart 	asoc->timoheartbeat = 0;
1194f42a358aSRandall Stewart 	asoc->timocookie = 0;
1195f42a358aSRandall Stewart 	asoc->timoshutdownack = 0;
11966e55db54SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&asoc->start_time);
11976e55db54SRandall Stewart 	asoc->discontinuity_time = asoc->start_time;
1198eacc51c5SRandall Stewart 	/*
1199eacc51c5SRandall Stewart 	 * sa_ignore MEMLEAK {memory is put in the assoc mapping array and
1200eacc51c5SRandall Stewart 	 * freed later whe the association is freed.
1201eacc51c5SRandall Stewart 	 */
1202f8829a4aSRandall Stewart 	return (0);
1203f8829a4aSRandall Stewart }
1204f8829a4aSRandall Stewart 
1205f8829a4aSRandall Stewart int
12060696e120SRandall Stewart sctp_expand_mapping_array(struct sctp_association *asoc, uint32_t needed)
1207f8829a4aSRandall Stewart {
1208f8829a4aSRandall Stewart 	/* mapping array needs to grow */
1209f8829a4aSRandall Stewart 	uint8_t *new_array;
12100696e120SRandall Stewart 	uint32_t new_size;
1211f8829a4aSRandall Stewart 
12120696e120SRandall Stewart 	new_size = asoc->mapping_array_size + ((needed + 7) / 8 + SCTP_MAPPING_ARRAY_INCR);
1213207304d4SRandall Stewart 	SCTP_MALLOC(new_array, uint8_t *, new_size, SCTP_M_MAP);
1214f8829a4aSRandall Stewart 	if (new_array == NULL) {
1215f8829a4aSRandall Stewart 		/* can't get more, forget it */
1216ad81507eSRandall Stewart 		SCTP_PRINTF("No memory for expansion of SCTP mapping array %d\n",
1217f8829a4aSRandall Stewart 		    new_size);
1218f8829a4aSRandall Stewart 		return (-1);
1219f8829a4aSRandall Stewart 	}
1220f8829a4aSRandall Stewart 	memset(new_array, 0, new_size);
1221f8829a4aSRandall Stewart 	memcpy(new_array, asoc->mapping_array, asoc->mapping_array_size);
1222207304d4SRandall Stewart 	SCTP_FREE(asoc->mapping_array, SCTP_M_MAP);
1223f8829a4aSRandall Stewart 	asoc->mapping_array = new_array;
1224f8829a4aSRandall Stewart 	asoc->mapping_array_size = new_size;
1225f8829a4aSRandall Stewart 	return (0);
1226f8829a4aSRandall Stewart }
1227f8829a4aSRandall Stewart 
1228830d754dSRandall Stewart /* EY - nr_sack version of the above method */
1229830d754dSRandall Stewart int
1230830d754dSRandall Stewart sctp_expand_nr_mapping_array(struct sctp_association *asoc, uint32_t needed)
1231830d754dSRandall Stewart {
1232830d754dSRandall Stewart 	/* nr mapping array needs to grow */
1233830d754dSRandall Stewart 	uint8_t *new_array;
1234830d754dSRandall Stewart 	uint32_t new_size;
1235830d754dSRandall Stewart 
1236830d754dSRandall Stewart 	new_size = asoc->nr_mapping_array_size + ((needed + 7) / 8 + SCTP_NR_MAPPING_ARRAY_INCR);
1237830d754dSRandall Stewart 	SCTP_MALLOC(new_array, uint8_t *, new_size, SCTP_M_MAP);
1238830d754dSRandall Stewart 	if (new_array == NULL) {
1239830d754dSRandall Stewart 		/* can't get more, forget it */
1240830d754dSRandall Stewart 		SCTP_PRINTF("No memory for expansion of SCTP mapping array %d\n",
1241830d754dSRandall Stewart 		    new_size);
1242830d754dSRandall Stewart 		return (-1);
1243830d754dSRandall Stewart 	}
1244830d754dSRandall Stewart 	memset(new_array, 0, new_size);
1245830d754dSRandall Stewart 	memcpy(new_array, asoc->nr_mapping_array, asoc->nr_mapping_array_size);
1246830d754dSRandall Stewart 	SCTP_FREE(asoc->nr_mapping_array, SCTP_M_MAP);
1247830d754dSRandall Stewart 	asoc->nr_mapping_array = new_array;
1248830d754dSRandall Stewart 	asoc->nr_mapping_array_size = new_size;
1249830d754dSRandall Stewart 	return (0);
1250830d754dSRandall Stewart }
1251830d754dSRandall Stewart 
125242551e99SRandall Stewart #if defined(SCTP_USE_THREAD_BASED_ITERATOR)
125342551e99SRandall Stewart static void
125442551e99SRandall Stewart sctp_iterator_work(struct sctp_iterator *it)
125542551e99SRandall Stewart {
125642551e99SRandall Stewart 	int iteration_count = 0;
125742551e99SRandall Stewart 	int inp_skip = 0;
125842551e99SRandall Stewart 
125942551e99SRandall Stewart 	SCTP_ITERATOR_LOCK();
1260ad81507eSRandall Stewart 	if (it->inp) {
126142551e99SRandall Stewart 		SCTP_INP_DECR_REF(it->inp);
1262ad81507eSRandall Stewart 	}
126342551e99SRandall Stewart 	if (it->inp == NULL) {
126442551e99SRandall Stewart 		/* iterator is complete */
126542551e99SRandall Stewart done_with_iterator:
126642551e99SRandall Stewart 		SCTP_ITERATOR_UNLOCK();
126742551e99SRandall Stewart 		if (it->function_atend != NULL) {
126842551e99SRandall Stewart 			(*it->function_atend) (it->pointer, it->val);
126942551e99SRandall Stewart 		}
1270207304d4SRandall Stewart 		SCTP_FREE(it, SCTP_M_ITER);
127142551e99SRandall Stewart 		return;
127242551e99SRandall Stewart 	}
127342551e99SRandall Stewart select_a_new_ep:
127442551e99SRandall Stewart 	SCTP_INP_WLOCK(it->inp);
127542551e99SRandall Stewart 	while (((it->pcb_flags) &&
127642551e99SRandall Stewart 	    ((it->inp->sctp_flags & it->pcb_flags) != it->pcb_flags)) ||
127742551e99SRandall Stewart 	    ((it->pcb_features) &&
127842551e99SRandall Stewart 	    ((it->inp->sctp_features & it->pcb_features) != it->pcb_features))) {
127942551e99SRandall Stewart 		/* endpoint flags or features don't match, so keep looking */
128042551e99SRandall Stewart 		if (it->iterator_flags & SCTP_ITERATOR_DO_SINGLE_INP) {
128142551e99SRandall Stewart 			SCTP_INP_WUNLOCK(it->inp);
128242551e99SRandall Stewart 			goto done_with_iterator;
128342551e99SRandall Stewart 		}
128442551e99SRandall Stewart 		SCTP_INP_WUNLOCK(it->inp);
128542551e99SRandall Stewart 		it->inp = LIST_NEXT(it->inp, sctp_list);
128642551e99SRandall Stewart 		if (it->inp == NULL) {
128742551e99SRandall Stewart 			goto done_with_iterator;
128842551e99SRandall Stewart 		}
128942551e99SRandall Stewart 		SCTP_INP_WLOCK(it->inp);
129042551e99SRandall Stewart 	}
129142551e99SRandall Stewart 
129242551e99SRandall Stewart 	SCTP_INP_WUNLOCK(it->inp);
129342551e99SRandall Stewart 	SCTP_INP_RLOCK(it->inp);
129442551e99SRandall Stewart 
129542551e99SRandall Stewart 	/* now go through each assoc which is in the desired state */
129642551e99SRandall Stewart 	if (it->done_current_ep == 0) {
129742551e99SRandall Stewart 		if (it->function_inp != NULL)
129842551e99SRandall Stewart 			inp_skip = (*it->function_inp) (it->inp, it->pointer, it->val);
129942551e99SRandall Stewart 		it->done_current_ep = 1;
130042551e99SRandall Stewart 	}
130142551e99SRandall Stewart 	if (it->stcb == NULL) {
130242551e99SRandall Stewart 		/* run the per instance function */
130342551e99SRandall Stewart 		it->stcb = LIST_FIRST(&it->inp->sctp_asoc_list);
130442551e99SRandall Stewart 	}
130542551e99SRandall Stewart 	if ((inp_skip) || it->stcb == NULL) {
130642551e99SRandall Stewart 		if (it->function_inp_end != NULL) {
130742551e99SRandall Stewart 			inp_skip = (*it->function_inp_end) (it->inp,
130842551e99SRandall Stewart 			    it->pointer,
130942551e99SRandall Stewart 			    it->val);
131042551e99SRandall Stewart 		}
131142551e99SRandall Stewart 		SCTP_INP_RUNLOCK(it->inp);
131242551e99SRandall Stewart 		goto no_stcb;
131342551e99SRandall Stewart 	}
131442551e99SRandall Stewart 	while (it->stcb) {
131542551e99SRandall Stewart 		SCTP_TCB_LOCK(it->stcb);
131642551e99SRandall Stewart 		if (it->asoc_state && ((it->stcb->asoc.state & it->asoc_state) != it->asoc_state)) {
131742551e99SRandall Stewart 			/* not in the right state... keep looking */
131842551e99SRandall Stewart 			SCTP_TCB_UNLOCK(it->stcb);
131942551e99SRandall Stewart 			goto next_assoc;
132042551e99SRandall Stewart 		}
132142551e99SRandall Stewart 		/* see if we have limited out the iterator loop */
132242551e99SRandall Stewart 		iteration_count++;
132342551e99SRandall Stewart 		if (iteration_count > SCTP_ITERATOR_MAX_AT_ONCE) {
132442551e99SRandall Stewart 			/* Pause to let others grab the lock */
132542551e99SRandall Stewart 			atomic_add_int(&it->stcb->asoc.refcnt, 1);
132642551e99SRandall Stewart 			SCTP_TCB_UNLOCK(it->stcb);
1327c4739e2fSRandall Stewart 
1328c4739e2fSRandall Stewart 			SCTP_INP_INCR_REF(it->inp);
132942551e99SRandall Stewart 			SCTP_INP_RUNLOCK(it->inp);
133042551e99SRandall Stewart 			SCTP_ITERATOR_UNLOCK();
133142551e99SRandall Stewart 			SCTP_ITERATOR_LOCK();
133242551e99SRandall Stewart 			SCTP_INP_RLOCK(it->inp);
1333c4739e2fSRandall Stewart 
1334c4739e2fSRandall Stewart 			SCTP_INP_DECR_REF(it->inp);
133542551e99SRandall Stewart 			SCTP_TCB_LOCK(it->stcb);
133642551e99SRandall Stewart 			atomic_add_int(&it->stcb->asoc.refcnt, -1);
133742551e99SRandall Stewart 			iteration_count = 0;
133842551e99SRandall Stewart 		}
133942551e99SRandall Stewart 		/* run function on this one */
134042551e99SRandall Stewart 		(*it->function_assoc) (it->inp, it->stcb, it->pointer, it->val);
134142551e99SRandall Stewart 
134242551e99SRandall Stewart 		/*
134342551e99SRandall Stewart 		 * we lie here, it really needs to have its own type but
134442551e99SRandall Stewart 		 * first I must verify that this won't effect things :-0
134542551e99SRandall Stewart 		 */
134642551e99SRandall Stewart 		if (it->no_chunk_output == 0)
1347ceaad40aSRandall Stewart 			sctp_chunk_output(it->inp, it->stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
134842551e99SRandall Stewart 
134942551e99SRandall Stewart 		SCTP_TCB_UNLOCK(it->stcb);
135042551e99SRandall Stewart next_assoc:
135142551e99SRandall Stewart 		it->stcb = LIST_NEXT(it->stcb, sctp_tcblist);
135242551e99SRandall Stewart 		if (it->stcb == NULL) {
135342551e99SRandall Stewart 			/* Run last function */
135442551e99SRandall Stewart 			if (it->function_inp_end != NULL) {
135542551e99SRandall Stewart 				inp_skip = (*it->function_inp_end) (it->inp,
135642551e99SRandall Stewart 				    it->pointer,
135742551e99SRandall Stewart 				    it->val);
135842551e99SRandall Stewart 			}
135942551e99SRandall Stewart 		}
136042551e99SRandall Stewart 	}
136142551e99SRandall Stewart 	SCTP_INP_RUNLOCK(it->inp);
136242551e99SRandall Stewart no_stcb:
136342551e99SRandall Stewart 	/* done with all assocs on this endpoint, move on to next endpoint */
136442551e99SRandall Stewart 	it->done_current_ep = 0;
136542551e99SRandall Stewart 	SCTP_INP_WLOCK(it->inp);
136642551e99SRandall Stewart 	SCTP_INP_WUNLOCK(it->inp);
136742551e99SRandall Stewart 	if (it->iterator_flags & SCTP_ITERATOR_DO_SINGLE_INP) {
136842551e99SRandall Stewart 		it->inp = NULL;
136942551e99SRandall Stewart 	} else {
137042551e99SRandall Stewart 		SCTP_INP_INFO_RLOCK();
137142551e99SRandall Stewart 		it->inp = LIST_NEXT(it->inp, sctp_list);
137242551e99SRandall Stewart 		SCTP_INP_INFO_RUNLOCK();
137342551e99SRandall Stewart 	}
137442551e99SRandall Stewart 	if (it->inp == NULL) {
137542551e99SRandall Stewart 		goto done_with_iterator;
137642551e99SRandall Stewart 	}
137742551e99SRandall Stewart 	goto select_a_new_ep;
137842551e99SRandall Stewart }
137942551e99SRandall Stewart 
138042551e99SRandall Stewart void
138142551e99SRandall Stewart sctp_iterator_worker(void)
138242551e99SRandall Stewart {
138342551e99SRandall Stewart 	struct sctp_iterator *it = NULL;
138442551e99SRandall Stewart 
138542551e99SRandall Stewart 	/* This function is called with the WQ lock in place */
138642551e99SRandall Stewart 
1387b3f1ea41SRandall Stewart 	SCTP_BASE_INFO(iterator_running) = 1;
138842551e99SRandall Stewart again:
1389b3f1ea41SRandall Stewart 	it = TAILQ_FIRST(&SCTP_BASE_INFO(iteratorhead));
139042551e99SRandall Stewart 	while (it) {
139142551e99SRandall Stewart 		/* now lets work on this one */
1392b3f1ea41SRandall Stewart 		TAILQ_REMOVE(&SCTP_BASE_INFO(iteratorhead), it, sctp_nxt_itr);
139342551e99SRandall Stewart 		SCTP_IPI_ITERATOR_WQ_UNLOCK();
139442551e99SRandall Stewart 		sctp_iterator_work(it);
139542551e99SRandall Stewart 		SCTP_IPI_ITERATOR_WQ_LOCK();
13963c503c28SRandall Stewart 		/* sa_ignore FREED_MEMORY */
1397b3f1ea41SRandall Stewart 		it = TAILQ_FIRST(&SCTP_BASE_INFO(iteratorhead));
139842551e99SRandall Stewart 	}
1399b3f1ea41SRandall Stewart 	if (TAILQ_FIRST(&SCTP_BASE_INFO(iteratorhead))) {
140042551e99SRandall Stewart 		goto again;
140142551e99SRandall Stewart 	}
1402b3f1ea41SRandall Stewart 	SCTP_BASE_INFO(iterator_running) = 0;
140342551e99SRandall Stewart 	return;
140442551e99SRandall Stewart }
140542551e99SRandall Stewart 
140642551e99SRandall Stewart #endif
140742551e99SRandall Stewart 
1408f8829a4aSRandall Stewart 
1409f8829a4aSRandall Stewart static void
1410f8829a4aSRandall Stewart sctp_handle_addr_wq(void)
1411f8829a4aSRandall Stewart {
1412f8829a4aSRandall Stewart 	/* deal with the ADDR wq from the rtsock calls */
1413f8829a4aSRandall Stewart 	struct sctp_laddr *wi;
141442551e99SRandall Stewart 	struct sctp_asconf_iterator *asc;
1415f8829a4aSRandall Stewart 
141642551e99SRandall Stewart 	SCTP_MALLOC(asc, struct sctp_asconf_iterator *,
1417207304d4SRandall Stewart 	    sizeof(struct sctp_asconf_iterator), SCTP_M_ASC_IT);
141842551e99SRandall Stewart 	if (asc == NULL) {
141942551e99SRandall Stewart 		/* Try later, no memory */
1420f8829a4aSRandall Stewart 		sctp_timer_start(SCTP_TIMER_TYPE_ADDR_WQ,
1421f8829a4aSRandall Stewart 		    (struct sctp_inpcb *)NULL,
1422f8829a4aSRandall Stewart 		    (struct sctp_tcb *)NULL,
1423f8829a4aSRandall Stewart 		    (struct sctp_nets *)NULL);
142442551e99SRandall Stewart 		return;
1425f8829a4aSRandall Stewart 	}
142642551e99SRandall Stewart 	LIST_INIT(&asc->list_of_work);
142742551e99SRandall Stewart 	asc->cnt = 0;
142842551e99SRandall Stewart 	SCTP_IPI_ITERATOR_WQ_LOCK();
1429b3f1ea41SRandall Stewart 	wi = LIST_FIRST(&SCTP_BASE_INFO(addr_wq));
143042551e99SRandall Stewart 	while (wi != NULL) {
143142551e99SRandall Stewart 		LIST_REMOVE(wi, sctp_nxt_addr);
143242551e99SRandall Stewart 		LIST_INSERT_HEAD(&asc->list_of_work, wi, sctp_nxt_addr);
143342551e99SRandall Stewart 		asc->cnt++;
1434b3f1ea41SRandall Stewart 		wi = LIST_FIRST(&SCTP_BASE_INFO(addr_wq));
1435f8829a4aSRandall Stewart 	}
143642551e99SRandall Stewart 	SCTP_IPI_ITERATOR_WQ_UNLOCK();
143742551e99SRandall Stewart 	if (asc->cnt == 0) {
1438207304d4SRandall Stewart 		SCTP_FREE(asc, SCTP_M_ASC_IT);
143942551e99SRandall Stewart 	} else {
14401b649582SRandall Stewart 		(void)sctp_initiate_iterator(sctp_asconf_iterator_ep,
14411b649582SRandall Stewart 		    sctp_asconf_iterator_stcb,
144242551e99SRandall Stewart 		    NULL,	/* No ep end for boundall */
144342551e99SRandall Stewart 		    SCTP_PCB_FLAGS_BOUNDALL,
144442551e99SRandall Stewart 		    SCTP_PCB_ANY_FEATURES,
14451b649582SRandall Stewart 		    SCTP_ASOC_ANY_STATE,
14461b649582SRandall Stewart 		    (void *)asc, 0,
14471b649582SRandall Stewart 		    sctp_asconf_iterator_end, NULL, 0);
144842551e99SRandall Stewart 	}
1449f8829a4aSRandall Stewart }
1450f8829a4aSRandall Stewart 
1451b54d3a6cSRandall Stewart int retcode = 0;
1452b54d3a6cSRandall Stewart int cur_oerr = 0;
1453b54d3a6cSRandall Stewart 
1454f8829a4aSRandall Stewart void
1455f8829a4aSRandall Stewart sctp_timeout_handler(void *t)
1456f8829a4aSRandall Stewart {
1457f8829a4aSRandall Stewart 	struct sctp_inpcb *inp;
1458f8829a4aSRandall Stewart 	struct sctp_tcb *stcb;
1459f8829a4aSRandall Stewart 	struct sctp_nets *net;
1460f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
1461ceaad40aSRandall Stewart 
1462ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
1463ceaad40aSRandall Stewart 	struct socket *so;
1464ceaad40aSRandall Stewart 
1465ceaad40aSRandall Stewart #endif
1466d61374e1SRandall Stewart 	int did_output, type;
1467f8829a4aSRandall Stewart 	struct sctp_iterator *it = NULL;
1468f8829a4aSRandall Stewart 
1469f8829a4aSRandall Stewart 	tmr = (struct sctp_timer *)t;
1470f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)tmr->ep;
1471f8829a4aSRandall Stewart 	stcb = (struct sctp_tcb *)tmr->tcb;
1472f8829a4aSRandall Stewart 	net = (struct sctp_nets *)tmr->net;
1473f8829a4aSRandall Stewart 	did_output = 1;
1474f8829a4aSRandall Stewart 
1475f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1476f8829a4aSRandall Stewart 	sctp_audit_log(0xF0, (uint8_t) tmr->type);
1477f8829a4aSRandall Stewart 	sctp_auditing(3, inp, stcb, net);
1478f8829a4aSRandall Stewart #endif
1479f8829a4aSRandall Stewart 
1480f8829a4aSRandall Stewart 	/* sanity checks... */
1481f8829a4aSRandall Stewart 	if (tmr->self != (void *)tmr) {
1482f8829a4aSRandall Stewart 		/*
1483ad81507eSRandall Stewart 		 * SCTP_PRINTF("Stale SCTP timer fired (%p), ignoring...\n",
1484f8829a4aSRandall Stewart 		 * tmr);
1485f8829a4aSRandall Stewart 		 */
1486f8829a4aSRandall Stewart 		return;
1487f8829a4aSRandall Stewart 	}
1488a5d547adSRandall Stewart 	tmr->stopped_from = 0xa001;
1489f8829a4aSRandall Stewart 	if (!SCTP_IS_TIMER_TYPE_VALID(tmr->type)) {
1490f8829a4aSRandall Stewart 		/*
1491ad81507eSRandall Stewart 		 * SCTP_PRINTF("SCTP timer fired with invalid type: 0x%x\n",
1492f8829a4aSRandall Stewart 		 * tmr->type);
1493f8829a4aSRandall Stewart 		 */
1494f8829a4aSRandall Stewart 		return;
1495f8829a4aSRandall Stewart 	}
1496a5d547adSRandall Stewart 	tmr->stopped_from = 0xa002;
1497f8829a4aSRandall Stewart 	if ((tmr->type != SCTP_TIMER_TYPE_ADDR_WQ) && (inp == NULL)) {
1498f8829a4aSRandall Stewart 		return;
1499f8829a4aSRandall Stewart 	}
1500f8829a4aSRandall Stewart 	/* if this is an iterator timeout, get the struct and clear inp */
1501a5d547adSRandall Stewart 	tmr->stopped_from = 0xa003;
1502f8829a4aSRandall Stewart 	if (tmr->type == SCTP_TIMER_TYPE_ITERATOR) {
1503f8829a4aSRandall Stewart 		it = (struct sctp_iterator *)inp;
1504f8829a4aSRandall Stewart 		inp = NULL;
1505f8829a4aSRandall Stewart 	}
1506d61374e1SRandall Stewart 	type = tmr->type;
1507f8829a4aSRandall Stewart 	if (inp) {
1508f8829a4aSRandall Stewart 		SCTP_INP_INCR_REF(inp);
1509f8829a4aSRandall Stewart 		if ((inp->sctp_socket == 0) &&
1510f8829a4aSRandall Stewart 		    ((tmr->type != SCTP_TIMER_TYPE_INPKILL) &&
1511a1e13272SRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_SEND) &&
1512a1e13272SRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_RECV) &&
1513a1e13272SRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_HEARTBEAT) &&
1514f8829a4aSRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_SHUTDOWN) &&
1515f8829a4aSRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_SHUTDOWNACK) &&
1516f8829a4aSRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_SHUTDOWNGUARD) &&
1517f8829a4aSRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_ASOCKILL))
1518f8829a4aSRandall Stewart 		    ) {
1519f8829a4aSRandall Stewart 			SCTP_INP_DECR_REF(inp);
1520f8829a4aSRandall Stewart 			return;
1521f8829a4aSRandall Stewart 		}
1522f8829a4aSRandall Stewart 	}
1523a5d547adSRandall Stewart 	tmr->stopped_from = 0xa004;
1524f8829a4aSRandall Stewart 	if (stcb) {
1525c105859eSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
1526f8829a4aSRandall Stewart 		if (stcb->asoc.state == 0) {
1527c105859eSRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, -1);
1528f8829a4aSRandall Stewart 			if (inp) {
1529f8829a4aSRandall Stewart 				SCTP_INP_DECR_REF(inp);
1530f8829a4aSRandall Stewart 			}
1531f8829a4aSRandall Stewart 			return;
1532f8829a4aSRandall Stewart 		}
1533f8829a4aSRandall Stewart 	}
1534a5d547adSRandall Stewart 	tmr->stopped_from = 0xa005;
1535ad81507eSRandall Stewart 	SCTPDBG(SCTP_DEBUG_TIMER1, "Timer type %d goes off\n", tmr->type);
1536139bc87fSRandall Stewart 	if (!SCTP_OS_TIMER_ACTIVE(&tmr->timer)) {
1537f8829a4aSRandall Stewart 		if (inp) {
1538f8829a4aSRandall Stewart 			SCTP_INP_DECR_REF(inp);
1539f8829a4aSRandall Stewart 		}
1540207304d4SRandall Stewart 		if (stcb) {
1541207304d4SRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, -1);
1542207304d4SRandall Stewart 		}
1543f8829a4aSRandall Stewart 		return;
1544f8829a4aSRandall Stewart 	}
1545a5d547adSRandall Stewart 	tmr->stopped_from = 0xa006;
1546a5d547adSRandall Stewart 
1547f8829a4aSRandall Stewart 	if (stcb) {
1548f8829a4aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
154950cec919SRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, -1);
1550b54d3a6cSRandall Stewart 		if ((tmr->type != SCTP_TIMER_TYPE_ASOCKILL) &&
1551b54d3a6cSRandall Stewart 		    ((stcb->asoc.state == 0) ||
1552b54d3a6cSRandall Stewart 		    (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED))) {
1553b54d3a6cSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
1554b54d3a6cSRandall Stewart 			if (inp) {
1555b54d3a6cSRandall Stewart 				SCTP_INP_DECR_REF(inp);
1556b54d3a6cSRandall Stewart 			}
1557b54d3a6cSRandall Stewart 			return;
1558b54d3a6cSRandall Stewart 		}
1559f8829a4aSRandall Stewart 	}
156044b7479bSRandall Stewart 	/* record in stopped what t-o occured */
156144b7479bSRandall Stewart 	tmr->stopped_from = tmr->type;
156244b7479bSRandall Stewart 
1563f8829a4aSRandall Stewart 	/* mark as being serviced now */
156444b7479bSRandall Stewart 	if (SCTP_OS_TIMER_PENDING(&tmr->timer)) {
156544b7479bSRandall Stewart 		/*
156644b7479bSRandall Stewart 		 * Callout has been rescheduled.
156744b7479bSRandall Stewart 		 */
156844b7479bSRandall Stewart 		goto get_out;
156944b7479bSRandall Stewart 	}
157044b7479bSRandall Stewart 	if (!SCTP_OS_TIMER_ACTIVE(&tmr->timer)) {
157144b7479bSRandall Stewart 		/*
157244b7479bSRandall Stewart 		 * Not active, so no action.
157344b7479bSRandall Stewart 		 */
157444b7479bSRandall Stewart 		goto get_out;
157544b7479bSRandall Stewart 	}
1576139bc87fSRandall Stewart 	SCTP_OS_TIMER_DEACTIVATE(&tmr->timer);
1577f8829a4aSRandall Stewart 
1578f8829a4aSRandall Stewart 	/* call the handler for the appropriate timer type */
1579f8829a4aSRandall Stewart 	switch (tmr->type) {
1580d61a0ae0SRandall Stewart 	case SCTP_TIMER_TYPE_ZERO_COPY:
1581eacc51c5SRandall Stewart 		if (inp == NULL) {
1582eacc51c5SRandall Stewart 			break;
1583eacc51c5SRandall Stewart 		}
1584d61a0ae0SRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_ZERO_COPY_ACTIVE)) {
1585d61a0ae0SRandall Stewart 			SCTP_ZERO_COPY_EVENT(inp, inp->sctp_socket);
1586d61a0ae0SRandall Stewart 		}
1587d61a0ae0SRandall Stewart 		break;
1588ad21a364SRandall Stewart 	case SCTP_TIMER_TYPE_ZCOPY_SENDQ:
1589eacc51c5SRandall Stewart 		if (inp == NULL) {
1590eacc51c5SRandall Stewart 			break;
1591eacc51c5SRandall Stewart 		}
1592ad21a364SRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_ZERO_COPY_ACTIVE)) {
1593ad21a364SRandall Stewart 			SCTP_ZERO_COPY_SENDQ_EVENT(inp, inp->sctp_socket);
1594ad21a364SRandall Stewart 		}
1595ad21a364SRandall Stewart 		break;
1596f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ADDR_WQ:
1597f8829a4aSRandall Stewart 		sctp_handle_addr_wq();
1598f8829a4aSRandall Stewart 		break;
1599f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ITERATOR:
1600f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoiterator);
1601f8829a4aSRandall Stewart 		sctp_iterator_timer(it);
1602f8829a4aSRandall Stewart 		break;
1603f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
1604ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1605ad81507eSRandall Stewart 			break;
1606ad81507eSRandall Stewart 		}
1607f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timodata);
1608f42a358aSRandall Stewart 		stcb->asoc.timodata++;
1609f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up--;
1610f8829a4aSRandall Stewart 		if (stcb->asoc.num_send_timers_up < 0) {
1611f8829a4aSRandall Stewart 			stcb->asoc.num_send_timers_up = 0;
1612f8829a4aSRandall Stewart 		}
1613b54d3a6cSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
1614b54d3a6cSRandall Stewart 		cur_oerr = stcb->asoc.overall_error_count;
1615b54d3a6cSRandall Stewart 		retcode = sctp_t3rxt_timer(inp, stcb, net);
1616b54d3a6cSRandall Stewart 		if (retcode) {
1617f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1618f8829a4aSRandall Stewart 
1619f8829a4aSRandall Stewart 			goto out_decr;
1620f8829a4aSRandall Stewart 		}
1621b54d3a6cSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
1622f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1623f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1624f8829a4aSRandall Stewart #endif
1625ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
1626f8829a4aSRandall Stewart 		if ((stcb->asoc.num_send_timers_up == 0) &&
1627f8829a4aSRandall Stewart 		    (stcb->asoc.sent_queue_cnt > 0)
1628f8829a4aSRandall Stewart 		    ) {
1629f8829a4aSRandall Stewart 			struct sctp_tmit_chunk *chk;
1630f8829a4aSRandall Stewart 
1631f8829a4aSRandall Stewart 			/*
1632f8829a4aSRandall Stewart 			 * safeguard. If there on some on the sent queue
1633f8829a4aSRandall Stewart 			 * somewhere but no timers running something is
1634f8829a4aSRandall Stewart 			 * wrong... so we start a timer on the first chunk
1635f8829a4aSRandall Stewart 			 * on the send queue on whatever net it is sent to.
1636f8829a4aSRandall Stewart 			 */
1637f8829a4aSRandall Stewart 			chk = TAILQ_FIRST(&stcb->asoc.sent_queue);
1638f8829a4aSRandall Stewart 			sctp_timer_start(SCTP_TIMER_TYPE_SEND, inp, stcb,
1639f8829a4aSRandall Stewart 			    chk->whoTo);
1640f8829a4aSRandall Stewart 		}
1641f8829a4aSRandall Stewart 		break;
1642f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
1643ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1644ad81507eSRandall Stewart 			break;
1645ad81507eSRandall Stewart 		}
1646f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoinit);
1647f42a358aSRandall Stewart 		stcb->asoc.timoinit++;
1648f8829a4aSRandall Stewart 		if (sctp_t1init_timer(inp, stcb, net)) {
1649f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1650f8829a4aSRandall Stewart 			goto out_decr;
1651f8829a4aSRandall Stewart 		}
1652f8829a4aSRandall Stewart 		/* We do output but not here */
1653f8829a4aSRandall Stewart 		did_output = 0;
1654f8829a4aSRandall Stewart 		break;
1655f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
1656ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1657ad81507eSRandall Stewart 			break;
1658c4739e2fSRandall Stewart 		} {
1659c4739e2fSRandall Stewart 			int abort_flag;
1660c4739e2fSRandall Stewart 
1661f8829a4aSRandall Stewart 			SCTP_STAT_INCR(sctps_timosack);
1662f42a358aSRandall Stewart 			stcb->asoc.timosack++;
1663c4739e2fSRandall Stewart 			if (stcb->asoc.cumulative_tsn != stcb->asoc.highest_tsn_inside_map)
1664c4739e2fSRandall Stewart 				sctp_sack_check(stcb, 0, 0, &abort_flag);
1665830d754dSRandall Stewart 
1666830d754dSRandall Stewart 			/*
1667830d754dSRandall Stewart 			 * EY if nr_sacks used then send an nr-sack , a sack
1668830d754dSRandall Stewart 			 * otherwise
1669830d754dSRandall Stewart 			 */
1670830d754dSRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_nr_sack_on_off) && stcb->asoc.peer_supports_nr_sack)
1671830d754dSRandall Stewart 				sctp_send_nr_sack(stcb);
1672830d754dSRandall Stewart 			else
1673f8829a4aSRandall Stewart 				sctp_send_sack(stcb);
1674c4739e2fSRandall Stewart 		}
1675f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1676f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1677f8829a4aSRandall Stewart #endif
1678ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SACK_TMR, SCTP_SO_NOT_LOCKED);
1679f8829a4aSRandall Stewart 		break;
1680f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
1681ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1682ad81507eSRandall Stewart 			break;
1683ad81507eSRandall Stewart 		}
1684f8829a4aSRandall Stewart 		if (sctp_shutdown_timer(inp, stcb, net)) {
1685f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1686f8829a4aSRandall Stewart 			goto out_decr;
1687f8829a4aSRandall Stewart 		}
1688f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoshutdown);
1689f42a358aSRandall Stewart 		stcb->asoc.timoshutdown++;
1690f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1691f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1692f8829a4aSRandall Stewart #endif
1693ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SHUT_TMR, SCTP_SO_NOT_LOCKED);
1694f8829a4aSRandall Stewart 		break;
1695f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
1696f8829a4aSRandall Stewart 		{
16974c9179adSRandall Stewart 			struct sctp_nets *lnet;
1698f8829a4aSRandall Stewart 			int cnt_of_unconf = 0;
1699f8829a4aSRandall Stewart 
1700ad81507eSRandall Stewart 			if ((stcb == NULL) || (inp == NULL)) {
1701ad81507eSRandall Stewart 				break;
1702ad81507eSRandall Stewart 			}
1703f8829a4aSRandall Stewart 			SCTP_STAT_INCR(sctps_timoheartbeat);
1704f42a358aSRandall Stewart 			stcb->asoc.timoheartbeat++;
17054c9179adSRandall Stewart 			TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
17064c9179adSRandall Stewart 				if ((lnet->dest_state & SCTP_ADDR_UNCONFIRMED) &&
17074c9179adSRandall Stewart 				    (lnet->dest_state & SCTP_ADDR_REACHABLE)) {
1708f8829a4aSRandall Stewart 					cnt_of_unconf++;
1709f8829a4aSRandall Stewart 				}
1710f8829a4aSRandall Stewart 			}
1711f8829a4aSRandall Stewart 			if (cnt_of_unconf == 0) {
17124c9179adSRandall Stewart 				if (sctp_heartbeat_timer(inp, stcb, lnet,
17134c9179adSRandall Stewart 				    cnt_of_unconf)) {
1714f8829a4aSRandall Stewart 					/* no need to unlock on tcb its gone */
1715f8829a4aSRandall Stewart 					goto out_decr;
1716f8829a4aSRandall Stewart 				}
1717f8829a4aSRandall Stewart 			}
1718f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
17194c9179adSRandall Stewart 			sctp_auditing(4, inp, stcb, lnet);
1720f8829a4aSRandall Stewart #endif
17214c9179adSRandall Stewart 			sctp_timer_start(SCTP_TIMER_TYPE_HEARTBEAT,
17224c9179adSRandall Stewart 			    stcb->sctp_ep, stcb, lnet);
1723ceaad40aSRandall Stewart 			sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_HB_TMR, SCTP_SO_NOT_LOCKED);
1724f8829a4aSRandall Stewart 		}
1725f8829a4aSRandall Stewart 		break;
1726f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
1727ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1728ad81507eSRandall Stewart 			break;
1729ad81507eSRandall Stewart 		}
1730f8829a4aSRandall Stewart 		if (sctp_cookie_timer(inp, stcb, net)) {
1731f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1732f8829a4aSRandall Stewart 			goto out_decr;
1733f8829a4aSRandall Stewart 		}
1734f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timocookie);
1735f42a358aSRandall Stewart 		stcb->asoc.timocookie++;
1736f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1737f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1738f8829a4aSRandall Stewart #endif
1739f8829a4aSRandall Stewart 		/*
1740f8829a4aSRandall Stewart 		 * We consider T3 and Cookie timer pretty much the same with
1741f8829a4aSRandall Stewart 		 * respect to where from in chunk_output.
1742f8829a4aSRandall Stewart 		 */
1743ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
1744f8829a4aSRandall Stewart 		break;
1745f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
1746f8829a4aSRandall Stewart 		{
1747f8829a4aSRandall Stewart 			struct timeval tv;
1748f8829a4aSRandall Stewart 			int i, secret;
1749f8829a4aSRandall Stewart 
1750ad81507eSRandall Stewart 			if (inp == NULL) {
1751ad81507eSRandall Stewart 				break;
1752ad81507eSRandall Stewart 			}
1753f8829a4aSRandall Stewart 			SCTP_STAT_INCR(sctps_timosecret);
17546e55db54SRandall Stewart 			(void)SCTP_GETTIME_TIMEVAL(&tv);
1755f8829a4aSRandall Stewart 			SCTP_INP_WLOCK(inp);
1756f8829a4aSRandall Stewart 			inp->sctp_ep.time_of_secret_change = tv.tv_sec;
1757f8829a4aSRandall Stewart 			inp->sctp_ep.last_secret_number =
1758f8829a4aSRandall Stewart 			    inp->sctp_ep.current_secret_number;
1759f8829a4aSRandall Stewart 			inp->sctp_ep.current_secret_number++;
1760f8829a4aSRandall Stewart 			if (inp->sctp_ep.current_secret_number >=
1761f8829a4aSRandall Stewart 			    SCTP_HOW_MANY_SECRETS) {
1762f8829a4aSRandall Stewart 				inp->sctp_ep.current_secret_number = 0;
1763f8829a4aSRandall Stewart 			}
1764f8829a4aSRandall Stewart 			secret = (int)inp->sctp_ep.current_secret_number;
1765f8829a4aSRandall Stewart 			for (i = 0; i < SCTP_NUMBER_OF_SECRETS; i++) {
1766f8829a4aSRandall Stewart 				inp->sctp_ep.secret_key[secret][i] =
1767f8829a4aSRandall Stewart 				    sctp_select_initial_TSN(&inp->sctp_ep);
1768f8829a4aSRandall Stewart 			}
1769f8829a4aSRandall Stewart 			SCTP_INP_WUNLOCK(inp);
1770f8829a4aSRandall Stewart 			sctp_timer_start(SCTP_TIMER_TYPE_NEWCOOKIE, inp, stcb, net);
1771f8829a4aSRandall Stewart 		}
1772f8829a4aSRandall Stewart 		did_output = 0;
1773f8829a4aSRandall Stewart 		break;
1774f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
1775ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1776ad81507eSRandall Stewart 			break;
1777ad81507eSRandall Stewart 		}
1778f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timopathmtu);
1779f8829a4aSRandall Stewart 		sctp_pathmtu_timer(inp, stcb, net);
1780f8829a4aSRandall Stewart 		did_output = 0;
1781f8829a4aSRandall Stewart 		break;
1782f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
1783ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1784ad81507eSRandall Stewart 			break;
1785ad81507eSRandall Stewart 		}
1786f8829a4aSRandall Stewart 		if (sctp_shutdownack_timer(inp, stcb, net)) {
1787f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1788f8829a4aSRandall Stewart 			goto out_decr;
1789f8829a4aSRandall Stewart 		}
1790f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoshutdownack);
1791f42a358aSRandall Stewart 		stcb->asoc.timoshutdownack++;
1792f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1793f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1794f8829a4aSRandall Stewart #endif
1795ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SHUT_ACK_TMR, SCTP_SO_NOT_LOCKED);
1796f8829a4aSRandall Stewart 		break;
1797f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
1798ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1799ad81507eSRandall Stewart 			break;
1800ad81507eSRandall Stewart 		}
1801f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoshutdownguard);
1802f8829a4aSRandall Stewart 		sctp_abort_an_association(inp, stcb,
1803ceaad40aSRandall Stewart 		    SCTP_SHUTDOWN_GUARD_EXPIRES, NULL, SCTP_SO_NOT_LOCKED);
1804f8829a4aSRandall Stewart 		/* no need to unlock on tcb its gone */
1805f8829a4aSRandall Stewart 		goto out_decr;
1806f8829a4aSRandall Stewart 
1807f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_STRRESET:
1808ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1809ad81507eSRandall Stewart 			break;
1810ad81507eSRandall Stewart 		}
1811f8829a4aSRandall Stewart 		if (sctp_strreset_timer(inp, stcb, net)) {
1812f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1813f8829a4aSRandall Stewart 			goto out_decr;
1814f8829a4aSRandall Stewart 		}
1815f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timostrmrst);
1816ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_STRRST_TMR, SCTP_SO_NOT_LOCKED);
1817f8829a4aSRandall Stewart 		break;
1818f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_EARLYFR:
1819f8829a4aSRandall Stewart 		/* Need to do FR of things for net */
1820ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1821ad81507eSRandall Stewart 			break;
1822ad81507eSRandall Stewart 		}
1823f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoearlyfr);
1824f8829a4aSRandall Stewart 		sctp_early_fr_timer(inp, stcb, net);
1825f8829a4aSRandall Stewart 		break;
1826f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASCONF:
1827ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1828ad81507eSRandall Stewart 			break;
1829ad81507eSRandall Stewart 		}
1830f8829a4aSRandall Stewart 		if (sctp_asconf_timer(inp, stcb, net)) {
1831f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1832f8829a4aSRandall Stewart 			goto out_decr;
1833f8829a4aSRandall Stewart 		}
1834f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoasconf);
1835f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1836f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1837f8829a4aSRandall Stewart #endif
1838ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_ASCONF_TMR, SCTP_SO_NOT_LOCKED);
1839f8829a4aSRandall Stewart 		break;
1840851b7298SRandall Stewart 	case SCTP_TIMER_TYPE_PRIM_DELETED:
1841851b7298SRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1842851b7298SRandall Stewart 			break;
1843851b7298SRandall Stewart 		}
184404ee05e8SRandall Stewart 		sctp_delete_prim_timer(inp, stcb, net);
1845851b7298SRandall Stewart 		SCTP_STAT_INCR(sctps_timodelprim);
1846851b7298SRandall Stewart 		break;
1847f8829a4aSRandall Stewart 
1848f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_AUTOCLOSE:
1849ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1850ad81507eSRandall Stewart 			break;
1851ad81507eSRandall Stewart 		}
1852f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoautoclose);
1853f8829a4aSRandall Stewart 		sctp_autoclose_timer(inp, stcb, net);
1854ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_AUTOCLOSE_TMR, SCTP_SO_NOT_LOCKED);
1855f8829a4aSRandall Stewart 		did_output = 0;
1856f8829a4aSRandall Stewart 		break;
1857f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASOCKILL:
1858ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1859ad81507eSRandall Stewart 			break;
1860ad81507eSRandall Stewart 		}
1861f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoassockill);
1862f8829a4aSRandall Stewart 		/* Can we free it yet? */
1863f8829a4aSRandall Stewart 		SCTP_INP_DECR_REF(inp);
1864a5d547adSRandall Stewart 		sctp_timer_stop(SCTP_TIMER_TYPE_ASOCKILL, inp, stcb, NULL, SCTP_FROM_SCTPUTIL + SCTP_LOC_1);
1865ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
1866ceaad40aSRandall Stewart 		so = SCTP_INP_SO(inp);
1867ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
1868ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
1869ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
1870ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
1871ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
1872ceaad40aSRandall Stewart #endif
1873c4739e2fSRandall Stewart 		(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC, SCTP_FROM_SCTPUTIL + SCTP_LOC_2);
1874ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
1875ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
1876ceaad40aSRandall Stewart #endif
1877f8829a4aSRandall Stewart 		/*
1878f8829a4aSRandall Stewart 		 * free asoc, always unlocks (or destroy's) so prevent
1879f8829a4aSRandall Stewart 		 * duplicate unlock or unlock of a free mtx :-0
1880f8829a4aSRandall Stewart 		 */
1881f8829a4aSRandall Stewart 		stcb = NULL;
1882f8829a4aSRandall Stewart 		goto out_no_decr;
1883f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INPKILL:
1884f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoinpkill);
1885ad81507eSRandall Stewart 		if (inp == NULL) {
1886ad81507eSRandall Stewart 			break;
1887ad81507eSRandall Stewart 		}
1888f8829a4aSRandall Stewart 		/*
1889f8829a4aSRandall Stewart 		 * special case, take away our increment since WE are the
1890f8829a4aSRandall Stewart 		 * killer
1891f8829a4aSRandall Stewart 		 */
1892f8829a4aSRandall Stewart 		SCTP_INP_DECR_REF(inp);
1893a5d547adSRandall Stewart 		sctp_timer_stop(SCTP_TIMER_TYPE_INPKILL, inp, NULL, NULL, SCTP_FROM_SCTPUTIL + SCTP_LOC_3);
1894b0552ae2SRandall Stewart 		sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
1895b0552ae2SRandall Stewart 		    SCTP_CALLED_DIRECTLY_NOCMPSET);
1896d61374e1SRandall Stewart 		inp = NULL;
1897f8829a4aSRandall Stewart 		goto out_no_decr;
1898f8829a4aSRandall Stewart 	default:
1899ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_TIMER1, "sctp_timeout_handler:unknown timer %d\n",
1900f8829a4aSRandall Stewart 		    tmr->type);
1901f8829a4aSRandall Stewart 		break;
1902f8829a4aSRandall Stewart 	};
1903f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1904f8829a4aSRandall Stewart 	sctp_audit_log(0xF1, (uint8_t) tmr->type);
1905f8829a4aSRandall Stewart 	if (inp)
1906f8829a4aSRandall Stewart 		sctp_auditing(5, inp, stcb, net);
1907f8829a4aSRandall Stewart #endif
1908f8829a4aSRandall Stewart 	if ((did_output) && stcb) {
1909f8829a4aSRandall Stewart 		/*
1910f8829a4aSRandall Stewart 		 * Now we need to clean up the control chunk chain if an
1911f8829a4aSRandall Stewart 		 * ECNE is on it. It must be marked as UNSENT again so next
1912f8829a4aSRandall Stewart 		 * call will continue to send it until such time that we get
1913f8829a4aSRandall Stewart 		 * a CWR, to remove it. It is, however, less likely that we
1914f8829a4aSRandall Stewart 		 * will find a ecn echo on the chain though.
