xref: /freebsd/sys/netinet/sctputil.c (revision e2e7c62edc8bae58eb8db1b9d6e56e45c9692540)
1f8829a4aSRandall Stewart /*-
2830d754dSRandall Stewart  * Copyright (c) 2001-2008, by Cisco Systems, Inc. All rights reserved.
35d40cf5dSRandall Stewart  * Copyright (c) 2008-2011, by Randall Stewart. All rights reserved.
45d40cf5dSRandall Stewart  * Copyright (c) 2008-2011, by Michael Tuexen. All rights reserved.
5f8829a4aSRandall Stewart  *
6f8829a4aSRandall Stewart  * Redistribution and use in source and binary forms, with or without
7f8829a4aSRandall Stewart  * modification, are permitted provided that the following conditions are met:
8f8829a4aSRandall Stewart  *
9f8829a4aSRandall Stewart  * a) Redistributions of source code must retain the above copyright notice,
10f8829a4aSRandall Stewart  *   this list of conditions and the following disclaimer.
11f8829a4aSRandall Stewart  *
12f8829a4aSRandall Stewart  * b) Redistributions in binary form must reproduce the above copyright
13f8829a4aSRandall Stewart  *    notice, this list of conditions and the following disclaimer in
14f8829a4aSRandall Stewart  *   the documentation and/or other materials provided with the distribution.
15f8829a4aSRandall Stewart  *
16f8829a4aSRandall Stewart  * c) Neither the name of Cisco Systems, Inc. nor the names of its
17f8829a4aSRandall Stewart  *    contributors may be used to endorse or promote products derived
18f8829a4aSRandall Stewart  *    from this software without specific prior written permission.
19f8829a4aSRandall Stewart  *
20f8829a4aSRandall Stewart  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
21f8829a4aSRandall Stewart  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
22f8829a4aSRandall Stewart  * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
23f8829a4aSRandall Stewart  * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
24f8829a4aSRandall Stewart  * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
25f8829a4aSRandall Stewart  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
26f8829a4aSRandall Stewart  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
27f8829a4aSRandall Stewart  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
28f8829a4aSRandall Stewart  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
29f8829a4aSRandall Stewart  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
30f8829a4aSRandall Stewart  * THE POSSIBILITY OF SUCH DAMAGE.
31f8829a4aSRandall Stewart  */
32f8829a4aSRandall Stewart 
33f8829a4aSRandall Stewart /* $KAME: sctputil.c,v 1.37 2005/03/07 23:26:09 itojun Exp $	 */
34f8829a4aSRandall Stewart 
35f8829a4aSRandall Stewart #include <sys/cdefs.h>
36f8829a4aSRandall Stewart __FBSDID("$FreeBSD$");
37f8829a4aSRandall Stewart 
38f8829a4aSRandall Stewart #include <netinet/sctp_os.h>
39f8829a4aSRandall Stewart #include <netinet/sctp_pcb.h>
40f8829a4aSRandall Stewart #include <netinet/sctputil.h>
41f8829a4aSRandall Stewart #include <netinet/sctp_var.h>
4242551e99SRandall Stewart #include <netinet/sctp_sysctl.h>
43f8829a4aSRandall Stewart #ifdef INET6
44f8829a4aSRandall Stewart #endif
45f8829a4aSRandall Stewart #include <netinet/sctp_header.h>
46f8829a4aSRandall Stewart #include <netinet/sctp_output.h>
47f8829a4aSRandall Stewart #include <netinet/sctp_uio.h>
48f8829a4aSRandall Stewart #include <netinet/sctp_timer.h>
49f8829a4aSRandall Stewart #include <netinet/sctp_indata.h>/* for sctp_deliver_data() */
50f8829a4aSRandall Stewart #include <netinet/sctp_auth.h>
51f8829a4aSRandall Stewart #include <netinet/sctp_asconf.h>
52f7517433SRandall Stewart #include <netinet/sctp_bsd_addr.h>
53f8829a4aSRandall Stewart 
54f8829a4aSRandall Stewart 
55b9e7085aSRandall Stewart #ifndef KTR_SCTP
56b9e7085aSRandall Stewart #define KTR_SCTP KTR_SUBSYS
5780fefe0aSRandall Stewart #endif
58f8829a4aSRandall Stewart 
590e9a9c10SMichael Tuexen extern struct sctp_cc_functions sctp_cc_functions[];
60f7a77f6fSMichael Tuexen extern struct sctp_ss_functions sctp_ss_functions[];
610e9a9c10SMichael Tuexen 
62f8829a4aSRandall Stewart void
63f8829a4aSRandall Stewart sctp_sblog(struct sockbuf *sb,
64f8829a4aSRandall Stewart     struct sctp_tcb *stcb, int from, int incr)
65f8829a4aSRandall Stewart {
6680fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
67f8829a4aSRandall Stewart 
6880fefe0aSRandall Stewart 	sctp_clog.x.sb.stcb = stcb;
6980fefe0aSRandall Stewart 	sctp_clog.x.sb.so_sbcc = sb->sb_cc;
70f8829a4aSRandall Stewart 	if (stcb)
7180fefe0aSRandall Stewart 		sctp_clog.x.sb.stcb_sbcc = stcb->asoc.sb_cc;
72f8829a4aSRandall Stewart 	else
7380fefe0aSRandall Stewart 		sctp_clog.x.sb.stcb_sbcc = 0;
7480fefe0aSRandall Stewart 	sctp_clog.x.sb.incr = incr;
75c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
7680fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_SB,
7780fefe0aSRandall Stewart 	    from,
7880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
7980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
8080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
8180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
82f8829a4aSRandall Stewart }
83f8829a4aSRandall Stewart 
84f8829a4aSRandall Stewart void
85f8829a4aSRandall Stewart sctp_log_closing(struct sctp_inpcb *inp, struct sctp_tcb *stcb, int16_t loc)
86f8829a4aSRandall Stewart {
8780fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
88f8829a4aSRandall Stewart 
8980fefe0aSRandall Stewart 	sctp_clog.x.close.inp = (void *)inp;
9080fefe0aSRandall Stewart 	sctp_clog.x.close.sctp_flags = inp->sctp_flags;
91f8829a4aSRandall Stewart 	if (stcb) {
9280fefe0aSRandall Stewart 		sctp_clog.x.close.stcb = (void *)stcb;
9380fefe0aSRandall Stewart 		sctp_clog.x.close.state = (uint16_t) stcb->asoc.state;
94f8829a4aSRandall Stewart 	} else {
9580fefe0aSRandall Stewart 		sctp_clog.x.close.stcb = 0;
9680fefe0aSRandall Stewart 		sctp_clog.x.close.state = 0;
97f8829a4aSRandall Stewart 	}
9880fefe0aSRandall Stewart 	sctp_clog.x.close.loc = loc;
99c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
10080fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_CLOSE,
10180fefe0aSRandall Stewart 	    0,
10280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
10380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
10480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
10580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
106f8829a4aSRandall Stewart }
107f8829a4aSRandall Stewart 
108f8829a4aSRandall Stewart 
109f8829a4aSRandall Stewart void
110f8829a4aSRandall Stewart rto_logging(struct sctp_nets *net, int from)
111f8829a4aSRandall Stewart {
11280fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
113f8829a4aSRandall Stewart 
114bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
11580fefe0aSRandall Stewart 	sctp_clog.x.rto.net = (void *)net;
116be1d9176SMichael Tuexen 	sctp_clog.x.rto.rtt = net->rtt / 1000;
117c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
11880fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RTT,
11980fefe0aSRandall Stewart 	    from,
12080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
12180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
12280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
12380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
12480fefe0aSRandall Stewart 
125f8829a4aSRandall Stewart }
126f8829a4aSRandall Stewart 
127f8829a4aSRandall Stewart void
1286a91f103SRandall Stewart sctp_log_strm_del_alt(struct sctp_tcb *stcb, uint32_t tsn, uint16_t sseq, uint16_t stream, int from)
129f8829a4aSRandall Stewart {
13080fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
131f8829a4aSRandall Stewart 
13280fefe0aSRandall Stewart 	sctp_clog.x.strlog.stcb = stcb;
13380fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_tsn = tsn;
13480fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_sseq = sseq;
13580fefe0aSRandall Stewart 	sctp_clog.x.strlog.e_tsn = 0;
13680fefe0aSRandall Stewart 	sctp_clog.x.strlog.e_sseq = 0;
13780fefe0aSRandall Stewart 	sctp_clog.x.strlog.strm = stream;
138c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
13980fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_STRM,
14080fefe0aSRandall Stewart 	    from,
14180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
14280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
14380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
14480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
14580fefe0aSRandall Stewart 
146f8829a4aSRandall Stewart }
147f8829a4aSRandall Stewart 
148f8829a4aSRandall Stewart void
149f8829a4aSRandall Stewart sctp_log_nagle_event(struct sctp_tcb *stcb, int action)
150f8829a4aSRandall Stewart {
15180fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
152f8829a4aSRandall Stewart 
15380fefe0aSRandall Stewart 	sctp_clog.x.nagle.stcb = (void *)stcb;
15480fefe0aSRandall Stewart 	sctp_clog.x.nagle.total_flight = stcb->asoc.total_flight;
15580fefe0aSRandall Stewart 	sctp_clog.x.nagle.total_in_queue = stcb->asoc.total_output_queue_size;
15680fefe0aSRandall Stewart 	sctp_clog.x.nagle.count_in_queue = stcb->asoc.chunks_on_out_queue;
15780fefe0aSRandall Stewart 	sctp_clog.x.nagle.count_in_flight = stcb->asoc.total_flight_count;
158c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
15980fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_NAGLE,
16080fefe0aSRandall Stewart 	    action,
16180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
16280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
16380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
16480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
165f8829a4aSRandall Stewart }
166f8829a4aSRandall Stewart 
167f8829a4aSRandall Stewart 
168f8829a4aSRandall Stewart void
169f8829a4aSRandall Stewart sctp_log_sack(uint32_t old_cumack, uint32_t cumack, uint32_t tsn, uint16_t gaps, uint16_t dups, int from)
170f8829a4aSRandall Stewart {
17180fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
172f8829a4aSRandall Stewart 
17380fefe0aSRandall Stewart 	sctp_clog.x.sack.cumack = cumack;
17480fefe0aSRandall Stewart 	sctp_clog.x.sack.oldcumack = old_cumack;
17580fefe0aSRandall Stewart 	sctp_clog.x.sack.tsn = tsn;
17680fefe0aSRandall Stewart 	sctp_clog.x.sack.numGaps = gaps;
17780fefe0aSRandall Stewart 	sctp_clog.x.sack.numDups = dups;
178c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
17980fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_SACK,
18080fefe0aSRandall Stewart 	    from,
18180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
18280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
18380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
18480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
185f8829a4aSRandall Stewart }
186f8829a4aSRandall Stewart 
187f8829a4aSRandall Stewart void
188f8829a4aSRandall Stewart sctp_log_map(uint32_t map, uint32_t cum, uint32_t high, int from)
189f8829a4aSRandall Stewart {
19080fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
191f8829a4aSRandall Stewart 
192bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
19380fefe0aSRandall Stewart 	sctp_clog.x.map.base = map;
19480fefe0aSRandall Stewart 	sctp_clog.x.map.cum = cum;
19580fefe0aSRandall Stewart 	sctp_clog.x.map.high = high;
196c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
19780fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MAP,
19880fefe0aSRandall Stewart 	    from,
19980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
20080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
20180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
20280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
203f8829a4aSRandall Stewart }
204f8829a4aSRandall Stewart 
205f8829a4aSRandall Stewart void
206f8829a4aSRandall Stewart sctp_log_fr(uint32_t biggest_tsn, uint32_t biggest_new_tsn, uint32_t tsn,
207f8829a4aSRandall Stewart     int from)
208f8829a4aSRandall Stewart {
20980fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
210f8829a4aSRandall Stewart 
211bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
21280fefe0aSRandall Stewart 	sctp_clog.x.fr.largest_tsn = biggest_tsn;
21380fefe0aSRandall Stewart 	sctp_clog.x.fr.largest_new_tsn = biggest_new_tsn;
21480fefe0aSRandall Stewart 	sctp_clog.x.fr.tsn = tsn;
215c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
21680fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_FR,
21780fefe0aSRandall Stewart 	    from,
21880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
21980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
22080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
22180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
22280fefe0aSRandall Stewart 
223f8829a4aSRandall Stewart }
224f8829a4aSRandall Stewart 
225f8829a4aSRandall Stewart 
226f8829a4aSRandall Stewart void
227f8829a4aSRandall Stewart sctp_log_mb(struct mbuf *m, int from)
228f8829a4aSRandall Stewart {
22980fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
230f8829a4aSRandall Stewart 
23180fefe0aSRandall Stewart 	sctp_clog.x.mb.mp = m;
23280fefe0aSRandall Stewart 	sctp_clog.x.mb.mbuf_flags = (uint8_t) (SCTP_BUF_GET_FLAGS(m));
23380fefe0aSRandall Stewart 	sctp_clog.x.mb.size = (uint16_t) (SCTP_BUF_LEN(m));
23480fefe0aSRandall Stewart 	sctp_clog.x.mb.data = SCTP_BUF_AT(m, 0);
235139bc87fSRandall Stewart 	if (SCTP_BUF_IS_EXTENDED(m)) {
23680fefe0aSRandall Stewart 		sctp_clog.x.mb.ext = SCTP_BUF_EXTEND_BASE(m);
23780fefe0aSRandall Stewart 		sctp_clog.x.mb.refcnt = (uint8_t) (SCTP_BUF_EXTEND_REFCNT(m));
238f8829a4aSRandall Stewart 	} else {
23980fefe0aSRandall Stewart 		sctp_clog.x.mb.ext = 0;
24080fefe0aSRandall Stewart 		sctp_clog.x.mb.refcnt = 0;
241f8829a4aSRandall Stewart 	}
242c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
24380fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MBUF,
24480fefe0aSRandall Stewart 	    from,
24580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
24680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
24780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
24880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
249f8829a4aSRandall Stewart }
250f8829a4aSRandall Stewart 
251f8829a4aSRandall Stewart 
252f8829a4aSRandall Stewart void
253f8829a4aSRandall Stewart sctp_log_strm_del(struct sctp_queued_to_read *control, struct sctp_queued_to_read *poschk,
254f8829a4aSRandall Stewart     int from)
255f8829a4aSRandall Stewart {
25680fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
257f8829a4aSRandall Stewart 
258f8829a4aSRandall Stewart 	if (control == NULL) {
259ad81507eSRandall Stewart 		SCTP_PRINTF("Gak log of NULL?\n");
260f8829a4aSRandall Stewart 		return;
261f8829a4aSRandall Stewart 	}
26280fefe0aSRandall Stewart 	sctp_clog.x.strlog.stcb = control->stcb;
26380fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_tsn = control->sinfo_tsn;
26480fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_sseq = control->sinfo_ssn;
26580fefe0aSRandall Stewart 	sctp_clog.x.strlog.strm = control->sinfo_stream;
266f8829a4aSRandall Stewart 	if (poschk != NULL) {
26780fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_tsn = poschk->sinfo_tsn;
26880fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_sseq = poschk->sinfo_ssn;
269f8829a4aSRandall Stewart 	} else {
27080fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_tsn = 0;
27180fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_sseq = 0;
272f8829a4aSRandall Stewart 	}
273c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
27480fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_STRM,
27580fefe0aSRandall Stewart 	    from,
27680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
27780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
27880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
27980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
28080fefe0aSRandall Stewart 
281f8829a4aSRandall Stewart }
282f8829a4aSRandall Stewart 
283f8829a4aSRandall Stewart void
284f8829a4aSRandall Stewart sctp_log_cwnd(struct sctp_tcb *stcb, struct sctp_nets *net, int augment, uint8_t from)
285f8829a4aSRandall Stewart {
28680fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
287f8829a4aSRandall Stewart 
28880fefe0aSRandall Stewart 	sctp_clog.x.cwnd.net = net;
289f8829a4aSRandall Stewart 	if (stcb->asoc.send_queue_cnt > 255)
29080fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = 255;
291f8829a4aSRandall Stewart 	else
29280fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = stcb->asoc.send_queue_cnt;
293f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt > 255)
29480fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = 255;
295f8829a4aSRandall Stewart 	else
29680fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = stcb->asoc.stream_queue_cnt;
297f8829a4aSRandall Stewart 
298f8829a4aSRandall Stewart 	if (net) {
29980fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cwnd_new_value = net->cwnd;
30080fefe0aSRandall Stewart 		sctp_clog.x.cwnd.inflight = net->flight_size;
30180fefe0aSRandall Stewart 		sctp_clog.x.cwnd.pseudo_cumack = net->pseudo_cumack;
30280fefe0aSRandall Stewart 		sctp_clog.x.cwnd.meets_pseudo_cumack = net->new_pseudo_cumack;
30380fefe0aSRandall Stewart 		sctp_clog.x.cwnd.need_new_pseudo_cumack = net->find_pseudo_cumack;
304f8829a4aSRandall Stewart 	}
305f8829a4aSRandall Stewart 	if (SCTP_CWNDLOG_PRESEND == from) {
30680fefe0aSRandall Stewart 		sctp_clog.x.cwnd.meets_pseudo_cumack = stcb->asoc.peers_rwnd;
307f8829a4aSRandall Stewart 	}
30880fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_augment = augment;
309c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
31080fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_CWND,
31180fefe0aSRandall Stewart 	    from,
31280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
31380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
31480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
31580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
31680fefe0aSRandall Stewart 
317f8829a4aSRandall Stewart }
318f8829a4aSRandall Stewart 
319f8829a4aSRandall Stewart void
320f8829a4aSRandall Stewart sctp_log_lock(struct sctp_inpcb *inp, struct sctp_tcb *stcb, uint8_t from)
321f8829a4aSRandall Stewart {
32280fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
323f8829a4aSRandall Stewart 
324bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
32503b0b021SRandall Stewart 	if (inp) {
32680fefe0aSRandall Stewart 		sctp_clog.x.lock.sock = (void *)inp->sctp_socket;
32703b0b021SRandall Stewart 
32803b0b021SRandall Stewart 	} else {
32980fefe0aSRandall Stewart 		sctp_clog.x.lock.sock = (void *)NULL;
33003b0b021SRandall Stewart 	}
33180fefe0aSRandall Stewart 	sctp_clog.x.lock.inp = (void *)inp;
332f8829a4aSRandall Stewart 	if (stcb) {
33380fefe0aSRandall Stewart 		sctp_clog.x.lock.tcb_lock = mtx_owned(&stcb->tcb_mtx);
334f8829a4aSRandall Stewart 	} else {
33580fefe0aSRandall Stewart 		sctp_clog.x.lock.tcb_lock = SCTP_LOCK_UNKNOWN;
336f8829a4aSRandall Stewart 	}
337f8829a4aSRandall Stewart 	if (inp) {
33880fefe0aSRandall Stewart 		sctp_clog.x.lock.inp_lock = mtx_owned(&inp->inp_mtx);
33980fefe0aSRandall Stewart 		sctp_clog.x.lock.create_lock = mtx_owned(&inp->inp_create_mtx);
340f8829a4aSRandall Stewart 	} else {
34180fefe0aSRandall Stewart 		sctp_clog.x.lock.inp_lock = SCTP_LOCK_UNKNOWN;
34280fefe0aSRandall Stewart 		sctp_clog.x.lock.create_lock = SCTP_LOCK_UNKNOWN;
343f8829a4aSRandall Stewart 	}
344b3f1ea41SRandall Stewart 	sctp_clog.x.lock.info_lock = rw_wowned(&SCTP_BASE_INFO(ipi_ep_mtx));
34552129fcdSRandall Stewart 	if (inp && (inp->sctp_socket)) {
34680fefe0aSRandall Stewart 		sctp_clog.x.lock.sock_lock = mtx_owned(&(inp->sctp_socket->so_rcv.sb_mtx));
34780fefe0aSRandall Stewart 		sctp_clog.x.lock.sockrcvbuf_lock = mtx_owned(&(inp->sctp_socket->so_rcv.sb_mtx));
34880fefe0aSRandall Stewart 		sctp_clog.x.lock.socksndbuf_lock = mtx_owned(&(inp->sctp_socket->so_snd.sb_mtx));
349f8829a4aSRandall Stewart 	} else {
35080fefe0aSRandall Stewart 		sctp_clog.x.lock.sock_lock = SCTP_LOCK_UNKNOWN;
35180fefe0aSRandall Stewart 		sctp_clog.x.lock.sockrcvbuf_lock = SCTP_LOCK_UNKNOWN;
35280fefe0aSRandall Stewart 		sctp_clog.x.lock.socksndbuf_lock = SCTP_LOCK_UNKNOWN;
353f8829a4aSRandall Stewart 	}
354c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
35580fefe0aSRandall Stewart 	    SCTP_LOG_LOCK_EVENT,
35680fefe0aSRandall Stewart 	    from,
35780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
35880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
35980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
36080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
36180fefe0aSRandall Stewart 
362f8829a4aSRandall Stewart }
363f8829a4aSRandall Stewart 
364f8829a4aSRandall Stewart void
365f8829a4aSRandall Stewart sctp_log_maxburst(struct sctp_tcb *stcb, struct sctp_nets *net, int error, int burst, uint8_t from)
366f8829a4aSRandall Stewart {
36780fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
368f8829a4aSRandall Stewart 
369bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
37080fefe0aSRandall Stewart 	sctp_clog.x.cwnd.net = net;
37180fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_new_value = error;
37280fefe0aSRandall Stewart 	sctp_clog.x.cwnd.inflight = net->flight_size;
37380fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_augment = burst;
374f8829a4aSRandall Stewart 	if (stcb->asoc.send_queue_cnt > 255)
37580fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = 255;
376f8829a4aSRandall Stewart 	else
37780fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = stcb->asoc.send_queue_cnt;
378f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt > 255)
37980fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = 255;
380f8829a4aSRandall Stewart 	else
38180fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = stcb->asoc.stream_queue_cnt;
382c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
38380fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MAXBURST,
38480fefe0aSRandall Stewart 	    from,
38580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
38680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
38780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
38880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
38980fefe0aSRandall Stewart 
390f8829a4aSRandall Stewart }
391f8829a4aSRandall Stewart 
392f8829a4aSRandall Stewart void
393f8829a4aSRandall Stewart sctp_log_rwnd(uint8_t from, uint32_t peers_rwnd, uint32_t snd_size, uint32_t overhead)
394f8829a4aSRandall Stewart {
39580fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
396f8829a4aSRandall Stewart 
39780fefe0aSRandall Stewart 	sctp_clog.x.rwnd.rwnd = peers_rwnd;
39880fefe0aSRandall Stewart 	sctp_clog.x.rwnd.send_size = snd_size;
39980fefe0aSRandall Stewart 	sctp_clog.x.rwnd.overhead = overhead;
40080fefe0aSRandall Stewart 	sctp_clog.x.rwnd.new_rwnd = 0;
401c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
40280fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RWND,
40380fefe0aSRandall Stewart 	    from,
40480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
40580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
40680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
40780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
408f8829a4aSRandall Stewart }
409f8829a4aSRandall Stewart 
410f8829a4aSRandall Stewart void
411f8829a4aSRandall Stewart sctp_log_rwnd_set(uint8_t from, uint32_t peers_rwnd, uint32_t flight_size, uint32_t overhead, uint32_t a_rwndval)
412f8829a4aSRandall Stewart {
41380fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
414f8829a4aSRandall Stewart 
41580fefe0aSRandall Stewart 	sctp_clog.x.rwnd.rwnd = peers_rwnd;
41680fefe0aSRandall Stewart 	sctp_clog.x.rwnd.send_size = flight_size;
41780fefe0aSRandall Stewart 	sctp_clog.x.rwnd.overhead = overhead;
41880fefe0aSRandall Stewart 	sctp_clog.x.rwnd.new_rwnd = a_rwndval;
419c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
42080fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RWND,
42180fefe0aSRandall Stewart 	    from,
42280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
42380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
42480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
42580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
426f8829a4aSRandall Stewart }
427f8829a4aSRandall Stewart 
428f8829a4aSRandall Stewart void
429f8829a4aSRandall Stewart sctp_log_mbcnt(uint8_t from, uint32_t total_oq, uint32_t book, uint32_t total_mbcnt_q, uint32_t mbcnt)
430f8829a4aSRandall Stewart {
43180fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
432f8829a4aSRandall Stewart 
43380fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.total_queue_size = total_oq;
43480fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.size_change = book;
43580fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.total_queue_mb_size = total_mbcnt_q;
43680fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.mbcnt_change = mbcnt;
437c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
43880fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MBCNT,
43980fefe0aSRandall Stewart 	    from,
44080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
44180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
44280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
44380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
44480fefe0aSRandall Stewart 
445f8829a4aSRandall Stewart }
446f8829a4aSRandall Stewart 
447f8829a4aSRandall Stewart void
448f8829a4aSRandall Stewart sctp_misc_ints(uint8_t from, uint32_t a, uint32_t b, uint32_t c, uint32_t d)
449f8829a4aSRandall Stewart {
450c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
45180fefe0aSRandall Stewart 	    SCTP_LOG_MISC_EVENT,
45280fefe0aSRandall Stewart 	    from,
45380fefe0aSRandall Stewart 	    a, b, c, d);
454f8829a4aSRandall Stewart }
455f8829a4aSRandall Stewart 
456f8829a4aSRandall Stewart void
457f8829a4aSRandall Stewart sctp_wakeup_log(struct sctp_tcb *stcb, uint32_t cumtsn, uint32_t wake_cnt, int from)
458f8829a4aSRandall Stewart {
45980fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
460f8829a4aSRandall Stewart 
46180fefe0aSRandall Stewart 	sctp_clog.x.wake.stcb = (void *)stcb;
46280fefe0aSRandall Stewart 	sctp_clog.x.wake.wake_cnt = wake_cnt;
46380fefe0aSRandall Stewart 	sctp_clog.x.wake.flight = stcb->asoc.total_flight_count;
46480fefe0aSRandall Stewart 	sctp_clog.x.wake.send_q = stcb->asoc.send_queue_cnt;
46580fefe0aSRandall Stewart 	sctp_clog.x.wake.sent_q = stcb->asoc.sent_queue_cnt;
466f8829a4aSRandall Stewart 
467f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt < 0xff)
46880fefe0aSRandall Stewart 		sctp_clog.x.wake.stream_qcnt = (uint8_t) stcb->asoc.stream_queue_cnt;
469f8829a4aSRandall Stewart 	else
47080fefe0aSRandall Stewart 		sctp_clog.x.wake.stream_qcnt = 0xff;
471f8829a4aSRandall Stewart 
472f8829a4aSRandall Stewart 	if (stcb->asoc.chunks_on_out_queue < 0xff)
47380fefe0aSRandall Stewart 		sctp_clog.x.wake.chunks_on_oque = (uint8_t) stcb->asoc.chunks_on_out_queue;
474f8829a4aSRandall Stewart 	else
47580fefe0aSRandall Stewart 		sctp_clog.x.wake.chunks_on_oque = 0xff;
476f8829a4aSRandall Stewart 
47780fefe0aSRandall Stewart 	sctp_clog.x.wake.sctpflags = 0;
478f8829a4aSRandall Stewart 	/* set in the defered mode stuff */
479f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_DONT_WAKE)
48080fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 1;
481f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_WAKEOUTPUT)
48280fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 2;
483f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_WAKEINPUT)
48480fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 4;
485f8829a4aSRandall Stewart 	/* what about the sb */
486f8829a4aSRandall Stewart 	if (stcb->sctp_socket) {
487f8829a4aSRandall Stewart 		struct socket *so = stcb->sctp_socket;
488f8829a4aSRandall Stewart 
48980fefe0aSRandall Stewart 		sctp_clog.x.wake.sbflags = (uint8_t) ((so->so_snd.sb_flags & 0x00ff));
490f8829a4aSRandall Stewart 	} else {
49180fefe0aSRandall Stewart 		sctp_clog.x.wake.sbflags = 0xff;
492f8829a4aSRandall Stewart 	}
493c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
49480fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_WAKE,
49580fefe0aSRandall Stewart 	    from,
49680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
49780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
49880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
49980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
50080fefe0aSRandall Stewart 
501f8829a4aSRandall Stewart }
502f8829a4aSRandall Stewart 
503f8829a4aSRandall Stewart void
504f8829a4aSRandall Stewart sctp_log_block(uint8_t from, struct socket *so, struct sctp_association *asoc, int sendlen)
505f8829a4aSRandall Stewart {
50680fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
507f8829a4aSRandall Stewart 
50880fefe0aSRandall Stewart 	sctp_clog.x.blk.onsb = asoc->total_output_queue_size;
50980fefe0aSRandall Stewart 	sctp_clog.x.blk.send_sent_qcnt = (uint16_t) (asoc->send_queue_cnt + asoc->sent_queue_cnt);
51080fefe0aSRandall Stewart 	sctp_clog.x.blk.peer_rwnd = asoc->peers_rwnd;
51180fefe0aSRandall Stewart 	sctp_clog.x.blk.stream_qcnt = (uint16_t) asoc->stream_queue_cnt;
51280fefe0aSRandall Stewart 	sctp_clog.x.blk.chunks_on_oque = (uint16_t) asoc->chunks_on_out_queue;
51380fefe0aSRandall Stewart 	sctp_clog.x.blk.flight_size = (uint16_t) (asoc->total_flight / 1024);
51480fefe0aSRandall Stewart 	sctp_clog.x.blk.sndlen = sendlen;
515c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
51680fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_BLOCK,
51780fefe0aSRandall Stewart 	    from,
51880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
51980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
52080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
52180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
52280fefe0aSRandall Stewart 
523f8829a4aSRandall Stewart }
524f8829a4aSRandall Stewart 
525f8829a4aSRandall Stewart int
52642551e99SRandall Stewart sctp_fill_stat_log(void *optval, size_t *optsize)
527f8829a4aSRandall Stewart {
52880fefe0aSRandall Stewart 	/* May need to fix this if ktrdump does not work */
529f8829a4aSRandall Stewart 	return (0);
530f8829a4aSRandall Stewart }
531f8829a4aSRandall Stewart 
532f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
533f8829a4aSRandall Stewart uint8_t sctp_audit_data[SCTP_AUDIT_SIZE][2];
534f8829a4aSRandall Stewart static int sctp_audit_indx = 0;
535f8829a4aSRandall Stewart 
536f8829a4aSRandall Stewart static
537f8829a4aSRandall Stewart void
538f8829a4aSRandall Stewart sctp_print_audit_report(void)
539f8829a4aSRandall Stewart {
540f8829a4aSRandall Stewart 	int i;
541f8829a4aSRandall Stewart 	int cnt;
542f8829a4aSRandall Stewart 
543f8829a4aSRandall Stewart 	cnt = 0;
544f8829a4aSRandall Stewart 	for (i = sctp_audit_indx; i < SCTP_AUDIT_SIZE; i++) {
545f8829a4aSRandall Stewart 		if ((sctp_audit_data[i][0] == 0xe0) &&
546f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
547f8829a4aSRandall Stewart 			cnt = 0;
548ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
549f8829a4aSRandall Stewart 		} else if (sctp_audit_data[i][0] == 0xf0) {
550f8829a4aSRandall Stewart 			cnt = 0;
551ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
552f8829a4aSRandall Stewart 		} else if ((sctp_audit_data[i][0] == 0xc0) &&
553f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
554ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
555f8829a4aSRandall Stewart 			cnt = 0;
556f8829a4aSRandall Stewart 		}
557ad81507eSRandall Stewart 		SCTP_PRINTF("%2.2x%2.2x ", (uint32_t) sctp_audit_data[i][0],
558f8829a4aSRandall Stewart 		    (uint32_t) sctp_audit_data[i][1]);
559f8829a4aSRandall Stewart 		cnt++;
560f8829a4aSRandall Stewart 		if ((cnt % 14) == 0)
561ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
562f8829a4aSRandall Stewart 	}
563f8829a4aSRandall Stewart 	for (i = 0; i < sctp_audit_indx; i++) {
564f8829a4aSRandall Stewart 		if ((sctp_audit_data[i][0] == 0xe0) &&
565f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
566f8829a4aSRandall Stewart 			cnt = 0;
567ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
568f8829a4aSRandall Stewart 		} else if (sctp_audit_data[i][0] == 0xf0) {
569f8829a4aSRandall Stewart 			cnt = 0;
570ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
571f8829a4aSRandall Stewart 		} else if ((sctp_audit_data[i][0] == 0xc0) &&
572f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
573ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
574f8829a4aSRandall Stewart 			cnt = 0;
575f8829a4aSRandall Stewart 		}
576ad81507eSRandall Stewart 		SCTP_PRINTF("%2.2x%2.2x ", (uint32_t) sctp_audit_data[i][0],
577f8829a4aSRandall Stewart 		    (uint32_t) sctp_audit_data[i][1]);
578f8829a4aSRandall Stewart 		cnt++;
579f8829a4aSRandall Stewart 		if ((cnt % 14) == 0)
580ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
581f8829a4aSRandall Stewart 	}
582ad81507eSRandall Stewart 	SCTP_PRINTF("\n");
583f8829a4aSRandall Stewart }
584f8829a4aSRandall Stewart 
585f8829a4aSRandall Stewart void
586f8829a4aSRandall Stewart sctp_auditing(int from, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
587f8829a4aSRandall Stewart     struct sctp_nets *net)
588f8829a4aSRandall Stewart {
589f8829a4aSRandall Stewart 	int resend_cnt, tot_out, rep, tot_book_cnt;
590f8829a4aSRandall Stewart 	struct sctp_nets *lnet;
591f8829a4aSRandall Stewart 	struct sctp_tmit_chunk *chk;
592f8829a4aSRandall Stewart 
593f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = 0xAA;
594f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] = 0x000000ff & from;
595f8829a4aSRandall Stewart 	sctp_audit_indx++;
596f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
597f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
598f8829a4aSRandall Stewart 	}
599f8829a4aSRandall Stewart 	if (inp == NULL) {
600f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
601f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0x01;
602f8829a4aSRandall Stewart 		sctp_audit_indx++;
603f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
604f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
605f8829a4aSRandall Stewart 		}
606f8829a4aSRandall Stewart 		return;
607f8829a4aSRandall Stewart 	}
608f8829a4aSRandall Stewart 	if (stcb == NULL) {
609f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
610f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0x02;
611f8829a4aSRandall Stewart 		sctp_audit_indx++;
612f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
613f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
614f8829a4aSRandall Stewart 		}
615f8829a4aSRandall Stewart 		return;
616f8829a4aSRandall Stewart 	}
617f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = 0xA1;
618f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] =
619f8829a4aSRandall Stewart 	    (0x000000ff & stcb->asoc.sent_queue_retran_cnt);
620f8829a4aSRandall Stewart 	sctp_audit_indx++;
621f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
622f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
623f8829a4aSRandall Stewart 	}
624f8829a4aSRandall Stewart 	rep = 0;
625f8829a4aSRandall Stewart 	tot_book_cnt = 0;
626f8829a4aSRandall Stewart 	resend_cnt = tot_out = 0;
627f8829a4aSRandall Stewart 	TAILQ_FOREACH(chk, &stcb->asoc.sent_queue, sctp_next) {
628f8829a4aSRandall Stewart 		if (chk->sent == SCTP_DATAGRAM_RESEND) {
629f8829a4aSRandall Stewart 			resend_cnt++;
630f8829a4aSRandall Stewart 		} else if (chk->sent < SCTP_DATAGRAM_RESEND) {
631f8829a4aSRandall Stewart 			tot_out += chk->book_size;
632f8829a4aSRandall Stewart 			tot_book_cnt++;
633f8829a4aSRandall Stewart 		}
634f8829a4aSRandall Stewart 	}
635f8829a4aSRandall Stewart 	if (resend_cnt != stcb->asoc.sent_queue_retran_cnt) {
636f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
637f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA1;
638f8829a4aSRandall Stewart 		sctp_audit_indx++;
639f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
640f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
641f8829a4aSRandall Stewart 		}
642ad81507eSRandall Stewart 		SCTP_PRINTF("resend_cnt:%d asoc-tot:%d\n",
643f8829a4aSRandall Stewart 		    resend_cnt, stcb->asoc.sent_queue_retran_cnt);
644f8829a4aSRandall Stewart 		rep = 1;
645f8829a4aSRandall Stewart 		stcb->asoc.sent_queue_retran_cnt = resend_cnt;
646f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xA2;
647f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] =
648f8829a4aSRandall Stewart 		    (0x000000ff & stcb->asoc.sent_queue_retran_cnt);
649f8829a4aSRandall Stewart 		sctp_audit_indx++;
650f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
651f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
652f8829a4aSRandall Stewart 		}
653f8829a4aSRandall Stewart 	}
654f8829a4aSRandall Stewart 	if (tot_out != stcb->asoc.total_flight) {
655f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
656f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA2;
657f8829a4aSRandall Stewart 		sctp_audit_indx++;
658f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
659f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
660f8829a4aSRandall Stewart 		}
661f8829a4aSRandall Stewart 		rep = 1;
662ad81507eSRandall Stewart 		SCTP_PRINTF("tot_flt:%d asoc_tot:%d\n", tot_out,
663f8829a4aSRandall Stewart 		    (int)stcb->asoc.total_flight);
664f8829a4aSRandall Stewart 		stcb->asoc.total_flight = tot_out;
665f8829a4aSRandall Stewart 	}
666f8829a4aSRandall Stewart 	if (tot_book_cnt != stcb->asoc.total_flight_count) {
667f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
668f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA5;
669f8829a4aSRandall Stewart 		sctp_audit_indx++;
670f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
671f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
672f8829a4aSRandall Stewart 		}
673f8829a4aSRandall Stewart 		rep = 1;
674f31e6c7fSMichael Tuexen 		SCTP_PRINTF("tot_flt_book:%d\n", tot_book_cnt);
675f8829a4aSRandall Stewart 
676f8829a4aSRandall Stewart 		stcb->asoc.total_flight_count = tot_book_cnt;
677f8829a4aSRandall Stewart 	}
678f8829a4aSRandall Stewart 	tot_out = 0;
679f8829a4aSRandall Stewart 	TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
680f8829a4aSRandall Stewart 		tot_out += lnet->flight_size;
681f8829a4aSRandall Stewart 	}
682f8829a4aSRandall Stewart 	if (tot_out != stcb->asoc.total_flight) {
683f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
684f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA3;
685f8829a4aSRandall Stewart 		sctp_audit_indx++;
686f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
687f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
688f8829a4aSRandall Stewart 		}
689f8829a4aSRandall Stewart 		rep = 1;
690ad81507eSRandall Stewart 		SCTP_PRINTF("real flight:%d net total was %d\n",
691f8829a4aSRandall Stewart 		    stcb->asoc.total_flight, tot_out);
692f8829a4aSRandall Stewart 		/* now corrective action */
693f8829a4aSRandall Stewart 		TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
694f8829a4aSRandall Stewart 
695f8829a4aSRandall Stewart 			tot_out = 0;
696f8829a4aSRandall Stewart 			TAILQ_FOREACH(chk, &stcb->asoc.sent_queue, sctp_next) {
697f8829a4aSRandall Stewart 				if ((chk->whoTo == lnet) &&
698f8829a4aSRandall Stewart 				    (chk->sent < SCTP_DATAGRAM_RESEND)) {
699f8829a4aSRandall Stewart 					tot_out += chk->book_size;
700f8829a4aSRandall Stewart 				}
701f8829a4aSRandall Stewart 			}
702f8829a4aSRandall Stewart 			if (lnet->flight_size != tot_out) {
703f31e6c7fSMichael Tuexen 				SCTP_PRINTF("net:%p flight was %d corrected to %d\n",
704f31e6c7fSMichael Tuexen 				    lnet, lnet->flight_size,
705ad81507eSRandall Stewart 				    tot_out);
706f8829a4aSRandall Stewart 				lnet->flight_size = tot_out;
707f8829a4aSRandall Stewart 			}
708f8829a4aSRandall Stewart 		}
709f8829a4aSRandall Stewart 	}
710f8829a4aSRandall Stewart 	if (rep) {
711f8829a4aSRandall Stewart 		sctp_print_audit_report();
712f8829a4aSRandall Stewart 	}
713f8829a4aSRandall Stewart }
714f8829a4aSRandall Stewart 
715f8829a4aSRandall Stewart void
716f8829a4aSRandall Stewart sctp_audit_log(uint8_t ev, uint8_t fd)
717f8829a4aSRandall Stewart {
718f8829a4aSRandall Stewart 
719f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = ev;
720f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] = fd;
721f8829a4aSRandall Stewart 	sctp_audit_indx++;
722f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
723f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
724f8829a4aSRandall Stewart 	}
725f8829a4aSRandall Stewart }
726f8829a4aSRandall Stewart 
727f8829a4aSRandall Stewart #endif
728f8829a4aSRandall Stewart 
729f8829a4aSRandall Stewart /*
73012af6654SMichael Tuexen  * sctp_stop_timers_for_shutdown() should be called
73112af6654SMichael Tuexen  * when entering the SHUTDOWN_SENT or SHUTDOWN_ACK_SENT
73212af6654SMichael Tuexen  * state to make sure that all timers are stopped.
73312af6654SMichael Tuexen  */
73412af6654SMichael Tuexen void
73512af6654SMichael Tuexen sctp_stop_timers_for_shutdown(struct sctp_tcb *stcb)
73612af6654SMichael Tuexen {
73712af6654SMichael Tuexen 	struct sctp_association *asoc;
73812af6654SMichael Tuexen 	struct sctp_nets *net;
73912af6654SMichael Tuexen 
74012af6654SMichael Tuexen 	asoc = &stcb->asoc;
74112af6654SMichael Tuexen 
74212af6654SMichael Tuexen 	(void)SCTP_OS_TIMER_STOP(&asoc->hb_timer.timer);
74312af6654SMichael Tuexen 	(void)SCTP_OS_TIMER_STOP(&asoc->dack_timer.timer);
74412af6654SMichael Tuexen 	(void)SCTP_OS_TIMER_STOP(&asoc->strreset_timer.timer);
74512af6654SMichael Tuexen 	(void)SCTP_OS_TIMER_STOP(&asoc->asconf_timer.timer);
74612af6654SMichael Tuexen 	(void)SCTP_OS_TIMER_STOP(&asoc->autoclose_timer.timer);
74712af6654SMichael Tuexen 	(void)SCTP_OS_TIMER_STOP(&asoc->delayed_event_timer.timer);
74812af6654SMichael Tuexen 	TAILQ_FOREACH(net, &asoc->nets, sctp_next) {
74912af6654SMichael Tuexen 		(void)SCTP_OS_TIMER_STOP(&net->fr_timer.timer);
75012af6654SMichael Tuexen 		(void)SCTP_OS_TIMER_STOP(&net->pmtu_timer.timer);
75112af6654SMichael Tuexen 	}
75212af6654SMichael Tuexen }
75312af6654SMichael Tuexen 
75412af6654SMichael Tuexen /*
755f8829a4aSRandall Stewart  * a list of sizes based on typical mtu's, used only if next hop size not
756f8829a4aSRandall Stewart  * returned.
757f8829a4aSRandall Stewart  */
758437fc91aSMichael Tuexen static uint32_t sctp_mtu_sizes[] = {
759f8829a4aSRandall Stewart 	68,
760f8829a4aSRandall Stewart 	296,
761f8829a4aSRandall Stewart 	508,
762f8829a4aSRandall Stewart 	512,
763f8829a4aSRandall Stewart 	544,
764f8829a4aSRandall Stewart 	576,
765f8829a4aSRandall Stewart 	1006,
766f8829a4aSRandall Stewart 	1492,
767f8829a4aSRandall Stewart 	1500,
768f8829a4aSRandall Stewart 	1536,
769f8829a4aSRandall Stewart 	2002,
770f8829a4aSRandall Stewart 	2048,
771f8829a4aSRandall Stewart 	4352,
772f8829a4aSRandall Stewart 	4464,
773f8829a4aSRandall Stewart 	8166,
774f8829a4aSRandall Stewart 	17914,
775f8829a4aSRandall Stewart 	32000,
776f8829a4aSRandall Stewart 	65535
777f8829a4aSRandall Stewart };
778f8829a4aSRandall Stewart 
779f8829a4aSRandall Stewart /*
780437fc91aSMichael Tuexen  * Return the largest MTU smaller than val. If there is no
781437fc91aSMichael Tuexen  * entry, just return val.
782f8829a4aSRandall Stewart  */
783437fc91aSMichael Tuexen uint32_t
784437fc91aSMichael Tuexen sctp_get_prev_mtu(uint32_t val)
785437fc91aSMichael Tuexen {
786437fc91aSMichael Tuexen 	uint32_t i;
787437fc91aSMichael Tuexen 
788437fc91aSMichael Tuexen 	if (val <= sctp_mtu_sizes[0]) {
789437fc91aSMichael Tuexen 		return (val);
790437fc91aSMichael Tuexen 	}
791437fc91aSMichael Tuexen 	for (i = 1; i < (sizeof(sctp_mtu_sizes) / sizeof(uint32_t)); i++) {
792437fc91aSMichael Tuexen 		if (val <= sctp_mtu_sizes[i]) {
793f8829a4aSRandall Stewart 			break;
794f8829a4aSRandall Stewart 		}
795f8829a4aSRandall Stewart 	}
796437fc91aSMichael Tuexen 	return (sctp_mtu_sizes[i - 1]);
797437fc91aSMichael Tuexen }
798437fc91aSMichael Tuexen 
799437fc91aSMichael Tuexen /*
800437fc91aSMichael Tuexen  * Return the smallest MTU larger than val. If there is no
801437fc91aSMichael Tuexen  * entry, just return val.
802437fc91aSMichael Tuexen  */
803437fc91aSMichael Tuexen uint32_t
804437fc91aSMichael Tuexen sctp_get_next_mtu(struct sctp_inpcb *inp, uint32_t val)
805437fc91aSMichael Tuexen {
806437fc91aSMichael Tuexen 	/* select another MTU that is just bigger than this one */
807437fc91aSMichael Tuexen 	uint32_t i;
808437fc91aSMichael Tuexen 
809437fc91aSMichael Tuexen 	for (i = 0; i < (sizeof(sctp_mtu_sizes) / sizeof(uint32_t)); i++) {
810437fc91aSMichael Tuexen 		if (val < sctp_mtu_sizes[i]) {
811437fc91aSMichael Tuexen 			return (sctp_mtu_sizes[i]);
812437fc91aSMichael Tuexen 		}
813437fc91aSMichael Tuexen 	}
814437fc91aSMichael Tuexen 	return (val);
815f8829a4aSRandall Stewart }
816f8829a4aSRandall Stewart 
817f8829a4aSRandall Stewart void
818f8829a4aSRandall Stewart sctp_fill_random_store(struct sctp_pcb *m)
819f8829a4aSRandall Stewart {
820f8829a4aSRandall Stewart 	/*
821f8829a4aSRandall Stewart 	 * Here we use the MD5/SHA-1 to hash with our good randomNumbers and
822f8829a4aSRandall Stewart 	 * our counter. The result becomes our good random numbers and we
823f8829a4aSRandall Stewart 	 * then setup to give these out. Note that we do no locking to
824f8829a4aSRandall Stewart 	 * protect this. This is ok, since if competing folks call this we
82517205eccSRandall Stewart 	 * will get more gobbled gook in the random store which is what we
826f8829a4aSRandall Stewart 	 * want. There is a danger that two guys will use the same random
827f8829a4aSRandall Stewart 	 * numbers, but thats ok too since that is random as well :->
828f8829a4aSRandall Stewart 	 */
829f8829a4aSRandall Stewart 	m->store_at = 0;
830ad81507eSRandall Stewart 	(void)sctp_hmac(SCTP_HMAC, (uint8_t *) m->random_numbers,
831f8829a4aSRandall Stewart 	    sizeof(m->random_numbers), (uint8_t *) & m->random_counter,
832f8829a4aSRandall Stewart 	    sizeof(m->random_counter), (uint8_t *) m->random_store);
833f8829a4aSRandall Stewart 	m->random_counter++;
834f8829a4aSRandall Stewart }
835f8829a4aSRandall Stewart 
836f8829a4aSRandall Stewart uint32_t
837851b7298SRandall Stewart sctp_select_initial_TSN(struct sctp_pcb *inp)
838f8829a4aSRandall Stewart {
839f8829a4aSRandall Stewart 	/*
840f8829a4aSRandall Stewart 	 * A true implementation should use random selection process to get
841f8829a4aSRandall Stewart 	 * the initial stream sequence number, using RFC1750 as a good
842f8829a4aSRandall Stewart 	 * guideline
843f8829a4aSRandall Stewart 	 */
844139bc87fSRandall Stewart 	uint32_t x, *xp;
845f8829a4aSRandall Stewart 	uint8_t *p;
846851b7298SRandall Stewart 	int store_at, new_store;
847f8829a4aSRandall Stewart 
848851b7298SRandall Stewart 	if (inp->initial_sequence_debug != 0) {
849f8829a4aSRandall Stewart 		uint32_t ret;
850f8829a4aSRandall Stewart 
851851b7298SRandall Stewart 		ret = inp->initial_sequence_debug;
852851b7298SRandall Stewart 		inp->initial_sequence_debug++;
853f8829a4aSRandall Stewart 		return (ret);
854f8829a4aSRandall Stewart 	}
855851b7298SRandall Stewart retry:
856851b7298SRandall Stewart 	store_at = inp->store_at;
857851b7298SRandall Stewart 	new_store = store_at + sizeof(uint32_t);
858851b7298SRandall Stewart 	if (new_store >= (SCTP_SIGNATURE_SIZE - 3)) {
859851b7298SRandall Stewart 		new_store = 0;
860f8829a4aSRandall Stewart 	}
861851b7298SRandall Stewart 	if (!atomic_cmpset_int(&inp->store_at, store_at, new_store)) {
862851b7298SRandall Stewart 		goto retry;
863851b7298SRandall Stewart 	}
864851b7298SRandall Stewart 	if (new_store == 0) {
865851b7298SRandall Stewart 		/* Refill the random store */
866851b7298SRandall Stewart 		sctp_fill_random_store(inp);
867851b7298SRandall Stewart 	}
868851b7298SRandall Stewart 	p = &inp->random_store[store_at];
869139bc87fSRandall Stewart 	xp = (uint32_t *) p;
870f8829a4aSRandall Stewart 	x = *xp;
871f8829a4aSRandall Stewart 	return (x);
872f8829a4aSRandall Stewart }
873f8829a4aSRandall Stewart 
874f8829a4aSRandall Stewart uint32_t
875830d754dSRandall Stewart sctp_select_a_tag(struct sctp_inpcb *inp, uint16_t lport, uint16_t rport, int save_in_twait)
876f8829a4aSRandall Stewart {
8777291848aSMichael Tuexen 	uint32_t x, not_done;
878f8829a4aSRandall Stewart 	struct timeval now;
879f8829a4aSRandall Stewart 
8806e55db54SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&now);
881f8829a4aSRandall Stewart 	not_done = 1;
882f8829a4aSRandall Stewart 	while (not_done) {
883851b7298SRandall Stewart 		x = sctp_select_initial_TSN(&inp->sctp_ep);
884f8829a4aSRandall Stewart 		if (x == 0) {
885f8829a4aSRandall Stewart 			/* we never use 0 */
886f8829a4aSRandall Stewart 			continue;
887f8829a4aSRandall Stewart 		}
888830d754dSRandall Stewart 		if (sctp_is_vtag_good(inp, x, lport, rport, &now, save_in_twait)) {
889f8829a4aSRandall Stewart 			not_done = 0;
890f8829a4aSRandall Stewart 		}
891f8829a4aSRandall Stewart 	}
892f8829a4aSRandall Stewart 	return (x);
893f8829a4aSRandall Stewart }
894f8829a4aSRandall Stewart 
895f8829a4aSRandall Stewart int
8960696e120SRandall Stewart sctp_init_asoc(struct sctp_inpcb *m, struct sctp_tcb *stcb,
897b5c16493SMichael Tuexen     uint32_t override_tag, uint32_t vrf_id)
898f8829a4aSRandall Stewart {
8990696e120SRandall Stewart 	struct sctp_association *asoc;
9000696e120SRandall Stewart 
901f8829a4aSRandall Stewart 	/*
902f8829a4aSRandall Stewart 	 * Anything set to zero is taken care of by the allocation routine's
903f8829a4aSRandall Stewart 	 * bzero
904f8829a4aSRandall Stewart 	 */
905f8829a4aSRandall Stewart 
906f8829a4aSRandall Stewart 	/*
907f8829a4aSRandall Stewart 	 * Up front select what scoping to apply on addresses I tell my peer
908f8829a4aSRandall Stewart 	 * Not sure what to do with these right now, we will need to come up
909f8829a4aSRandall Stewart 	 * with a way to set them. We may need to pass them through from the
910f8829a4aSRandall Stewart 	 * caller in the sctp_aloc_assoc() function.
