xref: /freebsd/sys/netinet/sctputil.c (revision b1deed45e68155f3524f2f695136cd99f1eaa9c0)
1f8829a4aSRandall Stewart /*-
2830d754dSRandall Stewart  * Copyright (c) 2001-2008, by Cisco Systems, Inc. All rights reserved.
3807aad63SMichael Tuexen  * Copyright (c) 2008-2012, by Randall Stewart. All rights reserved.
4807aad63SMichael Tuexen  * Copyright (c) 2008-2012, by Michael Tuexen. All rights reserved.
5f8829a4aSRandall Stewart  *
6f8829a4aSRandall Stewart  * Redistribution and use in source and binary forms, with or without
7f8829a4aSRandall Stewart  * modification, are permitted provided that the following conditions are met:
8f8829a4aSRandall Stewart  *
9f8829a4aSRandall Stewart  * a) Redistributions of source code must retain the above copyright notice,
10f8829a4aSRandall Stewart  *    this list of conditions and the following disclaimer.
11f8829a4aSRandall Stewart  *
12f8829a4aSRandall Stewart  * b) Redistributions in binary form must reproduce the above copyright
13f8829a4aSRandall Stewart  *    notice, this list of conditions and the following disclaimer in
14f8829a4aSRandall Stewart  *    the documentation and/or other materials provided with the distribution.
15f8829a4aSRandall Stewart  *
16f8829a4aSRandall Stewart  * c) Neither the name of Cisco Systems, Inc. nor the names of its
17f8829a4aSRandall Stewart  *    contributors may be used to endorse or promote products derived
18f8829a4aSRandall Stewart  *    from this software without specific prior written permission.
19f8829a4aSRandall Stewart  *
20f8829a4aSRandall Stewart  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
21f8829a4aSRandall Stewart  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
22f8829a4aSRandall Stewart  * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
23f8829a4aSRandall Stewart  * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
24f8829a4aSRandall Stewart  * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
25f8829a4aSRandall Stewart  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
26f8829a4aSRandall Stewart  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
27f8829a4aSRandall Stewart  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
28f8829a4aSRandall Stewart  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
29f8829a4aSRandall Stewart  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
30f8829a4aSRandall Stewart  * THE POSSIBILITY OF SUCH DAMAGE.
31f8829a4aSRandall Stewart  */
32f8829a4aSRandall Stewart 
33f8829a4aSRandall Stewart #include <sys/cdefs.h>
34f8829a4aSRandall Stewart __FBSDID("$FreeBSD$");
35f8829a4aSRandall Stewart 
36f8829a4aSRandall Stewart #include <netinet/sctp_os.h>
37f8829a4aSRandall Stewart #include <netinet/sctp_pcb.h>
38f8829a4aSRandall Stewart #include <netinet/sctputil.h>
39f8829a4aSRandall Stewart #include <netinet/sctp_var.h>
4042551e99SRandall Stewart #include <netinet/sctp_sysctl.h>
41f8829a4aSRandall Stewart #ifdef INET6
423a51a264SMichael Tuexen #include <netinet6/sctp6_var.h>
43f8829a4aSRandall Stewart #endif
44f8829a4aSRandall Stewart #include <netinet/sctp_header.h>
45f8829a4aSRandall Stewart #include <netinet/sctp_output.h>
46f8829a4aSRandall Stewart #include <netinet/sctp_uio.h>
47f8829a4aSRandall Stewart #include <netinet/sctp_timer.h>
48f8829a4aSRandall Stewart #include <netinet/sctp_indata.h>/* for sctp_deliver_data() */
49f8829a4aSRandall Stewart #include <netinet/sctp_auth.h>
50f8829a4aSRandall Stewart #include <netinet/sctp_asconf.h>
51f7517433SRandall Stewart #include <netinet/sctp_bsd_addr.h>
523a51a264SMichael Tuexen #include <netinet/udp.h>
533a51a264SMichael Tuexen #include <netinet/udp_var.h>
543a51a264SMichael Tuexen #include <sys/proc.h>
55f8829a4aSRandall Stewart 
56f8829a4aSRandall Stewart 
57b9e7085aSRandall Stewart #ifndef KTR_SCTP
58b9e7085aSRandall Stewart #define KTR_SCTP KTR_SUBSYS
5980fefe0aSRandall Stewart #endif
60f8829a4aSRandall Stewart 
61ed654363SMichael Tuexen extern const struct sctp_cc_functions sctp_cc_functions[];
62ed654363SMichael Tuexen extern const struct sctp_ss_functions sctp_ss_functions[];
630e9a9c10SMichael Tuexen 
64f8829a4aSRandall Stewart void
65dcb68fbaSMichael Tuexen sctp_sblog(struct sockbuf *sb, struct sctp_tcb *stcb, int from, int incr)
66f8829a4aSRandall Stewart {
6780fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
68f8829a4aSRandall Stewart 
6980fefe0aSRandall Stewart 	sctp_clog.x.sb.stcb = stcb;
704e88d37aSMichael Tuexen 	sctp_clog.x.sb.so_sbcc = sb->sb_cc;
71f8829a4aSRandall Stewart 	if (stcb)
724e88d37aSMichael Tuexen 		sctp_clog.x.sb.stcb_sbcc = stcb->asoc.sb_cc;
73f8829a4aSRandall Stewart 	else
7480fefe0aSRandall Stewart 		sctp_clog.x.sb.stcb_sbcc = 0;
7580fefe0aSRandall Stewart 	sctp_clog.x.sb.incr = incr;
76c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
7780fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_SB,
7880fefe0aSRandall Stewart 	    from,
7980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
8080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
8180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
8280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
83f8829a4aSRandall Stewart }
84f8829a4aSRandall Stewart 
85f8829a4aSRandall Stewart void
86f8829a4aSRandall Stewart sctp_log_closing(struct sctp_inpcb *inp, struct sctp_tcb *stcb, int16_t loc)
87f8829a4aSRandall Stewart {
8880fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
89f8829a4aSRandall Stewart 
9080fefe0aSRandall Stewart 	sctp_clog.x.close.inp = (void *)inp;
9180fefe0aSRandall Stewart 	sctp_clog.x.close.sctp_flags = inp->sctp_flags;
92f8829a4aSRandall Stewart 	if (stcb) {
9380fefe0aSRandall Stewart 		sctp_clog.x.close.stcb = (void *)stcb;
9480fefe0aSRandall Stewart 		sctp_clog.x.close.state = (uint16_t) stcb->asoc.state;
95f8829a4aSRandall Stewart 	} else {
9680fefe0aSRandall Stewart 		sctp_clog.x.close.stcb = 0;
9780fefe0aSRandall Stewart 		sctp_clog.x.close.state = 0;
98f8829a4aSRandall Stewart 	}
9980fefe0aSRandall Stewart 	sctp_clog.x.close.loc = loc;
100c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
10180fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_CLOSE,
10280fefe0aSRandall Stewart 	    0,
10380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
10480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
10580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
10680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
107f8829a4aSRandall Stewart }
108f8829a4aSRandall Stewart 
109f8829a4aSRandall Stewart void
110f8829a4aSRandall Stewart rto_logging(struct sctp_nets *net, int from)
111f8829a4aSRandall Stewart {
11280fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
113f8829a4aSRandall Stewart 
114bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
11580fefe0aSRandall Stewart 	sctp_clog.x.rto.net = (void *)net;
116be1d9176SMichael Tuexen 	sctp_clog.x.rto.rtt = net->rtt / 1000;
117c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
11880fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RTT,
11980fefe0aSRandall Stewart 	    from,
12080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
12180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
12280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
12380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
124f8829a4aSRandall Stewart }
125f8829a4aSRandall Stewart 
126f8829a4aSRandall Stewart void
1276a91f103SRandall Stewart sctp_log_strm_del_alt(struct sctp_tcb *stcb, uint32_t tsn, uint16_t sseq, uint16_t stream, int from)
128f8829a4aSRandall Stewart {
12980fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
130f8829a4aSRandall Stewart 
13180fefe0aSRandall Stewart 	sctp_clog.x.strlog.stcb = stcb;
13280fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_tsn = tsn;
13380fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_sseq = sseq;
13480fefe0aSRandall Stewart 	sctp_clog.x.strlog.e_tsn = 0;
13580fefe0aSRandall Stewart 	sctp_clog.x.strlog.e_sseq = 0;
13680fefe0aSRandall Stewart 	sctp_clog.x.strlog.strm = stream;
137c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
13880fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_STRM,
13980fefe0aSRandall Stewart 	    from,
14080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
14180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
14280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
14380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
144f8829a4aSRandall Stewart }
145f8829a4aSRandall Stewart 
146f8829a4aSRandall Stewart void
147f8829a4aSRandall Stewart sctp_log_nagle_event(struct sctp_tcb *stcb, int action)
148f8829a4aSRandall Stewart {
14980fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
150f8829a4aSRandall Stewart 
15180fefe0aSRandall Stewart 	sctp_clog.x.nagle.stcb = (void *)stcb;
15280fefe0aSRandall Stewart 	sctp_clog.x.nagle.total_flight = stcb->asoc.total_flight;
15380fefe0aSRandall Stewart 	sctp_clog.x.nagle.total_in_queue = stcb->asoc.total_output_queue_size;
15480fefe0aSRandall Stewart 	sctp_clog.x.nagle.count_in_queue = stcb->asoc.chunks_on_out_queue;
15580fefe0aSRandall Stewart 	sctp_clog.x.nagle.count_in_flight = stcb->asoc.total_flight_count;
156c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
15780fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_NAGLE,
15880fefe0aSRandall Stewart 	    action,
15980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
16080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
16180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
16280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
163f8829a4aSRandall Stewart }
164f8829a4aSRandall Stewart 
165f8829a4aSRandall Stewart void
166f8829a4aSRandall Stewart sctp_log_sack(uint32_t old_cumack, uint32_t cumack, uint32_t tsn, uint16_t gaps, uint16_t dups, int from)
167f8829a4aSRandall Stewart {
16880fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
169f8829a4aSRandall Stewart 
17080fefe0aSRandall Stewart 	sctp_clog.x.sack.cumack = cumack;
17180fefe0aSRandall Stewart 	sctp_clog.x.sack.oldcumack = old_cumack;
17280fefe0aSRandall Stewart 	sctp_clog.x.sack.tsn = tsn;
17380fefe0aSRandall Stewart 	sctp_clog.x.sack.numGaps = gaps;
17480fefe0aSRandall Stewart 	sctp_clog.x.sack.numDups = dups;
175c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
17680fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_SACK,
17780fefe0aSRandall Stewart 	    from,
17880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
17980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
18080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
18180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
182f8829a4aSRandall Stewart }
183f8829a4aSRandall Stewart 
184f8829a4aSRandall Stewart void
185f8829a4aSRandall Stewart sctp_log_map(uint32_t map, uint32_t cum, uint32_t high, int from)
186f8829a4aSRandall Stewart {
18780fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
188f8829a4aSRandall Stewart 
189bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
19080fefe0aSRandall Stewart 	sctp_clog.x.map.base = map;
19180fefe0aSRandall Stewart 	sctp_clog.x.map.cum = cum;
19280fefe0aSRandall Stewart 	sctp_clog.x.map.high = high;
193c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
19480fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MAP,
19580fefe0aSRandall Stewart 	    from,
19680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
19780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
19880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
19980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
200f8829a4aSRandall Stewart }
201f8829a4aSRandall Stewart 
202f8829a4aSRandall Stewart void
203dcb68fbaSMichael Tuexen sctp_log_fr(uint32_t biggest_tsn, uint32_t biggest_new_tsn, uint32_t tsn, int from)
204f8829a4aSRandall Stewart {
20580fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
206f8829a4aSRandall Stewart 
207bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
20880fefe0aSRandall Stewart 	sctp_clog.x.fr.largest_tsn = biggest_tsn;
20980fefe0aSRandall Stewart 	sctp_clog.x.fr.largest_new_tsn = biggest_new_tsn;
21080fefe0aSRandall Stewart 	sctp_clog.x.fr.tsn = tsn;
211c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
21280fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_FR,
21380fefe0aSRandall Stewart 	    from,
21480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
21580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
21680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
21780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
218f8829a4aSRandall Stewart }
219f8829a4aSRandall Stewart 
2204be807c4SMichael Tuexen #ifdef SCTP_MBUF_LOGGING
221f8829a4aSRandall Stewart void
222f8829a4aSRandall Stewart sctp_log_mb(struct mbuf *m, int from)
223f8829a4aSRandall Stewart {
22480fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
225f8829a4aSRandall Stewart 
22680fefe0aSRandall Stewart 	sctp_clog.x.mb.mp = m;
22780fefe0aSRandall Stewart 	sctp_clog.x.mb.mbuf_flags = (uint8_t) (SCTP_BUF_GET_FLAGS(m));
22880fefe0aSRandall Stewart 	sctp_clog.x.mb.size = (uint16_t) (SCTP_BUF_LEN(m));
22980fefe0aSRandall Stewart 	sctp_clog.x.mb.data = SCTP_BUF_AT(m, 0);
230139bc87fSRandall Stewart 	if (SCTP_BUF_IS_EXTENDED(m)) {
23180fefe0aSRandall Stewart 		sctp_clog.x.mb.ext = SCTP_BUF_EXTEND_BASE(m);
23280fefe0aSRandall Stewart 		sctp_clog.x.mb.refcnt = (uint8_t) (SCTP_BUF_EXTEND_REFCNT(m));
233f8829a4aSRandall Stewart 	} else {
23480fefe0aSRandall Stewart 		sctp_clog.x.mb.ext = 0;
23580fefe0aSRandall Stewart 		sctp_clog.x.mb.refcnt = 0;
236f8829a4aSRandall Stewart 	}
237c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
23880fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MBUF,
23980fefe0aSRandall Stewart 	    from,
24080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
24180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
24280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
24380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
244f8829a4aSRandall Stewart }
245f8829a4aSRandall Stewart 
246f8829a4aSRandall Stewart void
2474be807c4SMichael Tuexen sctp_log_mbc(struct mbuf *m, int from)
2484be807c4SMichael Tuexen {
2494be807c4SMichael Tuexen 	struct mbuf *mat;
2504be807c4SMichael Tuexen 
2514be807c4SMichael Tuexen 	for (mat = m; mat; mat = SCTP_BUF_NEXT(mat)) {
2524be807c4SMichael Tuexen 		sctp_log_mb(mat, from);
2534be807c4SMichael Tuexen 	}
2544be807c4SMichael Tuexen }
2554be807c4SMichael Tuexen 
2564be807c4SMichael Tuexen #endif
2574be807c4SMichael Tuexen 
2584be807c4SMichael Tuexen void
259dcb68fbaSMichael Tuexen sctp_log_strm_del(struct sctp_queued_to_read *control, struct sctp_queued_to_read *poschk, int from)
260f8829a4aSRandall Stewart {
26180fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
262f8829a4aSRandall Stewart 
263f8829a4aSRandall Stewart 	if (control == NULL) {
264ad81507eSRandall Stewart 		SCTP_PRINTF("Gak log of NULL?\n");
265f8829a4aSRandall Stewart 		return;
266f8829a4aSRandall Stewart 	}
26780fefe0aSRandall Stewart 	sctp_clog.x.strlog.stcb = control->stcb;
26880fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_tsn = control->sinfo_tsn;
26980fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_sseq = control->sinfo_ssn;
27080fefe0aSRandall Stewart 	sctp_clog.x.strlog.strm = control->sinfo_stream;
271f8829a4aSRandall Stewart 	if (poschk != NULL) {
27280fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_tsn = poschk->sinfo_tsn;
27380fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_sseq = poschk->sinfo_ssn;
274f8829a4aSRandall Stewart 	} else {
27580fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_tsn = 0;
27680fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_sseq = 0;
277f8829a4aSRandall Stewart 	}
278c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
27980fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_STRM,
28080fefe0aSRandall Stewart 	    from,
28180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
28280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
28380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
28480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
285f8829a4aSRandall Stewart }
286f8829a4aSRandall Stewart 
287f8829a4aSRandall Stewart void
288f8829a4aSRandall Stewart sctp_log_cwnd(struct sctp_tcb *stcb, struct sctp_nets *net, int augment, uint8_t from)
289f8829a4aSRandall Stewart {
29080fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
291f8829a4aSRandall Stewart 
29280fefe0aSRandall Stewart 	sctp_clog.x.cwnd.net = net;
293f8829a4aSRandall Stewart 	if (stcb->asoc.send_queue_cnt > 255)
29480fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = 255;
295f8829a4aSRandall Stewart 	else
29680fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = stcb->asoc.send_queue_cnt;
297f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt > 255)
29880fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = 255;
299f8829a4aSRandall Stewart 	else
30080fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = stcb->asoc.stream_queue_cnt;
301f8829a4aSRandall Stewart 
302f8829a4aSRandall Stewart 	if (net) {
30380fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cwnd_new_value = net->cwnd;
30480fefe0aSRandall Stewart 		sctp_clog.x.cwnd.inflight = net->flight_size;
30580fefe0aSRandall Stewart 		sctp_clog.x.cwnd.pseudo_cumack = net->pseudo_cumack;
30680fefe0aSRandall Stewart 		sctp_clog.x.cwnd.meets_pseudo_cumack = net->new_pseudo_cumack;
30780fefe0aSRandall Stewart 		sctp_clog.x.cwnd.need_new_pseudo_cumack = net->find_pseudo_cumack;
308f8829a4aSRandall Stewart 	}
309f8829a4aSRandall Stewart 	if (SCTP_CWNDLOG_PRESEND == from) {
31080fefe0aSRandall Stewart 		sctp_clog.x.cwnd.meets_pseudo_cumack = stcb->asoc.peers_rwnd;
311f8829a4aSRandall Stewart 	}
31280fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_augment = augment;
313c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
31480fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_CWND,
31580fefe0aSRandall Stewart 	    from,
31680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
31780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
31880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
31980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
320f8829a4aSRandall Stewart }
321f8829a4aSRandall Stewart 
322f8829a4aSRandall Stewart void
323f8829a4aSRandall Stewart sctp_log_lock(struct sctp_inpcb *inp, struct sctp_tcb *stcb, uint8_t from)
324f8829a4aSRandall Stewart {
32580fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
326f8829a4aSRandall Stewart 
327bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
32803b0b021SRandall Stewart 	if (inp) {
32980fefe0aSRandall Stewart 		sctp_clog.x.lock.sock = (void *)inp->sctp_socket;
33003b0b021SRandall Stewart 
33103b0b021SRandall Stewart 	} else {
33280fefe0aSRandall Stewart 		sctp_clog.x.lock.sock = (void *)NULL;
33303b0b021SRandall Stewart 	}
33480fefe0aSRandall Stewart 	sctp_clog.x.lock.inp = (void *)inp;
335f8829a4aSRandall Stewart 	if (stcb) {
33680fefe0aSRandall Stewart 		sctp_clog.x.lock.tcb_lock = mtx_owned(&stcb->tcb_mtx);
337f8829a4aSRandall Stewart 	} else {
33880fefe0aSRandall Stewart 		sctp_clog.x.lock.tcb_lock = SCTP_LOCK_UNKNOWN;
339f8829a4aSRandall Stewart 	}
340f8829a4aSRandall Stewart 	if (inp) {
34180fefe0aSRandall Stewart 		sctp_clog.x.lock.inp_lock = mtx_owned(&inp->inp_mtx);
34280fefe0aSRandall Stewart 		sctp_clog.x.lock.create_lock = mtx_owned(&inp->inp_create_mtx);
343f8829a4aSRandall Stewart 	} else {
34480fefe0aSRandall Stewart 		sctp_clog.x.lock.inp_lock = SCTP_LOCK_UNKNOWN;
34580fefe0aSRandall Stewart 		sctp_clog.x.lock.create_lock = SCTP_LOCK_UNKNOWN;
346f8829a4aSRandall Stewart 	}
347b3f1ea41SRandall Stewart 	sctp_clog.x.lock.info_lock = rw_wowned(&SCTP_BASE_INFO(ipi_ep_mtx));
34852129fcdSRandall Stewart 	if (inp && (inp->sctp_socket)) {
34980fefe0aSRandall Stewart 		sctp_clog.x.lock.sock_lock = mtx_owned(&(inp->sctp_socket->so_rcv.sb_mtx));
35080fefe0aSRandall Stewart 		sctp_clog.x.lock.sockrcvbuf_lock = mtx_owned(&(inp->sctp_socket->so_rcv.sb_mtx));
35180fefe0aSRandall Stewart 		sctp_clog.x.lock.socksndbuf_lock = mtx_owned(&(inp->sctp_socket->so_snd.sb_mtx));
352f8829a4aSRandall Stewart 	} else {
35380fefe0aSRandall Stewart 		sctp_clog.x.lock.sock_lock = SCTP_LOCK_UNKNOWN;
35480fefe0aSRandall Stewart 		sctp_clog.x.lock.sockrcvbuf_lock = SCTP_LOCK_UNKNOWN;
35580fefe0aSRandall Stewart 		sctp_clog.x.lock.socksndbuf_lock = SCTP_LOCK_UNKNOWN;
356f8829a4aSRandall Stewart 	}
357c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
35880fefe0aSRandall Stewart 	    SCTP_LOG_LOCK_EVENT,
35980fefe0aSRandall Stewart 	    from,
36080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
36180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
36280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
36380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
364f8829a4aSRandall Stewart }
365f8829a4aSRandall Stewart 
366f8829a4aSRandall Stewart void
367f8829a4aSRandall Stewart sctp_log_maxburst(struct sctp_tcb *stcb, struct sctp_nets *net, int error, int burst, uint8_t from)
368f8829a4aSRandall Stewart {
36980fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
370f8829a4aSRandall Stewart 
371bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
37280fefe0aSRandall Stewart 	sctp_clog.x.cwnd.net = net;
37380fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_new_value = error;
37480fefe0aSRandall Stewart 	sctp_clog.x.cwnd.inflight = net->flight_size;
37580fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_augment = burst;
376f8829a4aSRandall Stewart 	if (stcb->asoc.send_queue_cnt > 255)
37780fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = 255;
378f8829a4aSRandall Stewart 	else
37980fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = stcb->asoc.send_queue_cnt;
380f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt > 255)
38180fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = 255;
382f8829a4aSRandall Stewart 	else
38380fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = stcb->asoc.stream_queue_cnt;
384c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
38580fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MAXBURST,
38680fefe0aSRandall Stewart 	    from,
38780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
38880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
38980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
39080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
391f8829a4aSRandall Stewart }
392f8829a4aSRandall Stewart 
393f8829a4aSRandall Stewart void
394f8829a4aSRandall Stewart sctp_log_rwnd(uint8_t from, uint32_t peers_rwnd, uint32_t snd_size, uint32_t overhead)
395f8829a4aSRandall Stewart {
39680fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
397f8829a4aSRandall Stewart 
39880fefe0aSRandall Stewart 	sctp_clog.x.rwnd.rwnd = peers_rwnd;
39980fefe0aSRandall Stewart 	sctp_clog.x.rwnd.send_size = snd_size;
40080fefe0aSRandall Stewart 	sctp_clog.x.rwnd.overhead = overhead;
40180fefe0aSRandall Stewart 	sctp_clog.x.rwnd.new_rwnd = 0;
402c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
40380fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RWND,
40480fefe0aSRandall Stewart 	    from,
40580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
40680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
40780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
40880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
409f8829a4aSRandall Stewart }
410f8829a4aSRandall Stewart 
411f8829a4aSRandall Stewart void
412f8829a4aSRandall Stewart sctp_log_rwnd_set(uint8_t from, uint32_t peers_rwnd, uint32_t flight_size, uint32_t overhead, uint32_t a_rwndval)
413f8829a4aSRandall Stewart {
41480fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
415f8829a4aSRandall Stewart 
41680fefe0aSRandall Stewart 	sctp_clog.x.rwnd.rwnd = peers_rwnd;
41780fefe0aSRandall Stewart 	sctp_clog.x.rwnd.send_size = flight_size;
41880fefe0aSRandall Stewart 	sctp_clog.x.rwnd.overhead = overhead;
41980fefe0aSRandall Stewart 	sctp_clog.x.rwnd.new_rwnd = a_rwndval;
420c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
42180fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RWND,
42280fefe0aSRandall Stewart 	    from,
42380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
42480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
42580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
42680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
427f8829a4aSRandall Stewart }
428f8829a4aSRandall Stewart 
4294be807c4SMichael Tuexen #ifdef SCTP_MBCNT_LOGGING
4304be807c4SMichael Tuexen static void
431f8829a4aSRandall Stewart sctp_log_mbcnt(uint8_t from, uint32_t total_oq, uint32_t book, uint32_t total_mbcnt_q, uint32_t mbcnt)
432f8829a4aSRandall Stewart {
43380fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
434f8829a4aSRandall Stewart 
43580fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.total_queue_size = total_oq;
43680fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.size_change = book;
43780fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.total_queue_mb_size = total_mbcnt_q;
43880fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.mbcnt_change = mbcnt;
439c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
44080fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MBCNT,
44180fefe0aSRandall Stewart 	    from,
44280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
44380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
44480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
44580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
446f8829a4aSRandall Stewart }
447f8829a4aSRandall Stewart 
4484be807c4SMichael Tuexen #endif
4494be807c4SMichael Tuexen 
450f8829a4aSRandall Stewart void
451f8829a4aSRandall Stewart sctp_misc_ints(uint8_t from, uint32_t a, uint32_t b, uint32_t c, uint32_t d)
452f8829a4aSRandall Stewart {
453c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
45480fefe0aSRandall Stewart 	    SCTP_LOG_MISC_EVENT,
45580fefe0aSRandall Stewart 	    from,
45680fefe0aSRandall Stewart 	    a, b, c, d);
457f8829a4aSRandall Stewart }
458f8829a4aSRandall Stewart 
459f8829a4aSRandall Stewart void
4607215cc1bSMichael Tuexen sctp_wakeup_log(struct sctp_tcb *stcb, uint32_t wake_cnt, int from)
461f8829a4aSRandall Stewart {
46280fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
463f8829a4aSRandall Stewart 
46480fefe0aSRandall Stewart 	sctp_clog.x.wake.stcb = (void *)stcb;
46580fefe0aSRandall Stewart 	sctp_clog.x.wake.wake_cnt = wake_cnt;
46680fefe0aSRandall Stewart 	sctp_clog.x.wake.flight = stcb->asoc.total_flight_count;
46780fefe0aSRandall Stewart 	sctp_clog.x.wake.send_q = stcb->asoc.send_queue_cnt;
46880fefe0aSRandall Stewart 	sctp_clog.x.wake.sent_q = stcb->asoc.sent_queue_cnt;
469f8829a4aSRandall Stewart 
470f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt < 0xff)
47180fefe0aSRandall Stewart 		sctp_clog.x.wake.stream_qcnt = (uint8_t) stcb->asoc.stream_queue_cnt;
472f8829a4aSRandall Stewart 	else
47380fefe0aSRandall Stewart 		sctp_clog.x.wake.stream_qcnt = 0xff;
474f8829a4aSRandall Stewart 
475f8829a4aSRandall Stewart 	if (stcb->asoc.chunks_on_out_queue < 0xff)
47680fefe0aSRandall Stewart 		sctp_clog.x.wake.chunks_on_oque = (uint8_t) stcb->asoc.chunks_on_out_queue;
477f8829a4aSRandall Stewart 	else
47880fefe0aSRandall Stewart 		sctp_clog.x.wake.chunks_on_oque = 0xff;
479f8829a4aSRandall Stewart 
48080fefe0aSRandall Stewart 	sctp_clog.x.wake.sctpflags = 0;
481f8829a4aSRandall Stewart 	/* set in the defered mode stuff */
482f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_DONT_WAKE)
48380fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 1;
484f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_WAKEOUTPUT)
48580fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 2;
486f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_WAKEINPUT)
48780fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 4;
488f8829a4aSRandall Stewart 	/* what about the sb */
489f8829a4aSRandall Stewart 	if (stcb->sctp_socket) {
490f8829a4aSRandall Stewart 		struct socket *so = stcb->sctp_socket;
491f8829a4aSRandall Stewart 
49280fefe0aSRandall Stewart 		sctp_clog.x.wake.sbflags = (uint8_t) ((so->so_snd.sb_flags & 0x00ff));
493f8829a4aSRandall Stewart 	} else {
49480fefe0aSRandall Stewart 		sctp_clog.x.wake.sbflags = 0xff;
495f8829a4aSRandall Stewart 	}
496c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
49780fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_WAKE,
49880fefe0aSRandall Stewart 	    from,
49980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
50080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
50180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
50280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
503f8829a4aSRandall Stewart }
504f8829a4aSRandall Stewart 
505f8829a4aSRandall Stewart void
5069a8e3088SMichael Tuexen sctp_log_block(uint8_t from, struct sctp_association *asoc, size_t sendlen)
507f8829a4aSRandall Stewart {
50880fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
509f8829a4aSRandall Stewart 
51080fefe0aSRandall Stewart 	sctp_clog.x.blk.onsb = asoc->total_output_queue_size;
51180fefe0aSRandall Stewart 	sctp_clog.x.blk.send_sent_qcnt = (uint16_t) (asoc->send_queue_cnt + asoc->sent_queue_cnt);
51280fefe0aSRandall Stewart 	sctp_clog.x.blk.peer_rwnd = asoc->peers_rwnd;
51380fefe0aSRandall Stewart 	sctp_clog.x.blk.stream_qcnt = (uint16_t) asoc->stream_queue_cnt;
51480fefe0aSRandall Stewart 	sctp_clog.x.blk.chunks_on_oque = (uint16_t) asoc->chunks_on_out_queue;
51580fefe0aSRandall Stewart 	sctp_clog.x.blk.flight_size = (uint16_t) (asoc->total_flight / 1024);
5169a8e3088SMichael Tuexen 	sctp_clog.x.blk.sndlen = (uint32_t) sendlen;
517c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
51880fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_BLOCK,
51980fefe0aSRandall Stewart 	    from,
52080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
52180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
52280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
52380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
524f8829a4aSRandall Stewart }
525f8829a4aSRandall Stewart 
526f8829a4aSRandall Stewart int
5277215cc1bSMichael Tuexen sctp_fill_stat_log(void *optval SCTP_UNUSED, size_t *optsize SCTP_UNUSED)
528f8829a4aSRandall Stewart {
52980fefe0aSRandall Stewart 	/* May need to fix this if ktrdump does not work */
530f8829a4aSRandall Stewart 	return (0);
531f8829a4aSRandall Stewart }
532f8829a4aSRandall Stewart 
533f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
534f8829a4aSRandall Stewart uint8_t sctp_audit_data[SCTP_AUDIT_SIZE][2];
535f8829a4aSRandall Stewart static int sctp_audit_indx = 0;
536f8829a4aSRandall Stewart 
537f8829a4aSRandall Stewart static
538f8829a4aSRandall Stewart void
539f8829a4aSRandall Stewart sctp_print_audit_report(void)
540f8829a4aSRandall Stewart {
541f8829a4aSRandall Stewart 	int i;
542f8829a4aSRandall Stewart 	int cnt;
543f8829a4aSRandall Stewart 
544f8829a4aSRandall Stewart 	cnt = 0;
545f8829a4aSRandall Stewart 	for (i = sctp_audit_indx; i < SCTP_AUDIT_SIZE; i++) {
546f8829a4aSRandall Stewart 		if ((sctp_audit_data[i][0] == 0xe0) &&
547f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
548f8829a4aSRandall Stewart 			cnt = 0;
549ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
550f8829a4aSRandall Stewart 		} else if (sctp_audit_data[i][0] == 0xf0) {
551f8829a4aSRandall Stewart 			cnt = 0;
552ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
553f8829a4aSRandall Stewart 		} else if ((sctp_audit_data[i][0] == 0xc0) &&
554f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
555ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
556f8829a4aSRandall Stewart 			cnt = 0;
557f8829a4aSRandall Stewart 		}
558ad81507eSRandall Stewart 		SCTP_PRINTF("%2.2x%2.2x ", (uint32_t) sctp_audit_data[i][0],
559f8829a4aSRandall Stewart 		    (uint32_t) sctp_audit_data[i][1]);
560f8829a4aSRandall Stewart 		cnt++;
561f8829a4aSRandall Stewart 		if ((cnt % 14) == 0)
562ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
563f8829a4aSRandall Stewart 	}
564f8829a4aSRandall Stewart 	for (i = 0; i < sctp_audit_indx; i++) {
565f8829a4aSRandall Stewart 		if ((sctp_audit_data[i][0] == 0xe0) &&
566f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
567f8829a4aSRandall Stewart 			cnt = 0;
568ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
569f8829a4aSRandall Stewart 		} else if (sctp_audit_data[i][0] == 0xf0) {
570f8829a4aSRandall Stewart 			cnt = 0;
571ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
572f8829a4aSRandall Stewart 		} else if ((sctp_audit_data[i][0] == 0xc0) &&
573f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
574ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
575f8829a4aSRandall Stewart 			cnt = 0;
576f8829a4aSRandall Stewart 		}
577ad81507eSRandall Stewart 		SCTP_PRINTF("%2.2x%2.2x ", (uint32_t) sctp_audit_data[i][0],
578f8829a4aSRandall Stewart 		    (uint32_t) sctp_audit_data[i][1]);
579f8829a4aSRandall Stewart 		cnt++;
580f8829a4aSRandall Stewart 		if ((cnt % 14) == 0)
581ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
582f8829a4aSRandall Stewart 	}
583ad81507eSRandall Stewart 	SCTP_PRINTF("\n");
584f8829a4aSRandall Stewart }
585f8829a4aSRandall Stewart 
586f8829a4aSRandall Stewart void
587f8829a4aSRandall Stewart sctp_auditing(int from, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
588f8829a4aSRandall Stewart     struct sctp_nets *net)
589f8829a4aSRandall Stewart {
590f8829a4aSRandall Stewart 	int resend_cnt, tot_out, rep, tot_book_cnt;
591f8829a4aSRandall Stewart 	struct sctp_nets *lnet;
592f8829a4aSRandall Stewart 	struct sctp_tmit_chunk *chk;
593f8829a4aSRandall Stewart 
594f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = 0xAA;
595f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] = 0x000000ff & from;
596f8829a4aSRandall Stewart 	sctp_audit_indx++;
597f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
598f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
599f8829a4aSRandall Stewart 	}
600f8829a4aSRandall Stewart 	if (inp == NULL) {
601f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
602f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0x01;
603f8829a4aSRandall Stewart 		sctp_audit_indx++;
604f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
605f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
606f8829a4aSRandall Stewart 		}
607f8829a4aSRandall Stewart 		return;
608f8829a4aSRandall Stewart 	}
609f8829a4aSRandall Stewart 	if (stcb == NULL) {
610f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
611f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0x02;
612f8829a4aSRandall Stewart 		sctp_audit_indx++;
613f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
614f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
615f8829a4aSRandall Stewart 		}
616f8829a4aSRandall Stewart 		return;
617f8829a4aSRandall Stewart 	}
618f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = 0xA1;
619f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] =
620f8829a4aSRandall Stewart 	    (0x000000ff & stcb->asoc.sent_queue_retran_cnt);
621f8829a4aSRandall Stewart 	sctp_audit_indx++;
622f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
623f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
624f8829a4aSRandall Stewart 	}
625f8829a4aSRandall Stewart 	rep = 0;
626f8829a4aSRandall Stewart 	tot_book_cnt = 0;
627f8829a4aSRandall Stewart 	resend_cnt = tot_out = 0;
628f8829a4aSRandall Stewart 	TAILQ_FOREACH(chk, &stcb->asoc.sent_queue, sctp_next) {
629f8829a4aSRandall Stewart 		if (chk->sent == SCTP_DATAGRAM_RESEND) {
630f8829a4aSRandall Stewart 			resend_cnt++;
631f8829a4aSRandall Stewart 		} else if (chk->sent < SCTP_DATAGRAM_RESEND) {
632f8829a4aSRandall Stewart 			tot_out += chk->book_size;
633f8829a4aSRandall Stewart 			tot_book_cnt++;
634f8829a4aSRandall Stewart 		}
635f8829a4aSRandall Stewart 	}
636f8829a4aSRandall Stewart 	if (resend_cnt != stcb->asoc.sent_queue_retran_cnt) {
637f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
638f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA1;
639f8829a4aSRandall Stewart 		sctp_audit_indx++;
640f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
641f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
642f8829a4aSRandall Stewart 		}
643ad81507eSRandall Stewart 		SCTP_PRINTF("resend_cnt:%d asoc-tot:%d\n",
644f8829a4aSRandall Stewart 		    resend_cnt, stcb->asoc.sent_queue_retran_cnt);
645f8829a4aSRandall Stewart 		rep = 1;
646f8829a4aSRandall Stewart 		stcb->asoc.sent_queue_retran_cnt = resend_cnt;
647f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xA2;
648f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] =
649f8829a4aSRandall Stewart 		    (0x000000ff & stcb->asoc.sent_queue_retran_cnt);
650f8829a4aSRandall Stewart 		sctp_audit_indx++;
651f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
652f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
653f8829a4aSRandall Stewart 		}
654f8829a4aSRandall Stewart 	}
655f8829a4aSRandall Stewart 	if (tot_out != stcb->asoc.total_flight) {
656f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
657f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA2;
658f8829a4aSRandall Stewart 		sctp_audit_indx++;
659f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
660f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
661f8829a4aSRandall Stewart 		}
662f8829a4aSRandall Stewart 		rep = 1;
663ad81507eSRandall Stewart 		SCTP_PRINTF("tot_flt:%d asoc_tot:%d\n", tot_out,
664f8829a4aSRandall Stewart 		    (int)stcb->asoc.total_flight);
665f8829a4aSRandall Stewart 		stcb->asoc.total_flight = tot_out;
666f8829a4aSRandall Stewart 	}
667f8829a4aSRandall Stewart 	if (tot_book_cnt != stcb->asoc.total_flight_count) {
668f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
669f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA5;
670f8829a4aSRandall Stewart 		sctp_audit_indx++;
671f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
672f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
673f8829a4aSRandall Stewart 		}
674f8829a4aSRandall Stewart 		rep = 1;
675f31e6c7fSMichael Tuexen 		SCTP_PRINTF("tot_flt_book:%d\n", tot_book_cnt);
676f8829a4aSRandall Stewart 
677f8829a4aSRandall Stewart 		stcb->asoc.total_flight_count = tot_book_cnt;
678f8829a4aSRandall Stewart 	}
679f8829a4aSRandall Stewart 	tot_out = 0;
680f8829a4aSRandall Stewart 	TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
681f8829a4aSRandall Stewart 		tot_out += lnet->flight_size;
682f8829a4aSRandall Stewart 	}
683f8829a4aSRandall Stewart 	if (tot_out != stcb->asoc.total_flight) {
684f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
685f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA3;
686f8829a4aSRandall Stewart 		sctp_audit_indx++;
687f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
688f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
689f8829a4aSRandall Stewart 		}
690f8829a4aSRandall Stewart 		rep = 1;
691ad81507eSRandall Stewart 		SCTP_PRINTF("real flight:%d net total was %d\n",
692f8829a4aSRandall Stewart 		    stcb->asoc.total_flight, tot_out);
693f8829a4aSRandall Stewart 		/* now corrective action */
694f8829a4aSRandall Stewart 		TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
695f8829a4aSRandall Stewart 
696f8829a4aSRandall Stewart 			tot_out = 0;
697f8829a4aSRandall Stewart 			TAILQ_FOREACH(chk, &stcb->asoc.sent_queue, sctp_next) {
698f8829a4aSRandall Stewart 				if ((chk->whoTo == lnet) &&
699f8829a4aSRandall Stewart 				    (chk->sent < SCTP_DATAGRAM_RESEND)) {
700f8829a4aSRandall Stewart 					tot_out += chk->book_size;
701f8829a4aSRandall Stewart 				}
702f8829a4aSRandall Stewart 			}
703f8829a4aSRandall Stewart 			if (lnet->flight_size != tot_out) {
704f31e6c7fSMichael Tuexen 				SCTP_PRINTF("net:%p flight was %d corrected to %d\n",
705dd294dceSMichael Tuexen 				    (void *)lnet, lnet->flight_size,
706ad81507eSRandall Stewart 				    tot_out);
707f8829a4aSRandall Stewart 				lnet->flight_size = tot_out;
708f8829a4aSRandall Stewart 			}
709f8829a4aSRandall Stewart 		}
710f8829a4aSRandall Stewart 	}
711f8829a4aSRandall Stewart 	if (rep) {
712f8829a4aSRandall Stewart 		sctp_print_audit_report();
713f8829a4aSRandall Stewart 	}
714f8829a4aSRandall Stewart }
715f8829a4aSRandall Stewart 
716f8829a4aSRandall Stewart void
717f8829a4aSRandall Stewart sctp_audit_log(uint8_t ev, uint8_t fd)
718f8829a4aSRandall Stewart {
719f8829a4aSRandall Stewart 
720f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = ev;
721f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] = fd;
722f8829a4aSRandall Stewart 	sctp_audit_indx++;
723f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
724f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
725f8829a4aSRandall Stewart 	}
726f8829a4aSRandall Stewart }
727f8829a4aSRandall Stewart 
728f8829a4aSRandall Stewart #endif
729f8829a4aSRandall Stewart 
730f8829a4aSRandall Stewart /*
73112af6654SMichael Tuexen  * sctp_stop_timers_for_shutdown() should be called
73212af6654SMichael Tuexen  * when entering the SHUTDOWN_SENT or SHUTDOWN_ACK_SENT
73312af6654SMichael Tuexen  * state to make sure that all timers are stopped.
73412af6654SMichael Tuexen  */
73512af6654SMichael Tuexen void
73612af6654SMichael Tuexen sctp_stop_timers_for_shutdown(struct sctp_tcb *stcb)
73712af6654SMichael Tuexen {
73812af6654SMichael Tuexen 	struct sctp_association *asoc;
73912af6654SMichael Tuexen 	struct sctp_nets *net;
74012af6654SMichael Tuexen 
74112af6654SMichael Tuexen 	asoc = &stcb->asoc;
74212af6654SMichael Tuexen 
74312af6654SMichael Tuexen 	(void)SCTP_OS_TIMER_STOP(&asoc->dack_timer.timer);
74412af6654SMichael Tuexen 	(void)SCTP_OS_TIMER_STOP(&asoc->strreset_timer.timer);
74512af6654SMichael Tuexen 	(void)SCTP_OS_TIMER_STOP(&asoc->asconf_timer.timer);
74612af6654SMichael Tuexen 	(void)SCTP_OS_TIMER_STOP(&asoc->autoclose_timer.timer);
74712af6654SMichael Tuexen 	(void)SCTP_OS_TIMER_STOP(&asoc->delayed_event_timer.timer);
74812af6654SMichael Tuexen 	TAILQ_FOREACH(net, &asoc->nets, sctp_next) {
74912af6654SMichael Tuexen 		(void)SCTP_OS_TIMER_STOP(&net->pmtu_timer.timer);
750ca85e948SMichael Tuexen 		(void)SCTP_OS_TIMER_STOP(&net->hb_timer.timer);
75112af6654SMichael Tuexen 	}
75212af6654SMichael Tuexen }
75312af6654SMichael Tuexen 
75412af6654SMichael Tuexen /*
755f8829a4aSRandall Stewart  * a list of sizes based on typical mtu's, used only if next hop size not
756f8829a4aSRandall Stewart  * returned.
757f8829a4aSRandall Stewart  */
758437fc91aSMichael Tuexen static uint32_t sctp_mtu_sizes[] = {
759f8829a4aSRandall Stewart 	68,
760f8829a4aSRandall Stewart 	296,
761f8829a4aSRandall Stewart 	508,
762f8829a4aSRandall Stewart 	512,
763f8829a4aSRandall Stewart 	544,
764f8829a4aSRandall Stewart 	576,
765f8829a4aSRandall Stewart 	1006,
766f8829a4aSRandall Stewart 	1492,
767f8829a4aSRandall Stewart 	1500,
768f8829a4aSRandall Stewart 	1536,
769f8829a4aSRandall Stewart 	2002,
770f8829a4aSRandall Stewart 	2048,
771f8829a4aSRandall Stewart 	4352,
772f8829a4aSRandall Stewart 	4464,
773f8829a4aSRandall Stewart 	8166,
774f8829a4aSRandall Stewart 	17914,
775f8829a4aSRandall Stewart 	32000,
776f8829a4aSRandall Stewart 	65535
777f8829a4aSRandall Stewart };
778f8829a4aSRandall Stewart 
779f8829a4aSRandall Stewart /*
780437fc91aSMichael Tuexen  * Return the largest MTU smaller than val. If there is no
781437fc91aSMichael Tuexen  * entry, just return val.
782f8829a4aSRandall Stewart  */
783437fc91aSMichael Tuexen uint32_t
784437fc91aSMichael Tuexen sctp_get_prev_mtu(uint32_t val)
785437fc91aSMichael Tuexen {
786437fc91aSMichael Tuexen 	uint32_t i;
787437fc91aSMichael Tuexen 
788437fc91aSMichael Tuexen 	if (val <= sctp_mtu_sizes[0]) {
789437fc91aSMichael Tuexen 		return (val);
790437fc91aSMichael Tuexen 	}
791437fc91aSMichael Tuexen 	for (i = 1; i < (sizeof(sctp_mtu_sizes) / sizeof(uint32_t)); i++) {
792437fc91aSMichael Tuexen 		if (val <= sctp_mtu_sizes[i]) {
793f8829a4aSRandall Stewart 			break;
794f8829a4aSRandall Stewart 		}
795f8829a4aSRandall Stewart 	}
796437fc91aSMichael Tuexen 	return (sctp_mtu_sizes[i - 1]);
797437fc91aSMichael Tuexen }
798437fc91aSMichael Tuexen 
799437fc91aSMichael Tuexen /*
800437fc91aSMichael Tuexen  * Return the smallest MTU larger than val. If there is no
801437fc91aSMichael Tuexen  * entry, just return val.
802437fc91aSMichael Tuexen  */
803437fc91aSMichael Tuexen uint32_t
8047215cc1bSMichael Tuexen sctp_get_next_mtu(uint32_t val)
805437fc91aSMichael Tuexen {
806437fc91aSMichael Tuexen 	/* select another MTU that is just bigger than this one */
807437fc91aSMichael Tuexen 	uint32_t i;
808437fc91aSMichael Tuexen 
809437fc91aSMichael Tuexen 	for (i = 0; i < (sizeof(sctp_mtu_sizes) / sizeof(uint32_t)); i++) {
810437fc91aSMichael Tuexen 		if (val < sctp_mtu_sizes[i]) {
811437fc91aSMichael Tuexen 			return (sctp_mtu_sizes[i]);
812437fc91aSMichael Tuexen 		}
813437fc91aSMichael Tuexen 	}
814437fc91aSMichael Tuexen 	return (val);
815f8829a4aSRandall Stewart }
816f8829a4aSRandall Stewart 
817f8829a4aSRandall Stewart void
818f8829a4aSRandall Stewart sctp_fill_random_store(struct sctp_pcb *m)
819f8829a4aSRandall Stewart {
820f8829a4aSRandall Stewart 	/*
821f8829a4aSRandall Stewart 	 * Here we use the MD5/SHA-1 to hash with our good randomNumbers and
822f8829a4aSRandall Stewart 	 * our counter. The result becomes our good random numbers and we
823f8829a4aSRandall Stewart 	 * then setup to give these out. Note that we do no locking to
824f8829a4aSRandall Stewart 	 * protect this. This is ok, since if competing folks call this we
82517205eccSRandall Stewart 	 * will get more gobbled gook in the random store which is what we
826f8829a4aSRandall Stewart 	 * want. There is a danger that two guys will use the same random
827f8829a4aSRandall Stewart 	 * numbers, but thats ok too since that is random as well :->
828f8829a4aSRandall Stewart 	 */
829f8829a4aSRandall Stewart 	m->store_at = 0;
830ad81507eSRandall Stewart 	(void)sctp_hmac(SCTP_HMAC, (uint8_t *) m->random_numbers,
831f8829a4aSRandall Stewart 	    sizeof(m->random_numbers), (uint8_t *) & m->random_counter,
832f8829a4aSRandall Stewart 	    sizeof(m->random_counter), (uint8_t *) m->random_store);
833f8829a4aSRandall Stewart 	m->random_counter++;
834f8829a4aSRandall Stewart }
835f8829a4aSRandall Stewart 
836f8829a4aSRandall Stewart uint32_t
837851b7298SRandall Stewart sctp_select_initial_TSN(struct sctp_pcb *inp)
838f8829a4aSRandall Stewart {
839f8829a4aSRandall Stewart 	/*
840f8829a4aSRandall Stewart 	 * A true implementation should use random selection process to get
841f8829a4aSRandall Stewart 	 * the initial stream sequence number, using RFC1750 as a good
842f8829a4aSRandall Stewart 	 * guideline
843f8829a4aSRandall Stewart 	 */
844139bc87fSRandall Stewart 	uint32_t x, *xp;
845f8829a4aSRandall Stewart 	uint8_t *p;
846851b7298SRandall Stewart 	int store_at, new_store;
847f8829a4aSRandall Stewart 
848851b7298SRandall Stewart 	if (inp->initial_sequence_debug != 0) {
849f8829a4aSRandall Stewart 		uint32_t ret;
850f8829a4aSRandall Stewart 
851851b7298SRandall Stewart 		ret = inp->initial_sequence_debug;
852851b7298SRandall Stewart 		inp->initial_sequence_debug++;
853f8829a4aSRandall Stewart 		return (ret);
854f8829a4aSRandall Stewart 	}
855851b7298SRandall Stewart retry:
856851b7298SRandall Stewart 	store_at = inp->store_at;
857851b7298SRandall Stewart 	new_store = store_at + sizeof(uint32_t);
858851b7298SRandall Stewart 	if (new_store >= (SCTP_SIGNATURE_SIZE - 3)) {
859851b7298SRandall Stewart 		new_store = 0;
860f8829a4aSRandall Stewart 	}
861851b7298SRandall Stewart 	if (!atomic_cmpset_int(&inp->store_at, store_at, new_store)) {
862851b7298SRandall Stewart 		goto retry;
863851b7298SRandall Stewart 	}
864851b7298SRandall Stewart 	if (new_store == 0) {
865851b7298SRandall Stewart 		/* Refill the random store */
866851b7298SRandall Stewart 		sctp_fill_random_store(inp);
867851b7298SRandall Stewart 	}
868851b7298SRandall Stewart 	p = &inp->random_store[store_at];
869139bc87fSRandall Stewart 	xp = (uint32_t *) p;
870f8829a4aSRandall Stewart 	x = *xp;
871f8829a4aSRandall Stewart 	return (x);
872f8829a4aSRandall Stewart }
873f8829a4aSRandall Stewart 
874f8829a4aSRandall Stewart uint32_t
8757215cc1bSMichael Tuexen sctp_select_a_tag(struct sctp_inpcb *inp, uint16_t lport, uint16_t rport, int check)
876f8829a4aSRandall Stewart {
8777215cc1bSMichael Tuexen 	uint32_t x;
878f8829a4aSRandall Stewart 	struct timeval now;
879f8829a4aSRandall Stewart 
8807215cc1bSMichael Tuexen 	if (check) {
8816e55db54SRandall Stewart 		(void)SCTP_GETTIME_TIMEVAL(&now);
8827215cc1bSMichael Tuexen 	}
8837215cc1bSMichael Tuexen 	for (;;) {
884851b7298SRandall Stewart 		x = sctp_select_initial_TSN(&inp->sctp_ep);
885f8829a4aSRandall Stewart 		if (x == 0) {
886f8829a4aSRandall Stewart 			/* we never use 0 */
887f8829a4aSRandall Stewart 			continue;
888f8829a4aSRandall Stewart 		}
8897215cc1bSMichael Tuexen 		if (!check || sctp_is_vtag_good(x, lport, rport, &now)) {
8907215cc1bSMichael Tuexen 			break;
891f8829a4aSRandall Stewart 		}
892f8829a4aSRandall Stewart 	}
893f8829a4aSRandall Stewart 	return (x);
894f8829a4aSRandall Stewart }
895f8829a4aSRandall Stewart 
896e92c2a8dSMichael Tuexen int32_t
897e92c2a8dSMichael Tuexen sctp_map_assoc_state(int kernel_state)
898e92c2a8dSMichael Tuexen {
899e92c2a8dSMichael Tuexen 	int32_t user_state;
900e92c2a8dSMichael Tuexen 
901e92c2a8dSMichael Tuexen 	if (kernel_state & SCTP_STATE_WAS_ABORTED) {
902e92c2a8dSMichael Tuexen 		user_state = SCTP_CLOSED;
903e92c2a8dSMichael Tuexen 	} else if (kernel_state & SCTP_STATE_SHUTDOWN_PENDING) {
904e92c2a8dSMichael Tuexen 		user_state = SCTP_SHUTDOWN_PENDING;
905e92c2a8dSMichael Tuexen 	} else {
906e92c2a8dSMichael Tuexen 		switch (kernel_state & SCTP_STATE_MASK) {
907e92c2a8dSMichael Tuexen 		case SCTP_STATE_EMPTY:
908e92c2a8dSMichael Tuexen 			user_state = SCTP_CLOSED;
909e92c2a8dSMichael Tuexen 			break;
910e92c2a8dSMichael Tuexen 		case SCTP_STATE_INUSE:
911e92c2a8dSMichael Tuexen 			user_state = SCTP_CLOSED;
912e92c2a8dSMichael Tuexen 			break;
913e92c2a8dSMichael Tuexen 		case SCTP_STATE_COOKIE_WAIT:
914e92c2a8dSMichael Tuexen 			user_state = SCTP_COOKIE_WAIT;
915e92c2a8dSMichael Tuexen 			break;
916e92c2a8dSMichael Tuexen 		case SCTP_STATE_COOKIE_ECHOED:
917e92c2a8dSMichael Tuexen 			user_state = SCTP_COOKIE_ECHOED;
918e92c2a8dSMichael Tuexen 			break;
919e92c2a8dSMichael Tuexen 		case SCTP_STATE_OPEN:
920e92c2a8dSMichael Tuexen 			user_state = SCTP_ESTABLISHED;
921e92c2a8dSMichael Tuexen 			break;
922e92c2a8dSMichael Tuexen 		case SCTP_STATE_SHUTDOWN_SENT:
923e92c2a8dSMichael Tuexen 			user_state = SCTP_SHUTDOWN_SENT;
924e92c2a8dSMichael Tuexen 			break;
925e92c2a8dSMichael Tuexen 		case SCTP_STATE_SHUTDOWN_RECEIVED:
926e92c2a8dSMichael Tuexen 			user_state = SCTP_SHUTDOWN_RECEIVED;
927e92c2a8dSMichael Tuexen 			break;
928e92c2a8dSMichael Tuexen 		case SCTP_STATE_SHUTDOWN_ACK_SENT:
929e92c2a8dSMichael Tuexen 			user_state = SCTP_SHUTDOWN_ACK_SENT;
930e92c2a8dSMichael Tuexen 			break;
931e92c2a8dSMichael Tuexen 		default:
932e92c2a8dSMichael Tuexen 			user_state = SCTP_CLOSED;
933e92c2a8dSMichael Tuexen 			break;
934e92c2a8dSMichael Tuexen 		}
935e92c2a8dSMichael Tuexen 	}
936e92c2a8dSMichael Tuexen 	return (user_state);
937e92c2a8dSMichael Tuexen }
938e92c2a8dSMichael Tuexen 
939f8829a4aSRandall Stewart int
940a1cb341bSMichael Tuexen sctp_init_asoc(struct sctp_inpcb *inp, struct sctp_tcb *stcb,
941c979034bSMichael Tuexen     uint32_t override_tag, uint32_t vrf_id, uint16_t o_strms)
942f8829a4aSRandall Stewart {
9430696e120SRandall Stewart 	struct sctp_association *asoc;
9440696e120SRandall Stewart 
945f8829a4aSRandall Stewart 	/*
946f8829a4aSRandall Stewart 	 * Anything set to zero is taken care of by the allocation routine's
947f8829a4aSRandall Stewart 	 * bzero
948f8829a4aSRandall Stewart 	 */
949f8829a4aSRandall Stewart 
950f8829a4aSRandall Stewart 	/*
951f8829a4aSRandall Stewart 	 * Up front select what scoping to apply on addresses I tell my peer
952f8829a4aSRandall Stewart 	 * Not sure what to do with these right now, we will need to come up
953f8829a4aSRandall Stewart 	 * with a way to set them. We may need to pass them through from the
954f8829a4aSRandall Stewart 	 * caller in the sctp_aloc_assoc() function.
