xref: /freebsd/sys/netinet/sctputil.c (revision ea44232b3aca1fefd7d9000396e56b3521081147)
1f8829a4aSRandall Stewart /*-
2830d754dSRandall Stewart  * Copyright (c) 2001-2008, by Cisco Systems, Inc. All rights reserved.
3f8829a4aSRandall Stewart  *
4f8829a4aSRandall Stewart  * Redistribution and use in source and binary forms, with or without
5f8829a4aSRandall Stewart  * modification, are permitted provided that the following conditions are met:
6f8829a4aSRandall Stewart  *
7f8829a4aSRandall Stewart  * a) Redistributions of source code must retain the above copyright notice,
8f8829a4aSRandall Stewart  *   this list of conditions and the following disclaimer.
9f8829a4aSRandall Stewart  *
10f8829a4aSRandall Stewart  * b) Redistributions in binary form must reproduce the above copyright
11f8829a4aSRandall Stewart  *    notice, this list of conditions and the following disclaimer in
12f8829a4aSRandall Stewart  *   the documentation and/or other materials provided with the distribution.
13f8829a4aSRandall Stewart  *
14f8829a4aSRandall Stewart  * c) Neither the name of Cisco Systems, Inc. nor the names of its
15f8829a4aSRandall Stewart  *    contributors may be used to endorse or promote products derived
16f8829a4aSRandall Stewart  *    from this software without specific prior written permission.
17f8829a4aSRandall Stewart  *
18f8829a4aSRandall Stewart  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
19f8829a4aSRandall Stewart  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
20f8829a4aSRandall Stewart  * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
21f8829a4aSRandall Stewart  * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
22f8829a4aSRandall Stewart  * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
23f8829a4aSRandall Stewart  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
24f8829a4aSRandall Stewart  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
25f8829a4aSRandall Stewart  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
26f8829a4aSRandall Stewart  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
27f8829a4aSRandall Stewart  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
28f8829a4aSRandall Stewart  * THE POSSIBILITY OF SUCH DAMAGE.
29f8829a4aSRandall Stewart  */
30f8829a4aSRandall Stewart 
31f8829a4aSRandall Stewart /* $KAME: sctputil.c,v 1.37 2005/03/07 23:26:09 itojun Exp $	 */
32f8829a4aSRandall Stewart 
33f8829a4aSRandall Stewart #include <sys/cdefs.h>
34f8829a4aSRandall Stewart __FBSDID("$FreeBSD$");
35f8829a4aSRandall Stewart 
36f8829a4aSRandall Stewart #include <netinet/sctp_os.h>
37f8829a4aSRandall Stewart #include <netinet/sctp_pcb.h>
38f8829a4aSRandall Stewart #include <netinet/sctputil.h>
39f8829a4aSRandall Stewart #include <netinet/sctp_var.h>
4042551e99SRandall Stewart #include <netinet/sctp_sysctl.h>
41f8829a4aSRandall Stewart #ifdef INET6
42f8829a4aSRandall Stewart #endif
43f8829a4aSRandall Stewart #include <netinet/sctp_header.h>
44f8829a4aSRandall Stewart #include <netinet/sctp_output.h>
45f8829a4aSRandall Stewart #include <netinet/sctp_uio.h>
46f8829a4aSRandall Stewart #include <netinet/sctp_timer.h>
47f8829a4aSRandall Stewart #include <netinet/sctp_indata.h>/* for sctp_deliver_data() */
48f8829a4aSRandall Stewart #include <netinet/sctp_auth.h>
49f8829a4aSRandall Stewart #include <netinet/sctp_asconf.h>
50b54d3a6cSRandall Stewart #include <netinet/sctp_cc_functions.h>
51f8829a4aSRandall Stewart 
52f8829a4aSRandall Stewart #define NUMBER_OF_MTU_SIZES 18
53f8829a4aSRandall Stewart 
54f8829a4aSRandall Stewart 
55a99b6783SRandall Stewart #if defined(__Windows__) && !defined(SCTP_LOCAL_TRACE_BUF)
56a99b6783SRandall Stewart #include "eventrace_netinet.h"
57a99b6783SRandall Stewart #include "sctputil.tmh"		/* this is the file that will be auto
58a99b6783SRandall Stewart 				 * generated */
59a99b6783SRandall Stewart #else
60b9e7085aSRandall Stewart #ifndef KTR_SCTP
61b9e7085aSRandall Stewart #define KTR_SCTP KTR_SUBSYS
6280fefe0aSRandall Stewart #endif
63a99b6783SRandall Stewart #endif
64f8829a4aSRandall Stewart 
65f8829a4aSRandall Stewart void
66f8829a4aSRandall Stewart sctp_sblog(struct sockbuf *sb,
67f8829a4aSRandall Stewart     struct sctp_tcb *stcb, int from, int incr)
68f8829a4aSRandall Stewart {
6980fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
70f8829a4aSRandall Stewart 
7180fefe0aSRandall Stewart 	sctp_clog.x.sb.stcb = stcb;
7280fefe0aSRandall Stewart 	sctp_clog.x.sb.so_sbcc = sb->sb_cc;
73f8829a4aSRandall Stewart 	if (stcb)
7480fefe0aSRandall Stewart 		sctp_clog.x.sb.stcb_sbcc = stcb->asoc.sb_cc;
75f8829a4aSRandall Stewart 	else
7680fefe0aSRandall Stewart 		sctp_clog.x.sb.stcb_sbcc = 0;
7780fefe0aSRandall Stewart 	sctp_clog.x.sb.incr = incr;
78c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
7980fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_SB,
8080fefe0aSRandall Stewart 	    from,
8180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
8280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
8380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
8480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
85f8829a4aSRandall Stewart }
86f8829a4aSRandall Stewart 
87f8829a4aSRandall Stewart void
88f8829a4aSRandall Stewart sctp_log_closing(struct sctp_inpcb *inp, struct sctp_tcb *stcb, int16_t loc)
89f8829a4aSRandall Stewart {
9080fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
91f8829a4aSRandall Stewart 
9280fefe0aSRandall Stewart 	sctp_clog.x.close.inp = (void *)inp;
9380fefe0aSRandall Stewart 	sctp_clog.x.close.sctp_flags = inp->sctp_flags;
94f8829a4aSRandall Stewart 	if (stcb) {
9580fefe0aSRandall Stewart 		sctp_clog.x.close.stcb = (void *)stcb;
9680fefe0aSRandall Stewart 		sctp_clog.x.close.state = (uint16_t) stcb->asoc.state;
97f8829a4aSRandall Stewart 	} else {
9880fefe0aSRandall Stewart 		sctp_clog.x.close.stcb = 0;
9980fefe0aSRandall Stewart 		sctp_clog.x.close.state = 0;
100f8829a4aSRandall Stewart 	}
10180fefe0aSRandall Stewart 	sctp_clog.x.close.loc = loc;
102c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
10380fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_CLOSE,
10480fefe0aSRandall Stewart 	    0,
10580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
10680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
10780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
10880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
109f8829a4aSRandall Stewart }
110f8829a4aSRandall Stewart 
111f8829a4aSRandall Stewart 
112f8829a4aSRandall Stewart void
113f8829a4aSRandall Stewart rto_logging(struct sctp_nets *net, int from)
114f8829a4aSRandall Stewart {
11580fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
116f8829a4aSRandall Stewart 
117bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
11880fefe0aSRandall Stewart 	sctp_clog.x.rto.net = (void *)net;
11980fefe0aSRandall Stewart 	sctp_clog.x.rto.rtt = net->prev_rtt;
120c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
12180fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RTT,
12280fefe0aSRandall Stewart 	    from,
12380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
12480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
12580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
12680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
12780fefe0aSRandall Stewart 
128f8829a4aSRandall Stewart }
129f8829a4aSRandall Stewart 
130f8829a4aSRandall Stewart void
1316a91f103SRandall Stewart sctp_log_strm_del_alt(struct sctp_tcb *stcb, uint32_t tsn, uint16_t sseq, uint16_t stream, int from)
132f8829a4aSRandall Stewart {
13380fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
134f8829a4aSRandall Stewart 
13580fefe0aSRandall Stewart 	sctp_clog.x.strlog.stcb = stcb;
13680fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_tsn = tsn;
13780fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_sseq = sseq;
13880fefe0aSRandall Stewart 	sctp_clog.x.strlog.e_tsn = 0;
13980fefe0aSRandall Stewart 	sctp_clog.x.strlog.e_sseq = 0;
14080fefe0aSRandall Stewart 	sctp_clog.x.strlog.strm = stream;
141c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
14280fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_STRM,
14380fefe0aSRandall Stewart 	    from,
14480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
14580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
14680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
14780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
14880fefe0aSRandall Stewart 
149f8829a4aSRandall Stewart }
150f8829a4aSRandall Stewart 
151f8829a4aSRandall Stewart void
152f8829a4aSRandall Stewart sctp_log_nagle_event(struct sctp_tcb *stcb, int action)
153f8829a4aSRandall Stewart {
15480fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
155f8829a4aSRandall Stewart 
15680fefe0aSRandall Stewart 	sctp_clog.x.nagle.stcb = (void *)stcb;
15780fefe0aSRandall Stewart 	sctp_clog.x.nagle.total_flight = stcb->asoc.total_flight;
15880fefe0aSRandall Stewart 	sctp_clog.x.nagle.total_in_queue = stcb->asoc.total_output_queue_size;
15980fefe0aSRandall Stewart 	sctp_clog.x.nagle.count_in_queue = stcb->asoc.chunks_on_out_queue;
16080fefe0aSRandall Stewart 	sctp_clog.x.nagle.count_in_flight = stcb->asoc.total_flight_count;
161c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
16280fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_NAGLE,
16380fefe0aSRandall Stewart 	    action,
16480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
16580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
16680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
16780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
168f8829a4aSRandall Stewart }
169f8829a4aSRandall Stewart 
170f8829a4aSRandall Stewart 
171f8829a4aSRandall Stewart void
172f8829a4aSRandall Stewart sctp_log_sack(uint32_t old_cumack, uint32_t cumack, uint32_t tsn, uint16_t gaps, uint16_t dups, int from)
173f8829a4aSRandall Stewart {
17480fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
175f8829a4aSRandall Stewart 
17680fefe0aSRandall Stewart 	sctp_clog.x.sack.cumack = cumack;
17780fefe0aSRandall Stewart 	sctp_clog.x.sack.oldcumack = old_cumack;
17880fefe0aSRandall Stewart 	sctp_clog.x.sack.tsn = tsn;
17980fefe0aSRandall Stewart 	sctp_clog.x.sack.numGaps = gaps;
18080fefe0aSRandall Stewart 	sctp_clog.x.sack.numDups = dups;
181c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
18280fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_SACK,
18380fefe0aSRandall Stewart 	    from,
18480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
18580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
18680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
18780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
188f8829a4aSRandall Stewart }
189f8829a4aSRandall Stewart 
190f8829a4aSRandall Stewart void
191f8829a4aSRandall Stewart sctp_log_map(uint32_t map, uint32_t cum, uint32_t high, int from)
192f8829a4aSRandall Stewart {
19380fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
194f8829a4aSRandall Stewart 
195bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
19680fefe0aSRandall Stewart 	sctp_clog.x.map.base = map;
19780fefe0aSRandall Stewart 	sctp_clog.x.map.cum = cum;
19880fefe0aSRandall Stewart 	sctp_clog.x.map.high = high;
199c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
20080fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MAP,
20180fefe0aSRandall Stewart 	    from,
20280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
20380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
20480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
20580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
206f8829a4aSRandall Stewart }
207f8829a4aSRandall Stewart 
208f8829a4aSRandall Stewart void
209f8829a4aSRandall Stewart sctp_log_fr(uint32_t biggest_tsn, uint32_t biggest_new_tsn, uint32_t tsn,
210f8829a4aSRandall Stewart     int from)
211f8829a4aSRandall Stewart {
21280fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
213f8829a4aSRandall Stewart 
214bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
21580fefe0aSRandall Stewart 	sctp_clog.x.fr.largest_tsn = biggest_tsn;
21680fefe0aSRandall Stewart 	sctp_clog.x.fr.largest_new_tsn = biggest_new_tsn;
21780fefe0aSRandall Stewart 	sctp_clog.x.fr.tsn = tsn;
218c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
21980fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_FR,
22080fefe0aSRandall Stewart 	    from,
22180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
22280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
22380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
22480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
22580fefe0aSRandall Stewart 
226f8829a4aSRandall Stewart }
227f8829a4aSRandall Stewart 
228f8829a4aSRandall Stewart 
229f8829a4aSRandall Stewart void
230f8829a4aSRandall Stewart sctp_log_mb(struct mbuf *m, int from)
231f8829a4aSRandall Stewart {
23280fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
233f8829a4aSRandall Stewart 
23480fefe0aSRandall Stewart 	sctp_clog.x.mb.mp = m;
23580fefe0aSRandall Stewart 	sctp_clog.x.mb.mbuf_flags = (uint8_t) (SCTP_BUF_GET_FLAGS(m));
23680fefe0aSRandall Stewart 	sctp_clog.x.mb.size = (uint16_t) (SCTP_BUF_LEN(m));
23780fefe0aSRandall Stewart 	sctp_clog.x.mb.data = SCTP_BUF_AT(m, 0);
238139bc87fSRandall Stewart 	if (SCTP_BUF_IS_EXTENDED(m)) {
23980fefe0aSRandall Stewart 		sctp_clog.x.mb.ext = SCTP_BUF_EXTEND_BASE(m);
24080fefe0aSRandall Stewart 		sctp_clog.x.mb.refcnt = (uint8_t) (SCTP_BUF_EXTEND_REFCNT(m));
241f8829a4aSRandall Stewart 	} else {
24280fefe0aSRandall Stewart 		sctp_clog.x.mb.ext = 0;
24380fefe0aSRandall Stewart 		sctp_clog.x.mb.refcnt = 0;