1915f8829a4aSRandall Stewart 		 */
1916f8829a4aSRandall Stewart 		sctp_fix_ecn_echo(&stcb->asoc);
1917f8829a4aSRandall Stewart 	}
191844b7479bSRandall Stewart get_out:
1919f8829a4aSRandall Stewart 	if (stcb) {
1920f8829a4aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
1921f8829a4aSRandall Stewart 	}
1922f8829a4aSRandall Stewart out_decr:
1923f8829a4aSRandall Stewart 	if (inp) {
1924f8829a4aSRandall Stewart 		SCTP_INP_DECR_REF(inp);
1925f8829a4aSRandall Stewart 	}
1926f8829a4aSRandall Stewart out_no_decr:
1927ad81507eSRandall Stewart 	SCTPDBG(SCTP_DEBUG_TIMER1, "Timer now complete (type %d)\n",
1928d61374e1SRandall Stewart 	    type);
1929f8829a4aSRandall Stewart }
1930f8829a4aSRandall Stewart 
1931ad81507eSRandall Stewart void
1932f8829a4aSRandall Stewart sctp_timer_start(int t_type, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
1933f8829a4aSRandall Stewart     struct sctp_nets *net)
1934f8829a4aSRandall Stewart {
1935f8829a4aSRandall Stewart 	int to_ticks;
1936f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
1937f8829a4aSRandall Stewart 
1938139bc87fSRandall Stewart 	if ((t_type != SCTP_TIMER_TYPE_ADDR_WQ) && (inp == NULL))
1939ad81507eSRandall Stewart 		return;
1940f8829a4aSRandall Stewart 
1941f8829a4aSRandall Stewart 	to_ticks = 0;
1942f8829a4aSRandall Stewart 
1943f8829a4aSRandall Stewart 	tmr = NULL;
1944f8829a4aSRandall Stewart 	if (stcb) {
1945f8829a4aSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
1946f8829a4aSRandall Stewart 	}
1947f8829a4aSRandall Stewart 	switch (t_type) {
1948d61a0ae0SRandall Stewart 	case SCTP_TIMER_TYPE_ZERO_COPY:
1949d61a0ae0SRandall Stewart 		tmr = &inp->sctp_ep.zero_copy_timer;
1950d61a0ae0SRandall Stewart 		to_ticks = SCTP_ZERO_COPY_TICK_DELAY;
1951d61a0ae0SRandall Stewart 		break;
1952ad21a364SRandall Stewart 	case SCTP_TIMER_TYPE_ZCOPY_SENDQ:
1953ad21a364SRandall Stewart 		tmr = &inp->sctp_ep.zero_copy_sendq_timer;
1954ad21a364SRandall Stewart 		to_ticks = SCTP_ZERO_COPY_SENDQ_TICK_DELAY;
1955ad21a364SRandall Stewart 		break;
1956f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ADDR_WQ:
1957f8829a4aSRandall Stewart 		/* Only 1 tick away :-) */
1958b3f1ea41SRandall Stewart 		tmr = &SCTP_BASE_INFO(addr_wq_timer);
195942551e99SRandall Stewart 		to_ticks = SCTP_ADDRESS_TICK_DELAY;
1960f8829a4aSRandall Stewart 		break;
1961f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ITERATOR:
1962f8829a4aSRandall Stewart 		{
1963f8829a4aSRandall Stewart 			struct sctp_iterator *it;
1964f8829a4aSRandall Stewart 
1965f8829a4aSRandall Stewart 			it = (struct sctp_iterator *)inp;
1966f8829a4aSRandall Stewart 			tmr = &it->tmr;
1967f8829a4aSRandall Stewart 			to_ticks = SCTP_ITERATOR_TICKS;
1968f8829a4aSRandall Stewart 		}
1969f8829a4aSRandall Stewart 		break;
1970f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
1971f8829a4aSRandall Stewart 		/* Here we use the RTO timer */
1972f8829a4aSRandall Stewart 		{
1973f8829a4aSRandall Stewart 			int rto_val;
1974f8829a4aSRandall Stewart 
1975f8829a4aSRandall Stewart 			if ((stcb == NULL) || (net == NULL)) {
1976ad81507eSRandall Stewart 				return;
1977f8829a4aSRandall Stewart 			}
1978f8829a4aSRandall Stewart 			tmr = &net->rxt_timer;
1979f8829a4aSRandall Stewart 			if (net->RTO == 0) {
1980f8829a4aSRandall Stewart 				rto_val = stcb->asoc.initial_rto;
1981f8829a4aSRandall Stewart 			} else {
1982f8829a4aSRandall Stewart 				rto_val = net->RTO;
1983f8829a4aSRandall Stewart 			}
1984f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(rto_val);
1985f8829a4aSRandall Stewart 		}
1986f8829a4aSRandall Stewart 		break;
1987f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
1988f8829a4aSRandall Stewart 		/*
1989f8829a4aSRandall Stewart 		 * Here we use the INIT timer default usually about 1
1990f8829a4aSRandall Stewart 		 * minute.
1991f8829a4aSRandall Stewart 		 */
1992f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
1993ad81507eSRandall Stewart 			return;
1994f8829a4aSRandall Stewart 		}
1995f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
1996f8829a4aSRandall Stewart 		if (net->RTO == 0) {
1997f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
1998f8829a4aSRandall Stewart 		} else {
1999f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2000f8829a4aSRandall Stewart 		}
2001f8829a4aSRandall Stewart 		break;
2002f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
2003f8829a4aSRandall Stewart 		/*
2004f8829a4aSRandall Stewart 		 * Here we use the Delayed-Ack timer value from the inp
2005f8829a4aSRandall Stewart 		 * ususually about 200ms.
2006f8829a4aSRandall Stewart 		 */
2007f8829a4aSRandall Stewart 		if (stcb == NULL) {
2008ad81507eSRandall Stewart 			return;
2009f8829a4aSRandall Stewart 		}
2010f8829a4aSRandall Stewart 		tmr = &stcb->asoc.dack_timer;
2011f8829a4aSRandall Stewart 		to_ticks = MSEC_TO_TICKS(stcb->asoc.delayed_ack);
2012f8829a4aSRandall Stewart 		break;
2013f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
2014f8829a4aSRandall Stewart 		/* Here we use the RTO of the destination. */
2015f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2016ad81507eSRandall Stewart 			return;
2017f8829a4aSRandall Stewart 		}
2018f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2019f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2020f8829a4aSRandall Stewart 		} else {
2021f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2022f8829a4aSRandall Stewart 		}
2023f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2024f8829a4aSRandall Stewart 		break;
2025f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
2026f8829a4aSRandall Stewart 		/*
2027f8829a4aSRandall Stewart 		 * the net is used here so that we can add in the RTO. Even
2028f8829a4aSRandall Stewart 		 * though we use a different timer. We also add the HB timer
2029f8829a4aSRandall Stewart 		 * PLUS a random jitter.
2030f8829a4aSRandall Stewart 		 */
2031ad81507eSRandall Stewart 		if ((inp == NULL) || (stcb == NULL)) {
2032ad81507eSRandall Stewart 			return;
2033ad81507eSRandall Stewart 		} else {
2034f8829a4aSRandall Stewart 			uint32_t rndval;
2035f8829a4aSRandall Stewart 			uint8_t this_random;
2036f8829a4aSRandall Stewart 			int cnt_of_unconf = 0;
2037f8829a4aSRandall Stewart 			struct sctp_nets *lnet;
2038f8829a4aSRandall Stewart 
2039f8829a4aSRandall Stewart 			TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
2040f8829a4aSRandall Stewart 				if ((lnet->dest_state & SCTP_ADDR_UNCONFIRMED) &&
2041f8829a4aSRandall Stewart 				    (lnet->dest_state & SCTP_ADDR_REACHABLE)) {
2042f8829a4aSRandall Stewart 					cnt_of_unconf++;
2043f8829a4aSRandall Stewart 				}
2044f8829a4aSRandall Stewart 			}
2045f8829a4aSRandall Stewart 			if (cnt_of_unconf) {
20463c503c28SRandall Stewart 				net = lnet = NULL;
2047ad81507eSRandall Stewart 				(void)sctp_heartbeat_timer(inp, stcb, lnet, cnt_of_unconf);
2048f8829a4aSRandall Stewart 			}
2049f8829a4aSRandall Stewart 			if (stcb->asoc.hb_random_idx > 3) {
2050f8829a4aSRandall Stewart 				rndval = sctp_select_initial_TSN(&inp->sctp_ep);
2051f8829a4aSRandall Stewart 				memcpy(stcb->asoc.hb_random_values, &rndval,
2052f8829a4aSRandall Stewart 				    sizeof(stcb->asoc.hb_random_values));
2053f8829a4aSRandall Stewart 				stcb->asoc.hb_random_idx = 0;
205442551e99SRandall Stewart 			}
2055f8829a4aSRandall Stewart 			this_random = stcb->asoc.hb_random_values[stcb->asoc.hb_random_idx];
2056f8829a4aSRandall Stewart 			stcb->asoc.hb_random_idx++;
2057f8829a4aSRandall Stewart 			stcb->asoc.hb_ect_randombit = 0;
2058f8829a4aSRandall Stewart 			/*
2059f8829a4aSRandall Stewart 			 * this_random will be 0 - 256 ms RTO is in ms.
2060f8829a4aSRandall Stewart 			 */
2061f8829a4aSRandall Stewart 			if ((stcb->asoc.hb_is_disabled) &&
2062f8829a4aSRandall Stewart 			    (cnt_of_unconf == 0)) {
2063ad81507eSRandall Stewart 				return;
2064f8829a4aSRandall Stewart 			}
2065f8829a4aSRandall Stewart 			if (net) {
2066f8829a4aSRandall Stewart 				int delay;
2067f8829a4aSRandall Stewart 
2068f8829a4aSRandall Stewart 				delay = stcb->asoc.heart_beat_delay;
2069f8829a4aSRandall Stewart 				TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
2070f8829a4aSRandall Stewart 					if ((lnet->dest_state & SCTP_ADDR_UNCONFIRMED) &&
2071f8829a4aSRandall Stewart 					    ((lnet->dest_state & SCTP_ADDR_OUT_OF_SCOPE) == 0) &&
2072f8829a4aSRandall Stewart 					    (lnet->dest_state & SCTP_ADDR_REACHABLE)) {
2073f8829a4aSRandall Stewart 						delay = 0;
2074f8829a4aSRandall Stewart 					}
2075f8829a4aSRandall Stewart 				}
2076f8829a4aSRandall Stewart 				if (net->RTO == 0) {
2077f8829a4aSRandall Stewart 					/* Never been checked */
2078f8829a4aSRandall Stewart 					to_ticks = this_random + stcb->asoc.initial_rto + delay;
2079f8829a4aSRandall Stewart 				} else {
2080f8829a4aSRandall Stewart 					/* set rto_val to the ms */
2081f8829a4aSRandall Stewart 					to_ticks = delay + net->RTO + this_random;
2082f8829a4aSRandall Stewart 				}
2083f8829a4aSRandall Stewart 			} else {
2084f8829a4aSRandall Stewart 				if (cnt_of_unconf) {
2085f8829a4aSRandall Stewart 					to_ticks = this_random + stcb->asoc.initial_rto;
2086f8829a4aSRandall Stewart 				} else {
2087f8829a4aSRandall Stewart 					to_ticks = stcb->asoc.heart_beat_delay + this_random + stcb->asoc.initial_rto;
2088f8829a4aSRandall Stewart 				}
2089f8829a4aSRandall Stewart 			}
2090f8829a4aSRandall Stewart 			/*
2091f8829a4aSRandall Stewart 			 * Now we must convert the to_ticks that are now in
2092f8829a4aSRandall Stewart 			 * ms to ticks.
2093f8829a4aSRandall Stewart 			 */
2094f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(to_ticks);
2095f8829a4aSRandall Stewart 			tmr = &stcb->asoc.hb_timer;
2096f8829a4aSRandall Stewart 		}
2097f8829a4aSRandall Stewart 		break;
2098f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
2099f8829a4aSRandall Stewart 		/*
2100f8829a4aSRandall Stewart 		 * Here we can use the RTO timer from the network since one
2101f8829a4aSRandall Stewart 		 * RTT was compelete. If a retran happened then we will be
2102f8829a4aSRandall Stewart 		 * using the RTO initial value.
2103f8829a4aSRandall Stewart 		 */
2104f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2105ad81507eSRandall Stewart 			return;
2106f8829a4aSRandall Stewart 		}
2107f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2108f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2109f8829a4aSRandall Stewart 		} else {
2110f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2111f8829a4aSRandall Stewart 		}
2112f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2113f8829a4aSRandall Stewart 		break;
2114f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
2115f8829a4aSRandall Stewart 		/*
2116f8829a4aSRandall Stewart 		 * nothing needed but the endpoint here ususually about 60
2117f8829a4aSRandall Stewart 		 * minutes.
2118f8829a4aSRandall Stewart 		 */
2119ad81507eSRandall Stewart 		if (inp == NULL) {
2120ad81507eSRandall Stewart 			return;
2121ad81507eSRandall Stewart 		}
2122f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2123f8829a4aSRandall Stewart 		to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_SIGNATURE];
2124f8829a4aSRandall Stewart 		break;
2125f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASOCKILL:
2126f8829a4aSRandall Stewart 		if (stcb == NULL) {
2127ad81507eSRandall Stewart 			return;
2128f8829a4aSRandall Stewart 		}
2129f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2130f8829a4aSRandall Stewart 		to_ticks = MSEC_TO_TICKS(SCTP_ASOC_KILL_TIMEOUT);
2131f8829a4aSRandall Stewart 		break;
2132f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INPKILL:
2133f8829a4aSRandall Stewart 		/*
2134f8829a4aSRandall Stewart 		 * The inp is setup to die. We re-use the signature_chage
2135f8829a4aSRandall Stewart 		 * timer since that has stopped and we are in the GONE
2136f8829a4aSRandall Stewart 		 * state.
2137f8829a4aSRandall Stewart 		 */
2138ad81507eSRandall Stewart 		if (inp == NULL) {
2139ad81507eSRandall Stewart 			return;
2140ad81507eSRandall Stewart 		}
2141f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2142f8829a4aSRandall Stewart 		to_ticks = MSEC_TO_TICKS(SCTP_INP_KILL_TIMEOUT);
2143f8829a4aSRandall Stewart 		break;
2144f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
2145f8829a4aSRandall Stewart 		/*
2146f8829a4aSRandall Stewart 		 * Here we use the value found in the EP for PMTU ususually
2147f8829a4aSRandall Stewart 		 * about 10 minutes.
2148f8829a4aSRandall Stewart 		 */
2149ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
2150ad81507eSRandall Stewart 			return;
2151f8829a4aSRandall Stewart 		}
2152f8829a4aSRandall Stewart 		if (net == NULL) {
2153ad81507eSRandall Stewart 			return;
2154f8829a4aSRandall Stewart 		}
2155f8829a4aSRandall Stewart 		to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_PMTU];
2156f8829a4aSRandall Stewart 		tmr = &net->pmtu_timer;
2157f8829a4aSRandall Stewart 		break;
2158f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
2159f8829a4aSRandall Stewart 		/* Here we use the RTO of the destination */
2160f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2161ad81507eSRandall Stewart 			return;
2162f8829a4aSRandall Stewart 		}
2163f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2164f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2165f8829a4aSRandall Stewart 		} else {
2166f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2167f8829a4aSRandall Stewart 		}
2168f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2169f8829a4aSRandall Stewart 		break;
2170f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
2171f8829a4aSRandall Stewart 		/*
2172f8829a4aSRandall Stewart 		 * Here we use the endpoints shutdown guard timer usually
2173f8829a4aSRandall Stewart 		 * about 3 minutes.
2174f8829a4aSRandall Stewart 		 */
2175ad81507eSRandall Stewart 		if ((inp == NULL) || (stcb == NULL)) {
2176ad81507eSRandall Stewart 			return;
2177f8829a4aSRandall Stewart 		}
2178f8829a4aSRandall Stewart 		to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_MAXSHUTDOWN];
2179f8829a4aSRandall Stewart 		tmr = &stcb->asoc.shut_guard_timer;
2180f8829a4aSRandall Stewart 		break;
2181f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_STRRESET:
2182f8829a4aSRandall Stewart 		/*
21831b649582SRandall Stewart 		 * Here the timer comes from the stcb but its value is from
21841b649582SRandall Stewart 		 * the net's RTO.
2185f8829a4aSRandall Stewart 		 */
2186f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2187ad81507eSRandall Stewart 			return;
2188f8829a4aSRandall Stewart 		}
2189f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2190f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2191f8829a4aSRandall Stewart 		} else {
2192f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2193f8829a4aSRandall Stewart 		}
2194f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2195f8829a4aSRandall Stewart 		break;
2196f8829a4aSRandall Stewart 
2197f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_EARLYFR:
2198f8829a4aSRandall Stewart 		{
2199f8829a4aSRandall Stewart 			unsigned int msec;
2200f8829a4aSRandall Stewart 
2201f8829a4aSRandall Stewart 			if ((stcb == NULL) || (net == NULL)) {
2202ad81507eSRandall Stewart 				return;
2203f8829a4aSRandall Stewart 			}
2204f8829a4aSRandall Stewart 			if (net->flight_size > net->cwnd) {
2205f8829a4aSRandall Stewart 				/* no need to start */
2206ad81507eSRandall Stewart 				return;
2207f8829a4aSRandall Stewart 			}
2208f8829a4aSRandall Stewart 			SCTP_STAT_INCR(sctps_earlyfrstart);
2209f8829a4aSRandall Stewart 			if (net->lastsa == 0) {
2210f8829a4aSRandall Stewart 				/* Hmm no rtt estimate yet? */
2211f8829a4aSRandall Stewart 				msec = stcb->asoc.initial_rto >> 2;
2212f8829a4aSRandall Stewart 			} else {
2213f8829a4aSRandall Stewart 				msec = ((net->lastsa >> 2) + net->lastsv) >> 1;
2214f8829a4aSRandall Stewart 			}
2215b3f1ea41SRandall Stewart 			if (msec < SCTP_BASE_SYSCTL(sctp_early_fr_msec)) {
2216b3f1ea41SRandall Stewart 				msec = SCTP_BASE_SYSCTL(sctp_early_fr_msec);
2217f8829a4aSRandall Stewart 				if (msec < SCTP_MINFR_MSEC_FLOOR) {
2218f8829a4aSRandall Stewart 					msec = SCTP_MINFR_MSEC_FLOOR;
2219f8829a4aSRandall Stewart 				}
2220f8829a4aSRandall Stewart 			}
2221f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(msec);
2222f8829a4aSRandall Stewart 			tmr = &net->fr_timer;
2223f8829a4aSRandall Stewart 		}
2224f8829a4aSRandall Stewart 		break;
2225f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASCONF:
2226f8829a4aSRandall Stewart 		/*
22271b649582SRandall Stewart 		 * Here the timer comes from the stcb but its value is from
22281b649582SRandall Stewart 		 * the net's RTO.
2229f8829a4aSRandall Stewart 		 */
2230f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2231ad81507eSRandall Stewart 			return;
2232f8829a4aSRandall Stewart 		}
2233f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2234f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2235f8829a4aSRandall Stewart 		} else {
2236f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2237f8829a4aSRandall Stewart 		}
2238f8829a4aSRandall Stewart 		tmr = &stcb->asoc.asconf_timer;
2239f8829a4aSRandall Stewart 		break;
2240851b7298SRandall Stewart 	case SCTP_TIMER_TYPE_PRIM_DELETED:
2241851b7298SRandall Stewart 		if ((stcb == NULL) || (net != NULL)) {
2242851b7298SRandall Stewart 			return;
2243851b7298SRandall Stewart 		}
2244851b7298SRandall Stewart 		to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2245851b7298SRandall Stewart 		tmr = &stcb->asoc.delete_prim_timer;
2246851b7298SRandall Stewart 		break;
2247f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_AUTOCLOSE:
2248f8829a4aSRandall Stewart 		if (stcb == NULL) {
2249ad81507eSRandall Stewart 			return;
2250f8829a4aSRandall Stewart 		}
2251f8829a4aSRandall Stewart 		if (stcb->asoc.sctp_autoclose_ticks == 0) {
2252f8829a4aSRandall Stewart 			/*
2253f8829a4aSRandall Stewart 			 * Really an error since stcb is NOT set to
2254f8829a4aSRandall Stewart 			 * autoclose
2255f8829a4aSRandall Stewart 			 */
2256ad81507eSRandall Stewart 			return;
2257f8829a4aSRandall Stewart 		}
2258f8829a4aSRandall Stewart 		to_ticks = stcb->asoc.sctp_autoclose_ticks;
2259f8829a4aSRandall Stewart 		tmr = &stcb->asoc.autoclose_timer;
2260f8829a4aSRandall Stewart 		break;
2261f8829a4aSRandall Stewart 	default:
2262ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_TIMER1, "%s: Unknown timer type %d\n",
2263ad81507eSRandall Stewart 		    __FUNCTION__, t_type);
2264ad81507eSRandall Stewart 		return;
2265f8829a4aSRandall Stewart 		break;
2266f8829a4aSRandall Stewart 	};
2267f8829a4aSRandall Stewart 	if ((to_ticks <= 0) || (tmr == NULL)) {
2268ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_TIMER1, "%s: %d:software error to_ticks:%d tmr:%p not set ??\n",
2269ad81507eSRandall Stewart 		    __FUNCTION__, t_type, to_ticks, tmr);
2270ad81507eSRandall Stewart 		return;
2271f8829a4aSRandall Stewart 	}
2272139bc87fSRandall Stewart 	if (SCTP_OS_TIMER_PENDING(&tmr->timer)) {
2273f8829a4aSRandall Stewart 		/*
2274f8829a4aSRandall Stewart 		 * we do NOT allow you to have it already running. if it is
2275f8829a4aSRandall Stewart 		 * we leave the current one up unchanged
2276f8829a4aSRandall Stewart 		 */
2277ad81507eSRandall Stewart 		return;
2278f8829a4aSRandall Stewart 	}
2279f8829a4aSRandall Stewart 	/* At this point we can proceed */
2280f8829a4aSRandall Stewart 	if (t_type == SCTP_TIMER_TYPE_SEND) {
2281f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up++;
2282f8829a4aSRandall Stewart 	}
2283a5d547adSRandall Stewart 	tmr->stopped_from = 0;
2284f8829a4aSRandall Stewart 	tmr->type = t_type;
2285f8829a4aSRandall Stewart 	tmr->ep = (void *)inp;
2286f8829a4aSRandall Stewart 	tmr->tcb = (void *)stcb;
2287f8829a4aSRandall Stewart 	tmr->net = (void *)net;
2288f8829a4aSRandall Stewart 	tmr->self = (void *)tmr;
2289c4739e2fSRandall Stewart 	tmr->ticks = sctp_get_tick_count();
2290ad81507eSRandall Stewart 	(void)SCTP_OS_TIMER_START(&tmr->timer, to_ticks, sctp_timeout_handler, tmr);
2291ad81507eSRandall Stewart 	return;
2292f8829a4aSRandall Stewart }
2293f8829a4aSRandall Stewart 
22946e55db54SRandall Stewart void
2295f8829a4aSRandall Stewart sctp_timer_stop(int t_type, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
2296a5d547adSRandall Stewart     struct sctp_nets *net, uint32_t from)
2297f8829a4aSRandall Stewart {
2298f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
2299f8829a4aSRandall Stewart 
2300f8829a4aSRandall Stewart 	if ((t_type != SCTP_TIMER_TYPE_ADDR_WQ) &&
2301f8829a4aSRandall Stewart 	    (inp == NULL))
23026e55db54SRandall Stewart 		return;
2303f8829a4aSRandall Stewart 
2304f8829a4aSRandall Stewart 	tmr = NULL;
2305f8829a4aSRandall Stewart 	if (stcb) {
2306f8829a4aSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
2307f8829a4aSRandall Stewart 	}
2308f8829a4aSRandall Stewart 	switch (t_type) {
2309d61a0ae0SRandall Stewart 	case SCTP_TIMER_TYPE_ZERO_COPY:
2310d61a0ae0SRandall Stewart 		tmr = &inp->sctp_ep.zero_copy_timer;
2311d61a0ae0SRandall Stewart 		break;
2312ad21a364SRandall Stewart 	case SCTP_TIMER_TYPE_ZCOPY_SENDQ:
2313ad21a364SRandall Stewart 		tmr = &inp->sctp_ep.zero_copy_sendq_timer;
2314ad21a364SRandall Stewart 		break;
2315f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ADDR_WQ:
2316b3f1ea41SRandall Stewart 		tmr = &SCTP_BASE_INFO(addr_wq_timer);
2317f8829a4aSRandall Stewart 		break;
2318f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_EARLYFR:
2319f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23206e55db54SRandall Stewart 			return;
2321f8829a4aSRandall Stewart 		}
2322f8829a4aSRandall Stewart 		tmr = &net->fr_timer;
2323f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_earlyfrstop);
2324f8829a4aSRandall Stewart 		break;
2325f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ITERATOR:
2326f8829a4aSRandall Stewart 		{
2327f8829a4aSRandall Stewart 			struct sctp_iterator *it;
2328f8829a4aSRandall Stewart 
2329f8829a4aSRandall Stewart 			it = (struct sctp_iterator *)inp;
2330f8829a4aSRandall Stewart 			tmr = &it->tmr;
2331f8829a4aSRandall Stewart 		}
2332f8829a4aSRandall Stewart 		break;
2333f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
2334f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23356e55db54SRandall Stewart 			return;
2336f8829a4aSRandall Stewart 		}
2337f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2338f8829a4aSRandall Stewart 		break;
2339f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
2340f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23416e55db54SRandall Stewart 			return;
2342f8829a4aSRandall Stewart 		}
2343f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2344f8829a4aSRandall Stewart 		break;
2345f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
2346f8829a4aSRandall Stewart 		if (stcb == NULL) {
23476e55db54SRandall Stewart 			return;
2348f8829a4aSRandall Stewart 		}
2349f8829a4aSRandall Stewart 		tmr = &stcb->asoc.dack_timer;
2350f8829a4aSRandall Stewart 		break;
2351f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
2352f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23536e55db54SRandall Stewart 			return;
2354f8829a4aSRandall Stewart 		}
2355f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2356f8829a4aSRandall Stewart 		break;
2357f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
2358f8829a4aSRandall Stewart 		if (stcb == NULL) {
23596e55db54SRandall Stewart 			return;
2360f8829a4aSRandall Stewart 		}
2361f8829a4aSRandall Stewart 		tmr = &stcb->asoc.hb_timer;
2362f8829a4aSRandall Stewart 		break;
2363f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
2364f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23656e55db54SRandall Stewart 			return;
2366f8829a4aSRandall Stewart 		}
2367f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2368f8829a4aSRandall Stewart 		break;
2369f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
2370f8829a4aSRandall Stewart 		/* nothing needed but the endpoint here */
2371f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2372f8829a4aSRandall Stewart 		/*
2373f8829a4aSRandall Stewart 		 * We re-use the newcookie timer for the INP kill timer. We
2374f8829a4aSRandall Stewart 		 * must assure that we do not kill it by accident.
2375f8829a4aSRandall Stewart 		 */
2376f8829a4aSRandall Stewart 		break;
2377f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASOCKILL:
2378f8829a4aSRandall Stewart 		/*
2379f8829a4aSRandall Stewart 		 * Stop the asoc kill timer.
2380f8829a4aSRandall Stewart 		 */
2381f8829a4aSRandall Stewart 		if (stcb == NULL) {
23826e55db54SRandall Stewart 			return;
2383f8829a4aSRandall Stewart 		}
2384f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2385f8829a4aSRandall Stewart 		break;
2386f8829a4aSRandall Stewart 
2387f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INPKILL:
2388f8829a4aSRandall Stewart 		/*
2389f8829a4aSRandall Stewart 		 * The inp is setup to die. We re-use the signature_chage
2390f8829a4aSRandall Stewart 		 * timer since that has stopped and we are in the GONE
2391f8829a4aSRandall Stewart 		 * state.
2392f8829a4aSRandall Stewart 		 */
2393f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2394f8829a4aSRandall Stewart 		break;
2395f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
2396f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23976e55db54SRandall Stewart 			return;
2398f8829a4aSRandall Stewart 		}
2399f8829a4aSRandall Stewart 		tmr = &net->pmtu_timer;
2400f8829a4aSRandall Stewart 		break;
2401f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
2402f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
24036e55db54SRandall Stewart 			return;
2404f8829a4aSRandall Stewart 		}
2405f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2406f8829a4aSRandall Stewart 		break;
2407f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
2408f8829a4aSRandall Stewart 		if (stcb == NULL) {
24096e55db54SRandall Stewart 			return;
2410f8829a4aSRandall Stewart 		}
2411f8829a4aSRandall Stewart 		tmr = &stcb->asoc.shut_guard_timer;
2412f8829a4aSRandall Stewart 		break;
2413f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_STRRESET:
2414f8829a4aSRandall Stewart 		if (stcb == NULL) {
24156e55db54SRandall Stewart 			return;
2416f8829a4aSRandall Stewart 		}
2417f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2418f8829a4aSRandall Stewart 		break;
2419f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASCONF:
2420f8829a4aSRandall Stewart 		if (stcb == NULL) {
24216e55db54SRandall Stewart 			return;
2422f8829a4aSRandall Stewart 		}
2423f8829a4aSRandall Stewart 		tmr = &stcb->asoc.asconf_timer;
2424f8829a4aSRandall Stewart 		break;
2425851b7298SRandall Stewart 	case SCTP_TIMER_TYPE_PRIM_DELETED:
2426851b7298SRandall Stewart 		if (stcb == NULL) {
2427851b7298SRandall Stewart 			return;
2428851b7298SRandall Stewart 		}
2429851b7298SRandall Stewart 		tmr = &stcb->asoc.delete_prim_timer;
2430851b7298SRandall Stewart 		break;
2431f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_AUTOCLOSE:
2432f8829a4aSRandall Stewart 		if (stcb == NULL) {
24336e55db54SRandall Stewart 			return;
2434f8829a4aSRandall Stewart 		}
2435f8829a4aSRandall Stewart 		tmr = &stcb->asoc.autoclose_timer;
2436f8829a4aSRandall Stewart 		break;
2437f8829a4aSRandall Stewart 	default:
2438ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_TIMER1, "%s: Unknown timer type %d\n",
2439ad81507eSRandall Stewart 		    __FUNCTION__, t_type);
2440f8829a4aSRandall Stewart 		break;
2441f8829a4aSRandall Stewart 	};
2442f8829a4aSRandall Stewart 	if (tmr == NULL) {
24436e55db54SRandall Stewart 		return;
2444f8829a4aSRandall Stewart 	}
2445f8829a4aSRandall Stewart 	if ((tmr->type != t_type) && tmr->type) {
2446f8829a4aSRandall Stewart 		/*
2447f8829a4aSRandall Stewart 		 * Ok we have a timer that is under joint use. Cookie timer
2448f8829a4aSRandall Stewart 		 * per chance with the SEND timer. We therefore are NOT
2449f8829a4aSRandall Stewart 		 * running the timer that the caller wants stopped.  So just
2450f8829a4aSRandall Stewart 		 * return.
2451f8829a4aSRandall Stewart 		 */
24526e55db54SRandall Stewart 		return;
2453f8829a4aSRandall Stewart 	}
2454ad81507eSRandall Stewart 	if ((t_type == SCTP_TIMER_TYPE_SEND) && (stcb != NULL)) {
2455f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up--;
2456f8829a4aSRandall Stewart 		if (stcb->asoc.num_send_timers_up < 0) {
2457f8829a4aSRandall Stewart 			stcb->asoc.num_send_timers_up = 0;
2458f8829a4aSRandall Stewart 		}
2459f8829a4aSRandall Stewart 	}
2460f8829a4aSRandall Stewart 	tmr->self = NULL;
2461a5d547adSRandall Stewart 	tmr->stopped_from = from;
24626e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&tmr->timer);
24636e55db54SRandall Stewart 	return;
2464f8829a4aSRandall Stewart }
2465f8829a4aSRandall Stewart 
2466f8829a4aSRandall Stewart uint32_t
2467f8829a4aSRandall Stewart sctp_calculate_len(struct mbuf *m)
2468f8829a4aSRandall Stewart {
2469f8829a4aSRandall Stewart 	uint32_t tlen = 0;
2470f8829a4aSRandall Stewart 	struct mbuf *at;
2471f8829a4aSRandall Stewart 
2472f8829a4aSRandall Stewart 	at = m;
2473f8829a4aSRandall Stewart 	while (at) {
2474139bc87fSRandall Stewart 		tlen += SCTP_BUF_LEN(at);
2475139bc87fSRandall Stewart 		at = SCTP_BUF_NEXT(at);
2476f8829a4aSRandall Stewart 	}
2477f8829a4aSRandall Stewart 	return (tlen);
2478f8829a4aSRandall Stewart }
2479f8829a4aSRandall Stewart 
2480f8829a4aSRandall Stewart void
2481f8829a4aSRandall Stewart sctp_mtu_size_reset(struct sctp_inpcb *inp,
248244b7479bSRandall Stewart     struct sctp_association *asoc, uint32_t mtu)
2483f8829a4aSRandall Stewart {
2484f8829a4aSRandall Stewart 	/*
2485f8829a4aSRandall Stewart 	 * Reset the P-MTU size on this association, this involves changing
2486f8829a4aSRandall Stewart 	 * the asoc MTU, going through ANY chunk+overhead larger than mtu to
2487f8829a4aSRandall Stewart 	 * allow the DF flag to be cleared.
2488f8829a4aSRandall Stewart 	 */
2489f8829a4aSRandall Stewart 	struct sctp_tmit_chunk *chk;
2490f8829a4aSRandall Stewart 	unsigned int eff_mtu, ovh;
2491f8829a4aSRandall Stewart 
249217205eccSRandall Stewart #ifdef SCTP_PRINT_FOR_B_AND_M
2493ad81507eSRandall Stewart 	SCTP_PRINTF("sctp_mtu_size_reset(%p, asoc:%p mtu:%d\n",
249417205eccSRandall Stewart 	    inp, asoc, mtu);
249517205eccSRandall Stewart #endif
2496f8829a4aSRandall Stewart 	asoc->smallest_mtu = mtu;
2497f8829a4aSRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) {
2498f8829a4aSRandall Stewart 		ovh = SCTP_MIN_OVERHEAD;
2499f8829a4aSRandall Stewart 	} else {
2500f8829a4aSRandall Stewart 		ovh = SCTP_MIN_V4_OVERHEAD;
2501f8829a4aSRandall Stewart 	}
2502f8829a4aSRandall Stewart 	eff_mtu = mtu - ovh;
2503f8829a4aSRandall Stewart 	TAILQ_FOREACH(chk, &asoc->send_queue, sctp_next) {
2504f8829a4aSRandall Stewart 
2505f8829a4aSRandall Stewart 		if (chk->send_size > eff_mtu) {
2506f8829a4aSRandall Stewart 			chk->flags |= CHUNK_FLAGS_FRAGMENT_OK;
2507f8829a4aSRandall Stewart 		}
2508f8829a4aSRandall Stewart 	}
2509f8829a4aSRandall Stewart 	TAILQ_FOREACH(chk, &asoc->sent_queue, sctp_next) {
2510f8829a4aSRandall Stewart 		if (chk->send_size > eff_mtu) {
2511f8829a4aSRandall Stewart 			chk->flags |= CHUNK_FLAGS_FRAGMENT_OK;
2512f8829a4aSRandall Stewart 		}
2513f8829a4aSRandall Stewart 	}
2514f8829a4aSRandall Stewart }
2515f8829a4aSRandall Stewart 
2516f8829a4aSRandall Stewart 
2517f8829a4aSRandall Stewart /*
2518f8829a4aSRandall Stewart  * given an association and starting time of the current RTT period return
2519f42a358aSRandall Stewart  * RTO in number of msecs net should point to the current network
2520f8829a4aSRandall Stewart  */
2521f8829a4aSRandall Stewart uint32_t
2522f8829a4aSRandall Stewart sctp_calculate_rto(struct sctp_tcb *stcb,
2523f8829a4aSRandall Stewart     struct sctp_association *asoc,
2524f8829a4aSRandall Stewart     struct sctp_nets *net,
252518e198d3SRandall Stewart     struct timeval *told,
252618e198d3SRandall Stewart     int safe)
2527f8829a4aSRandall Stewart {
252818e198d3SRandall Stewart 	/*-
2529f8829a4aSRandall Stewart 	 * given an association and the starting time of the current RTT
2530f42a358aSRandall Stewart 	 * period (in value1/value2) return RTO in number of msecs.
2531f8829a4aSRandall Stewart 	 */
2532f8829a4aSRandall Stewart 	int calc_time = 0;
2533f8829a4aSRandall Stewart 	int o_calctime;
25345e54f665SRandall Stewart 	uint32_t new_rto = 0;
2535f8829a4aSRandall Stewart 	int first_measure = 0;
253618e198d3SRandall Stewart 	struct timeval now, then, *old;
2537f8829a4aSRandall Stewart 
253818e198d3SRandall Stewart 	/* Copy it out for sparc64 */
253918e198d3SRandall Stewart 	if (safe == sctp_align_unsafe_makecopy) {
254018e198d3SRandall Stewart 		old = &then;
254118e198d3SRandall Stewart 		memcpy(&then, told, sizeof(struct timeval));
254218e198d3SRandall Stewart 	} else if (safe == sctp_align_safe_nocopy) {
254318e198d3SRandall Stewart 		old = told;
254418e198d3SRandall Stewart 	} else {
254518e198d3SRandall Stewart 		/* error */
254618e198d3SRandall Stewart 		SCTP_PRINTF("Huh, bad rto calc call\n");
254718e198d3SRandall Stewart 		return (0);
254818e198d3SRandall Stewart 	}
2549f8829a4aSRandall Stewart 	/************************/
2550f8829a4aSRandall Stewart 	/* 1. calculate new RTT */
2551f8829a4aSRandall Stewart 	/************************/
2552f8829a4aSRandall Stewart 	/* get the current time */
25536e55db54SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&now);
2554f8829a4aSRandall Stewart 	/* compute the RTT value */
2555f8829a4aSRandall Stewart 	if ((u_long)now.tv_sec > (u_long)old->tv_sec) {
2556f8829a4aSRandall Stewart 		calc_time = ((u_long)now.tv_sec - (u_long)old->tv_sec) * 1000;
2557f8829a4aSRandall Stewart 		if ((u_long)now.tv_usec > (u_long)old->tv_usec) {
2558f8829a4aSRandall Stewart 			calc_time += (((u_long)now.tv_usec -
2559f8829a4aSRandall Stewart 			    (u_long)old->tv_usec) / 1000);
2560f8829a4aSRandall Stewart 		} else if ((u_long)now.tv_usec < (u_long)old->tv_usec) {
2561f8829a4aSRandall Stewart 			/* Borrow 1,000ms from current calculation */
2562f8829a4aSRandall Stewart 			calc_time -= 1000;
2563f8829a4aSRandall Stewart 			/* Add in the slop over */
2564f8829a4aSRandall Stewart 			calc_time += ((int)now.tv_usec / 1000);
2565f8829a4aSRandall Stewart 			/* Add in the pre-second ms's */
2566f8829a4aSRandall Stewart 			calc_time += (((int)1000000 - (int)old->tv_usec) / 1000);
2567f8829a4aSRandall Stewart 		}
2568f8829a4aSRandall Stewart 	} else if ((u_long)now.tv_sec == (u_long)old->tv_sec) {
2569f8829a4aSRandall Stewart 		if ((u_long)now.tv_usec > (u_long)old->tv_usec) {
2570f8829a4aSRandall Stewart 			calc_time = ((u_long)now.tv_usec -
2571f8829a4aSRandall Stewart 			    (u_long)old->tv_usec) / 1000;
2572f8829a4aSRandall Stewart 		} else if ((u_long)now.tv_usec < (u_long)old->tv_usec) {
2573f8829a4aSRandall Stewart 			/* impossible .. garbage in nothing out */
25745e54f665SRandall Stewart 			goto calc_rto;
2575a5d547adSRandall Stewart 		} else if ((u_long)now.tv_usec == (u_long)old->tv_usec) {
2576a5d547adSRandall Stewart 			/*
2577a5d547adSRandall Stewart 			 * We have to have 1 usec :-D this must be the
2578a5d547adSRandall Stewart 			 * loopback.