955f8829a4aSRandall Stewart 	 */
956f8829a4aSRandall Stewart 	int i;
957f8829a4aSRandall Stewart 
958f0396ad1SMichael Tuexen #if defined(SCTP_DETAILED_STR_STATS)
959f0396ad1SMichael Tuexen 	int j;
960f0396ad1SMichael Tuexen 
961f0396ad1SMichael Tuexen #endif
962f0396ad1SMichael Tuexen 
9630696e120SRandall Stewart 	asoc = &stcb->asoc;
964f8829a4aSRandall Stewart 	/* init all variables to a known value. */
965c4739e2fSRandall Stewart 	SCTP_SET_STATE(&stcb->asoc, SCTP_STATE_INUSE);
966a1cb341bSMichael Tuexen 	asoc->max_burst = inp->sctp_ep.max_burst;
967a1cb341bSMichael Tuexen 	asoc->fr_max_burst = inp->sctp_ep.fr_max_burst;
968a1cb341bSMichael Tuexen 	asoc->heart_beat_delay = TICKS_TO_MSEC(inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_HEARTBEAT]);
969a1cb341bSMichael Tuexen 	asoc->cookie_life = inp->sctp_ep.def_cookie_life;
970a1cb341bSMichael Tuexen 	asoc->sctp_cmt_on_off = inp->sctp_cmt_on_off;
971f342355aSMichael Tuexen 	asoc->ecn_supported = inp->ecn_supported;
972dd973b0eSMichael Tuexen 	asoc->prsctp_supported = inp->prsctp_supported;
97344249214SRandall Stewart 	asoc->idata_supported = inp->idata_supported;
974c79bec9cSMichael Tuexen 	asoc->auth_supported = inp->auth_supported;
975c79bec9cSMichael Tuexen 	asoc->asconf_supported = inp->asconf_supported;
976317e00efSMichael Tuexen 	asoc->reconfig_supported = inp->reconfig_supported;
977caea9879SMichael Tuexen 	asoc->nrsack_supported = inp->nrsack_supported;
978cb9b8e6fSMichael Tuexen 	asoc->pktdrop_supported = inp->pktdrop_supported;
97944249214SRandall Stewart 	asoc->idata_supported = inp->idata_supported;
980ca85e948SMichael Tuexen 	asoc->sctp_cmt_pf = (uint8_t) 0;
981a1cb341bSMichael Tuexen 	asoc->sctp_frag_point = inp->sctp_frag_point;
982a1cb341bSMichael Tuexen 	asoc->sctp_features = inp->sctp_features;
983a1cb341bSMichael Tuexen 	asoc->default_dscp = inp->sctp_ep.default_dscp;
98459b6d5beSMichael Tuexen 	asoc->max_cwnd = inp->max_cwnd;
98542551e99SRandall Stewart #ifdef INET6
986a1cb341bSMichael Tuexen 	if (inp->sctp_ep.default_flowlabel) {
987a1cb341bSMichael Tuexen 		asoc->default_flowlabel = inp->sctp_ep.default_flowlabel;
98858bdb691SMichael Tuexen 	} else {
989a1cb341bSMichael Tuexen 		if (inp->ip_inp.inp.inp_flags & IN6P_AUTOFLOWLABEL) {
990a1cb341bSMichael Tuexen 			asoc->default_flowlabel = sctp_select_initial_TSN(&inp->sctp_ep);
99158bdb691SMichael Tuexen 			asoc->default_flowlabel &= 0x000fffff;
99258bdb691SMichael Tuexen 			asoc->default_flowlabel |= 0x80000000;
99358bdb691SMichael Tuexen 		} else {
994f8829a4aSRandall Stewart 			asoc->default_flowlabel = 0;
99558bdb691SMichael Tuexen 		}
99658bdb691SMichael Tuexen 	}
997f8829a4aSRandall Stewart #endif
9989f22f500SRandall Stewart 	asoc->sb_send_resv = 0;
999f8829a4aSRandall Stewart 	if (override_tag) {
1000f8829a4aSRandall Stewart 		asoc->my_vtag = override_tag;
1001f8829a4aSRandall Stewart 	} else {
1002a1cb341bSMichael Tuexen 		asoc->my_vtag = sctp_select_a_tag(inp, stcb->sctp_ep->sctp_lport, stcb->rport, 1);
1003f8829a4aSRandall Stewart 	}
1004de0e935bSRandall Stewart 	/* Get the nonce tags */
1005a1cb341bSMichael Tuexen 	asoc->my_vtag_nonce = sctp_select_a_tag(inp, stcb->sctp_ep->sctp_lport, stcb->rport, 0);
1006a1cb341bSMichael Tuexen 	asoc->peer_vtag_nonce = sctp_select_a_tag(inp, stcb->sctp_ep->sctp_lport, stcb->rport, 0);
100742551e99SRandall Stewart 	asoc->vrf_id = vrf_id;
1008de0e935bSRandall Stewart 
100918e198d3SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
101018e198d3SRandall Stewart 	asoc->tsn_in_at = 0;
101118e198d3SRandall Stewart 	asoc->tsn_out_at = 0;
101218e198d3SRandall Stewart 	asoc->tsn_in_wrapped = 0;
101318e198d3SRandall Stewart 	asoc->tsn_out_wrapped = 0;
101418e198d3SRandall Stewart 	asoc->cumack_log_at = 0;
1015b201f536SRandall Stewart 	asoc->cumack_log_atsnt = 0;
101618e198d3SRandall Stewart #endif
101718e198d3SRandall Stewart #ifdef SCTP_FS_SPEC_LOG
101818e198d3SRandall Stewart 	asoc->fs_index = 0;
101918e198d3SRandall Stewart #endif
1020f8829a4aSRandall Stewart 	asoc->refcnt = 0;
1021f8829a4aSRandall Stewart 	asoc->assoc_up_sent = 0;
1022f8829a4aSRandall Stewart 	asoc->asconf_seq_out = asoc->str_reset_seq_out = asoc->init_seq_number = asoc->sending_seq =
1023a1cb341bSMichael Tuexen 	    sctp_select_initial_TSN(&inp->sctp_ep);
1024c54a18d2SRandall Stewart 	asoc->asconf_seq_out_acked = asoc->asconf_seq_out - 1;
1025f8829a4aSRandall Stewart 	/* we are optimisitic here */
1026830d754dSRandall Stewart 	asoc->peer_supports_nat = 0;
1027f8829a4aSRandall Stewart 	asoc->sent_queue_retran_cnt = 0;
1028f8829a4aSRandall Stewart 
1029f8829a4aSRandall Stewart 	/* for CMT */
10308933fa13SRandall Stewart 	asoc->last_net_cmt_send_started = NULL;
1031f8829a4aSRandall Stewart 
1032f8829a4aSRandall Stewart 	/* This will need to be adjusted */
1033f8829a4aSRandall Stewart 	asoc->last_acked_seq = asoc->init_seq_number - 1;
1034f8829a4aSRandall Stewart 	asoc->advanced_peer_ack_point = asoc->last_acked_seq;
1035f8829a4aSRandall Stewart 	asoc->asconf_seq_in = asoc->last_acked_seq;
1036f8829a4aSRandall Stewart 
1037f8829a4aSRandall Stewart 	/* here we are different, we hold the next one we expect */
1038f8829a4aSRandall Stewart 	asoc->str_reset_seq_in = asoc->last_acked_seq + 1;
1039f8829a4aSRandall Stewart 
1040a1cb341bSMichael Tuexen 	asoc->initial_init_rto_max = inp->sctp_ep.initial_init_rto_max;
1041a1cb341bSMichael Tuexen 	asoc->initial_rto = inp->sctp_ep.initial_rto;
1042f8829a4aSRandall Stewart 
1043a1cb341bSMichael Tuexen 	asoc->max_init_times = inp->sctp_ep.max_init_times;
1044a1cb341bSMichael Tuexen 	asoc->max_send_times = inp->sctp_ep.max_send_times;
1045a1cb341bSMichael Tuexen 	asoc->def_net_failure = inp->sctp_ep.def_net_failure;
1046a1cb341bSMichael Tuexen 	asoc->def_net_pf_threshold = inp->sctp_ep.def_net_pf_threshold;
1047f8829a4aSRandall Stewart 	asoc->free_chunk_cnt = 0;
1048f8829a4aSRandall Stewart 
1049f8829a4aSRandall Stewart 	asoc->iam_blocking = 0;
1050a1cb341bSMichael Tuexen 	asoc->context = inp->sctp_context;
1051a1cb341bSMichael Tuexen 	asoc->local_strreset_support = inp->local_strreset_support;
1052a1cb341bSMichael Tuexen 	asoc->def_send = inp->def_send;
1053a1cb341bSMichael Tuexen 	asoc->delayed_ack = TICKS_TO_MSEC(inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_RECV]);
1054a1cb341bSMichael Tuexen 	asoc->sack_freq = inp->sctp_ep.sctp_sack_freq;
1055f8829a4aSRandall Stewart 	asoc->pr_sctp_cnt = 0;
1056f8829a4aSRandall Stewart 	asoc->total_output_queue_size = 0;
1057f8829a4aSRandall Stewart 
1058a1cb341bSMichael Tuexen 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) {
1059a1cb341bSMichael Tuexen 		asoc->scope.ipv6_addr_legal = 1;
1060a1cb341bSMichael Tuexen 		if (SCTP_IPV6_V6ONLY(inp) == 0) {
1061a1cb341bSMichael Tuexen 			asoc->scope.ipv4_addr_legal = 1;
1062f8829a4aSRandall Stewart 		} else {
1063a1cb341bSMichael Tuexen 			asoc->scope.ipv4_addr_legal = 0;
1064f8829a4aSRandall Stewart 		}
1065f8829a4aSRandall Stewart 	} else {
1066a1cb341bSMichael Tuexen 		asoc->scope.ipv6_addr_legal = 0;
1067a1cb341bSMichael Tuexen 		asoc->scope.ipv4_addr_legal = 1;
1068f8829a4aSRandall Stewart 	}
1069f8829a4aSRandall Stewart 
1070a1cb341bSMichael Tuexen 	asoc->my_rwnd = max(SCTP_SB_LIMIT_RCV(inp->sctp_socket), SCTP_MINIMAL_RWND);
1071a1cb341bSMichael Tuexen 	asoc->peers_rwnd = SCTP_SB_LIMIT_RCV(inp->sctp_socket);
1072f8829a4aSRandall Stewart 
1073a1cb341bSMichael Tuexen 	asoc->smallest_mtu = inp->sctp_frag_point;
1074a1cb341bSMichael Tuexen 	asoc->minrto = inp->sctp_ep.sctp_minrto;
1075a1cb341bSMichael Tuexen 	asoc->maxrto = inp->sctp_ep.sctp_maxrto;
1076f8829a4aSRandall Stewart 
1077f8829a4aSRandall Stewart 	asoc->locked_on_sending = NULL;
1078f8829a4aSRandall Stewart 	asoc->stream_locked_on = 0;
1079f8829a4aSRandall Stewart 	asoc->ecn_echo_cnt_onq = 0;
1080f8829a4aSRandall Stewart 	asoc->stream_locked = 0;
1081f8829a4aSRandall Stewart 
108242551e99SRandall Stewart 	asoc->send_sack = 1;
108342551e99SRandall Stewart 
108442551e99SRandall Stewart 	LIST_INIT(&asoc->sctp_restricted_addrs);
108542551e99SRandall Stewart 
1086f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->nets);
1087f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->pending_reply_queue);
10882afb3e84SRandall Stewart 	TAILQ_INIT(&asoc->asconf_ack_sent);
1089f8829a4aSRandall Stewart 	/* Setup to fill the hb random cache at first HB */
1090f8829a4aSRandall Stewart 	asoc->hb_random_idx = 4;
1091f8829a4aSRandall Stewart 
1092a1cb341bSMichael Tuexen 	asoc->sctp_autoclose_ticks = inp->sctp_ep.auto_close_time;
1093f8829a4aSRandall Stewart 
1094a1cb341bSMichael Tuexen 	stcb->asoc.congestion_control_module = inp->sctp_ep.sctp_default_cc_module;
1095a1cb341bSMichael Tuexen 	stcb->asoc.cc_functions = sctp_cc_functions[inp->sctp_ep.sctp_default_cc_module];
1096b54d3a6cSRandall Stewart 
1097a1cb341bSMichael Tuexen 	stcb->asoc.stream_scheduling_module = inp->sctp_ep.sctp_default_ss_module;
1098a1cb341bSMichael Tuexen 	stcb->asoc.ss_functions = sctp_ss_functions[inp->sctp_ep.sctp_default_ss_module];
1099f7a77f6fSMichael Tuexen 
1100b54d3a6cSRandall Stewart 	/*
1101f8829a4aSRandall Stewart 	 * Now the stream parameters, here we allocate space for all streams
1102f8829a4aSRandall Stewart 	 * that we request by default.
1103f8829a4aSRandall Stewart 	 */
1104ea44232bSRandall Stewart 	asoc->strm_realoutsize = asoc->streamoutcnt = asoc->pre_open_streams =
1105c979034bSMichael Tuexen 	    o_strms;
1106f8829a4aSRandall Stewart 	SCTP_MALLOC(asoc->strmout, struct sctp_stream_out *,
1107f8829a4aSRandall Stewart 	    asoc->streamoutcnt * sizeof(struct sctp_stream_out),
1108207304d4SRandall Stewart 	    SCTP_M_STRMO);
1109f8829a4aSRandall Stewart 	if (asoc->strmout == NULL) {
1110f8829a4aSRandall Stewart 		/* big trouble no memory */
1111c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
1112f8829a4aSRandall Stewart 		return (ENOMEM);
1113f8829a4aSRandall Stewart 	}
1114f8829a4aSRandall Stewart 	for (i = 0; i < asoc->streamoutcnt; i++) {
1115f8829a4aSRandall Stewart 		/*
1116f8829a4aSRandall Stewart 		 * inbound side must be set to 0xffff, also NOTE when we get
1117f8829a4aSRandall Stewart 		 * the INIT-ACK back (for INIT sender) we MUST reduce the
1118f8829a4aSRandall Stewart 		 * count (streamoutcnt) but first check if we sent to any of
1119f8829a4aSRandall Stewart 		 * the upper streams that were dropped (if some were). Those
1120f8829a4aSRandall Stewart 		 * that were dropped must be notified to the upper layer as
1121f8829a4aSRandall Stewart 		 * failed to send.
1122f8829a4aSRandall Stewart 		 */
1123f3b05218SMichael Tuexen 		asoc->strmout[i].next_sequence_send = 0x0;
1124f8829a4aSRandall Stewart 		TAILQ_INIT(&asoc->strmout[i].outqueue);
1125325c8c46SMichael Tuexen 		asoc->strmout[i].chunks_on_queues = 0;
1126f0396ad1SMichael Tuexen #if defined(SCTP_DETAILED_STR_STATS)
1127f0396ad1SMichael Tuexen 		for (j = 0; j < SCTP_PR_SCTP_MAX + 1; j++) {
1128f0396ad1SMichael Tuexen 			asoc->strmout[i].abandoned_sent[j] = 0;
1129f0396ad1SMichael Tuexen 			asoc->strmout[i].abandoned_unsent[j] = 0;
1130f0396ad1SMichael Tuexen 		}
1131f0396ad1SMichael Tuexen #else
1132f0396ad1SMichael Tuexen 		asoc->strmout[i].abandoned_sent[0] = 0;
1133f0396ad1SMichael Tuexen 		asoc->strmout[i].abandoned_unsent[0] = 0;
1134f0396ad1SMichael Tuexen #endif
1135f8829a4aSRandall Stewart 		asoc->strmout[i].stream_no = i;
1136f8829a4aSRandall Stewart 		asoc->strmout[i].last_msg_incomplete = 0;
11377cca1775SRandall Stewart 		asoc->strmout[i].state = SCTP_STREAM_OPENING;
1138252f7f93SMichael Tuexen 		asoc->ss_functions.sctp_ss_init_stream(&asoc->strmout[i], NULL);
1139f8829a4aSRandall Stewart 	}
1140f7a77f6fSMichael Tuexen 	asoc->ss_functions.sctp_ss_init(stcb, asoc, 0);
1141f7a77f6fSMichael Tuexen 
1142f8829a4aSRandall Stewart 	/* Now the mapping array */
1143f8829a4aSRandall Stewart 	asoc->mapping_array_size = SCTP_INITIAL_MAPPING_ARRAY;
1144f8829a4aSRandall Stewart 	SCTP_MALLOC(asoc->mapping_array, uint8_t *, asoc->mapping_array_size,
1145207304d4SRandall Stewart 	    SCTP_M_MAP);
1146f8829a4aSRandall Stewart 	if (asoc->mapping_array == NULL) {
1147207304d4SRandall Stewart 		SCTP_FREE(asoc->strmout, SCTP_M_STRMO);
1148c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
1149f8829a4aSRandall Stewart 		return (ENOMEM);
1150f8829a4aSRandall Stewart 	}
1151f8829a4aSRandall Stewart 	memset(asoc->mapping_array, 0, asoc->mapping_array_size);
1152b5c16493SMichael Tuexen 	SCTP_MALLOC(asoc->nr_mapping_array, uint8_t *, asoc->mapping_array_size,
1153830d754dSRandall Stewart 	    SCTP_M_MAP);
1154bf1be571SRandall Stewart 	if (asoc->nr_mapping_array == NULL) {
1155bf1be571SRandall Stewart 		SCTP_FREE(asoc->strmout, SCTP_M_STRMO);
1156bf1be571SRandall Stewart 		SCTP_FREE(asoc->mapping_array, SCTP_M_MAP);
1157bf1be571SRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
1158bf1be571SRandall Stewart 		return (ENOMEM);
1159bf1be571SRandall Stewart 	}
1160b5c16493SMichael Tuexen 	memset(asoc->nr_mapping_array, 0, asoc->mapping_array_size);
1161830d754dSRandall Stewart 
1162f8829a4aSRandall Stewart 	/* Now the init of the other outqueues */
1163f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->free_chunks);
1164f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->control_send_queue);
1165c54a18d2SRandall Stewart 	TAILQ_INIT(&asoc->asconf_send_queue);
1166f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->send_queue);
1167f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->sent_queue);
1168f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->resetHead);
1169a1cb341bSMichael Tuexen 	asoc->max_inbound_streams = inp->sctp_ep.max_open_streams_intome;
1170f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->asconf_queue);
1171f8829a4aSRandall Stewart 	/* authentication fields */
1172f8829a4aSRandall Stewart 	asoc->authinfo.random = NULL;
1173830d754dSRandall Stewart 	asoc->authinfo.active_keyid = 0;
1174f8829a4aSRandall Stewart 	asoc->authinfo.assoc_key = NULL;
1175f8829a4aSRandall Stewart 	asoc->authinfo.assoc_keyid = 0;
1176f8829a4aSRandall Stewart 	asoc->authinfo.recv_key = NULL;
1177f8829a4aSRandall Stewart 	asoc->authinfo.recv_keyid = 0;
1178f8829a4aSRandall Stewart 	LIST_INIT(&asoc->shared_keys);
1179f42a358aSRandall Stewart 	asoc->marked_retrans = 0;
1180a1cb341bSMichael Tuexen 	asoc->port = inp->sctp_ep.port;
1181f42a358aSRandall Stewart 	asoc->timoinit = 0;
1182f42a358aSRandall Stewart 	asoc->timodata = 0;
1183f42a358aSRandall Stewart 	asoc->timosack = 0;
1184f42a358aSRandall Stewart 	asoc->timoshutdown = 0;
1185f42a358aSRandall Stewart 	asoc->timoheartbeat = 0;
1186f42a358aSRandall Stewart 	asoc->timocookie = 0;
1187f42a358aSRandall Stewart 	asoc->timoshutdownack = 0;
11886e55db54SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&asoc->start_time);
11896e55db54SRandall Stewart 	asoc->discontinuity_time = asoc->start_time;
1190f0396ad1SMichael Tuexen 	for (i = 0; i < SCTP_PR_SCTP_MAX + 1; i++) {
1191f0396ad1SMichael Tuexen 		asoc->abandoned_unsent[i] = 0;
1192f0396ad1SMichael Tuexen 		asoc->abandoned_sent[i] = 0;
1193f0396ad1SMichael Tuexen 	}
1194eacc51c5SRandall Stewart 	/*
1195eacc51c5SRandall Stewart 	 * sa_ignore MEMLEAK {memory is put in the assoc mapping array and
119677acdc25SRandall Stewart 	 * freed later when the association is freed.
1197eacc51c5SRandall Stewart 	 */
1198f8829a4aSRandall Stewart 	return (0);
1199f8829a4aSRandall Stewart }
1200f8829a4aSRandall Stewart 
12010e13104dSRandall Stewart void
12020e13104dSRandall Stewart sctp_print_mapping_array(struct sctp_association *asoc)
12030e13104dSRandall Stewart {
1204aed5947cSMichael Tuexen 	unsigned int i, limit;
12050e13104dSRandall Stewart 
1206cd3fd531SMichael Tuexen 	SCTP_PRINTF("Mapping array size: %d, baseTSN: %8.8x, cumAck: %8.8x, highestTSN: (%8.8x, %8.8x).\n",
12070e13104dSRandall Stewart 	    asoc->mapping_array_size,
12080e13104dSRandall Stewart 	    asoc->mapping_array_base_tsn,
12090e13104dSRandall Stewart 	    asoc->cumulative_tsn,
1210aed5947cSMichael Tuexen 	    asoc->highest_tsn_inside_map,
1211aed5947cSMichael Tuexen 	    asoc->highest_tsn_inside_nr_map);
1212aed5947cSMichael Tuexen 	for (limit = asoc->mapping_array_size; limit > 1; limit--) {
121360990c0cSMichael Tuexen 		if (asoc->mapping_array[limit - 1] != 0) {
121477acdc25SRandall Stewart 			break;
121577acdc25SRandall Stewart 		}
121677acdc25SRandall Stewart 	}
1217cd3fd531SMichael Tuexen 	SCTP_PRINTF("Renegable mapping array (last %d entries are zero):\n", asoc->mapping_array_size - limit);
121877acdc25SRandall Stewart 	for (i = 0; i < limit; i++) {
1219cd3fd531SMichael Tuexen 		SCTP_PRINTF("%2.2x%c", asoc->mapping_array[i], ((i + 1) % 16) ? ' ' : '\n');
122077acdc25SRandall Stewart 	}
1221aed5947cSMichael Tuexen 	if (limit % 16)
1222cd3fd531SMichael Tuexen 		SCTP_PRINTF("\n");
1223aed5947cSMichael Tuexen 	for (limit = asoc->mapping_array_size; limit > 1; limit--) {
1224aed5947cSMichael Tuexen 		if (asoc->nr_mapping_array[limit - 1]) {
122577acdc25SRandall Stewart 			break;
122677acdc25SRandall Stewart 		}
122777acdc25SRandall Stewart 	}
1228cd3fd531SMichael Tuexen 	SCTP_PRINTF("Non renegable mapping array (last %d entries are zero):\n", asoc->mapping_array_size - limit);
122977acdc25SRandall Stewart 	for (i = 0; i < limit; i++) {
1230cd3fd531SMichael Tuexen 		SCTP_PRINTF("%2.2x%c", asoc->nr_mapping_array[i], ((i + 1) % 16) ? ' ' : '\n');
12310e13104dSRandall Stewart 	}
1232aed5947cSMichael Tuexen 	if (limit % 16)
1233cd3fd531SMichael Tuexen 		SCTP_PRINTF("\n");
12340e13104dSRandall Stewart }
12350e13104dSRandall Stewart 
1236f8829a4aSRandall Stewart int
12370696e120SRandall Stewart sctp_expand_mapping_array(struct sctp_association *asoc, uint32_t needed)
1238f8829a4aSRandall Stewart {
1239f8829a4aSRandall Stewart 	/* mapping array needs to grow */
1240b5c16493SMichael Tuexen 	uint8_t *new_array1, *new_array2;
12410696e120SRandall Stewart 	uint32_t new_size;
1242f8829a4aSRandall Stewart 
12430696e120SRandall Stewart 	new_size = asoc->mapping_array_size + ((needed + 7) / 8 + SCTP_MAPPING_ARRAY_INCR);
1244b5c16493SMichael Tuexen 	SCTP_MALLOC(new_array1, uint8_t *, new_size, SCTP_M_MAP);
1245b5c16493SMichael Tuexen 	SCTP_MALLOC(new_array2, uint8_t *, new_size, SCTP_M_MAP);
1246b5c16493SMichael Tuexen 	if ((new_array1 == NULL) || (new_array2 == NULL)) {
1247f8829a4aSRandall Stewart 		/* can't get more, forget it */
1248b5c16493SMichael Tuexen 		SCTP_PRINTF("No memory for expansion of SCTP mapping array %d\n", new_size);
1249b5c16493SMichael Tuexen 		if (new_array1) {
1250b5c16493SMichael Tuexen 			SCTP_FREE(new_array1, SCTP_M_MAP);
1251b5c16493SMichael Tuexen 		}
1252b5c16493SMichael Tuexen 		if (new_array2) {
1253b5c16493SMichael Tuexen 			SCTP_FREE(new_array2, SCTP_M_MAP);
1254b5c16493SMichael Tuexen 		}
1255f8829a4aSRandall Stewart 		return (-1);
1256f8829a4aSRandall Stewart 	}
1257b5c16493SMichael Tuexen 	memset(new_array1, 0, new_size);
1258b5c16493SMichael Tuexen 	memset(new_array2, 0, new_size);
1259b5c16493SMichael Tuexen 	memcpy(new_array1, asoc->mapping_array, asoc->mapping_array_size);
1260b5c16493SMichael Tuexen 	memcpy(new_array2, asoc->nr_mapping_array, asoc->mapping_array_size);
1261207304d4SRandall Stewart 	SCTP_FREE(asoc->mapping_array, SCTP_M_MAP);
1262830d754dSRandall Stewart 	SCTP_FREE(asoc->nr_mapping_array, SCTP_M_MAP);
1263b5c16493SMichael Tuexen 	asoc->mapping_array = new_array1;
1264b5c16493SMichael Tuexen 	asoc->nr_mapping_array = new_array2;
1265b5c16493SMichael Tuexen 	asoc->mapping_array_size = new_size;
1266830d754dSRandall Stewart 	return (0);
1267830d754dSRandall Stewart }
1268830d754dSRandall Stewart 
12698933fa13SRandall Stewart 
127042551e99SRandall Stewart static void
127142551e99SRandall Stewart sctp_iterator_work(struct sctp_iterator *it)
127242551e99SRandall Stewart {
127342551e99SRandall Stewart 	int iteration_count = 0;
127442551e99SRandall Stewart 	int inp_skip = 0;
1275ec4c19fcSRandall Stewart 	int first_in = 1;
1276ec4c19fcSRandall Stewart 	struct sctp_inpcb *tinp;
127742551e99SRandall Stewart 
1278ec4c19fcSRandall Stewart 	SCTP_INP_INFO_RLOCK();
127942551e99SRandall Stewart 	SCTP_ITERATOR_LOCK();
1280ad81507eSRandall Stewart 	if (it->inp) {
1281ec4c19fcSRandall Stewart 		SCTP_INP_RLOCK(it->inp);
128242551e99SRandall Stewart 		SCTP_INP_DECR_REF(it->inp);
1283ad81507eSRandall Stewart 	}
128442551e99SRandall Stewart 	if (it->inp == NULL) {
128542551e99SRandall Stewart 		/* iterator is complete */
128642551e99SRandall Stewart done_with_iterator:
128742551e99SRandall Stewart 		SCTP_ITERATOR_UNLOCK();
1288ec4c19fcSRandall Stewart 		SCTP_INP_INFO_RUNLOCK();
128942551e99SRandall Stewart 		if (it->function_atend != NULL) {
129042551e99SRandall Stewart 			(*it->function_atend) (it->pointer, it->val);
129142551e99SRandall Stewart 		}
1292207304d4SRandall Stewart 		SCTP_FREE(it, SCTP_M_ITER);
129342551e99SRandall Stewart 		return;
129442551e99SRandall Stewart 	}
129542551e99SRandall Stewart select_a_new_ep:
1296ec4c19fcSRandall Stewart 	if (first_in) {
1297ec4c19fcSRandall Stewart 		first_in = 0;
1298ec4c19fcSRandall Stewart 	} else {
1299f7517433SRandall Stewart 		SCTP_INP_RLOCK(it->inp);
1300ec4c19fcSRandall Stewart 	}
130142551e99SRandall Stewart 	while (((it->pcb_flags) &&
130242551e99SRandall Stewart 	    ((it->inp->sctp_flags & it->pcb_flags) != it->pcb_flags)) ||
130342551e99SRandall Stewart 	    ((it->pcb_features) &&
130442551e99SRandall Stewart 	    ((it->inp->sctp_features & it->pcb_features) != it->pcb_features))) {
130542551e99SRandall Stewart 		/* endpoint flags or features don't match, so keep looking */
130642551e99SRandall Stewart 		if (it->iterator_flags & SCTP_ITERATOR_DO_SINGLE_INP) {
1307f7517433SRandall Stewart 			SCTP_INP_RUNLOCK(it->inp);
130842551e99SRandall Stewart 			goto done_with_iterator;
130942551e99SRandall Stewart 		}
1310ec4c19fcSRandall Stewart 		tinp = it->inp;
131142551e99SRandall Stewart 		it->inp = LIST_NEXT(it->inp, sctp_list);
1312ec4c19fcSRandall Stewart 		SCTP_INP_RUNLOCK(tinp);
131342551e99SRandall Stewart 		if (it->inp == NULL) {
131442551e99SRandall Stewart 			goto done_with_iterator;
131542551e99SRandall Stewart 		}
131642551e99SRandall Stewart 		SCTP_INP_RLOCK(it->inp);
1317f7517433SRandall Stewart 	}
131842551e99SRandall Stewart 	/* now go through each assoc which is in the desired state */
131942551e99SRandall Stewart 	if (it->done_current_ep == 0) {
132042551e99SRandall Stewart 		if (it->function_inp != NULL)
132142551e99SRandall Stewart 			inp_skip = (*it->function_inp) (it->inp, it->pointer, it->val);
132242551e99SRandall Stewart 		it->done_current_ep = 1;
132342551e99SRandall Stewart 	}
132442551e99SRandall Stewart 	if (it->stcb == NULL) {
132542551e99SRandall Stewart 		/* run the per instance function */
132642551e99SRandall Stewart 		it->stcb = LIST_FIRST(&it->inp->sctp_asoc_list);
132742551e99SRandall Stewart 	}
132842551e99SRandall Stewart 	if ((inp_skip) || it->stcb == NULL) {
132942551e99SRandall Stewart 		if (it->function_inp_end != NULL) {
133042551e99SRandall Stewart 			inp_skip = (*it->function_inp_end) (it->inp,
133142551e99SRandall Stewart 			    it->pointer,
133242551e99SRandall Stewart 			    it->val);
133342551e99SRandall Stewart 		}
133442551e99SRandall Stewart 		SCTP_INP_RUNLOCK(it->inp);
133542551e99SRandall Stewart 		goto no_stcb;
133642551e99SRandall Stewart 	}
133742551e99SRandall Stewart 	while (it->stcb) {
133842551e99SRandall Stewart 		SCTP_TCB_LOCK(it->stcb);
133942551e99SRandall Stewart 		if (it->asoc_state && ((it->stcb->asoc.state & it->asoc_state) != it->asoc_state)) {
134042551e99SRandall Stewart 			/* not in the right state... keep looking */
134142551e99SRandall Stewart 			SCTP_TCB_UNLOCK(it->stcb);
134242551e99SRandall Stewart 			goto next_assoc;
134342551e99SRandall Stewart 		}
134442551e99SRandall Stewart 		/* see if we have limited out the iterator loop */
134542551e99SRandall Stewart 		iteration_count++;
134642551e99SRandall Stewart 		if (iteration_count > SCTP_ITERATOR_MAX_AT_ONCE) {
134742551e99SRandall Stewart 			/* Pause to let others grab the lock */
134842551e99SRandall Stewart 			atomic_add_int(&it->stcb->asoc.refcnt, 1);
134942551e99SRandall Stewart 			SCTP_TCB_UNLOCK(it->stcb);
1350c4739e2fSRandall Stewart 			SCTP_INP_INCR_REF(it->inp);
135142551e99SRandall Stewart 			SCTP_INP_RUNLOCK(it->inp);
135242551e99SRandall Stewart 			SCTP_ITERATOR_UNLOCK();
1353ec4c19fcSRandall Stewart 			SCTP_INP_INFO_RUNLOCK();
1354ec4c19fcSRandall Stewart 			SCTP_INP_INFO_RLOCK();
135542551e99SRandall Stewart 			SCTP_ITERATOR_LOCK();
1356f7517433SRandall Stewart 			if (sctp_it_ctl.iterator_flags) {
1357f7517433SRandall Stewart 				/* We won't be staying here */
1358f7517433SRandall Stewart 				SCTP_INP_DECR_REF(it->inp);
1359f7517433SRandall Stewart 				atomic_add_int(&it->stcb->asoc.refcnt, -1);
1360f7517433SRandall Stewart 				if (sctp_it_ctl.iterator_flags &
1361f7517433SRandall Stewart 				    SCTP_ITERATOR_STOP_CUR_IT) {
1362f7517433SRandall Stewart 					sctp_it_ctl.iterator_flags &= ~SCTP_ITERATOR_STOP_CUR_IT;
1363f7517433SRandall Stewart 					goto done_with_iterator;
1364f7517433SRandall Stewart 				}
1365f7517433SRandall Stewart 				if (sctp_it_ctl.iterator_flags &
1366f7517433SRandall Stewart 				    SCTP_ITERATOR_STOP_CUR_INP) {
1367f7517433SRandall Stewart 					sctp_it_ctl.iterator_flags &= ~SCTP_ITERATOR_STOP_CUR_INP;
1368f7517433SRandall Stewart 					goto no_stcb;
1369f7517433SRandall Stewart 				}
1370f7517433SRandall Stewart 				/* If we reach here huh? */
1371cd3fd531SMichael Tuexen 				SCTP_PRINTF("Unknown it ctl flag %x\n",
1372f7517433SRandall Stewart 				    sctp_it_ctl.iterator_flags);
1373f7517433SRandall Stewart 				sctp_it_ctl.iterator_flags = 0;
1374f7517433SRandall Stewart 			}
137542551e99SRandall Stewart 			SCTP_INP_RLOCK(it->inp);
1376c4739e2fSRandall Stewart 			SCTP_INP_DECR_REF(it->inp);
137742551e99SRandall Stewart 			SCTP_TCB_LOCK(it->stcb);
137842551e99SRandall Stewart 			atomic_add_int(&it->stcb->asoc.refcnt, -1);
137942551e99SRandall Stewart 			iteration_count = 0;
138042551e99SRandall Stewart 		}
138142551e99SRandall Stewart 		/* run function on this one */
138242551e99SRandall Stewart 		(*it->function_assoc) (it->inp, it->stcb, it->pointer, it->val);
138342551e99SRandall Stewart 
138442551e99SRandall Stewart 		/*
138542551e99SRandall Stewart 		 * we lie here, it really needs to have its own type but
138642551e99SRandall Stewart 		 * first I must verify that this won't effect things :-0
138742551e99SRandall Stewart 		 */
138842551e99SRandall Stewart 		if (it->no_chunk_output == 0)
1389ceaad40aSRandall Stewart 			sctp_chunk_output(it->inp, it->stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
139042551e99SRandall Stewart 
139142551e99SRandall Stewart 		SCTP_TCB_UNLOCK(it->stcb);
139242551e99SRandall Stewart next_assoc:
139342551e99SRandall Stewart 		it->stcb = LIST_NEXT(it->stcb, sctp_tcblist);
139442551e99SRandall Stewart 		if (it->stcb == NULL) {
139542551e99SRandall Stewart 			/* Run last function */
139642551e99SRandall Stewart 			if (it->function_inp_end != NULL) {
139742551e99SRandall Stewart 				inp_skip = (*it->function_inp_end) (it->inp,
139842551e99SRandall Stewart 				    it->pointer,
139942551e99SRandall Stewart 				    it->val);
140042551e99SRandall Stewart 			}
140142551e99SRandall Stewart 		}
140242551e99SRandall Stewart 	}
140342551e99SRandall Stewart 	SCTP_INP_RUNLOCK(it->inp);
140442551e99SRandall Stewart no_stcb:
140542551e99SRandall Stewart 	/* done with all assocs on this endpoint, move on to next endpoint */
140642551e99SRandall Stewart 	it->done_current_ep = 0;
140742551e99SRandall Stewart 	if (it->iterator_flags & SCTP_ITERATOR_DO_SINGLE_INP) {
140842551e99SRandall Stewart 		it->inp = NULL;
140942551e99SRandall Stewart 	} else {
141042551e99SRandall Stewart 		it->inp = LIST_NEXT(it->inp, sctp_list);
141142551e99SRandall Stewart 	}
141242551e99SRandall Stewart 	if (it->inp == NULL) {
141342551e99SRandall Stewart 		goto done_with_iterator;
141442551e99SRandall Stewart 	}
141542551e99SRandall Stewart 	goto select_a_new_ep;
141642551e99SRandall Stewart }
141742551e99SRandall Stewart 
141842551e99SRandall Stewart void
141942551e99SRandall Stewart sctp_iterator_worker(void)
142042551e99SRandall Stewart {
14214a9ef3f8SMichael Tuexen 	struct sctp_iterator *it, *nit;
142242551e99SRandall Stewart 
142342551e99SRandall Stewart 	/* This function is called with the WQ lock in place */
142442551e99SRandall Stewart 
1425f7517433SRandall Stewart 	sctp_it_ctl.iterator_running = 1;
14264a9ef3f8SMichael Tuexen 	TAILQ_FOREACH_SAFE(it, &sctp_it_ctl.iteratorhead, sctp_nxt_itr, nit) {
14274a9ef3f8SMichael Tuexen 		sctp_it_ctl.cur_it = it;
142842551e99SRandall Stewart 		/* now lets work on this one */
1429f7517433SRandall Stewart 		TAILQ_REMOVE(&sctp_it_ctl.iteratorhead, it, sctp_nxt_itr);
143042551e99SRandall Stewart 		SCTP_IPI_ITERATOR_WQ_UNLOCK();
1431f7517433SRandall Stewart 		CURVNET_SET(it->vn);
143242551e99SRandall Stewart 		sctp_iterator_work(it);
1433f79aab18SRandall Stewart 		sctp_it_ctl.cur_it = NULL;
1434f7517433SRandall Stewart 		CURVNET_RESTORE();
143542551e99SRandall Stewart 		SCTP_IPI_ITERATOR_WQ_LOCK();
14363c503c28SRandall Stewart 		/* sa_ignore FREED_MEMORY */
143742551e99SRandall Stewart 	}
1438f7517433SRandall Stewart 	sctp_it_ctl.iterator_running = 0;
143942551e99SRandall Stewart 	return;
144042551e99SRandall Stewart }
144142551e99SRandall Stewart 
1442f8829a4aSRandall Stewart 
1443f8829a4aSRandall Stewart static void
1444f8829a4aSRandall Stewart sctp_handle_addr_wq(void)
1445f8829a4aSRandall Stewart {
1446f8829a4aSRandall Stewart 	/* deal with the ADDR wq from the rtsock calls */
14474a9ef3f8SMichael Tuexen 	struct sctp_laddr *wi, *nwi;
144842551e99SRandall Stewart 	struct sctp_asconf_iterator *asc;
1449f8829a4aSRandall Stewart 
145042551e99SRandall Stewart 	SCTP_MALLOC(asc, struct sctp_asconf_iterator *,
1451207304d4SRandall Stewart 	    sizeof(struct sctp_asconf_iterator), SCTP_M_ASC_IT);
145242551e99SRandall Stewart 	if (asc == NULL) {
145342551e99SRandall Stewart 		/* Try later, no memory */
1454f8829a4aSRandall Stewart 		sctp_timer_start(SCTP_TIMER_TYPE_ADDR_WQ,
1455f8829a4aSRandall Stewart 		    (struct sctp_inpcb *)NULL,
1456f8829a4aSRandall Stewart 		    (struct sctp_tcb *)NULL,
1457f8829a4aSRandall Stewart 		    (struct sctp_nets *)NULL);
145842551e99SRandall Stewart 		return;
1459f8829a4aSRandall Stewart 	}
146042551e99SRandall Stewart 	LIST_INIT(&asc->list_of_work);
146142551e99SRandall Stewart 	asc->cnt = 0;
1462f7517433SRandall Stewart 
1463f7517433SRandall Stewart 	SCTP_WQ_ADDR_LOCK();
14644a9ef3f8SMichael Tuexen 	LIST_FOREACH_SAFE(wi, &SCTP_BASE_INFO(addr_wq), sctp_nxt_addr, nwi) {
146542551e99SRandall Stewart 		LIST_REMOVE(wi, sctp_nxt_addr);
146642551e99SRandall Stewart 		LIST_INSERT_HEAD(&asc->list_of_work, wi, sctp_nxt_addr);
146742551e99SRandall Stewart 		asc->cnt++;
1468f8829a4aSRandall Stewart 	}
1469f7517433SRandall Stewart 	SCTP_WQ_ADDR_UNLOCK();
1470f7517433SRandall Stewart 
147142551e99SRandall Stewart 	if (asc->cnt == 0) {
1472207304d4SRandall Stewart 		SCTP_FREE(asc, SCTP_M_ASC_IT);
147342551e99SRandall Stewart 	} else {
14742b1c7de4SMichael Tuexen 		int ret;
14752b1c7de4SMichael Tuexen 
14762b1c7de4SMichael Tuexen 		ret = sctp_initiate_iterator(sctp_asconf_iterator_ep,
14771b649582SRandall Stewart 		    sctp_asconf_iterator_stcb,
147842551e99SRandall Stewart 		    NULL,	/* No ep end for boundall */
147942551e99SRandall Stewart 		    SCTP_PCB_FLAGS_BOUNDALL,
148042551e99SRandall Stewart 		    SCTP_PCB_ANY_FEATURES,
14811b649582SRandall Stewart 		    SCTP_ASOC_ANY_STATE,
14821b649582SRandall Stewart 		    (void *)asc, 0,
14831b649582SRandall Stewart 		    sctp_asconf_iterator_end, NULL, 0);
14842b1c7de4SMichael Tuexen 		if (ret) {
14852b1c7de4SMichael Tuexen 			SCTP_PRINTF("Failed to initiate iterator for handle_addr_wq\n");
1486467f0d55SMichael Tuexen 			/*
1487467f0d55SMichael Tuexen 			 * Freeing if we are stopping or put back on the
1488467f0d55SMichael Tuexen 			 * addr_wq.
1489467f0d55SMichael Tuexen 			 */
14902b1c7de4SMichael Tuexen 			if (SCTP_BASE_VAR(sctp_pcb_initialized) == 0) {
14912b1c7de4SMichael Tuexen 				sctp_asconf_iterator_end(asc, 0);
14922b1c7de4SMichael Tuexen 			} else {
14932b1c7de4SMichael Tuexen 				SCTP_WQ_ADDR_LOCK();
14942b1c7de4SMichael Tuexen 				LIST_FOREACH(wi, &asc->list_of_work, sctp_nxt_addr) {
14952b1c7de4SMichael Tuexen 					LIST_INSERT_HEAD(&SCTP_BASE_INFO(addr_wq), wi, sctp_nxt_addr);
14962b1c7de4SMichael Tuexen 				}
14972b1c7de4SMichael Tuexen 				SCTP_WQ_ADDR_UNLOCK();
14982b1c7de4SMichael Tuexen 				SCTP_FREE(asc, SCTP_M_ASC_IT);
14992b1c7de4SMichael Tuexen 			}
15002b1c7de4SMichael Tuexen 		}
150142551e99SRandall Stewart 	}
1502f8829a4aSRandall Stewart }
1503f8829a4aSRandall Stewart 
1504f8829a4aSRandall Stewart void
1505f8829a4aSRandall Stewart sctp_timeout_handler(void *t)
1506f8829a4aSRandall Stewart {
1507f8829a4aSRandall Stewart 	struct sctp_inpcb *inp;
1508f8829a4aSRandall Stewart 	struct sctp_tcb *stcb;
1509f8829a4aSRandall Stewart 	struct sctp_nets *net;
1510f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
1511267dbe63SMichael Tuexen 	struct mbuf *op_err;
1512ceaad40aSRandall Stewart 
1513ceaad40aSRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
1514ceaad40aSRandall Stewart 	struct socket *so;
1515ceaad40aSRandall Stewart 
1516ceaad40aSRandall Stewart #endif
1517548f47a8SMichael Tuexen 	int did_output;
1518fa89f692SMichael Tuexen 	int type;
1519f8829a4aSRandall Stewart 
1520f8829a4aSRandall Stewart 	tmr = (struct sctp_timer *)t;
1521f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)tmr->ep;
1522f8829a4aSRandall Stewart 	stcb = (struct sctp_tcb *)tmr->tcb;
1523f8829a4aSRandall Stewart 	net = (struct sctp_nets *)tmr->net;
15248518270eSMichael Tuexen 	CURVNET_SET((struct vnet *)tmr->vnet);
1525f8829a4aSRandall Stewart 	did_output = 1;
1526f8829a4aSRandall Stewart 
1527f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1528f8829a4aSRandall Stewart 	sctp_audit_log(0xF0, (uint8_t) tmr->type);
1529f8829a4aSRandall Stewart 	sctp_auditing(3, inp, stcb, net);
1530f8829a4aSRandall Stewart #endif
1531f8829a4aSRandall Stewart 
1532f8829a4aSRandall Stewart 	/* sanity checks... */
1533f8829a4aSRandall Stewart 	if (tmr->self != (void *)tmr) {
1534f8829a4aSRandall Stewart 		/*
1535ad81507eSRandall Stewart 		 * SCTP_PRINTF("Stale SCTP timer fired (%p), ignoring...\n",
1536dd294dceSMichael Tuexen 		 * (void *)tmr);
1537f8829a4aSRandall Stewart 		 */
15388518270eSMichael Tuexen 		CURVNET_RESTORE();
1539f8829a4aSRandall Stewart 		return;
1540f8829a4aSRandall Stewart 	}
1541a5d547adSRandall Stewart 	tmr->stopped_from = 0xa001;
1542f8829a4aSRandall Stewart 	if (!SCTP_IS_TIMER_TYPE_VALID(tmr->type)) {
1543f8829a4aSRandall Stewart 		/*
1544ad81507eSRandall Stewart 		 * SCTP_PRINTF("SCTP timer fired with invalid type: 0x%x\n",
1545f8829a4aSRandall Stewart 		 * tmr->type);
1546f8829a4aSRandall Stewart 		 */
15478518270eSMichael Tuexen 		CURVNET_RESTORE();
1548f8829a4aSRandall Stewart 		return;
1549f8829a4aSRandall Stewart 	}
1550a5d547adSRandall Stewart 	tmr->stopped_from = 0xa002;
1551f8829a4aSRandall Stewart 	if ((tmr->type != SCTP_TIMER_TYPE_ADDR_WQ) && (inp == NULL)) {
15528518270eSMichael Tuexen 		CURVNET_RESTORE();
1553f8829a4aSRandall Stewart 		return;
1554f8829a4aSRandall Stewart 	}
1555f8829a4aSRandall Stewart 	/* if this is an iterator timeout, get the struct and clear inp */
1556a5d547adSRandall Stewart 	tmr->stopped_from = 0xa003;
1557f8829a4aSRandall Stewart 	if (inp) {
1558f8829a4aSRandall Stewart 		SCTP_INP_INCR_REF(inp);
1559aa1808b7SMichael Tuexen 		if ((inp->sctp_socket == NULL) &&
1560f8829a4aSRandall Stewart 		    ((tmr->type != SCTP_TIMER_TYPE_INPKILL) &&
1561810ec536SMichael Tuexen 		    (tmr->type != SCTP_TIMER_TYPE_INIT) &&
1562a1e13272SRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_SEND) &&
1563a1e13272SRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_RECV) &&
1564a1e13272SRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_HEARTBEAT) &&
1565f8829a4aSRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_SHUTDOWN) &&
1566f8829a4aSRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_SHUTDOWNACK) &&
1567f8829a4aSRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_SHUTDOWNGUARD) &&
1568f8829a4aSRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_ASOCKILL))
1569f8829a4aSRandall Stewart 		    ) {
1570f8829a4aSRandall Stewart 			SCTP_INP_DECR_REF(inp);
15718518270eSMichael Tuexen 			CURVNET_RESTORE();
1572f8829a4aSRandall Stewart 			return;
1573f8829a4aSRandall Stewart 		}
1574f8829a4aSRandall Stewart 	}
1575a5d547adSRandall Stewart 	tmr->stopped_from = 0xa004;
1576f8829a4aSRandall Stewart 	if (stcb) {
1577c105859eSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
1578f8829a4aSRandall Stewart 		if (stcb->asoc.state == 0) {
1579c105859eSRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, -1);
1580f8829a4aSRandall Stewart 			if (inp) {
1581f8829a4aSRandall Stewart 				SCTP_INP_DECR_REF(inp);
1582f8829a4aSRandall Stewart 			}
15838518270eSMichael Tuexen 			CURVNET_RESTORE();
1584f8829a4aSRandall Stewart 			return;
1585f8829a4aSRandall Stewart 		}
1586f8829a4aSRandall Stewart 	}
1587fa89f692SMichael Tuexen 	type = tmr->type;
1588a5d547adSRandall Stewart 	tmr->stopped_from = 0xa005;
1589fa89f692SMichael Tuexen 	SCTPDBG(SCTP_DEBUG_TIMER1, "Timer type %d goes off\n", type);
1590139bc87fSRandall Stewart 	if (!SCTP_OS_TIMER_ACTIVE(&tmr->timer)) {
1591f8829a4aSRandall Stewart 		if (inp) {
1592f8829a4aSRandall Stewart 			SCTP_INP_DECR_REF(inp);
1593f8829a4aSRandall Stewart 		}
1594207304d4SRandall Stewart 		if (stcb) {
1595207304d4SRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, -1);
1596207304d4SRandall Stewart 		}
15978518270eSMichael Tuexen 		CURVNET_RESTORE();
1598f8829a4aSRandall Stewart 		return;
1599f8829a4aSRandall Stewart 	}
1600a5d547adSRandall Stewart 	tmr->stopped_from = 0xa006;
1601a5d547adSRandall Stewart 
1602f8829a4aSRandall Stewart 	if (stcb) {
1603f8829a4aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
160450cec919SRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, -1);
1605fa89f692SMichael Tuexen 		if ((type != SCTP_TIMER_TYPE_ASOCKILL) &&
1606b54d3a6cSRandall Stewart 		    ((stcb->asoc.state == 0) ||
1607b54d3a6cSRandall Stewart 		    (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED))) {
1608b54d3a6cSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
1609b54d3a6cSRandall Stewart 			if (inp) {
1610b54d3a6cSRandall Stewart 				SCTP_INP_DECR_REF(inp);
1611b54d3a6cSRandall Stewart 			}
16128518270eSMichael Tuexen 			CURVNET_RESTORE();
1613b54d3a6cSRandall Stewart 			return;
1614b54d3a6cSRandall Stewart 		}
1615f8829a4aSRandall Stewart 	}
161644b7479bSRandall Stewart 	/* record in stopped what t-o occured */
1617fa89f692SMichael Tuexen 	tmr->stopped_from = type;
161844b7479bSRandall Stewart 
1619f8829a4aSRandall Stewart 	/* mark as being serviced now */
162044b7479bSRandall Stewart 	if (SCTP_OS_TIMER_PENDING(&tmr->timer)) {
162144b7479bSRandall Stewart 		/*
162244b7479bSRandall Stewart 		 * Callout has been rescheduled.
162344b7479bSRandall Stewart 		 */
162444b7479bSRandall Stewart 		goto get_out;
162544b7479bSRandall Stewart 	}
162644b7479bSRandall Stewart 	if (!SCTP_OS_TIMER_ACTIVE(&tmr->timer)) {
162744b7479bSRandall Stewart 		/*
162844b7479bSRandall Stewart 		 * Not active, so no action.
162944b7479bSRandall Stewart 		 */
163044b7479bSRandall Stewart 		goto get_out;
163144b7479bSRandall Stewart 	}
1632139bc87fSRandall Stewart 	SCTP_OS_TIMER_DEACTIVATE(&tmr->timer);
1633f8829a4aSRandall Stewart 
1634f8829a4aSRandall Stewart 	/* call the handler for the appropriate timer type */
1635fa89f692SMichael Tuexen 	switch (type) {
1636d61a0ae0SRandall Stewart 	case SCTP_TIMER_TYPE_ZERO_COPY:
1637eacc51c5SRandall Stewart 		if (inp == NULL) {
1638eacc51c5SRandall Stewart 			break;
1639eacc51c5SRandall Stewart 		}
1640d61a0ae0SRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_ZERO_COPY_ACTIVE)) {
1641d61a0ae0SRandall Stewart 			SCTP_ZERO_COPY_EVENT(inp, inp->sctp_socket);
1642d61a0ae0SRandall Stewart 		}
1643d61a0ae0SRandall Stewart 		break;
1644ad21a364SRandall Stewart 	case SCTP_TIMER_TYPE_ZCOPY_SENDQ:
1645eacc51c5SRandall Stewart 		if (inp == NULL) {
1646eacc51c5SRandall Stewart 			break;
1647eacc51c5SRandall Stewart 		}
1648ad21a364SRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_ZERO_COPY_ACTIVE)) {
1649ad21a364SRandall Stewart 			SCTP_ZERO_COPY_SENDQ_EVENT(inp, inp->sctp_socket);
1650ad21a364SRandall Stewart 		}
1651ad21a364SRandall Stewart 		break;
1652f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ADDR_WQ:
1653f8829a4aSRandall Stewart 		sctp_handle_addr_wq();
1654f8829a4aSRandall Stewart 		break;
1655f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
1656ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1657ad81507eSRandall Stewart 			break;
1658ad81507eSRandall Stewart 		}
1659f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timodata);
1660f42a358aSRandall Stewart 		stcb->asoc.timodata++;
1661f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up--;
1662f8829a4aSRandall Stewart 		if (stcb->asoc.num_send_timers_up < 0) {
1663f8829a4aSRandall Stewart 			stcb->asoc.num_send_timers_up = 0;
1664f8829a4aSRandall Stewart 		}
1665b54d3a6cSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
166660990c0cSMichael Tuexen 		if (sctp_t3rxt_timer(inp, stcb, net)) {
1667f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1668f8829a4aSRandall Stewart 
1669f8829a4aSRandall Stewart 			goto out_decr;
1670f8829a4aSRandall Stewart 		}
1671b54d3a6cSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
1672f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1673f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1674f8829a4aSRandall Stewart #endif
1675ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
1676f8829a4aSRandall Stewart 		if ((stcb->asoc.num_send_timers_up == 0) &&
16774a9ef3f8SMichael Tuexen 		    (stcb->asoc.sent_queue_cnt > 0)) {
1678f8829a4aSRandall Stewart 			struct sctp_tmit_chunk *chk;
1679f8829a4aSRandall Stewart 
1680f8829a4aSRandall Stewart 			/*
1681f8829a4aSRandall Stewart 			 * safeguard. If there on some on the sent queue
1682f8829a4aSRandall Stewart 			 * somewhere but no timers running something is
1683f8829a4aSRandall Stewart 			 * wrong... so we start a timer on the first chunk
1684f8829a4aSRandall Stewart 			 * on the send queue on whatever net it is sent to.
1685f8829a4aSRandall Stewart 			 */
1686f8829a4aSRandall Stewart 			chk = TAILQ_FIRST(&stcb->asoc.sent_queue);
1687f8829a4aSRandall Stewart 			sctp_timer_start(SCTP_TIMER_TYPE_SEND, inp, stcb,
1688f8829a4aSRandall Stewart 			    chk->whoTo);
1689f8829a4aSRandall Stewart 		}
1690f8829a4aSRandall Stewart 		break;
1691f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
1692ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1693ad81507eSRandall Stewart 			break;
1694ad81507eSRandall Stewart 		}
1695f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoinit);
1696f42a358aSRandall Stewart 		stcb->asoc.timoinit++;
1697f8829a4aSRandall Stewart 		if (sctp_t1init_timer(inp, stcb, net)) {
1698f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1699f8829a4aSRandall Stewart 			goto out_decr;
1700f8829a4aSRandall Stewart 		}
1701f8829a4aSRandall Stewart 		/* We do output but not here */
1702f8829a4aSRandall Stewart 		did_output = 0;
1703f8829a4aSRandall Stewart 		break;
1704f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
1705ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1706ad81507eSRandall Stewart 			break;
1707ca85e948SMichael Tuexen 		}
1708f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timosack);
1709f42a358aSRandall Stewart 		stcb->asoc.timosack++;
1710689e6a5fSMichael Tuexen 		sctp_send_sack(stcb, SCTP_SO_NOT_LOCKED);
1711f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1712f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1713f8829a4aSRandall Stewart #endif
1714ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SACK_TMR, SCTP_SO_NOT_LOCKED);
1715f8829a4aSRandall Stewart 		break;
1716f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
1717ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1718ad81507eSRandall Stewart 			break;
1719ad81507eSRandall Stewart 		}
1720f8829a4aSRandall Stewart 		if (sctp_shutdown_timer(inp, stcb, net)) {
1721f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1722f8829a4aSRandall Stewart 			goto out_decr;
1723f8829a4aSRandall Stewart 		}
1724f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoshutdown);
1725f42a358aSRandall Stewart 		stcb->asoc.timoshutdown++;
1726f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1727f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1728f8829a4aSRandall Stewart #endif
1729ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SHUT_TMR, SCTP_SO_NOT_LOCKED);
1730f8829a4aSRandall Stewart 		break;
1731f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
1732ca85e948SMichael Tuexen 		if ((stcb == NULL) || (inp == NULL) || (net == NULL)) {
1733ad81507eSRandall Stewart 			break;
1734ad81507eSRandall Stewart 		}
1735f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoheartbeat);
1736f42a358aSRandall Stewart 		stcb->asoc.timoheartbeat++;
1737ca85e948SMichael Tuexen 		if (sctp_heartbeat_timer(inp, stcb, net)) {
1738f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1739f8829a4aSRandall Stewart 			goto out_decr;
1740f8829a4aSRandall Stewart 		}
1741f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1742ca85e948SMichael Tuexen 		sctp_auditing(4, inp, stcb, net);
1743f8829a4aSRandall Stewart #endif
1744ca85e948SMichael Tuexen 		if (!(net->dest_state & SCTP_ADDR_NOHB)) {
1745629749b6SMichael Tuexen 			sctp_timer_start(SCTP_TIMER_TYPE_HEARTBEAT, inp, stcb, net);
1746ceaad40aSRandall Stewart 			sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_HB_TMR, SCTP_SO_NOT_LOCKED);
1747f8829a4aSRandall Stewart 		}
1748f8829a4aSRandall Stewart 		break;
1749f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
1750ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1751ad81507eSRandall Stewart 			break;
1752ad81507eSRandall Stewart 		}
1753f8829a4aSRandall Stewart 		if (sctp_cookie_timer(inp, stcb, net)) {
1754f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1755f8829a4aSRandall Stewart 			goto out_decr;
1756f8829a4aSRandall Stewart 		}
1757f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timocookie);
1758f42a358aSRandall Stewart 		stcb->asoc.timocookie++;
1759f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1760f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1761f8829a4aSRandall Stewart #endif
1762f8829a4aSRandall Stewart 		/*
1763f8829a4aSRandall Stewart 		 * We consider T3 and Cookie timer pretty much the same with
1764f8829a4aSRandall Stewart 		 * respect to where from in chunk_output.