244f8829a4aSRandall Stewart 	}
245c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
24680fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MBUF,
24780fefe0aSRandall Stewart 	    from,
24880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
24980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
25080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
25180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
252f8829a4aSRandall Stewart }
253f8829a4aSRandall Stewart 
254f8829a4aSRandall Stewart 
255f8829a4aSRandall Stewart void
256f8829a4aSRandall Stewart sctp_log_strm_del(struct sctp_queued_to_read *control, struct sctp_queued_to_read *poschk,
257f8829a4aSRandall Stewart     int from)
258f8829a4aSRandall Stewart {
25980fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
260f8829a4aSRandall Stewart 
261f8829a4aSRandall Stewart 	if (control == NULL) {
262ad81507eSRandall Stewart 		SCTP_PRINTF("Gak log of NULL?\n");
263f8829a4aSRandall Stewart 		return;
264f8829a4aSRandall Stewart 	}
26580fefe0aSRandall Stewart 	sctp_clog.x.strlog.stcb = control->stcb;
26680fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_tsn = control->sinfo_tsn;
26780fefe0aSRandall Stewart 	sctp_clog.x.strlog.n_sseq = control->sinfo_ssn;
26880fefe0aSRandall Stewart 	sctp_clog.x.strlog.strm = control->sinfo_stream;
269f8829a4aSRandall Stewart 	if (poschk != NULL) {
27080fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_tsn = poschk->sinfo_tsn;
27180fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_sseq = poschk->sinfo_ssn;
272f8829a4aSRandall Stewart 	} else {
27380fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_tsn = 0;
27480fefe0aSRandall Stewart 		sctp_clog.x.strlog.e_sseq = 0;
275f8829a4aSRandall Stewart 	}
276c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
27780fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_STRM,
27880fefe0aSRandall Stewart 	    from,
27980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
28080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
28180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
28280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
28380fefe0aSRandall Stewart 
284f8829a4aSRandall Stewart }
285f8829a4aSRandall Stewart 
286f8829a4aSRandall Stewart void
287f8829a4aSRandall Stewart sctp_log_cwnd(struct sctp_tcb *stcb, struct sctp_nets *net, int augment, uint8_t from)
288f8829a4aSRandall Stewart {
28980fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
290f8829a4aSRandall Stewart 
29180fefe0aSRandall Stewart 	sctp_clog.x.cwnd.net = net;
292f8829a4aSRandall Stewart 	if (stcb->asoc.send_queue_cnt > 255)
29380fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = 255;
294f8829a4aSRandall Stewart 	else
29580fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = stcb->asoc.send_queue_cnt;
296f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt > 255)
29780fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = 255;
298f8829a4aSRandall Stewart 	else
29980fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = stcb->asoc.stream_queue_cnt;
300f8829a4aSRandall Stewart 
301f8829a4aSRandall Stewart 	if (net) {
30280fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cwnd_new_value = net->cwnd;
30380fefe0aSRandall Stewart 		sctp_clog.x.cwnd.inflight = net->flight_size;
30480fefe0aSRandall Stewart 		sctp_clog.x.cwnd.pseudo_cumack = net->pseudo_cumack;
30580fefe0aSRandall Stewart 		sctp_clog.x.cwnd.meets_pseudo_cumack = net->new_pseudo_cumack;
30680fefe0aSRandall Stewart 		sctp_clog.x.cwnd.need_new_pseudo_cumack = net->find_pseudo_cumack;
307f8829a4aSRandall Stewart 	}
308f8829a4aSRandall Stewart 	if (SCTP_CWNDLOG_PRESEND == from) {
30980fefe0aSRandall Stewart 		sctp_clog.x.cwnd.meets_pseudo_cumack = stcb->asoc.peers_rwnd;
310f8829a4aSRandall Stewart 	}
31180fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_augment = augment;
312c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
31380fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_CWND,
31480fefe0aSRandall Stewart 	    from,
31580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
31680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
31780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
31880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
31980fefe0aSRandall Stewart 
320f8829a4aSRandall Stewart }
321f8829a4aSRandall Stewart 
322f8829a4aSRandall Stewart void
323f8829a4aSRandall Stewart sctp_log_lock(struct sctp_inpcb *inp, struct sctp_tcb *stcb, uint8_t from)
324f8829a4aSRandall Stewart {
32580fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
326f8829a4aSRandall Stewart 
327bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
32803b0b021SRandall Stewart 	if (inp) {
32980fefe0aSRandall Stewart 		sctp_clog.x.lock.sock = (void *)inp->sctp_socket;
33003b0b021SRandall Stewart 
33103b0b021SRandall Stewart 	} else {
33280fefe0aSRandall Stewart 		sctp_clog.x.lock.sock = (void *)NULL;
33303b0b021SRandall Stewart 	}
33480fefe0aSRandall Stewart 	sctp_clog.x.lock.inp = (void *)inp;
335f8829a4aSRandall Stewart 	if (stcb) {
33680fefe0aSRandall Stewart 		sctp_clog.x.lock.tcb_lock = mtx_owned(&stcb->tcb_mtx);
337f8829a4aSRandall Stewart 	} else {
33880fefe0aSRandall Stewart 		sctp_clog.x.lock.tcb_lock = SCTP_LOCK_UNKNOWN;
339f8829a4aSRandall Stewart 	}
340f8829a4aSRandall Stewart 	if (inp) {
34180fefe0aSRandall Stewart 		sctp_clog.x.lock.inp_lock = mtx_owned(&inp->inp_mtx);
34280fefe0aSRandall Stewart 		sctp_clog.x.lock.create_lock = mtx_owned(&inp->inp_create_mtx);
343f8829a4aSRandall Stewart 	} else {
34480fefe0aSRandall Stewart 		sctp_clog.x.lock.inp_lock = SCTP_LOCK_UNKNOWN;
34580fefe0aSRandall Stewart 		sctp_clog.x.lock.create_lock = SCTP_LOCK_UNKNOWN;
346f8829a4aSRandall Stewart 	}
347b3f1ea41SRandall Stewart 	sctp_clog.x.lock.info_lock = rw_wowned(&SCTP_BASE_INFO(ipi_ep_mtx));
348f8829a4aSRandall Stewart 	if (inp->sctp_socket) {
34980fefe0aSRandall Stewart 		sctp_clog.x.lock.sock_lock = mtx_owned(&(inp->sctp_socket->so_rcv.sb_mtx));
35080fefe0aSRandall Stewart 		sctp_clog.x.lock.sockrcvbuf_lock = mtx_owned(&(inp->sctp_socket->so_rcv.sb_mtx));
35180fefe0aSRandall Stewart 		sctp_clog.x.lock.socksndbuf_lock = mtx_owned(&(inp->sctp_socket->so_snd.sb_mtx));
352f8829a4aSRandall Stewart 	} else {
35380fefe0aSRandall Stewart 		sctp_clog.x.lock.sock_lock = SCTP_LOCK_UNKNOWN;
35480fefe0aSRandall Stewart 		sctp_clog.x.lock.sockrcvbuf_lock = SCTP_LOCK_UNKNOWN;
35580fefe0aSRandall Stewart 		sctp_clog.x.lock.socksndbuf_lock = SCTP_LOCK_UNKNOWN;
356f8829a4aSRandall Stewart 	}
357c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
35880fefe0aSRandall Stewart 	    SCTP_LOG_LOCK_EVENT,
35980fefe0aSRandall Stewart 	    from,
36080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
36180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
36280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
36380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
36480fefe0aSRandall Stewart 
365f8829a4aSRandall Stewart }
366f8829a4aSRandall Stewart 
367f8829a4aSRandall Stewart void
368f8829a4aSRandall Stewart sctp_log_maxburst(struct sctp_tcb *stcb, struct sctp_nets *net, int error, int burst, uint8_t from)
369f8829a4aSRandall Stewart {
37080fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
371f8829a4aSRandall Stewart 
372bfefd190SRandall Stewart 	memset(&sctp_clog, 0, sizeof(sctp_clog));
37380fefe0aSRandall Stewart 	sctp_clog.x.cwnd.net = net;
37480fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_new_value = error;
37580fefe0aSRandall Stewart 	sctp_clog.x.cwnd.inflight = net->flight_size;
37680fefe0aSRandall Stewart 	sctp_clog.x.cwnd.cwnd_augment = burst;
377f8829a4aSRandall Stewart 	if (stcb->asoc.send_queue_cnt > 255)
37880fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = 255;
379f8829a4aSRandall Stewart 	else
38080fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_send = stcb->asoc.send_queue_cnt;
381f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt > 255)
38280fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = 255;
383f8829a4aSRandall Stewart 	else
38480fefe0aSRandall Stewart 		sctp_clog.x.cwnd.cnt_in_str = stcb->asoc.stream_queue_cnt;
385c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
38680fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MAXBURST,
38780fefe0aSRandall Stewart 	    from,
38880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
38980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
39080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
39180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
39280fefe0aSRandall Stewart 
393f8829a4aSRandall Stewart }
394f8829a4aSRandall Stewart 
395f8829a4aSRandall Stewart void
396f8829a4aSRandall Stewart sctp_log_rwnd(uint8_t from, uint32_t peers_rwnd, uint32_t snd_size, uint32_t overhead)
397f8829a4aSRandall Stewart {
39880fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
399f8829a4aSRandall Stewart 
40080fefe0aSRandall Stewart 	sctp_clog.x.rwnd.rwnd = peers_rwnd;
40180fefe0aSRandall Stewart 	sctp_clog.x.rwnd.send_size = snd_size;
40280fefe0aSRandall Stewart 	sctp_clog.x.rwnd.overhead = overhead;
40380fefe0aSRandall Stewart 	sctp_clog.x.rwnd.new_rwnd = 0;
404c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
40580fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RWND,
40680fefe0aSRandall Stewart 	    from,
40780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
40880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
40980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
41080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
411f8829a4aSRandall Stewart }
412f8829a4aSRandall Stewart 
413f8829a4aSRandall Stewart void
414f8829a4aSRandall Stewart sctp_log_rwnd_set(uint8_t from, uint32_t peers_rwnd, uint32_t flight_size, uint32_t overhead, uint32_t a_rwndval)
415f8829a4aSRandall Stewart {
41680fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
417f8829a4aSRandall Stewart 
41880fefe0aSRandall Stewart 	sctp_clog.x.rwnd.rwnd = peers_rwnd;
41980fefe0aSRandall Stewart 	sctp_clog.x.rwnd.send_size = flight_size;
42080fefe0aSRandall Stewart 	sctp_clog.x.rwnd.overhead = overhead;
42180fefe0aSRandall Stewart 	sctp_clog.x.rwnd.new_rwnd = a_rwndval;
422c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
42380fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_RWND,
42480fefe0aSRandall Stewart 	    from,
42580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
42680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
42780fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
42880fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
429f8829a4aSRandall Stewart }
430f8829a4aSRandall Stewart 
431f8829a4aSRandall Stewart void
432f8829a4aSRandall Stewart sctp_log_mbcnt(uint8_t from, uint32_t total_oq, uint32_t book, uint32_t total_mbcnt_q, uint32_t mbcnt)
433f8829a4aSRandall Stewart {
43480fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
435f8829a4aSRandall Stewart 
43680fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.total_queue_size = total_oq;
43780fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.size_change = book;
43880fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.total_queue_mb_size = total_mbcnt_q;
43980fefe0aSRandall Stewart 	sctp_clog.x.mbcnt.mbcnt_change = mbcnt;
440c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
44180fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_MBCNT,
44280fefe0aSRandall Stewart 	    from,
44380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
44480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
44580fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
44680fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
44780fefe0aSRandall Stewart 
448f8829a4aSRandall Stewart }
449f8829a4aSRandall Stewart 
450f8829a4aSRandall Stewart void
451f8829a4aSRandall Stewart sctp_misc_ints(uint8_t from, uint32_t a, uint32_t b, uint32_t c, uint32_t d)
452f8829a4aSRandall Stewart {
453c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
45480fefe0aSRandall Stewart 	    SCTP_LOG_MISC_EVENT,
45580fefe0aSRandall Stewart 	    from,
45680fefe0aSRandall Stewart 	    a, b, c, d);
457f8829a4aSRandall Stewart }
458f8829a4aSRandall Stewart 
459f8829a4aSRandall Stewart void
460f8829a4aSRandall Stewart sctp_wakeup_log(struct sctp_tcb *stcb, uint32_t cumtsn, uint32_t wake_cnt, int from)
461f8829a4aSRandall Stewart {
46280fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
463f8829a4aSRandall Stewart 
46480fefe0aSRandall Stewart 	sctp_clog.x.wake.stcb = (void *)stcb;
46580fefe0aSRandall Stewart 	sctp_clog.x.wake.wake_cnt = wake_cnt;
46680fefe0aSRandall Stewart 	sctp_clog.x.wake.flight = stcb->asoc.total_flight_count;
46780fefe0aSRandall Stewart 	sctp_clog.x.wake.send_q = stcb->asoc.send_queue_cnt;
46880fefe0aSRandall Stewart 	sctp_clog.x.wake.sent_q = stcb->asoc.sent_queue_cnt;
469f8829a4aSRandall Stewart 
470f8829a4aSRandall Stewart 	if (stcb->asoc.stream_queue_cnt < 0xff)
47180fefe0aSRandall Stewart 		sctp_clog.x.wake.stream_qcnt = (uint8_t) stcb->asoc.stream_queue_cnt;
472f8829a4aSRandall Stewart 	else
47380fefe0aSRandall Stewart 		sctp_clog.x.wake.stream_qcnt = 0xff;
474f8829a4aSRandall Stewart 
475f8829a4aSRandall Stewart 	if (stcb->asoc.chunks_on_out_queue < 0xff)
47680fefe0aSRandall Stewart 		sctp_clog.x.wake.chunks_on_oque = (uint8_t) stcb->asoc.chunks_on_out_queue;
477f8829a4aSRandall Stewart 	else
47880fefe0aSRandall Stewart 		sctp_clog.x.wake.chunks_on_oque = 0xff;
479f8829a4aSRandall Stewart 
48080fefe0aSRandall Stewart 	sctp_clog.x.wake.sctpflags = 0;
481f8829a4aSRandall Stewart 	/* set in the defered mode stuff */