2579a5d547adSRandall Stewart 			 */
2580a5d547adSRandall Stewart 			calc_time = 1;
2581f8829a4aSRandall Stewart 		} else {
2582f8829a4aSRandall Stewart 			/* impossible .. garbage in nothing out */
25835e54f665SRandall Stewart 			goto calc_rto;
2584f8829a4aSRandall Stewart 		}
2585f8829a4aSRandall Stewart 	} else {
2586f8829a4aSRandall Stewart 		/* Clock wrapped? */
25875e54f665SRandall Stewart 		goto calc_rto;
2588f8829a4aSRandall Stewart 	}
2589f8829a4aSRandall Stewart 	/***************************/
2590f8829a4aSRandall Stewart 	/* 2. update RTTVAR & SRTT */
2591f8829a4aSRandall Stewart 	/***************************/
2592f8829a4aSRandall Stewart 	o_calctime = calc_time;
2593f8829a4aSRandall Stewart 	/* this is Van Jacobson's integer version */
25949a972525SRandall Stewart 	if (net->RTO_measured) {
2595108df27cSRandall Stewart 		calc_time -= (net->lastsa >> SCTP_RTT_SHIFT);	/* take away 1/8th when
2596108df27cSRandall Stewart 								 * shift=3 */
2597b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RTTVAR_LOGGING_ENABLE) {
2598f8829a4aSRandall Stewart 			rto_logging(net, SCTP_LOG_RTTVAR);
259980fefe0aSRandall Stewart 		}
2600f8829a4aSRandall Stewart 		net->prev_rtt = o_calctime;
2601108df27cSRandall Stewart 		net->lastsa += calc_time;	/* add 7/8th into sa when
2602108df27cSRandall Stewart 						 * shift=3 */
2603f8829a4aSRandall Stewart 		if (calc_time < 0) {
2604f8829a4aSRandall Stewart 			calc_time = -calc_time;
2605f8829a4aSRandall Stewart 		}
2606108df27cSRandall Stewart 		calc_time -= (net->lastsv >> SCTP_RTT_VAR_SHIFT);	/* take away 1/4 when
2607108df27cSRandall Stewart 									 * VAR shift=2 */
2608f8829a4aSRandall Stewart 		net->lastsv += calc_time;
2609f8829a4aSRandall Stewart 		if (net->lastsv == 0) {
2610f8829a4aSRandall Stewart 			net->lastsv = SCTP_CLOCK_GRANULARITY;
2611f8829a4aSRandall Stewart 		}
2612f8829a4aSRandall Stewart 	} else {
2613f8829a4aSRandall Stewart 		/* First RTO measurment */
26149a972525SRandall Stewart 		net->RTO_measured = 1;
2615108df27cSRandall Stewart 		net->lastsa = calc_time << SCTP_RTT_SHIFT;	/* Multiply by 8 when
2616108df27cSRandall Stewart 								 * shift=3 */
2617108df27cSRandall Stewart 		net->lastsv = calc_time;
2618108df27cSRandall Stewart 		if (net->lastsv == 0) {
2619108df27cSRandall Stewart 			net->lastsv = SCTP_CLOCK_GRANULARITY;
2620108df27cSRandall Stewart 		}
2621f8829a4aSRandall Stewart 		first_measure = 1;
2622f8829a4aSRandall Stewart 		net->prev_rtt = o_calctime;
2623b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RTTVAR_LOGGING_ENABLE) {
2624f8829a4aSRandall Stewart 			rto_logging(net, SCTP_LOG_INITIAL_RTT);
262580fefe0aSRandall Stewart 		}
2626f8829a4aSRandall Stewart 	}
26275e54f665SRandall Stewart calc_rto:
2628108df27cSRandall Stewart 	new_rto = (net->lastsa >> SCTP_RTT_SHIFT) + net->lastsv;
2629f8829a4aSRandall Stewart 	if ((new_rto > SCTP_SAT_NETWORK_MIN) &&
2630f8829a4aSRandall Stewart 	    (stcb->asoc.sat_network_lockout == 0)) {
2631f8829a4aSRandall Stewart 		stcb->asoc.sat_network = 1;
2632f8829a4aSRandall Stewart 	} else if ((!first_measure) && stcb->asoc.sat_network) {
2633f8829a4aSRandall Stewart 		stcb->asoc.sat_network = 0;
2634f8829a4aSRandall Stewart 		stcb->asoc.sat_network_lockout = 1;
2635f8829a4aSRandall Stewart 	}
2636f8829a4aSRandall Stewart 	/* bound it, per C6/C7 in Section 5.3.1 */
2637f8829a4aSRandall Stewart 	if (new_rto < stcb->asoc.minrto) {
2638f8829a4aSRandall Stewart 		new_rto = stcb->asoc.minrto;
2639f8829a4aSRandall Stewart 	}
2640f8829a4aSRandall Stewart 	if (new_rto > stcb->asoc.maxrto) {
2641f8829a4aSRandall Stewart 		new_rto = stcb->asoc.maxrto;
2642f8829a4aSRandall Stewart 	}
26435e54f665SRandall Stewart 	/* we are now returning the RTO */
26445e54f665SRandall Stewart 	return (new_rto);
2645f8829a4aSRandall Stewart }
2646f8829a4aSRandall Stewart 
2647f8829a4aSRandall Stewart /*
2648f8829a4aSRandall Stewart  * return a pointer to a contiguous piece of data from the given mbuf chain
2649f8829a4aSRandall Stewart  * starting at 'off' for 'len' bytes.  If the desired piece spans more than
2650f8829a4aSRandall Stewart  * one mbuf, a copy is made at 'ptr'. caller must ensure that the buffer size
2651f8829a4aSRandall Stewart  * is >= 'len' returns NULL if there there isn't 'len' bytes in the chain.
2652f8829a4aSRandall Stewart  */
265372fb6fdbSRandall Stewart caddr_t
2654f8829a4aSRandall Stewart sctp_m_getptr(struct mbuf *m, int off, int len, uint8_t * in_ptr)
2655f8829a4aSRandall Stewart {
2656f8829a4aSRandall Stewart 	uint32_t count;
2657f8829a4aSRandall Stewart 	uint8_t *ptr;
2658f8829a4aSRandall Stewart 
2659f8829a4aSRandall Stewart 	ptr = in_ptr;
2660f8829a4aSRandall Stewart 	if ((off < 0) || (len <= 0))
2661f8829a4aSRandall Stewart 		return (NULL);
2662f8829a4aSRandall Stewart 
2663f8829a4aSRandall Stewart 	/* find the desired start location */
2664f8829a4aSRandall Stewart 	while ((m != NULL) && (off > 0)) {
2665139bc87fSRandall Stewart 		if (off < SCTP_BUF_LEN(m))
2666f8829a4aSRandall Stewart 			break;
2667139bc87fSRandall Stewart 		off -= SCTP_BUF_LEN(m);
2668139bc87fSRandall Stewart 		m = SCTP_BUF_NEXT(m);
2669f8829a4aSRandall Stewart 	}
2670f8829a4aSRandall Stewart 	if (m == NULL)
2671f8829a4aSRandall Stewart 		return (NULL);
2672f8829a4aSRandall Stewart 
2673f8829a4aSRandall Stewart 	/* is the current mbuf large enough (eg. contiguous)? */
2674139bc87fSRandall Stewart 	if ((SCTP_BUF_LEN(m) - off) >= len) {
2675f8829a4aSRandall Stewart 		return (mtod(m, caddr_t)+off);
2676f8829a4aSRandall Stewart 	} else {
2677f8829a4aSRandall Stewart 		/* else, it spans more than one mbuf, so save a temp copy... */
2678f8829a4aSRandall Stewart 		while ((m != NULL) && (len > 0)) {
2679139bc87fSRandall Stewart 			count = min(SCTP_BUF_LEN(m) - off, len);
2680f8829a4aSRandall Stewart 			bcopy(mtod(m, caddr_t)+off, ptr, count);
2681f8829a4aSRandall Stewart 			len -= count;
2682f8829a4aSRandall Stewart 			ptr += count;
2683f8829a4aSRandall Stewart 			off = 0;
2684139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
2685f8829a4aSRandall Stewart 		}
2686f8829a4aSRandall Stewart 		if ((m == NULL) && (len > 0))
2687f8829a4aSRandall Stewart 			return (NULL);
2688f8829a4aSRandall Stewart 		else
2689f8829a4aSRandall Stewart 			return ((caddr_t)in_ptr);
2690f8829a4aSRandall Stewart 	}
2691f8829a4aSRandall Stewart }
2692f8829a4aSRandall Stewart 
2693f8829a4aSRandall Stewart 
269444b7479bSRandall Stewart 
2695f8829a4aSRandall Stewart struct sctp_paramhdr *
2696f8829a4aSRandall Stewart sctp_get_next_param(struct mbuf *m,
2697f8829a4aSRandall Stewart     int offset,
2698f8829a4aSRandall Stewart     struct sctp_paramhdr *pull,
2699f8829a4aSRandall Stewart     int pull_limit)
2700f8829a4aSRandall Stewart {
2701f8829a4aSRandall Stewart 	/* This just provides a typed signature to Peter's Pull routine */
2702f8829a4aSRandall Stewart 	return ((struct sctp_paramhdr *)sctp_m_getptr(m, offset, pull_limit,
2703f8829a4aSRandall Stewart 	    (uint8_t *) pull));
2704f8829a4aSRandall Stewart }
2705f8829a4aSRandall Stewart 
2706f8829a4aSRandall Stewart 
2707f8829a4aSRandall Stewart int
2708f8829a4aSRandall Stewart sctp_add_pad_tombuf(struct mbuf *m, int padlen)
2709f8829a4aSRandall Stewart {
2710f8829a4aSRandall Stewart 	/*
2711f8829a4aSRandall Stewart 	 * add padlen bytes of 0 filled padding to the end of the mbuf. If
2712f8829a4aSRandall Stewart 	 * padlen is > 3 this routine will fail.
2713f8829a4aSRandall Stewart 	 */
2714f8829a4aSRandall Stewart 	uint8_t *dp;
2715f8829a4aSRandall Stewart 	int i;
2716f8829a4aSRandall Stewart 
2717f8829a4aSRandall Stewart 	if (padlen > 3) {
2718c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET_PKT(m, NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOBUFS);
2719f8829a4aSRandall Stewart 		return (ENOBUFS);
2720f8829a4aSRandall Stewart 	}
272141eee555SRandall Stewart 	if (padlen <= M_TRAILINGSPACE(m)) {
2722f8829a4aSRandall Stewart 		/*
2723f8829a4aSRandall Stewart 		 * The easy way. We hope the majority of the time we hit
2724f8829a4aSRandall Stewart 		 * here :)
2725f8829a4aSRandall Stewart 		 */
2726139bc87fSRandall Stewart 		dp = (uint8_t *) (mtod(m, caddr_t)+SCTP_BUF_LEN(m));
2727139bc87fSRandall Stewart 		SCTP_BUF_LEN(m) += padlen;
2728f8829a4aSRandall Stewart 	} else {
2729f8829a4aSRandall Stewart 		/* Hard way we must grow the mbuf */
2730f8829a4aSRandall Stewart 		struct mbuf *tmp;
2731f8829a4aSRandall Stewart 
2732f8829a4aSRandall Stewart 		tmp = sctp_get_mbuf_for_msg(padlen, 0, M_DONTWAIT, 1, MT_DATA);
2733f8829a4aSRandall Stewart 		if (tmp == NULL) {
2734f8829a4aSRandall Stewart 			/* Out of space GAK! we are in big trouble. */
2735c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET_PKT(m, NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
2736f8829a4aSRandall Stewart 			return (ENOSPC);
2737f8829a4aSRandall Stewart 		}
2738f8829a4aSRandall Stewart 		/* setup and insert in middle */
2739139bc87fSRandall Stewart 		SCTP_BUF_LEN(tmp) = padlen;
274041eee555SRandall Stewart 		SCTP_BUF_NEXT(tmp) = NULL;
2741139bc87fSRandall Stewart 		SCTP_BUF_NEXT(m) = tmp;
2742f8829a4aSRandall Stewart 		dp = mtod(tmp, uint8_t *);
2743f8829a4aSRandall Stewart 	}
2744f8829a4aSRandall Stewart 	/* zero out the pad */
2745f8829a4aSRandall Stewart 	for (i = 0; i < padlen; i++) {
2746f8829a4aSRandall Stewart 		*dp = 0;
2747f8829a4aSRandall Stewart 		dp++;
2748f8829a4aSRandall Stewart 	}
2749f8829a4aSRandall Stewart 	return (0);
2750f8829a4aSRandall Stewart }
2751f8829a4aSRandall Stewart 
2752f8829a4aSRandall Stewart int
2753f8829a4aSRandall Stewart sctp_pad_lastmbuf(struct mbuf *m, int padval, struct mbuf *last_mbuf)
2754f8829a4aSRandall Stewart {
2755f8829a4aSRandall Stewart 	/* find the last mbuf in chain and pad it */
2756f8829a4aSRandall Stewart 	struct mbuf *m_at;
2757f8829a4aSRandall Stewart 
2758f8829a4aSRandall Stewart 	m_at = m;
2759f8829a4aSRandall Stewart 	if (last_mbuf) {
2760f8829a4aSRandall Stewart 		return (sctp_add_pad_tombuf(last_mbuf, padval));
2761f8829a4aSRandall Stewart 	} else {
2762f8829a4aSRandall Stewart 		while (m_at) {
2763139bc87fSRandall Stewart 			if (SCTP_BUF_NEXT(m_at) == NULL) {
2764f8829a4aSRandall Stewart 				return (sctp_add_pad_tombuf(m_at, padval));
2765f8829a4aSRandall Stewart 			}
2766139bc87fSRandall Stewart 			m_at = SCTP_BUF_NEXT(m_at);
2767f8829a4aSRandall Stewart 		}
2768f8829a4aSRandall Stewart 	}
2769c4739e2fSRandall Stewart 	SCTP_LTRACE_ERR_RET_PKT(m, NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EFAULT);
2770f8829a4aSRandall Stewart 	return (EFAULT);
2771f8829a4aSRandall Stewart }
2772f8829a4aSRandall Stewart 
2773f8829a4aSRandall Stewart int sctp_asoc_change_wake = 0;
2774f8829a4aSRandall Stewart 
2775f8829a4aSRandall Stewart static void
2776f8829a4aSRandall Stewart sctp_notify_assoc_change(uint32_t event, struct sctp_tcb *stcb,
2777ceaad40aSRandall Stewart     uint32_t error, void *data, int so_locked
2778ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
2779ceaad40aSRandall Stewart     SCTP_UNUSED
2780ceaad40aSRandall Stewart #endif
2781ceaad40aSRandall Stewart )
2782f8829a4aSRandall Stewart {
2783f8829a4aSRandall Stewart 	struct mbuf *m_notify;
2784f8829a4aSRandall Stewart 	struct sctp_assoc_change *sac;
2785f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
2786f8829a4aSRandall Stewart 
2787ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2788ceaad40aSRandall Stewart 	struct socket *so;
2789ceaad40aSRandall Stewart 
2790ceaad40aSRandall Stewart #endif
2791ceaad40aSRandall Stewart 
2792f8829a4aSRandall Stewart 	/*
2793f8829a4aSRandall Stewart 	 * For TCP model AND UDP connected sockets we will send an error up
2794f8829a4aSRandall Stewart 	 * when an ABORT comes in.
2795f8829a4aSRandall Stewart 	 */
2796f8829a4aSRandall Stewart 	if (((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
2797f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) &&
27983c503c28SRandall Stewart 	    ((event == SCTP_COMM_LOST) || (event == SCTP_CANT_STR_ASSOC))) {
2799c4739e2fSRandall Stewart 		if (SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_COOKIE_WAIT) {
2800c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ECONNREFUSED);
280144b7479bSRandall Stewart 			stcb->sctp_socket->so_error = ECONNREFUSED;
2802c4739e2fSRandall Stewart 		} else {
2803c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ECONNRESET);
2804f8829a4aSRandall Stewart 			stcb->sctp_socket->so_error = ECONNRESET;
2805c4739e2fSRandall Stewart 		}
2806f8829a4aSRandall Stewart 		/* Wake ANY sleepers */
2807ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2808ceaad40aSRandall Stewart 		so = SCTP_INP_SO(stcb->sctp_ep);
2809ceaad40aSRandall Stewart 		if (!so_locked) {
2810ceaad40aSRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, 1);
2811ceaad40aSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
2812ceaad40aSRandall Stewart 			SCTP_SOCKET_LOCK(so, 1);
2813ceaad40aSRandall Stewart 			SCTP_TCB_LOCK(stcb);
2814ceaad40aSRandall Stewart 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
2815ceaad40aSRandall Stewart 			if (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET) {
2816ceaad40aSRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
2817ceaad40aSRandall Stewart 				return;
2818ceaad40aSRandall Stewart 			}
2819ceaad40aSRandall Stewart 		}
2820ceaad40aSRandall Stewart #endif
2821f8829a4aSRandall Stewart 		sorwakeup(stcb->sctp_socket);
2822f8829a4aSRandall Stewart 		sowwakeup(stcb->sctp_socket);
2823ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2824ceaad40aSRandall Stewart 		if (!so_locked) {
2825ceaad40aSRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
2826ceaad40aSRandall Stewart 		}
2827ceaad40aSRandall Stewart #endif
2828f8829a4aSRandall Stewart 		sctp_asoc_change_wake++;
2829f8829a4aSRandall Stewart 	}
2830f8829a4aSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_RECVASSOCEVNT)) {
2831f8829a4aSRandall Stewart 		/* event not enabled */
2832f8829a4aSRandall Stewart 		return;
2833f8829a4aSRandall Stewart 	}
2834139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_assoc_change), 0, M_DONTWAIT, 1, MT_DATA);
2835f8829a4aSRandall Stewart 	if (m_notify == NULL)
2836f8829a4aSRandall Stewart 		/* no space left */
2837f8829a4aSRandall Stewart 		return;
2838139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
2839f8829a4aSRandall Stewart 
2840f8829a4aSRandall Stewart 	sac = mtod(m_notify, struct sctp_assoc_change *);
2841f8829a4aSRandall Stewart 	sac->sac_type = SCTP_ASSOC_CHANGE;
2842f8829a4aSRandall Stewart 	sac->sac_flags = 0;
2843f8829a4aSRandall Stewart 	sac->sac_length = sizeof(struct sctp_assoc_change);
2844f8829a4aSRandall Stewart 	sac->sac_state = event;
2845f8829a4aSRandall Stewart 	sac->sac_error = error;
2846f8829a4aSRandall Stewart 	/* XXX verify these stream counts */
2847f8829a4aSRandall Stewart 	sac->sac_outbound_streams = stcb->asoc.streamoutcnt;
2848f8829a4aSRandall Stewart 	sac->sac_inbound_streams = stcb->asoc.streamincnt;
2849f8829a4aSRandall Stewart 	sac->sac_assoc_id = sctp_get_associd(stcb);
2850139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_assoc_change);
2851139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
2852f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
2853f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
2854f8829a4aSRandall Stewart 	    m_notify);
2855f8829a4aSRandall Stewart 	if (control == NULL) {
2856f8829a4aSRandall Stewart 		/* no memory */
2857f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
2858f8829a4aSRandall Stewart 		return;
2859f8829a4aSRandall Stewart 	}
2860139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
2861f8829a4aSRandall Stewart 	/* not that we need this */
2862f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
2863139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
2864f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
2865f8829a4aSRandall Stewart 	    control,
2866ceaad40aSRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, so_locked);
2867f8829a4aSRandall Stewart 	if (event == SCTP_COMM_LOST) {
2868f8829a4aSRandall Stewart 		/* Wake up any sleeper */
2869ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2870ceaad40aSRandall Stewart 		so = SCTP_INP_SO(stcb->sctp_ep);
2871ceaad40aSRandall Stewart 		if (!so_locked) {
2872ceaad40aSRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, 1);
2873ceaad40aSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
2874ceaad40aSRandall Stewart 			SCTP_SOCKET_LOCK(so, 1);
2875ceaad40aSRandall Stewart 			SCTP_TCB_LOCK(stcb);
2876ceaad40aSRandall Stewart 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
2877ceaad40aSRandall Stewart 			if (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET) {
2878ceaad40aSRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
2879ceaad40aSRandall Stewart 				return;
2880ceaad40aSRandall Stewart 			}
2881ceaad40aSRandall Stewart 		}
2882ceaad40aSRandall Stewart #endif
2883f8829a4aSRandall Stewart 		sctp_sowwakeup(stcb->sctp_ep, stcb->sctp_socket);
2884ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2885ceaad40aSRandall Stewart 		if (!so_locked) {
2886ceaad40aSRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
2887ceaad40aSRandall Stewart 		}
2888ceaad40aSRandall Stewart #endif
2889f8829a4aSRandall Stewart 	}
2890f8829a4aSRandall Stewart }
2891f8829a4aSRandall Stewart 
2892f8829a4aSRandall Stewart static void
2893f8829a4aSRandall Stewart sctp_notify_peer_addr_change(struct sctp_tcb *stcb, uint32_t state,
2894f8829a4aSRandall Stewart     struct sockaddr *sa, uint32_t error)
2895f8829a4aSRandall Stewart {
2896f8829a4aSRandall Stewart 	struct mbuf *m_notify;
2897f8829a4aSRandall Stewart 	struct sctp_paddr_change *spc;
2898f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
2899f8829a4aSRandall Stewart 
2900830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_RECVPADDREVNT)) {
2901f8829a4aSRandall Stewart 		/* event not enabled */
2902f8829a4aSRandall Stewart 		return;
2903830d754dSRandall Stewart 	}
2904139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_paddr_change), 0, M_DONTWAIT, 1, MT_DATA);
2905f8829a4aSRandall Stewart 	if (m_notify == NULL)
2906f8829a4aSRandall Stewart 		return;
2907139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
2908f8829a4aSRandall Stewart 	spc = mtod(m_notify, struct sctp_paddr_change *);
2909f8829a4aSRandall Stewart 	spc->spc_type = SCTP_PEER_ADDR_CHANGE;
2910f8829a4aSRandall Stewart 	spc->spc_flags = 0;
2911f8829a4aSRandall Stewart 	spc->spc_length = sizeof(struct sctp_paddr_change);
29125e2c2d87SRandall Stewart 	switch (sa->sa_family) {
29135e2c2d87SRandall Stewart 	case AF_INET:
2914f8829a4aSRandall Stewart 		memcpy(&spc->spc_aaddr, sa, sizeof(struct sockaddr_in));
29155e2c2d87SRandall Stewart 		break;
29165e2c2d87SRandall Stewart #ifdef INET6
29175e2c2d87SRandall Stewart 	case AF_INET6:
29185e2c2d87SRandall Stewart 		{
2919f42a358aSRandall Stewart 			struct sockaddr_in6 *sin6;
2920f42a358aSRandall Stewart 
2921f8829a4aSRandall Stewart 			memcpy(&spc->spc_aaddr, sa, sizeof(struct sockaddr_in6));
2922f42a358aSRandall Stewart 
2923f42a358aSRandall Stewart 			sin6 = (struct sockaddr_in6 *)&spc->spc_aaddr;
2924f42a358aSRandall Stewart 			if (IN6_IS_SCOPE_LINKLOCAL(&sin6->sin6_addr)) {
292542551e99SRandall Stewart 				if (sin6->sin6_scope_id == 0) {
292642551e99SRandall Stewart 					/* recover scope_id for user */
2927f42a358aSRandall Stewart 					(void)sa6_recoverscope(sin6);
292842551e99SRandall Stewart 				} else {
292942551e99SRandall Stewart 					/* clear embedded scope_id for user */
293042551e99SRandall Stewart 					in6_clearscope(&sin6->sin6_addr);
293142551e99SRandall Stewart 				}
2932f42a358aSRandall Stewart 			}
29335e2c2d87SRandall Stewart 			break;
29345e2c2d87SRandall Stewart 		}
29355e2c2d87SRandall Stewart #endif
29365e2c2d87SRandall Stewart 	default:
29375e2c2d87SRandall Stewart 		/* TSNH */
29385e2c2d87SRandall Stewart 		break;
2939f8829a4aSRandall Stewart 	}
2940f8829a4aSRandall Stewart 	spc->spc_state = state;
2941f8829a4aSRandall Stewart 	spc->spc_error = error;
2942f8829a4aSRandall Stewart 	spc->spc_assoc_id = sctp_get_associd(stcb);
2943f8829a4aSRandall Stewart 
2944139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_paddr_change);
2945139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
2946f8829a4aSRandall Stewart 
2947f8829a4aSRandall Stewart 	/* append to socket */
2948f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
2949f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
2950f8829a4aSRandall Stewart 	    m_notify);
2951f8829a4aSRandall Stewart 	if (control == NULL) {
2952f8829a4aSRandall Stewart 		/* no memory */
2953f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
2954f8829a4aSRandall Stewart 		return;
2955f8829a4aSRandall Stewart 	}
2956139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
2957139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
2958f8829a4aSRandall Stewart 	/* not that we need this */
2959f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
2960f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
2961f8829a4aSRandall Stewart 	    control,
2962ceaad40aSRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_SO_NOT_LOCKED);
2963f8829a4aSRandall Stewart }
2964f8829a4aSRandall Stewart 
2965f8829a4aSRandall Stewart 
2966f8829a4aSRandall Stewart static void
2967f8829a4aSRandall Stewart sctp_notify_send_failed(struct sctp_tcb *stcb, uint32_t error,
2968ceaad40aSRandall Stewart     struct sctp_tmit_chunk *chk, int so_locked
2969ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
2970ceaad40aSRandall Stewart     SCTP_UNUSED
2971ceaad40aSRandall Stewart #endif
2972ceaad40aSRandall Stewart )
2973f8829a4aSRandall Stewart {
2974830d754dSRandall Stewart 	struct mbuf *m_notify;
2975f8829a4aSRandall Stewart 	struct sctp_send_failed *ssf;
2976f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
2977f8829a4aSRandall Stewart 	int length;
2978f8829a4aSRandall Stewart 
2979830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_RECVSENDFAILEVNT)) {
2980f8829a4aSRandall Stewart 		/* event not enabled */
2981f8829a4aSRandall Stewart 		return;
2982830d754dSRandall Stewart 	}
2983139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_send_failed), 0, M_DONTWAIT, 1, MT_DATA);
2984f8829a4aSRandall Stewart 	if (m_notify == NULL)
2985f8829a4aSRandall Stewart 		/* no space left */
2986f8829a4aSRandall Stewart 		return;
2987fc14de76SRandall Stewart 	length = sizeof(struct sctp_send_failed) + chk->send_size;
2988fc14de76SRandall Stewart 	length -= sizeof(struct sctp_data_chunk);
2989139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
2990f8829a4aSRandall Stewart 	ssf = mtod(m_notify, struct sctp_send_failed *);
2991f8829a4aSRandall Stewart 	ssf->ssf_type = SCTP_SEND_FAILED;
2992f8829a4aSRandall Stewart 	if (error == SCTP_NOTIFY_DATAGRAM_UNSENT)
2993f8829a4aSRandall Stewart 		ssf->ssf_flags = SCTP_DATA_UNSENT;
2994f8829a4aSRandall Stewart 	else
2995f8829a4aSRandall Stewart 		ssf->ssf_flags = SCTP_DATA_SENT;
2996f8829a4aSRandall Stewart 	ssf->ssf_length = length;
2997f8829a4aSRandall Stewart 	ssf->ssf_error = error;
2998f8829a4aSRandall Stewart 	/* not exactly what the user sent in, but should be close :) */
2999d00aff5dSRandall Stewart 	bzero(&ssf->ssf_info, sizeof(ssf->ssf_info));
3000f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_stream = chk->rec.data.stream_number;
3001f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_ssn = chk->rec.data.stream_seq;
3002f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_flags = chk->rec.data.rcv_flags;
3003f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_ppid = chk->rec.data.payloadtype;
3004f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_context = chk->rec.data.context;
3005f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_assoc_id = sctp_get_associd(stcb);
3006f8829a4aSRandall Stewart 	ssf->ssf_assoc_id = sctp_get_associd(stcb);
3007fc14de76SRandall Stewart 
3008139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = chk->data;
3009139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_send_failed);
3010830d754dSRandall Stewart 	if (chk->data) {
3011830d754dSRandall Stewart 		/*
3012830d754dSRandall Stewart 		 * trim off the sctp chunk header(it should be there)
3013830d754dSRandall Stewart 		 */
3014830d754dSRandall Stewart 		if (chk->send_size >= sizeof(struct sctp_data_chunk)) {
3015830d754dSRandall Stewart 			m_adj(chk->data, sizeof(struct sctp_data_chunk));
3016830d754dSRandall Stewart 			sctp_mbuf_crush(chk->data);
3017830d754dSRandall Stewart 			chk->send_size -= sizeof(struct sctp_data_chunk);
3018830d754dSRandall Stewart 		}
3019830d754dSRandall Stewart 	}
3020f8829a4aSRandall Stewart 	/* Steal off the mbuf */
3021f8829a4aSRandall Stewart 	chk->data = NULL;
3022f8829a4aSRandall Stewart 	/*
3023f8829a4aSRandall Stewart 	 * For this case, we check the actual socket buffer, since the assoc
3024f8829a4aSRandall Stewart 	 * is going away we don't want to overfill the socket buffer for a
3025f8829a4aSRandall Stewart 	 * non-reader
3026f8829a4aSRandall Stewart 	 */
3027139bc87fSRandall Stewart 	if (sctp_sbspace_failedmsgs(&stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3028f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3029f8829a4aSRandall Stewart 		return;
3030f8829a4aSRandall Stewart 	}
3031f8829a4aSRandall Stewart 	/* append to socket */
3032f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3033f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3034f8829a4aSRandall Stewart 	    m_notify);
3035f8829a4aSRandall Stewart 	if (control == NULL) {
3036f8829a4aSRandall Stewart 		/* no memory */
3037f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3038f8829a4aSRandall Stewart 		return;
3039f8829a4aSRandall Stewart 	}
3040139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3041f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3042f8829a4aSRandall Stewart 	    control,
3043ceaad40aSRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, so_locked);
3044f8829a4aSRandall Stewart }
3045f8829a4aSRandall Stewart 
3046f8829a4aSRandall Stewart 
3047f8829a4aSRandall Stewart static void
3048f8829a4aSRandall Stewart sctp_notify_send_failed2(struct sctp_tcb *stcb, uint32_t error,
3049ceaad40aSRandall Stewart     struct sctp_stream_queue_pending *sp, int so_locked
3050ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3051ceaad40aSRandall Stewart     SCTP_UNUSED
3052ceaad40aSRandall Stewart #endif
3053ceaad40aSRandall Stewart )
3054f8829a4aSRandall Stewart {
3055f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3056f8829a4aSRandall Stewart 	struct sctp_send_failed *ssf;
3057f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3058f8829a4aSRandall Stewart 	int length;
3059f8829a4aSRandall Stewart 
3060830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_RECVSENDFAILEVNT)) {
3061f8829a4aSRandall Stewart 		/* event not enabled */
3062f8829a4aSRandall Stewart 		return;
3063830d754dSRandall Stewart 	}
3064f8829a4aSRandall Stewart 	length = sizeof(struct sctp_send_failed) + sp->length;
3065d00aff5dSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_send_failed), 0, M_DONTWAIT, 1, MT_DATA);
3066f8829a4aSRandall Stewart 	if (m_notify == NULL)
3067f8829a4aSRandall Stewart 		/* no space left */
3068f8829a4aSRandall Stewart 		return;
3069139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3070f8829a4aSRandall Stewart 	ssf = mtod(m_notify, struct sctp_send_failed *);
3071f8829a4aSRandall Stewart 	ssf->ssf_type = SCTP_SEND_FAILED;
3072f8829a4aSRandall Stewart 	if (error == SCTP_NOTIFY_DATAGRAM_UNSENT)
3073f8829a4aSRandall Stewart 		ssf->ssf_flags = SCTP_DATA_UNSENT;
3074f8829a4aSRandall Stewart 	else
3075f8829a4aSRandall Stewart 		ssf->ssf_flags = SCTP_DATA_SENT;
3076f8829a4aSRandall Stewart 	ssf->ssf_length = length;
3077f8829a4aSRandall Stewart 	ssf->ssf_error = error;
3078f8829a4aSRandall Stewart 	/* not exactly what the user sent in, but should be close :) */
3079d00aff5dSRandall Stewart 	bzero(&ssf->ssf_info, sizeof(ssf->ssf_info));
3080f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_stream = sp->stream;
3081f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_ssn = sp->strseq;
3082fc14de76SRandall Stewart 	if (sp->some_taken) {
3083fc14de76SRandall Stewart 		ssf->ssf_info.sinfo_flags = SCTP_DATA_LAST_FRAG;
3084fc14de76SRandall Stewart 	} else {
3085fc14de76SRandall Stewart 		ssf->ssf_info.sinfo_flags = SCTP_DATA_NOT_FRAG;
3086fc14de76SRandall Stewart 	}
3087f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_ppid = sp->ppid;
3088f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_context = sp->context;
3089f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_assoc_id = sctp_get_associd(stcb);
3090f8829a4aSRandall Stewart 	ssf->ssf_assoc_id = sctp_get_associd(stcb);
3091139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = sp->data;
3092139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_send_failed);
3093f8829a4aSRandall Stewart 
3094f8829a4aSRandall Stewart 	/* Steal off the mbuf */
3095f8829a4aSRandall Stewart 	sp->data = NULL;
3096f8829a4aSRandall Stewart 	/*
3097f8829a4aSRandall Stewart 	 * For this case, we check the actual socket buffer, since the assoc
3098f8829a4aSRandall Stewart 	 * is going away we don't want to overfill the socket buffer for a
3099f8829a4aSRandall Stewart 	 * non-reader
3100f8829a4aSRandall Stewart 	 */
3101139bc87fSRandall Stewart 	if (sctp_sbspace_failedmsgs(&stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3102f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3103f8829a4aSRandall Stewart 		return;
3104f8829a4aSRandall Stewart 	}
3105f8829a4aSRandall Stewart 	/* append to socket */
3106f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3107f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3108f8829a4aSRandall Stewart 	    m_notify);
3109f8829a4aSRandall Stewart 	if (control == NULL) {
3110f8829a4aSRandall Stewart 		/* no memory */
3111f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3112f8829a4aSRandall Stewart 		return;
3113f8829a4aSRandall Stewart 	}
3114139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3115f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3116f8829a4aSRandall Stewart 	    control,
3117ceaad40aSRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, so_locked);
3118f8829a4aSRandall Stewart }
3119f8829a4aSRandall Stewart 
3120f8829a4aSRandall Stewart 
3121f8829a4aSRandall Stewart 
3122f8829a4aSRandall Stewart static void
3123f8829a4aSRandall Stewart sctp_notify_adaptation_layer(struct sctp_tcb *stcb,
3124f8829a4aSRandall Stewart     uint32_t error)
3125f8829a4aSRandall Stewart {
3126f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3127f8829a4aSRandall Stewart 	struct sctp_adaptation_event *sai;
3128f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3129f8829a4aSRandall Stewart 
3130830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_ADAPTATIONEVNT)) {
3131f8829a4aSRandall Stewart 		/* event not enabled */
3132f8829a4aSRandall Stewart 		return;
3133830d754dSRandall Stewart 	}
3134139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_adaption_event), 0, M_DONTWAIT, 1, MT_DATA);
3135f8829a4aSRandall Stewart 	if (m_notify == NULL)
3136f8829a4aSRandall Stewart 		/* no space left */
3137f8829a4aSRandall Stewart 		return;
3138139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3139f8829a4aSRandall Stewart 	sai = mtod(m_notify, struct sctp_adaptation_event *);
3140f8829a4aSRandall Stewart 	sai->sai_type = SCTP_ADAPTATION_INDICATION;
3141f8829a4aSRandall Stewart 	sai->sai_flags = 0;
3142f8829a4aSRandall Stewart 	sai->sai_length = sizeof(struct sctp_adaptation_event);
31432afb3e84SRandall Stewart 	sai->sai_adaptation_ind = stcb->asoc.peers_adaptation;
3144f8829a4aSRandall Stewart 	sai->sai_assoc_id = sctp_get_associd(stcb);
3145f8829a4aSRandall Stewart 
3146139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_adaptation_event);
3147139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3148f8829a4aSRandall Stewart 
3149f8829a4aSRandall Stewart 	/* append to socket */
3150f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3151f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3152f8829a4aSRandall Stewart 	    m_notify);
3153f8829a4aSRandall Stewart 	if (control == NULL) {
3154f8829a4aSRandall Stewart 		/* no memory */
3155f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3156f8829a4aSRandall Stewart 		return;
3157f8829a4aSRandall Stewart 	}
3158139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3159139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3160f8829a4aSRandall Stewart 	/* not that we need this */
3161f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
3162f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3163f8829a4aSRandall Stewart 	    control,
3164ceaad40aSRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_SO_NOT_LOCKED);
3165f8829a4aSRandall Stewart }
3166f8829a4aSRandall Stewart 
316703b0b021SRandall Stewart /* This always must be called with the read-queue LOCKED in the INP */
3168f8829a4aSRandall Stewart void
31692dad8a55SRandall Stewart sctp_notify_partial_delivery_indication(struct sctp_tcb *stcb, uint32_t error,
31702dad8a55SRandall Stewart     int nolock, uint32_t val)
3171f8829a4aSRandall Stewart {
3172f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3173f8829a4aSRandall Stewart 	struct sctp_pdapi_event *pdapi;
3174f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
317503b0b021SRandall Stewart 	struct sockbuf *sb;
3176f8829a4aSRandall Stewart 
3177830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_PDAPIEVNT)) {
3178f8829a4aSRandall Stewart 		/* event not enabled */
3179f8829a4aSRandall Stewart 		return;
3180830d754dSRandall Stewart 	}
3181139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_pdapi_event), 0, M_DONTWAIT, 1, MT_DATA);
3182f8829a4aSRandall Stewart 	if (m_notify == NULL)
3183f8829a4aSRandall Stewart 		/* no space left */
3184f8829a4aSRandall Stewart 		return;
3185139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3186f8829a4aSRandall Stewart 	pdapi = mtod(m_notify, struct sctp_pdapi_event *);
3187f8829a4aSRandall Stewart 	pdapi->pdapi_type = SCTP_PARTIAL_DELIVERY_EVENT;
3188f8829a4aSRandall Stewart 	pdapi->pdapi_flags = 0;
3189f8829a4aSRandall Stewart 	pdapi->pdapi_length = sizeof(struct sctp_pdapi_event);
3190f8829a4aSRandall Stewart 	pdapi->pdapi_indication = error;
31919a6142d8SRandall Stewart 	pdapi->pdapi_stream = (val >> 16);
31929a6142d8SRandall Stewart 	pdapi->pdapi_seq = (val & 0x0000ffff);
3193f8829a4aSRandall Stewart 	pdapi->pdapi_assoc_id = sctp_get_associd(stcb);
3194f8829a4aSRandall Stewart 
3195139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_pdapi_event);
3196139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3197f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3198f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3199f8829a4aSRandall Stewart 	    m_notify);
3200f8829a4aSRandall Stewart 	if (control == NULL) {
3201f8829a4aSRandall Stewart 		/* no memory */
3202f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3203f8829a4aSRandall Stewart 		return;
3204f8829a4aSRandall Stewart 	}
3205139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3206139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3207f8829a4aSRandall Stewart 	/* not that we need this */
3208f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
320903b0b021SRandall Stewart 	control->held_length = 0;
321003b0b021SRandall Stewart 	control->length = 0;
321103b0b021SRandall Stewart 	if (nolock == 0) {
321203b0b021SRandall Stewart 		SCTP_INP_READ_LOCK(stcb->sctp_ep);
321303b0b021SRandall Stewart 	}
321403b0b021SRandall Stewart 	sb = &stcb->sctp_socket->so_rcv;
3215b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
3216139bc87fSRandall Stewart 		sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m_notify));
321780fefe0aSRandall Stewart 	}
321803b0b021SRandall Stewart 	sctp_sballoc(stcb, sb, m_notify);
3219b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
322003b0b021SRandall Stewart 		sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
322180fefe0aSRandall Stewart 	}
3222139bc87fSRandall Stewart 	atomic_add_int(&control->length, SCTP_BUF_LEN(m_notify));
322303b0b021SRandall Stewart 	control->end_added = 1;
322403b0b021SRandall Stewart 	if (stcb->asoc.control_pdapi)
322503b0b021SRandall Stewart 		TAILQ_INSERT_AFTER(&stcb->sctp_ep->read_queue, stcb->asoc.control_pdapi, control, next);
322603b0b021SRandall Stewart 	else {
322703b0b021SRandall Stewart 		/* we really should not see this case */
322803b0b021SRandall Stewart 		TAILQ_INSERT_TAIL(&stcb->sctp_ep->read_queue, control, next);
322903b0b021SRandall Stewart 	}
323003b0b021SRandall Stewart 	if (nolock == 0) {
323103b0b021SRandall Stewart 		SCTP_INP_READ_UNLOCK(stcb->sctp_ep);
323203b0b021SRandall Stewart 	}
323303b0b021SRandall Stewart 	if (stcb->sctp_ep && stcb->sctp_socket) {
323403b0b021SRandall Stewart 		/* This should always be the case */
323503b0b021SRandall Stewart 		sctp_sorwakeup(stcb->sctp_ep, stcb->sctp_socket);
3236f8829a4aSRandall Stewart 	}
3237f8829a4aSRandall Stewart }
3238f8829a4aSRandall Stewart 
3239f8829a4aSRandall Stewart static void
3240f8829a4aSRandall Stewart sctp_notify_shutdown_event(struct sctp_tcb *stcb)
3241f8829a4aSRandall Stewart {
3242f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3243f8829a4aSRandall Stewart 	struct sctp_shutdown_event *sse;
3244f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3245f8829a4aSRandall Stewart 
3246f8829a4aSRandall Stewart 	/*
3247f8829a4aSRandall Stewart 	 * For TCP model AND UDP connected sockets we will send an error up
3248f8829a4aSRandall Stewart 	 * when an SHUTDOWN completes
3249f8829a4aSRandall Stewart 	 */
3250f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
3251f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
3252f8829a4aSRandall Stewart 		/* mark socket closed for read/write and wakeup! */
3253ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3254ceaad40aSRandall Stewart 		struct socket *so;
3255ceaad40aSRandall Stewart 
3256ceaad40aSRandall Stewart 		so = SCTP_INP_SO(stcb->sctp_ep);
3257ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
3258ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
3259ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
3260ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
3261ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
3262ceaad40aSRandall Stewart 		if (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET) {