911f8829a4aSRandall Stewart 	 */
912f8829a4aSRandall Stewart 	int i;
913f8829a4aSRandall Stewart 
9140696e120SRandall Stewart 	asoc = &stcb->asoc;
915f8829a4aSRandall Stewart 	/* init all variables to a known value. */
916c4739e2fSRandall Stewart 	SCTP_SET_STATE(&stcb->asoc, SCTP_STATE_INUSE);
917f8829a4aSRandall Stewart 	asoc->max_burst = m->sctp_ep.max_burst;
918899288aeSRandall Stewart 	asoc->fr_max_burst = m->sctp_ep.fr_max_burst;
919f8829a4aSRandall Stewart 	asoc->heart_beat_delay = TICKS_TO_MSEC(m->sctp_ep.sctp_timeoutticks[SCTP_TIMER_HEARTBEAT]);
920f8829a4aSRandall Stewart 	asoc->cookie_life = m->sctp_ep.def_cookie_life;
92120083c2eSMichael Tuexen 	asoc->sctp_cmt_on_off = m->sctp_cmt_on_off;
922c446091bSMichael Tuexen 	asoc->ecn_allowed = m->sctp_ecn_enable;
923830d754dSRandall Stewart 	asoc->sctp_nr_sack_on_off = (uint8_t) SCTP_BASE_SYSCTL(sctp_nr_sack_on_off);
924b3f1ea41SRandall Stewart 	asoc->sctp_cmt_pf = (uint8_t) SCTP_BASE_SYSCTL(sctp_cmt_pf);
925d61a0ae0SRandall Stewart 	asoc->sctp_frag_point = m->sctp_frag_point;
926*e2e7c62eSMichael Tuexen 	asoc->sctp_features = m->sctp_features;
92742551e99SRandall Stewart #ifdef INET
928f8829a4aSRandall Stewart 	asoc->default_tos = m->ip_inp.inp.inp_ip_tos;
929f8829a4aSRandall Stewart #else
930f8829a4aSRandall Stewart 	asoc->default_tos = 0;
931f8829a4aSRandall Stewart #endif
932f8829a4aSRandall Stewart 
93342551e99SRandall Stewart #ifdef INET6
934f8829a4aSRandall Stewart 	asoc->default_flowlabel = ((struct in6pcb *)m)->in6p_flowinfo;
935f8829a4aSRandall Stewart #else
936f8829a4aSRandall Stewart 	asoc->default_flowlabel = 0;
937f8829a4aSRandall Stewart #endif
9389f22f500SRandall Stewart 	asoc->sb_send_resv = 0;
939f8829a4aSRandall Stewart 	if (override_tag) {
940f8829a4aSRandall Stewart 		asoc->my_vtag = override_tag;
941f8829a4aSRandall Stewart 	} else {
942830d754dSRandall Stewart 		asoc->my_vtag = sctp_select_a_tag(m, stcb->sctp_ep->sctp_lport, stcb->rport, 1);
943f8829a4aSRandall Stewart 	}
944de0e935bSRandall Stewart 	/* Get the nonce tags */
945830d754dSRandall Stewart 	asoc->my_vtag_nonce = sctp_select_a_tag(m, stcb->sctp_ep->sctp_lport, stcb->rport, 0);
946830d754dSRandall Stewart 	asoc->peer_vtag_nonce = sctp_select_a_tag(m, stcb->sctp_ep->sctp_lport, stcb->rport, 0);
94742551e99SRandall Stewart 	asoc->vrf_id = vrf_id;
948de0e935bSRandall Stewart 
949f8829a4aSRandall Stewart 	if (sctp_is_feature_on(m, SCTP_PCB_FLAGS_DONOT_HEARTBEAT))
950f8829a4aSRandall Stewart 		asoc->hb_is_disabled = 1;
951f8829a4aSRandall Stewart 	else
952f8829a4aSRandall Stewart 		asoc->hb_is_disabled = 0;
953f8829a4aSRandall Stewart 
95418e198d3SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
95518e198d3SRandall Stewart 	asoc->tsn_in_at = 0;
95618e198d3SRandall Stewart 	asoc->tsn_out_at = 0;
95718e198d3SRandall Stewart 	asoc->tsn_in_wrapped = 0;
95818e198d3SRandall Stewart 	asoc->tsn_out_wrapped = 0;
95918e198d3SRandall Stewart 	asoc->cumack_log_at = 0;
960b201f536SRandall Stewart 	asoc->cumack_log_atsnt = 0;
96118e198d3SRandall Stewart #endif
96218e198d3SRandall Stewart #ifdef SCTP_FS_SPEC_LOG
96318e198d3SRandall Stewart 	asoc->fs_index = 0;
96418e198d3SRandall Stewart #endif
965f8829a4aSRandall Stewart 	asoc->refcnt = 0;
966f8829a4aSRandall Stewart 	asoc->assoc_up_sent = 0;
967f8829a4aSRandall Stewart 	asoc->asconf_seq_out = asoc->str_reset_seq_out = asoc->init_seq_number = asoc->sending_seq =
968f8829a4aSRandall Stewart 	    sctp_select_initial_TSN(&m->sctp_ep);
969c54a18d2SRandall Stewart 	asoc->asconf_seq_out_acked = asoc->asconf_seq_out - 1;
970f8829a4aSRandall Stewart 	/* we are optimisitic here */
971f8829a4aSRandall Stewart 	asoc->peer_supports_pktdrop = 1;
972830d754dSRandall Stewart 	asoc->peer_supports_nat = 0;
973f8829a4aSRandall Stewart 	asoc->sent_queue_retran_cnt = 0;
974f8829a4aSRandall Stewart 
975f8829a4aSRandall Stewart 	/* for CMT */
9768933fa13SRandall Stewart 	asoc->last_net_cmt_send_started = NULL;
977f8829a4aSRandall Stewart 
978f8829a4aSRandall Stewart 	/* This will need to be adjusted */
979f8829a4aSRandall Stewart 	asoc->last_acked_seq = asoc->init_seq_number - 1;
980f8829a4aSRandall Stewart 	asoc->advanced_peer_ack_point = asoc->last_acked_seq;
981f8829a4aSRandall Stewart 	asoc->asconf_seq_in = asoc->last_acked_seq;
982f8829a4aSRandall Stewart 
983f8829a4aSRandall Stewart 	/* here we are different, we hold the next one we expect */
984f8829a4aSRandall Stewart 	asoc->str_reset_seq_in = asoc->last_acked_seq + 1;
985f8829a4aSRandall Stewart 
986f8829a4aSRandall Stewart 	asoc->initial_init_rto_max = m->sctp_ep.initial_init_rto_max;
987f8829a4aSRandall Stewart 	asoc->initial_rto = m->sctp_ep.initial_rto;
988f8829a4aSRandall Stewart 
989f8829a4aSRandall Stewart 	asoc->max_init_times = m->sctp_ep.max_init_times;
990f8829a4aSRandall Stewart 	asoc->max_send_times = m->sctp_ep.max_send_times;
991f8829a4aSRandall Stewart 	asoc->def_net_failure = m->sctp_ep.def_net_failure;
992f8829a4aSRandall Stewart 	asoc->free_chunk_cnt = 0;
993f8829a4aSRandall Stewart 
994f8829a4aSRandall Stewart 	asoc->iam_blocking = 0;
995493d8e5aSRandall Stewart 
996f8829a4aSRandall Stewart 	asoc->context = m->sctp_context;
997f8829a4aSRandall Stewart 	asoc->def_send = m->def_send;
998f8829a4aSRandall Stewart 	asoc->delayed_ack = TICKS_TO_MSEC(m->sctp_ep.sctp_timeoutticks[SCTP_TIMER_RECV]);
99942551e99SRandall Stewart 	asoc->sack_freq = m->sctp_ep.sctp_sack_freq;
1000f8829a4aSRandall Stewart 	asoc->pr_sctp_cnt = 0;
1001f8829a4aSRandall Stewart 	asoc->total_output_queue_size = 0;
1002f8829a4aSRandall Stewart 
1003f8829a4aSRandall Stewart 	if (m->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) {
1004f8829a4aSRandall Stewart 		struct in6pcb *inp6;
1005f8829a4aSRandall Stewart 
1006f8829a4aSRandall Stewart 		/* Its a V6 socket */
1007f8829a4aSRandall Stewart 		inp6 = (struct in6pcb *)m;
1008f8829a4aSRandall Stewart 		asoc->ipv6_addr_legal = 1;
1009f8829a4aSRandall Stewart 		/* Now look at the binding flag to see if V4 will be legal */
101044b7479bSRandall Stewart 		if (SCTP_IPV6_V6ONLY(inp6) == 0) {
1011f8829a4aSRandall Stewart 			asoc->ipv4_addr_legal = 1;
1012f8829a4aSRandall Stewart 		} else {
1013f8829a4aSRandall Stewart 			/* V4 addresses are NOT legal on the association */
1014f8829a4aSRandall Stewart 			asoc->ipv4_addr_legal = 0;
1015f8829a4aSRandall Stewart 		}
1016f8829a4aSRandall Stewart 	} else {
1017f8829a4aSRandall Stewart 		/* Its a V4 socket, no - V6 */
1018f8829a4aSRandall Stewart 		asoc->ipv4_addr_legal = 1;
1019f8829a4aSRandall Stewart 		asoc->ipv6_addr_legal = 0;
1020f8829a4aSRandall Stewart 	}
1021f8829a4aSRandall Stewart 
102262c1ff9cSRandall Stewart 	asoc->my_rwnd = max(SCTP_SB_LIMIT_RCV(m->sctp_socket), SCTP_MINIMAL_RWND);
102362c1ff9cSRandall Stewart 	asoc->peers_rwnd = SCTP_SB_LIMIT_RCV(m->sctp_socket);
1024f8829a4aSRandall Stewart 
1025f8829a4aSRandall Stewart 	asoc->smallest_mtu = m->sctp_frag_point;
1026f8829a4aSRandall Stewart 	asoc->minrto = m->sctp_ep.sctp_minrto;
1027f8829a4aSRandall Stewart 	asoc->maxrto = m->sctp_ep.sctp_maxrto;
1028f8829a4aSRandall Stewart 
1029f8829a4aSRandall Stewart 	asoc->locked_on_sending = NULL;
1030f8829a4aSRandall Stewart 	asoc->stream_locked_on = 0;
1031f8829a4aSRandall Stewart 	asoc->ecn_echo_cnt_onq = 0;
1032f8829a4aSRandall Stewart 	asoc->stream_locked = 0;
1033f8829a4aSRandall Stewart 
103442551e99SRandall Stewart 	asoc->send_sack = 1;
103542551e99SRandall Stewart 
103642551e99SRandall Stewart 	LIST_INIT(&asoc->sctp_restricted_addrs);
103742551e99SRandall Stewart 
1038f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->nets);
1039f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->pending_reply_queue);
10402afb3e84SRandall Stewart 	TAILQ_INIT(&asoc->asconf_ack_sent);
1041f8829a4aSRandall Stewart 	/* Setup to fill the hb random cache at first HB */
1042f8829a4aSRandall Stewart 	asoc->hb_random_idx = 4;
1043f8829a4aSRandall Stewart 
1044f8829a4aSRandall Stewart 	asoc->sctp_autoclose_ticks = m->sctp_ep.auto_close_time;
1045f8829a4aSRandall Stewart 
10460e9a9c10SMichael Tuexen 	stcb->asoc.congestion_control_module = m->sctp_ep.sctp_default_cc_module;
10470e9a9c10SMichael Tuexen 	stcb->asoc.cc_functions = sctp_cc_functions[m->sctp_ep.sctp_default_cc_module];
1048b54d3a6cSRandall Stewart 
1049f7a77f6fSMichael Tuexen 	stcb->asoc.stream_scheduling_module = m->sctp_ep.sctp_default_ss_module;
1050f7a77f6fSMichael Tuexen 	stcb->asoc.ss_functions = sctp_ss_functions[m->sctp_ep.sctp_default_ss_module];
1051f7a77f6fSMichael Tuexen 
1052b54d3a6cSRandall Stewart 	/*
1053f8829a4aSRandall Stewart 	 * Now the stream parameters, here we allocate space for all streams
1054f8829a4aSRandall Stewart 	 * that we request by default.
1055f8829a4aSRandall Stewart 	 */
1056ea44232bSRandall Stewart 	asoc->strm_realoutsize = asoc->streamoutcnt = asoc->pre_open_streams =
1057f8829a4aSRandall Stewart 	    m->sctp_ep.pre_open_stream_count;
1058f8829a4aSRandall Stewart 	SCTP_MALLOC(asoc->strmout, struct sctp_stream_out *,
1059f8829a4aSRandall Stewart 	    asoc->streamoutcnt * sizeof(struct sctp_stream_out),
1060207304d4SRandall Stewart 	    SCTP_M_STRMO);
1061f8829a4aSRandall Stewart 	if (asoc->strmout == NULL) {
1062f8829a4aSRandall Stewart 		/* big trouble no memory */
1063c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
1064f8829a4aSRandall Stewart 		return (ENOMEM);
1065f8829a4aSRandall Stewart 	}
1066f8829a4aSRandall Stewart 	for (i = 0; i < asoc->streamoutcnt; i++) {
1067f8829a4aSRandall Stewart 		/*
1068f8829a4aSRandall Stewart 		 * inbound side must be set to 0xffff, also NOTE when we get
1069f8829a4aSRandall Stewart 		 * the INIT-ACK back (for INIT sender) we MUST reduce the
1070f8829a4aSRandall Stewart 		 * count (streamoutcnt) but first check if we sent to any of
1071f8829a4aSRandall Stewart 		 * the upper streams that were dropped (if some were). Those
1072f8829a4aSRandall Stewart 		 * that were dropped must be notified to the upper layer as
1073f8829a4aSRandall Stewart 		 * failed to send.
1074f8829a4aSRandall Stewart 		 */
1075f8829a4aSRandall Stewart 		asoc->strmout[i].next_sequence_sent = 0x0;
1076f8829a4aSRandall Stewart 		TAILQ_INIT(&asoc->strmout[i].outqueue);
1077f8829a4aSRandall Stewart 		asoc->strmout[i].stream_no = i;
1078f8829a4aSRandall Stewart 		asoc->strmout[i].last_msg_incomplete = 0;
1079252f7f93SMichael Tuexen 		asoc->ss_functions.sctp_ss_init_stream(&asoc->strmout[i], NULL);
1080f8829a4aSRandall Stewart 	}
1081f7a77f6fSMichael Tuexen 	asoc->ss_functions.sctp_ss_init(stcb, asoc, 0);
1082f7a77f6fSMichael Tuexen 
1083f8829a4aSRandall Stewart 	/* Now the mapping array */
1084f8829a4aSRandall Stewart 	asoc->mapping_array_size = SCTP_INITIAL_MAPPING_ARRAY;
1085f8829a4aSRandall Stewart 	SCTP_MALLOC(asoc->mapping_array, uint8_t *, asoc->mapping_array_size,
1086207304d4SRandall Stewart 	    SCTP_M_MAP);
1087f8829a4aSRandall Stewart 	if (asoc->mapping_array == NULL) {
1088207304d4SRandall Stewart 		SCTP_FREE(asoc->strmout, SCTP_M_STRMO);
1089c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
1090f8829a4aSRandall Stewart 		return (ENOMEM);
1091f8829a4aSRandall Stewart 	}
1092f8829a4aSRandall Stewart 	memset(asoc->mapping_array, 0, asoc->mapping_array_size);
1093b5c16493SMichael Tuexen 	SCTP_MALLOC(asoc->nr_mapping_array, uint8_t *, asoc->mapping_array_size,
1094830d754dSRandall Stewart 	    SCTP_M_MAP);
1095bf1be571SRandall Stewart 	if (asoc->nr_mapping_array == NULL) {
1096bf1be571SRandall Stewart 		SCTP_FREE(asoc->strmout, SCTP_M_STRMO);
1097bf1be571SRandall Stewart 		SCTP_FREE(asoc->mapping_array, SCTP_M_MAP);
1098bf1be571SRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
1099bf1be571SRandall Stewart 		return (ENOMEM);
1100bf1be571SRandall Stewart 	}
1101b5c16493SMichael Tuexen 	memset(asoc->nr_mapping_array, 0, asoc->mapping_array_size);
1102830d754dSRandall Stewart 
1103f8829a4aSRandall Stewart 	/* Now the init of the other outqueues */
1104f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->free_chunks);
1105f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->control_send_queue);
1106c54a18d2SRandall Stewart 	TAILQ_INIT(&asoc->asconf_send_queue);
1107f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->send_queue);
1108f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->sent_queue);
1109f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->reasmqueue);
1110f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->resetHead);
1111f8829a4aSRandall Stewart 	asoc->max_inbound_streams = m->sctp_ep.max_open_streams_intome;
1112f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->asconf_queue);
1113f8829a4aSRandall Stewart 	/* authentication fields */
1114f8829a4aSRandall Stewart 	asoc->authinfo.random = NULL;
1115830d754dSRandall Stewart 	asoc->authinfo.active_keyid = 0;
1116f8829a4aSRandall Stewart 	asoc->authinfo.assoc_key = NULL;
1117f8829a4aSRandall Stewart 	asoc->authinfo.assoc_keyid = 0;
1118f8829a4aSRandall Stewart 	asoc->authinfo.recv_key = NULL;
1119f8829a4aSRandall Stewart 	asoc->authinfo.recv_keyid = 0;
1120f8829a4aSRandall Stewart 	LIST_INIT(&asoc->shared_keys);
1121f42a358aSRandall Stewart 	asoc->marked_retrans = 0;
1122f42a358aSRandall Stewart 	asoc->timoinit = 0;
1123f42a358aSRandall Stewart 	asoc->timodata = 0;
1124f42a358aSRandall Stewart 	asoc->timosack = 0;
1125f42a358aSRandall Stewart 	asoc->timoshutdown = 0;
1126f42a358aSRandall Stewart 	asoc->timoheartbeat = 0;
1127f42a358aSRandall Stewart 	asoc->timocookie = 0;
1128f42a358aSRandall Stewart 	asoc->timoshutdownack = 0;
11296e55db54SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&asoc->start_time);
11306e55db54SRandall Stewart 	asoc->discontinuity_time = asoc->start_time;
1131eacc51c5SRandall Stewart 	/*
1132eacc51c5SRandall Stewart 	 * sa_ignore MEMLEAK {memory is put in the assoc mapping array and
113377acdc25SRandall Stewart 	 * freed later when the association is freed.
1134eacc51c5SRandall Stewart 	 */
1135f8829a4aSRandall Stewart 	return (0);
1136f8829a4aSRandall Stewart }
1137f8829a4aSRandall Stewart 
11380e13104dSRandall Stewart void
11390e13104dSRandall Stewart sctp_print_mapping_array(struct sctp_association *asoc)
11400e13104dSRandall Stewart {
1141aed5947cSMichael Tuexen 	unsigned int i, limit;
11420e13104dSRandall Stewart 
1143aed5947cSMichael Tuexen 	printf("Mapping array size: %d, baseTSN: %8.8x, cumAck: %8.8x, highestTSN: (%8.8x, %8.8x).\n",
11440e13104dSRandall Stewart 	    asoc->mapping_array_size,
11450e13104dSRandall Stewart 	    asoc->mapping_array_base_tsn,
11460e13104dSRandall Stewart 	    asoc->cumulative_tsn,
1147aed5947cSMichael Tuexen 	    asoc->highest_tsn_inside_map,
1148aed5947cSMichael Tuexen 	    asoc->highest_tsn_inside_nr_map);
1149aed5947cSMichael Tuexen 	for (limit = asoc->mapping_array_size; limit > 1; limit--) {
1150aed5947cSMichael Tuexen 		if (asoc->mapping_array[limit - 1]) {
115177acdc25SRandall Stewart 			break;
115277acdc25SRandall Stewart 		}
115377acdc25SRandall Stewart 	}
1154aed5947cSMichael Tuexen 	printf("Renegable mapping array (last %d entries are zero):\n", asoc->mapping_array_size - limit);
115577acdc25SRandall Stewart 	for (i = 0; i < limit; i++) {
1156aed5947cSMichael Tuexen 		printf("%2.2x%c", asoc->mapping_array[i], ((i + 1) % 16) ? ' ' : '\n');
115777acdc25SRandall Stewart 	}
1158aed5947cSMichael Tuexen 	if (limit % 16)
115977acdc25SRandall Stewart 		printf("\n");
1160aed5947cSMichael Tuexen 	for (limit = asoc->mapping_array_size; limit > 1; limit--) {
1161aed5947cSMichael Tuexen 		if (asoc->nr_mapping_array[limit - 1]) {
116277acdc25SRandall Stewart 			break;
116377acdc25SRandall Stewart 		}
116477acdc25SRandall Stewart 	}
1165aed5947cSMichael Tuexen 	printf("Non renegable mapping array (last %d entries are zero):\n", asoc->mapping_array_size - limit);
116677acdc25SRandall Stewart 	for (i = 0; i < limit; i++) {
1167553aff12SMichael Tuexen 		printf("%2.2x%c", asoc->nr_mapping_array[i], ((i + 1) % 16) ? ' ' : '\n');
11680e13104dSRandall Stewart 	}
1169aed5947cSMichael Tuexen 	if (limit % 16)
11700e13104dSRandall Stewart 		printf("\n");
11710e13104dSRandall Stewart }
11720e13104dSRandall Stewart 
1173f8829a4aSRandall Stewart int
11740696e120SRandall Stewart sctp_expand_mapping_array(struct sctp_association *asoc, uint32_t needed)
1175f8829a4aSRandall Stewart {
1176f8829a4aSRandall Stewart 	/* mapping array needs to grow */
1177b5c16493SMichael Tuexen 	uint8_t *new_array1, *new_array2;
11780696e120SRandall Stewart 	uint32_t new_size;
1179f8829a4aSRandall Stewart 
11800696e120SRandall Stewart 	new_size = asoc->mapping_array_size + ((needed + 7) / 8 + SCTP_MAPPING_ARRAY_INCR);
1181b5c16493SMichael Tuexen 	SCTP_MALLOC(new_array1, uint8_t *, new_size, SCTP_M_MAP);
1182b5c16493SMichael Tuexen 	SCTP_MALLOC(new_array2, uint8_t *, new_size, SCTP_M_MAP);
1183b5c16493SMichael Tuexen 	if ((new_array1 == NULL) || (new_array2 == NULL)) {
1184f8829a4aSRandall Stewart 		/* can't get more, forget it */
1185b5c16493SMichael Tuexen 		SCTP_PRINTF("No memory for expansion of SCTP mapping array %d\n", new_size);
1186b5c16493SMichael Tuexen 		if (new_array1) {
1187b5c16493SMichael Tuexen 			SCTP_FREE(new_array1, SCTP_M_MAP);
1188b5c16493SMichael Tuexen 		}
1189b5c16493SMichael Tuexen 		if (new_array2) {
1190b5c16493SMichael Tuexen 			SCTP_FREE(new_array2, SCTP_M_MAP);
1191b5c16493SMichael Tuexen 		}
1192f8829a4aSRandall Stewart 		return (-1);
1193f8829a4aSRandall Stewart 	}
1194b5c16493SMichael Tuexen 	memset(new_array1, 0, new_size);
1195b5c16493SMichael Tuexen 	memset(new_array2, 0, new_size);
1196b5c16493SMichael Tuexen 	memcpy(new_array1, asoc->mapping_array, asoc->mapping_array_size);
1197b5c16493SMichael Tuexen 	memcpy(new_array2, asoc->nr_mapping_array, asoc->mapping_array_size);
1198207304d4SRandall Stewart 	SCTP_FREE(asoc->mapping_array, SCTP_M_MAP);
1199830d754dSRandall Stewart 	SCTP_FREE(asoc->nr_mapping_array, SCTP_M_MAP);
1200b5c16493SMichael Tuexen 	asoc->mapping_array = new_array1;
1201b5c16493SMichael Tuexen 	asoc->nr_mapping_array = new_array2;
1202b5c16493SMichael Tuexen 	asoc->mapping_array_size = new_size;
1203830d754dSRandall Stewart 	return (0);
1204830d754dSRandall Stewart }
1205830d754dSRandall Stewart 
12068933fa13SRandall Stewart 
120742551e99SRandall Stewart static void
120842551e99SRandall Stewart sctp_iterator_work(struct sctp_iterator *it)
120942551e99SRandall Stewart {
121042551e99SRandall Stewart 	int iteration_count = 0;
121142551e99SRandall Stewart 	int inp_skip = 0;
1212ec4c19fcSRandall Stewart 	int first_in = 1;
1213ec4c19fcSRandall Stewart 	struct sctp_inpcb *tinp;
121442551e99SRandall Stewart 
1215ec4c19fcSRandall Stewart 	SCTP_INP_INFO_RLOCK();
121642551e99SRandall Stewart 	SCTP_ITERATOR_LOCK();
1217ad81507eSRandall Stewart 	if (it->inp) {
1218ec4c19fcSRandall Stewart 		SCTP_INP_RLOCK(it->inp);
121942551e99SRandall Stewart 		SCTP_INP_DECR_REF(it->inp);
1220ad81507eSRandall Stewart 	}
122142551e99SRandall Stewart 	if (it->inp == NULL) {
122242551e99SRandall Stewart 		/* iterator is complete */
122342551e99SRandall Stewart done_with_iterator:
122442551e99SRandall Stewart 		SCTP_ITERATOR_UNLOCK();
1225ec4c19fcSRandall Stewart 		SCTP_INP_INFO_RUNLOCK();
122642551e99SRandall Stewart 		if (it->function_atend != NULL) {
122742551e99SRandall Stewart 			(*it->function_atend) (it->pointer, it->val);
122842551e99SRandall Stewart 		}
1229207304d4SRandall Stewart 		SCTP_FREE(it, SCTP_M_ITER);
123042551e99SRandall Stewart 		return;
123142551e99SRandall Stewart 	}
123242551e99SRandall Stewart select_a_new_ep:
1233ec4c19fcSRandall Stewart 	if (first_in) {
1234ec4c19fcSRandall Stewart 		first_in = 0;
1235ec4c19fcSRandall Stewart 	} else {
1236f7517433SRandall Stewart 		SCTP_INP_RLOCK(it->inp);
1237ec4c19fcSRandall Stewart 	}
123842551e99SRandall Stewart 	while (((it->pcb_flags) &&
123942551e99SRandall Stewart 	    ((it->inp->sctp_flags & it->pcb_flags) != it->pcb_flags)) ||
124042551e99SRandall Stewart 	    ((it->pcb_features) &&
124142551e99SRandall Stewart 	    ((it->inp->sctp_features & it->pcb_features) != it->pcb_features))) {
124242551e99SRandall Stewart 		/* endpoint flags or features don't match, so keep looking */
124342551e99SRandall Stewart 		if (it->iterator_flags & SCTP_ITERATOR_DO_SINGLE_INP) {
1244f7517433SRandall Stewart 			SCTP_INP_RUNLOCK(it->inp);
124542551e99SRandall Stewart 			goto done_with_iterator;
124642551e99SRandall Stewart 		}
1247ec4c19fcSRandall Stewart 		tinp = it->inp;
124842551e99SRandall Stewart 		it->inp = LIST_NEXT(it->inp, sctp_list);
1249ec4c19fcSRandall Stewart 		SCTP_INP_RUNLOCK(tinp);
125042551e99SRandall Stewart 		if (it->inp == NULL) {
125142551e99SRandall Stewart 			goto done_with_iterator;
125242551e99SRandall Stewart 		}
125342551e99SRandall Stewart 		SCTP_INP_RLOCK(it->inp);
1254f7517433SRandall Stewart 	}
125542551e99SRandall Stewart 	/* now go through each assoc which is in the desired state */
125642551e99SRandall Stewart 	if (it->done_current_ep == 0) {
125742551e99SRandall Stewart 		if (it->function_inp != NULL)
125842551e99SRandall Stewart 			inp_skip = (*it->function_inp) (it->inp, it->pointer, it->val);
125942551e99SRandall Stewart 		it->done_current_ep = 1;
126042551e99SRandall Stewart 	}
126142551e99SRandall Stewart 	if (it->stcb == NULL) {
126242551e99SRandall Stewart 		/* run the per instance function */
126342551e99SRandall Stewart 		it->stcb = LIST_FIRST(&it->inp->sctp_asoc_list);
126442551e99SRandall Stewart 	}
126542551e99SRandall Stewart 	if ((inp_skip) || it->stcb == NULL) {
126642551e99SRandall Stewart 		if (it->function_inp_end != NULL) {
126742551e99SRandall Stewart 			inp_skip = (*it->function_inp_end) (it->inp,
126842551e99SRandall Stewart 			    it->pointer,
126942551e99SRandall Stewart 			    it->val);
127042551e99SRandall Stewart 		}
127142551e99SRandall Stewart 		SCTP_INP_RUNLOCK(it->inp);
127242551e99SRandall Stewart 		goto no_stcb;
127342551e99SRandall Stewart 	}
127442551e99SRandall Stewart 	while (it->stcb) {
127542551e99SRandall Stewart 		SCTP_TCB_LOCK(it->stcb);
127642551e99SRandall Stewart 		if (it->asoc_state && ((it->stcb->asoc.state & it->asoc_state) != it->asoc_state)) {
127742551e99SRandall Stewart 			/* not in the right state... keep looking */
127842551e99SRandall Stewart 			SCTP_TCB_UNLOCK(it->stcb);
127942551e99SRandall Stewart 			goto next_assoc;
128042551e99SRandall Stewart 		}
128142551e99SRandall Stewart 		/* see if we have limited out the iterator loop */
128242551e99SRandall Stewart 		iteration_count++;
128342551e99SRandall Stewart 		if (iteration_count > SCTP_ITERATOR_MAX_AT_ONCE) {
128442551e99SRandall Stewart 			/* Pause to let others grab the lock */
128542551e99SRandall Stewart 			atomic_add_int(&it->stcb->asoc.refcnt, 1);
128642551e99SRandall Stewart 			SCTP_TCB_UNLOCK(it->stcb);
1287c4739e2fSRandall Stewart 			SCTP_INP_INCR_REF(it->inp);
128842551e99SRandall Stewart 			SCTP_INP_RUNLOCK(it->inp);
128942551e99SRandall Stewart 			SCTP_ITERATOR_UNLOCK();
1290ec4c19fcSRandall Stewart 			SCTP_INP_INFO_RUNLOCK();
1291ec4c19fcSRandall Stewart 			SCTP_INP_INFO_RLOCK();
129242551e99SRandall Stewart 			SCTP_ITERATOR_LOCK();
1293f7517433SRandall Stewart 			if (sctp_it_ctl.iterator_flags) {
1294f7517433SRandall Stewart 				/* We won't be staying here */
1295f7517433SRandall Stewart 				SCTP_INP_DECR_REF(it->inp);
1296f7517433SRandall Stewart 				atomic_add_int(&it->stcb->asoc.refcnt, -1);
1297f7517433SRandall Stewart 				if (sctp_it_ctl.iterator_flags &
1298f7517433SRandall Stewart 				    SCTP_ITERATOR_MUST_EXIT) {
1299f7517433SRandall Stewart 					goto done_with_iterator;
1300f7517433SRandall Stewart 				}
1301f7517433SRandall Stewart 				if (sctp_it_ctl.iterator_flags &
1302f7517433SRandall Stewart 				    SCTP_ITERATOR_STOP_CUR_IT) {
1303f7517433SRandall Stewart 					sctp_it_ctl.iterator_flags &= ~SCTP_ITERATOR_STOP_CUR_IT;
1304f7517433SRandall Stewart 					goto done_with_iterator;
1305f7517433SRandall Stewart 				}
1306f7517433SRandall Stewart 				if (sctp_it_ctl.iterator_flags &
1307f7517433SRandall Stewart 				    SCTP_ITERATOR_STOP_CUR_INP) {
1308f7517433SRandall Stewart 					sctp_it_ctl.iterator_flags &= ~SCTP_ITERATOR_STOP_CUR_INP;
1309f7517433SRandall Stewart 					goto no_stcb;
1310f7517433SRandall Stewart 				}
1311f7517433SRandall Stewart 				/* If we reach here huh? */
1312f7517433SRandall Stewart 				printf("Unknown it ctl flag %x\n",
1313f7517433SRandall Stewart 				    sctp_it_ctl.iterator_flags);
1314f7517433SRandall Stewart 				sctp_it_ctl.iterator_flags = 0;
1315f7517433SRandall Stewart 			}
131642551e99SRandall Stewart 			SCTP_INP_RLOCK(it->inp);
1317c4739e2fSRandall Stewart 			SCTP_INP_DECR_REF(it->inp);
131842551e99SRandall Stewart 			SCTP_TCB_LOCK(it->stcb);
131942551e99SRandall Stewart 			atomic_add_int(&it->stcb->asoc.refcnt, -1);
132042551e99SRandall Stewart 			iteration_count = 0;
132142551e99SRandall Stewart 		}
132242551e99SRandall Stewart 		/* run function on this one */
132342551e99SRandall Stewart 		(*it->function_assoc) (it->inp, it->stcb, it->pointer, it->val);
132442551e99SRandall Stewart 
132542551e99SRandall Stewart 		/*
132642551e99SRandall Stewart 		 * we lie here, it really needs to have its own type but
132742551e99SRandall Stewart 		 * first I must verify that this won't effect things :-0
132842551e99SRandall Stewart 		 */
132942551e99SRandall Stewart 		if (it->no_chunk_output == 0)
1330ceaad40aSRandall Stewart 			sctp_chunk_output(it->inp, it->stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
133142551e99SRandall Stewart 
133242551e99SRandall Stewart 		SCTP_TCB_UNLOCK(it->stcb);
133342551e99SRandall Stewart next_assoc:
133442551e99SRandall Stewart 		it->stcb = LIST_NEXT(it->stcb, sctp_tcblist);
133542551e99SRandall Stewart 		if (it->stcb == NULL) {
133642551e99SRandall Stewart 			/* Run last function */
133742551e99SRandall Stewart 			if (it->function_inp_end != NULL) {
133842551e99SRandall Stewart 				inp_skip = (*it->function_inp_end) (it->inp,
133942551e99SRandall Stewart 				    it->pointer,
134042551e99SRandall Stewart 				    it->val);
134142551e99SRandall Stewart 			}
134242551e99SRandall Stewart 		}
134342551e99SRandall Stewart 	}
134442551e99SRandall Stewart 	SCTP_INP_RUNLOCK(it->inp);
134542551e99SRandall Stewart no_stcb:
134642551e99SRandall Stewart 	/* done with all assocs on this endpoint, move on to next endpoint */
134742551e99SRandall Stewart 	it->done_current_ep = 0;
134842551e99SRandall Stewart 	if (it->iterator_flags & SCTP_ITERATOR_DO_SINGLE_INP) {
134942551e99SRandall Stewart 		it->inp = NULL;
135042551e99SRandall Stewart 	} else {
135142551e99SRandall Stewart 		it->inp = LIST_NEXT(it->inp, sctp_list);
135242551e99SRandall Stewart 	}
135342551e99SRandall Stewart 	if (it->inp == NULL) {
135442551e99SRandall Stewart 		goto done_with_iterator;
135542551e99SRandall Stewart 	}
135642551e99SRandall Stewart 	goto select_a_new_ep;
135742551e99SRandall Stewart }
135842551e99SRandall Stewart 
135942551e99SRandall Stewart void
136042551e99SRandall Stewart sctp_iterator_worker(void)
136142551e99SRandall Stewart {
13624a9ef3f8SMichael Tuexen 	struct sctp_iterator *it, *nit;
136342551e99SRandall Stewart 
136442551e99SRandall Stewart 	/* This function is called with the WQ lock in place */
136542551e99SRandall Stewart 
1366f7517433SRandall Stewart 	sctp_it_ctl.iterator_running = 1;
13674a9ef3f8SMichael Tuexen 	TAILQ_FOREACH_SAFE(it, &sctp_it_ctl.iteratorhead, sctp_nxt_itr, nit) {
13684a9ef3f8SMichael Tuexen 		sctp_it_ctl.cur_it = it;
136942551e99SRandall Stewart 		/* now lets work on this one */
1370f7517433SRandall Stewart 		TAILQ_REMOVE(&sctp_it_ctl.iteratorhead, it, sctp_nxt_itr);
137142551e99SRandall Stewart 		SCTP_IPI_ITERATOR_WQ_UNLOCK();
1372f7517433SRandall Stewart 		CURVNET_SET(it->vn);
137342551e99SRandall Stewart 		sctp_iterator_work(it);
1374f79aab18SRandall Stewart 		sctp_it_ctl.cur_it = NULL;
1375f7517433SRandall Stewart 		CURVNET_RESTORE();
137642551e99SRandall Stewart 		SCTP_IPI_ITERATOR_WQ_LOCK();
1377f7517433SRandall Stewart 		if (sctp_it_ctl.iterator_flags & SCTP_ITERATOR_MUST_EXIT) {
1378f7517433SRandall Stewart 			break;
1379f7517433SRandall Stewart 		}
13803c503c28SRandall Stewart 		/* sa_ignore FREED_MEMORY */
138142551e99SRandall Stewart 	}
1382f7517433SRandall Stewart 	sctp_it_ctl.iterator_running = 0;
138342551e99SRandall Stewart 	return;
138442551e99SRandall Stewart }
138542551e99SRandall Stewart 
1386f8829a4aSRandall Stewart 
1387f8829a4aSRandall Stewart static void
1388f8829a4aSRandall Stewart sctp_handle_addr_wq(void)
1389f8829a4aSRandall Stewart {
1390f8829a4aSRandall Stewart 	/* deal with the ADDR wq from the rtsock calls */
13914a9ef3f8SMichael Tuexen 	struct sctp_laddr *wi, *nwi;
139242551e99SRandall Stewart 	struct sctp_asconf_iterator *asc;
1393f8829a4aSRandall Stewart 
139442551e99SRandall Stewart 	SCTP_MALLOC(asc, struct sctp_asconf_iterator *,
1395207304d4SRandall Stewart 	    sizeof(struct sctp_asconf_iterator), SCTP_M_ASC_IT);
139642551e99SRandall Stewart 	if (asc == NULL) {
139742551e99SRandall Stewart 		/* Try later, no memory */
1398f8829a4aSRandall Stewart 		sctp_timer_start(SCTP_TIMER_TYPE_ADDR_WQ,
1399f8829a4aSRandall Stewart 		    (struct sctp_inpcb *)NULL,
1400f8829a4aSRandall Stewart 		    (struct sctp_tcb *)NULL,
1401f8829a4aSRandall Stewart 		    (struct sctp_nets *)NULL);
140242551e99SRandall Stewart 		return;
1403f8829a4aSRandall Stewart 	}
140442551e99SRandall Stewart 	LIST_INIT(&asc->list_of_work);
140542551e99SRandall Stewart 	asc->cnt = 0;
1406f7517433SRandall Stewart 
1407f7517433SRandall Stewart 	SCTP_WQ_ADDR_LOCK();
14084a9ef3f8SMichael Tuexen 	LIST_FOREACH_SAFE(wi, &SCTP_BASE_INFO(addr_wq), sctp_nxt_addr, nwi) {
140942551e99SRandall Stewart 		LIST_REMOVE(wi, sctp_nxt_addr);
141042551e99SRandall Stewart 		LIST_INSERT_HEAD(&asc->list_of_work, wi, sctp_nxt_addr);
141142551e99SRandall Stewart 		asc->cnt++;
1412f8829a4aSRandall Stewart 	}
1413f7517433SRandall Stewart 	SCTP_WQ_ADDR_UNLOCK();
1414f7517433SRandall Stewart 
141542551e99SRandall Stewart 	if (asc->cnt == 0) {
1416207304d4SRandall Stewart 		SCTP_FREE(asc, SCTP_M_ASC_IT);
141742551e99SRandall Stewart 	} else {
14181b649582SRandall Stewart 		(void)sctp_initiate_iterator(sctp_asconf_iterator_ep,
14191b649582SRandall Stewart 		    sctp_asconf_iterator_stcb,
142042551e99SRandall Stewart 		    NULL,	/* No ep end for boundall */
142142551e99SRandall Stewart 		    SCTP_PCB_FLAGS_BOUNDALL,
142242551e99SRandall Stewart 		    SCTP_PCB_ANY_FEATURES,
14231b649582SRandall Stewart 		    SCTP_ASOC_ANY_STATE,
14241b649582SRandall Stewart 		    (void *)asc, 0,
14251b649582SRandall Stewart 		    sctp_asconf_iterator_end, NULL, 0);
142642551e99SRandall Stewart 	}
1427f8829a4aSRandall Stewart }
1428f8829a4aSRandall Stewart 
1429b54d3a6cSRandall Stewart int retcode = 0;
1430b54d3a6cSRandall Stewart int cur_oerr = 0;
1431b54d3a6cSRandall Stewart 
1432f8829a4aSRandall Stewart void
1433f8829a4aSRandall Stewart sctp_timeout_handler(void *t)
1434f8829a4aSRandall Stewart {
1435f8829a4aSRandall Stewart 	struct sctp_inpcb *inp;
1436f8829a4aSRandall Stewart 	struct sctp_tcb *stcb;
1437f8829a4aSRandall Stewart 	struct sctp_nets *net;
1438f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
1439ceaad40aSRandall Stewart 
1440ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
1441ceaad40aSRandall Stewart 	struct socket *so;
1442ceaad40aSRandall Stewart 
1443ceaad40aSRandall Stewart #endif
1444d61374e1SRandall Stewart 	int did_output, type;
1445f8829a4aSRandall Stewart 
1446f8829a4aSRandall Stewart 	tmr = (struct sctp_timer *)t;
1447f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)tmr->ep;
1448f8829a4aSRandall Stewart 	stcb = (struct sctp_tcb *)tmr->tcb;
1449f8829a4aSRandall Stewart 	net = (struct sctp_nets *)tmr->net;
14508518270eSMichael Tuexen 	CURVNET_SET((struct vnet *)tmr->vnet);
1451f8829a4aSRandall Stewart 	did_output = 1;
1452f8829a4aSRandall Stewart 
1453f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1454f8829a4aSRandall Stewart 	sctp_audit_log(0xF0, (uint8_t) tmr->type);
1455f8829a4aSRandall Stewart 	sctp_auditing(3, inp, stcb, net);
1456f8829a4aSRandall Stewart #endif
1457f8829a4aSRandall Stewart 
1458f8829a4aSRandall Stewart 	/* sanity checks... */
1459f8829a4aSRandall Stewart 	if (tmr->self != (void *)tmr) {
1460f8829a4aSRandall Stewart 		/*
1461ad81507eSRandall Stewart 		 * SCTP_PRINTF("Stale SCTP timer fired (%p), ignoring...\n",
1462f8829a4aSRandall Stewart 		 * tmr);
1463f8829a4aSRandall Stewart 		 */
14648518270eSMichael Tuexen 		CURVNET_RESTORE();
1465f8829a4aSRandall Stewart 		return;
1466f8829a4aSRandall Stewart 	}
1467a5d547adSRandall Stewart 	tmr->stopped_from = 0xa001;
1468f8829a4aSRandall Stewart 	if (!SCTP_IS_TIMER_TYPE_VALID(tmr->type)) {
1469f8829a4aSRandall Stewart 		/*
1470ad81507eSRandall Stewart 		 * SCTP_PRINTF("SCTP timer fired with invalid type: 0x%x\n",
1471f8829a4aSRandall Stewart 		 * tmr->type);
1472f8829a4aSRandall Stewart 		 */
14738518270eSMichael Tuexen 		CURVNET_RESTORE();
1474f8829a4aSRandall Stewart 		return;
1475f8829a4aSRandall Stewart 	}
1476a5d547adSRandall Stewart 	tmr->stopped_from = 0xa002;
1477f8829a4aSRandall Stewart 	if ((tmr->type != SCTP_TIMER_TYPE_ADDR_WQ) && (inp == NULL)) {
14788518270eSMichael Tuexen 		CURVNET_RESTORE();
1479f8829a4aSRandall Stewart 		return;
1480f8829a4aSRandall Stewart 	}
1481f8829a4aSRandall Stewart 	/* if this is an iterator timeout, get the struct and clear inp */
1482a5d547adSRandall Stewart 	tmr->stopped_from = 0xa003;
1483d61374e1SRandall Stewart 	type = tmr->type;
1484f8829a4aSRandall Stewart 	if (inp) {
1485f8829a4aSRandall Stewart 		SCTP_INP_INCR_REF(inp);
1486f8829a4aSRandall Stewart 		if ((inp->sctp_socket == 0) &&
1487f8829a4aSRandall Stewart 		    ((tmr->type != SCTP_TIMER_TYPE_INPKILL) &&
1488810ec536SMichael Tuexen 		    (tmr->type != SCTP_TIMER_TYPE_INIT) &&
1489a1e13272SRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_SEND) &&
1490a1e13272SRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_RECV) &&
1491a1e13272SRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_HEARTBEAT) &&
1492f8829a4aSRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_SHUTDOWN) &&
1493f8829a4aSRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_SHUTDOWNACK) &&
1494f8829a4aSRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_SHUTDOWNGUARD) &&
1495f8829a4aSRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_ASOCKILL))
1496f8829a4aSRandall Stewart 		    ) {
1497f8829a4aSRandall Stewart 			SCTP_INP_DECR_REF(inp);
14988518270eSMichael Tuexen 			CURVNET_RESTORE();
1499f8829a4aSRandall Stewart 			return;
1500f8829a4aSRandall Stewart 		}
1501f8829a4aSRandall Stewart 	}
1502a5d547adSRandall Stewart 	tmr->stopped_from = 0xa004;
1503f8829a4aSRandall Stewart 	if (stcb) {
1504c105859eSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
1505f8829a4aSRandall Stewart 		if (stcb->asoc.state == 0) {
1506c105859eSRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, -1);
1507f8829a4aSRandall Stewart 			if (inp) {
1508f8829a4aSRandall Stewart 				SCTP_INP_DECR_REF(inp);
1509f8829a4aSRandall Stewart 			}
15108518270eSMichael Tuexen 			CURVNET_RESTORE();
1511f8829a4aSRandall Stewart 			return;
1512f8829a4aSRandall Stewart 		}
1513f8829a4aSRandall Stewart 	}
1514a5d547adSRandall Stewart 	tmr->stopped_from = 0xa005;
1515ad81507eSRandall Stewart 	SCTPDBG(SCTP_DEBUG_TIMER1, "Timer type %d goes off\n", tmr->type);
1516139bc87fSRandall Stewart 	if (!SCTP_OS_TIMER_ACTIVE(&tmr->timer)) {
1517f8829a4aSRandall Stewart 		if (inp) {
1518f8829a4aSRandall Stewart 			SCTP_INP_DECR_REF(inp);
1519f8829a4aSRandall Stewart 		}
1520207304d4SRandall Stewart 		if (stcb) {
1521207304d4SRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, -1);
1522207304d4SRandall Stewart 		}
15238518270eSMichael Tuexen 		CURVNET_RESTORE();
1524f8829a4aSRandall Stewart 		return;
1525f8829a4aSRandall Stewart 	}
1526a5d547adSRandall Stewart 	tmr->stopped_from = 0xa006;
1527a5d547adSRandall Stewart 
1528f8829a4aSRandall Stewart 	if (stcb) {
1529f8829a4aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
153050cec919SRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, -1);
1531b54d3a6cSRandall Stewart 		if ((tmr->type != SCTP_TIMER_TYPE_ASOCKILL) &&
1532b54d3a6cSRandall Stewart 		    ((stcb->asoc.state == 0) ||
1533b54d3a6cSRandall Stewart 		    (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED))) {
1534b54d3a6cSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
1535b54d3a6cSRandall Stewart 			if (inp) {
1536b54d3a6cSRandall Stewart 				SCTP_INP_DECR_REF(inp);
1537b54d3a6cSRandall Stewart 			}
15388518270eSMichael Tuexen 			CURVNET_RESTORE();
1539b54d3a6cSRandall Stewart 			return;
1540b54d3a6cSRandall Stewart 		}
1541f8829a4aSRandall Stewart 	}
154244b7479bSRandall Stewart 	/* record in stopped what t-o occured */
154344b7479bSRandall Stewart 	tmr->stopped_from = tmr->type;
154444b7479bSRandall Stewart 
1545f8829a4aSRandall Stewart 	/* mark as being serviced now */
154644b7479bSRandall Stewart 	if (SCTP_OS_TIMER_PENDING(&tmr->timer)) {
154744b7479bSRandall Stewart 		/*
154844b7479bSRandall Stewart 		 * Callout has been rescheduled.
154944b7479bSRandall Stewart 		 */
155044b7479bSRandall Stewart 		goto get_out;
155144b7479bSRandall Stewart 	}
155244b7479bSRandall Stewart 	if (!SCTP_OS_TIMER_ACTIVE(&tmr->timer)) {
155344b7479bSRandall Stewart 		/*
155444b7479bSRandall Stewart 		 * Not active, so no action.
155544b7479bSRandall Stewart 		 */
155644b7479bSRandall Stewart 		goto get_out;
155744b7479bSRandall Stewart 	}
1558139bc87fSRandall Stewart 	SCTP_OS_TIMER_DEACTIVATE(&tmr->timer);
1559f8829a4aSRandall Stewart 
1560f8829a4aSRandall Stewart 	/* call the handler for the appropriate timer type */
1561f8829a4aSRandall Stewart 	switch (tmr->type) {
1562d61a0ae0SRandall Stewart 	case SCTP_TIMER_TYPE_ZERO_COPY:
1563eacc51c5SRandall Stewart 		if (inp == NULL) {
1564eacc51c5SRandall Stewart 			break;
1565eacc51c5SRandall Stewart 		}
1566d61a0ae0SRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_ZERO_COPY_ACTIVE)) {
1567d61a0ae0SRandall Stewart 			SCTP_ZERO_COPY_EVENT(inp, inp->sctp_socket);
1568d61a0ae0SRandall Stewart 		}
1569d61a0ae0SRandall Stewart 		break;
1570ad21a364SRandall Stewart 	case SCTP_TIMER_TYPE_ZCOPY_SENDQ:
1571eacc51c5SRandall Stewart 		if (inp == NULL) {
1572eacc51c5SRandall Stewart 			break;
1573eacc51c5SRandall Stewart 		}
1574ad21a364SRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_ZERO_COPY_ACTIVE)) {
1575ad21a364SRandall Stewart 			SCTP_ZERO_COPY_SENDQ_EVENT(inp, inp->sctp_socket);
1576ad21a364SRandall Stewart 		}
1577ad21a364SRandall Stewart 		break;
1578f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ADDR_WQ:
1579f8829a4aSRandall Stewart 		sctp_handle_addr_wq();
1580f8829a4aSRandall Stewart 		break;
1581f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
1582ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1583ad81507eSRandall Stewart 			break;
1584ad81507eSRandall Stewart 		}
1585f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timodata);
1586f42a358aSRandall Stewart 		stcb->asoc.timodata++;
1587f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up--;
1588f8829a4aSRandall Stewart 		if (stcb->asoc.num_send_timers_up < 0) {
1589f8829a4aSRandall Stewart 			stcb->asoc.num_send_timers_up = 0;
1590f8829a4aSRandall Stewart 		}
1591b54d3a6cSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
1592b54d3a6cSRandall Stewart 		cur_oerr = stcb->asoc.overall_error_count;
1593b54d3a6cSRandall Stewart 		retcode = sctp_t3rxt_timer(inp, stcb, net);
1594b54d3a6cSRandall Stewart 		if (retcode) {
1595f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1596f8829a4aSRandall Stewart 
1597f8829a4aSRandall Stewart 			goto out_decr;
1598f8829a4aSRandall Stewart 		}
1599b54d3a6cSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
1600f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1601f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1602f8829a4aSRandall Stewart #endif
1603ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
1604f8829a4aSRandall Stewart 		if ((stcb->asoc.num_send_timers_up == 0) &&
16054a9ef3f8SMichael Tuexen 		    (stcb->asoc.sent_queue_cnt > 0)) {
1606f8829a4aSRandall Stewart 			struct sctp_tmit_chunk *chk;
1607f8829a4aSRandall Stewart 
1608f8829a4aSRandall Stewart 			/*
1609f8829a4aSRandall Stewart 			 * safeguard. If there on some on the sent queue
1610f8829a4aSRandall Stewart 			 * somewhere but no timers running something is
1611f8829a4aSRandall Stewart 			 * wrong... so we start a timer on the first chunk
1612f8829a4aSRandall Stewart 			 * on the send queue on whatever net it is sent to.
1613f8829a4aSRandall Stewart 			 */
1614f8829a4aSRandall Stewart 			chk = TAILQ_FIRST(&stcb->asoc.sent_queue);
1615f8829a4aSRandall Stewart 			sctp_timer_start(SCTP_TIMER_TYPE_SEND, inp, stcb,
1616f8829a4aSRandall Stewart 			    chk->whoTo);
1617f8829a4aSRandall Stewart 		}
1618f8829a4aSRandall Stewart 		break;
1619f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
1620ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1621ad81507eSRandall Stewart 			break;
1622ad81507eSRandall Stewart 		}
1623f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoinit);
1624f42a358aSRandall Stewart 		stcb->asoc.timoinit++;
1625f8829a4aSRandall Stewart 		if (sctp_t1init_timer(inp, stcb, net)) {
1626f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1627f8829a4aSRandall Stewart 			goto out_decr;
1628f8829a4aSRandall Stewart 		}
1629f8829a4aSRandall Stewart 		/* We do output but not here */
1630f8829a4aSRandall Stewart 		did_output = 0;
1631f8829a4aSRandall Stewart 		break;
1632f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
1633ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1634ad81507eSRandall Stewart 			break;
1635c4739e2fSRandall Stewart 		} {
1636f8829a4aSRandall Stewart 			SCTP_STAT_INCR(sctps_timosack);
1637f42a358aSRandall Stewart 			stcb->asoc.timosack++;
1638689e6a5fSMichael Tuexen 			sctp_send_sack(stcb, SCTP_SO_NOT_LOCKED);
1639c4739e2fSRandall Stewart 		}
1640f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1641f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1642f8829a4aSRandall Stewart #endif
1643ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SACK_TMR, SCTP_SO_NOT_LOCKED);
1644f8829a4aSRandall Stewart 		break;
1645f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
1646ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1647ad81507eSRandall Stewart 			break;
1648ad81507eSRandall Stewart 		}
1649f8829a4aSRandall Stewart 		if (sctp_shutdown_timer(inp, stcb, net)) {
1650f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1651f8829a4aSRandall Stewart 			goto out_decr;
1652f8829a4aSRandall Stewart 		}
1653f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoshutdown);
1654f42a358aSRandall Stewart 		stcb->asoc.timoshutdown++;
1655f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1656f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1657f8829a4aSRandall Stewart #endif
1658ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SHUT_TMR, SCTP_SO_NOT_LOCKED);
1659f8829a4aSRandall Stewart 		break;
1660f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
1661f8829a4aSRandall Stewart 		{
16624c9179adSRandall Stewart 			struct sctp_nets *lnet;
1663f8829a4aSRandall Stewart 			int cnt_of_unconf = 0;
1664f8829a4aSRandall Stewart 
1665ad81507eSRandall Stewart 			if ((stcb == NULL) || (inp == NULL)) {
1666ad81507eSRandall Stewart 				break;
1667ad81507eSRandall Stewart 			}
1668f8829a4aSRandall Stewart 			SCTP_STAT_INCR(sctps_timoheartbeat);
1669f42a358aSRandall Stewart 			stcb->asoc.timoheartbeat++;
16704c9179adSRandall Stewart 			TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
16714c9179adSRandall Stewart 				if ((lnet->dest_state & SCTP_ADDR_UNCONFIRMED) &&
16724c9179adSRandall Stewart 				    (lnet->dest_state & SCTP_ADDR_REACHABLE)) {
1673f8829a4aSRandall Stewart 					cnt_of_unconf++;
1674f8829a4aSRandall Stewart 				}
1675f8829a4aSRandall Stewart 			}
1676f8829a4aSRandall Stewart 			if (cnt_of_unconf == 0) {
16774c9179adSRandall Stewart 				if (sctp_heartbeat_timer(inp, stcb, lnet,
16784c9179adSRandall Stewart 				    cnt_of_unconf)) {
1679f8829a4aSRandall Stewart 					/* no need to unlock on tcb its gone */
1680f8829a4aSRandall Stewart 					goto out_decr;
1681f8829a4aSRandall Stewart 				}
1682f8829a4aSRandall Stewart 			}
1683f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
16844c9179adSRandall Stewart 			sctp_auditing(4, inp, stcb, lnet);
1685f8829a4aSRandall Stewart #endif
16864c9179adSRandall Stewart 			sctp_timer_start(SCTP_TIMER_TYPE_HEARTBEAT,
16874c9179adSRandall Stewart 			    stcb->sctp_ep, stcb, lnet);
1688ceaad40aSRandall Stewart 			sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_HB_TMR, SCTP_SO_NOT_LOCKED);
1689f8829a4aSRandall Stewart 		}
1690f8829a4aSRandall Stewart 		break;
1691f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
1692ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1693ad81507eSRandall Stewart 			break;
1694ad81507eSRandall Stewart 		}
1695f8829a4aSRandall Stewart 		if (sctp_cookie_timer(inp, stcb, net)) {
1696f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1697f8829a4aSRandall Stewart 			goto out_decr;
1698f8829a4aSRandall Stewart 		}
1699f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timocookie);
1700f42a358aSRandall Stewart 		stcb->asoc.timocookie++;
1701f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1702f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1703f8829a4aSRandall Stewart #endif
1704f8829a4aSRandall Stewart 		/*
1705f8829a4aSRandall Stewart 		 * We consider T3 and Cookie timer pretty much the same with
1706f8829a4aSRandall Stewart 		 * respect to where from in chunk_output.