482f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_DONT_WAKE)
48380fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 1;
484f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_WAKEOUTPUT)
48580fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 2;
486f8829a4aSRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_WAKEINPUT)
48780fefe0aSRandall Stewart 		sctp_clog.x.wake.sctpflags |= 4;
488f8829a4aSRandall Stewart 	/* what about the sb */
489f8829a4aSRandall Stewart 	if (stcb->sctp_socket) {
490f8829a4aSRandall Stewart 		struct socket *so = stcb->sctp_socket;
491f8829a4aSRandall Stewart 
49280fefe0aSRandall Stewart 		sctp_clog.x.wake.sbflags = (uint8_t) ((so->so_snd.sb_flags & 0x00ff));
493f8829a4aSRandall Stewart 	} else {
49480fefe0aSRandall Stewart 		sctp_clog.x.wake.sbflags = 0xff;
495f8829a4aSRandall Stewart 	}
496c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
49780fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_WAKE,
49880fefe0aSRandall Stewart 	    from,
49980fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
50080fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
50180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
50280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
50380fefe0aSRandall Stewart 
504f8829a4aSRandall Stewart }
505f8829a4aSRandall Stewart 
506f8829a4aSRandall Stewart void
507f8829a4aSRandall Stewart sctp_log_block(uint8_t from, struct socket *so, struct sctp_association *asoc, int sendlen)
508f8829a4aSRandall Stewart {
50980fefe0aSRandall Stewart 	struct sctp_cwnd_log sctp_clog;
510f8829a4aSRandall Stewart 
51180fefe0aSRandall Stewart 	sctp_clog.x.blk.onsb = asoc->total_output_queue_size;
51280fefe0aSRandall Stewart 	sctp_clog.x.blk.send_sent_qcnt = (uint16_t) (asoc->send_queue_cnt + asoc->sent_queue_cnt);
51380fefe0aSRandall Stewart 	sctp_clog.x.blk.peer_rwnd = asoc->peers_rwnd;
51480fefe0aSRandall Stewart 	sctp_clog.x.blk.stream_qcnt = (uint16_t) asoc->stream_queue_cnt;
51580fefe0aSRandall Stewart 	sctp_clog.x.blk.chunks_on_oque = (uint16_t) asoc->chunks_on_out_queue;
51680fefe0aSRandall Stewart 	sctp_clog.x.blk.flight_size = (uint16_t) (asoc->total_flight / 1024);
51780fefe0aSRandall Stewart 	sctp_clog.x.blk.sndlen = sendlen;
518c4739e2fSRandall Stewart 	SCTP_CTR6(KTR_SCTP, "SCTP:%d[%d]:%x-%x-%x-%x",
51980fefe0aSRandall Stewart 	    SCTP_LOG_EVENT_BLOCK,
52080fefe0aSRandall Stewart 	    from,
52180fefe0aSRandall Stewart 	    sctp_clog.x.misc.log1,
52280fefe0aSRandall Stewart 	    sctp_clog.x.misc.log2,
52380fefe0aSRandall Stewart 	    sctp_clog.x.misc.log3,
52480fefe0aSRandall Stewart 	    sctp_clog.x.misc.log4);
52580fefe0aSRandall Stewart 
526f8829a4aSRandall Stewart }
527f8829a4aSRandall Stewart 
528f8829a4aSRandall Stewart int
52942551e99SRandall Stewart sctp_fill_stat_log(void *optval, size_t *optsize)
530f8829a4aSRandall Stewart {
53180fefe0aSRandall Stewart 	/* May need to fix this if ktrdump does not work */
532f8829a4aSRandall Stewart 	return (0);
533f8829a4aSRandall Stewart }
534f8829a4aSRandall Stewart 
535f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
536f8829a4aSRandall Stewart uint8_t sctp_audit_data[SCTP_AUDIT_SIZE][2];
537f8829a4aSRandall Stewart static int sctp_audit_indx = 0;
538f8829a4aSRandall Stewart 
539f8829a4aSRandall Stewart static
540f8829a4aSRandall Stewart void
541f8829a4aSRandall Stewart sctp_print_audit_report(void)
542f8829a4aSRandall Stewart {
543f8829a4aSRandall Stewart 	int i;
544f8829a4aSRandall Stewart 	int cnt;
545f8829a4aSRandall Stewart 
546f8829a4aSRandall Stewart 	cnt = 0;
547f8829a4aSRandall Stewart 	for (i = sctp_audit_indx; i < SCTP_AUDIT_SIZE; i++) {
548f8829a4aSRandall Stewart 		if ((sctp_audit_data[i][0] == 0xe0) &&
549f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
550f8829a4aSRandall Stewart 			cnt = 0;
551ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
552f8829a4aSRandall Stewart 		} else if (sctp_audit_data[i][0] == 0xf0) {
553f8829a4aSRandall Stewart 			cnt = 0;
554ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
555f8829a4aSRandall Stewart 		} else if ((sctp_audit_data[i][0] == 0xc0) &&
556f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
557ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
558f8829a4aSRandall Stewart 			cnt = 0;
559f8829a4aSRandall Stewart 		}
560ad81507eSRandall Stewart 		SCTP_PRINTF("%2.2x%2.2x ", (uint32_t) sctp_audit_data[i][0],
561f8829a4aSRandall Stewart 		    (uint32_t) sctp_audit_data[i][1]);
562f8829a4aSRandall Stewart 		cnt++;
563f8829a4aSRandall Stewart 		if ((cnt % 14) == 0)
564ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
565f8829a4aSRandall Stewart 	}
566f8829a4aSRandall Stewart 	for (i = 0; i < sctp_audit_indx; i++) {
567f8829a4aSRandall Stewart 		if ((sctp_audit_data[i][0] == 0xe0) &&
568f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
569f8829a4aSRandall Stewart 			cnt = 0;
570ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
571f8829a4aSRandall Stewart 		} else if (sctp_audit_data[i][0] == 0xf0) {
572f8829a4aSRandall Stewart 			cnt = 0;
573ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
574f8829a4aSRandall Stewart 		} else if ((sctp_audit_data[i][0] == 0xc0) &&
575f8829a4aSRandall Stewart 		    (sctp_audit_data[i][1] == 0x01)) {
576ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
577f8829a4aSRandall Stewart 			cnt = 0;
578f8829a4aSRandall Stewart 		}
579ad81507eSRandall Stewart 		SCTP_PRINTF("%2.2x%2.2x ", (uint32_t) sctp_audit_data[i][0],
580f8829a4aSRandall Stewart 		    (uint32_t) sctp_audit_data[i][1]);
581f8829a4aSRandall Stewart 		cnt++;
582f8829a4aSRandall Stewart 		if ((cnt % 14) == 0)
583ad81507eSRandall Stewart 			SCTP_PRINTF("\n");
584f8829a4aSRandall Stewart 	}
585ad81507eSRandall Stewart 	SCTP_PRINTF("\n");
586f8829a4aSRandall Stewart }
587f8829a4aSRandall Stewart 
588f8829a4aSRandall Stewart void
589f8829a4aSRandall Stewart sctp_auditing(int from, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
590f8829a4aSRandall Stewart     struct sctp_nets *net)
591f8829a4aSRandall Stewart {
592f8829a4aSRandall Stewart 	int resend_cnt, tot_out, rep, tot_book_cnt;
593f8829a4aSRandall Stewart 	struct sctp_nets *lnet;
594f8829a4aSRandall Stewart 	struct sctp_tmit_chunk *chk;
595f8829a4aSRandall Stewart 
596f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = 0xAA;
597f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] = 0x000000ff & from;
598f8829a4aSRandall Stewart 	sctp_audit_indx++;
599f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
600f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
601f8829a4aSRandall Stewart 	}
602f8829a4aSRandall Stewart 	if (inp == NULL) {
603f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
604f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0x01;
605f8829a4aSRandall Stewart 		sctp_audit_indx++;
606f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
607f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
608f8829a4aSRandall Stewart 		}
609f8829a4aSRandall Stewart 		return;
610f8829a4aSRandall Stewart 	}
611f8829a4aSRandall Stewart 	if (stcb == NULL) {
612f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
613f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0x02;
614f8829a4aSRandall Stewart 		sctp_audit_indx++;
615f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
616f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
617f8829a4aSRandall Stewart 		}
618f8829a4aSRandall Stewart 		return;
619f8829a4aSRandall Stewart 	}
620f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = 0xA1;
621f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] =
622f8829a4aSRandall Stewart 	    (0x000000ff & stcb->asoc.sent_queue_retran_cnt);
623f8829a4aSRandall Stewart 	sctp_audit_indx++;
624f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
625f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
626f8829a4aSRandall Stewart 	}
627f8829a4aSRandall Stewart 	rep = 0;
628f8829a4aSRandall Stewart 	tot_book_cnt = 0;
629f8829a4aSRandall Stewart 	resend_cnt = tot_out = 0;
630f8829a4aSRandall Stewart 	TAILQ_FOREACH(chk, &stcb->asoc.sent_queue, sctp_next) {
631f8829a4aSRandall Stewart 		if (chk->sent == SCTP_DATAGRAM_RESEND) {
632f8829a4aSRandall Stewart 			resend_cnt++;
633f8829a4aSRandall Stewart 		} else if (chk->sent < SCTP_DATAGRAM_RESEND) {
634f8829a4aSRandall Stewart 			tot_out += chk->book_size;
635f8829a4aSRandall Stewart 			tot_book_cnt++;
636f8829a4aSRandall Stewart 		}
637f8829a4aSRandall Stewart 	}
638f8829a4aSRandall Stewart 	if (resend_cnt != stcb->asoc.sent_queue_retran_cnt) {
639f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
640f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA1;
641f8829a4aSRandall Stewart 		sctp_audit_indx++;
642f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
643f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
644f8829a4aSRandall Stewart 		}
645ad81507eSRandall Stewart 		SCTP_PRINTF("resend_cnt:%d asoc-tot:%d\n",
646f8829a4aSRandall Stewart 		    resend_cnt, stcb->asoc.sent_queue_retran_cnt);
647f8829a4aSRandall Stewart 		rep = 1;
648f8829a4aSRandall Stewart 		stcb->asoc.sent_queue_retran_cnt = resend_cnt;
649f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xA2;
650f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] =
651f8829a4aSRandall Stewart 		    (0x000000ff & stcb->asoc.sent_queue_retran_cnt);
652f8829a4aSRandall Stewart 		sctp_audit_indx++;
653f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
654f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
655f8829a4aSRandall Stewart 		}
656f8829a4aSRandall Stewart 	}
657f8829a4aSRandall Stewart 	if (tot_out != stcb->asoc.total_flight) {
658f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
659f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA2;
660f8829a4aSRandall Stewart 		sctp_audit_indx++;
661f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
662f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
663f8829a4aSRandall Stewart 		}
664f8829a4aSRandall Stewart 		rep = 1;
665ad81507eSRandall Stewart 		SCTP_PRINTF("tot_flt:%d asoc_tot:%d\n", tot_out,
666f8829a4aSRandall Stewart 		    (int)stcb->asoc.total_flight);
667f8829a4aSRandall Stewart 		stcb->asoc.total_flight = tot_out;
668f8829a4aSRandall Stewart 	}
669f8829a4aSRandall Stewart 	if (tot_book_cnt != stcb->asoc.total_flight_count) {
670f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
671f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA5;
672f8829a4aSRandall Stewart 		sctp_audit_indx++;
673f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
674f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
675f8829a4aSRandall Stewart 		}
676f8829a4aSRandall Stewart 		rep = 1;
677ad81507eSRandall Stewart 		SCTP_PRINTF("tot_flt_book:%d\n", tot_book);
678f8829a4aSRandall Stewart 
679f8829a4aSRandall Stewart 		stcb->asoc.total_flight_count = tot_book_cnt;
680f8829a4aSRandall Stewart 	}
681f8829a4aSRandall Stewart 	tot_out = 0;
682f8829a4aSRandall Stewart 	TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
683f8829a4aSRandall Stewart 		tot_out += lnet->flight_size;
684f8829a4aSRandall Stewart 	}
685f8829a4aSRandall Stewart 	if (tot_out != stcb->asoc.total_flight) {
686f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][0] = 0xAF;
687f8829a4aSRandall Stewart 		sctp_audit_data[sctp_audit_indx][1] = 0xA3;
688f8829a4aSRandall Stewart 		sctp_audit_indx++;
689f8829a4aSRandall Stewart 		if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
690f8829a4aSRandall Stewart 			sctp_audit_indx = 0;
691f8829a4aSRandall Stewart 		}
692f8829a4aSRandall Stewart 		rep = 1;
693ad81507eSRandall Stewart 		SCTP_PRINTF("real flight:%d net total was %d\n",
694f8829a4aSRandall Stewart 		    stcb->asoc.total_flight, tot_out);
695f8829a4aSRandall Stewart 		/* now corrective action */
696f8829a4aSRandall Stewart 		TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
697f8829a4aSRandall Stewart 
698f8829a4aSRandall Stewart 			tot_out = 0;
699f8829a4aSRandall Stewart 			TAILQ_FOREACH(chk, &stcb->asoc.sent_queue, sctp_next) {
700f8829a4aSRandall Stewart 				if ((chk->whoTo == lnet) &&
701f8829a4aSRandall Stewart 				    (chk->sent < SCTP_DATAGRAM_RESEND)) {
702f8829a4aSRandall Stewart 					tot_out += chk->book_size;
703f8829a4aSRandall Stewart 				}
704f8829a4aSRandall Stewart 			}
705f8829a4aSRandall Stewart 			if (lnet->flight_size != tot_out) {
706ad81507eSRandall Stewart 				SCTP_PRINTF("net:%x flight was %d corrected to %d\n",
707ad81507eSRandall Stewart 				    (uint32_t) lnet, lnet->flight_size,
708ad81507eSRandall Stewart 				    tot_out);
709f8829a4aSRandall Stewart 				lnet->flight_size = tot_out;
710f8829a4aSRandall Stewart 			}
711f8829a4aSRandall Stewart 		}
712f8829a4aSRandall Stewart 	}
713f8829a4aSRandall Stewart 	if (rep) {
714f8829a4aSRandall Stewart 		sctp_print_audit_report();
715f8829a4aSRandall Stewart 	}
716f8829a4aSRandall Stewart }
717f8829a4aSRandall Stewart 
718f8829a4aSRandall Stewart void
719f8829a4aSRandall Stewart sctp_audit_log(uint8_t ev, uint8_t fd)
720f8829a4aSRandall Stewart {
721f8829a4aSRandall Stewart 
722f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][0] = ev;
723f8829a4aSRandall Stewart 	sctp_audit_data[sctp_audit_indx][1] = fd;
724f8829a4aSRandall Stewart 	sctp_audit_indx++;
725f8829a4aSRandall Stewart 	if (sctp_audit_indx >= SCTP_AUDIT_SIZE) {
726f8829a4aSRandall Stewart 		sctp_audit_indx = 0;
727f8829a4aSRandall Stewart 	}
728f8829a4aSRandall Stewart }
729f8829a4aSRandall Stewart 
730f8829a4aSRandall Stewart #endif
731f8829a4aSRandall Stewart 
732f8829a4aSRandall Stewart /*
733f8829a4aSRandall Stewart  * a list of sizes based on typical mtu's, used only if next hop size not
734f8829a4aSRandall Stewart  * returned.