3263ceaad40aSRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
3264ceaad40aSRandall Stewart 			return;
3265ceaad40aSRandall Stewart 		}
3266ceaad40aSRandall Stewart #endif
3267f8829a4aSRandall Stewart 		socantsendmore(stcb->sctp_socket);
3268ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3269ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
3270ceaad40aSRandall Stewart #endif
3271f8829a4aSRandall Stewart 	}
3272830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_RECVSHUTDOWNEVNT)) {
3273f8829a4aSRandall Stewart 		/* event not enabled */
3274f8829a4aSRandall Stewart 		return;
3275830d754dSRandall Stewart 	}
3276139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_shutdown_event), 0, M_DONTWAIT, 1, MT_DATA);
3277f8829a4aSRandall Stewart 	if (m_notify == NULL)
3278f8829a4aSRandall Stewart 		/* no space left */
3279f8829a4aSRandall Stewart 		return;
3280f8829a4aSRandall Stewart 	sse = mtod(m_notify, struct sctp_shutdown_event *);
3281f8829a4aSRandall Stewart 	sse->sse_type = SCTP_SHUTDOWN_EVENT;
3282f8829a4aSRandall Stewart 	sse->sse_flags = 0;
3283f8829a4aSRandall Stewart 	sse->sse_length = sizeof(struct sctp_shutdown_event);
3284f8829a4aSRandall Stewart 	sse->sse_assoc_id = sctp_get_associd(stcb);
3285f8829a4aSRandall Stewart 
3286139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_shutdown_event);
3287139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3288f8829a4aSRandall Stewart 
3289f8829a4aSRandall Stewart 	/* append to socket */
3290f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3291f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3292f8829a4aSRandall Stewart 	    m_notify);
3293f8829a4aSRandall Stewart 	if (control == NULL) {
3294f8829a4aSRandall Stewart 		/* no memory */
3295f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3296f8829a4aSRandall Stewart 		return;
3297f8829a4aSRandall Stewart 	}
3298139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3299139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3300f8829a4aSRandall Stewart 	/* not that we need this */
3301f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
3302f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3303f8829a4aSRandall Stewart 	    control,
3304ceaad40aSRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_SO_NOT_LOCKED);
3305f8829a4aSRandall Stewart }
3306f8829a4aSRandall Stewart 
3307f8829a4aSRandall Stewart static void
3308830d754dSRandall Stewart sctp_notify_sender_dry_event(struct sctp_tcb *stcb,
3309830d754dSRandall Stewart     int so_locked
3310830d754dSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3311830d754dSRandall Stewart     SCTP_UNUSED
3312830d754dSRandall Stewart #endif
3313830d754dSRandall Stewart )
3314830d754dSRandall Stewart {
3315830d754dSRandall Stewart 	struct mbuf *m_notify;
3316830d754dSRandall Stewart 	struct sctp_sender_dry_event *event;
3317830d754dSRandall Stewart 	struct sctp_queued_to_read *control;
3318830d754dSRandall Stewart 
3319830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_DRYEVNT)) {
3320830d754dSRandall Stewart 		/* event not enabled */
3321830d754dSRandall Stewart 		return;
3322830d754dSRandall Stewart 	}
3323830d754dSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_sender_dry_event), 0, M_DONTWAIT, 1, MT_DATA);
3324830d754dSRandall Stewart 	if (m_notify == NULL) {
3325830d754dSRandall Stewart 		/* no space left */
3326830d754dSRandall Stewart 		return;
3327830d754dSRandall Stewart 	}
3328830d754dSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3329830d754dSRandall Stewart 	event = mtod(m_notify, struct sctp_sender_dry_event *);
3330830d754dSRandall Stewart 	event->sender_dry_type = SCTP_SENDER_DRY_EVENT;
3331830d754dSRandall Stewart 	event->sender_dry_flags = 0;
3332830d754dSRandall Stewart 	event->sender_dry_length = sizeof(struct sctp_sender_dry_event);
3333830d754dSRandall Stewart 	event->sender_dry_assoc_id = sctp_get_associd(stcb);
3334830d754dSRandall Stewart 
3335830d754dSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_sender_dry_event);
3336830d754dSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3337830d754dSRandall Stewart 
3338830d754dSRandall Stewart 	/* append to socket */
3339830d754dSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3340830d754dSRandall Stewart 	    0, 0, 0, 0, 0, 0, m_notify);
3341830d754dSRandall Stewart 	if (control == NULL) {
3342830d754dSRandall Stewart 		/* no memory */
3343830d754dSRandall Stewart 		sctp_m_freem(m_notify);
3344830d754dSRandall Stewart 		return;
3345830d754dSRandall Stewart 	}
3346830d754dSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3347830d754dSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3348830d754dSRandall Stewart 	/* not that we need this */
3349830d754dSRandall Stewart 	control->tail_mbuf = m_notify;
3350830d754dSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb, control,
3351830d754dSRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, so_locked);
3352830d754dSRandall Stewart }
3353830d754dSRandall Stewart 
3354830d754dSRandall Stewart static void
3355f8829a4aSRandall Stewart sctp_notify_stream_reset(struct sctp_tcb *stcb,
3356f8829a4aSRandall Stewart     int number_entries, uint16_t * list, int flag)
3357f8829a4aSRandall Stewart {
3358f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3359f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3360f8829a4aSRandall Stewart 	struct sctp_stream_reset_event *strreset;
3361f8829a4aSRandall Stewart 	int len;
3362f8829a4aSRandall Stewart 
3363830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_STREAM_RESETEVNT)) {
3364f8829a4aSRandall Stewart 		/* event not enabled */
3365f8829a4aSRandall Stewart 		return;
3366830d754dSRandall Stewart 	}
3367139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(MCLBYTES, 0, M_DONTWAIT, 1, MT_DATA);
3368f8829a4aSRandall Stewart 	if (m_notify == NULL)
3369f8829a4aSRandall Stewart 		/* no space left */
3370f8829a4aSRandall Stewart 		return;
3371139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3372f8829a4aSRandall Stewart 	len = sizeof(struct sctp_stream_reset_event) + (number_entries * sizeof(uint16_t));
3373f8829a4aSRandall Stewart 	if (len > M_TRAILINGSPACE(m_notify)) {
3374f8829a4aSRandall Stewart 		/* never enough room */
3375f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3376f8829a4aSRandall Stewart 		return;
3377f8829a4aSRandall Stewart 	}
3378f8829a4aSRandall Stewart 	strreset = mtod(m_notify, struct sctp_stream_reset_event *);
3379f8829a4aSRandall Stewart 	strreset->strreset_type = SCTP_STREAM_RESET_EVENT;
3380f8829a4aSRandall Stewart 	if (number_entries == 0) {
3381f8829a4aSRandall Stewart 		strreset->strreset_flags = flag | SCTP_STRRESET_ALL_STREAMS;
3382f8829a4aSRandall Stewart 	} else {
3383f8829a4aSRandall Stewart 		strreset->strreset_flags = flag | SCTP_STRRESET_STREAM_LIST;
3384f8829a4aSRandall Stewart 	}
3385f8829a4aSRandall Stewart 	strreset->strreset_length = len;
3386f8829a4aSRandall Stewart 	strreset->strreset_assoc_id = sctp_get_associd(stcb);
3387f8829a4aSRandall Stewart 	if (number_entries) {
3388f8829a4aSRandall Stewart 		int i;
3389f8829a4aSRandall Stewart 
3390f8829a4aSRandall Stewart 		for (i = 0; i < number_entries; i++) {
3391f8829a4aSRandall Stewart 			strreset->strreset_list[i] = ntohs(list[i]);
3392f8829a4aSRandall Stewart 		}
3393f8829a4aSRandall Stewart 	}
3394139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = len;
3395139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3396139bc87fSRandall Stewart 	if (sctp_sbspace(&stcb->asoc, &stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3397f8829a4aSRandall Stewart 		/* no space */
3398f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3399f8829a4aSRandall Stewart 		return;
3400f8829a4aSRandall Stewart 	}
3401f8829a4aSRandall Stewart 	/* append to socket */
3402f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3403f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3404f8829a4aSRandall Stewart 	    m_notify);
3405f8829a4aSRandall Stewart 	if (control == NULL) {
3406f8829a4aSRandall Stewart 		/* no memory */
3407f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3408f8829a4aSRandall Stewart 		return;
3409f8829a4aSRandall Stewart 	}
3410139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3411139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3412f8829a4aSRandall Stewart 	/* not that we need this */
3413f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
3414f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3415f8829a4aSRandall Stewart 	    control,
3416ceaad40aSRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_SO_NOT_LOCKED);
3417f8829a4aSRandall Stewart }
3418f8829a4aSRandall Stewart 
3419f8829a4aSRandall Stewart 
3420f8829a4aSRandall Stewart void
3421f8829a4aSRandall Stewart sctp_ulp_notify(uint32_t notification, struct sctp_tcb *stcb,
3422ceaad40aSRandall Stewart     uint32_t error, void *data, int so_locked
3423ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3424ceaad40aSRandall Stewart     SCTP_UNUSED
3425ceaad40aSRandall Stewart #endif
3426ceaad40aSRandall Stewart )
3427f8829a4aSRandall Stewart {
3428830d754dSRandall Stewart 	if ((stcb == NULL) ||
3429830d754dSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
3430f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
3431830d754dSRandall Stewart 	    (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET)) {
3432830d754dSRandall Stewart 		/* If the socket is gone we are out of here */
3433f8829a4aSRandall Stewart 		return;
3434f8829a4aSRandall Stewart 	}
3435a99b6783SRandall Stewart 	if (stcb->sctp_socket->so_rcv.sb_state & SBS_CANTRCVMORE) {
3436a99b6783SRandall Stewart 		return;
3437a99b6783SRandall Stewart 	}
343817205eccSRandall Stewart 	if (stcb && ((stcb->asoc.state & SCTP_STATE_COOKIE_WAIT) ||
343917205eccSRandall Stewart 	    (stcb->asoc.state & SCTP_STATE_COOKIE_ECHOED))) {
344017205eccSRandall Stewart 		if ((notification == SCTP_NOTIFY_INTERFACE_DOWN) ||
344117205eccSRandall Stewart 		    (notification == SCTP_NOTIFY_INTERFACE_UP) ||
344217205eccSRandall Stewart 		    (notification == SCTP_NOTIFY_INTERFACE_CONFIRMED)) {
344317205eccSRandall Stewart 			/* Don't report these in front states */
344417205eccSRandall Stewart 			return;
344517205eccSRandall Stewart 		}
344617205eccSRandall Stewart 	}
3447f8829a4aSRandall Stewart 	switch (notification) {
3448f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_UP:
3449f8829a4aSRandall Stewart 		if (stcb->asoc.assoc_up_sent == 0) {
3450ceaad40aSRandall Stewart 			sctp_notify_assoc_change(SCTP_COMM_UP, stcb, error, NULL, so_locked);
3451f8829a4aSRandall Stewart 			stcb->asoc.assoc_up_sent = 1;
3452f8829a4aSRandall Stewart 		}
34532afb3e84SRandall Stewart 		if (stcb->asoc.adaptation_needed && (stcb->asoc.adaptation_sent == 0)) {
34542afb3e84SRandall Stewart 			sctp_notify_adaptation_layer(stcb, error);
34552afb3e84SRandall Stewart 		}
3456830d754dSRandall Stewart 		if (stcb->asoc.peer_supports_auth == 0) {
3457830d754dSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_NO_PEER_AUTH, stcb, 0,
3458830d754dSRandall Stewart 			    NULL, so_locked);
3459830d754dSRandall Stewart 		}
3460f8829a4aSRandall Stewart 		break;
3461f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_DOWN:
3462ceaad40aSRandall Stewart 		sctp_notify_assoc_change(SCTP_SHUTDOWN_COMP, stcb, error, NULL, so_locked);
3463f8829a4aSRandall Stewart 		break;
3464f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_DOWN:
3465f8829a4aSRandall Stewart 		{
3466f8829a4aSRandall Stewart 			struct sctp_nets *net;
3467f8829a4aSRandall Stewart 
3468f8829a4aSRandall Stewart 			net = (struct sctp_nets *)data;
3469f8829a4aSRandall Stewart 			sctp_notify_peer_addr_change(stcb, SCTP_ADDR_UNREACHABLE,
3470f8829a4aSRandall Stewart 			    (struct sockaddr *)&net->ro._l_addr, error);
3471f8829a4aSRandall Stewart 			break;
3472f8829a4aSRandall Stewart 		}
3473f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_UP:
3474f8829a4aSRandall Stewart 		{
3475f8829a4aSRandall Stewart 			struct sctp_nets *net;
3476f8829a4aSRandall Stewart 
3477f8829a4aSRandall Stewart 			net = (struct sctp_nets *)data;
3478f8829a4aSRandall Stewart 			sctp_notify_peer_addr_change(stcb, SCTP_ADDR_AVAILABLE,
3479f8829a4aSRandall Stewart 			    (struct sockaddr *)&net->ro._l_addr, error);
3480f8829a4aSRandall Stewart 			break;
3481f8829a4aSRandall Stewart 		}
3482f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_CONFIRMED:
3483f8829a4aSRandall Stewart 		{
3484f8829a4aSRandall Stewart 			struct sctp_nets *net;
3485f8829a4aSRandall Stewart 
3486f8829a4aSRandall Stewart 			net = (struct sctp_nets *)data;
3487f8829a4aSRandall Stewart 			sctp_notify_peer_addr_change(stcb, SCTP_ADDR_CONFIRMED,
3488f8829a4aSRandall Stewart 			    (struct sockaddr *)&net->ro._l_addr, error);
3489f8829a4aSRandall Stewart 			break;
3490f8829a4aSRandall Stewart 		}
3491f8829a4aSRandall Stewart 	case SCTP_NOTIFY_SPECIAL_SP_FAIL:
3492f8829a4aSRandall Stewart 		sctp_notify_send_failed2(stcb, error,
3493ceaad40aSRandall Stewart 		    (struct sctp_stream_queue_pending *)data, so_locked);
3494f8829a4aSRandall Stewart 		break;
3495f8829a4aSRandall Stewart 	case SCTP_NOTIFY_DG_FAIL:
3496f8829a4aSRandall Stewart 		sctp_notify_send_failed(stcb, error,
3497ceaad40aSRandall Stewart 		    (struct sctp_tmit_chunk *)data, so_locked);
3498f8829a4aSRandall Stewart 		break;
3499f8829a4aSRandall Stewart 	case SCTP_NOTIFY_PARTIAL_DELVIERY_INDICATION:
35009a6142d8SRandall Stewart 		{
35019a6142d8SRandall Stewart 			uint32_t val;
35029a6142d8SRandall Stewart 
35039a6142d8SRandall Stewart 			val = *((uint32_t *) data);
35049a6142d8SRandall Stewart 
35059a6142d8SRandall Stewart 			sctp_notify_partial_delivery_indication(stcb, error, 0, val);
35069a6142d8SRandall Stewart 		}
3507f8829a4aSRandall Stewart 		break;
3508f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STRDATA_ERR:
3509f8829a4aSRandall Stewart 		break;
3510f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_ABORTED:
3511c105859eSRandall Stewart 		if ((stcb) && (((stcb->asoc.state & SCTP_STATE_MASK) == SCTP_STATE_COOKIE_WAIT) ||
3512c105859eSRandall Stewart 		    ((stcb->asoc.state & SCTP_STATE_MASK) == SCTP_STATE_COOKIE_ECHOED))) {
3513ceaad40aSRandall Stewart 			sctp_notify_assoc_change(SCTP_CANT_STR_ASSOC, stcb, error, NULL, so_locked);
3514c105859eSRandall Stewart 		} else {
3515ceaad40aSRandall Stewart 			sctp_notify_assoc_change(SCTP_COMM_LOST, stcb, error, NULL, so_locked);
3516c105859eSRandall Stewart 		}
3517f8829a4aSRandall Stewart 		break;
3518f8829a4aSRandall Stewart 	case SCTP_NOTIFY_PEER_OPENED_STREAM:
3519f8829a4aSRandall Stewart 		break;
3520f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STREAM_OPENED_OK:
3521f8829a4aSRandall Stewart 		break;
3522f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_RESTART:
3523ceaad40aSRandall Stewart 		sctp_notify_assoc_change(SCTP_RESTART, stcb, error, data, so_locked);
3524830d754dSRandall Stewart 		if (stcb->asoc.peer_supports_auth == 0) {
3525830d754dSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_NO_PEER_AUTH, stcb, 0,
3526830d754dSRandall Stewart 			    NULL, so_locked);
3527830d754dSRandall Stewart 		}
3528f8829a4aSRandall Stewart 		break;
3529f8829a4aSRandall Stewart 	case SCTP_NOTIFY_HB_RESP:
3530f8829a4aSRandall Stewart 		break;
3531f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_SEND:
3532f8829a4aSRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data), SCTP_STRRESET_OUTBOUND_STR);
3533f8829a4aSRandall Stewart 		break;
3534f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_RECV:
3535f8829a4aSRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data), SCTP_STRRESET_INBOUND_STR);
3536f8829a4aSRandall Stewart 		break;
3537f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_FAILED_OUT:
3538671d309cSRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data), (SCTP_STRRESET_OUTBOUND_STR | SCTP_STRRESET_FAILED));
3539f8829a4aSRandall Stewart 		break;
3540f8829a4aSRandall Stewart 
3541f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_FAILED_IN:
3542671d309cSRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data), (SCTP_STRRESET_INBOUND_STR | SCTP_STRRESET_FAILED));
3543f8829a4aSRandall Stewart 		break;
3544f8829a4aSRandall Stewart 
3545f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_ADD_IP:
3546f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_ADDED, data,
3547f8829a4aSRandall Stewart 		    error);
3548f8829a4aSRandall Stewart 		break;
3549f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_DELETE_IP:
3550f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_REMOVED, data,
3551f8829a4aSRandall Stewart 		    error);
3552f8829a4aSRandall Stewart 		break;
3553f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_SET_PRIMARY:
3554f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_MADE_PRIM, data,
3555f8829a4aSRandall Stewart 		    error);
3556f8829a4aSRandall Stewart 		break;
3557f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_SUCCESS:
3558f8829a4aSRandall Stewart 		break;
3559f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_FAILED:
3560f8829a4aSRandall Stewart 		break;
3561f8829a4aSRandall Stewart 	case SCTP_NOTIFY_PEER_SHUTDOWN:
3562f8829a4aSRandall Stewart 		sctp_notify_shutdown_event(stcb);
3563f8829a4aSRandall Stewart 		break;
3564f8829a4aSRandall Stewart 	case SCTP_NOTIFY_AUTH_NEW_KEY:
3565f8829a4aSRandall Stewart 		sctp_notify_authentication(stcb, SCTP_AUTH_NEWKEY, error,
3566830d754dSRandall Stewart 		    (uint16_t) (uintptr_t) data,
3567830d754dSRandall Stewart 		    so_locked);
3568f8829a4aSRandall Stewart 		break;
3569830d754dSRandall Stewart 	case SCTP_NOTIFY_AUTH_FREE_KEY:
3570830d754dSRandall Stewart 		sctp_notify_authentication(stcb, SCTP_AUTH_FREE_KEY, error,
3571830d754dSRandall Stewart 		    (uint16_t) (uintptr_t) data,
3572830d754dSRandall Stewart 		    so_locked);
3573f8829a4aSRandall Stewart 		break;
3574830d754dSRandall Stewart 	case SCTP_NOTIFY_NO_PEER_AUTH:
3575830d754dSRandall Stewart 		sctp_notify_authentication(stcb, SCTP_AUTH_NO_AUTH, error,
3576830d754dSRandall Stewart 		    (uint16_t) (uintptr_t) data,
3577830d754dSRandall Stewart 		    so_locked);
3578830d754dSRandall Stewart 		break;
3579830d754dSRandall Stewart 	case SCTP_NOTIFY_SENDER_DRY:
3580830d754dSRandall Stewart 		sctp_notify_sender_dry_event(stcb, so_locked);
3581830d754dSRandall Stewart 		break;
3582f8829a4aSRandall Stewart 	default:
3583ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_UTIL1, "%s: unknown notification %xh (%u)\n",
3584ad81507eSRandall Stewart 		    __FUNCTION__, notification, notification);
3585f8829a4aSRandall Stewart 		break;
3586f8829a4aSRandall Stewart 	}			/* end switch */
3587f8829a4aSRandall Stewart }
3588f8829a4aSRandall Stewart 
3589f8829a4aSRandall Stewart void
3590ceaad40aSRandall Stewart sctp_report_all_outbound(struct sctp_tcb *stcb, int holds_lock, int so_locked
3591ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3592ceaad40aSRandall Stewart     SCTP_UNUSED
3593ceaad40aSRandall Stewart #endif
3594ceaad40aSRandall Stewart )
3595f8829a4aSRandall Stewart {
3596f8829a4aSRandall Stewart 	struct sctp_association *asoc;
3597f8829a4aSRandall Stewart 	struct sctp_stream_out *outs;
3598f8829a4aSRandall Stewart 	struct sctp_tmit_chunk *chk;
3599f8829a4aSRandall Stewart 	struct sctp_stream_queue_pending *sp;
36007f34832bSRandall Stewart 	int i;
3601f8829a4aSRandall Stewart 
3602f8829a4aSRandall Stewart 	asoc = &stcb->asoc;
3603f8829a4aSRandall Stewart 
3604ad81507eSRandall Stewart 	if (stcb == NULL) {
3605ad81507eSRandall Stewart 		return;
3606ad81507eSRandall Stewart 	}
3607f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
3608f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
3609f8829a4aSRandall Stewart 	    (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET)) {
3610f8829a4aSRandall Stewart 		return;
3611f8829a4aSRandall Stewart 	}
3612f8829a4aSRandall Stewart 	/* now through all the gunk freeing chunks */
3613ad81507eSRandall Stewart 	if (holds_lock == 0) {
36147f34832bSRandall Stewart 		SCTP_TCB_SEND_LOCK(stcb);
3615ad81507eSRandall Stewart 	}
3616d00aff5dSRandall Stewart 	/* sent queue SHOULD be empty */
3617d00aff5dSRandall Stewart 	if (!TAILQ_EMPTY(&asoc->sent_queue)) {
3618d00aff5dSRandall Stewart 		chk = TAILQ_FIRST(&asoc->sent_queue);
3619d00aff5dSRandall Stewart 		while (chk) {
3620d00aff5dSRandall Stewart 			TAILQ_REMOVE(&asoc->sent_queue, chk, sctp_next);
3621d00aff5dSRandall Stewart 			asoc->sent_queue_cnt--;
3622d00aff5dSRandall Stewart 			sctp_free_bufspace(stcb, asoc, chk, 1);
3623d00aff5dSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_DG_FAIL, stcb,
3624ceaad40aSRandall Stewart 			    SCTP_NOTIFY_DATAGRAM_SENT, chk, so_locked);
3625d00aff5dSRandall Stewart 			if (chk->data) {
3626d00aff5dSRandall Stewart 				sctp_m_freem(chk->data);
3627d00aff5dSRandall Stewart 				chk->data = NULL;
3628d00aff5dSRandall Stewart 			}
3629d00aff5dSRandall Stewart 			sctp_free_a_chunk(stcb, chk);
3630d00aff5dSRandall Stewart 			/* sa_ignore FREED_MEMORY */
3631d00aff5dSRandall Stewart 			chk = TAILQ_FIRST(&asoc->sent_queue);
3632d00aff5dSRandall Stewart 		}
3633d00aff5dSRandall Stewart 	}
3634d00aff5dSRandall Stewart 	/* pending send queue SHOULD be empty */
3635d00aff5dSRandall Stewart 	if (!TAILQ_EMPTY(&asoc->send_queue)) {
3636d00aff5dSRandall Stewart 		chk = TAILQ_FIRST(&asoc->send_queue);
3637d00aff5dSRandall Stewart 		while (chk) {
3638d00aff5dSRandall Stewart 			TAILQ_REMOVE(&asoc->send_queue, chk, sctp_next);
3639d00aff5dSRandall Stewart 			asoc->send_queue_cnt--;
3640d00aff5dSRandall Stewart 			sctp_free_bufspace(stcb, asoc, chk, 1);
3641ceaad40aSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_DG_FAIL, stcb, SCTP_NOTIFY_DATAGRAM_UNSENT, chk, so_locked);
3642d00aff5dSRandall Stewart 			if (chk->data) {
3643d00aff5dSRandall Stewart 				sctp_m_freem(chk->data);
3644d00aff5dSRandall Stewart 				chk->data = NULL;
3645d00aff5dSRandall Stewart 			}
3646d00aff5dSRandall Stewart 			sctp_free_a_chunk(stcb, chk);
3647d00aff5dSRandall Stewart 			/* sa_ignore FREED_MEMORY */
3648d00aff5dSRandall Stewart 			chk = TAILQ_FIRST(&asoc->send_queue);
3649d00aff5dSRandall Stewart 		}
3650d00aff5dSRandall Stewart 	}
36517f34832bSRandall Stewart 	for (i = 0; i < stcb->asoc.streamoutcnt; i++) {
36527f34832bSRandall Stewart 		/* For each stream */
36537f34832bSRandall Stewart 		outs = &stcb->asoc.strmout[i];
36547f34832bSRandall Stewart 		/* clean up any sends there */
3655f8829a4aSRandall Stewart 		stcb->asoc.locked_on_sending = NULL;
3656f8829a4aSRandall Stewart 		sp = TAILQ_FIRST(&outs->outqueue);
3657f8829a4aSRandall Stewart 		while (sp) {
3658f8829a4aSRandall Stewart 			stcb->asoc.stream_queue_cnt--;
3659f8829a4aSRandall Stewart 			TAILQ_REMOVE(&outs->outqueue, sp, next);
3660f8829a4aSRandall Stewart 			sctp_free_spbufspace(stcb, asoc, sp);
3661f8829a4aSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_SPECIAL_SP_FAIL, stcb,
3662ceaad40aSRandall Stewart 			    SCTP_NOTIFY_DATAGRAM_UNSENT, (void *)sp, so_locked);
3663f8829a4aSRandall Stewart 			if (sp->data) {
3664f8829a4aSRandall Stewart 				sctp_m_freem(sp->data);
3665f8829a4aSRandall Stewart 				sp->data = NULL;
3666f8829a4aSRandall Stewart 			}
3667f8829a4aSRandall Stewart 			if (sp->net)
3668f8829a4aSRandall Stewart 				sctp_free_remote_addr(sp->net);
3669f8829a4aSRandall Stewart 			sp->net = NULL;
3670f8829a4aSRandall Stewart 			/* Free the chunk */
3671f8829a4aSRandall Stewart 			sctp_free_a_strmoq(stcb, sp);
36723c503c28SRandall Stewart 			/* sa_ignore FREED_MEMORY */
3673f8829a4aSRandall Stewart 			sp = TAILQ_FIRST(&outs->outqueue);
3674f8829a4aSRandall Stewart 		}
3675f8829a4aSRandall Stewart 	}
3676f8829a4aSRandall Stewart 
3677ad81507eSRandall Stewart 	if (holds_lock == 0) {
36787f34832bSRandall Stewart 		SCTP_TCB_SEND_UNLOCK(stcb);
3679f8829a4aSRandall Stewart 	}
3680ad81507eSRandall Stewart }
3681f8829a4aSRandall Stewart 
3682f8829a4aSRandall Stewart void
3683ceaad40aSRandall Stewart sctp_abort_notification(struct sctp_tcb *stcb, int error, int so_locked
3684ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3685ceaad40aSRandall Stewart     SCTP_UNUSED
3686ceaad40aSRandall Stewart #endif
3687ceaad40aSRandall Stewart )
3688f8829a4aSRandall Stewart {
3689f8829a4aSRandall Stewart 
3690ad81507eSRandall Stewart 	if (stcb == NULL) {
3691ad81507eSRandall Stewart 		return;
3692ad81507eSRandall Stewart 	}
3693f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
3694f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
3695f8829a4aSRandall Stewart 	    (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET)) {
3696f8829a4aSRandall Stewart 		return;
3697f8829a4aSRandall Stewart 	}
3698f8829a4aSRandall Stewart 	/* Tell them we lost the asoc */
3699ceaad40aSRandall Stewart 	sctp_report_all_outbound(stcb, 1, so_locked);
3700f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL) ||
3701f8829a4aSRandall Stewart 	    ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) &&
3702f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_CONNECTED))) {
3703f8829a4aSRandall Stewart 		stcb->sctp_ep->sctp_flags |= SCTP_PCB_FLAGS_WAS_ABORTED;
3704f8829a4aSRandall Stewart 	}
3705ceaad40aSRandall Stewart 	sctp_ulp_notify(SCTP_NOTIFY_ASSOC_ABORTED, stcb, error, NULL, so_locked);
3706f8829a4aSRandall Stewart }
3707f8829a4aSRandall Stewart 
3708f8829a4aSRandall Stewart void
3709f8829a4aSRandall Stewart sctp_abort_association(struct sctp_inpcb *inp, struct sctp_tcb *stcb,
371017205eccSRandall Stewart     struct mbuf *m, int iphlen, struct sctphdr *sh, struct mbuf *op_err,
3711c54a18d2SRandall Stewart     uint32_t vrf_id, uint16_t port)
3712f8829a4aSRandall Stewart {
3713f8829a4aSRandall Stewart 	uint32_t vtag;
3714f8829a4aSRandall Stewart 
3715ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3716ceaad40aSRandall Stewart 	struct socket *so;
3717ceaad40aSRandall Stewart 
3718ceaad40aSRandall Stewart #endif
3719ceaad40aSRandall Stewart 
3720f8829a4aSRandall Stewart 	vtag = 0;
3721f8829a4aSRandall Stewart 	if (stcb != NULL) {
3722f8829a4aSRandall Stewart 		/* We have a TCB to abort, send notification too */
3723f8829a4aSRandall Stewart 		vtag = stcb->asoc.peer_vtag;
3724ceaad40aSRandall Stewart 		sctp_abort_notification(stcb, 0, SCTP_SO_NOT_LOCKED);
372517205eccSRandall Stewart 		/* get the assoc vrf id and table id */
372617205eccSRandall Stewart 		vrf_id = stcb->asoc.vrf_id;
372763981c2bSRandall Stewart 		stcb->asoc.state |= SCTP_STATE_WAS_ABORTED;
3728f8829a4aSRandall Stewart 	}
3729c54a18d2SRandall Stewart 	sctp_send_abort(m, iphlen, sh, vtag, op_err, vrf_id, port);
3730f8829a4aSRandall Stewart 	if (stcb != NULL) {
3731f8829a4aSRandall Stewart 		/* Ok, now lets free it */
3732ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3733ceaad40aSRandall Stewart 		so = SCTP_INP_SO(inp);
3734ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
3735ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
3736ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
3737ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
3738ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
3739ceaad40aSRandall Stewart #endif
3740c4739e2fSRandall Stewart 		(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC, SCTP_FROM_SCTPUTIL + SCTP_LOC_4);
3741ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3742ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
3743ceaad40aSRandall Stewart #endif
3744f8829a4aSRandall Stewart 	} else {
3745f8829a4aSRandall Stewart 		if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
3746f8829a4aSRandall Stewart 			if (LIST_FIRST(&inp->sctp_asoc_list) == NULL) {
3747b0552ae2SRandall Stewart 				sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
3748b0552ae2SRandall Stewart 				    SCTP_CALLED_DIRECTLY_NOCMPSET);
3749f8829a4aSRandall Stewart 			}
3750f8829a4aSRandall Stewart 		}
3751f8829a4aSRandall Stewart 	}
3752f8829a4aSRandall Stewart }
3753f8829a4aSRandall Stewart 
3754f1f73e57SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
3755f1f73e57SRandall Stewart void
3756f1f73e57SRandall Stewart sctp_print_out_track_log(struct sctp_tcb *stcb)
3757f1f73e57SRandall Stewart {
375818e198d3SRandall Stewart #ifdef NOSIY_PRINTS
3759f1f73e57SRandall Stewart 	int i;
3760f1f73e57SRandall Stewart 
3761ad81507eSRandall Stewart 	SCTP_PRINTF("Last ep reason:%x\n", stcb->sctp_ep->last_abort_code);
3762ad81507eSRandall Stewart 	SCTP_PRINTF("IN bound TSN log-aaa\n");
3763f1f73e57SRandall Stewart 	if ((stcb->asoc.tsn_in_at == 0) && (stcb->asoc.tsn_in_wrapped == 0)) {
3764ad81507eSRandall Stewart 		SCTP_PRINTF("None rcvd\n");
3765f1f73e57SRandall Stewart 		goto none_in;
3766f1f73e57SRandall Stewart 	}
3767f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_in_wrapped) {
3768f1f73e57SRandall Stewart 		for (i = stcb->asoc.tsn_in_at; i < SCTP_TSN_LOG_SIZE; i++) {
3769ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
3770f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].tsn,
3771f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].strm,
3772f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].seq,
3773f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].flgs,
3774f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].sz);
3775f1f73e57SRandall Stewart 		}
3776f1f73e57SRandall Stewart 	}
3777f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_in_at) {
3778f1f73e57SRandall Stewart 		for (i = 0; i < stcb->asoc.tsn_in_at; i++) {
3779ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
3780f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].tsn,
3781f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].strm,
3782f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].seq,
3783f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].flgs,
3784f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].sz);
3785f1f73e57SRandall Stewart 		}
3786f1f73e57SRandall Stewart 	}
3787f1f73e57SRandall Stewart none_in:
3788ad81507eSRandall Stewart 	SCTP_PRINTF("OUT bound TSN log-aaa\n");
3789ad81507eSRandall Stewart 	if ((stcb->asoc.tsn_out_at == 0) &&
3790ad81507eSRandall Stewart 	    (stcb->asoc.tsn_out_wrapped == 0)) {
3791ad81507eSRandall Stewart 		SCTP_PRINTF("None sent\n");
3792f1f73e57SRandall Stewart 	}
3793f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_out_wrapped) {
3794f1f73e57SRandall Stewart 		for (i = stcb->asoc.tsn_out_at; i < SCTP_TSN_LOG_SIZE; i++) {
3795ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
3796f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].tsn,
3797f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].strm,
3798f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].seq,
3799f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].flgs,
3800f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].sz);
3801f1f73e57SRandall Stewart 		}
3802f1f73e57SRandall Stewart 	}
3803f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_out_at) {
3804f1f73e57SRandall Stewart 		for (i = 0; i < stcb->asoc.tsn_out_at; i++) {
3805ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
3806f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].tsn,
3807f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].strm,
3808f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].seq,
3809f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].flgs,
3810f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].sz);
3811f1f73e57SRandall Stewart 		}
3812f1f73e57SRandall Stewart 	}
381318e198d3SRandall Stewart #endif
3814f1f73e57SRandall Stewart }
3815f1f73e57SRandall Stewart 
3816f1f73e57SRandall Stewart #endif
3817f1f73e57SRandall Stewart 
3818f8829a4aSRandall Stewart void
3819f8829a4aSRandall Stewart sctp_abort_an_association(struct sctp_inpcb *inp, struct sctp_tcb *stcb,
3820ceaad40aSRandall Stewart     int error, struct mbuf *op_err,
3821ceaad40aSRandall Stewart     int so_locked
3822ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3823ceaad40aSRandall Stewart     SCTP_UNUSED
3824ceaad40aSRandall Stewart #endif
3825ceaad40aSRandall Stewart )
3826f8829a4aSRandall Stewart {
3827f8829a4aSRandall Stewart 	uint32_t vtag;
3828f8829a4aSRandall Stewart 
3829ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3830ceaad40aSRandall Stewart 	struct socket *so;
3831ceaad40aSRandall Stewart 
3832ceaad40aSRandall Stewart #endif
3833ceaad40aSRandall Stewart 
3834ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3835ceaad40aSRandall Stewart 	so = SCTP_INP_SO(inp);
3836ceaad40aSRandall Stewart #endif
3837f8829a4aSRandall Stewart 	if (stcb == NULL) {
3838f8829a4aSRandall Stewart 		/* Got to have a TCB */
3839f8829a4aSRandall Stewart 		if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
3840f8829a4aSRandall Stewart 			if (LIST_FIRST(&inp->sctp_asoc_list) == NULL) {
3841b0552ae2SRandall Stewart 				sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
3842b0552ae2SRandall Stewart 				    SCTP_CALLED_DIRECTLY_NOCMPSET);
3843f8829a4aSRandall Stewart 			}
3844f8829a4aSRandall Stewart 		}
3845f8829a4aSRandall Stewart 		return;
384663981c2bSRandall Stewart 	} else {
384763981c2bSRandall Stewart 		stcb->asoc.state |= SCTP_STATE_WAS_ABORTED;
3848f8829a4aSRandall Stewart 	}
3849f8829a4aSRandall Stewart 	vtag = stcb->asoc.peer_vtag;
3850f8829a4aSRandall Stewart 	/* notify the ulp */
3851f8829a4aSRandall Stewart 	if ((inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) == 0)
3852ceaad40aSRandall Stewart 		sctp_abort_notification(stcb, error, so_locked);
3853f8829a4aSRandall Stewart 	/* notify the peer */
3854b201f536SRandall Stewart #if defined(SCTP_PANIC_ON_ABORT)
3855b201f536SRandall Stewart 	panic("aborting an association");
3856b201f536SRandall Stewart #endif
3857ceaad40aSRandall Stewart 	sctp_send_abort_tcb(stcb, op_err, so_locked);
3858f8829a4aSRandall Stewart 	SCTP_STAT_INCR_COUNTER32(sctps_aborted);
3859f8829a4aSRandall Stewart 	if ((SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_OPEN) ||
3860f8829a4aSRandall Stewart 	    (SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_SHUTDOWN_RECEIVED)) {
3861f8829a4aSRandall Stewart 		SCTP_STAT_DECR_GAUGE32(sctps_currestab);
3862f8829a4aSRandall Stewart 	}
3863f8829a4aSRandall Stewart 	/* now free the asoc */
3864f1f73e57SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
3865f1f73e57SRandall Stewart 	sctp_print_out_track_log(stcb);
3866f1f73e57SRandall Stewart #endif
3867ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3868ceaad40aSRandall Stewart 	if (!so_locked) {
3869ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
3870ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
3871ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
3872ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
3873ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
3874ceaad40aSRandall Stewart 	}
3875ceaad40aSRandall Stewart #endif
3876c4739e2fSRandall Stewart 	(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC, SCTP_FROM_SCTPUTIL + SCTP_LOC_5);
3877ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3878ceaad40aSRandall Stewart 	if (!so_locked) {
3879ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
3880ceaad40aSRandall Stewart 	}
3881ceaad40aSRandall Stewart #endif
3882f8829a4aSRandall Stewart }
3883f8829a4aSRandall Stewart 
3884f8829a4aSRandall Stewart void
3885f8829a4aSRandall Stewart sctp_handle_ootb(struct mbuf *m, int iphlen, int offset, struct sctphdr *sh,
3886c54a18d2SRandall Stewart     struct sctp_inpcb *inp, struct mbuf *op_err, uint32_t vrf_id, uint16_t port)
3887f8829a4aSRandall Stewart {
3888f8829a4aSRandall Stewart 	struct sctp_chunkhdr *ch, chunk_buf;
3889f8829a4aSRandall Stewart 	unsigned int chk_length;
3890f8829a4aSRandall Stewart 
3891f8829a4aSRandall Stewart 	SCTP_STAT_INCR_COUNTER32(sctps_outoftheblue);
3892f8829a4aSRandall Stewart 	/* Generate a TO address for future reference */
3893f8829a4aSRandall Stewart 	if (inp && (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE)) {
3894f8829a4aSRandall Stewart 		if (LIST_FIRST(&inp->sctp_asoc_list) == NULL) {
3895b0552ae2SRandall Stewart 			sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
3896b0552ae2SRandall Stewart 			    SCTP_CALLED_DIRECTLY_NOCMPSET);
3897f8829a4aSRandall Stewart 		}
3898f8829a4aSRandall Stewart 	}
3899f8829a4aSRandall Stewart 	ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
3900f8829a4aSRandall Stewart 	    sizeof(*ch), (uint8_t *) & chunk_buf);
3901f8829a4aSRandall Stewart 	while (ch != NULL) {
3902f8829a4aSRandall Stewart 		chk_length = ntohs(ch->chunk_length);
3903f8829a4aSRandall Stewart 		if (chk_length < sizeof(*ch)) {
3904f8829a4aSRandall Stewart 			/* break to abort land */
3905f8829a4aSRandall Stewart 			break;
3906f8829a4aSRandall Stewart 		}
3907f8829a4aSRandall Stewart 		switch (ch->chunk_type) {
3908d55b0b1bSRandall Stewart 		case SCTP_COOKIE_ECHO:
3909d55b0b1bSRandall Stewart 			/* We hit here only if the assoc is being freed */
3910d55b0b1bSRandall Stewart 			return;
3911f8829a4aSRandall Stewart 		case SCTP_PACKET_DROPPED:
3912f8829a4aSRandall Stewart 			/* we don't respond to pkt-dropped */
3913f8829a4aSRandall Stewart 			return;
3914f8829a4aSRandall Stewart 		case SCTP_ABORT_ASSOCIATION:
3915f8829a4aSRandall Stewart 			/* we don't respond with an ABORT to an ABORT */
3916f8829a4aSRandall Stewart 			return;
3917f8829a4aSRandall Stewart 		case SCTP_SHUTDOWN_COMPLETE:
3918f8829a4aSRandall Stewart 			/*
3919f8829a4aSRandall Stewart 			 * we ignore it since we are not waiting for it and
3920f8829a4aSRandall Stewart 			 * peer is gone
3921f8829a4aSRandall Stewart 			 */
3922f8829a4aSRandall Stewart 			return;
3923f8829a4aSRandall Stewart 		case SCTP_SHUTDOWN_ACK:
3924c54a18d2SRandall Stewart 			sctp_send_shutdown_complete2(m, iphlen, sh, vrf_id, port);
3925f8829a4aSRandall Stewart 			return;
3926f8829a4aSRandall Stewart 		default:
3927f8829a4aSRandall Stewart 			break;
3928f8829a4aSRandall Stewart 		}
3929f8829a4aSRandall Stewart 		offset += SCTP_SIZE32(chk_length);
3930f8829a4aSRandall Stewart 		ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
3931f8829a4aSRandall Stewart 		    sizeof(*ch), (uint8_t *) & chunk_buf);
3932f8829a4aSRandall Stewart 	}
3933c54a18d2SRandall Stewart 	sctp_send_abort(m, iphlen, sh, 0, op_err, vrf_id, port);
3934f8829a4aSRandall Stewart }
3935f8829a4aSRandall Stewart 
3936f8829a4aSRandall Stewart /*
3937f8829a4aSRandall Stewart  * check the inbound datagram to make sure there is not an abort inside it,
3938f8829a4aSRandall Stewart  * if there is return 1, else return 0.