1707f8829a4aSRandall Stewart 		 */
1708ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
1709f8829a4aSRandall Stewart 		break;
1710f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
1711f8829a4aSRandall Stewart 		{
1712f8829a4aSRandall Stewart 			struct timeval tv;
1713f8829a4aSRandall Stewart 			int i, secret;
1714f8829a4aSRandall Stewart 
1715ad81507eSRandall Stewart 			if (inp == NULL) {
1716ad81507eSRandall Stewart 				break;
1717ad81507eSRandall Stewart 			}
1718f8829a4aSRandall Stewart 			SCTP_STAT_INCR(sctps_timosecret);
17196e55db54SRandall Stewart 			(void)SCTP_GETTIME_TIMEVAL(&tv);
1720f8829a4aSRandall Stewart 			SCTP_INP_WLOCK(inp);
1721f8829a4aSRandall Stewart 			inp->sctp_ep.time_of_secret_change = tv.tv_sec;
1722f8829a4aSRandall Stewart 			inp->sctp_ep.last_secret_number =
1723f8829a4aSRandall Stewart 			    inp->sctp_ep.current_secret_number;
1724f8829a4aSRandall Stewart 			inp->sctp_ep.current_secret_number++;
1725f8829a4aSRandall Stewart 			if (inp->sctp_ep.current_secret_number >=
1726f8829a4aSRandall Stewart 			    SCTP_HOW_MANY_SECRETS) {
1727f8829a4aSRandall Stewart 				inp->sctp_ep.current_secret_number = 0;
1728f8829a4aSRandall Stewart 			}
1729f8829a4aSRandall Stewart 			secret = (int)inp->sctp_ep.current_secret_number;
1730f8829a4aSRandall Stewart 			for (i = 0; i < SCTP_NUMBER_OF_SECRETS; i++) {
1731f8829a4aSRandall Stewart 				inp->sctp_ep.secret_key[secret][i] =
1732f8829a4aSRandall Stewart 				    sctp_select_initial_TSN(&inp->sctp_ep);
1733f8829a4aSRandall Stewart 			}
1734f8829a4aSRandall Stewart 			SCTP_INP_WUNLOCK(inp);
1735f8829a4aSRandall Stewart 			sctp_timer_start(SCTP_TIMER_TYPE_NEWCOOKIE, inp, stcb, net);
1736f8829a4aSRandall Stewart 		}
1737f8829a4aSRandall Stewart 		did_output = 0;
1738f8829a4aSRandall Stewart 		break;
1739f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
1740ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1741ad81507eSRandall Stewart 			break;
1742ad81507eSRandall Stewart 		}
1743f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timopathmtu);
1744f8829a4aSRandall Stewart 		sctp_pathmtu_timer(inp, stcb, net);
1745f8829a4aSRandall Stewart 		did_output = 0;
1746f8829a4aSRandall Stewart 		break;
1747f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
1748ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1749ad81507eSRandall Stewart 			break;
1750ad81507eSRandall Stewart 		}
1751f8829a4aSRandall Stewart 		if (sctp_shutdownack_timer(inp, stcb, net)) {
1752f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1753f8829a4aSRandall Stewart 			goto out_decr;
1754f8829a4aSRandall Stewart 		}
1755f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoshutdownack);
1756f42a358aSRandall Stewart 		stcb->asoc.timoshutdownack++;
1757f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1758f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1759f8829a4aSRandall Stewart #endif
1760ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SHUT_ACK_TMR, SCTP_SO_NOT_LOCKED);
1761f8829a4aSRandall Stewart 		break;
1762f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
1763ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1764ad81507eSRandall Stewart 			break;
1765ad81507eSRandall Stewart 		}
1766f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoshutdownguard);
1767f8829a4aSRandall Stewart 		sctp_abort_an_association(inp, stcb,
1768ceaad40aSRandall Stewart 		    SCTP_SHUTDOWN_GUARD_EXPIRES, NULL, SCTP_SO_NOT_LOCKED);
1769f8829a4aSRandall Stewart 		/* no need to unlock on tcb its gone */
1770f8829a4aSRandall Stewart 		goto out_decr;
1771f8829a4aSRandall Stewart 
1772f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_STRRESET:
1773ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1774ad81507eSRandall Stewart 			break;
1775ad81507eSRandall Stewart 		}
1776f8829a4aSRandall Stewart 		if (sctp_strreset_timer(inp, stcb, net)) {
1777f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1778f8829a4aSRandall Stewart 			goto out_decr;
1779f8829a4aSRandall Stewart 		}
1780f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timostrmrst);
1781ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_STRRST_TMR, SCTP_SO_NOT_LOCKED);
1782f8829a4aSRandall Stewart 		break;
1783f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_EARLYFR:
1784f8829a4aSRandall Stewart 		/* Need to do FR of things for net */
1785ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1786ad81507eSRandall Stewart 			break;
1787ad81507eSRandall Stewart 		}
1788f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoearlyfr);
1789f8829a4aSRandall Stewart 		sctp_early_fr_timer(inp, stcb, net);
1790f8829a4aSRandall Stewart 		break;
1791f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASCONF:
1792ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1793ad81507eSRandall Stewart 			break;
1794ad81507eSRandall Stewart 		}
1795f8829a4aSRandall Stewart 		if (sctp_asconf_timer(inp, stcb, net)) {
1796f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1797f8829a4aSRandall Stewart 			goto out_decr;
1798f8829a4aSRandall Stewart 		}
1799f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoasconf);
1800f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1801f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1802f8829a4aSRandall Stewart #endif
1803ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_ASCONF_TMR, SCTP_SO_NOT_LOCKED);
1804f8829a4aSRandall Stewart 		break;
1805851b7298SRandall Stewart 	case SCTP_TIMER_TYPE_PRIM_DELETED:
1806851b7298SRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1807851b7298SRandall Stewart 			break;
1808851b7298SRandall Stewart 		}
180904ee05e8SRandall Stewart 		sctp_delete_prim_timer(inp, stcb, net);
1810851b7298SRandall Stewart 		SCTP_STAT_INCR(sctps_timodelprim);
1811851b7298SRandall Stewart 		break;
1812f8829a4aSRandall Stewart 
1813f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_AUTOCLOSE:
1814ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1815ad81507eSRandall Stewart 			break;
1816ad81507eSRandall Stewart 		}
1817f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoautoclose);
1818f8829a4aSRandall Stewart 		sctp_autoclose_timer(inp, stcb, net);
1819ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_AUTOCLOSE_TMR, SCTP_SO_NOT_LOCKED);
1820f8829a4aSRandall Stewart 		did_output = 0;
1821f8829a4aSRandall Stewart 		break;
1822f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASOCKILL:
1823ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1824ad81507eSRandall Stewart 			break;
1825ad81507eSRandall Stewart 		}
1826f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoassockill);
1827f8829a4aSRandall Stewart 		/* Can we free it yet? */
1828f8829a4aSRandall Stewart 		SCTP_INP_DECR_REF(inp);
1829a5d547adSRandall Stewart 		sctp_timer_stop(SCTP_TIMER_TYPE_ASOCKILL, inp, stcb, NULL, SCTP_FROM_SCTPUTIL + SCTP_LOC_1);
1830ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
1831ceaad40aSRandall Stewart 		so = SCTP_INP_SO(inp);
1832ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
1833ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
1834ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
1835ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
1836ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
1837ceaad40aSRandall Stewart #endif
1838c4739e2fSRandall Stewart 		(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC, SCTP_FROM_SCTPUTIL + SCTP_LOC_2);
1839ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
1840ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
1841ceaad40aSRandall Stewart #endif
1842f8829a4aSRandall Stewart 		/*
1843f8829a4aSRandall Stewart 		 * free asoc, always unlocks (or destroy's) so prevent
1844f8829a4aSRandall Stewart 		 * duplicate unlock or unlock of a free mtx :-0
1845f8829a4aSRandall Stewart 		 */
1846f8829a4aSRandall Stewart 		stcb = NULL;
1847f8829a4aSRandall Stewart 		goto out_no_decr;
1848f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INPKILL:
1849f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoinpkill);
1850ad81507eSRandall Stewart 		if (inp == NULL) {
1851ad81507eSRandall Stewart 			break;
1852ad81507eSRandall Stewart 		}
1853f8829a4aSRandall Stewart 		/*
1854f8829a4aSRandall Stewart 		 * special case, take away our increment since WE are the
1855f8829a4aSRandall Stewart 		 * killer
1856f8829a4aSRandall Stewart 		 */
1857f8829a4aSRandall Stewart 		SCTP_INP_DECR_REF(inp);
1858a5d547adSRandall Stewart 		sctp_timer_stop(SCTP_TIMER_TYPE_INPKILL, inp, NULL, NULL, SCTP_FROM_SCTPUTIL + SCTP_LOC_3);
1859b0552ae2SRandall Stewart 		sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
18600c7dc840SRandall Stewart 		    SCTP_CALLED_FROM_INPKILL_TIMER);
1861d61374e1SRandall Stewart 		inp = NULL;
1862f8829a4aSRandall Stewart 		goto out_no_decr;
1863f8829a4aSRandall Stewart 	default:
1864ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_TIMER1, "sctp_timeout_handler:unknown timer %d\n",
1865f8829a4aSRandall Stewart 		    tmr->type);
1866f8829a4aSRandall Stewart 		break;
1867f8829a4aSRandall Stewart 	};
1868f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1869f8829a4aSRandall Stewart 	sctp_audit_log(0xF1, (uint8_t) tmr->type);
1870f8829a4aSRandall Stewart 	if (inp)
1871f8829a4aSRandall Stewart 		sctp_auditing(5, inp, stcb, net);
1872f8829a4aSRandall Stewart #endif
1873f8829a4aSRandall Stewart 	if ((did_output) && stcb) {
1874f8829a4aSRandall Stewart 		/*
1875f8829a4aSRandall Stewart 		 * Now we need to clean up the control chunk chain if an
1876f8829a4aSRandall Stewart 		 * ECNE is on it. It must be marked as UNSENT again so next
1877f8829a4aSRandall Stewart 		 * call will continue to send it until such time that we get
1878f8829a4aSRandall Stewart 		 * a CWR, to remove it. It is, however, less likely that we
1879f8829a4aSRandall Stewart 		 * will find a ecn echo on the chain though.
1880f8829a4aSRandall Stewart 		 */
1881f8829a4aSRandall Stewart 		sctp_fix_ecn_echo(&stcb->asoc);
1882f8829a4aSRandall Stewart 	}
188344b7479bSRandall Stewart get_out:
1884f8829a4aSRandall Stewart 	if (stcb) {
1885f8829a4aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
1886f8829a4aSRandall Stewart 	}
1887f8829a4aSRandall Stewart out_decr:
1888f8829a4aSRandall Stewart 	if (inp) {
1889f8829a4aSRandall Stewart 		SCTP_INP_DECR_REF(inp);
1890f8829a4aSRandall Stewart 	}
1891f8829a4aSRandall Stewart out_no_decr:
1892ad81507eSRandall Stewart 	SCTPDBG(SCTP_DEBUG_TIMER1, "Timer now complete (type %d)\n",
1893d61374e1SRandall Stewart 	    type);
18948518270eSMichael Tuexen 	CURVNET_RESTORE();
1895f8829a4aSRandall Stewart }
1896f8829a4aSRandall Stewart 
1897ad81507eSRandall Stewart void
1898f8829a4aSRandall Stewart sctp_timer_start(int t_type, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
1899f8829a4aSRandall Stewart     struct sctp_nets *net)
1900f8829a4aSRandall Stewart {
1901f8829a4aSRandall Stewart 	int to_ticks;
1902f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
1903f8829a4aSRandall Stewart 
1904139bc87fSRandall Stewart 	if ((t_type != SCTP_TIMER_TYPE_ADDR_WQ) && (inp == NULL))
1905ad81507eSRandall Stewart 		return;
1906f8829a4aSRandall Stewart 
1907f8829a4aSRandall Stewart 	to_ticks = 0;
1908f8829a4aSRandall Stewart 
1909f8829a4aSRandall Stewart 	tmr = NULL;
1910f8829a4aSRandall Stewart 	if (stcb) {
1911f8829a4aSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
1912f8829a4aSRandall Stewart 	}
1913f8829a4aSRandall Stewart 	switch (t_type) {
1914d61a0ae0SRandall Stewart 	case SCTP_TIMER_TYPE_ZERO_COPY:
1915d61a0ae0SRandall Stewart 		tmr = &inp->sctp_ep.zero_copy_timer;
1916d61a0ae0SRandall Stewart 		to_ticks = SCTP_ZERO_COPY_TICK_DELAY;
1917d61a0ae0SRandall Stewart 		break;
1918ad21a364SRandall Stewart 	case SCTP_TIMER_TYPE_ZCOPY_SENDQ:
1919ad21a364SRandall Stewart 		tmr = &inp->sctp_ep.zero_copy_sendq_timer;
1920ad21a364SRandall Stewart 		to_ticks = SCTP_ZERO_COPY_SENDQ_TICK_DELAY;
1921ad21a364SRandall Stewart 		break;
1922f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ADDR_WQ:
1923f8829a4aSRandall Stewart 		/* Only 1 tick away :-) */
1924b3f1ea41SRandall Stewart 		tmr = &SCTP_BASE_INFO(addr_wq_timer);
192542551e99SRandall Stewart 		to_ticks = SCTP_ADDRESS_TICK_DELAY;
1926f8829a4aSRandall Stewart 		break;
1927f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
1928f8829a4aSRandall Stewart 		/* Here we use the RTO timer */
1929f8829a4aSRandall Stewart 		{
1930f8829a4aSRandall Stewart 			int rto_val;
1931f8829a4aSRandall Stewart 
1932f8829a4aSRandall Stewart 			if ((stcb == NULL) || (net == NULL)) {
1933ad81507eSRandall Stewart 				return;
1934f8829a4aSRandall Stewart 			}
1935f8829a4aSRandall Stewart 			tmr = &net->rxt_timer;
1936f8829a4aSRandall Stewart 			if (net->RTO == 0) {
1937f8829a4aSRandall Stewart 				rto_val = stcb->asoc.initial_rto;
1938f8829a4aSRandall Stewart 			} else {
1939f8829a4aSRandall Stewart 				rto_val = net->RTO;
1940f8829a4aSRandall Stewart 			}
1941f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(rto_val);
1942f8829a4aSRandall Stewart 		}
1943f8829a4aSRandall Stewart 		break;
1944f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
1945f8829a4aSRandall Stewart 		/*
1946f8829a4aSRandall Stewart 		 * Here we use the INIT timer default usually about 1
1947f8829a4aSRandall Stewart 		 * minute.
1948f8829a4aSRandall Stewart 		 */
1949f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
1950ad81507eSRandall Stewart 			return;
1951f8829a4aSRandall Stewart 		}
1952f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
1953f8829a4aSRandall Stewart 		if (net->RTO == 0) {
1954f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
1955f8829a4aSRandall Stewart 		} else {
1956f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
1957f8829a4aSRandall Stewart 		}
1958f8829a4aSRandall Stewart 		break;
1959f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
1960f8829a4aSRandall Stewart 		/*
1961f8829a4aSRandall Stewart 		 * Here we use the Delayed-Ack timer value from the inp
1962f8829a4aSRandall Stewart 		 * ususually about 200ms.
1963f8829a4aSRandall Stewart 		 */
1964f8829a4aSRandall Stewart 		if (stcb == NULL) {
1965ad81507eSRandall Stewart 			return;
1966f8829a4aSRandall Stewart 		}
1967f8829a4aSRandall Stewart 		tmr = &stcb->asoc.dack_timer;
1968f8829a4aSRandall Stewart 		to_ticks = MSEC_TO_TICKS(stcb->asoc.delayed_ack);
1969f8829a4aSRandall Stewart 		break;
1970f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
1971f8829a4aSRandall Stewart 		/* Here we use the RTO of the destination. */
1972f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
1973ad81507eSRandall Stewart 			return;
1974f8829a4aSRandall Stewart 		}
1975f8829a4aSRandall Stewart 		if (net->RTO == 0) {
1976f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
1977f8829a4aSRandall Stewart 		} else {
1978f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
1979f8829a4aSRandall Stewart 		}
1980f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
1981f8829a4aSRandall Stewart 		break;
1982f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
1983f8829a4aSRandall Stewart 		/*
1984f8829a4aSRandall Stewart 		 * the net is used here so that we can add in the RTO. Even
1985f8829a4aSRandall Stewart 		 * though we use a different timer. We also add the HB timer
1986f8829a4aSRandall Stewart 		 * PLUS a random jitter.
1987f8829a4aSRandall Stewart 		 */
1988ad81507eSRandall Stewart 		if ((inp == NULL) || (stcb == NULL)) {
1989ad81507eSRandall Stewart 			return;
1990ad81507eSRandall Stewart 		} else {
1991f8829a4aSRandall Stewart 			uint32_t rndval;
1992f8829a4aSRandall Stewart 			uint8_t this_random;
1993f8829a4aSRandall Stewart 			int cnt_of_unconf = 0;
1994f8829a4aSRandall Stewart 			struct sctp_nets *lnet;
1995f8829a4aSRandall Stewart 
1996f8829a4aSRandall Stewart 			TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
1997f8829a4aSRandall Stewart 				if ((lnet->dest_state & SCTP_ADDR_UNCONFIRMED) &&
1998f8829a4aSRandall Stewart 				    (lnet->dest_state & SCTP_ADDR_REACHABLE)) {
1999f8829a4aSRandall Stewart 					cnt_of_unconf++;
2000f8829a4aSRandall Stewart 				}
2001f8829a4aSRandall Stewart 			}
2002f8829a4aSRandall Stewart 			if (cnt_of_unconf) {
20033c503c28SRandall Stewart 				net = lnet = NULL;
2004ad81507eSRandall Stewart 				(void)sctp_heartbeat_timer(inp, stcb, lnet, cnt_of_unconf);
2005f8829a4aSRandall Stewart 			}
2006f8829a4aSRandall Stewart 			if (stcb->asoc.hb_random_idx > 3) {
2007f8829a4aSRandall Stewart 				rndval = sctp_select_initial_TSN(&inp->sctp_ep);
2008f8829a4aSRandall Stewart 				memcpy(stcb->asoc.hb_random_values, &rndval,
2009f8829a4aSRandall Stewart 				    sizeof(stcb->asoc.hb_random_values));
2010f8829a4aSRandall Stewart 				stcb->asoc.hb_random_idx = 0;
201142551e99SRandall Stewart 			}
2012f8829a4aSRandall Stewart 			this_random = stcb->asoc.hb_random_values[stcb->asoc.hb_random_idx];
2013f8829a4aSRandall Stewart 			stcb->asoc.hb_random_idx++;
2014f8829a4aSRandall Stewart 			stcb->asoc.hb_ect_randombit = 0;
2015f8829a4aSRandall Stewart 			/*
2016f8829a4aSRandall Stewart 			 * this_random will be 0 - 256 ms RTO is in ms.
2017f8829a4aSRandall Stewart 			 */
2018f8829a4aSRandall Stewart 			if ((stcb->asoc.hb_is_disabled) &&
2019f8829a4aSRandall Stewart 			    (cnt_of_unconf == 0)) {
2020ad81507eSRandall Stewart 				return;
2021f8829a4aSRandall Stewart 			}
2022f8829a4aSRandall Stewart 			if (net) {
2023f8829a4aSRandall Stewart 				int delay;
2024f8829a4aSRandall Stewart 
2025f8829a4aSRandall Stewart 				delay = stcb->asoc.heart_beat_delay;
2026f8829a4aSRandall Stewart 				TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
2027f8829a4aSRandall Stewart 					if ((lnet->dest_state & SCTP_ADDR_UNCONFIRMED) &&
2028f8829a4aSRandall Stewart 					    ((lnet->dest_state & SCTP_ADDR_OUT_OF_SCOPE) == 0) &&
2029f8829a4aSRandall Stewart 					    (lnet->dest_state & SCTP_ADDR_REACHABLE)) {
2030f8829a4aSRandall Stewart 						delay = 0;
2031f8829a4aSRandall Stewart 					}
2032f8829a4aSRandall Stewart 				}
2033f8829a4aSRandall Stewart 				if (net->RTO == 0) {
2034f8829a4aSRandall Stewart 					/* Never been checked */
2035f8829a4aSRandall Stewart 					to_ticks = this_random + stcb->asoc.initial_rto + delay;
2036f8829a4aSRandall Stewart 				} else {
2037f8829a4aSRandall Stewart 					/* set rto_val to the ms */
2038f8829a4aSRandall Stewart 					to_ticks = delay + net->RTO + this_random;
2039f8829a4aSRandall Stewart 				}
2040f8829a4aSRandall Stewart 			} else {
2041f8829a4aSRandall Stewart 				if (cnt_of_unconf) {
2042f8829a4aSRandall Stewart 					to_ticks = this_random + stcb->asoc.initial_rto;
2043f8829a4aSRandall Stewart 				} else {
2044f8829a4aSRandall Stewart 					to_ticks = stcb->asoc.heart_beat_delay + this_random + stcb->asoc.initial_rto;
2045f8829a4aSRandall Stewart 				}
2046f8829a4aSRandall Stewart 			}
2047f8829a4aSRandall Stewart 			/*
2048f8829a4aSRandall Stewart 			 * Now we must convert the to_ticks that are now in
2049f8829a4aSRandall Stewart 			 * ms to ticks.
2050f8829a4aSRandall Stewart 			 */
2051f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(to_ticks);
2052f8829a4aSRandall Stewart 			tmr = &stcb->asoc.hb_timer;
2053f8829a4aSRandall Stewart 		}
2054f8829a4aSRandall Stewart 		break;
2055f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
2056f8829a4aSRandall Stewart 		/*
2057f8829a4aSRandall Stewart 		 * Here we can use the RTO timer from the network since one
2058f8829a4aSRandall Stewart 		 * RTT was compelete. If a retran happened then we will be
2059f8829a4aSRandall Stewart 		 * using the RTO initial value.
2060f8829a4aSRandall Stewart 		 */
2061f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2062ad81507eSRandall Stewart 			return;
2063f8829a4aSRandall Stewart 		}
2064f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2065f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2066f8829a4aSRandall Stewart 		} else {
2067f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2068f8829a4aSRandall Stewart 		}
2069f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2070f8829a4aSRandall Stewart 		break;
2071f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
2072f8829a4aSRandall Stewart 		/*
2073f8829a4aSRandall Stewart 		 * nothing needed but the endpoint here ususually about 60
2074f8829a4aSRandall Stewart 		 * minutes.
2075f8829a4aSRandall Stewart 		 */
2076ad81507eSRandall Stewart 		if (inp == NULL) {
2077ad81507eSRandall Stewart 			return;
2078ad81507eSRandall Stewart 		}
2079f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2080f8829a4aSRandall Stewart 		to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_SIGNATURE];
2081f8829a4aSRandall Stewart 		break;
2082f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASOCKILL:
2083f8829a4aSRandall Stewart 		if (stcb == NULL) {
2084ad81507eSRandall Stewart 			return;
2085f8829a4aSRandall Stewart 		}
2086f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2087f8829a4aSRandall Stewart 		to_ticks = MSEC_TO_TICKS(SCTP_ASOC_KILL_TIMEOUT);
2088f8829a4aSRandall Stewart 		break;
2089f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INPKILL:
2090f8829a4aSRandall Stewart 		/*
2091f8829a4aSRandall Stewart 		 * The inp is setup to die. We re-use the signature_chage
2092f8829a4aSRandall Stewart 		 * timer since that has stopped and we are in the GONE
2093f8829a4aSRandall Stewart 		 * state.
2094f8829a4aSRandall Stewart 		 */
2095ad81507eSRandall Stewart 		if (inp == NULL) {
2096ad81507eSRandall Stewart 			return;
2097ad81507eSRandall Stewart 		}
2098f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2099f8829a4aSRandall Stewart 		to_ticks = MSEC_TO_TICKS(SCTP_INP_KILL_TIMEOUT);
2100f8829a4aSRandall Stewart 		break;
2101f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
2102f8829a4aSRandall Stewart 		/*
2103f8829a4aSRandall Stewart 		 * Here we use the value found in the EP for PMTU ususually
2104f8829a4aSRandall Stewart 		 * about 10 minutes.
2105f8829a4aSRandall Stewart 		 */
2106ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
2107ad81507eSRandall Stewart 			return;
2108f8829a4aSRandall Stewart 		}
2109f8829a4aSRandall Stewart 		if (net == NULL) {
2110ad81507eSRandall Stewart 			return;
2111f8829a4aSRandall Stewart 		}
2112f8829a4aSRandall Stewart 		to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_PMTU];
2113f8829a4aSRandall Stewart 		tmr = &net->pmtu_timer;
2114f8829a4aSRandall Stewart 		break;
2115f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
2116f8829a4aSRandall Stewart 		/* Here we use the RTO of the destination */
2117f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2118ad81507eSRandall Stewart 			return;
2119f8829a4aSRandall Stewart 		}
2120f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2121f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2122f8829a4aSRandall Stewart 		} else {
2123f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2124f8829a4aSRandall Stewart 		}
2125f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2126f8829a4aSRandall Stewart 		break;
2127f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
2128f8829a4aSRandall Stewart 		/*
2129f8829a4aSRandall Stewart 		 * Here we use the endpoints shutdown guard timer usually
2130f8829a4aSRandall Stewart 		 * about 3 minutes.
2131f8829a4aSRandall Stewart 		 */
2132ad81507eSRandall Stewart 		if ((inp == NULL) || (stcb == NULL)) {
2133ad81507eSRandall Stewart 			return;
2134f8829a4aSRandall Stewart 		}
2135f8829a4aSRandall Stewart 		to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_MAXSHUTDOWN];
2136f8829a4aSRandall Stewart 		tmr = &stcb->asoc.shut_guard_timer;
2137f8829a4aSRandall Stewart 		break;
2138f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_STRRESET:
2139f8829a4aSRandall Stewart 		/*
21401b649582SRandall Stewart 		 * Here the timer comes from the stcb but its value is from
21411b649582SRandall Stewart 		 * the net's RTO.
2142f8829a4aSRandall Stewart 		 */
2143f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2144ad81507eSRandall Stewart 			return;
2145f8829a4aSRandall Stewart 		}
2146f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2147f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2148f8829a4aSRandall Stewart 		} else {
2149f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2150f8829a4aSRandall Stewart 		}
2151f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2152f8829a4aSRandall Stewart 		break;
2153f8829a4aSRandall Stewart 
2154f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_EARLYFR:
2155f8829a4aSRandall Stewart 		{
2156f8829a4aSRandall Stewart 			unsigned int msec;
2157f8829a4aSRandall Stewart 
2158f8829a4aSRandall Stewart 			if ((stcb == NULL) || (net == NULL)) {
2159ad81507eSRandall Stewart 				return;
2160f8829a4aSRandall Stewart 			}
2161f8829a4aSRandall Stewart 			if (net->flight_size > net->cwnd) {
2162f8829a4aSRandall Stewart 				/* no need to start */
2163ad81507eSRandall Stewart 				return;
2164f8829a4aSRandall Stewart 			}
2165f8829a4aSRandall Stewart 			SCTP_STAT_INCR(sctps_earlyfrstart);
2166f8829a4aSRandall Stewart 			if (net->lastsa == 0) {
2167f8829a4aSRandall Stewart 				/* Hmm no rtt estimate yet? */
2168f8829a4aSRandall Stewart 				msec = stcb->asoc.initial_rto >> 2;
2169f8829a4aSRandall Stewart 			} else {
2170f8829a4aSRandall Stewart 				msec = ((net->lastsa >> 2) + net->lastsv) >> 1;
2171f8829a4aSRandall Stewart 			}
2172b3f1ea41SRandall Stewart 			if (msec < SCTP_BASE_SYSCTL(sctp_early_fr_msec)) {
2173b3f1ea41SRandall Stewart 				msec = SCTP_BASE_SYSCTL(sctp_early_fr_msec);
2174f8829a4aSRandall Stewart 				if (msec < SCTP_MINFR_MSEC_FLOOR) {
2175f8829a4aSRandall Stewart 					msec = SCTP_MINFR_MSEC_FLOOR;
2176f8829a4aSRandall Stewart 				}
2177f8829a4aSRandall Stewart 			}
2178f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(msec);
2179f8829a4aSRandall Stewart 			tmr = &net->fr_timer;
2180f8829a4aSRandall Stewart 		}
2181f8829a4aSRandall Stewart 		break;
2182f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASCONF:
2183f8829a4aSRandall Stewart 		/*
21841b649582SRandall Stewart 		 * Here the timer comes from the stcb but its value is from
21851b649582SRandall Stewart 		 * the net's RTO.
2186f8829a4aSRandall Stewart 		 */
2187f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2188ad81507eSRandall Stewart 			return;
2189f8829a4aSRandall Stewart 		}
2190f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2191f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2192f8829a4aSRandall Stewart 		} else {
2193f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2194f8829a4aSRandall Stewart 		}
2195f8829a4aSRandall Stewart 		tmr = &stcb->asoc.asconf_timer;
2196f8829a4aSRandall Stewart 		break;
2197851b7298SRandall Stewart 	case SCTP_TIMER_TYPE_PRIM_DELETED:
2198851b7298SRandall Stewart 		if ((stcb == NULL) || (net != NULL)) {
2199851b7298SRandall Stewart 			return;
2200851b7298SRandall Stewart 		}
2201851b7298SRandall Stewart 		to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2202851b7298SRandall Stewart 		tmr = &stcb->asoc.delete_prim_timer;
2203851b7298SRandall Stewart 		break;
2204f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_AUTOCLOSE:
2205f8829a4aSRandall Stewart 		if (stcb == NULL) {
2206ad81507eSRandall Stewart 			return;
2207f8829a4aSRandall Stewart 		}
2208f8829a4aSRandall Stewart 		if (stcb->asoc.sctp_autoclose_ticks == 0) {
2209f8829a4aSRandall Stewart 			/*
2210f8829a4aSRandall Stewart 			 * Really an error since stcb is NOT set to
2211f8829a4aSRandall Stewart 			 * autoclose
2212f8829a4aSRandall Stewart 			 */
2213ad81507eSRandall Stewart 			return;
2214f8829a4aSRandall Stewart 		}
2215f8829a4aSRandall Stewart 		to_ticks = stcb->asoc.sctp_autoclose_ticks;
2216f8829a4aSRandall Stewart 		tmr = &stcb->asoc.autoclose_timer;
2217f8829a4aSRandall Stewart 		break;
2218f8829a4aSRandall Stewart 	default:
2219ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_TIMER1, "%s: Unknown timer type %d\n",
2220ad81507eSRandall Stewart 		    __FUNCTION__, t_type);
2221ad81507eSRandall Stewart 		return;
2222f8829a4aSRandall Stewart 		break;
2223f8829a4aSRandall Stewart 	};
2224f8829a4aSRandall Stewart 	if ((to_ticks <= 0) || (tmr == NULL)) {
2225ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_TIMER1, "%s: %d:software error to_ticks:%d tmr:%p not set ??\n",
2226ad81507eSRandall Stewart 		    __FUNCTION__, t_type, to_ticks, tmr);
2227ad81507eSRandall Stewart 		return;
2228f8829a4aSRandall Stewart 	}
2229139bc87fSRandall Stewart 	if (SCTP_OS_TIMER_PENDING(&tmr->timer)) {
2230f8829a4aSRandall Stewart 		/*
2231f8829a4aSRandall Stewart 		 * we do NOT allow you to have it already running. if it is
2232f8829a4aSRandall Stewart 		 * we leave the current one up unchanged
2233f8829a4aSRandall Stewart 		 */
2234ad81507eSRandall Stewart 		return;
2235f8829a4aSRandall Stewart 	}
2236f8829a4aSRandall Stewart 	/* At this point we can proceed */
2237f8829a4aSRandall Stewart 	if (t_type == SCTP_TIMER_TYPE_SEND) {
2238f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up++;
2239f8829a4aSRandall Stewart 	}
2240a5d547adSRandall Stewart 	tmr->stopped_from = 0;
2241f8829a4aSRandall Stewart 	tmr->type = t_type;
2242f8829a4aSRandall Stewart 	tmr->ep = (void *)inp;
2243f8829a4aSRandall Stewart 	tmr->tcb = (void *)stcb;
2244f8829a4aSRandall Stewart 	tmr->net = (void *)net;
2245f8829a4aSRandall Stewart 	tmr->self = (void *)tmr;
22468518270eSMichael Tuexen 	tmr->vnet = (void *)curvnet;
2247c4739e2fSRandall Stewart 	tmr->ticks = sctp_get_tick_count();
2248ad81507eSRandall Stewart 	(void)SCTP_OS_TIMER_START(&tmr->timer, to_ticks, sctp_timeout_handler, tmr);
2249ad81507eSRandall Stewart 	return;
2250f8829a4aSRandall Stewart }
2251f8829a4aSRandall Stewart 
22526e55db54SRandall Stewart void
2253f8829a4aSRandall Stewart sctp_timer_stop(int t_type, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
2254a5d547adSRandall Stewart     struct sctp_nets *net, uint32_t from)
2255f8829a4aSRandall Stewart {
2256f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
2257f8829a4aSRandall Stewart 
2258f8829a4aSRandall Stewart 	if ((t_type != SCTP_TIMER_TYPE_ADDR_WQ) &&
2259f8829a4aSRandall Stewart 	    (inp == NULL))
22606e55db54SRandall Stewart 		return;
2261f8829a4aSRandall Stewart 
2262f8829a4aSRandall Stewart 	tmr = NULL;
2263f8829a4aSRandall Stewart 	if (stcb) {
2264f8829a4aSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
2265f8829a4aSRandall Stewart 	}
2266f8829a4aSRandall Stewart 	switch (t_type) {
2267d61a0ae0SRandall Stewart 	case SCTP_TIMER_TYPE_ZERO_COPY:
2268d61a0ae0SRandall Stewart 		tmr = &inp->sctp_ep.zero_copy_timer;
2269d61a0ae0SRandall Stewart 		break;
2270ad21a364SRandall Stewart 	case SCTP_TIMER_TYPE_ZCOPY_SENDQ:
2271ad21a364SRandall Stewart 		tmr = &inp->sctp_ep.zero_copy_sendq_timer;
2272ad21a364SRandall Stewart 		break;
2273f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ADDR_WQ:
2274b3f1ea41SRandall Stewart 		tmr = &SCTP_BASE_INFO(addr_wq_timer);
2275f8829a4aSRandall Stewart 		break;
2276f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_EARLYFR:
2277f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
22786e55db54SRandall Stewart 			return;
2279f8829a4aSRandall Stewart 		}
2280f8829a4aSRandall Stewart 		tmr = &net->fr_timer;
2281f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_earlyfrstop);
2282f8829a4aSRandall Stewart 		break;
2283f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
2284f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
22856e55db54SRandall Stewart 			return;
2286f8829a4aSRandall Stewart 		}
2287f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2288f8829a4aSRandall Stewart 		break;
2289f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
2290f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
22916e55db54SRandall Stewart 			return;
2292f8829a4aSRandall Stewart 		}
2293f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2294f8829a4aSRandall Stewart 		break;
2295f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
2296f8829a4aSRandall Stewart 		if (stcb == NULL) {
22976e55db54SRandall Stewart 			return;
2298f8829a4aSRandall Stewart 		}
2299f8829a4aSRandall Stewart 		tmr = &stcb->asoc.dack_timer;
2300f8829a4aSRandall Stewart 		break;
2301f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
2302f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23036e55db54SRandall Stewart 			return;
2304f8829a4aSRandall Stewart 		}
2305f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2306f8829a4aSRandall Stewart 		break;
2307f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
2308f8829a4aSRandall Stewart 		if (stcb == NULL) {
23096e55db54SRandall Stewart 			return;
2310f8829a4aSRandall Stewart 		}
2311f8829a4aSRandall Stewart 		tmr = &stcb->asoc.hb_timer;
2312f8829a4aSRandall Stewart 		break;
2313f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
2314f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23156e55db54SRandall Stewart 			return;
2316f8829a4aSRandall Stewart 		}
2317f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2318f8829a4aSRandall Stewart 		break;
2319f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
2320f8829a4aSRandall Stewart 		/* nothing needed but the endpoint here */
2321f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2322f8829a4aSRandall Stewart 		/*
2323f8829a4aSRandall Stewart 		 * We re-use the newcookie timer for the INP kill timer. We
2324f8829a4aSRandall Stewart 		 * must assure that we do not kill it by accident.
2325f8829a4aSRandall Stewart 		 */
2326f8829a4aSRandall Stewart 		break;
2327f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASOCKILL:
2328f8829a4aSRandall Stewart 		/*
2329f8829a4aSRandall Stewart 		 * Stop the asoc kill timer.
2330f8829a4aSRandall Stewart 		 */
2331f8829a4aSRandall Stewart 		if (stcb == NULL) {
23326e55db54SRandall Stewart 			return;
2333f8829a4aSRandall Stewart 		}
2334f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2335f8829a4aSRandall Stewart 		break;
2336f8829a4aSRandall Stewart 
2337f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INPKILL:
2338f8829a4aSRandall Stewart 		/*
2339f8829a4aSRandall Stewart 		 * The inp is setup to die. We re-use the signature_chage
2340f8829a4aSRandall Stewart 		 * timer since that has stopped and we are in the GONE
2341f8829a4aSRandall Stewart 		 * state.
2342f8829a4aSRandall Stewart 		 */
2343f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2344f8829a4aSRandall Stewart 		break;
2345f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
2346f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23476e55db54SRandall Stewart 			return;
2348f8829a4aSRandall Stewart 		}
2349f8829a4aSRandall Stewart 		tmr = &net->pmtu_timer;
2350f8829a4aSRandall Stewart 		break;
2351f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
2352f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23536e55db54SRandall Stewart 			return;
2354f8829a4aSRandall Stewart 		}
2355f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2356f8829a4aSRandall Stewart 		break;
2357f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
2358f8829a4aSRandall Stewart 		if (stcb == NULL) {
23596e55db54SRandall Stewart 			return;
2360f8829a4aSRandall Stewart 		}
2361f8829a4aSRandall Stewart 		tmr = &stcb->asoc.shut_guard_timer;
2362f8829a4aSRandall Stewart 		break;
2363f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_STRRESET:
2364f8829a4aSRandall Stewart 		if (stcb == NULL) {
23656e55db54SRandall Stewart 			return;
2366f8829a4aSRandall Stewart 		}
2367f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2368f8829a4aSRandall Stewart 		break;
2369f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASCONF:
2370f8829a4aSRandall Stewart 		if (stcb == NULL) {
23716e55db54SRandall Stewart 			return;
2372f8829a4aSRandall Stewart 		}
2373f8829a4aSRandall Stewart 		tmr = &stcb->asoc.asconf_timer;
2374f8829a4aSRandall Stewart 		break;
2375851b7298SRandall Stewart 	case SCTP_TIMER_TYPE_PRIM_DELETED:
2376851b7298SRandall Stewart 		if (stcb == NULL) {
2377851b7298SRandall Stewart 			return;
2378851b7298SRandall Stewart 		}
2379851b7298SRandall Stewart 		tmr = &stcb->asoc.delete_prim_timer;
2380851b7298SRandall Stewart 		break;
2381f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_AUTOCLOSE:
2382f8829a4aSRandall Stewart 		if (stcb == NULL) {
23836e55db54SRandall Stewart 			return;
2384f8829a4aSRandall Stewart 		}
2385f8829a4aSRandall Stewart 		tmr = &stcb->asoc.autoclose_timer;
2386f8829a4aSRandall Stewart 		break;
2387f8829a4aSRandall Stewart 	default:
2388ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_TIMER1, "%s: Unknown timer type %d\n",
2389ad81507eSRandall Stewart 		    __FUNCTION__, t_type);
2390f8829a4aSRandall Stewart 		break;
2391f8829a4aSRandall Stewart 	};
2392f8829a4aSRandall Stewart 	if (tmr == NULL) {
23936e55db54SRandall Stewart 		return;
2394f8829a4aSRandall Stewart 	}
2395f8829a4aSRandall Stewart 	if ((tmr->type != t_type) && tmr->type) {
2396f8829a4aSRandall Stewart 		/*
2397f8829a4aSRandall Stewart 		 * Ok we have a timer that is under joint use. Cookie timer
2398f8829a4aSRandall Stewart 		 * per chance with the SEND timer. We therefore are NOT
2399f8829a4aSRandall Stewart 		 * running the timer that the caller wants stopped.  So just
2400f8829a4aSRandall Stewart 		 * return.
2401f8829a4aSRandall Stewart 		 */
24026e55db54SRandall Stewart 		return;
2403f8829a4aSRandall Stewart 	}
2404ad81507eSRandall Stewart 	if ((t_type == SCTP_TIMER_TYPE_SEND) && (stcb != NULL)) {
2405f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up--;
2406f8829a4aSRandall Stewart 		if (stcb->asoc.num_send_timers_up < 0) {
2407f8829a4aSRandall Stewart 			stcb->asoc.num_send_timers_up = 0;
2408f8829a4aSRandall Stewart 		}
2409f8829a4aSRandall Stewart 	}
2410f8829a4aSRandall Stewart 	tmr->self = NULL;
2411a5d547adSRandall Stewart 	tmr->stopped_from = from;
24126e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&tmr->timer);
24136e55db54SRandall Stewart 	return;
2414f8829a4aSRandall Stewart }
2415f8829a4aSRandall Stewart 
2416f8829a4aSRandall Stewart uint32_t
2417f8829a4aSRandall Stewart sctp_calculate_len(struct mbuf *m)
2418f8829a4aSRandall Stewart {
2419f8829a4aSRandall Stewart 	uint32_t tlen = 0;
2420f8829a4aSRandall Stewart 	struct mbuf *at;
2421f8829a4aSRandall Stewart 
2422f8829a4aSRandall Stewart 	at = m;
2423f8829a4aSRandall Stewart 	while (at) {
2424139bc87fSRandall Stewart 		tlen += SCTP_BUF_LEN(at);
2425139bc87fSRandall Stewart 		at = SCTP_BUF_NEXT(at);
2426f8829a4aSRandall Stewart 	}
2427f8829a4aSRandall Stewart 	return (tlen);
2428f8829a4aSRandall Stewart }
2429f8829a4aSRandall Stewart 
2430f8829a4aSRandall Stewart void
2431f8829a4aSRandall Stewart sctp_mtu_size_reset(struct sctp_inpcb *inp,
243244b7479bSRandall Stewart     struct sctp_association *asoc, uint32_t mtu)
2433f8829a4aSRandall Stewart {
2434f8829a4aSRandall Stewart 	/*
2435f8829a4aSRandall Stewart 	 * Reset the P-MTU size on this association, this involves changing
2436f8829a4aSRandall Stewart 	 * the asoc MTU, going through ANY chunk+overhead larger than mtu to
2437f8829a4aSRandall Stewart 	 * allow the DF flag to be cleared.
2438f8829a4aSRandall Stewart 	 */
2439f8829a4aSRandall Stewart 	struct sctp_tmit_chunk *chk;
2440f8829a4aSRandall Stewart 	unsigned int eff_mtu, ovh;
2441f8829a4aSRandall Stewart 
2442f8829a4aSRandall Stewart 	asoc->smallest_mtu = mtu;
2443f8829a4aSRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) {
2444f8829a4aSRandall Stewart 		ovh = SCTP_MIN_OVERHEAD;
2445f8829a4aSRandall Stewart 	} else {
2446f8829a4aSRandall Stewart 		ovh = SCTP_MIN_V4_OVERHEAD;
2447f8829a4aSRandall Stewart 	}
2448f8829a4aSRandall Stewart 	eff_mtu = mtu - ovh;
2449f8829a4aSRandall Stewart 	TAILQ_FOREACH(chk, &asoc->send_queue, sctp_next) {
2450f8829a4aSRandall Stewart 		if (chk->send_size > eff_mtu) {
2451f8829a4aSRandall Stewart 			chk->flags |= CHUNK_FLAGS_FRAGMENT_OK;
2452f8829a4aSRandall Stewart 		}
2453f8829a4aSRandall Stewart 	}
2454f8829a4aSRandall Stewart 	TAILQ_FOREACH(chk, &asoc->sent_queue, sctp_next) {
2455f8829a4aSRandall Stewart 		if (chk->send_size > eff_mtu) {
2456f8829a4aSRandall Stewart 			chk->flags |= CHUNK_FLAGS_FRAGMENT_OK;
2457f8829a4aSRandall Stewart 		}
2458f8829a4aSRandall Stewart 	}
2459f8829a4aSRandall Stewart }
2460f8829a4aSRandall Stewart 
2461f8829a4aSRandall Stewart 
2462f8829a4aSRandall Stewart /*
2463f8829a4aSRandall Stewart  * given an association and starting time of the current RTT period return
2464f42a358aSRandall Stewart  * RTO in number of msecs net should point to the current network
2465f8829a4aSRandall Stewart  */
2466899288aeSRandall Stewart 
2467f8829a4aSRandall Stewart uint32_t
2468f8829a4aSRandall Stewart sctp_calculate_rto(struct sctp_tcb *stcb,
2469f8829a4aSRandall Stewart     struct sctp_association *asoc,
2470f8829a4aSRandall Stewart     struct sctp_nets *net,
247118e198d3SRandall Stewart     struct timeval *told,
2472f79aab18SRandall Stewart     int safe, int rtt_from_sack)
2473f8829a4aSRandall Stewart {
247418e198d3SRandall Stewart 	/*-
2475f8829a4aSRandall Stewart 	 * given an association and the starting time of the current RTT
2476f42a358aSRandall Stewart 	 * period (in value1/value2) return RTO in number of msecs.
2477f8829a4aSRandall Stewart 	 */
2478be1d9176SMichael Tuexen 	int32_t rtt;		/* RTT in ms */
2479be1d9176SMichael Tuexen 	uint32_t new_rto;
2480f8829a4aSRandall Stewart 	int first_measure = 0;
248118e198d3SRandall Stewart 	struct timeval now, then, *old;
2482f8829a4aSRandall Stewart 
248318e198d3SRandall Stewart 	/* Copy it out for sparc64 */
248418e198d3SRandall Stewart 	if (safe == sctp_align_unsafe_makecopy) {
248518e198d3SRandall Stewart 		old = &then;
248618e198d3SRandall Stewart 		memcpy(&then, told, sizeof(struct timeval));
248718e198d3SRandall Stewart 	} else if (safe == sctp_align_safe_nocopy) {
248818e198d3SRandall Stewart 		old = told;
248918e198d3SRandall Stewart 	} else {
249018e198d3SRandall Stewart 		/* error */
249118e198d3SRandall Stewart 		SCTP_PRINTF("Huh, bad rto calc call\n");
249218e198d3SRandall Stewart 		return (0);
249318e198d3SRandall Stewart 	}
2494f8829a4aSRandall Stewart 	/************************/
2495f8829a4aSRandall Stewart 	/* 1. calculate new RTT */
2496f8829a4aSRandall Stewart 	/************************/
2497f8829a4aSRandall Stewart 	/* get the current time */
2498299108c5SRandall Stewart 	if (stcb->asoc.use_precise_time) {
2499299108c5SRandall Stewart 		(void)SCTP_GETPTIME_TIMEVAL(&now);
2500299108c5SRandall Stewart 	} else {
25016e55db54SRandall Stewart 		(void)SCTP_GETTIME_TIMEVAL(&now);
2502299108c5SRandall Stewart 	}
2503be1d9176SMichael Tuexen 	timevalsub(&now, old);
2504be1d9176SMichael Tuexen 	/* store the current RTT in us */
2505be1d9176SMichael Tuexen 	net->rtt = (uint64_t) 10000000 *(uint64_t) now.tv_sec +
2506be1d9176SMichael Tuexen 	         (uint64_t) now.tv_usec;
2507be1d9176SMichael Tuexen 
2508be1d9176SMichael Tuexen 	/* computer rtt in ms */
2509be1d9176SMichael Tuexen 	rtt = net->rtt / 1000;
2510f79aab18SRandall Stewart 	if ((asoc->cc_functions.sctp_rtt_calculated) && (rtt_from_sack == SCTP_RTT_FROM_DATA)) {
2511f79aab18SRandall Stewart 		/*
2512f79aab18SRandall Stewart 		 * Tell the CC module that a new update has just occurred
2513f79aab18SRandall Stewart 		 * from a sack
2514f79aab18SRandall Stewart 		 */
2515f79aab18SRandall Stewart 		(*asoc->cc_functions.sctp_rtt_calculated) (stcb, net, &now);
2516f79aab18SRandall Stewart 	}
2517f79aab18SRandall Stewart 	/*
2518f79aab18SRandall Stewart 	 * Do we need to determine the lan? We do this only on sacks i.e.
2519f79aab18SRandall Stewart 	 * RTT being determined from data not non-data (HB/INIT->INITACK).
2520f79aab18SRandall Stewart 	 */
2521f79aab18SRandall Stewart 	if ((rtt_from_sack == SCTP_RTT_FROM_DATA) &&
2522be1d9176SMichael Tuexen 	    (net->lan_type == SCTP_LAN_UNKNOWN)) {
2523be1d9176SMichael Tuexen 		if (net->rtt > SCTP_LOCAL_LAN_RTT) {
2524899288aeSRandall Stewart 			net->lan_type = SCTP_LAN_INTERNET;
2525899288aeSRandall Stewart 		} else {
2526899288aeSRandall Stewart 			net->lan_type = SCTP_LAN_LOCAL;
2527899288aeSRandall Stewart 		}
2528899288aeSRandall Stewart 	}
2529f8829a4aSRandall Stewart 	/***************************/
2530f8829a4aSRandall Stewart 	/* 2. update RTTVAR & SRTT */
2531f8829a4aSRandall Stewart 	/***************************/
2532be1d9176SMichael Tuexen 	/*-
2533be1d9176SMichael Tuexen 	 * Compute the scaled average lastsa and the
2534be1d9176SMichael Tuexen 	 * scaled variance lastsv as described in van Jacobson
2535be1d9176SMichael Tuexen 	 * Paper "Congestion Avoidance and Control", Annex A.
2536be1d9176SMichael Tuexen 	 *
2537be1d9176SMichael Tuexen 	 * (net->lastsa >> SCTP_RTT_SHIFT) is the srtt
2538be1d9176SMichael Tuexen 	 * (net->lastsa >> SCTP_RTT_VAR_SHIFT) is the rttvar
2539be1d9176SMichael Tuexen 	 */
25409a972525SRandall Stewart 	if (net->RTO_measured) {
2541be1d9176SMichael Tuexen 		rtt -= (net->lastsa >> SCTP_RTT_SHIFT);
2542be1d9176SMichael Tuexen 		net->lastsa += rtt;
2543be1d9176SMichael Tuexen 		if (rtt < 0) {
2544be1d9176SMichael Tuexen 			rtt = -rtt;
2545be1d9176SMichael Tuexen 		}
2546be1d9176SMichael Tuexen 		rtt -= (net->lastsv >> SCTP_RTT_VAR_SHIFT);
2547be1d9176SMichael Tuexen 		net->lastsv += rtt;
2548b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RTTVAR_LOGGING_ENABLE) {
2549f8829a4aSRandall Stewart 			rto_logging(net, SCTP_LOG_RTTVAR);
255080fefe0aSRandall Stewart 		}
2551f8829a4aSRandall Stewart 	} else {
2552f8829a4aSRandall Stewart 		/* First RTO measurment */
25539a972525SRandall Stewart 		net->RTO_measured = 1;
2554f8829a4aSRandall Stewart 		first_measure = 1;
2555be1d9176SMichael Tuexen 		net->lastsa = rtt << SCTP_RTT_SHIFT;
2556be1d9176SMichael Tuexen 		net->lastsv = (rtt / 2) << SCTP_RTT_VAR_SHIFT;
2557b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RTTVAR_LOGGING_ENABLE) {
2558f8829a4aSRandall Stewart 			rto_logging(net, SCTP_LOG_INITIAL_RTT);
255980fefe0aSRandall Stewart 		}
2560f8829a4aSRandall Stewart 	}
2561be1d9176SMichael Tuexen 	if (net->lastsv == 0) {
2562be1d9176SMichael Tuexen 		net->lastsv = SCTP_CLOCK_GRANULARITY;
2563be1d9176SMichael Tuexen 	}
2564108df27cSRandall Stewart 	new_rto = (net->lastsa >> SCTP_RTT_SHIFT) + net->lastsv;
2565f8829a4aSRandall Stewart 	if ((new_rto > SCTP_SAT_NETWORK_MIN) &&
2566f8829a4aSRandall Stewart 	    (stcb->asoc.sat_network_lockout == 0)) {
2567f8829a4aSRandall Stewart 		stcb->asoc.sat_network = 1;
2568f8829a4aSRandall Stewart 	} else if ((!first_measure) && stcb->asoc.sat_network) {
2569f8829a4aSRandall Stewart 		stcb->asoc.sat_network = 0;
2570f8829a4aSRandall Stewart 		stcb->asoc.sat_network_lockout = 1;
2571f8829a4aSRandall Stewart 	}
2572f8829a4aSRandall Stewart 	/* bound it, per C6/C7 in Section 5.3.1 */
2573f8829a4aSRandall Stewart 	if (new_rto < stcb->asoc.minrto) {
2574f8829a4aSRandall Stewart 		new_rto = stcb->asoc.minrto;
2575f8829a4aSRandall Stewart 	}
2576f8829a4aSRandall Stewart 	if (new_rto > stcb->asoc.maxrto) {
2577f8829a4aSRandall Stewart 		new_rto = stcb->asoc.maxrto;
2578f8829a4aSRandall Stewart 	}
25795e54f665SRandall Stewart 	/* we are now returning the RTO */
25805e54f665SRandall Stewart 	return (new_rto);
2581f8829a4aSRandall Stewart }
2582f8829a4aSRandall Stewart 
2583f8829a4aSRandall Stewart /*
2584f8829a4aSRandall Stewart  * return a pointer to a contiguous piece of data from the given mbuf chain
2585f8829a4aSRandall Stewart  * starting at 'off' for 'len' bytes.  If the desired piece spans more than
2586f8829a4aSRandall Stewart  * one mbuf, a copy is made at 'ptr'. caller must ensure that the buffer size
2587f8829a4aSRandall Stewart  * is >= 'len' returns NULL if there there isn't 'len' bytes in the chain.
2588f8829a4aSRandall Stewart  */
258972fb6fdbSRandall Stewart caddr_t
2590f8829a4aSRandall Stewart sctp_m_getptr(struct mbuf *m, int off, int len, uint8_t * in_ptr)
2591f8829a4aSRandall Stewart {
2592f8829a4aSRandall Stewart 	uint32_t count;
2593f8829a4aSRandall Stewart 	uint8_t *ptr;
2594f8829a4aSRandall Stewart 
2595f8829a4aSRandall Stewart 	ptr = in_ptr;
2596f8829a4aSRandall Stewart 	if ((off < 0) || (len <= 0))
2597f8829a4aSRandall Stewart 		return (NULL);
2598f8829a4aSRandall Stewart 
2599f8829a4aSRandall Stewart 	/* find the desired start location */
2600f8829a4aSRandall Stewart 	while ((m != NULL) && (off > 0)) {
2601139bc87fSRandall Stewart 		if (off < SCTP_BUF_LEN(m))
2602f8829a4aSRandall Stewart 			break;
2603139bc87fSRandall Stewart 		off -= SCTP_BUF_LEN(m);
2604139bc87fSRandall Stewart 		m = SCTP_BUF_NEXT(m);
2605f8829a4aSRandall Stewart 	}
2606f8829a4aSRandall Stewart 	if (m == NULL)
2607f8829a4aSRandall Stewart 		return (NULL);
2608f8829a4aSRandall Stewart 
2609f8829a4aSRandall Stewart 	/* is the current mbuf large enough (eg. contiguous)? */
2610139bc87fSRandall Stewart 	if ((SCTP_BUF_LEN(m) - off) >= len) {
2611f8829a4aSRandall Stewart 		return (mtod(m, caddr_t)+off);
2612f8829a4aSRandall Stewart 	} else {
2613f8829a4aSRandall Stewart 		/* else, it spans more than one mbuf, so save a temp copy... */
2614f8829a4aSRandall Stewart 		while ((m != NULL) && (len > 0)) {
2615139bc87fSRandall Stewart 			count = min(SCTP_BUF_LEN(m) - off, len);
2616f8829a4aSRandall Stewart 			bcopy(mtod(m, caddr_t)+off, ptr, count);
2617f8829a4aSRandall Stewart 			len -= count;
2618f8829a4aSRandall Stewart 			ptr += count;
2619f8829a4aSRandall Stewart 			off = 0;
2620139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
2621f8829a4aSRandall Stewart 		}
2622f8829a4aSRandall Stewart 		if ((m == NULL) && (len > 0))
2623f8829a4aSRandall Stewart 			return (NULL);
2624f8829a4aSRandall Stewart 		else
2625f8829a4aSRandall Stewart 			return ((caddr_t)in_ptr);
2626f8829a4aSRandall Stewart 	}
2627f8829a4aSRandall Stewart }
2628f8829a4aSRandall Stewart 
2629f8829a4aSRandall Stewart 
263044b7479bSRandall Stewart 
2631f8829a4aSRandall Stewart struct sctp_paramhdr *
2632f8829a4aSRandall Stewart sctp_get_next_param(struct mbuf *m,
2633f8829a4aSRandall Stewart     int offset,
2634f8829a4aSRandall Stewart     struct sctp_paramhdr *pull,
2635f8829a4aSRandall Stewart     int pull_limit)
2636f8829a4aSRandall Stewart {
2637f8829a4aSRandall Stewart 	/* This just provides a typed signature to Peter's Pull routine */
2638f8829a4aSRandall Stewart 	return ((struct sctp_paramhdr *)sctp_m_getptr(m, offset, pull_limit,
2639f8829a4aSRandall Stewart 	    (uint8_t *) pull));
2640f8829a4aSRandall Stewart }
2641f8829a4aSRandall Stewart 
2642f8829a4aSRandall Stewart 
2643f8829a4aSRandall Stewart int
2644f8829a4aSRandall Stewart sctp_add_pad_tombuf(struct mbuf *m, int padlen)
2645f8829a4aSRandall Stewart {
2646f8829a4aSRandall Stewart 	/*
2647f8829a4aSRandall Stewart 	 * add padlen bytes of 0 filled padding to the end of the mbuf. If
2648f8829a4aSRandall Stewart 	 * padlen is > 3 this routine will fail.