1765f8829a4aSRandall Stewart 		 */
1766ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
1767f8829a4aSRandall Stewart 		break;
1768f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
1769f8829a4aSRandall Stewart 		{
1770f8829a4aSRandall Stewart 			struct timeval tv;
1771f8829a4aSRandall Stewart 			int i, secret;
1772f8829a4aSRandall Stewart 
1773ad81507eSRandall Stewart 			if (inp == NULL) {
1774ad81507eSRandall Stewart 				break;
1775ad81507eSRandall Stewart 			}
1776f8829a4aSRandall Stewart 			SCTP_STAT_INCR(sctps_timosecret);
17776e55db54SRandall Stewart 			(void)SCTP_GETTIME_TIMEVAL(&tv);
1778f8829a4aSRandall Stewart 			SCTP_INP_WLOCK(inp);
1779f8829a4aSRandall Stewart 			inp->sctp_ep.time_of_secret_change = tv.tv_sec;
1780f8829a4aSRandall Stewart 			inp->sctp_ep.last_secret_number =
1781f8829a4aSRandall Stewart 			    inp->sctp_ep.current_secret_number;
1782f8829a4aSRandall Stewart 			inp->sctp_ep.current_secret_number++;
1783f8829a4aSRandall Stewart 			if (inp->sctp_ep.current_secret_number >=
1784f8829a4aSRandall Stewart 			    SCTP_HOW_MANY_SECRETS) {
1785f8829a4aSRandall Stewart 				inp->sctp_ep.current_secret_number = 0;
1786f8829a4aSRandall Stewart 			}
1787f8829a4aSRandall Stewart 			secret = (int)inp->sctp_ep.current_secret_number;
1788f8829a4aSRandall Stewart 			for (i = 0; i < SCTP_NUMBER_OF_SECRETS; i++) {
1789f8829a4aSRandall Stewart 				inp->sctp_ep.secret_key[secret][i] =
1790f8829a4aSRandall Stewart 				    sctp_select_initial_TSN(&inp->sctp_ep);
1791f8829a4aSRandall Stewart 			}
1792f8829a4aSRandall Stewart 			SCTP_INP_WUNLOCK(inp);
1793f8829a4aSRandall Stewart 			sctp_timer_start(SCTP_TIMER_TYPE_NEWCOOKIE, inp, stcb, net);
1794f8829a4aSRandall Stewart 		}
1795f8829a4aSRandall Stewart 		did_output = 0;
1796f8829a4aSRandall Stewart 		break;
1797f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
1798ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1799ad81507eSRandall Stewart 			break;
1800ad81507eSRandall Stewart 		}
1801f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timopathmtu);
1802f8829a4aSRandall Stewart 		sctp_pathmtu_timer(inp, stcb, net);
1803f8829a4aSRandall Stewart 		did_output = 0;
1804f8829a4aSRandall Stewart 		break;
1805f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
1806ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1807ad81507eSRandall Stewart 			break;
1808ad81507eSRandall Stewart 		}
1809f8829a4aSRandall Stewart 		if (sctp_shutdownack_timer(inp, stcb, net)) {
1810f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1811f8829a4aSRandall Stewart 			goto out_decr;
1812f8829a4aSRandall Stewart 		}
1813f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoshutdownack);
1814f42a358aSRandall Stewart 		stcb->asoc.timoshutdownack++;
1815f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1816f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1817f8829a4aSRandall Stewart #endif
1818ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SHUT_ACK_TMR, SCTP_SO_NOT_LOCKED);
1819f8829a4aSRandall Stewart 		break;
1820f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
1821ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1822ad81507eSRandall Stewart 			break;
1823ad81507eSRandall Stewart 		}
1824f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoshutdownguard);
1825267dbe63SMichael Tuexen 		op_err = sctp_generate_cause(SCTP_BASE_SYSCTL(sctp_diag_info_code),
1826267dbe63SMichael Tuexen 		    "Shutdown guard timer expired");
1827267dbe63SMichael Tuexen 		sctp_abort_an_association(inp, stcb, op_err, SCTP_SO_NOT_LOCKED);
1828f8829a4aSRandall Stewart 		/* no need to unlock on tcb its gone */
1829f8829a4aSRandall Stewart 		goto out_decr;
1830f8829a4aSRandall Stewart 
1831f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_STRRESET:
1832ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1833ad81507eSRandall Stewart 			break;
1834ad81507eSRandall Stewart 		}
1835f8829a4aSRandall Stewart 		if (sctp_strreset_timer(inp, stcb, net)) {
1836f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1837f8829a4aSRandall Stewart 			goto out_decr;
1838f8829a4aSRandall Stewart 		}
1839f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timostrmrst);
1840ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_STRRST_TMR, SCTP_SO_NOT_LOCKED);
1841f8829a4aSRandall Stewart 		break;
1842f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASCONF:
1843ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1844ad81507eSRandall Stewart 			break;
1845ad81507eSRandall Stewart 		}
1846f8829a4aSRandall Stewart 		if (sctp_asconf_timer(inp, stcb, net)) {
1847f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1848f8829a4aSRandall Stewart 			goto out_decr;
1849f8829a4aSRandall Stewart 		}
1850f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoasconf);
1851f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1852f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1853f8829a4aSRandall Stewart #endif
1854ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_ASCONF_TMR, SCTP_SO_NOT_LOCKED);
1855f8829a4aSRandall Stewart 		break;
1856851b7298SRandall Stewart 	case SCTP_TIMER_TYPE_PRIM_DELETED:
1857851b7298SRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1858851b7298SRandall Stewart 			break;
1859851b7298SRandall Stewart 		}
186004ee05e8SRandall Stewart 		sctp_delete_prim_timer(inp, stcb, net);
1861851b7298SRandall Stewart 		SCTP_STAT_INCR(sctps_timodelprim);
1862851b7298SRandall Stewart 		break;
1863f8829a4aSRandall Stewart 
1864f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_AUTOCLOSE:
1865ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1866ad81507eSRandall Stewart 			break;
1867ad81507eSRandall Stewart 		}
1868f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoautoclose);
1869f8829a4aSRandall Stewart 		sctp_autoclose_timer(inp, stcb, net);
1870ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_AUTOCLOSE_TMR, SCTP_SO_NOT_LOCKED);
1871f8829a4aSRandall Stewart 		did_output = 0;
1872f8829a4aSRandall Stewart 		break;
1873f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASOCKILL:
1874ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1875ad81507eSRandall Stewart 			break;
1876ad81507eSRandall Stewart 		}
1877f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoassockill);
1878f8829a4aSRandall Stewart 		/* Can we free it yet? */
1879f8829a4aSRandall Stewart 		SCTP_INP_DECR_REF(inp);
1880ba785902SMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_ASOCKILL, inp, stcb, NULL,
1881ba785902SMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_1);
1882ceaad40aSRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
1883ceaad40aSRandall Stewart 		so = SCTP_INP_SO(inp);
1884ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
1885ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
1886ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
1887ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
1888ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
1889ceaad40aSRandall Stewart #endif
1890ba785902SMichael Tuexen 		(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
1891ba785902SMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_2);
1892ceaad40aSRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
1893ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
1894ceaad40aSRandall Stewart #endif
1895f8829a4aSRandall Stewart 		/*
1896f8829a4aSRandall Stewart 		 * free asoc, always unlocks (or destroy's) so prevent
1897f8829a4aSRandall Stewart 		 * duplicate unlock or unlock of a free mtx :-0
1898f8829a4aSRandall Stewart 		 */
1899f8829a4aSRandall Stewart 		stcb = NULL;
1900f8829a4aSRandall Stewart 		goto out_no_decr;
1901f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INPKILL:
1902f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoinpkill);
1903ad81507eSRandall Stewart 		if (inp == NULL) {
1904ad81507eSRandall Stewart 			break;
1905ad81507eSRandall Stewart 		}
1906f8829a4aSRandall Stewart 		/*
1907f8829a4aSRandall Stewart 		 * special case, take away our increment since WE are the
1908f8829a4aSRandall Stewart 		 * killer
1909f8829a4aSRandall Stewart 		 */
1910f8829a4aSRandall Stewart 		SCTP_INP_DECR_REF(inp);
1911ba785902SMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_INPKILL, inp, NULL, NULL,
1912ba785902SMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_3);
1913b0552ae2SRandall Stewart 		sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
19140c7dc840SRandall Stewart 		    SCTP_CALLED_FROM_INPKILL_TIMER);
1915d61374e1SRandall Stewart 		inp = NULL;
1916f8829a4aSRandall Stewart 		goto out_no_decr;
1917f8829a4aSRandall Stewart 	default:
1918ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_TIMER1, "sctp_timeout_handler:unknown timer %d\n",
1919fa89f692SMichael Tuexen 		    type);
1920f8829a4aSRandall Stewart 		break;
192160990c0cSMichael Tuexen 	}
1922f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1923fa89f692SMichael Tuexen 	sctp_audit_log(0xF1, (uint8_t) type);
1924f8829a4aSRandall Stewart 	if (inp)
1925f8829a4aSRandall Stewart 		sctp_auditing(5, inp, stcb, net);
1926f8829a4aSRandall Stewart #endif
1927f8829a4aSRandall Stewart 	if ((did_output) && stcb) {
1928f8829a4aSRandall Stewart 		/*
1929f8829a4aSRandall Stewart 		 * Now we need to clean up the control chunk chain if an
1930f8829a4aSRandall Stewart 		 * ECNE is on it. It must be marked as UNSENT again so next
1931f8829a4aSRandall Stewart 		 * call will continue to send it until such time that we get
1932f8829a4aSRandall Stewart 		 * a CWR, to remove it. It is, however, less likely that we
1933f8829a4aSRandall Stewart 		 * will find a ecn echo on the chain though.
1934f8829a4aSRandall Stewart 		 */
1935f8829a4aSRandall Stewart 		sctp_fix_ecn_echo(&stcb->asoc);
1936f8829a4aSRandall Stewart 	}
193744b7479bSRandall Stewart get_out:
1938f8829a4aSRandall Stewart 	if (stcb) {
1939f8829a4aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
1940f8829a4aSRandall Stewart 	}
1941f8829a4aSRandall Stewart out_decr:
1942f8829a4aSRandall Stewart 	if (inp) {
1943f8829a4aSRandall Stewart 		SCTP_INP_DECR_REF(inp);
1944f8829a4aSRandall Stewart 	}
1945f8829a4aSRandall Stewart out_no_decr:
1946fa89f692SMichael Tuexen 	SCTPDBG(SCTP_DEBUG_TIMER1, "Timer now complete (type = %d)\n", type);
19478518270eSMichael Tuexen 	CURVNET_RESTORE();
1948f8829a4aSRandall Stewart }
1949f8829a4aSRandall Stewart 
1950ad81507eSRandall Stewart void
1951f8829a4aSRandall Stewart sctp_timer_start(int t_type, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
1952f8829a4aSRandall Stewart     struct sctp_nets *net)
1953f8829a4aSRandall Stewart {
1954ca85e948SMichael Tuexen 	uint32_t to_ticks;
1955f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
1956f8829a4aSRandall Stewart 
1957139bc87fSRandall Stewart 	if ((t_type != SCTP_TIMER_TYPE_ADDR_WQ) && (inp == NULL))
1958ad81507eSRandall Stewart 		return;
1959f8829a4aSRandall Stewart 
1960f8829a4aSRandall Stewart 	tmr = NULL;
1961f8829a4aSRandall Stewart 	if (stcb) {
1962f8829a4aSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
1963f8829a4aSRandall Stewart 	}
1964f8829a4aSRandall Stewart 	switch (t_type) {
1965d61a0ae0SRandall Stewart 	case SCTP_TIMER_TYPE_ZERO_COPY:
1966d61a0ae0SRandall Stewart 		tmr = &inp->sctp_ep.zero_copy_timer;
1967d61a0ae0SRandall Stewart 		to_ticks = SCTP_ZERO_COPY_TICK_DELAY;
1968d61a0ae0SRandall Stewart 		break;
1969ad21a364SRandall Stewart 	case SCTP_TIMER_TYPE_ZCOPY_SENDQ:
1970ad21a364SRandall Stewart 		tmr = &inp->sctp_ep.zero_copy_sendq_timer;
1971ad21a364SRandall Stewart 		to_ticks = SCTP_ZERO_COPY_SENDQ_TICK_DELAY;
1972ad21a364SRandall Stewart 		break;
1973f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ADDR_WQ:
1974f8829a4aSRandall Stewart 		/* Only 1 tick away :-) */
1975b3f1ea41SRandall Stewart 		tmr = &SCTP_BASE_INFO(addr_wq_timer);
197642551e99SRandall Stewart 		to_ticks = SCTP_ADDRESS_TICK_DELAY;
1977f8829a4aSRandall Stewart 		break;
1978f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
1979f8829a4aSRandall Stewart 		/* Here we use the RTO timer */
1980f8829a4aSRandall Stewart 		{
1981f8829a4aSRandall Stewart 			int rto_val;
1982f8829a4aSRandall Stewart 
1983f8829a4aSRandall Stewart 			if ((stcb == NULL) || (net == NULL)) {
1984ad81507eSRandall Stewart 				return;
1985f8829a4aSRandall Stewart 			}
1986f8829a4aSRandall Stewart 			tmr = &net->rxt_timer;
1987f8829a4aSRandall Stewart 			if (net->RTO == 0) {
1988f8829a4aSRandall Stewart 				rto_val = stcb->asoc.initial_rto;
1989f8829a4aSRandall Stewart 			} else {
1990f8829a4aSRandall Stewart 				rto_val = net->RTO;
1991f8829a4aSRandall Stewart 			}
1992f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(rto_val);
1993f8829a4aSRandall Stewart 		}
1994f8829a4aSRandall Stewart 		break;
1995f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
1996f8829a4aSRandall Stewart 		/*
1997f8829a4aSRandall Stewart 		 * Here we use the INIT timer default usually about 1
1998f8829a4aSRandall Stewart 		 * minute.
1999f8829a4aSRandall Stewart 		 */
2000f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2001ad81507eSRandall Stewart 			return;
2002f8829a4aSRandall Stewart 		}
2003f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2004f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2005f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2006f8829a4aSRandall Stewart 		} else {
2007f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2008f8829a4aSRandall Stewart 		}
2009f8829a4aSRandall Stewart 		break;
2010f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
2011f8829a4aSRandall Stewart 		/*
2012f8829a4aSRandall Stewart 		 * Here we use the Delayed-Ack timer value from the inp
2013f8829a4aSRandall Stewart 		 * ususually about 200ms.
2014f8829a4aSRandall Stewart 		 */
2015f8829a4aSRandall Stewart 		if (stcb == NULL) {
2016ad81507eSRandall Stewart 			return;
2017f8829a4aSRandall Stewart 		}
2018f8829a4aSRandall Stewart 		tmr = &stcb->asoc.dack_timer;
2019f8829a4aSRandall Stewart 		to_ticks = MSEC_TO_TICKS(stcb->asoc.delayed_ack);
2020f8829a4aSRandall Stewart 		break;
2021f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
2022f8829a4aSRandall Stewart 		/* Here we use the RTO of the destination. */
2023f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2024ad81507eSRandall Stewart 			return;
2025f8829a4aSRandall Stewart 		}
2026f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2027f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2028f8829a4aSRandall Stewart 		} else {
2029f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2030f8829a4aSRandall Stewart 		}
2031f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2032f8829a4aSRandall Stewart 		break;
2033f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
2034f8829a4aSRandall Stewart 		/*
2035f8829a4aSRandall Stewart 		 * the net is used here so that we can add in the RTO. Even
2036f8829a4aSRandall Stewart 		 * though we use a different timer. We also add the HB timer
2037f8829a4aSRandall Stewart 		 * PLUS a random jitter.
2038f8829a4aSRandall Stewart 		 */
2039f3ba71beSMichael Tuexen 		if ((stcb == NULL) || (net == NULL)) {
2040ad81507eSRandall Stewart 			return;
2041ad81507eSRandall Stewart 		} else {
2042f8829a4aSRandall Stewart 			uint32_t rndval;
2043ca85e948SMichael Tuexen 			uint32_t jitter;
2044f8829a4aSRandall Stewart 
2045ca85e948SMichael Tuexen 			if ((net->dest_state & SCTP_ADDR_NOHB) &&
2046ca85e948SMichael Tuexen 			    !(net->dest_state & SCTP_ADDR_UNCONFIRMED)) {
2047ad81507eSRandall Stewart 				return;
2048f8829a4aSRandall Stewart 			}
2049f8829a4aSRandall Stewart 			if (net->RTO == 0) {
2050ca85e948SMichael Tuexen 				to_ticks = stcb->asoc.initial_rto;
2051f8829a4aSRandall Stewart 			} else {
2052ca85e948SMichael Tuexen 				to_ticks = net->RTO;
2053f8829a4aSRandall Stewart 			}
2054ca85e948SMichael Tuexen 			rndval = sctp_select_initial_TSN(&inp->sctp_ep);
2055ca85e948SMichael Tuexen 			jitter = rndval % to_ticks;
2056ca85e948SMichael Tuexen 			if (jitter >= (to_ticks >> 1)) {
2057ca85e948SMichael Tuexen 				to_ticks = to_ticks + (jitter - (to_ticks >> 1));
2058f8829a4aSRandall Stewart 			} else {
2059ca85e948SMichael Tuexen 				to_ticks = to_ticks - jitter;
2060f8829a4aSRandall Stewart 			}
2061ca85e948SMichael Tuexen 			if (!(net->dest_state & SCTP_ADDR_UNCONFIRMED) &&
2062ca85e948SMichael Tuexen 			    !(net->dest_state & SCTP_ADDR_PF)) {
2063ca85e948SMichael Tuexen 				to_ticks += net->heart_beat_delay;
2064f8829a4aSRandall Stewart 			}
2065f8829a4aSRandall Stewart 			/*
2066f8829a4aSRandall Stewart 			 * Now we must convert the to_ticks that are now in
2067f8829a4aSRandall Stewart 			 * ms to ticks.
2068f8829a4aSRandall Stewart 			 */
2069f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(to_ticks);
2070ca85e948SMichael Tuexen 			tmr = &net->hb_timer;
2071f8829a4aSRandall Stewart 		}
2072f8829a4aSRandall Stewart 		break;
2073f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
2074f8829a4aSRandall Stewart 		/*
2075f8829a4aSRandall Stewart 		 * Here we can use the RTO timer from the network since one
2076f8829a4aSRandall Stewart 		 * RTT was compelete. If a retran happened then we will be
2077f8829a4aSRandall Stewart 		 * using the RTO initial value.
2078f8829a4aSRandall Stewart 		 */
2079f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2080ad81507eSRandall Stewart 			return;
2081f8829a4aSRandall Stewart 		}
2082f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2083f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2084f8829a4aSRandall Stewart 		} else {
2085f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2086f8829a4aSRandall Stewart 		}
2087f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2088f8829a4aSRandall Stewart 		break;
2089f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
2090f8829a4aSRandall Stewart 		/*
2091f8829a4aSRandall Stewart 		 * nothing needed but the endpoint here ususually about 60
2092f8829a4aSRandall Stewart 		 * minutes.
2093f8829a4aSRandall Stewart 		 */
2094f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2095f8829a4aSRandall Stewart 		to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_SIGNATURE];
2096f8829a4aSRandall Stewart 		break;
2097f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASOCKILL:
2098f8829a4aSRandall Stewart 		if (stcb == NULL) {
2099ad81507eSRandall Stewart 			return;
2100f8829a4aSRandall Stewart 		}
2101f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2102f8829a4aSRandall Stewart 		to_ticks = MSEC_TO_TICKS(SCTP_ASOC_KILL_TIMEOUT);
2103f8829a4aSRandall Stewart 		break;
2104f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INPKILL:
2105f8829a4aSRandall Stewart 		/*
2106f8829a4aSRandall Stewart 		 * The inp is setup to die. We re-use the signature_chage
2107f8829a4aSRandall Stewart 		 * timer since that has stopped and we are in the GONE
2108f8829a4aSRandall Stewart 		 * state.
2109f8829a4aSRandall Stewart 		 */
2110f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2111f8829a4aSRandall Stewart 		to_ticks = MSEC_TO_TICKS(SCTP_INP_KILL_TIMEOUT);
2112f8829a4aSRandall Stewart 		break;
2113f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
2114f8829a4aSRandall Stewart 		/*
2115f8829a4aSRandall Stewart 		 * Here we use the value found in the EP for PMTU ususually
2116f8829a4aSRandall Stewart 		 * about 10 minutes.
2117f8829a4aSRandall Stewart 		 */
2118f3ba71beSMichael Tuexen 		if ((stcb == NULL) || (net == NULL)) {
2119ad81507eSRandall Stewart 			return;
2120f8829a4aSRandall Stewart 		}
212180c79bbeSMichael Tuexen 		if (net->dest_state & SCTP_ADDR_NO_PMTUD) {
212280c79bbeSMichael Tuexen 			return;
212380c79bbeSMichael Tuexen 		}
2124f8829a4aSRandall Stewart 		to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_PMTU];
2125f8829a4aSRandall Stewart 		tmr = &net->pmtu_timer;
2126f8829a4aSRandall Stewart 		break;
2127f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
2128f8829a4aSRandall Stewart 		/* Here we use the RTO of the destination */
2129f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2130ad81507eSRandall Stewart 			return;
2131f8829a4aSRandall Stewart 		}
2132f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2133f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2134f8829a4aSRandall Stewart 		} else {
2135f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2136f8829a4aSRandall Stewart 		}
2137f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2138f8829a4aSRandall Stewart 		break;
2139f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
2140f8829a4aSRandall Stewart 		/*
2141f8829a4aSRandall Stewart 		 * Here we use the endpoints shutdown guard timer usually
2142f8829a4aSRandall Stewart 		 * about 3 minutes.
2143f8829a4aSRandall Stewart 		 */
2144f3ba71beSMichael Tuexen 		if (stcb == NULL) {
2145ad81507eSRandall Stewart 			return;
2146f8829a4aSRandall Stewart 		}
21472e2d6794SMichael Tuexen 		if (inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_MAXSHUTDOWN] == 0) {
21482e2d6794SMichael Tuexen 			to_ticks = 5 * MSEC_TO_TICKS(stcb->asoc.maxrto);
21492e2d6794SMichael Tuexen 		} else {
2150f8829a4aSRandall Stewart 			to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_MAXSHUTDOWN];
21512e2d6794SMichael Tuexen 		}
2152f8829a4aSRandall Stewart 		tmr = &stcb->asoc.shut_guard_timer;
2153f8829a4aSRandall Stewart 		break;
2154f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_STRRESET:
2155f8829a4aSRandall Stewart 		/*
21561b649582SRandall Stewart 		 * Here the timer comes from the stcb but its value is from
21571b649582SRandall Stewart 		 * the net's RTO.
2158f8829a4aSRandall Stewart 		 */
2159f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2160ad81507eSRandall Stewart 			return;
2161f8829a4aSRandall Stewart 		}
2162f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2163f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2164f8829a4aSRandall Stewart 		} else {
2165f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2166f8829a4aSRandall Stewart 		}
2167f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2168f8829a4aSRandall Stewart 		break;
2169f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASCONF:
2170f8829a4aSRandall Stewart 		/*
21711b649582SRandall Stewart 		 * Here the timer comes from the stcb but its value is from
21721b649582SRandall Stewart 		 * the net's RTO.
2173f8829a4aSRandall Stewart 		 */
2174f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2175ad81507eSRandall Stewart 			return;
2176f8829a4aSRandall Stewart 		}
2177f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2178f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2179f8829a4aSRandall Stewart 		} else {
2180f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2181f8829a4aSRandall Stewart 		}
2182f8829a4aSRandall Stewart 		tmr = &stcb->asoc.asconf_timer;
2183f8829a4aSRandall Stewart 		break;
2184851b7298SRandall Stewart 	case SCTP_TIMER_TYPE_PRIM_DELETED:
2185851b7298SRandall Stewart 		if ((stcb == NULL) || (net != NULL)) {
2186851b7298SRandall Stewart 			return;
2187851b7298SRandall Stewart 		}
2188851b7298SRandall Stewart 		to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2189851b7298SRandall Stewart 		tmr = &stcb->asoc.delete_prim_timer;
2190851b7298SRandall Stewart 		break;
2191f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_AUTOCLOSE:
2192f8829a4aSRandall Stewart 		if (stcb == NULL) {
2193ad81507eSRandall Stewart 			return;
2194f8829a4aSRandall Stewart 		}
2195f8829a4aSRandall Stewart 		if (stcb->asoc.sctp_autoclose_ticks == 0) {
2196f8829a4aSRandall Stewart 			/*
2197f8829a4aSRandall Stewart 			 * Really an error since stcb is NOT set to
2198f8829a4aSRandall Stewart 			 * autoclose
2199f8829a4aSRandall Stewart 			 */
2200ad81507eSRandall Stewart 			return;
2201f8829a4aSRandall Stewart 		}
2202f8829a4aSRandall Stewart 		to_ticks = stcb->asoc.sctp_autoclose_ticks;
2203f8829a4aSRandall Stewart 		tmr = &stcb->asoc.autoclose_timer;
2204f8829a4aSRandall Stewart 		break;
2205f8829a4aSRandall Stewart 	default:
2206ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_TIMER1, "%s: Unknown timer type %d\n",
22076e9c45e0SMichael Tuexen 		    __func__, t_type);
2208ad81507eSRandall Stewart 		return;
2209f8829a4aSRandall Stewart 		break;
221060990c0cSMichael Tuexen 	}
2211f8829a4aSRandall Stewart 	if ((to_ticks <= 0) || (tmr == NULL)) {
2212ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_TIMER1, "%s: %d:software error to_ticks:%d tmr:%p not set ??\n",
22136e9c45e0SMichael Tuexen 		    __func__, t_type, to_ticks, (void *)tmr);
2214ad81507eSRandall Stewart 		return;
2215f8829a4aSRandall Stewart 	}
2216139bc87fSRandall Stewart 	if (SCTP_OS_TIMER_PENDING(&tmr->timer)) {
2217f8829a4aSRandall Stewart 		/*
2218f8829a4aSRandall Stewart 		 * we do NOT allow you to have it already running. if it is
2219f8829a4aSRandall Stewart 		 * we leave the current one up unchanged
2220f8829a4aSRandall Stewart 		 */
2221ad81507eSRandall Stewart 		return;
2222f8829a4aSRandall Stewart 	}
2223f8829a4aSRandall Stewart 	/* At this point we can proceed */
2224f8829a4aSRandall Stewart 	if (t_type == SCTP_TIMER_TYPE_SEND) {
2225f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up++;
2226f8829a4aSRandall Stewart 	}
2227a5d547adSRandall Stewart 	tmr->stopped_from = 0;
2228f8829a4aSRandall Stewart 	tmr->type = t_type;
2229f8829a4aSRandall Stewart 	tmr->ep = (void *)inp;
2230f8829a4aSRandall Stewart 	tmr->tcb = (void *)stcb;
2231f8829a4aSRandall Stewart 	tmr->net = (void *)net;
2232f8829a4aSRandall Stewart 	tmr->self = (void *)tmr;
22338518270eSMichael Tuexen 	tmr->vnet = (void *)curvnet;
2234c4739e2fSRandall Stewart 	tmr->ticks = sctp_get_tick_count();
2235ad81507eSRandall Stewart 	(void)SCTP_OS_TIMER_START(&tmr->timer, to_ticks, sctp_timeout_handler, tmr);
2236ad81507eSRandall Stewart 	return;
2237f8829a4aSRandall Stewart }
2238f8829a4aSRandall Stewart 
22396e55db54SRandall Stewart void
2240f8829a4aSRandall Stewart sctp_timer_stop(int t_type, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
2241a5d547adSRandall Stewart     struct sctp_nets *net, uint32_t from)
2242f8829a4aSRandall Stewart {
2243f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
2244f8829a4aSRandall Stewart 
2245f8829a4aSRandall Stewart 	if ((t_type != SCTP_TIMER_TYPE_ADDR_WQ) &&
2246f8829a4aSRandall Stewart 	    (inp == NULL))
22476e55db54SRandall Stewart 		return;
2248f8829a4aSRandall Stewart 
2249f8829a4aSRandall Stewart 	tmr = NULL;
2250f8829a4aSRandall Stewart 	if (stcb) {
2251f8829a4aSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
2252f8829a4aSRandall Stewart 	}
2253f8829a4aSRandall Stewart 	switch (t_type) {
2254d61a0ae0SRandall Stewart 	case SCTP_TIMER_TYPE_ZERO_COPY:
2255d61a0ae0SRandall Stewart 		tmr = &inp->sctp_ep.zero_copy_timer;
2256d61a0ae0SRandall Stewart 		break;
2257ad21a364SRandall Stewart 	case SCTP_TIMER_TYPE_ZCOPY_SENDQ:
2258ad21a364SRandall Stewart 		tmr = &inp->sctp_ep.zero_copy_sendq_timer;
2259ad21a364SRandall Stewart 		break;
2260f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ADDR_WQ:
2261b3f1ea41SRandall Stewart 		tmr = &SCTP_BASE_INFO(addr_wq_timer);
2262f8829a4aSRandall Stewart 		break;
2263f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
2264f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
22656e55db54SRandall Stewart 			return;
2266f8829a4aSRandall Stewart 		}
2267f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2268f8829a4aSRandall Stewart 		break;
2269f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
2270f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
22716e55db54SRandall Stewart 			return;
2272f8829a4aSRandall Stewart 		}
2273f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2274f8829a4aSRandall Stewart 		break;
2275f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
2276f8829a4aSRandall Stewart 		if (stcb == NULL) {
22776e55db54SRandall Stewart 			return;
2278f8829a4aSRandall Stewart 		}
2279f8829a4aSRandall Stewart 		tmr = &stcb->asoc.dack_timer;
2280f8829a4aSRandall Stewart 		break;
2281f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
2282f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
22836e55db54SRandall Stewart 			return;
2284f8829a4aSRandall Stewart 		}
2285f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2286f8829a4aSRandall Stewart 		break;
2287f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
2288ca85e948SMichael Tuexen 		if ((stcb == NULL) || (net == NULL)) {
22896e55db54SRandall Stewart 			return;
2290f8829a4aSRandall Stewart 		}
2291ca85e948SMichael Tuexen 		tmr = &net->hb_timer;
2292f8829a4aSRandall Stewart 		break;
2293f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
2294f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
22956e55db54SRandall Stewart 			return;
2296f8829a4aSRandall Stewart 		}
2297f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2298f8829a4aSRandall Stewart 		break;
2299f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
2300f8829a4aSRandall Stewart 		/* nothing needed but the endpoint here */
2301f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2302f8829a4aSRandall Stewart 		/*
2303f8829a4aSRandall Stewart 		 * We re-use the newcookie timer for the INP kill timer. We
2304f8829a4aSRandall Stewart 		 * must assure that we do not kill it by accident.
2305f8829a4aSRandall Stewart 		 */
2306f8829a4aSRandall Stewart 		break;
2307f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASOCKILL:
2308f8829a4aSRandall Stewart 		/*
2309f8829a4aSRandall Stewart 		 * Stop the asoc kill timer.
2310f8829a4aSRandall Stewart 		 */
2311f8829a4aSRandall Stewart 		if (stcb == NULL) {
23126e55db54SRandall Stewart 			return;
2313f8829a4aSRandall Stewart 		}
2314f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2315f8829a4aSRandall Stewart 		break;
2316f8829a4aSRandall Stewart 
2317f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INPKILL:
2318f8829a4aSRandall Stewart 		/*
2319f8829a4aSRandall Stewart 		 * The inp is setup to die. We re-use the signature_chage
2320f8829a4aSRandall Stewart 		 * timer since that has stopped and we are in the GONE
2321f8829a4aSRandall Stewart 		 * state.
2322f8829a4aSRandall Stewart 		 */
2323f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2324f8829a4aSRandall Stewart 		break;
2325f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
2326f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23276e55db54SRandall Stewart 			return;
2328f8829a4aSRandall Stewart 		}
2329f8829a4aSRandall Stewart 		tmr = &net->pmtu_timer;
2330f8829a4aSRandall Stewart 		break;
2331f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
2332f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23336e55db54SRandall Stewart 			return;
2334f8829a4aSRandall Stewart 		}
2335f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2336f8829a4aSRandall Stewart 		break;
2337f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
2338f8829a4aSRandall Stewart 		if (stcb == NULL) {
23396e55db54SRandall Stewart 			return;
2340f8829a4aSRandall Stewart 		}
2341f8829a4aSRandall Stewart 		tmr = &stcb->asoc.shut_guard_timer;
2342f8829a4aSRandall Stewart 		break;
2343f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_STRRESET:
2344f8829a4aSRandall Stewart 		if (stcb == NULL) {
23456e55db54SRandall Stewart 			return;
2346f8829a4aSRandall Stewart 		}
2347f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2348f8829a4aSRandall Stewart 		break;
2349f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASCONF:
2350f8829a4aSRandall Stewart 		if (stcb == NULL) {
23516e55db54SRandall Stewart 			return;
2352f8829a4aSRandall Stewart 		}
2353f8829a4aSRandall Stewart 		tmr = &stcb->asoc.asconf_timer;
2354f8829a4aSRandall Stewart 		break;
2355851b7298SRandall Stewart 	case SCTP_TIMER_TYPE_PRIM_DELETED:
2356851b7298SRandall Stewart 		if (stcb == NULL) {
2357851b7298SRandall Stewart 			return;
2358851b7298SRandall Stewart 		}
2359851b7298SRandall Stewart 		tmr = &stcb->asoc.delete_prim_timer;
2360851b7298SRandall Stewart 		break;
2361f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_AUTOCLOSE:
2362f8829a4aSRandall Stewart 		if (stcb == NULL) {
23636e55db54SRandall Stewart 			return;
2364f8829a4aSRandall Stewart 		}
2365f8829a4aSRandall Stewart 		tmr = &stcb->asoc.autoclose_timer;
2366f8829a4aSRandall Stewart 		break;
2367f8829a4aSRandall Stewart 	default:
2368ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_TIMER1, "%s: Unknown timer type %d\n",
23696e9c45e0SMichael Tuexen 		    __func__, t_type);
2370f8829a4aSRandall Stewart 		break;
237160990c0cSMichael Tuexen 	}
2372f8829a4aSRandall Stewart 	if (tmr == NULL) {
23736e55db54SRandall Stewart 		return;
2374f8829a4aSRandall Stewart 	}
2375f8829a4aSRandall Stewart 	if ((tmr->type != t_type) && tmr->type) {
2376f8829a4aSRandall Stewart 		/*
2377f8829a4aSRandall Stewart 		 * Ok we have a timer that is under joint use. Cookie timer
2378f8829a4aSRandall Stewart 		 * per chance with the SEND timer. We therefore are NOT
2379f8829a4aSRandall Stewart 		 * running the timer that the caller wants stopped.  So just
2380f8829a4aSRandall Stewart 		 * return.
2381f8829a4aSRandall Stewart 		 */
23826e55db54SRandall Stewart 		return;
2383f8829a4aSRandall Stewart 	}
2384ad81507eSRandall Stewart 	if ((t_type == SCTP_TIMER_TYPE_SEND) && (stcb != NULL)) {
2385f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up--;
2386f8829a4aSRandall Stewart 		if (stcb->asoc.num_send_timers_up < 0) {
2387f8829a4aSRandall Stewart 			stcb->asoc.num_send_timers_up = 0;
2388f8829a4aSRandall Stewart 		}
2389f8829a4aSRandall Stewart 	}
2390f8829a4aSRandall Stewart 	tmr->self = NULL;
2391a5d547adSRandall Stewart 	tmr->stopped_from = from;
23926e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&tmr->timer);
23936e55db54SRandall Stewart 	return;
2394f8829a4aSRandall Stewart }
2395f8829a4aSRandall Stewart 
2396f8829a4aSRandall Stewart uint32_t
2397f8829a4aSRandall Stewart sctp_calculate_len(struct mbuf *m)
2398f8829a4aSRandall Stewart {
2399f8829a4aSRandall Stewart 	uint32_t tlen = 0;
2400f8829a4aSRandall Stewart 	struct mbuf *at;
2401f8829a4aSRandall Stewart 
2402f8829a4aSRandall Stewart 	at = m;
2403f8829a4aSRandall Stewart 	while (at) {
2404139bc87fSRandall Stewart 		tlen += SCTP_BUF_LEN(at);
2405139bc87fSRandall Stewart 		at = SCTP_BUF_NEXT(at);
2406f8829a4aSRandall Stewart 	}
2407f8829a4aSRandall Stewart 	return (tlen);
2408f8829a4aSRandall Stewart }
2409f8829a4aSRandall Stewart 
2410f8829a4aSRandall Stewart void
2411f8829a4aSRandall Stewart sctp_mtu_size_reset(struct sctp_inpcb *inp,
241244b7479bSRandall Stewart     struct sctp_association *asoc, uint32_t mtu)
2413f8829a4aSRandall Stewart {
2414f8829a4aSRandall Stewart 	/*
2415f8829a4aSRandall Stewart 	 * Reset the P-MTU size on this association, this involves changing
2416f8829a4aSRandall Stewart 	 * the asoc MTU, going through ANY chunk+overhead larger than mtu to
2417f8829a4aSRandall Stewart 	 * allow the DF flag to be cleared.
2418f8829a4aSRandall Stewart 	 */
2419f8829a4aSRandall Stewart 	struct sctp_tmit_chunk *chk;
2420f8829a4aSRandall Stewart 	unsigned int eff_mtu, ovh;
2421f8829a4aSRandall Stewart 
2422f8829a4aSRandall Stewart 	asoc->smallest_mtu = mtu;
2423f8829a4aSRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) {
2424f8829a4aSRandall Stewart 		ovh = SCTP_MIN_OVERHEAD;
2425f8829a4aSRandall Stewart 	} else {
2426f8829a4aSRandall Stewart 		ovh = SCTP_MIN_V4_OVERHEAD;
2427f8829a4aSRandall Stewart 	}
2428f8829a4aSRandall Stewart 	eff_mtu = mtu - ovh;
2429f8829a4aSRandall Stewart 	TAILQ_FOREACH(chk, &asoc->send_queue, sctp_next) {
2430f8829a4aSRandall Stewart 		if (chk->send_size > eff_mtu) {
2431f8829a4aSRandall Stewart 			chk->flags |= CHUNK_FLAGS_FRAGMENT_OK;
2432f8829a4aSRandall Stewart 		}
2433f8829a4aSRandall Stewart 	}
2434f8829a4aSRandall Stewart 	TAILQ_FOREACH(chk, &asoc->sent_queue, sctp_next) {
2435f8829a4aSRandall Stewart 		if (chk->send_size > eff_mtu) {
2436f8829a4aSRandall Stewart 			chk->flags |= CHUNK_FLAGS_FRAGMENT_OK;
2437f8829a4aSRandall Stewart 		}
2438f8829a4aSRandall Stewart 	}
2439f8829a4aSRandall Stewart }
2440f8829a4aSRandall Stewart 
2441f8829a4aSRandall Stewart 
2442f8829a4aSRandall Stewart /*
2443f8829a4aSRandall Stewart  * given an association and starting time of the current RTT period return
2444f42a358aSRandall Stewart  * RTO in number of msecs net should point to the current network
2445f8829a4aSRandall Stewart  */
2446899288aeSRandall Stewart 
2447f8829a4aSRandall Stewart uint32_t
2448f8829a4aSRandall Stewart sctp_calculate_rto(struct sctp_tcb *stcb,
2449f8829a4aSRandall Stewart     struct sctp_association *asoc,
2450f8829a4aSRandall Stewart     struct sctp_nets *net,
245118e198d3SRandall Stewart     struct timeval *told,
2452f79aab18SRandall Stewart     int safe, int rtt_from_sack)
2453f8829a4aSRandall Stewart {
245418e198d3SRandall Stewart 	/*-
2455f8829a4aSRandall Stewart 	 * given an association and the starting time of the current RTT
2456f42a358aSRandall Stewart 	 * period (in value1/value2) return RTO in number of msecs.
2457f8829a4aSRandall Stewart 	 */
2458be1d9176SMichael Tuexen 	int32_t rtt;		/* RTT in ms */
2459be1d9176SMichael Tuexen 	uint32_t new_rto;
2460f8829a4aSRandall Stewart 	int first_measure = 0;
246118e198d3SRandall Stewart 	struct timeval now, then, *old;
2462f8829a4aSRandall Stewart 
246318e198d3SRandall Stewart 	/* Copy it out for sparc64 */
246418e198d3SRandall Stewart 	if (safe == sctp_align_unsafe_makecopy) {
246518e198d3SRandall Stewart 		old = &then;
246618e198d3SRandall Stewart 		memcpy(&then, told, sizeof(struct timeval));
246718e198d3SRandall Stewart 	} else if (safe == sctp_align_safe_nocopy) {
246818e198d3SRandall Stewart 		old = told;
246918e198d3SRandall Stewart 	} else {
247018e198d3SRandall Stewart 		/* error */
247118e198d3SRandall Stewart 		SCTP_PRINTF("Huh, bad rto calc call\n");
247218e198d3SRandall Stewart 		return (0);
247318e198d3SRandall Stewart 	}
2474f8829a4aSRandall Stewart 	/************************/
2475f8829a4aSRandall Stewart 	/* 1. calculate new RTT */
2476f8829a4aSRandall Stewart 	/************************/
2477f8829a4aSRandall Stewart 	/* get the current time */
2478299108c5SRandall Stewart 	if (stcb->asoc.use_precise_time) {
2479299108c5SRandall Stewart 		(void)SCTP_GETPTIME_TIMEVAL(&now);
2480299108c5SRandall Stewart 	} else {
24816e55db54SRandall Stewart 		(void)SCTP_GETTIME_TIMEVAL(&now);
2482299108c5SRandall Stewart 	}
2483be1d9176SMichael Tuexen 	timevalsub(&now, old);
2484be1d9176SMichael Tuexen 	/* store the current RTT in us */
248581eb4e63SMichael Tuexen 	net->rtt = (uint64_t) 1000000 *(uint64_t) now.tv_sec +
2486be1d9176SMichael Tuexen 	        (uint64_t) now.tv_usec;
2487be1d9176SMichael Tuexen 
2488b60b0fe6SMichael Tuexen 	/* compute rtt in ms */
2489b60b0fe6SMichael Tuexen 	rtt = (int32_t) (net->rtt / 1000);
2490f79aab18SRandall Stewart 	if ((asoc->cc_functions.sctp_rtt_calculated) && (rtt_from_sack == SCTP_RTT_FROM_DATA)) {
2491f79aab18SRandall Stewart 		/*
2492f79aab18SRandall Stewart 		 * Tell the CC module that a new update has just occurred
2493f79aab18SRandall Stewart 		 * from a sack
2494f79aab18SRandall Stewart 		 */
2495f79aab18SRandall Stewart 		(*asoc->cc_functions.sctp_rtt_calculated) (stcb, net, &now);
2496f79aab18SRandall Stewart 	}
2497f79aab18SRandall Stewart 	/*
2498f79aab18SRandall Stewart 	 * Do we need to determine the lan? We do this only on sacks i.e.
2499f79aab18SRandall Stewart 	 * RTT being determined from data not non-data (HB/INIT->INITACK).
2500f79aab18SRandall Stewart 	 */
2501f79aab18SRandall Stewart 	if ((rtt_from_sack == SCTP_RTT_FROM_DATA) &&
2502be1d9176SMichael Tuexen 	    (net->lan_type == SCTP_LAN_UNKNOWN)) {
2503be1d9176SMichael Tuexen 		if (net->rtt > SCTP_LOCAL_LAN_RTT) {
2504899288aeSRandall Stewart 			net->lan_type = SCTP_LAN_INTERNET;
2505899288aeSRandall Stewart 		} else {
2506899288aeSRandall Stewart 			net->lan_type = SCTP_LAN_LOCAL;
2507899288aeSRandall Stewart 		}
2508899288aeSRandall Stewart 	}
2509f8829a4aSRandall Stewart 	/***************************/
2510f8829a4aSRandall Stewart 	/* 2. update RTTVAR & SRTT */
2511f8829a4aSRandall Stewart 	/***************************/
2512be1d9176SMichael Tuexen 	/*-
2513be1d9176SMichael Tuexen 	 * Compute the scaled average lastsa and the
2514be1d9176SMichael Tuexen 	 * scaled variance lastsv as described in van Jacobson
2515be1d9176SMichael Tuexen 	 * Paper "Congestion Avoidance and Control", Annex A.
2516be1d9176SMichael Tuexen 	 *
2517be1d9176SMichael Tuexen 	 * (net->lastsa >> SCTP_RTT_SHIFT) is the srtt
2518be1d9176SMichael Tuexen 	 * (net->lastsa >> SCTP_RTT_VAR_SHIFT) is the rttvar
2519be1d9176SMichael Tuexen 	 */
25209a972525SRandall Stewart 	if (net->RTO_measured) {
2521be1d9176SMichael Tuexen 		rtt -= (net->lastsa >> SCTP_RTT_SHIFT);
2522be1d9176SMichael Tuexen 		net->lastsa += rtt;
2523be1d9176SMichael Tuexen 		if (rtt < 0) {
2524be1d9176SMichael Tuexen 			rtt = -rtt;
2525be1d9176SMichael Tuexen 		}
2526be1d9176SMichael Tuexen 		rtt -= (net->lastsv >> SCTP_RTT_VAR_SHIFT);
2527be1d9176SMichael Tuexen 		net->lastsv += rtt;
2528b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RTTVAR_LOGGING_ENABLE) {
2529f8829a4aSRandall Stewart 			rto_logging(net, SCTP_LOG_RTTVAR);
253080fefe0aSRandall Stewart 		}
2531f8829a4aSRandall Stewart 	} else {
2532f8829a4aSRandall Stewart 		/* First RTO measurment */
25339a972525SRandall Stewart 		net->RTO_measured = 1;
2534f8829a4aSRandall Stewart 		first_measure = 1;
2535be1d9176SMichael Tuexen 		net->lastsa = rtt << SCTP_RTT_SHIFT;
2536be1d9176SMichael Tuexen 		net->lastsv = (rtt / 2) << SCTP_RTT_VAR_SHIFT;
2537b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RTTVAR_LOGGING_ENABLE) {
2538f8829a4aSRandall Stewart 			rto_logging(net, SCTP_LOG_INITIAL_RTT);
253980fefe0aSRandall Stewart 		}
2540f8829a4aSRandall Stewart 	}
2541be1d9176SMichael Tuexen 	if (net->lastsv == 0) {
2542be1d9176SMichael Tuexen 		net->lastsv = SCTP_CLOCK_GRANULARITY;
2543be1d9176SMichael Tuexen 	}
2544108df27cSRandall Stewart 	new_rto = (net->lastsa >> SCTP_RTT_SHIFT) + net->lastsv;
2545f8829a4aSRandall Stewart 	if ((new_rto > SCTP_SAT_NETWORK_MIN) &&
2546f8829a4aSRandall Stewart 	    (stcb->asoc.sat_network_lockout == 0)) {
2547f8829a4aSRandall Stewart 		stcb->asoc.sat_network = 1;
2548f8829a4aSRandall Stewart 	} else if ((!first_measure) && stcb->asoc.sat_network) {
2549f8829a4aSRandall Stewart 		stcb->asoc.sat_network = 0;
2550f8829a4aSRandall Stewart 		stcb->asoc.sat_network_lockout = 1;
2551f8829a4aSRandall Stewart 	}
2552f8829a4aSRandall Stewart 	/* bound it, per C6/C7 in Section 5.3.1 */
2553f8829a4aSRandall Stewart 	if (new_rto < stcb->asoc.minrto) {
2554f8829a4aSRandall Stewart 		new_rto = stcb->asoc.minrto;
2555f8829a4aSRandall Stewart 	}
2556f8829a4aSRandall Stewart 	if (new_rto > stcb->asoc.maxrto) {
2557f8829a4aSRandall Stewart 		new_rto = stcb->asoc.maxrto;
2558f8829a4aSRandall Stewart 	}
25595e54f665SRandall Stewart 	/* we are now returning the RTO */
25605e54f665SRandall Stewart 	return (new_rto);
2561f8829a4aSRandall Stewart }
2562f8829a4aSRandall Stewart 
2563f8829a4aSRandall Stewart /*
2564f8829a4aSRandall Stewart  * return a pointer to a contiguous piece of data from the given mbuf chain
2565f8829a4aSRandall Stewart  * starting at 'off' for 'len' bytes.  If the desired piece spans more than
2566f8829a4aSRandall Stewart  * one mbuf, a copy is made at 'ptr'. caller must ensure that the buffer size
2567f8829a4aSRandall Stewart  * is >= 'len' returns NULL if there there isn't 'len' bytes in the chain.
2568f8829a4aSRandall Stewart  */
256972fb6fdbSRandall Stewart caddr_t
2570f8829a4aSRandall Stewart sctp_m_getptr(struct mbuf *m, int off, int len, uint8_t * in_ptr)
2571f8829a4aSRandall Stewart {
2572f8829a4aSRandall Stewart 	uint32_t count;
2573f8829a4aSRandall Stewart 	uint8_t *ptr;
2574f8829a4aSRandall Stewart 
2575f8829a4aSRandall Stewart 	ptr = in_ptr;
2576f8829a4aSRandall Stewart 	if ((off < 0) || (len <= 0))
2577f8829a4aSRandall Stewart 		return (NULL);
2578f8829a4aSRandall Stewart 
2579f8829a4aSRandall Stewart 	/* find the desired start location */
2580f8829a4aSRandall Stewart 	while ((m != NULL) && (off > 0)) {
2581139bc87fSRandall Stewart 		if (off < SCTP_BUF_LEN(m))
2582f8829a4aSRandall Stewart 			break;
2583139bc87fSRandall Stewart 		off -= SCTP_BUF_LEN(m);
2584139bc87fSRandall Stewart 		m = SCTP_BUF_NEXT(m);
2585f8829a4aSRandall Stewart 	}
2586f8829a4aSRandall Stewart 	if (m == NULL)
2587f8829a4aSRandall Stewart 		return (NULL);
2588f8829a4aSRandall Stewart 
2589f8829a4aSRandall Stewart 	/* is the current mbuf large enough (eg. contiguous)? */
2590139bc87fSRandall Stewart 	if ((SCTP_BUF_LEN(m) - off) >= len) {
2591f8829a4aSRandall Stewart 		return (mtod(m, caddr_t)+off);
2592f8829a4aSRandall Stewart 	} else {
2593f8829a4aSRandall Stewart 		/* else, it spans more than one mbuf, so save a temp copy... */
2594f8829a4aSRandall Stewart 		while ((m != NULL) && (len > 0)) {
2595139bc87fSRandall Stewart 			count = min(SCTP_BUF_LEN(m) - off, len);
2596f8829a4aSRandall Stewart 			bcopy(mtod(m, caddr_t)+off, ptr, count);
2597f8829a4aSRandall Stewart 			len -= count;
2598f8829a4aSRandall Stewart 			ptr += count;
2599f8829a4aSRandall Stewart 			off = 0;
2600139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
2601f8829a4aSRandall Stewart 		}
2602f8829a4aSRandall Stewart 		if ((m == NULL) && (len > 0))
2603f8829a4aSRandall Stewart 			return (NULL);
2604f8829a4aSRandall Stewart 		else
2605f8829a4aSRandall Stewart 			return ((caddr_t)in_ptr);
2606f8829a4aSRandall Stewart 	}
2607f8829a4aSRandall Stewart }
2608f8829a4aSRandall Stewart 
2609f8829a4aSRandall Stewart 
261044b7479bSRandall Stewart 
2611f8829a4aSRandall Stewart struct sctp_paramhdr *
2612f8829a4aSRandall Stewart sctp_get_next_param(struct mbuf *m,
2613f8829a4aSRandall Stewart     int offset,
2614f8829a4aSRandall Stewart     struct sctp_paramhdr *pull,
2615f8829a4aSRandall Stewart     int pull_limit)
2616f8829a4aSRandall Stewart {
2617f8829a4aSRandall Stewart 	/* This just provides a typed signature to Peter's Pull routine */
2618f8829a4aSRandall Stewart 	return ((struct sctp_paramhdr *)sctp_m_getptr(m, offset, pull_limit,
2619f8829a4aSRandall Stewart 	    (uint8_t *) pull));
2620f8829a4aSRandall Stewart }
2621f8829a4aSRandall Stewart 
2622f8829a4aSRandall Stewart 
2623ce11b842SMichael Tuexen struct mbuf *
2624f8829a4aSRandall Stewart sctp_add_pad_tombuf(struct mbuf *m, int padlen)
2625f8829a4aSRandall Stewart {
2626ce11b842SMichael Tuexen 	struct mbuf *m_last;
2627ce11b842SMichael Tuexen 	caddr_t dp;
2628f8829a4aSRandall Stewart 
2629f8829a4aSRandall Stewart 	if (padlen > 3) {
2630ce11b842SMichael Tuexen 		return (NULL);
2631f8829a4aSRandall Stewart 	}
263241eee555SRandall Stewart 	if (padlen <= M_TRAILINGSPACE(m)) {
2633f8829a4aSRandall Stewart 		/*
2634f8829a4aSRandall Stewart 		 * The easy way. We hope the majority of the time we hit
2635f8829a4aSRandall Stewart 		 * here :)
2636f8829a4aSRandall Stewart 		 */
2637ce11b842SMichael Tuexen 		m_last = m;
2638f8829a4aSRandall Stewart 	} else {
2639ce11b842SMichael Tuexen 		/* Hard way we must grow the mbuf chain */
2640ce11b842SMichael Tuexen 		m_last = sctp_get_mbuf_for_msg(padlen, 0, M_NOWAIT, 1, MT_DATA);
2641ce11b842SMichael Tuexen 		if (m_last == NULL) {
2642ce11b842SMichael Tuexen 			return (NULL);
2643f8829a4aSRandall Stewart 		}
2644ce11b842SMichael Tuexen 		SCTP_BUF_LEN(m_last) = 0;
2645ce11b842SMichael Tuexen 		SCTP_BUF_NEXT(m_last) = NULL;
2646ce11b842SMichael Tuexen 		SCTP_BUF_NEXT(m) = m_last;
2647f8829a4aSRandall Stewart 	}
2648ce11b842SMichael Tuexen 	dp = mtod(m_last, caddr_t)+SCTP_BUF_LEN(m_last);
2649ce11b842SMichael Tuexen 	SCTP_BUF_LEN(m_last) += padlen;
2650ce11b842SMichael Tuexen 	memset(dp, 0, padlen);
2651ce11b842SMichael Tuexen 	return (m_last);
2652f8829a4aSRandall Stewart }
2653f8829a4aSRandall Stewart 
2654ce11b842SMichael Tuexen struct mbuf *
2655f8829a4aSRandall Stewart sctp_pad_lastmbuf(struct mbuf *m, int padval, struct mbuf *last_mbuf)
2656f8829a4aSRandall Stewart {
2657f8829a4aSRandall Stewart 	/* find the last mbuf in chain and pad it */
2658f8829a4aSRandall Stewart 	struct mbuf *m_at;
2659f8829a4aSRandall Stewart 
2660ce11b842SMichael Tuexen 	if (last_mbuf != NULL) {
2661f8829a4aSRandall Stewart 		return (sctp_add_pad_tombuf(last_mbuf, padval));
2662f8829a4aSRandall Stewart 	} else {
266317267b32SMichael Tuexen 		for (m_at = m; m_at; m_at = SCTP_BUF_NEXT(m_at)) {
2664139bc87fSRandall Stewart 			if (SCTP_BUF_NEXT(m_at) == NULL) {
2665f8829a4aSRandall Stewart 				return (sctp_add_pad_tombuf(m_at, padval));
2666f8829a4aSRandall Stewart 			}
2667f8829a4aSRandall Stewart 		}
2668f8829a4aSRandall Stewart 	}
2669ce11b842SMichael Tuexen 	return (NULL);
2670f8829a4aSRandall Stewart }
2671f8829a4aSRandall Stewart 
2672f8829a4aSRandall Stewart static void
2673c5b5675dSMichael Tuexen sctp_notify_assoc_change(uint16_t state, struct sctp_tcb *stcb,
2674410a3b1eSMichael Tuexen     uint16_t error, struct sctp_abort_chunk *abort, uint8_t from_peer, int so_locked
2675ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
2676ceaad40aSRandall Stewart     SCTP_UNUSED
2677ceaad40aSRandall Stewart #endif
2678ceaad40aSRandall Stewart )
2679f8829a4aSRandall Stewart {
2680f8829a4aSRandall Stewart 	struct mbuf *m_notify;
2681f8829a4aSRandall Stewart 	struct sctp_assoc_change *sac;
2682f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
26839a8e3088SMichael Tuexen 	unsigned int notif_len;
26849a8e3088SMichael Tuexen 	uint16_t abort_len;
2685e06b67c7SMichael Tuexen 	unsigned int i;
2686f8829a4aSRandall Stewart 
2687ceaad40aSRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2688ceaad40aSRandall Stewart 	struct socket *so;
2689ceaad40aSRandall Stewart 
2690ceaad40aSRandall Stewart #endif
2691ceaad40aSRandall Stewart 
269259713bbfSMichael Tuexen 	if (stcb == NULL) {
269359713bbfSMichael Tuexen 		return;
269459713bbfSMichael Tuexen 	}
269558411b08SMichael Tuexen 	if (sctp_stcb_is_feature_on(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVASSOCEVNT)) {
26969a8e3088SMichael Tuexen 		notif_len = (unsigned int)sizeof(struct sctp_assoc_change);
2697a2b42326SMichael Tuexen 		if (abort != NULL) {
2698c9eb4473SMichael Tuexen 			abort_len = ntohs(abort->ch.chunk_length);
2699a2b42326SMichael Tuexen 		} else {
2700a2b42326SMichael Tuexen 			abort_len = 0;
2701c5b5675dSMichael Tuexen 		}
2702a2b42326SMichael Tuexen 		if ((state == SCTP_COMM_UP) || (state == SCTP_RESTART)) {
2703a2b42326SMichael Tuexen 			notif_len += SCTP_ASSOC_SUPPORTS_MAX;
2704a2b42326SMichael Tuexen 		} else if ((state == SCTP_COMM_LOST) || (state == SCTP_CANT_STR_ASSOC)) {
2705a2b42326SMichael Tuexen 			notif_len += abort_len;
2706a2b42326SMichael Tuexen 		}
2707eb1b1807SGleb Smirnoff 		m_notify = sctp_get_mbuf_for_msg(notif_len, 0, M_NOWAIT, 1, MT_DATA);
2708a2b42326SMichael Tuexen 		if (m_notify == NULL) {
2709a2b42326SMichael Tuexen 			/* Retry with smaller value. */
27109a8e3088SMichael Tuexen 			notif_len = (unsigned int)sizeof(struct sctp_assoc_change);
2711eb1b1807SGleb Smirnoff 			m_notify = sctp_get_mbuf_for_msg(notif_len, 0, M_NOWAIT, 1, MT_DATA);
2712a2b42326SMichael Tuexen 			if (m_notify == NULL) {
271358411b08SMichael Tuexen 				goto set_error;
2714a2b42326SMichael Tuexen 			}
2715a2b42326SMichael Tuexen 		}
2716a2b42326SMichael Tuexen 		SCTP_BUF_NEXT(m_notify) = NULL;
2717f8829a4aSRandall Stewart 		sac = mtod(m_notify, struct sctp_assoc_change *);
2718e432298aSXin LI 		memset(sac, 0, notif_len);
2719f8829a4aSRandall Stewart 		sac->sac_type = SCTP_ASSOC_CHANGE;
2720f8829a4aSRandall Stewart 		sac->sac_flags = 0;
2721f8829a4aSRandall Stewart 		sac->sac_length = sizeof(struct sctp_assoc_change);
2722c5b5675dSMichael Tuexen 		sac->sac_state = state;
2723f8829a4aSRandall Stewart 		sac->sac_error = error;
2724f8829a4aSRandall Stewart 		/* XXX verify these stream counts */
2725f8829a4aSRandall Stewart 		sac->sac_outbound_streams = stcb->asoc.streamoutcnt;
2726f8829a4aSRandall Stewart 		sac->sac_inbound_streams = stcb->asoc.streamincnt;
2727f8829a4aSRandall Stewart 		sac->sac_assoc_id = sctp_get_associd(stcb);
2728a2b42326SMichael Tuexen 		if (notif_len > sizeof(struct sctp_assoc_change)) {
2729c5b5675dSMichael Tuexen 			if ((state == SCTP_COMM_UP) || (state == SCTP_RESTART)) {
2730e06b67c7SMichael Tuexen 				i = 0;
2731c79bec9cSMichael Tuexen 				if (stcb->asoc.prsctp_supported == 1) {
2732e06b67c7SMichael Tuexen 					sac->sac_info[i++] = SCTP_ASSOC_SUPPORTS_PR;
2733e06b67c7SMichael Tuexen 				}
2734c79bec9cSMichael Tuexen 				if (stcb->asoc.auth_supported == 1) {
2735e06b67c7SMichael Tuexen 					sac->sac_info[i++] = SCTP_ASSOC_SUPPORTS_AUTH;
2736e06b67c7SMichael Tuexen 				}
2737c79bec9cSMichael Tuexen 				if (stcb->asoc.asconf_supported == 1) {
2738e06b67c7SMichael Tuexen 					sac->sac_info[i++] = SCTP_ASSOC_SUPPORTS_ASCONF;
2739e06b67c7SMichael Tuexen 				}
274044249214SRandall Stewart 				if (stcb->asoc.idata_supported == 1) {
274144249214SRandall Stewart 					sac->sac_info[i++] = SCTP_ASSOC_SUPPORTS_INTERLEAVING;
274244249214SRandall Stewart 				}
2743e06b67c7SMichael Tuexen 				sac->sac_info[i++] = SCTP_ASSOC_SUPPORTS_MULTIBUF;
2744c79bec9cSMichael Tuexen 				if (stcb->asoc.reconfig_supported == 1) {
2745e06b67c7SMichael Tuexen 					sac->sac_info[i++] = SCTP_ASSOC_SUPPORTS_RE_CONFIG;
2746e06b67c7SMichael Tuexen 				}
2747e06b67c7SMichael Tuexen 				sac->sac_length += i;
2748a2b42326SMichael Tuexen 			} else if ((state == SCTP_COMM_LOST) || (state == SCTP_CANT_STR_ASSOC)) {
2749a2b42326SMichael Tuexen 				memcpy(sac->sac_info, abort, abort_len);
2750a2b42326SMichael Tuexen 				sac->sac_length += abort_len;
2751a2b42326SMichael Tuexen 			}
2752c5b5675dSMichael Tuexen 		}
2753e06b67c7SMichael Tuexen 		SCTP_BUF_LEN(m_notify) = sac->sac_length;
2754f8829a4aSRandall Stewart 		control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
27557215cc1bSMichael Tuexen 		    0, 0, stcb->asoc.context, 0, 0, 0,
2756f8829a4aSRandall Stewart 		    m_notify);
275758411b08SMichael Tuexen 		if (control != NULL) {
2758139bc87fSRandall Stewart 			control->length = SCTP_BUF_LEN(m_notify);
2759f8829a4aSRandall Stewart 			/* not that we need this */
2760f8829a4aSRandall Stewart 			control->tail_mbuf = m_notify;
2761139bc87fSRandall Stewart 			control->spec_flags = M_NOTIFICATION;
2762f8829a4aSRandall Stewart 			sctp_add_to_readq(stcb->sctp_ep, stcb,
2763f8829a4aSRandall Stewart 			    control,
2764cfde3ff7SRandall Stewart 			    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD,
2765cfde3ff7SRandall Stewart 			    so_locked);
276658411b08SMichael Tuexen 		} else {
276758411b08SMichael Tuexen 			sctp_m_freem(m_notify);
276858411b08SMichael Tuexen 		}
276958411b08SMichael Tuexen 	}
277058411b08SMichael Tuexen 	/*
277158411b08SMichael Tuexen 	 * For 1-to-1 style sockets, we send up and error when an ABORT
277258411b08SMichael Tuexen 	 * comes in.