735f8829a4aSRandall Stewart  */
736f8829a4aSRandall Stewart static int sctp_mtu_sizes[] = {
737f8829a4aSRandall Stewart 	68,
738f8829a4aSRandall Stewart 	296,
739f8829a4aSRandall Stewart 	508,
740f8829a4aSRandall Stewart 	512,
741f8829a4aSRandall Stewart 	544,
742f8829a4aSRandall Stewart 	576,
743f8829a4aSRandall Stewart 	1006,
744f8829a4aSRandall Stewart 	1492,
745f8829a4aSRandall Stewart 	1500,
746f8829a4aSRandall Stewart 	1536,
747f8829a4aSRandall Stewart 	2002,
748f8829a4aSRandall Stewart 	2048,
749f8829a4aSRandall Stewart 	4352,
750f8829a4aSRandall Stewart 	4464,
751f8829a4aSRandall Stewart 	8166,
752f8829a4aSRandall Stewart 	17914,
753f8829a4aSRandall Stewart 	32000,
754f8829a4aSRandall Stewart 	65535
755f8829a4aSRandall Stewart };
756f8829a4aSRandall Stewart 
757f8829a4aSRandall Stewart void
758f8829a4aSRandall Stewart sctp_stop_timers_for_shutdown(struct sctp_tcb *stcb)
759f8829a4aSRandall Stewart {
760f8829a4aSRandall Stewart 	struct sctp_association *asoc;
761f8829a4aSRandall Stewart 	struct sctp_nets *net;
762f8829a4aSRandall Stewart 
763f8829a4aSRandall Stewart 	asoc = &stcb->asoc;
764f8829a4aSRandall Stewart 
7656e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&asoc->hb_timer.timer);
7666e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&asoc->dack_timer.timer);
7676e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&asoc->strreset_timer.timer);
7686e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&asoc->asconf_timer.timer);
7696e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&asoc->autoclose_timer.timer);
7706e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&asoc->delayed_event_timer.timer);
771f8829a4aSRandall Stewart 	TAILQ_FOREACH(net, &asoc->nets, sctp_next) {
7726e55db54SRandall Stewart 		(void)SCTP_OS_TIMER_STOP(&net->fr_timer.timer);
7736e55db54SRandall Stewart 		(void)SCTP_OS_TIMER_STOP(&net->pmtu_timer.timer);
774f8829a4aSRandall Stewart 	}
775f8829a4aSRandall Stewart }
776f8829a4aSRandall Stewart 
777f8829a4aSRandall Stewart int
778f8829a4aSRandall Stewart find_next_best_mtu(int totsz)
779f8829a4aSRandall Stewart {
780f8829a4aSRandall Stewart 	int i, perfer;
781f8829a4aSRandall Stewart 
782f8829a4aSRandall Stewart 	/*
783f8829a4aSRandall Stewart 	 * if we are in here we must find the next best fit based on the
784f8829a4aSRandall Stewart 	 * size of the dg that failed to be sent.
785f8829a4aSRandall Stewart 	 */
786f8829a4aSRandall Stewart 	perfer = 0;
787f8829a4aSRandall Stewart 	for (i = 0; i < NUMBER_OF_MTU_SIZES; i++) {
788f8829a4aSRandall Stewart 		if (totsz < sctp_mtu_sizes[i]) {
789f8829a4aSRandall Stewart 			perfer = i - 1;
790f8829a4aSRandall Stewart 			if (perfer < 0)
791f8829a4aSRandall Stewart 				perfer = 0;
792f8829a4aSRandall Stewart 			break;
793f8829a4aSRandall Stewart 		}
794f8829a4aSRandall Stewart 	}
795f8829a4aSRandall Stewart 	return (sctp_mtu_sizes[perfer]);
796f8829a4aSRandall Stewart }
797f8829a4aSRandall Stewart 
798f8829a4aSRandall Stewart void
799f8829a4aSRandall Stewart sctp_fill_random_store(struct sctp_pcb *m)
800f8829a4aSRandall Stewart {
801f8829a4aSRandall Stewart 	/*
802f8829a4aSRandall Stewart 	 * Here we use the MD5/SHA-1 to hash with our good randomNumbers and
803f8829a4aSRandall Stewart 	 * our counter. The result becomes our good random numbers and we
804f8829a4aSRandall Stewart 	 * then setup to give these out. Note that we do no locking to
805f8829a4aSRandall Stewart 	 * protect this. This is ok, since if competing folks call this we
80617205eccSRandall Stewart 	 * will get more gobbled gook in the random store which is what we
807f8829a4aSRandall Stewart 	 * want. There is a danger that two guys will use the same random
808f8829a4aSRandall Stewart 	 * numbers, but thats ok too since that is random as well :->
809f8829a4aSRandall Stewart 	 */
810f8829a4aSRandall Stewart 	m->store_at = 0;
811ad81507eSRandall Stewart 	(void)sctp_hmac(SCTP_HMAC, (uint8_t *) m->random_numbers,
812f8829a4aSRandall Stewart 	    sizeof(m->random_numbers), (uint8_t *) & m->random_counter,
813f8829a4aSRandall Stewart 	    sizeof(m->random_counter), (uint8_t *) m->random_store);
814f8829a4aSRandall Stewart 	m->random_counter++;
815f8829a4aSRandall Stewart }
816f8829a4aSRandall Stewart 
817f8829a4aSRandall Stewart uint32_t
818851b7298SRandall Stewart sctp_select_initial_TSN(struct sctp_pcb *inp)
819f8829a4aSRandall Stewart {
820f8829a4aSRandall Stewart 	/*
821f8829a4aSRandall Stewart 	 * A true implementation should use random selection process to get
822f8829a4aSRandall Stewart 	 * the initial stream sequence number, using RFC1750 as a good
823f8829a4aSRandall Stewart 	 * guideline
824f8829a4aSRandall Stewart 	 */
825139bc87fSRandall Stewart 	uint32_t x, *xp;
826f8829a4aSRandall Stewart 	uint8_t *p;
827851b7298SRandall Stewart 	int store_at, new_store;
828f8829a4aSRandall Stewart 
829851b7298SRandall Stewart 	if (inp->initial_sequence_debug != 0) {
830f8829a4aSRandall Stewart 		uint32_t ret;
831f8829a4aSRandall Stewart 
832851b7298SRandall Stewart 		ret = inp->initial_sequence_debug;
833851b7298SRandall Stewart 		inp->initial_sequence_debug++;
834f8829a4aSRandall Stewart 		return (ret);
835f8829a4aSRandall Stewart 	}
836851b7298SRandall Stewart retry:
837851b7298SRandall Stewart 	store_at = inp->store_at;
838851b7298SRandall Stewart 	new_store = store_at + sizeof(uint32_t);
839851b7298SRandall Stewart 	if (new_store >= (SCTP_SIGNATURE_SIZE - 3)) {
840851b7298SRandall Stewart 		new_store = 0;
841f8829a4aSRandall Stewart 	}
842851b7298SRandall Stewart 	if (!atomic_cmpset_int(&inp->store_at, store_at, new_store)) {
843851b7298SRandall Stewart 		goto retry;
844851b7298SRandall Stewart 	}
845851b7298SRandall Stewart 	if (new_store == 0) {
846851b7298SRandall Stewart 		/* Refill the random store */
847851b7298SRandall Stewart 		sctp_fill_random_store(inp);
848851b7298SRandall Stewart 	}
849851b7298SRandall Stewart 	p = &inp->random_store[store_at];
850139bc87fSRandall Stewart 	xp = (uint32_t *) p;
851f8829a4aSRandall Stewart 	x = *xp;
852f8829a4aSRandall Stewart 	return (x);
853f8829a4aSRandall Stewart }
854f8829a4aSRandall Stewart 
855f8829a4aSRandall Stewart uint32_t
856830d754dSRandall Stewart sctp_select_a_tag(struct sctp_inpcb *inp, uint16_t lport, uint16_t rport, int save_in_twait)
857f8829a4aSRandall Stewart {
858f8829a4aSRandall Stewart 	u_long x, not_done;
859f8829a4aSRandall Stewart 	struct timeval now;
860f8829a4aSRandall Stewart 
8616e55db54SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&now);
862f8829a4aSRandall Stewart 	not_done = 1;
863f8829a4aSRandall Stewart 	while (not_done) {
864851b7298SRandall Stewart 		x = sctp_select_initial_TSN(&inp->sctp_ep);
865f8829a4aSRandall Stewart 		if (x == 0) {
866f8829a4aSRandall Stewart 			/* we never use 0 */
867f8829a4aSRandall Stewart 			continue;
868f8829a4aSRandall Stewart 		}
869830d754dSRandall Stewart 		if (sctp_is_vtag_good(inp, x, lport, rport, &now, save_in_twait)) {
870f8829a4aSRandall Stewart 			not_done = 0;
871f8829a4aSRandall Stewart 		}
872f8829a4aSRandall Stewart 	}
873f8829a4aSRandall Stewart 	return (x);
874f8829a4aSRandall Stewart }
875f8829a4aSRandall Stewart 
876f8829a4aSRandall Stewart int
8770696e120SRandall Stewart sctp_init_asoc(struct sctp_inpcb *m, struct sctp_tcb *stcb,
87842551e99SRandall Stewart     int for_a_init, uint32_t override_tag, uint32_t vrf_id)
879f8829a4aSRandall Stewart {
8800696e120SRandall Stewart 	struct sctp_association *asoc;
8810696e120SRandall Stewart 
882f8829a4aSRandall Stewart 	/*
883f8829a4aSRandall Stewart 	 * Anything set to zero is taken care of by the allocation routine's
884f8829a4aSRandall Stewart 	 * bzero
885f8829a4aSRandall Stewart 	 */
886f8829a4aSRandall Stewart 
887f8829a4aSRandall Stewart 	/*
888f8829a4aSRandall Stewart 	 * Up front select what scoping to apply on addresses I tell my peer
889f8829a4aSRandall Stewart 	 * Not sure what to do with these right now, we will need to come up
890f8829a4aSRandall Stewart 	 * with a way to set them. We may need to pass them through from the
891f8829a4aSRandall Stewart 	 * caller in the sctp_aloc_assoc() function.