2649f8829a4aSRandall Stewart 	 */
2650f8829a4aSRandall Stewart 	uint8_t *dp;
2651f8829a4aSRandall Stewart 	int i;
2652f8829a4aSRandall Stewart 
2653f8829a4aSRandall Stewart 	if (padlen > 3) {
2654c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET_PKT(m, NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOBUFS);
2655f8829a4aSRandall Stewart 		return (ENOBUFS);
2656f8829a4aSRandall Stewart 	}
265741eee555SRandall Stewart 	if (padlen <= M_TRAILINGSPACE(m)) {
2658f8829a4aSRandall Stewart 		/*
2659f8829a4aSRandall Stewart 		 * The easy way. We hope the majority of the time we hit
2660f8829a4aSRandall Stewart 		 * here :)
2661f8829a4aSRandall Stewart 		 */
2662139bc87fSRandall Stewart 		dp = (uint8_t *) (mtod(m, caddr_t)+SCTP_BUF_LEN(m));
2663139bc87fSRandall Stewart 		SCTP_BUF_LEN(m) += padlen;
2664f8829a4aSRandall Stewart 	} else {
2665f8829a4aSRandall Stewart 		/* Hard way we must grow the mbuf */
2666f8829a4aSRandall Stewart 		struct mbuf *tmp;
2667f8829a4aSRandall Stewart 
2668f8829a4aSRandall Stewart 		tmp = sctp_get_mbuf_for_msg(padlen, 0, M_DONTWAIT, 1, MT_DATA);
2669f8829a4aSRandall Stewart 		if (tmp == NULL) {
2670f8829a4aSRandall Stewart 			/* Out of space GAK! we are in big trouble. */
2671c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET_PKT(m, NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
2672f8829a4aSRandall Stewart 			return (ENOSPC);
2673f8829a4aSRandall Stewart 		}
2674f8829a4aSRandall Stewart 		/* setup and insert in middle */
2675139bc87fSRandall Stewart 		SCTP_BUF_LEN(tmp) = padlen;
267641eee555SRandall Stewart 		SCTP_BUF_NEXT(tmp) = NULL;
2677139bc87fSRandall Stewart 		SCTP_BUF_NEXT(m) = tmp;
2678f8829a4aSRandall Stewart 		dp = mtod(tmp, uint8_t *);
2679f8829a4aSRandall Stewart 	}
2680f8829a4aSRandall Stewart 	/* zero out the pad */
2681f8829a4aSRandall Stewart 	for (i = 0; i < padlen; i++) {
2682f8829a4aSRandall Stewart 		*dp = 0;
2683f8829a4aSRandall Stewart 		dp++;
2684f8829a4aSRandall Stewart 	}
2685f8829a4aSRandall Stewart 	return (0);
2686f8829a4aSRandall Stewart }
2687f8829a4aSRandall Stewart 
2688f8829a4aSRandall Stewart int
2689f8829a4aSRandall Stewart sctp_pad_lastmbuf(struct mbuf *m, int padval, struct mbuf *last_mbuf)
2690f8829a4aSRandall Stewart {
2691f8829a4aSRandall Stewart 	/* find the last mbuf in chain and pad it */
2692f8829a4aSRandall Stewart 	struct mbuf *m_at;
2693f8829a4aSRandall Stewart 
2694f8829a4aSRandall Stewart 	m_at = m;
2695f8829a4aSRandall Stewart 	if (last_mbuf) {
2696f8829a4aSRandall Stewart 		return (sctp_add_pad_tombuf(last_mbuf, padval));
2697f8829a4aSRandall Stewart 	} else {
2698f8829a4aSRandall Stewart 		while (m_at) {
2699139bc87fSRandall Stewart 			if (SCTP_BUF_NEXT(m_at) == NULL) {
2700f8829a4aSRandall Stewart 				return (sctp_add_pad_tombuf(m_at, padval));
2701f8829a4aSRandall Stewart 			}
2702139bc87fSRandall Stewart 			m_at = SCTP_BUF_NEXT(m_at);
2703f8829a4aSRandall Stewart 		}
2704f8829a4aSRandall Stewart 	}
2705c4739e2fSRandall Stewart 	SCTP_LTRACE_ERR_RET_PKT(m, NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EFAULT);
2706f8829a4aSRandall Stewart 	return (EFAULT);
2707f8829a4aSRandall Stewart }
2708f8829a4aSRandall Stewart 
2709f8829a4aSRandall Stewart static void
2710f8829a4aSRandall Stewart sctp_notify_assoc_change(uint32_t event, struct sctp_tcb *stcb,
2711ceaad40aSRandall Stewart     uint32_t error, void *data, int so_locked
2712ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
2713ceaad40aSRandall Stewart     SCTP_UNUSED
2714ceaad40aSRandall Stewart #endif
2715ceaad40aSRandall Stewart )
2716f8829a4aSRandall Stewart {
2717f8829a4aSRandall Stewart 	struct mbuf *m_notify;
2718f8829a4aSRandall Stewart 	struct sctp_assoc_change *sac;
2719f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
2720f8829a4aSRandall Stewart 
2721ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2722ceaad40aSRandall Stewart 	struct socket *so;
2723ceaad40aSRandall Stewart 
2724ceaad40aSRandall Stewart #endif
2725ceaad40aSRandall Stewart 
2726f8829a4aSRandall Stewart 	/*
2727f8829a4aSRandall Stewart 	 * For TCP model AND UDP connected sockets we will send an error up
2728f8829a4aSRandall Stewart 	 * when an ABORT comes in.
2729f8829a4aSRandall Stewart 	 */
2730f8829a4aSRandall Stewart 	if (((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
2731f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) &&
27323c503c28SRandall Stewart 	    ((event == SCTP_COMM_LOST) || (event == SCTP_CANT_STR_ASSOC))) {
2733c4739e2fSRandall Stewart 		if (SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_COOKIE_WAIT) {
2734c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ECONNREFUSED);
273544b7479bSRandall Stewart 			stcb->sctp_socket->so_error = ECONNREFUSED;
2736c4739e2fSRandall Stewart 		} else {
2737c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ECONNRESET);
2738f8829a4aSRandall Stewart 			stcb->sctp_socket->so_error = ECONNRESET;
2739c4739e2fSRandall Stewart 		}
2740f8829a4aSRandall Stewart 		/* Wake ANY sleepers */
2741ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2742ceaad40aSRandall Stewart 		so = SCTP_INP_SO(stcb->sctp_ep);
2743ceaad40aSRandall Stewart 		if (!so_locked) {
2744ceaad40aSRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, 1);
2745ceaad40aSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
2746ceaad40aSRandall Stewart 			SCTP_SOCKET_LOCK(so, 1);
2747ceaad40aSRandall Stewart 			SCTP_TCB_LOCK(stcb);
2748ceaad40aSRandall Stewart 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
2749ceaad40aSRandall Stewart 			if (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET) {
2750ceaad40aSRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
2751ceaad40aSRandall Stewart 				return;
2752ceaad40aSRandall Stewart 			}
2753ceaad40aSRandall Stewart 		}
2754ceaad40aSRandall Stewart #endif
27558b4da1c3SMichael Tuexen 		socantrcvmore(stcb->sctp_socket);
2756f8829a4aSRandall Stewart 		sorwakeup(stcb->sctp_socket);
2757f8829a4aSRandall Stewart 		sowwakeup(stcb->sctp_socket);
2758ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2759ceaad40aSRandall Stewart 		if (!so_locked) {
2760ceaad40aSRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
2761ceaad40aSRandall Stewart 		}
2762ceaad40aSRandall Stewart #endif
2763f8829a4aSRandall Stewart 	}
2764*e2e7c62eSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVASSOCEVNT)) {
2765f8829a4aSRandall Stewart 		/* event not enabled */
2766f8829a4aSRandall Stewart 		return;
2767f8829a4aSRandall Stewart 	}
2768139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_assoc_change), 0, M_DONTWAIT, 1, MT_DATA);
2769f8829a4aSRandall Stewart 	if (m_notify == NULL)
2770f8829a4aSRandall Stewart 		/* no space left */
2771f8829a4aSRandall Stewart 		return;
2772139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
2773f8829a4aSRandall Stewart 
2774f8829a4aSRandall Stewart 	sac = mtod(m_notify, struct sctp_assoc_change *);
2775f8829a4aSRandall Stewart 	sac->sac_type = SCTP_ASSOC_CHANGE;
2776f8829a4aSRandall Stewart 	sac->sac_flags = 0;
2777f8829a4aSRandall Stewart 	sac->sac_length = sizeof(struct sctp_assoc_change);
2778f8829a4aSRandall Stewart 	sac->sac_state = event;
2779f8829a4aSRandall Stewart 	sac->sac_error = error;
2780f8829a4aSRandall Stewart 	/* XXX verify these stream counts */
2781f8829a4aSRandall Stewart 	sac->sac_outbound_streams = stcb->asoc.streamoutcnt;
2782f8829a4aSRandall Stewart 	sac->sac_inbound_streams = stcb->asoc.streamincnt;
2783f8829a4aSRandall Stewart 	sac->sac_assoc_id = sctp_get_associd(stcb);
2784139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_assoc_change);
2785139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
2786f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
2787f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
2788f8829a4aSRandall Stewart 	    m_notify);
2789f8829a4aSRandall Stewart 	if (control == NULL) {
2790f8829a4aSRandall Stewart 		/* no memory */
2791f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
2792f8829a4aSRandall Stewart 		return;
2793f8829a4aSRandall Stewart 	}
2794139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
2795f8829a4aSRandall Stewart 	/* not that we need this */
2796f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
2797139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
2798f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
2799f8829a4aSRandall Stewart 	    control,
2800cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD,
2801cfde3ff7SRandall Stewart 	    so_locked);
2802f8829a4aSRandall Stewart 	if (event == SCTP_COMM_LOST) {
2803f8829a4aSRandall Stewart 		/* Wake up any sleeper */
2804ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2805ceaad40aSRandall Stewart 		so = SCTP_INP_SO(stcb->sctp_ep);
2806ceaad40aSRandall Stewart 		if (!so_locked) {
2807ceaad40aSRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, 1);
2808ceaad40aSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
2809ceaad40aSRandall Stewart 			SCTP_SOCKET_LOCK(so, 1);
2810ceaad40aSRandall Stewart 			SCTP_TCB_LOCK(stcb);
2811ceaad40aSRandall Stewart 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
2812ceaad40aSRandall Stewart 			if (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET) {
2813ceaad40aSRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
2814ceaad40aSRandall Stewart 				return;
2815ceaad40aSRandall Stewart 			}
2816ceaad40aSRandall Stewart 		}
2817ceaad40aSRandall Stewart #endif
2818f8829a4aSRandall Stewart 		sctp_sowwakeup(stcb->sctp_ep, stcb->sctp_socket);
2819ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2820ceaad40aSRandall Stewart 		if (!so_locked) {
2821ceaad40aSRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
2822ceaad40aSRandall Stewart 		}
2823ceaad40aSRandall Stewart #endif
2824f8829a4aSRandall Stewart 	}
2825f8829a4aSRandall Stewart }
2826f8829a4aSRandall Stewart 
2827f8829a4aSRandall Stewart static void
2828f8829a4aSRandall Stewart sctp_notify_peer_addr_change(struct sctp_tcb *stcb, uint32_t state,
2829f8829a4aSRandall Stewart     struct sockaddr *sa, uint32_t error)
2830f8829a4aSRandall Stewart {
2831f8829a4aSRandall Stewart 	struct mbuf *m_notify;
2832f8829a4aSRandall Stewart 	struct sctp_paddr_change *spc;
2833f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
2834f8829a4aSRandall Stewart 
2835*e2e7c62eSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVPADDREVNT)) {
2836f8829a4aSRandall Stewart 		/* event not enabled */
2837f8829a4aSRandall Stewart 		return;
2838830d754dSRandall Stewart 	}
2839139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_paddr_change), 0, M_DONTWAIT, 1, MT_DATA);
2840f8829a4aSRandall Stewart 	if (m_notify == NULL)
2841f8829a4aSRandall Stewart 		return;
2842139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
2843f8829a4aSRandall Stewart 	spc = mtod(m_notify, struct sctp_paddr_change *);
2844f8829a4aSRandall Stewart 	spc->spc_type = SCTP_PEER_ADDR_CHANGE;
2845f8829a4aSRandall Stewart 	spc->spc_flags = 0;
2846f8829a4aSRandall Stewart 	spc->spc_length = sizeof(struct sctp_paddr_change);
28475e2c2d87SRandall Stewart 	switch (sa->sa_family) {
2848ea5eba11SMichael Tuexen #ifdef INET
28495e2c2d87SRandall Stewart 	case AF_INET:
2850f8829a4aSRandall Stewart 		memcpy(&spc->spc_aaddr, sa, sizeof(struct sockaddr_in));
28515e2c2d87SRandall Stewart 		break;
2852ea5eba11SMichael Tuexen #endif
28535e2c2d87SRandall Stewart #ifdef INET6
28545e2c2d87SRandall Stewart 	case AF_INET6:
28555e2c2d87SRandall Stewart 		{
2856f42a358aSRandall Stewart 			struct sockaddr_in6 *sin6;
2857f42a358aSRandall Stewart 
2858f8829a4aSRandall Stewart 			memcpy(&spc->spc_aaddr, sa, sizeof(struct sockaddr_in6));
2859f42a358aSRandall Stewart 
2860f42a358aSRandall Stewart 			sin6 = (struct sockaddr_in6 *)&spc->spc_aaddr;
2861f42a358aSRandall Stewart 			if (IN6_IS_SCOPE_LINKLOCAL(&sin6->sin6_addr)) {
286242551e99SRandall Stewart 				if (sin6->sin6_scope_id == 0) {
286342551e99SRandall Stewart 					/* recover scope_id for user */
2864f42a358aSRandall Stewart 					(void)sa6_recoverscope(sin6);
286542551e99SRandall Stewart 				} else {
286642551e99SRandall Stewart 					/* clear embedded scope_id for user */
286742551e99SRandall Stewart 					in6_clearscope(&sin6->sin6_addr);
286842551e99SRandall Stewart 				}
2869f42a358aSRandall Stewart 			}
28705e2c2d87SRandall Stewart 			break;
28715e2c2d87SRandall Stewart 		}
28725e2c2d87SRandall Stewart #endif
28735e2c2d87SRandall Stewart 	default:
28745e2c2d87SRandall Stewart 		/* TSNH */
28755e2c2d87SRandall Stewart 		break;
2876f8829a4aSRandall Stewart 	}
2877f8829a4aSRandall Stewart 	spc->spc_state = state;
2878f8829a4aSRandall Stewart 	spc->spc_error = error;
2879f8829a4aSRandall Stewart 	spc->spc_assoc_id = sctp_get_associd(stcb);
2880f8829a4aSRandall Stewart 
2881139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_paddr_change);
2882139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
2883f8829a4aSRandall Stewart 
2884f8829a4aSRandall Stewart 	/* append to socket */
2885f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
2886f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
2887f8829a4aSRandall Stewart 	    m_notify);
2888f8829a4aSRandall Stewart 	if (control == NULL) {
2889f8829a4aSRandall Stewart 		/* no memory */
2890f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
2891f8829a4aSRandall Stewart 		return;
2892f8829a4aSRandall Stewart 	}
2893139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
2894139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
2895f8829a4aSRandall Stewart 	/* not that we need this */
2896f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
2897f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
2898f8829a4aSRandall Stewart 	    control,
2899cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1,
2900cfde3ff7SRandall Stewart 	    SCTP_READ_LOCK_NOT_HELD,
2901cfde3ff7SRandall Stewart 	    SCTP_SO_NOT_LOCKED);
2902f8829a4aSRandall Stewart }
2903f8829a4aSRandall Stewart 
2904f8829a4aSRandall Stewart 
2905f8829a4aSRandall Stewart static void
2906f8829a4aSRandall Stewart sctp_notify_send_failed(struct sctp_tcb *stcb, uint32_t error,
2907ceaad40aSRandall Stewart     struct sctp_tmit_chunk *chk, int so_locked
2908ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
2909ceaad40aSRandall Stewart     SCTP_UNUSED
2910ceaad40aSRandall Stewart #endif
2911ceaad40aSRandall Stewart )
2912f8829a4aSRandall Stewart {
2913830d754dSRandall Stewart 	struct mbuf *m_notify;
2914f8829a4aSRandall Stewart 	struct sctp_send_failed *ssf;
2915f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
2916f8829a4aSRandall Stewart 	int length;
2917f8829a4aSRandall Stewart 
2918*e2e7c62eSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVSENDFAILEVNT)) {
2919f8829a4aSRandall Stewart 		/* event not enabled */
2920f8829a4aSRandall Stewart 		return;
2921830d754dSRandall Stewart 	}
2922139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_send_failed), 0, M_DONTWAIT, 1, MT_DATA);
2923f8829a4aSRandall Stewart 	if (m_notify == NULL)
2924f8829a4aSRandall Stewart 		/* no space left */
2925f8829a4aSRandall Stewart 		return;
2926fc14de76SRandall Stewart 	length = sizeof(struct sctp_send_failed) + chk->send_size;
2927fc14de76SRandall Stewart 	length -= sizeof(struct sctp_data_chunk);
2928139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
2929f8829a4aSRandall Stewart 	ssf = mtod(m_notify, struct sctp_send_failed *);
2930f8829a4aSRandall Stewart 	ssf->ssf_type = SCTP_SEND_FAILED;
2931f8829a4aSRandall Stewart 	if (error == SCTP_NOTIFY_DATAGRAM_UNSENT)
2932f8829a4aSRandall Stewart 		ssf->ssf_flags = SCTP_DATA_UNSENT;
2933f8829a4aSRandall Stewart 	else
2934f8829a4aSRandall Stewart 		ssf->ssf_flags = SCTP_DATA_SENT;
2935f8829a4aSRandall Stewart 	ssf->ssf_length = length;
2936f8829a4aSRandall Stewart 	ssf->ssf_error = error;
2937f8829a4aSRandall Stewart 	/* not exactly what the user sent in, but should be close :) */
2938d00aff5dSRandall Stewart 	bzero(&ssf->ssf_info, sizeof(ssf->ssf_info));
2939f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_stream = chk->rec.data.stream_number;
2940f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_ssn = chk->rec.data.stream_seq;
2941f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_flags = chk->rec.data.rcv_flags;
2942f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_ppid = chk->rec.data.payloadtype;
2943f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_context = chk->rec.data.context;
2944f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_assoc_id = sctp_get_associd(stcb);
2945f8829a4aSRandall Stewart 	ssf->ssf_assoc_id = sctp_get_associd(stcb);
2946fc14de76SRandall Stewart 
2947830d754dSRandall Stewart 	if (chk->data) {
2948830d754dSRandall Stewart 		/*
2949830d754dSRandall Stewart 		 * trim off the sctp chunk header(it should be there)
2950830d754dSRandall Stewart 		 */
2951830d754dSRandall Stewart 		if (chk->send_size >= sizeof(struct sctp_data_chunk)) {
2952830d754dSRandall Stewart 			m_adj(chk->data, sizeof(struct sctp_data_chunk));
2953830d754dSRandall Stewart 			sctp_mbuf_crush(chk->data);
2954830d754dSRandall Stewart 			chk->send_size -= sizeof(struct sctp_data_chunk);
2955830d754dSRandall Stewart 		}
2956830d754dSRandall Stewart 	}
2957810ec536SMichael Tuexen 	SCTP_BUF_NEXT(m_notify) = chk->data;
2958810ec536SMichael Tuexen 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_send_failed);
2959f8829a4aSRandall Stewart 	/* Steal off the mbuf */
2960f8829a4aSRandall Stewart 	chk->data = NULL;
2961f8829a4aSRandall Stewart 	/*
2962f8829a4aSRandall Stewart 	 * For this case, we check the actual socket buffer, since the assoc
2963f8829a4aSRandall Stewart 	 * is going away we don't want to overfill the socket buffer for a
2964f8829a4aSRandall Stewart 	 * non-reader
2965f8829a4aSRandall Stewart 	 */
2966139bc87fSRandall Stewart 	if (sctp_sbspace_failedmsgs(&stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
2967f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
2968f8829a4aSRandall Stewart 		return;
2969f8829a4aSRandall Stewart 	}
2970f8829a4aSRandall Stewart 	/* append to socket */
2971f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
2972f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
2973f8829a4aSRandall Stewart 	    m_notify);
2974f8829a4aSRandall Stewart 	if (control == NULL) {
2975f8829a4aSRandall Stewart 		/* no memory */
2976f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
2977f8829a4aSRandall Stewart 		return;
2978f8829a4aSRandall Stewart 	}
2979139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
2980f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
2981f8829a4aSRandall Stewart 	    control,
2982cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1,
2983cfde3ff7SRandall Stewart 	    SCTP_READ_LOCK_NOT_HELD,
2984cfde3ff7SRandall Stewart 	    so_locked);
2985f8829a4aSRandall Stewart }
2986f8829a4aSRandall Stewart 
2987f8829a4aSRandall Stewart 
2988f8829a4aSRandall Stewart static void
2989f8829a4aSRandall Stewart sctp_notify_send_failed2(struct sctp_tcb *stcb, uint32_t error,
2990ceaad40aSRandall Stewart     struct sctp_stream_queue_pending *sp, int so_locked
2991ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
2992ceaad40aSRandall Stewart     SCTP_UNUSED
2993ceaad40aSRandall Stewart #endif
2994ceaad40aSRandall Stewart )
2995f8829a4aSRandall Stewart {
2996f8829a4aSRandall Stewart 	struct mbuf *m_notify;
2997f8829a4aSRandall Stewart 	struct sctp_send_failed *ssf;
2998f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
2999f8829a4aSRandall Stewart 	int length;
3000f8829a4aSRandall Stewart 
3001*e2e7c62eSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVSENDFAILEVNT)) {
3002f8829a4aSRandall Stewart 		/* event not enabled */
3003f8829a4aSRandall Stewart 		return;
3004830d754dSRandall Stewart 	}
3005f8829a4aSRandall Stewart 	length = sizeof(struct sctp_send_failed) + sp->length;
3006d00aff5dSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_send_failed), 0, M_DONTWAIT, 1, MT_DATA);
3007f8829a4aSRandall Stewart 	if (m_notify == NULL)
3008f8829a4aSRandall Stewart 		/* no space left */
3009f8829a4aSRandall Stewart 		return;
3010139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3011f8829a4aSRandall Stewart 	ssf = mtod(m_notify, struct sctp_send_failed *);
3012f8829a4aSRandall Stewart 	ssf->ssf_type = SCTP_SEND_FAILED;
3013f8829a4aSRandall Stewart 	if (error == SCTP_NOTIFY_DATAGRAM_UNSENT)
3014f8829a4aSRandall Stewart 		ssf->ssf_flags = SCTP_DATA_UNSENT;
3015f8829a4aSRandall Stewart 	else
3016f8829a4aSRandall Stewart 		ssf->ssf_flags = SCTP_DATA_SENT;
3017f8829a4aSRandall Stewart 	ssf->ssf_length = length;
3018f8829a4aSRandall Stewart 	ssf->ssf_error = error;
3019f8829a4aSRandall Stewart 	/* not exactly what the user sent in, but should be close :) */
3020d00aff5dSRandall Stewart 	bzero(&ssf->ssf_info, sizeof(ssf->ssf_info));
3021f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_stream = sp->stream;
3022f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_ssn = sp->strseq;
3023fc14de76SRandall Stewart 	if (sp->some_taken) {
3024fc14de76SRandall Stewart 		ssf->ssf_info.sinfo_flags = SCTP_DATA_LAST_FRAG;
3025fc14de76SRandall Stewart 	} else {
3026fc14de76SRandall Stewart 		ssf->ssf_info.sinfo_flags = SCTP_DATA_NOT_FRAG;
3027fc14de76SRandall Stewart 	}
3028f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_ppid = sp->ppid;
3029f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_context = sp->context;
3030f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_assoc_id = sctp_get_associd(stcb);
3031f8829a4aSRandall Stewart 	ssf->ssf_assoc_id = sctp_get_associd(stcb);
3032139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = sp->data;
3033139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_send_failed);
3034f8829a4aSRandall Stewart 
3035f8829a4aSRandall Stewart 	/* Steal off the mbuf */
3036f8829a4aSRandall Stewart 	sp->data = NULL;
3037f8829a4aSRandall Stewart 	/*
3038f8829a4aSRandall Stewart 	 * For this case, we check the actual socket buffer, since the assoc
3039f8829a4aSRandall Stewart 	 * is going away we don't want to overfill the socket buffer for a
3040f8829a4aSRandall Stewart 	 * non-reader
3041f8829a4aSRandall Stewart 	 */
3042139bc87fSRandall Stewart 	if (sctp_sbspace_failedmsgs(&stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3043f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3044f8829a4aSRandall Stewart 		return;
3045f8829a4aSRandall Stewart 	}
3046f8829a4aSRandall Stewart 	/* append to socket */
3047f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3048f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3049f8829a4aSRandall Stewart 	    m_notify);
3050f8829a4aSRandall Stewart 	if (control == NULL) {
3051f8829a4aSRandall Stewart 		/* no memory */
3052f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3053f8829a4aSRandall Stewart 		return;
3054f8829a4aSRandall Stewart 	}
3055139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3056f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3057f8829a4aSRandall Stewart 	    control,
3058cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, so_locked);
3059f8829a4aSRandall Stewart }
3060f8829a4aSRandall Stewart 
3061f8829a4aSRandall Stewart 
3062f8829a4aSRandall Stewart 
3063f8829a4aSRandall Stewart static void
3064f8829a4aSRandall Stewart sctp_notify_adaptation_layer(struct sctp_tcb *stcb,
3065f8829a4aSRandall Stewart     uint32_t error)
3066f8829a4aSRandall Stewart {
3067f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3068f8829a4aSRandall Stewart 	struct sctp_adaptation_event *sai;
3069f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3070f8829a4aSRandall Stewart 
3071*e2e7c62eSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_ADAPTATIONEVNT)) {
3072f8829a4aSRandall Stewart 		/* event not enabled */
3073f8829a4aSRandall Stewart 		return;
3074830d754dSRandall Stewart 	}
3075139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_adaption_event), 0, M_DONTWAIT, 1, MT_DATA);
3076f8829a4aSRandall Stewart 	if (m_notify == NULL)
3077f8829a4aSRandall Stewart 		/* no space left */
3078f8829a4aSRandall Stewart 		return;
3079139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3080f8829a4aSRandall Stewart 	sai = mtod(m_notify, struct sctp_adaptation_event *);
3081f8829a4aSRandall Stewart 	sai->sai_type = SCTP_ADAPTATION_INDICATION;
3082f8829a4aSRandall Stewart 	sai->sai_flags = 0;
3083f8829a4aSRandall Stewart 	sai->sai_length = sizeof(struct sctp_adaptation_event);
30842afb3e84SRandall Stewart 	sai->sai_adaptation_ind = stcb->asoc.peers_adaptation;
3085f8829a4aSRandall Stewart 	sai->sai_assoc_id = sctp_get_associd(stcb);
3086f8829a4aSRandall Stewart 
3087139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_adaptation_event);
3088139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3089f8829a4aSRandall Stewart 
3090f8829a4aSRandall Stewart 	/* append to socket */
3091f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3092f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3093f8829a4aSRandall Stewart 	    m_notify);
3094f8829a4aSRandall Stewart 	if (control == NULL) {
3095f8829a4aSRandall Stewart 		/* no memory */
3096f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3097f8829a4aSRandall Stewart 		return;
3098f8829a4aSRandall Stewart 	}
3099139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3100139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3101f8829a4aSRandall Stewart 	/* not that we need this */
3102f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
3103f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3104f8829a4aSRandall Stewart 	    control,
3105cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, SCTP_SO_NOT_LOCKED);
3106f8829a4aSRandall Stewart }
3107f8829a4aSRandall Stewart 
310803b0b021SRandall Stewart /* This always must be called with the read-queue LOCKED in the INP */
3109810ec536SMichael Tuexen static void
31102dad8a55SRandall Stewart sctp_notify_partial_delivery_indication(struct sctp_tcb *stcb, uint32_t error,
3111810ec536SMichael Tuexen     uint32_t val, int so_locked
3112810ec536SMichael Tuexen #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3113810ec536SMichael Tuexen     SCTP_UNUSED
3114810ec536SMichael Tuexen #endif
3115810ec536SMichael Tuexen )
3116f8829a4aSRandall Stewart {
3117f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3118f8829a4aSRandall Stewart 	struct sctp_pdapi_event *pdapi;
3119f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
312003b0b021SRandall Stewart 	struct sockbuf *sb;
3121f8829a4aSRandall Stewart 
3122*e2e7c62eSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_PDAPIEVNT)) {
3123f8829a4aSRandall Stewart 		/* event not enabled */
3124f8829a4aSRandall Stewart 		return;
3125830d754dSRandall Stewart 	}
3126cd1386abSMichael Tuexen 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_CANT_READ) {
3127cd1386abSMichael Tuexen 		return;
3128cd1386abSMichael Tuexen 	}
3129139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_pdapi_event), 0, M_DONTWAIT, 1, MT_DATA);
3130f8829a4aSRandall Stewart 	if (m_notify == NULL)
3131f8829a4aSRandall Stewart 		/* no space left */
3132f8829a4aSRandall Stewart 		return;
3133139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3134f8829a4aSRandall Stewart 	pdapi = mtod(m_notify, struct sctp_pdapi_event *);
3135f8829a4aSRandall Stewart 	pdapi->pdapi_type = SCTP_PARTIAL_DELIVERY_EVENT;
3136f8829a4aSRandall Stewart 	pdapi->pdapi_flags = 0;
3137f8829a4aSRandall Stewart 	pdapi->pdapi_length = sizeof(struct sctp_pdapi_event);
3138f8829a4aSRandall Stewart 	pdapi->pdapi_indication = error;
31399a6142d8SRandall Stewart 	pdapi->pdapi_stream = (val >> 16);
31409a6142d8SRandall Stewart 	pdapi->pdapi_seq = (val & 0x0000ffff);
3141f8829a4aSRandall Stewart 	pdapi->pdapi_assoc_id = sctp_get_associd(stcb);
3142f8829a4aSRandall Stewart 
3143139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_pdapi_event);
3144139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3145f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3146f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3147f8829a4aSRandall Stewart 	    m_notify);
3148f8829a4aSRandall Stewart 	if (control == NULL) {
3149f8829a4aSRandall Stewart 		/* no memory */
3150f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3151f8829a4aSRandall Stewart 		return;
3152f8829a4aSRandall Stewart 	}
3153139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3154139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3155f8829a4aSRandall Stewart 	/* not that we need this */
3156f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
315703b0b021SRandall Stewart 	control->held_length = 0;
315803b0b021SRandall Stewart 	control->length = 0;
315903b0b021SRandall Stewart 	sb = &stcb->sctp_socket->so_rcv;
3160b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
3161139bc87fSRandall Stewart 		sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m_notify));
316280fefe0aSRandall Stewart 	}
316303b0b021SRandall Stewart 	sctp_sballoc(stcb, sb, m_notify);
3164b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
316503b0b021SRandall Stewart 		sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
316680fefe0aSRandall Stewart 	}
3167139bc87fSRandall Stewart 	atomic_add_int(&control->length, SCTP_BUF_LEN(m_notify));
316803b0b021SRandall Stewart 	control->end_added = 1;
316903b0b021SRandall Stewart 	if (stcb->asoc.control_pdapi)
317003b0b021SRandall Stewart 		TAILQ_INSERT_AFTER(&stcb->sctp_ep->read_queue, stcb->asoc.control_pdapi, control, next);
317103b0b021SRandall Stewart 	else {
317203b0b021SRandall Stewart 		/* we really should not see this case */
317303b0b021SRandall Stewart 		TAILQ_INSERT_TAIL(&stcb->sctp_ep->read_queue, control, next);
317403b0b021SRandall Stewart 	}
317503b0b021SRandall Stewart 	if (stcb->sctp_ep && stcb->sctp_socket) {
317603b0b021SRandall Stewart 		/* This should always be the case */
3177810ec536SMichael Tuexen #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3178810ec536SMichael Tuexen 		struct socket *so;
3179810ec536SMichael Tuexen 
3180810ec536SMichael Tuexen 		so = SCTP_INP_SO(stcb->sctp_ep);
3181810ec536SMichael Tuexen 		if (!so_locked) {
3182810ec536SMichael Tuexen 			atomic_add_int(&stcb->asoc.refcnt, 1);
3183810ec536SMichael Tuexen 			SCTP_TCB_UNLOCK(stcb);
3184810ec536SMichael Tuexen 			SCTP_SOCKET_LOCK(so, 1);
3185810ec536SMichael Tuexen 			SCTP_TCB_LOCK(stcb);
3186810ec536SMichael Tuexen 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
3187810ec536SMichael Tuexen 			if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
3188810ec536SMichael Tuexen 				SCTP_SOCKET_UNLOCK(so, 1);
3189810ec536SMichael Tuexen 				return;
3190810ec536SMichael Tuexen 			}
3191810ec536SMichael Tuexen 		}
3192810ec536SMichael Tuexen #endif
319303b0b021SRandall Stewart 		sctp_sorwakeup(stcb->sctp_ep, stcb->sctp_socket);
3194810ec536SMichael Tuexen #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3195810ec536SMichael Tuexen 		if (!so_locked) {
3196810ec536SMichael Tuexen 			SCTP_SOCKET_UNLOCK(so, 1);
3197810ec536SMichael Tuexen 		}
3198810ec536SMichael Tuexen #endif
3199f8829a4aSRandall Stewart 	}
3200f8829a4aSRandall Stewart }
3201f8829a4aSRandall Stewart 
3202f8829a4aSRandall Stewart static void
3203f8829a4aSRandall Stewart sctp_notify_shutdown_event(struct sctp_tcb *stcb)
3204f8829a4aSRandall Stewart {
3205f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3206f8829a4aSRandall Stewart 	struct sctp_shutdown_event *sse;
3207f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3208f8829a4aSRandall Stewart 
3209f8829a4aSRandall Stewart 	/*
3210f8829a4aSRandall Stewart 	 * For TCP model AND UDP connected sockets we will send an error up
3211f8829a4aSRandall Stewart 	 * when an SHUTDOWN completes
3212f8829a4aSRandall Stewart 	 */
3213f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
3214f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
3215f8829a4aSRandall Stewart 		/* mark socket closed for read/write and wakeup! */
3216ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3217ceaad40aSRandall Stewart 		struct socket *so;
3218ceaad40aSRandall Stewart 
3219ceaad40aSRandall Stewart 		so = SCTP_INP_SO(stcb->sctp_ep);
3220ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
3221ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
3222ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
3223ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
3224ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
3225ceaad40aSRandall Stewart 		if (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET) {
3226ceaad40aSRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
3227ceaad40aSRandall Stewart 			return;
3228ceaad40aSRandall Stewart 		}
3229ceaad40aSRandall Stewart #endif
3230f8829a4aSRandall Stewart 		socantsendmore(stcb->sctp_socket);
3231ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3232ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
3233ceaad40aSRandall Stewart #endif
3234f8829a4aSRandall Stewart 	}
3235*e2e7c62eSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_RECVSHUTDOWNEVNT)) {
3236f8829a4aSRandall Stewart 		/* event not enabled */
3237f8829a4aSRandall Stewart 		return;
3238830d754dSRandall Stewart 	}
3239139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_shutdown_event), 0, M_DONTWAIT, 1, MT_DATA);
3240f8829a4aSRandall Stewart 	if (m_notify == NULL)
3241f8829a4aSRandall Stewart 		/* no space left */
3242f8829a4aSRandall Stewart 		return;
3243f8829a4aSRandall Stewart 	sse = mtod(m_notify, struct sctp_shutdown_event *);
3244f8829a4aSRandall Stewart 	sse->sse_type = SCTP_SHUTDOWN_EVENT;
3245f8829a4aSRandall Stewart 	sse->sse_flags = 0;
3246f8829a4aSRandall Stewart 	sse->sse_length = sizeof(struct sctp_shutdown_event);
3247f8829a4aSRandall Stewart 	sse->sse_assoc_id = sctp_get_associd(stcb);
3248f8829a4aSRandall Stewart 
3249139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_shutdown_event);
3250139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3251f8829a4aSRandall Stewart 
3252f8829a4aSRandall Stewart 	/* append to socket */
3253f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3254f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3255f8829a4aSRandall Stewart 	    m_notify);
3256f8829a4aSRandall Stewart 	if (control == NULL) {
3257f8829a4aSRandall Stewart 		/* no memory */
3258f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3259f8829a4aSRandall Stewart 		return;
3260f8829a4aSRandall Stewart 	}
3261139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3262139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3263f8829a4aSRandall Stewart 	/* not that we need this */
3264f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
3265f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3266f8829a4aSRandall Stewart 	    control,
3267cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, SCTP_SO_NOT_LOCKED);
3268f8829a4aSRandall Stewart }
3269f8829a4aSRandall Stewart 
3270f8829a4aSRandall Stewart static void
3271830d754dSRandall Stewart sctp_notify_sender_dry_event(struct sctp_tcb *stcb,
3272830d754dSRandall Stewart     int so_locked
3273830d754dSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3274830d754dSRandall Stewart     SCTP_UNUSED
3275830d754dSRandall Stewart #endif
3276830d754dSRandall Stewart )
3277830d754dSRandall Stewart {
3278830d754dSRandall Stewart 	struct mbuf *m_notify;
3279830d754dSRandall Stewart 	struct sctp_sender_dry_event *event;
3280830d754dSRandall Stewart 	struct sctp_queued_to_read *control;
3281830d754dSRandall Stewart 
3282*e2e7c62eSMichael Tuexen 	if (sctp_stcb_is_feature_off(stcb->sctp_ep, stcb, SCTP_PCB_FLAGS_DRYEVNT)) {
3283830d754dSRandall Stewart 		/* event not enabled */
3284830d754dSRandall Stewart 		return;
3285830d754dSRandall Stewart 	}
3286830d754dSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_sender_dry_event), 0, M_DONTWAIT, 1, MT_DATA);
3287830d754dSRandall Stewart 	if (m_notify == NULL) {
3288830d754dSRandall Stewart 		/* no space left */
3289830d754dSRandall Stewart 		return;
3290830d754dSRandall Stewart 	}
3291830d754dSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3292830d754dSRandall Stewart 	event = mtod(m_notify, struct sctp_sender_dry_event *);
3293830d754dSRandall Stewart 	event->sender_dry_type = SCTP_SENDER_DRY_EVENT;
3294830d754dSRandall Stewart 	event->sender_dry_flags = 0;
3295830d754dSRandall Stewart 	event->sender_dry_length = sizeof(struct sctp_sender_dry_event);
3296830d754dSRandall Stewart 	event->sender_dry_assoc_id = sctp_get_associd(stcb);
3297830d754dSRandall Stewart 
3298830d754dSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_sender_dry_event);
3299830d754dSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3300830d754dSRandall Stewart 
3301830d754dSRandall Stewart 	/* append to socket */
3302830d754dSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3303830d754dSRandall Stewart 	    0, 0, 0, 0, 0, 0, m_notify);
3304830d754dSRandall Stewart 	if (control == NULL) {
3305830d754dSRandall Stewart 		/* no memory */
3306830d754dSRandall Stewart 		sctp_m_freem(m_notify);
3307830d754dSRandall Stewart 		return;
3308830d754dSRandall Stewart 	}
3309830d754dSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3310830d754dSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3311830d754dSRandall Stewart 	/* not that we need this */
3312830d754dSRandall Stewart 	control->tail_mbuf = m_notify;
3313830d754dSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb, control,
3314cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, so_locked);
3315830d754dSRandall Stewart }
3316830d754dSRandall Stewart 
3317ea44232bSRandall Stewart 
3318ea44232bSRandall Stewart static void
3319ea44232bSRandall Stewart sctp_notify_stream_reset_add(struct sctp_tcb *stcb, int number_entries, int flag)
3320ea44232bSRandall Stewart {
3321ea44232bSRandall Stewart 	struct mbuf *m_notify;
3322ea44232bSRandall Stewart 	struct sctp_queued_to_read *control;
3323ea44232bSRandall Stewart 	struct sctp_stream_reset_event *strreset;
3324ea44232bSRandall Stewart 	int len;
3325ea44232bSRandall Stewart 
3326ea44232bSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_STREAM_RESETEVNT)) {
3327ea44232bSRandall Stewart 		/* event not enabled */
3328ea44232bSRandall Stewart 		return;
3329ea44232bSRandall Stewart 	}
3330ea44232bSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(MCLBYTES, 0, M_DONTWAIT, 1, MT_DATA);
3331ea44232bSRandall Stewart 	if (m_notify == NULL)
3332ea44232bSRandall Stewart 		/* no space left */
3333ea44232bSRandall Stewart 		return;
3334ea44232bSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3335ea44232bSRandall Stewart 	len = sizeof(struct sctp_stream_reset_event) + (number_entries * sizeof(uint16_t));
3336ea44232bSRandall Stewart 	if (len > M_TRAILINGSPACE(m_notify)) {
3337ea44232bSRandall Stewart 		/* never enough room */
3338ea44232bSRandall Stewart 		sctp_m_freem(m_notify);
3339ea44232bSRandall Stewart 		return;
3340ea44232bSRandall Stewart 	}
3341ea44232bSRandall Stewart 	strreset = mtod(m_notify, struct sctp_stream_reset_event *);
3342ea44232bSRandall Stewart 	strreset->strreset_type = SCTP_STREAM_RESET_EVENT;
3343ea44232bSRandall Stewart 	strreset->strreset_flags = SCTP_STRRESET_ADD_STREAM | flag;
3344ea44232bSRandall Stewart 	strreset->strreset_length = len;
3345ea44232bSRandall Stewart 	strreset->strreset_assoc_id = sctp_get_associd(stcb);
3346ea44232bSRandall Stewart 	strreset->strreset_list[0] = number_entries;
3347ea44232bSRandall Stewart 
3348ea44232bSRandall Stewart 	SCTP_BUF_LEN(m_notify) = len;
3349ea44232bSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3350ea44232bSRandall Stewart 	if (sctp_sbspace(&stcb->asoc, &stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3351ea44232bSRandall Stewart 		/* no space */
3352ea44232bSRandall Stewart 		sctp_m_freem(m_notify);
3353ea44232bSRandall Stewart 		return;
3354ea44232bSRandall Stewart 	}
3355ea44232bSRandall Stewart 	/* append to socket */
3356ea44232bSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3357ea44232bSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3358ea44232bSRandall Stewart 	    m_notify);
3359ea44232bSRandall Stewart 	if (control == NULL) {
3360ea44232bSRandall Stewart 		/* no memory */
3361ea44232bSRandall Stewart 		sctp_m_freem(m_notify);
3362ea44232bSRandall Stewart 		return;
3363ea44232bSRandall Stewart 	}
3364ea44232bSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3365ea44232bSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3366ea44232bSRandall Stewart 	/* not that we need this */
3367ea44232bSRandall Stewart 	control->tail_mbuf = m_notify;
3368ea44232bSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3369ea44232bSRandall Stewart 	    control,
3370cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, SCTP_SO_NOT_LOCKED);
3371ea44232bSRandall Stewart }
3372ea44232bSRandall Stewart 
3373ea44232bSRandall Stewart 
3374830d754dSRandall Stewart static void
3375f8829a4aSRandall Stewart sctp_notify_stream_reset(struct sctp_tcb *stcb,
3376f8829a4aSRandall Stewart     int number_entries, uint16_t * list, int flag)
3377f8829a4aSRandall Stewart {
3378f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3379f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3380f8829a4aSRandall Stewart 	struct sctp_stream_reset_event *strreset;
3381f8829a4aSRandall Stewart 	int len;
3382f8829a4aSRandall Stewart 
3383830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_STREAM_RESETEVNT)) {
3384f8829a4aSRandall Stewart 		/* event not enabled */
3385f8829a4aSRandall Stewart 		return;
3386830d754dSRandall Stewart 	}
3387139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(MCLBYTES, 0, M_DONTWAIT, 1, MT_DATA);
3388f8829a4aSRandall Stewart 	if (m_notify == NULL)
3389f8829a4aSRandall Stewart 		/* no space left */
3390f8829a4aSRandall Stewart 		return;
3391139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3392f8829a4aSRandall Stewart 	len = sizeof(struct sctp_stream_reset_event) + (number_entries * sizeof(uint16_t));
3393f8829a4aSRandall Stewart 	if (len > M_TRAILINGSPACE(m_notify)) {
3394f8829a4aSRandall Stewart 		/* never enough room */
3395f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3396f8829a4aSRandall Stewart 		return;
3397f8829a4aSRandall Stewart 	}
3398f8829a4aSRandall Stewart 	strreset = mtod(m_notify, struct sctp_stream_reset_event *);
3399f8829a4aSRandall Stewart 	strreset->strreset_type = SCTP_STREAM_RESET_EVENT;
3400f8829a4aSRandall Stewart 	if (number_entries == 0) {
3401f8829a4aSRandall Stewart 		strreset->strreset_flags = flag | SCTP_STRRESET_ALL_STREAMS;
3402f8829a4aSRandall Stewart 	} else {
3403f8829a4aSRandall Stewart 		strreset->strreset_flags = flag | SCTP_STRRESET_STREAM_LIST;
3404f8829a4aSRandall Stewart 	}
3405f8829a4aSRandall Stewart 	strreset->strreset_length = len;
3406f8829a4aSRandall Stewart 	strreset->strreset_assoc_id = sctp_get_associd(stcb);
3407f8829a4aSRandall Stewart 	if (number_entries) {
3408f8829a4aSRandall Stewart 		int i;
3409f8829a4aSRandall Stewart 
3410f8829a4aSRandall Stewart 		for (i = 0; i < number_entries; i++) {
3411f8829a4aSRandall Stewart 			strreset->strreset_list[i] = ntohs(list[i]);
3412f8829a4aSRandall Stewart 		}
3413f8829a4aSRandall Stewart 	}
3414139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = len;
3415139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3416139bc87fSRandall Stewart 	if (sctp_sbspace(&stcb->asoc, &stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3417f8829a4aSRandall Stewart 		/* no space */
3418f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3419f8829a4aSRandall Stewart 		return;
3420f8829a4aSRandall Stewart 	}
3421f8829a4aSRandall Stewart 	/* append to socket */
3422f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3423f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3424f8829a4aSRandall Stewart 	    m_notify);
3425f8829a4aSRandall Stewart 	if (control == NULL) {
3426f8829a4aSRandall Stewart 		/* no memory */
3427f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3428f8829a4aSRandall Stewart 		return;
3429f8829a4aSRandall Stewart 	}
3430139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3431139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3432f8829a4aSRandall Stewart 	/* not that we need this */
3433f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
3434f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3435f8829a4aSRandall Stewart 	    control,
3436cfde3ff7SRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_READ_LOCK_NOT_HELD, SCTP_SO_NOT_LOCKED);
3437f8829a4aSRandall Stewart }
3438f8829a4aSRandall Stewart 
3439f8829a4aSRandall Stewart 
3440f8829a4aSRandall Stewart void
3441f8829a4aSRandall Stewart sctp_ulp_notify(uint32_t notification, struct sctp_tcb *stcb,
3442ceaad40aSRandall Stewart     uint32_t error, void *data, int so_locked
3443ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3444ceaad40aSRandall Stewart     SCTP_UNUSED
3445ceaad40aSRandall Stewart #endif
3446ceaad40aSRandall Stewart )
3447f8829a4aSRandall Stewart {
3448830d754dSRandall Stewart 	if ((stcb == NULL) ||
3449830d754dSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
3450f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
3451830d754dSRandall Stewart 	    (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET)) {
3452830d754dSRandall Stewart 		/* If the socket is gone we are out of here */
3453f8829a4aSRandall Stewart 		return;
3454f8829a4aSRandall Stewart 	}
3455a99b6783SRandall Stewart 	if (stcb->sctp_socket->so_rcv.sb_state & SBS_CANTRCVMORE) {
3456a99b6783SRandall Stewart 		return;
3457a99b6783SRandall Stewart 	}
345817205eccSRandall Stewart 	if (stcb && ((stcb->asoc.state & SCTP_STATE_COOKIE_WAIT) ||
345917205eccSRandall Stewart 	    (stcb->asoc.state & SCTP_STATE_COOKIE_ECHOED))) {
346017205eccSRandall Stewart 		if ((notification == SCTP_NOTIFY_INTERFACE_DOWN) ||
346117205eccSRandall Stewart 		    (notification == SCTP_NOTIFY_INTERFACE_UP) ||
346217205eccSRandall Stewart 		    (notification == SCTP_NOTIFY_INTERFACE_CONFIRMED)) {
346317205eccSRandall Stewart 			/* Don't report these in front states */
346417205eccSRandall Stewart 			return;
346517205eccSRandall Stewart 		}
346617205eccSRandall Stewart 	}
3467f8829a4aSRandall Stewart 	switch (notification) {
3468f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_UP:
3469f8829a4aSRandall Stewart 		if (stcb->asoc.assoc_up_sent == 0) {
3470ceaad40aSRandall Stewart 			sctp_notify_assoc_change(SCTP_COMM_UP, stcb, error, NULL, so_locked);
3471f8829a4aSRandall Stewart 			stcb->asoc.assoc_up_sent = 1;
3472f8829a4aSRandall Stewart 		}
34732afb3e84SRandall Stewart 		if (stcb->asoc.adaptation_needed && (stcb->asoc.adaptation_sent == 0)) {
34742afb3e84SRandall Stewart 			sctp_notify_adaptation_layer(stcb, error);
34752afb3e84SRandall Stewart 		}
3476830d754dSRandall Stewart 		if (stcb->asoc.peer_supports_auth == 0) {
3477830d754dSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_NO_PEER_AUTH, stcb, 0,
3478830d754dSRandall Stewart 			    NULL, so_locked);
3479830d754dSRandall Stewart 		}
3480f8829a4aSRandall Stewart 		break;
3481f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_DOWN:
3482ceaad40aSRandall Stewart 		sctp_notify_assoc_change(SCTP_SHUTDOWN_COMP, stcb, error, NULL, so_locked);
3483f8829a4aSRandall Stewart 		break;
3484f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_DOWN:
3485f8829a4aSRandall Stewart 		{
3486f8829a4aSRandall Stewart 			struct sctp_nets *net;
3487f8829a4aSRandall Stewart 
3488f8829a4aSRandall Stewart 			net = (struct sctp_nets *)data;
3489f8829a4aSRandall Stewart 			sctp_notify_peer_addr_change(stcb, SCTP_ADDR_UNREACHABLE,
3490f8829a4aSRandall Stewart 			    (struct sockaddr *)&net->ro._l_addr, error);
3491f8829a4aSRandall Stewart 			break;
3492f8829a4aSRandall Stewart 		}
3493f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_UP:
3494f8829a4aSRandall Stewart 		{
3495f8829a4aSRandall Stewart 			struct sctp_nets *net;
3496f8829a4aSRandall Stewart 
3497f8829a4aSRandall Stewart 			net = (struct sctp_nets *)data;
3498f8829a4aSRandall Stewart 			sctp_notify_peer_addr_change(stcb, SCTP_ADDR_AVAILABLE,
3499f8829a4aSRandall Stewart 			    (struct sockaddr *)&net->ro._l_addr, error);
3500f8829a4aSRandall Stewart 			break;
3501f8829a4aSRandall Stewart 		}
3502f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_CONFIRMED:
3503f8829a4aSRandall Stewart 		{
3504f8829a4aSRandall Stewart 			struct sctp_nets *net;
3505f8829a4aSRandall Stewart 
3506f8829a4aSRandall Stewart 			net = (struct sctp_nets *)data;
3507f8829a4aSRandall Stewart 			sctp_notify_peer_addr_change(stcb, SCTP_ADDR_CONFIRMED,
3508f8829a4aSRandall Stewart 			    (struct sockaddr *)&net->ro._l_addr, error);
3509f8829a4aSRandall Stewart 			break;
3510f8829a4aSRandall Stewart 		}
3511f8829a4aSRandall Stewart 	case SCTP_NOTIFY_SPECIAL_SP_FAIL:
3512f8829a4aSRandall Stewart 		sctp_notify_send_failed2(stcb, error,
3513ceaad40aSRandall Stewart 		    (struct sctp_stream_queue_pending *)data, so_locked);
3514f8829a4aSRandall Stewart 		break;
3515f8829a4aSRandall Stewart 	case SCTP_NOTIFY_DG_FAIL:
3516f8829a4aSRandall Stewart 		sctp_notify_send_failed(stcb, error,
3517ceaad40aSRandall Stewart 		    (struct sctp_tmit_chunk *)data, so_locked);
3518f8829a4aSRandall Stewart 		break;
3519f8829a4aSRandall Stewart 	case SCTP_NOTIFY_PARTIAL_DELVIERY_INDICATION:
35209a6142d8SRandall Stewart 		{
35219a6142d8SRandall Stewart 			uint32_t val;