277358411b08SMichael Tuexen 	 */
277458411b08SMichael Tuexen set_error:
277558411b08SMichael Tuexen 	if (((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
277658411b08SMichael Tuexen 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) &&
277758411b08SMichael Tuexen 	    ((state == SCTP_COMM_LOST) || (state == SCTP_CANT_STR_ASSOC))) {
2778e045904fSMichael Tuexen 		SOCK_LOCK(stcb->sctp_socket);
2779410a3b1eSMichael Tuexen 		if (from_peer) {
278058411b08SMichael Tuexen 			if (SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_COOKIE_WAIT) {
278158411b08SMichael Tuexen 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ECONNREFUSED);
278258411b08SMichael Tuexen 				stcb->sctp_socket->so_error = ECONNREFUSED;
278358411b08SMichael Tuexen 			} else {
278458411b08SMichael Tuexen 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ECONNRESET);
278558411b08SMichael Tuexen 				stcb->sctp_socket->so_error = ECONNRESET;
278658411b08SMichael Tuexen 			}
2787410a3b1eSMichael Tuexen 		} else {
2788553bb068SMichael Tuexen 			if ((SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_COOKIE_WAIT) ||
2789553bb068SMichael Tuexen 			    (SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_COOKIE_ECHOED)) {
2790553bb068SMichael Tuexen 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ETIMEDOUT);
2791553bb068SMichael Tuexen 				stcb->sctp_socket->so_error = ETIMEDOUT;
2792553bb068SMichael Tuexen 			} else {
2793410a3b1eSMichael Tuexen 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ECONNABORTED);
2794410a3b1eSMichael Tuexen 				stcb->sctp_socket->so_error = ECONNABORTED;
2795410a3b1eSMichael Tuexen 			}
279658411b08SMichael Tuexen 		}
2797553bb068SMichael Tuexen 	}
279858411b08SMichael Tuexen 	/* Wake ANY sleepers */
2799ceaad40aSRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2800ceaad40aSRandall Stewart 	so = SCTP_INP_SO(stcb->sctp_ep);
2801ceaad40aSRandall Stewart 	if (!so_locked) {
2802ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
2803ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
2804ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
2805ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
2806ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
2807ceaad40aSRandall Stewart 		if (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET) {
2808ceaad40aSRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
2809ceaad40aSRandall Stewart 			return;
2810ceaad40aSRandall Stewart 		}
2811ceaad40aSRandall Stewart 	}
2812ceaad40aSRandall Stewart #endif
281358411b08SMichael Tuexen 	if (((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
281458411b08SMichael Tuexen 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) &&
281558411b08SMichael Tuexen 	    ((state == SCTP_COMM_LOST) || (state == SCTP_CANT_STR_ASSOC))) {
2816e045904fSMichael Tuexen 		socantrcvmore_locked(stcb->sctp_socket);
281758411b08SMichael Tuexen 	}
281858411b08SMichael Tuexen 	sorwakeup(stcb->sctp_socket);
281958411b08SMichael Tuexen 	sowwakeup(stcb->sctp_socket);
2820ceaad40aSRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2821ceaad40aSRandall Stewart 	if (!so_locked) {
2822ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
2823ceaad40aSRandall Stewart 	}
2824ceaad40aSRandall Stewart #endif
2825f8829a4aSRandall Stewart }
2826f8829a4aSRandall Stewart 
2827f8829a4aSRandall Stewart static void
2828f8829a4aSRandall Stewart sctp_notify_peer_addr_change(struct sctp_tcb *stcb, uint32_t state,
28293cb3567dSMichael Tuexen     struct sockaddr *sa, uint32_t error, int so_locked
28303cb3567dSMichael Tuexen #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
28313cb3567dSMichael Tuexen     SCTP_UNUSED
28323cb3567dSMichael Tuexen #endif
28333cb3567dSMichael Tuexen )
2834f8829a4aSRandall Stewart {
2835f8829a4aSRandall Stewart 	struct mbuf *m_notify;
2836f8829a4aSRandall Stewart 	struct sctp_paddr_change *spc;
2837f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
2838f8829a4aSRandall Stewart 
283960990c0cSMichael Tuexen 	if ((stcb == NULL) ||
284060990c0cSMichael Tuexen 	    sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVPADDREVNT)) {
2841f8829a4aSRandall Stewart 		/* event not enabled */
2842f8829a4aSRandall Stewart 		return;
2843830d754dSRandall Stewart 	}
2844eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_paddr_change), 0, M_NOWAIT, 1, MT_DATA);
2845f8829a4aSRandall Stewart 	if (m_notify == NULL)
2846f8829a4aSRandall Stewart 		return;
2847139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
2848f8829a4aSRandall Stewart 	spc = mtod(m_notify, struct sctp_paddr_change *);
284956711f94SMichael Tuexen 	memset(spc, 0, sizeof(struct sctp_paddr_change));
2850f8829a4aSRandall Stewart 	spc->spc_type = SCTP_PEER_ADDR_CHANGE;
2851f8829a4aSRandall Stewart 	spc->spc_flags = 0;
2852f8829a4aSRandall Stewart 	spc->spc_length = sizeof(struct sctp_paddr_change);
28535e2c2d87SRandall Stewart 	switch (sa->sa_family) {
2854ea5eba11SMichael Tuexen #ifdef INET
28555e2c2d87SRandall Stewart 	case AF_INET:
2856d59107f7SMichael Tuexen #ifdef INET6
2857d59107f7SMichael Tuexen 		if (sctp_is_feature_on(stcb->sctp_ep, SCTP_PCB_FLAGS_NEEDS_MAPPED_V4)) {
2858d59107f7SMichael Tuexen 			in6_sin_2_v4mapsin6((struct sockaddr_in *)sa,
2859d59107f7SMichael Tuexen 			    (struct sockaddr_in6 *)&spc->spc_aaddr);
2860d59107f7SMichael Tuexen 		} else {
2861f8829a4aSRandall Stewart 			memcpy(&spc->spc_aaddr, sa, sizeof(struct sockaddr_in));
2862d59107f7SMichael Tuexen 		}
2863d59107f7SMichael Tuexen #else
2864d59107f7SMichael Tuexen 		memcpy(&spc->spc_aaddr, sa, sizeof(struct sockaddr_in));
2865d59107f7SMichael Tuexen #endif
28665e2c2d87SRandall Stewart 		break;
2867ea5eba11SMichael Tuexen #endif
28685e2c2d87SRandall Stewart #ifdef INET6
28695e2c2d87SRandall Stewart 	case AF_INET6:
28705e2c2d87SRandall Stewart 		{
2871f42a358aSRandall Stewart 			struct sockaddr_in6 *sin6;
2872f42a358aSRandall Stewart 
2873f8829a4aSRandall Stewart 			memcpy(&spc->spc_aaddr, sa, sizeof(struct sockaddr_in6));
2874f42a358aSRandall Stewart 
2875f42a358aSRandall Stewart 			sin6 = (struct sockaddr_in6 *)&spc->spc_aaddr;
2876f42a358aSRandall Stewart 			if (IN6_IS_SCOPE_LINKLOCAL(&sin6->sin6_addr)) {
287742551e99SRandall Stewart 				if (sin6->sin6_scope_id == 0) {
287842551e99SRandall Stewart 					/* recover scope_id for user */
2879f42a358aSRandall Stewart 					(void)sa6_recoverscope(sin6);
288042551e99SRandall Stewart 				} else {
288142551e99SRandall Stewart 					/* clear embedded scope_id for user */
288242551e99SRandall Stewart 					in6_clearscope(&sin6->sin6_addr);
288342551e99SRandall Stewart 				}
2884f42a358aSRandall Stewart 			}
28855e2c2d87SRandall Stewart 			break;
28865e2c2d87SRandall Stewart 		}
28875e2c2d87SRandall Stewart #endif
28885e2c2d87SRandall Stewart 	default:
28895e2c2d87SRandall Stewart 		/* TSNH */
28905e2c2d87SRandall Stewart 		break;
2891f8829a4aSRandall Stewart 	}
2892f8829a4aSRandall Stewart 	spc->spc_state = state;
2893f8829a4aSRandall Stewart 	spc->spc_error = error;
2894f8829a4aSRandall Stewart 	spc->spc_assoc_id = sctp_get_associd(stcb);
2895f8829a4aSRandall Stewart 
2896139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_paddr_change);
2897139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
2898f8829a4aSRandall Stewart 
2899f8829a4aSRandall Stewart 	/* append to socket */
2900f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
29017215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
2902f8829a4aSRandall Stewart 	    m_notify);
2903f8829a4aSRandall Stewart 	if (control == NULL) {
2904f8829a4aSRandall Stewart 		/* no memory */
2905f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
2906f8829a4aSRandall Stewart 		return;
2907f8829a4aSRandall Stewart 	}
2908139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
2909139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
2910f8829a4aSRandall Stewart 	/* not that we need this */
2911f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
2912f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
2913f8829a4aSRandall Stewart 	    control,
2914cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1,
2915cfde3ff7SRandall Stewart 	    SCTP_READ_LOCK_NOT_HELD,
29163cb3567dSMichael Tuexen 	    so_locked);
2917f8829a4aSRandall Stewart }
2918f8829a4aSRandall Stewart 
2919f8829a4aSRandall Stewart 
2920f8829a4aSRandall Stewart static void
29211edc9dbaSMichael Tuexen sctp_notify_send_failed(struct sctp_tcb *stcb, uint8_t sent, uint32_t error,
2922ceaad40aSRandall Stewart     struct sctp_tmit_chunk *chk, int so_locked
2923ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
2924ceaad40aSRandall Stewart     SCTP_UNUSED
2925ceaad40aSRandall Stewart #endif
2926ceaad40aSRandall Stewart )
2927f8829a4aSRandall Stewart {
2928830d754dSRandall Stewart 	struct mbuf *m_notify;
2929f8829a4aSRandall Stewart 	struct sctp_send_failed *ssf;
29309935403aSMichael Tuexen 	struct sctp_send_failed_event *ssfe;
2931f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
2932f8829a4aSRandall Stewart 	int length;
2933f8829a4aSRandall Stewart 
293460990c0cSMichael Tuexen 	if ((stcb == NULL) ||
29359935403aSMichael Tuexen 	    (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVSENDFAILEVNT) &&
29369935403aSMichael Tuexen 	    sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVNSENDFAILEVNT))) {
2937f8829a4aSRandall Stewart 		/* event not enabled */
2938f8829a4aSRandall Stewart 		return;
2939830d754dSRandall Stewart 	}
29409935403aSMichael Tuexen 	if (sctp_stcb_is_feature_on(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVNSENDFAILEVNT)) {
29419935403aSMichael Tuexen 		length = sizeof(struct sctp_send_failed_event);
29429935403aSMichael Tuexen 	} else {
29439935403aSMichael Tuexen 		length = sizeof(struct sctp_send_failed);
29449935403aSMichael Tuexen 	}
2945eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(length, 0, M_NOWAIT, 1, MT_DATA);
2946f8829a4aSRandall Stewart 	if (m_notify == NULL)
2947f8829a4aSRandall Stewart 		/* no space left */
2948f8829a4aSRandall Stewart 		return;
2949139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
29509935403aSMichael Tuexen 	if (sctp_stcb_is_feature_on(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVNSENDFAILEVNT)) {
29519935403aSMichael Tuexen 		ssfe = mtod(m_notify, struct sctp_send_failed_event *);
2952e432298aSXin LI 		memset(ssfe, 0, length);
29539935403aSMichael Tuexen 		ssfe->ssfe_type = SCTP_SEND_FAILED_EVENT;
29541edc9dbaSMichael Tuexen 		if (sent) {
29559935403aSMichael Tuexen 			ssfe->ssfe_flags = SCTP_DATA_SENT;
29561edc9dbaSMichael Tuexen 		} else {
29571edc9dbaSMichael Tuexen 			ssfe->ssfe_flags = SCTP_DATA_UNSENT;
29581edc9dbaSMichael Tuexen 		}
2959e432298aSXin LI 		length += chk->send_size;
2960e432298aSXin LI 		length -= sizeof(struct sctp_data_chunk);
29619935403aSMichael Tuexen 		ssfe->ssfe_length = length;
29629935403aSMichael Tuexen 		ssfe->ssfe_error = error;
29639935403aSMichael Tuexen 		/* not exactly what the user sent in, but should be close :) */
29649935403aSMichael Tuexen 		ssfe->ssfe_info.snd_sid = chk->rec.data.stream_number;
29659935403aSMichael Tuexen 		ssfe->ssfe_info.snd_flags = chk->rec.data.rcv_flags;
29669935403aSMichael Tuexen 		ssfe->ssfe_info.snd_ppid = chk->rec.data.payloadtype;
29679935403aSMichael Tuexen 		ssfe->ssfe_info.snd_context = chk->rec.data.context;
29689935403aSMichael Tuexen 		ssfe->ssfe_info.snd_assoc_id = sctp_get_associd(stcb);
29699935403aSMichael Tuexen 		ssfe->ssfe_assoc_id = sctp_get_associd(stcb);
29709935403aSMichael Tuexen 		SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_send_failed_event);
29719935403aSMichael Tuexen 	} else {
2972f8829a4aSRandall Stewart 		ssf = mtod(m_notify, struct sctp_send_failed *);
2973e432298aSXin LI 		memset(ssf, 0, length);
2974f8829a4aSRandall Stewart 		ssf->ssf_type = SCTP_SEND_FAILED;
29751edc9dbaSMichael Tuexen 		if (sent) {
2976f8829a4aSRandall Stewart 			ssf->ssf_flags = SCTP_DATA_SENT;
29771edc9dbaSMichael Tuexen 		} else {
29781edc9dbaSMichael Tuexen 			ssf->ssf_flags = SCTP_DATA_UNSENT;
29791edc9dbaSMichael Tuexen 		}
2980e432298aSXin LI 		length += chk->send_size;
2981e432298aSXin LI 		length -= sizeof(struct sctp_data_chunk);
2982f8829a4aSRandall Stewart 		ssf->ssf_length = length;
2983f8829a4aSRandall Stewart 		ssf->ssf_error = error;
2984f8829a4aSRandall Stewart 		/* not exactly what the user sent in, but should be close :) */
2985d00aff5dSRandall Stewart 		bzero(&ssf->ssf_info, sizeof(ssf->ssf_info));
2986f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_stream = chk->rec.data.stream_number;
2987f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_ssn = chk->rec.data.stream_seq;
2988f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_flags = chk->rec.data.rcv_flags;
2989f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_ppid = chk->rec.data.payloadtype;
2990f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_context = chk->rec.data.context;
2991f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_assoc_id = sctp_get_associd(stcb);
2992f8829a4aSRandall Stewart 		ssf->ssf_assoc_id = sctp_get_associd(stcb);
29939935403aSMichael Tuexen 		SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_send_failed);
29949935403aSMichael Tuexen 	}
2995830d754dSRandall Stewart 	if (chk->data) {
2996830d754dSRandall Stewart 		/*
2997830d754dSRandall Stewart 		 * trim off the sctp chunk header(it should be there)
2998830d754dSRandall Stewart 		 */
2999830d754dSRandall Stewart 		if (chk->send_size >= sizeof(struct sctp_data_chunk)) {
3000830d754dSRandall Stewart 			m_adj(chk->data, sizeof(struct sctp_data_chunk));
3001830d754dSRandall Stewart 			sctp_mbuf_crush(chk->data);
3002830d754dSRandall Stewart 			chk->send_size -= sizeof(struct sctp_data_chunk);
3003830d754dSRandall Stewart 		}
3004830d754dSRandall Stewart 	}
3005810ec536SMichael Tuexen 	SCTP_BUF_NEXT(m_notify) = chk->data;
3006f8829a4aSRandall Stewart 	/* Steal off the mbuf */
3007f8829a4aSRandall Stewart 	chk->data = NULL;
3008f8829a4aSRandall Stewart 	/*
3009f8829a4aSRandall Stewart 	 * For this case, we check the actual socket buffer, since the assoc
3010f8829a4aSRandall Stewart 	 * is going away we don't want to overfill the socket buffer for a
3011f8829a4aSRandall Stewart 	 * non-reader
3012f8829a4aSRandall Stewart 	 */
3013139bc87fSRandall Stewart 	if (sctp_sbspace_failedmsgs(&stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3014f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3015f8829a4aSRandall Stewart 		return;
3016f8829a4aSRandall Stewart 	}
3017f8829a4aSRandall Stewart 	/* append to socket */
3018f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
30197215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3020f8829a4aSRandall Stewart 	    m_notify);
3021f8829a4aSRandall Stewart 	if (control == NULL) {
3022f8829a4aSRandall Stewart 		/* no memory */
3023f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3024f8829a4aSRandall Stewart 		return;
3025f8829a4aSRandall Stewart 	}
3026139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3027f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3028f8829a4aSRandall Stewart 	    control,
3029cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1,
3030cfde3ff7SRandall Stewart 	    SCTP_READ_LOCK_NOT_HELD,
3031cfde3ff7SRandall Stewart 	    so_locked);
3032f8829a4aSRandall Stewart }
3033f8829a4aSRandall Stewart 
3034f8829a4aSRandall Stewart 
3035f8829a4aSRandall Stewart static void
3036f8829a4aSRandall Stewart sctp_notify_send_failed2(struct sctp_tcb *stcb, uint32_t error,
3037ceaad40aSRandall Stewart     struct sctp_stream_queue_pending *sp, int so_locked
3038ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3039ceaad40aSRandall Stewart     SCTP_UNUSED
3040ceaad40aSRandall Stewart #endif
3041ceaad40aSRandall Stewart )
3042f8829a4aSRandall Stewart {
3043f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3044f8829a4aSRandall Stewart 	struct sctp_send_failed *ssf;
30459935403aSMichael Tuexen 	struct sctp_send_failed_event *ssfe;
3046f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3047f8829a4aSRandall Stewart 	int length;
3048f8829a4aSRandall Stewart 
304960990c0cSMichael Tuexen 	if ((stcb == NULL) ||
30509935403aSMichael Tuexen 	    (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVSENDFAILEVNT) &&
30519935403aSMichael Tuexen 	    sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVNSENDFAILEVNT))) {
3052f8829a4aSRandall Stewart 		/* event not enabled */
3053f8829a4aSRandall Stewart 		return;
3054830d754dSRandall Stewart 	}
30559935403aSMichael Tuexen 	if (sctp_stcb_is_feature_on(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVNSENDFAILEVNT)) {
30569935403aSMichael Tuexen 		length = sizeof(struct sctp_send_failed_event);
30579935403aSMichael Tuexen 	} else {
30589935403aSMichael Tuexen 		length = sizeof(struct sctp_send_failed);
30599935403aSMichael Tuexen 	}
3060eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(length, 0, M_NOWAIT, 1, MT_DATA);
30619935403aSMichael Tuexen 	if (m_notify == NULL) {
3062f8829a4aSRandall Stewart 		/* no space left */
3063f8829a4aSRandall Stewart 		return;
30649935403aSMichael Tuexen 	}
3065139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
30669935403aSMichael Tuexen 	if (sctp_stcb_is_feature_on(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVNSENDFAILEVNT)) {
30679935403aSMichael Tuexen 		ssfe = mtod(m_notify, struct sctp_send_failed_event *);
3068e432298aSXin LI 		memset(ssfe, 0, length);
3069ad83c8a5SMichael Tuexen 		ssfe->ssfe_type = SCTP_SEND_FAILED_EVENT;
30709935403aSMichael Tuexen 		ssfe->ssfe_flags = SCTP_DATA_UNSENT;
3071e432298aSXin LI 		length += sp->length;
30729935403aSMichael Tuexen 		ssfe->ssfe_length = length;
30739935403aSMichael Tuexen 		ssfe->ssfe_error = error;
30749935403aSMichael Tuexen 		/* not exactly what the user sent in, but should be close :) */
30759935403aSMichael Tuexen 		ssfe->ssfe_info.snd_sid = sp->stream;
30769935403aSMichael Tuexen 		if (sp->some_taken) {
30779935403aSMichael Tuexen 			ssfe->ssfe_info.snd_flags = SCTP_DATA_LAST_FRAG;
30789935403aSMichael Tuexen 		} else {
30799935403aSMichael Tuexen 			ssfe->ssfe_info.snd_flags = SCTP_DATA_NOT_FRAG;
30809935403aSMichael Tuexen 		}
30819935403aSMichael Tuexen 		ssfe->ssfe_info.snd_ppid = sp->ppid;
30829935403aSMichael Tuexen 		ssfe->ssfe_info.snd_context = sp->context;
30839935403aSMichael Tuexen 		ssfe->ssfe_info.snd_assoc_id = sctp_get_associd(stcb);
30849935403aSMichael Tuexen 		ssfe->ssfe_assoc_id = sctp_get_associd(stcb);
30859935403aSMichael Tuexen 		SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_send_failed_event);
30869935403aSMichael Tuexen 	} else {
3087f8829a4aSRandall Stewart 		ssf = mtod(m_notify, struct sctp_send_failed *);
3088e432298aSXin LI 		memset(ssf, 0, length);
3089f8829a4aSRandall Stewart 		ssf->ssf_type = SCTP_SEND_FAILED;
3090f8829a4aSRandall Stewart 		ssf->ssf_flags = SCTP_DATA_UNSENT;
3091e432298aSXin LI 		length += sp->length;
3092f8829a4aSRandall Stewart 		ssf->ssf_length = length;
3093f8829a4aSRandall Stewart 		ssf->ssf_error = error;
3094f8829a4aSRandall Stewart 		/* not exactly what the user sent in, but should be close :) */
3095f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_stream = sp->stream;
3096f3b05218SMichael Tuexen 		ssf->ssf_info.sinfo_ssn = 0;
3097fc14de76SRandall Stewart 		if (sp->some_taken) {
3098fc14de76SRandall Stewart 			ssf->ssf_info.sinfo_flags = SCTP_DATA_LAST_FRAG;
3099fc14de76SRandall Stewart 		} else {
3100fc14de76SRandall Stewart 			ssf->ssf_info.sinfo_flags = SCTP_DATA_NOT_FRAG;
3101fc14de76SRandall Stewart 		}
3102f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_ppid = sp->ppid;
3103f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_context = sp->context;
3104f8829a4aSRandall Stewart 		ssf->ssf_info.sinfo_assoc_id = sctp_get_associd(stcb);
3105f8829a4aSRandall Stewart 		ssf->ssf_assoc_id = sctp_get_associd(stcb);
3106139bc87fSRandall Stewart 		SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_send_failed);
31079935403aSMichael Tuexen 	}
31089935403aSMichael Tuexen 	SCTP_BUF_NEXT(m_notify) = sp->data;
3109f8829a4aSRandall Stewart 
3110f8829a4aSRandall Stewart 	/* Steal off the mbuf */
3111f8829a4aSRandall Stewart 	sp->data = NULL;
3112f8829a4aSRandall Stewart 	/*
3113f8829a4aSRandall Stewart 	 * For this case, we check the actual socket buffer, since the assoc
3114f8829a4aSRandall Stewart 	 * is going away we don't want to overfill the socket buffer for a
3115f8829a4aSRandall Stewart 	 * non-reader
3116f8829a4aSRandall Stewart 	 */
3117139bc87fSRandall Stewart 	if (sctp_sbspace_failedmsgs(&stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3118f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3119f8829a4aSRandall Stewart 		return;
3120f8829a4aSRandall Stewart 	}
3121f8829a4aSRandall Stewart 	/* append to socket */
3122f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
31237215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3124f8829a4aSRandall Stewart 	    m_notify);
3125f8829a4aSRandall Stewart 	if (control == NULL) {
3126f8829a4aSRandall Stewart 		/* no memory */
3127f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3128f8829a4aSRandall Stewart 		return;
3129f8829a4aSRandall Stewart 	}
3130139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3131f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3132f8829a4aSRandall Stewart 	    control,
3133cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, so_locked);
3134f8829a4aSRandall Stewart }
3135f8829a4aSRandall Stewart 
3136f8829a4aSRandall Stewart 
3137f8829a4aSRandall Stewart 
3138f8829a4aSRandall Stewart static void
31397215cc1bSMichael Tuexen sctp_notify_adaptation_layer(struct sctp_tcb *stcb)
3140f8829a4aSRandall Stewart {
3141f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3142f8829a4aSRandall Stewart 	struct sctp_adaptation_event *sai;
3143f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3144f8829a4aSRandall Stewart 
314560990c0cSMichael Tuexen 	if ((stcb == NULL) ||
314660990c0cSMichael Tuexen 	    sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_ADAPTATIONEVNT)) {
3147f8829a4aSRandall Stewart 		/* event not enabled */
3148f8829a4aSRandall Stewart 		return;
3149830d754dSRandall Stewart 	}
3150eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_adaption_event), 0, M_NOWAIT, 1, MT_DATA);
3151f8829a4aSRandall Stewart 	if (m_notify == NULL)
3152f8829a4aSRandall Stewart 		/* no space left */
3153f8829a4aSRandall Stewart 		return;
3154139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3155f8829a4aSRandall Stewart 	sai = mtod(m_notify, struct sctp_adaptation_event *);
3156e432298aSXin LI 	memset(sai, 0, sizeof(struct sctp_adaptation_event));
3157f8829a4aSRandall Stewart 	sai->sai_type = SCTP_ADAPTATION_INDICATION;
3158f8829a4aSRandall Stewart 	sai->sai_flags = 0;
3159f8829a4aSRandall Stewart 	sai->sai_length = sizeof(struct sctp_adaptation_event);
31602afb3e84SRandall Stewart 	sai->sai_adaptation_ind = stcb->asoc.peers_adaptation;
3161f8829a4aSRandall Stewart 	sai->sai_assoc_id = sctp_get_associd(stcb);
3162f8829a4aSRandall Stewart 
3163139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_adaptation_event);
3164139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3165f8829a4aSRandall Stewart 
3166f8829a4aSRandall Stewart 	/* append to socket */
3167f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
31687215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3169f8829a4aSRandall Stewart 	    m_notify);
3170f8829a4aSRandall Stewart 	if (control == NULL) {
3171f8829a4aSRandall Stewart 		/* no memory */
3172f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3173f8829a4aSRandall Stewart 		return;
3174f8829a4aSRandall Stewart 	}
3175139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3176139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3177f8829a4aSRandall Stewart 	/* not that we need this */
3178f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
3179f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3180f8829a4aSRandall Stewart 	    control,
3181cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, SCTP_SO_NOT_LOCKED);
3182f8829a4aSRandall Stewart }
3183f8829a4aSRandall Stewart 
318403b0b021SRandall Stewart /* This always must be called with the read-queue LOCKED in the INP */
3185810ec536SMichael Tuexen static void
31862dad8a55SRandall Stewart sctp_notify_partial_delivery_indication(struct sctp_tcb *stcb, uint32_t error,
3187810ec536SMichael Tuexen     uint32_t val, int so_locked
3188810ec536SMichael Tuexen #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3189810ec536SMichael Tuexen     SCTP_UNUSED
3190810ec536SMichael Tuexen #endif
3191810ec536SMichael Tuexen )
3192f8829a4aSRandall Stewart {
3193f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3194f8829a4aSRandall Stewart 	struct sctp_pdapi_event *pdapi;
3195f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
319603b0b021SRandall Stewart 	struct sockbuf *sb;
3197f8829a4aSRandall Stewart 
319860990c0cSMichael Tuexen 	if ((stcb == NULL) ||
319960990c0cSMichael Tuexen 	    sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_PDAPIEVNT)) {
3200f8829a4aSRandall Stewart 		/* event not enabled */
3201f8829a4aSRandall Stewart 		return;
3202830d754dSRandall Stewart 	}
3203cd1386abSMichael Tuexen 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_CANT_READ) {
3204cd1386abSMichael Tuexen 		return;
3205cd1386abSMichael Tuexen 	}
3206eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_pdapi_event), 0, M_NOWAIT, 1, MT_DATA);
3207f8829a4aSRandall Stewart 	if (m_notify == NULL)
3208f8829a4aSRandall Stewart 		/* no space left */
3209f8829a4aSRandall Stewart 		return;
3210139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3211f8829a4aSRandall Stewart 	pdapi = mtod(m_notify, struct sctp_pdapi_event *);
3212e432298aSXin LI 	memset(pdapi, 0, sizeof(struct sctp_pdapi_event));
3213f8829a4aSRandall Stewart 	pdapi->pdapi_type = SCTP_PARTIAL_DELIVERY_EVENT;
3214f8829a4aSRandall Stewart 	pdapi->pdapi_flags = 0;
3215f8829a4aSRandall Stewart 	pdapi->pdapi_length = sizeof(struct sctp_pdapi_event);
3216f8829a4aSRandall Stewart 	pdapi->pdapi_indication = error;
32179a6142d8SRandall Stewart 	pdapi->pdapi_stream = (val >> 16);
32189a6142d8SRandall Stewart 	pdapi->pdapi_seq = (val & 0x0000ffff);
3219f8829a4aSRandall Stewart 	pdapi->pdapi_assoc_id = sctp_get_associd(stcb);
3220f8829a4aSRandall Stewart 
3221139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_pdapi_event);
3222139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3223f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
32247215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3225f8829a4aSRandall Stewart 	    m_notify);
3226f8829a4aSRandall Stewart 	if (control == NULL) {
3227f8829a4aSRandall Stewart 		/* no memory */
3228f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3229f8829a4aSRandall Stewart 		return;
3230f8829a4aSRandall Stewart 	}
3231139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3232139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3233f8829a4aSRandall Stewart 	/* not that we need this */
3234f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
323503b0b021SRandall Stewart 	control->held_length = 0;
323603b0b021SRandall Stewart 	control->length = 0;
323703b0b021SRandall Stewart 	sb = &stcb->sctp_socket->so_rcv;
3238b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
3239139bc87fSRandall Stewart 		sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m_notify));
324080fefe0aSRandall Stewart 	}
324103b0b021SRandall Stewart 	sctp_sballoc(stcb, sb, m_notify);
3242b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
324303b0b021SRandall Stewart 		sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
324480fefe0aSRandall Stewart 	}
3245139bc87fSRandall Stewart 	atomic_add_int(&control->length, SCTP_BUF_LEN(m_notify));
324603b0b021SRandall Stewart 	control->end_added = 1;
324703b0b021SRandall Stewart 	if (stcb->asoc.control_pdapi)
324803b0b021SRandall Stewart 		TAILQ_INSERT_AFTER(&stcb->sctp_ep->read_queue, stcb->asoc.control_pdapi, control, next);
324903b0b021SRandall Stewart 	else {
325003b0b021SRandall Stewart 		/* we really should not see this case */
325103b0b021SRandall Stewart 		TAILQ_INSERT_TAIL(&stcb->sctp_ep->read_queue, control, next);
325203b0b021SRandall Stewart 	}
325303b0b021SRandall Stewart 	if (stcb->sctp_ep && stcb->sctp_socket) {
325403b0b021SRandall Stewart 		/* This should always be the case */
3255810ec536SMichael Tuexen #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3256810ec536SMichael Tuexen 		struct socket *so;
3257810ec536SMichael Tuexen 
3258810ec536SMichael Tuexen 		so = SCTP_INP_SO(stcb->sctp_ep);
3259810ec536SMichael Tuexen 		if (!so_locked) {
3260810ec536SMichael Tuexen 			atomic_add_int(&stcb->asoc.refcnt, 1);
3261810ec536SMichael Tuexen 			SCTP_TCB_UNLOCK(stcb);
3262810ec536SMichael Tuexen 			SCTP_SOCKET_LOCK(so, 1);
3263810ec536SMichael Tuexen 			SCTP_TCB_LOCK(stcb);
3264810ec536SMichael Tuexen 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
3265810ec536SMichael Tuexen 			if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
3266810ec536SMichael Tuexen 				SCTP_SOCKET_UNLOCK(so, 1);
3267810ec536SMichael Tuexen 				return;
3268810ec536SMichael Tuexen 			}
3269810ec536SMichael Tuexen 		}
3270810ec536SMichael Tuexen #endif
327103b0b021SRandall Stewart 		sctp_sorwakeup(stcb->sctp_ep, stcb->sctp_socket);
3272810ec536SMichael Tuexen #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3273810ec536SMichael Tuexen 		if (!so_locked) {
3274810ec536SMichael Tuexen 			SCTP_SOCKET_UNLOCK(so, 1);
3275810ec536SMichael Tuexen 		}
3276810ec536SMichael Tuexen #endif
3277f8829a4aSRandall Stewart 	}
3278f8829a4aSRandall Stewart }
3279f8829a4aSRandall Stewart 
3280f8829a4aSRandall Stewart static void
3281f8829a4aSRandall Stewart sctp_notify_shutdown_event(struct sctp_tcb *stcb)
3282f8829a4aSRandall Stewart {
3283f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3284f8829a4aSRandall Stewart 	struct sctp_shutdown_event *sse;
3285f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3286f8829a4aSRandall Stewart 
3287f8829a4aSRandall Stewart 	/*
3288f8829a4aSRandall Stewart 	 * For TCP model AND UDP connected sockets we will send an error up
3289f8829a4aSRandall Stewart 	 * when an SHUTDOWN completes
3290f8829a4aSRandall Stewart 	 */
3291f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
3292f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
3293f8829a4aSRandall Stewart 		/* mark socket closed for read/write and wakeup! */
3294ceaad40aSRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3295ceaad40aSRandall Stewart 		struct socket *so;
3296ceaad40aSRandall Stewart 
3297ceaad40aSRandall Stewart 		so = SCTP_INP_SO(stcb->sctp_ep);
3298ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
3299ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
3300ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
3301ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
3302ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
3303ceaad40aSRandall Stewart 		if (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET) {
3304ceaad40aSRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
3305ceaad40aSRandall Stewart 			return;
3306ceaad40aSRandall Stewart 		}
3307ceaad40aSRandall Stewart #endif
3308f8829a4aSRandall Stewart 		socantsendmore(stcb->sctp_socket);
3309ceaad40aSRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3310ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
3311ceaad40aSRandall Stewart #endif
3312f8829a4aSRandall Stewart 	}
3313e2e7c62eSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVSHUTDOWNEVNT)) {
3314f8829a4aSRandall Stewart 		/* event not enabled */
3315f8829a4aSRandall Stewart 		return;
3316830d754dSRandall Stewart 	}
3317eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_shutdown_event), 0, M_NOWAIT, 1, MT_DATA);
3318f8829a4aSRandall Stewart 	if (m_notify == NULL)
3319f8829a4aSRandall Stewart 		/* no space left */
3320f8829a4aSRandall Stewart 		return;
3321f8829a4aSRandall Stewart 	sse = mtod(m_notify, struct sctp_shutdown_event *);
3322e432298aSXin LI 	memset(sse, 0, sizeof(struct sctp_shutdown_event));
3323f8829a4aSRandall Stewart 	sse->sse_type = SCTP_SHUTDOWN_EVENT;
3324f8829a4aSRandall Stewart 	sse->sse_flags = 0;
3325f8829a4aSRandall Stewart 	sse->sse_length = sizeof(struct sctp_shutdown_event);
3326f8829a4aSRandall Stewart 	sse->sse_assoc_id = sctp_get_associd(stcb);
3327f8829a4aSRandall Stewart 
3328139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_shutdown_event);
3329139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3330f8829a4aSRandall Stewart 
3331f8829a4aSRandall Stewart 	/* append to socket */
3332f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
33337215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3334f8829a4aSRandall Stewart 	    m_notify);
3335f8829a4aSRandall Stewart 	if (control == NULL) {
3336f8829a4aSRandall Stewart 		/* no memory */
3337f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3338f8829a4aSRandall Stewart 		return;
3339f8829a4aSRandall Stewart 	}
3340139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3341139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3342f8829a4aSRandall Stewart 	/* not that we need this */
3343f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
3344f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3345f8829a4aSRandall Stewart 	    control,
3346cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, SCTP_SO_NOT_LOCKED);
3347f8829a4aSRandall Stewart }
3348f8829a4aSRandall Stewart 
3349f8829a4aSRandall Stewart static void
3350830d754dSRandall Stewart sctp_notify_sender_dry_event(struct sctp_tcb *stcb,
3351830d754dSRandall Stewart     int so_locked
3352830d754dSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3353830d754dSRandall Stewart     SCTP_UNUSED
3354830d754dSRandall Stewart #endif
3355830d754dSRandall Stewart )
3356830d754dSRandall Stewart {
3357830d754dSRandall Stewart 	struct mbuf *m_notify;
3358830d754dSRandall Stewart 	struct sctp_sender_dry_event *event;
3359830d754dSRandall Stewart 	struct sctp_queued_to_read *control;
3360830d754dSRandall Stewart 
336160990c0cSMichael Tuexen 	if ((stcb == NULL) ||
336260990c0cSMichael Tuexen 	    sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_DRYEVNT)) {
3363830d754dSRandall Stewart 		/* event not enabled */
3364830d754dSRandall Stewart 		return;
3365830d754dSRandall Stewart 	}
3366eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_sender_dry_event), 0, M_NOWAIT, 1, MT_DATA);
3367830d754dSRandall Stewart 	if (m_notify == NULL) {
3368830d754dSRandall Stewart 		/* no space left */
3369830d754dSRandall Stewart 		return;
3370830d754dSRandall Stewart 	}
3371830d754dSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3372830d754dSRandall Stewart 	event = mtod(m_notify, struct sctp_sender_dry_event *);
3373e432298aSXin LI 	memset(event, 0, sizeof(struct sctp_sender_dry_event));
3374830d754dSRandall Stewart 	event->sender_dry_type = SCTP_SENDER_DRY_EVENT;
3375830d754dSRandall Stewart 	event->sender_dry_flags = 0;
3376830d754dSRandall Stewart 	event->sender_dry_length = sizeof(struct sctp_sender_dry_event);
3377830d754dSRandall Stewart 	event->sender_dry_assoc_id = sctp_get_associd(stcb);
3378830d754dSRandall Stewart 
3379830d754dSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_sender_dry_event);
3380830d754dSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3381830d754dSRandall Stewart 
3382830d754dSRandall Stewart 	/* append to socket */
3383830d754dSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
33847215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
33857215cc1bSMichael Tuexen 	    m_notify);
3386830d754dSRandall Stewart 	if (control == NULL) {
3387830d754dSRandall Stewart 		/* no memory */
3388830d754dSRandall Stewart 		sctp_m_freem(m_notify);
3389830d754dSRandall Stewart 		return;
3390830d754dSRandall Stewart 	}
3391830d754dSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3392830d754dSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3393830d754dSRandall Stewart 	/* not that we need this */
3394830d754dSRandall Stewart 	control->tail_mbuf = m_notify;
3395830d754dSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb, control,
3396cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, so_locked);
3397830d754dSRandall Stewart }
3398830d754dSRandall Stewart 
3399ea44232bSRandall Stewart 
3400c4e848b7SRandall Stewart void
3401c4e848b7SRandall Stewart sctp_notify_stream_reset_add(struct sctp_tcb *stcb, uint16_t numberin, uint16_t numberout, int flag)
3402ea44232bSRandall Stewart {
3403ea44232bSRandall Stewart 	struct mbuf *m_notify;
3404ea44232bSRandall Stewart 	struct sctp_queued_to_read *control;
3405c4e848b7SRandall Stewart 	struct sctp_stream_change_event *stradd;
3406ea44232bSRandall Stewart 
34078c501e51SMichael Tuexen 	if ((stcb == NULL) ||
34088c501e51SMichael Tuexen 	    (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_STREAM_CHANGEEVNT))) {
3409ea44232bSRandall Stewart 		/* event not enabled */
3410ea44232bSRandall Stewart 		return;
3411ea44232bSRandall Stewart 	}
3412c4e848b7SRandall Stewart 	if ((stcb->asoc.peer_req_out) && flag) {
3413c4e848b7SRandall Stewart 		/* Peer made the request, don't tell the local user */
3414c4e848b7SRandall Stewart 		stcb->asoc.peer_req_out = 0;
3415c4e848b7SRandall Stewart 		return;
3416c4e848b7SRandall Stewart 	}
3417c4e848b7SRandall Stewart 	stcb->asoc.peer_req_out = 0;
3418e432298aSXin LI 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_stream_change_event), 0, M_NOWAIT, 1, MT_DATA);
3419ea44232bSRandall Stewart 	if (m_notify == NULL)
3420ea44232bSRandall Stewart 		/* no space left */
3421ea44232bSRandall Stewart 		return;
3422ea44232bSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3423c4e848b7SRandall Stewart 	stradd = mtod(m_notify, struct sctp_stream_change_event *);
3424e432298aSXin LI 	memset(stradd, 0, sizeof(struct sctp_stream_change_event));
3425c4e848b7SRandall Stewart 	stradd->strchange_type = SCTP_STREAM_CHANGE_EVENT;
3426c4e848b7SRandall Stewart 	stradd->strchange_flags = flag;
3427e432298aSXin LI 	stradd->strchange_length = sizeof(struct sctp_stream_change_event);
3428c4e848b7SRandall Stewart 	stradd->strchange_assoc_id = sctp_get_associd(stcb);
3429c4e848b7SRandall Stewart 	stradd->strchange_instrms = numberin;
3430c4e848b7SRandall Stewart 	stradd->strchange_outstrms = numberout;
3431e432298aSXin LI 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_stream_change_event);
3432ea44232bSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3433ea44232bSRandall Stewart 	if (sctp_sbspace(&stcb->asoc, &stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3434ea44232bSRandall Stewart 		/* no space */
3435ea44232bSRandall Stewart 		sctp_m_freem(m_notify);
3436ea44232bSRandall Stewart 		return;
3437ea44232bSRandall Stewart 	}
3438ea44232bSRandall Stewart 	/* append to socket */
3439ea44232bSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
34407215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3441ea44232bSRandall Stewart 	    m_notify);
3442ea44232bSRandall Stewart 	if (control == NULL) {
3443ea44232bSRandall Stewart 		/* no memory */
3444ea44232bSRandall Stewart 		sctp_m_freem(m_notify);
3445ea44232bSRandall Stewart 		return;
3446ea44232bSRandall Stewart 	}
3447ea44232bSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3448ea44232bSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3449ea44232bSRandall Stewart 	/* not that we need this */
3450ea44232bSRandall Stewart 	control->tail_mbuf = m_notify;
3451ea44232bSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3452ea44232bSRandall Stewart 	    control,
3453cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, SCTP_SO_NOT_LOCKED);
3454ea44232bSRandall Stewart }
3455ea44232bSRandall Stewart 
3456c4e848b7SRandall Stewart void
3457c4e848b7SRandall Stewart sctp_notify_stream_reset_tsn(struct sctp_tcb *stcb, uint32_t sending_tsn, uint32_t recv_tsn, int flag)
3458c4e848b7SRandall Stewart {
3459c4e848b7SRandall Stewart 	struct mbuf *m_notify;
3460c4e848b7SRandall Stewart 	struct sctp_queued_to_read *control;
3461c4e848b7SRandall Stewart 	struct sctp_assoc_reset_event *strasoc;
3462c4e848b7SRandall Stewart 
34638c501e51SMichael Tuexen 	if ((stcb == NULL) ||
34648c501e51SMichael Tuexen 	    (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_ASSOC_RESETEVNT))) {
3465c4e848b7SRandall Stewart 		/* event not enabled */
3466c4e848b7SRandall Stewart 		return;
3467c4e848b7SRandall Stewart 	}
3468e432298aSXin LI 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_assoc_reset_event), 0, M_NOWAIT, 1, MT_DATA);
3469c4e848b7SRandall Stewart 	if (m_notify == NULL)
3470c4e848b7SRandall Stewart 		/* no space left */
3471c4e848b7SRandall Stewart 		return;
3472c4e848b7SRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3473c4e848b7SRandall Stewart 	strasoc = mtod(m_notify, struct sctp_assoc_reset_event *);
3474e432298aSXin LI 	memset(strasoc, 0, sizeof(struct sctp_assoc_reset_event));
3475c4e848b7SRandall Stewart 	strasoc->assocreset_type = SCTP_ASSOC_RESET_EVENT;
3476c4e848b7SRandall Stewart 	strasoc->assocreset_flags = flag;
3477e432298aSXin LI 	strasoc->assocreset_length = sizeof(struct sctp_assoc_reset_event);
3478c4e848b7SRandall Stewart 	strasoc->assocreset_assoc_id = sctp_get_associd(stcb);
3479c4e848b7SRandall Stewart 	strasoc->assocreset_local_tsn = sending_tsn;
3480c4e848b7SRandall Stewart 	strasoc->assocreset_remote_tsn = recv_tsn;
3481e432298aSXin LI 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_assoc_reset_event);
3482c4e848b7SRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3483c4e848b7SRandall Stewart 	if (sctp_sbspace(&stcb->asoc, &stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3484c4e848b7SRandall Stewart 		/* no space */
3485c4e848b7SRandall Stewart 		sctp_m_freem(m_notify);
3486c4e848b7SRandall Stewart 		return;
3487c4e848b7SRandall Stewart 	}
3488c4e848b7SRandall Stewart 	/* append to socket */
3489c4e848b7SRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3490c4e848b7SRandall Stewart 	    0, 0, stcb->asoc.context, 0, 0, 0,
3491c4e848b7SRandall Stewart 	    m_notify);
3492c4e848b7SRandall Stewart 	if (control == NULL) {
3493c4e848b7SRandall Stewart 		/* no memory */
3494c4e848b7SRandall Stewart 		sctp_m_freem(m_notify);
3495c4e848b7SRandall Stewart 		return;
3496c4e848b7SRandall Stewart 	}
3497c4e848b7SRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3498c4e848b7SRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3499c4e848b7SRandall Stewart 	/* not that we need this */
3500c4e848b7SRandall Stewart 	control->tail_mbuf = m_notify;
3501c4e848b7SRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3502c4e848b7SRandall Stewart 	    control,
3503c4e848b7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, SCTP_SO_NOT_LOCKED);
3504c4e848b7SRandall Stewart }
3505c4e848b7SRandall Stewart 
3506c4e848b7SRandall Stewart 
3507ea44232bSRandall Stewart 
3508830d754dSRandall Stewart static void
3509f8829a4aSRandall Stewart sctp_notify_stream_reset(struct sctp_tcb *stcb,
3510f8829a4aSRandall Stewart     int number_entries, uint16_t * list, int flag)
3511f8829a4aSRandall Stewart {
3512f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3513f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3514f8829a4aSRandall Stewart 	struct sctp_stream_reset_event *strreset;
3515f8829a4aSRandall Stewart 	int len;
3516f8829a4aSRandall Stewart 
35178c501e51SMichael Tuexen 	if ((stcb == NULL) ||
35188c501e51SMichael Tuexen 	    (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_STREAM_RESETEVNT))) {
3519f8829a4aSRandall Stewart 		/* event not enabled */
3520f8829a4aSRandall Stewart 		return;
3521830d754dSRandall Stewart 	}
3522eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(MCLBYTES, 0, M_NOWAIT, 1, MT_DATA);
3523f8829a4aSRandall Stewart 	if (m_notify == NULL)
3524f8829a4aSRandall Stewart 		/* no space left */
3525f8829a4aSRandall Stewart 		return;
3526139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3527f8829a4aSRandall Stewart 	len = sizeof(struct sctp_stream_reset_event) + (number_entries * sizeof(uint16_t));
3528f8829a4aSRandall Stewart 	if (len > M_TRAILINGSPACE(m_notify)) {
3529f8829a4aSRandall Stewart 		/* never enough room */
3530f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3531f8829a4aSRandall Stewart 		return;
3532f8829a4aSRandall Stewart 	}
3533f8829a4aSRandall Stewart 	strreset = mtod(m_notify, struct sctp_stream_reset_event *);
3534e432298aSXin LI 	memset(strreset, 0, len);
3535f8829a4aSRandall Stewart 	strreset->strreset_type = SCTP_STREAM_RESET_EVENT;
3536c4e848b7SRandall Stewart 	strreset->strreset_flags = flag;
3537f8829a4aSRandall Stewart 	strreset->strreset_length = len;
3538f8829a4aSRandall Stewart 	strreset->strreset_assoc_id = sctp_get_associd(stcb);
3539f8829a4aSRandall Stewart 	if (number_entries) {
3540f8829a4aSRandall Stewart 		int i;
3541f8829a4aSRandall Stewart 
3542f8829a4aSRandall Stewart 		for (i = 0; i < number_entries; i++) {
3543c4e848b7SRandall Stewart 			strreset->strreset_stream_list[i] = ntohs(list[i]);
3544f8829a4aSRandall Stewart 		}
3545f8829a4aSRandall Stewart 	}
3546139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = len;
3547139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3548139bc87fSRandall Stewart 	if (sctp_sbspace(&stcb->asoc, &stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3549f8829a4aSRandall Stewart 		/* no space */
3550f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3551f8829a4aSRandall Stewart 		return;
3552f8829a4aSRandall Stewart 	}
3553f8829a4aSRandall Stewart 	/* append to socket */
3554f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
35557215cc1bSMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3556f8829a4aSRandall Stewart 	    m_notify);
3557f8829a4aSRandall Stewart 	if (control == NULL) {
3558f8829a4aSRandall Stewart 		/* no memory */
3559f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3560f8829a4aSRandall Stewart 		return;
3561f8829a4aSRandall Stewart 	}
3562139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3563139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3564f8829a4aSRandall Stewart 	/* not that we need this */
3565f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
3566f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3567f8829a4aSRandall Stewart 	    control,
3568cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, SCTP_SO_NOT_LOCKED);
3569f8829a4aSRandall Stewart }
3570f8829a4aSRandall Stewart 
3571f8829a4aSRandall Stewart 
3572389b1b11SMichael Tuexen static void
3573389b1b11SMichael Tuexen sctp_notify_remote_error(struct sctp_tcb *stcb, uint16_t error, struct sctp_error_chunk *chunk)
3574389b1b11SMichael Tuexen {
3575389b1b11SMichael Tuexen 	struct mbuf *m_notify;
3576389b1b11SMichael Tuexen 	struct sctp_remote_error *sre;
3577389b1b11SMichael Tuexen 	struct sctp_queued_to_read *control;
35789a8e3088SMichael Tuexen 	unsigned int notif_len;
35799a8e3088SMichael Tuexen 	uint16_t chunk_len;
3580389b1b11SMichael Tuexen 
3581389b1b11SMichael Tuexen 	if ((stcb == NULL) ||
3582389b1b11SMichael Tuexen 	    sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVPEERERR)) {
3583389b1b11SMichael Tuexen 		return;
3584389b1b11SMichael Tuexen 	}
3585389b1b11SMichael Tuexen 	if (chunk != NULL) {
3586c9eb4473SMichael Tuexen 		chunk_len = ntohs(chunk->ch.chunk_length);
3587389b1b11SMichael Tuexen 	} else {
3588389b1b11SMichael Tuexen 		chunk_len = 0;
3589389b1b11SMichael Tuexen 	}
35909a8e3088SMichael Tuexen 	notif_len = (unsigned int)(sizeof(struct sctp_remote_error) + chunk_len);
3591eb1b1807SGleb Smirnoff 	m_notify = sctp_get_mbuf_for_msg(notif_len, 0, M_NOWAIT, 1, MT_DATA);
3592389b1b11SMichael Tuexen 	if (m_notify == NULL) {
3593389b1b11SMichael Tuexen 		/* Retry with smaller value. */
35949a8e3088SMichael Tuexen 		notif_len = (unsigned int)sizeof(struct sctp_remote_error);
3595eb1b1807SGleb Smirnoff 		m_notify = sctp_get_mbuf_for_msg(notif_len, 0, M_NOWAIT, 1, MT_DATA);
3596389b1b11SMichael Tuexen 		if (m_notify == NULL) {
3597389b1b11SMichael Tuexen 			return;
3598389b1b11SMichael Tuexen 		}
3599389b1b11SMichael Tuexen 	}
3600389b1b11SMichael Tuexen 	SCTP_BUF_NEXT(m_notify) = NULL;
3601389b1b11SMichael Tuexen 	sre = mtod(m_notify, struct sctp_remote_error *);
360256711f94SMichael Tuexen 	memset(sre, 0, notif_len);
3603389b1b11SMichael Tuexen 	sre->sre_type = SCTP_REMOTE_ERROR;
3604389b1b11SMichael Tuexen 	sre->sre_flags = 0;
3605389b1b11SMichael Tuexen 	sre->sre_length = sizeof(struct sctp_remote_error);
3606389b1b11SMichael Tuexen 	sre->sre_error = error;
3607389b1b11SMichael Tuexen 	sre->sre_assoc_id = sctp_get_associd(stcb);
3608389b1b11SMichael Tuexen 	if (notif_len > sizeof(struct sctp_remote_error)) {
3609389b1b11SMichael Tuexen 		memcpy(sre->sre_data, chunk, chunk_len);
3610389b1b11SMichael Tuexen 		sre->sre_length += chunk_len;
3611389b1b11SMichael Tuexen 	}
3612389b1b11SMichael Tuexen 	SCTP_BUF_LEN(m_notify) = sre->sre_length;
3613389b1b11SMichael Tuexen 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3614389b1b11SMichael Tuexen 	    0, 0, stcb->asoc.context, 0, 0, 0,
3615389b1b11SMichael Tuexen 	    m_notify);
3616389b1b11SMichael Tuexen 	if (control != NULL) {
3617389b1b11SMichael Tuexen 		control->length = SCTP_BUF_LEN(m_notify);
3618389b1b11SMichael Tuexen 		/* not that we need this */
3619389b1b11SMichael Tuexen 		control->tail_mbuf = m_notify;
3620389b1b11SMichael Tuexen 		control->spec_flags = M_NOTIFICATION;
3621389b1b11SMichael Tuexen 		sctp_add_to_readq(stcb->sctp_ep, stcb,
3622389b1b11SMichael Tuexen 		    control,
3623389b1b11SMichael Tuexen 		    &stcb->sctp_socket->so_rcv, 1,
3624389b1b11SMichael Tuexen 		    SCTP_READ_LOCK_NOT_HELD, SCTP_SO_NOT_LOCKED);
3625389b1b11SMichael Tuexen 	} else {
3626389b1b11SMichael Tuexen 		sctp_m_freem(m_notify);
3627389b1b11SMichael Tuexen 	}
3628389b1b11SMichael Tuexen }
3629389b1b11SMichael Tuexen 
3630389b1b11SMichael Tuexen 