892f8829a4aSRandall Stewart 	 */
893f8829a4aSRandall Stewart 	int i;
894f8829a4aSRandall Stewart 
8950696e120SRandall Stewart 	asoc = &stcb->asoc;
896f8829a4aSRandall Stewart 	/* init all variables to a known value. */
897c4739e2fSRandall Stewart 	SCTP_SET_STATE(&stcb->asoc, SCTP_STATE_INUSE);
898f8829a4aSRandall Stewart 	asoc->max_burst = m->sctp_ep.max_burst;
899f8829a4aSRandall Stewart 	asoc->heart_beat_delay = TICKS_TO_MSEC(m->sctp_ep.sctp_timeoutticks[SCTP_TIMER_HEARTBEAT]);
900f8829a4aSRandall Stewart 	asoc->cookie_life = m->sctp_ep.def_cookie_life;
901b3f1ea41SRandall Stewart 	asoc->sctp_cmt_on_off = (uint8_t) SCTP_BASE_SYSCTL(sctp_cmt_on_off);
902830d754dSRandall Stewart 	/* EY Init nr_sack variable */
903830d754dSRandall Stewart 	asoc->sctp_nr_sack_on_off = (uint8_t) SCTP_BASE_SYSCTL(sctp_nr_sack_on_off);
904b54d3a6cSRandall Stewart 	/* JRS 5/21/07 - Init CMT PF variables */
905b3f1ea41SRandall Stewart 	asoc->sctp_cmt_pf = (uint8_t) SCTP_BASE_SYSCTL(sctp_cmt_pf);
906d61a0ae0SRandall Stewart 	asoc->sctp_frag_point = m->sctp_frag_point;
90742551e99SRandall Stewart #ifdef INET
908f8829a4aSRandall Stewart 	asoc->default_tos = m->ip_inp.inp.inp_ip_tos;
909f8829a4aSRandall Stewart #else
910f8829a4aSRandall Stewart 	asoc->default_tos = 0;
911f8829a4aSRandall Stewart #endif
912f8829a4aSRandall Stewart 
91342551e99SRandall Stewart #ifdef INET6
914f8829a4aSRandall Stewart 	asoc->default_flowlabel = ((struct in6pcb *)m)->in6p_flowinfo;
915f8829a4aSRandall Stewart #else
916f8829a4aSRandall Stewart 	asoc->default_flowlabel = 0;
917f8829a4aSRandall Stewart #endif
9189f22f500SRandall Stewart 	asoc->sb_send_resv = 0;
919f8829a4aSRandall Stewart 	if (override_tag) {
920830d754dSRandall Stewart #ifdef MICHAELS_EXPERIMENT
921830d754dSRandall Stewart 		if (sctp_is_in_timewait(override_tag, stcb->sctp_ep->sctp_lport, stcb->rport)) {
922fb8fb8f8SRandall Stewart 			/*
923fb8fb8f8SRandall Stewart 			 * It must be in the time-wait hash, we put it there
924fb8fb8f8SRandall Stewart 			 * when we aloc one. If not the peer is playing
925fb8fb8f8SRandall Stewart 			 * games.
926fb8fb8f8SRandall Stewart 			 */
927f8829a4aSRandall Stewart 			asoc->my_vtag = override_tag;
928f8829a4aSRandall Stewart 		} else {
929c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
930df6e0cc3SRandall Stewart #ifdef INVARIANTS
931fb8fb8f8SRandall Stewart 			panic("Huh is_in_timewait fails");
932df6e0cc3SRandall Stewart #endif
933f8829a4aSRandall Stewart 			return (ENOMEM);
934f8829a4aSRandall Stewart 		}
935830d754dSRandall Stewart #else
936830d754dSRandall Stewart 		asoc->my_vtag = override_tag;
937830d754dSRandall Stewart #endif
938f8829a4aSRandall Stewart 	} else {
939830d754dSRandall Stewart 		asoc->my_vtag = sctp_select_a_tag(m, stcb->sctp_ep->sctp_lport, stcb->rport, 1);
940f8829a4aSRandall Stewart 	}
941de0e935bSRandall Stewart 	/* Get the nonce tags */
942830d754dSRandall Stewart 	asoc->my_vtag_nonce = sctp_select_a_tag(m, stcb->sctp_ep->sctp_lport, stcb->rport, 0);
943830d754dSRandall Stewart 	asoc->peer_vtag_nonce = sctp_select_a_tag(m, stcb->sctp_ep->sctp_lport, stcb->rport, 0);
94442551e99SRandall Stewart 	asoc->vrf_id = vrf_id;
945de0e935bSRandall Stewart 
946f8829a4aSRandall Stewart 	if (sctp_is_feature_on(m, SCTP_PCB_FLAGS_DONOT_HEARTBEAT))
947f8829a4aSRandall Stewart 		asoc->hb_is_disabled = 1;
948f8829a4aSRandall Stewart 	else
949f8829a4aSRandall Stewart 		asoc->hb_is_disabled = 0;
950f8829a4aSRandall Stewart 
95118e198d3SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
95218e198d3SRandall Stewart 	asoc->tsn_in_at = 0;
95318e198d3SRandall Stewart 	asoc->tsn_out_at = 0;
95418e198d3SRandall Stewart 	asoc->tsn_in_wrapped = 0;
95518e198d3SRandall Stewart 	asoc->tsn_out_wrapped = 0;
95618e198d3SRandall Stewart 	asoc->cumack_log_at = 0;
957b201f536SRandall Stewart 	asoc->cumack_log_atsnt = 0;
95818e198d3SRandall Stewart #endif
95918e198d3SRandall Stewart #ifdef SCTP_FS_SPEC_LOG
96018e198d3SRandall Stewart 	asoc->fs_index = 0;
96118e198d3SRandall Stewart #endif
962f8829a4aSRandall Stewart 	asoc->refcnt = 0;
963f8829a4aSRandall Stewart 	asoc->assoc_up_sent = 0;
964f8829a4aSRandall Stewart 	asoc->asconf_seq_out = asoc->str_reset_seq_out = asoc->init_seq_number = asoc->sending_seq =
965f8829a4aSRandall Stewart 	    sctp_select_initial_TSN(&m->sctp_ep);
966c54a18d2SRandall Stewart 	asoc->asconf_seq_out_acked = asoc->asconf_seq_out - 1;
967f8829a4aSRandall Stewart 	/* we are optimisitic here */
968f8829a4aSRandall Stewart 	asoc->peer_supports_pktdrop = 1;
969830d754dSRandall Stewart 	asoc->peer_supports_nat = 0;
970f8829a4aSRandall Stewart 	asoc->sent_queue_retran_cnt = 0;
971f8829a4aSRandall Stewart 
972f8829a4aSRandall Stewart 	/* for CMT */
973f8829a4aSRandall Stewart 	asoc->last_net_data_came_from = NULL;
974f8829a4aSRandall Stewart 
975f8829a4aSRandall Stewart 	/* This will need to be adjusted */
976f8829a4aSRandall Stewart 	asoc->last_cwr_tsn = asoc->init_seq_number - 1;
977f8829a4aSRandall Stewart 	asoc->last_acked_seq = asoc->init_seq_number - 1;
978f8829a4aSRandall Stewart 	asoc->advanced_peer_ack_point = asoc->last_acked_seq;
979f8829a4aSRandall Stewart 	asoc->asconf_seq_in = asoc->last_acked_seq;
980f8829a4aSRandall Stewart 
981f8829a4aSRandall Stewart 	/* here we are different, we hold the next one we expect */
982f8829a4aSRandall Stewart 	asoc->str_reset_seq_in = asoc->last_acked_seq + 1;
983f8829a4aSRandall Stewart 
984f8829a4aSRandall Stewart 	asoc->initial_init_rto_max = m->sctp_ep.initial_init_rto_max;
985f8829a4aSRandall Stewart 	asoc->initial_rto = m->sctp_ep.initial_rto;
986f8829a4aSRandall Stewart 
987f8829a4aSRandall Stewart 	asoc->max_init_times = m->sctp_ep.max_init_times;
988f8829a4aSRandall Stewart 	asoc->max_send_times = m->sctp_ep.max_send_times;
989f8829a4aSRandall Stewart 	asoc->def_net_failure = m->sctp_ep.def_net_failure;
990f8829a4aSRandall Stewart 	asoc->free_chunk_cnt = 0;
991f8829a4aSRandall Stewart 
992f8829a4aSRandall Stewart 	asoc->iam_blocking = 0;
993f8829a4aSRandall Stewart 	/* ECN Nonce initialization */
994f8829a4aSRandall Stewart 	asoc->context = m->sctp_context;
995f8829a4aSRandall Stewart 	asoc->def_send = m->def_send;
996f8829a4aSRandall Stewart 	asoc->ecn_nonce_allowed = 0;
997f8829a4aSRandall Stewart 	asoc->receiver_nonce_sum = 1;
998f8829a4aSRandall Stewart 	asoc->nonce_sum_expect_base = 1;
999f8829a4aSRandall Stewart 	asoc->nonce_sum_check = 1;
1000f8829a4aSRandall Stewart 	asoc->nonce_resync_tsn = 0;
1001f8829a4aSRandall Stewart 	asoc->nonce_wait_for_ecne = 0;
1002f8829a4aSRandall Stewart 	asoc->nonce_wait_tsn = 0;
1003f8829a4aSRandall Stewart 	asoc->delayed_ack = TICKS_TO_MSEC(m->sctp_ep.sctp_timeoutticks[SCTP_TIMER_RECV]);
100442551e99SRandall Stewart 	asoc->sack_freq = m->sctp_ep.sctp_sack_freq;
1005f8829a4aSRandall Stewart 	asoc->pr_sctp_cnt = 0;
1006f8829a4aSRandall Stewart 	asoc->total_output_queue_size = 0;
1007f8829a4aSRandall Stewart 
1008f8829a4aSRandall Stewart 	if (m->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) {
1009f8829a4aSRandall Stewart 		struct in6pcb *inp6;
1010f8829a4aSRandall Stewart 
1011f8829a4aSRandall Stewart 		/* Its a V6 socket */
1012f8829a4aSRandall Stewart 		inp6 = (struct in6pcb *)m;
1013f8829a4aSRandall Stewart 		asoc->ipv6_addr_legal = 1;
1014f8829a4aSRandall Stewart 		/* Now look at the binding flag to see if V4 will be legal */
101544b7479bSRandall Stewart 		if (SCTP_IPV6_V6ONLY(inp6) == 0) {
1016f8829a4aSRandall Stewart 			asoc->ipv4_addr_legal = 1;
1017f8829a4aSRandall Stewart 		} else {
1018f8829a4aSRandall Stewart 			/* V4 addresses are NOT legal on the association */
1019f8829a4aSRandall Stewart 			asoc->ipv4_addr_legal = 0;
1020f8829a4aSRandall Stewart 		}
1021f8829a4aSRandall Stewart 	} else {
1022f8829a4aSRandall Stewart 		/* Its a V4 socket, no - V6 */
1023f8829a4aSRandall Stewart 		asoc->ipv4_addr_legal = 1;
1024f8829a4aSRandall Stewart 		asoc->ipv6_addr_legal = 0;
1025f8829a4aSRandall Stewart 	}
1026f8829a4aSRandall Stewart 
102762c1ff9cSRandall Stewart 	asoc->my_rwnd = max(SCTP_SB_LIMIT_RCV(m->sctp_socket), SCTP_MINIMAL_RWND);
102862c1ff9cSRandall Stewart 	asoc->peers_rwnd = SCTP_SB_LIMIT_RCV(m->sctp_socket);
1029f8829a4aSRandall Stewart 
1030f8829a4aSRandall Stewart 	asoc->smallest_mtu = m->sctp_frag_point;
103117205eccSRandall Stewart #ifdef SCTP_PRINT_FOR_B_AND_M
1032ad81507eSRandall Stewart 	SCTP_PRINTF("smallest_mtu init'd with asoc to :%d\n",
103317205eccSRandall Stewart 	    asoc->smallest_mtu);
103417205eccSRandall Stewart #endif
1035f8829a4aSRandall Stewart 	asoc->minrto = m->sctp_ep.sctp_minrto;
1036f8829a4aSRandall Stewart 	asoc->maxrto = m->sctp_ep.sctp_maxrto;
1037f8829a4aSRandall Stewart 
1038f8829a4aSRandall Stewart 	asoc->locked_on_sending = NULL;
1039f8829a4aSRandall Stewart 	asoc->stream_locked_on = 0;
1040f8829a4aSRandall Stewart 	asoc->ecn_echo_cnt_onq = 0;
1041f8829a4aSRandall Stewart 	asoc->stream_locked = 0;
1042f8829a4aSRandall Stewart 
104342551e99SRandall Stewart 	asoc->send_sack = 1;
104442551e99SRandall Stewart 
104542551e99SRandall Stewart 	LIST_INIT(&asoc->sctp_restricted_addrs);
104642551e99SRandall Stewart 
1047f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->nets);
1048f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->pending_reply_queue);
10492afb3e84SRandall Stewart 	TAILQ_INIT(&asoc->asconf_ack_sent);
1050f8829a4aSRandall Stewart 	/* Setup to fill the hb random cache at first HB */
1051f8829a4aSRandall Stewart 	asoc->hb_random_idx = 4;
1052f8829a4aSRandall Stewart 
1053f8829a4aSRandall Stewart 	asoc->sctp_autoclose_ticks = m->sctp_ep.auto_close_time;
1054f8829a4aSRandall Stewart 
1055f8829a4aSRandall Stewart 	/*
1056b54d3a6cSRandall Stewart 	 * JRS - Pick the default congestion control module based on the
1057b54d3a6cSRandall Stewart 	 * sysctl.