35229a6142d8SRandall Stewart 
35239a6142d8SRandall Stewart 			val = *((uint32_t *) data);
35249a6142d8SRandall Stewart 
3525810ec536SMichael Tuexen 			sctp_notify_partial_delivery_indication(stcb, error, val, so_locked);
3526f8829a4aSRandall Stewart 			break;
3527810ec536SMichael Tuexen 		}
3528f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STRDATA_ERR:
3529f8829a4aSRandall Stewart 		break;
3530f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_ABORTED:
3531c105859eSRandall Stewart 		if ((stcb) && (((stcb->asoc.state & SCTP_STATE_MASK) == SCTP_STATE_COOKIE_WAIT) ||
3532c105859eSRandall Stewart 		    ((stcb->asoc.state & SCTP_STATE_MASK) == SCTP_STATE_COOKIE_ECHOED))) {
3533ceaad40aSRandall Stewart 			sctp_notify_assoc_change(SCTP_CANT_STR_ASSOC, stcb, error, NULL, so_locked);
3534c105859eSRandall Stewart 		} else {
3535ceaad40aSRandall Stewart 			sctp_notify_assoc_change(SCTP_COMM_LOST, stcb, error, NULL, so_locked);
3536c105859eSRandall Stewart 		}
3537f8829a4aSRandall Stewart 		break;
3538f8829a4aSRandall Stewart 	case SCTP_NOTIFY_PEER_OPENED_STREAM:
3539f8829a4aSRandall Stewart 		break;
3540f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STREAM_OPENED_OK:
3541f8829a4aSRandall Stewart 		break;
3542f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_RESTART:
3543ceaad40aSRandall Stewart 		sctp_notify_assoc_change(SCTP_RESTART, stcb, error, data, so_locked);
3544830d754dSRandall Stewart 		if (stcb->asoc.peer_supports_auth == 0) {
3545830d754dSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_NO_PEER_AUTH, stcb, 0,
3546830d754dSRandall Stewart 			    NULL, so_locked);
3547830d754dSRandall Stewart 		}
3548f8829a4aSRandall Stewart 		break;
3549f8829a4aSRandall Stewart 	case SCTP_NOTIFY_HB_RESP:
3550f8829a4aSRandall Stewart 		break;
3551ea44232bSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_INSTREAM_ADD_OK:
3552ea44232bSRandall Stewart 		sctp_notify_stream_reset_add(stcb, error, SCTP_STRRESET_INBOUND_STR);
3553ea44232bSRandall Stewart 		break;
3554ea44232bSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_ADD_OK:
3555ea44232bSRandall Stewart 		sctp_notify_stream_reset_add(stcb, error, SCTP_STRRESET_OUTBOUND_STR);
3556ea44232bSRandall Stewart 		break;
3557ea44232bSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_ADD_FAIL:
3558ea44232bSRandall Stewart 		sctp_notify_stream_reset_add(stcb, error, (SCTP_STRRESET_FAILED | SCTP_STRRESET_OUTBOUND_STR));
3559ea44232bSRandall Stewart 		break;
3560ea44232bSRandall Stewart 
3561f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_SEND:
3562f8829a4aSRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data), SCTP_STRRESET_OUTBOUND_STR);
3563f8829a4aSRandall Stewart 		break;
3564f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_RECV:
3565f8829a4aSRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data), SCTP_STRRESET_INBOUND_STR);
3566f8829a4aSRandall Stewart 		break;
3567f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_FAILED_OUT:
3568671d309cSRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data), (SCTP_STRRESET_OUTBOUND_STR | SCTP_STRRESET_FAILED));
3569f8829a4aSRandall Stewart 		break;
3570f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_FAILED_IN:
3571671d309cSRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data), (SCTP_STRRESET_INBOUND_STR | SCTP_STRRESET_FAILED));
3572f8829a4aSRandall Stewart 		break;
3573f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_ADD_IP:
3574f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_ADDED, data,
3575f8829a4aSRandall Stewart 		    error);
3576f8829a4aSRandall Stewart 		break;
3577f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_DELETE_IP:
3578f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_REMOVED, data,
3579f8829a4aSRandall Stewart 		    error);
3580f8829a4aSRandall Stewart 		break;
3581f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_SET_PRIMARY:
3582f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_MADE_PRIM, data,
3583f8829a4aSRandall Stewart 		    error);
3584f8829a4aSRandall Stewart 		break;
3585f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_SUCCESS:
3586f8829a4aSRandall Stewart 		break;
3587f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_FAILED:
3588f8829a4aSRandall Stewart 		break;
3589f8829a4aSRandall Stewart 	case SCTP_NOTIFY_PEER_SHUTDOWN:
3590f8829a4aSRandall Stewart 		sctp_notify_shutdown_event(stcb);
3591f8829a4aSRandall Stewart 		break;
3592f8829a4aSRandall Stewart 	case SCTP_NOTIFY_AUTH_NEW_KEY:
3593f8829a4aSRandall Stewart 		sctp_notify_authentication(stcb, SCTP_AUTH_NEWKEY, error,
3594830d754dSRandall Stewart 		    (uint16_t) (uintptr_t) data,
3595830d754dSRandall Stewart 		    so_locked);
3596f8829a4aSRandall Stewart 		break;
3597830d754dSRandall Stewart 	case SCTP_NOTIFY_AUTH_FREE_KEY:
3598830d754dSRandall Stewart 		sctp_notify_authentication(stcb, SCTP_AUTH_FREE_KEY, error,
3599830d754dSRandall Stewart 		    (uint16_t) (uintptr_t) data,
3600830d754dSRandall Stewart 		    so_locked);
3601f8829a4aSRandall Stewart 		break;
3602830d754dSRandall Stewart 	case SCTP_NOTIFY_NO_PEER_AUTH:
3603830d754dSRandall Stewart 		sctp_notify_authentication(stcb, SCTP_AUTH_NO_AUTH, error,
3604830d754dSRandall Stewart 		    (uint16_t) (uintptr_t) data,
3605830d754dSRandall Stewart 		    so_locked);
3606830d754dSRandall Stewart 		break;
3607830d754dSRandall Stewart 	case SCTP_NOTIFY_SENDER_DRY:
3608830d754dSRandall Stewart 		sctp_notify_sender_dry_event(stcb, so_locked);
3609830d754dSRandall Stewart 		break;
3610f8829a4aSRandall Stewart 	default:
3611ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_UTIL1, "%s: unknown notification %xh (%u)\n",
3612ad81507eSRandall Stewart 		    __FUNCTION__, notification, notification);
3613f8829a4aSRandall Stewart 		break;
3614f8829a4aSRandall Stewart 	}			/* end switch */
3615f8829a4aSRandall Stewart }
3616f8829a4aSRandall Stewart 
3617f8829a4aSRandall Stewart void
3618ceaad40aSRandall Stewart sctp_report_all_outbound(struct sctp_tcb *stcb, int holds_lock, int so_locked
3619ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3620ceaad40aSRandall Stewart     SCTP_UNUSED
3621ceaad40aSRandall Stewart #endif
3622ceaad40aSRandall Stewart )
3623f8829a4aSRandall Stewart {
3624f8829a4aSRandall Stewart 	struct sctp_association *asoc;
3625f8829a4aSRandall Stewart 	struct sctp_stream_out *outs;
36264a9ef3f8SMichael Tuexen 	struct sctp_tmit_chunk *chk, *nchk;
36274a9ef3f8SMichael Tuexen 	struct sctp_stream_queue_pending *sp, *nsp;
36287f34832bSRandall Stewart 	int i;
3629f8829a4aSRandall Stewart 
3630ad81507eSRandall Stewart 	if (stcb == NULL) {
3631ad81507eSRandall Stewart 		return;
3632ad81507eSRandall Stewart 	}
36334a9ef3f8SMichael Tuexen 	asoc = &stcb->asoc;
36344a9ef3f8SMichael Tuexen 	if (asoc->state & SCTP_STATE_ABOUT_TO_BE_FREED) {
3635478fbccbSRandall Stewart 		/* already being freed */
3636478fbccbSRandall Stewart 		return;
3637478fbccbSRandall Stewart 	}
3638f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
3639f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
36404a9ef3f8SMichael Tuexen 	    (asoc->state & SCTP_STATE_CLOSED_SOCKET)) {
3641f8829a4aSRandall Stewart 		return;
3642f8829a4aSRandall Stewart 	}
3643f8829a4aSRandall Stewart 	/* now through all the gunk freeing chunks */
3644ad81507eSRandall Stewart 	if (holds_lock == 0) {
36457f34832bSRandall Stewart 		SCTP_TCB_SEND_LOCK(stcb);
3646ad81507eSRandall Stewart 	}
3647d00aff5dSRandall Stewart 	/* sent queue SHOULD be empty */
36484a9ef3f8SMichael Tuexen 	TAILQ_FOREACH_SAFE(chk, &asoc->sent_queue, sctp_next, nchk) {
3649d00aff5dSRandall Stewart 		TAILQ_REMOVE(&asoc->sent_queue, chk, sctp_next);
3650d00aff5dSRandall Stewart 		asoc->sent_queue_cnt--;
36510c0982b8SRandall Stewart 		if (chk->data != NULL) {
3652d00aff5dSRandall Stewart 			sctp_free_bufspace(stcb, asoc, chk, 1);
3653d00aff5dSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_DG_FAIL, stcb,
3654ceaad40aSRandall Stewart 			    SCTP_NOTIFY_DATAGRAM_SENT, chk, so_locked);
3655810ec536SMichael Tuexen 			if (chk->data) {
3656d00aff5dSRandall Stewart 				sctp_m_freem(chk->data);
3657d00aff5dSRandall Stewart 				chk->data = NULL;
3658d00aff5dSRandall Stewart 			}
3659810ec536SMichael Tuexen 		}
3660689e6a5fSMichael Tuexen 		sctp_free_a_chunk(stcb, chk, so_locked);
3661d00aff5dSRandall Stewart 		/* sa_ignore FREED_MEMORY */
3662d00aff5dSRandall Stewart 	}
3663d00aff5dSRandall Stewart 	/* pending send queue SHOULD be empty */
36644a9ef3f8SMichael Tuexen 	TAILQ_FOREACH_SAFE(chk, &asoc->send_queue, sctp_next, nchk) {
3665d00aff5dSRandall Stewart 		TAILQ_REMOVE(&asoc->send_queue, chk, sctp_next);
3666d00aff5dSRandall Stewart 		asoc->send_queue_cnt--;
36670c0982b8SRandall Stewart 		if (chk->data != NULL) {
3668d00aff5dSRandall Stewart 			sctp_free_bufspace(stcb, asoc, chk, 1);
36690c0982b8SRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_DG_FAIL, stcb,
36700c0982b8SRandall Stewart 			    SCTP_NOTIFY_DATAGRAM_UNSENT, chk, so_locked);
3671810ec536SMichael Tuexen 			if (chk->data) {
3672d00aff5dSRandall Stewart 				sctp_m_freem(chk->data);
3673d00aff5dSRandall Stewart 				chk->data = NULL;
3674d00aff5dSRandall Stewart 			}
3675810ec536SMichael Tuexen 		}
3676689e6a5fSMichael Tuexen 		sctp_free_a_chunk(stcb, chk, so_locked);
3677d00aff5dSRandall Stewart 		/* sa_ignore FREED_MEMORY */
3678d00aff5dSRandall Stewart 	}
36794a9ef3f8SMichael Tuexen 	for (i = 0; i < asoc->streamoutcnt; i++) {
36807f34832bSRandall Stewart 		/* For each stream */
36814a9ef3f8SMichael Tuexen 		outs = &asoc->strmout[i];
36827f34832bSRandall Stewart 		/* clean up any sends there */
36834a9ef3f8SMichael Tuexen 		asoc->locked_on_sending = NULL;
36844a9ef3f8SMichael Tuexen 		TAILQ_FOREACH_SAFE(sp, &outs->outqueue, next, nsp) {
36854a9ef3f8SMichael Tuexen 			asoc->stream_queue_cnt--;
3686f8829a4aSRandall Stewart 			TAILQ_REMOVE(&outs->outqueue, sp, next);
3687f8829a4aSRandall Stewart 			sctp_free_spbufspace(stcb, asoc, sp);
3688478fbccbSRandall Stewart 			if (sp->data) {
3689f8829a4aSRandall Stewart 				sctp_ulp_notify(SCTP_NOTIFY_SPECIAL_SP_FAIL, stcb,
3690ceaad40aSRandall Stewart 				    SCTP_NOTIFY_DATAGRAM_UNSENT, (void *)sp, so_locked);
3691f8829a4aSRandall Stewart 				if (sp->data) {
3692f8829a4aSRandall Stewart 					sctp_m_freem(sp->data);
3693f8829a4aSRandall Stewart 					sp->data = NULL;
3694f8829a4aSRandall Stewart 				}
3695478fbccbSRandall Stewart 			}
36969eea4a2dSMichael Tuexen 			if (sp->net) {
3697f8829a4aSRandall Stewart 				sctp_free_remote_addr(sp->net);
3698f8829a4aSRandall Stewart 				sp->net = NULL;
36999eea4a2dSMichael Tuexen 			}
3700f8829a4aSRandall Stewart 			/* Free the chunk */
3701689e6a5fSMichael Tuexen 			sctp_free_a_strmoq(stcb, sp, so_locked);
37023c503c28SRandall Stewart 			/* sa_ignore FREED_MEMORY */
3703f8829a4aSRandall Stewart 		}
3704f8829a4aSRandall Stewart 	}
3705f8829a4aSRandall Stewart 
3706ad81507eSRandall Stewart 	if (holds_lock == 0) {
37077f34832bSRandall Stewart 		SCTP_TCB_SEND_UNLOCK(stcb);
3708f8829a4aSRandall Stewart 	}
3709ad81507eSRandall Stewart }
3710f8829a4aSRandall Stewart 
3711f8829a4aSRandall Stewart void
3712ceaad40aSRandall Stewart sctp_abort_notification(struct sctp_tcb *stcb, int error, int so_locked
3713ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3714ceaad40aSRandall Stewart     SCTP_UNUSED
3715ceaad40aSRandall Stewart #endif
3716ceaad40aSRandall Stewart )
3717f8829a4aSRandall Stewart {
3718f8829a4aSRandall Stewart 
3719ad81507eSRandall Stewart 	if (stcb == NULL) {
3720ad81507eSRandall Stewart 		return;
3721ad81507eSRandall Stewart 	}
3722f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
3723f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
3724f8829a4aSRandall Stewart 	    (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET)) {
3725f8829a4aSRandall Stewart 		return;
3726f8829a4aSRandall Stewart 	}
3727f8829a4aSRandall Stewart 	/* Tell them we lost the asoc */
3728ceaad40aSRandall Stewart 	sctp_report_all_outbound(stcb, 1, so_locked);
3729f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL) ||
3730f8829a4aSRandall Stewart 	    ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) &&
3731f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_CONNECTED))) {
3732f8829a4aSRandall Stewart 		stcb->sctp_ep->sctp_flags |= SCTP_PCB_FLAGS_WAS_ABORTED;
3733f8829a4aSRandall Stewart 	}
3734ceaad40aSRandall Stewart 	sctp_ulp_notify(SCTP_NOTIFY_ASSOC_ABORTED, stcb, error, NULL, so_locked);
3735f8829a4aSRandall Stewart }
3736f8829a4aSRandall Stewart 
3737f8829a4aSRandall Stewart void
3738f8829a4aSRandall Stewart sctp_abort_association(struct sctp_inpcb *inp, struct sctp_tcb *stcb,
373917205eccSRandall Stewart     struct mbuf *m, int iphlen, struct sctphdr *sh, struct mbuf *op_err,
3740c54a18d2SRandall Stewart     uint32_t vrf_id, uint16_t port)
3741f8829a4aSRandall Stewart {
3742f8829a4aSRandall Stewart 	uint32_t vtag;
3743f8829a4aSRandall Stewart 
3744ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3745ceaad40aSRandall Stewart 	struct socket *so;
3746ceaad40aSRandall Stewart 
3747ceaad40aSRandall Stewart #endif
3748ceaad40aSRandall Stewart 
3749f8829a4aSRandall Stewart 	vtag = 0;
3750f8829a4aSRandall Stewart 	if (stcb != NULL) {
3751f8829a4aSRandall Stewart 		/* We have a TCB to abort, send notification too */
3752f8829a4aSRandall Stewart 		vtag = stcb->asoc.peer_vtag;
3753ceaad40aSRandall Stewart 		sctp_abort_notification(stcb, 0, SCTP_SO_NOT_LOCKED);
375417205eccSRandall Stewart 		/* get the assoc vrf id and table id */
375517205eccSRandall Stewart 		vrf_id = stcb->asoc.vrf_id;
375663981c2bSRandall Stewart 		stcb->asoc.state |= SCTP_STATE_WAS_ABORTED;
3757f8829a4aSRandall Stewart 	}
3758c54a18d2SRandall Stewart 	sctp_send_abort(m, iphlen, sh, vtag, op_err, vrf_id, port);
3759f8829a4aSRandall Stewart 	if (stcb != NULL) {
3760f8829a4aSRandall Stewart 		/* Ok, now lets free it */
3761ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3762ceaad40aSRandall Stewart 		so = SCTP_INP_SO(inp);
3763ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
3764ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
3765ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
3766ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
3767ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
3768ceaad40aSRandall Stewart #endif
37690271d0cdSMichael Tuexen 		SCTP_STAT_INCR_COUNTER32(sctps_aborted);
37700271d0cdSMichael Tuexen 		if ((SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_OPEN) ||
37710271d0cdSMichael Tuexen 		    (SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_SHUTDOWN_RECEIVED)) {
37720271d0cdSMichael Tuexen 			SCTP_STAT_DECR_GAUGE32(sctps_currestab);
37730271d0cdSMichael Tuexen 		}
3774c4739e2fSRandall Stewart 		(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC, SCTP_FROM_SCTPUTIL + SCTP_LOC_4);
3775ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3776ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
3777ceaad40aSRandall Stewart #endif
3778f8829a4aSRandall Stewart 	}
3779f8829a4aSRandall Stewart }
3780f8829a4aSRandall Stewart 
3781f1f73e57SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
3782f1f73e57SRandall Stewart void
3783f1f73e57SRandall Stewart sctp_print_out_track_log(struct sctp_tcb *stcb)
3784f1f73e57SRandall Stewart {
378518e198d3SRandall Stewart #ifdef NOSIY_PRINTS
3786f1f73e57SRandall Stewart 	int i;
3787f1f73e57SRandall Stewart 
3788ad81507eSRandall Stewart 	SCTP_PRINTF("Last ep reason:%x\n", stcb->sctp_ep->last_abort_code);
3789ad81507eSRandall Stewart 	SCTP_PRINTF("IN bound TSN log-aaa\n");
3790f1f73e57SRandall Stewart 	if ((stcb->asoc.tsn_in_at == 0) && (stcb->asoc.tsn_in_wrapped == 0)) {
3791ad81507eSRandall Stewart 		SCTP_PRINTF("None rcvd\n");
3792f1f73e57SRandall Stewart 		goto none_in;
3793f1f73e57SRandall Stewart 	}
3794f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_in_wrapped) {
3795f1f73e57SRandall Stewart 		for (i = stcb->asoc.tsn_in_at; i < SCTP_TSN_LOG_SIZE; i++) {
3796ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
3797f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].tsn,
3798f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].strm,
3799f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].seq,
3800f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].flgs,
3801f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].sz);
3802f1f73e57SRandall Stewart 		}
3803f1f73e57SRandall Stewart 	}
3804f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_in_at) {
3805f1f73e57SRandall Stewart 		for (i = 0; i < stcb->asoc.tsn_in_at; i++) {
3806ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
3807f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].tsn,
3808f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].strm,
3809f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].seq,
3810f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].flgs,
3811f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].sz);
3812f1f73e57SRandall Stewart 		}
3813f1f73e57SRandall Stewart 	}
3814f1f73e57SRandall Stewart none_in:
3815ad81507eSRandall Stewart 	SCTP_PRINTF("OUT bound TSN log-aaa\n");
3816ad81507eSRandall Stewart 	if ((stcb->asoc.tsn_out_at == 0) &&
3817ad81507eSRandall Stewart 	    (stcb->asoc.tsn_out_wrapped == 0)) {
3818ad81507eSRandall Stewart 		SCTP_PRINTF("None sent\n");
3819f1f73e57SRandall Stewart 	}
3820f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_out_wrapped) {
3821f1f73e57SRandall Stewart 		for (i = stcb->asoc.tsn_out_at; i < SCTP_TSN_LOG_SIZE; i++) {
3822ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
3823f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].tsn,
3824f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].strm,
3825f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].seq,
3826f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].flgs,
3827f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].sz);
3828f1f73e57SRandall Stewart 		}
3829f1f73e57SRandall Stewart 	}
3830f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_out_at) {
3831f1f73e57SRandall Stewart 		for (i = 0; i < stcb->asoc.tsn_out_at; i++) {
3832ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
3833f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].tsn,
3834f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].strm,
3835f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].seq,
3836f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].flgs,
3837f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].sz);
3838f1f73e57SRandall Stewart 		}
3839f1f73e57SRandall Stewart 	}
384018e198d3SRandall Stewart #endif
3841f1f73e57SRandall Stewart }
3842f1f73e57SRandall Stewart 
3843f1f73e57SRandall Stewart #endif
3844f1f73e57SRandall Stewart 
3845f8829a4aSRandall Stewart void
3846f8829a4aSRandall Stewart sctp_abort_an_association(struct sctp_inpcb *inp, struct sctp_tcb *stcb,
3847ceaad40aSRandall Stewart     int error, struct mbuf *op_err,
3848ceaad40aSRandall Stewart     int so_locked
3849ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3850ceaad40aSRandall Stewart     SCTP_UNUSED
3851ceaad40aSRandall Stewart #endif
3852ceaad40aSRandall Stewart )
3853f8829a4aSRandall Stewart {
3854ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3855ceaad40aSRandall Stewart 	struct socket *so;
3856ceaad40aSRandall Stewart 
3857ceaad40aSRandall Stewart #endif
3858ceaad40aSRandall Stewart 
3859ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3860ceaad40aSRandall Stewart 	so = SCTP_INP_SO(inp);
3861ceaad40aSRandall Stewart #endif
3862f8829a4aSRandall Stewart 	if (stcb == NULL) {
3863f8829a4aSRandall Stewart 		/* Got to have a TCB */
3864f8829a4aSRandall Stewart 		if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
3865f8829a4aSRandall Stewart 			if (LIST_FIRST(&inp->sctp_asoc_list) == NULL) {
3866b0552ae2SRandall Stewart 				sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
3867b0552ae2SRandall Stewart 				    SCTP_CALLED_DIRECTLY_NOCMPSET);
3868f8829a4aSRandall Stewart 			}
3869f8829a4aSRandall Stewart 		}
3870f8829a4aSRandall Stewart 		return;
387163981c2bSRandall Stewart 	} else {
387263981c2bSRandall Stewart 		stcb->asoc.state |= SCTP_STATE_WAS_ABORTED;
3873f8829a4aSRandall Stewart 	}
3874f8829a4aSRandall Stewart 	/* notify the ulp */
3875f8829a4aSRandall Stewart 	if ((inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) == 0)
3876ceaad40aSRandall Stewart 		sctp_abort_notification(stcb, error, so_locked);
3877f8829a4aSRandall Stewart 	/* notify the peer */
3878b201f536SRandall Stewart #if defined(SCTP_PANIC_ON_ABORT)
3879b201f536SRandall Stewart 	panic("aborting an association");
3880b201f536SRandall Stewart #endif
3881ceaad40aSRandall Stewart 	sctp_send_abort_tcb(stcb, op_err, so_locked);
3882f8829a4aSRandall Stewart 	SCTP_STAT_INCR_COUNTER32(sctps_aborted);
3883f8829a4aSRandall Stewart 	if ((SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_OPEN) ||
3884f8829a4aSRandall Stewart 	    (SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_SHUTDOWN_RECEIVED)) {
3885f8829a4aSRandall Stewart 		SCTP_STAT_DECR_GAUGE32(sctps_currestab);
3886f8829a4aSRandall Stewart 	}
3887f8829a4aSRandall Stewart 	/* now free the asoc */
3888f1f73e57SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
3889f1f73e57SRandall Stewart 	sctp_print_out_track_log(stcb);
3890f1f73e57SRandall Stewart #endif
3891ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3892ceaad40aSRandall Stewart 	if (!so_locked) {
3893ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
3894ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
3895ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
3896ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
3897ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
3898ceaad40aSRandall Stewart 	}
3899ceaad40aSRandall Stewart #endif
3900c4739e2fSRandall Stewart 	(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC, SCTP_FROM_SCTPUTIL + SCTP_LOC_5);
3901ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3902ceaad40aSRandall Stewart 	if (!so_locked) {
3903ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
3904ceaad40aSRandall Stewart 	}
3905ceaad40aSRandall Stewart #endif
3906f8829a4aSRandall Stewart }
3907f8829a4aSRandall Stewart 
3908f8829a4aSRandall Stewart void
3909f8829a4aSRandall Stewart sctp_handle_ootb(struct mbuf *m, int iphlen, int offset, struct sctphdr *sh,
3910c54a18d2SRandall Stewart     struct sctp_inpcb *inp, struct mbuf *op_err, uint32_t vrf_id, uint16_t port)
3911f8829a4aSRandall Stewart {
3912f8829a4aSRandall Stewart 	struct sctp_chunkhdr *ch, chunk_buf;
3913f8829a4aSRandall Stewart 	unsigned int chk_length;
3914f8829a4aSRandall Stewart 
3915f8829a4aSRandall Stewart 	SCTP_STAT_INCR_COUNTER32(sctps_outoftheblue);
3916f8829a4aSRandall Stewart 	/* Generate a TO address for future reference */
3917f8829a4aSRandall Stewart 	if (inp && (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE)) {
3918f8829a4aSRandall Stewart 		if (LIST_FIRST(&inp->sctp_asoc_list) == NULL) {
3919b0552ae2SRandall Stewart 			sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
3920b0552ae2SRandall Stewart 			    SCTP_CALLED_DIRECTLY_NOCMPSET);
3921f8829a4aSRandall Stewart 		}
3922f8829a4aSRandall Stewart 	}
3923f8829a4aSRandall Stewart 	ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
3924f8829a4aSRandall Stewart 	    sizeof(*ch), (uint8_t *) & chunk_buf);
3925f8829a4aSRandall Stewart 	while (ch != NULL) {
3926f8829a4aSRandall Stewart 		chk_length = ntohs(ch->chunk_length);
3927f8829a4aSRandall Stewart 		if (chk_length < sizeof(*ch)) {
3928f8829a4aSRandall Stewart 			/* break to abort land */
3929f8829a4aSRandall Stewart 			break;
3930f8829a4aSRandall Stewart 		}
3931f8829a4aSRandall Stewart 		switch (ch->chunk_type) {
3932d55b0b1bSRandall Stewart 		case SCTP_COOKIE_ECHO:
3933d55b0b1bSRandall Stewart 			/* We hit here only if the assoc is being freed */
3934d55b0b1bSRandall Stewart 			return;
3935f8829a4aSRandall Stewart 		case SCTP_PACKET_DROPPED:
3936f8829a4aSRandall Stewart 			/* we don't respond to pkt-dropped */
3937f8829a4aSRandall Stewart 			return;
3938f8829a4aSRandall Stewart 		case SCTP_ABORT_ASSOCIATION:
3939f8829a4aSRandall Stewart 			/* we don't respond with an ABORT to an ABORT */
3940f8829a4aSRandall Stewart 			return;
3941f8829a4aSRandall Stewart 		case SCTP_SHUTDOWN_COMPLETE:
3942f8829a4aSRandall Stewart 			/*
3943f8829a4aSRandall Stewart 			 * we ignore it since we are not waiting for it and
3944f8829a4aSRandall Stewart 			 * peer is gone
3945f8829a4aSRandall Stewart 			 */
3946f8829a4aSRandall Stewart 			return;
3947f8829a4aSRandall Stewart 		case SCTP_SHUTDOWN_ACK:
3948c54a18d2SRandall Stewart 			sctp_send_shutdown_complete2(m, iphlen, sh, vrf_id, port);
3949f8829a4aSRandall Stewart 			return;
3950f8829a4aSRandall Stewart 		default:
3951f8829a4aSRandall Stewart 			break;
3952f8829a4aSRandall Stewart 		}
3953f8829a4aSRandall Stewart 		offset += SCTP_SIZE32(chk_length);
3954f8829a4aSRandall Stewart 		ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
3955f8829a4aSRandall Stewart 		    sizeof(*ch), (uint8_t *) & chunk_buf);
3956f8829a4aSRandall Stewart 	}
3957c54a18d2SRandall Stewart 	sctp_send_abort(m, iphlen, sh, 0, op_err, vrf_id, port);
3958f8829a4aSRandall Stewart }
3959f8829a4aSRandall Stewart 
3960f8829a4aSRandall Stewart /*
3961f8829a4aSRandall Stewart  * check the inbound datagram to make sure there is not an abort inside it,
3962f8829a4aSRandall Stewart  * if there is return 1, else return 0.
3963f8829a4aSRandall Stewart  */
3964f8829a4aSRandall Stewart int
3965f8829a4aSRandall Stewart sctp_is_there_an_abort_here(struct mbuf *m, int iphlen, uint32_t * vtagfill)
3966f8829a4aSRandall Stewart {
3967f8829a4aSRandall Stewart 	struct sctp_chunkhdr *ch;
3968f8829a4aSRandall Stewart 	struct sctp_init_chunk *init_chk, chunk_buf;
3969f8829a4aSRandall Stewart 	int offset;
3970f8829a4aSRandall Stewart 	unsigned int chk_length;
3971f8829a4aSRandall Stewart 
3972f8829a4aSRandall Stewart 	offset = iphlen + sizeof(struct sctphdr);
3973f8829a4aSRandall Stewart 	ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset, sizeof(*ch),
3974f8829a4aSRandall Stewart 	    (uint8_t *) & chunk_buf);
3975f8829a4aSRandall Stewart 	while (ch != NULL) {
3976f8829a4aSRandall Stewart 		chk_length = ntohs(ch->chunk_length);
3977f8829a4aSRandall Stewart 		if (chk_length < sizeof(*ch)) {
3978f8829a4aSRandall Stewart 			/* packet is probably corrupt */
3979f8829a4aSRandall Stewart 			break;
3980f8829a4aSRandall Stewart 		}
3981f8829a4aSRandall Stewart 		/* we seem to be ok, is it an abort? */
3982f8829a4aSRandall Stewart 		if (ch->chunk_type == SCTP_ABORT_ASSOCIATION) {
3983f8829a4aSRandall Stewart 			/* yep, tell them */
3984f8829a4aSRandall Stewart 			return (1);
3985f8829a4aSRandall Stewart 		}
3986f8829a4aSRandall Stewart 		if (ch->chunk_type == SCTP_INITIATION) {
3987f8829a4aSRandall Stewart 			/* need to update the Vtag */
3988f8829a4aSRandall Stewart 			init_chk = (struct sctp_init_chunk *)sctp_m_getptr(m,
3989f8829a4aSRandall Stewart 			    offset, sizeof(*init_chk), (uint8_t *) & chunk_buf);
3990f8829a4aSRandall Stewart 			if (init_chk != NULL) {
3991f8829a4aSRandall Stewart 				*vtagfill = ntohl(init_chk->init.initiate_tag);
3992f8829a4aSRandall Stewart 			}
3993f8829a4aSRandall Stewart 		}
3994f8829a4aSRandall Stewart 		/* Nope, move to the next chunk */
3995f8829a4aSRandall Stewart 		offset += SCTP_SIZE32(chk_length);
3996f8829a4aSRandall Stewart 		ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
3997f8829a4aSRandall Stewart 		    sizeof(*ch), (uint8_t *) & chunk_buf);
3998f8829a4aSRandall Stewart 	}
3999f8829a4aSRandall Stewart 	return (0);
4000f8829a4aSRandall Stewart }
4001f8829a4aSRandall Stewart 
4002f8829a4aSRandall Stewart /*
4003f8829a4aSRandall Stewart  * currently (2/02), ifa_addr embeds scope_id's and don't have sin6_scope_id
4004f8829a4aSRandall Stewart  * set (i.e. it's 0) so, create this function to compare link local scopes
4005f8829a4aSRandall Stewart  */
40065e2c2d87SRandall Stewart #ifdef INET6
4007f8829a4aSRandall Stewart uint32_t
4008f8829a4aSRandall Stewart sctp_is_same_scope(struct sockaddr_in6 *addr1, struct sockaddr_in6 *addr2)
4009f8829a4aSRandall Stewart {
4010f8829a4aSRandall Stewart 	struct sockaddr_in6 a, b;
4011f8829a4aSRandall Stewart 
4012f8829a4aSRandall Stewart 	/* save copies */
4013f8829a4aSRandall Stewart 	a = *addr1;
4014f8829a4aSRandall Stewart 	b = *addr2;
4015f8829a4aSRandall Stewart 
4016f8829a4aSRandall Stewart 	if (a.sin6_scope_id == 0)
4017f8829a4aSRandall Stewart 		if (sa6_recoverscope(&a)) {
4018f8829a4aSRandall Stewart 			/* can't get scope, so can't match */
4019f8829a4aSRandall Stewart 			return (0);
4020f8829a4aSRandall Stewart 		}
4021f8829a4aSRandall Stewart 	if (b.sin6_scope_id == 0)
4022f8829a4aSRandall Stewart 		if (sa6_recoverscope(&b)) {
4023f8829a4aSRandall Stewart 			/* can't get scope, so can't match */
4024f8829a4aSRandall Stewart 			return (0);
4025f8829a4aSRandall Stewart 		}
4026f8829a4aSRandall Stewart 	if (a.sin6_scope_id != b.sin6_scope_id)
4027f8829a4aSRandall Stewart 		return (0);
4028f8829a4aSRandall Stewart 
4029f8829a4aSRandall Stewart 	return (1);
4030f8829a4aSRandall Stewart }
4031f8829a4aSRandall Stewart 
4032f8829a4aSRandall Stewart /*
4033f8829a4aSRandall Stewart  * returns a sockaddr_in6 with embedded scope recovered and removed
4034f8829a4aSRandall Stewart  */
4035f8829a4aSRandall Stewart struct sockaddr_in6 *
4036f8829a4aSRandall Stewart sctp_recover_scope(struct sockaddr_in6 *addr, struct sockaddr_in6 *store)
4037f8829a4aSRandall Stewart {
4038f8829a4aSRandall Stewart 	/* check and strip embedded scope junk */
4039f8829a4aSRandall Stewart 	if (addr->sin6_family == AF_INET6) {
4040f8829a4aSRandall Stewart 		if (IN6_IS_SCOPE_LINKLOCAL(&addr->sin6_addr)) {
4041f8829a4aSRandall Stewart 			if (addr->sin6_scope_id == 0) {
4042f8829a4aSRandall Stewart 				*store = *addr;
4043f8829a4aSRandall Stewart 				if (!sa6_recoverscope(store)) {
4044f8829a4aSRandall Stewart 					/* use the recovered scope */
4045f8829a4aSRandall Stewart 					addr = store;
4046f8829a4aSRandall Stewart 				}
4047f42a358aSRandall Stewart 			} else {
4048f8829a4aSRandall Stewart 				/* else, return the original "to" addr */
4049f42a358aSRandall Stewart 				in6_clearscope(&addr->sin6_addr);
4050f8829a4aSRandall Stewart 			}
4051f8829a4aSRandall Stewart 		}
4052f8829a4aSRandall Stewart 	}
4053f8829a4aSRandall Stewart 	return (addr);
4054f8829a4aSRandall Stewart }
4055f8829a4aSRandall Stewart 
40565e2c2d87SRandall Stewart #endif
40575e2c2d87SRandall Stewart 
4058f8829a4aSRandall Stewart /*
4059f8829a4aSRandall Stewart  * are the two addresses the same?  currently a "scopeless" check returns: 1
4060f8829a4aSRandall Stewart  * if same, 0 if not
4061f8829a4aSRandall Stewart  */
406272fb6fdbSRandall Stewart int
4063f8829a4aSRandall Stewart sctp_cmpaddr(struct sockaddr *sa1, struct sockaddr *sa2)
4064f8829a4aSRandall Stewart {
4065f8829a4aSRandall Stewart 
4066f8829a4aSRandall Stewart 	/* must be valid */
4067f8829a4aSRandall Stewart 	if (sa1 == NULL || sa2 == NULL)
4068f8829a4aSRandall Stewart 		return (0);
4069f8829a4aSRandall Stewart 
4070f8829a4aSRandall Stewart 	/* must be the same family */
4071f8829a4aSRandall Stewart 	if (sa1->sa_family != sa2->sa_family)
4072f8829a4aSRandall Stewart 		return (0);
4073f8829a4aSRandall Stewart 
40745e2c2d87SRandall Stewart 	switch (sa1->sa_family) {
40755e2c2d87SRandall Stewart #ifdef INET6
40765e2c2d87SRandall Stewart 	case AF_INET6:
40775e2c2d87SRandall Stewart 		{
4078f8829a4aSRandall Stewart 			/* IPv6 addresses */
4079f8829a4aSRandall Stewart 			struct sockaddr_in6 *sin6_1, *sin6_2;
4080f8829a4aSRandall Stewart 
4081f8829a4aSRandall Stewart 			sin6_1 = (struct sockaddr_in6 *)sa1;
4082f8829a4aSRandall Stewart 			sin6_2 = (struct sockaddr_in6 *)sa2;
4083c54a18d2SRandall Stewart 			return (SCTP6_ARE_ADDR_EQUAL(sin6_1,
4084c54a18d2SRandall Stewart 			    sin6_2));
40855e2c2d87SRandall Stewart 		}
40865e2c2d87SRandall Stewart #endif
4087ea5eba11SMichael Tuexen #ifdef INET
40885e2c2d87SRandall Stewart 	case AF_INET:
40895e2c2d87SRandall Stewart 		{
4090f8829a4aSRandall Stewart 			/* IPv4 addresses */
4091f8829a4aSRandall Stewart 			struct sockaddr_in *sin_1, *sin_2;
4092f8829a4aSRandall Stewart 
4093f8829a4aSRandall Stewart 			sin_1 = (struct sockaddr_in *)sa1;
4094f8829a4aSRandall Stewart 			sin_2 = (struct sockaddr_in *)sa2;
4095f8829a4aSRandall Stewart 			return (sin_1->sin_addr.s_addr == sin_2->sin_addr.s_addr);
40965e2c2d87SRandall Stewart 		}
4097ea5eba11SMichael Tuexen #endif
40985e2c2d87SRandall Stewart 	default:
4099f8829a4aSRandall Stewart 		/* we don't do these... */
4100f8829a4aSRandall Stewart 		return (0);
4101f8829a4aSRandall Stewart 	}
4102f8829a4aSRandall Stewart }
4103f8829a4aSRandall Stewart 
4104f8829a4aSRandall Stewart void
4105f8829a4aSRandall Stewart sctp_print_address(struct sockaddr *sa)
4106f8829a4aSRandall Stewart {
41075e2c2d87SRandall Stewart #ifdef INET6
41087d32aa0cSBjoern A. Zeeb 	char ip6buf[INET6_ADDRSTRLEN];
4109f8829a4aSRandall Stewart 
4110ad81507eSRandall Stewart 	ip6buf[0] = 0;
41115e2c2d87SRandall Stewart #endif
41125e2c2d87SRandall Stewart 
41135e2c2d87SRandall Stewart 	switch (sa->sa_family) {
41145e2c2d87SRandall Stewart #ifdef INET6
41155e2c2d87SRandall Stewart 	case AF_INET6:
41165e2c2d87SRandall Stewart 		{
4117ad81507eSRandall Stewart 			struct sockaddr_in6 *sin6;
4118ad81507eSRandall Stewart 
4119f8829a4aSRandall Stewart 			sin6 = (struct sockaddr_in6 *)sa;
4120ad81507eSRandall Stewart 			SCTP_PRINTF("IPv6 address: %s:port:%d scope:%u\n",
41217d32aa0cSBjoern A. Zeeb 			    ip6_sprintf(ip6buf, &sin6->sin6_addr),
41227d32aa0cSBjoern A. Zeeb 			    ntohs(sin6->sin6_port),
4123f8829a4aSRandall Stewart 			    sin6->sin6_scope_id);
41245e2c2d87SRandall Stewart 			break;
41255e2c2d87SRandall Stewart 		}
41265e2c2d87SRandall Stewart #endif
4127ea5eba11SMichael Tuexen #ifdef INET
41285e2c2d87SRandall Stewart 	case AF_INET:
41295e2c2d87SRandall Stewart 		{
4130f8829a4aSRandall Stewart 			struct sockaddr_in *sin;
4131f8829a4aSRandall Stewart 			unsigned char *p;
4132f8829a4aSRandall Stewart 
4133f8829a4aSRandall Stewart 			sin = (struct sockaddr_in *)sa;
4134f8829a4aSRandall Stewart 			p = (unsigned char *)&sin->sin_addr;
4135ad81507eSRandall Stewart 			SCTP_PRINTF("IPv4 address: %u.%u.%u.%u:%d\n",
4136f8829a4aSRandall Stewart 			    p[0], p[1], p[2], p[3], ntohs(sin->sin_port));
41375e2c2d87SRandall Stewart 			break;
41385e2c2d87SRandall Stewart 		}
4139ea5eba11SMichael Tuexen #endif
41405e2c2d87SRandall Stewart 	default:
4141ad81507eSRandall Stewart 		SCTP_PRINTF("?\n");
41425e2c2d87SRandall Stewart 		break;
4143f8829a4aSRandall Stewart 	}
4144f8829a4aSRandall Stewart }
4145f8829a4aSRandall Stewart 
4146f8829a4aSRandall Stewart void
4147f8829a4aSRandall Stewart sctp_print_address_pkt(struct ip *iph, struct sctphdr *sh)
4148f8829a4aSRandall Stewart {
41495e2c2d87SRandall Stewart 	switch (iph->ip_v) {
4150ea5eba11SMichael Tuexen #ifdef INET
41515e2c2d87SRandall Stewart 	case IPVERSION:
41525e2c2d87SRandall Stewart 		{
4153f8829a4aSRandall Stewart 			struct sockaddr_in lsa, fsa;
4154f8829a4aSRandall Stewart 
4155f8829a4aSRandall Stewart 			bzero(&lsa, sizeof(lsa));
4156f8829a4aSRandall Stewart 			lsa.sin_len = sizeof(lsa);
4157f8829a4aSRandall Stewart 			lsa.sin_family = AF_INET;
4158f8829a4aSRandall Stewart 			lsa.sin_addr = iph->ip_src;
4159f8829a4aSRandall Stewart 			lsa.sin_port = sh->src_port;
4160f8829a4aSRandall Stewart 			bzero(&fsa, sizeof(fsa));
4161f8829a4aSRandall Stewart 			fsa.sin_len = sizeof(fsa);
4162f8829a4aSRandall Stewart 			fsa.sin_family = AF_INET;
4163f8829a4aSRandall Stewart 			fsa.sin_addr = iph->ip_dst;
4164f8829a4aSRandall Stewart 			fsa.sin_port = sh->dest_port;
4165ad81507eSRandall Stewart 			SCTP_PRINTF("src: ");
4166f8829a4aSRandall Stewart 			sctp_print_address((struct sockaddr *)&lsa);
4167ad81507eSRandall Stewart 			SCTP_PRINTF("dest: ");
4168f8829a4aSRandall Stewart 			sctp_print_address((struct sockaddr *)&fsa);
41695e2c2d87SRandall Stewart 			break;
41705e2c2d87SRandall Stewart 		}
4171ea5eba11SMichael Tuexen #endif
41725e2c2d87SRandall Stewart #ifdef INET6
41735e2c2d87SRandall Stewart 	case IPV6_VERSION >> 4:
41745e2c2d87SRandall Stewart 		{
4175f8829a4aSRandall Stewart 			struct ip6_hdr *ip6;
4176f8829a4aSRandall Stewart 			struct sockaddr_in6 lsa6, fsa6;
4177f8829a4aSRandall Stewart 
4178f8829a4aSRandall Stewart 			ip6 = (struct ip6_hdr *)iph;
4179f8829a4aSRandall Stewart 			bzero(&lsa6, sizeof(lsa6));
4180f8829a4aSRandall Stewart 			lsa6.sin6_len = sizeof(lsa6);
4181f8829a4aSRandall Stewart 			lsa6.sin6_family = AF_INET6;
4182f8829a4aSRandall Stewart 			lsa6.sin6_addr = ip6->ip6_src;
4183f8829a4aSRandall Stewart 			lsa6.sin6_port = sh->src_port;
4184f8829a4aSRandall Stewart 			bzero(&fsa6, sizeof(fsa6));
4185f8829a4aSRandall Stewart 			fsa6.sin6_len = sizeof(fsa6);
4186f8829a4aSRandall Stewart 			fsa6.sin6_family = AF_INET6;
4187f8829a4aSRandall Stewart 			fsa6.sin6_addr = ip6->ip6_dst;
4188f8829a4aSRandall Stewart 			fsa6.sin6_port = sh->dest_port;
4189ad81507eSRandall Stewart 			SCTP_PRINTF("src: ");
4190f8829a4aSRandall Stewart 			sctp_print_address((struct sockaddr *)&lsa6);
4191ad81507eSRandall Stewart 			SCTP_PRINTF("dest: ");
4192f8829a4aSRandall Stewart 			sctp_print_address((struct sockaddr *)&fsa6);
41935e2c2d87SRandall Stewart 			break;
41945e2c2d87SRandall Stewart 		}
41955e2c2d87SRandall Stewart #endif
41965e2c2d87SRandall Stewart 	default:
41975e2c2d87SRandall Stewart 		/* TSNH */
41985e2c2d87SRandall Stewart 		break;
4199f8829a4aSRandall Stewart 	}
4200f8829a4aSRandall Stewart }
4201f8829a4aSRandall Stewart 
4202f8829a4aSRandall Stewart void
4203f8829a4aSRandall Stewart sctp_pull_off_control_to_new_inp(struct sctp_inpcb *old_inp,
4204f8829a4aSRandall Stewart     struct sctp_inpcb *new_inp,
4205d06c82f1SRandall Stewart     struct sctp_tcb *stcb,
4206d06c82f1SRandall Stewart     int waitflags)
4207f8829a4aSRandall Stewart {
4208f8829a4aSRandall Stewart 	/*
4209f8829a4aSRandall Stewart 	 * go through our old INP and pull off any control structures that
4210f8829a4aSRandall Stewart 	 * belong to stcb and move then to the new inp.
4211f8829a4aSRandall Stewart 	 */
4212f8829a4aSRandall Stewart 	struct socket *old_so, *new_so;
4213f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control, *nctl;
4214f8829a4aSRandall Stewart 	struct sctp_readhead tmp_queue;
4215f8829a4aSRandall Stewart 	struct mbuf *m;
4216bff64a4dSRandall Stewart 	int error = 0;
4217f8829a4aSRandall Stewart 
4218f8829a4aSRandall Stewart 	old_so = old_inp->sctp_socket;
4219f8829a4aSRandall Stewart 	new_so = new_inp->sctp_socket;
4220f8829a4aSRandall Stewart 	TAILQ_INIT(&tmp_queue);
4221d06c82f1SRandall Stewart 	error = sblock(&old_so->so_rcv, waitflags);
4222f8829a4aSRandall Stewart 	if (error) {
4223f8829a4aSRandall Stewart 		/*
4224f8829a4aSRandall Stewart 		 * Gak, can't get sblock, we have a problem. data will be
4225f8829a4aSRandall Stewart 		 * left stranded.. and we don't dare look at it since the
4226f8829a4aSRandall Stewart 		 * other thread may be reading something. Oh well, its a
4227f8829a4aSRandall Stewart 		 * screwed up app that does a peeloff OR a accept while
4228f8829a4aSRandall Stewart 		 * reading from the main socket... actually its only the
4229f8829a4aSRandall Stewart 		 * peeloff() case, since I think read will fail on a
4230f8829a4aSRandall Stewart 		 * listening socket..
4231f8829a4aSRandall Stewart 		 */
4232f8829a4aSRandall Stewart 		return;
4233f8829a4aSRandall Stewart 	}
4234f8829a4aSRandall Stewart 	/* lock the socket buffers */
4235f8829a4aSRandall Stewart 	SCTP_INP_READ_LOCK(old_inp);
42364a9ef3f8SMichael Tuexen 	TAILQ_FOREACH_SAFE(control, &old_inp->read_queue, next, nctl) {
4237f8829a4aSRandall Stewart 		/* Pull off all for out target stcb */
4238f8829a4aSRandall Stewart 		if (control->stcb == stcb) {
4239f8829a4aSRandall Stewart 			/* remove it we want it */
4240f8829a4aSRandall Stewart 			TAILQ_REMOVE(&old_inp->read_queue, control, next);
4241f8829a4aSRandall Stewart 			TAILQ_INSERT_TAIL(&tmp_queue, control, next);
4242f8829a4aSRandall Stewart 			m = control->data;
4243f8829a4aSRandall Stewart 			while (m) {
4244b3f1ea41SRandall Stewart 				if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4245139bc87fSRandall Stewart 					sctp_sblog(&old_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
424680fefe0aSRandall Stewart 				}
4247f8829a4aSRandall Stewart 				sctp_sbfree(control, stcb, &old_so->so_rcv, m);
4248b3f1ea41SRandall Stewart 				if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4249f8829a4aSRandall Stewart 					sctp_sblog(&old_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
425080fefe0aSRandall Stewart 				}
4251139bc87fSRandall Stewart 				m = SCTP_BUF_NEXT(m);
4252f8829a4aSRandall Stewart 			}
4253f8829a4aSRandall Stewart 		}
4254f8829a4aSRandall Stewart 	}
4255f8829a4aSRandall Stewart 	SCTP_INP_READ_UNLOCK(old_inp);
4256f8829a4aSRandall Stewart 	/* Remove the sb-lock on the old socket */
4257f8829a4aSRandall Stewart 
4258f8829a4aSRandall Stewart 	sbunlock(&old_so->so_rcv);
4259f8829a4aSRandall Stewart 	/* Now we move them over to the new socket buffer */
4260f8829a4aSRandall Stewart 	SCTP_INP_READ_LOCK(new_inp);
42614a9ef3f8SMichael Tuexen 	TAILQ_FOREACH_SAFE(control, &tmp_queue, next, nctl) {
4262f8829a4aSRandall Stewart 		TAILQ_INSERT_TAIL(&new_inp->read_queue, control, next);
4263f8829a4aSRandall Stewart 		m = control->data;
4264f8829a4aSRandall Stewart 		while (m) {
4265b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4266139bc87fSRandall Stewart 				sctp_sblog(&new_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m));
426780fefe0aSRandall Stewart 			}
4268f8829a4aSRandall Stewart 			sctp_sballoc(stcb, &new_so->so_rcv, m);
4269b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4270f8829a4aSRandall Stewart 				sctp_sblog(&new_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
427180fefe0aSRandall Stewart 			}
4272139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
4273f8829a4aSRandall Stewart 		}
4274f8829a4aSRandall Stewart 	}
4275f8829a4aSRandall Stewart 	SCTP_INP_READ_UNLOCK(new_inp);
4276f8829a4aSRandall Stewart }
4277f8829a4aSRandall Stewart 
4278f8829a4aSRandall Stewart void
4279f8829a4aSRandall Stewart sctp_add_to_readq(struct sctp_inpcb *inp,
4280f8829a4aSRandall Stewart     struct sctp_tcb *stcb,
4281f8829a4aSRandall Stewart     struct sctp_queued_to_read *control,
4282f8829a4aSRandall Stewart     struct sockbuf *sb,
4283ceaad40aSRandall Stewart     int end,
4284cfde3ff7SRandall Stewart     int inp_read_lock_held,
4285ceaad40aSRandall Stewart     int so_locked
4286ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
4287ceaad40aSRandall Stewart     SCTP_UNUSED
4288ceaad40aSRandall Stewart #endif
4289ceaad40aSRandall Stewart )
4290f8829a4aSRandall Stewart {
4291f8829a4aSRandall Stewart 	/*
4292f8829a4aSRandall Stewart 	 * Here we must place the control on the end of the socket read
4293f8829a4aSRandall Stewart 	 * queue AND increment sb_cc so that select will work properly on
4294f8829a4aSRandall Stewart 	 * read.
4295f8829a4aSRandall Stewart 	 */
4296f8829a4aSRandall Stewart 	struct mbuf *m, *prev = NULL;
4297f8829a4aSRandall Stewart 
429803b0b021SRandall Stewart 	if (inp == NULL) {
429903b0b021SRandall Stewart 		/* Gak, TSNH!! */
4300a5d547adSRandall Stewart #ifdef INVARIANTS
430103b0b021SRandall Stewart 		panic("Gak, inp NULL on add_to_readq");
430203b0b021SRandall Stewart #endif
430303b0b021SRandall Stewart 		return;
430403b0b021SRandall Stewart 	}
4305cfde3ff7SRandall Stewart 	if (inp_read_lock_held == 0)
4306f8829a4aSRandall Stewart 		SCTP_INP_READ_LOCK(inp);
4307cd1386abSMichael Tuexen 	if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_CANT_READ) {
4308cd1386abSMichael Tuexen 		sctp_free_remote_addr(control->whoFrom);
4309cd1386abSMichael Tuexen 		if (control->data) {
4310cd1386abSMichael Tuexen 			sctp_m_freem(control->data);
4311cd1386abSMichael Tuexen 			control->data = NULL;
4312cd1386abSMichael Tuexen 		}
4313cd1386abSMichael Tuexen 		SCTP_ZONE_FREE(SCTP_BASE_INFO(ipi_zone_readq), control);
4314cd1386abSMichael Tuexen 		if (inp_read_lock_held == 0)
4315cd1386abSMichael Tuexen 			SCTP_INP_READ_UNLOCK(inp);
4316cd1386abSMichael Tuexen 		return;
4317cd1386abSMichael Tuexen 	}
431842551e99SRandall Stewart 	if (!(control->spec_flags & M_NOTIFICATION)) {
4319a5d547adSRandall Stewart 		atomic_add_int(&inp->total_recvs, 1);
432042551e99SRandall Stewart 		if (!control->do_not_ref_stcb) {
4321a5d547adSRandall Stewart 			atomic_add_int(&stcb->total_recvs, 1);
432242551e99SRandall Stewart 		}
432342551e99SRandall Stewart 	}
4324f8829a4aSRandall Stewart 	m = control->data;
4325f8829a4aSRandall Stewart 	control->held_length = 0;
4326f8829a4aSRandall Stewart 	control->length = 0;
4327f8829a4aSRandall Stewart 	while (m) {
4328139bc87fSRandall Stewart 		if (SCTP_BUF_LEN(m) == 0) {
4329f8829a4aSRandall Stewart 			/* Skip mbufs with NO length */
4330f8829a4aSRandall Stewart 			if (prev == NULL) {
4331f8829a4aSRandall Stewart 				/* First one */
4332f8829a4aSRandall Stewart 				control->data = sctp_m_free(m);
4333f8829a4aSRandall Stewart 				m = control->data;
4334f8829a4aSRandall Stewart 			} else {
4335139bc87fSRandall Stewart 				SCTP_BUF_NEXT(prev) = sctp_m_free(m);
4336139bc87fSRandall Stewart 				m = SCTP_BUF_NEXT(prev);
4337f8829a4aSRandall Stewart 			}
4338f8829a4aSRandall Stewart 			if (m == NULL) {
4339c2ede4b3SMartin Blapp 				control->tail_mbuf = prev;
4340f8829a4aSRandall Stewart 			}
4341f8829a4aSRandall Stewart 			continue;
4342f8829a4aSRandall Stewart 		}
4343f8829a4aSRandall Stewart 		prev = m;
4344b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4345139bc87fSRandall Stewart 			sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m));
434680fefe0aSRandall Stewart 		}
4347f8829a4aSRandall Stewart 		sctp_sballoc(stcb, sb, m);
4348b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4349f8829a4aSRandall Stewart 			sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
435080fefe0aSRandall Stewart 		}
4351139bc87fSRandall Stewart 		atomic_add_int(&control->length, SCTP_BUF_LEN(m));
4352139bc87fSRandall Stewart 		m = SCTP_BUF_NEXT(m);
4353f8829a4aSRandall Stewart 	}
4354f8829a4aSRandall Stewart 	if (prev != NULL) {
4355f8829a4aSRandall Stewart 		control->tail_mbuf = prev;
4356f8829a4aSRandall Stewart 	} else {
4357139bc87fSRandall Stewart 		/* Everything got collapsed out?? */
4358cd1386abSMichael Tuexen 		sctp_free_remote_addr(control->whoFrom);
4359cd1386abSMichael Tuexen 		SCTP_ZONE_FREE(SCTP_BASE_INFO(ipi_zone_readq), control);
4360cfde3ff7SRandall Stewart 		if (inp_read_lock_held == 0)
436147a490cbSMichael Tuexen 			SCTP_INP_READ_UNLOCK(inp);
4362f8829a4aSRandall Stewart 		return;
4363f8829a4aSRandall Stewart 	}
4364f8829a4aSRandall Stewart 	if (end) {
4365f8829a4aSRandall Stewart 		control->end_added = 1;
4366f8829a4aSRandall Stewart 	}
4367f8829a4aSRandall Stewart 	TAILQ_INSERT_TAIL(&inp->read_queue, control, next);
4368cfde3ff7SRandall Stewart 	if (inp_read_lock_held == 0)
4369f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
4370f8829a4aSRandall Stewart 	if (inp && inp->sctp_socket) {
437117205eccSRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_ZERO_COPY_ACTIVE)) {
437217205eccSRandall Stewart 			SCTP_ZERO_COPY_EVENT(inp, inp->sctp_socket);
4373ceaad40aSRandall Stewart 		} else {
4374ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4375ceaad40aSRandall Stewart 			struct socket *so;
4376ceaad40aSRandall Stewart 
4377ceaad40aSRandall Stewart 			so = SCTP_INP_SO(inp);
4378ceaad40aSRandall Stewart 			if (!so_locked) {
4379ceaad40aSRandall Stewart 				atomic_add_int(&stcb->asoc.refcnt, 1);
4380ceaad40aSRandall Stewart 				SCTP_TCB_UNLOCK(stcb);
4381ceaad40aSRandall Stewart 				SCTP_SOCKET_LOCK(so, 1);
4382ceaad40aSRandall Stewart 				SCTP_TCB_LOCK(stcb);
4383ceaad40aSRandall Stewart 				atomic_subtract_int(&stcb->asoc.refcnt, 1);
4384ceaad40aSRandall Stewart 				if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
4385ceaad40aSRandall Stewart 					SCTP_SOCKET_UNLOCK(so, 1);
4386ceaad40aSRandall Stewart 					return;
4387ceaad40aSRandall Stewart 				}
4388ceaad40aSRandall Stewart 			}
4389ceaad40aSRandall Stewart #endif
4390f8829a4aSRandall Stewart 			sctp_sorwakeup(inp, inp->sctp_socket);
4391ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4392ceaad40aSRandall Stewart 			if (!so_locked) {
4393ceaad40aSRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
4394ceaad40aSRandall Stewart 			}
4395ceaad40aSRandall Stewart #endif
4396ceaad40aSRandall Stewart 		}
4397f8829a4aSRandall Stewart 	}
4398f8829a4aSRandall Stewart }
4399f8829a4aSRandall Stewart 
4400f8829a4aSRandall Stewart 
4401f8829a4aSRandall Stewart int
4402f8829a4aSRandall Stewart sctp_append_to_readq(struct sctp_inpcb *inp,
4403f8829a4aSRandall Stewart     struct sctp_tcb *stcb,
4404f8829a4aSRandall Stewart     struct sctp_queued_to_read *control,
4405f8829a4aSRandall Stewart     struct mbuf *m,
4406f8829a4aSRandall Stewart     int end,
4407f8829a4aSRandall Stewart     int ctls_cumack,
4408f8829a4aSRandall Stewart     struct sockbuf *sb)
4409f8829a4aSRandall Stewart {
4410f8829a4aSRandall Stewart 	/*
4411f8829a4aSRandall Stewart 	 * A partial delivery API event is underway. OR we are appending on
4412f8829a4aSRandall Stewart 	 * the reassembly queue.