3939f8829a4aSRandall Stewart  */
3940f8829a4aSRandall Stewart int
3941f8829a4aSRandall Stewart sctp_is_there_an_abort_here(struct mbuf *m, int iphlen, uint32_t * vtagfill)
3942f8829a4aSRandall Stewart {
3943f8829a4aSRandall Stewart 	struct sctp_chunkhdr *ch;
3944f8829a4aSRandall Stewart 	struct sctp_init_chunk *init_chk, chunk_buf;
3945f8829a4aSRandall Stewart 	int offset;
3946f8829a4aSRandall Stewart 	unsigned int chk_length;
3947f8829a4aSRandall Stewart 
3948f8829a4aSRandall Stewart 	offset = iphlen + sizeof(struct sctphdr);
3949f8829a4aSRandall Stewart 	ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset, sizeof(*ch),
3950f8829a4aSRandall Stewart 	    (uint8_t *) & chunk_buf);
3951f8829a4aSRandall Stewart 	while (ch != NULL) {
3952f8829a4aSRandall Stewart 		chk_length = ntohs(ch->chunk_length);
3953f8829a4aSRandall Stewart 		if (chk_length < sizeof(*ch)) {
3954f8829a4aSRandall Stewart 			/* packet is probably corrupt */
3955f8829a4aSRandall Stewart 			break;
3956f8829a4aSRandall Stewart 		}
3957f8829a4aSRandall Stewart 		/* we seem to be ok, is it an abort? */
3958f8829a4aSRandall Stewart 		if (ch->chunk_type == SCTP_ABORT_ASSOCIATION) {
3959f8829a4aSRandall Stewart 			/* yep, tell them */
3960f8829a4aSRandall Stewart 			return (1);
3961f8829a4aSRandall Stewart 		}
3962f8829a4aSRandall Stewart 		if (ch->chunk_type == SCTP_INITIATION) {
3963f8829a4aSRandall Stewart 			/* need to update the Vtag */
3964f8829a4aSRandall Stewart 			init_chk = (struct sctp_init_chunk *)sctp_m_getptr(m,
3965f8829a4aSRandall Stewart 			    offset, sizeof(*init_chk), (uint8_t *) & chunk_buf);
3966f8829a4aSRandall Stewart 			if (init_chk != NULL) {
3967f8829a4aSRandall Stewart 				*vtagfill = ntohl(init_chk->init.initiate_tag);
3968f8829a4aSRandall Stewart 			}
3969f8829a4aSRandall Stewart 		}
3970f8829a4aSRandall Stewart 		/* Nope, move to the next chunk */
3971f8829a4aSRandall Stewart 		offset += SCTP_SIZE32(chk_length);
3972f8829a4aSRandall Stewart 		ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
3973f8829a4aSRandall Stewart 		    sizeof(*ch), (uint8_t *) & chunk_buf);
3974f8829a4aSRandall Stewart 	}
3975f8829a4aSRandall Stewart 	return (0);
3976f8829a4aSRandall Stewart }
3977f8829a4aSRandall Stewart 
3978f8829a4aSRandall Stewart /*
3979f8829a4aSRandall Stewart  * currently (2/02), ifa_addr embeds scope_id's and don't have sin6_scope_id
3980f8829a4aSRandall Stewart  * set (i.e. it's 0) so, create this function to compare link local scopes
3981f8829a4aSRandall Stewart  */
39825e2c2d87SRandall Stewart #ifdef INET6
3983f8829a4aSRandall Stewart uint32_t
3984f8829a4aSRandall Stewart sctp_is_same_scope(struct sockaddr_in6 *addr1, struct sockaddr_in6 *addr2)
3985f8829a4aSRandall Stewart {
3986f8829a4aSRandall Stewart 	struct sockaddr_in6 a, b;
3987f8829a4aSRandall Stewart 
3988f8829a4aSRandall Stewart 	/* save copies */
3989f8829a4aSRandall Stewart 	a = *addr1;
3990f8829a4aSRandall Stewart 	b = *addr2;
3991f8829a4aSRandall Stewart 
3992f8829a4aSRandall Stewart 	if (a.sin6_scope_id == 0)
3993f8829a4aSRandall Stewart 		if (sa6_recoverscope(&a)) {
3994f8829a4aSRandall Stewart 			/* can't get scope, so can't match */
3995f8829a4aSRandall Stewart 			return (0);
3996f8829a4aSRandall Stewart 		}
3997f8829a4aSRandall Stewart 	if (b.sin6_scope_id == 0)
3998f8829a4aSRandall Stewart 		if (sa6_recoverscope(&b)) {
3999f8829a4aSRandall Stewart 			/* can't get scope, so can't match */
4000f8829a4aSRandall Stewart 			return (0);
4001f8829a4aSRandall Stewart 		}
4002f8829a4aSRandall Stewart 	if (a.sin6_scope_id != b.sin6_scope_id)
4003f8829a4aSRandall Stewart 		return (0);
4004f8829a4aSRandall Stewart 
4005f8829a4aSRandall Stewart 	return (1);
4006f8829a4aSRandall Stewart }
4007f8829a4aSRandall Stewart 
4008f8829a4aSRandall Stewart /*
4009f8829a4aSRandall Stewart  * returns a sockaddr_in6 with embedded scope recovered and removed
4010f8829a4aSRandall Stewart  */
4011f8829a4aSRandall Stewart struct sockaddr_in6 *
4012f8829a4aSRandall Stewart sctp_recover_scope(struct sockaddr_in6 *addr, struct sockaddr_in6 *store)
4013f8829a4aSRandall Stewart {
4014f8829a4aSRandall Stewart 	/* check and strip embedded scope junk */
4015f8829a4aSRandall Stewart 	if (addr->sin6_family == AF_INET6) {
4016f8829a4aSRandall Stewart 		if (IN6_IS_SCOPE_LINKLOCAL(&addr->sin6_addr)) {
4017f8829a4aSRandall Stewart 			if (addr->sin6_scope_id == 0) {
4018f8829a4aSRandall Stewart 				*store = *addr;
4019f8829a4aSRandall Stewart 				if (!sa6_recoverscope(store)) {
4020f8829a4aSRandall Stewart 					/* use the recovered scope */
4021f8829a4aSRandall Stewart 					addr = store;
4022f8829a4aSRandall Stewart 				}
4023f42a358aSRandall Stewart 			} else {
4024f8829a4aSRandall Stewart 				/* else, return the original "to" addr */
4025f42a358aSRandall Stewart 				in6_clearscope(&addr->sin6_addr);
4026f8829a4aSRandall Stewart 			}
4027f8829a4aSRandall Stewart 		}
4028f8829a4aSRandall Stewart 	}
4029f8829a4aSRandall Stewart 	return (addr);
4030f8829a4aSRandall Stewart }
4031f8829a4aSRandall Stewart 
40325e2c2d87SRandall Stewart #endif
40335e2c2d87SRandall Stewart 
4034f8829a4aSRandall Stewart /*
4035f8829a4aSRandall Stewart  * are the two addresses the same?  currently a "scopeless" check returns: 1
4036f8829a4aSRandall Stewart  * if same, 0 if not
4037f8829a4aSRandall Stewart  */
403872fb6fdbSRandall Stewart int
4039f8829a4aSRandall Stewart sctp_cmpaddr(struct sockaddr *sa1, struct sockaddr *sa2)
4040f8829a4aSRandall Stewart {
4041f8829a4aSRandall Stewart 
4042f8829a4aSRandall Stewart 	/* must be valid */
4043f8829a4aSRandall Stewart 	if (sa1 == NULL || sa2 == NULL)
4044f8829a4aSRandall Stewart 		return (0);
4045f8829a4aSRandall Stewart 
4046f8829a4aSRandall Stewart 	/* must be the same family */
4047f8829a4aSRandall Stewart 	if (sa1->sa_family != sa2->sa_family)
4048f8829a4aSRandall Stewart 		return (0);
4049f8829a4aSRandall Stewart 
40505e2c2d87SRandall Stewart 	switch (sa1->sa_family) {
40515e2c2d87SRandall Stewart #ifdef INET6
40525e2c2d87SRandall Stewart 	case AF_INET6:
40535e2c2d87SRandall Stewart 		{
4054f8829a4aSRandall Stewart 			/* IPv6 addresses */
4055f8829a4aSRandall Stewart 			struct sockaddr_in6 *sin6_1, *sin6_2;
4056f8829a4aSRandall Stewart 
4057f8829a4aSRandall Stewart 			sin6_1 = (struct sockaddr_in6 *)sa1;
4058f8829a4aSRandall Stewart 			sin6_2 = (struct sockaddr_in6 *)sa2;
4059c54a18d2SRandall Stewart 			return (SCTP6_ARE_ADDR_EQUAL(sin6_1,
4060c54a18d2SRandall Stewart 			    sin6_2));
40615e2c2d87SRandall Stewart 		}
40625e2c2d87SRandall Stewart #endif
40635e2c2d87SRandall Stewart 	case AF_INET:
40645e2c2d87SRandall Stewart 		{
4065f8829a4aSRandall Stewart 			/* IPv4 addresses */
4066f8829a4aSRandall Stewart 			struct sockaddr_in *sin_1, *sin_2;
4067f8829a4aSRandall Stewart 
4068f8829a4aSRandall Stewart 			sin_1 = (struct sockaddr_in *)sa1;
4069f8829a4aSRandall Stewart 			sin_2 = (struct sockaddr_in *)sa2;
4070f8829a4aSRandall Stewart 			return (sin_1->sin_addr.s_addr == sin_2->sin_addr.s_addr);
40715e2c2d87SRandall Stewart 		}
40725e2c2d87SRandall Stewart 	default:
4073f8829a4aSRandall Stewart 		/* we don't do these... */
4074f8829a4aSRandall Stewart 		return (0);
4075f8829a4aSRandall Stewart 	}
4076f8829a4aSRandall Stewart }
4077f8829a4aSRandall Stewart 
4078f8829a4aSRandall Stewart void
4079f8829a4aSRandall Stewart sctp_print_address(struct sockaddr *sa)
4080f8829a4aSRandall Stewart {
40815e2c2d87SRandall Stewart #ifdef INET6
40827d32aa0cSBjoern A. Zeeb 	char ip6buf[INET6_ADDRSTRLEN];
4083f8829a4aSRandall Stewart 
4084ad81507eSRandall Stewart 	ip6buf[0] = 0;
40855e2c2d87SRandall Stewart #endif
40865e2c2d87SRandall Stewart 
40875e2c2d87SRandall Stewart 	switch (sa->sa_family) {
40885e2c2d87SRandall Stewart #ifdef INET6
40895e2c2d87SRandall Stewart 	case AF_INET6:
40905e2c2d87SRandall Stewart 		{
4091ad81507eSRandall Stewart 			struct sockaddr_in6 *sin6;
4092ad81507eSRandall Stewart 
4093f8829a4aSRandall Stewart 			sin6 = (struct sockaddr_in6 *)sa;
4094ad81507eSRandall Stewart 			SCTP_PRINTF("IPv6 address: %s:port:%d scope:%u\n",
40957d32aa0cSBjoern A. Zeeb 			    ip6_sprintf(ip6buf, &sin6->sin6_addr),
40967d32aa0cSBjoern A. Zeeb 			    ntohs(sin6->sin6_port),
4097f8829a4aSRandall Stewart 			    sin6->sin6_scope_id);
40985e2c2d87SRandall Stewart 			break;
40995e2c2d87SRandall Stewart 		}
41005e2c2d87SRandall Stewart #endif
41015e2c2d87SRandall Stewart 	case AF_INET:
41025e2c2d87SRandall Stewart 		{
4103f8829a4aSRandall Stewart 			struct sockaddr_in *sin;
4104f8829a4aSRandall Stewart 			unsigned char *p;
4105f8829a4aSRandall Stewart 
4106f8829a4aSRandall Stewart 			sin = (struct sockaddr_in *)sa;
4107f8829a4aSRandall Stewart 			p = (unsigned char *)&sin->sin_addr;
4108ad81507eSRandall Stewart 			SCTP_PRINTF("IPv4 address: %u.%u.%u.%u:%d\n",
4109f8829a4aSRandall Stewart 			    p[0], p[1], p[2], p[3], ntohs(sin->sin_port));
41105e2c2d87SRandall Stewart 			break;
41115e2c2d87SRandall Stewart 		}
41125e2c2d87SRandall Stewart 	default:
4113ad81507eSRandall Stewart 		SCTP_PRINTF("?\n");
41145e2c2d87SRandall Stewart 		break;
4115f8829a4aSRandall Stewart 	}
4116f8829a4aSRandall Stewart }
4117f8829a4aSRandall Stewart 
4118f8829a4aSRandall Stewart void
4119f8829a4aSRandall Stewart sctp_print_address_pkt(struct ip *iph, struct sctphdr *sh)
4120f8829a4aSRandall Stewart {
41215e2c2d87SRandall Stewart 	switch (iph->ip_v) {
41225e2c2d87SRandall Stewart 		case IPVERSION:
41235e2c2d87SRandall Stewart 		{
4124f8829a4aSRandall Stewart 			struct sockaddr_in lsa, fsa;
4125f8829a4aSRandall Stewart 
4126f8829a4aSRandall Stewart 			bzero(&lsa, sizeof(lsa));
4127f8829a4aSRandall Stewart 			lsa.sin_len = sizeof(lsa);
4128f8829a4aSRandall Stewart 			lsa.sin_family = AF_INET;
4129f8829a4aSRandall Stewart 			lsa.sin_addr = iph->ip_src;
4130f8829a4aSRandall Stewart 			lsa.sin_port = sh->src_port;
4131f8829a4aSRandall Stewart 			bzero(&fsa, sizeof(fsa));
4132f8829a4aSRandall Stewart 			fsa.sin_len = sizeof(fsa);
4133f8829a4aSRandall Stewart 			fsa.sin_family = AF_INET;
4134f8829a4aSRandall Stewart 			fsa.sin_addr = iph->ip_dst;
4135f8829a4aSRandall Stewart 			fsa.sin_port = sh->dest_port;
4136ad81507eSRandall Stewart 			SCTP_PRINTF("src: ");
4137f8829a4aSRandall Stewart 			sctp_print_address((struct sockaddr *)&lsa);
4138ad81507eSRandall Stewart 			SCTP_PRINTF("dest: ");
4139f8829a4aSRandall Stewart 			sctp_print_address((struct sockaddr *)&fsa);
41405e2c2d87SRandall Stewart 			break;
41415e2c2d87SRandall Stewart 		}
41425e2c2d87SRandall Stewart #ifdef INET6
41435e2c2d87SRandall Stewart 	case IPV6_VERSION >> 4:
41445e2c2d87SRandall Stewart 		{
4145f8829a4aSRandall Stewart 			struct ip6_hdr *ip6;
4146f8829a4aSRandall Stewart 			struct sockaddr_in6 lsa6, fsa6;
4147f8829a4aSRandall Stewart 
4148f8829a4aSRandall Stewart 			ip6 = (struct ip6_hdr *)iph;
4149f8829a4aSRandall Stewart 			bzero(&lsa6, sizeof(lsa6));
4150f8829a4aSRandall Stewart 			lsa6.sin6_len = sizeof(lsa6);
4151f8829a4aSRandall Stewart 			lsa6.sin6_family = AF_INET6;
4152f8829a4aSRandall Stewart 			lsa6.sin6_addr = ip6->ip6_src;
4153f8829a4aSRandall Stewart 			lsa6.sin6_port = sh->src_port;
4154f8829a4aSRandall Stewart 			bzero(&fsa6, sizeof(fsa6));
4155f8829a4aSRandall Stewart 			fsa6.sin6_len = sizeof(fsa6);
4156f8829a4aSRandall Stewart 			fsa6.sin6_family = AF_INET6;
4157f8829a4aSRandall Stewart 			fsa6.sin6_addr = ip6->ip6_dst;
4158f8829a4aSRandall Stewart 			fsa6.sin6_port = sh->dest_port;
4159ad81507eSRandall Stewart 			SCTP_PRINTF("src: ");
4160f8829a4aSRandall Stewart 			sctp_print_address((struct sockaddr *)&lsa6);
4161ad81507eSRandall Stewart 			SCTP_PRINTF("dest: ");
4162f8829a4aSRandall Stewart 			sctp_print_address((struct sockaddr *)&fsa6);
41635e2c2d87SRandall Stewart 			break;
41645e2c2d87SRandall Stewart 		}
41655e2c2d87SRandall Stewart #endif
41665e2c2d87SRandall Stewart 	default:
41675e2c2d87SRandall Stewart 		/* TSNH */
41685e2c2d87SRandall Stewart 		break;
4169f8829a4aSRandall Stewart 	}
4170f8829a4aSRandall Stewart }
4171f8829a4aSRandall Stewart 
4172f8829a4aSRandall Stewart void
4173f8829a4aSRandall Stewart sctp_pull_off_control_to_new_inp(struct sctp_inpcb *old_inp,
4174f8829a4aSRandall Stewart     struct sctp_inpcb *new_inp,
4175d06c82f1SRandall Stewart     struct sctp_tcb *stcb,
4176d06c82f1SRandall Stewart     int waitflags)
4177f8829a4aSRandall Stewart {
4178f8829a4aSRandall Stewart 	/*
4179f8829a4aSRandall Stewart 	 * go through our old INP and pull off any control structures that
4180f8829a4aSRandall Stewart 	 * belong to stcb and move then to the new inp.
4181f8829a4aSRandall Stewart 	 */
4182f8829a4aSRandall Stewart 	struct socket *old_so, *new_so;
4183f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control, *nctl;
4184f8829a4aSRandall Stewart 	struct sctp_readhead tmp_queue;
4185f8829a4aSRandall Stewart 	struct mbuf *m;
4186bff64a4dSRandall Stewart 	int error = 0;
4187f8829a4aSRandall Stewart 
4188f8829a4aSRandall Stewart 	old_so = old_inp->sctp_socket;
4189f8829a4aSRandall Stewart 	new_so = new_inp->sctp_socket;
4190f8829a4aSRandall Stewart 	TAILQ_INIT(&tmp_queue);
4191d06c82f1SRandall Stewart 	error = sblock(&old_so->so_rcv, waitflags);
4192f8829a4aSRandall Stewart 	if (error) {
4193f8829a4aSRandall Stewart 		/*
4194f8829a4aSRandall Stewart 		 * Gak, can't get sblock, we have a problem. data will be
4195f8829a4aSRandall Stewart 		 * left stranded.. and we don't dare look at it since the
4196f8829a4aSRandall Stewart 		 * other thread may be reading something. Oh well, its a
4197f8829a4aSRandall Stewart 		 * screwed up app that does a peeloff OR a accept while
4198f8829a4aSRandall Stewart 		 * reading from the main socket... actually its only the
4199f8829a4aSRandall Stewart 		 * peeloff() case, since I think read will fail on a
4200f8829a4aSRandall Stewart 		 * listening socket..
4201f8829a4aSRandall Stewart 		 */
4202f8829a4aSRandall Stewart 		return;
4203f8829a4aSRandall Stewart 	}
4204f8829a4aSRandall Stewart 	/* lock the socket buffers */
4205f8829a4aSRandall Stewart 	SCTP_INP_READ_LOCK(old_inp);
4206f8829a4aSRandall Stewart 	control = TAILQ_FIRST(&old_inp->read_queue);
4207f8829a4aSRandall Stewart 	/* Pull off all for out target stcb */
4208f8829a4aSRandall Stewart 	while (control) {
4209f8829a4aSRandall Stewart 		nctl = TAILQ_NEXT(control, next);
4210f8829a4aSRandall Stewart 		if (control->stcb == stcb) {
4211f8829a4aSRandall Stewart 			/* remove it we want it */
4212f8829a4aSRandall Stewart 			TAILQ_REMOVE(&old_inp->read_queue, control, next);
4213f8829a4aSRandall Stewart 			TAILQ_INSERT_TAIL(&tmp_queue, control, next);
4214f8829a4aSRandall Stewart 			m = control->data;
4215f8829a4aSRandall Stewart 			while (m) {
4216b3f1ea41SRandall Stewart 				if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4217139bc87fSRandall Stewart 					sctp_sblog(&old_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
421880fefe0aSRandall Stewart 				}
4219f8829a4aSRandall Stewart 				sctp_sbfree(control, stcb, &old_so->so_rcv, m);
4220b3f1ea41SRandall Stewart 				if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4221f8829a4aSRandall Stewart 					sctp_sblog(&old_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
422280fefe0aSRandall Stewart 				}
4223139bc87fSRandall Stewart 				m = SCTP_BUF_NEXT(m);
4224f8829a4aSRandall Stewart 			}
4225f8829a4aSRandall Stewart 		}
4226f8829a4aSRandall Stewart 		control = nctl;
4227f8829a4aSRandall Stewart 	}
4228f8829a4aSRandall Stewart 	SCTP_INP_READ_UNLOCK(old_inp);
4229f8829a4aSRandall Stewart 	/* Remove the sb-lock on the old socket */
4230f8829a4aSRandall Stewart 
4231f8829a4aSRandall Stewart 	sbunlock(&old_so->so_rcv);
4232f8829a4aSRandall Stewart 	/* Now we move them over to the new socket buffer */
4233f8829a4aSRandall Stewart 	control = TAILQ_FIRST(&tmp_queue);
4234f8829a4aSRandall Stewart 	SCTP_INP_READ_LOCK(new_inp);
4235f8829a4aSRandall Stewart 	while (control) {
4236f8829a4aSRandall Stewart 		nctl = TAILQ_NEXT(control, next);
4237f8829a4aSRandall Stewart 		TAILQ_INSERT_TAIL(&new_inp->read_queue, control, next);
4238f8829a4aSRandall Stewart 		m = control->data;
4239f8829a4aSRandall Stewart 		while (m) {
4240b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4241139bc87fSRandall Stewart 				sctp_sblog(&new_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m));
424280fefe0aSRandall Stewart 			}
4243f8829a4aSRandall Stewart 			sctp_sballoc(stcb, &new_so->so_rcv, m);
4244b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4245f8829a4aSRandall Stewart 				sctp_sblog(&new_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
424680fefe0aSRandall Stewart 			}
4247139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
4248f8829a4aSRandall Stewart 		}
4249f8829a4aSRandall Stewart 		control = nctl;
4250f8829a4aSRandall Stewart 	}
4251f8829a4aSRandall Stewart 	SCTP_INP_READ_UNLOCK(new_inp);
4252f8829a4aSRandall Stewart }
4253f8829a4aSRandall Stewart 
4254f8829a4aSRandall Stewart void
4255f8829a4aSRandall Stewart sctp_add_to_readq(struct sctp_inpcb *inp,
4256f8829a4aSRandall Stewart     struct sctp_tcb *stcb,
4257f8829a4aSRandall Stewart     struct sctp_queued_to_read *control,
4258f8829a4aSRandall Stewart     struct sockbuf *sb,
4259ceaad40aSRandall Stewart     int end,
4260ceaad40aSRandall Stewart     int so_locked
4261ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
4262ceaad40aSRandall Stewart     SCTP_UNUSED
4263ceaad40aSRandall Stewart #endif
4264ceaad40aSRandall Stewart )
4265f8829a4aSRandall Stewart {
4266f8829a4aSRandall Stewart 	/*
4267f8829a4aSRandall Stewart 	 * Here we must place the control on the end of the socket read
4268f8829a4aSRandall Stewart 	 * queue AND increment sb_cc so that select will work properly on
4269f8829a4aSRandall Stewart 	 * read.
4270f8829a4aSRandall Stewart 	 */
4271f8829a4aSRandall Stewart 	struct mbuf *m, *prev = NULL;
4272f8829a4aSRandall Stewart 
427303b0b021SRandall Stewart 	if (inp == NULL) {
427403b0b021SRandall Stewart 		/* Gak, TSNH!! */
4275a5d547adSRandall Stewart #ifdef INVARIANTS
427603b0b021SRandall Stewart 		panic("Gak, inp NULL on add_to_readq");
427703b0b021SRandall Stewart #endif
427803b0b021SRandall Stewart 		return;
427903b0b021SRandall Stewart 	}
4280f8829a4aSRandall Stewart 	SCTP_INP_READ_LOCK(inp);
428142551e99SRandall Stewart 	if (!(control->spec_flags & M_NOTIFICATION)) {
4282a5d547adSRandall Stewart 		atomic_add_int(&inp->total_recvs, 1);
428342551e99SRandall Stewart 		if (!control->do_not_ref_stcb) {
4284a5d547adSRandall Stewart 			atomic_add_int(&stcb->total_recvs, 1);
428542551e99SRandall Stewart 		}
428642551e99SRandall Stewart 	}
4287f8829a4aSRandall Stewart 	m = control->data;
4288f8829a4aSRandall Stewart 	control->held_length = 0;
4289f8829a4aSRandall Stewart 	control->length = 0;
4290f8829a4aSRandall Stewart 	while (m) {
4291139bc87fSRandall Stewart 		if (SCTP_BUF_LEN(m) == 0) {
4292f8829a4aSRandall Stewart 			/* Skip mbufs with NO length */
4293f8829a4aSRandall Stewart 			if (prev == NULL) {
4294f8829a4aSRandall Stewart 				/* First one */
4295f8829a4aSRandall Stewart 				control->data = sctp_m_free(m);
4296f8829a4aSRandall Stewart 				m = control->data;
4297f8829a4aSRandall Stewart 			} else {
4298139bc87fSRandall Stewart 				SCTP_BUF_NEXT(prev) = sctp_m_free(m);
4299139bc87fSRandall Stewart 				m = SCTP_BUF_NEXT(prev);
4300f8829a4aSRandall Stewart 			}
4301f8829a4aSRandall Stewart 			if (m == NULL) {
4302f8829a4aSRandall Stewart 				control->tail_mbuf = prev;;
4303f8829a4aSRandall Stewart 			}
4304f8829a4aSRandall Stewart 			continue;
4305f8829a4aSRandall Stewart 		}
4306f8829a4aSRandall Stewart 		prev = m;
4307b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4308139bc87fSRandall Stewart 			sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m));
430980fefe0aSRandall Stewart 		}
4310f8829a4aSRandall Stewart 		sctp_sballoc(stcb, sb, m);
4311b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4312f8829a4aSRandall Stewart 			sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
431380fefe0aSRandall Stewart 		}
4314139bc87fSRandall Stewart 		atomic_add_int(&control->length, SCTP_BUF_LEN(m));
4315139bc87fSRandall Stewart 		m = SCTP_BUF_NEXT(m);
4316f8829a4aSRandall Stewart 	}
4317f8829a4aSRandall Stewart 	if (prev != NULL) {
4318f8829a4aSRandall Stewart 		control->tail_mbuf = prev;
4319f8829a4aSRandall Stewart 	} else {
4320139bc87fSRandall Stewart 		/* Everything got collapsed out?? */
4321f8829a4aSRandall Stewart 		return;
4322f8829a4aSRandall Stewart 	}
4323f8829a4aSRandall Stewart 	if (end) {
4324f8829a4aSRandall Stewart 		control->end_added = 1;
4325f8829a4aSRandall Stewart 	}
4326f8829a4aSRandall Stewart 	TAILQ_INSERT_TAIL(&inp->read_queue, control, next);
4327f8829a4aSRandall Stewart 	SCTP_INP_READ_UNLOCK(inp);
4328f8829a4aSRandall Stewart 	if (inp && inp->sctp_socket) {
432917205eccSRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_ZERO_COPY_ACTIVE)) {
433017205eccSRandall Stewart 			SCTP_ZERO_COPY_EVENT(inp, inp->sctp_socket);
4331ceaad40aSRandall Stewart 		} else {
4332ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4333ceaad40aSRandall Stewart 			struct socket *so;
4334ceaad40aSRandall Stewart 
4335ceaad40aSRandall Stewart 			so = SCTP_INP_SO(inp);
4336ceaad40aSRandall Stewart 			if (!so_locked) {
4337ceaad40aSRandall Stewart 				atomic_add_int(&stcb->asoc.refcnt, 1);
4338ceaad40aSRandall Stewart 				SCTP_TCB_UNLOCK(stcb);
4339ceaad40aSRandall Stewart 				SCTP_SOCKET_LOCK(so, 1);
4340ceaad40aSRandall Stewart 				SCTP_TCB_LOCK(stcb);
4341ceaad40aSRandall Stewart 				atomic_subtract_int(&stcb->asoc.refcnt, 1);
4342ceaad40aSRandall Stewart 				if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
4343ceaad40aSRandall Stewart 					SCTP_SOCKET_UNLOCK(so, 1);
4344ceaad40aSRandall Stewart 					return;
4345ceaad40aSRandall Stewart 				}
4346ceaad40aSRandall Stewart 			}
4347ceaad40aSRandall Stewart #endif
4348f8829a4aSRandall Stewart 			sctp_sorwakeup(inp, inp->sctp_socket);
4349ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4350ceaad40aSRandall Stewart 			if (!so_locked) {
4351ceaad40aSRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
4352ceaad40aSRandall Stewart 			}
4353ceaad40aSRandall Stewart #endif
4354ceaad40aSRandall Stewart 		}
4355f8829a4aSRandall Stewart 	}
4356f8829a4aSRandall Stewart }
4357f8829a4aSRandall Stewart 
4358f8829a4aSRandall Stewart 
4359f8829a4aSRandall Stewart int
4360f8829a4aSRandall Stewart sctp_append_to_readq(struct sctp_inpcb *inp,
4361f8829a4aSRandall Stewart     struct sctp_tcb *stcb,
4362f8829a4aSRandall Stewart     struct sctp_queued_to_read *control,
4363f8829a4aSRandall Stewart     struct mbuf *m,
4364f8829a4aSRandall Stewart     int end,
4365f8829a4aSRandall Stewart     int ctls_cumack,
4366f8829a4aSRandall Stewart     struct sockbuf *sb)
4367f8829a4aSRandall Stewart {
4368f8829a4aSRandall Stewart 	/*
4369f8829a4aSRandall Stewart 	 * A partial delivery API event is underway. OR we are appending on
4370f8829a4aSRandall Stewart 	 * the reassembly queue.
4371f8829a4aSRandall Stewart 	 *
4372f8829a4aSRandall Stewart 	 * If PDAPI this means we need to add m to the end of the data.
4373f8829a4aSRandall Stewart 	 * Increase the length in the control AND increment the sb_cc.
4374f8829a4aSRandall Stewart 	 * Otherwise sb is NULL and all we need to do is put it at the end
4375f8829a4aSRandall Stewart 	 * of the mbuf chain.
4376f8829a4aSRandall Stewart 	 */
4377f8829a4aSRandall Stewart 	int len = 0;
4378f8829a4aSRandall Stewart 	struct mbuf *mm, *tail = NULL, *prev = NULL;
4379f8829a4aSRandall Stewart 
4380f8829a4aSRandall Stewart 	if (inp) {
4381f8829a4aSRandall Stewart 		SCTP_INP_READ_LOCK(inp);
4382f8829a4aSRandall Stewart 	}
4383f8829a4aSRandall Stewart 	if (control == NULL) {
4384f8829a4aSRandall Stewart get_out:
4385f8829a4aSRandall Stewart 		if (inp) {
4386f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
4387f8829a4aSRandall Stewart 		}
4388f8829a4aSRandall Stewart 		return (-1);
4389f8829a4aSRandall Stewart 	}
4390139bc87fSRandall Stewart 	if (control->end_added) {
4391f8829a4aSRandall Stewart 		/* huh this one is complete? */
4392f8829a4aSRandall Stewart 		goto get_out;
4393f8829a4aSRandall Stewart 	}
4394f8829a4aSRandall Stewart 	mm = m;
4395f8829a4aSRandall Stewart 	if (mm == NULL) {
4396f8829a4aSRandall Stewart 		goto get_out;
4397f8829a4aSRandall Stewart 	}
4398f8829a4aSRandall Stewart 	while (mm) {
4399139bc87fSRandall Stewart 		if (SCTP_BUF_LEN(mm) == 0) {
4400f8829a4aSRandall Stewart 			/* Skip mbufs with NO lenght */
4401f8829a4aSRandall Stewart 			if (prev == NULL) {
4402f8829a4aSRandall Stewart 				/* First one */
4403f8829a4aSRandall Stewart 				m = sctp_m_free(mm);
4404f8829a4aSRandall Stewart 				mm = m;
4405f8829a4aSRandall Stewart 			} else {
4406139bc87fSRandall Stewart 				SCTP_BUF_NEXT(prev) = sctp_m_free(mm);
4407139bc87fSRandall Stewart 				mm = SCTP_BUF_NEXT(prev);
4408f8829a4aSRandall Stewart 			}
4409f8829a4aSRandall Stewart 			continue;
4410f8829a4aSRandall Stewart 		}
4411f8829a4aSRandall Stewart 		prev = mm;
4412139bc87fSRandall Stewart 		len += SCTP_BUF_LEN(mm);
4413f8829a4aSRandall Stewart 		if (sb) {
4414b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4415139bc87fSRandall Stewart 				sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(mm));
441680fefe0aSRandall Stewart 			}
4417f8829a4aSRandall Stewart 			sctp_sballoc(stcb, sb, mm);
4418b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4419f8829a4aSRandall Stewart 				sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
442080fefe0aSRandall Stewart 			}
4421f8829a4aSRandall Stewart 		}
4422139bc87fSRandall Stewart 		mm = SCTP_BUF_NEXT(mm);
4423f8829a4aSRandall Stewart 	}
4424f8829a4aSRandall Stewart 	if (prev) {
4425f8829a4aSRandall Stewart 		tail = prev;
4426f8829a4aSRandall Stewart 	} else {
4427f8829a4aSRandall Stewart 		/* Really there should always be a prev */
4428f8829a4aSRandall Stewart 		if (m == NULL) {
4429f8829a4aSRandall Stewart 			/* Huh nothing left? */
4430a5d547adSRandall Stewart #ifdef INVARIANTS
4431f8829a4aSRandall Stewart 			panic("Nothing left to add?");
4432f8829a4aSRandall Stewart #else
4433f8829a4aSRandall Stewart 			goto get_out;
4434f8829a4aSRandall Stewart #endif
4435f8829a4aSRandall Stewart 		}
4436f8829a4aSRandall Stewart 		tail = m;
4437f8829a4aSRandall Stewart 	}
4438f8829a4aSRandall Stewart 	if (control->tail_mbuf) {
4439f8829a4aSRandall Stewart 		/* append */
4440139bc87fSRandall Stewart 		SCTP_BUF_NEXT(control->tail_mbuf) = m;
4441f8829a4aSRandall Stewart 		control->tail_mbuf = tail;
4442f8829a4aSRandall Stewart 	} else {
4443f8829a4aSRandall Stewart 		/* nothing there */
4444a5d547adSRandall Stewart #ifdef INVARIANTS
4445f8829a4aSRandall Stewart 		if (control->data != NULL) {
4446f8829a4aSRandall Stewart 			panic("This should NOT happen");
4447f8829a4aSRandall Stewart 		}
4448f8829a4aSRandall Stewart #endif
4449f8829a4aSRandall Stewart 		control->data = m;
4450f8829a4aSRandall Stewart 		control->tail_mbuf = tail;
4451f8829a4aSRandall Stewart 	}
445218e198d3SRandall Stewart 	atomic_add_int(&control->length, len);
445318e198d3SRandall Stewart 	if (end) {
445418e198d3SRandall Stewart 		/* message is complete */
445518e198d3SRandall Stewart 		if (stcb && (control == stcb->asoc.control_pdapi)) {
445618e198d3SRandall Stewart 			stcb->asoc.control_pdapi = NULL;
445718e198d3SRandall Stewart 		}
445818e198d3SRandall Stewart 		control->held_length = 0;
445918e198d3SRandall Stewart 		control->end_added = 1;
446018e198d3SRandall Stewart 	}
4461ad81507eSRandall Stewart 	if (stcb == NULL) {
4462ad81507eSRandall Stewart 		control->do_not_ref_stcb = 1;
4463ad81507eSRandall Stewart 	}
4464f8829a4aSRandall Stewart 	/*
4465f8829a4aSRandall Stewart 	 * When we are appending in partial delivery, the cum-ack is used
4466f8829a4aSRandall Stewart 	 * for the actual pd-api highest tsn on this mbuf. The true cum-ack
4467f8829a4aSRandall Stewart 	 * is populated in the outbound sinfo structure from the true cumack
4468f8829a4aSRandall Stewart 	 * if the association exists...
4469f8829a4aSRandall Stewart 	 */
4470f8829a4aSRandall Stewart 	control->sinfo_tsn = control->sinfo_cumtsn = ctls_cumack;
4471f8829a4aSRandall Stewart 	if (inp) {
4472f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
4473f8829a4aSRandall Stewart 	}
4474f8829a4aSRandall Stewart 	if (inp && inp->sctp_socket) {
447517205eccSRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_ZERO_COPY_ACTIVE)) {
447617205eccSRandall Stewart 			SCTP_ZERO_COPY_EVENT(inp, inp->sctp_socket);
4477ceaad40aSRandall Stewart 		} else {
4478ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4479ceaad40aSRandall Stewart 			struct socket *so;
4480ceaad40aSRandall Stewart 
4481ceaad40aSRandall Stewart 			so = SCTP_INP_SO(inp);
4482ceaad40aSRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, 1);
4483ceaad40aSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
4484ceaad40aSRandall Stewart 			SCTP_SOCKET_LOCK(so, 1);
4485ceaad40aSRandall Stewart 			SCTP_TCB_LOCK(stcb);
4486ceaad40aSRandall Stewart 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
4487ceaad40aSRandall Stewart 			if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
4488ceaad40aSRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
4489ceaad40aSRandall Stewart 				return (0);
4490ceaad40aSRandall Stewart 			}
4491ceaad40aSRandall Stewart #endif
4492f8829a4aSRandall Stewart 			sctp_sorwakeup(inp, inp->sctp_socket);
4493ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4494ceaad40aSRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
4495ceaad40aSRandall Stewart #endif
4496ceaad40aSRandall Stewart 		}
4497f8829a4aSRandall Stewart 	}
4498f8829a4aSRandall Stewart 	return (0);
4499f8829a4aSRandall Stewart }
4500f8829a4aSRandall Stewart 
4501f8829a4aSRandall Stewart 
4502f8829a4aSRandall Stewart 
4503f8829a4aSRandall Stewart /*************HOLD THIS COMMENT FOR PATCH FILE OF
4504f8829a4aSRandall Stewart  *************ALTERNATE ROUTING CODE
4505f8829a4aSRandall Stewart  */
4506f8829a4aSRandall Stewart 
4507f8829a4aSRandall Stewart /*************HOLD THIS COMMENT FOR END OF PATCH FILE OF
4508f8829a4aSRandall Stewart  *************ALTERNATE ROUTING CODE
4509f8829a4aSRandall Stewart  */
4510f8829a4aSRandall Stewart 
4511f8829a4aSRandall Stewart struct mbuf *
4512f8829a4aSRandall Stewart sctp_generate_invmanparam(int err)
4513f8829a4aSRandall Stewart {
4514f8829a4aSRandall Stewart 	/* Return a MBUF with a invalid mandatory parameter */
4515f8829a4aSRandall Stewart 	struct mbuf *m;
4516f8829a4aSRandall Stewart 
4517f8829a4aSRandall Stewart 	m = sctp_get_mbuf_for_msg(sizeof(struct sctp_paramhdr), 0, M_DONTWAIT, 1, MT_DATA);
4518f8829a4aSRandall Stewart 	if (m) {
4519f8829a4aSRandall Stewart 		struct sctp_paramhdr *ph;
4520f8829a4aSRandall Stewart 
4521139bc87fSRandall Stewart 		SCTP_BUF_LEN(m) = sizeof(struct sctp_paramhdr);
4522f8829a4aSRandall Stewart 		ph = mtod(m, struct sctp_paramhdr *);
4523f8829a4aSRandall Stewart 		ph->param_length = htons(sizeof(struct sctp_paramhdr));
4524f8829a4aSRandall Stewart 		ph->param_type = htons(err);
4525f8829a4aSRandall Stewart 	}
4526f8829a4aSRandall Stewart 	return (m);
4527f8829a4aSRandall Stewart }
4528f8829a4aSRandall Stewart 
4529f8829a4aSRandall Stewart #ifdef SCTP_MBCNT_LOGGING
4530f8829a4aSRandall Stewart void
4531f8829a4aSRandall Stewart sctp_free_bufspace(struct sctp_tcb *stcb, struct sctp_association *asoc,
4532f8829a4aSRandall Stewart     struct sctp_tmit_chunk *tp1, int chk_cnt)
4533f8829a4aSRandall Stewart {
4534f8829a4aSRandall Stewart 	if (tp1->data == NULL) {
4535f8829a4aSRandall Stewart 		return;
4536f8829a4aSRandall Stewart 	}
4537f8829a4aSRandall Stewart 	asoc->chunks_on_out_queue -= chk_cnt;
4538b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_MBCNT_LOGGING_ENABLE) {
4539f8829a4aSRandall Stewart 		sctp_log_mbcnt(SCTP_LOG_MBCNT_DECREASE,
4540f8829a4aSRandall Stewart 		    asoc->total_output_queue_size,
4541f8829a4aSRandall Stewart 		    tp1->book_size,
4542f8829a4aSRandall Stewart 		    0,
4543f8829a4aSRandall Stewart 		    tp1->mbcnt);
454480fefe0aSRandall Stewart 	}
4545f8829a4aSRandall Stewart 	if (asoc->total_output_queue_size >= tp1->book_size) {
454644b7479bSRandall Stewart 		atomic_add_int(&asoc->total_output_queue_size, -tp1->book_size);
4547f8829a4aSRandall Stewart 	} else {
4548f8829a4aSRandall Stewart 		asoc->total_output_queue_size = 0;
4549f8829a4aSRandall Stewart 	}
4550f8829a4aSRandall Stewart 
4551f8829a4aSRandall Stewart 	if (stcb->sctp_socket && (((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) ||
4552f8829a4aSRandall Stewart 	    ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE)))) {
4553f8829a4aSRandall Stewart 		if (stcb->sctp_socket->so_snd.sb_cc >= tp1->book_size) {
4554f8829a4aSRandall Stewart 			stcb->sctp_socket->so_snd.sb_cc -= tp1->book_size;
4555f8829a4aSRandall Stewart 		} else {
4556f8829a4aSRandall Stewart 			stcb->sctp_socket->so_snd.sb_cc = 0;
4557f8829a4aSRandall Stewart 
4558f8829a4aSRandall Stewart 		}
4559f8829a4aSRandall Stewart 	}
4560f8829a4aSRandall Stewart }
4561f8829a4aSRandall Stewart 
4562f8829a4aSRandall Stewart #endif
4563f8829a4aSRandall Stewart 
4564f8829a4aSRandall Stewart int
4565f8829a4aSRandall Stewart sctp_release_pr_sctp_chunk(struct sctp_tcb *stcb, struct sctp_tmit_chunk *tp1,
4566ceaad40aSRandall Stewart     int reason, struct sctpchunk_listhead *queue, int so_locked
4567ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
4568ceaad40aSRandall Stewart     SCTP_UNUSED
4569ceaad40aSRandall Stewart #endif
4570ceaad40aSRandall Stewart )
4571f8829a4aSRandall Stewart {
4572f8829a4aSRandall Stewart 	int ret_sz = 0;
4573f8829a4aSRandall Stewart 	int notdone;
4574f8829a4aSRandall Stewart 	uint8_t foundeom = 0;
4575f8829a4aSRandall Stewart 
4576f8829a4aSRandall Stewart 	do {
4577f8829a4aSRandall Stewart 		ret_sz += tp1->book_size;
4578f8829a4aSRandall Stewart 		tp1->sent = SCTP_FORWARD_TSN_SKIP;
4579f8829a4aSRandall Stewart 		if (tp1->data) {
4580ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4581ceaad40aSRandall Stewart 			struct socket *so;
4582ceaad40aSRandall Stewart 
4583ceaad40aSRandall Stewart #endif
4584f8829a4aSRandall Stewart 			sctp_free_bufspace(stcb, &stcb->asoc, tp1, 1);
4585830d754dSRandall Stewart 			sctp_flight_size_decrease(tp1);
4586830d754dSRandall Stewart 			sctp_total_flight_decrease(stcb, tp1);
4587830d754dSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_DG_FAIL, stcb, reason, tp1, so_locked);
4588f8829a4aSRandall Stewart 			sctp_m_freem(tp1->data);
4589f8829a4aSRandall Stewart 			tp1->data = NULL;
4590ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4591ceaad40aSRandall Stewart 			so = SCTP_INP_SO(stcb->sctp_ep);
4592ceaad40aSRandall Stewart 			if (!so_locked) {
4593ceaad40aSRandall Stewart 				atomic_add_int(&stcb->asoc.refcnt, 1);
4594ceaad40aSRandall Stewart 				SCTP_TCB_UNLOCK(stcb);
4595ceaad40aSRandall Stewart 				SCTP_SOCKET_LOCK(so, 1);
4596ceaad40aSRandall Stewart 				SCTP_TCB_LOCK(stcb);
4597ceaad40aSRandall Stewart 				atomic_subtract_int(&stcb->asoc.refcnt, 1);
4598ceaad40aSRandall Stewart 				if (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET) {
4599ceaad40aSRandall Stewart 					/*
4600ceaad40aSRandall Stewart 					 * assoc was freed while we were
4601ceaad40aSRandall Stewart 					 * unlocked
4602ceaad40aSRandall Stewart 					 */
4603ceaad40aSRandall Stewart 					SCTP_SOCKET_UNLOCK(so, 1);
4604ceaad40aSRandall Stewart 					return (ret_sz);
4605ceaad40aSRandall Stewart 				}
4606ceaad40aSRandall Stewart 			}
4607ceaad40aSRandall Stewart #endif
4608f8829a4aSRandall Stewart 			sctp_sowwakeup(stcb->sctp_ep, stcb->sctp_socket);
4609ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4610ceaad40aSRandall Stewart 			if (!so_locked) {
4611ceaad40aSRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
4612ceaad40aSRandall Stewart 			}
4613ceaad40aSRandall Stewart #endif
4614f8829a4aSRandall Stewart 		}
4615f8829a4aSRandall Stewart 		if (PR_SCTP_BUF_ENABLED(tp1->flags)) {
4616f8829a4aSRandall Stewart 			stcb->asoc.sent_queue_cnt_removeable--;
4617f8829a4aSRandall Stewart 		}
4618f8829a4aSRandall Stewart 		if (queue == &stcb->asoc.send_queue) {
4619f8829a4aSRandall Stewart 			TAILQ_REMOVE(&stcb->asoc.send_queue, tp1, sctp_next);
4620f8829a4aSRandall Stewart 			/* on to the sent queue */
4621f8829a4aSRandall Stewart 			TAILQ_INSERT_TAIL(&stcb->asoc.sent_queue, tp1,
4622f8829a4aSRandall Stewart 			    sctp_next);
4623f8829a4aSRandall Stewart 			stcb->asoc.sent_queue_cnt++;
4624f8829a4aSRandall Stewart 		}
4625f8829a4aSRandall Stewart 		if ((tp1->rec.data.rcv_flags & SCTP_DATA_NOT_FRAG) ==
4626f8829a4aSRandall Stewart 		    SCTP_DATA_NOT_FRAG) {
4627f8829a4aSRandall Stewart 			/* not frag'ed we ae done   */
4628f8829a4aSRandall Stewart 			notdone = 0;
4629f8829a4aSRandall Stewart 			foundeom = 1;
4630f8829a4aSRandall Stewart 		} else if (tp1->rec.data.rcv_flags & SCTP_DATA_LAST_FRAG) {
4631f8829a4aSRandall Stewart 			/* end of frag, we are done */
4632f8829a4aSRandall Stewart 			notdone = 0;
4633f8829a4aSRandall Stewart 			foundeom = 1;
4634f8829a4aSRandall Stewart 		} else {
4635f8829a4aSRandall Stewart 			/*
4636f8829a4aSRandall Stewart 			 * Its a begin or middle piece, we must mark all of
4637f8829a4aSRandall Stewart 			 * it
4638f8829a4aSRandall Stewart 			 */
4639f8829a4aSRandall Stewart 			notdone = 1;
4640f8829a4aSRandall Stewart 			tp1 = TAILQ_NEXT(tp1, sctp_next);
4641f8829a4aSRandall Stewart 		}
4642f8829a4aSRandall Stewart 	} while (tp1 && notdone);
4643f8829a4aSRandall Stewart 	if ((foundeom == 0) && (queue == &stcb->asoc.sent_queue)) {
4644f8829a4aSRandall Stewart 		/*
4645f8829a4aSRandall Stewart 		 * The multi-part message was scattered across the send and
4646f8829a4aSRandall Stewart 		 * sent queue.
4647f8829a4aSRandall Stewart 		 */
4648f8829a4aSRandall Stewart 		tp1 = TAILQ_FIRST(&stcb->asoc.send_queue);
4649f8829a4aSRandall Stewart 		/*
4650f8829a4aSRandall Stewart 		 * recurse throught the send_queue too, starting at the
4651f8829a4aSRandall Stewart 		 * beginning.