1058b54d3a6cSRandall Stewart 	 */
1059b54d3a6cSRandall Stewart 	switch (m->sctp_ep.sctp_default_cc_module) {
1060b54d3a6cSRandall Stewart 		/* JRS - Standard TCP congestion control */
1061b54d3a6cSRandall Stewart 	case SCTP_CC_RFC2581:
1062b54d3a6cSRandall Stewart 		{
1063b54d3a6cSRandall Stewart 			stcb->asoc.congestion_control_module = SCTP_CC_RFC2581;
1064b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_set_initial_cc_param = &sctp_set_initial_cc_param;
1065b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_sack = &sctp_cwnd_update_after_sack;
1066b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr = &sctp_cwnd_update_after_fr;
1067b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_timeout = &sctp_cwnd_update_after_timeout;
1068b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_ecn_echo = &sctp_cwnd_update_after_ecn_echo;
1069b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_packet_dropped = &sctp_cwnd_update_after_packet_dropped;
1070b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_output = &sctp_cwnd_update_after_output;
1071b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr_timer = &sctp_cwnd_update_after_fr_timer;
1072b54d3a6cSRandall Stewart 			break;
1073b54d3a6cSRandall Stewart 		}
1074b54d3a6cSRandall Stewart 		/* JRS - High Speed TCP congestion control (Floyd) */
1075b54d3a6cSRandall Stewart 	case SCTP_CC_HSTCP:
1076b54d3a6cSRandall Stewart 		{
1077b54d3a6cSRandall Stewart 			stcb->asoc.congestion_control_module = SCTP_CC_HSTCP;
1078b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_set_initial_cc_param = &sctp_set_initial_cc_param;
1079b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_sack = &sctp_hs_cwnd_update_after_sack;
1080b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr = &sctp_hs_cwnd_update_after_fr;
1081b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_timeout = &sctp_cwnd_update_after_timeout;
1082b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_ecn_echo = &sctp_cwnd_update_after_ecn_echo;
1083b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_packet_dropped = &sctp_cwnd_update_after_packet_dropped;
1084b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_output = &sctp_cwnd_update_after_output;
1085b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr_timer = &sctp_cwnd_update_after_fr_timer;
1086b54d3a6cSRandall Stewart 			break;
1087b54d3a6cSRandall Stewart 		}
1088b54d3a6cSRandall Stewart 		/* JRS - HTCP congestion control */
1089b54d3a6cSRandall Stewart 	case SCTP_CC_HTCP:
1090b54d3a6cSRandall Stewart 		{
1091b54d3a6cSRandall Stewart 			stcb->asoc.congestion_control_module = SCTP_CC_HTCP;
1092b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_set_initial_cc_param = &sctp_htcp_set_initial_cc_param;
1093b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_sack = &sctp_htcp_cwnd_update_after_sack;
1094b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr = &sctp_htcp_cwnd_update_after_fr;
1095b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_timeout = &sctp_htcp_cwnd_update_after_timeout;
1096b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_ecn_echo = &sctp_htcp_cwnd_update_after_ecn_echo;
1097b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_packet_dropped = &sctp_cwnd_update_after_packet_dropped;
1098b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_output = &sctp_cwnd_update_after_output;
1099b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr_timer = &sctp_htcp_cwnd_update_after_fr_timer;
1100b54d3a6cSRandall Stewart 			break;
1101b54d3a6cSRandall Stewart 		}
1102b54d3a6cSRandall Stewart 		/* JRS - By default, use RFC2581 */
1103b54d3a6cSRandall Stewart 	default:
1104b54d3a6cSRandall Stewart 		{
1105b54d3a6cSRandall Stewart 			stcb->asoc.congestion_control_module = SCTP_CC_RFC2581;
1106b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_set_initial_cc_param = &sctp_set_initial_cc_param;
1107b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_sack = &sctp_cwnd_update_after_sack;
1108b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr = &sctp_cwnd_update_after_fr;
1109b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_timeout = &sctp_cwnd_update_after_timeout;
1110b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_ecn_echo = &sctp_cwnd_update_after_ecn_echo;
1111b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_packet_dropped = &sctp_cwnd_update_after_packet_dropped;
1112b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_output = &sctp_cwnd_update_after_output;
1113b54d3a6cSRandall Stewart 			stcb->asoc.cc_functions.sctp_cwnd_update_after_fr_timer = &sctp_cwnd_update_after_fr_timer;
1114b54d3a6cSRandall Stewart 			break;
1115b54d3a6cSRandall Stewart 		}
1116b54d3a6cSRandall Stewart 	}
1117b54d3a6cSRandall Stewart 
1118b54d3a6cSRandall Stewart 	/*
1119f8829a4aSRandall Stewart 	 * Now the stream parameters, here we allocate space for all streams
1120f8829a4aSRandall Stewart 	 * that we request by default.
1121f8829a4aSRandall Stewart 	 */
1122ea44232bSRandall Stewart 	asoc->strm_realoutsize = asoc->streamoutcnt = asoc->pre_open_streams =
1123f8829a4aSRandall Stewart 	    m->sctp_ep.pre_open_stream_count;
1124f8829a4aSRandall Stewart 	SCTP_MALLOC(asoc->strmout, struct sctp_stream_out *,
1125f8829a4aSRandall Stewart 	    asoc->streamoutcnt * sizeof(struct sctp_stream_out),
1126207304d4SRandall Stewart 	    SCTP_M_STRMO);
1127f8829a4aSRandall Stewart 	if (asoc->strmout == NULL) {
1128f8829a4aSRandall Stewart 		/* big trouble no memory */
1129c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
1130f8829a4aSRandall Stewart 		return (ENOMEM);
1131f8829a4aSRandall Stewart 	}
1132f8829a4aSRandall Stewart 	for (i = 0; i < asoc->streamoutcnt; i++) {
1133f8829a4aSRandall Stewart 		/*
1134f8829a4aSRandall Stewart 		 * inbound side must be set to 0xffff, also NOTE when we get
1135f8829a4aSRandall Stewart 		 * the INIT-ACK back (for INIT sender) we MUST reduce the
1136f8829a4aSRandall Stewart 		 * count (streamoutcnt) but first check if we sent to any of
1137f8829a4aSRandall Stewart 		 * the upper streams that were dropped (if some were). Those
1138f8829a4aSRandall Stewart 		 * that were dropped must be notified to the upper layer as
1139f8829a4aSRandall Stewart 		 * failed to send.
1140f8829a4aSRandall Stewart 		 */
1141f8829a4aSRandall Stewart 		asoc->strmout[i].next_sequence_sent = 0x0;
1142f8829a4aSRandall Stewart 		TAILQ_INIT(&asoc->strmout[i].outqueue);
1143f8829a4aSRandall Stewart 		asoc->strmout[i].stream_no = i;
1144f8829a4aSRandall Stewart 		asoc->strmout[i].last_msg_incomplete = 0;
1145f8829a4aSRandall Stewart 		asoc->strmout[i].next_spoke.tqe_next = 0;
1146f8829a4aSRandall Stewart 		asoc->strmout[i].next_spoke.tqe_prev = 0;
1147f8829a4aSRandall Stewart 	}
1148f8829a4aSRandall Stewart 	/* Now the mapping array */
1149f8829a4aSRandall Stewart 	asoc->mapping_array_size = SCTP_INITIAL_MAPPING_ARRAY;
1150f8829a4aSRandall Stewart 	SCTP_MALLOC(asoc->mapping_array, uint8_t *, asoc->mapping_array_size,
1151207304d4SRandall Stewart 	    SCTP_M_MAP);
1152f8829a4aSRandall Stewart 	if (asoc->mapping_array == NULL) {
1153207304d4SRandall Stewart 		SCTP_FREE(asoc->strmout, SCTP_M_STRMO);
1154c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
1155f8829a4aSRandall Stewart 		return (ENOMEM);
1156f8829a4aSRandall Stewart 	}
1157f8829a4aSRandall Stewart 	memset(asoc->mapping_array, 0, asoc->mapping_array_size);
1158830d754dSRandall Stewart 	/* EY  - initialize the nr_mapping_array just like mapping array */
1159830d754dSRandall Stewart 	asoc->nr_mapping_array_size = SCTP_INITIAL_NR_MAPPING_ARRAY;
1160830d754dSRandall Stewart 	SCTP_MALLOC(asoc->nr_mapping_array, uint8_t *, asoc->nr_mapping_array_size,
1161830d754dSRandall Stewart 	    SCTP_M_MAP);
1162830d754dSRandall Stewart 	/*
1163830d754dSRandall Stewart 	 * if (asoc->nr_mapping_array == NULL) { SCTP_FREE(asoc->strmout,
1164830d754dSRandall Stewart 	 * SCTP_M_STRMO); SCTP_LTRACE_ERR_RET(NULL, stcb, NULL,
1165830d754dSRandall Stewart 	 * SCTP_FROM_SCTPUTIL, ENOMEM); return (ENOMEM); }
1166830d754dSRandall Stewart 	 */
1167830d754dSRandall Stewart 	memset(asoc->nr_mapping_array, 0, asoc->nr_mapping_array_size);
1168830d754dSRandall Stewart 
1169f8829a4aSRandall Stewart 	/* Now the init of the other outqueues */
1170f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->free_chunks);
1171f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->out_wheel);
1172f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->control_send_queue);
1173c54a18d2SRandall Stewart 	TAILQ_INIT(&asoc->asconf_send_queue);
1174f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->send_queue);
1175f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->sent_queue);
1176f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->reasmqueue);
1177f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->resetHead);
1178f8829a4aSRandall Stewart 	asoc->max_inbound_streams = m->sctp_ep.max_open_streams_intome;
1179f8829a4aSRandall Stewart 	TAILQ_INIT(&asoc->asconf_queue);
1180f8829a4aSRandall Stewart 	/* authentication fields */
1181f8829a4aSRandall Stewart 	asoc->authinfo.random = NULL;
1182830d754dSRandall Stewart 	asoc->authinfo.active_keyid = 0;
1183f8829a4aSRandall Stewart 	asoc->authinfo.assoc_key = NULL;
1184f8829a4aSRandall Stewart 	asoc->authinfo.assoc_keyid = 0;
1185f8829a4aSRandall Stewart 	asoc->authinfo.recv_key = NULL;
1186f8829a4aSRandall Stewart 	asoc->authinfo.recv_keyid = 0;
1187f8829a4aSRandall Stewart 	LIST_INIT(&asoc->shared_keys);
1188f42a358aSRandall Stewart 	asoc->marked_retrans = 0;
1189f42a358aSRandall Stewart 	asoc->timoinit = 0;
1190f42a358aSRandall Stewart 	asoc->timodata = 0;
1191f42a358aSRandall Stewart 	asoc->timosack = 0;
1192f42a358aSRandall Stewart 	asoc->timoshutdown = 0;
1193f42a358aSRandall Stewart 	asoc->timoheartbeat = 0;
1194f42a358aSRandall Stewart 	asoc->timocookie = 0;
1195f42a358aSRandall Stewart 	asoc->timoshutdownack = 0;
11966e55db54SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&asoc->start_time);
11976e55db54SRandall Stewart 	asoc->discontinuity_time = asoc->start_time;
1198eacc51c5SRandall Stewart 	/*
1199eacc51c5SRandall Stewart 	 * sa_ignore MEMLEAK {memory is put in the assoc mapping array and
1200eacc51c5SRandall Stewart 	 * freed later whe the association is freed.