3631f8829a4aSRandall Stewart void
3632f8829a4aSRandall Stewart sctp_ulp_notify(uint32_t notification, struct sctp_tcb *stcb,
3633ceaad40aSRandall Stewart     uint32_t error, void *data, int so_locked
3634ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3635ceaad40aSRandall Stewart     SCTP_UNUSED
3636ceaad40aSRandall Stewart #endif
3637ceaad40aSRandall Stewart )
3638f8829a4aSRandall Stewart {
3639830d754dSRandall Stewart 	if ((stcb == NULL) ||
3640830d754dSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
3641f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
3642830d754dSRandall Stewart 	    (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET)) {
3643830d754dSRandall Stewart 		/* If the socket is gone we are out of here */
3644f8829a4aSRandall Stewart 		return;
3645f8829a4aSRandall Stewart 	}
3646a99b6783SRandall Stewart 	if (stcb->sctp_socket->so_rcv.sb_state & SBS_CANTRCVMORE) {
3647a99b6783SRandall Stewart 		return;
3648a99b6783SRandall Stewart 	}
3649fb4a67d2SMichael Tuexen 	if ((stcb->asoc.state & SCTP_STATE_COOKIE_WAIT) ||
3650fb4a67d2SMichael Tuexen 	    (stcb->asoc.state & SCTP_STATE_COOKIE_ECHOED)) {
365117205eccSRandall Stewart 		if ((notification == SCTP_NOTIFY_INTERFACE_DOWN) ||
365217205eccSRandall Stewart 		    (notification == SCTP_NOTIFY_INTERFACE_UP) ||
365317205eccSRandall Stewart 		    (notification == SCTP_NOTIFY_INTERFACE_CONFIRMED)) {
365417205eccSRandall Stewart 			/* Don't report these in front states */
365517205eccSRandall Stewart 			return;
365617205eccSRandall Stewart 		}
365717205eccSRandall Stewart 	}
3658f8829a4aSRandall Stewart 	switch (notification) {
3659f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_UP:
3660f8829a4aSRandall Stewart 		if (stcb->asoc.assoc_up_sent == 0) {
3661410a3b1eSMichael Tuexen 			sctp_notify_assoc_change(SCTP_COMM_UP, stcb, error, NULL, 0, so_locked);
3662f8829a4aSRandall Stewart 			stcb->asoc.assoc_up_sent = 1;
3663f8829a4aSRandall Stewart 		}
36642afb3e84SRandall Stewart 		if (stcb->asoc.adaptation_needed && (stcb->asoc.adaptation_sent == 0)) {
36657215cc1bSMichael Tuexen 			sctp_notify_adaptation_layer(stcb);
36662afb3e84SRandall Stewart 		}
3667c79bec9cSMichael Tuexen 		if (stcb->asoc.auth_supported == 0) {
3668830d754dSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_NO_PEER_AUTH, stcb, 0,
3669830d754dSRandall Stewart 			    NULL, so_locked);
3670830d754dSRandall Stewart 		}
3671f8829a4aSRandall Stewart 		break;
3672f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_DOWN:
3673410a3b1eSMichael Tuexen 		sctp_notify_assoc_change(SCTP_SHUTDOWN_COMP, stcb, error, NULL, 0, so_locked);
3674f8829a4aSRandall Stewart 		break;
3675f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_DOWN:
3676f8829a4aSRandall Stewart 		{
3677f8829a4aSRandall Stewart 			struct sctp_nets *net;
3678f8829a4aSRandall Stewart 
3679f8829a4aSRandall Stewart 			net = (struct sctp_nets *)data;
3680f8829a4aSRandall Stewart 			sctp_notify_peer_addr_change(stcb, SCTP_ADDR_UNREACHABLE,
36813cb3567dSMichael Tuexen 			    (struct sockaddr *)&net->ro._l_addr, error, so_locked);
3682f8829a4aSRandall Stewart 			break;
3683f8829a4aSRandall Stewart 		}
3684f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_UP:
3685f8829a4aSRandall Stewart 		{
3686f8829a4aSRandall Stewart 			struct sctp_nets *net;
3687f8829a4aSRandall Stewart 
3688f8829a4aSRandall Stewart 			net = (struct sctp_nets *)data;
3689f8829a4aSRandall Stewart 			sctp_notify_peer_addr_change(stcb, SCTP_ADDR_AVAILABLE,
36903cb3567dSMichael Tuexen 			    (struct sockaddr *)&net->ro._l_addr, error, so_locked);
3691f8829a4aSRandall Stewart 			break;
3692f8829a4aSRandall Stewart 		}
3693f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_CONFIRMED:
3694f8829a4aSRandall Stewart 		{
3695f8829a4aSRandall Stewart 			struct sctp_nets *net;
3696f8829a4aSRandall Stewart 
3697f8829a4aSRandall Stewart 			net = (struct sctp_nets *)data;
3698f8829a4aSRandall Stewart 			sctp_notify_peer_addr_change(stcb, SCTP_ADDR_CONFIRMED,
36993cb3567dSMichael Tuexen 			    (struct sockaddr *)&net->ro._l_addr, error, so_locked);
3700f8829a4aSRandall Stewart 			break;
3701f8829a4aSRandall Stewart 		}
3702f8829a4aSRandall Stewart 	case SCTP_NOTIFY_SPECIAL_SP_FAIL:
3703f8829a4aSRandall Stewart 		sctp_notify_send_failed2(stcb, error,
3704ceaad40aSRandall Stewart 		    (struct sctp_stream_queue_pending *)data, so_locked);
3705f8829a4aSRandall Stewart 		break;
37061edc9dbaSMichael Tuexen 	case SCTP_NOTIFY_SENT_DG_FAIL:
37071edc9dbaSMichael Tuexen 		sctp_notify_send_failed(stcb, 1, error,
37081edc9dbaSMichael Tuexen 		    (struct sctp_tmit_chunk *)data, so_locked);
37091edc9dbaSMichael Tuexen 		break;
37101edc9dbaSMichael Tuexen 	case SCTP_NOTIFY_UNSENT_DG_FAIL:
37111edc9dbaSMichael Tuexen 		sctp_notify_send_failed(stcb, 0, error,
3712ceaad40aSRandall Stewart 		    (struct sctp_tmit_chunk *)data, so_locked);
3713f8829a4aSRandall Stewart 		break;
3714f8829a4aSRandall Stewart 	case SCTP_NOTIFY_PARTIAL_DELVIERY_INDICATION:
37159a6142d8SRandall Stewart 		{
37169a6142d8SRandall Stewart 			uint32_t val;
37179a6142d8SRandall Stewart 
37189a6142d8SRandall Stewart 			val = *((uint32_t *) data);
37199a6142d8SRandall Stewart 
3720810ec536SMichael Tuexen 			sctp_notify_partial_delivery_indication(stcb, error, val, so_locked);
3721f8829a4aSRandall Stewart 			break;
3722810ec536SMichael Tuexen 		}
3723410a3b1eSMichael Tuexen 	case SCTP_NOTIFY_ASSOC_LOC_ABORTED:
3724fb4a67d2SMichael Tuexen 		if (((stcb->asoc.state & SCTP_STATE_MASK) == SCTP_STATE_COOKIE_WAIT) ||
3725fb4a67d2SMichael Tuexen 		    ((stcb->asoc.state & SCTP_STATE_MASK) == SCTP_STATE_COOKIE_ECHOED)) {
3726410a3b1eSMichael Tuexen 			sctp_notify_assoc_change(SCTP_CANT_STR_ASSOC, stcb, error, data, 0, so_locked);
3727c105859eSRandall Stewart 		} else {
3728410a3b1eSMichael Tuexen 			sctp_notify_assoc_change(SCTP_COMM_LOST, stcb, error, data, 0, so_locked);
3729410a3b1eSMichael Tuexen 		}
3730410a3b1eSMichael Tuexen 		break;
3731410a3b1eSMichael Tuexen 	case SCTP_NOTIFY_ASSOC_REM_ABORTED:
3732fb4a67d2SMichael Tuexen 		if (((stcb->asoc.state & SCTP_STATE_MASK) == SCTP_STATE_COOKIE_WAIT) ||
3733fb4a67d2SMichael Tuexen 		    ((stcb->asoc.state & SCTP_STATE_MASK) == SCTP_STATE_COOKIE_ECHOED)) {
3734410a3b1eSMichael Tuexen 			sctp_notify_assoc_change(SCTP_CANT_STR_ASSOC, stcb, error, data, 1, so_locked);
3735410a3b1eSMichael Tuexen 		} else {
3736410a3b1eSMichael Tuexen 			sctp_notify_assoc_change(SCTP_COMM_LOST, stcb, error, data, 1, so_locked);
3737c105859eSRandall Stewart 		}
3738f8829a4aSRandall Stewart 		break;
3739f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_RESTART:
3740410a3b1eSMichael Tuexen 		sctp_notify_assoc_change(SCTP_RESTART, stcb, error, NULL, 0, so_locked);
3741c79bec9cSMichael Tuexen 		if (stcb->asoc.auth_supported == 0) {
3742830d754dSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_NO_PEER_AUTH, stcb, 0,
3743830d754dSRandall Stewart 			    NULL, so_locked);
3744830d754dSRandall Stewart 		}
3745f8829a4aSRandall Stewart 		break;
3746f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_SEND:
3747d7714577SMichael Tuexen 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data), SCTP_STREAM_RESET_OUTGOING_SSN);
3748f8829a4aSRandall Stewart 		break;
3749f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_RECV:
3750d7714577SMichael Tuexen 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data), SCTP_STREAM_RESET_INCOMING);
3751f8829a4aSRandall Stewart 		break;
3752f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_FAILED_OUT:
3753c4e848b7SRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data),
3754d7714577SMichael Tuexen 		    (SCTP_STREAM_RESET_OUTGOING_SSN | SCTP_STREAM_RESET_FAILED));
3755f8829a4aSRandall Stewart 		break;
3756d4260646SMichael Tuexen 	case SCTP_NOTIFY_STR_RESET_DENIED_OUT:
3757d4260646SMichael Tuexen 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data),
3758d4260646SMichael Tuexen 		    (SCTP_STREAM_RESET_OUTGOING_SSN | SCTP_STREAM_RESET_DENIED));
3759d4260646SMichael Tuexen 		break;
3760f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_FAILED_IN:
3761c4e848b7SRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data),
3762d7714577SMichael Tuexen 		    (SCTP_STREAM_RESET_INCOMING | SCTP_STREAM_RESET_FAILED));
3763f8829a4aSRandall Stewart 		break;
3764d4260646SMichael Tuexen 	case SCTP_NOTIFY_STR_RESET_DENIED_IN:
3765d4260646SMichael Tuexen 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data),
3766d4260646SMichael Tuexen 		    (SCTP_STREAM_RESET_INCOMING | SCTP_STREAM_RESET_DENIED));
3767d4260646SMichael Tuexen 		break;
3768f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_ADD_IP:
3769f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_ADDED, data,
37703cb3567dSMichael Tuexen 		    error, so_locked);
3771f8829a4aSRandall Stewart 		break;
3772f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_DELETE_IP:
3773f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_REMOVED, data,
37743cb3567dSMichael Tuexen 		    error, so_locked);
3775f8829a4aSRandall Stewart 		break;
3776f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_SET_PRIMARY:
3777f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_MADE_PRIM, data,
37783cb3567dSMichael Tuexen 		    error, so_locked);
3779f8829a4aSRandall Stewart 		break;
3780f8829a4aSRandall Stewart 	case SCTP_NOTIFY_PEER_SHUTDOWN:
3781f8829a4aSRandall Stewart 		sctp_notify_shutdown_event(stcb);
3782f8829a4aSRandall Stewart 		break;
3783f8829a4aSRandall Stewart 	case SCTP_NOTIFY_AUTH_NEW_KEY:
378478f28045SMichael Tuexen 		sctp_notify_authentication(stcb, SCTP_AUTH_NEW_KEY, error,
3785830d754dSRandall Stewart 		    (uint16_t) (uintptr_t) data,
3786830d754dSRandall Stewart 		    so_locked);
3787f8829a4aSRandall Stewart 		break;
3788830d754dSRandall Stewart 	case SCTP_NOTIFY_AUTH_FREE_KEY:
3789830d754dSRandall Stewart 		sctp_notify_authentication(stcb, SCTP_AUTH_FREE_KEY, error,
3790830d754dSRandall Stewart 		    (uint16_t) (uintptr_t) data,
3791830d754dSRandall Stewart 		    so_locked);
3792f8829a4aSRandall Stewart 		break;
3793830d754dSRandall Stewart 	case SCTP_NOTIFY_NO_PEER_AUTH:
3794830d754dSRandall Stewart 		sctp_notify_authentication(stcb, SCTP_AUTH_NO_AUTH, error,
3795830d754dSRandall Stewart 		    (uint16_t) (uintptr_t) data,
3796830d754dSRandall Stewart 		    so_locked);
3797830d754dSRandall Stewart 		break;
3798830d754dSRandall Stewart 	case SCTP_NOTIFY_SENDER_DRY:
3799830d754dSRandall Stewart 		sctp_notify_sender_dry_event(stcb, so_locked);
3800830d754dSRandall Stewart 		break;
3801389b1b11SMichael Tuexen 	case SCTP_NOTIFY_REMOTE_ERROR:
3802389b1b11SMichael Tuexen 		sctp_notify_remote_error(stcb, error, data);
3803389b1b11SMichael Tuexen 		break;
3804f8829a4aSRandall Stewart 	default:
3805ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_UTIL1, "%s: unknown notification %xh (%u)\n",
38066e9c45e0SMichael Tuexen 		    __func__, notification, notification);
3807f8829a4aSRandall Stewart 		break;
3808f8829a4aSRandall Stewart 	}			/* end switch */
3809f8829a4aSRandall Stewart }
3810f8829a4aSRandall Stewart 
3811f8829a4aSRandall Stewart void
38121edc9dbaSMichael Tuexen sctp_report_all_outbound(struct sctp_tcb *stcb, uint16_t error, int holds_lock, int so_locked
3813ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3814ceaad40aSRandall Stewart     SCTP_UNUSED
3815ceaad40aSRandall Stewart #endif
3816ceaad40aSRandall Stewart )
3817f8829a4aSRandall Stewart {
3818f8829a4aSRandall Stewart 	struct sctp_association *asoc;
3819f8829a4aSRandall Stewart 	struct sctp_stream_out *outs;
38204a9ef3f8SMichael Tuexen 	struct sctp_tmit_chunk *chk, *nchk;
38214a9ef3f8SMichael Tuexen 	struct sctp_stream_queue_pending *sp, *nsp;
38227f34832bSRandall Stewart 	int i;
3823f8829a4aSRandall Stewart 
3824ad81507eSRandall Stewart 	if (stcb == NULL) {
3825ad81507eSRandall Stewart 		return;
3826ad81507eSRandall Stewart 	}
38274a9ef3f8SMichael Tuexen 	asoc = &stcb->asoc;
38284a9ef3f8SMichael Tuexen 	if (asoc->state & SCTP_STATE_ABOUT_TO_BE_FREED) {
3829478fbccbSRandall Stewart 		/* already being freed */
3830478fbccbSRandall Stewart 		return;
3831478fbccbSRandall Stewart 	}
3832f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
3833f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
38344a9ef3f8SMichael Tuexen 	    (asoc->state & SCTP_STATE_CLOSED_SOCKET)) {
3835f8829a4aSRandall Stewart 		return;
3836f8829a4aSRandall Stewart 	}
3837f8829a4aSRandall Stewart 	/* now through all the gunk freeing chunks */
3838ad81507eSRandall Stewart 	if (holds_lock == 0) {
38397f34832bSRandall Stewart 		SCTP_TCB_SEND_LOCK(stcb);
3840ad81507eSRandall Stewart 	}
3841d00aff5dSRandall Stewart 	/* sent queue SHOULD be empty */
38424a9ef3f8SMichael Tuexen 	TAILQ_FOREACH_SAFE(chk, &asoc->sent_queue, sctp_next, nchk) {
3843d00aff5dSRandall Stewart 		TAILQ_REMOVE(&asoc->sent_queue, chk, sctp_next);
3844d00aff5dSRandall Stewart 		asoc->sent_queue_cnt--;
3845325c8c46SMichael Tuexen 		if (chk->sent != SCTP_DATAGRAM_NR_ACKED) {
3846a7ad6026SMichael Tuexen 			if (asoc->strmout[chk->rec.data.stream_number].chunks_on_queues > 0) {
3847a7ad6026SMichael Tuexen 				asoc->strmout[chk->rec.data.stream_number].chunks_on_queues--;
3848a7ad6026SMichael Tuexen #ifdef INVARIANTS
3849a7ad6026SMichael Tuexen 			} else {
3850a7ad6026SMichael Tuexen 				panic("No chunks on the queues for sid %u.", chk->rec.data.stream_number);
3851a7ad6026SMichael Tuexen #endif
3852a7ad6026SMichael Tuexen 			}
3853a7ad6026SMichael Tuexen 		}
38540c0982b8SRandall Stewart 		if (chk->data != NULL) {
3855d00aff5dSRandall Stewart 			sctp_free_bufspace(stcb, asoc, chk, 1);
38561edc9dbaSMichael Tuexen 			sctp_ulp_notify(SCTP_NOTIFY_SENT_DG_FAIL, stcb,
38571edc9dbaSMichael Tuexen 			    error, chk, so_locked);
3858810ec536SMichael Tuexen 			if (chk->data) {
3859d00aff5dSRandall Stewart 				sctp_m_freem(chk->data);
3860d00aff5dSRandall Stewart 				chk->data = NULL;
3861d00aff5dSRandall Stewart 			}
3862810ec536SMichael Tuexen 		}
3863689e6a5fSMichael Tuexen 		sctp_free_a_chunk(stcb, chk, so_locked);
3864d00aff5dSRandall Stewart 		/* sa_ignore FREED_MEMORY */
3865d00aff5dSRandall Stewart 	}
3866d00aff5dSRandall Stewart 	/* pending send queue SHOULD be empty */
38674a9ef3f8SMichael Tuexen 	TAILQ_FOREACH_SAFE(chk, &asoc->send_queue, sctp_next, nchk) {
3868d00aff5dSRandall Stewart 		TAILQ_REMOVE(&asoc->send_queue, chk, sctp_next);
3869d00aff5dSRandall Stewart 		asoc->send_queue_cnt--;
3870a7ad6026SMichael Tuexen 		if (asoc->strmout[chk->rec.data.stream_number].chunks_on_queues > 0) {
3871a7ad6026SMichael Tuexen 			asoc->strmout[chk->rec.data.stream_number].chunks_on_queues--;
3872a7ad6026SMichael Tuexen #ifdef INVARIANTS
3873a7ad6026SMichael Tuexen 		} else {
3874a7ad6026SMichael Tuexen 			panic("No chunks on the queues for sid %u.", chk->rec.data.stream_number);
3875a7ad6026SMichael Tuexen #endif
3876a7ad6026SMichael Tuexen 		}
38770c0982b8SRandall Stewart 		if (chk->data != NULL) {
3878d00aff5dSRandall Stewart 			sctp_free_bufspace(stcb, asoc, chk, 1);
38791edc9dbaSMichael Tuexen 			sctp_ulp_notify(SCTP_NOTIFY_UNSENT_DG_FAIL, stcb,
38801edc9dbaSMichael Tuexen 			    error, chk, so_locked);
3881810ec536SMichael Tuexen 			if (chk->data) {
3882d00aff5dSRandall Stewart 				sctp_m_freem(chk->data);
3883d00aff5dSRandall Stewart 				chk->data = NULL;
3884d00aff5dSRandall Stewart 			}
3885810ec536SMichael Tuexen 		}
3886689e6a5fSMichael Tuexen 		sctp_free_a_chunk(stcb, chk, so_locked);
3887d00aff5dSRandall Stewart 		/* sa_ignore FREED_MEMORY */
3888d00aff5dSRandall Stewart 	}
38894a9ef3f8SMichael Tuexen 	for (i = 0; i < asoc->streamoutcnt; i++) {
38907f34832bSRandall Stewart 		/* For each stream */
38914a9ef3f8SMichael Tuexen 		outs = &asoc->strmout[i];
38927f34832bSRandall Stewart 		/* clean up any sends there */
38934a9ef3f8SMichael Tuexen 		asoc->locked_on_sending = NULL;
38944a9ef3f8SMichael Tuexen 		TAILQ_FOREACH_SAFE(sp, &outs->outqueue, next, nsp) {
38954a9ef3f8SMichael Tuexen 			asoc->stream_queue_cnt--;
3896f8829a4aSRandall Stewart 			TAILQ_REMOVE(&outs->outqueue, sp, next);
3897f8829a4aSRandall Stewart 			sctp_free_spbufspace(stcb, asoc, sp);
3898478fbccbSRandall Stewart 			if (sp->data) {
3899f8829a4aSRandall Stewart 				sctp_ulp_notify(SCTP_NOTIFY_SPECIAL_SP_FAIL, stcb,
39001edc9dbaSMichael Tuexen 				    error, (void *)sp, so_locked);
3901f8829a4aSRandall Stewart 				if (sp->data) {
3902f8829a4aSRandall Stewart 					sctp_m_freem(sp->data);
3903f8829a4aSRandall Stewart 					sp->data = NULL;
3904d07b2ac6SMichael Tuexen 					sp->tail_mbuf = NULL;
3905d07b2ac6SMichael Tuexen 					sp->length = 0;
3906f8829a4aSRandall Stewart 				}
3907478fbccbSRandall Stewart 			}
39089eea4a2dSMichael Tuexen 			if (sp->net) {
3909f8829a4aSRandall Stewart 				sctp_free_remote_addr(sp->net);
3910f8829a4aSRandall Stewart 				sp->net = NULL;
39119eea4a2dSMichael Tuexen 			}
3912f8829a4aSRandall Stewart 			/* Free the chunk */
3913689e6a5fSMichael Tuexen 			sctp_free_a_strmoq(stcb, sp, so_locked);
39143c503c28SRandall Stewart 			/* sa_ignore FREED_MEMORY */
3915f8829a4aSRandall Stewart 		}
3916f8829a4aSRandall Stewart 	}
3917f8829a4aSRandall Stewart 
3918ad81507eSRandall Stewart 	if (holds_lock == 0) {
39197f34832bSRandall Stewart 		SCTP_TCB_SEND_UNLOCK(stcb);
3920f8829a4aSRandall Stewart 	}
3921ad81507eSRandall Stewart }
3922f8829a4aSRandall Stewart 
3923f8829a4aSRandall Stewart void
3924410a3b1eSMichael Tuexen sctp_abort_notification(struct sctp_tcb *stcb, uint8_t from_peer, uint16_t error,
3925a2b42326SMichael Tuexen     struct sctp_abort_chunk *abort, int so_locked
3926ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3927ceaad40aSRandall Stewart     SCTP_UNUSED
3928ceaad40aSRandall Stewart #endif
3929ceaad40aSRandall Stewart )
3930f8829a4aSRandall Stewart {
3931ad81507eSRandall Stewart 	if (stcb == NULL) {
3932ad81507eSRandall Stewart 		return;
3933ad81507eSRandall Stewart 	}
3934c55b70ceSMichael Tuexen 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL) ||
3935c55b70ceSMichael Tuexen 	    ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) &&
3936c55b70ceSMichael Tuexen 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_CONNECTED))) {
3937c55b70ceSMichael Tuexen 		stcb->sctp_ep->sctp_flags |= SCTP_PCB_FLAGS_WAS_ABORTED;
3938c55b70ceSMichael Tuexen 	}
3939f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
3940f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
3941f8829a4aSRandall Stewart 	    (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET)) {
3942f8829a4aSRandall Stewart 		return;
3943f8829a4aSRandall Stewart 	}
3944f8829a4aSRandall Stewart 	/* Tell them we lost the asoc */
39451edc9dbaSMichael Tuexen 	sctp_report_all_outbound(stcb, error, 1, so_locked);
3946410a3b1eSMichael Tuexen 	if (from_peer) {
3947410a3b1eSMichael Tuexen 		sctp_ulp_notify(SCTP_NOTIFY_ASSOC_REM_ABORTED, stcb, error, abort, so_locked);
3948410a3b1eSMichael Tuexen 	} else {
3949410a3b1eSMichael Tuexen 		sctp_ulp_notify(SCTP_NOTIFY_ASSOC_LOC_ABORTED, stcb, error, abort, so_locked);
3950410a3b1eSMichael Tuexen 	}
3951f8829a4aSRandall Stewart }
3952f8829a4aSRandall Stewart 
3953f8829a4aSRandall Stewart void
3954f8829a4aSRandall Stewart sctp_abort_association(struct sctp_inpcb *inp, struct sctp_tcb *stcb,
3955b1754ad1SMichael Tuexen     struct mbuf *m, int iphlen,
3956b1754ad1SMichael Tuexen     struct sockaddr *src, struct sockaddr *dst,
3957b1754ad1SMichael Tuexen     struct sctphdr *sh, struct mbuf *op_err,
3958457b4b88SMichael Tuexen     uint8_t mflowtype, uint32_t mflowid,
3959c54a18d2SRandall Stewart     uint32_t vrf_id, uint16_t port)
3960f8829a4aSRandall Stewart {
3961f8829a4aSRandall Stewart 	uint32_t vtag;
3962f8829a4aSRandall Stewart 
3963ceaad40aSRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3964ceaad40aSRandall Stewart 	struct socket *so;
3965ceaad40aSRandall Stewart 
3966ceaad40aSRandall Stewart #endif
3967ceaad40aSRandall Stewart 
3968f8829a4aSRandall Stewart 	vtag = 0;
3969f8829a4aSRandall Stewart 	if (stcb != NULL) {
3970f8829a4aSRandall Stewart 		/* We have a TCB to abort, send notification too */
3971f8829a4aSRandall Stewart 		vtag = stcb->asoc.peer_vtag;
3972410a3b1eSMichael Tuexen 		sctp_abort_notification(stcb, 0, 0, NULL, SCTP_SO_NOT_LOCKED);
397317205eccSRandall Stewart 		/* get the assoc vrf id and table id */
397417205eccSRandall Stewart 		vrf_id = stcb->asoc.vrf_id;
397563981c2bSRandall Stewart 		stcb->asoc.state |= SCTP_STATE_WAS_ABORTED;
3976f8829a4aSRandall Stewart 	}
3977b1754ad1SMichael Tuexen 	sctp_send_abort(m, iphlen, src, dst, sh, vtag, op_err,
3978d089f9b9SMichael Tuexen 	    mflowtype, mflowid, inp->fibnum,
3979f30ac432SMichael Tuexen 	    vrf_id, port);
3980f8829a4aSRandall Stewart 	if (stcb != NULL) {
3981f8829a4aSRandall Stewart 		/* Ok, now lets free it */
3982ceaad40aSRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3983ceaad40aSRandall Stewart 		so = SCTP_INP_SO(inp);
3984ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
3985ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
3986ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
3987ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
3988ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
3989ceaad40aSRandall Stewart #endif
39900271d0cdSMichael Tuexen 		SCTP_STAT_INCR_COUNTER32(sctps_aborted);
39910271d0cdSMichael Tuexen 		if ((SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_OPEN) ||
39920271d0cdSMichael Tuexen 		    (SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_SHUTDOWN_RECEIVED)) {
39930271d0cdSMichael Tuexen 			SCTP_STAT_DECR_GAUGE32(sctps_currestab);
39940271d0cdSMichael Tuexen 		}
3995ba785902SMichael Tuexen 		(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
3996ba785902SMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_4);
3997ceaad40aSRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3998ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
3999ceaad40aSRandall Stewart #endif
4000f8829a4aSRandall Stewart 	}
4001f8829a4aSRandall Stewart }
4002f8829a4aSRandall Stewart 
4003f1f73e57SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
4004f1f73e57SRandall Stewart void
4005f1f73e57SRandall Stewart sctp_print_out_track_log(struct sctp_tcb *stcb)
4006f1f73e57SRandall Stewart {
400718e198d3SRandall Stewart #ifdef NOSIY_PRINTS
4008f1f73e57SRandall Stewart 	int i;
4009f1f73e57SRandall Stewart 
4010ad81507eSRandall Stewart 	SCTP_PRINTF("Last ep reason:%x\n", stcb->sctp_ep->last_abort_code);
4011ad81507eSRandall Stewart 	SCTP_PRINTF("IN bound TSN log-aaa\n");
4012f1f73e57SRandall Stewart 	if ((stcb->asoc.tsn_in_at == 0) && (stcb->asoc.tsn_in_wrapped == 0)) {
4013ad81507eSRandall Stewart 		SCTP_PRINTF("None rcvd\n");
4014f1f73e57SRandall Stewart 		goto none_in;
4015f1f73e57SRandall Stewart 	}
4016f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_in_wrapped) {
4017f1f73e57SRandall Stewart 		for (i = stcb->asoc.tsn_in_at; i < SCTP_TSN_LOG_SIZE; i++) {
4018ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
4019f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].tsn,
4020f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].strm,
4021f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].seq,
4022f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].flgs,
4023f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].sz);
4024f1f73e57SRandall Stewart 		}
4025f1f73e57SRandall Stewart 	}
4026f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_in_at) {
4027f1f73e57SRandall Stewart 		for (i = 0; i < stcb->asoc.tsn_in_at; i++) {
4028ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
4029f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].tsn,
4030f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].strm,
4031f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].seq,
4032f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].flgs,
4033f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].sz);
4034f1f73e57SRandall Stewart 		}
4035f1f73e57SRandall Stewart 	}
4036f1f73e57SRandall Stewart none_in:
4037ad81507eSRandall Stewart 	SCTP_PRINTF("OUT bound TSN log-aaa\n");
4038ad81507eSRandall Stewart 	if ((stcb->asoc.tsn_out_at == 0) &&
4039ad81507eSRandall Stewart 	    (stcb->asoc.tsn_out_wrapped == 0)) {
4040ad81507eSRandall Stewart 		SCTP_PRINTF("None sent\n");
4041f1f73e57SRandall Stewart 	}
4042f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_out_wrapped) {
4043f1f73e57SRandall Stewart 		for (i = stcb->asoc.tsn_out_at; i < SCTP_TSN_LOG_SIZE; i++) {
4044ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
4045f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].tsn,
4046f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].strm,
4047f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].seq,
4048f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].flgs,
4049f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].sz);
4050f1f73e57SRandall Stewart 		}
4051f1f73e57SRandall Stewart 	}
4052f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_out_at) {
4053f1f73e57SRandall Stewart 		for (i = 0; i < stcb->asoc.tsn_out_at; i++) {
4054ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
4055f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].tsn,
4056f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].strm,
4057f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].seq,
4058f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].flgs,
4059f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].sz);
4060f1f73e57SRandall Stewart 		}
4061f1f73e57SRandall Stewart 	}
406218e198d3SRandall Stewart #endif
4063f1f73e57SRandall Stewart }
4064f1f73e57SRandall Stewart 
4065f1f73e57SRandall Stewart #endif
4066f1f73e57SRandall Stewart 
4067f8829a4aSRandall Stewart void
4068f8829a4aSRandall Stewart sctp_abort_an_association(struct sctp_inpcb *inp, struct sctp_tcb *stcb,
4069a2b42326SMichael Tuexen     struct mbuf *op_err,
4070ceaad40aSRandall Stewart     int so_locked
4071ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
4072ceaad40aSRandall Stewart     SCTP_UNUSED
4073ceaad40aSRandall Stewart #endif
4074ceaad40aSRandall Stewart )
4075f8829a4aSRandall Stewart {
4076ceaad40aSRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4077ceaad40aSRandall Stewart 	struct socket *so;
4078ceaad40aSRandall Stewart 
4079ceaad40aSRandall Stewart #endif
4080ceaad40aSRandall Stewart 
4081ceaad40aSRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4082ceaad40aSRandall Stewart 	so = SCTP_INP_SO(inp);
4083ceaad40aSRandall Stewart #endif
4084f8829a4aSRandall Stewart 	if (stcb == NULL) {
4085f8829a4aSRandall Stewart 		/* Got to have a TCB */
4086f8829a4aSRandall Stewart 		if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
4087fe1831e0SMichael Tuexen 			if (LIST_EMPTY(&inp->sctp_asoc_list)) {
4088b0552ae2SRandall Stewart 				sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
4089b0552ae2SRandall Stewart 				    SCTP_CALLED_DIRECTLY_NOCMPSET);
4090f8829a4aSRandall Stewart 			}
4091f8829a4aSRandall Stewart 		}
4092f8829a4aSRandall Stewart 		return;
409363981c2bSRandall Stewart 	} else {
409463981c2bSRandall Stewart 		stcb->asoc.state |= SCTP_STATE_WAS_ABORTED;
4095f8829a4aSRandall Stewart 	}
4096f8829a4aSRandall Stewart 	/* notify the ulp */
4097a2b42326SMichael Tuexen 	if ((inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) == 0) {
4098410a3b1eSMichael Tuexen 		sctp_abort_notification(stcb, 0, 0, NULL, so_locked);
4099a2b42326SMichael Tuexen 	}
4100f8829a4aSRandall Stewart 	/* notify the peer */
4101ceaad40aSRandall Stewart 	sctp_send_abort_tcb(stcb, op_err, so_locked);
4102f8829a4aSRandall Stewart 	SCTP_STAT_INCR_COUNTER32(sctps_aborted);
4103f8829a4aSRandall Stewart 	if ((SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_OPEN) ||
4104f8829a4aSRandall Stewart 	    (SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_SHUTDOWN_RECEIVED)) {
4105f8829a4aSRandall Stewart 		SCTP_STAT_DECR_GAUGE32(sctps_currestab);
4106f8829a4aSRandall Stewart 	}
4107f8829a4aSRandall Stewart 	/* now free the asoc */
4108f1f73e57SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
4109f1f73e57SRandall Stewart 	sctp_print_out_track_log(stcb);
4110f1f73e57SRandall Stewart #endif
4111ceaad40aSRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4112ceaad40aSRandall Stewart 	if (!so_locked) {
4113ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
4114ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
4115ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
4116ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
4117ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
4118ceaad40aSRandall Stewart 	}
4119ceaad40aSRandall Stewart #endif
4120ba785902SMichael Tuexen 	(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
4121ba785902SMichael Tuexen 	    SCTP_FROM_SCTPUTIL + SCTP_LOC_5);
4122ceaad40aSRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4123ceaad40aSRandall Stewart 	if (!so_locked) {
4124ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
4125ceaad40aSRandall Stewart 	}
4126ceaad40aSRandall Stewart #endif
4127f8829a4aSRandall Stewart }
4128f8829a4aSRandall Stewart 
4129f8829a4aSRandall Stewart void
4130b1754ad1SMichael Tuexen sctp_handle_ootb(struct mbuf *m, int iphlen, int offset,
4131b1754ad1SMichael Tuexen     struct sockaddr *src, struct sockaddr *dst,
4132b1754ad1SMichael Tuexen     struct sctphdr *sh, struct sctp_inpcb *inp,
4133ff1ffd74SMichael Tuexen     struct mbuf *cause,
4134d089f9b9SMichael Tuexen     uint8_t mflowtype, uint32_t mflowid, uint16_t fibnum,
4135f30ac432SMichael Tuexen     uint32_t vrf_id, uint16_t port)
4136f8829a4aSRandall Stewart {
4137f8829a4aSRandall Stewart 	struct sctp_chunkhdr *ch, chunk_buf;
4138f8829a4aSRandall Stewart 	unsigned int chk_length;
4139c58e60beSMichael Tuexen 	int contains_init_chunk;
4140f8829a4aSRandall Stewart 
4141f8829a4aSRandall Stewart 	SCTP_STAT_INCR_COUNTER32(sctps_outoftheblue);
4142f8829a4aSRandall Stewart 	/* Generate a TO address for future reference */
4143f8829a4aSRandall Stewart 	if (inp && (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE)) {
4144fe1831e0SMichael Tuexen 		if (LIST_EMPTY(&inp->sctp_asoc_list)) {
4145b0552ae2SRandall Stewart 			sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
4146b0552ae2SRandall Stewart 			    SCTP_CALLED_DIRECTLY_NOCMPSET);
4147f8829a4aSRandall Stewart 		}
4148f8829a4aSRandall Stewart 	}
4149c58e60beSMichael Tuexen 	contains_init_chunk = 0;
4150f8829a4aSRandall Stewart 	ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
4151f8829a4aSRandall Stewart 	    sizeof(*ch), (uint8_t *) & chunk_buf);
4152f8829a4aSRandall Stewart 	while (ch != NULL) {
4153f8829a4aSRandall Stewart 		chk_length = ntohs(ch->chunk_length);
4154f8829a4aSRandall Stewart 		if (chk_length < sizeof(*ch)) {
4155f8829a4aSRandall Stewart 			/* break to abort land */
4156f8829a4aSRandall Stewart 			break;
4157f8829a4aSRandall Stewart 		}
4158f8829a4aSRandall Stewart 		switch (ch->chunk_type) {
4159c58e60beSMichael Tuexen 		case SCTP_INIT:
4160c58e60beSMichael Tuexen 			contains_init_chunk = 1;
4161c58e60beSMichael Tuexen 			break;
4162f8829a4aSRandall Stewart 		case SCTP_PACKET_DROPPED:
4163f8829a4aSRandall Stewart 			/* we don't respond to pkt-dropped */
4164f8829a4aSRandall Stewart 			return;
4165f8829a4aSRandall Stewart 		case SCTP_ABORT_ASSOCIATION:
4166f8829a4aSRandall Stewart 			/* we don't respond with an ABORT to an ABORT */
4167f8829a4aSRandall Stewart 			return;
4168f8829a4aSRandall Stewart 		case SCTP_SHUTDOWN_COMPLETE:
4169f8829a4aSRandall Stewart 			/*
4170f8829a4aSRandall Stewart 			 * we ignore it since we are not waiting for it and
4171f8829a4aSRandall Stewart 			 * peer is gone
4172f8829a4aSRandall Stewart 			 */
4173f8829a4aSRandall Stewart 			return;
4174f8829a4aSRandall Stewart 		case SCTP_SHUTDOWN_ACK:
4175b1754ad1SMichael Tuexen 			sctp_send_shutdown_complete2(src, dst, sh,
4176d089f9b9SMichael Tuexen 			    mflowtype, mflowid, fibnum,
4177f30ac432SMichael Tuexen 			    vrf_id, port);
4178f8829a4aSRandall Stewart 			return;
4179f8829a4aSRandall Stewart 		default:
4180f8829a4aSRandall Stewart 			break;
4181f8829a4aSRandall Stewart 		}
4182f8829a4aSRandall Stewart 		offset += SCTP_SIZE32(chk_length);
4183f8829a4aSRandall Stewart 		ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
4184f8829a4aSRandall Stewart 		    sizeof(*ch), (uint8_t *) & chunk_buf);
4185f8829a4aSRandall Stewart 	}
4186c58e60beSMichael Tuexen 	if ((SCTP_BASE_SYSCTL(sctp_blackhole) == 0) ||
4187c58e60beSMichael Tuexen 	    ((SCTP_BASE_SYSCTL(sctp_blackhole) == 1) &&
4188c58e60beSMichael Tuexen 	    (contains_init_chunk == 0))) {
4189ff1ffd74SMichael Tuexen 		sctp_send_abort(m, iphlen, src, dst, sh, 0, cause,
4190d089f9b9SMichael Tuexen 		    mflowtype, mflowid, fibnum,
4191f30ac432SMichael Tuexen 		    vrf_id, port);
4192f8829a4aSRandall Stewart 	}
4193c58e60beSMichael Tuexen }
4194f8829a4aSRandall Stewart 
4195f8829a4aSRandall Stewart /*
4196f8829a4aSRandall Stewart  * check the inbound datagram to make sure there is not an abort inside it,
4197f8829a4aSRandall Stewart  * if there is return 1, else return 0.
4198f8829a4aSRandall Stewart  */
4199f8829a4aSRandall Stewart int
4200f8829a4aSRandall Stewart sctp_is_there_an_abort_here(struct mbuf *m, int iphlen, uint32_t * vtagfill)
4201f8829a4aSRandall Stewart {
4202f8829a4aSRandall Stewart 	struct sctp_chunkhdr *ch;
4203f8829a4aSRandall Stewart 	struct sctp_init_chunk *init_chk, chunk_buf;
4204f8829a4aSRandall Stewart 	int offset;
4205f8829a4aSRandall Stewart 	unsigned int chk_length;
4206f8829a4aSRandall Stewart 
4207f8829a4aSRandall Stewart 	offset = iphlen + sizeof(struct sctphdr);
4208f8829a4aSRandall Stewart 	ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset, sizeof(*ch),
4209f8829a4aSRandall Stewart 	    (uint8_t *) & chunk_buf);
4210f8829a4aSRandall Stewart 	while (ch != NULL) {
4211f8829a4aSRandall Stewart 		chk_length = ntohs(ch->chunk_length);
4212f8829a4aSRandall Stewart 		if (chk_length < sizeof(*ch)) {
4213f8829a4aSRandall Stewart 			/* packet is probably corrupt */
4214f8829a4aSRandall Stewart 			break;
4215f8829a4aSRandall Stewart 		}
4216f8829a4aSRandall Stewart 		/* we seem to be ok, is it an abort? */
4217f8829a4aSRandall Stewart 		if (ch->chunk_type == SCTP_ABORT_ASSOCIATION) {
4218f8829a4aSRandall Stewart 			/* yep, tell them */
4219f8829a4aSRandall Stewart 			return (1);
4220f8829a4aSRandall Stewart 		}
4221f8829a4aSRandall Stewart 		if (ch->chunk_type == SCTP_INITIATION) {
4222f8829a4aSRandall Stewart 			/* need to update the Vtag */
4223f8829a4aSRandall Stewart 			init_chk = (struct sctp_init_chunk *)sctp_m_getptr(m,
4224f8829a4aSRandall Stewart 			    offset, sizeof(*init_chk), (uint8_t *) & chunk_buf);
4225f8829a4aSRandall Stewart 			if (init_chk != NULL) {
4226f8829a4aSRandall Stewart 				*vtagfill = ntohl(init_chk->init.initiate_tag);
4227f8829a4aSRandall Stewart 			}
4228f8829a4aSRandall Stewart 		}
4229f8829a4aSRandall Stewart 		/* Nope, move to the next chunk */
4230f8829a4aSRandall Stewart 		offset += SCTP_SIZE32(chk_length);
4231f8829a4aSRandall Stewart 		ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
4232f8829a4aSRandall Stewart 		    sizeof(*ch), (uint8_t *) & chunk_buf);
4233f8829a4aSRandall Stewart 	}
4234f8829a4aSRandall Stewart 	return (0);
4235f8829a4aSRandall Stewart }
4236f8829a4aSRandall Stewart 
4237f8829a4aSRandall Stewart /*
4238f8829a4aSRandall Stewart  * currently (2/02), ifa_addr embeds scope_id's and don't have sin6_scope_id
4239f8829a4aSRandall Stewart  * set (i.e. it's 0) so, create this function to compare link local scopes
4240f8829a4aSRandall Stewart  */
42415e2c2d87SRandall Stewart #ifdef INET6
4242f8829a4aSRandall Stewart uint32_t
4243f8829a4aSRandall Stewart sctp_is_same_scope(struct sockaddr_in6 *addr1, struct sockaddr_in6 *addr2)
4244f8829a4aSRandall Stewart {
4245f8829a4aSRandall Stewart 	struct sockaddr_in6 a, b;
4246f8829a4aSRandall Stewart 
4247f8829a4aSRandall Stewart 	/* save copies */
4248f8829a4aSRandall Stewart 	a = *addr1;
4249f8829a4aSRandall Stewart 	b = *addr2;
4250f8829a4aSRandall Stewart 
4251f8829a4aSRandall Stewart 	if (a.sin6_scope_id == 0)
4252f8829a4aSRandall Stewart 		if (sa6_recoverscope(&a)) {
4253f8829a4aSRandall Stewart 			/* can't get scope, so can't match */
4254f8829a4aSRandall Stewart 			return (0);
4255f8829a4aSRandall Stewart 		}
4256f8829a4aSRandall Stewart 	if (b.sin6_scope_id == 0)
4257f8829a4aSRandall Stewart 		if (sa6_recoverscope(&b)) {
4258f8829a4aSRandall Stewart 			/* can't get scope, so can't match */
4259f8829a4aSRandall Stewart 			return (0);
4260f8829a4aSRandall Stewart 		}
4261f8829a4aSRandall Stewart 	if (a.sin6_scope_id != b.sin6_scope_id)
4262f8829a4aSRandall Stewart 		return (0);
4263f8829a4aSRandall Stewart 
4264f8829a4aSRandall Stewart 	return (1);
4265f8829a4aSRandall Stewart }
4266f8829a4aSRandall Stewart 
4267f8829a4aSRandall Stewart /*
4268f8829a4aSRandall Stewart  * returns a sockaddr_in6 with embedded scope recovered and removed
4269f8829a4aSRandall Stewart  */
4270f8829a4aSRandall Stewart struct sockaddr_in6 *
4271f8829a4aSRandall Stewart sctp_recover_scope(struct sockaddr_in6 *addr, struct sockaddr_in6 *store)
4272f8829a4aSRandall Stewart {
4273f8829a4aSRandall Stewart 	/* check and strip embedded scope junk */
4274f8829a4aSRandall Stewart 	if (addr->sin6_family == AF_INET6) {
4275f8829a4aSRandall Stewart 		if (IN6_IS_SCOPE_LINKLOCAL(&addr->sin6_addr)) {
4276f8829a4aSRandall Stewart 			if (addr->sin6_scope_id == 0) {
4277f8829a4aSRandall Stewart 				*store = *addr;
4278f8829a4aSRandall Stewart 				if (!sa6_recoverscope(store)) {
4279f8829a4aSRandall Stewart 					/* use the recovered scope */
4280f8829a4aSRandall Stewart 					addr = store;
4281f8829a4aSRandall Stewart 				}
4282f42a358aSRandall Stewart 			} else {
4283f8829a4aSRandall Stewart 				/* else, return the original "to" addr */
4284f42a358aSRandall Stewart 				in6_clearscope(&addr->sin6_addr);
4285f8829a4aSRandall Stewart 			}
4286f8829a4aSRandall Stewart 		}
4287f8829a4aSRandall Stewart 	}
4288f8829a4aSRandall Stewart 	return (addr);
4289f8829a4aSRandall Stewart }
4290f8829a4aSRandall Stewart 
42915e2c2d87SRandall Stewart #endif
42925e2c2d87SRandall Stewart 
4293f8829a4aSRandall Stewart /*
4294f8829a4aSRandall Stewart  * are the two addresses the same?  currently a "scopeless" check returns: 1
4295f8829a4aSRandall Stewart  * if same, 0 if not
4296f8829a4aSRandall Stewart  */
429772fb6fdbSRandall Stewart int
4298f8829a4aSRandall Stewart sctp_cmpaddr(struct sockaddr *sa1, struct sockaddr *sa2)
4299f8829a4aSRandall Stewart {
4300f8829a4aSRandall Stewart 
4301f8829a4aSRandall Stewart 	/* must be valid */
4302f8829a4aSRandall Stewart 	if (sa1 == NULL || sa2 == NULL)
4303f8829a4aSRandall Stewart 		return (0);
4304f8829a4aSRandall Stewart 
4305f8829a4aSRandall Stewart 	/* must be the same family */
4306f8829a4aSRandall Stewart 	if (sa1->sa_family != sa2->sa_family)
4307f8829a4aSRandall Stewart 		return (0);
4308f8829a4aSRandall Stewart 
43095e2c2d87SRandall Stewart 	switch (sa1->sa_family) {
43105e2c2d87SRandall Stewart #ifdef INET6
43115e2c2d87SRandall Stewart 	case AF_INET6:
43125e2c2d87SRandall Stewart 		{
4313f8829a4aSRandall Stewart 			/* IPv6 addresses */
4314f8829a4aSRandall Stewart 			struct sockaddr_in6 *sin6_1, *sin6_2;
4315f8829a4aSRandall Stewart 
4316f8829a4aSRandall Stewart 			sin6_1 = (struct sockaddr_in6 *)sa1;
4317f8829a4aSRandall Stewart 			sin6_2 = (struct sockaddr_in6 *)sa2;
4318c54a18d2SRandall Stewart 			return (SCTP6_ARE_ADDR_EQUAL(sin6_1,
4319c54a18d2SRandall Stewart 			    sin6_2));
43205e2c2d87SRandall Stewart 		}
43215e2c2d87SRandall Stewart #endif
4322ea5eba11SMichael Tuexen #ifdef INET
43235e2c2d87SRandall Stewart 	case AF_INET:
43245e2c2d87SRandall Stewart 		{
4325f8829a4aSRandall Stewart 			/* IPv4 addresses */
4326f8829a4aSRandall Stewart 			struct sockaddr_in *sin_1, *sin_2;
4327f8829a4aSRandall Stewart 
4328f8829a4aSRandall Stewart 			sin_1 = (struct sockaddr_in *)sa1;
4329f8829a4aSRandall Stewart 			sin_2 = (struct sockaddr_in *)sa2;
4330f8829a4aSRandall Stewart 			return (sin_1->sin_addr.s_addr == sin_2->sin_addr.s_addr);
43315e2c2d87SRandall Stewart 		}
4332ea5eba11SMichael Tuexen #endif
43335e2c2d87SRandall Stewart 	default:
4334f8829a4aSRandall Stewart 		/* we don't do these... */
4335f8829a4aSRandall Stewart 		return (0);
4336f8829a4aSRandall Stewart 	}
4337f8829a4aSRandall Stewart }
4338f8829a4aSRandall Stewart 
4339f8829a4aSRandall Stewart void
4340f8829a4aSRandall Stewart sctp_print_address(struct sockaddr *sa)
4341f8829a4aSRandall Stewart {
43425e2c2d87SRandall Stewart #ifdef INET6
43437d32aa0cSBjoern A. Zeeb 	char ip6buf[INET6_ADDRSTRLEN];
4344f8829a4aSRandall Stewart 
43455e2c2d87SRandall Stewart #endif
43465e2c2d87SRandall Stewart 
43475e2c2d87SRandall Stewart 	switch (sa->sa_family) {
43485e2c2d87SRandall Stewart #ifdef INET6
43495e2c2d87SRandall Stewart 	case AF_INET6:
43505e2c2d87SRandall Stewart 		{
4351ad81507eSRandall Stewart 			struct sockaddr_in6 *sin6;
4352ad81507eSRandall Stewart 
4353f8829a4aSRandall Stewart 			sin6 = (struct sockaddr_in6 *)sa;
4354ad81507eSRandall Stewart 			SCTP_PRINTF("IPv6 address: %s:port:%d scope:%u\n",
43557d32aa0cSBjoern A. Zeeb 			    ip6_sprintf(ip6buf, &sin6->sin6_addr),
43567d32aa0cSBjoern A. Zeeb 			    ntohs(sin6->sin6_port),
4357f8829a4aSRandall Stewart 			    sin6->sin6_scope_id);
43585e2c2d87SRandall Stewart 			break;
43595e2c2d87SRandall Stewart 		}
43605e2c2d87SRandall Stewart #endif
4361ea5eba11SMichael Tuexen #ifdef INET
43625e2c2d87SRandall Stewart 	case AF_INET:
43635e2c2d87SRandall Stewart 		{
4364f8829a4aSRandall Stewart 			struct sockaddr_in *sin;
4365f8829a4aSRandall Stewart 			unsigned char *p;
4366f8829a4aSRandall Stewart 
4367f8829a4aSRandall Stewart 			sin = (struct sockaddr_in *)sa;
4368f8829a4aSRandall Stewart 			p = (unsigned char *)&sin->sin_addr;
4369ad81507eSRandall Stewart 			SCTP_PRINTF("IPv4 address: %u.%u.%u.%u:%d\n",
4370f8829a4aSRandall Stewart 			    p[0], p[1], p[2], p[3], ntohs(sin->sin_port));
43715e2c2d87SRandall Stewart 			break;
43725e2c2d87SRandall Stewart 		}
4373ea5eba11SMichael Tuexen #endif
43745e2c2d87SRandall Stewart 	default:
4375ad81507eSRandall Stewart 		SCTP_PRINTF("?\n");
43765e2c2d87SRandall Stewart 		break;
4377f8829a4aSRandall Stewart 	}
4378f8829a4aSRandall Stewart }
4379f8829a4aSRandall Stewart 
4380f8829a4aSRandall Stewart void
4381f8829a4aSRandall Stewart sctp_pull_off_control_to_new_inp(struct sctp_inpcb *old_inp,
4382f8829a4aSRandall Stewart     struct sctp_inpcb *new_inp,
4383d06c82f1SRandall Stewart     struct sctp_tcb *stcb,
4384d06c82f1SRandall Stewart     int waitflags)
4385f8829a4aSRandall Stewart {
4386f8829a4aSRandall Stewart 	/*
4387f8829a4aSRandall Stewart 	 * go through our old INP and pull off any control structures that
4388f8829a4aSRandall Stewart 	 * belong to stcb and move then to the new inp.
4389f8829a4aSRandall Stewart 	 */
4390f8829a4aSRandall Stewart 	struct socket *old_so, *new_so;
4391f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control, *nctl;
4392f8829a4aSRandall Stewart 	struct sctp_readhead tmp_queue;
4393f8829a4aSRandall Stewart 	struct mbuf *m;
4394bff64a4dSRandall Stewart 	int error = 0;
4395f8829a4aSRandall Stewart 
4396f8829a4aSRandall Stewart 	old_so = old_inp->sctp_socket;
4397f8829a4aSRandall Stewart 	new_so = new_inp->sctp_socket;
4398f8829a4aSRandall Stewart 	TAILQ_INIT(&tmp_queue);
4399d06c82f1SRandall Stewart 	error = sblock(&old_so->so_rcv, waitflags);
4400f8829a4aSRandall Stewart 	if (error) {
4401f8829a4aSRandall Stewart 		/*
4402f8829a4aSRandall Stewart 		 * Gak, can't get sblock, we have a problem. data will be
4403f8829a4aSRandall Stewart 		 * left stranded.. and we don't dare look at it since the
4404f8829a4aSRandall Stewart 		 * other thread may be reading something. Oh well, its a
4405f8829a4aSRandall Stewart 		 * screwed up app that does a peeloff OR a accept while
4406f8829a4aSRandall Stewart 		 * reading from the main socket... actually its only the
4407f8829a4aSRandall Stewart 		 * peeloff() case, since I think read will fail on a
4408f8829a4aSRandall Stewart 		 * listening socket..
4409f8829a4aSRandall Stewart 		 */
4410f8829a4aSRandall Stewart 		return;
4411f8829a4aSRandall Stewart 	}
4412f8829a4aSRandall Stewart 	/* lock the socket buffers */
4413f8829a4aSRandall Stewart 	SCTP_INP_READ_LOCK(old_inp);
44144a9ef3f8SMichael Tuexen 	TAILQ_FOREACH_SAFE(control, &old_inp->read_queue, next, nctl) {
4415f8829a4aSRandall Stewart 		/* Pull off all for out target stcb */
4416f8829a4aSRandall Stewart 		if (control->stcb == stcb) {
4417f8829a4aSRandall Stewart 			/* remove it we want it */
4418f8829a4aSRandall Stewart 			TAILQ_REMOVE(&old_inp->read_queue, control, next);
4419f8829a4aSRandall Stewart 			TAILQ_INSERT_TAIL(&tmp_queue, control, next);
4420f8829a4aSRandall Stewart 			m = control->data;
4421f8829a4aSRandall Stewart 			while (m) {
4422b3f1ea41SRandall Stewart 				if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4423139bc87fSRandall Stewart 					sctp_sblog(&old_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
442480fefe0aSRandall Stewart 				}
4425f8829a4aSRandall Stewart 				sctp_sbfree(control, stcb, &old_so->so_rcv, m);
4426b3f1ea41SRandall Stewart 				if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4427f8829a4aSRandall Stewart 					sctp_sblog(&old_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
442880fefe0aSRandall Stewart 				}
4429139bc87fSRandall Stewart 				m = SCTP_BUF_NEXT(m);
4430f8829a4aSRandall Stewart 			}
4431f8829a4aSRandall Stewart 		}
4432f8829a4aSRandall Stewart 	}
4433f8829a4aSRandall Stewart 	SCTP_INP_READ_UNLOCK(old_inp);
4434f8829a4aSRandall Stewart 	/* Remove the sb-lock on the old socket */
4435f8829a4aSRandall Stewart 
4436f8829a4aSRandall Stewart 	sbunlock(&old_so->so_rcv);
4437f8829a4aSRandall Stewart 	/* Now we move them over to the new socket buffer */
4438f8829a4aSRandall Stewart 	SCTP_INP_READ_LOCK(new_inp);
44394a9ef3f8SMichael Tuexen 	TAILQ_FOREACH_SAFE(control, &tmp_queue, next, nctl) {
4440f8829a4aSRandall Stewart 		TAILQ_INSERT_TAIL(&new_inp->read_queue, control, next);
4441f8829a4aSRandall Stewart 		m = control->data;
4442f8829a4aSRandall Stewart 		while (m) {
4443b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4444139bc87fSRandall Stewart 				sctp_sblog(&new_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m));
444580fefe0aSRandall Stewart 			}
4446f8829a4aSRandall Stewart 			sctp_sballoc(stcb, &new_so->so_rcv, m);
4447b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4448f8829a4aSRandall Stewart 				sctp_sblog(&new_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
444980fefe0aSRandall Stewart 			}
4450139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
4451f8829a4aSRandall Stewart 		}
4452f8829a4aSRandall Stewart 	}
4453f8829a4aSRandall Stewart 	SCTP_INP_READ_UNLOCK(new_inp);
4454f8829a4aSRandall Stewart }
4455f8829a4aSRandall Stewart 
4456f8829a4aSRandall Stewart void
4457*b1deed45SMichael Tuexen sctp_wakeup_the_read_socket(struct sctp_inpcb *inp,
4458*b1deed45SMichael Tuexen     struct sctp_tcb *stcb,
4459*b1deed45SMichael Tuexen     int so_locked
4460*b1deed45SMichael Tuexen #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
4461*b1deed45SMichael Tuexen     SCTP_UNUSED
4462*b1deed45SMichael Tuexen #endif
4463*b1deed45SMichael Tuexen )
446444249214SRandall Stewart {
4465*b1deed45SMichael Tuexen 	if ((inp != NULL) && (inp->sctp_socket != NULL)) {
446644249214SRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_ZERO_COPY_ACTIVE)) {
446744249214SRandall Stewart 			SCTP_ZERO_COPY_EVENT(inp, inp->sctp_socket);
446844249214SRandall Stewart 		} else {
446944249214SRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
447044249214SRandall Stewart 			struct socket *so;
447144249214SRandall Stewart 
447244249214SRandall Stewart 			so = SCTP_INP_SO(inp);
447344249214SRandall Stewart 			if (!so_locked) {
447444249214SRandall Stewart 				if (stcb) {
447544249214SRandall Stewart 					atomic_add_int(&stcb->asoc.refcnt, 1);
447644249214SRandall Stewart 					SCTP_TCB_UNLOCK(stcb);
447744249214SRandall Stewart 				}
447844249214SRandall Stewart 				SCTP_SOCKET_LOCK(so, 1);
447944249214SRandall Stewart 				if (stcb) {
448044249214SRandall Stewart 					SCTP_TCB_LOCK(stcb);
448144249214SRandall Stewart 					atomic_subtract_int(&stcb->asoc.refcnt, 1);
448244249214SRandall Stewart 				}
448344249214SRandall Stewart 				if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
448444249214SRandall Stewart 					SCTP_SOCKET_UNLOCK(so, 1);
448544249214SRandall Stewart 					return;
448644249214SRandall Stewart 				}
448744249214SRandall Stewart 			}
448844249214SRandall Stewart #endif
448944249214SRandall Stewart 			sctp_sorwakeup(inp, inp->sctp_socket);
449044249214SRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
449144249214SRandall Stewart 			if (!so_locked) {
449244249214SRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
449344249214SRandall Stewart 			}
449444249214SRandall Stewart #endif
449544249214SRandall Stewart 		}
449644249214SRandall Stewart 	}
449744249214SRandall Stewart }
449844249214SRandall Stewart 
449944249214SRandall Stewart void
4500f8829a4aSRandall Stewart sctp_add_to_readq(struct sctp_inpcb *inp,
4501f8829a4aSRandall Stewart     struct sctp_tcb *stcb,
4502f8829a4aSRandall Stewart     struct sctp_queued_to_read *control,
4503f8829a4aSRandall Stewart     struct sockbuf *sb,
4504ceaad40aSRandall Stewart     int end,
4505cfde3ff7SRandall Stewart     int inp_read_lock_held,
4506ceaad40aSRandall Stewart     int so_locked
4507ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
4508ceaad40aSRandall Stewart     SCTP_UNUSED
4509ceaad40aSRandall Stewart #endif
4510ceaad40aSRandall Stewart )
4511f8829a4aSRandall Stewart {
4512f8829a4aSRandall Stewart 	/*
4513f8829a4aSRandall Stewart 	 * Here we must place the control on the end of the socket read
45144e88d37aSMichael Tuexen 	 * queue AND increment sb_cc so that select will work properly on
4515f8829a4aSRandall Stewart 	 * read.