4413f8829a4aSRandall Stewart 	 *
4414f8829a4aSRandall Stewart 	 * If PDAPI this means we need to add m to the end of the data.
4415f8829a4aSRandall Stewart 	 * Increase the length in the control AND increment the sb_cc.
4416f8829a4aSRandall Stewart 	 * Otherwise sb is NULL and all we need to do is put it at the end
4417f8829a4aSRandall Stewart 	 * of the mbuf chain.
4418f8829a4aSRandall Stewart 	 */
4419f8829a4aSRandall Stewart 	int len = 0;
4420f8829a4aSRandall Stewart 	struct mbuf *mm, *tail = NULL, *prev = NULL;
4421f8829a4aSRandall Stewart 
4422f8829a4aSRandall Stewart 	if (inp) {
4423f8829a4aSRandall Stewart 		SCTP_INP_READ_LOCK(inp);
4424f8829a4aSRandall Stewart 	}
4425f8829a4aSRandall Stewart 	if (control == NULL) {
4426f8829a4aSRandall Stewart get_out:
4427f8829a4aSRandall Stewart 		if (inp) {
4428f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
4429f8829a4aSRandall Stewart 		}
4430f8829a4aSRandall Stewart 		return (-1);
4431f8829a4aSRandall Stewart 	}
4432cd1386abSMichael Tuexen 	if (inp && (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_CANT_READ)) {
4433cd1386abSMichael Tuexen 		SCTP_INP_READ_UNLOCK(inp);
4434cd1386abSMichael Tuexen 		return 0;
4435cd1386abSMichael Tuexen 	}
4436139bc87fSRandall Stewart 	if (control->end_added) {
4437f8829a4aSRandall Stewart 		/* huh this one is complete? */
4438f8829a4aSRandall Stewart 		goto get_out;
4439f8829a4aSRandall Stewart 	}
4440f8829a4aSRandall Stewart 	mm = m;
4441f8829a4aSRandall Stewart 	if (mm == NULL) {
4442f8829a4aSRandall Stewart 		goto get_out;
4443f8829a4aSRandall Stewart 	}
4444f8829a4aSRandall Stewart 	while (mm) {
4445139bc87fSRandall Stewart 		if (SCTP_BUF_LEN(mm) == 0) {
4446f8829a4aSRandall Stewart 			/* Skip mbufs with NO lenght */
4447f8829a4aSRandall Stewart 			if (prev == NULL) {
4448f8829a4aSRandall Stewart 				/* First one */
4449f8829a4aSRandall Stewart 				m = sctp_m_free(mm);
4450f8829a4aSRandall Stewart 				mm = m;
4451f8829a4aSRandall Stewart 			} else {
4452139bc87fSRandall Stewart 				SCTP_BUF_NEXT(prev) = sctp_m_free(mm);
4453139bc87fSRandall Stewart 				mm = SCTP_BUF_NEXT(prev);
4454f8829a4aSRandall Stewart 			}
4455f8829a4aSRandall Stewart 			continue;
4456f8829a4aSRandall Stewart 		}
4457f8829a4aSRandall Stewart 		prev = mm;
4458139bc87fSRandall Stewart 		len += SCTP_BUF_LEN(mm);
4459f8829a4aSRandall Stewart 		if (sb) {
4460b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4461139bc87fSRandall Stewart 				sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(mm));
446280fefe0aSRandall Stewart 			}
4463f8829a4aSRandall Stewart 			sctp_sballoc(stcb, sb, mm);
4464b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4465f8829a4aSRandall Stewart 				sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
446680fefe0aSRandall Stewart 			}
4467f8829a4aSRandall Stewart 		}
4468139bc87fSRandall Stewart 		mm = SCTP_BUF_NEXT(mm);
4469f8829a4aSRandall Stewart 	}
4470f8829a4aSRandall Stewart 	if (prev) {
4471f8829a4aSRandall Stewart 		tail = prev;
4472f8829a4aSRandall Stewart 	} else {
4473f8829a4aSRandall Stewart 		/* Really there should always be a prev */
4474f8829a4aSRandall Stewart 		if (m == NULL) {
4475f8829a4aSRandall Stewart 			/* Huh nothing left? */
4476a5d547adSRandall Stewart #ifdef INVARIANTS
4477f8829a4aSRandall Stewart 			panic("Nothing left to add?");
4478f8829a4aSRandall Stewart #else
4479f8829a4aSRandall Stewart 			goto get_out;
4480f8829a4aSRandall Stewart #endif
4481f8829a4aSRandall Stewart 		}
4482f8829a4aSRandall Stewart 		tail = m;
4483f8829a4aSRandall Stewart 	}
4484f8829a4aSRandall Stewart 	if (control->tail_mbuf) {
4485f8829a4aSRandall Stewart 		/* append */
4486139bc87fSRandall Stewart 		SCTP_BUF_NEXT(control->tail_mbuf) = m;
4487f8829a4aSRandall Stewart 		control->tail_mbuf = tail;
4488f8829a4aSRandall Stewart 	} else {
4489f8829a4aSRandall Stewart 		/* nothing there */
4490a5d547adSRandall Stewart #ifdef INVARIANTS
4491f8829a4aSRandall Stewart 		if (control->data != NULL) {
4492f8829a4aSRandall Stewart 			panic("This should NOT happen");
4493f8829a4aSRandall Stewart 		}
4494f8829a4aSRandall Stewart #endif
4495f8829a4aSRandall Stewart 		control->data = m;
4496f8829a4aSRandall Stewart 		control->tail_mbuf = tail;
4497f8829a4aSRandall Stewart 	}
449818e198d3SRandall Stewart 	atomic_add_int(&control->length, len);
449918e198d3SRandall Stewart 	if (end) {
450018e198d3SRandall Stewart 		/* message is complete */
450118e198d3SRandall Stewart 		if (stcb && (control == stcb->asoc.control_pdapi)) {
450218e198d3SRandall Stewart 			stcb->asoc.control_pdapi = NULL;
450318e198d3SRandall Stewart 		}
450418e198d3SRandall Stewart 		control->held_length = 0;
450518e198d3SRandall Stewart 		control->end_added = 1;
450618e198d3SRandall Stewart 	}
4507ad81507eSRandall Stewart 	if (stcb == NULL) {
4508ad81507eSRandall Stewart 		control->do_not_ref_stcb = 1;
4509ad81507eSRandall Stewart 	}
4510f8829a4aSRandall Stewart 	/*
4511f8829a4aSRandall Stewart 	 * When we are appending in partial delivery, the cum-ack is used
4512f8829a4aSRandall Stewart 	 * for the actual pd-api highest tsn on this mbuf. The true cum-ack
4513f8829a4aSRandall Stewart 	 * is populated in the outbound sinfo structure from the true cumack
4514f8829a4aSRandall Stewart 	 * if the association exists...
4515f8829a4aSRandall Stewart 	 */
4516f8829a4aSRandall Stewart 	control->sinfo_tsn = control->sinfo_cumtsn = ctls_cumack;
4517f8829a4aSRandall Stewart 	if (inp) {
4518f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
4519f8829a4aSRandall Stewart 	}
4520f8829a4aSRandall Stewart 	if (inp && inp->sctp_socket) {
452117205eccSRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_ZERO_COPY_ACTIVE)) {
452217205eccSRandall Stewart 			SCTP_ZERO_COPY_EVENT(inp, inp->sctp_socket);
4523ceaad40aSRandall Stewart 		} else {
4524ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4525ceaad40aSRandall Stewart 			struct socket *so;
4526ceaad40aSRandall Stewart 
4527ceaad40aSRandall Stewart 			so = SCTP_INP_SO(inp);
4528ceaad40aSRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, 1);
4529ceaad40aSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
4530ceaad40aSRandall Stewart 			SCTP_SOCKET_LOCK(so, 1);
4531ceaad40aSRandall Stewart 			SCTP_TCB_LOCK(stcb);
4532ceaad40aSRandall Stewart 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
4533ceaad40aSRandall Stewart 			if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
4534ceaad40aSRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
4535ceaad40aSRandall Stewart 				return (0);
4536ceaad40aSRandall Stewart 			}
4537ceaad40aSRandall Stewart #endif
4538f8829a4aSRandall Stewart 			sctp_sorwakeup(inp, inp->sctp_socket);
4539ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4540ceaad40aSRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
4541ceaad40aSRandall Stewart #endif
4542ceaad40aSRandall Stewart 		}
4543f8829a4aSRandall Stewart 	}
4544f8829a4aSRandall Stewart 	return (0);
4545f8829a4aSRandall Stewart }
4546f8829a4aSRandall Stewart 
4547f8829a4aSRandall Stewart 
4548f8829a4aSRandall Stewart 
4549f8829a4aSRandall Stewart /*************HOLD THIS COMMENT FOR PATCH FILE OF
4550f8829a4aSRandall Stewart  *************ALTERNATE ROUTING CODE
4551f8829a4aSRandall Stewart  */
4552f8829a4aSRandall Stewart 
4553f8829a4aSRandall Stewart /*************HOLD THIS COMMENT FOR END OF PATCH FILE OF
4554f8829a4aSRandall Stewart  *************ALTERNATE ROUTING CODE
4555f8829a4aSRandall Stewart  */
4556f8829a4aSRandall Stewart 
4557f8829a4aSRandall Stewart struct mbuf *
4558f8829a4aSRandall Stewart sctp_generate_invmanparam(int err)
4559f8829a4aSRandall Stewart {
4560f8829a4aSRandall Stewart 	/* Return a MBUF with a invalid mandatory parameter */
4561f8829a4aSRandall Stewart 	struct mbuf *m;
4562f8829a4aSRandall Stewart 
4563f8829a4aSRandall Stewart 	m = sctp_get_mbuf_for_msg(sizeof(struct sctp_paramhdr), 0, M_DONTWAIT, 1, MT_DATA);
4564f8829a4aSRandall Stewart 	if (m) {
4565f8829a4aSRandall Stewart 		struct sctp_paramhdr *ph;
4566f8829a4aSRandall Stewart 
4567139bc87fSRandall Stewart 		SCTP_BUF_LEN(m) = sizeof(struct sctp_paramhdr);
4568f8829a4aSRandall Stewart 		ph = mtod(m, struct sctp_paramhdr *);
4569f8829a4aSRandall Stewart 		ph->param_length = htons(sizeof(struct sctp_paramhdr));
4570f8829a4aSRandall Stewart 		ph->param_type = htons(err);
4571f8829a4aSRandall Stewart 	}
4572f8829a4aSRandall Stewart 	return (m);
4573f8829a4aSRandall Stewart }
4574f8829a4aSRandall Stewart 
4575f8829a4aSRandall Stewart #ifdef SCTP_MBCNT_LOGGING
4576f8829a4aSRandall Stewart void
4577f8829a4aSRandall Stewart sctp_free_bufspace(struct sctp_tcb *stcb, struct sctp_association *asoc,
4578f8829a4aSRandall Stewart     struct sctp_tmit_chunk *tp1, int chk_cnt)
4579f8829a4aSRandall Stewart {
4580f8829a4aSRandall Stewart 	if (tp1->data == NULL) {
4581f8829a4aSRandall Stewart 		return;
4582f8829a4aSRandall Stewart 	}
4583f8829a4aSRandall Stewart 	asoc->chunks_on_out_queue -= chk_cnt;
4584b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_MBCNT_LOGGING_ENABLE) {
4585f8829a4aSRandall Stewart 		sctp_log_mbcnt(SCTP_LOG_MBCNT_DECREASE,
4586f8829a4aSRandall Stewart 		    asoc->total_output_queue_size,
4587f8829a4aSRandall Stewart 		    tp1->book_size,
4588f8829a4aSRandall Stewart 		    0,
4589f8829a4aSRandall Stewart 		    tp1->mbcnt);
459080fefe0aSRandall Stewart 	}
4591f8829a4aSRandall Stewart 	if (asoc->total_output_queue_size >= tp1->book_size) {
459244b7479bSRandall Stewart 		atomic_add_int(&asoc->total_output_queue_size, -tp1->book_size);
4593f8829a4aSRandall Stewart 	} else {
4594f8829a4aSRandall Stewart 		asoc->total_output_queue_size = 0;
4595f8829a4aSRandall Stewart 	}
4596f8829a4aSRandall Stewart 
4597f8829a4aSRandall Stewart 	if (stcb->sctp_socket && (((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) ||
4598f8829a4aSRandall Stewart 	    ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE)))) {
4599f8829a4aSRandall Stewart 		if (stcb->sctp_socket->so_snd.sb_cc >= tp1->book_size) {
4600f8829a4aSRandall Stewart 			stcb->sctp_socket->so_snd.sb_cc -= tp1->book_size;
4601f8829a4aSRandall Stewart 		} else {
4602f8829a4aSRandall Stewart 			stcb->sctp_socket->so_snd.sb_cc = 0;
4603f8829a4aSRandall Stewart 
4604f8829a4aSRandall Stewart 		}
4605f8829a4aSRandall Stewart 	}
4606f8829a4aSRandall Stewart }
4607f8829a4aSRandall Stewart 
4608f8829a4aSRandall Stewart #endif
4609f8829a4aSRandall Stewart 
4610f8829a4aSRandall Stewart int
4611f8829a4aSRandall Stewart sctp_release_pr_sctp_chunk(struct sctp_tcb *stcb, struct sctp_tmit_chunk *tp1,
46120c0982b8SRandall Stewart     int reason, int so_locked
4613ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
4614ceaad40aSRandall Stewart     SCTP_UNUSED
4615ceaad40aSRandall Stewart #endif
4616ceaad40aSRandall Stewart )
4617f8829a4aSRandall Stewart {
46180c0982b8SRandall Stewart 	struct sctp_stream_out *strq;
46194a9ef3f8SMichael Tuexen 	struct sctp_tmit_chunk *chk = NULL, *tp2;
46200c0982b8SRandall Stewart 	struct sctp_stream_queue_pending *sp;
46210c0982b8SRandall Stewart 	uint16_t stream = 0, seq = 0;
46220c0982b8SRandall Stewart 	uint8_t foundeom = 0;
4623f8829a4aSRandall Stewart 	int ret_sz = 0;
4624f8829a4aSRandall Stewart 	int notdone;
46250c0982b8SRandall Stewart 	int do_wakeup_routine = 0;
4626f8829a4aSRandall Stewart 
46270c0982b8SRandall Stewart 	stream = tp1->rec.data.stream_number;
46280c0982b8SRandall Stewart 	seq = tp1->rec.data.stream_seq;
4629f8829a4aSRandall Stewart 	do {
4630f8829a4aSRandall Stewart 		ret_sz += tp1->book_size;
46310c0982b8SRandall Stewart 		if (tp1->data != NULL) {
46328933fa13SRandall Stewart 			if (tp1->sent < SCTP_DATAGRAM_RESEND) {
4633830d754dSRandall Stewart 				sctp_flight_size_decrease(tp1);
4634830d754dSRandall Stewart 				sctp_total_flight_decrease(stcb, tp1);
46358933fa13SRandall Stewart 			}
46368933fa13SRandall Stewart 			sctp_free_bufspace(stcb, &stcb->asoc, tp1, 1);
46370c0982b8SRandall Stewart 			stcb->asoc.peers_rwnd += tp1->send_size;
46380c0982b8SRandall Stewart 			stcb->asoc.peers_rwnd += SCTP_BASE_SYSCTL(sctp_peer_chunk_oh);
4639830d754dSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_DG_FAIL, stcb, reason, tp1, so_locked);
46402f99457bSMichael Tuexen 			if (tp1->data) {
4641f8829a4aSRandall Stewart 				sctp_m_freem(tp1->data);
4642f8829a4aSRandall Stewart 				tp1->data = NULL;
46432f99457bSMichael Tuexen 			}
46440c0982b8SRandall Stewart 			do_wakeup_routine = 1;
4645f8829a4aSRandall Stewart 			if (PR_SCTP_BUF_ENABLED(tp1->flags)) {
4646f8829a4aSRandall Stewart 				stcb->asoc.sent_queue_cnt_removeable--;
4647f8829a4aSRandall Stewart 			}
4648f8829a4aSRandall Stewart 		}
46498933fa13SRandall Stewart 		tp1->sent = SCTP_FORWARD_TSN_SKIP;
4650f8829a4aSRandall Stewart 		if ((tp1->rec.data.rcv_flags & SCTP_DATA_NOT_FRAG) ==
4651f8829a4aSRandall Stewart 		    SCTP_DATA_NOT_FRAG) {
4652f8829a4aSRandall Stewart 			/* not frag'ed we ae done   */
4653f8829a4aSRandall Stewart 			notdone = 0;
4654f8829a4aSRandall Stewart 			foundeom = 1;
4655f8829a4aSRandall Stewart 		} else if (tp1->rec.data.rcv_flags & SCTP_DATA_LAST_FRAG) {
4656f8829a4aSRandall Stewart 			/* end of frag, we are done */
4657f8829a4aSRandall Stewart 			notdone = 0;
4658f8829a4aSRandall Stewart 			foundeom = 1;
4659f8829a4aSRandall Stewart 		} else {
4660f8829a4aSRandall Stewart 			/*
4661f8829a4aSRandall Stewart 			 * Its a begin or middle piece, we must mark all of
4662f8829a4aSRandall Stewart 			 * it
4663f8829a4aSRandall Stewart 			 */
4664f8829a4aSRandall Stewart 			notdone = 1;
4665f8829a4aSRandall Stewart 			tp1 = TAILQ_NEXT(tp1, sctp_next);
4666f8829a4aSRandall Stewart 		}
4667f8829a4aSRandall Stewart 	} while (tp1 && notdone);
46680c0982b8SRandall Stewart 	if (foundeom == 0) {
4669f8829a4aSRandall Stewart 		/*
4670f8829a4aSRandall Stewart 		 * The multi-part message was scattered across the send and
4671f8829a4aSRandall Stewart 		 * sent queue.
4672f8829a4aSRandall Stewart 		 */
46734a9ef3f8SMichael Tuexen 		TAILQ_FOREACH_SAFE(tp1, &stcb->asoc.send_queue, sctp_next, tp2) {
46744a9ef3f8SMichael Tuexen 			if ((tp1->rec.data.stream_number != stream) ||
46754a9ef3f8SMichael Tuexen 			    (tp1->rec.data.stream_seq != seq)) {
46764a9ef3f8SMichael Tuexen 				break;
46774a9ef3f8SMichael Tuexen 			}
46780c0982b8SRandall Stewart 			/*
46790c0982b8SRandall Stewart 			 * save to chk in case we have some on stream out
46800c0982b8SRandall Stewart 			 * queue. If so and we have an un-transmitted one we
46810c0982b8SRandall Stewart 			 * don't have to fudge the TSN.
46820c0982b8SRandall Stewart 			 */
46830c0982b8SRandall Stewart 			chk = tp1;
46840c0982b8SRandall Stewart 			ret_sz += tp1->book_size;
46850c0982b8SRandall Stewart 			sctp_free_bufspace(stcb, &stcb->asoc, tp1, 1);
46862f99457bSMichael Tuexen 			sctp_ulp_notify(SCTP_NOTIFY_DG_FAIL, stcb, reason, tp1, so_locked);
46872f99457bSMichael Tuexen 			if (tp1->data) {
46880c0982b8SRandall Stewart 				sctp_m_freem(tp1->data);
46892f99457bSMichael Tuexen 				tp1->data = NULL;
46902f99457bSMichael Tuexen 			}
46918933fa13SRandall Stewart 			/* No flight involved here book the size to 0 */
46928933fa13SRandall Stewart 			tp1->book_size = 0;
46930c0982b8SRandall Stewart 			if (tp1->rec.data.rcv_flags & SCTP_DATA_LAST_FRAG) {
46940c0982b8SRandall Stewart 				foundeom = 1;
4695f8829a4aSRandall Stewart 			}
46960c0982b8SRandall Stewart 			do_wakeup_routine = 1;
46970c0982b8SRandall Stewart 			tp1->sent = SCTP_FORWARD_TSN_SKIP;
46980c0982b8SRandall Stewart 			TAILQ_REMOVE(&stcb->asoc.send_queue, tp1, sctp_next);
46990c0982b8SRandall Stewart 			/*
47000c0982b8SRandall Stewart 			 * on to the sent queue so we can wait for it to be
47010c0982b8SRandall Stewart 			 * passed by.
47020c0982b8SRandall Stewart 			 */
47030c0982b8SRandall Stewart 			TAILQ_INSERT_TAIL(&stcb->asoc.sent_queue, tp1,
47040c0982b8SRandall Stewart 			    sctp_next);
47050c0982b8SRandall Stewart 			stcb->asoc.send_queue_cnt--;
47060c0982b8SRandall Stewart 			stcb->asoc.sent_queue_cnt++;
47070c0982b8SRandall Stewart 		}
47080c0982b8SRandall Stewart 	}
47090c0982b8SRandall Stewart 	if (foundeom == 0) {
47100c0982b8SRandall Stewart 		/*
47110c0982b8SRandall Stewart 		 * Still no eom found. That means there is stuff left on the
47120c0982b8SRandall Stewart 		 * stream out queue.. yuck.
47130c0982b8SRandall Stewart 		 */
47140c0982b8SRandall Stewart 		strq = &stcb->asoc.strmout[stream];
47150c0982b8SRandall Stewart 		SCTP_TCB_SEND_LOCK(stcb);
47164a9ef3f8SMichael Tuexen 		TAILQ_FOREACH(sp, &strq->outqueue, next) {
47174a9ef3f8SMichael Tuexen 			/* FIXME: Shouldn't this be a serial number check? */
47184a9ef3f8SMichael Tuexen 			if (sp->strseq > seq) {
47194a9ef3f8SMichael Tuexen 				break;
47204a9ef3f8SMichael Tuexen 			}
47210c0982b8SRandall Stewart 			/* Check if its our SEQ */
47220c0982b8SRandall Stewart 			if (sp->strseq == seq) {
47230c0982b8SRandall Stewart 				sp->discard_rest = 1;
47240c0982b8SRandall Stewart 				/*
47250c0982b8SRandall Stewart 				 * We may need to put a chunk on the queue
47260c0982b8SRandall Stewart 				 * that holds the TSN that would have been
47270c0982b8SRandall Stewart 				 * sent with the LAST bit.
47280c0982b8SRandall Stewart 				 */
47290c0982b8SRandall Stewart 				if (chk == NULL) {
47300c0982b8SRandall Stewart 					/* Yep, we have to */
47310c0982b8SRandall Stewart 					sctp_alloc_a_chunk(stcb, chk);
47320c0982b8SRandall Stewart 					if (chk == NULL) {
47330c0982b8SRandall Stewart 						/*
47340c0982b8SRandall Stewart 						 * we are hosed. All we can
47350c0982b8SRandall Stewart 						 * do is nothing.. which
47360c0982b8SRandall Stewart 						 * will cause an abort if
47370c0982b8SRandall Stewart 						 * the peer is paying
47380c0982b8SRandall Stewart 						 * attention.
47390c0982b8SRandall Stewart 						 */
47400c0982b8SRandall Stewart 						goto oh_well;
47410c0982b8SRandall Stewart 					}
47420c0982b8SRandall Stewart 					memset(chk, 0, sizeof(*chk));
47430c0982b8SRandall Stewart 					chk->rec.data.rcv_flags = SCTP_DATA_LAST_FRAG;
47440c0982b8SRandall Stewart 					chk->sent = SCTP_FORWARD_TSN_SKIP;
47450c0982b8SRandall Stewart 					chk->asoc = &stcb->asoc;
47460c0982b8SRandall Stewart 					chk->rec.data.stream_seq = sp->strseq;
47470c0982b8SRandall Stewart 					chk->rec.data.stream_number = sp->stream;
47480c0982b8SRandall Stewart 					chk->rec.data.payloadtype = sp->ppid;
47490c0982b8SRandall Stewart 					chk->rec.data.context = sp->context;
47500c0982b8SRandall Stewart 					chk->flags = sp->act_flags;
47519eea4a2dSMichael Tuexen 					if (sp->net)
47520c0982b8SRandall Stewart 						chk->whoTo = sp->net;
47539eea4a2dSMichael Tuexen 					else
47549eea4a2dSMichael Tuexen 						chk->whoTo = stcb->asoc.primary_destination;
47550c0982b8SRandall Stewart 					atomic_add_int(&chk->whoTo->ref_count, 1);
47560c0982b8SRandall Stewart 					chk->rec.data.TSN_seq = atomic_fetchadd_int(&stcb->asoc.sending_seq, 1);
47570c0982b8SRandall Stewart 					stcb->asoc.pr_sctp_cnt++;
47580c0982b8SRandall Stewart 					chk->pr_sctp_on = 1;
47590c0982b8SRandall Stewart 					TAILQ_INSERT_TAIL(&stcb->asoc.sent_queue, chk, sctp_next);
47600c0982b8SRandall Stewart 					stcb->asoc.sent_queue_cnt++;
47618933fa13SRandall Stewart 					stcb->asoc.pr_sctp_cnt++;
47620c0982b8SRandall Stewart 				} else {
47630c0982b8SRandall Stewart 					chk->rec.data.rcv_flags |= SCTP_DATA_LAST_FRAG;
47640c0982b8SRandall Stewart 				}
47650c0982b8SRandall Stewart 		oh_well:
47660c0982b8SRandall Stewart 				if (sp->data) {
47670c0982b8SRandall Stewart 					/*
47680c0982b8SRandall Stewart 					 * Pull any data to free up the SB
47690c0982b8SRandall Stewart 					 * and allow sender to "add more"
47700c0982b8SRandall Stewart 					 * whilc we will throw away :-)
47710c0982b8SRandall Stewart 					 */
47720c0982b8SRandall Stewart 					sctp_free_spbufspace(stcb, &stcb->asoc,
47730c0982b8SRandall Stewart 					    sp);
47740c0982b8SRandall Stewart 					ret_sz += sp->length;
47750c0982b8SRandall Stewart 					do_wakeup_routine = 1;
47760c0982b8SRandall Stewart 					sp->some_taken = 1;
47770c0982b8SRandall Stewart 					sctp_m_freem(sp->data);
47780c0982b8SRandall Stewart 					sp->length = 0;
47790c0982b8SRandall Stewart 					sp->data = NULL;
47800c0982b8SRandall Stewart 					sp->tail_mbuf = NULL;
47810c0982b8SRandall Stewart 				}
47820c0982b8SRandall Stewart 				break;
47830c0982b8SRandall Stewart 			}
47844a9ef3f8SMichael Tuexen 		}		/* End tailq_foreach */
47850c0982b8SRandall Stewart 		SCTP_TCB_SEND_UNLOCK(stcb);
47860c0982b8SRandall Stewart 	}
47870c0982b8SRandall Stewart 	if (do_wakeup_routine) {
47880c0982b8SRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
47898933fa13SRandall Stewart 		struct socket *so;
47908933fa13SRandall Stewart 
47910c0982b8SRandall Stewart 		so = SCTP_INP_SO(stcb->sctp_ep);
47920c0982b8SRandall Stewart 		if (!so_locked) {
47930c0982b8SRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, 1);
47940c0982b8SRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
47950c0982b8SRandall Stewart 			SCTP_SOCKET_LOCK(so, 1);
47960c0982b8SRandall Stewart 			SCTP_TCB_LOCK(stcb);
47970c0982b8SRandall Stewart 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
47980c0982b8SRandall Stewart 			if (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET) {
47990c0982b8SRandall Stewart 				/* assoc was freed while we were unlocked */
48000c0982b8SRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
48010c0982b8SRandall Stewart 				return (ret_sz);
48020c0982b8SRandall Stewart 			}
48030c0982b8SRandall Stewart 		}
48040c0982b8SRandall Stewart #endif
48050c0982b8SRandall Stewart 		sctp_sowwakeup(stcb->sctp_ep, stcb->sctp_socket);
48060c0982b8SRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
48070c0982b8SRandall Stewart 		if (!so_locked) {
48080c0982b8SRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
48090c0982b8SRandall Stewart 		}
48100c0982b8SRandall Stewart #endif
4811f8829a4aSRandall Stewart 	}
4812f8829a4aSRandall Stewart 	return (ret_sz);
4813f8829a4aSRandall Stewart }
4814f8829a4aSRandall Stewart 
4815f8829a4aSRandall Stewart /*
4816f8829a4aSRandall Stewart  * checks to see if the given address, sa, is one that is currently known by
4817f8829a4aSRandall Stewart  * the kernel note: can't distinguish the same address on multiple interfaces
4818f8829a4aSRandall Stewart  * and doesn't handle multiple addresses with different zone/scope id's note:
4819f8829a4aSRandall Stewart  * ifa_ifwithaddr() compares the entire sockaddr struct
4820f8829a4aSRandall Stewart  */
482142551e99SRandall Stewart struct sctp_ifa *
482280fefe0aSRandall Stewart sctp_find_ifa_in_ep(struct sctp_inpcb *inp, struct sockaddr *addr,
482380fefe0aSRandall Stewart     int holds_lock)
4824f8829a4aSRandall Stewart {
482542551e99SRandall Stewart 	struct sctp_laddr *laddr;
4826f8829a4aSRandall Stewart 
4827ad81507eSRandall Stewart 	if (holds_lock == 0) {
482842551e99SRandall Stewart 		SCTP_INP_RLOCK(inp);
4829ad81507eSRandall Stewart 	}
483042551e99SRandall Stewart 	LIST_FOREACH(laddr, &inp->sctp_addr_list, sctp_nxt_addr) {
483142551e99SRandall Stewart 		if (laddr->ifa == NULL)
4832f8829a4aSRandall Stewart 			continue;
483342551e99SRandall Stewart 		if (addr->sa_family != laddr->ifa->address.sa.sa_family)
483442551e99SRandall Stewart 			continue;
4835e6194c2eSMichael Tuexen #ifdef INET
483642551e99SRandall Stewart 		if (addr->sa_family == AF_INET) {
483742551e99SRandall Stewart 			if (((struct sockaddr_in *)addr)->sin_addr.s_addr ==
483842551e99SRandall Stewart 			    laddr->ifa->address.sin.sin_addr.s_addr) {
483942551e99SRandall Stewart 				/* found him. */
4840ad81507eSRandall Stewart 				if (holds_lock == 0) {
484142551e99SRandall Stewart 					SCTP_INP_RUNLOCK(inp);
4842ad81507eSRandall Stewart 				}
484342551e99SRandall Stewart 				return (laddr->ifa);
484442551e99SRandall Stewart 				break;
484542551e99SRandall Stewart 			}
48465e2c2d87SRandall Stewart 		}
4847e6194c2eSMichael Tuexen #endif
48485e2c2d87SRandall Stewart #ifdef INET6
48495e2c2d87SRandall Stewart 		if (addr->sa_family == AF_INET6) {
4850c54a18d2SRandall Stewart 			if (SCTP6_ARE_ADDR_EQUAL((struct sockaddr_in6 *)addr,
4851c54a18d2SRandall Stewart 			    &laddr->ifa->address.sin6)) {
485242551e99SRandall Stewart 				/* found him. */
4853ad81507eSRandall Stewart 				if (holds_lock == 0) {
485442551e99SRandall Stewart 					SCTP_INP_RUNLOCK(inp);
4855ad81507eSRandall Stewart 				}
485642551e99SRandall Stewart 				return (laddr->ifa);
485742551e99SRandall Stewart 				break;
485842551e99SRandall Stewart 			}
485942551e99SRandall Stewart 		}
48605e2c2d87SRandall Stewart #endif
486142551e99SRandall Stewart 	}
4862ad81507eSRandall Stewart 	if (holds_lock == 0) {
486342551e99SRandall Stewart 		SCTP_INP_RUNLOCK(inp);
4864ad81507eSRandall Stewart 	}
486542551e99SRandall Stewart 	return (NULL);
486642551e99SRandall Stewart }
4867f8829a4aSRandall Stewart 
48686a27c376SRandall Stewart uint32_t
48696a27c376SRandall Stewart sctp_get_ifa_hash_val(struct sockaddr *addr)
48706a27c376SRandall Stewart {
4871ea5eba11SMichael Tuexen 	switch (addr->sa_family) {
4872ea5eba11SMichael Tuexen #ifdef INET
4873ea5eba11SMichael Tuexen 	case AF_INET:
4874ea5eba11SMichael Tuexen 		{
48756a27c376SRandall Stewart 			struct sockaddr_in *sin;
48766a27c376SRandall Stewart 
48776a27c376SRandall Stewart 			sin = (struct sockaddr_in *)addr;
48786a27c376SRandall Stewart 			return (sin->sin_addr.s_addr ^ (sin->sin_addr.s_addr >> 16));
4879ea5eba11SMichael Tuexen 		}
4880ea5eba11SMichael Tuexen #endif
4881ea5eba11SMichael Tuexen #ifdef INET6
4882ea5eba11SMichael Tuexen 	case INET6:
4883ea5eba11SMichael Tuexen 		{
48846a27c376SRandall Stewart 			struct sockaddr_in6 *sin6;
48856a27c376SRandall Stewart 			uint32_t hash_of_addr;
48866a27c376SRandall Stewart 
48876a27c376SRandall Stewart 			sin6 = (struct sockaddr_in6 *)addr;
48886a27c376SRandall Stewart 			hash_of_addr = (sin6->sin6_addr.s6_addr32[0] +
48896a27c376SRandall Stewart 			    sin6->sin6_addr.s6_addr32[1] +
48906a27c376SRandall Stewart 			    sin6->sin6_addr.s6_addr32[2] +
48916a27c376SRandall Stewart 			    sin6->sin6_addr.s6_addr32[3]);
48926a27c376SRandall Stewart 			hash_of_addr = (hash_of_addr ^ (hash_of_addr >> 16));
48936a27c376SRandall Stewart 			return (hash_of_addr);
48946a27c376SRandall Stewart 		}
4895ea5eba11SMichael Tuexen #endif
4896ea5eba11SMichael Tuexen 	default:
4897ea5eba11SMichael Tuexen 		break;
4898ea5eba11SMichael Tuexen 	}
48996a27c376SRandall Stewart 	return (0);
49006a27c376SRandall Stewart }
49016a27c376SRandall Stewart 
490242551e99SRandall Stewart struct sctp_ifa *
490342551e99SRandall Stewart sctp_find_ifa_by_addr(struct sockaddr *addr, uint32_t vrf_id, int holds_lock)
490442551e99SRandall Stewart {
490542551e99SRandall Stewart 	struct sctp_ifa *sctp_ifap;
490642551e99SRandall Stewart 	struct sctp_vrf *vrf;
49076a27c376SRandall Stewart 	struct sctp_ifalist *hash_head;
49086a27c376SRandall Stewart 	uint32_t hash_of_addr;
490942551e99SRandall Stewart 
491042551e99SRandall Stewart 	if (holds_lock == 0)
4911c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RLOCK();
491242551e99SRandall Stewart 
4913bff64a4dSRandall Stewart 	vrf = sctp_find_vrf(vrf_id);
4914bff64a4dSRandall Stewart 	if (vrf == NULL) {
4915df6e0cc3SRandall Stewart stage_right:
4916bff64a4dSRandall Stewart 		if (holds_lock == 0)
4917c99efcf6SRandall Stewart 			SCTP_IPI_ADDR_RUNLOCK();
4918bff64a4dSRandall Stewart 		return (NULL);
4919bff64a4dSRandall Stewart 	}
4920bff64a4dSRandall Stewart 	hash_of_addr = sctp_get_ifa_hash_val(addr);
4921bff64a4dSRandall Stewart 
492217205eccSRandall Stewart 	hash_head = &vrf->vrf_addr_hash[(hash_of_addr & vrf->vrf_addr_hashmark)];
4923bff64a4dSRandall Stewart 	if (hash_head == NULL) {
4924ad81507eSRandall Stewart 		SCTP_PRINTF("hash_of_addr:%x mask:%x table:%x - ",
4925c99efcf6SRandall Stewart 		    hash_of_addr, (uint32_t) vrf->vrf_addr_hashmark,
4926c99efcf6SRandall Stewart 		    (uint32_t) (hash_of_addr & vrf->vrf_addr_hashmark));
4927bff64a4dSRandall Stewart 		sctp_print_address(addr);
4928ad81507eSRandall Stewart 		SCTP_PRINTF("No such bucket for address\n");
4929bff64a4dSRandall Stewart 		if (holds_lock == 0)
4930c99efcf6SRandall Stewart 			SCTP_IPI_ADDR_RUNLOCK();
4931bff64a4dSRandall Stewart 
4932bff64a4dSRandall Stewart 		return (NULL);
4933bff64a4dSRandall Stewart 	}
49346a27c376SRandall Stewart 	LIST_FOREACH(sctp_ifap, hash_head, next_bucket) {
4935bff64a4dSRandall Stewart 		if (sctp_ifap == NULL) {
4936df6e0cc3SRandall Stewart #ifdef INVARIANTS
4937bff64a4dSRandall Stewart 			panic("Huh LIST_FOREACH corrupt");
4938df6e0cc3SRandall Stewart 			goto stage_right;
4939df6e0cc3SRandall Stewart #else
4940df6e0cc3SRandall Stewart 			SCTP_PRINTF("LIST corrupt of sctp_ifap's?\n");
4941df6e0cc3SRandall Stewart 			goto stage_right;
4942df6e0cc3SRandall Stewart #endif
4943bff64a4dSRandall Stewart 		}
49446a27c376SRandall Stewart 		if (addr->sa_family != sctp_ifap->address.sa.sa_family)
49456a27c376SRandall Stewart 			continue;
4946e6194c2eSMichael Tuexen #ifdef INET
49476a27c376SRandall Stewart 		if (addr->sa_family == AF_INET) {
49486a27c376SRandall Stewart 			if (((struct sockaddr_in *)addr)->sin_addr.s_addr ==
49496a27c376SRandall Stewart 			    sctp_ifap->address.sin.sin_addr.s_addr) {
49506a27c376SRandall Stewart 				/* found him. */
495142551e99SRandall Stewart 				if (holds_lock == 0)
4952c99efcf6SRandall Stewart 					SCTP_IPI_ADDR_RUNLOCK();
495342551e99SRandall Stewart 				return (sctp_ifap);
49546a27c376SRandall Stewart 				break;
49556a27c376SRandall Stewart 			}
49565e2c2d87SRandall Stewart 		}
4957e6194c2eSMichael Tuexen #endif
49585e2c2d87SRandall Stewart #ifdef INET6
49595e2c2d87SRandall Stewart 		if (addr->sa_family == AF_INET6) {
4960c54a18d2SRandall Stewart 			if (SCTP6_ARE_ADDR_EQUAL((struct sockaddr_in6 *)addr,
4961c54a18d2SRandall Stewart 			    &sctp_ifap->address.sin6)) {
49626a27c376SRandall Stewart 				/* found him. */
49636a27c376SRandall Stewart 				if (holds_lock == 0)
4964c99efcf6SRandall Stewart 					SCTP_IPI_ADDR_RUNLOCK();
49656a27c376SRandall Stewart 				return (sctp_ifap);
49666a27c376SRandall Stewart 				break;
49676a27c376SRandall Stewart 			}
496842551e99SRandall Stewart 		}
49695e2c2d87SRandall Stewart #endif
497042551e99SRandall Stewart 	}
497142551e99SRandall Stewart 	if (holds_lock == 0)
4972c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RUNLOCK();
4973f8829a4aSRandall Stewart 	return (NULL);
4974f8829a4aSRandall Stewart }
4975f8829a4aSRandall Stewart 
4976f8829a4aSRandall Stewart static void
49774c9179adSRandall Stewart sctp_user_rcvd(struct sctp_tcb *stcb, uint32_t * freed_so_far, int hold_rlock,
4978f8829a4aSRandall Stewart     uint32_t rwnd_req)
4979f8829a4aSRandall Stewart {
4980f8829a4aSRandall Stewart 	/* User pulled some data, do we need a rwnd update? */
4981f8829a4aSRandall Stewart 	int r_unlocked = 0;
4982f8829a4aSRandall Stewart 	uint32_t dif, rwnd;
4983f8829a4aSRandall Stewart 	struct socket *so = NULL;
4984f8829a4aSRandall Stewart 
4985f8829a4aSRandall Stewart 	if (stcb == NULL)
4986f8829a4aSRandall Stewart 		return;
4987f8829a4aSRandall Stewart 
498850cec919SRandall Stewart 	atomic_add_int(&stcb->asoc.refcnt, 1);
4989f8829a4aSRandall Stewart 
499062c1ff9cSRandall Stewart 	if (stcb->asoc.state & (SCTP_STATE_ABOUT_TO_BE_FREED |
499162c1ff9cSRandall Stewart 	    SCTP_STATE_SHUTDOWN_RECEIVED |
49924c9179adSRandall Stewart 	    SCTP_STATE_SHUTDOWN_ACK_SENT)) {
4993f8829a4aSRandall Stewart 		/* Pre-check If we are freeing no update */
4994f8829a4aSRandall Stewart 		goto no_lock;
4995f8829a4aSRandall Stewart 	}
4996f8829a4aSRandall Stewart 	SCTP_INP_INCR_REF(stcb->sctp_ep);
4997f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
4998f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE)) {
4999f8829a4aSRandall Stewart 		goto out;
5000f8829a4aSRandall Stewart 	}
5001f8829a4aSRandall Stewart 	so = stcb->sctp_socket;
5002f8829a4aSRandall Stewart 	if (so == NULL) {
5003f8829a4aSRandall Stewart 		goto out;
5004f8829a4aSRandall Stewart 	}
5005f8829a4aSRandall Stewart 	atomic_add_int(&stcb->freed_by_sorcv_sincelast, *freed_so_far);
5006f8829a4aSRandall Stewart 	/* Have you have freed enough to look */
5007f8829a4aSRandall Stewart 	*freed_so_far = 0;
5008f8829a4aSRandall Stewart 	/* Yep, its worth a look and the lock overhead */
5009f8829a4aSRandall Stewart 
5010f8829a4aSRandall Stewart 	/* Figure out what the rwnd would be */
5011f8829a4aSRandall Stewart 	rwnd = sctp_calc_rwnd(stcb, &stcb->asoc);
5012f8829a4aSRandall Stewart 	if (rwnd >= stcb->asoc.my_last_reported_rwnd) {
5013f8829a4aSRandall Stewart 		dif = rwnd - stcb->asoc.my_last_reported_rwnd;
5014f8829a4aSRandall Stewart 	} else {
5015f8829a4aSRandall Stewart 		dif = 0;
5016f8829a4aSRandall Stewart 	}
5017f8829a4aSRandall Stewart 	if (dif >= rwnd_req) {
5018f8829a4aSRandall Stewart 		if (hold_rlock) {
5019f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(stcb->sctp_ep);
5020f8829a4aSRandall Stewart 			r_unlocked = 1;
5021f8829a4aSRandall Stewart 		}
5022f8829a4aSRandall Stewart 		if (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
5023f8829a4aSRandall Stewart 			/*
5024f8829a4aSRandall Stewart 			 * One last check before we allow the guy possibly
5025f8829a4aSRandall Stewart 			 * to get in. There is a race, where the guy has not
5026f8829a4aSRandall Stewart 			 * reached the gate. In that case
5027f8829a4aSRandall Stewart 			 */
5028f8829a4aSRandall Stewart 			goto out;
5029f8829a4aSRandall Stewart 		}
5030f8829a4aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
5031f8829a4aSRandall Stewart 		if (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
5032f8829a4aSRandall Stewart 			/* No reports here */
5033f8829a4aSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
5034f8829a4aSRandall Stewart 			goto out;
5035f8829a4aSRandall Stewart 		}
5036f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_wu_sacks_sent);
5037689e6a5fSMichael Tuexen 		sctp_send_sack(stcb, SCTP_SO_LOCKED);
5038830d754dSRandall Stewart 
5039f8829a4aSRandall Stewart 		sctp_chunk_output(stcb->sctp_ep, stcb,
5040ceaad40aSRandall Stewart 		    SCTP_OUTPUT_FROM_USR_RCVD, SCTP_SO_LOCKED);
5041f8829a4aSRandall Stewart 		/* make sure no timer is running */
5042a5d547adSRandall Stewart 		sctp_timer_stop(SCTP_TIMER_TYPE_RECV, stcb->sctp_ep, stcb, NULL, SCTP_FROM_SCTPUTIL + SCTP_LOC_6);
5043f8829a4aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
5044f8829a4aSRandall Stewart 	} else {
5045f8829a4aSRandall Stewart 		/* Update how much we have pending */
5046f8829a4aSRandall Stewart 		stcb->freed_by_sorcv_sincelast = dif;
5047f8829a4aSRandall Stewart 	}
5048f8829a4aSRandall Stewart out:
5049f8829a4aSRandall Stewart 	if (so && r_unlocked && hold_rlock) {
5050f8829a4aSRandall Stewart 		SCTP_INP_READ_LOCK(stcb->sctp_ep);
5051f8829a4aSRandall Stewart 	}
5052f8829a4aSRandall Stewart 	SCTP_INP_DECR_REF(stcb->sctp_ep);
5053f8829a4aSRandall Stewart no_lock:
505450cec919SRandall Stewart 	atomic_add_int(&stcb->asoc.refcnt, -1);
5055f8829a4aSRandall Stewart 	return;
5056f8829a4aSRandall Stewart }
5057f8829a4aSRandall Stewart 
5058f8829a4aSRandall Stewart int
5059f8829a4aSRandall Stewart sctp_sorecvmsg(struct socket *so,
5060f8829a4aSRandall Stewart     struct uio *uio,
5061f8829a4aSRandall Stewart     struct mbuf **mp,
5062f8829a4aSRandall Stewart     struct sockaddr *from,
5063f8829a4aSRandall Stewart     int fromlen,
5064f8829a4aSRandall Stewart     int *msg_flags,
5065f8829a4aSRandall Stewart     struct sctp_sndrcvinfo *sinfo,
5066f8829a4aSRandall Stewart     int filling_sinfo)
5067f8829a4aSRandall Stewart {
5068f8829a4aSRandall Stewart 	/*
5069f8829a4aSRandall Stewart 	 * MSG flags we will look at MSG_DONTWAIT - non-blocking IO.
5070f8829a4aSRandall Stewart 	 * MSG_PEEK - Look don't touch :-D (only valid with OUT mbuf copy
5071f8829a4aSRandall Stewart 	 * mp=NULL thus uio is the copy method to userland) MSG_WAITALL - ??
5072f8829a4aSRandall Stewart 	 * On the way out we may send out any combination of:
5073f8829a4aSRandall Stewart 	 * MSG_NOTIFICATION MSG_EOR
5074f8829a4aSRandall Stewart 	 *
5075f8829a4aSRandall Stewart 	 */
5076f8829a4aSRandall Stewart 	struct sctp_inpcb *inp = NULL;
5077f8829a4aSRandall Stewart 	int my_len = 0;
5078f8829a4aSRandall Stewart 	int cp_len = 0, error = 0;
5079f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control = NULL, *ctl = NULL, *nxt = NULL;
508094b0d969SMichael Tuexen 	struct mbuf *m = NULL;
5081f8829a4aSRandall Stewart 	struct sctp_tcb *stcb = NULL;
5082f8829a4aSRandall Stewart 	int wakeup_read_socket = 0;
5083f8829a4aSRandall Stewart 	int freecnt_applied = 0;
5084f8829a4aSRandall Stewart 	int out_flags = 0, in_flags = 0;
5085f8829a4aSRandall Stewart 	int block_allowed = 1;
50864c9179adSRandall Stewart 	uint32_t freed_so_far = 0;
508781aca91aSRandall Stewart 	uint32_t copied_so_far = 0;
508893164cf9SRandall Stewart 	int in_eeor_mode = 0;
5089f8829a4aSRandall Stewart 	int no_rcv_needed = 0;
5090f8829a4aSRandall Stewart 	uint32_t rwnd_req = 0;
5091f8829a4aSRandall Stewart 	int hold_sblock = 0;
5092f8829a4aSRandall Stewart 	int hold_rlock = 0;
509342551e99SRandall Stewart 	int slen = 0;
50944c9179adSRandall Stewart 	uint32_t held_length = 0;
50957abab911SRobert Watson 	int sockbuf_lock = 0;
5096f8829a4aSRandall Stewart 
509717205eccSRandall Stewart 	if (uio == NULL) {
5098c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
509917205eccSRandall Stewart 		return (EINVAL);
510017205eccSRandall Stewart 	}
5101f8829a4aSRandall Stewart 	if (msg_flags) {
5102f8829a4aSRandall Stewart 		in_flags = *msg_flags;
5103c105859eSRandall Stewart 		if (in_flags & MSG_PEEK)
5104c105859eSRandall Stewart 			SCTP_STAT_INCR(sctps_read_peeks);
5105f8829a4aSRandall Stewart 	} else {
5106f8829a4aSRandall Stewart 		in_flags = 0;
5107f8829a4aSRandall Stewart 	}
5108f8829a4aSRandall Stewart 	slen = uio->uio_resid;
510917205eccSRandall Stewart 
5110f8829a4aSRandall Stewart 	/* Pull in and set up our int flags */
5111f8829a4aSRandall Stewart 	if (in_flags & MSG_OOB) {
5112f8829a4aSRandall Stewart 		/* Out of band's NOT supported */
5113f8829a4aSRandall Stewart 		return (EOPNOTSUPP);
5114f8829a4aSRandall Stewart 	}
5115f8829a4aSRandall Stewart 	if ((in_flags & MSG_PEEK) && (mp != NULL)) {
5116c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
5117f8829a4aSRandall Stewart 		return (EINVAL);
5118f8829a4aSRandall Stewart 	}
5119f8829a4aSRandall Stewart 	if ((in_flags & (MSG_DONTWAIT
5120f8829a4aSRandall Stewart 	    | MSG_NBIO
5121f8829a4aSRandall Stewart 	    )) ||
512242551e99SRandall Stewart 	    SCTP_SO_IS_NBIO(so)) {
5123f8829a4aSRandall Stewart 		block_allowed = 0;
5124f8829a4aSRandall Stewart 	}
5125f8829a4aSRandall Stewart 	/* setup the endpoint */
5126f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)so->so_pcb;
5127f8829a4aSRandall Stewart 	if (inp == NULL) {
5128c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EFAULT);
5129f8829a4aSRandall Stewart 		return (EFAULT);
5130f8829a4aSRandall Stewart 	}
513162c1ff9cSRandall Stewart 	rwnd_req = (SCTP_SB_LIMIT_RCV(so) >> SCTP_RWND_HIWAT_SHIFT);
5132f8829a4aSRandall Stewart 	/* Must be at least a MTU's worth */
5133f8829a4aSRandall Stewart 	if (rwnd_req < SCTP_MIN_RWND)
5134f8829a4aSRandall Stewart 		rwnd_req = SCTP_MIN_RWND;
5135f8829a4aSRandall Stewart 	in_eeor_mode = sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXPLICIT_EOR);
5136b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
5137f8829a4aSRandall Stewart 		sctp_misc_ints(SCTP_SORECV_ENTER,
513817205eccSRandall Stewart 		    rwnd_req, in_eeor_mode, so->so_rcv.sb_cc, uio->uio_resid);
513980fefe0aSRandall Stewart 	}
5140b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
5141f8829a4aSRandall Stewart 		sctp_misc_ints(SCTP_SORECV_ENTERPL,
514217205eccSRandall Stewart 		    rwnd_req, block_allowed, so->so_rcv.sb_cc, uio->uio_resid);
514380fefe0aSRandall Stewart 	}
5144265de5bbSRobert Watson 	error = sblock(&so->so_rcv, (block_allowed ? SBL_WAIT : 0));
51457abab911SRobert Watson 	sockbuf_lock = 1;
5146f8829a4aSRandall Stewart 	if (error) {
5147f8829a4aSRandall Stewart 		goto release_unlocked;
5148f8829a4aSRandall Stewart 	}
5149f8829a4aSRandall Stewart restart:
51507abab911SRobert Watson 
5151f8829a4aSRandall Stewart 
5152f8829a4aSRandall Stewart restart_nosblocks:
5153f8829a4aSRandall Stewart 	if (hold_sblock == 0) {
5154f8829a4aSRandall Stewart 		SOCKBUF_LOCK(&so->so_rcv);
5155f8829a4aSRandall Stewart 		hold_sblock = 1;
5156f8829a4aSRandall Stewart 	}
5157f8829a4aSRandall Stewart 	if ((inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
5158f8829a4aSRandall Stewart 	    (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE)) {
5159f8829a4aSRandall Stewart 		goto out;
5160f8829a4aSRandall Stewart 	}
516144b7479bSRandall Stewart 	if (so->so_rcv.sb_state & SBS_CANTRCVMORE) {
5162f8829a4aSRandall Stewart 		if (so->so_error) {
5163f8829a4aSRandall Stewart 			error = so->so_error;
516444b7479bSRandall Stewart 			if ((in_flags & MSG_PEEK) == 0)
516544b7479bSRandall Stewart 				so->so_error = 0;
51669f22f500SRandall Stewart 			goto out;
5167f8829a4aSRandall Stewart 		} else {
51689f22f500SRandall Stewart 			if (so->so_rcv.sb_cc == 0) {
5169c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOTCONN);
51707924093fSRandall Stewart 				/* indicate EOF */
51717924093fSRandall Stewart 				error = 0;
5172f8829a4aSRandall Stewart 				goto out;
5173f8829a4aSRandall Stewart 			}
51749f22f500SRandall Stewart 		}
51759f22f500SRandall Stewart 	}
5176f8829a4aSRandall Stewart 	if ((so->so_rcv.sb_cc <= held_length) && block_allowed) {
5177f8829a4aSRandall Stewart 		/* we need to wait for data */
5178f8829a4aSRandall Stewart 		if ((so->so_rcv.sb_cc == 0) &&
5179f8829a4aSRandall Stewart 		    ((inp->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
5180f8829a4aSRandall Stewart 		    (inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL))) {
5181f8829a4aSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_CONNECTED) == 0) {
5182f8829a4aSRandall Stewart 				/*
5183f8829a4aSRandall Stewart 				 * For active open side clear flags for
5184f8829a4aSRandall Stewart 				 * re-use passive open is blocked by
5185f8829a4aSRandall Stewart 				 * connect.