4652f8829a4aSRandall Stewart 		 */
4653f8829a4aSRandall Stewart 		if (tp1) {
4654f8829a4aSRandall Stewart 			ret_sz += sctp_release_pr_sctp_chunk(stcb, tp1, reason,
4655ceaad40aSRandall Stewart 			    &stcb->asoc.send_queue, so_locked);
4656f8829a4aSRandall Stewart 		} else {
4657ad81507eSRandall Stewart 			SCTP_PRINTF("hmm, nothing on the send queue and no EOM?\n");
4658f8829a4aSRandall Stewart 		}
4659f8829a4aSRandall Stewart 	}
4660f8829a4aSRandall Stewart 	return (ret_sz);
4661f8829a4aSRandall Stewart }
4662f8829a4aSRandall Stewart 
4663f8829a4aSRandall Stewart /*
4664f8829a4aSRandall Stewart  * checks to see if the given address, sa, is one that is currently known by
4665f8829a4aSRandall Stewart  * the kernel note: can't distinguish the same address on multiple interfaces
4666f8829a4aSRandall Stewart  * and doesn't handle multiple addresses with different zone/scope id's note:
4667f8829a4aSRandall Stewart  * ifa_ifwithaddr() compares the entire sockaddr struct
4668f8829a4aSRandall Stewart  */
466942551e99SRandall Stewart struct sctp_ifa *
467080fefe0aSRandall Stewart sctp_find_ifa_in_ep(struct sctp_inpcb *inp, struct sockaddr *addr,
467180fefe0aSRandall Stewart     int holds_lock)
4672f8829a4aSRandall Stewart {
467342551e99SRandall Stewart 	struct sctp_laddr *laddr;
4674f8829a4aSRandall Stewart 
4675ad81507eSRandall Stewart 	if (holds_lock == 0) {
467642551e99SRandall Stewart 		SCTP_INP_RLOCK(inp);
4677ad81507eSRandall Stewart 	}
467842551e99SRandall Stewart 	LIST_FOREACH(laddr, &inp->sctp_addr_list, sctp_nxt_addr) {
467942551e99SRandall Stewart 		if (laddr->ifa == NULL)
4680f8829a4aSRandall Stewart 			continue;
468142551e99SRandall Stewart 		if (addr->sa_family != laddr->ifa->address.sa.sa_family)
468242551e99SRandall Stewart 			continue;
468342551e99SRandall Stewart 		if (addr->sa_family == AF_INET) {
468442551e99SRandall Stewart 			if (((struct sockaddr_in *)addr)->sin_addr.s_addr ==
468542551e99SRandall Stewart 			    laddr->ifa->address.sin.sin_addr.s_addr) {
468642551e99SRandall Stewart 				/* found him. */
4687ad81507eSRandall Stewart 				if (holds_lock == 0) {
468842551e99SRandall Stewart 					SCTP_INP_RUNLOCK(inp);
4689ad81507eSRandall Stewart 				}
469042551e99SRandall Stewart 				return (laddr->ifa);
469142551e99SRandall Stewart 				break;
469242551e99SRandall Stewart 			}
46935e2c2d87SRandall Stewart 		}
46945e2c2d87SRandall Stewart #ifdef INET6
46955e2c2d87SRandall Stewart 		if (addr->sa_family == AF_INET6) {
4696c54a18d2SRandall Stewart 			if (SCTP6_ARE_ADDR_EQUAL((struct sockaddr_in6 *)addr,
4697c54a18d2SRandall Stewart 			    &laddr->ifa->address.sin6)) {
469842551e99SRandall Stewart 				/* found him. */
4699ad81507eSRandall Stewart 				if (holds_lock == 0) {
470042551e99SRandall Stewart 					SCTP_INP_RUNLOCK(inp);
4701ad81507eSRandall Stewart 				}
470242551e99SRandall Stewart 				return (laddr->ifa);
470342551e99SRandall Stewart 				break;
470442551e99SRandall Stewart 			}
470542551e99SRandall Stewart 		}
47065e2c2d87SRandall Stewart #endif
470742551e99SRandall Stewart 	}
4708ad81507eSRandall Stewart 	if (holds_lock == 0) {
470942551e99SRandall Stewart 		SCTP_INP_RUNLOCK(inp);
4710ad81507eSRandall Stewart 	}
471142551e99SRandall Stewart 	return (NULL);
471242551e99SRandall Stewart }
4713f8829a4aSRandall Stewart 
47146a27c376SRandall Stewart uint32_t
47156a27c376SRandall Stewart sctp_get_ifa_hash_val(struct sockaddr *addr)
47166a27c376SRandall Stewart {
47176a27c376SRandall Stewart 	if (addr->sa_family == AF_INET) {
47186a27c376SRandall Stewart 		struct sockaddr_in *sin;
47196a27c376SRandall Stewart 
47206a27c376SRandall Stewart 		sin = (struct sockaddr_in *)addr;
47216a27c376SRandall Stewart 		return (sin->sin_addr.s_addr ^ (sin->sin_addr.s_addr >> 16));
47226a27c376SRandall Stewart 	} else if (addr->sa_family == AF_INET6) {
47236a27c376SRandall Stewart 		struct sockaddr_in6 *sin6;
47246a27c376SRandall Stewart 		uint32_t hash_of_addr;
47256a27c376SRandall Stewart 
47266a27c376SRandall Stewart 		sin6 = (struct sockaddr_in6 *)addr;
47276a27c376SRandall Stewart 		hash_of_addr = (sin6->sin6_addr.s6_addr32[0] +
47286a27c376SRandall Stewart 		    sin6->sin6_addr.s6_addr32[1] +
47296a27c376SRandall Stewart 		    sin6->sin6_addr.s6_addr32[2] +
47306a27c376SRandall Stewart 		    sin6->sin6_addr.s6_addr32[3]);
47316a27c376SRandall Stewart 		hash_of_addr = (hash_of_addr ^ (hash_of_addr >> 16));
47326a27c376SRandall Stewart 		return (hash_of_addr);
47336a27c376SRandall Stewart 	}
47346a27c376SRandall Stewart 	return (0);
47356a27c376SRandall Stewart }
47366a27c376SRandall Stewart 
473742551e99SRandall Stewart struct sctp_ifa *
473842551e99SRandall Stewart sctp_find_ifa_by_addr(struct sockaddr *addr, uint32_t vrf_id, int holds_lock)
473942551e99SRandall Stewart {
474042551e99SRandall Stewart 	struct sctp_ifa *sctp_ifap;
474142551e99SRandall Stewart 	struct sctp_vrf *vrf;
47426a27c376SRandall Stewart 	struct sctp_ifalist *hash_head;
47436a27c376SRandall Stewart 	uint32_t hash_of_addr;
474442551e99SRandall Stewart 
474542551e99SRandall Stewart 	if (holds_lock == 0)
4746c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RLOCK();
474742551e99SRandall Stewart 
4748bff64a4dSRandall Stewart 	vrf = sctp_find_vrf(vrf_id);
4749bff64a4dSRandall Stewart 	if (vrf == NULL) {
4750df6e0cc3SRandall Stewart stage_right:
4751bff64a4dSRandall Stewart 		if (holds_lock == 0)
4752c99efcf6SRandall Stewart 			SCTP_IPI_ADDR_RUNLOCK();
4753bff64a4dSRandall Stewart 		return (NULL);
4754bff64a4dSRandall Stewart 	}
4755bff64a4dSRandall Stewart 	hash_of_addr = sctp_get_ifa_hash_val(addr);
4756bff64a4dSRandall Stewart 
475717205eccSRandall Stewart 	hash_head = &vrf->vrf_addr_hash[(hash_of_addr & vrf->vrf_addr_hashmark)];
4758bff64a4dSRandall Stewart 	if (hash_head == NULL) {
4759ad81507eSRandall Stewart 		SCTP_PRINTF("hash_of_addr:%x mask:%x table:%x - ",
4760c99efcf6SRandall Stewart 		    hash_of_addr, (uint32_t) vrf->vrf_addr_hashmark,
4761c99efcf6SRandall Stewart 		    (uint32_t) (hash_of_addr & vrf->vrf_addr_hashmark));
4762bff64a4dSRandall Stewart 		sctp_print_address(addr);
4763ad81507eSRandall Stewart 		SCTP_PRINTF("No such bucket for address\n");
4764bff64a4dSRandall Stewart 		if (holds_lock == 0)
4765c99efcf6SRandall Stewart 			SCTP_IPI_ADDR_RUNLOCK();
4766bff64a4dSRandall Stewart 
4767bff64a4dSRandall Stewart 		return (NULL);
4768bff64a4dSRandall Stewart 	}
47696a27c376SRandall Stewart 	LIST_FOREACH(sctp_ifap, hash_head, next_bucket) {
4770bff64a4dSRandall Stewart 		if (sctp_ifap == NULL) {
4771df6e0cc3SRandall Stewart #ifdef INVARIANTS
4772bff64a4dSRandall Stewart 			panic("Huh LIST_FOREACH corrupt");
4773df6e0cc3SRandall Stewart 			goto stage_right;
4774df6e0cc3SRandall Stewart #else
4775df6e0cc3SRandall Stewart 			SCTP_PRINTF("LIST corrupt of sctp_ifap's?\n");
4776df6e0cc3SRandall Stewart 			goto stage_right;
4777df6e0cc3SRandall Stewart #endif
4778bff64a4dSRandall Stewart 		}
47796a27c376SRandall Stewart 		if (addr->sa_family != sctp_ifap->address.sa.sa_family)
47806a27c376SRandall Stewart 			continue;
47816a27c376SRandall Stewart 		if (addr->sa_family == AF_INET) {
47826a27c376SRandall Stewart 			if (((struct sockaddr_in *)addr)->sin_addr.s_addr ==
47836a27c376SRandall Stewart 			    sctp_ifap->address.sin.sin_addr.s_addr) {
47846a27c376SRandall Stewart 				/* found him. */
478542551e99SRandall Stewart 				if (holds_lock == 0)
4786c99efcf6SRandall Stewart 					SCTP_IPI_ADDR_RUNLOCK();
478742551e99SRandall Stewart 				return (sctp_ifap);
47886a27c376SRandall Stewart 				break;
47896a27c376SRandall Stewart 			}
47905e2c2d87SRandall Stewart 		}
47915e2c2d87SRandall Stewart #ifdef INET6
47925e2c2d87SRandall Stewart 		if (addr->sa_family == AF_INET6) {
4793c54a18d2SRandall Stewart 			if (SCTP6_ARE_ADDR_EQUAL((struct sockaddr_in6 *)addr,
4794c54a18d2SRandall Stewart 			    &sctp_ifap->address.sin6)) {
47956a27c376SRandall Stewart 				/* found him. */
47966a27c376SRandall Stewart 				if (holds_lock == 0)
4797c99efcf6SRandall Stewart 					SCTP_IPI_ADDR_RUNLOCK();
47986a27c376SRandall Stewart 				return (sctp_ifap);
47996a27c376SRandall Stewart 				break;
48006a27c376SRandall Stewart 			}
480142551e99SRandall Stewart 		}
48025e2c2d87SRandall Stewart #endif
480342551e99SRandall Stewart 	}
480442551e99SRandall Stewart 	if (holds_lock == 0)
4805c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RUNLOCK();
4806f8829a4aSRandall Stewart 	return (NULL);
4807f8829a4aSRandall Stewart }
4808f8829a4aSRandall Stewart 
4809f8829a4aSRandall Stewart static void
48104c9179adSRandall Stewart sctp_user_rcvd(struct sctp_tcb *stcb, uint32_t * freed_so_far, int hold_rlock,
4811f8829a4aSRandall Stewart     uint32_t rwnd_req)
4812f8829a4aSRandall Stewart {
4813f8829a4aSRandall Stewart 	/* User pulled some data, do we need a rwnd update? */
4814f8829a4aSRandall Stewart 	int r_unlocked = 0;
4815f8829a4aSRandall Stewart 	uint32_t dif, rwnd;
4816f8829a4aSRandall Stewart 	struct socket *so = NULL;
4817f8829a4aSRandall Stewart 
4818f8829a4aSRandall Stewart 	if (stcb == NULL)
4819f8829a4aSRandall Stewart 		return;
4820f8829a4aSRandall Stewart 
482150cec919SRandall Stewart 	atomic_add_int(&stcb->asoc.refcnt, 1);
4822f8829a4aSRandall Stewart 
482362c1ff9cSRandall Stewart 	if (stcb->asoc.state & (SCTP_STATE_ABOUT_TO_BE_FREED |
482462c1ff9cSRandall Stewart 	    SCTP_STATE_SHUTDOWN_RECEIVED |
48254c9179adSRandall Stewart 	    SCTP_STATE_SHUTDOWN_ACK_SENT)) {
4826f8829a4aSRandall Stewart 		/* Pre-check If we are freeing no update */
4827f8829a4aSRandall Stewart 		goto no_lock;
4828f8829a4aSRandall Stewart 	}
4829f8829a4aSRandall Stewart 	SCTP_INP_INCR_REF(stcb->sctp_ep);
4830f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
4831f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE)) {
4832f8829a4aSRandall Stewart 		goto out;
4833f8829a4aSRandall Stewart 	}
4834f8829a4aSRandall Stewart 	so = stcb->sctp_socket;
4835f8829a4aSRandall Stewart 	if (so == NULL) {
4836f8829a4aSRandall Stewart 		goto out;
4837f8829a4aSRandall Stewart 	}
4838f8829a4aSRandall Stewart 	atomic_add_int(&stcb->freed_by_sorcv_sincelast, *freed_so_far);
4839f8829a4aSRandall Stewart 	/* Have you have freed enough to look */
4840f8829a4aSRandall Stewart 	*freed_so_far = 0;
4841f8829a4aSRandall Stewart 	/* Yep, its worth a look and the lock overhead */
4842f8829a4aSRandall Stewart 
4843f8829a4aSRandall Stewart 	/* Figure out what the rwnd would be */
4844f8829a4aSRandall Stewart 	rwnd = sctp_calc_rwnd(stcb, &stcb->asoc);
4845f8829a4aSRandall Stewart 	if (rwnd >= stcb->asoc.my_last_reported_rwnd) {
4846f8829a4aSRandall Stewart 		dif = rwnd - stcb->asoc.my_last_reported_rwnd;
4847f8829a4aSRandall Stewart 	} else {
4848f8829a4aSRandall Stewart 		dif = 0;
4849f8829a4aSRandall Stewart 	}
4850f8829a4aSRandall Stewart 	if (dif >= rwnd_req) {
4851f8829a4aSRandall Stewart 		if (hold_rlock) {
4852f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(stcb->sctp_ep);
4853f8829a4aSRandall Stewart 			r_unlocked = 1;
4854f8829a4aSRandall Stewart 		}
4855f8829a4aSRandall Stewart 		if (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
4856f8829a4aSRandall Stewart 			/*
4857f8829a4aSRandall Stewart 			 * One last check before we allow the guy possibly
4858f8829a4aSRandall Stewart 			 * to get in. There is a race, where the guy has not
4859f8829a4aSRandall Stewart 			 * reached the gate. In that case
4860f8829a4aSRandall Stewart 			 */
4861f8829a4aSRandall Stewart 			goto out;
4862f8829a4aSRandall Stewart 		}
4863f8829a4aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
4864f8829a4aSRandall Stewart 		if (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
4865f8829a4aSRandall Stewart 			/* No reports here */
4866f8829a4aSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
4867f8829a4aSRandall Stewart 			goto out;
4868f8829a4aSRandall Stewart 		}
4869f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_wu_sacks_sent);
4870830d754dSRandall Stewart 		/*
4871830d754dSRandall Stewart 		 * EY if nr_sacks used then send an nr-sack , a sack
4872830d754dSRandall Stewart 		 * otherwise
4873830d754dSRandall Stewart 		 */
4874830d754dSRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_nr_sack_on_off) && stcb->asoc.peer_supports_nr_sack)
4875830d754dSRandall Stewart 			sctp_send_nr_sack(stcb);
4876830d754dSRandall Stewart 		else
4877f8829a4aSRandall Stewart 			sctp_send_sack(stcb);
4878830d754dSRandall Stewart 
4879f8829a4aSRandall Stewart 		sctp_chunk_output(stcb->sctp_ep, stcb,
4880ceaad40aSRandall Stewart 		    SCTP_OUTPUT_FROM_USR_RCVD, SCTP_SO_LOCKED);
4881f8829a4aSRandall Stewart 		/* make sure no timer is running */
4882a5d547adSRandall Stewart 		sctp_timer_stop(SCTP_TIMER_TYPE_RECV, stcb->sctp_ep, stcb, NULL, SCTP_FROM_SCTPUTIL + SCTP_LOC_6);
4883f8829a4aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
4884f8829a4aSRandall Stewart 	} else {
4885f8829a4aSRandall Stewart 		/* Update how much we have pending */
4886f8829a4aSRandall Stewart 		stcb->freed_by_sorcv_sincelast = dif;
4887f8829a4aSRandall Stewart 	}
4888f8829a4aSRandall Stewart out:
4889f8829a4aSRandall Stewart 	if (so && r_unlocked && hold_rlock) {
4890f8829a4aSRandall Stewart 		SCTP_INP_READ_LOCK(stcb->sctp_ep);
4891f8829a4aSRandall Stewart 	}
4892f8829a4aSRandall Stewart 	SCTP_INP_DECR_REF(stcb->sctp_ep);
4893f8829a4aSRandall Stewart no_lock:
489450cec919SRandall Stewart 	atomic_add_int(&stcb->asoc.refcnt, -1);
4895f8829a4aSRandall Stewart 	return;
4896f8829a4aSRandall Stewart }
4897f8829a4aSRandall Stewart 
4898f8829a4aSRandall Stewart int
4899f8829a4aSRandall Stewart sctp_sorecvmsg(struct socket *so,
4900f8829a4aSRandall Stewart     struct uio *uio,
4901f8829a4aSRandall Stewart     struct mbuf **mp,
4902f8829a4aSRandall Stewart     struct sockaddr *from,
4903f8829a4aSRandall Stewart     int fromlen,
4904f8829a4aSRandall Stewart     int *msg_flags,
4905f8829a4aSRandall Stewart     struct sctp_sndrcvinfo *sinfo,
4906f8829a4aSRandall Stewart     int filling_sinfo)
4907f8829a4aSRandall Stewart {
4908f8829a4aSRandall Stewart 	/*
4909f8829a4aSRandall Stewart 	 * MSG flags we will look at MSG_DONTWAIT - non-blocking IO.
4910f8829a4aSRandall Stewart 	 * MSG_PEEK - Look don't touch :-D (only valid with OUT mbuf copy
4911f8829a4aSRandall Stewart 	 * mp=NULL thus uio is the copy method to userland) MSG_WAITALL - ??
4912f8829a4aSRandall Stewart 	 * On the way out we may send out any combination of:
4913f8829a4aSRandall Stewart 	 * MSG_NOTIFICATION MSG_EOR
4914f8829a4aSRandall Stewart 	 *
4915f8829a4aSRandall Stewart 	 */
4916f8829a4aSRandall Stewart 	struct sctp_inpcb *inp = NULL;
4917f8829a4aSRandall Stewart 	int my_len = 0;
4918f8829a4aSRandall Stewart 	int cp_len = 0, error = 0;
4919f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control = NULL, *ctl = NULL, *nxt = NULL;
4920f8829a4aSRandall Stewart 	struct mbuf *m = NULL, *embuf = NULL;
4921f8829a4aSRandall Stewart 	struct sctp_tcb *stcb = NULL;
4922f8829a4aSRandall Stewart 	int wakeup_read_socket = 0;
4923f8829a4aSRandall Stewart 	int freecnt_applied = 0;
4924f8829a4aSRandall Stewart 	int out_flags = 0, in_flags = 0;
4925f8829a4aSRandall Stewart 	int block_allowed = 1;
49264c9179adSRandall Stewart 	uint32_t freed_so_far = 0;
492781aca91aSRandall Stewart 	uint32_t copied_so_far = 0;
492893164cf9SRandall Stewart 	int in_eeor_mode = 0;
4929f8829a4aSRandall Stewart 	int no_rcv_needed = 0;
4930f8829a4aSRandall Stewart 	uint32_t rwnd_req = 0;
4931f8829a4aSRandall Stewart 	int hold_sblock = 0;
4932f8829a4aSRandall Stewart 	int hold_rlock = 0;
493342551e99SRandall Stewart 	int slen = 0;
49344c9179adSRandall Stewart 	uint32_t held_length = 0;
49357abab911SRobert Watson 	int sockbuf_lock = 0;
4936f8829a4aSRandall Stewart 
493717205eccSRandall Stewart 	if (uio == NULL) {
4938c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
493917205eccSRandall Stewart 		return (EINVAL);
494017205eccSRandall Stewart 	}
4941f8829a4aSRandall Stewart 	if (msg_flags) {
4942f8829a4aSRandall Stewart 		in_flags = *msg_flags;
4943c105859eSRandall Stewart 		if (in_flags & MSG_PEEK)
4944c105859eSRandall Stewart 			SCTP_STAT_INCR(sctps_read_peeks);
4945f8829a4aSRandall Stewart 	} else {
4946f8829a4aSRandall Stewart 		in_flags = 0;
4947f8829a4aSRandall Stewart 	}
4948f8829a4aSRandall Stewart 	slen = uio->uio_resid;
494917205eccSRandall Stewart 
4950f8829a4aSRandall Stewart 	/* Pull in and set up our int flags */
4951f8829a4aSRandall Stewart 	if (in_flags & MSG_OOB) {
4952f8829a4aSRandall Stewart 		/* Out of band's NOT supported */
4953f8829a4aSRandall Stewart 		return (EOPNOTSUPP);
4954f8829a4aSRandall Stewart 	}
4955f8829a4aSRandall Stewart 	if ((in_flags & MSG_PEEK) && (mp != NULL)) {
4956c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
4957f8829a4aSRandall Stewart 		return (EINVAL);
4958f8829a4aSRandall Stewart 	}
4959f8829a4aSRandall Stewart 	if ((in_flags & (MSG_DONTWAIT
4960f8829a4aSRandall Stewart 	    | MSG_NBIO
4961f8829a4aSRandall Stewart 	    )) ||
496242551e99SRandall Stewart 	    SCTP_SO_IS_NBIO(so)) {
4963f8829a4aSRandall Stewart 		block_allowed = 0;
4964f8829a4aSRandall Stewart 	}
4965f8829a4aSRandall Stewart 	/* setup the endpoint */
4966f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)so->so_pcb;
4967f8829a4aSRandall Stewart 	if (inp == NULL) {
4968c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EFAULT);
4969f8829a4aSRandall Stewart 		return (EFAULT);
4970f8829a4aSRandall Stewart 	}
497162c1ff9cSRandall Stewart 	rwnd_req = (SCTP_SB_LIMIT_RCV(so) >> SCTP_RWND_HIWAT_SHIFT);
4972f8829a4aSRandall Stewart 	/* Must be at least a MTU's worth */
4973f8829a4aSRandall Stewart 	if (rwnd_req < SCTP_MIN_RWND)
4974f8829a4aSRandall Stewart 		rwnd_req = SCTP_MIN_RWND;
4975f8829a4aSRandall Stewart 	in_eeor_mode = sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXPLICIT_EOR);
4976b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
4977f8829a4aSRandall Stewart 		sctp_misc_ints(SCTP_SORECV_ENTER,
497817205eccSRandall Stewart 		    rwnd_req, in_eeor_mode, so->so_rcv.sb_cc, uio->uio_resid);
497980fefe0aSRandall Stewart 	}
4980b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
4981f8829a4aSRandall Stewart 		sctp_misc_ints(SCTP_SORECV_ENTERPL,
498217205eccSRandall Stewart 		    rwnd_req, block_allowed, so->so_rcv.sb_cc, uio->uio_resid);
498380fefe0aSRandall Stewart 	}
4984265de5bbSRobert Watson 	error = sblock(&so->so_rcv, (block_allowed ? SBL_WAIT : 0));
49857abab911SRobert Watson 	sockbuf_lock = 1;
4986f8829a4aSRandall Stewart 	if (error) {
4987f8829a4aSRandall Stewart 		goto release_unlocked;
4988f8829a4aSRandall Stewart 	}
4989f8829a4aSRandall Stewart restart:
49907abab911SRobert Watson 
4991f8829a4aSRandall Stewart 
4992f8829a4aSRandall Stewart restart_nosblocks:
4993f8829a4aSRandall Stewart 	if (hold_sblock == 0) {
4994f8829a4aSRandall Stewart 		SOCKBUF_LOCK(&so->so_rcv);
4995f8829a4aSRandall Stewart 		hold_sblock = 1;
4996f8829a4aSRandall Stewart 	}
4997f8829a4aSRandall Stewart 	if ((inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
4998f8829a4aSRandall Stewart 	    (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE)) {
4999f8829a4aSRandall Stewart 		goto out;
5000f8829a4aSRandall Stewart 	}
500144b7479bSRandall Stewart 	if (so->so_rcv.sb_state & SBS_CANTRCVMORE) {
5002f8829a4aSRandall Stewart 		if (so->so_error) {
5003f8829a4aSRandall Stewart 			error = so->so_error;
500444b7479bSRandall Stewart 			if ((in_flags & MSG_PEEK) == 0)
500544b7479bSRandall Stewart 				so->so_error = 0;
50069f22f500SRandall Stewart 			goto out;
5007f8829a4aSRandall Stewart 		} else {
50089f22f500SRandall Stewart 			if (so->so_rcv.sb_cc == 0) {
5009c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOTCONN);
50107924093fSRandall Stewart 				/* indicate EOF */
50117924093fSRandall Stewart 				error = 0;
5012f8829a4aSRandall Stewart 				goto out;
5013f8829a4aSRandall Stewart 			}
50149f22f500SRandall Stewart 		}
50159f22f500SRandall Stewart 	}
5016f8829a4aSRandall Stewart 	if ((so->so_rcv.sb_cc <= held_length) && block_allowed) {
5017f8829a4aSRandall Stewart 		/* we need to wait for data */
5018f8829a4aSRandall Stewart 		if ((so->so_rcv.sb_cc == 0) &&
5019f8829a4aSRandall Stewart 		    ((inp->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
5020f8829a4aSRandall Stewart 		    (inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL))) {
5021f8829a4aSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_CONNECTED) == 0) {
5022f8829a4aSRandall Stewart 				/*
5023f8829a4aSRandall Stewart 				 * For active open side clear flags for
5024f8829a4aSRandall Stewart 				 * re-use passive open is blocked by
5025f8829a4aSRandall Stewart 				 * connect.
5026f8829a4aSRandall Stewart 				 */
5027f8829a4aSRandall Stewart 				if (inp->sctp_flags & SCTP_PCB_FLAGS_WAS_ABORTED) {
5028f8829a4aSRandall Stewart 					/*
5029f8829a4aSRandall Stewart 					 * You were aborted, passive side
5030f8829a4aSRandall Stewart 					 * always hits here
5031f8829a4aSRandall Stewart 					 */
5032c4739e2fSRandall Stewart 					SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ECONNRESET);
5033f8829a4aSRandall Stewart 					error = ECONNRESET;
5034f8829a4aSRandall Stewart 					/*
5035f8829a4aSRandall Stewart 					 * You get this once if you are
5036f8829a4aSRandall Stewart 					 * active open side
5037f8829a4aSRandall Stewart 					 */
5038f8829a4aSRandall Stewart 					if (!(inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
5039f8829a4aSRandall Stewart 						/*
5040f8829a4aSRandall Stewart 						 * Remove flag if on the
5041f8829a4aSRandall Stewart 						 * active open side
5042f8829a4aSRandall Stewart 						 */
5043f8829a4aSRandall Stewart 						inp->sctp_flags &= ~SCTP_PCB_FLAGS_WAS_ABORTED;
5044f8829a4aSRandall Stewart 					}
5045f8829a4aSRandall Stewart 				}
5046f8829a4aSRandall Stewart 				so->so_state &= ~(SS_ISCONNECTING |
5047f8829a4aSRandall Stewart 				    SS_ISDISCONNECTING |
5048f8829a4aSRandall Stewart 				    SS_ISCONFIRMING |
5049f8829a4aSRandall Stewart 				    SS_ISCONNECTED);
5050f8829a4aSRandall Stewart 				if (error == 0) {
5051f8829a4aSRandall Stewart 					if ((inp->sctp_flags & SCTP_PCB_FLAGS_WAS_CONNECTED) == 0) {
5052c4739e2fSRandall Stewart 						SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOTCONN);
5053f8829a4aSRandall Stewart 						error = ENOTCONN;
5054f8829a4aSRandall Stewart 					} else {
5055f8829a4aSRandall Stewart 						inp->sctp_flags &= ~SCTP_PCB_FLAGS_WAS_CONNECTED;
5056f8829a4aSRandall Stewart 					}
5057f8829a4aSRandall Stewart 				}
5058f8829a4aSRandall Stewart 				goto out;
5059f8829a4aSRandall Stewart 			}
5060f8829a4aSRandall Stewart 		}
5061f8829a4aSRandall Stewart 		error = sbwait(&so->so_rcv);
5062f8829a4aSRandall Stewart 		if (error) {
5063f8829a4aSRandall Stewart 			goto out;
5064f8829a4aSRandall Stewart 		}
5065f8829a4aSRandall Stewart 		held_length = 0;
5066f8829a4aSRandall Stewart 		goto restart_nosblocks;
5067f8829a4aSRandall Stewart 	} else if (so->so_rcv.sb_cc == 0) {
506844b7479bSRandall Stewart 		if (so->so_error) {
506944b7479bSRandall Stewart 			error = so->so_error;
507044b7479bSRandall Stewart 			if ((in_flags & MSG_PEEK) == 0)
507144b7479bSRandall Stewart 				so->so_error = 0;
507244b7479bSRandall Stewart 		} else {
507344b7479bSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
507444b7479bSRandall Stewart 			    (inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
507544b7479bSRandall Stewart 				if ((inp->sctp_flags & SCTP_PCB_FLAGS_CONNECTED) == 0) {
507644b7479bSRandall Stewart 					/*
507744b7479bSRandall Stewart 					 * For active open side clear flags
507844b7479bSRandall Stewart 					 * for re-use passive open is
507944b7479bSRandall Stewart 					 * blocked by connect.
508044b7479bSRandall Stewart 					 */
508144b7479bSRandall Stewart 					if (inp->sctp_flags & SCTP_PCB_FLAGS_WAS_ABORTED) {
508244b7479bSRandall Stewart 						/*
508344b7479bSRandall Stewart 						 * You were aborted, passive
508444b7479bSRandall Stewart 						 * side always hits here
508544b7479bSRandall Stewart 						 */
5086c4739e2fSRandall Stewart 						SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ECONNRESET);
508744b7479bSRandall Stewart 						error = ECONNRESET;
508844b7479bSRandall Stewart 						/*
508944b7479bSRandall Stewart 						 * You get this once if you
509044b7479bSRandall Stewart 						 * are active open side
509144b7479bSRandall Stewart 						 */
509244b7479bSRandall Stewart 						if (!(inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
509344b7479bSRandall Stewart 							/*
509444b7479bSRandall Stewart 							 * Remove flag if on
509544b7479bSRandall Stewart 							 * the active open
509644b7479bSRandall Stewart 							 * side
509744b7479bSRandall Stewart 							 */
509844b7479bSRandall Stewart 							inp->sctp_flags &= ~SCTP_PCB_FLAGS_WAS_ABORTED;
509944b7479bSRandall Stewart 						}
510044b7479bSRandall Stewart 					}
510144b7479bSRandall Stewart 					so->so_state &= ~(SS_ISCONNECTING |
510244b7479bSRandall Stewart 					    SS_ISDISCONNECTING |
510344b7479bSRandall Stewart 					    SS_ISCONFIRMING |
510444b7479bSRandall Stewart 					    SS_ISCONNECTED);
510544b7479bSRandall Stewart 					if (error == 0) {
510644b7479bSRandall Stewart 						if ((inp->sctp_flags & SCTP_PCB_FLAGS_WAS_CONNECTED) == 0) {
5107c4739e2fSRandall Stewart 							SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOTCONN);
510844b7479bSRandall Stewart 							error = ENOTCONN;
510944b7479bSRandall Stewart 						} else {
511044b7479bSRandall Stewart 							inp->sctp_flags &= ~SCTP_PCB_FLAGS_WAS_CONNECTED;
511144b7479bSRandall Stewart 						}
511244b7479bSRandall Stewart 					}
511344b7479bSRandall Stewart 					goto out;
511444b7479bSRandall Stewart 				}
511544b7479bSRandall Stewart 			}
5116c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EWOULDBLOCK);
5117f8829a4aSRandall Stewart 			error = EWOULDBLOCK;
511844b7479bSRandall Stewart 		}
5119f8829a4aSRandall Stewart 		goto out;
5120f8829a4aSRandall Stewart 	}
5121d06c82f1SRandall Stewart 	if (hold_sblock == 1) {
5122d06c82f1SRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
5123d06c82f1SRandall Stewart 		hold_sblock = 0;
5124d06c82f1SRandall Stewart 	}
5125f8829a4aSRandall Stewart 	/* we possibly have data we can read */
51263c503c28SRandall Stewart 	/* sa_ignore FREED_MEMORY */
5127f8829a4aSRandall Stewart 	control = TAILQ_FIRST(&inp->read_queue);
5128f8829a4aSRandall Stewart 	if (control == NULL) {
5129f8829a4aSRandall Stewart 		/*
5130f8829a4aSRandall Stewart 		 * This could be happening since the appender did the
5131f8829a4aSRandall Stewart 		 * increment but as not yet did the tailq insert onto the
5132f8829a4aSRandall Stewart 		 * read_queue
5133f8829a4aSRandall Stewart 		 */
5134f8829a4aSRandall Stewart 		if (hold_rlock == 0) {
5135f8829a4aSRandall Stewart 			SCTP_INP_READ_LOCK(inp);
5136f8829a4aSRandall Stewart 			hold_rlock = 1;
5137f8829a4aSRandall Stewart 		}
5138f8829a4aSRandall Stewart 		control = TAILQ_FIRST(&inp->read_queue);
5139f8829a4aSRandall Stewart 		if ((control == NULL) && (so->so_rcv.sb_cc != 0)) {
5140a5d547adSRandall Stewart #ifdef INVARIANTS
5141f8829a4aSRandall Stewart 			panic("Huh, its non zero and nothing on control?");
5142f8829a4aSRandall Stewart #endif
5143f8829a4aSRandall Stewart 			so->so_rcv.sb_cc = 0;
5144f8829a4aSRandall Stewart 		}
5145f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
5146f8829a4aSRandall Stewart 		hold_rlock = 0;
5147f8829a4aSRandall Stewart 		goto restart;
5148f8829a4aSRandall Stewart 	}
5149f8829a4aSRandall Stewart 	if ((control->length == 0) &&
5150f8829a4aSRandall Stewart 	    (control->do_not_ref_stcb)) {
5151f8829a4aSRandall Stewart 		/*
5152f8829a4aSRandall Stewart 		 * Clean up code for freeing assoc that left behind a
5153f8829a4aSRandall Stewart 		 * pdapi.. maybe a peer in EEOR that just closed after
5154f8829a4aSRandall Stewart 		 * sending and never indicated a EOR.
5155f8829a4aSRandall Stewart 		 */
5156f8829a4aSRandall Stewart 		if (hold_rlock == 0) {
5157f8829a4aSRandall Stewart 			hold_rlock = 1;
5158f8829a4aSRandall Stewart 			SCTP_INP_READ_LOCK(inp);
5159f8829a4aSRandall Stewart 		}
5160f8829a4aSRandall Stewart 		control->held_length = 0;
5161f8829a4aSRandall Stewart 		if (control->data) {
5162f8829a4aSRandall Stewart 			/* Hmm there is data here .. fix */
51634c9179adSRandall Stewart 			struct mbuf *m_tmp;
5164f8829a4aSRandall Stewart 			int cnt = 0;
5165f8829a4aSRandall Stewart 
51664c9179adSRandall Stewart 			m_tmp = control->data;
51674c9179adSRandall Stewart 			while (m_tmp) {
51684c9179adSRandall Stewart 				cnt += SCTP_BUF_LEN(m_tmp);
51694c9179adSRandall Stewart 				if (SCTP_BUF_NEXT(m_tmp) == NULL) {
51704c9179adSRandall Stewart 					control->tail_mbuf = m_tmp;
5171f8829a4aSRandall Stewart 					control->end_added = 1;
5172f8829a4aSRandall Stewart 				}
51734c9179adSRandall Stewart 				m_tmp = SCTP_BUF_NEXT(m_tmp);
5174f8829a4aSRandall Stewart 			}
5175f8829a4aSRandall Stewart 			control->length = cnt;
5176f8829a4aSRandall Stewart 		} else {
5177f8829a4aSRandall Stewart 			/* remove it */
5178f8829a4aSRandall Stewart 			TAILQ_REMOVE(&inp->read_queue, control, next);
5179f8829a4aSRandall Stewart 			/* Add back any hiddend data */
5180f8829a4aSRandall Stewart 			sctp_free_remote_addr(control->whoFrom);
5181f8829a4aSRandall Stewart 			sctp_free_a_readq(stcb, control);
5182f8829a4aSRandall Stewart 		}
5183f8829a4aSRandall Stewart 		if (hold_rlock) {
5184f8829a4aSRandall Stewart 			hold_rlock = 0;
5185f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
5186f8829a4aSRandall Stewart 		}
5187f8829a4aSRandall Stewart 		goto restart;
5188f8829a4aSRandall Stewart 	}
5189f8829a4aSRandall Stewart 	if (control->length == 0) {
5190f8829a4aSRandall Stewart 		if ((sctp_is_feature_on(inp, SCTP_PCB_FLAGS_FRAG_INTERLEAVE)) &&
5191f8829a4aSRandall Stewart 		    (filling_sinfo)) {
5192f8829a4aSRandall Stewart 			/* find a more suitable one then this */
5193f8829a4aSRandall Stewart 			ctl = TAILQ_NEXT(control, next);
5194f8829a4aSRandall Stewart 			while (ctl) {
51959a6142d8SRandall Stewart 				if ((ctl->stcb != control->stcb) && (ctl->length) &&
51969a6142d8SRandall Stewart 				    (ctl->some_taken ||
51976114cd96SRandall Stewart 				    (ctl->spec_flags & M_NOTIFICATION) ||
51989a6142d8SRandall Stewart 				    ((ctl->do_not_ref_stcb == 0) &&
51999a6142d8SRandall Stewart 				    (ctl->stcb->asoc.strmin[ctl->sinfo_stream].delivery_started == 0)))
52009a6142d8SRandall Stewart 				    ) {
52019a6142d8SRandall Stewart 					/*-
52029a6142d8SRandall Stewart 					 * If we have a different TCB next, and there is data
52039a6142d8SRandall Stewart 					 * present. If we have already taken some (pdapi), OR we can
52049a6142d8SRandall Stewart 					 * ref the tcb and no delivery as started on this stream, we
520517205eccSRandall Stewart 					 * take it. Note we allow a notification on a different
520617205eccSRandall Stewart 					 * assoc to be delivered..
52079a6142d8SRandall Stewart 					 */
52089a6142d8SRandall Stewart 					control = ctl;
52099a6142d8SRandall Stewart 					goto found_one;
52109a6142d8SRandall Stewart 				} else if ((sctp_is_feature_on(inp, SCTP_PCB_FLAGS_INTERLEAVE_STRMS)) &&
52119a6142d8SRandall Stewart 					    (ctl->length) &&
52129a6142d8SRandall Stewart 					    ((ctl->some_taken) ||
52139a6142d8SRandall Stewart 					    ((ctl->do_not_ref_stcb == 0) &&
521417205eccSRandall Stewart 					    ((ctl->spec_flags & M_NOTIFICATION) == 0) &&
52159a6142d8SRandall Stewart 					    (ctl->stcb->asoc.strmin[ctl->sinfo_stream].delivery_started == 0)))
52169a6142d8SRandall Stewart 				    ) {
52179a6142d8SRandall Stewart 					/*-
52189a6142d8SRandall Stewart 					 * If we have the same tcb, and there is data present, and we
52199a6142d8SRandall Stewart 					 * have the strm interleave feature present. Then if we have
52209a6142d8SRandall Stewart 					 * taken some (pdapi) or we can refer to tht tcb AND we have
52219a6142d8SRandall Stewart 					 * not started a delivery for this stream, we can take it.
522217205eccSRandall Stewart 					 * Note we do NOT allow a notificaiton on the same assoc to
522317205eccSRandall Stewart 					 * be delivered.
52249a6142d8SRandall Stewart 					 */
5225f8829a4aSRandall Stewart 					control = ctl;
5226f8829a4aSRandall Stewart 					goto found_one;
5227f8829a4aSRandall Stewart 				}
5228f8829a4aSRandall Stewart 				ctl = TAILQ_NEXT(ctl, next);
5229f8829a4aSRandall Stewart 			}
5230f8829a4aSRandall Stewart 		}
5231f8829a4aSRandall Stewart 		/*
5232f8829a4aSRandall Stewart 		 * if we reach here, not suitable replacement is available
5233f8829a4aSRandall Stewart 		 * <or> fragment interleave is NOT on. So stuff the sb_cc
5234f8829a4aSRandall Stewart 		 * into the our held count, and its time to sleep again.
5235f8829a4aSRandall Stewart 		 */
5236f8829a4aSRandall Stewart 		held_length = so->so_rcv.sb_cc;
5237f8829a4aSRandall Stewart 		control->held_length = so->so_rcv.sb_cc;
5238f8829a4aSRandall Stewart 		goto restart;
5239f8829a4aSRandall Stewart 	}
5240f8829a4aSRandall Stewart 	/* Clear the held length since there is something to read */
5241f8829a4aSRandall Stewart 	control->held_length = 0;
5242f8829a4aSRandall Stewart 	if (hold_rlock) {
5243f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
5244f8829a4aSRandall Stewart 		hold_rlock = 0;
5245f8829a4aSRandall Stewart 	}
5246f8829a4aSRandall Stewart found_one:
5247f8829a4aSRandall Stewart 	/*
5248f8829a4aSRandall Stewart 	 * If we reach here, control has a some data for us to read off.
5249f8829a4aSRandall Stewart 	 * Note that stcb COULD be NULL.
5250f8829a4aSRandall Stewart 	 */
52519c04b296SRandall Stewart 	control->some_taken++;
5252f8829a4aSRandall Stewart 	if (hold_sblock) {
5253f8829a4aSRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
5254f8829a4aSRandall Stewart 		hold_sblock = 0;
5255f8829a4aSRandall Stewart 	}
5256f8829a4aSRandall Stewart 	stcb = control->stcb;
5257f8829a4aSRandall Stewart 	if (stcb) {
52580696e120SRandall Stewart 		if ((control->do_not_ref_stcb == 0) &&
52590696e120SRandall Stewart 		    (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED)) {
526050cec919SRandall Stewart 			if (freecnt_applied == 0)
5261f8829a4aSRandall Stewart 				stcb = NULL;
5262f8829a4aSRandall Stewart 		} else if (control->do_not_ref_stcb == 0) {
5263f8829a4aSRandall Stewart 			/* you can't free it on me please */
5264f8829a4aSRandall Stewart 			/*
5265f8829a4aSRandall Stewart 			 * The lock on the socket buffer protects us so the
5266f8829a4aSRandall Stewart 			 * free code will stop. But since we used the
5267f8829a4aSRandall Stewart 			 * socketbuf lock and the sender uses the tcb_lock
5268f8829a4aSRandall Stewart 			 * to increment, we need to use the atomic add to
5269f8829a4aSRandall Stewart 			 * the refcnt
5270f8829a4aSRandall Stewart 			 */
5271d55b0b1bSRandall Stewart 			if (freecnt_applied) {
5272d55b0b1bSRandall Stewart #ifdef INVARIANTS
5273207304d4SRandall Stewart 				panic("refcnt already incremented");
5274d55b0b1bSRandall Stewart #else
5275d55b0b1bSRandall Stewart 				printf("refcnt already incremented?\n");
5276d55b0b1bSRandall Stewart #endif
5277d55b0b1bSRandall Stewart 			} else {
527850cec919SRandall Stewart 				atomic_add_int(&stcb->asoc.refcnt, 1);
5279f8829a4aSRandall Stewart 				freecnt_applied = 1;
5280d55b0b1bSRandall Stewart 			}
5281f8829a4aSRandall Stewart 			/*
5282f8829a4aSRandall Stewart 			 * Setup to remember how much we have not yet told
5283f8829a4aSRandall Stewart 			 * the peer our rwnd has opened up. Note we grab the
5284f8829a4aSRandall Stewart 			 * value from the tcb from last time. Note too that
52850696e120SRandall Stewart 			 * sack sending clears this when a sack is sent,
5286f8829a4aSRandall Stewart 			 * which is fine. Once we hit the rwnd_req, we then
5287f8829a4aSRandall Stewart 			 * will go to the sctp_user_rcvd() that will not
5288f8829a4aSRandall Stewart 			 * lock until it KNOWs it MUST send a WUP-SACK.
5289f8829a4aSRandall Stewart 			 */
5290f8829a4aSRandall Stewart 			freed_so_far = stcb->freed_by_sorcv_sincelast;
5291f8829a4aSRandall Stewart 			stcb->freed_by_sorcv_sincelast = 0;
5292f8829a4aSRandall Stewart 		}
5293f8829a4aSRandall Stewart 	}
52946114cd96SRandall Stewart 	if (stcb &&
52956114cd96SRandall Stewart 	    ((control->spec_flags & M_NOTIFICATION) == 0) &&
52966114cd96SRandall Stewart 	    control->do_not_ref_stcb == 0) {
5297d06c82f1SRandall Stewart 		stcb->asoc.strmin[control->sinfo_stream].delivery_started = 1;
5298d06c82f1SRandall Stewart 	}
5299f8829a4aSRandall Stewart 	/* First lets get off the sinfo and sockaddr info */
5300f8829a4aSRandall Stewart 	if ((sinfo) && filling_sinfo) {
5301f8829a4aSRandall Stewart 		memcpy(sinfo, control, sizeof(struct sctp_nonpad_sndrcvinfo));
5302f8829a4aSRandall Stewart 		nxt = TAILQ_NEXT(control, next);
5303f8829a4aSRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXT_RCVINFO)) {
5304f8829a4aSRandall Stewart 			struct sctp_extrcvinfo *s_extra;
5305f8829a4aSRandall Stewart 
5306f8829a4aSRandall Stewart 			s_extra = (struct sctp_extrcvinfo *)sinfo;
53079a6142d8SRandall Stewart 			if ((nxt) &&
53089a6142d8SRandall Stewart 			    (nxt->length)) {
53099a6142d8SRandall Stewart 				s_extra->sreinfo_next_flags = SCTP_NEXT_MSG_AVAIL;
5310f8829a4aSRandall Stewart 				if (nxt->sinfo_flags & SCTP_UNORDERED) {
53119a6142d8SRandall Stewart 					s_extra->sreinfo_next_flags |= SCTP_NEXT_MSG_IS_UNORDERED;
5312f8829a4aSRandall Stewart 				}
5313f42a358aSRandall Stewart 				if (nxt->spec_flags & M_NOTIFICATION) {
53149a6142d8SRandall Stewart 					s_extra->sreinfo_next_flags |= SCTP_NEXT_MSG_IS_NOTIFICATION;
5315f42a358aSRandall Stewart 				}
53169a6142d8SRandall Stewart 				s_extra->sreinfo_next_aid = nxt->sinfo_assoc_id;
53179a6142d8SRandall Stewart 				s_extra->sreinfo_next_length = nxt->length;
53189a6142d8SRandall Stewart 				s_extra->sreinfo_next_ppid = nxt->sinfo_ppid;
53199a6142d8SRandall Stewart 				s_extra->sreinfo_next_stream = nxt->sinfo_stream;
5320f8829a4aSRandall Stewart 				if (nxt->tail_mbuf != NULL) {
5321139bc87fSRandall Stewart 					if (nxt->end_added) {
53229a6142d8SRandall Stewart 						s_extra->sreinfo_next_flags |= SCTP_NEXT_MSG_ISCOMPLETE;
5323f8829a4aSRandall Stewart 					}
5324f8829a4aSRandall Stewart 				}
5325f8829a4aSRandall Stewart 			} else {
5326f8829a4aSRandall Stewart 				/*
5327f8829a4aSRandall Stewart 				 * we explicitly 0 this, since the memcpy
5328f8829a4aSRandall Stewart 				 * got some other things beyond the older
5329f8829a4aSRandall Stewart 				 * sinfo_ that is on the control's structure
5330f8829a4aSRandall Stewart 				 * :-D
5331f8829a4aSRandall Stewart 				 */
53329a6142d8SRandall Stewart 				nxt = NULL;
53339a6142d8SRandall Stewart 				s_extra->sreinfo_next_flags = SCTP_NO_NEXT_MSG;
53349a6142d8SRandall Stewart 				s_extra->sreinfo_next_aid = 0;
53359a6142d8SRandall Stewart 				s_extra->sreinfo_next_length = 0;
53369a6142d8SRandall Stewart 				s_extra->sreinfo_next_ppid = 0;
53379a6142d8SRandall Stewart 				s_extra->sreinfo_next_stream = 0;
5338f8829a4aSRandall Stewart 			}
5339f8829a4aSRandall Stewart 		}
5340f8829a4aSRandall Stewart 		/*
5341f8829a4aSRandall Stewart 		 * update off the real current cum-ack, if we have an stcb.