4516f8829a4aSRandall Stewart 	 */
4517f8829a4aSRandall Stewart 	struct mbuf *m, *prev = NULL;
4518f8829a4aSRandall Stewart 
451903b0b021SRandall Stewart 	if (inp == NULL) {
452003b0b021SRandall Stewart 		/* Gak, TSNH!! */
4521a5d547adSRandall Stewart #ifdef INVARIANTS
452203b0b021SRandall Stewart 		panic("Gak, inp NULL on add_to_readq");
452303b0b021SRandall Stewart #endif
452403b0b021SRandall Stewart 		return;
452503b0b021SRandall Stewart 	}
4526cfde3ff7SRandall Stewart 	if (inp_read_lock_held == 0)
4527f8829a4aSRandall Stewart 		SCTP_INP_READ_LOCK(inp);
4528cd1386abSMichael Tuexen 	if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_CANT_READ) {
4529cd1386abSMichael Tuexen 		sctp_free_remote_addr(control->whoFrom);
4530cd1386abSMichael Tuexen 		if (control->data) {
4531cd1386abSMichael Tuexen 			sctp_m_freem(control->data);
4532cd1386abSMichael Tuexen 			control->data = NULL;
4533cd1386abSMichael Tuexen 		}
453444249214SRandall Stewart 		sctp_free_a_readq(stcb, control);
4535cd1386abSMichael Tuexen 		if (inp_read_lock_held == 0)
4536cd1386abSMichael Tuexen 			SCTP_INP_READ_UNLOCK(inp);
4537cd1386abSMichael Tuexen 		return;
4538cd1386abSMichael Tuexen 	}
453942551e99SRandall Stewart 	if (!(control->spec_flags & M_NOTIFICATION)) {
4540a5d547adSRandall Stewart 		atomic_add_int(&inp->total_recvs, 1);
454142551e99SRandall Stewart 		if (!control->do_not_ref_stcb) {
4542a5d547adSRandall Stewart 			atomic_add_int(&stcb->total_recvs, 1);
454342551e99SRandall Stewart 		}
454442551e99SRandall Stewart 	}
4545f8829a4aSRandall Stewart 	m = control->data;
4546f8829a4aSRandall Stewart 	control->held_length = 0;
4547f8829a4aSRandall Stewart 	control->length = 0;
4548f8829a4aSRandall Stewart 	while (m) {
4549139bc87fSRandall Stewart 		if (SCTP_BUF_LEN(m) == 0) {
4550f8829a4aSRandall Stewart 			/* Skip mbufs with NO length */
4551f8829a4aSRandall Stewart 			if (prev == NULL) {
4552f8829a4aSRandall Stewart 				/* First one */
4553f8829a4aSRandall Stewart 				control->data = sctp_m_free(m);
4554f8829a4aSRandall Stewart 				m = control->data;
4555f8829a4aSRandall Stewart 			} else {
4556139bc87fSRandall Stewart 				SCTP_BUF_NEXT(prev) = sctp_m_free(m);
4557139bc87fSRandall Stewart 				m = SCTP_BUF_NEXT(prev);
4558f8829a4aSRandall Stewart 			}
4559f8829a4aSRandall Stewart 			if (m == NULL) {
4560c2ede4b3SMartin Blapp 				control->tail_mbuf = prev;
4561f8829a4aSRandall Stewart 			}
4562f8829a4aSRandall Stewart 			continue;
4563f8829a4aSRandall Stewart 		}
4564f8829a4aSRandall Stewart 		prev = m;
4565b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4566139bc87fSRandall Stewart 			sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m));
456780fefe0aSRandall Stewart 		}
4568f8829a4aSRandall Stewart 		sctp_sballoc(stcb, sb, m);
4569b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4570f8829a4aSRandall Stewart 			sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
457180fefe0aSRandall Stewart 		}
4572139bc87fSRandall Stewart 		atomic_add_int(&control->length, SCTP_BUF_LEN(m));
4573139bc87fSRandall Stewart 		m = SCTP_BUF_NEXT(m);
4574f8829a4aSRandall Stewart 	}
4575f8829a4aSRandall Stewart 	if (prev != NULL) {
4576f8829a4aSRandall Stewart 		control->tail_mbuf = prev;
4577f8829a4aSRandall Stewart 	} else {
4578139bc87fSRandall Stewart 		/* Everything got collapsed out?? */
4579cd1386abSMichael Tuexen 		sctp_free_remote_addr(control->whoFrom);
458044249214SRandall Stewart 		sctp_free_a_readq(stcb, control);
4581cfde3ff7SRandall Stewart 		if (inp_read_lock_held == 0)
458247a490cbSMichael Tuexen 			SCTP_INP_READ_UNLOCK(inp);
4583f8829a4aSRandall Stewart 		return;
4584f8829a4aSRandall Stewart 	}
4585f8829a4aSRandall Stewart 	if (end) {
4586f8829a4aSRandall Stewart 		control->end_added = 1;
4587f8829a4aSRandall Stewart 	}
4588f8829a4aSRandall Stewart 	TAILQ_INSERT_TAIL(&inp->read_queue, control, next);
458944249214SRandall Stewart 	control->on_read_q = 1;
4590cfde3ff7SRandall Stewart 	if (inp_read_lock_held == 0)
4591f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
4592f8829a4aSRandall Stewart 	if (inp && inp->sctp_socket) {
4593*b1deed45SMichael Tuexen 		sctp_wakeup_the_read_socket(inp, stcb, so_locked);
4594f8829a4aSRandall Stewart 	}
4595f8829a4aSRandall Stewart }
4596f8829a4aSRandall Stewart 
4597f8829a4aSRandall Stewart 
4598f8829a4aSRandall Stewart int
4599f8829a4aSRandall Stewart sctp_append_to_readq(struct sctp_inpcb *inp,
4600f8829a4aSRandall Stewart     struct sctp_tcb *stcb,
4601f8829a4aSRandall Stewart     struct sctp_queued_to_read *control,
4602f8829a4aSRandall Stewart     struct mbuf *m,
4603f8829a4aSRandall Stewart     int end,
4604f8829a4aSRandall Stewart     int ctls_cumack,
4605f8829a4aSRandall Stewart     struct sockbuf *sb)
4606f8829a4aSRandall Stewart {
4607f8829a4aSRandall Stewart 	/*
4608f8829a4aSRandall Stewart 	 * A partial delivery API event is underway. OR we are appending on
4609f8829a4aSRandall Stewart 	 * the reassembly queue.
4610f8829a4aSRandall Stewart 	 *
4611f8829a4aSRandall Stewart 	 * If PDAPI this means we need to add m to the end of the data.
46124e88d37aSMichael Tuexen 	 * Increase the length in the control AND increment the sb_cc.
4613f8829a4aSRandall Stewart 	 * Otherwise sb is NULL and all we need to do is put it at the end
4614f8829a4aSRandall Stewart 	 * of the mbuf chain.
4615f8829a4aSRandall Stewart 	 */
4616f8829a4aSRandall Stewart 	int len = 0;
4617f8829a4aSRandall Stewart 	struct mbuf *mm, *tail = NULL, *prev = NULL;
4618f8829a4aSRandall Stewart 
4619f8829a4aSRandall Stewart 	if (inp) {
4620f8829a4aSRandall Stewart 		SCTP_INP_READ_LOCK(inp);
4621f8829a4aSRandall Stewart 	}
4622f8829a4aSRandall Stewart 	if (control == NULL) {
4623f8829a4aSRandall Stewart get_out:
4624f8829a4aSRandall Stewart 		if (inp) {
4625f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
4626f8829a4aSRandall Stewart 		}
4627f8829a4aSRandall Stewart 		return (-1);
4628f8829a4aSRandall Stewart 	}
4629cd1386abSMichael Tuexen 	if (inp && (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_CANT_READ)) {
4630cd1386abSMichael Tuexen 		SCTP_INP_READ_UNLOCK(inp);
463160990c0cSMichael Tuexen 		return (0);
4632cd1386abSMichael Tuexen 	}
4633139bc87fSRandall Stewart 	if (control->end_added) {
4634f8829a4aSRandall Stewart 		/* huh this one is complete? */
4635f8829a4aSRandall Stewart 		goto get_out;
4636f8829a4aSRandall Stewart 	}
4637f8829a4aSRandall Stewart 	mm = m;
4638f8829a4aSRandall Stewart 	if (mm == NULL) {
4639f8829a4aSRandall Stewart 		goto get_out;
4640f8829a4aSRandall Stewart 	}
4641f8829a4aSRandall Stewart 	while (mm) {
4642139bc87fSRandall Stewart 		if (SCTP_BUF_LEN(mm) == 0) {
4643f8829a4aSRandall Stewart 			/* Skip mbufs with NO lenght */
4644f8829a4aSRandall Stewart 			if (prev == NULL) {
4645f8829a4aSRandall Stewart 				/* First one */
4646f8829a4aSRandall Stewart 				m = sctp_m_free(mm);
4647f8829a4aSRandall Stewart 				mm = m;
4648f8829a4aSRandall Stewart 			} else {
4649139bc87fSRandall Stewart 				SCTP_BUF_NEXT(prev) = sctp_m_free(mm);
4650139bc87fSRandall Stewart 				mm = SCTP_BUF_NEXT(prev);
4651f8829a4aSRandall Stewart 			}
4652f8829a4aSRandall Stewart 			continue;
4653f8829a4aSRandall Stewart 		}
4654f8829a4aSRandall Stewart 		prev = mm;
4655139bc87fSRandall Stewart 		len += SCTP_BUF_LEN(mm);
4656f8829a4aSRandall Stewart 		if (sb) {
4657b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4658139bc87fSRandall Stewart 				sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(mm));
465980fefe0aSRandall Stewart 			}
4660f8829a4aSRandall Stewart 			sctp_sballoc(stcb, sb, mm);
4661b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4662f8829a4aSRandall Stewart 				sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
466380fefe0aSRandall Stewart 			}
4664f8829a4aSRandall Stewart 		}
4665139bc87fSRandall Stewart 		mm = SCTP_BUF_NEXT(mm);
4666f8829a4aSRandall Stewart 	}
4667f8829a4aSRandall Stewart 	if (prev) {
4668f8829a4aSRandall Stewart 		tail = prev;
4669f8829a4aSRandall Stewart 	} else {
4670f8829a4aSRandall Stewart 		/* Really there should always be a prev */
4671f8829a4aSRandall Stewart 		if (m == NULL) {
4672f8829a4aSRandall Stewart 			/* Huh nothing left? */
4673a5d547adSRandall Stewart #ifdef INVARIANTS
4674f8829a4aSRandall Stewart 			panic("Nothing left to add?");
4675f8829a4aSRandall Stewart #else
4676f8829a4aSRandall Stewart 			goto get_out;
4677f8829a4aSRandall Stewart #endif
4678f8829a4aSRandall Stewart 		}
4679f8829a4aSRandall Stewart 		tail = m;
4680f8829a4aSRandall Stewart 	}
4681f8829a4aSRandall Stewart 	if (control->tail_mbuf) {
4682f8829a4aSRandall Stewart 		/* append */
4683139bc87fSRandall Stewart 		SCTP_BUF_NEXT(control->tail_mbuf) = m;
4684f8829a4aSRandall Stewart 		control->tail_mbuf = tail;
4685f8829a4aSRandall Stewart 	} else {
4686f8829a4aSRandall Stewart 		/* nothing there */
4687a5d547adSRandall Stewart #ifdef INVARIANTS
4688f8829a4aSRandall Stewart 		if (control->data != NULL) {
4689f8829a4aSRandall Stewart 			panic("This should NOT happen");
4690f8829a4aSRandall Stewart 		}
4691f8829a4aSRandall Stewart #endif
4692f8829a4aSRandall Stewart 		control->data = m;
4693f8829a4aSRandall Stewart 		control->tail_mbuf = tail;
4694f8829a4aSRandall Stewart 	}
469518e198d3SRandall Stewart 	atomic_add_int(&control->length, len);
469618e198d3SRandall Stewart 	if (end) {
469718e198d3SRandall Stewart 		/* message is complete */
469818e198d3SRandall Stewart 		if (stcb && (control == stcb->asoc.control_pdapi)) {
469918e198d3SRandall Stewart 			stcb->asoc.control_pdapi = NULL;
470018e198d3SRandall Stewart 		}
470118e198d3SRandall Stewart 		control->held_length = 0;
470218e198d3SRandall Stewart 		control->end_added = 1;
470318e198d3SRandall Stewart 	}
4704ad81507eSRandall Stewart 	if (stcb == NULL) {
4705ad81507eSRandall Stewart 		control->do_not_ref_stcb = 1;
4706ad81507eSRandall Stewart 	}
4707f8829a4aSRandall Stewart 	/*
4708f8829a4aSRandall Stewart 	 * When we are appending in partial delivery, the cum-ack is used
4709f8829a4aSRandall Stewart 	 * for the actual pd-api highest tsn on this mbuf. The true cum-ack
4710f8829a4aSRandall Stewart 	 * is populated in the outbound sinfo structure from the true cumack
4711f8829a4aSRandall Stewart 	 * if the association exists...
4712f8829a4aSRandall Stewart 	 */
4713f8829a4aSRandall Stewart 	control->sinfo_tsn = control->sinfo_cumtsn = ctls_cumack;
4714f8829a4aSRandall Stewart 	if (inp) {
4715f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
4716f8829a4aSRandall Stewart 	}
4717f8829a4aSRandall Stewart 	if (inp && inp->sctp_socket) {
471817205eccSRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_ZERO_COPY_ACTIVE)) {
471917205eccSRandall Stewart 			SCTP_ZERO_COPY_EVENT(inp, inp->sctp_socket);
4720ceaad40aSRandall Stewart 		} else {
4721ceaad40aSRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4722ceaad40aSRandall Stewart 			struct socket *so;
4723ceaad40aSRandall Stewart 
4724ceaad40aSRandall Stewart 			so = SCTP_INP_SO(inp);
472560990c0cSMichael Tuexen 			if (stcb) {
4726ceaad40aSRandall Stewart 				atomic_add_int(&stcb->asoc.refcnt, 1);
4727ceaad40aSRandall Stewart 				SCTP_TCB_UNLOCK(stcb);
472860990c0cSMichael Tuexen 			}
4729ceaad40aSRandall Stewart 			SCTP_SOCKET_LOCK(so, 1);
473060990c0cSMichael Tuexen 			if (stcb) {
4731ceaad40aSRandall Stewart 				SCTP_TCB_LOCK(stcb);
4732ceaad40aSRandall Stewart 				atomic_subtract_int(&stcb->asoc.refcnt, 1);
473360990c0cSMichael Tuexen 			}
4734ceaad40aSRandall Stewart 			if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
4735ceaad40aSRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
4736ceaad40aSRandall Stewart 				return (0);
4737ceaad40aSRandall Stewart 			}
4738ceaad40aSRandall Stewart #endif
4739f8829a4aSRandall Stewart 			sctp_sorwakeup(inp, inp->sctp_socket);
4740ceaad40aSRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4741ceaad40aSRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
4742ceaad40aSRandall Stewart #endif
4743ceaad40aSRandall Stewart 		}
4744f8829a4aSRandall Stewart 	}
4745f8829a4aSRandall Stewart 	return (0);
4746f8829a4aSRandall Stewart }
4747f8829a4aSRandall Stewart 
4748f8829a4aSRandall Stewart 
4749f8829a4aSRandall Stewart 
4750f8829a4aSRandall Stewart /*************HOLD THIS COMMENT FOR PATCH FILE OF
4751f8829a4aSRandall Stewart  *************ALTERNATE ROUTING CODE
4752f8829a4aSRandall Stewart  */
4753f8829a4aSRandall Stewart 
4754f8829a4aSRandall Stewart /*************HOLD THIS COMMENT FOR END OF PATCH FILE OF
4755f8829a4aSRandall Stewart  *************ALTERNATE ROUTING CODE
4756f8829a4aSRandall Stewart  */
4757f8829a4aSRandall Stewart 
4758f8829a4aSRandall Stewart struct mbuf *
4759ff1ffd74SMichael Tuexen sctp_generate_cause(uint16_t code, char *info)
4760f8829a4aSRandall Stewart {
4761f8829a4aSRandall Stewart 	struct mbuf *m;
4762ff1ffd74SMichael Tuexen 	struct sctp_gen_error_cause *cause;
47639a8e3088SMichael Tuexen 	size_t info_len;
47649a8e3088SMichael Tuexen 	uint16_t len;
4765f8829a4aSRandall Stewart 
4766ff1ffd74SMichael Tuexen 	if ((code == 0) || (info == NULL)) {
4767ff1ffd74SMichael Tuexen 		return (NULL);
4768ff1ffd74SMichael Tuexen 	}
4769ff1ffd74SMichael Tuexen 	info_len = strlen(info);
47709a8e3088SMichael Tuexen 	if (info_len > (SCTP_MAX_CAUSE_LENGTH - sizeof(struct sctp_paramhdr))) {
47719a8e3088SMichael Tuexen 		return (NULL);
47729a8e3088SMichael Tuexen 	}
47739a8e3088SMichael Tuexen 	len = (uint16_t) (sizeof(struct sctp_paramhdr) + info_len);
4774ff1ffd74SMichael Tuexen 	m = sctp_get_mbuf_for_msg(len, 0, M_NOWAIT, 1, MT_DATA);
4775ff1ffd74SMichael Tuexen 	if (m != NULL) {
4776ff1ffd74SMichael Tuexen 		SCTP_BUF_LEN(m) = len;
4777ff1ffd74SMichael Tuexen 		cause = mtod(m, struct sctp_gen_error_cause *);
4778ff1ffd74SMichael Tuexen 		cause->code = htons(code);
47799a8e3088SMichael Tuexen 		cause->length = htons(len);
4780ff1ffd74SMichael Tuexen 		memcpy(cause->info, info, info_len);
4781f8829a4aSRandall Stewart 	}
4782f8829a4aSRandall Stewart 	return (m);
4783f8829a4aSRandall Stewart }
4784f8829a4aSRandall Stewart 
478532451da4SMichael Tuexen struct mbuf *
478632451da4SMichael Tuexen sctp_generate_no_user_data_cause(uint32_t tsn)
478732451da4SMichael Tuexen {
478832451da4SMichael Tuexen 	struct mbuf *m;
478932451da4SMichael Tuexen 	struct sctp_error_no_user_data *no_user_data_cause;
47909a8e3088SMichael Tuexen 	uint16_t len;
479132451da4SMichael Tuexen 
47929a8e3088SMichael Tuexen 	len = (uint16_t) sizeof(struct sctp_error_no_user_data);
479332451da4SMichael Tuexen 	m = sctp_get_mbuf_for_msg(len, 0, M_NOWAIT, 1, MT_DATA);
479432451da4SMichael Tuexen 	if (m != NULL) {
479532451da4SMichael Tuexen 		SCTP_BUF_LEN(m) = len;
479632451da4SMichael Tuexen 		no_user_data_cause = mtod(m, struct sctp_error_no_user_data *);
479732451da4SMichael Tuexen 		no_user_data_cause->cause.code = htons(SCTP_CAUSE_NO_USER_DATA);
47989a8e3088SMichael Tuexen 		no_user_data_cause->cause.length = htons(len);
479932451da4SMichael Tuexen 		no_user_data_cause->tsn = tsn;	/* tsn is passed in as NBO */
480032451da4SMichael Tuexen 	}
480132451da4SMichael Tuexen 	return (m);
480232451da4SMichael Tuexen }
480332451da4SMichael Tuexen 
4804f8829a4aSRandall Stewart #ifdef SCTP_MBCNT_LOGGING
4805f8829a4aSRandall Stewart void
4806f8829a4aSRandall Stewart sctp_free_bufspace(struct sctp_tcb *stcb, struct sctp_association *asoc,
4807f8829a4aSRandall Stewart     struct sctp_tmit_chunk *tp1, int chk_cnt)
4808f8829a4aSRandall Stewart {
4809f8829a4aSRandall Stewart 	if (tp1->data == NULL) {
4810f8829a4aSRandall Stewart 		return;
4811f8829a4aSRandall Stewart 	}
4812f8829a4aSRandall Stewart 	asoc->chunks_on_out_queue -= chk_cnt;
4813b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_MBCNT_LOGGING_ENABLE) {
4814f8829a4aSRandall Stewart 		sctp_log_mbcnt(SCTP_LOG_MBCNT_DECREASE,
4815f8829a4aSRandall Stewart 		    asoc->total_output_queue_size,
4816f8829a4aSRandall Stewart 		    tp1->book_size,
4817f8829a4aSRandall Stewart 		    0,
4818f8829a4aSRandall Stewart 		    tp1->mbcnt);
481980fefe0aSRandall Stewart 	}
4820f8829a4aSRandall Stewart 	if (asoc->total_output_queue_size >= tp1->book_size) {
482144b7479bSRandall Stewart 		atomic_add_int(&asoc->total_output_queue_size, -tp1->book_size);
4822f8829a4aSRandall Stewart 	} else {
4823f8829a4aSRandall Stewart 		asoc->total_output_queue_size = 0;
4824f8829a4aSRandall Stewart 	}
4825f8829a4aSRandall Stewart 
4826f8829a4aSRandall Stewart 	if (stcb->sctp_socket && (((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) ||
4827f8829a4aSRandall Stewart 	    ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE)))) {
48284e88d37aSMichael Tuexen 		if (stcb->sctp_socket->so_snd.sb_cc >= tp1->book_size) {
48294e88d37aSMichael Tuexen 			stcb->sctp_socket->so_snd.sb_cc -= tp1->book_size;
4830f8829a4aSRandall Stewart 		} else {
48314e88d37aSMichael Tuexen 			stcb->sctp_socket->so_snd.sb_cc = 0;
4832f8829a4aSRandall Stewart 
4833f8829a4aSRandall Stewart 		}
4834f8829a4aSRandall Stewart 	}
4835f8829a4aSRandall Stewart }
4836f8829a4aSRandall Stewart 
4837f8829a4aSRandall Stewart #endif
4838f8829a4aSRandall Stewart 
4839f8829a4aSRandall Stewart int
4840f8829a4aSRandall Stewart sctp_release_pr_sctp_chunk(struct sctp_tcb *stcb, struct sctp_tmit_chunk *tp1,
48411edc9dbaSMichael Tuexen     uint8_t sent, int so_locked
4842ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
4843ceaad40aSRandall Stewart     SCTP_UNUSED
4844ceaad40aSRandall Stewart #endif
4845ceaad40aSRandall Stewart )
4846f8829a4aSRandall Stewart {
48470c0982b8SRandall Stewart 	struct sctp_stream_out *strq;
48484a9ef3f8SMichael Tuexen 	struct sctp_tmit_chunk *chk = NULL, *tp2;
48490c0982b8SRandall Stewart 	struct sctp_stream_queue_pending *sp;
48500c0982b8SRandall Stewart 	uint16_t stream = 0, seq = 0;
48510c0982b8SRandall Stewart 	uint8_t foundeom = 0;
4852f8829a4aSRandall Stewart 	int ret_sz = 0;
4853f8829a4aSRandall Stewart 	int notdone;
48540c0982b8SRandall Stewart 	int do_wakeup_routine = 0;
4855f8829a4aSRandall Stewart 
48560c0982b8SRandall Stewart 	stream = tp1->rec.data.stream_number;
48570c0982b8SRandall Stewart 	seq = tp1->rec.data.stream_seq;
4858f0396ad1SMichael Tuexen 	if (sent || !(tp1->rec.data.rcv_flags & SCTP_DATA_FIRST_FRAG)) {
4859f0396ad1SMichael Tuexen 		stcb->asoc.abandoned_sent[0]++;
4860f0396ad1SMichael Tuexen 		stcb->asoc.abandoned_sent[PR_SCTP_POLICY(tp1->flags)]++;
4861f0396ad1SMichael Tuexen 		stcb->asoc.strmout[stream].abandoned_sent[0]++;
4862f0396ad1SMichael Tuexen #if defined(SCTP_DETAILED_STR_STATS)
4863f0396ad1SMichael Tuexen 		stcb->asoc.strmout[stream].abandoned_sent[PR_SCTP_POLICY(tp1->flags)]++;
4864f0396ad1SMichael Tuexen #endif
4865f0396ad1SMichael Tuexen 	} else {
4866f0396ad1SMichael Tuexen 		stcb->asoc.abandoned_unsent[0]++;
4867f0396ad1SMichael Tuexen 		stcb->asoc.abandoned_unsent[PR_SCTP_POLICY(tp1->flags)]++;
4868f0396ad1SMichael Tuexen 		stcb->asoc.strmout[stream].abandoned_unsent[0]++;
4869f0396ad1SMichael Tuexen #if defined(SCTP_DETAILED_STR_STATS)
4870f0396ad1SMichael Tuexen 		stcb->asoc.strmout[stream].abandoned_unsent[PR_SCTP_POLICY(tp1->flags)]++;
4871f0396ad1SMichael Tuexen #endif
4872f0396ad1SMichael Tuexen 	}
4873f8829a4aSRandall Stewart 	do {
4874f8829a4aSRandall Stewart 		ret_sz += tp1->book_size;
48750c0982b8SRandall Stewart 		if (tp1->data != NULL) {
48768933fa13SRandall Stewart 			if (tp1->sent < SCTP_DATAGRAM_RESEND) {
4877830d754dSRandall Stewart 				sctp_flight_size_decrease(tp1);
4878830d754dSRandall Stewart 				sctp_total_flight_decrease(stcb, tp1);
48798933fa13SRandall Stewart 			}
48808933fa13SRandall Stewart 			sctp_free_bufspace(stcb, &stcb->asoc, tp1, 1);
48810c0982b8SRandall Stewart 			stcb->asoc.peers_rwnd += tp1->send_size;
48820c0982b8SRandall Stewart 			stcb->asoc.peers_rwnd += SCTP_BASE_SYSCTL(sctp_peer_chunk_oh);
48831edc9dbaSMichael Tuexen 			if (sent) {
48841edc9dbaSMichael Tuexen 				sctp_ulp_notify(SCTP_NOTIFY_SENT_DG_FAIL, stcb, 0, tp1, so_locked);
48851edc9dbaSMichael Tuexen 			} else {
48861edc9dbaSMichael Tuexen 				sctp_ulp_notify(SCTP_NOTIFY_UNSENT_DG_FAIL, stcb, 0, tp1, so_locked);
48871edc9dbaSMichael Tuexen 			}
48882f99457bSMichael Tuexen 			if (tp1->data) {
4889f8829a4aSRandall Stewart 				sctp_m_freem(tp1->data);
4890f8829a4aSRandall Stewart 				tp1->data = NULL;
48912f99457bSMichael Tuexen 			}
48920c0982b8SRandall Stewart 			do_wakeup_routine = 1;
4893f8829a4aSRandall Stewart 			if (PR_SCTP_BUF_ENABLED(tp1->flags)) {
4894f8829a4aSRandall Stewart 				stcb->asoc.sent_queue_cnt_removeable--;
4895f8829a4aSRandall Stewart 			}
4896f8829a4aSRandall Stewart 		}
48978933fa13SRandall Stewart 		tp1->sent = SCTP_FORWARD_TSN_SKIP;
4898f8829a4aSRandall Stewart 		if ((tp1->rec.data.rcv_flags & SCTP_DATA_NOT_FRAG) ==
4899f8829a4aSRandall Stewart 		    SCTP_DATA_NOT_FRAG) {
4900f8829a4aSRandall Stewart 			/* not frag'ed we ae done   */
4901f8829a4aSRandall Stewart 			notdone = 0;
4902f8829a4aSRandall Stewart 			foundeom = 1;
4903f8829a4aSRandall Stewart 		} else if (tp1->rec.data.rcv_flags & SCTP_DATA_LAST_FRAG) {
4904f8829a4aSRandall Stewart 			/* end of frag, we are done */
4905f8829a4aSRandall Stewart 			notdone = 0;
4906f8829a4aSRandall Stewart 			foundeom = 1;
4907f8829a4aSRandall Stewart 		} else {
4908f8829a4aSRandall Stewart 			/*
4909f8829a4aSRandall Stewart 			 * Its a begin or middle piece, we must mark all of
4910f8829a4aSRandall Stewart 			 * it
4911f8829a4aSRandall Stewart 			 */
4912f8829a4aSRandall Stewart 			notdone = 1;
4913f8829a4aSRandall Stewart 			tp1 = TAILQ_NEXT(tp1, sctp_next);
4914f8829a4aSRandall Stewart 		}
4915f8829a4aSRandall Stewart 	} while (tp1 && notdone);
49160c0982b8SRandall Stewart 	if (foundeom == 0) {
4917f8829a4aSRandall Stewart 		/*
4918f8829a4aSRandall Stewart 		 * The multi-part message was scattered across the send and
4919f8829a4aSRandall Stewart 		 * sent queue.
4920f8829a4aSRandall Stewart 		 */
49214a9ef3f8SMichael Tuexen 		TAILQ_FOREACH_SAFE(tp1, &stcb->asoc.send_queue, sctp_next, tp2) {
49224a9ef3f8SMichael Tuexen 			if ((tp1->rec.data.stream_number != stream) ||
49234a9ef3f8SMichael Tuexen 			    (tp1->rec.data.stream_seq != seq)) {
49244a9ef3f8SMichael Tuexen 				break;
49254a9ef3f8SMichael Tuexen 			}
49260c0982b8SRandall Stewart 			/*
49270c0982b8SRandall Stewart 			 * save to chk in case we have some on stream out
49280c0982b8SRandall Stewart 			 * queue. If so and we have an un-transmitted one we
49290c0982b8SRandall Stewart 			 * don't have to fudge the TSN.
49300c0982b8SRandall Stewart 			 */
49310c0982b8SRandall Stewart 			chk = tp1;
49320c0982b8SRandall Stewart 			ret_sz += tp1->book_size;
49330c0982b8SRandall Stewart 			sctp_free_bufspace(stcb, &stcb->asoc, tp1, 1);
49341edc9dbaSMichael Tuexen 			if (sent) {
49351edc9dbaSMichael Tuexen 				sctp_ulp_notify(SCTP_NOTIFY_SENT_DG_FAIL, stcb, 0, tp1, so_locked);
49361edc9dbaSMichael Tuexen 			} else {
49371edc9dbaSMichael Tuexen 				sctp_ulp_notify(SCTP_NOTIFY_UNSENT_DG_FAIL, stcb, 0, tp1, so_locked);
49381edc9dbaSMichael Tuexen 			}
49392f99457bSMichael Tuexen 			if (tp1->data) {
49400c0982b8SRandall Stewart 				sctp_m_freem(tp1->data);
49412f99457bSMichael Tuexen 				tp1->data = NULL;
49422f99457bSMichael Tuexen 			}
49438933fa13SRandall Stewart 			/* No flight involved here book the size to 0 */
49448933fa13SRandall Stewart 			tp1->book_size = 0;
49450c0982b8SRandall Stewart 			if (tp1->rec.data.rcv_flags & SCTP_DATA_LAST_FRAG) {
49460c0982b8SRandall Stewart 				foundeom = 1;
4947f8829a4aSRandall Stewart 			}
49480c0982b8SRandall Stewart 			do_wakeup_routine = 1;
49490c0982b8SRandall Stewart 			tp1->sent = SCTP_FORWARD_TSN_SKIP;
49500c0982b8SRandall Stewart 			TAILQ_REMOVE(&stcb->asoc.send_queue, tp1, sctp_next);
49510c0982b8SRandall Stewart 			/*
49520c0982b8SRandall Stewart 			 * on to the sent queue so we can wait for it to be
49530c0982b8SRandall Stewart 			 * passed by.
49540c0982b8SRandall Stewart 			 */
49550c0982b8SRandall Stewart 			TAILQ_INSERT_TAIL(&stcb->asoc.sent_queue, tp1,
49560c0982b8SRandall Stewart 			    sctp_next);
49570c0982b8SRandall Stewart 			stcb->asoc.send_queue_cnt--;
49580c0982b8SRandall Stewart 			stcb->asoc.sent_queue_cnt++;
49590c0982b8SRandall Stewart 		}
49600c0982b8SRandall Stewart 	}
49610c0982b8SRandall Stewart 	if (foundeom == 0) {
49620c0982b8SRandall Stewart 		/*
49630c0982b8SRandall Stewart 		 * Still no eom found. That means there is stuff left on the
49640c0982b8SRandall Stewart 		 * stream out queue.. yuck.
49650c0982b8SRandall Stewart 		 */
49660c0982b8SRandall Stewart 		SCTP_TCB_SEND_LOCK(stcb);
4967f3b05218SMichael Tuexen 		strq = &stcb->asoc.strmout[stream];
4968f3b05218SMichael Tuexen 		sp = TAILQ_FIRST(&strq->outqueue);
4969f3b05218SMichael Tuexen 		if (sp != NULL) {
49700c0982b8SRandall Stewart 			sp->discard_rest = 1;
49710c0982b8SRandall Stewart 			/*
4972f3b05218SMichael Tuexen 			 * We may need to put a chunk on the queue that
4973f3b05218SMichael Tuexen 			 * holds the TSN that would have been sent with the
4974f3b05218SMichael Tuexen 			 * LAST bit.
49750c0982b8SRandall Stewart 			 */
49760c0982b8SRandall Stewart 			if (chk == NULL) {
49770c0982b8SRandall Stewart 				/* Yep, we have to */
49780c0982b8SRandall Stewart 				sctp_alloc_a_chunk(stcb, chk);
49790c0982b8SRandall Stewart 				if (chk == NULL) {
49800c0982b8SRandall Stewart 					/*
4981f3b05218SMichael Tuexen 					 * we are hosed. All we can do is
4982f3b05218SMichael Tuexen 					 * nothing.. which will cause an
4983f3b05218SMichael Tuexen 					 * abort if the peer is paying
49840c0982b8SRandall Stewart 					 * attention.
49850c0982b8SRandall Stewart 					 */
49860c0982b8SRandall Stewart 					goto oh_well;
49870c0982b8SRandall Stewart 				}
49880c0982b8SRandall Stewart 				memset(chk, 0, sizeof(*chk));
49890c0982b8SRandall Stewart 				chk->rec.data.rcv_flags = SCTP_DATA_LAST_FRAG;
49900c0982b8SRandall Stewart 				chk->sent = SCTP_FORWARD_TSN_SKIP;
49910c0982b8SRandall Stewart 				chk->asoc = &stcb->asoc;
4992f3b05218SMichael Tuexen 				chk->rec.data.stream_seq = strq->next_sequence_send;
49930c0982b8SRandall Stewart 				chk->rec.data.stream_number = sp->stream;
49940c0982b8SRandall Stewart 				chk->rec.data.payloadtype = sp->ppid;
49950c0982b8SRandall Stewart 				chk->rec.data.context = sp->context;
49960c0982b8SRandall Stewart 				chk->flags = sp->act_flags;
49977fd5b436SMichael Tuexen 				chk->whoTo = NULL;
49980c0982b8SRandall Stewart 				chk->rec.data.TSN_seq = atomic_fetchadd_int(&stcb->asoc.sending_seq, 1);
49997fd5b436SMichael Tuexen 				strq->chunks_on_queues++;
50000c0982b8SRandall Stewart 				TAILQ_INSERT_TAIL(&stcb->asoc.sent_queue, chk, sctp_next);
50010c0982b8SRandall Stewart 				stcb->asoc.sent_queue_cnt++;
50028933fa13SRandall Stewart 				stcb->asoc.pr_sctp_cnt++;
50030c0982b8SRandall Stewart 			} else {
50040c0982b8SRandall Stewart 				chk->rec.data.rcv_flags |= SCTP_DATA_LAST_FRAG;
50050c0982b8SRandall Stewart 			}
5006f3b05218SMichael Tuexen 			strq->next_sequence_send++;
50070c0982b8SRandall Stewart 	oh_well:
50080c0982b8SRandall Stewart 			if (sp->data) {
50090c0982b8SRandall Stewart 				/*
5010f3b05218SMichael Tuexen 				 * Pull any data to free up the SB and allow
5011f3b05218SMichael Tuexen 				 * sender to "add more" while we will throw
5012f3b05218SMichael Tuexen 				 * away :-)
50130c0982b8SRandall Stewart 				 */
5014f3b05218SMichael Tuexen 				sctp_free_spbufspace(stcb, &stcb->asoc, sp);
50150c0982b8SRandall Stewart 				ret_sz += sp->length;
50160c0982b8SRandall Stewart 				do_wakeup_routine = 1;
50170c0982b8SRandall Stewart 				sp->some_taken = 1;
50180c0982b8SRandall Stewart 				sctp_m_freem(sp->data);
50190c0982b8SRandall Stewart 				sp->data = NULL;
50200c0982b8SRandall Stewart 				sp->tail_mbuf = NULL;
5021d07b2ac6SMichael Tuexen 				sp->length = 0;
50220c0982b8SRandall Stewart 			}
50230c0982b8SRandall Stewart 		}
50240c0982b8SRandall Stewart 		SCTP_TCB_SEND_UNLOCK(stcb);
50250c0982b8SRandall Stewart 	}
50260c0982b8SRandall Stewart 	if (do_wakeup_routine) {
50270c0982b8SRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
50288933fa13SRandall Stewart 		struct socket *so;
50298933fa13SRandall Stewart 
50300c0982b8SRandall Stewart 		so = SCTP_INP_SO(stcb->sctp_ep);
50310c0982b8SRandall Stewart 		if (!so_locked) {
50320c0982b8SRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, 1);
50330c0982b8SRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
50340c0982b8SRandall Stewart 			SCTP_SOCKET_LOCK(so, 1);
50350c0982b8SRandall Stewart 			SCTP_TCB_LOCK(stcb);
50360c0982b8SRandall Stewart 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
50370c0982b8SRandall Stewart 			if (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET) {
50380c0982b8SRandall Stewart 				/* assoc was freed while we were unlocked */
50390c0982b8SRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
50400c0982b8SRandall Stewart 				return (ret_sz);
50410c0982b8SRandall Stewart 			}
50420c0982b8SRandall Stewart 		}
50430c0982b8SRandall Stewart #endif
50440c0982b8SRandall Stewart 		sctp_sowwakeup(stcb->sctp_ep, stcb->sctp_socket);
50450c0982b8SRandall Stewart #if defined(__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
50460c0982b8SRandall Stewart 		if (!so_locked) {
50470c0982b8SRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
50480c0982b8SRandall Stewart 		}
50490c0982b8SRandall Stewart #endif
5050f8829a4aSRandall Stewart 	}
5051f8829a4aSRandall Stewart 	return (ret_sz);
5052f8829a4aSRandall Stewart }
5053f8829a4aSRandall Stewart 
5054f8829a4aSRandall Stewart /*
5055f8829a4aSRandall Stewart  * checks to see if the given address, sa, is one that is currently known by
5056f8829a4aSRandall Stewart  * the kernel note: can't distinguish the same address on multiple interfaces
5057f8829a4aSRandall Stewart  * and doesn't handle multiple addresses with different zone/scope id's note:
5058f8829a4aSRandall Stewart  * ifa_ifwithaddr() compares the entire sockaddr struct
5059f8829a4aSRandall Stewart  */
506042551e99SRandall Stewart struct sctp_ifa *
506180fefe0aSRandall Stewart sctp_find_ifa_in_ep(struct sctp_inpcb *inp, struct sockaddr *addr,
506280fefe0aSRandall Stewart     int holds_lock)
5063f8829a4aSRandall Stewart {
506442551e99SRandall Stewart 	struct sctp_laddr *laddr;
5065f8829a4aSRandall Stewart 
5066ad81507eSRandall Stewart 	if (holds_lock == 0) {
506742551e99SRandall Stewart 		SCTP_INP_RLOCK(inp);
5068ad81507eSRandall Stewart 	}
506942551e99SRandall Stewart 	LIST_FOREACH(laddr, &inp->sctp_addr_list, sctp_nxt_addr) {
507042551e99SRandall Stewart 		if (laddr->ifa == NULL)
5071f8829a4aSRandall Stewart 			continue;
507242551e99SRandall Stewart 		if (addr->sa_family != laddr->ifa->address.sa.sa_family)
507342551e99SRandall Stewart 			continue;
5074e6194c2eSMichael Tuexen #ifdef INET
507542551e99SRandall Stewart 		if (addr->sa_family == AF_INET) {
507642551e99SRandall Stewart 			if (((struct sockaddr_in *)addr)->sin_addr.s_addr ==
507742551e99SRandall Stewart 			    laddr->ifa->address.sin.sin_addr.s_addr) {
507842551e99SRandall Stewart 				/* found him. */
5079ad81507eSRandall Stewart 				if (holds_lock == 0) {
508042551e99SRandall Stewart 					SCTP_INP_RUNLOCK(inp);
5081ad81507eSRandall Stewart 				}
508242551e99SRandall Stewart 				return (laddr->ifa);
508342551e99SRandall Stewart 				break;
508442551e99SRandall Stewart 			}
50855e2c2d87SRandall Stewart 		}
5086e6194c2eSMichael Tuexen #endif
50875e2c2d87SRandall Stewart #ifdef INET6
50885e2c2d87SRandall Stewart 		if (addr->sa_family == AF_INET6) {
5089c54a18d2SRandall Stewart 			if (SCTP6_ARE_ADDR_EQUAL((struct sockaddr_in6 *)addr,
5090c54a18d2SRandall Stewart 			    &laddr->ifa->address.sin6)) {
509142551e99SRandall Stewart 				/* found him. */
5092ad81507eSRandall Stewart 				if (holds_lock == 0) {
509342551e99SRandall Stewart 					SCTP_INP_RUNLOCK(inp);
5094ad81507eSRandall Stewart 				}
509542551e99SRandall Stewart 				return (laddr->ifa);
509642551e99SRandall Stewart 				break;
509742551e99SRandall Stewart 			}
509842551e99SRandall Stewart 		}
50995e2c2d87SRandall Stewart #endif
510042551e99SRandall Stewart 	}
5101ad81507eSRandall Stewart 	if (holds_lock == 0) {
510242551e99SRandall Stewart 		SCTP_INP_RUNLOCK(inp);
5103ad81507eSRandall Stewart 	}
510442551e99SRandall Stewart 	return (NULL);
510542551e99SRandall Stewart }
5106f8829a4aSRandall Stewart 
51076a27c376SRandall Stewart uint32_t
51086a27c376SRandall Stewart sctp_get_ifa_hash_val(struct sockaddr *addr)
51096a27c376SRandall Stewart {
5110ea5eba11SMichael Tuexen 	switch (addr->sa_family) {
5111ea5eba11SMichael Tuexen #ifdef INET
5112ea5eba11SMichael Tuexen 	case AF_INET:
5113ea5eba11SMichael Tuexen 		{
51146a27c376SRandall Stewart 			struct sockaddr_in *sin;
51156a27c376SRandall Stewart 
51166a27c376SRandall Stewart 			sin = (struct sockaddr_in *)addr;
51176a27c376SRandall Stewart 			return (sin->sin_addr.s_addr ^ (sin->sin_addr.s_addr >> 16));
5118ea5eba11SMichael Tuexen 		}
5119ea5eba11SMichael Tuexen #endif
5120ea5eba11SMichael Tuexen #ifdef INET6
51212c2e3218SMichael Tuexen 	case AF_INET6:
5122ea5eba11SMichael Tuexen 		{
51236a27c376SRandall Stewart 			struct sockaddr_in6 *sin6;
51246a27c376SRandall Stewart 			uint32_t hash_of_addr;
51256a27c376SRandall Stewart 
51266a27c376SRandall Stewart 			sin6 = (struct sockaddr_in6 *)addr;
51276a27c376SRandall Stewart 			hash_of_addr = (sin6->sin6_addr.s6_addr32[0] +
51286a27c376SRandall Stewart 			    sin6->sin6_addr.s6_addr32[1] +
51296a27c376SRandall Stewart 			    sin6->sin6_addr.s6_addr32[2] +
51306a27c376SRandall Stewart 			    sin6->sin6_addr.s6_addr32[3]);
51316a27c376SRandall Stewart 			hash_of_addr = (hash_of_addr ^ (hash_of_addr >> 16));
51326a27c376SRandall Stewart 			return (hash_of_addr);
51336a27c376SRandall Stewart 		}
5134ea5eba11SMichael Tuexen #endif
5135ea5eba11SMichael Tuexen 	default:
5136ea5eba11SMichael Tuexen 		break;
5137ea5eba11SMichael Tuexen 	}
51386a27c376SRandall Stewart 	return (0);
51396a27c376SRandall Stewart }
51406a27c376SRandall Stewart 
514142551e99SRandall Stewart struct sctp_ifa *
514242551e99SRandall Stewart sctp_find_ifa_by_addr(struct sockaddr *addr, uint32_t vrf_id, int holds_lock)
514342551e99SRandall Stewart {
514442551e99SRandall Stewart 	struct sctp_ifa *sctp_ifap;
514542551e99SRandall Stewart 	struct sctp_vrf *vrf;
51466a27c376SRandall Stewart 	struct sctp_ifalist *hash_head;
51476a27c376SRandall Stewart 	uint32_t hash_of_addr;
514842551e99SRandall Stewart 
514942551e99SRandall Stewart 	if (holds_lock == 0)
5150c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RLOCK();
515142551e99SRandall Stewart 
5152bff64a4dSRandall Stewart 	vrf = sctp_find_vrf(vrf_id);
5153bff64a4dSRandall Stewart 	if (vrf == NULL) {
5154bff64a4dSRandall Stewart 		if (holds_lock == 0)
5155c99efcf6SRandall Stewart 			SCTP_IPI_ADDR_RUNLOCK();
5156bff64a4dSRandall Stewart 		return (NULL);
5157bff64a4dSRandall Stewart 	}
5158bff64a4dSRandall Stewart 	hash_of_addr = sctp_get_ifa_hash_val(addr);
5159bff64a4dSRandall Stewart 
516017205eccSRandall Stewart 	hash_head = &vrf->vrf_addr_hash[(hash_of_addr & vrf->vrf_addr_hashmark)];
5161bff64a4dSRandall Stewart 	if (hash_head == NULL) {
5162ad81507eSRandall Stewart 		SCTP_PRINTF("hash_of_addr:%x mask:%x table:%x - ",
5163c99efcf6SRandall Stewart 		    hash_of_addr, (uint32_t) vrf->vrf_addr_hashmark,
5164c99efcf6SRandall Stewart 		    (uint32_t) (hash_of_addr & vrf->vrf_addr_hashmark));
5165bff64a4dSRandall Stewart 		sctp_print_address(addr);
5166ad81507eSRandall Stewart 		SCTP_PRINTF("No such bucket for address\n");
5167bff64a4dSRandall Stewart 		if (holds_lock == 0)
5168c99efcf6SRandall Stewart 			SCTP_IPI_ADDR_RUNLOCK();
5169bff64a4dSRandall Stewart 
5170bff64a4dSRandall Stewart 		return (NULL);
5171bff64a4dSRandall Stewart 	}
51726a27c376SRandall Stewart 	LIST_FOREACH(sctp_ifap, hash_head, next_bucket) {
51736a27c376SRandall Stewart 		if (addr->sa_family != sctp_ifap->address.sa.sa_family)
51746a27c376SRandall Stewart 			continue;
5175e6194c2eSMichael Tuexen #ifdef INET
51766a27c376SRandall Stewart 		if (addr->sa_family == AF_INET) {
51776a27c376SRandall Stewart 			if (((struct sockaddr_in *)addr)->sin_addr.s_addr ==
51786a27c376SRandall Stewart 			    sctp_ifap->address.sin.sin_addr.s_addr) {
51796a27c376SRandall Stewart 				/* found him. */
518042551e99SRandall Stewart 				if (holds_lock == 0)
5181c99efcf6SRandall Stewart 					SCTP_IPI_ADDR_RUNLOCK();
518242551e99SRandall Stewart 				return (sctp_ifap);
51836a27c376SRandall Stewart 				break;
51846a27c376SRandall Stewart 			}
51855e2c2d87SRandall Stewart 		}
5186e6194c2eSMichael Tuexen #endif
51875e2c2d87SRandall Stewart #ifdef INET6
51885e2c2d87SRandall Stewart 		if (addr->sa_family == AF_INET6) {
5189c54a18d2SRandall Stewart 			if (SCTP6_ARE_ADDR_EQUAL((struct sockaddr_in6 *)addr,
5190c54a18d2SRandall Stewart 			    &sctp_ifap->address.sin6)) {
51916a27c376SRandall Stewart 				/* found him. */
51926a27c376SRandall Stewart 				if (holds_lock == 0)
5193c99efcf6SRandall Stewart 					SCTP_IPI_ADDR_RUNLOCK();
51946a27c376SRandall Stewart 				return (sctp_ifap);
51956a27c376SRandall Stewart 				break;
51966a27c376SRandall Stewart 			}
519742551e99SRandall Stewart 		}
51985e2c2d87SRandall Stewart #endif
519942551e99SRandall Stewart 	}
520042551e99SRandall Stewart 	if (holds_lock == 0)
5201c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RUNLOCK();
5202f8829a4aSRandall Stewart 	return (NULL);
5203f8829a4aSRandall Stewart }
5204f8829a4aSRandall Stewart 
5205f8829a4aSRandall Stewart static void
52064c9179adSRandall Stewart sctp_user_rcvd(struct sctp_tcb *stcb, uint32_t * freed_so_far, int hold_rlock,
5207f8829a4aSRandall Stewart     uint32_t rwnd_req)
5208f8829a4aSRandall Stewart {
5209f8829a4aSRandall Stewart 	/* User pulled some data, do we need a rwnd update? */
5210f8829a4aSRandall Stewart 	int r_unlocked = 0;
5211f8829a4aSRandall Stewart 	uint32_t dif, rwnd;
5212f8829a4aSRandall Stewart 	struct socket *so = NULL;
5213f8829a4aSRandall Stewart 
5214f8829a4aSRandall Stewart 	if (stcb == NULL)
5215f8829a4aSRandall Stewart 		return;
5216f8829a4aSRandall Stewart 
521750cec919SRandall Stewart 	atomic_add_int(&stcb->asoc.refcnt, 1);
5218f8829a4aSRandall Stewart 
521962c1ff9cSRandall Stewart 	if (stcb->asoc.state & (SCTP_STATE_ABOUT_TO_BE_FREED |
522062c1ff9cSRandall Stewart 	    SCTP_STATE_SHUTDOWN_RECEIVED |
52214c9179adSRandall Stewart 	    SCTP_STATE_SHUTDOWN_ACK_SENT)) {
5222f8829a4aSRandall Stewart 		/* Pre-check If we are freeing no update */
5223f8829a4aSRandall Stewart 		goto no_lock;
5224f8829a4aSRandall Stewart 	}
5225f8829a4aSRandall Stewart 	SCTP_INP_INCR_REF(stcb->sctp_ep);
5226f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
5227f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE)) {
5228f8829a4aSRandall Stewart 		goto out;
5229f8829a4aSRandall Stewart 	}
5230f8829a4aSRandall Stewart 	so = stcb->sctp_socket;
5231f8829a4aSRandall Stewart 	if (so == NULL) {
5232f8829a4aSRandall Stewart 		goto out;
5233f8829a4aSRandall Stewart 	}
5234f8829a4aSRandall Stewart 	atomic_add_int(&stcb->freed_by_sorcv_sincelast, *freed_so_far);
5235f8829a4aSRandall Stewart 	/* Have you have freed enough to look */
5236f8829a4aSRandall Stewart 	*freed_so_far = 0;
5237f8829a4aSRandall Stewart 	/* Yep, its worth a look and the lock overhead */
5238f8829a4aSRandall Stewart 
5239f8829a4aSRandall Stewart 	/* Figure out what the rwnd would be */
5240f8829a4aSRandall Stewart 	rwnd = sctp_calc_rwnd(stcb, &stcb->asoc);
5241f8829a4aSRandall Stewart 	if (rwnd >= stcb->asoc.my_last_reported_rwnd) {
5242f8829a4aSRandall Stewart 		dif = rwnd - stcb->asoc.my_last_reported_rwnd;
5243f8829a4aSRandall Stewart 	} else {
5244f8829a4aSRandall Stewart 		dif = 0;
5245f8829a4aSRandall Stewart 	}
5246f8829a4aSRandall Stewart 	if (dif >= rwnd_req) {
5247f8829a4aSRandall Stewart 		if (hold_rlock) {
5248f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(stcb->sctp_ep);
5249f8829a4aSRandall Stewart 			r_unlocked = 1;
5250f8829a4aSRandall Stewart 		}
5251f8829a4aSRandall Stewart 		if (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
5252f8829a4aSRandall Stewart 			/*
5253f8829a4aSRandall Stewart 			 * One last check before we allow the guy possibly
5254f8829a4aSRandall Stewart 			 * to get in. There is a race, where the guy has not
5255f8829a4aSRandall Stewart 			 * reached the gate. In that case
5256f8829a4aSRandall Stewart 			 */
5257f8829a4aSRandall Stewart 			goto out;
5258f8829a4aSRandall Stewart 		}
5259f8829a4aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
5260f8829a4aSRandall Stewart 		if (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
5261f8829a4aSRandall Stewart 			/* No reports here */
5262f8829a4aSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
5263f8829a4aSRandall Stewart 			goto out;
5264f8829a4aSRandall Stewart 		}
5265f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_wu_sacks_sent);
5266689e6a5fSMichael Tuexen 		sctp_send_sack(stcb, SCTP_SO_LOCKED);
5267830d754dSRandall Stewart 
5268f8829a4aSRandall Stewart 		sctp_chunk_output(stcb->sctp_ep, stcb,
5269ceaad40aSRandall Stewart 		    SCTP_OUTPUT_FROM_USR_RCVD, SCTP_SO_LOCKED);
5270f8829a4aSRandall Stewart 		/* make sure no timer is running */
5271ba785902SMichael Tuexen 		sctp_timer_stop(SCTP_TIMER_TYPE_RECV, stcb->sctp_ep, stcb, NULL,
5272ba785902SMichael Tuexen 		    SCTP_FROM_SCTPUTIL + SCTP_LOC_6);
5273f8829a4aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
5274f8829a4aSRandall Stewart 	} else {
5275f8829a4aSRandall Stewart 		/* Update how much we have pending */
5276f8829a4aSRandall Stewart 		stcb->freed_by_sorcv_sincelast = dif;
5277f8829a4aSRandall Stewart 	}
5278f8829a4aSRandall Stewart out:
5279f8829a4aSRandall Stewart 	if (so && r_unlocked && hold_rlock) {
5280f8829a4aSRandall Stewart 		SCTP_INP_READ_LOCK(stcb->sctp_ep);
5281f8829a4aSRandall Stewart 	}
5282f8829a4aSRandall Stewart 	SCTP_INP_DECR_REF(stcb->sctp_ep);
5283f8829a4aSRandall Stewart no_lock:
528450cec919SRandall Stewart 	atomic_add_int(&stcb->asoc.refcnt, -1);
5285f8829a4aSRandall Stewart 	return;
5286f8829a4aSRandall Stewart }
5287f8829a4aSRandall Stewart 
5288f8829a4aSRandall Stewart int
5289f8829a4aSRandall Stewart sctp_sorecvmsg(struct socket *so,
5290f8829a4aSRandall Stewart     struct uio *uio,
5291f8829a4aSRandall Stewart     struct mbuf **mp,
5292f8829a4aSRandall Stewart     struct sockaddr *from,
5293f8829a4aSRandall Stewart     int fromlen,
5294f8829a4aSRandall Stewart     int *msg_flags,
5295f8829a4aSRandall Stewart     struct sctp_sndrcvinfo *sinfo,
5296f8829a4aSRandall Stewart     int filling_sinfo)
5297f8829a4aSRandall Stewart {
5298f8829a4aSRandall Stewart 	/*
5299f8829a4aSRandall Stewart 	 * MSG flags we will look at MSG_DONTWAIT - non-blocking IO.
5300f8829a4aSRandall Stewart 	 * MSG_PEEK - Look don't touch :-D (only valid with OUT mbuf copy
5301f8829a4aSRandall Stewart 	 * mp=NULL thus uio is the copy method to userland) MSG_WAITALL - ??
5302f8829a4aSRandall Stewart 	 * On the way out we may send out any combination of:
5303f8829a4aSRandall Stewart 	 * MSG_NOTIFICATION MSG_EOR
5304f8829a4aSRandall Stewart 	 *
5305f8829a4aSRandall Stewart 	 */
5306f8829a4aSRandall Stewart 	struct sctp_inpcb *inp = NULL;
5307f8829a4aSRandall Stewart 	int my_len = 0;
5308f8829a4aSRandall Stewart 	int cp_len = 0, error = 0;
5309f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control = NULL, *ctl = NULL, *nxt = NULL;
531094b0d969SMichael Tuexen 	struct mbuf *m = NULL;
5311f8829a4aSRandall Stewart 	struct sctp_tcb *stcb = NULL;
5312f8829a4aSRandall Stewart 	int wakeup_read_socket = 0;
5313f8829a4aSRandall Stewart 	int freecnt_applied = 0;
5314f8829a4aSRandall Stewart 	int out_flags = 0, in_flags = 0;
5315f8829a4aSRandall Stewart 	int block_allowed = 1;
53164c9179adSRandall Stewart 	uint32_t freed_so_far = 0;
531781aca91aSRandall Stewart 	uint32_t copied_so_far = 0;
531893164cf9SRandall Stewart 	int in_eeor_mode = 0;
5319f8829a4aSRandall Stewart 	int no_rcv_needed = 0;
5320f8829a4aSRandall Stewart 	uint32_t rwnd_req = 0;
5321f8829a4aSRandall Stewart 	int hold_sblock = 0;
5322f8829a4aSRandall Stewart 	int hold_rlock = 0;
53239a8e3088SMichael Tuexen 	ssize_t slen = 0;
53244c9179adSRandall Stewart 	uint32_t held_length = 0;
53257abab911SRobert Watson 	int sockbuf_lock = 0;
5326f8829a4aSRandall Stewart 
532717205eccSRandall Stewart 	if (uio == NULL) {
5328c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
532917205eccSRandall Stewart 		return (EINVAL);
533017205eccSRandall Stewart 	}
5331f8829a4aSRandall Stewart 	if (msg_flags) {
5332f8829a4aSRandall Stewart 		in_flags = *msg_flags;
5333c105859eSRandall Stewart 		if (in_flags & MSG_PEEK)
5334c105859eSRandall Stewart 			SCTP_STAT_INCR(sctps_read_peeks);
5335f8829a4aSRandall Stewart 	} else {
5336f8829a4aSRandall Stewart 		in_flags = 0;
5337f8829a4aSRandall Stewart 	}
5338f8829a4aSRandall Stewart 	slen = uio->uio_resid;
533917205eccSRandall Stewart 
5340f8829a4aSRandall Stewart 	/* Pull in and set up our int flags */
5341f8829a4aSRandall Stewart 	if (in_flags & MSG_OOB) {
5342f8829a4aSRandall Stewart 		/* Out of band's NOT supported */
5343f8829a4aSRandall Stewart 		return (EOPNOTSUPP);
5344f8829a4aSRandall Stewart 	}
5345f8829a4aSRandall Stewart 	if ((in_flags & MSG_PEEK) && (mp != NULL)) {
5346c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
5347f8829a4aSRandall Stewart 		return (EINVAL);
5348f8829a4aSRandall Stewart 	}
5349f8829a4aSRandall Stewart 	if ((in_flags & (MSG_DONTWAIT
5350f8829a4aSRandall Stewart 	    | MSG_NBIO
5351f8829a4aSRandall Stewart 	    )) ||
535242551e99SRandall Stewart 	    SCTP_SO_IS_NBIO(so)) {
5353f8829a4aSRandall Stewart 		block_allowed = 0;
5354f8829a4aSRandall Stewart 	}
5355f8829a4aSRandall Stewart 	/* setup the endpoint */
5356f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)so->so_pcb;
5357f8829a4aSRandall Stewart 	if (inp == NULL) {
5358c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EFAULT);
5359f8829a4aSRandall Stewart 		return (EFAULT);
5360f8829a4aSRandall Stewart 	}
536162c1ff9cSRandall Stewart 	rwnd_req = (SCTP_SB_LIMIT_RCV(so) >> SCTP_RWND_HIWAT_SHIFT);
5362f8829a4aSRandall Stewart 	/* Must be at least a MTU's worth */
5363f8829a4aSRandall Stewart 	if (rwnd_req < SCTP_MIN_RWND)
5364f8829a4aSRandall Stewart 		rwnd_req = SCTP_MIN_RWND;
5365f8829a4aSRandall Stewart 	in_eeor_mode = sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXPLICIT_EOR);
5366b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
5367f8829a4aSRandall Stewart 		sctp_misc_ints(SCTP_SORECV_ENTER,
53689a8e3088SMichael Tuexen 		    rwnd_req, in_eeor_mode, so->so_rcv.sb_cc, (uint32_t) uio->uio_resid);
536980fefe0aSRandall Stewart 	}
5370b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
5371f8829a4aSRandall Stewart 		sctp_misc_ints(SCTP_SORECV_ENTERPL,
53729a8e3088SMichael Tuexen 		    rwnd_req, block_allowed, so->so_rcv.sb_cc, (uint32_t) uio->uio_resid);
537380fefe0aSRandall Stewart 	}
5374265de5bbSRobert Watson 	error = sblock(&so->so_rcv, (block_allowed ? SBL_WAIT : 0));
5375f8829a4aSRandall Stewart 	if (error) {
5376f8829a4aSRandall Stewart 		goto release_unlocked;
5377f8829a4aSRandall Stewart 	}
53788e1e6e5fSMateusz Guzik 	sockbuf_lock = 1;
5379f8829a4aSRandall Stewart restart:
53807abab911SRobert Watson 
5381f8829a4aSRandall Stewart 
5382f8829a4aSRandall Stewart restart_nosblocks:
5383f8829a4aSRandall Stewart 	if (hold_sblock == 0) {
5384f8829a4aSRandall Stewart 		SOCKBUF_LOCK(&so->so_rcv);
5385f8829a4aSRandall Stewart 		hold_sblock = 1;
5386f8829a4aSRandall Stewart 	}
5387f8829a4aSRandall Stewart 	if ((inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
5388f8829a4aSRandall Stewart 	    (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE)) {
5389f8829a4aSRandall Stewart 		goto out;
5390f8829a4aSRandall Stewart 	}
53914e88d37aSMichael Tuexen 	if ((so->so_rcv.sb_state & SBS_CANTRCVMORE) && (so->so_rcv.sb_cc == 0)) {
5392f8829a4aSRandall Stewart 		if (so->so_error) {
5393f8829a4aSRandall Stewart 			error = so->so_error;
539444b7479bSRandall Stewart 			if ((in_flags & MSG_PEEK) == 0)
539544b7479bSRandall Stewart 				so->so_error = 0;
53969f22f500SRandall Stewart 			goto out;
5397f8829a4aSRandall Stewart 		} else {
53984e88d37aSMichael Tuexen 			if (so->so_rcv.sb_cc == 0) {
53997924093fSRandall Stewart 				/* indicate EOF */
54007924093fSRandall Stewart 				error = 0;
5401f8829a4aSRandall Stewart 				goto out;
5402f8829a4aSRandall Stewart 			}
54039f22f500SRandall Stewart 		}
54049f22f500SRandall Stewart 	}
54054e88d37aSMichael Tuexen 	if ((so->so_rcv.sb_cc <= held_length) && block_allowed) {
5406f8829a4aSRandall Stewart 		/* we need to wait for data */
54074e88d37aSMichael Tuexen 		if ((so->so_rcv.sb_cc == 0) &&
5408f8829a4aSRandall Stewart 		    ((inp->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
5409f8829a4aSRandall Stewart 		    (inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL))) {
5410f8829a4aSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_CONNECTED) == 0) {
5411f8829a4aSRandall Stewart 				/*
5412f8829a4aSRandall Stewart 				 * For active open side clear flags for
5413f8829a4aSRandall Stewart 				 * re-use passive open is blocked by
5414f8829a4aSRandall Stewart 				 * connect.