5186f8829a4aSRandall Stewart 				 */
5187f8829a4aSRandall Stewart 				if (inp->sctp_flags & SCTP_PCB_FLAGS_WAS_ABORTED) {
5188f8829a4aSRandall Stewart 					/*
5189f8829a4aSRandall Stewart 					 * You were aborted, passive side
5190f8829a4aSRandall Stewart 					 * always hits here
5191f8829a4aSRandall Stewart 					 */
5192c4739e2fSRandall Stewart 					SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ECONNRESET);
5193f8829a4aSRandall Stewart 					error = ECONNRESET;
5194f8829a4aSRandall Stewart 					/*
5195f8829a4aSRandall Stewart 					 * You get this once if you are
5196f8829a4aSRandall Stewart 					 * active open side
5197f8829a4aSRandall Stewart 					 */
5198f8829a4aSRandall Stewart 					if (!(inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
5199f8829a4aSRandall Stewart 						/*
5200f8829a4aSRandall Stewart 						 * Remove flag if on the
5201f8829a4aSRandall Stewart 						 * active open side
5202f8829a4aSRandall Stewart 						 */
5203f8829a4aSRandall Stewart 						inp->sctp_flags &= ~SCTP_PCB_FLAGS_WAS_ABORTED;
5204f8829a4aSRandall Stewart 					}
5205f8829a4aSRandall Stewart 				}
5206f8829a4aSRandall Stewart 				so->so_state &= ~(SS_ISCONNECTING |
5207f8829a4aSRandall Stewart 				    SS_ISDISCONNECTING |
5208f8829a4aSRandall Stewart 				    SS_ISCONFIRMING |
5209f8829a4aSRandall Stewart 				    SS_ISCONNECTED);
5210f8829a4aSRandall Stewart 				if (error == 0) {
5211f8829a4aSRandall Stewart 					if ((inp->sctp_flags & SCTP_PCB_FLAGS_WAS_CONNECTED) == 0) {
5212c4739e2fSRandall Stewart 						SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOTCONN);
5213f8829a4aSRandall Stewart 						error = ENOTCONN;
5214f8829a4aSRandall Stewart 					} else {
5215f8829a4aSRandall Stewart 						inp->sctp_flags &= ~SCTP_PCB_FLAGS_WAS_CONNECTED;
5216f8829a4aSRandall Stewart 					}
5217f8829a4aSRandall Stewart 				}
5218f8829a4aSRandall Stewart 				goto out;
5219f8829a4aSRandall Stewart 			}
5220f8829a4aSRandall Stewart 		}
5221f8829a4aSRandall Stewart 		error = sbwait(&so->so_rcv);
5222f8829a4aSRandall Stewart 		if (error) {
5223f8829a4aSRandall Stewart 			goto out;
5224f8829a4aSRandall Stewart 		}
5225f8829a4aSRandall Stewart 		held_length = 0;
5226f8829a4aSRandall Stewart 		goto restart_nosblocks;
5227f8829a4aSRandall Stewart 	} else if (so->so_rcv.sb_cc == 0) {
522844b7479bSRandall Stewart 		if (so->so_error) {
522944b7479bSRandall Stewart 			error = so->so_error;
523044b7479bSRandall Stewart 			if ((in_flags & MSG_PEEK) == 0)
523144b7479bSRandall Stewart 				so->so_error = 0;
523244b7479bSRandall Stewart 		} else {
523344b7479bSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
523444b7479bSRandall Stewart 			    (inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
523544b7479bSRandall Stewart 				if ((inp->sctp_flags & SCTP_PCB_FLAGS_CONNECTED) == 0) {
523644b7479bSRandall Stewart 					/*
523744b7479bSRandall Stewart 					 * For active open side clear flags
523844b7479bSRandall Stewart 					 * for re-use passive open is
523944b7479bSRandall Stewart 					 * blocked by connect.
524044b7479bSRandall Stewart 					 */
524144b7479bSRandall Stewart 					if (inp->sctp_flags & SCTP_PCB_FLAGS_WAS_ABORTED) {
524244b7479bSRandall Stewart 						/*
524344b7479bSRandall Stewart 						 * You were aborted, passive
524444b7479bSRandall Stewart 						 * side always hits here
524544b7479bSRandall Stewart 						 */
5246c4739e2fSRandall Stewart 						SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ECONNRESET);
524744b7479bSRandall Stewart 						error = ECONNRESET;
524844b7479bSRandall Stewart 						/*
524944b7479bSRandall Stewart 						 * You get this once if you
525044b7479bSRandall Stewart 						 * are active open side
525144b7479bSRandall Stewart 						 */
525244b7479bSRandall Stewart 						if (!(inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
525344b7479bSRandall Stewart 							/*
525444b7479bSRandall Stewart 							 * Remove flag if on
525544b7479bSRandall Stewart 							 * the active open
525644b7479bSRandall Stewart 							 * side
525744b7479bSRandall Stewart 							 */
525844b7479bSRandall Stewart 							inp->sctp_flags &= ~SCTP_PCB_FLAGS_WAS_ABORTED;
525944b7479bSRandall Stewart 						}
526044b7479bSRandall Stewart 					}
526144b7479bSRandall Stewart 					so->so_state &= ~(SS_ISCONNECTING |
526244b7479bSRandall Stewart 					    SS_ISDISCONNECTING |
526344b7479bSRandall Stewart 					    SS_ISCONFIRMING |
526444b7479bSRandall Stewart 					    SS_ISCONNECTED);
526544b7479bSRandall Stewart 					if (error == 0) {
526644b7479bSRandall Stewart 						if ((inp->sctp_flags & SCTP_PCB_FLAGS_WAS_CONNECTED) == 0) {
5267c4739e2fSRandall Stewart 							SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOTCONN);
526844b7479bSRandall Stewart 							error = ENOTCONN;
526944b7479bSRandall Stewart 						} else {
527044b7479bSRandall Stewart 							inp->sctp_flags &= ~SCTP_PCB_FLAGS_WAS_CONNECTED;
527144b7479bSRandall Stewart 						}
527244b7479bSRandall Stewart 					}
527344b7479bSRandall Stewart 					goto out;
527444b7479bSRandall Stewart 				}
527544b7479bSRandall Stewart 			}
5276c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EWOULDBLOCK);
5277f8829a4aSRandall Stewart 			error = EWOULDBLOCK;
527844b7479bSRandall Stewart 		}
5279f8829a4aSRandall Stewart 		goto out;
5280f8829a4aSRandall Stewart 	}
5281d06c82f1SRandall Stewart 	if (hold_sblock == 1) {
5282d06c82f1SRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
5283d06c82f1SRandall Stewart 		hold_sblock = 0;
5284d06c82f1SRandall Stewart 	}
5285f8829a4aSRandall Stewart 	/* we possibly have data we can read */
52863c503c28SRandall Stewart 	/* sa_ignore FREED_MEMORY */
5287f8829a4aSRandall Stewart 	control = TAILQ_FIRST(&inp->read_queue);
5288f8829a4aSRandall Stewart 	if (control == NULL) {
5289f8829a4aSRandall Stewart 		/*
5290f8829a4aSRandall Stewart 		 * This could be happening since the appender did the
5291f8829a4aSRandall Stewart 		 * increment but as not yet did the tailq insert onto the
5292f8829a4aSRandall Stewart 		 * read_queue
5293f8829a4aSRandall Stewart 		 */
5294f8829a4aSRandall Stewart 		if (hold_rlock == 0) {
5295f8829a4aSRandall Stewart 			SCTP_INP_READ_LOCK(inp);
5296f8829a4aSRandall Stewart 			hold_rlock = 1;
5297f8829a4aSRandall Stewart 		}
5298f8829a4aSRandall Stewart 		control = TAILQ_FIRST(&inp->read_queue);
5299f8829a4aSRandall Stewart 		if ((control == NULL) && (so->so_rcv.sb_cc != 0)) {
5300a5d547adSRandall Stewart #ifdef INVARIANTS
5301f8829a4aSRandall Stewart 			panic("Huh, its non zero and nothing on control?");
5302f8829a4aSRandall Stewart #endif
5303f8829a4aSRandall Stewart 			so->so_rcv.sb_cc = 0;
5304f8829a4aSRandall Stewart 		}
5305f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
5306f8829a4aSRandall Stewart 		hold_rlock = 0;
5307f8829a4aSRandall Stewart 		goto restart;
5308f8829a4aSRandall Stewart 	}
5309f8829a4aSRandall Stewart 	if ((control->length == 0) &&
5310f8829a4aSRandall Stewart 	    (control->do_not_ref_stcb)) {
5311f8829a4aSRandall Stewart 		/*
5312f8829a4aSRandall Stewart 		 * Clean up code for freeing assoc that left behind a
5313f8829a4aSRandall Stewart 		 * pdapi.. maybe a peer in EEOR that just closed after
5314f8829a4aSRandall Stewart 		 * sending and never indicated a EOR.
5315f8829a4aSRandall Stewart 		 */
5316f8829a4aSRandall Stewart 		if (hold_rlock == 0) {
5317f8829a4aSRandall Stewart 			hold_rlock = 1;
5318f8829a4aSRandall Stewart 			SCTP_INP_READ_LOCK(inp);
5319f8829a4aSRandall Stewart 		}
5320f8829a4aSRandall Stewart 		control->held_length = 0;
5321f8829a4aSRandall Stewart 		if (control->data) {
5322f8829a4aSRandall Stewart 			/* Hmm there is data here .. fix */
53234c9179adSRandall Stewart 			struct mbuf *m_tmp;
5324f8829a4aSRandall Stewart 			int cnt = 0;
5325f8829a4aSRandall Stewart 
53264c9179adSRandall Stewart 			m_tmp = control->data;
53274c9179adSRandall Stewart 			while (m_tmp) {
53284c9179adSRandall Stewart 				cnt += SCTP_BUF_LEN(m_tmp);
53294c9179adSRandall Stewart 				if (SCTP_BUF_NEXT(m_tmp) == NULL) {
53304c9179adSRandall Stewart 					control->tail_mbuf = m_tmp;
5331f8829a4aSRandall Stewart 					control->end_added = 1;
5332f8829a4aSRandall Stewart 				}
53334c9179adSRandall Stewart 				m_tmp = SCTP_BUF_NEXT(m_tmp);
5334f8829a4aSRandall Stewart 			}
5335f8829a4aSRandall Stewart 			control->length = cnt;
5336f8829a4aSRandall Stewart 		} else {
5337f8829a4aSRandall Stewart 			/* remove it */
5338f8829a4aSRandall Stewart 			TAILQ_REMOVE(&inp->read_queue, control, next);
5339f8829a4aSRandall Stewart 			/* Add back any hiddend data */
5340f8829a4aSRandall Stewart 			sctp_free_remote_addr(control->whoFrom);
5341f8829a4aSRandall Stewart 			sctp_free_a_readq(stcb, control);
5342f8829a4aSRandall Stewart 		}
5343f8829a4aSRandall Stewart 		if (hold_rlock) {
5344f8829a4aSRandall Stewart 			hold_rlock = 0;
5345f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
5346f8829a4aSRandall Stewart 		}
5347f8829a4aSRandall Stewart 		goto restart;
5348f8829a4aSRandall Stewart 	}
5349810ec536SMichael Tuexen 	if ((control->length == 0) &&
5350810ec536SMichael Tuexen 	    (control->end_added == 1)) {
5351810ec536SMichael Tuexen 		/*
5352810ec536SMichael Tuexen 		 * Do we also need to check for (control->pdapi_aborted ==
5353810ec536SMichael Tuexen 		 * 1)?
5354810ec536SMichael Tuexen 		 */
5355810ec536SMichael Tuexen 		if (hold_rlock == 0) {
5356810ec536SMichael Tuexen 			hold_rlock = 1;
5357810ec536SMichael Tuexen 			SCTP_INP_READ_LOCK(inp);
5358810ec536SMichael Tuexen 		}
5359810ec536SMichael Tuexen 		TAILQ_REMOVE(&inp->read_queue, control, next);
5360810ec536SMichael Tuexen 		if (control->data) {
5361810ec536SMichael Tuexen #ifdef INVARIANTS
5362810ec536SMichael Tuexen 			panic("control->data not null but control->length == 0");
5363810ec536SMichael Tuexen #else
5364810ec536SMichael Tuexen 			SCTP_PRINTF("Strange, data left in the control buffer. Cleaning up.\n");
5365810ec536SMichael Tuexen 			sctp_m_freem(control->data);
5366810ec536SMichael Tuexen 			control->data = NULL;
5367810ec536SMichael Tuexen #endif
5368810ec536SMichael Tuexen 		}
5369810ec536SMichael Tuexen 		if (control->aux_data) {
5370810ec536SMichael Tuexen 			sctp_m_free(control->aux_data);
5371810ec536SMichael Tuexen 			control->aux_data = NULL;
5372810ec536SMichael Tuexen 		}
5373810ec536SMichael Tuexen 		sctp_free_remote_addr(control->whoFrom);
5374810ec536SMichael Tuexen 		sctp_free_a_readq(stcb, control);
5375810ec536SMichael Tuexen 		if (hold_rlock) {
5376810ec536SMichael Tuexen 			hold_rlock = 0;
5377810ec536SMichael Tuexen 			SCTP_INP_READ_UNLOCK(inp);
5378810ec536SMichael Tuexen 		}
5379810ec536SMichael Tuexen 		goto restart;
5380810ec536SMichael Tuexen 	}
5381f8829a4aSRandall Stewart 	if (control->length == 0) {
5382f8829a4aSRandall Stewart 		if ((sctp_is_feature_on(inp, SCTP_PCB_FLAGS_FRAG_INTERLEAVE)) &&
5383f8829a4aSRandall Stewart 		    (filling_sinfo)) {
5384f8829a4aSRandall Stewart 			/* find a more suitable one then this */
5385f8829a4aSRandall Stewart 			ctl = TAILQ_NEXT(control, next);
5386f8829a4aSRandall Stewart 			while (ctl) {
53879a6142d8SRandall Stewart 				if ((ctl->stcb != control->stcb) && (ctl->length) &&
53889a6142d8SRandall Stewart 				    (ctl->some_taken ||
53896114cd96SRandall Stewart 				    (ctl->spec_flags & M_NOTIFICATION) ||
53909a6142d8SRandall Stewart 				    ((ctl->do_not_ref_stcb == 0) &&
53919a6142d8SRandall Stewart 				    (ctl->stcb->asoc.strmin[ctl->sinfo_stream].delivery_started == 0)))
53929a6142d8SRandall Stewart 				    ) {
53939a6142d8SRandall Stewart 					/*-
53949a6142d8SRandall Stewart 					 * If we have a different TCB next, and there is data
53959a6142d8SRandall Stewart 					 * present. If we have already taken some (pdapi), OR we can
53969a6142d8SRandall Stewart 					 * ref the tcb and no delivery as started on this stream, we
539717205eccSRandall Stewart 					 * take it. Note we allow a notification on a different
539817205eccSRandall Stewart 					 * assoc to be delivered..
53999a6142d8SRandall Stewart 					 */
54009a6142d8SRandall Stewart 					control = ctl;
54019a6142d8SRandall Stewart 					goto found_one;
54029a6142d8SRandall Stewart 				} else if ((sctp_is_feature_on(inp, SCTP_PCB_FLAGS_INTERLEAVE_STRMS)) &&
54039a6142d8SRandall Stewart 					    (ctl->length) &&
54049a6142d8SRandall Stewart 					    ((ctl->some_taken) ||
54059a6142d8SRandall Stewart 					    ((ctl->do_not_ref_stcb == 0) &&
540617205eccSRandall Stewart 					    ((ctl->spec_flags & M_NOTIFICATION) == 0) &&
5407b5c16493SMichael Tuexen 				    (ctl->stcb->asoc.strmin[ctl->sinfo_stream].delivery_started == 0)))) {
54089a6142d8SRandall Stewart 					/*-
54099a6142d8SRandall Stewart 					 * If we have the same tcb, and there is data present, and we
54109a6142d8SRandall Stewart 					 * have the strm interleave feature present. Then if we have
54119a6142d8SRandall Stewart 					 * taken some (pdapi) or we can refer to tht tcb AND we have
54129a6142d8SRandall Stewart 					 * not started a delivery for this stream, we can take it.
541317205eccSRandall Stewart 					 * Note we do NOT allow a notificaiton on the same assoc to
541417205eccSRandall Stewart 					 * be delivered.
54159a6142d8SRandall Stewart 					 */
5416f8829a4aSRandall Stewart 					control = ctl;
5417f8829a4aSRandall Stewart 					goto found_one;
5418f8829a4aSRandall Stewart 				}
5419f8829a4aSRandall Stewart 				ctl = TAILQ_NEXT(ctl, next);
5420f8829a4aSRandall Stewart 			}
5421f8829a4aSRandall Stewart 		}
5422f8829a4aSRandall Stewart 		/*
5423f8829a4aSRandall Stewart 		 * if we reach here, not suitable replacement is available
5424f8829a4aSRandall Stewart 		 * <or> fragment interleave is NOT on. So stuff the sb_cc
5425f8829a4aSRandall Stewart 		 * into the our held count, and its time to sleep again.
5426f8829a4aSRandall Stewart 		 */
5427f8829a4aSRandall Stewart 		held_length = so->so_rcv.sb_cc;
5428f8829a4aSRandall Stewart 		control->held_length = so->so_rcv.sb_cc;
5429f8829a4aSRandall Stewart 		goto restart;
5430f8829a4aSRandall Stewart 	}
5431f8829a4aSRandall Stewart 	/* Clear the held length since there is something to read */
5432f8829a4aSRandall Stewart 	control->held_length = 0;
5433f8829a4aSRandall Stewart 	if (hold_rlock) {
5434f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
5435f8829a4aSRandall Stewart 		hold_rlock = 0;
5436f8829a4aSRandall Stewart 	}
5437f8829a4aSRandall Stewart found_one:
5438f8829a4aSRandall Stewart 	/*
5439f8829a4aSRandall Stewart 	 * If we reach here, control has a some data for us to read off.
5440f8829a4aSRandall Stewart 	 * Note that stcb COULD be NULL.
5441f8829a4aSRandall Stewart 	 */
54429c04b296SRandall Stewart 	control->some_taken++;
5443f8829a4aSRandall Stewart 	if (hold_sblock) {
5444f8829a4aSRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
5445f8829a4aSRandall Stewart 		hold_sblock = 0;
5446f8829a4aSRandall Stewart 	}
5447f8829a4aSRandall Stewart 	stcb = control->stcb;
5448f8829a4aSRandall Stewart 	if (stcb) {
54490696e120SRandall Stewart 		if ((control->do_not_ref_stcb == 0) &&
54500696e120SRandall Stewart 		    (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED)) {
545150cec919SRandall Stewart 			if (freecnt_applied == 0)
5452f8829a4aSRandall Stewart 				stcb = NULL;
5453f8829a4aSRandall Stewart 		} else if (control->do_not_ref_stcb == 0) {
5454f8829a4aSRandall Stewart 			/* you can't free it on me please */
5455f8829a4aSRandall Stewart 			/*
5456f8829a4aSRandall Stewart 			 * The lock on the socket buffer protects us so the
5457f8829a4aSRandall Stewart 			 * free code will stop. But since we used the
5458f8829a4aSRandall Stewart 			 * socketbuf lock and the sender uses the tcb_lock
5459f8829a4aSRandall Stewart 			 * to increment, we need to use the atomic add to
5460f8829a4aSRandall Stewart 			 * the refcnt
5461f8829a4aSRandall Stewart 			 */
5462d55b0b1bSRandall Stewart 			if (freecnt_applied) {
5463d55b0b1bSRandall Stewart #ifdef INVARIANTS
5464207304d4SRandall Stewart 				panic("refcnt already incremented");
5465d55b0b1bSRandall Stewart #else
5466d55b0b1bSRandall Stewart 				printf("refcnt already incremented?\n");
5467d55b0b1bSRandall Stewart #endif
5468d55b0b1bSRandall Stewart 			} else {
546950cec919SRandall Stewart 				atomic_add_int(&stcb->asoc.refcnt, 1);
5470f8829a4aSRandall Stewart 				freecnt_applied = 1;
5471d55b0b1bSRandall Stewart 			}
5472f8829a4aSRandall Stewart 			/*
5473f8829a4aSRandall Stewart 			 * Setup to remember how much we have not yet told
5474f8829a4aSRandall Stewart 			 * the peer our rwnd has opened up. Note we grab the
5475f8829a4aSRandall Stewart 			 * value from the tcb from last time. Note too that
54760696e120SRandall Stewart 			 * sack sending clears this when a sack is sent,
5477f8829a4aSRandall Stewart 			 * which is fine. Once we hit the rwnd_req, we then
5478f8829a4aSRandall Stewart 			 * will go to the sctp_user_rcvd() that will not
5479f8829a4aSRandall Stewart 			 * lock until it KNOWs it MUST send a WUP-SACK.
5480f8829a4aSRandall Stewart 			 */
5481f8829a4aSRandall Stewart 			freed_so_far = stcb->freed_by_sorcv_sincelast;
5482f8829a4aSRandall Stewart 			stcb->freed_by_sorcv_sincelast = 0;
5483f8829a4aSRandall Stewart 		}
5484f8829a4aSRandall Stewart 	}
54856114cd96SRandall Stewart 	if (stcb &&
54866114cd96SRandall Stewart 	    ((control->spec_flags & M_NOTIFICATION) == 0) &&
54876114cd96SRandall Stewart 	    control->do_not_ref_stcb == 0) {
5488d06c82f1SRandall Stewart 		stcb->asoc.strmin[control->sinfo_stream].delivery_started = 1;
5489d06c82f1SRandall Stewart 	}
5490f8829a4aSRandall Stewart 	/* First lets get off the sinfo and sockaddr info */
5491f8829a4aSRandall Stewart 	if ((sinfo) && filling_sinfo) {
5492f8829a4aSRandall Stewart 		memcpy(sinfo, control, sizeof(struct sctp_nonpad_sndrcvinfo));
5493f8829a4aSRandall Stewart 		nxt = TAILQ_NEXT(control, next);
5494*e2e7c62eSMichael Tuexen 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXT_RCVINFO) ||
5495*e2e7c62eSMichael Tuexen 		    sctp_is_feature_on(inp, SCTP_PCB_FLAGS_RECVNXTINFO)) {
5496f8829a4aSRandall Stewart 			struct sctp_extrcvinfo *s_extra;
5497f8829a4aSRandall Stewart 
5498f8829a4aSRandall Stewart 			s_extra = (struct sctp_extrcvinfo *)sinfo;
54999a6142d8SRandall Stewart 			if ((nxt) &&
55009a6142d8SRandall Stewart 			    (nxt->length)) {
55019a6142d8SRandall Stewart 				s_extra->sreinfo_next_flags = SCTP_NEXT_MSG_AVAIL;
5502f8829a4aSRandall Stewart 				if (nxt->sinfo_flags & SCTP_UNORDERED) {
55039a6142d8SRandall Stewart 					s_extra->sreinfo_next_flags |= SCTP_NEXT_MSG_IS_UNORDERED;
5504f8829a4aSRandall Stewart 				}
5505f42a358aSRandall Stewart 				if (nxt->spec_flags & M_NOTIFICATION) {
55069a6142d8SRandall Stewart 					s_extra->sreinfo_next_flags |= SCTP_NEXT_MSG_IS_NOTIFICATION;
5507f42a358aSRandall Stewart 				}
55089a6142d8SRandall Stewart 				s_extra->sreinfo_next_aid = nxt->sinfo_assoc_id;
55099a6142d8SRandall Stewart 				s_extra->sreinfo_next_length = nxt->length;
55109a6142d8SRandall Stewart 				s_extra->sreinfo_next_ppid = nxt->sinfo_ppid;
55119a6142d8SRandall Stewart 				s_extra->sreinfo_next_stream = nxt->sinfo_stream;
5512f8829a4aSRandall Stewart 				if (nxt->tail_mbuf != NULL) {
5513139bc87fSRandall Stewart 					if (nxt->end_added) {
55149a6142d8SRandall Stewart 						s_extra->sreinfo_next_flags |= SCTP_NEXT_MSG_ISCOMPLETE;
5515f8829a4aSRandall Stewart 					}
5516f8829a4aSRandall Stewart 				}
5517f8829a4aSRandall Stewart 			} else {
5518f8829a4aSRandall Stewart 				/*
5519f8829a4aSRandall Stewart 				 * we explicitly 0 this, since the memcpy
5520f8829a4aSRandall Stewart 				 * got some other things beyond the older
5521f8829a4aSRandall Stewart 				 * sinfo_ that is on the control's structure
5522f8829a4aSRandall Stewart 				 * :-D
5523f8829a4aSRandall Stewart 				 */
55249a6142d8SRandall Stewart 				nxt = NULL;
55259a6142d8SRandall Stewart 				s_extra->sreinfo_next_flags = SCTP_NO_NEXT_MSG;
55269a6142d8SRandall Stewart 				s_extra->sreinfo_next_aid = 0;
55279a6142d8SRandall Stewart 				s_extra->sreinfo_next_length = 0;
55289a6142d8SRandall Stewart 				s_extra->sreinfo_next_ppid = 0;
55299a6142d8SRandall Stewart 				s_extra->sreinfo_next_stream = 0;
5530f8829a4aSRandall Stewart 			}
5531f8829a4aSRandall Stewart 		}
5532f8829a4aSRandall Stewart 		/*
5533f8829a4aSRandall Stewart 		 * update off the real current cum-ack, if we have an stcb.
5534f8829a4aSRandall Stewart 		 */
55350696e120SRandall Stewart 		if ((control->do_not_ref_stcb == 0) && stcb)
5536f8829a4aSRandall Stewart 			sinfo->sinfo_cumtsn = stcb->asoc.cumulative_tsn;
5537f8829a4aSRandall Stewart 		/*
5538f8829a4aSRandall Stewart 		 * mask off the high bits, we keep the actual chunk bits in
5539f8829a4aSRandall Stewart 		 * there.
5540f8829a4aSRandall Stewart 		 */
5541f8829a4aSRandall Stewart 		sinfo->sinfo_flags &= 0x00ff;
55425f26a41dSRandall Stewart 		if ((control->sinfo_flags >> 8) & SCTP_DATA_UNORDERED) {
55435f26a41dSRandall Stewart 			sinfo->sinfo_flags |= SCTP_UNORDERED;
55445f26a41dSRandall Stewart 		}
5545f8829a4aSRandall Stewart 	}
554618e198d3SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
554718e198d3SRandall Stewart 	{
554818e198d3SRandall Stewart 		int index, newindex;
554918e198d3SRandall Stewart 		struct sctp_pcbtsn_rlog *entry;
555018e198d3SRandall Stewart 
555118e198d3SRandall Stewart 		do {
555218e198d3SRandall Stewart 			index = inp->readlog_index;
555318e198d3SRandall Stewart 			newindex = index + 1;
555418e198d3SRandall Stewart 			if (newindex >= SCTP_READ_LOG_SIZE) {
555518e198d3SRandall Stewart 				newindex = 0;
555618e198d3SRandall Stewart 			}
555718e198d3SRandall Stewart 		} while (atomic_cmpset_int(&inp->readlog_index, index, newindex) == 0);
555818e198d3SRandall Stewart 		entry = &inp->readlog[index];
555918e198d3SRandall Stewart 		entry->vtag = control->sinfo_assoc_id;
556018e198d3SRandall Stewart 		entry->strm = control->sinfo_stream;
556118e198d3SRandall Stewart 		entry->seq = control->sinfo_ssn;
556218e198d3SRandall Stewart 		entry->sz = control->length;
556318e198d3SRandall Stewart 		entry->flgs = control->sinfo_flags;
556418e198d3SRandall Stewart 	}
556518e198d3SRandall Stewart #endif
5566f8829a4aSRandall Stewart 	if (fromlen && from) {
5567f8829a4aSRandall Stewart 		struct sockaddr *to;
5568f8829a4aSRandall Stewart 
556942551e99SRandall Stewart #ifdef INET
5570baf3da66SRandall Stewart 		cp_len = min((size_t)fromlen, (size_t)control->whoFrom->ro._l_addr.sin.sin_len);
5571f8829a4aSRandall Stewart 		memcpy(from, &control->whoFrom->ro._l_addr, cp_len);
5572f8829a4aSRandall Stewart 		((struct sockaddr_in *)from)->sin_port = control->port_from;
5573f8829a4aSRandall Stewart #else
5574f8829a4aSRandall Stewart 		/* No AF_INET use AF_INET6 */
5575baf3da66SRandall Stewart 		cp_len = min((size_t)fromlen, (size_t)control->whoFrom->ro._l_addr.sin6.sin6_len);
5576f8829a4aSRandall Stewart 		memcpy(from, &control->whoFrom->ro._l_addr, cp_len);
5577f8829a4aSRandall Stewart 		((struct sockaddr_in6 *)from)->sin6_port = control->port_from;
5578f8829a4aSRandall Stewart #endif
5579f8829a4aSRandall Stewart 
5580f8829a4aSRandall Stewart 		to = from;
558142551e99SRandall Stewart #if defined(INET) && defined(INET6)
55825e2c2d87SRandall Stewart 		if ((sctp_is_feature_on(inp, SCTP_PCB_FLAGS_NEEDS_MAPPED_V4)) &&
5583f8829a4aSRandall Stewart 		    (to->sa_family == AF_INET) &&
5584f8829a4aSRandall Stewart 		    ((size_t)fromlen >= sizeof(struct sockaddr_in6))) {
5585f8829a4aSRandall Stewart 			struct sockaddr_in *sin;
5586f8829a4aSRandall Stewart 			struct sockaddr_in6 sin6;
5587f8829a4aSRandall Stewart 
5588f8829a4aSRandall Stewart 			sin = (struct sockaddr_in *)to;
5589f8829a4aSRandall Stewart 			bzero(&sin6, sizeof(sin6));
5590f8829a4aSRandall Stewart 			sin6.sin6_family = AF_INET6;
5591f8829a4aSRandall Stewart 			sin6.sin6_len = sizeof(struct sockaddr_in6);
5592d6af161aSRandall Stewart 			sin6.sin6_addr.s6_addr32[2] = htonl(0xffff);
5593f8829a4aSRandall Stewart 			bcopy(&sin->sin_addr,
5594d6af161aSRandall Stewart 			    &sin6.sin6_addr.s6_addr32[3],
5595d6af161aSRandall Stewart 			    sizeof(sin6.sin6_addr.s6_addr32[3]));
5596f8829a4aSRandall Stewart 			sin6.sin6_port = sin->sin_port;
5597f8829a4aSRandall Stewart 			memcpy(from, (caddr_t)&sin6, sizeof(sin6));
5598f8829a4aSRandall Stewart 		}
5599f8829a4aSRandall Stewart #endif
560042551e99SRandall Stewart #if defined(INET6)
5601f8829a4aSRandall Stewart 		{
5602f8829a4aSRandall Stewart 			struct sockaddr_in6 lsa6, *to6;
5603f8829a4aSRandall Stewart 
5604f8829a4aSRandall Stewart 			to6 = (struct sockaddr_in6 *)to;
5605f8829a4aSRandall Stewart 			sctp_recover_scope_mac(to6, (&lsa6));
5606f8829a4aSRandall Stewart 		}
5607f8829a4aSRandall Stewart #endif
5608f8829a4aSRandall Stewart 	}
5609f8829a4aSRandall Stewart 	/* now copy out what data we can */
5610f8829a4aSRandall Stewart 	if (mp == NULL) {
5611f8829a4aSRandall Stewart 		/* copy out each mbuf in the chain up to length */
5612f8829a4aSRandall Stewart get_more_data:
5613f8829a4aSRandall Stewart 		m = control->data;
5614f8829a4aSRandall Stewart 		while (m) {
5615f8829a4aSRandall Stewart 			/* Move out all we can */
5616f8829a4aSRandall Stewart 			cp_len = (int)uio->uio_resid;
5617139bc87fSRandall Stewart 			my_len = (int)SCTP_BUF_LEN(m);
5618f8829a4aSRandall Stewart 			if (cp_len > my_len) {
5619f8829a4aSRandall Stewart 				/* not enough in this buf */
5620f8829a4aSRandall Stewart 				cp_len = my_len;
5621f8829a4aSRandall Stewart 			}
5622f8829a4aSRandall Stewart 			if (hold_rlock) {
5623f8829a4aSRandall Stewart 				SCTP_INP_READ_UNLOCK(inp);
5624f8829a4aSRandall Stewart 				hold_rlock = 0;
5625f8829a4aSRandall Stewart 			}
5626f8829a4aSRandall Stewart 			if (cp_len > 0)
5627f8829a4aSRandall Stewart 				error = uiomove(mtod(m, char *), cp_len, uio);
5628f8829a4aSRandall Stewart 			/* re-read */
5629f8829a4aSRandall Stewart 			if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
5630f8829a4aSRandall Stewart 				goto release;
5631f8829a4aSRandall Stewart 			}
56320696e120SRandall Stewart 			if ((control->do_not_ref_stcb == 0) && stcb &&
5633f8829a4aSRandall Stewart 			    stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
5634f8829a4aSRandall Stewart 				no_rcv_needed = 1;
5635f8829a4aSRandall Stewart 			}
5636f8829a4aSRandall Stewart 			if (error) {
5637f8829a4aSRandall Stewart 				/* error we are out of here */
5638f8829a4aSRandall Stewart 				goto release;
5639f8829a4aSRandall Stewart 			}
5640139bc87fSRandall Stewart 			if ((SCTP_BUF_NEXT(m) == NULL) &&
5641139bc87fSRandall Stewart 			    (cp_len >= SCTP_BUF_LEN(m)) &&
5642f8829a4aSRandall Stewart 			    ((control->end_added == 0) ||
56430696e120SRandall Stewart 			    (control->end_added &&
56440696e120SRandall Stewart 			    (TAILQ_NEXT(control, next) == NULL)))
5645f8829a4aSRandall Stewart 			    ) {
5646f8829a4aSRandall Stewart 				SCTP_INP_READ_LOCK(inp);
5647f8829a4aSRandall Stewart 				hold_rlock = 1;
5648f8829a4aSRandall Stewart 			}
5649139bc87fSRandall Stewart 			if (cp_len == SCTP_BUF_LEN(m)) {
5650139bc87fSRandall Stewart 				if ((SCTP_BUF_NEXT(m) == NULL) &&
5651139bc87fSRandall Stewart 				    (control->end_added)) {
5652f8829a4aSRandall Stewart 					out_flags |= MSG_EOR;
565352129fcdSRandall Stewart 					if ((control->do_not_ref_stcb == 0) &&
565452129fcdSRandall Stewart 					    (control->stcb != NULL) &&
565552129fcdSRandall Stewart 					    ((control->spec_flags & M_NOTIFICATION) == 0))
5656ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
5657f8829a4aSRandall Stewart 				}
5658139bc87fSRandall Stewart 				if (control->spec_flags & M_NOTIFICATION) {
5659f8829a4aSRandall Stewart 					out_flags |= MSG_NOTIFICATION;
5660f8829a4aSRandall Stewart 				}
5661f8829a4aSRandall Stewart 				/* we ate up the mbuf */
5662f8829a4aSRandall Stewart 				if (in_flags & MSG_PEEK) {
5663f8829a4aSRandall Stewart 					/* just looking */
5664139bc87fSRandall Stewart 					m = SCTP_BUF_NEXT(m);
5665f8829a4aSRandall Stewart 					copied_so_far += cp_len;
5666f8829a4aSRandall Stewart 				} else {
5667f8829a4aSRandall Stewart 					/* dispose of the mbuf */
5668b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5669f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv,
5670139bc87fSRandall Stewart 						    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
567180fefe0aSRandall Stewart 					}
5672f8829a4aSRandall Stewart 					sctp_sbfree(control, stcb, &so->so_rcv, m);
5673b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5674f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv,
5675f8829a4aSRandall Stewart 						    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
567680fefe0aSRandall Stewart 					}
5677f8829a4aSRandall Stewart 					copied_so_far += cp_len;
5678f8829a4aSRandall Stewart 					freed_so_far += cp_len;
5679c4739e2fSRandall Stewart 					freed_so_far += MSIZE;
568018e198d3SRandall Stewart 					atomic_subtract_int(&control->length, cp_len);
5681f8829a4aSRandall Stewart 					control->data = sctp_m_free(m);
5682f8829a4aSRandall Stewart 					m = control->data;
5683f8829a4aSRandall Stewart 					/*
5684f8829a4aSRandall Stewart 					 * been through it all, must hold sb
5685f8829a4aSRandall Stewart 					 * lock ok to null tail
5686f8829a4aSRandall Stewart 					 */
5687f8829a4aSRandall Stewart 					if (control->data == NULL) {
5688a5d547adSRandall Stewart #ifdef INVARIANTS
5689f8829a4aSRandall Stewart 						if ((control->end_added == 0) ||
5690f8829a4aSRandall Stewart 						    (TAILQ_NEXT(control, next) == NULL)) {
5691f8829a4aSRandall Stewart 							/*
5692f8829a4aSRandall Stewart 							 * If the end is not
5693f8829a4aSRandall Stewart 							 * added, OR the
5694f8829a4aSRandall Stewart 							 * next is NOT null
5695f8829a4aSRandall Stewart 							 * we MUST have the
5696f8829a4aSRandall Stewart 							 * lock.
5697f8829a4aSRandall Stewart 							 */
5698f8829a4aSRandall Stewart 							if (mtx_owned(&inp->inp_rdata_mtx) == 0) {
5699f8829a4aSRandall Stewart 								panic("Hmm we don't own the lock?");
5700f8829a4aSRandall Stewart 							}
5701f8829a4aSRandall Stewart 						}
5702f8829a4aSRandall Stewart #endif
5703f8829a4aSRandall Stewart 						control->tail_mbuf = NULL;
5704a5d547adSRandall Stewart #ifdef INVARIANTS
5705f8829a4aSRandall Stewart 						if ((control->end_added) && ((out_flags & MSG_EOR) == 0)) {
5706f8829a4aSRandall Stewart 							panic("end_added, nothing left and no MSG_EOR");
5707f8829a4aSRandall Stewart 						}
5708f8829a4aSRandall Stewart #endif
5709f8829a4aSRandall Stewart 					}
5710f8829a4aSRandall Stewart 				}
5711f8829a4aSRandall Stewart 			} else {
5712f8829a4aSRandall Stewart 				/* Do we need to trim the mbuf? */
5713139bc87fSRandall Stewart 				if (control->spec_flags & M_NOTIFICATION) {
5714f8829a4aSRandall Stewart 					out_flags |= MSG_NOTIFICATION;
5715f8829a4aSRandall Stewart 				}
5716f8829a4aSRandall Stewart 				if ((in_flags & MSG_PEEK) == 0) {
5717139bc87fSRandall Stewart 					SCTP_BUF_RESV_UF(m, cp_len);
5718139bc87fSRandall Stewart 					SCTP_BUF_LEN(m) -= cp_len;
5719b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5720f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, cp_len);
572180fefe0aSRandall Stewart 					}
5722f8829a4aSRandall Stewart 					atomic_subtract_int(&so->so_rcv.sb_cc, cp_len);
57230696e120SRandall Stewart 					if ((control->do_not_ref_stcb == 0) &&
57240696e120SRandall Stewart 					    stcb) {
5725f8829a4aSRandall Stewart 						atomic_subtract_int(&stcb->asoc.sb_cc, cp_len);
5726f8829a4aSRandall Stewart 					}
5727f8829a4aSRandall Stewart 					copied_so_far += cp_len;
5728f8829a4aSRandall Stewart 					freed_so_far += cp_len;
5729c4739e2fSRandall Stewart 					freed_so_far += MSIZE;
5730b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5731f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv, control->do_not_ref_stcb ? NULL : stcb,
5732f8829a4aSRandall Stewart 						    SCTP_LOG_SBRESULT, 0);
573380fefe0aSRandall Stewart 					}
573418e198d3SRandall Stewart 					atomic_subtract_int(&control->length, cp_len);
5735f8829a4aSRandall Stewart 				} else {
5736f8829a4aSRandall Stewart 					copied_so_far += cp_len;
5737f8829a4aSRandall Stewart 				}
5738f8829a4aSRandall Stewart 			}
5739d61a0ae0SRandall Stewart 			if ((out_flags & MSG_EOR) || (uio->uio_resid == 0)) {
5740f8829a4aSRandall Stewart 				break;
5741f8829a4aSRandall Stewart 			}
5742f8829a4aSRandall Stewart 			if (((stcb) && (in_flags & MSG_PEEK) == 0) &&
5743f8829a4aSRandall Stewart 			    (control->do_not_ref_stcb == 0) &&
5744f8829a4aSRandall Stewart 			    (freed_so_far >= rwnd_req)) {
5745f8829a4aSRandall Stewart 				sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
5746f8829a4aSRandall Stewart 			}
5747f8829a4aSRandall Stewart 		}		/* end while(m) */
5748f8829a4aSRandall Stewart 		/*
5749f8829a4aSRandall Stewart 		 * At this point we have looked at it all and we either have
5750f8829a4aSRandall Stewart 		 * a MSG_EOR/or read all the user wants... <OR>
5751f8829a4aSRandall Stewart 		 * control->length == 0.
5752f8829a4aSRandall Stewart 		 */
5753d61a0ae0SRandall Stewart 		if ((out_flags & MSG_EOR) && ((in_flags & MSG_PEEK) == 0)) {
5754f8829a4aSRandall Stewart 			/* we are done with this control */
5755f8829a4aSRandall Stewart 			if (control->length == 0) {
5756f8829a4aSRandall Stewart 				if (control->data) {
5757a5d547adSRandall Stewart #ifdef INVARIANTS
5758f8829a4aSRandall Stewart 					panic("control->data not null at read eor?");
5759f8829a4aSRandall Stewart #else
5760ad81507eSRandall Stewart 					SCTP_PRINTF("Strange, data left in the control buffer .. invarients would panic?\n");
5761f8829a4aSRandall Stewart 					sctp_m_freem(control->data);
5762f8829a4aSRandall Stewart 					control->data = NULL;
5763f8829a4aSRandall Stewart #endif
5764f8829a4aSRandall Stewart 				}
5765f8829a4aSRandall Stewart 		done_with_control:
5766f8829a4aSRandall Stewart 				if (TAILQ_NEXT(control, next) == NULL) {
5767f8829a4aSRandall Stewart 					/*
5768f8829a4aSRandall Stewart 					 * If we don't have a next we need a
5769b201f536SRandall Stewart 					 * lock, if there is a next
5770b201f536SRandall Stewart 					 * interrupt is filling ahead of us
5771b201f536SRandall Stewart 					 * and we don't need a lock to
5772b201f536SRandall Stewart 					 * remove this guy (which is the
5773b201f536SRandall Stewart 					 * head of the queue).
5774f8829a4aSRandall Stewart 					 */
5775f8829a4aSRandall Stewart 					if (hold_rlock == 0) {
5776f8829a4aSRandall Stewart 						SCTP_INP_READ_LOCK(inp);
5777f8829a4aSRandall Stewart 						hold_rlock = 1;
5778f8829a4aSRandall Stewart 					}
5779f8829a4aSRandall Stewart 				}
5780f8829a4aSRandall Stewart 				TAILQ_REMOVE(&inp->read_queue, control, next);
5781f8829a4aSRandall Stewart 				/* Add back any hiddend data */
5782f8829a4aSRandall Stewart 				if (control->held_length) {
5783f8829a4aSRandall Stewart 					held_length = 0;
5784f8829a4aSRandall Stewart 					control->held_length = 0;
5785f8829a4aSRandall Stewart 					wakeup_read_socket = 1;
5786f8829a4aSRandall Stewart 				}
578717205eccSRandall Stewart 				if (control->aux_data) {
578817205eccSRandall Stewart 					sctp_m_free(control->aux_data);
578917205eccSRandall Stewart 					control->aux_data = NULL;
579017205eccSRandall Stewart 				}
5791f8829a4aSRandall Stewart 				no_rcv_needed = control->do_not_ref_stcb;
5792f8829a4aSRandall Stewart 				sctp_free_remote_addr(control->whoFrom);
5793f8829a4aSRandall Stewart 				control->data = NULL;
5794f8829a4aSRandall Stewart 				sctp_free_a_readq(stcb, control);
5795f8829a4aSRandall Stewart 				control = NULL;
57960696e120SRandall Stewart 				if ((freed_so_far >= rwnd_req) &&
57970696e120SRandall Stewart 				    (no_rcv_needed == 0))
5798f8829a4aSRandall Stewart 					sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
5799f8829a4aSRandall Stewart 
5800f8829a4aSRandall Stewart 			} else {
5801f8829a4aSRandall Stewart 				/*
5802f8829a4aSRandall Stewart 				 * The user did not read all of this
5803f8829a4aSRandall Stewart 				 * message, turn off the returned MSG_EOR
5804f8829a4aSRandall Stewart 				 * since we are leaving more behind on the
5805f8829a4aSRandall Stewart 				 * control to read.
5806f8829a4aSRandall Stewart 				 */
5807a5d547adSRandall Stewart #ifdef INVARIANTS
58080696e120SRandall Stewart 				if (control->end_added &&
58090696e120SRandall Stewart 				    (control->data == NULL) &&
5810f8829a4aSRandall Stewart 				    (control->tail_mbuf == NULL)) {
5811f8829a4aSRandall Stewart 					panic("Gak, control->length is corrupt?");
5812f8829a4aSRandall Stewart 				}
5813f8829a4aSRandall Stewart #endif
5814f8829a4aSRandall Stewart 				no_rcv_needed = control->do_not_ref_stcb;
5815f8829a4aSRandall Stewart 				out_flags &= ~MSG_EOR;
5816f8829a4aSRandall Stewart 			}
5817f8829a4aSRandall Stewart 		}
5818f8829a4aSRandall Stewart 		if (out_flags & MSG_EOR) {
5819f8829a4aSRandall Stewart 			goto release;
5820f8829a4aSRandall Stewart 		}
5821f8829a4aSRandall Stewart 		if ((uio->uio_resid == 0) ||
5822f8829a4aSRandall Stewart 		    ((in_eeor_mode) && (copied_so_far >= max(so->so_rcv.sb_lowat, 1)))
5823f8829a4aSRandall Stewart 		    ) {
5824f8829a4aSRandall Stewart 			goto release;
5825f8829a4aSRandall Stewart 		}
5826f8829a4aSRandall Stewart 		/*
5827f8829a4aSRandall Stewart 		 * If I hit here the receiver wants more and this message is
5828f8829a4aSRandall Stewart 		 * NOT done (pd-api). So two questions. Can we block? if not
5829f8829a4aSRandall Stewart 		 * we are done. Did the user NOT set MSG_WAITALL?
5830f8829a4aSRandall Stewart 		 */
5831f8829a4aSRandall Stewart 		if (block_allowed == 0) {
5832f8829a4aSRandall Stewart 			goto release;
5833f8829a4aSRandall Stewart 		}
5834f8829a4aSRandall Stewart 		/*
5835f8829a4aSRandall Stewart 		 * We need to wait for more data a few things: - We don't
5836f8829a4aSRandall Stewart 		 * sbunlock() so we don't get someone else reading. - We
5837f8829a4aSRandall Stewart 		 * must be sure to account for the case where what is added
5838f8829a4aSRandall Stewart 		 * is NOT to our control when we wakeup.
5839f8829a4aSRandall Stewart 		 */
5840f8829a4aSRandall Stewart 
5841f8829a4aSRandall Stewart 		/*
5842f8829a4aSRandall Stewart 		 * Do we need to tell the transport a rwnd update might be
5843f8829a4aSRandall Stewart 		 * needed before we go to sleep?
5844f8829a4aSRandall Stewart 		 */
5845f8829a4aSRandall Stewart 		if (((stcb) && (in_flags & MSG_PEEK) == 0) &&
5846f8829a4aSRandall Stewart 		    ((freed_so_far >= rwnd_req) &&
5847f8829a4aSRandall Stewart 		    (control->do_not_ref_stcb == 0) &&
5848f8829a4aSRandall Stewart 		    (no_rcv_needed == 0))) {
5849f8829a4aSRandall Stewart 			sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
5850f8829a4aSRandall Stewart 		}
5851f8829a4aSRandall Stewart wait_some_more:
585244b7479bSRandall Stewart 		if (so->so_rcv.sb_state & SBS_CANTRCVMORE) {
5853f8829a4aSRandall Stewart 			goto release;
5854f8829a4aSRandall Stewart 		}
5855f8829a4aSRandall Stewart 		if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE)
5856f8829a4aSRandall Stewart 			goto release;
5857f8829a4aSRandall Stewart 
5858f8829a4aSRandall Stewart 		if (hold_rlock == 1) {
5859f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
5860f8829a4aSRandall Stewart 			hold_rlock = 0;
5861f8829a4aSRandall Stewart 		}
5862f8829a4aSRandall Stewart 		if (hold_sblock == 0) {
5863f8829a4aSRandall Stewart 			SOCKBUF_LOCK(&so->so_rcv);
5864f8829a4aSRandall Stewart 			hold_sblock = 1;
5865f8829a4aSRandall Stewart 		}
5866851b7298SRandall Stewart 		if ((copied_so_far) && (control->length == 0) &&
5867b5c16493SMichael Tuexen 		    (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_FRAG_INTERLEAVE))) {
5868851b7298SRandall Stewart 			goto release;
5869851b7298SRandall Stewart 		}
5870f8829a4aSRandall Stewart 		if (so->so_rcv.sb_cc <= control->held_length) {
5871f8829a4aSRandall Stewart 			error = sbwait(&so->so_rcv);
5872f8829a4aSRandall Stewart 			if (error) {
5873f8829a4aSRandall Stewart 				goto release;
5874f8829a4aSRandall Stewart 			}
5875f8829a4aSRandall Stewart 			control->held_length = 0;
5876f8829a4aSRandall Stewart 		}
5877f8829a4aSRandall Stewart 		if (hold_sblock) {
5878f8829a4aSRandall Stewart 			SOCKBUF_UNLOCK(&so->so_rcv);
5879f8829a4aSRandall Stewart 			hold_sblock = 0;
5880f8829a4aSRandall Stewart 		}
5881f8829a4aSRandall Stewart 		if (control->length == 0) {
5882f8829a4aSRandall Stewart 			/* still nothing here */
5883f8829a4aSRandall Stewart 			if (control->end_added == 1) {
5884f8829a4aSRandall Stewart 				/* he aborted, or is done i.e.did a shutdown */
5885f8829a4aSRandall Stewart 				out_flags |= MSG_EOR;
58869a6142d8SRandall Stewart 				if (control->pdapi_aborted) {
58876114cd96SRandall Stewart 					if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
5888ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
58899a6142d8SRandall Stewart 
589003b0b021SRandall Stewart 					out_flags |= MSG_TRUNC;
58919a6142d8SRandall Stewart 				} else {
58926114cd96SRandall Stewart 					if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
5893ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
58949a6142d8SRandall Stewart 				}
5895f8829a4aSRandall Stewart 				goto done_with_control;
5896f8829a4aSRandall Stewart 			}
5897f8829a4aSRandall Stewart 			if (so->so_rcv.sb_cc > held_length) {
5898f8829a4aSRandall Stewart 				control->held_length = so->so_rcv.sb_cc;
5899f8829a4aSRandall Stewart 				held_length = 0;
5900f8829a4aSRandall Stewart 			}
5901f8829a4aSRandall Stewart 			goto wait_some_more;
5902f8829a4aSRandall Stewart 		} else if (control->data == NULL) {
590350cec919SRandall Stewart 			/*
590450cec919SRandall Stewart 			 * we must re-sync since data is probably being
590550cec919SRandall Stewart 			 * added
590650cec919SRandall Stewart 			 */
590750cec919SRandall Stewart 			SCTP_INP_READ_LOCK(inp);
590850cec919SRandall Stewart 			if ((control->length > 0) && (control->data == NULL)) {
590950cec919SRandall Stewart 				/*
591050cec919SRandall Stewart 				 * big trouble.. we have the lock and its
591150cec919SRandall Stewart 				 * corrupt?
591250cec919SRandall Stewart 				 */
59139c04b296SRandall Stewart #ifdef INVARIANTS
5914f8829a4aSRandall Stewart 				panic("Impossible data==NULL length !=0");
59159c04b296SRandall Stewart #endif
59169c04b296SRandall Stewart 				out_flags |= MSG_EOR;
59179c04b296SRandall Stewart 				out_flags |= MSG_TRUNC;
59189c04b296SRandall Stewart 				control->length = 0;
59199c04b296SRandall Stewart 				SCTP_INP_READ_UNLOCK(inp);
59209c04b296SRandall Stewart 				goto done_with_control;
5921f8829a4aSRandall Stewart 			}
592250cec919SRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
592350cec919SRandall Stewart 			/* We will fall around to get more data */
592450cec919SRandall Stewart 		}
5925f8829a4aSRandall Stewart 		goto get_more_data;
5926f8829a4aSRandall Stewart 	} else {
592717205eccSRandall Stewart 		/*-
592817205eccSRandall Stewart 		 * Give caller back the mbuf chain,
592917205eccSRandall Stewart 		 * store in uio_resid the length
5930f8829a4aSRandall Stewart 		 */
593117205eccSRandall Stewart 		wakeup_read_socket = 0;
5932f8829a4aSRandall Stewart 		if ((control->end_added == 0) ||
5933f8829a4aSRandall Stewart 		    (TAILQ_NEXT(control, next) == NULL)) {
5934f8829a4aSRandall Stewart 			/* Need to get rlock */
5935f8829a4aSRandall Stewart 			if (hold_rlock == 0) {
5936f8829a4aSRandall Stewart 				SCTP_INP_READ_LOCK(inp);
5937f8829a4aSRandall Stewart 				hold_rlock = 1;
5938f8829a4aSRandall Stewart 			}
5939f8829a4aSRandall Stewart 		}
5940139bc87fSRandall Stewart 		if (control->end_added) {
5941f8829a4aSRandall Stewart 			out_flags |= MSG_EOR;
59426114cd96SRandall Stewart 			if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
5943ee7f9857SRandall Stewart 				control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
5944f8829a4aSRandall Stewart 		}
5945139bc87fSRandall Stewart 		if (control->spec_flags & M_NOTIFICATION) {
5946f8829a4aSRandall Stewart 			out_flags |= MSG_NOTIFICATION;
5947f8829a4aSRandall Stewart 		}
594817205eccSRandall Stewart 		uio->uio_resid = control->length;
5949f8829a4aSRandall Stewart 		*mp = control->data;
5950f8829a4aSRandall Stewart 		m = control->data;
5951f8829a4aSRandall Stewart 		while (m) {
5952b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5953f8829a4aSRandall Stewart 				sctp_sblog(&so->so_rcv,
5954139bc87fSRandall Stewart 				    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
595580fefe0aSRandall Stewart 			}
5956f8829a4aSRandall Stewart 			sctp_sbfree(control, stcb, &so->so_rcv, m);
5957139bc87fSRandall Stewart 			freed_so_far += SCTP_BUF_LEN(m);
5958c4739e2fSRandall Stewart 			freed_so_far += MSIZE;
5959b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5960f8829a4aSRandall Stewart 				sctp_sblog(&so->so_rcv,
5961f8829a4aSRandall Stewart 				    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
596280fefe0aSRandall Stewart 			}
5963139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
5964f8829a4aSRandall Stewart 		}
5965f8829a4aSRandall Stewart 		control->data = control->tail_mbuf = NULL;
5966f8829a4aSRandall Stewart 		control->length = 0;
5967f8829a4aSRandall Stewart 		if (out_flags & MSG_EOR) {
5968f8829a4aSRandall Stewart 			/* Done with this control */
5969f8829a4aSRandall Stewart 			goto done_with_control;
5970f8829a4aSRandall Stewart 		}
5971f8829a4aSRandall Stewart 	}
5972f8829a4aSRandall Stewart release:
5973f8829a4aSRandall Stewart 	if (hold_rlock == 1) {
5974f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
5975f8829a4aSRandall Stewart 		hold_rlock = 0;
5976f8829a4aSRandall Stewart 	}
59777abab911SRobert Watson 	if (hold_sblock == 1) {
59787abab911SRobert Watson 		SOCKBUF_UNLOCK(&so->so_rcv);
59797abab911SRobert Watson 		hold_sblock = 0;
5980f8829a4aSRandall Stewart 	}
5981f8829a4aSRandall Stewart 	sbunlock(&so->so_rcv);
59827abab911SRobert Watson 	sockbuf_lock = 0;
5983f8829a4aSRandall Stewart 
5984f8829a4aSRandall Stewart release_unlocked:
5985f8829a4aSRandall Stewart 	if (hold_sblock) {
5986f8829a4aSRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
5987f8829a4aSRandall Stewart 		hold_sblock = 0;
5988f8829a4aSRandall Stewart 	}
5989f8829a4aSRandall Stewart 	if ((stcb) && (in_flags & MSG_PEEK) == 0) {
5990f8829a4aSRandall Stewart 		if ((freed_so_far >= rwnd_req) &&
5991f8829a4aSRandall Stewart 		    (control && (control->do_not_ref_stcb == 0)) &&
5992f8829a4aSRandall Stewart 		    (no_rcv_needed == 0))
5993f8829a4aSRandall Stewart 			sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
5994f8829a4aSRandall Stewart 	}
5995f8829a4aSRandall Stewart out:
59961b9f62a0SRandall Stewart 	if (msg_flags) {
59971b9f62a0SRandall Stewart 		*msg_flags = out_flags;
59981b9f62a0SRandall Stewart 	}
59999a6142d8SRandall Stewart 	if (((out_flags & MSG_EOR) == 0) &&
60009a6142d8SRandall Stewart 	    ((in_flags & MSG_PEEK) == 0) &&
60019a6142d8SRandall Stewart 	    (sinfo) &&
6002*e2e7c62eSMichael Tuexen 	    (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXT_RCVINFO) ||
6003*e2e7c62eSMichael Tuexen 	    sctp_is_feature_on(inp, SCTP_PCB_FLAGS_RECVNXTINFO))) {
60049a6142d8SRandall Stewart 		struct sctp_extrcvinfo *s_extra;
60059a6142d8SRandall Stewart 
60069a6142d8SRandall Stewart 		s_extra = (struct sctp_extrcvinfo *)sinfo;
60079a6142d8SRandall Stewart 		s_extra->sreinfo_next_flags = SCTP_NO_NEXT_MSG;
60089a6142d8SRandall Stewart 	}
6009f8829a4aSRandall Stewart 	if (hold_rlock == 1) {
6010f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
6011f8829a4aSRandall Stewart 		hold_rlock = 0;
6012f8829a4aSRandall Stewart 	}
6013f8829a4aSRandall Stewart 	if (hold_sblock) {
6014f8829a4aSRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
6015f8829a4aSRandall Stewart 		hold_sblock = 0;
6016f8829a4aSRandall Stewart 	}
60177abab911SRobert Watson 	if (sockbuf_lock) {
60187abab911SRobert Watson 		sbunlock(&so->so_rcv);
60197abab911SRobert Watson 	}
602050cec919SRandall Stewart 	if (freecnt_applied) {
6021f8829a4aSRandall Stewart 		/*
6022f8829a4aSRandall Stewart 		 * The lock on the socket buffer protects us so the free
6023f8829a4aSRandall Stewart 		 * code will stop. But since we used the socketbuf lock and
6024f8829a4aSRandall Stewart 		 * the sender uses the tcb_lock to increment, we need to use
6025f8829a4aSRandall Stewart 		 * the atomic add to the refcnt.