1201eacc51c5SRandall Stewart 	 */
1202f8829a4aSRandall Stewart 	return (0);
1203f8829a4aSRandall Stewart }
1204f8829a4aSRandall Stewart 
1205f8829a4aSRandall Stewart int
12060696e120SRandall Stewart sctp_expand_mapping_array(struct sctp_association *asoc, uint32_t needed)
1207f8829a4aSRandall Stewart {
1208f8829a4aSRandall Stewart 	/* mapping array needs to grow */
1209f8829a4aSRandall Stewart 	uint8_t *new_array;
12100696e120SRandall Stewart 	uint32_t new_size;
1211f8829a4aSRandall Stewart 
12120696e120SRandall Stewart 	new_size = asoc->mapping_array_size + ((needed + 7) / 8 + SCTP_MAPPING_ARRAY_INCR);
1213207304d4SRandall Stewart 	SCTP_MALLOC(new_array, uint8_t *, new_size, SCTP_M_MAP);
1214f8829a4aSRandall Stewart 	if (new_array == NULL) {
1215f8829a4aSRandall Stewart 		/* can't get more, forget it */
1216ad81507eSRandall Stewart 		SCTP_PRINTF("No memory for expansion of SCTP mapping array %d\n",
1217f8829a4aSRandall Stewart 		    new_size);
1218f8829a4aSRandall Stewart 		return (-1);
1219f8829a4aSRandall Stewart 	}
1220f8829a4aSRandall Stewart 	memset(new_array, 0, new_size);
1221f8829a4aSRandall Stewart 	memcpy(new_array, asoc->mapping_array, asoc->mapping_array_size);
1222207304d4SRandall Stewart 	SCTP_FREE(asoc->mapping_array, SCTP_M_MAP);
1223f8829a4aSRandall Stewart 	asoc->mapping_array = new_array;
1224f8829a4aSRandall Stewart 	asoc->mapping_array_size = new_size;
1225f8829a4aSRandall Stewart 	return (0);
1226f8829a4aSRandall Stewart }
1227f8829a4aSRandall Stewart 
1228830d754dSRandall Stewart /* EY - nr_sack version of the above method */
1229830d754dSRandall Stewart int
1230830d754dSRandall Stewart sctp_expand_nr_mapping_array(struct sctp_association *asoc, uint32_t needed)
1231830d754dSRandall Stewart {
1232830d754dSRandall Stewart 	/* nr mapping array needs to grow */
1233830d754dSRandall Stewart 	uint8_t *new_array;
1234830d754dSRandall Stewart 	uint32_t new_size;
1235830d754dSRandall Stewart 
1236830d754dSRandall Stewart 	new_size = asoc->nr_mapping_array_size + ((needed + 7) / 8 + SCTP_NR_MAPPING_ARRAY_INCR);
1237830d754dSRandall Stewart 	SCTP_MALLOC(new_array, uint8_t *, new_size, SCTP_M_MAP);
1238830d754dSRandall Stewart 	if (new_array == NULL) {
1239830d754dSRandall Stewart 		/* can't get more, forget it */
1240830d754dSRandall Stewart 		SCTP_PRINTF("No memory for expansion of SCTP mapping array %d\n",
1241830d754dSRandall Stewart 		    new_size);
1242830d754dSRandall Stewart 		return (-1);
1243830d754dSRandall Stewart 	}
1244830d754dSRandall Stewart 	memset(new_array, 0, new_size);
1245830d754dSRandall Stewart 	memcpy(new_array, asoc->nr_mapping_array, asoc->nr_mapping_array_size);
1246830d754dSRandall Stewart 	SCTP_FREE(asoc->nr_mapping_array, SCTP_M_MAP);
1247830d754dSRandall Stewart 	asoc->nr_mapping_array = new_array;
1248830d754dSRandall Stewart 	asoc->nr_mapping_array_size = new_size;
1249830d754dSRandall Stewart 	return (0);
1250830d754dSRandall Stewart }
1251830d754dSRandall Stewart 
125242551e99SRandall Stewart #if defined(SCTP_USE_THREAD_BASED_ITERATOR)
125342551e99SRandall Stewart static void
125442551e99SRandall Stewart sctp_iterator_work(struct sctp_iterator *it)
125542551e99SRandall Stewart {
125642551e99SRandall Stewart 	int iteration_count = 0;
125742551e99SRandall Stewart 	int inp_skip = 0;
125842551e99SRandall Stewart 
125942551e99SRandall Stewart 	SCTP_ITERATOR_LOCK();
1260ad81507eSRandall Stewart 	if (it->inp) {
126142551e99SRandall Stewart 		SCTP_INP_DECR_REF(it->inp);
1262ad81507eSRandall Stewart 	}
126342551e99SRandall Stewart 	if (it->inp == NULL) {
126442551e99SRandall Stewart 		/* iterator is complete */
126542551e99SRandall Stewart done_with_iterator:
126642551e99SRandall Stewart 		SCTP_ITERATOR_UNLOCK();
126742551e99SRandall Stewart 		if (it->function_atend != NULL) {
126842551e99SRandall Stewart 			(*it->function_atend) (it->pointer, it->val);
126942551e99SRandall Stewart 		}
1270207304d4SRandall Stewart 		SCTP_FREE(it, SCTP_M_ITER);
127142551e99SRandall Stewart 		return;
127242551e99SRandall Stewart 	}
127342551e99SRandall Stewart select_a_new_ep:
127442551e99SRandall Stewart 	SCTP_INP_WLOCK(it->inp);
127542551e99SRandall Stewart 	while (((it->pcb_flags) &&
127642551e99SRandall Stewart 	    ((it->inp->sctp_flags & it->pcb_flags) != it->pcb_flags)) ||
127742551e99SRandall Stewart 	    ((it->pcb_features) &&
127842551e99SRandall Stewart 	    ((it->inp->sctp_features & it->pcb_features) != it->pcb_features))) {
127942551e99SRandall Stewart 		/* endpoint flags or features don't match, so keep looking */
128042551e99SRandall Stewart 		if (it->iterator_flags & SCTP_ITERATOR_DO_SINGLE_INP) {
128142551e99SRandall Stewart 			SCTP_INP_WUNLOCK(it->inp);
128242551e99SRandall Stewart 			goto done_with_iterator;
128342551e99SRandall Stewart 		}
128442551e99SRandall Stewart 		SCTP_INP_WUNLOCK(it->inp);
128542551e99SRandall Stewart 		it->inp = LIST_NEXT(it->inp, sctp_list);
128642551e99SRandall Stewart 		if (it->inp == NULL) {
128742551e99SRandall Stewart 			goto done_with_iterator;
128842551e99SRandall Stewart 		}
128942551e99SRandall Stewart 		SCTP_INP_WLOCK(it->inp);
129042551e99SRandall Stewart 	}
129142551e99SRandall Stewart 
129242551e99SRandall Stewart 	SCTP_INP_WUNLOCK(it->inp);
129342551e99SRandall Stewart 	SCTP_INP_RLOCK(it->inp);
129442551e99SRandall Stewart 
129542551e99SRandall Stewart 	/* now go through each assoc which is in the desired state */
129642551e99SRandall Stewart 	if (it->done_current_ep == 0) {
129742551e99SRandall Stewart 		if (it->function_inp != NULL)
129842551e99SRandall Stewart 			inp_skip = (*it->function_inp) (it->inp, it->pointer, it->val);
129942551e99SRandall Stewart 		it->done_current_ep = 1;
130042551e99SRandall Stewart 	}
130142551e99SRandall Stewart 	if (it->stcb == NULL) {
130242551e99SRandall Stewart 		/* run the per instance function */
130342551e99SRandall Stewart 		it->stcb = LIST_FIRST(&it->inp->sctp_asoc_list);
130442551e99SRandall Stewart 	}
130542551e99SRandall Stewart 	if ((inp_skip) || it->stcb == NULL) {
130642551e99SRandall Stewart 		if (it->function_inp_end != NULL) {
130742551e99SRandall Stewart 			inp_skip = (*it->function_inp_end) (it->inp,
130842551e99SRandall Stewart 			    it->pointer,
130942551e99SRandall Stewart 			    it->val);
131042551e99SRandall Stewart 		}
131142551e99SRandall Stewart 		SCTP_INP_RUNLOCK(it->inp);
131242551e99SRandall Stewart 		goto no_stcb;
131342551e99SRandall Stewart 	}
131442551e99SRandall Stewart 	while (it->stcb) {
131542551e99SRandall Stewart 		SCTP_TCB_LOCK(it->stcb);
131642551e99SRandall Stewart 		if (it->asoc_state && ((it->stcb->asoc.state & it->asoc_state) != it->asoc_state)) {
131742551e99SRandall Stewart 			/* not in the right state... keep looking */
131842551e99SRandall Stewart 			SCTP_TCB_UNLOCK(it->stcb);
131942551e99SRandall Stewart 			goto next_assoc;
132042551e99SRandall Stewart 		}
132142551e99SRandall Stewart 		/* see if we have limited out the iterator loop */
132242551e99SRandall Stewart 		iteration_count++;
132342551e99SRandall Stewart 		if (iteration_count > SCTP_ITERATOR_MAX_AT_ONCE) {
132442551e99SRandall Stewart 			/* Pause to let others grab the lock */
132542551e99SRandall Stewart 			atomic_add_int(&it->stcb->asoc.refcnt, 1);
132642551e99SRandall Stewart 			SCTP_TCB_UNLOCK(it->stcb);
1327c4739e2fSRandall Stewart 
1328c4739e2fSRandall Stewart 			SCTP_INP_INCR_REF(it->inp);
132942551e99SRandall Stewart 			SCTP_INP_RUNLOCK(it->inp);
133042551e99SRandall Stewart 			SCTP_ITERATOR_UNLOCK();
133142551e99SRandall Stewart 			SCTP_ITERATOR_LOCK();
133242551e99SRandall Stewart 			SCTP_INP_RLOCK(it->inp);
1333c4739e2fSRandall Stewart 
1334c4739e2fSRandall Stewart 			SCTP_INP_DECR_REF(it->inp);
133542551e99SRandall Stewart 			SCTP_TCB_LOCK(it->stcb);
133642551e99SRandall Stewart 			atomic_add_int(&it->stcb->asoc.refcnt, -1);
133742551e99SRandall Stewart 			iteration_count = 0;
133842551e99SRandall Stewart 		}
133942551e99SRandall Stewart 		/* run function on this one */
134042551e99SRandall Stewart 		(*it->function_assoc) (it->inp, it->stcb, it->pointer, it->val);
134142551e99SRandall Stewart 
134242551e99SRandall Stewart 		/*
134342551e99SRandall Stewart 		 * we lie here, it really needs to have its own type but
134442551e99SRandall Stewart 		 * first I must verify that this won't effect things :-0
134542551e99SRandall Stewart 		 */
134642551e99SRandall Stewart 		if (it->no_chunk_output == 0)
1347ceaad40aSRandall Stewart 			sctp_chunk_output(it->inp, it->stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
134842551e99SRandall Stewart 
134942551e99SRandall Stewart 		SCTP_TCB_UNLOCK(it->stcb);
135042551e99SRandall Stewart next_assoc:
135142551e99SRandall Stewart 		it->stcb = LIST_NEXT(it->stcb, sctp_tcblist);
135242551e99SRandall Stewart 		if (it->stcb == NULL) {
135342551e99SRandall Stewart 			/* Run last function */
135442551e99SRandall Stewart 			if (it->function_inp_end != NULL) {
135542551e99SRandall Stewart 				inp_skip = (*it->function_inp_end) (it->inp,
135642551e99SRandall Stewart 				    it->pointer,
135742551e99SRandall Stewart 				    it->val);
135842551e99SRandall Stewart 			}
135942551e99SRandall Stewart 		}
136042551e99SRandall Stewart 	}
136142551e99SRandall Stewart 	SCTP_INP_RUNLOCK(it->inp);
136242551e99SRandall Stewart no_stcb:
136342551e99SRandall Stewart 	/* done with all assocs on this endpoint, move on to next endpoint */
136442551e99SRandall Stewart 	it->done_current_ep = 0;
136542551e99SRandall Stewart 	SCTP_INP_WLOCK(it->inp);
136642551e99SRandall Stewart 	SCTP_INP_WUNLOCK(it->inp);
136742551e99SRandall Stewart 	if (it->iterator_flags & SCTP_ITERATOR_DO_SINGLE_INP) {
136842551e99SRandall Stewart 		it->inp = NULL;
136942551e99SRandall Stewart 	} else {
137042551e99SRandall Stewart 		SCTP_INP_INFO_RLOCK();
137142551e99SRandall Stewart 		it->inp = LIST_NEXT(it->inp, sctp_list);
137242551e99SRandall Stewart 		SCTP_INP_INFO_RUNLOCK();
137342551e99SRandall Stewart 	}
137442551e99SRandall Stewart 	if (it->inp == NULL) {
137542551e99SRandall Stewart 		goto done_with_iterator;
137642551e99SRandall Stewart 	}
137742551e99SRandall Stewart 	goto select_a_new_ep;
137842551e99SRandall Stewart }
137942551e99SRandall Stewart 
138042551e99SRandall Stewart void
138142551e99SRandall Stewart sctp_iterator_worker(void)
138242551e99SRandall Stewart {
138342551e99SRandall Stewart 	struct sctp_iterator *it = NULL;
138442551e99SRandall Stewart 
138542551e99SRandall Stewart 	/* This function is called with the WQ lock in place */
138642551e99SRandall Stewart 
1387b3f1ea41SRandall Stewart 	SCTP_BASE_INFO(iterator_running) = 1;
138842551e99SRandall Stewart again:
1389b3f1ea41SRandall Stewart 	it = TAILQ_FIRST(&SCTP_BASE_INFO(iteratorhead));
139042551e99SRandall Stewart 	while (it) {
139142551e99SRandall Stewart 		/* now lets work on this one */
1392b3f1ea41SRandall Stewart 		TAILQ_REMOVE(&SCTP_BASE_INFO(iteratorhead), it, sctp_nxt_itr);
139342551e99SRandall Stewart 		SCTP_IPI_ITERATOR_WQ_UNLOCK();
139442551e99SRandall Stewart 		sctp_iterator_work(it);
139542551e99SRandall Stewart 		SCTP_IPI_ITERATOR_WQ_LOCK();
13963c503c28SRandall Stewart 		/* sa_ignore FREED_MEMORY */
1397b3f1ea41SRandall Stewart 		it = TAILQ_FIRST(&SCTP_BASE_INFO(iteratorhead));
139842551e99SRandall Stewart 	}
1399b3f1ea41SRandall Stewart 	if (TAILQ_FIRST(&SCTP_BASE_INFO(iteratorhead))) {
140042551e99SRandall Stewart 		goto again;
140142551e99SRandall Stewart 	}
1402b3f1ea41SRandall Stewart 	SCTP_BASE_INFO(iterator_running) = 0;
140342551e99SRandall Stewart 	return;
140442551e99SRandall Stewart }
140542551e99SRandall Stewart 
140642551e99SRandall Stewart #endif
140742551e99SRandall Stewart 
1408f8829a4aSRandall Stewart 
1409f8829a4aSRandall Stewart static void
1410f8829a4aSRandall Stewart sctp_handle_addr_wq(void)
1411f8829a4aSRandall Stewart {
1412f8829a4aSRandall Stewart 	/* deal with the ADDR wq from the rtsock calls */
1413f8829a4aSRandall Stewart 	struct sctp_laddr *wi;
141442551e99SRandall Stewart 	struct sctp_asconf_iterator *asc;
1415f8829a4aSRandall Stewart 
141642551e99SRandall Stewart 	SCTP_MALLOC(asc, struct sctp_asconf_iterator *,