5415f8829a4aSRandall Stewart 				 */
5416f8829a4aSRandall Stewart 				if (inp->sctp_flags & SCTP_PCB_FLAGS_WAS_ABORTED) {
5417f8829a4aSRandall Stewart 					/*
5418f8829a4aSRandall Stewart 					 * You were aborted, passive side
5419f8829a4aSRandall Stewart 					 * always hits here
5420f8829a4aSRandall Stewart 					 */
5421c4739e2fSRandall Stewart 					SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ECONNRESET);
5422f8829a4aSRandall Stewart 					error = ECONNRESET;
5423f8829a4aSRandall Stewart 				}
5424f8829a4aSRandall Stewart 				so->so_state &= ~(SS_ISCONNECTING |
5425f8829a4aSRandall Stewart 				    SS_ISDISCONNECTING |
5426f8829a4aSRandall Stewart 				    SS_ISCONFIRMING |
5427f8829a4aSRandall Stewart 				    SS_ISCONNECTED);
5428f8829a4aSRandall Stewart 				if (error == 0) {
5429f8829a4aSRandall Stewart 					if ((inp->sctp_flags & SCTP_PCB_FLAGS_WAS_CONNECTED) == 0) {
5430c4739e2fSRandall Stewart 						SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOTCONN);
5431f8829a4aSRandall Stewart 						error = ENOTCONN;
5432f8829a4aSRandall Stewart 					}
5433f8829a4aSRandall Stewart 				}
5434f8829a4aSRandall Stewart 				goto out;
5435f8829a4aSRandall Stewart 			}
5436f8829a4aSRandall Stewart 		}
5437f8829a4aSRandall Stewart 		error = sbwait(&so->so_rcv);
5438f8829a4aSRandall Stewart 		if (error) {
5439f8829a4aSRandall Stewart 			goto out;
5440f8829a4aSRandall Stewart 		}
5441f8829a4aSRandall Stewart 		held_length = 0;
5442f8829a4aSRandall Stewart 		goto restart_nosblocks;
54434e88d37aSMichael Tuexen 	} else if (so->so_rcv.sb_cc == 0) {
544444b7479bSRandall Stewart 		if (so->so_error) {
544544b7479bSRandall Stewart 			error = so->so_error;
544644b7479bSRandall Stewart 			if ((in_flags & MSG_PEEK) == 0)
544744b7479bSRandall Stewart 				so->so_error = 0;
544844b7479bSRandall Stewart 		} else {
544944b7479bSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
545044b7479bSRandall Stewart 			    (inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
545144b7479bSRandall Stewart 				if ((inp->sctp_flags & SCTP_PCB_FLAGS_CONNECTED) == 0) {
545244b7479bSRandall Stewart 					/*
545344b7479bSRandall Stewart 					 * For active open side clear flags
545444b7479bSRandall Stewart 					 * for re-use passive open is
545544b7479bSRandall Stewart 					 * blocked by connect.
545644b7479bSRandall Stewart 					 */
545744b7479bSRandall Stewart 					if (inp->sctp_flags & SCTP_PCB_FLAGS_WAS_ABORTED) {
545844b7479bSRandall Stewart 						/*
545944b7479bSRandall Stewart 						 * You were aborted, passive
546044b7479bSRandall Stewart 						 * side always hits here
546144b7479bSRandall Stewart 						 */
5462c4739e2fSRandall Stewart 						SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ECONNRESET);
546344b7479bSRandall Stewart 						error = ECONNRESET;
546444b7479bSRandall Stewart 					}
546544b7479bSRandall Stewart 					so->so_state &= ~(SS_ISCONNECTING |
546644b7479bSRandall Stewart 					    SS_ISDISCONNECTING |
546744b7479bSRandall Stewart 					    SS_ISCONFIRMING |
546844b7479bSRandall Stewart 					    SS_ISCONNECTED);
546944b7479bSRandall Stewart 					if (error == 0) {
547044b7479bSRandall Stewart 						if ((inp->sctp_flags & SCTP_PCB_FLAGS_WAS_CONNECTED) == 0) {
5471c4739e2fSRandall Stewart 							SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOTCONN);
547244b7479bSRandall Stewart 							error = ENOTCONN;
547344b7479bSRandall Stewart 						}
547444b7479bSRandall Stewart 					}
547544b7479bSRandall Stewart 					goto out;
547644b7479bSRandall Stewart 				}
547744b7479bSRandall Stewart 			}
5478c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EWOULDBLOCK);
5479f8829a4aSRandall Stewart 			error = EWOULDBLOCK;
548044b7479bSRandall Stewart 		}
5481f8829a4aSRandall Stewart 		goto out;
5482f8829a4aSRandall Stewart 	}
5483d06c82f1SRandall Stewart 	if (hold_sblock == 1) {
5484d06c82f1SRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
5485d06c82f1SRandall Stewart 		hold_sblock = 0;
5486d06c82f1SRandall Stewart 	}
5487f8829a4aSRandall Stewart 	/* we possibly have data we can read */
54883c503c28SRandall Stewart 	/* sa_ignore FREED_MEMORY */
5489f8829a4aSRandall Stewart 	control = TAILQ_FIRST(&inp->read_queue);
5490f8829a4aSRandall Stewart 	if (control == NULL) {
5491f8829a4aSRandall Stewart 		/*
5492f8829a4aSRandall Stewart 		 * This could be happening since the appender did the
5493f8829a4aSRandall Stewart 		 * increment but as not yet did the tailq insert onto the
5494f8829a4aSRandall Stewart 		 * read_queue
5495f8829a4aSRandall Stewart 		 */
5496f8829a4aSRandall Stewart 		if (hold_rlock == 0) {
5497f8829a4aSRandall Stewart 			SCTP_INP_READ_LOCK(inp);
5498f8829a4aSRandall Stewart 		}
5499f8829a4aSRandall Stewart 		control = TAILQ_FIRST(&inp->read_queue);
55004e88d37aSMichael Tuexen 		if ((control == NULL) && (so->so_rcv.sb_cc != 0)) {
5501a5d547adSRandall Stewart #ifdef INVARIANTS
5502f8829a4aSRandall Stewart 			panic("Huh, its non zero and nothing on control?");
5503f8829a4aSRandall Stewart #endif
55044e88d37aSMichael Tuexen 			so->so_rcv.sb_cc = 0;
5505f8829a4aSRandall Stewart 		}
5506f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
5507f8829a4aSRandall Stewart 		hold_rlock = 0;
5508f8829a4aSRandall Stewart 		goto restart;
5509f8829a4aSRandall Stewart 	}
5510f8829a4aSRandall Stewart 	if ((control->length == 0) &&
5511f8829a4aSRandall Stewart 	    (control->do_not_ref_stcb)) {
5512f8829a4aSRandall Stewart 		/*
5513f8829a4aSRandall Stewart 		 * Clean up code for freeing assoc that left behind a
5514f8829a4aSRandall Stewart 		 * pdapi.. maybe a peer in EEOR that just closed after
5515f8829a4aSRandall Stewart 		 * sending and never indicated a EOR.
5516f8829a4aSRandall Stewart 		 */
5517f8829a4aSRandall Stewart 		if (hold_rlock == 0) {
5518f8829a4aSRandall Stewart 			hold_rlock = 1;
5519f8829a4aSRandall Stewart 			SCTP_INP_READ_LOCK(inp);
5520f8829a4aSRandall Stewart 		}
5521f8829a4aSRandall Stewart 		control->held_length = 0;
5522f8829a4aSRandall Stewart 		if (control->data) {
5523f8829a4aSRandall Stewart 			/* Hmm there is data here .. fix */
55244c9179adSRandall Stewart 			struct mbuf *m_tmp;
5525f8829a4aSRandall Stewart 			int cnt = 0;
5526f8829a4aSRandall Stewart 
55274c9179adSRandall Stewart 			m_tmp = control->data;
55284c9179adSRandall Stewart 			while (m_tmp) {
55294c9179adSRandall Stewart 				cnt += SCTP_BUF_LEN(m_tmp);
55304c9179adSRandall Stewart 				if (SCTP_BUF_NEXT(m_tmp) == NULL) {
55314c9179adSRandall Stewart 					control->tail_mbuf = m_tmp;
5532f8829a4aSRandall Stewart 					control->end_added = 1;
5533f8829a4aSRandall Stewart 				}
55344c9179adSRandall Stewart 				m_tmp = SCTP_BUF_NEXT(m_tmp);
5535f8829a4aSRandall Stewart 			}
5536f8829a4aSRandall Stewart 			control->length = cnt;
5537f8829a4aSRandall Stewart 		} else {
5538f8829a4aSRandall Stewart 			/* remove it */
5539f8829a4aSRandall Stewart 			TAILQ_REMOVE(&inp->read_queue, control, next);
5540f8829a4aSRandall Stewart 			/* Add back any hiddend data */
5541f8829a4aSRandall Stewart 			sctp_free_remote_addr(control->whoFrom);
5542f8829a4aSRandall Stewart 			sctp_free_a_readq(stcb, control);
5543f8829a4aSRandall Stewart 		}
5544f8829a4aSRandall Stewart 		if (hold_rlock) {
5545f8829a4aSRandall Stewart 			hold_rlock = 0;
5546f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
5547f8829a4aSRandall Stewart 		}
5548f8829a4aSRandall Stewart 		goto restart;
5549f8829a4aSRandall Stewart 	}
5550810ec536SMichael Tuexen 	if ((control->length == 0) &&
5551810ec536SMichael Tuexen 	    (control->end_added == 1)) {
5552810ec536SMichael Tuexen 		/*
5553810ec536SMichael Tuexen 		 * Do we also need to check for (control->pdapi_aborted ==
5554810ec536SMichael Tuexen 		 * 1)?
5555810ec536SMichael Tuexen 		 */
5556810ec536SMichael Tuexen 		if (hold_rlock == 0) {
5557810ec536SMichael Tuexen 			hold_rlock = 1;
5558810ec536SMichael Tuexen 			SCTP_INP_READ_LOCK(inp);
5559810ec536SMichael Tuexen 		}
5560810ec536SMichael Tuexen 		TAILQ_REMOVE(&inp->read_queue, control, next);
5561810ec536SMichael Tuexen 		if (control->data) {
5562810ec536SMichael Tuexen #ifdef INVARIANTS
5563810ec536SMichael Tuexen 			panic("control->data not null but control->length == 0");
5564810ec536SMichael Tuexen #else
5565810ec536SMichael Tuexen 			SCTP_PRINTF("Strange, data left in the control buffer. Cleaning up.\n");
5566810ec536SMichael Tuexen 			sctp_m_freem(control->data);
5567810ec536SMichael Tuexen 			control->data = NULL;
5568810ec536SMichael Tuexen #endif
5569810ec536SMichael Tuexen 		}
5570810ec536SMichael Tuexen 		if (control->aux_data) {
5571810ec536SMichael Tuexen 			sctp_m_free(control->aux_data);
5572810ec536SMichael Tuexen 			control->aux_data = NULL;
5573810ec536SMichael Tuexen 		}
557498d5fd97SMichael Tuexen #ifdef INVARIANTS
557544249214SRandall Stewart 		if (control->on_strm_q) {
557644249214SRandall Stewart 			panic("About to free ctl:%p so:%p and its in %d",
557744249214SRandall Stewart 			    control, so, control->on_strm_q);
557844249214SRandall Stewart 		}
557998d5fd97SMichael Tuexen #endif
5580810ec536SMichael Tuexen 		sctp_free_remote_addr(control->whoFrom);
5581810ec536SMichael Tuexen 		sctp_free_a_readq(stcb, control);
5582810ec536SMichael Tuexen 		if (hold_rlock) {
5583810ec536SMichael Tuexen 			hold_rlock = 0;
5584810ec536SMichael Tuexen 			SCTP_INP_READ_UNLOCK(inp);
5585810ec536SMichael Tuexen 		}
5586810ec536SMichael Tuexen 		goto restart;
5587810ec536SMichael Tuexen 	}
5588f8829a4aSRandall Stewart 	if (control->length == 0) {
5589f8829a4aSRandall Stewart 		if ((sctp_is_feature_on(inp, SCTP_PCB_FLAGS_FRAG_INTERLEAVE)) &&
5590f8829a4aSRandall Stewart 		    (filling_sinfo)) {
5591f8829a4aSRandall Stewart 			/* find a more suitable one then this */
5592f8829a4aSRandall Stewart 			ctl = TAILQ_NEXT(control, next);
5593f8829a4aSRandall Stewart 			while (ctl) {
55949a6142d8SRandall Stewart 				if ((ctl->stcb != control->stcb) && (ctl->length) &&
55959a6142d8SRandall Stewart 				    (ctl->some_taken ||
55966114cd96SRandall Stewart 				    (ctl->spec_flags & M_NOTIFICATION) ||
55979a6142d8SRandall Stewart 				    ((ctl->do_not_ref_stcb == 0) &&
55989a6142d8SRandall Stewart 				    (ctl->stcb->asoc.strmin[ctl->sinfo_stream].delivery_started == 0)))
55999a6142d8SRandall Stewart 				    ) {
56009a6142d8SRandall Stewart 					/*-
56019a6142d8SRandall Stewart 					 * If we have a different TCB next, and there is data
56029a6142d8SRandall Stewart 					 * present. If we have already taken some (pdapi), OR we can
56039a6142d8SRandall Stewart 					 * ref the tcb and no delivery as started on this stream, we
560417205eccSRandall Stewart 					 * take it. Note we allow a notification on a different
560517205eccSRandall Stewart 					 * assoc to be delivered..
56069a6142d8SRandall Stewart 					 */
56079a6142d8SRandall Stewart 					control = ctl;
56089a6142d8SRandall Stewart 					goto found_one;
56099a6142d8SRandall Stewart 				} else if ((sctp_is_feature_on(inp, SCTP_PCB_FLAGS_INTERLEAVE_STRMS)) &&
56109a6142d8SRandall Stewart 					    (ctl->length) &&
56119a6142d8SRandall Stewart 					    ((ctl->some_taken) ||
56129a6142d8SRandall Stewart 					    ((ctl->do_not_ref_stcb == 0) &&
561317205eccSRandall Stewart 					    ((ctl->spec_flags & M_NOTIFICATION) == 0) &&
5614b5c16493SMichael Tuexen 				    (ctl->stcb->asoc.strmin[ctl->sinfo_stream].delivery_started == 0)))) {
56159a6142d8SRandall Stewart 					/*-
56169a6142d8SRandall Stewart 					 * If we have the same tcb, and there is data present, and we
56179a6142d8SRandall Stewart 					 * have the strm interleave feature present. Then if we have
56189a6142d8SRandall Stewart 					 * taken some (pdapi) or we can refer to tht tcb AND we have
56199a6142d8SRandall Stewart 					 * not started a delivery for this stream, we can take it.
562017205eccSRandall Stewart 					 * Note we do NOT allow a notificaiton on the same assoc to
562117205eccSRandall Stewart 					 * be delivered.
56229a6142d8SRandall Stewart 					 */
5623f8829a4aSRandall Stewart 					control = ctl;
5624f8829a4aSRandall Stewart 					goto found_one;
5625f8829a4aSRandall Stewart 				}
5626f8829a4aSRandall Stewart 				ctl = TAILQ_NEXT(ctl, next);
5627f8829a4aSRandall Stewart 			}
5628f8829a4aSRandall Stewart 		}
5629f8829a4aSRandall Stewart 		/*
5630f8829a4aSRandall Stewart 		 * if we reach here, not suitable replacement is available
56314e88d37aSMichael Tuexen 		 * <or> fragment interleave is NOT on. So stuff the sb_cc
5632f8829a4aSRandall Stewart 		 * into the our held count, and its time to sleep again.
5633f8829a4aSRandall Stewart 		 */
56344e88d37aSMichael Tuexen 		held_length = so->so_rcv.sb_cc;
56354e88d37aSMichael Tuexen 		control->held_length = so->so_rcv.sb_cc;
5636f8829a4aSRandall Stewart 		goto restart;
5637f8829a4aSRandall Stewart 	}
5638f8829a4aSRandall Stewart 	/* Clear the held length since there is something to read */
5639f8829a4aSRandall Stewart 	control->held_length = 0;
5640f8829a4aSRandall Stewart 	if (hold_rlock) {
5641f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
5642f8829a4aSRandall Stewart 		hold_rlock = 0;
5643f8829a4aSRandall Stewart 	}
5644f8829a4aSRandall Stewart found_one:
5645f8829a4aSRandall Stewart 	/*
5646f8829a4aSRandall Stewart 	 * If we reach here, control has a some data for us to read off.
5647f8829a4aSRandall Stewart 	 * Note that stcb COULD be NULL.
5648f8829a4aSRandall Stewart 	 */
56499c04b296SRandall Stewart 	control->some_taken++;
5650f8829a4aSRandall Stewart 	if (hold_sblock) {
5651f8829a4aSRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
5652f8829a4aSRandall Stewart 		hold_sblock = 0;
5653f8829a4aSRandall Stewart 	}
5654f8829a4aSRandall Stewart 	stcb = control->stcb;
5655f8829a4aSRandall Stewart 	if (stcb) {
56560696e120SRandall Stewart 		if ((control->do_not_ref_stcb == 0) &&
56570696e120SRandall Stewart 		    (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED)) {
565850cec919SRandall Stewart 			if (freecnt_applied == 0)
5659f8829a4aSRandall Stewart 				stcb = NULL;
5660f8829a4aSRandall Stewart 		} else if (control->do_not_ref_stcb == 0) {
5661f8829a4aSRandall Stewart 			/* you can't free it on me please */
5662f8829a4aSRandall Stewart 			/*
5663f8829a4aSRandall Stewart 			 * The lock on the socket buffer protects us so the
5664f8829a4aSRandall Stewart 			 * free code will stop. But since we used the
5665f8829a4aSRandall Stewart 			 * socketbuf lock and the sender uses the tcb_lock
5666f8829a4aSRandall Stewart 			 * to increment, we need to use the atomic add to
5667f8829a4aSRandall Stewart 			 * the refcnt
5668f8829a4aSRandall Stewart 			 */
5669d55b0b1bSRandall Stewart 			if (freecnt_applied) {
5670d55b0b1bSRandall Stewart #ifdef INVARIANTS
5671207304d4SRandall Stewart 				panic("refcnt already incremented");
5672d55b0b1bSRandall Stewart #else
5673cd3fd531SMichael Tuexen 				SCTP_PRINTF("refcnt already incremented?\n");
5674d55b0b1bSRandall Stewart #endif
5675d55b0b1bSRandall Stewart 			} else {
567650cec919SRandall Stewart 				atomic_add_int(&stcb->asoc.refcnt, 1);
5677f8829a4aSRandall Stewart 				freecnt_applied = 1;
5678d55b0b1bSRandall Stewart 			}
5679f8829a4aSRandall Stewart 			/*
5680f8829a4aSRandall Stewart 			 * Setup to remember how much we have not yet told
5681f8829a4aSRandall Stewart 			 * the peer our rwnd has opened up. Note we grab the
5682f8829a4aSRandall Stewart 			 * value from the tcb from last time. Note too that
56830696e120SRandall Stewart 			 * sack sending clears this when a sack is sent,
5684f8829a4aSRandall Stewart 			 * which is fine. Once we hit the rwnd_req, we then
5685f8829a4aSRandall Stewart 			 * will go to the sctp_user_rcvd() that will not
5686f8829a4aSRandall Stewart 			 * lock until it KNOWs it MUST send a WUP-SACK.
5687f8829a4aSRandall Stewart 			 */
5688f8829a4aSRandall Stewart 			freed_so_far = stcb->freed_by_sorcv_sincelast;
5689f8829a4aSRandall Stewart 			stcb->freed_by_sorcv_sincelast = 0;
5690f8829a4aSRandall Stewart 		}
5691f8829a4aSRandall Stewart 	}
56926114cd96SRandall Stewart 	if (stcb &&
56936114cd96SRandall Stewart 	    ((control->spec_flags & M_NOTIFICATION) == 0) &&
56946114cd96SRandall Stewart 	    control->do_not_ref_stcb == 0) {
5695d06c82f1SRandall Stewart 		stcb->asoc.strmin[control->sinfo_stream].delivery_started = 1;
5696d06c82f1SRandall Stewart 	}
5697f8829a4aSRandall Stewart 	/* First lets get off the sinfo and sockaddr info */
5698f8829a4aSRandall Stewart 	if ((sinfo) && filling_sinfo) {
5699f8829a4aSRandall Stewart 		memcpy(sinfo, control, sizeof(struct sctp_nonpad_sndrcvinfo));
5700f8829a4aSRandall Stewart 		nxt = TAILQ_NEXT(control, next);
5701e2e7c62eSMichael Tuexen 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXT_RCVINFO) ||
5702e2e7c62eSMichael Tuexen 		    sctp_is_feature_on(inp, SCTP_PCB_FLAGS_RECVNXTINFO)) {
5703f8829a4aSRandall Stewart 			struct sctp_extrcvinfo *s_extra;
5704f8829a4aSRandall Stewart 
5705f8829a4aSRandall Stewart 			s_extra = (struct sctp_extrcvinfo *)sinfo;
57069a6142d8SRandall Stewart 			if ((nxt) &&
57079a6142d8SRandall Stewart 			    (nxt->length)) {
5708b70b526dSMichael Tuexen 				s_extra->serinfo_next_flags = SCTP_NEXT_MSG_AVAIL;
5709f8829a4aSRandall Stewart 				if (nxt->sinfo_flags & SCTP_UNORDERED) {
5710b70b526dSMichael Tuexen 					s_extra->serinfo_next_flags |= SCTP_NEXT_MSG_IS_UNORDERED;
5711f8829a4aSRandall Stewart 				}
5712f42a358aSRandall Stewart 				if (nxt->spec_flags & M_NOTIFICATION) {
5713b70b526dSMichael Tuexen 					s_extra->serinfo_next_flags |= SCTP_NEXT_MSG_IS_NOTIFICATION;
5714f42a358aSRandall Stewart 				}
5715b70b526dSMichael Tuexen 				s_extra->serinfo_next_aid = nxt->sinfo_assoc_id;
5716b70b526dSMichael Tuexen 				s_extra->serinfo_next_length = nxt->length;
5717b70b526dSMichael Tuexen 				s_extra->serinfo_next_ppid = nxt->sinfo_ppid;
5718b70b526dSMichael Tuexen 				s_extra->serinfo_next_stream = nxt->sinfo_stream;
5719f8829a4aSRandall Stewart 				if (nxt->tail_mbuf != NULL) {
5720139bc87fSRandall Stewart 					if (nxt->end_added) {
5721b70b526dSMichael Tuexen 						s_extra->serinfo_next_flags |= SCTP_NEXT_MSG_ISCOMPLETE;
5722f8829a4aSRandall Stewart 					}
5723f8829a4aSRandall Stewart 				}
5724f8829a4aSRandall Stewart 			} else {
5725f8829a4aSRandall Stewart 				/*
5726f8829a4aSRandall Stewart 				 * we explicitly 0 this, since the memcpy
5727f8829a4aSRandall Stewart 				 * got some other things beyond the older
5728f8829a4aSRandall Stewart 				 * sinfo_ that is on the control's structure
5729f8829a4aSRandall Stewart 				 * :-D
5730f8829a4aSRandall Stewart 				 */
57319a6142d8SRandall Stewart 				nxt = NULL;
5732b70b526dSMichael Tuexen 				s_extra->serinfo_next_flags = SCTP_NO_NEXT_MSG;
5733b70b526dSMichael Tuexen 				s_extra->serinfo_next_aid = 0;
5734b70b526dSMichael Tuexen 				s_extra->serinfo_next_length = 0;
5735b70b526dSMichael Tuexen 				s_extra->serinfo_next_ppid = 0;
5736b70b526dSMichael Tuexen 				s_extra->serinfo_next_stream = 0;
5737f8829a4aSRandall Stewart 			}
5738f8829a4aSRandall Stewart 		}
5739f8829a4aSRandall Stewart 		/*
5740f8829a4aSRandall Stewart 		 * update off the real current cum-ack, if we have an stcb.
5741f8829a4aSRandall Stewart 		 */
57420696e120SRandall Stewart 		if ((control->do_not_ref_stcb == 0) && stcb)
5743f8829a4aSRandall Stewart 			sinfo->sinfo_cumtsn = stcb->asoc.cumulative_tsn;
5744f8829a4aSRandall Stewart 		/*
5745f8829a4aSRandall Stewart 		 * mask off the high bits, we keep the actual chunk bits in
5746f8829a4aSRandall Stewart 		 * there.
5747f8829a4aSRandall Stewart 		 */
5748f8829a4aSRandall Stewart 		sinfo->sinfo_flags &= 0x00ff;
57495f26a41dSRandall Stewart 		if ((control->sinfo_flags >> 8) & SCTP_DATA_UNORDERED) {
57505f26a41dSRandall Stewart 			sinfo->sinfo_flags |= SCTP_UNORDERED;
57515f26a41dSRandall Stewart 		}
5752f8829a4aSRandall Stewart 	}
575318e198d3SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
575418e198d3SRandall Stewart 	{
575518e198d3SRandall Stewart 		int index, newindex;
575618e198d3SRandall Stewart 		struct sctp_pcbtsn_rlog *entry;
575718e198d3SRandall Stewart 
575818e198d3SRandall Stewart 		do {
575918e198d3SRandall Stewart 			index = inp->readlog_index;
576018e198d3SRandall Stewart 			newindex = index + 1;
576118e198d3SRandall Stewart 			if (newindex >= SCTP_READ_LOG_SIZE) {
576218e198d3SRandall Stewart 				newindex = 0;
576318e198d3SRandall Stewart 			}
576418e198d3SRandall Stewart 		} while (atomic_cmpset_int(&inp->readlog_index, index, newindex) == 0);
576518e198d3SRandall Stewart 		entry = &inp->readlog[index];
576618e198d3SRandall Stewart 		entry->vtag = control->sinfo_assoc_id;
576718e198d3SRandall Stewart 		entry->strm = control->sinfo_stream;
576818e198d3SRandall Stewart 		entry->seq = control->sinfo_ssn;
576918e198d3SRandall Stewart 		entry->sz = control->length;
577018e198d3SRandall Stewart 		entry->flgs = control->sinfo_flags;
577118e198d3SRandall Stewart 	}
577218e198d3SRandall Stewart #endif
5773d59107f7SMichael Tuexen 	if ((fromlen > 0) && (from != NULL)) {
5774d59107f7SMichael Tuexen 		union sctp_sockstore store;
5775d59107f7SMichael Tuexen 		size_t len;
5776d59107f7SMichael Tuexen 
5777b5b6e5c2SMichael Tuexen 		switch (control->whoFrom->ro._l_addr.sa.sa_family) {
5778b5b6e5c2SMichael Tuexen #ifdef INET6
5779b5b6e5c2SMichael Tuexen 		case AF_INET6:
5780d59107f7SMichael Tuexen 			len = sizeof(struct sockaddr_in6);
5781d59107f7SMichael Tuexen 			store.sin6 = control->whoFrom->ro._l_addr.sin6;
5782d59107f7SMichael Tuexen 			store.sin6.sin6_port = control->port_from;
5783b5b6e5c2SMichael Tuexen 			break;
5784f8829a4aSRandall Stewart #endif
5785b5b6e5c2SMichael Tuexen #ifdef INET
5786b5b6e5c2SMichael Tuexen 		case AF_INET:
5787d59107f7SMichael Tuexen #ifdef INET6
5788d59107f7SMichael Tuexen 			if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_NEEDS_MAPPED_V4)) {
5789d59107f7SMichael Tuexen 				len = sizeof(struct sockaddr_in6);
5790d59107f7SMichael Tuexen 				in6_sin_2_v4mapsin6(&control->whoFrom->ro._l_addr.sin,
5791d59107f7SMichael Tuexen 				    &store.sin6);
5792d59107f7SMichael Tuexen 				store.sin6.sin6_port = control->port_from;
5793d59107f7SMichael Tuexen 			} else {
5794d59107f7SMichael Tuexen 				len = sizeof(struct sockaddr_in);
5795d59107f7SMichael Tuexen 				store.sin = control->whoFrom->ro._l_addr.sin;
5796d59107f7SMichael Tuexen 				store.sin.sin_port = control->port_from;
5797d59107f7SMichael Tuexen 			}
5798d59107f7SMichael Tuexen #else
5799d59107f7SMichael Tuexen 			len = sizeof(struct sockaddr_in);
5800d59107f7SMichael Tuexen 			store.sin = control->whoFrom->ro._l_addr.sin;
5801d59107f7SMichael Tuexen 			store.sin.sin_port = control->port_from;
5802d59107f7SMichael Tuexen #endif
5803b5b6e5c2SMichael Tuexen 			break;
5804b5b6e5c2SMichael Tuexen #endif
5805b5b6e5c2SMichael Tuexen 		default:
5806d59107f7SMichael Tuexen 			len = 0;
5807b5b6e5c2SMichael Tuexen 			break;
5808b5b6e5c2SMichael Tuexen 		}
5809d59107f7SMichael Tuexen 		memcpy(from, &store, min((size_t)fromlen, len));
5810e0e00a4dSMichael Tuexen #ifdef INET6
5811f8829a4aSRandall Stewart 		{
5812b5b6e5c2SMichael Tuexen 			struct sockaddr_in6 lsa6, *from6;
5813f8829a4aSRandall Stewart 
5814b5b6e5c2SMichael Tuexen 			from6 = (struct sockaddr_in6 *)from;
5815b5b6e5c2SMichael Tuexen 			sctp_recover_scope_mac(from6, (&lsa6));
5816f8829a4aSRandall Stewart 		}
5817f8829a4aSRandall Stewart #endif
5818f8829a4aSRandall Stewart 	}
5819f8829a4aSRandall Stewart 	/* now copy out what data we can */
5820f8829a4aSRandall Stewart 	if (mp == NULL) {
5821f8829a4aSRandall Stewart 		/* copy out each mbuf in the chain up to length */
5822f8829a4aSRandall Stewart get_more_data:
5823f8829a4aSRandall Stewart 		m = control->data;
5824f8829a4aSRandall Stewart 		while (m) {
5825f8829a4aSRandall Stewart 			/* Move out all we can */
5826f8829a4aSRandall Stewart 			cp_len = (int)uio->uio_resid;
5827139bc87fSRandall Stewart 			my_len = (int)SCTP_BUF_LEN(m);
5828f8829a4aSRandall Stewart 			if (cp_len > my_len) {
5829f8829a4aSRandall Stewart 				/* not enough in this buf */
5830f8829a4aSRandall Stewart 				cp_len = my_len;
5831f8829a4aSRandall Stewart 			}
5832f8829a4aSRandall Stewart 			if (hold_rlock) {
5833f8829a4aSRandall Stewart 				SCTP_INP_READ_UNLOCK(inp);
5834f8829a4aSRandall Stewart 				hold_rlock = 0;
5835f8829a4aSRandall Stewart 			}
5836f8829a4aSRandall Stewart 			if (cp_len > 0)
5837f8829a4aSRandall Stewart 				error = uiomove(mtod(m, char *), cp_len, uio);
5838f8829a4aSRandall Stewart 			/* re-read */
5839f8829a4aSRandall Stewart 			if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
5840f8829a4aSRandall Stewart 				goto release;
5841f8829a4aSRandall Stewart 			}
58420696e120SRandall Stewart 			if ((control->do_not_ref_stcb == 0) && stcb &&
5843f8829a4aSRandall Stewart 			    stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
5844f8829a4aSRandall Stewart 				no_rcv_needed = 1;
5845f8829a4aSRandall Stewart 			}
5846f8829a4aSRandall Stewart 			if (error) {
5847f8829a4aSRandall Stewart 				/* error we are out of here */
5848f8829a4aSRandall Stewart 				goto release;
5849f8829a4aSRandall Stewart 			}
5850f8829a4aSRandall Stewart 			SCTP_INP_READ_LOCK(inp);
5851f8829a4aSRandall Stewart 			hold_rlock = 1;
5852139bc87fSRandall Stewart 			if (cp_len == SCTP_BUF_LEN(m)) {
5853139bc87fSRandall Stewart 				if ((SCTP_BUF_NEXT(m) == NULL) &&
5854139bc87fSRandall Stewart 				    (control->end_added)) {
5855f8829a4aSRandall Stewart 					out_flags |= MSG_EOR;
585652129fcdSRandall Stewart 					if ((control->do_not_ref_stcb == 0) &&
585752129fcdSRandall Stewart 					    (control->stcb != NULL) &&
585852129fcdSRandall Stewart 					    ((control->spec_flags & M_NOTIFICATION) == 0))
5859ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
5860f8829a4aSRandall Stewart 				}
5861139bc87fSRandall Stewart 				if (control->spec_flags & M_NOTIFICATION) {
5862f8829a4aSRandall Stewart 					out_flags |= MSG_NOTIFICATION;
5863f8829a4aSRandall Stewart 				}
5864f8829a4aSRandall Stewart 				/* we ate up the mbuf */
5865f8829a4aSRandall Stewart 				if (in_flags & MSG_PEEK) {
5866f8829a4aSRandall Stewart 					/* just looking */
5867139bc87fSRandall Stewart 					m = SCTP_BUF_NEXT(m);
5868f8829a4aSRandall Stewart 					copied_so_far += cp_len;
5869f8829a4aSRandall Stewart 				} else {
5870f8829a4aSRandall Stewart 					/* dispose of the mbuf */
5871b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5872f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv,
5873139bc87fSRandall Stewart 						    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
587480fefe0aSRandall Stewart 					}
5875f8829a4aSRandall Stewart 					sctp_sbfree(control, stcb, &so->so_rcv, m);
5876b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5877f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv,
5878f8829a4aSRandall Stewart 						    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
587980fefe0aSRandall Stewart 					}
5880f8829a4aSRandall Stewart 					copied_so_far += cp_len;
5881f8829a4aSRandall Stewart 					freed_so_far += cp_len;
5882c4739e2fSRandall Stewart 					freed_so_far += MSIZE;
588318e198d3SRandall Stewart 					atomic_subtract_int(&control->length, cp_len);
5884f8829a4aSRandall Stewart 					control->data = sctp_m_free(m);
5885f8829a4aSRandall Stewart 					m = control->data;
5886f8829a4aSRandall Stewart 					/*
5887f8829a4aSRandall Stewart 					 * been through it all, must hold sb
5888f8829a4aSRandall Stewart 					 * lock ok to null tail
5889f8829a4aSRandall Stewart 					 */
5890f8829a4aSRandall Stewart 					if (control->data == NULL) {
5891a5d547adSRandall Stewart #ifdef INVARIANTS
5892f8829a4aSRandall Stewart 						if ((control->end_added == 0) ||
5893f8829a4aSRandall Stewart 						    (TAILQ_NEXT(control, next) == NULL)) {
5894f8829a4aSRandall Stewart 							/*
5895f8829a4aSRandall Stewart 							 * If the end is not
5896f8829a4aSRandall Stewart 							 * added, OR the
5897f8829a4aSRandall Stewart 							 * next is NOT null
5898f8829a4aSRandall Stewart 							 * we MUST have the
5899f8829a4aSRandall Stewart 							 * lock.
5900f8829a4aSRandall Stewart 							 */
5901f8829a4aSRandall Stewart 							if (mtx_owned(&inp->inp_rdata_mtx) == 0) {
5902f8829a4aSRandall Stewart 								panic("Hmm we don't own the lock?");
5903f8829a4aSRandall Stewart 							}
5904f8829a4aSRandall Stewart 						}
5905f8829a4aSRandall Stewart #endif
5906f8829a4aSRandall Stewart 						control->tail_mbuf = NULL;
5907a5d547adSRandall Stewart #ifdef INVARIANTS
5908f8829a4aSRandall Stewart 						if ((control->end_added) && ((out_flags & MSG_EOR) == 0)) {
5909f8829a4aSRandall Stewart 							panic("end_added, nothing left and no MSG_EOR");
5910f8829a4aSRandall Stewart 						}
5911f8829a4aSRandall Stewart #endif
5912f8829a4aSRandall Stewart 					}
5913f8829a4aSRandall Stewart 				}
5914f8829a4aSRandall Stewart 			} else {
5915f8829a4aSRandall Stewart 				/* Do we need to trim the mbuf? */
5916139bc87fSRandall Stewart 				if (control->spec_flags & M_NOTIFICATION) {
5917f8829a4aSRandall Stewart 					out_flags |= MSG_NOTIFICATION;
5918f8829a4aSRandall Stewart 				}
5919f8829a4aSRandall Stewart 				if ((in_flags & MSG_PEEK) == 0) {
5920139bc87fSRandall Stewart 					SCTP_BUF_RESV_UF(m, cp_len);
5921139bc87fSRandall Stewart 					SCTP_BUF_LEN(m) -= cp_len;
5922b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5923f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, cp_len);
592480fefe0aSRandall Stewart 					}
59254e88d37aSMichael Tuexen 					atomic_subtract_int(&so->so_rcv.sb_cc, cp_len);
59260696e120SRandall Stewart 					if ((control->do_not_ref_stcb == 0) &&
59270696e120SRandall Stewart 					    stcb) {
59284e88d37aSMichael Tuexen 						atomic_subtract_int(&stcb->asoc.sb_cc, cp_len);
5929f8829a4aSRandall Stewart 					}
5930f8829a4aSRandall Stewart 					copied_so_far += cp_len;
5931f8829a4aSRandall Stewart 					freed_so_far += cp_len;
5932c4739e2fSRandall Stewart 					freed_so_far += MSIZE;
5933b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5934f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv, control->do_not_ref_stcb ? NULL : stcb,
5935f8829a4aSRandall Stewart 						    SCTP_LOG_SBRESULT, 0);
593680fefe0aSRandall Stewart 					}
593718e198d3SRandall Stewart 					atomic_subtract_int(&control->length, cp_len);
5938f8829a4aSRandall Stewart 				} else {
5939f8829a4aSRandall Stewart 					copied_so_far += cp_len;
5940f8829a4aSRandall Stewart 				}
5941f8829a4aSRandall Stewart 			}
5942d61a0ae0SRandall Stewart 			if ((out_flags & MSG_EOR) || (uio->uio_resid == 0)) {
5943f8829a4aSRandall Stewart 				break;
5944f8829a4aSRandall Stewart 			}
5945f8829a4aSRandall Stewart 			if (((stcb) && (in_flags & MSG_PEEK) == 0) &&
5946f8829a4aSRandall Stewart 			    (control->do_not_ref_stcb == 0) &&
5947f8829a4aSRandall Stewart 			    (freed_so_far >= rwnd_req)) {
5948f8829a4aSRandall Stewart 				sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
5949f8829a4aSRandall Stewart 			}
5950f8829a4aSRandall Stewart 		}		/* end while(m) */
5951f8829a4aSRandall Stewart 		/*
5952f8829a4aSRandall Stewart 		 * At this point we have looked at it all and we either have
5953f8829a4aSRandall Stewart 		 * a MSG_EOR/or read all the user wants... <OR>
5954f8829a4aSRandall Stewart 		 * control->length == 0.
5955f8829a4aSRandall Stewart 		 */
5956d61a0ae0SRandall Stewart 		if ((out_flags & MSG_EOR) && ((in_flags & MSG_PEEK) == 0)) {
5957f8829a4aSRandall Stewart 			/* we are done with this control */
5958f8829a4aSRandall Stewart 			if (control->length == 0) {
5959f8829a4aSRandall Stewart 				if (control->data) {
5960a5d547adSRandall Stewart #ifdef INVARIANTS
5961f8829a4aSRandall Stewart 					panic("control->data not null at read eor?");
5962f8829a4aSRandall Stewart #else
5963ad81507eSRandall Stewart 					SCTP_PRINTF("Strange, data left in the control buffer .. invarients would panic?\n");
5964f8829a4aSRandall Stewart 					sctp_m_freem(control->data);
5965f8829a4aSRandall Stewart 					control->data = NULL;
5966f8829a4aSRandall Stewart #endif
5967f8829a4aSRandall Stewart 				}
5968f8829a4aSRandall Stewart 		done_with_control:
5969f8829a4aSRandall Stewart 				if (hold_rlock == 0) {
5970f8829a4aSRandall Stewart 					SCTP_INP_READ_LOCK(inp);
5971f8829a4aSRandall Stewart 					hold_rlock = 1;
5972f8829a4aSRandall Stewart 				}
5973f8829a4aSRandall Stewart 				TAILQ_REMOVE(&inp->read_queue, control, next);
5974f8829a4aSRandall Stewart 				/* Add back any hiddend data */
5975f8829a4aSRandall Stewart 				if (control->held_length) {
5976f8829a4aSRandall Stewart 					held_length = 0;
5977f8829a4aSRandall Stewart 					control->held_length = 0;
5978f8829a4aSRandall Stewart 					wakeup_read_socket = 1;
5979f8829a4aSRandall Stewart 				}
598017205eccSRandall Stewart 				if (control->aux_data) {
598117205eccSRandall Stewart 					sctp_m_free(control->aux_data);
598217205eccSRandall Stewart 					control->aux_data = NULL;
598317205eccSRandall Stewart 				}
5984f8829a4aSRandall Stewart 				no_rcv_needed = control->do_not_ref_stcb;
5985f8829a4aSRandall Stewart 				sctp_free_remote_addr(control->whoFrom);
5986f8829a4aSRandall Stewart 				control->data = NULL;
598798d5fd97SMichael Tuexen #ifdef INVARIANTS
598844249214SRandall Stewart 				if (control->on_strm_q) {
598944249214SRandall Stewart 					panic("About to free ctl:%p so:%p and its in %d",
599044249214SRandall Stewart 					    control, so, control->on_strm_q);
599144249214SRandall Stewart 				}
599298d5fd97SMichael Tuexen #endif
5993f8829a4aSRandall Stewart 				sctp_free_a_readq(stcb, control);
5994f8829a4aSRandall Stewart 				control = NULL;
59950696e120SRandall Stewart 				if ((freed_so_far >= rwnd_req) &&
59960696e120SRandall Stewart 				    (no_rcv_needed == 0))
5997f8829a4aSRandall Stewart 					sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
5998f8829a4aSRandall Stewart 
5999f8829a4aSRandall Stewart 			} else {
6000f8829a4aSRandall Stewart 				/*
6001f8829a4aSRandall Stewart 				 * The user did not read all of this
6002f8829a4aSRandall Stewart 				 * message, turn off the returned MSG_EOR
6003f8829a4aSRandall Stewart 				 * since we are leaving more behind on the
6004f8829a4aSRandall Stewart 				 * control to read.
6005f8829a4aSRandall Stewart 				 */
6006a5d547adSRandall Stewart #ifdef INVARIANTS
60070696e120SRandall Stewart 				if (control->end_added &&
60080696e120SRandall Stewart 				    (control->data == NULL) &&
6009f8829a4aSRandall Stewart 				    (control->tail_mbuf == NULL)) {
6010f8829a4aSRandall Stewart 					panic("Gak, control->length is corrupt?");
6011f8829a4aSRandall Stewart 				}
6012f8829a4aSRandall Stewart #endif
6013f8829a4aSRandall Stewart 				no_rcv_needed = control->do_not_ref_stcb;
6014f8829a4aSRandall Stewart 				out_flags &= ~MSG_EOR;
6015f8829a4aSRandall Stewart 			}
6016f8829a4aSRandall Stewart 		}
6017f8829a4aSRandall Stewart 		if (out_flags & MSG_EOR) {
6018f8829a4aSRandall Stewart 			goto release;
6019f8829a4aSRandall Stewart 		}
6020f8829a4aSRandall Stewart 		if ((uio->uio_resid == 0) ||
602104aab884SMichael Tuexen 		    ((in_eeor_mode) &&
602204aab884SMichael Tuexen 		    (copied_so_far >= (uint32_t) max(so->so_rcv.sb_lowat, 1)))) {
6023f8829a4aSRandall Stewart 			goto release;
6024f8829a4aSRandall Stewart 		}
6025f8829a4aSRandall Stewart 		/*
6026f8829a4aSRandall Stewart 		 * If I hit here the receiver wants more and this message is
6027f8829a4aSRandall Stewart 		 * NOT done (pd-api). So two questions. Can we block? if not
6028f8829a4aSRandall Stewart 		 * we are done. Did the user NOT set MSG_WAITALL?
6029f8829a4aSRandall Stewart 		 */
6030f8829a4aSRandall Stewart 		if (block_allowed == 0) {
6031f8829a4aSRandall Stewart 			goto release;
6032f8829a4aSRandall Stewart 		}
6033f8829a4aSRandall Stewart 		/*
6034f8829a4aSRandall Stewart 		 * We need to wait for more data a few things: - We don't
6035f8829a4aSRandall Stewart 		 * sbunlock() so we don't get someone else reading. - We
6036f8829a4aSRandall Stewart 		 * must be sure to account for the case where what is added
6037f8829a4aSRandall Stewart 		 * is NOT to our control when we wakeup.
6038f8829a4aSRandall Stewart 		 */
6039f8829a4aSRandall Stewart 
6040f8829a4aSRandall Stewart 		/*
6041f8829a4aSRandall Stewart 		 * Do we need to tell the transport a rwnd update might be
6042f8829a4aSRandall Stewart 		 * needed before we go to sleep?
6043f8829a4aSRandall Stewart 		 */
6044f8829a4aSRandall Stewart 		if (((stcb) && (in_flags & MSG_PEEK) == 0) &&
6045f8829a4aSRandall Stewart 		    ((freed_so_far >= rwnd_req) &&
6046f8829a4aSRandall Stewart 		    (control->do_not_ref_stcb == 0) &&
6047f8829a4aSRandall Stewart 		    (no_rcv_needed == 0))) {
6048f8829a4aSRandall Stewart 			sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
6049f8829a4aSRandall Stewart 		}
6050f8829a4aSRandall Stewart wait_some_more:
605144b7479bSRandall Stewart 		if (so->so_rcv.sb_state & SBS_CANTRCVMORE) {
6052f8829a4aSRandall Stewart 			goto release;
6053f8829a4aSRandall Stewart 		}
6054f8829a4aSRandall Stewart 		if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE)
6055f8829a4aSRandall Stewart 			goto release;
6056f8829a4aSRandall Stewart 
6057f8829a4aSRandall Stewart 		if (hold_rlock == 1) {
6058f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
6059f8829a4aSRandall Stewart 			hold_rlock = 0;
6060f8829a4aSRandall Stewart 		}
6061f8829a4aSRandall Stewart 		if (hold_sblock == 0) {
6062f8829a4aSRandall Stewart 			SOCKBUF_LOCK(&so->so_rcv);
6063f8829a4aSRandall Stewart 			hold_sblock = 1;
6064f8829a4aSRandall Stewart 		}
6065851b7298SRandall Stewart 		if ((copied_so_far) && (control->length == 0) &&
6066b5c16493SMichael Tuexen 		    (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_FRAG_INTERLEAVE))) {
6067851b7298SRandall Stewart 			goto release;
6068851b7298SRandall Stewart 		}
60694e88d37aSMichael Tuexen 		if (so->so_rcv.sb_cc <= control->held_length) {
6070f8829a4aSRandall Stewart 			error = sbwait(&so->so_rcv);
6071f8829a4aSRandall Stewart 			if (error) {
6072f8829a4aSRandall Stewart 				goto release;
6073f8829a4aSRandall Stewart 			}
6074f8829a4aSRandall Stewart 			control->held_length = 0;
6075f8829a4aSRandall Stewart 		}
6076f8829a4aSRandall Stewart 		if (hold_sblock) {
6077f8829a4aSRandall Stewart 			SOCKBUF_UNLOCK(&so->so_rcv);
6078f8829a4aSRandall Stewart 			hold_sblock = 0;
6079f8829a4aSRandall Stewart 		}
6080f8829a4aSRandall Stewart 		if (control->length == 0) {
6081f8829a4aSRandall Stewart 			/* still nothing here */
6082f8829a4aSRandall Stewart 			if (control->end_added == 1) {
6083f8829a4aSRandall Stewart 				/* he aborted, or is done i.e.did a shutdown */
6084f8829a4aSRandall Stewart 				out_flags |= MSG_EOR;
60859a6142d8SRandall Stewart 				if (control->pdapi_aborted) {
60866114cd96SRandall Stewart 					if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
6087ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
60889a6142d8SRandall Stewart 
608903b0b021SRandall Stewart 					out_flags |= MSG_TRUNC;
60909a6142d8SRandall Stewart 				} else {
60916114cd96SRandall Stewart 					if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
6092ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
60939a6142d8SRandall Stewart 				}
6094f8829a4aSRandall Stewart 				goto done_with_control;
6095f8829a4aSRandall Stewart 			}
60964e88d37aSMichael Tuexen 			if (so->so_rcv.sb_cc > held_length) {
60974e88d37aSMichael Tuexen 				control->held_length = so->so_rcv.sb_cc;
6098f8829a4aSRandall Stewart 				held_length = 0;
6099f8829a4aSRandall Stewart 			}
6100f8829a4aSRandall Stewart 			goto wait_some_more;
6101f8829a4aSRandall Stewart 		} else if (control->data == NULL) {
610250cec919SRandall Stewart 			/*
610350cec919SRandall Stewart 			 * we must re-sync since data is probably being
610450cec919SRandall Stewart 			 * added
610550cec919SRandall Stewart 			 */
610650cec919SRandall Stewart 			SCTP_INP_READ_LOCK(inp);
610750cec919SRandall Stewart 			if ((control->length > 0) && (control->data == NULL)) {
610850cec919SRandall Stewart 				/*
610950cec919SRandall Stewart 				 * big trouble.. we have the lock and its
611050cec919SRandall Stewart 				 * corrupt?
611150cec919SRandall Stewart 				 */
61129c04b296SRandall Stewart #ifdef INVARIANTS
61139d18771fSRandall Stewart 				panic("Impossible data==NULL length !=0");
61149c04b296SRandall Stewart #endif
61159c04b296SRandall Stewart 				out_flags |= MSG_EOR;
61169c04b296SRandall Stewart 				out_flags |= MSG_TRUNC;
61179c04b296SRandall Stewart 				control->length = 0;
61189c04b296SRandall Stewart 				SCTP_INP_READ_UNLOCK(inp);
61199c04b296SRandall Stewart 				goto done_with_control;
6120f8829a4aSRandall Stewart 			}
612150cec919SRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
612250cec919SRandall Stewart 			/* We will fall around to get more data */
612350cec919SRandall Stewart 		}
6124f8829a4aSRandall Stewart 		goto get_more_data;
6125f8829a4aSRandall Stewart 	} else {
612617205eccSRandall Stewart 		/*-
612717205eccSRandall Stewart 		 * Give caller back the mbuf chain,
612817205eccSRandall Stewart 		 * store in uio_resid the length
6129f8829a4aSRandall Stewart 		 */
613017205eccSRandall Stewart 		wakeup_read_socket = 0;
6131f8829a4aSRandall Stewart 		if ((control->end_added == 0) ||
6132f8829a4aSRandall Stewart 		    (TAILQ_NEXT(control, next) == NULL)) {
6133f8829a4aSRandall Stewart 			/* Need to get rlock */
6134f8829a4aSRandall Stewart 			if (hold_rlock == 0) {
6135f8829a4aSRandall Stewart 				SCTP_INP_READ_LOCK(inp);
6136f8829a4aSRandall Stewart 				hold_rlock = 1;
6137f8829a4aSRandall Stewart 			}
6138f8829a4aSRandall Stewart 		}
6139139bc87fSRandall Stewart 		if (control->end_added) {
6140f8829a4aSRandall Stewart 			out_flags |= MSG_EOR;
614160990c0cSMichael Tuexen 			if ((control->do_not_ref_stcb == 0) &&
614260990c0cSMichael Tuexen 			    (control->stcb != NULL) &&
614360990c0cSMichael Tuexen 			    ((control->spec_flags & M_NOTIFICATION) == 0))
6144ee7f9857SRandall Stewart 				control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
6145f8829a4aSRandall Stewart 		}
6146139bc87fSRandall Stewart 		if (control->spec_flags & M_NOTIFICATION) {
6147f8829a4aSRandall Stewart 			out_flags |= MSG_NOTIFICATION;
6148f8829a4aSRandall Stewart 		}
614917205eccSRandall Stewart 		uio->uio_resid = control->length;
6150f8829a4aSRandall Stewart 		*mp = control->data;
6151f8829a4aSRandall Stewart 		m = control->data;
6152f8829a4aSRandall Stewart 		while (m) {
6153b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
6154f8829a4aSRandall Stewart 				sctp_sblog(&so->so_rcv,
6155139bc87fSRandall Stewart 				    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
615680fefe0aSRandall Stewart 			}
6157f8829a4aSRandall Stewart 			sctp_sbfree(control, stcb, &so->so_rcv, m);
6158139bc87fSRandall Stewart 			freed_so_far += SCTP_BUF_LEN(m);
6159c4739e2fSRandall Stewart 			freed_so_far += MSIZE;
6160b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
6161f8829a4aSRandall Stewart 				sctp_sblog(&so->so_rcv,
6162f8829a4aSRandall Stewart 				    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
616380fefe0aSRandall Stewart 			}
6164139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
6165f8829a4aSRandall Stewart 		}
6166f8829a4aSRandall Stewart 		control->data = control->tail_mbuf = NULL;
6167f8829a4aSRandall Stewart 		control->length = 0;
6168f8829a4aSRandall Stewart 		if (out_flags & MSG_EOR) {
6169f8829a4aSRandall Stewart 			/* Done with this control */
6170f8829a4aSRandall Stewart 			goto done_with_control;
6171f8829a4aSRandall Stewart 		}
6172f8829a4aSRandall Stewart 	}
6173f8829a4aSRandall Stewart release:
6174f8829a4aSRandall Stewart 	if (hold_rlock == 1) {
6175f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
6176f8829a4aSRandall Stewart 		hold_rlock = 0;
6177f8829a4aSRandall Stewart 	}
61787abab911SRobert Watson 	if (hold_sblock == 1) {
61797abab911SRobert Watson 		SOCKBUF_UNLOCK(&so->so_rcv);
61807abab911SRobert Watson 		hold_sblock = 0;
6181f8829a4aSRandall Stewart 	}
6182f8829a4aSRandall Stewart 	sbunlock(&so->so_rcv);
61837abab911SRobert Watson 	sockbuf_lock = 0;
6184f8829a4aSRandall Stewart 
6185f8829a4aSRandall Stewart release_unlocked:
6186f8829a4aSRandall Stewart 	if (hold_sblock) {
6187f8829a4aSRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
6188f8829a4aSRandall Stewart 		hold_sblock = 0;
6189f8829a4aSRandall Stewart 	}
6190f8829a4aSRandall Stewart 	if ((stcb) && (in_flags & MSG_PEEK) == 0) {
6191f8829a4aSRandall Stewart 		if ((freed_so_far >= rwnd_req) &&
6192f8829a4aSRandall Stewart 		    (control && (control->do_not_ref_stcb == 0)) &&
6193f8829a4aSRandall Stewart 		    (no_rcv_needed == 0))
6194f8829a4aSRandall Stewart 			sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
6195f8829a4aSRandall Stewart 	}
6196f8829a4aSRandall Stewart out:
61971b9f62a0SRandall Stewart 	if (msg_flags) {
61981b9f62a0SRandall Stewart 		*msg_flags = out_flags;
61991b9f62a0SRandall Stewart 	}
62009a6142d8SRandall Stewart 	if (((out_flags & MSG_EOR) == 0) &&
62019a6142d8SRandall Stewart 	    ((in_flags & MSG_PEEK) == 0) &&
62029a6142d8SRandall Stewart 	    (sinfo) &&
6203e2e7c62eSMichael Tuexen 	    (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXT_RCVINFO) ||
6204e2e7c62eSMichael Tuexen 	    sctp_is_feature_on(inp, SCTP_PCB_FLAGS_RECVNXTINFO))) {
62059a6142d8SRandall Stewart 		struct sctp_extrcvinfo *s_extra;
62069a6142d8SRandall Stewart 
62079a6142d8SRandall Stewart 		s_extra = (struct sctp_extrcvinfo *)sinfo;
6208b70b526dSMichael Tuexen 		s_extra->serinfo_next_flags = SCTP_NO_NEXT_MSG;
62099a6142d8SRandall Stewart 	}
6210f8829a4aSRandall Stewart 	if (hold_rlock == 1) {
6211f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
6212f8829a4aSRandall Stewart 	}
6213f8829a4aSRandall Stewart 	if (hold_sblock) {
6214f8829a4aSRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
6215f8829a4aSRandall Stewart 	}
62167abab911SRobert Watson 	if (sockbuf_lock) {
62177abab911SRobert Watson 		sbunlock(&so->so_rcv);
62187abab911SRobert Watson 	}
621950cec919SRandall Stewart 	if (freecnt_applied) {
6220f8829a4aSRandall Stewart 		/*
6221f8829a4aSRandall Stewart 		 * The lock on the socket buffer protects us so the free
6222f8829a4aSRandall Stewart 		 * code will stop. But since we used the socketbuf lock and
6223f8829a4aSRandall Stewart 		 * the sender uses the tcb_lock to increment, we need to use
6224f8829a4aSRandall Stewart 		 * the atomic add to the refcnt.