6026f8829a4aSRandall Stewart 		 */
602750cec919SRandall Stewart 		if (stcb == NULL) {
6028df6e0cc3SRandall Stewart #ifdef INVARIANTS
602950cec919SRandall Stewart 			panic("stcb for refcnt has gone NULL?");
6030df6e0cc3SRandall Stewart 			goto stage_left;
6031df6e0cc3SRandall Stewart #else
6032df6e0cc3SRandall Stewart 			goto stage_left;
6033df6e0cc3SRandall Stewart #endif
603450cec919SRandall Stewart 		}
603550cec919SRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, -1);
6036f8829a4aSRandall Stewart 		freecnt_applied = 0;
6037f8829a4aSRandall Stewart 		/* Save the value back for next time */
6038f8829a4aSRandall Stewart 		stcb->freed_by_sorcv_sincelast = freed_so_far;
6039f8829a4aSRandall Stewart 	}
6040b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
6041f8829a4aSRandall Stewart 		if (stcb) {
6042f8829a4aSRandall Stewart 			sctp_misc_ints(SCTP_SORECV_DONE,
6043f8829a4aSRandall Stewart 			    freed_so_far,
6044f8829a4aSRandall Stewart 			    ((uio) ? (slen - uio->uio_resid) : slen),
6045f8829a4aSRandall Stewart 			    stcb->asoc.my_rwnd,
6046f8829a4aSRandall Stewart 			    so->so_rcv.sb_cc);
6047f8829a4aSRandall Stewart 		} else {
6048f8829a4aSRandall Stewart 			sctp_misc_ints(SCTP_SORECV_DONE,
6049f8829a4aSRandall Stewart 			    freed_so_far,
6050f8829a4aSRandall Stewart 			    ((uio) ? (slen - uio->uio_resid) : slen),
6051f8829a4aSRandall Stewart 			    0,
6052f8829a4aSRandall Stewart 			    so->so_rcv.sb_cc);
6053f8829a4aSRandall Stewart 		}
605480fefe0aSRandall Stewart 	}
6055df6e0cc3SRandall Stewart stage_left:
6056f8829a4aSRandall Stewart 	if (wakeup_read_socket) {
6057f8829a4aSRandall Stewart 		sctp_sorwakeup(inp, so);
6058f8829a4aSRandall Stewart 	}
6059f8829a4aSRandall Stewart 	return (error);
6060f8829a4aSRandall Stewart }
6061f8829a4aSRandall Stewart 
6062f8829a4aSRandall Stewart 
6063f8829a4aSRandall Stewart #ifdef SCTP_MBUF_LOGGING
6064f8829a4aSRandall Stewart struct mbuf *
6065f8829a4aSRandall Stewart sctp_m_free(struct mbuf *m)
6066f8829a4aSRandall Stewart {
6067b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_MBUF_LOGGING_ENABLE) {
6068139bc87fSRandall Stewart 		if (SCTP_BUF_IS_EXTENDED(m)) {
6069f8829a4aSRandall Stewart 			sctp_log_mb(m, SCTP_MBUF_IFREE);
6070f8829a4aSRandall Stewart 		}
607180fefe0aSRandall Stewart 	}
6072f8829a4aSRandall Stewart 	return (m_free(m));
6073f8829a4aSRandall Stewart }
6074f8829a4aSRandall Stewart 
6075f8829a4aSRandall Stewart void
6076f8829a4aSRandall Stewart sctp_m_freem(struct mbuf *mb)
6077f8829a4aSRandall Stewart {
6078f8829a4aSRandall Stewart 	while (mb != NULL)
6079f8829a4aSRandall Stewart 		mb = sctp_m_free(mb);
6080f8829a4aSRandall Stewart }
6081f8829a4aSRandall Stewart 
6082f8829a4aSRandall Stewart #endif
6083f8829a4aSRandall Stewart 
608442551e99SRandall Stewart int
608542551e99SRandall Stewart sctp_dynamic_set_primary(struct sockaddr *sa, uint32_t vrf_id)
608642551e99SRandall Stewart {
608742551e99SRandall Stewart 	/*
608842551e99SRandall Stewart 	 * Given a local address. For all associations that holds the
608942551e99SRandall Stewart 	 * address, request a peer-set-primary.
609042551e99SRandall Stewart 	 */
609142551e99SRandall Stewart 	struct sctp_ifa *ifa;
609242551e99SRandall Stewart 	struct sctp_laddr *wi;
609342551e99SRandall Stewart 
609442551e99SRandall Stewart 	ifa = sctp_find_ifa_by_addr(sa, vrf_id, 0);
609542551e99SRandall Stewart 	if (ifa == NULL) {
6096c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EADDRNOTAVAIL);
609742551e99SRandall Stewart 		return (EADDRNOTAVAIL);
609842551e99SRandall Stewart 	}
609942551e99SRandall Stewart 	/*
610042551e99SRandall Stewart 	 * Now that we have the ifa we must awaken the iterator with this
610142551e99SRandall Stewart 	 * message.
610242551e99SRandall Stewart 	 */
6103b3f1ea41SRandall Stewart 	wi = SCTP_ZONE_GET(SCTP_BASE_INFO(ipi_zone_laddr), struct sctp_laddr);
610442551e99SRandall Stewart 	if (wi == NULL) {
6105c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
610642551e99SRandall Stewart 		return (ENOMEM);
610742551e99SRandall Stewart 	}
610842551e99SRandall Stewart 	/* Now incr the count and int wi structure */
610942551e99SRandall Stewart 	SCTP_INCR_LADDR_COUNT();
611042551e99SRandall Stewart 	bzero(wi, sizeof(*wi));
6111d61a0ae0SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&wi->start_time);
611242551e99SRandall Stewart 	wi->ifa = ifa;
611342551e99SRandall Stewart 	wi->action = SCTP_SET_PRIM_ADDR;
611442551e99SRandall Stewart 	atomic_add_int(&ifa->refcount, 1);
611542551e99SRandall Stewart 
611642551e99SRandall Stewart 	/* Now add it to the work queue */
6117f7517433SRandall Stewart 	SCTP_WQ_ADDR_LOCK();
611842551e99SRandall Stewart 	/*
611942551e99SRandall Stewart 	 * Should this really be a tailq? As it is we will process the
612042551e99SRandall Stewart 	 * newest first :-0
612142551e99SRandall Stewart 	 */
6122b3f1ea41SRandall Stewart 	LIST_INSERT_HEAD(&SCTP_BASE_INFO(addr_wq), wi, sctp_nxt_addr);
6123f7517433SRandall Stewart 	SCTP_WQ_ADDR_UNLOCK();
612442551e99SRandall Stewart 	sctp_timer_start(SCTP_TIMER_TYPE_ADDR_WQ,
612542551e99SRandall Stewart 	    (struct sctp_inpcb *)NULL,
612642551e99SRandall Stewart 	    (struct sctp_tcb *)NULL,
612742551e99SRandall Stewart 	    (struct sctp_nets *)NULL);
612842551e99SRandall Stewart 	return (0);
612942551e99SRandall Stewart }
613042551e99SRandall Stewart 
613142551e99SRandall Stewart 
6132f8829a4aSRandall Stewart int
613317205eccSRandall Stewart sctp_soreceive(struct socket *so,
613417205eccSRandall Stewart     struct sockaddr **psa,
613517205eccSRandall Stewart     struct uio *uio,
613617205eccSRandall Stewart     struct mbuf **mp0,
613717205eccSRandall Stewart     struct mbuf **controlp,
613817205eccSRandall Stewart     int *flagsp)
6139f8829a4aSRandall Stewart {
6140f8829a4aSRandall Stewart 	int error, fromlen;
6141f8829a4aSRandall Stewart 	uint8_t sockbuf[256];
6142f8829a4aSRandall Stewart 	struct sockaddr *from;
6143f8829a4aSRandall Stewart 	struct sctp_extrcvinfo sinfo;
6144f8829a4aSRandall Stewart 	int filling_sinfo = 1;
6145f8829a4aSRandall Stewart 	struct sctp_inpcb *inp;
6146f8829a4aSRandall Stewart 
6147f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)so->so_pcb;
6148f8829a4aSRandall Stewart 	/* pickup the assoc we are reading from */
6149f8829a4aSRandall Stewart 	if (inp == NULL) {
6150c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6151f8829a4aSRandall Stewart 		return (EINVAL);
6152f8829a4aSRandall Stewart 	}
6153*e2e7c62eSMichael Tuexen 	if ((sctp_is_feature_off(inp, SCTP_PCB_FLAGS_RECVDATAIOEVNT) &&
6154*e2e7c62eSMichael Tuexen 	    sctp_is_feature_off(inp, SCTP_PCB_FLAGS_RECVRCVINFO) &&
6155*e2e7c62eSMichael Tuexen 	    sctp_is_feature_off(inp, SCTP_PCB_FLAGS_RECVNXTINFO)) ||
6156f8829a4aSRandall Stewart 	    (controlp == NULL)) {
6157f8829a4aSRandall Stewart 		/* user does not want the sndrcv ctl */
6158f8829a4aSRandall Stewart 		filling_sinfo = 0;
6159f8829a4aSRandall Stewart 	}
6160f8829a4aSRandall Stewart 	if (psa) {
6161f8829a4aSRandall Stewart 		from = (struct sockaddr *)sockbuf;
6162f8829a4aSRandall Stewart 		fromlen = sizeof(sockbuf);
6163f8829a4aSRandall Stewart 		from->sa_len = 0;
6164f8829a4aSRandall Stewart 	} else {
6165f8829a4aSRandall Stewart 		from = NULL;
6166f8829a4aSRandall Stewart 		fromlen = 0;
6167f8829a4aSRandall Stewart 	}
6168f8829a4aSRandall Stewart 
6169f8829a4aSRandall Stewart 	error = sctp_sorecvmsg(so, uio, mp0, from, fromlen, flagsp,
6170f8829a4aSRandall Stewart 	    (struct sctp_sndrcvinfo *)&sinfo, filling_sinfo);
6171f8829a4aSRandall Stewart 	if ((controlp) && (filling_sinfo)) {
6172f8829a4aSRandall Stewart 		/* copy back the sinfo in a CMSG format */
6173f8829a4aSRandall Stewart 		if (filling_sinfo)
6174f8829a4aSRandall Stewart 			*controlp = sctp_build_ctl_nchunk(inp,
6175f8829a4aSRandall Stewart 			    (struct sctp_sndrcvinfo *)&sinfo);
6176f8829a4aSRandall Stewart 		else
6177f8829a4aSRandall Stewart 			*controlp = NULL;
6178f8829a4aSRandall Stewart 	}
6179f8829a4aSRandall Stewart 	if (psa) {
6180f8829a4aSRandall Stewart 		/* copy back the address info */
6181f8829a4aSRandall Stewart 		if (from && from->sa_len) {
6182f8829a4aSRandall Stewart 			*psa = sodupsockaddr(from, M_NOWAIT);
6183f8829a4aSRandall Stewart 		} else {
6184f8829a4aSRandall Stewart 			*psa = NULL;
6185f8829a4aSRandall Stewart 		}
6186f8829a4aSRandall Stewart 	}
6187f8829a4aSRandall Stewart 	return (error);
6188f8829a4aSRandall Stewart }
618917205eccSRandall Stewart 
619017205eccSRandall Stewart 
619117205eccSRandall Stewart 
619217205eccSRandall Stewart 
619317205eccSRandall Stewart 
619417205eccSRandall Stewart int
6195d61a0ae0SRandall Stewart sctp_connectx_helper_add(struct sctp_tcb *stcb, struct sockaddr *addr,
6196d61a0ae0SRandall Stewart     int totaddr, int *error)
619717205eccSRandall Stewart {
619817205eccSRandall Stewart 	int added = 0;
619917205eccSRandall Stewart 	int i;
620017205eccSRandall Stewart 	struct sctp_inpcb *inp;
620117205eccSRandall Stewart 	struct sockaddr *sa;
620217205eccSRandall Stewart 	size_t incr = 0;
620317205eccSRandall Stewart 
620417205eccSRandall Stewart 	sa = addr;
620517205eccSRandall Stewart 	inp = stcb->sctp_ep;
620617205eccSRandall Stewart 	*error = 0;
620717205eccSRandall Stewart 	for (i = 0; i < totaddr; i++) {
6208ea5eba11SMichael Tuexen 		switch (sa->sa_family) {
6209ea5eba11SMichael Tuexen #ifdef INET
6210ea5eba11SMichael Tuexen 		case AF_INET:
621117205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in);
621217205eccSRandall Stewart 			if (sctp_add_remote_addr(stcb, sa, SCTP_DONOT_SETSCOPE, SCTP_ADDR_IS_CONFIRMED)) {
621317205eccSRandall Stewart 				/* assoc gone no un-lock */
6214c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOBUFS);
6215c4739e2fSRandall Stewart 				(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC, SCTP_FROM_SCTP_USRREQ + SCTP_LOC_7);
621617205eccSRandall Stewart 				*error = ENOBUFS;
621717205eccSRandall Stewart 				goto out_now;
621817205eccSRandall Stewart 			}
621917205eccSRandall Stewart 			added++;
6220ea5eba11SMichael Tuexen 			break;
6221ea5eba11SMichael Tuexen #endif
6222ea5eba11SMichael Tuexen #ifdef INET6
6223ea5eba11SMichael Tuexen 		case AF_INET6:
622417205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in6);
622517205eccSRandall Stewart 			if (sctp_add_remote_addr(stcb, sa, SCTP_DONOT_SETSCOPE, SCTP_ADDR_IS_CONFIRMED)) {
622617205eccSRandall Stewart 				/* assoc gone no un-lock */
6227c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOBUFS);
6228c4739e2fSRandall Stewart 				(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC, SCTP_FROM_SCTP_USRREQ + SCTP_LOC_8);
622917205eccSRandall Stewart 				*error = ENOBUFS;
623017205eccSRandall Stewart 				goto out_now;
623117205eccSRandall Stewart 			}
623217205eccSRandall Stewart 			added++;
6233ea5eba11SMichael Tuexen 			break;
6234ea5eba11SMichael Tuexen #endif
6235ea5eba11SMichael Tuexen 		default:
6236ea5eba11SMichael Tuexen 			break;
623717205eccSRandall Stewart 		}
623817205eccSRandall Stewart 		sa = (struct sockaddr *)((caddr_t)sa + incr);
623917205eccSRandall Stewart 	}
624017205eccSRandall Stewart out_now:
624117205eccSRandall Stewart 	return (added);
624217205eccSRandall Stewart }
624317205eccSRandall Stewart 
624417205eccSRandall Stewart struct sctp_tcb *
6245d61a0ae0SRandall Stewart sctp_connectx_helper_find(struct sctp_inpcb *inp, struct sockaddr *addr,
6246d61a0ae0SRandall Stewart     int *totaddr, int *num_v4, int *num_v6, int *error,
6247d61a0ae0SRandall Stewart     int limit, int *bad_addr)
624817205eccSRandall Stewart {
624917205eccSRandall Stewart 	struct sockaddr *sa;
625017205eccSRandall Stewart 	struct sctp_tcb *stcb = NULL;
625117205eccSRandall Stewart 	size_t incr, at, i;
625217205eccSRandall Stewart 
625317205eccSRandall Stewart 	at = incr = 0;
625417205eccSRandall Stewart 	sa = addr;
6255ea5eba11SMichael Tuexen 
625617205eccSRandall Stewart 	*error = *num_v6 = *num_v4 = 0;
625717205eccSRandall Stewart 	/* account and validate addresses */
62584c9179adSRandall Stewart 	for (i = 0; i < (size_t)*totaddr; i++) {
6259ea5eba11SMichael Tuexen 		switch (sa->sa_family) {
6260ea5eba11SMichael Tuexen #ifdef INET
6261ea5eba11SMichael Tuexen 		case AF_INET:
626217205eccSRandall Stewart 			(*num_v4) += 1;
626317205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in);
6264d61a0ae0SRandall Stewart 			if (sa->sa_len != incr) {
6265c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6266d61a0ae0SRandall Stewart 				*error = EINVAL;
6267d61a0ae0SRandall Stewart 				*bad_addr = 1;
6268d61a0ae0SRandall Stewart 				return (NULL);
6269d61a0ae0SRandall Stewart 			}
6270ea5eba11SMichael Tuexen 			break;
6271ea5eba11SMichael Tuexen #endif
6272ea5eba11SMichael Tuexen #ifdef INET6
6273ea5eba11SMichael Tuexen 		case AF_INET6:
6274ea5eba11SMichael Tuexen 			{
627517205eccSRandall Stewart 				struct sockaddr_in6 *sin6;
627617205eccSRandall Stewart 
627717205eccSRandall Stewart 				sin6 = (struct sockaddr_in6 *)sa;
627817205eccSRandall Stewart 				if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
627917205eccSRandall Stewart 					/* Must be non-mapped for connectx */
6280c4739e2fSRandall Stewart 					SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
628117205eccSRandall Stewart 					*error = EINVAL;
6282d61a0ae0SRandall Stewart 					*bad_addr = 1;
628317205eccSRandall Stewart 					return (NULL);
628417205eccSRandall Stewart 				}
628517205eccSRandall Stewart 				(*num_v6) += 1;
628617205eccSRandall Stewart 				incr = sizeof(struct sockaddr_in6);
6287d61a0ae0SRandall Stewart 				if (sa->sa_len != incr) {
6288c4739e2fSRandall Stewart 					SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6289d61a0ae0SRandall Stewart 					*error = EINVAL;
6290d61a0ae0SRandall Stewart 					*bad_addr = 1;
6291d61a0ae0SRandall Stewart 					return (NULL);
6292d61a0ae0SRandall Stewart 				}
6293ea5eba11SMichael Tuexen 				break;
6294ea5eba11SMichael Tuexen 			}
6295ea5eba11SMichael Tuexen #endif
6296ea5eba11SMichael Tuexen 		default:
629717205eccSRandall Stewart 			*totaddr = i;
629817205eccSRandall Stewart 			/* we are done */
629917205eccSRandall Stewart 			break;
630017205eccSRandall Stewart 		}
6301ea5eba11SMichael Tuexen 		if (i == (size_t)*totaddr) {
6302ea5eba11SMichael Tuexen 			break;
6303ea5eba11SMichael Tuexen 		}
6304d61a0ae0SRandall Stewart 		SCTP_INP_INCR_REF(inp);
630517205eccSRandall Stewart 		stcb = sctp_findassociation_ep_addr(&inp, sa, NULL, NULL, NULL);
630617205eccSRandall Stewart 		if (stcb != NULL) {
630717205eccSRandall Stewart 			/* Already have or am bring up an association */
630817205eccSRandall Stewart 			return (stcb);
6309d61a0ae0SRandall Stewart 		} else {
6310d61a0ae0SRandall Stewart 			SCTP_INP_DECR_REF(inp);
631117205eccSRandall Stewart 		}
63124c9179adSRandall Stewart 		if ((at + incr) > (size_t)limit) {
631317205eccSRandall Stewart 			*totaddr = i;
631417205eccSRandall Stewart 			break;
631517205eccSRandall Stewart 		}
631617205eccSRandall Stewart 		sa = (struct sockaddr *)((caddr_t)sa + incr);
631717205eccSRandall Stewart 	}
631817205eccSRandall Stewart 	return ((struct sctp_tcb *)NULL);
631917205eccSRandall Stewart }
632035918f85SRandall Stewart 
632135918f85SRandall Stewart /*
632235918f85SRandall Stewart  * sctp_bindx(ADD) for one address.
632335918f85SRandall Stewart  * assumes all arguments are valid/checked by caller.
632435918f85SRandall Stewart  */
632535918f85SRandall Stewart void
632635918f85SRandall Stewart sctp_bindx_add_address(struct socket *so, struct sctp_inpcb *inp,
632735918f85SRandall Stewart     struct sockaddr *sa, sctp_assoc_t assoc_id,
632835918f85SRandall Stewart     uint32_t vrf_id, int *error, void *p)
632935918f85SRandall Stewart {
633035918f85SRandall Stewart 	struct sockaddr *addr_touse;
63315e2c2d87SRandall Stewart 
63325e2c2d87SRandall Stewart #ifdef INET6
633335918f85SRandall Stewart 	struct sockaddr_in sin;
633435918f85SRandall Stewart 
63355e2c2d87SRandall Stewart #endif
63365e2c2d87SRandall Stewart 
633735918f85SRandall Stewart 	/* see if we're bound all already! */
633835918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
6339c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
634035918f85SRandall Stewart 		*error = EINVAL;
634135918f85SRandall Stewart 		return;
634235918f85SRandall Stewart 	}
634335918f85SRandall Stewart 	addr_touse = sa;
6344ea5eba11SMichael Tuexen #ifdef INET6
634535918f85SRandall Stewart 	if (sa->sa_family == AF_INET6) {
634635918f85SRandall Stewart 		struct sockaddr_in6 *sin6;
634735918f85SRandall Stewart 
634835918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in6)) {
6349c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
635035918f85SRandall Stewart 			*error = EINVAL;
635135918f85SRandall Stewart 			return;
635235918f85SRandall Stewart 		}
6353db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) == 0) {
6354db4fd95bSRandall Stewart 			/* can only bind v6 on PF_INET6 sockets */
6355c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6356db4fd95bSRandall Stewart 			*error = EINVAL;
6357db4fd95bSRandall Stewart 			return;
6358db4fd95bSRandall Stewart 		}
635935918f85SRandall Stewart 		sin6 = (struct sockaddr_in6 *)addr_touse;
636035918f85SRandall Stewart 		if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
6361db4fd95bSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6362db4fd95bSRandall Stewart 			    SCTP_IPV6_V6ONLY(inp)) {
6363db4fd95bSRandall Stewart 				/* can't bind v4-mapped on PF_INET sockets */
6364c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6365db4fd95bSRandall Stewart 				*error = EINVAL;
6366db4fd95bSRandall Stewart 				return;
6367db4fd95bSRandall Stewart 			}
636835918f85SRandall Stewart 			in6_sin6_2_sin(&sin, sin6);
636935918f85SRandall Stewart 			addr_touse = (struct sockaddr *)&sin;
637035918f85SRandall Stewart 		}
637135918f85SRandall Stewart 	}
637235918f85SRandall Stewart #endif
6373ea5eba11SMichael Tuexen #ifdef INET
637435918f85SRandall Stewart 	if (sa->sa_family == AF_INET) {
637535918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in)) {
6376c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
637735918f85SRandall Stewart 			*error = EINVAL;
637835918f85SRandall Stewart 			return;
637935918f85SRandall Stewart 		}
6380db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6381db4fd95bSRandall Stewart 		    SCTP_IPV6_V6ONLY(inp)) {
6382db4fd95bSRandall Stewart 			/* can't bind v4 on PF_INET sockets */
6383c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6384db4fd95bSRandall Stewart 			*error = EINVAL;
6385db4fd95bSRandall Stewart 			return;
6386db4fd95bSRandall Stewart 		}
638735918f85SRandall Stewart 	}
6388ea5eba11SMichael Tuexen #endif
638935918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_UNBOUND) {
639035918f85SRandall Stewart 		if (p == NULL) {
639135918f85SRandall Stewart 			/* Can't get proc for Net/Open BSD */
6392c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
639335918f85SRandall Stewart 			*error = EINVAL;
639435918f85SRandall Stewart 			return;
639535918f85SRandall Stewart 		}
63961b649582SRandall Stewart 		*error = sctp_inpcb_bind(so, addr_touse, NULL, p);
639735918f85SRandall Stewart 		return;
639835918f85SRandall Stewart 	}
639935918f85SRandall Stewart 	/*
640035918f85SRandall Stewart 	 * No locks required here since bind and mgmt_ep_sa all do their own
640135918f85SRandall Stewart 	 * locking. If we do something for the FIX: below we may need to
640235918f85SRandall Stewart 	 * lock in that case.
640335918f85SRandall Stewart 	 */
640435918f85SRandall Stewart 	if (assoc_id == 0) {
640535918f85SRandall Stewart 		/* add the address */
640635918f85SRandall Stewart 		struct sctp_inpcb *lep;
640797c76f10SRandall Stewart 		struct sockaddr_in *lsin = (struct sockaddr_in *)addr_touse;
640835918f85SRandall Stewart 
640997c76f10SRandall Stewart 		/* validate the incoming port */
641097c76f10SRandall Stewart 		if ((lsin->sin_port != 0) &&
641197c76f10SRandall Stewart 		    (lsin->sin_port != inp->sctp_lport)) {
6412c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
641397c76f10SRandall Stewart 			*error = EINVAL;
641497c76f10SRandall Stewart 			return;
641597c76f10SRandall Stewart 		} else {
641697c76f10SRandall Stewart 			/* user specified 0 port, set it to existing port */
641797c76f10SRandall Stewart 			lsin->sin_port = inp->sctp_lport;
641897c76f10SRandall Stewart 		}
641997c76f10SRandall Stewart 
642035918f85SRandall Stewart 		lep = sctp_pcb_findep(addr_touse, 1, 0, vrf_id);
642135918f85SRandall Stewart 		if (lep != NULL) {
642235918f85SRandall Stewart 			/*
642335918f85SRandall Stewart 			 * We must decrement the refcount since we have the
642435918f85SRandall Stewart 			 * ep already and are binding. No remove going on
642535918f85SRandall Stewart 			 * here.
642635918f85SRandall Stewart 			 */
64276d9e8f2bSRandall Stewart 			SCTP_INP_DECR_REF(lep);
642835918f85SRandall Stewart 		}
642935918f85SRandall Stewart 		if (lep == inp) {
643035918f85SRandall Stewart 			/* already bound to it.. ok */
643135918f85SRandall Stewart 			return;
643235918f85SRandall Stewart 		} else if (lep == NULL) {
643335918f85SRandall Stewart 			((struct sockaddr_in *)addr_touse)->sin_port = 0;
643435918f85SRandall Stewart 			*error = sctp_addr_mgmt_ep_sa(inp, addr_touse,
643535918f85SRandall Stewart 			    SCTP_ADD_IP_ADDRESS,
643680fefe0aSRandall Stewart 			    vrf_id, NULL);
643735918f85SRandall Stewart 		} else {
643835918f85SRandall Stewart 			*error = EADDRINUSE;
643935918f85SRandall Stewart 		}
644035918f85SRandall Stewart 		if (*error)
644135918f85SRandall Stewart 			return;
644235918f85SRandall Stewart 	} else {
644335918f85SRandall Stewart 		/*
644435918f85SRandall Stewart 		 * FIX: decide whether we allow assoc based bindx
644535918f85SRandall Stewart 		 */
644635918f85SRandall Stewart 	}
644735918f85SRandall Stewart }
644835918f85SRandall Stewart 
644935918f85SRandall Stewart /*
645035918f85SRandall Stewart  * sctp_bindx(DELETE) for one address.
645135918f85SRandall Stewart  * assumes all arguments are valid/checked by caller.
645235918f85SRandall Stewart  */
645335918f85SRandall Stewart void
645435918f85SRandall Stewart sctp_bindx_delete_address(struct socket *so, struct sctp_inpcb *inp,
645535918f85SRandall Stewart     struct sockaddr *sa, sctp_assoc_t assoc_id,
645635918f85SRandall Stewart     uint32_t vrf_id, int *error)
645735918f85SRandall Stewart {
645835918f85SRandall Stewart 	struct sockaddr *addr_touse;
64595e2c2d87SRandall Stewart 
64605e2c2d87SRandall Stewart #ifdef INET6
646135918f85SRandall Stewart 	struct sockaddr_in sin;
646235918f85SRandall Stewart 
64635e2c2d87SRandall Stewart #endif
64645e2c2d87SRandall Stewart 
646535918f85SRandall Stewart 	/* see if we're bound all already! */
646635918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
6467c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
646835918f85SRandall Stewart 		*error = EINVAL;
646935918f85SRandall Stewart 		return;
647035918f85SRandall Stewart 	}
647135918f85SRandall Stewart 	addr_touse = sa;
6472fc14de76SRandall Stewart #if defined(INET6) && !defined(__Userspace__)	/* TODO port in6_sin6_2_sin */
647335918f85SRandall Stewart 	if (sa->sa_family == AF_INET6) {
647435918f85SRandall Stewart 		struct sockaddr_in6 *sin6;
647535918f85SRandall Stewart 
647635918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in6)) {
6477c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
647835918f85SRandall Stewart 			*error = EINVAL;
647935918f85SRandall Stewart 			return;
648035918f85SRandall Stewart 		}
6481db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) == 0) {
6482db4fd95bSRandall Stewart 			/* can only bind v6 on PF_INET6 sockets */
6483c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6484db4fd95bSRandall Stewart 			*error = EINVAL;
6485db4fd95bSRandall Stewart 			return;
6486db4fd95bSRandall Stewart 		}
648735918f85SRandall Stewart 		sin6 = (struct sockaddr_in6 *)addr_touse;
648835918f85SRandall Stewart 		if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
6489db4fd95bSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6490db4fd95bSRandall Stewart 			    SCTP_IPV6_V6ONLY(inp)) {
6491db4fd95bSRandall Stewart 				/* can't bind mapped-v4 on PF_INET sockets */
6492c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6493db4fd95bSRandall Stewart 				*error = EINVAL;
6494db4fd95bSRandall Stewart 				return;
6495db4fd95bSRandall Stewart 			}
649635918f85SRandall Stewart 			in6_sin6_2_sin(&sin, sin6);
649735918f85SRandall Stewart 			addr_touse = (struct sockaddr *)&sin;
649835918f85SRandall Stewart 		}
649935918f85SRandall Stewart 	}
650035918f85SRandall Stewart #endif
6501ea5eba11SMichael Tuexen #ifdef INET
650235918f85SRandall Stewart 	if (sa->sa_family == AF_INET) {
650335918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in)) {
6504c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
650535918f85SRandall Stewart 			*error = EINVAL;
650635918f85SRandall Stewart 			return;
650735918f85SRandall Stewart 		}
6508db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6509db4fd95bSRandall Stewart 		    SCTP_IPV6_V6ONLY(inp)) {
6510db4fd95bSRandall Stewart 			/* can't bind v4 on PF_INET sockets */
6511c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6512db4fd95bSRandall Stewart 			*error = EINVAL;
6513db4fd95bSRandall Stewart 			return;
6514db4fd95bSRandall Stewart 		}
651535918f85SRandall Stewart 	}
6516ea5eba11SMichael Tuexen #endif
651735918f85SRandall Stewart 	/*
651835918f85SRandall Stewart 	 * No lock required mgmt_ep_sa does its own locking. If the FIX:
651935918f85SRandall Stewart 	 * below is ever changed we may need to lock before calling
652035918f85SRandall Stewart 	 * association level binding.
652135918f85SRandall Stewart 	 */
652235918f85SRandall Stewart 	if (assoc_id == 0) {
652335918f85SRandall Stewart 		/* delete the address */
652435918f85SRandall Stewart 		*error = sctp_addr_mgmt_ep_sa(inp, addr_touse,
652535918f85SRandall Stewart 		    SCTP_DEL_IP_ADDRESS,
652680fefe0aSRandall Stewart 		    vrf_id, NULL);
652735918f85SRandall Stewart 	} else {
652835918f85SRandall Stewart 		/*
652935918f85SRandall Stewart 		 * FIX: decide whether we allow assoc based bindx
653035918f85SRandall Stewart 		 */
653135918f85SRandall Stewart 	}
653235918f85SRandall Stewart }
65331b649582SRandall Stewart 
65341b649582SRandall Stewart /*
65351b649582SRandall Stewart  * returns the valid local address count for an assoc, taking into account
65361b649582SRandall Stewart  * all scoping rules
65371b649582SRandall Stewart  */
65381b649582SRandall Stewart int
65391b649582SRandall Stewart sctp_local_addr_count(struct sctp_tcb *stcb)
65401b649582SRandall Stewart {
65411b649582SRandall Stewart 	int loopback_scope, ipv4_local_scope, local_scope, site_scope;
65421b649582SRandall Stewart 	int ipv4_addr_legal, ipv6_addr_legal;
65431b649582SRandall Stewart 	struct sctp_vrf *vrf;
65441b649582SRandall Stewart 	struct sctp_ifn *sctp_ifn;
65451b649582SRandall Stewart 	struct sctp_ifa *sctp_ifa;
65461b649582SRandall Stewart 	int count = 0;
65471b649582SRandall Stewart 
65481b649582SRandall Stewart 	/* Turn on all the appropriate scopes */
65491b649582SRandall Stewart 	loopback_scope = stcb->asoc.loopback_scope;
65501b649582SRandall Stewart 	ipv4_local_scope = stcb->asoc.ipv4_local_scope;
65511b649582SRandall Stewart 	local_scope = stcb->asoc.local_scope;
65521b649582SRandall Stewart 	site_scope = stcb->asoc.site_scope;
65531b649582SRandall Stewart 	ipv4_addr_legal = ipv6_addr_legal = 0;
65541b649582SRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) {
65551b649582SRandall Stewart 		ipv6_addr_legal = 1;
65561b649582SRandall Stewart 		if (SCTP_IPV6_V6ONLY(stcb->sctp_ep) == 0) {
65571b649582SRandall Stewart 			ipv4_addr_legal = 1;
65581b649582SRandall Stewart 		}
65591b649582SRandall Stewart 	} else {
65601b649582SRandall Stewart 		ipv4_addr_legal = 1;
65611b649582SRandall Stewart 	}
65621b649582SRandall Stewart 
6563c99efcf6SRandall Stewart 	SCTP_IPI_ADDR_RLOCK();
65641b649582SRandall Stewart 	vrf = sctp_find_vrf(stcb->asoc.vrf_id);
65651b649582SRandall Stewart 	if (vrf == NULL) {
65661b649582SRandall Stewart 		/* no vrf, no addresses */
6567c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RUNLOCK();
65681b649582SRandall Stewart 		return (0);
65691b649582SRandall Stewart 	}
65701b649582SRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
65711b649582SRandall Stewart 		/*
65721b649582SRandall Stewart 		 * bound all case: go through all ifns on the vrf
65731b649582SRandall Stewart 		 */
65741b649582SRandall Stewart 		LIST_FOREACH(sctp_ifn, &vrf->ifnlist, next_ifn) {
65751b649582SRandall Stewart 			if ((loopback_scope == 0) &&
65761b649582SRandall Stewart 			    SCTP_IFN_IS_IFT_LOOP(sctp_ifn)) {
65771b649582SRandall Stewart 				continue;
65781b649582SRandall Stewart 			}
65791b649582SRandall Stewart 			LIST_FOREACH(sctp_ifa, &sctp_ifn->ifalist, next_ifa) {
65801b649582SRandall Stewart 				if (sctp_is_addr_restricted(stcb, sctp_ifa))
65811b649582SRandall Stewart 					continue;
65825e2c2d87SRandall Stewart 				switch (sctp_ifa->address.sa.sa_family) {
6583ea5eba11SMichael Tuexen #ifdef INET
65845e2c2d87SRandall Stewart 				case AF_INET:
65855e2c2d87SRandall Stewart 					if (ipv4_addr_legal) {
65861b649582SRandall Stewart 						struct sockaddr_in *sin;
65871b649582SRandall Stewart 
65881b649582SRandall Stewart 						sin = (struct sockaddr_in *)&sctp_ifa->address.sa;
65891b649582SRandall Stewart 						if (sin->sin_addr.s_addr == 0) {
65905e2c2d87SRandall Stewart 							/*
65915e2c2d87SRandall Stewart 							 * skip unspecified
65925e2c2d87SRandall Stewart 							 * addrs
65935e2c2d87SRandall Stewart 							 */
65941b649582SRandall Stewart 							continue;
65951b649582SRandall Stewart 						}
65961b649582SRandall Stewart 						if ((ipv4_local_scope == 0) &&
65971b649582SRandall Stewart 						    (IN4_ISPRIVATE_ADDRESS(&sin->sin_addr))) {
65981b649582SRandall Stewart 							continue;
65991b649582SRandall Stewart 						}
66001b649582SRandall Stewart 						/* count this one */
66011b649582SRandall Stewart 						count++;
66025e2c2d87SRandall Stewart 					} else {
66035e2c2d87SRandall Stewart 						continue;
66045e2c2d87SRandall Stewart 					}
66055e2c2d87SRandall Stewart 					break;
6606ea5eba11SMichael Tuexen #endif
66075e2c2d87SRandall Stewart #ifdef INET6
66085e2c2d87SRandall Stewart 				case AF_INET6:
66095e2c2d87SRandall Stewart 					if (ipv6_addr_legal) {
66101b649582SRandall Stewart 						struct sockaddr_in6 *sin6;
66111b649582SRandall Stewart 
66121b649582SRandall Stewart 						sin6 = (struct sockaddr_in6 *)&sctp_ifa->address.sa;
66131b649582SRandall Stewart 						if (IN6_IS_ADDR_UNSPECIFIED(&sin6->sin6_addr)) {
66141b649582SRandall Stewart 							continue;
66151b649582SRandall Stewart 						}
66161b649582SRandall Stewart 						if (IN6_IS_ADDR_LINKLOCAL(&sin6->sin6_addr)) {
66171b649582SRandall Stewart 							if (local_scope == 0)
66181b649582SRandall Stewart 								continue;
66191b649582SRandall Stewart 							if (sin6->sin6_scope_id == 0) {
66201b649582SRandall Stewart 								if (sa6_recoverscope(sin6) != 0)
66211b649582SRandall Stewart 									/*
66225e2c2d87SRandall Stewart 									 *
66235e2c2d87SRandall Stewart 									 * bad
66245e2c2d87SRandall Stewart 									 *
66255e2c2d87SRandall Stewart 									 * li
66265e2c2d87SRandall Stewart 									 * nk
66275e2c2d87SRandall Stewart 									 *
66285e2c2d87SRandall Stewart 									 * loc
66295e2c2d87SRandall Stewart 									 * al
66305e2c2d87SRandall Stewart 									 *
66315e2c2d87SRandall Stewart 									 * add
66325e2c2d87SRandall Stewart 									 * re
66335e2c2d87SRandall Stewart 									 * ss
66345e2c2d87SRandall Stewart 									 * */
66351b649582SRandall Stewart 									continue;
66361b649582SRandall Stewart 							}
66371b649582SRandall Stewart 						}
66381b649582SRandall Stewart 						if ((site_scope == 0) &&
66391b649582SRandall Stewart 						    (IN6_IS_ADDR_SITELOCAL(&sin6->sin6_addr))) {
66401b649582SRandall Stewart 							continue;
66411b649582SRandall Stewart 						}
66421b649582SRandall Stewart 						/* count this one */
66431b649582SRandall Stewart 						count++;
66441b649582SRandall Stewart 					}
66455e2c2d87SRandall Stewart 					break;
66465e2c2d87SRandall Stewart #endif
66475e2c2d87SRandall Stewart 				default:
66485e2c2d87SRandall Stewart 					/* TSNH */
66495e2c2d87SRandall Stewart 					break;
66505e2c2d87SRandall Stewart 				}
66511b649582SRandall Stewart 			}
66521b649582SRandall Stewart 		}
66531b649582SRandall Stewart 	} else {
66541b649582SRandall Stewart 		/*
66551b649582SRandall Stewart 		 * subset bound case
66561b649582SRandall Stewart 		 */
66571b649582SRandall Stewart 		struct sctp_laddr *laddr;
66581b649582SRandall Stewart 
66591b649582SRandall Stewart 		LIST_FOREACH(laddr, &stcb->sctp_ep->sctp_addr_list,
66601b649582SRandall Stewart 		    sctp_nxt_addr) {
66611b649582SRandall Stewart 			if (sctp_is_addr_restricted(stcb, laddr->ifa)) {
66621b649582SRandall Stewart 				continue;
66631b649582SRandall Stewart 			}
66641b649582SRandall Stewart 			/* count this one */
66651b649582SRandall Stewart 			count++;
66661b649582SRandall Stewart 		}
66671b649582SRandall Stewart 	}
6668c99efcf6SRandall Stewart 	SCTP_IPI_ADDR_RUNLOCK();
66691b649582SRandall Stewart 	return (count);
66701b649582SRandall Stewart }
6671c4739e2fSRandall Stewart 
6672c4739e2fSRandall Stewart #if defined(SCTP_LOCAL_TRACE_BUF)
6673c4739e2fSRandall Stewart 
6674c4739e2fSRandall Stewart void
6675b27a6b7dSRandall Stewart sctp_log_trace(uint32_t subsys, const char *str SCTP_UNUSED, uint32_t a, uint32_t b, uint32_t c, uint32_t d, uint32_t e, uint32_t f)
6676c4739e2fSRandall Stewart {
6677b27a6b7dSRandall Stewart 	uint32_t saveindex, newindex;
6678c4739e2fSRandall Stewart 
6679c4739e2fSRandall Stewart 	do {
6680b3f1ea41SRandall Stewart 		saveindex = SCTP_BASE_SYSCTL(sctp_log).index;
6681c4739e2fSRandall Stewart 		if (saveindex >= SCTP_MAX_LOGGING_SIZE) {
6682c4739e2fSRandall Stewart 			newindex = 1;
6683c4739e2fSRandall Stewart 		} else {
6684c4739e2fSRandall Stewart 			newindex = saveindex + 1;
6685c4739e2fSRandall Stewart 		}
6686b3f1ea41SRandall Stewart 	} while (atomic_cmpset_int(&SCTP_BASE_SYSCTL(sctp_log).index, saveindex, newindex) == 0);
6687c4739e2fSRandall Stewart 	if (saveindex >= SCTP_MAX_LOGGING_SIZE) {
6688c4739e2fSRandall Stewart 		saveindex = 0;
6689c4739e2fSRandall Stewart 	}
6690b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].timestamp = SCTP_GET_CYCLECOUNT;
6691b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].subsys = subsys;
6692b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[0] = a;
6693b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[1] = b;
6694b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[2] = c;
6695b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[3] = d;
6696b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[4] = e;
6697b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[5] = f;
6698c4739e2fSRandall Stewart }
6699c4739e2fSRandall Stewart 
6700c4739e2fSRandall Stewart #endif
6701ea5eba11SMichael Tuexen /* XXX: Remove the #ifdef after tunneling over IPv6 works also on FreeBSD. */
6702ea5eba11SMichael Tuexen #ifdef INET
6703c54a18d2SRandall Stewart /* We will need to add support
6704c54a18d2SRandall Stewart  * to bind the ports and such here
6705c54a18d2SRandall Stewart  * so we can do UDP tunneling. In
6706c54a18d2SRandall Stewart  * the mean-time, we return error
6707c54a18d2SRandall Stewart  */
6708a99b6783SRandall Stewart #include <netinet/udp.h>
6709a99b6783SRandall Stewart #include <netinet/udp_var.h>
6710a99b6783SRandall Stewart #include <sys/proc.h>
6711a1f2f7a5SRandall Stewart #ifdef INET6
6712a99b6783SRandall Stewart #include <netinet6/sctp6_var.h>
6713a1f2f7a5SRandall Stewart #endif
6714a99b6783SRandall Stewart 
6715a99b6783SRandall Stewart static void
6716a99b6783SRandall Stewart sctp_recv_udp_tunneled_packet(struct mbuf *m, int off, struct inpcb *ignored)
6717a99b6783SRandall Stewart {
6718a99b6783SRandall Stewart 	struct ip *iph;
6719a99b6783SRandall Stewart 	struct mbuf *sp, *last;
6720a99b6783SRandall Stewart 	struct udphdr *uhdr;
6721e6194c2eSMichael Tuexen 	uint16_t port = 0;
6722a99b6783SRandall Stewart 	int header_size = sizeof(struct udphdr) + sizeof(struct sctphdr);
6723a99b6783SRandall Stewart 
6724a99b6783SRandall Stewart 	/*
6725a99b6783SRandall Stewart 	 * Split out the mbuf chain. Leave the IP header in m, place the
6726a99b6783SRandall Stewart 	 * rest in the sp.
6727a99b6783SRandall Stewart 	 */
6728a99b6783SRandall Stewart 	if ((m->m_flags & M_PKTHDR) == 0) {
6729a99b6783SRandall Stewart 		/* Can't handle one that is not a pkt hdr */
6730a99b6783SRandall Stewart 		goto out;
6731a99b6783SRandall Stewart 	}
6732a99b6783SRandall Stewart 	/* pull the src port */
6733a99b6783SRandall Stewart 	iph = mtod(m, struct ip *);
6734a99b6783SRandall Stewart 	uhdr = (struct udphdr *)((caddr_t)iph + off);
6735a99b6783SRandall Stewart 
6736a99b6783SRandall Stewart 	port = uhdr->uh_sport;
6737a99b6783SRandall Stewart 	sp = m_split(m, off, M_DONTWAIT);
6738a99b6783SRandall Stewart 	if (sp == NULL) {
6739a99b6783SRandall Stewart 		/* Gak, drop packet, we can't do a split */
6740a99b6783SRandall Stewart 		goto out;
6741a99b6783SRandall Stewart 	}
6742a99b6783SRandall Stewart 	if (sp->m_pkthdr.len < header_size) {
6743a99b6783SRandall Stewart 		/* Gak, packet can't have an SCTP header in it - to small */
6744a99b6783SRandall Stewart 		m_freem(sp);
6745a99b6783SRandall Stewart 		goto out;
6746a99b6783SRandall Stewart 	}
6747a99b6783SRandall Stewart 	/* ok now pull up the UDP header and SCTP header together */
6748a99b6783SRandall Stewart 	sp = m_pullup(sp, header_size);
6749a99b6783SRandall Stewart 	if (sp == NULL) {
6750a99b6783SRandall Stewart 		/* Gak pullup failed */
6751a99b6783SRandall Stewart 		goto out;
6752a99b6783SRandall Stewart 	}
6753a99b6783SRandall Stewart 	/* trim out the UDP header */
6754a99b6783SRandall Stewart 	m_adj(sp, sizeof(struct udphdr));
6755a99b6783SRandall Stewart 
6756a99b6783SRandall Stewart 	/* Now reconstruct the mbuf chain */
6757a99b6783SRandall Stewart 	/* 1) find last one */
6758a99b6783SRandall Stewart 	last = m;
6759a99b6783SRandall Stewart 	while (last->m_next != NULL) {
6760a99b6783SRandall Stewart 		last = last->m_next;
6761a99b6783SRandall Stewart 	}
6762a99b6783SRandall Stewart 	last->m_next = sp;
6763a99b6783SRandall Stewart 	m->m_pkthdr.len += sp->m_pkthdr.len;
6764a99b6783SRandall Stewart 	last = m;
6765a99b6783SRandall Stewart 	while (last != NULL) {
6766a99b6783SRandall Stewart 		last = last->m_next;
6767a99b6783SRandall Stewart 	}
6768a99b6783SRandall Stewart 	/* Now its ready for sctp_input or sctp6_input */
6769a99b6783SRandall Stewart 	iph = mtod(m, struct ip *);
6770a99b6783SRandall Stewart 	switch (iph->ip_v) {
6771e6194c2eSMichael Tuexen #ifdef INET
6772a99b6783SRandall Stewart 	case IPVERSION:
6773a99b6783SRandall Stewart 		{
6774e6194c2eSMichael Tuexen 			uint16_t len;
6775e6194c2eSMichael Tuexen 
6776a99b6783SRandall Stewart 			/* its IPv4 */
6777a99b6783SRandall Stewart 			len = SCTP_GET_IPV4_LENGTH(iph);
6778a99b6783SRandall Stewart 			len -= sizeof(struct udphdr);
6779a99b6783SRandall Stewart 			SCTP_GET_IPV4_LENGTH(iph) = len;
6780a99b6783SRandall Stewart 			sctp_input_with_port(m, off, port);
6781a99b6783SRandall Stewart 			break;
6782a99b6783SRandall Stewart 		}
6783e6194c2eSMichael Tuexen #endif
6784a99b6783SRandall Stewart #ifdef INET6
6785a99b6783SRandall Stewart 	case IPV6_VERSION >> 4:
6786a99b6783SRandall Stewart 		{
6787a99b6783SRandall Stewart 			/* its IPv6 - NOT supported */
6788a99b6783SRandall Stewart 			goto out;
6789a99b6783SRandall Stewart 			break;
6790a99b6783SRandall Stewart 
6791a99b6783SRandall Stewart 		}
6792a99b6783SRandall Stewart #endif
6793a99b6783SRandall Stewart 	default:
6794a99b6783SRandall Stewart 		{
6795a99b6783SRandall Stewart 			m_freem(m);
6796a99b6783SRandall Stewart 			break;
6797a99b6783SRandall Stewart 		}
6798a99b6783SRandall Stewart 	}
6799a99b6783SRandall Stewart 	return;
6800a99b6783SRandall Stewart out:
6801a99b6783SRandall Stewart 	m_freem(m);
6802a99b6783SRandall Stewart }
6803c54a18d2SRandall Stewart 
6804c54a18d2SRandall Stewart void
6805c54a18d2SRandall Stewart sctp_over_udp_stop(void)
6806c54a18d2SRandall Stewart {
6807a99b6783SRandall Stewart 	struct socket *sop;
6808a99b6783SRandall Stewart 
6809a99b6783SRandall Stewart 	/*
6810a99b6783SRandall Stewart 	 * This function assumes sysctl caller holds sctp_sysctl_info_lock()
6811a99b6783SRandall Stewart 	 * for writting!
6812a99b6783SRandall Stewart 	 */
6813a99b6783SRandall Stewart 	if (SCTP_BASE_INFO(udp_tun_socket) == NULL) {
6814a99b6783SRandall Stewart 		/* Nothing to do */
6815c54a18d2SRandall Stewart 		return;
6816c54a18d2SRandall Stewart 	}
6817a99b6783SRandall Stewart 	sop = SCTP_BASE_INFO(udp_tun_socket);
6818a99b6783SRandall Stewart 	soclose(sop);
6819a99b6783SRandall Stewart 	SCTP_BASE_INFO(udp_tun_socket) = NULL;
6820a99b6783SRandall Stewart }
6821ea5eba11SMichael Tuexen 
6822c54a18d2SRandall Stewart int
6823c54a18d2SRandall Stewart sctp_over_udp_start(void)
6824c54a18d2SRandall Stewart {
6825a99b6783SRandall Stewart 	uint16_t port;
6826a99b6783SRandall Stewart 	int ret;
6827a99b6783SRandall Stewart 	struct sockaddr_in sin;
6828a99b6783SRandall Stewart 	struct socket *sop = NULL;
6829a99b6783SRandall Stewart 	struct thread *th;
6830a99b6783SRandall Stewart 	struct ucred *cred;
6831a99b6783SRandall Stewart 
6832a99b6783SRandall Stewart 	/*
6833a99b6783SRandall Stewart 	 * This function assumes sysctl caller holds sctp_sysctl_info_lock()
6834a99b6783SRandall Stewart 	 * for writting!
6835a99b6783SRandall Stewart 	 */
6836a99b6783SRandall Stewart 	port = SCTP_BASE_SYSCTL(sctp_udp_tunneling_port);
6837a99b6783SRandall Stewart 	if (port == 0) {
6838a99b6783SRandall Stewart 		/* Must have a port set */
6839a99b6783SRandall Stewart 		return (EINVAL);
6840a99b6783SRandall Stewart 	}
6841a99b6783SRandall Stewart 	if (SCTP_BASE_INFO(udp_tun_socket) != NULL) {
6842a99b6783SRandall Stewart 		/* Already running -- must stop first */
6843a99b6783SRandall Stewart 		return (EALREADY);
6844a99b6783SRandall Stewart 	}
6845a99b6783SRandall Stewart 	th = curthread;
6846a99b6783SRandall Stewart 	cred = th->td_ucred;
6847a99b6783SRandall Stewart 	if ((ret = socreate(PF_INET, &sop,
6848a99b6783SRandall Stewart 	    SOCK_DGRAM, IPPROTO_UDP, cred, th))) {
6849a99b6783SRandall Stewart 		return (ret);
6850a99b6783SRandall Stewart 	}
6851a99b6783SRandall Stewart 	SCTP_BASE_INFO(udp_tun_socket) = sop;
6852a99b6783SRandall Stewart 	/* call the special UDP hook */
6853a99b6783SRandall Stewart 	ret = udp_set_kernel_tunneling(sop, sctp_recv_udp_tunneled_packet);
6854a99b6783SRandall Stewart 	if (ret) {
6855a99b6783SRandall Stewart 		goto exit_stage_left;
6856a99b6783SRandall Stewart 	}
6857a99b6783SRandall Stewart 	/* Ok we have a socket, bind it to the port */
6858a99b6783SRandall Stewart 	memset(&sin, 0, sizeof(sin));
6859a99b6783SRandall Stewart 	sin.sin_len = sizeof(sin);
6860a99b6783SRandall Stewart 	sin.sin_family = AF_INET;
6861a99b6783SRandall Stewart 	sin.sin_port = htons(port);
6862a99b6783SRandall Stewart 	ret = sobind(sop, (struct sockaddr *)&sin, th);
6863a99b6783SRandall Stewart 	if (ret) {
6864a99b6783SRandall Stewart 		/* Close up we cant get the port */
6865a99b6783SRandall Stewart exit_stage_left:
6866a99b6783SRandall Stewart 		sctp_over_udp_stop();
6867a99b6783SRandall Stewart 		return (ret);
6868a99b6783SRandall Stewart 	}
6869a99b6783SRandall Stewart 	/*
6870a99b6783SRandall Stewart 	 * Ok we should now get UDP packets directly to our input routine
6871a99b6783SRandall Stewart 	 * sctp_recv_upd_tunneled_packet().
6872a99b6783SRandall Stewart 	 */
6873a99b6783SRandall Stewart 	return (0);
6874c54a18d2SRandall Stewart }
6875ea5eba11SMichael Tuexen 
6876ea5eba11SMichael Tuexen #endif
6877