5342f8829a4aSRandall Stewart 		 */
53430696e120SRandall Stewart 		if ((control->do_not_ref_stcb == 0) && stcb)
5344f8829a4aSRandall Stewart 			sinfo->sinfo_cumtsn = stcb->asoc.cumulative_tsn;
5345f8829a4aSRandall Stewart 		/*
5346f8829a4aSRandall Stewart 		 * mask off the high bits, we keep the actual chunk bits in
5347f8829a4aSRandall Stewart 		 * there.
5348f8829a4aSRandall Stewart 		 */
5349f8829a4aSRandall Stewart 		sinfo->sinfo_flags &= 0x00ff;
53505f26a41dSRandall Stewart 		if ((control->sinfo_flags >> 8) & SCTP_DATA_UNORDERED) {
53515f26a41dSRandall Stewart 			sinfo->sinfo_flags |= SCTP_UNORDERED;
53525f26a41dSRandall Stewart 		}
5353f8829a4aSRandall Stewart 	}
535418e198d3SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
535518e198d3SRandall Stewart 	{
535618e198d3SRandall Stewart 		int index, newindex;
535718e198d3SRandall Stewart 		struct sctp_pcbtsn_rlog *entry;
535818e198d3SRandall Stewart 
535918e198d3SRandall Stewart 		do {
536018e198d3SRandall Stewart 			index = inp->readlog_index;
536118e198d3SRandall Stewart 			newindex = index + 1;
536218e198d3SRandall Stewart 			if (newindex >= SCTP_READ_LOG_SIZE) {
536318e198d3SRandall Stewart 				newindex = 0;
536418e198d3SRandall Stewart 			}
536518e198d3SRandall Stewart 		} while (atomic_cmpset_int(&inp->readlog_index, index, newindex) == 0);
536618e198d3SRandall Stewart 		entry = &inp->readlog[index];
536718e198d3SRandall Stewart 		entry->vtag = control->sinfo_assoc_id;
536818e198d3SRandall Stewart 		entry->strm = control->sinfo_stream;
536918e198d3SRandall Stewart 		entry->seq = control->sinfo_ssn;
537018e198d3SRandall Stewart 		entry->sz = control->length;
537118e198d3SRandall Stewart 		entry->flgs = control->sinfo_flags;
537218e198d3SRandall Stewart 	}
537318e198d3SRandall Stewart #endif
5374f8829a4aSRandall Stewart 	if (fromlen && from) {
5375f8829a4aSRandall Stewart 		struct sockaddr *to;
5376f8829a4aSRandall Stewart 
537742551e99SRandall Stewart #ifdef INET
5378baf3da66SRandall Stewart 		cp_len = min((size_t)fromlen, (size_t)control->whoFrom->ro._l_addr.sin.sin_len);
5379f8829a4aSRandall Stewart 		memcpy(from, &control->whoFrom->ro._l_addr, cp_len);
5380f8829a4aSRandall Stewart 		((struct sockaddr_in *)from)->sin_port = control->port_from;
5381f8829a4aSRandall Stewart #else
5382f8829a4aSRandall Stewart 		/* No AF_INET use AF_INET6 */
5383baf3da66SRandall Stewart 		cp_len = min((size_t)fromlen, (size_t)control->whoFrom->ro._l_addr.sin6.sin6_len);
5384f8829a4aSRandall Stewart 		memcpy(from, &control->whoFrom->ro._l_addr, cp_len);
5385f8829a4aSRandall Stewart 		((struct sockaddr_in6 *)from)->sin6_port = control->port_from;
5386f8829a4aSRandall Stewart #endif
5387f8829a4aSRandall Stewart 
5388f8829a4aSRandall Stewart 		to = from;
538942551e99SRandall Stewart #if defined(INET) && defined(INET6)
53905e2c2d87SRandall Stewart 		if ((sctp_is_feature_on(inp, SCTP_PCB_FLAGS_NEEDS_MAPPED_V4)) &&
5391f8829a4aSRandall Stewart 		    (to->sa_family == AF_INET) &&
5392f8829a4aSRandall Stewart 		    ((size_t)fromlen >= sizeof(struct sockaddr_in6))) {
5393f8829a4aSRandall Stewart 			struct sockaddr_in *sin;
5394f8829a4aSRandall Stewart 			struct sockaddr_in6 sin6;
5395f8829a4aSRandall Stewart 
5396f8829a4aSRandall Stewart 			sin = (struct sockaddr_in *)to;
5397f8829a4aSRandall Stewart 			bzero(&sin6, sizeof(sin6));
5398f8829a4aSRandall Stewart 			sin6.sin6_family = AF_INET6;
5399f8829a4aSRandall Stewart 			sin6.sin6_len = sizeof(struct sockaddr_in6);
5400d6af161aSRandall Stewart 			sin6.sin6_addr.s6_addr32[2] = htonl(0xffff);
5401f8829a4aSRandall Stewart 			bcopy(&sin->sin_addr,
5402d6af161aSRandall Stewart 			    &sin6.sin6_addr.s6_addr32[3],
5403d6af161aSRandall Stewart 			    sizeof(sin6.sin6_addr.s6_addr32[3]));
5404f8829a4aSRandall Stewart 			sin6.sin6_port = sin->sin_port;
5405f8829a4aSRandall Stewart 			memcpy(from, (caddr_t)&sin6, sizeof(sin6));
5406f8829a4aSRandall Stewart 		}
5407f8829a4aSRandall Stewart #endif
540842551e99SRandall Stewart #if defined(INET6)
5409f8829a4aSRandall Stewart 		{
5410f8829a4aSRandall Stewart 			struct sockaddr_in6 lsa6, *to6;
5411f8829a4aSRandall Stewart 
5412f8829a4aSRandall Stewart 			to6 = (struct sockaddr_in6 *)to;
5413f8829a4aSRandall Stewart 			sctp_recover_scope_mac(to6, (&lsa6));
5414f8829a4aSRandall Stewart 		}
5415f8829a4aSRandall Stewart #endif
5416f8829a4aSRandall Stewart 	}
5417f8829a4aSRandall Stewart 	/* now copy out what data we can */
5418f8829a4aSRandall Stewart 	if (mp == NULL) {
5419f8829a4aSRandall Stewart 		/* copy out each mbuf in the chain up to length */
5420f8829a4aSRandall Stewart get_more_data:
5421f8829a4aSRandall Stewart 		m = control->data;
5422f8829a4aSRandall Stewart 		while (m) {
5423f8829a4aSRandall Stewart 			/* Move out all we can */
5424f8829a4aSRandall Stewart 			cp_len = (int)uio->uio_resid;
5425139bc87fSRandall Stewart 			my_len = (int)SCTP_BUF_LEN(m);
5426f8829a4aSRandall Stewart 			if (cp_len > my_len) {
5427f8829a4aSRandall Stewart 				/* not enough in this buf */
5428f8829a4aSRandall Stewart 				cp_len = my_len;
5429f8829a4aSRandall Stewart 			}
5430f8829a4aSRandall Stewart 			if (hold_rlock) {
5431f8829a4aSRandall Stewart 				SCTP_INP_READ_UNLOCK(inp);
5432f8829a4aSRandall Stewart 				hold_rlock = 0;
5433f8829a4aSRandall Stewart 			}
5434f8829a4aSRandall Stewart 			if (cp_len > 0)
5435f8829a4aSRandall Stewart 				error = uiomove(mtod(m, char *), cp_len, uio);
5436f8829a4aSRandall Stewart 			/* re-read */
5437f8829a4aSRandall Stewart 			if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
5438f8829a4aSRandall Stewart 				goto release;
5439f8829a4aSRandall Stewart 			}
54400696e120SRandall Stewart 			if ((control->do_not_ref_stcb == 0) && stcb &&
5441f8829a4aSRandall Stewart 			    stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
5442f8829a4aSRandall Stewart 				no_rcv_needed = 1;
5443f8829a4aSRandall Stewart 			}
5444f8829a4aSRandall Stewart 			if (error) {
5445f8829a4aSRandall Stewart 				/* error we are out of here */
5446f8829a4aSRandall Stewart 				goto release;
5447f8829a4aSRandall Stewart 			}
5448139bc87fSRandall Stewart 			if ((SCTP_BUF_NEXT(m) == NULL) &&
5449139bc87fSRandall Stewart 			    (cp_len >= SCTP_BUF_LEN(m)) &&
5450f8829a4aSRandall Stewart 			    ((control->end_added == 0) ||
54510696e120SRandall Stewart 			    (control->end_added &&
54520696e120SRandall Stewart 			    (TAILQ_NEXT(control, next) == NULL)))
5453f8829a4aSRandall Stewart 			    ) {
5454f8829a4aSRandall Stewart 				SCTP_INP_READ_LOCK(inp);
5455f8829a4aSRandall Stewart 				hold_rlock = 1;
5456f8829a4aSRandall Stewart 			}
5457139bc87fSRandall Stewart 			if (cp_len == SCTP_BUF_LEN(m)) {
5458139bc87fSRandall Stewart 				if ((SCTP_BUF_NEXT(m) == NULL) &&
5459139bc87fSRandall Stewart 				    (control->end_added)) {
5460f8829a4aSRandall Stewart 					out_flags |= MSG_EOR;
54616114cd96SRandall Stewart 					if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
5462ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
5463f8829a4aSRandall Stewart 				}
5464139bc87fSRandall Stewart 				if (control->spec_flags & M_NOTIFICATION) {
5465f8829a4aSRandall Stewart 					out_flags |= MSG_NOTIFICATION;
5466f8829a4aSRandall Stewart 				}
5467f8829a4aSRandall Stewart 				/* we ate up the mbuf */
5468f8829a4aSRandall Stewart 				if (in_flags & MSG_PEEK) {
5469f8829a4aSRandall Stewart 					/* just looking */
5470139bc87fSRandall Stewart 					m = SCTP_BUF_NEXT(m);
5471f8829a4aSRandall Stewart 					copied_so_far += cp_len;
5472f8829a4aSRandall Stewart 				} else {
5473f8829a4aSRandall Stewart 					/* dispose of the mbuf */
5474b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5475f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv,
5476139bc87fSRandall Stewart 						    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
547780fefe0aSRandall Stewart 					}
5478f8829a4aSRandall Stewart 					sctp_sbfree(control, stcb, &so->so_rcv, m);
5479b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5480f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv,
5481f8829a4aSRandall Stewart 						    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
548280fefe0aSRandall Stewart 					}
5483f8829a4aSRandall Stewart 					embuf = m;
5484f8829a4aSRandall Stewart 					copied_so_far += cp_len;
5485f8829a4aSRandall Stewart 					freed_so_far += cp_len;
5486c4739e2fSRandall Stewart 					freed_so_far += MSIZE;
548718e198d3SRandall Stewart 					atomic_subtract_int(&control->length, cp_len);
5488f8829a4aSRandall Stewart 					control->data = sctp_m_free(m);
5489f8829a4aSRandall Stewart 					m = control->data;
5490f8829a4aSRandall Stewart 					/*
5491f8829a4aSRandall Stewart 					 * been through it all, must hold sb
5492f8829a4aSRandall Stewart 					 * lock ok to null tail
5493f8829a4aSRandall Stewart 					 */
5494f8829a4aSRandall Stewart 					if (control->data == NULL) {
5495a5d547adSRandall Stewart #ifdef INVARIANTS
5496f8829a4aSRandall Stewart 						if ((control->end_added == 0) ||
5497f8829a4aSRandall Stewart 						    (TAILQ_NEXT(control, next) == NULL)) {
5498f8829a4aSRandall Stewart 							/*
5499f8829a4aSRandall Stewart 							 * If the end is not
5500f8829a4aSRandall Stewart 							 * added, OR the
5501f8829a4aSRandall Stewart 							 * next is NOT null
5502f8829a4aSRandall Stewart 							 * we MUST have the
5503f8829a4aSRandall Stewart 							 * lock.
5504f8829a4aSRandall Stewart 							 */
5505f8829a4aSRandall Stewart 							if (mtx_owned(&inp->inp_rdata_mtx) == 0) {
5506f8829a4aSRandall Stewart 								panic("Hmm we don't own the lock?");
5507f8829a4aSRandall Stewart 							}
5508f8829a4aSRandall Stewart 						}
5509f8829a4aSRandall Stewart #endif
5510f8829a4aSRandall Stewart 						control->tail_mbuf = NULL;
5511a5d547adSRandall Stewart #ifdef INVARIANTS
5512f8829a4aSRandall Stewart 						if ((control->end_added) && ((out_flags & MSG_EOR) == 0)) {
5513f8829a4aSRandall Stewart 							panic("end_added, nothing left and no MSG_EOR");
5514f8829a4aSRandall Stewart 						}
5515f8829a4aSRandall Stewart #endif
5516f8829a4aSRandall Stewart 					}
5517f8829a4aSRandall Stewart 				}
5518f8829a4aSRandall Stewart 			} else {
5519f8829a4aSRandall Stewart 				/* Do we need to trim the mbuf? */
5520139bc87fSRandall Stewart 				if (control->spec_flags & M_NOTIFICATION) {
5521f8829a4aSRandall Stewart 					out_flags |= MSG_NOTIFICATION;
5522f8829a4aSRandall Stewart 				}
5523f8829a4aSRandall Stewart 				if ((in_flags & MSG_PEEK) == 0) {
5524139bc87fSRandall Stewart 					SCTP_BUF_RESV_UF(m, cp_len);
5525139bc87fSRandall Stewart 					SCTP_BUF_LEN(m) -= cp_len;
5526b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5527f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, cp_len);
552880fefe0aSRandall Stewart 					}
5529f8829a4aSRandall Stewart 					atomic_subtract_int(&so->so_rcv.sb_cc, cp_len);
55300696e120SRandall Stewart 					if ((control->do_not_ref_stcb == 0) &&
55310696e120SRandall Stewart 					    stcb) {
5532f8829a4aSRandall Stewart 						atomic_subtract_int(&stcb->asoc.sb_cc, cp_len);
5533f8829a4aSRandall Stewart 					}
5534f8829a4aSRandall Stewart 					copied_so_far += cp_len;
5535f8829a4aSRandall Stewart 					embuf = m;
5536f8829a4aSRandall Stewart 					freed_so_far += cp_len;
5537c4739e2fSRandall Stewart 					freed_so_far += MSIZE;
5538b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5539f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv, control->do_not_ref_stcb ? NULL : stcb,
5540f8829a4aSRandall Stewart 						    SCTP_LOG_SBRESULT, 0);
554180fefe0aSRandall Stewart 					}
554218e198d3SRandall Stewart 					atomic_subtract_int(&control->length, cp_len);
5543f8829a4aSRandall Stewart 				} else {
5544f8829a4aSRandall Stewart 					copied_so_far += cp_len;
5545f8829a4aSRandall Stewart 				}
5546f8829a4aSRandall Stewart 			}
5547d61a0ae0SRandall Stewart 			if ((out_flags & MSG_EOR) || (uio->uio_resid == 0)) {
5548f8829a4aSRandall Stewart 				break;
5549f8829a4aSRandall Stewart 			}
5550f8829a4aSRandall Stewart 			if (((stcb) && (in_flags & MSG_PEEK) == 0) &&
5551f8829a4aSRandall Stewart 			    (control->do_not_ref_stcb == 0) &&
5552f8829a4aSRandall Stewart 			    (freed_so_far >= rwnd_req)) {
5553f8829a4aSRandall Stewart 				sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
5554f8829a4aSRandall Stewart 			}
5555f8829a4aSRandall Stewart 		}		/* end while(m) */
5556f8829a4aSRandall Stewart 		/*
5557f8829a4aSRandall Stewart 		 * At this point we have looked at it all and we either have
5558f8829a4aSRandall Stewart 		 * a MSG_EOR/or read all the user wants... <OR>
5559f8829a4aSRandall Stewart 		 * control->length == 0.
5560f8829a4aSRandall Stewart 		 */
5561d61a0ae0SRandall Stewart 		if ((out_flags & MSG_EOR) && ((in_flags & MSG_PEEK) == 0)) {
5562f8829a4aSRandall Stewart 			/* we are done with this control */
5563f8829a4aSRandall Stewart 			if (control->length == 0) {
5564f8829a4aSRandall Stewart 				if (control->data) {
5565a5d547adSRandall Stewart #ifdef INVARIANTS
5566f8829a4aSRandall Stewart 					panic("control->data not null at read eor?");
5567f8829a4aSRandall Stewart #else
5568ad81507eSRandall Stewart 					SCTP_PRINTF("Strange, data left in the control buffer .. invarients would panic?\n");
5569f8829a4aSRandall Stewart 					sctp_m_freem(control->data);
5570f8829a4aSRandall Stewart 					control->data = NULL;
5571f8829a4aSRandall Stewart #endif
5572f8829a4aSRandall Stewart 				}
5573f8829a4aSRandall Stewart 		done_with_control:
5574f8829a4aSRandall Stewart 				if (TAILQ_NEXT(control, next) == NULL) {
5575f8829a4aSRandall Stewart 					/*
5576f8829a4aSRandall Stewart 					 * If we don't have a next we need a
5577b201f536SRandall Stewart 					 * lock, if there is a next
5578b201f536SRandall Stewart 					 * interrupt is filling ahead of us
5579b201f536SRandall Stewart 					 * and we don't need a lock to
5580b201f536SRandall Stewart 					 * remove this guy (which is the
5581b201f536SRandall Stewart 					 * head of the queue).
5582f8829a4aSRandall Stewart 					 */
5583f8829a4aSRandall Stewart 					if (hold_rlock == 0) {
5584f8829a4aSRandall Stewart 						SCTP_INP_READ_LOCK(inp);
5585f8829a4aSRandall Stewart 						hold_rlock = 1;
5586f8829a4aSRandall Stewart 					}
5587f8829a4aSRandall Stewart 				}
5588f8829a4aSRandall Stewart 				TAILQ_REMOVE(&inp->read_queue, control, next);
5589f8829a4aSRandall Stewart 				/* Add back any hiddend data */
5590f8829a4aSRandall Stewart 				if (control->held_length) {
5591f8829a4aSRandall Stewart 					held_length = 0;
5592f8829a4aSRandall Stewart 					control->held_length = 0;
5593f8829a4aSRandall Stewart 					wakeup_read_socket = 1;
5594f8829a4aSRandall Stewart 				}
559517205eccSRandall Stewart 				if (control->aux_data) {
559617205eccSRandall Stewart 					sctp_m_free(control->aux_data);
559717205eccSRandall Stewart 					control->aux_data = NULL;
559817205eccSRandall Stewart 				}
5599f8829a4aSRandall Stewart 				no_rcv_needed = control->do_not_ref_stcb;
5600f8829a4aSRandall Stewart 				sctp_free_remote_addr(control->whoFrom);
5601f8829a4aSRandall Stewart 				control->data = NULL;
5602f8829a4aSRandall Stewart 				sctp_free_a_readq(stcb, control);
5603f8829a4aSRandall Stewart 				control = NULL;
56040696e120SRandall Stewart 				if ((freed_so_far >= rwnd_req) &&
56050696e120SRandall Stewart 				    (no_rcv_needed == 0))
5606f8829a4aSRandall Stewart 					sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
5607f8829a4aSRandall Stewart 
5608f8829a4aSRandall Stewart 			} else {
5609f8829a4aSRandall Stewart 				/*
5610f8829a4aSRandall Stewart 				 * The user did not read all of this
5611f8829a4aSRandall Stewart 				 * message, turn off the returned MSG_EOR
5612f8829a4aSRandall Stewart 				 * since we are leaving more behind on the
5613f8829a4aSRandall Stewart 				 * control to read.
5614f8829a4aSRandall Stewart 				 */
5615a5d547adSRandall Stewart #ifdef INVARIANTS
56160696e120SRandall Stewart 				if (control->end_added &&
56170696e120SRandall Stewart 				    (control->data == NULL) &&
5618f8829a4aSRandall Stewart 				    (control->tail_mbuf == NULL)) {
5619f8829a4aSRandall Stewart 					panic("Gak, control->length is corrupt?");
5620f8829a4aSRandall Stewart 				}
5621f8829a4aSRandall Stewart #endif
5622f8829a4aSRandall Stewart 				no_rcv_needed = control->do_not_ref_stcb;
5623f8829a4aSRandall Stewart 				out_flags &= ~MSG_EOR;
5624f8829a4aSRandall Stewart 			}
5625f8829a4aSRandall Stewart 		}
5626f8829a4aSRandall Stewart 		if (out_flags & MSG_EOR) {
5627f8829a4aSRandall Stewart 			goto release;
5628f8829a4aSRandall Stewart 		}
5629f8829a4aSRandall Stewart 		if ((uio->uio_resid == 0) ||
5630f8829a4aSRandall Stewart 		    ((in_eeor_mode) && (copied_so_far >= max(so->so_rcv.sb_lowat, 1)))
5631f8829a4aSRandall Stewart 		    ) {
5632f8829a4aSRandall Stewart 			goto release;
5633f8829a4aSRandall Stewart 		}
5634f8829a4aSRandall Stewart 		/*
5635f8829a4aSRandall Stewart 		 * If I hit here the receiver wants more and this message is
5636f8829a4aSRandall Stewart 		 * NOT done (pd-api). So two questions. Can we block? if not
5637f8829a4aSRandall Stewart 		 * we are done. Did the user NOT set MSG_WAITALL?
5638f8829a4aSRandall Stewart 		 */
5639f8829a4aSRandall Stewart 		if (block_allowed == 0) {
5640f8829a4aSRandall Stewart 			goto release;
5641f8829a4aSRandall Stewart 		}
5642f8829a4aSRandall Stewart 		/*
5643f8829a4aSRandall Stewart 		 * We need to wait for more data a few things: - We don't
5644f8829a4aSRandall Stewart 		 * sbunlock() so we don't get someone else reading. - We
5645f8829a4aSRandall Stewart 		 * must be sure to account for the case where what is added
5646f8829a4aSRandall Stewart 		 * is NOT to our control when we wakeup.
5647f8829a4aSRandall Stewart 		 */
5648f8829a4aSRandall Stewart 
5649f8829a4aSRandall Stewart 		/*
5650f8829a4aSRandall Stewart 		 * Do we need to tell the transport a rwnd update might be
5651f8829a4aSRandall Stewart 		 * needed before we go to sleep?
5652f8829a4aSRandall Stewart 		 */
5653f8829a4aSRandall Stewart 		if (((stcb) && (in_flags & MSG_PEEK) == 0) &&
5654f8829a4aSRandall Stewart 		    ((freed_so_far >= rwnd_req) &&
5655f8829a4aSRandall Stewart 		    (control->do_not_ref_stcb == 0) &&
5656f8829a4aSRandall Stewart 		    (no_rcv_needed == 0))) {
5657f8829a4aSRandall Stewart 			sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
5658f8829a4aSRandall Stewart 		}
5659f8829a4aSRandall Stewart wait_some_more:
566044b7479bSRandall Stewart 		if (so->so_rcv.sb_state & SBS_CANTRCVMORE) {
5661f8829a4aSRandall Stewart 			goto release;
5662f8829a4aSRandall Stewart 		}
5663f8829a4aSRandall Stewart 		if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE)
5664f8829a4aSRandall Stewart 			goto release;
5665f8829a4aSRandall Stewart 
5666f8829a4aSRandall Stewart 		if (hold_rlock == 1) {
5667f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
5668f8829a4aSRandall Stewart 			hold_rlock = 0;
5669f8829a4aSRandall Stewart 		}
5670f8829a4aSRandall Stewart 		if (hold_sblock == 0) {
5671f8829a4aSRandall Stewart 			SOCKBUF_LOCK(&so->so_rcv);
5672f8829a4aSRandall Stewart 			hold_sblock = 1;
5673f8829a4aSRandall Stewart 		}
5674851b7298SRandall Stewart 		if ((copied_so_far) && (control->length == 0) &&
5675851b7298SRandall Stewart 		    (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_FRAG_INTERLEAVE))
5676851b7298SRandall Stewart 		    ) {
5677851b7298SRandall Stewart 			goto release;
5678851b7298SRandall Stewart 		}
5679f8829a4aSRandall Stewart 		if (so->so_rcv.sb_cc <= control->held_length) {
5680f8829a4aSRandall Stewart 			error = sbwait(&so->so_rcv);
5681f8829a4aSRandall Stewart 			if (error) {
5682f8829a4aSRandall Stewart 				goto release;
5683f8829a4aSRandall Stewart 			}
5684f8829a4aSRandall Stewart 			control->held_length = 0;
5685f8829a4aSRandall Stewart 		}
5686f8829a4aSRandall Stewart 		if (hold_sblock) {
5687f8829a4aSRandall Stewart 			SOCKBUF_UNLOCK(&so->so_rcv);
5688f8829a4aSRandall Stewart 			hold_sblock = 0;
5689f8829a4aSRandall Stewart 		}
5690f8829a4aSRandall Stewart 		if (control->length == 0) {
5691f8829a4aSRandall Stewart 			/* still nothing here */
5692f8829a4aSRandall Stewart 			if (control->end_added == 1) {
5693f8829a4aSRandall Stewart 				/* he aborted, or is done i.e.did a shutdown */
5694f8829a4aSRandall Stewart 				out_flags |= MSG_EOR;
56959a6142d8SRandall Stewart 				if (control->pdapi_aborted) {
56966114cd96SRandall Stewart 					if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
5697ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
56989a6142d8SRandall Stewart 
569903b0b021SRandall Stewart 					out_flags |= MSG_TRUNC;
57009a6142d8SRandall Stewart 				} else {
57016114cd96SRandall Stewart 					if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
5702ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
57039a6142d8SRandall Stewart 				}
5704f8829a4aSRandall Stewart 				goto done_with_control;
5705f8829a4aSRandall Stewart 			}
5706f8829a4aSRandall Stewart 			if (so->so_rcv.sb_cc > held_length) {
5707f8829a4aSRandall Stewart 				control->held_length = so->so_rcv.sb_cc;
5708f8829a4aSRandall Stewart 				held_length = 0;
5709f8829a4aSRandall Stewart 			}
5710f8829a4aSRandall Stewart 			goto wait_some_more;
5711f8829a4aSRandall Stewart 		} else if (control->data == NULL) {
571250cec919SRandall Stewart 			/*
571350cec919SRandall Stewart 			 * we must re-sync since data is probably being
571450cec919SRandall Stewart 			 * added
571550cec919SRandall Stewart 			 */
571650cec919SRandall Stewart 			SCTP_INP_READ_LOCK(inp);
571750cec919SRandall Stewart 			if ((control->length > 0) && (control->data == NULL)) {
571850cec919SRandall Stewart 				/*
571950cec919SRandall Stewart 				 * big trouble.. we have the lock and its
572050cec919SRandall Stewart 				 * corrupt?
572150cec919SRandall Stewart 				 */
57229c04b296SRandall Stewart #ifdef INVARIANTS
5723f8829a4aSRandall Stewart 				panic("Impossible data==NULL length !=0");
57249c04b296SRandall Stewart #endif
57259c04b296SRandall Stewart 				out_flags |= MSG_EOR;
57269c04b296SRandall Stewart 				out_flags |= MSG_TRUNC;
57279c04b296SRandall Stewart 				control->length = 0;
57289c04b296SRandall Stewart 				SCTP_INP_READ_UNLOCK(inp);
57299c04b296SRandall Stewart 				goto done_with_control;
5730f8829a4aSRandall Stewart 			}
573150cec919SRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
573250cec919SRandall Stewart 			/* We will fall around to get more data */
573350cec919SRandall Stewart 		}
5734f8829a4aSRandall Stewart 		goto get_more_data;
5735f8829a4aSRandall Stewart 	} else {
573617205eccSRandall Stewart 		/*-
573717205eccSRandall Stewart 		 * Give caller back the mbuf chain,
573817205eccSRandall Stewart 		 * store in uio_resid the length
5739f8829a4aSRandall Stewart 		 */
574017205eccSRandall Stewart 		wakeup_read_socket = 0;
5741f8829a4aSRandall Stewart 		if ((control->end_added == 0) ||
5742f8829a4aSRandall Stewart 		    (TAILQ_NEXT(control, next) == NULL)) {
5743f8829a4aSRandall Stewart 			/* Need to get rlock */
5744f8829a4aSRandall Stewart 			if (hold_rlock == 0) {
5745f8829a4aSRandall Stewart 				SCTP_INP_READ_LOCK(inp);
5746f8829a4aSRandall Stewart 				hold_rlock = 1;
5747f8829a4aSRandall Stewart 			}
5748f8829a4aSRandall Stewart 		}
5749139bc87fSRandall Stewart 		if (control->end_added) {
5750f8829a4aSRandall Stewart 			out_flags |= MSG_EOR;
57516114cd96SRandall Stewart 			if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
5752ee7f9857SRandall Stewart 				control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
5753f8829a4aSRandall Stewart 		}
5754139bc87fSRandall Stewart 		if (control->spec_flags & M_NOTIFICATION) {
5755f8829a4aSRandall Stewart 			out_flags |= MSG_NOTIFICATION;
5756f8829a4aSRandall Stewart 		}
575717205eccSRandall Stewart 		uio->uio_resid = control->length;
5758f8829a4aSRandall Stewart 		*mp = control->data;
5759f8829a4aSRandall Stewart 		m = control->data;
5760f8829a4aSRandall Stewart 		while (m) {
5761b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5762f8829a4aSRandall Stewart 				sctp_sblog(&so->so_rcv,
5763139bc87fSRandall Stewart 				    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
576480fefe0aSRandall Stewart 			}
5765f8829a4aSRandall Stewart 			sctp_sbfree(control, stcb, &so->so_rcv, m);
5766139bc87fSRandall Stewart 			freed_so_far += SCTP_BUF_LEN(m);
5767c4739e2fSRandall Stewart 			freed_so_far += MSIZE;
5768b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5769f8829a4aSRandall Stewart 				sctp_sblog(&so->so_rcv,
5770f8829a4aSRandall Stewart 				    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
577180fefe0aSRandall Stewart 			}
5772139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
5773f8829a4aSRandall Stewart 		}
5774f8829a4aSRandall Stewart 		control->data = control->tail_mbuf = NULL;
5775f8829a4aSRandall Stewart 		control->length = 0;
5776f8829a4aSRandall Stewart 		if (out_flags & MSG_EOR) {
5777f8829a4aSRandall Stewart 			/* Done with this control */
5778f8829a4aSRandall Stewart 			goto done_with_control;
5779f8829a4aSRandall Stewart 		}
5780f8829a4aSRandall Stewart 	}
5781f8829a4aSRandall Stewart release:
5782f8829a4aSRandall Stewart 	if (hold_rlock == 1) {
5783f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
5784f8829a4aSRandall Stewart 		hold_rlock = 0;
5785f8829a4aSRandall Stewart 	}
57867abab911SRobert Watson 	if (hold_sblock == 1) {
57877abab911SRobert Watson 		SOCKBUF_UNLOCK(&so->so_rcv);
57887abab911SRobert Watson 		hold_sblock = 0;
5789f8829a4aSRandall Stewart 	}
5790f8829a4aSRandall Stewart 	sbunlock(&so->so_rcv);
57917abab911SRobert Watson 	sockbuf_lock = 0;
5792f8829a4aSRandall Stewart 
5793f8829a4aSRandall Stewart release_unlocked:
5794f8829a4aSRandall Stewart 	if (hold_sblock) {
5795f8829a4aSRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
5796f8829a4aSRandall Stewart 		hold_sblock = 0;
5797f8829a4aSRandall Stewart 	}
5798f8829a4aSRandall Stewart 	if ((stcb) && (in_flags & MSG_PEEK) == 0) {
5799f8829a4aSRandall Stewart 		if ((freed_so_far >= rwnd_req) &&
5800f8829a4aSRandall Stewart 		    (control && (control->do_not_ref_stcb == 0)) &&
5801f8829a4aSRandall Stewart 		    (no_rcv_needed == 0))
5802f8829a4aSRandall Stewart 			sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
5803f8829a4aSRandall Stewart 	}
5804f8829a4aSRandall Stewart out:
58051b9f62a0SRandall Stewart 	if (msg_flags) {
58061b9f62a0SRandall Stewart 		*msg_flags = out_flags;
58071b9f62a0SRandall Stewart 	}
58089a6142d8SRandall Stewart 	if (((out_flags & MSG_EOR) == 0) &&
58099a6142d8SRandall Stewart 	    ((in_flags & MSG_PEEK) == 0) &&
58109a6142d8SRandall Stewart 	    (sinfo) &&
58119a6142d8SRandall Stewart 	    (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXT_RCVINFO))) {
58129a6142d8SRandall Stewart 		struct sctp_extrcvinfo *s_extra;
58139a6142d8SRandall Stewart 
58149a6142d8SRandall Stewart 		s_extra = (struct sctp_extrcvinfo *)sinfo;
58159a6142d8SRandall Stewart 		s_extra->sreinfo_next_flags = SCTP_NO_NEXT_MSG;
58169a6142d8SRandall Stewart 	}
5817f8829a4aSRandall Stewart 	if (hold_rlock == 1) {
5818f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
5819f8829a4aSRandall Stewart 		hold_rlock = 0;
5820f8829a4aSRandall Stewart 	}
5821f8829a4aSRandall Stewart 	if (hold_sblock) {
5822f8829a4aSRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
5823f8829a4aSRandall Stewart 		hold_sblock = 0;
5824f8829a4aSRandall Stewart 	}
58257abab911SRobert Watson 	if (sockbuf_lock) {
58267abab911SRobert Watson 		sbunlock(&so->so_rcv);
58277abab911SRobert Watson 	}
582850cec919SRandall Stewart 	if (freecnt_applied) {
5829f8829a4aSRandall Stewart 		/*
5830f8829a4aSRandall Stewart 		 * The lock on the socket buffer protects us so the free
5831f8829a4aSRandall Stewart 		 * code will stop. But since we used the socketbuf lock and
5832f8829a4aSRandall Stewart 		 * the sender uses the tcb_lock to increment, we need to use
5833f8829a4aSRandall Stewart 		 * the atomic add to the refcnt.
5834f8829a4aSRandall Stewart 		 */
583550cec919SRandall Stewart 		if (stcb == NULL) {
5836df6e0cc3SRandall Stewart #ifdef INVARIANTS
583750cec919SRandall Stewart 			panic("stcb for refcnt has gone NULL?");
5838df6e0cc3SRandall Stewart 			goto stage_left;
5839df6e0cc3SRandall Stewart #else
5840df6e0cc3SRandall Stewart 			goto stage_left;
5841df6e0cc3SRandall Stewart #endif
584250cec919SRandall Stewart 		}
584350cec919SRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, -1);
5844f8829a4aSRandall Stewart 		freecnt_applied = 0;
5845f8829a4aSRandall Stewart 		/* Save the value back for next time */
5846f8829a4aSRandall Stewart 		stcb->freed_by_sorcv_sincelast = freed_so_far;
5847f8829a4aSRandall Stewart 	}
5848b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
5849f8829a4aSRandall Stewart 		if (stcb) {
5850f8829a4aSRandall Stewart 			sctp_misc_ints(SCTP_SORECV_DONE,
5851f8829a4aSRandall Stewart 			    freed_so_far,
5852f8829a4aSRandall Stewart 			    ((uio) ? (slen - uio->uio_resid) : slen),
5853f8829a4aSRandall Stewart 			    stcb->asoc.my_rwnd,
5854f8829a4aSRandall Stewart 			    so->so_rcv.sb_cc);
5855f8829a4aSRandall Stewart 		} else {
5856f8829a4aSRandall Stewart 			sctp_misc_ints(SCTP_SORECV_DONE,
5857f8829a4aSRandall Stewart 			    freed_so_far,
5858f8829a4aSRandall Stewart 			    ((uio) ? (slen - uio->uio_resid) : slen),
5859f8829a4aSRandall Stewart 			    0,
5860f8829a4aSRandall Stewart 			    so->so_rcv.sb_cc);
5861f8829a4aSRandall Stewart 		}
586280fefe0aSRandall Stewart 	}
5863df6e0cc3SRandall Stewart stage_left:
5864f8829a4aSRandall Stewart 	if (wakeup_read_socket) {
5865f8829a4aSRandall Stewart 		sctp_sorwakeup(inp, so);
5866f8829a4aSRandall Stewart 	}
5867f8829a4aSRandall Stewart 	return (error);
5868f8829a4aSRandall Stewart }
5869f8829a4aSRandall Stewart 
5870f8829a4aSRandall Stewart 
5871f8829a4aSRandall Stewart #ifdef SCTP_MBUF_LOGGING
5872f8829a4aSRandall Stewart struct mbuf *
5873f8829a4aSRandall Stewart sctp_m_free(struct mbuf *m)
5874f8829a4aSRandall Stewart {
5875b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_MBUF_LOGGING_ENABLE) {
5876139bc87fSRandall Stewart 		if (SCTP_BUF_IS_EXTENDED(m)) {
5877f8829a4aSRandall Stewart 			sctp_log_mb(m, SCTP_MBUF_IFREE);
5878f8829a4aSRandall Stewart 		}
587980fefe0aSRandall Stewart 	}
5880f8829a4aSRandall Stewart 	return (m_free(m));
5881f8829a4aSRandall Stewart }
5882f8829a4aSRandall Stewart 
5883f8829a4aSRandall Stewart void
5884f8829a4aSRandall Stewart sctp_m_freem(struct mbuf *mb)
5885f8829a4aSRandall Stewart {
5886f8829a4aSRandall Stewart 	while (mb != NULL)
5887f8829a4aSRandall Stewart 		mb = sctp_m_free(mb);
5888f8829a4aSRandall Stewart }
5889f8829a4aSRandall Stewart 
5890f8829a4aSRandall Stewart #endif
5891f8829a4aSRandall Stewart 
589242551e99SRandall Stewart int
589342551e99SRandall Stewart sctp_dynamic_set_primary(struct sockaddr *sa, uint32_t vrf_id)
589442551e99SRandall Stewart {
589542551e99SRandall Stewart 	/*
589642551e99SRandall Stewart 	 * Given a local address. For all associations that holds the
589742551e99SRandall Stewart 	 * address, request a peer-set-primary.
589842551e99SRandall Stewart 	 */
589942551e99SRandall Stewart 	struct sctp_ifa *ifa;
590042551e99SRandall Stewart 	struct sctp_laddr *wi;
590142551e99SRandall Stewart 
590242551e99SRandall Stewart 	ifa = sctp_find_ifa_by_addr(sa, vrf_id, 0);
590342551e99SRandall Stewart 	if (ifa == NULL) {
5904c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EADDRNOTAVAIL);
590542551e99SRandall Stewart 		return (EADDRNOTAVAIL);
590642551e99SRandall Stewart 	}
590742551e99SRandall Stewart 	/*
590842551e99SRandall Stewart 	 * Now that we have the ifa we must awaken the iterator with this
590942551e99SRandall Stewart 	 * message.
591042551e99SRandall Stewart 	 */
5911b3f1ea41SRandall Stewart 	wi = SCTP_ZONE_GET(SCTP_BASE_INFO(ipi_zone_laddr), struct sctp_laddr);
591242551e99SRandall Stewart 	if (wi == NULL) {
5913c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
591442551e99SRandall Stewart 		return (ENOMEM);
591542551e99SRandall Stewart 	}
591642551e99SRandall Stewart 	/* Now incr the count and int wi structure */
591742551e99SRandall Stewart 	SCTP_INCR_LADDR_COUNT();
591842551e99SRandall Stewart 	bzero(wi, sizeof(*wi));
5919d61a0ae0SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&wi->start_time);
592042551e99SRandall Stewart 	wi->ifa = ifa;
592142551e99SRandall Stewart 	wi->action = SCTP_SET_PRIM_ADDR;
592242551e99SRandall Stewart 	atomic_add_int(&ifa->refcount, 1);
592342551e99SRandall Stewart 
592442551e99SRandall Stewart 	/* Now add it to the work queue */
592542551e99SRandall Stewart 	SCTP_IPI_ITERATOR_WQ_LOCK();
592642551e99SRandall Stewart 	/*
592742551e99SRandall Stewart 	 * Should this really be a tailq? As it is we will process the
592842551e99SRandall Stewart 	 * newest first :-0
592942551e99SRandall Stewart 	 */
5930b3f1ea41SRandall Stewart 	LIST_INSERT_HEAD(&SCTP_BASE_INFO(addr_wq), wi, sctp_nxt_addr);
593142551e99SRandall Stewart 	sctp_timer_start(SCTP_TIMER_TYPE_ADDR_WQ,
593242551e99SRandall Stewart 	    (struct sctp_inpcb *)NULL,
593342551e99SRandall Stewart 	    (struct sctp_tcb *)NULL,
593442551e99SRandall Stewart 	    (struct sctp_nets *)NULL);
593542551e99SRandall Stewart 	SCTP_IPI_ITERATOR_WQ_UNLOCK();
593642551e99SRandall Stewart 	return (0);
593742551e99SRandall Stewart }
593842551e99SRandall Stewart 
593942551e99SRandall Stewart 
5940f8829a4aSRandall Stewart int
594117205eccSRandall Stewart sctp_soreceive(struct socket *so,
594217205eccSRandall Stewart     struct sockaddr **psa,
594317205eccSRandall Stewart     struct uio *uio,
594417205eccSRandall Stewart     struct mbuf **mp0,
594517205eccSRandall Stewart     struct mbuf **controlp,
594617205eccSRandall Stewart     int *flagsp)
5947f8829a4aSRandall Stewart {
5948f8829a4aSRandall Stewart 	int error, fromlen;
5949f8829a4aSRandall Stewart 	uint8_t sockbuf[256];
5950f8829a4aSRandall Stewart 	struct sockaddr *from;
5951f8829a4aSRandall Stewart 	struct sctp_extrcvinfo sinfo;
5952f8829a4aSRandall Stewart 	int filling_sinfo = 1;
5953f8829a4aSRandall Stewart 	struct sctp_inpcb *inp;
5954f8829a4aSRandall Stewart 
5955f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)so->so_pcb;
5956f8829a4aSRandall Stewart 	/* pickup the assoc we are reading from */
5957f8829a4aSRandall Stewart 	if (inp == NULL) {
5958c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
5959f8829a4aSRandall Stewart 		return (EINVAL);
5960f8829a4aSRandall Stewart 	}
5961f8829a4aSRandall Stewart 	if ((sctp_is_feature_off(inp,
5962f8829a4aSRandall Stewart 	    SCTP_PCB_FLAGS_RECVDATAIOEVNT)) ||
5963f8829a4aSRandall Stewart 	    (controlp == NULL)) {
5964f8829a4aSRandall Stewart 		/* user does not want the sndrcv ctl */
5965f8829a4aSRandall Stewart 		filling_sinfo = 0;
5966f8829a4aSRandall Stewart 	}
5967f8829a4aSRandall Stewart 	if (psa) {
5968f8829a4aSRandall Stewart 		from = (struct sockaddr *)sockbuf;
5969f8829a4aSRandall Stewart 		fromlen = sizeof(sockbuf);
5970f8829a4aSRandall Stewart 		from->sa_len = 0;
5971f8829a4aSRandall Stewart 	} else {
5972f8829a4aSRandall Stewart 		from = NULL;
5973f8829a4aSRandall Stewart 		fromlen = 0;
5974f8829a4aSRandall Stewart 	}
5975f8829a4aSRandall Stewart 
5976f8829a4aSRandall Stewart 	error = sctp_sorecvmsg(so, uio, mp0, from, fromlen, flagsp,
5977f8829a4aSRandall Stewart 	    (struct sctp_sndrcvinfo *)&sinfo, filling_sinfo);
5978f8829a4aSRandall Stewart 	if ((controlp) && (filling_sinfo)) {
5979f8829a4aSRandall Stewart 		/* copy back the sinfo in a CMSG format */
5980f8829a4aSRandall Stewart 		if (filling_sinfo)
5981f8829a4aSRandall Stewart 			*controlp = sctp_build_ctl_nchunk(inp,
5982f8829a4aSRandall Stewart 			    (struct sctp_sndrcvinfo *)&sinfo);
5983f8829a4aSRandall Stewart 		else
5984f8829a4aSRandall Stewart 			*controlp = NULL;
5985f8829a4aSRandall Stewart 	}
5986f8829a4aSRandall Stewart 	if (psa) {
5987f8829a4aSRandall Stewart 		/* copy back the address info */
5988f8829a4aSRandall Stewart 		if (from && from->sa_len) {
5989f8829a4aSRandall Stewart 			*psa = sodupsockaddr(from, M_NOWAIT);
5990f8829a4aSRandall Stewart 		} else {
5991f8829a4aSRandall Stewart 			*psa = NULL;
5992f8829a4aSRandall Stewart 		}
5993f8829a4aSRandall Stewart 	}
5994f8829a4aSRandall Stewart 	return (error);
5995f8829a4aSRandall Stewart }
599617205eccSRandall Stewart 
599717205eccSRandall Stewart 
599817205eccSRandall Stewart int
599917205eccSRandall Stewart sctp_l_soreceive(struct socket *so,
600017205eccSRandall Stewart     struct sockaddr **name,
600117205eccSRandall Stewart     struct uio *uio,
600217205eccSRandall Stewart     char **controlp,
600317205eccSRandall Stewart     int *controllen,
600417205eccSRandall Stewart     int *flag)
600517205eccSRandall Stewart {
600617205eccSRandall Stewart 	int error, fromlen;
600717205eccSRandall Stewart 	uint8_t sockbuf[256];
600817205eccSRandall Stewart 	struct sockaddr *from;
600917205eccSRandall Stewart 	struct sctp_extrcvinfo sinfo;
601017205eccSRandall Stewart 	int filling_sinfo = 1;
601117205eccSRandall Stewart 	struct sctp_inpcb *inp;
601217205eccSRandall Stewart 
601317205eccSRandall Stewart 	inp = (struct sctp_inpcb *)so->so_pcb;
601417205eccSRandall Stewart 	/* pickup the assoc we are reading from */
601517205eccSRandall Stewart 	if (inp == NULL) {
6016c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
601717205eccSRandall Stewart 		return (EINVAL);
601817205eccSRandall Stewart 	}
601917205eccSRandall Stewart 	if ((sctp_is_feature_off(inp,
602017205eccSRandall Stewart 	    SCTP_PCB_FLAGS_RECVDATAIOEVNT)) ||
602117205eccSRandall Stewart 	    (controlp == NULL)) {
602217205eccSRandall Stewart 		/* user does not want the sndrcv ctl */
602317205eccSRandall Stewart 		filling_sinfo = 0;
602417205eccSRandall Stewart 	}
602517205eccSRandall Stewart 	if (name) {
602617205eccSRandall Stewart 		from = (struct sockaddr *)sockbuf;
602717205eccSRandall Stewart 		fromlen = sizeof(sockbuf);
602817205eccSRandall Stewart 		from->sa_len = 0;
602917205eccSRandall Stewart 	} else {
603017205eccSRandall Stewart 		from = NULL;
603117205eccSRandall Stewart 		fromlen = 0;
603217205eccSRandall Stewart 	}
603317205eccSRandall Stewart 
603417205eccSRandall Stewart 	error = sctp_sorecvmsg(so, uio,
603517205eccSRandall Stewart 	    (struct mbuf **)NULL,
603617205eccSRandall Stewart 	    from, fromlen, flag,
603717205eccSRandall Stewart 	    (struct sctp_sndrcvinfo *)&sinfo,
603817205eccSRandall Stewart 	    filling_sinfo);
603917205eccSRandall Stewart 	if ((controlp) && (filling_sinfo)) {
604017205eccSRandall Stewart 		/*
604117205eccSRandall Stewart 		 * copy back the sinfo in a CMSG format note that the caller
604217205eccSRandall Stewart 		 * has reponsibility for freeing the memory.