6225f8829a4aSRandall Stewart 		 */
622650cec919SRandall Stewart 		if (stcb == NULL) {
6227df6e0cc3SRandall Stewart #ifdef INVARIANTS
622850cec919SRandall Stewart 			panic("stcb for refcnt has gone NULL?");
6229df6e0cc3SRandall Stewart 			goto stage_left;
6230df6e0cc3SRandall Stewart #else
6231df6e0cc3SRandall Stewart 			goto stage_left;
6232df6e0cc3SRandall Stewart #endif
623350cec919SRandall Stewart 		}
623450cec919SRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, -1);
6235f8829a4aSRandall Stewart 		/* Save the value back for next time */
6236f8829a4aSRandall Stewart 		stcb->freed_by_sorcv_sincelast = freed_so_far;
6237f8829a4aSRandall Stewart 	}
6238b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
6239f8829a4aSRandall Stewart 		if (stcb) {
6240f8829a4aSRandall Stewart 			sctp_misc_ints(SCTP_SORECV_DONE,
6241f8829a4aSRandall Stewart 			    freed_so_far,
62429a8e3088SMichael Tuexen 			    (uint32_t) ((uio) ? (slen - uio->uio_resid) : slen),
6243f8829a4aSRandall Stewart 			    stcb->asoc.my_rwnd,
62444e88d37aSMichael Tuexen 			    so->so_rcv.sb_cc);
6245f8829a4aSRandall Stewart 		} else {
6246f8829a4aSRandall Stewart 			sctp_misc_ints(SCTP_SORECV_DONE,
6247f8829a4aSRandall Stewart 			    freed_so_far,
62489a8e3088SMichael Tuexen 			    (uint32_t) ((uio) ? (slen - uio->uio_resid) : slen),
6249f8829a4aSRandall Stewart 			    0,
62504e88d37aSMichael Tuexen 			    so->so_rcv.sb_cc);
6251f8829a4aSRandall Stewart 		}
625280fefe0aSRandall Stewart 	}
6253df6e0cc3SRandall Stewart stage_left:
6254f8829a4aSRandall Stewart 	if (wakeup_read_socket) {
6255f8829a4aSRandall Stewart 		sctp_sorwakeup(inp, so);
6256f8829a4aSRandall Stewart 	}
6257f8829a4aSRandall Stewart 	return (error);
6258f8829a4aSRandall Stewart }
6259f8829a4aSRandall Stewart 
6260f8829a4aSRandall Stewart 
6261f8829a4aSRandall Stewart #ifdef SCTP_MBUF_LOGGING
6262f8829a4aSRandall Stewart struct mbuf *
6263f8829a4aSRandall Stewart sctp_m_free(struct mbuf *m)
6264f8829a4aSRandall Stewart {
6265b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_MBUF_LOGGING_ENABLE) {
6266f8829a4aSRandall Stewart 		sctp_log_mb(m, SCTP_MBUF_IFREE);
6267f8829a4aSRandall Stewart 	}
6268f8829a4aSRandall Stewart 	return (m_free(m));
6269f8829a4aSRandall Stewart }
6270f8829a4aSRandall Stewart 
6271f8829a4aSRandall Stewart void
6272f8829a4aSRandall Stewart sctp_m_freem(struct mbuf *mb)
6273f8829a4aSRandall Stewart {
6274f8829a4aSRandall Stewart 	while (mb != NULL)
6275f8829a4aSRandall Stewart 		mb = sctp_m_free(mb);
6276f8829a4aSRandall Stewart }
6277f8829a4aSRandall Stewart 
6278f8829a4aSRandall Stewart #endif
6279f8829a4aSRandall Stewart 
628042551e99SRandall Stewart int
628142551e99SRandall Stewart sctp_dynamic_set_primary(struct sockaddr *sa, uint32_t vrf_id)
628242551e99SRandall Stewart {
628342551e99SRandall Stewart 	/*
628442551e99SRandall Stewart 	 * Given a local address. For all associations that holds the
628542551e99SRandall Stewart 	 * address, request a peer-set-primary.
628642551e99SRandall Stewart 	 */
628742551e99SRandall Stewart 	struct sctp_ifa *ifa;
628842551e99SRandall Stewart 	struct sctp_laddr *wi;
628942551e99SRandall Stewart 
629042551e99SRandall Stewart 	ifa = sctp_find_ifa_by_addr(sa, vrf_id, 0);
629142551e99SRandall Stewart 	if (ifa == NULL) {
6292c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EADDRNOTAVAIL);
629342551e99SRandall Stewart 		return (EADDRNOTAVAIL);
629442551e99SRandall Stewart 	}
629542551e99SRandall Stewart 	/*
629642551e99SRandall Stewart 	 * Now that we have the ifa we must awaken the iterator with this
629742551e99SRandall Stewart 	 * message.
629842551e99SRandall Stewart 	 */
6299b3f1ea41SRandall Stewart 	wi = SCTP_ZONE_GET(SCTP_BASE_INFO(ipi_zone_laddr), struct sctp_laddr);
630042551e99SRandall Stewart 	if (wi == NULL) {
6301c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
630242551e99SRandall Stewart 		return (ENOMEM);
630342551e99SRandall Stewart 	}
630442551e99SRandall Stewart 	/* Now incr the count and int wi structure */
630542551e99SRandall Stewart 	SCTP_INCR_LADDR_COUNT();
630642551e99SRandall Stewart 	bzero(wi, sizeof(*wi));
6307d61a0ae0SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&wi->start_time);
630842551e99SRandall Stewart 	wi->ifa = ifa;
630942551e99SRandall Stewart 	wi->action = SCTP_SET_PRIM_ADDR;
631042551e99SRandall Stewart 	atomic_add_int(&ifa->refcount, 1);
631142551e99SRandall Stewart 
631242551e99SRandall Stewart 	/* Now add it to the work queue */
6313f7517433SRandall Stewart 	SCTP_WQ_ADDR_LOCK();
631442551e99SRandall Stewart 	/*
631542551e99SRandall Stewart 	 * Should this really be a tailq? As it is we will process the
631642551e99SRandall Stewart 	 * newest first :-0
631742551e99SRandall Stewart 	 */
6318b3f1ea41SRandall Stewart 	LIST_INSERT_HEAD(&SCTP_BASE_INFO(addr_wq), wi, sctp_nxt_addr);
6319f7517433SRandall Stewart 	SCTP_WQ_ADDR_UNLOCK();
632042551e99SRandall Stewart 	sctp_timer_start(SCTP_TIMER_TYPE_ADDR_WQ,
632142551e99SRandall Stewart 	    (struct sctp_inpcb *)NULL,
632242551e99SRandall Stewart 	    (struct sctp_tcb *)NULL,
632342551e99SRandall Stewart 	    (struct sctp_nets *)NULL);
632442551e99SRandall Stewart 	return (0);
632542551e99SRandall Stewart }
632642551e99SRandall Stewart 
632742551e99SRandall Stewart 
6328f8829a4aSRandall Stewart int
632917205eccSRandall Stewart sctp_soreceive(struct socket *so,
633017205eccSRandall Stewart     struct sockaddr **psa,
633117205eccSRandall Stewart     struct uio *uio,
633217205eccSRandall Stewart     struct mbuf **mp0,
633317205eccSRandall Stewart     struct mbuf **controlp,
633417205eccSRandall Stewart     int *flagsp)
6335f8829a4aSRandall Stewart {
6336f8829a4aSRandall Stewart 	int error, fromlen;
6337f8829a4aSRandall Stewart 	uint8_t sockbuf[256];
6338f8829a4aSRandall Stewart 	struct sockaddr *from;
6339f8829a4aSRandall Stewart 	struct sctp_extrcvinfo sinfo;
6340f8829a4aSRandall Stewart 	int filling_sinfo = 1;
6341f8829a4aSRandall Stewart 	struct sctp_inpcb *inp;
6342f8829a4aSRandall Stewart 
6343f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)so->so_pcb;
6344f8829a4aSRandall Stewart 	/* pickup the assoc we are reading from */
6345f8829a4aSRandall Stewart 	if (inp == NULL) {
6346c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6347f8829a4aSRandall Stewart 		return (EINVAL);
6348f8829a4aSRandall Stewart 	}
6349e2e7c62eSMichael Tuexen 	if ((sctp_is_feature_off(inp, SCTP_PCB_FLAGS_RECVDATAIOEVNT) &&
6350e2e7c62eSMichael Tuexen 	    sctp_is_feature_off(inp, SCTP_PCB_FLAGS_RECVRCVINFO) &&
6351e2e7c62eSMichael Tuexen 	    sctp_is_feature_off(inp, SCTP_PCB_FLAGS_RECVNXTINFO)) ||
6352f8829a4aSRandall Stewart 	    (controlp == NULL)) {
6353f8829a4aSRandall Stewart 		/* user does not want the sndrcv ctl */
6354f8829a4aSRandall Stewart 		filling_sinfo = 0;
6355f8829a4aSRandall Stewart 	}
6356f8829a4aSRandall Stewart 	if (psa) {
6357f8829a4aSRandall Stewart 		from = (struct sockaddr *)sockbuf;
6358f8829a4aSRandall Stewart 		fromlen = sizeof(sockbuf);
6359f8829a4aSRandall Stewart 		from->sa_len = 0;
6360f8829a4aSRandall Stewart 	} else {
6361f8829a4aSRandall Stewart 		from = NULL;
6362f8829a4aSRandall Stewart 		fromlen = 0;
6363f8829a4aSRandall Stewart 	}
6364f8829a4aSRandall Stewart 
6365e432298aSXin LI 	if (filling_sinfo) {
6366e432298aSXin LI 		memset(&sinfo, 0, sizeof(struct sctp_extrcvinfo));
6367e432298aSXin LI 	}
6368f8829a4aSRandall Stewart 	error = sctp_sorecvmsg(so, uio, mp0, from, fromlen, flagsp,
6369f8829a4aSRandall Stewart 	    (struct sctp_sndrcvinfo *)&sinfo, filling_sinfo);
6370e432298aSXin LI 	if (controlp != NULL) {
6371f8829a4aSRandall Stewart 		/* copy back the sinfo in a CMSG format */
6372f8829a4aSRandall Stewart 		if (filling_sinfo)
6373f8829a4aSRandall Stewart 			*controlp = sctp_build_ctl_nchunk(inp,
6374f8829a4aSRandall Stewart 			    (struct sctp_sndrcvinfo *)&sinfo);
6375f8829a4aSRandall Stewart 		else
6376f8829a4aSRandall Stewart 			*controlp = NULL;
6377f8829a4aSRandall Stewart 	}
6378f8829a4aSRandall Stewart 	if (psa) {
6379f8829a4aSRandall Stewart 		/* copy back the address info */
6380f8829a4aSRandall Stewart 		if (from && from->sa_len) {
6381f8829a4aSRandall Stewart 			*psa = sodupsockaddr(from, M_NOWAIT);
6382f8829a4aSRandall Stewart 		} else {
6383f8829a4aSRandall Stewart 			*psa = NULL;
6384f8829a4aSRandall Stewart 		}
6385f8829a4aSRandall Stewart 	}
6386f8829a4aSRandall Stewart 	return (error);
6387f8829a4aSRandall Stewart }
638817205eccSRandall Stewart 
638917205eccSRandall Stewart 
639017205eccSRandall Stewart 
639117205eccSRandall Stewart 
639217205eccSRandall Stewart 
639317205eccSRandall Stewart int
6394d61a0ae0SRandall Stewart sctp_connectx_helper_add(struct sctp_tcb *stcb, struct sockaddr *addr,
6395d61a0ae0SRandall Stewart     int totaddr, int *error)
639617205eccSRandall Stewart {
639717205eccSRandall Stewart 	int added = 0;
639817205eccSRandall Stewart 	int i;
639917205eccSRandall Stewart 	struct sctp_inpcb *inp;
640017205eccSRandall Stewart 	struct sockaddr *sa;
640117205eccSRandall Stewart 	size_t incr = 0;
640217205eccSRandall Stewart 
640392776dfdSMichael Tuexen #ifdef INET
640492776dfdSMichael Tuexen 	struct sockaddr_in *sin;
640592776dfdSMichael Tuexen 
640692776dfdSMichael Tuexen #endif
640792776dfdSMichael Tuexen #ifdef INET6
640892776dfdSMichael Tuexen 	struct sockaddr_in6 *sin6;
640992776dfdSMichael Tuexen 
641092776dfdSMichael Tuexen #endif
641192776dfdSMichael Tuexen 
641217205eccSRandall Stewart 	sa = addr;
641317205eccSRandall Stewart 	inp = stcb->sctp_ep;
641417205eccSRandall Stewart 	*error = 0;
641517205eccSRandall Stewart 	for (i = 0; i < totaddr; i++) {
6416ea5eba11SMichael Tuexen 		switch (sa->sa_family) {
6417ea5eba11SMichael Tuexen #ifdef INET
6418ea5eba11SMichael Tuexen 		case AF_INET:
641917205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in);
642092776dfdSMichael Tuexen 			sin = (struct sockaddr_in *)sa;
642192776dfdSMichael Tuexen 			if ((sin->sin_addr.s_addr == INADDR_ANY) ||
642292776dfdSMichael Tuexen 			    (sin->sin_addr.s_addr == INADDR_BROADCAST) ||
642392776dfdSMichael Tuexen 			    IN_MULTICAST(ntohl(sin->sin_addr.s_addr))) {
642492776dfdSMichael Tuexen 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6425ba785902SMichael Tuexen 				(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
6426ba785902SMichael Tuexen 				    SCTP_FROM_SCTPUTIL + SCTP_LOC_7);
642792776dfdSMichael Tuexen 				*error = EINVAL;
642892776dfdSMichael Tuexen 				goto out_now;
642992776dfdSMichael Tuexen 			}
6430ca85e948SMichael Tuexen 			if (sctp_add_remote_addr(stcb, sa, NULL, SCTP_DONOT_SETSCOPE, SCTP_ADDR_IS_CONFIRMED)) {
643117205eccSRandall Stewart 				/* assoc gone no un-lock */
6432c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOBUFS);
6433ba785902SMichael Tuexen 				(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
6434ba785902SMichael Tuexen 				    SCTP_FROM_SCTPUTIL + SCTP_LOC_8);
643517205eccSRandall Stewart 				*error = ENOBUFS;
643617205eccSRandall Stewart 				goto out_now;
643717205eccSRandall Stewart 			}
643817205eccSRandall Stewart 			added++;
6439ea5eba11SMichael Tuexen 			break;
6440ea5eba11SMichael Tuexen #endif
6441ea5eba11SMichael Tuexen #ifdef INET6
6442ea5eba11SMichael Tuexen 		case AF_INET6:
644317205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in6);
644492776dfdSMichael Tuexen 			sin6 = (struct sockaddr_in6 *)sa;
644592776dfdSMichael Tuexen 			if (IN6_IS_ADDR_UNSPECIFIED(&sin6->sin6_addr) ||
644692776dfdSMichael Tuexen 			    IN6_IS_ADDR_MULTICAST(&sin6->sin6_addr)) {
644792776dfdSMichael Tuexen 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6448ba785902SMichael Tuexen 				(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
6449ba785902SMichael Tuexen 				    SCTP_FROM_SCTPUTIL + SCTP_LOC_9);
645092776dfdSMichael Tuexen 				*error = EINVAL;
645192776dfdSMichael Tuexen 				goto out_now;
645292776dfdSMichael Tuexen 			}
6453ca85e948SMichael Tuexen 			if (sctp_add_remote_addr(stcb, sa, NULL, SCTP_DONOT_SETSCOPE, SCTP_ADDR_IS_CONFIRMED)) {
645417205eccSRandall Stewart 				/* assoc gone no un-lock */
6455c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOBUFS);
6456ba785902SMichael Tuexen 				(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC,
6457ba785902SMichael Tuexen 				    SCTP_FROM_SCTPUTIL + SCTP_LOC_10);
645817205eccSRandall Stewart 				*error = ENOBUFS;
645917205eccSRandall Stewart 				goto out_now;
646017205eccSRandall Stewart 			}
646117205eccSRandall Stewart 			added++;
6462ea5eba11SMichael Tuexen 			break;
6463ea5eba11SMichael Tuexen #endif
6464ea5eba11SMichael Tuexen 		default:
6465ea5eba11SMichael Tuexen 			break;
646617205eccSRandall Stewart 		}
646717205eccSRandall Stewart 		sa = (struct sockaddr *)((caddr_t)sa + incr);
646817205eccSRandall Stewart 	}
646917205eccSRandall Stewart out_now:
647017205eccSRandall Stewart 	return (added);
647117205eccSRandall Stewart }
647217205eccSRandall Stewart 
647317205eccSRandall Stewart struct sctp_tcb *
6474d61a0ae0SRandall Stewart sctp_connectx_helper_find(struct sctp_inpcb *inp, struct sockaddr *addr,
64759a8e3088SMichael Tuexen     unsigned int *totaddr,
64769a8e3088SMichael Tuexen     unsigned int *num_v4, unsigned int *num_v6, int *error,
64779a8e3088SMichael Tuexen     unsigned int limit, int *bad_addr)
647817205eccSRandall Stewart {
647917205eccSRandall Stewart 	struct sockaddr *sa;
648017205eccSRandall Stewart 	struct sctp_tcb *stcb = NULL;
64819a8e3088SMichael Tuexen 	unsigned int incr, at, i;
648217205eccSRandall Stewart 
648317205eccSRandall Stewart 	at = incr = 0;
648417205eccSRandall Stewart 	sa = addr;
648517205eccSRandall Stewart 	*error = *num_v6 = *num_v4 = 0;
648617205eccSRandall Stewart 	/* account and validate addresses */
64879a8e3088SMichael Tuexen 	for (i = 0; i < *totaddr; i++) {
6488ea5eba11SMichael Tuexen 		switch (sa->sa_family) {
6489ea5eba11SMichael Tuexen #ifdef INET
6490ea5eba11SMichael Tuexen 		case AF_INET:
6491d61a0ae0SRandall Stewart 			if (sa->sa_len != incr) {
6492c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6493d61a0ae0SRandall Stewart 				*error = EINVAL;
6494d61a0ae0SRandall Stewart 				*bad_addr = 1;
6495d61a0ae0SRandall Stewart 				return (NULL);
6496d61a0ae0SRandall Stewart 			}
64979a8e3088SMichael Tuexen 			(*num_v4) += 1;
64989a8e3088SMichael Tuexen 			incr = (unsigned int)sizeof(struct sockaddr_in);
6499ea5eba11SMichael Tuexen 			break;
6500ea5eba11SMichael Tuexen #endif
6501ea5eba11SMichael Tuexen #ifdef INET6
6502ea5eba11SMichael Tuexen 		case AF_INET6:
6503ea5eba11SMichael Tuexen 			{
650417205eccSRandall Stewart 				struct sockaddr_in6 *sin6;
650517205eccSRandall Stewart 
650617205eccSRandall Stewart 				sin6 = (struct sockaddr_in6 *)sa;
650717205eccSRandall Stewart 				if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
650817205eccSRandall Stewart 					/* Must be non-mapped for connectx */
6509c4739e2fSRandall Stewart 					SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
651017205eccSRandall Stewart 					*error = EINVAL;
6511d61a0ae0SRandall Stewart 					*bad_addr = 1;
651217205eccSRandall Stewart 					return (NULL);
651317205eccSRandall Stewart 				}
6514d61a0ae0SRandall Stewart 				if (sa->sa_len != incr) {
6515c4739e2fSRandall Stewart 					SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6516d61a0ae0SRandall Stewart 					*error = EINVAL;
6517d61a0ae0SRandall Stewart 					*bad_addr = 1;
6518d61a0ae0SRandall Stewart 					return (NULL);
6519d61a0ae0SRandall Stewart 				}
65209a8e3088SMichael Tuexen 				(*num_v6) += 1;
65219a8e3088SMichael Tuexen 				incr = (unsigned int)sizeof(struct sockaddr_in6);
6522ea5eba11SMichael Tuexen 				break;
6523ea5eba11SMichael Tuexen 			}
6524ea5eba11SMichael Tuexen #endif
6525ea5eba11SMichael Tuexen 		default:
652617205eccSRandall Stewart 			*totaddr = i;
652717205eccSRandall Stewart 			/* we are done */
652817205eccSRandall Stewart 			break;
652917205eccSRandall Stewart 		}
65309a8e3088SMichael Tuexen 		if (i == *totaddr) {
6531ea5eba11SMichael Tuexen 			break;
6532ea5eba11SMichael Tuexen 		}
6533d61a0ae0SRandall Stewart 		SCTP_INP_INCR_REF(inp);
653417205eccSRandall Stewart 		stcb = sctp_findassociation_ep_addr(&inp, sa, NULL, NULL, NULL);
653517205eccSRandall Stewart 		if (stcb != NULL) {
653617205eccSRandall Stewart 			/* Already have or am bring up an association */
653717205eccSRandall Stewart 			return (stcb);
6538d61a0ae0SRandall Stewart 		} else {
6539d61a0ae0SRandall Stewart 			SCTP_INP_DECR_REF(inp);
654017205eccSRandall Stewart 		}
65419a8e3088SMichael Tuexen 		if ((at + incr) > limit) {
654217205eccSRandall Stewart 			*totaddr = i;
654317205eccSRandall Stewart 			break;
654417205eccSRandall Stewart 		}
654517205eccSRandall Stewart 		sa = (struct sockaddr *)((caddr_t)sa + incr);
654617205eccSRandall Stewart 	}
654717205eccSRandall Stewart 	return ((struct sctp_tcb *)NULL);
654817205eccSRandall Stewart }
654935918f85SRandall Stewart 
655035918f85SRandall Stewart /*
655135918f85SRandall Stewart  * sctp_bindx(ADD) for one address.
655235918f85SRandall Stewart  * assumes all arguments are valid/checked by caller.
655335918f85SRandall Stewart  */
655435918f85SRandall Stewart void
655535918f85SRandall Stewart sctp_bindx_add_address(struct socket *so, struct sctp_inpcb *inp,
655635918f85SRandall Stewart     struct sockaddr *sa, sctp_assoc_t assoc_id,
655735918f85SRandall Stewart     uint32_t vrf_id, int *error, void *p)
655835918f85SRandall Stewart {
655935918f85SRandall Stewart 	struct sockaddr *addr_touse;
65605e2c2d87SRandall Stewart 
6561d59107f7SMichael Tuexen #if defined(INET) && defined(INET6)
656235918f85SRandall Stewart 	struct sockaddr_in sin;
656335918f85SRandall Stewart 
65645e2c2d87SRandall Stewart #endif
65655e2c2d87SRandall Stewart 
656635918f85SRandall Stewart 	/* see if we're bound all already! */
656735918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
6568c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
656935918f85SRandall Stewart 		*error = EINVAL;
657035918f85SRandall Stewart 		return;
657135918f85SRandall Stewart 	}
657235918f85SRandall Stewart 	addr_touse = sa;
6573ea5eba11SMichael Tuexen #ifdef INET6
657435918f85SRandall Stewart 	if (sa->sa_family == AF_INET6) {
6575d59107f7SMichael Tuexen #ifdef INET
657635918f85SRandall Stewart 		struct sockaddr_in6 *sin6;
657735918f85SRandall Stewart 
6578d59107f7SMichael Tuexen #endif
657935918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in6)) {
6580c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
658135918f85SRandall Stewart 			*error = EINVAL;
658235918f85SRandall Stewart 			return;
658335918f85SRandall Stewart 		}
6584db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) == 0) {
6585db4fd95bSRandall Stewart 			/* can only bind v6 on PF_INET6 sockets */
6586c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6587db4fd95bSRandall Stewart 			*error = EINVAL;
6588db4fd95bSRandall Stewart 			return;
6589db4fd95bSRandall Stewart 		}
6590d59107f7SMichael Tuexen #ifdef INET
659135918f85SRandall Stewart 		sin6 = (struct sockaddr_in6 *)addr_touse;
659235918f85SRandall Stewart 		if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
6593db4fd95bSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6594db4fd95bSRandall Stewart 			    SCTP_IPV6_V6ONLY(inp)) {
6595db4fd95bSRandall Stewart 				/* can't bind v4-mapped on PF_INET sockets */
6596c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6597db4fd95bSRandall Stewart 				*error = EINVAL;
6598db4fd95bSRandall Stewart 				return;
6599db4fd95bSRandall Stewart 			}
660035918f85SRandall Stewart 			in6_sin6_2_sin(&sin, sin6);
660135918f85SRandall Stewart 			addr_touse = (struct sockaddr *)&sin;
660235918f85SRandall Stewart 		}
6603d59107f7SMichael Tuexen #endif
660435918f85SRandall Stewart 	}
660535918f85SRandall Stewart #endif
6606ea5eba11SMichael Tuexen #ifdef INET
660735918f85SRandall Stewart 	if (sa->sa_family == AF_INET) {
660835918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in)) {
6609c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
661035918f85SRandall Stewart 			*error = EINVAL;
661135918f85SRandall Stewart 			return;
661235918f85SRandall Stewart 		}
6613db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6614db4fd95bSRandall Stewart 		    SCTP_IPV6_V6ONLY(inp)) {
6615db4fd95bSRandall Stewart 			/* can't bind v4 on PF_INET sockets */
6616c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6617db4fd95bSRandall Stewart 			*error = EINVAL;
6618db4fd95bSRandall Stewart 			return;
6619db4fd95bSRandall Stewart 		}
662035918f85SRandall Stewart 	}
6621ea5eba11SMichael Tuexen #endif
662235918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_UNBOUND) {
662335918f85SRandall Stewart 		if (p == NULL) {
662435918f85SRandall Stewart 			/* Can't get proc for Net/Open BSD */
6625c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
662635918f85SRandall Stewart 			*error = EINVAL;
662735918f85SRandall Stewart 			return;
662835918f85SRandall Stewart 		}
66291b649582SRandall Stewart 		*error = sctp_inpcb_bind(so, addr_touse, NULL, p);
663035918f85SRandall Stewart 		return;
663135918f85SRandall Stewart 	}
663235918f85SRandall Stewart 	/*
663335918f85SRandall Stewart 	 * No locks required here since bind and mgmt_ep_sa all do their own
663435918f85SRandall Stewart 	 * locking. If we do something for the FIX: below we may need to
663535918f85SRandall Stewart 	 * lock in that case.
663635918f85SRandall Stewart 	 */
663735918f85SRandall Stewart 	if (assoc_id == 0) {
663835918f85SRandall Stewart 		/* add the address */
663935918f85SRandall Stewart 		struct sctp_inpcb *lep;
664097c76f10SRandall Stewart 		struct sockaddr_in *lsin = (struct sockaddr_in *)addr_touse;
664135918f85SRandall Stewart 
664297c76f10SRandall Stewart 		/* validate the incoming port */
664397c76f10SRandall Stewart 		if ((lsin->sin_port != 0) &&
664497c76f10SRandall Stewart 		    (lsin->sin_port != inp->sctp_lport)) {
6645c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
664697c76f10SRandall Stewart 			*error = EINVAL;
664797c76f10SRandall Stewart 			return;
664897c76f10SRandall Stewart 		} else {
664997c76f10SRandall Stewart 			/* user specified 0 port, set it to existing port */
665097c76f10SRandall Stewart 			lsin->sin_port = inp->sctp_lport;
665197c76f10SRandall Stewart 		}
665297c76f10SRandall Stewart 
665335918f85SRandall Stewart 		lep = sctp_pcb_findep(addr_touse, 1, 0, vrf_id);
665435918f85SRandall Stewart 		if (lep != NULL) {
665535918f85SRandall Stewart 			/*
665635918f85SRandall Stewart 			 * We must decrement the refcount since we have the
665735918f85SRandall Stewart 			 * ep already and are binding. No remove going on
665835918f85SRandall Stewart 			 * here.
665935918f85SRandall Stewart 			 */
66606d9e8f2bSRandall Stewart 			SCTP_INP_DECR_REF(lep);
666135918f85SRandall Stewart 		}
666235918f85SRandall Stewart 		if (lep == inp) {
666335918f85SRandall Stewart 			/* already bound to it.. ok */
666435918f85SRandall Stewart 			return;
666535918f85SRandall Stewart 		} else if (lep == NULL) {
666635918f85SRandall Stewart 			((struct sockaddr_in *)addr_touse)->sin_port = 0;
666735918f85SRandall Stewart 			*error = sctp_addr_mgmt_ep_sa(inp, addr_touse,
666835918f85SRandall Stewart 			    SCTP_ADD_IP_ADDRESS,
666980fefe0aSRandall Stewart 			    vrf_id, NULL);
667035918f85SRandall Stewart 		} else {
667135918f85SRandall Stewart 			*error = EADDRINUSE;
667235918f85SRandall Stewart 		}
667335918f85SRandall Stewart 		if (*error)
667435918f85SRandall Stewart 			return;
667535918f85SRandall Stewart 	} else {
667635918f85SRandall Stewart 		/*
667735918f85SRandall Stewart 		 * FIX: decide whether we allow assoc based bindx
667835918f85SRandall Stewart 		 */
667935918f85SRandall Stewart 	}
668035918f85SRandall Stewart }
668135918f85SRandall Stewart 
668235918f85SRandall Stewart /*
668335918f85SRandall Stewart  * sctp_bindx(DELETE) for one address.
668435918f85SRandall Stewart  * assumes all arguments are valid/checked by caller.
668535918f85SRandall Stewart  */
668635918f85SRandall Stewart void
66877215cc1bSMichael Tuexen sctp_bindx_delete_address(struct sctp_inpcb *inp,
668835918f85SRandall Stewart     struct sockaddr *sa, sctp_assoc_t assoc_id,
668935918f85SRandall Stewart     uint32_t vrf_id, int *error)
669035918f85SRandall Stewart {
669135918f85SRandall Stewart 	struct sockaddr *addr_touse;
66925e2c2d87SRandall Stewart 
6693d59107f7SMichael Tuexen #if defined(INET) && defined(INET6)
669435918f85SRandall Stewart 	struct sockaddr_in sin;
669535918f85SRandall Stewart 
66965e2c2d87SRandall Stewart #endif
66975e2c2d87SRandall Stewart 
669835918f85SRandall Stewart 	/* see if we're bound all already! */
669935918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
6700c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
670135918f85SRandall Stewart 		*error = EINVAL;
670235918f85SRandall Stewart 		return;
670335918f85SRandall Stewart 	}
670435918f85SRandall Stewart 	addr_touse = sa;
6705e0e00a4dSMichael Tuexen #ifdef INET6
670635918f85SRandall Stewart 	if (sa->sa_family == AF_INET6) {
6707d59107f7SMichael Tuexen #ifdef INET
670835918f85SRandall Stewart 		struct sockaddr_in6 *sin6;
670935918f85SRandall Stewart 
6710d59107f7SMichael Tuexen #endif
6711d59107f7SMichael Tuexen 
671235918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in6)) {
6713c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
671435918f85SRandall Stewart 			*error = EINVAL;
671535918f85SRandall Stewart 			return;
671635918f85SRandall Stewart 		}
6717db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) == 0) {
6718db4fd95bSRandall Stewart 			/* can only bind v6 on PF_INET6 sockets */
6719c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6720db4fd95bSRandall Stewart 			*error = EINVAL;
6721db4fd95bSRandall Stewart 			return;
6722db4fd95bSRandall Stewart 		}
6723d59107f7SMichael Tuexen #ifdef INET
672435918f85SRandall Stewart 		sin6 = (struct sockaddr_in6 *)addr_touse;
672535918f85SRandall Stewart 		if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
6726db4fd95bSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6727db4fd95bSRandall Stewart 			    SCTP_IPV6_V6ONLY(inp)) {
6728db4fd95bSRandall Stewart 				/* can't bind mapped-v4 on PF_INET sockets */
6729c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6730db4fd95bSRandall Stewart 				*error = EINVAL;
6731db4fd95bSRandall Stewart 				return;
6732db4fd95bSRandall Stewart 			}
673335918f85SRandall Stewart 			in6_sin6_2_sin(&sin, sin6);
673435918f85SRandall Stewart 			addr_touse = (struct sockaddr *)&sin;
673535918f85SRandall Stewart 		}
6736d59107f7SMichael Tuexen #endif
673735918f85SRandall Stewart 	}
673835918f85SRandall Stewart #endif
6739ea5eba11SMichael Tuexen #ifdef INET
674035918f85SRandall Stewart 	if (sa->sa_family == AF_INET) {
674135918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in)) {
6742c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
674335918f85SRandall Stewart 			*error = EINVAL;
674435918f85SRandall Stewart 			return;
674535918f85SRandall Stewart 		}
6746db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6747db4fd95bSRandall Stewart 		    SCTP_IPV6_V6ONLY(inp)) {
6748db4fd95bSRandall Stewart 			/* can't bind v4 on PF_INET sockets */
6749c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6750db4fd95bSRandall Stewart 			*error = EINVAL;
6751db4fd95bSRandall Stewart 			return;
6752db4fd95bSRandall Stewart 		}
675335918f85SRandall Stewart 	}
6754ea5eba11SMichael Tuexen #endif
675535918f85SRandall Stewart 	/*
675635918f85SRandall Stewart 	 * No lock required mgmt_ep_sa does its own locking. If the FIX:
675735918f85SRandall Stewart 	 * below is ever changed we may need to lock before calling
675835918f85SRandall Stewart 	 * association level binding.
675935918f85SRandall Stewart 	 */
676035918f85SRandall Stewart 	if (assoc_id == 0) {
676135918f85SRandall Stewart 		/* delete the address */
676235918f85SRandall Stewart 		*error = sctp_addr_mgmt_ep_sa(inp, addr_touse,
676335918f85SRandall Stewart 		    SCTP_DEL_IP_ADDRESS,
676480fefe0aSRandall Stewart 		    vrf_id, NULL);
676535918f85SRandall Stewart 	} else {
676635918f85SRandall Stewart 		/*
676735918f85SRandall Stewart 		 * FIX: decide whether we allow assoc based bindx
676835918f85SRandall Stewart 		 */
676935918f85SRandall Stewart 	}
677035918f85SRandall Stewart }
67711b649582SRandall Stewart 
67721b649582SRandall Stewart /*
67731b649582SRandall Stewart  * returns the valid local address count for an assoc, taking into account
67741b649582SRandall Stewart  * all scoping rules
67751b649582SRandall Stewart  */
67761b649582SRandall Stewart int
67771b649582SRandall Stewart sctp_local_addr_count(struct sctp_tcb *stcb)
67781b649582SRandall Stewart {
6779b54ddf22SMichael Tuexen 	int loopback_scope;
6780b54ddf22SMichael Tuexen 
6781b54ddf22SMichael Tuexen #if defined(INET)
6782b54ddf22SMichael Tuexen 	int ipv4_local_scope, ipv4_addr_legal;
6783b54ddf22SMichael Tuexen 
6784b54ddf22SMichael Tuexen #endif
6785b54ddf22SMichael Tuexen #if defined (INET6)
6786b54ddf22SMichael Tuexen 	int local_scope, site_scope, ipv6_addr_legal;
6787b54ddf22SMichael Tuexen 
6788b54ddf22SMichael Tuexen #endif
67891b649582SRandall Stewart 	struct sctp_vrf *vrf;
67901b649582SRandall Stewart 	struct sctp_ifn *sctp_ifn;
67911b649582SRandall Stewart 	struct sctp_ifa *sctp_ifa;
67921b649582SRandall Stewart 	int count = 0;
67931b649582SRandall Stewart 
67941b649582SRandall Stewart 	/* Turn on all the appropriate scopes */
6795a1cb341bSMichael Tuexen 	loopback_scope = stcb->asoc.scope.loopback_scope;
6796b54ddf22SMichael Tuexen #if defined(INET)
6797a1cb341bSMichael Tuexen 	ipv4_local_scope = stcb->asoc.scope.ipv4_local_scope;
6798b54ddf22SMichael Tuexen 	ipv4_addr_legal = stcb->asoc.scope.ipv4_addr_legal;
6799b54ddf22SMichael Tuexen #endif
6800b54ddf22SMichael Tuexen #if defined(INET6)
6801a1cb341bSMichael Tuexen 	local_scope = stcb->asoc.scope.local_scope;
6802a1cb341bSMichael Tuexen 	site_scope = stcb->asoc.scope.site_scope;
6803a1cb341bSMichael Tuexen 	ipv6_addr_legal = stcb->asoc.scope.ipv6_addr_legal;
6804b54ddf22SMichael Tuexen #endif
6805c99efcf6SRandall Stewart 	SCTP_IPI_ADDR_RLOCK();
68061b649582SRandall Stewart 	vrf = sctp_find_vrf(stcb->asoc.vrf_id);
68071b649582SRandall Stewart 	if (vrf == NULL) {
68081b649582SRandall Stewart 		/* no vrf, no addresses */
6809c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RUNLOCK();
68101b649582SRandall Stewart 		return (0);
68111b649582SRandall Stewart 	}
68121b649582SRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
68131b649582SRandall Stewart 		/*
68141b649582SRandall Stewart 		 * bound all case: go through all ifns on the vrf
68151b649582SRandall Stewart 		 */
68161b649582SRandall Stewart 		LIST_FOREACH(sctp_ifn, &vrf->ifnlist, next_ifn) {
68171b649582SRandall Stewart 			if ((loopback_scope == 0) &&
68181b649582SRandall Stewart 			    SCTP_IFN_IS_IFT_LOOP(sctp_ifn)) {
68191b649582SRandall Stewart 				continue;
68201b649582SRandall Stewart 			}
68211b649582SRandall Stewart 			LIST_FOREACH(sctp_ifa, &sctp_ifn->ifalist, next_ifa) {
68221b649582SRandall Stewart 				if (sctp_is_addr_restricted(stcb, sctp_ifa))
68231b649582SRandall Stewart 					continue;
68245e2c2d87SRandall Stewart 				switch (sctp_ifa->address.sa.sa_family) {
6825ea5eba11SMichael Tuexen #ifdef INET
68265e2c2d87SRandall Stewart 				case AF_INET:
68275e2c2d87SRandall Stewart 					if (ipv4_addr_legal) {
68281b649582SRandall Stewart 						struct sockaddr_in *sin;
68291b649582SRandall Stewart 
683024aaac8dSMichael Tuexen 						sin = &sctp_ifa->address.sin;
68311b649582SRandall Stewart 						if (sin->sin_addr.s_addr == 0) {
68325e2c2d87SRandall Stewart 							/*
68335e2c2d87SRandall Stewart 							 * skip unspecified
68345e2c2d87SRandall Stewart 							 * addrs
68355e2c2d87SRandall Stewart 							 */
68361b649582SRandall Stewart 							continue;
68371b649582SRandall Stewart 						}
68386ba22f19SMichael Tuexen 						if (prison_check_ip4(stcb->sctp_ep->ip_inp.inp.inp_cred,
68396ba22f19SMichael Tuexen 						    &sin->sin_addr) != 0) {
68406ba22f19SMichael Tuexen 							continue;
68416ba22f19SMichael Tuexen 						}
68421b649582SRandall Stewart 						if ((ipv4_local_scope == 0) &&
68431b649582SRandall Stewart 						    (IN4_ISPRIVATE_ADDRESS(&sin->sin_addr))) {
68441b649582SRandall Stewart 							continue;
68451b649582SRandall Stewart 						}
68461b649582SRandall Stewart 						/* count this one */
68471b649582SRandall Stewart 						count++;
68485e2c2d87SRandall Stewart 					} else {
68495e2c2d87SRandall Stewart 						continue;
68505e2c2d87SRandall Stewart 					}
68515e2c2d87SRandall Stewart 					break;
6852ea5eba11SMichael Tuexen #endif
68535e2c2d87SRandall Stewart #ifdef INET6
68545e2c2d87SRandall Stewart 				case AF_INET6:
68555e2c2d87SRandall Stewart 					if (ipv6_addr_legal) {
68561b649582SRandall Stewart 						struct sockaddr_in6 *sin6;
68571b649582SRandall Stewart 
685824aaac8dSMichael Tuexen 						sin6 = &sctp_ifa->address.sin6;
68591b649582SRandall Stewart 						if (IN6_IS_ADDR_UNSPECIFIED(&sin6->sin6_addr)) {
68601b649582SRandall Stewart 							continue;
68611b649582SRandall Stewart 						}
68626ba22f19SMichael Tuexen 						if (prison_check_ip6(stcb->sctp_ep->ip_inp.inp.inp_cred,
68636ba22f19SMichael Tuexen 						    &sin6->sin6_addr) != 0) {
68646ba22f19SMichael Tuexen 							continue;
68656ba22f19SMichael Tuexen 						}
68661b649582SRandall Stewart 						if (IN6_IS_ADDR_LINKLOCAL(&sin6->sin6_addr)) {
68671b649582SRandall Stewart 							if (local_scope == 0)
68681b649582SRandall Stewart 								continue;
68691b649582SRandall Stewart 							if (sin6->sin6_scope_id == 0) {
68701b649582SRandall Stewart 								if (sa6_recoverscope(sin6) != 0)
68711b649582SRandall Stewart 									/*
68725e2c2d87SRandall Stewart 									 *
68735e2c2d87SRandall Stewart 									 * bad
68745e2c2d87SRandall Stewart 									 *
68755e2c2d87SRandall Stewart 									 * li
68765e2c2d87SRandall Stewart 									 * nk
68775e2c2d87SRandall Stewart 									 *
68785e2c2d87SRandall Stewart 									 * loc
68795e2c2d87SRandall Stewart 									 * al
68805e2c2d87SRandall Stewart 									 *
68815e2c2d87SRandall Stewart 									 * add
68825e2c2d87SRandall Stewart 									 * re
68835e2c2d87SRandall Stewart 									 * ss
68845e2c2d87SRandall Stewart 									 * */
68851b649582SRandall Stewart 									continue;
68861b649582SRandall Stewart 							}
68871b649582SRandall Stewart 						}
68881b649582SRandall Stewart 						if ((site_scope == 0) &&
68891b649582SRandall Stewart 						    (IN6_IS_ADDR_SITELOCAL(&sin6->sin6_addr))) {
68901b649582SRandall Stewart 							continue;
68911b649582SRandall Stewart 						}
68921b649582SRandall Stewart 						/* count this one */
68931b649582SRandall Stewart 						count++;
68941b649582SRandall Stewart 					}
68955e2c2d87SRandall Stewart 					break;
68965e2c2d87SRandall Stewart #endif
68975e2c2d87SRandall Stewart 				default:
68985e2c2d87SRandall Stewart 					/* TSNH */
68995e2c2d87SRandall Stewart 					break;
69005e2c2d87SRandall Stewart 				}
69011b649582SRandall Stewart 			}
69021b649582SRandall Stewart 		}
69031b649582SRandall Stewart 	} else {
69041b649582SRandall Stewart 		/*
69051b649582SRandall Stewart 		 * subset bound case
69061b649582SRandall Stewart 		 */
69071b649582SRandall Stewart 		struct sctp_laddr *laddr;
69081b649582SRandall Stewart 
69091b649582SRandall Stewart 		LIST_FOREACH(laddr, &stcb->sctp_ep->sctp_addr_list,
69101b649582SRandall Stewart 		    sctp_nxt_addr) {
69111b649582SRandall Stewart 			if (sctp_is_addr_restricted(stcb, laddr->ifa)) {
69121b649582SRandall Stewart 				continue;
69131b649582SRandall Stewart 			}
69141b649582SRandall Stewart 			/* count this one */
69151b649582SRandall Stewart 			count++;
69161b649582SRandall Stewart 		}
69171b649582SRandall Stewart 	}
6918c99efcf6SRandall Stewart 	SCTP_IPI_ADDR_RUNLOCK();
69191b649582SRandall Stewart 	return (count);
69201b649582SRandall Stewart }
6921c4739e2fSRandall Stewart 
6922c4739e2fSRandall Stewart #if defined(SCTP_LOCAL_TRACE_BUF)
6923c4739e2fSRandall Stewart 
6924c4739e2fSRandall Stewart void
6925b27a6b7dSRandall Stewart sctp_log_trace(uint32_t subsys, const char *str SCTP_UNUSED, uint32_t a, uint32_t b, uint32_t c, uint32_t d, uint32_t e, uint32_t f)
6926c4739e2fSRandall Stewart {
6927b27a6b7dSRandall Stewart 	uint32_t saveindex, newindex;
6928c4739e2fSRandall Stewart 
6929c4739e2fSRandall Stewart 	do {
6930b3f1ea41SRandall Stewart 		saveindex = SCTP_BASE_SYSCTL(sctp_log).index;
6931c4739e2fSRandall Stewart 		if (saveindex >= SCTP_MAX_LOGGING_SIZE) {
6932c4739e2fSRandall Stewart 			newindex = 1;
6933c4739e2fSRandall Stewart 		} else {
6934c4739e2fSRandall Stewart 			newindex = saveindex + 1;
6935c4739e2fSRandall Stewart 		}
6936b3f1ea41SRandall Stewart 	} while (atomic_cmpset_int(&SCTP_BASE_SYSCTL(sctp_log).index, saveindex, newindex) == 0);
6937c4739e2fSRandall Stewart 	if (saveindex >= SCTP_MAX_LOGGING_SIZE) {
6938c4739e2fSRandall Stewart 		saveindex = 0;
6939c4739e2fSRandall Stewart 	}
6940b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].timestamp = SCTP_GET_CYCLECOUNT;
6941b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].subsys = subsys;
6942b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[0] = a;
6943b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[1] = b;
6944b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[2] = c;
6945b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[3] = d;
6946b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[4] = e;
6947b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[5] = f;
6948c4739e2fSRandall Stewart }
6949c4739e2fSRandall Stewart 
6950c4739e2fSRandall Stewart #endif
6951a99b6783SRandall Stewart static void
69527cca1775SRandall Stewart sctp_recv_udp_tunneled_packet(struct mbuf *m, int off, struct inpcb *inp,
695381d3ec17SBryan Venteicher     const struct sockaddr *sa SCTP_UNUSED, void *ctx SCTP_UNUSED)
6954a99b6783SRandall Stewart {
6955a99b6783SRandall Stewart 	struct ip *iph;
69563a51a264SMichael Tuexen 
69573a51a264SMichael Tuexen #ifdef INET6
69583a51a264SMichael Tuexen 	struct ip6_hdr *ip6;
69593a51a264SMichael Tuexen 
69603a51a264SMichael Tuexen #endif
6961a99b6783SRandall Stewart 	struct mbuf *sp, *last;
6962a99b6783SRandall Stewart 	struct udphdr *uhdr;
6963285052f0SMichael Tuexen 	uint16_t port;
6964a99b6783SRandall Stewart 
6965a99b6783SRandall Stewart 	if ((m->m_flags & M_PKTHDR) == 0) {
6966a99b6783SRandall Stewart 		/* Can't handle one that is not a pkt hdr */
6967a99b6783SRandall Stewart 		goto out;
6968a99b6783SRandall Stewart 	}
6969285052f0SMichael Tuexen 	/* Pull the src port */
6970a99b6783SRandall Stewart 	iph = mtod(m, struct ip *);
6971a99b6783SRandall Stewart 	uhdr = (struct udphdr *)((caddr_t)iph + off);
6972a99b6783SRandall Stewart 	port = uhdr->uh_sport;
6973285052f0SMichael Tuexen 	/*
6974285052f0SMichael Tuexen 	 * Split out the mbuf chain. Leave the IP header in m, place the
6975285052f0SMichael Tuexen 	 * rest in the sp.
6976285052f0SMichael Tuexen 	 */
6977eb1b1807SGleb Smirnoff 	sp = m_split(m, off, M_NOWAIT);
6978a99b6783SRandall Stewart 	if (sp == NULL) {
6979a99b6783SRandall Stewart 		/* Gak, drop packet, we can't do a split */
6980a99b6783SRandall Stewart 		goto out;
6981a99b6783SRandall Stewart 	}
6982285052f0SMichael Tuexen 	if (sp->m_pkthdr.len < sizeof(struct udphdr) + sizeof(struct sctphdr)) {
6983285052f0SMichael Tuexen 		/* Gak, packet can't have an SCTP header in it - too small */
6984a99b6783SRandall Stewart 		m_freem(sp);
6985a99b6783SRandall Stewart 		goto out;
6986a99b6783SRandall Stewart 	}
6987285052f0SMichael Tuexen 	/* Now pull up the UDP header and SCTP header together */
6988285052f0SMichael Tuexen 	sp = m_pullup(sp, sizeof(struct udphdr) + sizeof(struct sctphdr));
6989a99b6783SRandall Stewart 	if (sp == NULL) {
6990a99b6783SRandall Stewart 		/* Gak pullup failed */
6991a99b6783SRandall Stewart 		goto out;
6992a99b6783SRandall Stewart 	}
6993285052f0SMichael Tuexen 	/* Trim out the UDP header */
6994a99b6783SRandall Stewart 	m_adj(sp, sizeof(struct udphdr));
6995a99b6783SRandall Stewart 
6996a99b6783SRandall Stewart 	/* Now reconstruct the mbuf chain */
6997285052f0SMichael Tuexen 	for (last = m; last->m_next; last = last->m_next);
6998a99b6783SRandall Stewart 	last->m_next = sp;
6999a99b6783SRandall Stewart 	m->m_pkthdr.len += sp->m_pkthdr.len;
700052f175beSMichael Tuexen 	/*
700152f175beSMichael Tuexen 	 * The CSUM_DATA_VALID flags indicates that the HW checked the UDP
700252f175beSMichael Tuexen 	 * checksum and it was valid. Since CSUM_DATA_VALID ==
700352f175beSMichael Tuexen 	 * CSUM_SCTP_VALID this would imply that the HW also verified the
700452f175beSMichael Tuexen 	 * SCTP checksum. Therefore, clear the bit.
700552f175beSMichael Tuexen 	 */
700652f175beSMichael Tuexen 	SCTPDBG(SCTP_DEBUG_CRCOFFLOAD,
700752f175beSMichael Tuexen 	    "sctp_recv_udp_tunneled_packet(): Packet of length %d received on %s with csum_flags 0x%b.\n",
700852f175beSMichael Tuexen 	    m->m_pkthdr.len,
700952f175beSMichael Tuexen 	    if_name(m->m_pkthdr.rcvif),
701052f175beSMichael Tuexen 	    (int)m->m_pkthdr.csum_flags, CSUM_BITS);
701152f175beSMichael Tuexen 	m->m_pkthdr.csum_flags &= ~CSUM_DATA_VALID;
7012a99b6783SRandall Stewart 	iph = mtod(m, struct ip *);
7013a99b6783SRandall Stewart 	switch (iph->ip_v) {
7014e6194c2eSMichael Tuexen #ifdef INET
7015a99b6783SRandall Stewart 	case IPVERSION:
701609c1c856SMichael Tuexen 		iph->ip_len = htons(ntohs(iph->ip_len) - sizeof(struct udphdr));
7017a99b6783SRandall Stewart 		sctp_input_with_port(m, off, port);
7018a99b6783SRandall Stewart 		break;
7019e6194c2eSMichael Tuexen #endif
7020a99b6783SRandall Stewart #ifdef INET6
7021a99b6783SRandall Stewart 	case IPV6_VERSION >> 4:
70223a51a264SMichael Tuexen 		ip6 = mtod(m, struct ip6_hdr *);
70233a51a264SMichael Tuexen 		ip6->ip6_plen = htons(ntohs(ip6->ip6_plen) - sizeof(struct udphdr));
70243a51a264SMichael Tuexen 		sctp6_input_with_port(&m, &off, port);
7025a99b6783SRandall Stewart 		break;
7026a99b6783SRandall Stewart #endif
7027a99b6783SRandall Stewart 	default:
7028285052f0SMichael Tuexen 		goto out;
7029a99b6783SRandall Stewart 		break;
7030a99b6783SRandall Stewart 	}
7031a99b6783SRandall Stewart 	return;
7032a99b6783SRandall Stewart out:
7033a99b6783SRandall Stewart 	m_freem(m);
7034a99b6783SRandall Stewart }
7035c54a18d2SRandall Stewart 
7036c54a18d2SRandall Stewart void
7037c54a18d2SRandall Stewart sctp_over_udp_stop(void)
7038c54a18d2SRandall Stewart {
7039a99b6783SRandall Stewart 	/*
7040a99b6783SRandall Stewart 	 * This function assumes sysctl caller holds sctp_sysctl_info_lock()
7041a99b6783SRandall Stewart 	 * for writting!
7042a99b6783SRandall Stewart 	 */
70433a51a264SMichael Tuexen #ifdef INET
70443a51a264SMichael Tuexen 	if (SCTP_BASE_INFO(udp4_tun_socket) != NULL) {
70453a51a264SMichael Tuexen 		soclose(SCTP_BASE_INFO(udp4_tun_socket));
70463a51a264SMichael Tuexen 		SCTP_BASE_INFO(udp4_tun_socket) = NULL;
7047c54a18d2SRandall Stewart 	}
70483a51a264SMichael Tuexen #endif
70493a51a264SMichael Tuexen #ifdef INET6
70503a51a264SMichael Tuexen 	if (SCTP_BASE_INFO(udp6_tun_socket) != NULL) {
70513a51a264SMichael Tuexen 		soclose(SCTP_BASE_INFO(udp6_tun_socket));
70523a51a264SMichael Tuexen 		SCTP_BASE_INFO(udp6_tun_socket) = NULL;
70533a51a264SMichael Tuexen 	}
70543a51a264SMichael Tuexen #endif
7055a99b6783SRandall Stewart }
7056ea5eba11SMichael Tuexen 
7057c54a18d2SRandall Stewart int
7058c54a18d2SRandall Stewart sctp_over_udp_start(void)
7059c54a18d2SRandall Stewart {
7060a99b6783SRandall Stewart 	uint16_t port;
7061a99b6783SRandall Stewart 	int ret;
7062a99b6783SRandall Stewart 
70633a51a264SMichael Tuexen #ifdef INET
70643a51a264SMichael Tuexen 	struct sockaddr_in sin;
70653a51a264SMichael Tuexen 
70663a51a264SMichael Tuexen #endif
70673a51a264SMichael Tuexen #ifdef INET6
70683a51a264SMichael Tuexen 	struct sockaddr_in6 sin6;
70693a51a264SMichael Tuexen 
70703a51a264SMichael Tuexen #endif
7071a99b6783SRandall Stewart 	/*
7072a99b6783SRandall Stewart 	 * This function assumes sysctl caller holds sctp_sysctl_info_lock()
7073a99b6783SRandall Stewart 	 * for writting!
7074a99b6783SRandall Stewart 	 */
7075a99b6783SRandall Stewart 	port = SCTP_BASE_SYSCTL(sctp_udp_tunneling_port);
70763a51a264SMichael Tuexen 	if (ntohs(port) == 0) {
7077a99b6783SRandall Stewart 		/* Must have a port set */
7078a99b6783SRandall Stewart 		return (EINVAL);
7079a99b6783SRandall Stewart 	}
70803a51a264SMichael Tuexen #ifdef INET
70813a51a264SMichael Tuexen 	if (SCTP_BASE_INFO(udp4_tun_socket) != NULL) {
7082a99b6783SRandall Stewart 		/* Already running -- must stop first */
7083a99b6783SRandall Stewart 		return (EALREADY);
7084a99b6783SRandall Stewart 	}
70853a51a264SMichael Tuexen #endif
70863a51a264SMichael Tuexen #ifdef INET6
70873a51a264SMichael Tuexen 	if (SCTP_BASE_INFO(udp6_tun_socket) != NULL) {
70883a51a264SMichael Tuexen 		/* Already running -- must stop first */
70893a51a264SMichael Tuexen 		return (EALREADY);
7090a99b6783SRandall Stewart 	}
70913a51a264SMichael Tuexen #endif
70923a51a264SMichael Tuexen #ifdef INET
70933a51a264SMichael Tuexen 	if ((ret = socreate(PF_INET, &SCTP_BASE_INFO(udp4_tun_socket),
70943a51a264SMichael Tuexen 	    SOCK_DGRAM, IPPROTO_UDP,
70953a51a264SMichael Tuexen 	    curthread->td_ucred, curthread))) {
7096a99b6783SRandall Stewart 		sctp_over_udp_stop();
7097a99b6783SRandall Stewart 		return (ret);
7098a99b6783SRandall Stewart 	}
70993a51a264SMichael Tuexen 	/* Call the special UDP hook. */
71003a51a264SMichael Tuexen 	if ((ret = udp_set_kernel_tunneling(SCTP_BASE_INFO(udp4_tun_socket),
710181d3ec17SBryan Venteicher 	    sctp_recv_udp_tunneled_packet, NULL))) {
71023a51a264SMichael Tuexen 		sctp_over_udp_stop();
71033a51a264SMichael Tuexen 		return (ret);
71043a51a264SMichael Tuexen 	}
71053a51a264SMichael Tuexen 	/* Ok, we have a socket, bind it to the port. */
71063a51a264SMichael Tuexen 	memset(&sin, 0, sizeof(struct sockaddr_in));
71073a51a264SMichael Tuexen 	sin.sin_len = sizeof(struct sockaddr_in);
71083a51a264SMichael Tuexen 	sin.sin_family = AF_INET;
71093a51a264SMichael Tuexen 	sin.sin_port = htons(port);
71103a51a264SMichael Tuexen 	if ((ret = sobind(SCTP_BASE_INFO(udp4_tun_socket),
71113a51a264SMichael Tuexen 	    (struct sockaddr *)&sin, curthread))) {
71123a51a264SMichael Tuexen 		sctp_over_udp_stop();
71133a51a264SMichael Tuexen 		return (ret);
71143a51a264SMichael Tuexen 	}
71153a51a264SMichael Tuexen #endif
71163a51a264SMichael Tuexen #ifdef INET6
71173a51a264SMichael Tuexen 	if ((ret = socreate(PF_INET6, &SCTP_BASE_INFO(udp6_tun_socket),
71183a51a264SMichael Tuexen 	    SOCK_DGRAM, IPPROTO_UDP,
71193a51a264SMichael Tuexen 	    curthread->td_ucred, curthread))) {
71203a51a264SMichael Tuexen 		sctp_over_udp_stop();
71213a51a264SMichael Tuexen 		return (ret);
71223a51a264SMichael Tuexen 	}
71233a51a264SMichael Tuexen 	/* Call the special UDP hook. */
71243a51a264SMichael Tuexen 	if ((ret = udp_set_kernel_tunneling(SCTP_BASE_INFO(udp6_tun_socket),
712581d3ec17SBryan Venteicher 	    sctp_recv_udp_tunneled_packet, NULL))) {
71263a51a264SMichael Tuexen 		sctp_over_udp_stop();
71273a51a264SMichael Tuexen 		return (ret);
71283a51a264SMichael Tuexen 	}
71293a51a264SMichael Tuexen 	/* Ok, we have a socket, bind it to the port. */
71303a51a264SMichael Tuexen 	memset(&sin6, 0, sizeof(struct sockaddr_in6));
71313a51a264SMichael Tuexen 	sin6.sin6_len = sizeof(struct sockaddr_in6);
71323a51a264SMichael Tuexen 	sin6.sin6_family = AF_INET6;
71333a51a264SMichael Tuexen 	sin6.sin6_port = htons(port);
71343a51a264SMichael Tuexen 	if ((ret = sobind(SCTP_BASE_INFO(udp6_tun_socket),
71353a51a264SMichael Tuexen 	    (struct sockaddr *)&sin6, curthread))) {
71363a51a264SMichael Tuexen 		sctp_over_udp_stop();
71373a51a264SMichael Tuexen 		return (ret);
71383a51a264SMichael Tuexen 	}
71393a51a264SMichael Tuexen #endif
7140a99b6783SRandall Stewart 	return (0);
7141c54a18d2SRandall Stewart }
7142