604317205eccSRandall Stewart 		 */
604417205eccSRandall Stewart 		if (filling_sinfo)
604517205eccSRandall Stewart 			*controlp = sctp_build_ctl_cchunk(inp,
604617205eccSRandall Stewart 			    controllen,
604717205eccSRandall Stewart 			    (struct sctp_sndrcvinfo *)&sinfo);
604817205eccSRandall Stewart 	}
604917205eccSRandall Stewart 	if (name) {
605017205eccSRandall Stewart 		/* copy back the address info */
605117205eccSRandall Stewart 		if (from && from->sa_len) {
605217205eccSRandall Stewart 			*name = sodupsockaddr(from, M_WAIT);
605317205eccSRandall Stewart 		} else {
605417205eccSRandall Stewart 			*name = NULL;
605517205eccSRandall Stewart 		}
605617205eccSRandall Stewart 	}
605717205eccSRandall Stewart 	return (error);
605817205eccSRandall Stewart }
605917205eccSRandall Stewart 
606017205eccSRandall Stewart 
606117205eccSRandall Stewart 
606217205eccSRandall Stewart 
606317205eccSRandall Stewart 
606417205eccSRandall Stewart 
606517205eccSRandall Stewart 
606617205eccSRandall Stewart int
6067d61a0ae0SRandall Stewart sctp_connectx_helper_add(struct sctp_tcb *stcb, struct sockaddr *addr,
6068d61a0ae0SRandall Stewart     int totaddr, int *error)
606917205eccSRandall Stewart {
607017205eccSRandall Stewart 	int added = 0;
607117205eccSRandall Stewart 	int i;
607217205eccSRandall Stewart 	struct sctp_inpcb *inp;
607317205eccSRandall Stewart 	struct sockaddr *sa;
607417205eccSRandall Stewart 	size_t incr = 0;
607517205eccSRandall Stewart 
607617205eccSRandall Stewart 	sa = addr;
607717205eccSRandall Stewart 	inp = stcb->sctp_ep;
607817205eccSRandall Stewart 	*error = 0;
607917205eccSRandall Stewart 	for (i = 0; i < totaddr; i++) {
608017205eccSRandall Stewart 		if (sa->sa_family == AF_INET) {
608117205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in);
608217205eccSRandall Stewart 			if (sctp_add_remote_addr(stcb, sa, SCTP_DONOT_SETSCOPE, SCTP_ADDR_IS_CONFIRMED)) {
608317205eccSRandall Stewart 				/* assoc gone no un-lock */
6084c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOBUFS);
6085c4739e2fSRandall Stewart 				(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC, SCTP_FROM_SCTP_USRREQ + SCTP_LOC_7);
608617205eccSRandall Stewart 				*error = ENOBUFS;
608717205eccSRandall Stewart 				goto out_now;
608817205eccSRandall Stewart 			}
608917205eccSRandall Stewart 			added++;
609017205eccSRandall Stewart 		} else if (sa->sa_family == AF_INET6) {
609117205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in6);
609217205eccSRandall Stewart 			if (sctp_add_remote_addr(stcb, sa, SCTP_DONOT_SETSCOPE, SCTP_ADDR_IS_CONFIRMED)) {
609317205eccSRandall Stewart 				/* assoc gone no un-lock */
6094c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOBUFS);
6095c4739e2fSRandall Stewart 				(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC, SCTP_FROM_SCTP_USRREQ + SCTP_LOC_8);
609617205eccSRandall Stewart 				*error = ENOBUFS;
609717205eccSRandall Stewart 				goto out_now;
609817205eccSRandall Stewart 			}
609917205eccSRandall Stewart 			added++;
610017205eccSRandall Stewart 		}
610117205eccSRandall Stewart 		sa = (struct sockaddr *)((caddr_t)sa + incr);
610217205eccSRandall Stewart 	}
610317205eccSRandall Stewart out_now:
610417205eccSRandall Stewart 	return (added);
610517205eccSRandall Stewart }
610617205eccSRandall Stewart 
610717205eccSRandall Stewart struct sctp_tcb *
6108d61a0ae0SRandall Stewart sctp_connectx_helper_find(struct sctp_inpcb *inp, struct sockaddr *addr,
6109d61a0ae0SRandall Stewart     int *totaddr, int *num_v4, int *num_v6, int *error,
6110d61a0ae0SRandall Stewart     int limit, int *bad_addr)
611117205eccSRandall Stewart {
611217205eccSRandall Stewart 	struct sockaddr *sa;
611317205eccSRandall Stewart 	struct sctp_tcb *stcb = NULL;
611417205eccSRandall Stewart 	size_t incr, at, i;
611517205eccSRandall Stewart 
611617205eccSRandall Stewart 	at = incr = 0;
611717205eccSRandall Stewart 	sa = addr;
611817205eccSRandall Stewart 	*error = *num_v6 = *num_v4 = 0;
611917205eccSRandall Stewart 	/* account and validate addresses */
61204c9179adSRandall Stewart 	for (i = 0; i < (size_t)*totaddr; i++) {
612117205eccSRandall Stewart 		if (sa->sa_family == AF_INET) {
612217205eccSRandall Stewart 			(*num_v4) += 1;
612317205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in);
6124d61a0ae0SRandall Stewart 			if (sa->sa_len != incr) {
6125c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6126d61a0ae0SRandall Stewart 				*error = EINVAL;
6127d61a0ae0SRandall Stewart 				*bad_addr = 1;
6128d61a0ae0SRandall Stewart 				return (NULL);
6129d61a0ae0SRandall Stewart 			}
613017205eccSRandall Stewart 		} else if (sa->sa_family == AF_INET6) {
613117205eccSRandall Stewart 			struct sockaddr_in6 *sin6;
613217205eccSRandall Stewart 
613317205eccSRandall Stewart 			sin6 = (struct sockaddr_in6 *)sa;
613417205eccSRandall Stewart 			if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
613517205eccSRandall Stewart 				/* Must be non-mapped for connectx */
6136c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
613717205eccSRandall Stewart 				*error = EINVAL;
6138d61a0ae0SRandall Stewart 				*bad_addr = 1;
613917205eccSRandall Stewart 				return (NULL);
614017205eccSRandall Stewart 			}
614117205eccSRandall Stewart 			(*num_v6) += 1;
614217205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in6);
6143d61a0ae0SRandall Stewart 			if (sa->sa_len != incr) {
6144c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6145d61a0ae0SRandall Stewart 				*error = EINVAL;
6146d61a0ae0SRandall Stewart 				*bad_addr = 1;
6147d61a0ae0SRandall Stewart 				return (NULL);
6148d61a0ae0SRandall Stewart 			}
614917205eccSRandall Stewart 		} else {
615017205eccSRandall Stewart 			*totaddr = i;
615117205eccSRandall Stewart 			/* we are done */
615217205eccSRandall Stewart 			break;
615317205eccSRandall Stewart 		}
6154d61a0ae0SRandall Stewart 		SCTP_INP_INCR_REF(inp);
615517205eccSRandall Stewart 		stcb = sctp_findassociation_ep_addr(&inp, sa, NULL, NULL, NULL);
615617205eccSRandall Stewart 		if (stcb != NULL) {
615717205eccSRandall Stewart 			/* Already have or am bring up an association */
615817205eccSRandall Stewart 			return (stcb);
6159d61a0ae0SRandall Stewart 		} else {
6160d61a0ae0SRandall Stewart 			SCTP_INP_DECR_REF(inp);
616117205eccSRandall Stewart 		}
61624c9179adSRandall Stewart 		if ((at + incr) > (size_t)limit) {
616317205eccSRandall Stewart 			*totaddr = i;
616417205eccSRandall Stewart 			break;
616517205eccSRandall Stewart 		}
616617205eccSRandall Stewart 		sa = (struct sockaddr *)((caddr_t)sa + incr);
616717205eccSRandall Stewart 	}
616817205eccSRandall Stewart 	return ((struct sctp_tcb *)NULL);
616917205eccSRandall Stewart }
617035918f85SRandall Stewart 
617135918f85SRandall Stewart /*
617235918f85SRandall Stewart  * sctp_bindx(ADD) for one address.
617335918f85SRandall Stewart  * assumes all arguments are valid/checked by caller.
617435918f85SRandall Stewart  */
617535918f85SRandall Stewart void
617635918f85SRandall Stewart sctp_bindx_add_address(struct socket *so, struct sctp_inpcb *inp,
617735918f85SRandall Stewart     struct sockaddr *sa, sctp_assoc_t assoc_id,
617835918f85SRandall Stewart     uint32_t vrf_id, int *error, void *p)
617935918f85SRandall Stewart {
618035918f85SRandall Stewart 	struct sockaddr *addr_touse;
61815e2c2d87SRandall Stewart 
61825e2c2d87SRandall Stewart #ifdef INET6
618335918f85SRandall Stewart 	struct sockaddr_in sin;
618435918f85SRandall Stewart 
61855e2c2d87SRandall Stewart #endif
61865e2c2d87SRandall Stewart 
618735918f85SRandall Stewart 	/* see if we're bound all already! */
618835918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
6189c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
619035918f85SRandall Stewart 		*error = EINVAL;
619135918f85SRandall Stewart 		return;
619235918f85SRandall Stewart 	}
619335918f85SRandall Stewart 	addr_touse = sa;
6194fc14de76SRandall Stewart #if defined(INET6) && !defined(__Userspace__)	/* TODO port in6_sin6_2_sin */
619535918f85SRandall Stewart 	if (sa->sa_family == AF_INET6) {
619635918f85SRandall Stewart 		struct sockaddr_in6 *sin6;
619735918f85SRandall Stewart 
619835918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in6)) {
6199c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
620035918f85SRandall Stewart 			*error = EINVAL;
620135918f85SRandall Stewart 			return;
620235918f85SRandall Stewart 		}
6203db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) == 0) {
6204db4fd95bSRandall Stewart 			/* can only bind v6 on PF_INET6 sockets */
6205c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6206db4fd95bSRandall Stewart 			*error = EINVAL;
6207db4fd95bSRandall Stewart 			return;
6208db4fd95bSRandall Stewart 		}
620935918f85SRandall Stewart 		sin6 = (struct sockaddr_in6 *)addr_touse;
621035918f85SRandall Stewart 		if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
6211db4fd95bSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6212db4fd95bSRandall Stewart 			    SCTP_IPV6_V6ONLY(inp)) {
6213db4fd95bSRandall Stewart 				/* can't bind v4-mapped on PF_INET sockets */
6214c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6215db4fd95bSRandall Stewart 				*error = EINVAL;
6216db4fd95bSRandall Stewart 				return;
6217db4fd95bSRandall Stewart 			}
621835918f85SRandall Stewart 			in6_sin6_2_sin(&sin, sin6);
621935918f85SRandall Stewart 			addr_touse = (struct sockaddr *)&sin;
622035918f85SRandall Stewart 		}
622135918f85SRandall Stewart 	}
622235918f85SRandall Stewart #endif
622335918f85SRandall Stewart 	if (sa->sa_family == AF_INET) {
622435918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in)) {
6225c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
622635918f85SRandall Stewart 			*error = EINVAL;
622735918f85SRandall Stewart 			return;
622835918f85SRandall Stewart 		}
6229db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6230db4fd95bSRandall Stewart 		    SCTP_IPV6_V6ONLY(inp)) {
6231db4fd95bSRandall Stewart 			/* can't bind v4 on PF_INET sockets */
6232c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6233db4fd95bSRandall Stewart 			*error = EINVAL;
6234db4fd95bSRandall Stewart 			return;
6235db4fd95bSRandall Stewart 		}
623635918f85SRandall Stewart 	}
623735918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_UNBOUND) {
623835918f85SRandall Stewart 		if (p == NULL) {
623935918f85SRandall Stewart 			/* Can't get proc for Net/Open BSD */
6240c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
624135918f85SRandall Stewart 			*error = EINVAL;
624235918f85SRandall Stewart 			return;
624335918f85SRandall Stewart 		}
62441b649582SRandall Stewart 		*error = sctp_inpcb_bind(so, addr_touse, NULL, p);
624535918f85SRandall Stewart 		return;
624635918f85SRandall Stewart 	}
624735918f85SRandall Stewart 	/*
624835918f85SRandall Stewart 	 * No locks required here since bind and mgmt_ep_sa all do their own
624935918f85SRandall Stewart 	 * locking. If we do something for the FIX: below we may need to
625035918f85SRandall Stewart 	 * lock in that case.
625135918f85SRandall Stewart 	 */
625235918f85SRandall Stewart 	if (assoc_id == 0) {
625335918f85SRandall Stewart 		/* add the address */
625435918f85SRandall Stewart 		struct sctp_inpcb *lep;
625597c76f10SRandall Stewart 		struct sockaddr_in *lsin = (struct sockaddr_in *)addr_touse;
625635918f85SRandall Stewart 
625797c76f10SRandall Stewart 		/* validate the incoming port */
625897c76f10SRandall Stewart 		if ((lsin->sin_port != 0) &&
625997c76f10SRandall Stewart 		    (lsin->sin_port != inp->sctp_lport)) {
6260c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
626197c76f10SRandall Stewart 			*error = EINVAL;
626297c76f10SRandall Stewart 			return;
626397c76f10SRandall Stewart 		} else {
626497c76f10SRandall Stewart 			/* user specified 0 port, set it to existing port */
626597c76f10SRandall Stewart 			lsin->sin_port = inp->sctp_lport;
626697c76f10SRandall Stewart 		}
626797c76f10SRandall Stewart 
626835918f85SRandall Stewart 		lep = sctp_pcb_findep(addr_touse, 1, 0, vrf_id);
626935918f85SRandall Stewart 		if (lep != NULL) {
627035918f85SRandall Stewart 			/*
627135918f85SRandall Stewart 			 * We must decrement the refcount since we have the
627235918f85SRandall Stewart 			 * ep already and are binding. No remove going on
627335918f85SRandall Stewart 			 * here.
627435918f85SRandall Stewart 			 */
62756d9e8f2bSRandall Stewart 			SCTP_INP_DECR_REF(lep);
627635918f85SRandall Stewart 		}
627735918f85SRandall Stewart 		if (lep == inp) {
627835918f85SRandall Stewart 			/* already bound to it.. ok */
627935918f85SRandall Stewart 			return;
628035918f85SRandall Stewart 		} else if (lep == NULL) {
628135918f85SRandall Stewart 			((struct sockaddr_in *)addr_touse)->sin_port = 0;
628235918f85SRandall Stewart 			*error = sctp_addr_mgmt_ep_sa(inp, addr_touse,
628335918f85SRandall Stewart 			    SCTP_ADD_IP_ADDRESS,
628480fefe0aSRandall Stewart 			    vrf_id, NULL);
628535918f85SRandall Stewart 		} else {
628635918f85SRandall Stewart 			*error = EADDRINUSE;
628735918f85SRandall Stewart 		}
628835918f85SRandall Stewart 		if (*error)
628935918f85SRandall Stewart 			return;
629035918f85SRandall Stewart 	} else {
629135918f85SRandall Stewart 		/*
629235918f85SRandall Stewart 		 * FIX: decide whether we allow assoc based bindx
629335918f85SRandall Stewart 		 */
629435918f85SRandall Stewart 	}
629535918f85SRandall Stewart }
629635918f85SRandall Stewart 
629735918f85SRandall Stewart /*
629835918f85SRandall Stewart  * sctp_bindx(DELETE) for one address.
629935918f85SRandall Stewart  * assumes all arguments are valid/checked by caller.
630035918f85SRandall Stewart  */
630135918f85SRandall Stewart void
630235918f85SRandall Stewart sctp_bindx_delete_address(struct socket *so, struct sctp_inpcb *inp,
630335918f85SRandall Stewart     struct sockaddr *sa, sctp_assoc_t assoc_id,
630435918f85SRandall Stewart     uint32_t vrf_id, int *error)
630535918f85SRandall Stewart {
630635918f85SRandall Stewart 	struct sockaddr *addr_touse;
63075e2c2d87SRandall Stewart 
63085e2c2d87SRandall Stewart #ifdef INET6
630935918f85SRandall Stewart 	struct sockaddr_in sin;
631035918f85SRandall Stewart 
63115e2c2d87SRandall Stewart #endif
63125e2c2d87SRandall Stewart 
631335918f85SRandall Stewart 	/* see if we're bound all already! */
631435918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
6315c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
631635918f85SRandall Stewart 		*error = EINVAL;
631735918f85SRandall Stewart 		return;
631835918f85SRandall Stewart 	}
631935918f85SRandall Stewart 	addr_touse = sa;
6320fc14de76SRandall Stewart #if defined(INET6) && !defined(__Userspace__)	/* TODO port in6_sin6_2_sin */
632135918f85SRandall Stewart 	if (sa->sa_family == AF_INET6) {
632235918f85SRandall Stewart 		struct sockaddr_in6 *sin6;
632335918f85SRandall Stewart 
632435918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in6)) {
6325c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
632635918f85SRandall Stewart 			*error = EINVAL;
632735918f85SRandall Stewart 			return;
632835918f85SRandall Stewart 		}
6329db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) == 0) {
6330db4fd95bSRandall Stewart 			/* can only bind v6 on PF_INET6 sockets */
6331c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6332db4fd95bSRandall Stewart 			*error = EINVAL;
6333db4fd95bSRandall Stewart 			return;
6334db4fd95bSRandall Stewart 		}
633535918f85SRandall Stewart 		sin6 = (struct sockaddr_in6 *)addr_touse;
633635918f85SRandall Stewart 		if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
6337db4fd95bSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6338db4fd95bSRandall Stewart 			    SCTP_IPV6_V6ONLY(inp)) {
6339db4fd95bSRandall Stewart 				/* can't bind mapped-v4 on PF_INET sockets */
6340c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6341db4fd95bSRandall Stewart 				*error = EINVAL;
6342db4fd95bSRandall Stewart 				return;
6343db4fd95bSRandall Stewart 			}
634435918f85SRandall Stewart 			in6_sin6_2_sin(&sin, sin6);
634535918f85SRandall Stewart 			addr_touse = (struct sockaddr *)&sin;
634635918f85SRandall Stewart 		}
634735918f85SRandall Stewart 	}
634835918f85SRandall Stewart #endif
634935918f85SRandall Stewart 	if (sa->sa_family == AF_INET) {
635035918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in)) {
6351c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
635235918f85SRandall Stewart 			*error = EINVAL;
635335918f85SRandall Stewart 			return;
635435918f85SRandall Stewart 		}
6355db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6356db4fd95bSRandall Stewart 		    SCTP_IPV6_V6ONLY(inp)) {
6357db4fd95bSRandall Stewart 			/* can't bind v4 on PF_INET sockets */
6358c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6359db4fd95bSRandall Stewart 			*error = EINVAL;
6360db4fd95bSRandall Stewart 			return;
6361db4fd95bSRandall Stewart 		}
636235918f85SRandall Stewart 	}
636335918f85SRandall Stewart 	/*
636435918f85SRandall Stewart 	 * No lock required mgmt_ep_sa does its own locking. If the FIX:
636535918f85SRandall Stewart 	 * below is ever changed we may need to lock before calling
636635918f85SRandall Stewart 	 * association level binding.
636735918f85SRandall Stewart 	 */
636835918f85SRandall Stewart 	if (assoc_id == 0) {
636935918f85SRandall Stewart 		/* delete the address */
637035918f85SRandall Stewart 		*error = sctp_addr_mgmt_ep_sa(inp, addr_touse,
637135918f85SRandall Stewart 		    SCTP_DEL_IP_ADDRESS,
637280fefe0aSRandall Stewart 		    vrf_id, NULL);
637335918f85SRandall Stewart 	} else {
637435918f85SRandall Stewart 		/*
637535918f85SRandall Stewart 		 * FIX: decide whether we allow assoc based bindx
637635918f85SRandall Stewart 		 */
637735918f85SRandall Stewart 	}
637835918f85SRandall Stewart }
63791b649582SRandall Stewart 
63801b649582SRandall Stewart /*
63811b649582SRandall Stewart  * returns the valid local address count for an assoc, taking into account
63821b649582SRandall Stewart  * all scoping rules
63831b649582SRandall Stewart  */
63841b649582SRandall Stewart int
63851b649582SRandall Stewart sctp_local_addr_count(struct sctp_tcb *stcb)
63861b649582SRandall Stewart {
63871b649582SRandall Stewart 	int loopback_scope, ipv4_local_scope, local_scope, site_scope;
63881b649582SRandall Stewart 	int ipv4_addr_legal, ipv6_addr_legal;
63891b649582SRandall Stewart 	struct sctp_vrf *vrf;
63901b649582SRandall Stewart 	struct sctp_ifn *sctp_ifn;
63911b649582SRandall Stewart 	struct sctp_ifa *sctp_ifa;
63921b649582SRandall Stewart 	int count = 0;
63931b649582SRandall Stewart 
63941b649582SRandall Stewart 	/* Turn on all the appropriate scopes */
63951b649582SRandall Stewart 	loopback_scope = stcb->asoc.loopback_scope;
63961b649582SRandall Stewart 	ipv4_local_scope = stcb->asoc.ipv4_local_scope;
63971b649582SRandall Stewart 	local_scope = stcb->asoc.local_scope;
63981b649582SRandall Stewart 	site_scope = stcb->asoc.site_scope;
63991b649582SRandall Stewart 	ipv4_addr_legal = ipv6_addr_legal = 0;
64001b649582SRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) {
64011b649582SRandall Stewart 		ipv6_addr_legal = 1;
64021b649582SRandall Stewart 		if (SCTP_IPV6_V6ONLY(stcb->sctp_ep) == 0) {
64031b649582SRandall Stewart 			ipv4_addr_legal = 1;
64041b649582SRandall Stewart 		}
64051b649582SRandall Stewart 	} else {
64061b649582SRandall Stewart 		ipv4_addr_legal = 1;
64071b649582SRandall Stewart 	}
64081b649582SRandall Stewart 
6409c99efcf6SRandall Stewart 	SCTP_IPI_ADDR_RLOCK();
64101b649582SRandall Stewart 	vrf = sctp_find_vrf(stcb->asoc.vrf_id);
64111b649582SRandall Stewart 	if (vrf == NULL) {
64121b649582SRandall Stewart 		/* no vrf, no addresses */
6413c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RUNLOCK();
64141b649582SRandall Stewart 		return (0);
64151b649582SRandall Stewart 	}
64161b649582SRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
64171b649582SRandall Stewart 		/*
64181b649582SRandall Stewart 		 * bound all case: go through all ifns on the vrf
64191b649582SRandall Stewart 		 */
64201b649582SRandall Stewart 		LIST_FOREACH(sctp_ifn, &vrf->ifnlist, next_ifn) {
64211b649582SRandall Stewart 			if ((loopback_scope == 0) &&
64221b649582SRandall Stewart 			    SCTP_IFN_IS_IFT_LOOP(sctp_ifn)) {
64231b649582SRandall Stewart 				continue;
64241b649582SRandall Stewart 			}
64251b649582SRandall Stewart 			LIST_FOREACH(sctp_ifa, &sctp_ifn->ifalist, next_ifa) {
64261b649582SRandall Stewart 				if (sctp_is_addr_restricted(stcb, sctp_ifa))
64271b649582SRandall Stewart 					continue;
64285e2c2d87SRandall Stewart 				switch (sctp_ifa->address.sa.sa_family) {
64295e2c2d87SRandall Stewart 				case AF_INET:
64305e2c2d87SRandall Stewart 					if (ipv4_addr_legal) {
64311b649582SRandall Stewart 						struct sockaddr_in *sin;
64321b649582SRandall Stewart 
64331b649582SRandall Stewart 						sin = (struct sockaddr_in *)&sctp_ifa->address.sa;
64341b649582SRandall Stewart 						if (sin->sin_addr.s_addr == 0) {
64355e2c2d87SRandall Stewart 							/*
64365e2c2d87SRandall Stewart 							 * skip unspecified
64375e2c2d87SRandall Stewart 							 * addrs
64385e2c2d87SRandall Stewart 							 */
64391b649582SRandall Stewart 							continue;
64401b649582SRandall Stewart 						}
64411b649582SRandall Stewart 						if ((ipv4_local_scope == 0) &&
64421b649582SRandall Stewart 						    (IN4_ISPRIVATE_ADDRESS(&sin->sin_addr))) {
64431b649582SRandall Stewart 							continue;
64441b649582SRandall Stewart 						}
64451b649582SRandall Stewart 						/* count this one */
64461b649582SRandall Stewart 						count++;
64475e2c2d87SRandall Stewart 					} else {
64485e2c2d87SRandall Stewart 						continue;
64495e2c2d87SRandall Stewart 					}
64505e2c2d87SRandall Stewart 					break;
64515e2c2d87SRandall Stewart #ifdef INET6
64525e2c2d87SRandall Stewart 				case AF_INET6:
64535e2c2d87SRandall Stewart 					if (ipv6_addr_legal) {
64541b649582SRandall Stewart 						struct sockaddr_in6 *sin6;
64551b649582SRandall Stewart 
64561b649582SRandall Stewart 						sin6 = (struct sockaddr_in6 *)&sctp_ifa->address.sa;
64571b649582SRandall Stewart 						if (IN6_IS_ADDR_UNSPECIFIED(&sin6->sin6_addr)) {
64581b649582SRandall Stewart 							continue;
64591b649582SRandall Stewart 						}
64601b649582SRandall Stewart 						if (IN6_IS_ADDR_LINKLOCAL(&sin6->sin6_addr)) {
64611b649582SRandall Stewart 							if (local_scope == 0)
64621b649582SRandall Stewart 								continue;
64631b649582SRandall Stewart 							if (sin6->sin6_scope_id == 0) {
64641b649582SRandall Stewart 								if (sa6_recoverscope(sin6) != 0)
64651b649582SRandall Stewart 									/*
64665e2c2d87SRandall Stewart 									 *
64675e2c2d87SRandall Stewart 									 * bad
64685e2c2d87SRandall Stewart 									 *
64695e2c2d87SRandall Stewart 									 * li
64705e2c2d87SRandall Stewart 									 * nk
64715e2c2d87SRandall Stewart 									 *
64725e2c2d87SRandall Stewart 									 * loc
64735e2c2d87SRandall Stewart 									 * al
64745e2c2d87SRandall Stewart 									 *
64755e2c2d87SRandall Stewart 									 * add
64765e2c2d87SRandall Stewart 									 * re
64775e2c2d87SRandall Stewart 									 * ss
64785e2c2d87SRandall Stewart 									 * */
64791b649582SRandall Stewart 									continue;
64801b649582SRandall Stewart 							}
64811b649582SRandall Stewart 						}
64821b649582SRandall Stewart 						if ((site_scope == 0) &&
64831b649582SRandall Stewart 						    (IN6_IS_ADDR_SITELOCAL(&sin6->sin6_addr))) {
64841b649582SRandall Stewart 							continue;
64851b649582SRandall Stewart 						}
64861b649582SRandall Stewart 						/* count this one */
64871b649582SRandall Stewart 						count++;
64881b649582SRandall Stewart 					}
64895e2c2d87SRandall Stewart 					break;
64905e2c2d87SRandall Stewart #endif
64915e2c2d87SRandall Stewart 				default:
64925e2c2d87SRandall Stewart 					/* TSNH */
64935e2c2d87SRandall Stewart 					break;
64945e2c2d87SRandall Stewart 				}
64951b649582SRandall Stewart 			}
64961b649582SRandall Stewart 		}
64971b649582SRandall Stewart 	} else {
64981b649582SRandall Stewart 		/*
64991b649582SRandall Stewart 		 * subset bound case
65001b649582SRandall Stewart 		 */
65011b649582SRandall Stewart 		struct sctp_laddr *laddr;
65021b649582SRandall Stewart 
65031b649582SRandall Stewart 		LIST_FOREACH(laddr, &stcb->sctp_ep->sctp_addr_list,
65041b649582SRandall Stewart 		    sctp_nxt_addr) {
65051b649582SRandall Stewart 			if (sctp_is_addr_restricted(stcb, laddr->ifa)) {
65061b649582SRandall Stewart 				continue;
65071b649582SRandall Stewart 			}
65081b649582SRandall Stewart 			/* count this one */
65091b649582SRandall Stewart 			count++;
65101b649582SRandall Stewart 		}
65111b649582SRandall Stewart 	}
6512c99efcf6SRandall Stewart 	SCTP_IPI_ADDR_RUNLOCK();
65131b649582SRandall Stewart 	return (count);
65141b649582SRandall Stewart }
6515c4739e2fSRandall Stewart 
6516c4739e2fSRandall Stewart #if defined(SCTP_LOCAL_TRACE_BUF)
6517c4739e2fSRandall Stewart 
6518c4739e2fSRandall Stewart void
6519b27a6b7dSRandall Stewart sctp_log_trace(uint32_t subsys, const char *str SCTP_UNUSED, uint32_t a, uint32_t b, uint32_t c, uint32_t d, uint32_t e, uint32_t f)
6520c4739e2fSRandall Stewart {
6521b27a6b7dSRandall Stewart 	uint32_t saveindex, newindex;
6522c4739e2fSRandall Stewart 
6523c4739e2fSRandall Stewart 	do {
6524b3f1ea41SRandall Stewart 		saveindex = SCTP_BASE_SYSCTL(sctp_log).index;
6525c4739e2fSRandall Stewart 		if (saveindex >= SCTP_MAX_LOGGING_SIZE) {
6526c4739e2fSRandall Stewart 			newindex = 1;
6527c4739e2fSRandall Stewart 		} else {
6528c4739e2fSRandall Stewart 			newindex = saveindex + 1;
6529c4739e2fSRandall Stewart 		}
6530b3f1ea41SRandall Stewart 	} while (atomic_cmpset_int(&SCTP_BASE_SYSCTL(sctp_log).index, saveindex, newindex) == 0);
6531c4739e2fSRandall Stewart 	if (saveindex >= SCTP_MAX_LOGGING_SIZE) {
6532c4739e2fSRandall Stewart 		saveindex = 0;
6533c4739e2fSRandall Stewart 	}
6534b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].timestamp = SCTP_GET_CYCLECOUNT;
6535b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].subsys = subsys;
6536b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[0] = a;
6537b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[1] = b;
6538b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[2] = c;
6539b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[3] = d;
6540b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[4] = e;
6541b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[5] = f;
6542c4739e2fSRandall Stewart }
6543c4739e2fSRandall Stewart 
6544c4739e2fSRandall Stewart #endif
6545c54a18d2SRandall Stewart /* We will need to add support
6546c54a18d2SRandall Stewart  * to bind the ports and such here
6547c54a18d2SRandall Stewart  * so we can do UDP tunneling. In
6548c54a18d2SRandall Stewart  * the mean-time, we return error
6549c54a18d2SRandall Stewart  */
6550a99b6783SRandall Stewart #include <netinet/udp.h>
6551a99b6783SRandall Stewart #include <netinet/udp_var.h>
6552a99b6783SRandall Stewart #include <sys/proc.h>
6553a99b6783SRandall Stewart #include <netinet6/sctp6_var.h>
6554a99b6783SRandall Stewart 
6555a99b6783SRandall Stewart static void
6556a99b6783SRandall Stewart sctp_recv_udp_tunneled_packet(struct mbuf *m, int off, struct inpcb *ignored)
6557a99b6783SRandall Stewart {
6558a99b6783SRandall Stewart 	struct ip *iph;
6559a99b6783SRandall Stewart 	struct mbuf *sp, *last;
6560a99b6783SRandall Stewart 	struct udphdr *uhdr;
6561a99b6783SRandall Stewart 	uint16_t port = 0, len;
6562a99b6783SRandall Stewart 	int header_size = sizeof(struct udphdr) + sizeof(struct sctphdr);
6563a99b6783SRandall Stewart 
6564a99b6783SRandall Stewart 	/*
6565a99b6783SRandall Stewart 	 * Split out the mbuf chain. Leave the IP header in m, place the
6566a99b6783SRandall Stewart 	 * rest in the sp.
6567a99b6783SRandall Stewart 	 */
6568a99b6783SRandall Stewart 	if ((m->m_flags & M_PKTHDR) == 0) {
6569a99b6783SRandall Stewart 		/* Can't handle one that is not a pkt hdr */
6570a99b6783SRandall Stewart 		goto out;
6571a99b6783SRandall Stewart 	}
6572a99b6783SRandall Stewart 	/* pull the src port */
6573a99b6783SRandall Stewart 	iph = mtod(m, struct ip *);
6574a99b6783SRandall Stewart 	uhdr = (struct udphdr *)((caddr_t)iph + off);
6575a99b6783SRandall Stewart 
6576a99b6783SRandall Stewart 	port = uhdr->uh_sport;
6577a99b6783SRandall Stewart 	sp = m_split(m, off, M_DONTWAIT);
6578a99b6783SRandall Stewart 	if (sp == NULL) {
6579a99b6783SRandall Stewart 		/* Gak, drop packet, we can't do a split */
6580a99b6783SRandall Stewart 		goto out;
6581a99b6783SRandall Stewart 	}
6582a99b6783SRandall Stewart 	if (sp->m_pkthdr.len < header_size) {
6583a99b6783SRandall Stewart 		/* Gak, packet can't have an SCTP header in it - to small */
6584a99b6783SRandall Stewart 		m_freem(sp);
6585a99b6783SRandall Stewart 		goto out;
6586a99b6783SRandall Stewart 	}
6587a99b6783SRandall Stewart 	/* ok now pull up the UDP header and SCTP header together */
6588a99b6783SRandall Stewart 	sp = m_pullup(sp, header_size);
6589a99b6783SRandall Stewart 	if (sp == NULL) {
6590a99b6783SRandall Stewart 		/* Gak pullup failed */
6591a99b6783SRandall Stewart 		goto out;
6592a99b6783SRandall Stewart 	}
6593a99b6783SRandall Stewart 	/* trim out the UDP header */
6594a99b6783SRandall Stewart 	m_adj(sp, sizeof(struct udphdr));
6595a99b6783SRandall Stewart 
6596a99b6783SRandall Stewart 	/* Now reconstruct the mbuf chain */
6597a99b6783SRandall Stewart 	/* 1) find last one */
6598a99b6783SRandall Stewart 	last = m;
6599a99b6783SRandall Stewart 	while (last->m_next != NULL) {
6600a99b6783SRandall Stewart 		last = last->m_next;
6601a99b6783SRandall Stewart 	}
6602a99b6783SRandall Stewart 	last->m_next = sp;
6603a99b6783SRandall Stewart 	m->m_pkthdr.len += sp->m_pkthdr.len;
6604a99b6783SRandall Stewart 	last = m;
6605a99b6783SRandall Stewart 	while (last != NULL) {
6606a99b6783SRandall Stewart 		last = last->m_next;
6607a99b6783SRandall Stewart 	}
6608a99b6783SRandall Stewart 	/* Now its ready for sctp_input or sctp6_input */
6609a99b6783SRandall Stewart 	iph = mtod(m, struct ip *);
6610a99b6783SRandall Stewart 	switch (iph->ip_v) {
6611a99b6783SRandall Stewart 	case IPVERSION:
6612a99b6783SRandall Stewart 		{
6613a99b6783SRandall Stewart 			/* its IPv4 */
6614a99b6783SRandall Stewart 			len = SCTP_GET_IPV4_LENGTH(iph);
6615a99b6783SRandall Stewart 			len -= sizeof(struct udphdr);
6616a99b6783SRandall Stewart 			SCTP_GET_IPV4_LENGTH(iph) = len;
6617a99b6783SRandall Stewart 			sctp_input_with_port(m, off, port);
6618a99b6783SRandall Stewart 			break;
6619a99b6783SRandall Stewart 		}
6620a99b6783SRandall Stewart #ifdef INET6
6621a99b6783SRandall Stewart 	case IPV6_VERSION >> 4:
6622a99b6783SRandall Stewart 		{
6623a99b6783SRandall Stewart 			/* its IPv6 - NOT supported */
6624a99b6783SRandall Stewart 			goto out;
6625a99b6783SRandall Stewart 			break;
6626a99b6783SRandall Stewart 
6627a99b6783SRandall Stewart 		}
6628a99b6783SRandall Stewart #endif
6629a99b6783SRandall Stewart 	default:
6630a99b6783SRandall Stewart 		{
6631a99b6783SRandall Stewart 			m_freem(m);
6632a99b6783SRandall Stewart 			break;
6633a99b6783SRandall Stewart 		}
6634a99b6783SRandall Stewart 	}
6635a99b6783SRandall Stewart 	return;
6636a99b6783SRandall Stewart out:
6637a99b6783SRandall Stewart 	m_freem(m);
6638a99b6783SRandall Stewart }
6639c54a18d2SRandall Stewart 
6640c54a18d2SRandall Stewart void
6641c54a18d2SRandall Stewart sctp_over_udp_stop(void)
6642c54a18d2SRandall Stewart {
6643a99b6783SRandall Stewart 	struct socket *sop;
6644a99b6783SRandall Stewart 
6645a99b6783SRandall Stewart 	/*
6646a99b6783SRandall Stewart 	 * This function assumes sysctl caller holds sctp_sysctl_info_lock()
6647a99b6783SRandall Stewart 	 * for writting!
6648a99b6783SRandall Stewart 	 */
6649a99b6783SRandall Stewart 	if (SCTP_BASE_INFO(udp_tun_socket) == NULL) {
6650a99b6783SRandall Stewart 		/* Nothing to do */
6651c54a18d2SRandall Stewart 		return;
6652c54a18d2SRandall Stewart 	}
6653a99b6783SRandall Stewart 	sop = SCTP_BASE_INFO(udp_tun_socket);
6654a99b6783SRandall Stewart 	soclose(sop);
6655a99b6783SRandall Stewart 	SCTP_BASE_INFO(udp_tun_socket) = NULL;
6656a99b6783SRandall Stewart }
6657c54a18d2SRandall Stewart int
6658c54a18d2SRandall Stewart sctp_over_udp_start(void)
6659c54a18d2SRandall Stewart {
6660a99b6783SRandall Stewart 	uint16_t port;
6661a99b6783SRandall Stewart 	int ret;
6662a99b6783SRandall Stewart 	struct sockaddr_in sin;
6663a99b6783SRandall Stewart 	struct socket *sop = NULL;
6664a99b6783SRandall Stewart 	struct thread *th;
6665a99b6783SRandall Stewart 	struct ucred *cred;
6666a99b6783SRandall Stewart 
6667a99b6783SRandall Stewart 	/*
6668a99b6783SRandall Stewart 	 * This function assumes sysctl caller holds sctp_sysctl_info_lock()
6669a99b6783SRandall Stewart 	 * for writting!
6670a99b6783SRandall Stewart 	 */
6671a99b6783SRandall Stewart 	port = SCTP_BASE_SYSCTL(sctp_udp_tunneling_port);
6672a99b6783SRandall Stewart 	if (port == 0) {
6673a99b6783SRandall Stewart 		/* Must have a port set */
6674a99b6783SRandall Stewart 		return (EINVAL);
6675a99b6783SRandall Stewart 	}
6676a99b6783SRandall Stewart 	if (SCTP_BASE_INFO(udp_tun_socket) != NULL) {
6677a99b6783SRandall Stewart 		/* Already running -- must stop first */
6678a99b6783SRandall Stewart 		return (EALREADY);
6679a99b6783SRandall Stewart 	}
6680a99b6783SRandall Stewart 	th = curthread;
6681a99b6783SRandall Stewart 	cred = th->td_ucred;
6682a99b6783SRandall Stewart 	if ((ret = socreate(PF_INET, &sop,
6683a99b6783SRandall Stewart 	    SOCK_DGRAM, IPPROTO_UDP, cred, th))) {
6684a99b6783SRandall Stewart 		return (ret);
6685a99b6783SRandall Stewart 	}
6686a99b6783SRandall Stewart 	SCTP_BASE_INFO(udp_tun_socket) = sop;
6687a99b6783SRandall Stewart 	/* call the special UDP hook */
6688a99b6783SRandall Stewart 	ret = udp_set_kernel_tunneling(sop, sctp_recv_udp_tunneled_packet);
6689a99b6783SRandall Stewart 	if (ret) {
6690a99b6783SRandall Stewart 		goto exit_stage_left;
6691a99b6783SRandall Stewart 	}
6692a99b6783SRandall Stewart 	/* Ok we have a socket, bind it to the port */
6693a99b6783SRandall Stewart 	memset(&sin, 0, sizeof(sin));
6694a99b6783SRandall Stewart 	sin.sin_len = sizeof(sin);
6695a99b6783SRandall Stewart 	sin.sin_family = AF_INET;
6696a99b6783SRandall Stewart 	sin.sin_port = htons(port);
6697a99b6783SRandall Stewart 	ret = sobind(sop, (struct sockaddr *)&sin, th);
6698a99b6783SRandall Stewart 	if (ret) {
6699a99b6783SRandall Stewart 		/* Close up we cant get the port */
6700a99b6783SRandall Stewart exit_stage_left:
6701a99b6783SRandall Stewart 		sctp_over_udp_stop();
6702a99b6783SRandall Stewart 		return (ret);
6703a99b6783SRandall Stewart 	}
6704a99b6783SRandall Stewart 	/*
6705a99b6783SRandall Stewart 	 * Ok we should now get UDP packets directly to our input routine
6706a99b6783SRandall Stewart 	 * sctp_recv_upd_tunneled_packet().
6707a99b6783SRandall Stewart 	 */
6708a99b6783SRandall Stewart 	return (0);
6709c54a18d2SRandall Stewart }
6710