1417207304d4SRandall Stewart 	    sizeof(struct sctp_asconf_iterator), SCTP_M_ASC_IT);
141842551e99SRandall Stewart 	if (asc == NULL) {
141942551e99SRandall Stewart 		/* Try later, no memory */
1420f8829a4aSRandall Stewart 		sctp_timer_start(SCTP_TIMER_TYPE_ADDR_WQ,
1421f8829a4aSRandall Stewart 		    (struct sctp_inpcb *)NULL,
1422f8829a4aSRandall Stewart 		    (struct sctp_tcb *)NULL,
1423f8829a4aSRandall Stewart 		    (struct sctp_nets *)NULL);
142442551e99SRandall Stewart 		return;
1425f8829a4aSRandall Stewart 	}
142642551e99SRandall Stewart 	LIST_INIT(&asc->list_of_work);
142742551e99SRandall Stewart 	asc->cnt = 0;
142842551e99SRandall Stewart 	SCTP_IPI_ITERATOR_WQ_LOCK();
1429b3f1ea41SRandall Stewart 	wi = LIST_FIRST(&SCTP_BASE_INFO(addr_wq));
143042551e99SRandall Stewart 	while (wi != NULL) {
143142551e99SRandall Stewart 		LIST_REMOVE(wi, sctp_nxt_addr);
143242551e99SRandall Stewart 		LIST_INSERT_HEAD(&asc->list_of_work, wi, sctp_nxt_addr);
143342551e99SRandall Stewart 		asc->cnt++;
1434b3f1ea41SRandall Stewart 		wi = LIST_FIRST(&SCTP_BASE_INFO(addr_wq));
1435f8829a4aSRandall Stewart 	}
143642551e99SRandall Stewart 	SCTP_IPI_ITERATOR_WQ_UNLOCK();
143742551e99SRandall Stewart 	if (asc->cnt == 0) {
1438207304d4SRandall Stewart 		SCTP_FREE(asc, SCTP_M_ASC_IT);
143942551e99SRandall Stewart 	} else {
14401b649582SRandall Stewart 		(void)sctp_initiate_iterator(sctp_asconf_iterator_ep,
14411b649582SRandall Stewart 		    sctp_asconf_iterator_stcb,
144242551e99SRandall Stewart 		    NULL,	/* No ep end for boundall */
144342551e99SRandall Stewart 		    SCTP_PCB_FLAGS_BOUNDALL,
144442551e99SRandall Stewart 		    SCTP_PCB_ANY_FEATURES,
14451b649582SRandall Stewart 		    SCTP_ASOC_ANY_STATE,
14461b649582SRandall Stewart 		    (void *)asc, 0,
14471b649582SRandall Stewart 		    sctp_asconf_iterator_end, NULL, 0);
144842551e99SRandall Stewart 	}
1449f8829a4aSRandall Stewart }
1450f8829a4aSRandall Stewart 
1451b54d3a6cSRandall Stewart int retcode = 0;
1452b54d3a6cSRandall Stewart int cur_oerr = 0;
1453b54d3a6cSRandall Stewart 
1454f8829a4aSRandall Stewart void
1455f8829a4aSRandall Stewart sctp_timeout_handler(void *t)
1456f8829a4aSRandall Stewart {
1457f8829a4aSRandall Stewart 	struct sctp_inpcb *inp;
1458f8829a4aSRandall Stewart 	struct sctp_tcb *stcb;
1459f8829a4aSRandall Stewart 	struct sctp_nets *net;
1460f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
1461ceaad40aSRandall Stewart 
1462ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
1463ceaad40aSRandall Stewart 	struct socket *so;
1464ceaad40aSRandall Stewart 
1465ceaad40aSRandall Stewart #endif
1466d61374e1SRandall Stewart 	int did_output, type;
1467f8829a4aSRandall Stewart 	struct sctp_iterator *it = NULL;
1468f8829a4aSRandall Stewart 
1469f8829a4aSRandall Stewart 	tmr = (struct sctp_timer *)t;
1470f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)tmr->ep;
1471f8829a4aSRandall Stewart 	stcb = (struct sctp_tcb *)tmr->tcb;
1472f8829a4aSRandall Stewart 	net = (struct sctp_nets *)tmr->net;
1473f8829a4aSRandall Stewart 	did_output = 1;
1474f8829a4aSRandall Stewart 
1475f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1476f8829a4aSRandall Stewart 	sctp_audit_log(0xF0, (uint8_t) tmr->type);
1477f8829a4aSRandall Stewart 	sctp_auditing(3, inp, stcb, net);
1478f8829a4aSRandall Stewart #endif
1479f8829a4aSRandall Stewart 
1480f8829a4aSRandall Stewart 	/* sanity checks... */
1481f8829a4aSRandall Stewart 	if (tmr->self != (void *)tmr) {
1482f8829a4aSRandall Stewart 		/*
1483ad81507eSRandall Stewart 		 * SCTP_PRINTF("Stale SCTP timer fired (%p), ignoring...\n",
1484f8829a4aSRandall Stewart 		 * tmr);
1485f8829a4aSRandall Stewart 		 */
1486f8829a4aSRandall Stewart 		return;
1487f8829a4aSRandall Stewart 	}
1488a5d547adSRandall Stewart 	tmr->stopped_from = 0xa001;
1489f8829a4aSRandall Stewart 	if (!SCTP_IS_TIMER_TYPE_VALID(tmr->type)) {
1490f8829a4aSRandall Stewart 		/*
1491ad81507eSRandall Stewart 		 * SCTP_PRINTF("SCTP timer fired with invalid type: 0x%x\n",
1492f8829a4aSRandall Stewart 		 * tmr->type);
1493f8829a4aSRandall Stewart 		 */
1494f8829a4aSRandall Stewart 		return;
1495f8829a4aSRandall Stewart 	}
1496a5d547adSRandall Stewart 	tmr->stopped_from = 0xa002;
1497f8829a4aSRandall Stewart 	if ((tmr->type != SCTP_TIMER_TYPE_ADDR_WQ) && (inp == NULL)) {
1498f8829a4aSRandall Stewart 		return;
1499f8829a4aSRandall Stewart 	}
1500f8829a4aSRandall Stewart 	/* if this is an iterator timeout, get the struct and clear inp */
1501a5d547adSRandall Stewart 	tmr->stopped_from = 0xa003;
1502f8829a4aSRandall Stewart 	if (tmr->type == SCTP_TIMER_TYPE_ITERATOR) {
1503f8829a4aSRandall Stewart 		it = (struct sctp_iterator *)inp;
1504f8829a4aSRandall Stewart 		inp = NULL;
1505f8829a4aSRandall Stewart 	}
1506d61374e1SRandall Stewart 	type = tmr->type;
1507f8829a4aSRandall Stewart 	if (inp) {
1508f8829a4aSRandall Stewart 		SCTP_INP_INCR_REF(inp);
1509f8829a4aSRandall Stewart 		if ((inp->sctp_socket == 0) &&
1510f8829a4aSRandall Stewart 		    ((tmr->type != SCTP_TIMER_TYPE_INPKILL) &&
1511a1e13272SRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_SEND) &&
1512a1e13272SRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_RECV) &&
1513a1e13272SRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_HEARTBEAT) &&
1514f8829a4aSRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_SHUTDOWN) &&
1515f8829a4aSRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_SHUTDOWNACK) &&
1516f8829a4aSRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_SHUTDOWNGUARD) &&
1517f8829a4aSRandall Stewart 		    (tmr->type != SCTP_TIMER_TYPE_ASOCKILL))
1518f8829a4aSRandall Stewart 		    ) {
1519f8829a4aSRandall Stewart 			SCTP_INP_DECR_REF(inp);
1520f8829a4aSRandall Stewart 			return;
1521f8829a4aSRandall Stewart 		}
1522f8829a4aSRandall Stewart 	}
1523a5d547adSRandall Stewart 	tmr->stopped_from = 0xa004;
1524f8829a4aSRandall Stewart 	if (stcb) {
1525c105859eSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
1526f8829a4aSRandall Stewart 		if (stcb->asoc.state == 0) {
1527c105859eSRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, -1);
1528f8829a4aSRandall Stewart 			if (inp) {
1529f8829a4aSRandall Stewart 				SCTP_INP_DECR_REF(inp);
1530f8829a4aSRandall Stewart 			}
1531f8829a4aSRandall Stewart 			return;
1532f8829a4aSRandall Stewart 		}
1533f8829a4aSRandall Stewart 	}
1534a5d547adSRandall Stewart 	tmr->stopped_from = 0xa005;
1535ad81507eSRandall Stewart 	SCTPDBG(SCTP_DEBUG_TIMER1, "Timer type %d goes off\n", tmr->type);
1536139bc87fSRandall Stewart 	if (!SCTP_OS_TIMER_ACTIVE(&tmr->timer)) {
1537f8829a4aSRandall Stewart 		if (inp) {
1538f8829a4aSRandall Stewart 			SCTP_INP_DECR_REF(inp);
1539f8829a4aSRandall Stewart 		}
1540207304d4SRandall Stewart 		if (stcb) {
1541207304d4SRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, -1);
1542207304d4SRandall Stewart 		}
1543f8829a4aSRandall Stewart 		return;
1544f8829a4aSRandall Stewart 	}
1545a5d547adSRandall Stewart 	tmr->stopped_from = 0xa006;
1546a5d547adSRandall Stewart 
1547f8829a4aSRandall Stewart 	if (stcb) {
1548f8829a4aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
154950cec919SRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, -1);
1550b54d3a6cSRandall Stewart 		if ((tmr->type != SCTP_TIMER_TYPE_ASOCKILL) &&
1551b54d3a6cSRandall Stewart 		    ((stcb->asoc.state == 0) ||
1552b54d3a6cSRandall Stewart 		    (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED))) {
1553b54d3a6cSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
1554b54d3a6cSRandall Stewart 			if (inp) {
1555b54d3a6cSRandall Stewart 				SCTP_INP_DECR_REF(inp);
1556b54d3a6cSRandall Stewart 			}
1557b54d3a6cSRandall Stewart 			return;
1558b54d3a6cSRandall Stewart 		}
1559f8829a4aSRandall Stewart 	}
156044b7479bSRandall Stewart 	/* record in stopped what t-o occured */
156144b7479bSRandall Stewart 	tmr->stopped_from = tmr->type;
156244b7479bSRandall Stewart 
1563f8829a4aSRandall Stewart 	/* mark as being serviced now */
156444b7479bSRandall Stewart 	if (SCTP_OS_TIMER_PENDING(&tmr->timer)) {
156544b7479bSRandall Stewart 		/*
156644b7479bSRandall Stewart 		 * Callout has been rescheduled.
156744b7479bSRandall Stewart 		 */
156844b7479bSRandall Stewart 		goto get_out;
156944b7479bSRandall Stewart 	}
157044b7479bSRandall Stewart 	if (!SCTP_OS_TIMER_ACTIVE(&tmr->timer)) {
157144b7479bSRandall Stewart 		/*
157244b7479bSRandall Stewart 		 * Not active, so no action.
157344b7479bSRandall Stewart 		 */
157444b7479bSRandall Stewart 		goto get_out;
157544b7479bSRandall Stewart 	}
1576139bc87fSRandall Stewart 	SCTP_OS_TIMER_DEACTIVATE(&tmr->timer);
1577f8829a4aSRandall Stewart 
1578f8829a4aSRandall Stewart 	/* call the handler for the appropriate timer type */
1579f8829a4aSRandall Stewart 	switch (tmr->type) {
1580d61a0ae0SRandall Stewart 	case SCTP_TIMER_TYPE_ZERO_COPY:
1581eacc51c5SRandall Stewart 		if (inp == NULL) {
1582eacc51c5SRandall Stewart 			break;
1583eacc51c5SRandall Stewart 		}
1584d61a0ae0SRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_ZERO_COPY_ACTIVE)) {
1585d61a0ae0SRandall Stewart 			SCTP_ZERO_COPY_EVENT(inp, inp->sctp_socket);
1586d61a0ae0SRandall Stewart 		}
1587d61a0ae0SRandall Stewart 		break;
1588ad21a364SRandall Stewart 	case SCTP_TIMER_TYPE_ZCOPY_SENDQ:
1589eacc51c5SRandall Stewart 		if (inp == NULL) {
1590eacc51c5SRandall Stewart 			break;
1591eacc51c5SRandall Stewart 		}
1592ad21a364SRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_ZERO_COPY_ACTIVE)) {
1593ad21a364SRandall Stewart 			SCTP_ZERO_COPY_SENDQ_EVENT(inp, inp->sctp_socket);
1594ad21a364SRandall Stewart 		}
1595ad21a364SRandall Stewart 		break;
1596f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ADDR_WQ:
1597f8829a4aSRandall Stewart 		sctp_handle_addr_wq();
1598f8829a4aSRandall Stewart 		break;
1599f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ITERATOR:
1600f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoiterator);
1601f8829a4aSRandall Stewart 		sctp_iterator_timer(it);
1602f8829a4aSRandall Stewart 		break;
1603f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
1604ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1605ad81507eSRandall Stewart 			break;
1606ad81507eSRandall Stewart 		}
1607f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timodata);
1608f42a358aSRandall Stewart 		stcb->asoc.timodata++;
1609f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up--;
1610f8829a4aSRandall Stewart 		if (stcb->asoc.num_send_timers_up < 0) {
1611f8829a4aSRandall Stewart 			stcb->asoc.num_send_timers_up = 0;
1612f8829a4aSRandall Stewart 		}
1613b54d3a6cSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
1614b54d3a6cSRandall Stewart 		cur_oerr = stcb->asoc.overall_error_count;
1615b54d3a6cSRandall Stewart 		retcode = sctp_t3rxt_timer(inp, stcb, net);
1616b54d3a6cSRandall Stewart 		if (retcode) {
1617f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1618f8829a4aSRandall Stewart 
1619f8829a4aSRandall Stewart 			goto out_decr;
1620f8829a4aSRandall Stewart 		}
1621b54d3a6cSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
1622f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1623f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1624f8829a4aSRandall Stewart #endif
1625ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
1626f8829a4aSRandall Stewart 		if ((stcb->asoc.num_send_timers_up == 0) &&
1627f8829a4aSRandall Stewart 		    (stcb->asoc.sent_queue_cnt > 0)
1628f8829a4aSRandall Stewart 		    ) {
1629f8829a4aSRandall Stewart 			struct sctp_tmit_chunk *chk;
1630f8829a4aSRandall Stewart 
1631f8829a4aSRandall Stewart 			/*
1632f8829a4aSRandall Stewart 			 * safeguard. If there on some on the sent queue
1633f8829a4aSRandall Stewart 			 * somewhere but no timers running something is
1634f8829a4aSRandall Stewart 			 * wrong... so we start a timer on the first chunk
1635f8829a4aSRandall Stewart 			 * on the send queue on whatever net it is sent to.
1636f8829a4aSRandall Stewart 			 */
1637f8829a4aSRandall Stewart 			chk = TAILQ_FIRST(&stcb->asoc.sent_queue);
1638f8829a4aSRandall Stewart 			sctp_timer_start(SCTP_TIMER_TYPE_SEND, inp, stcb,
1639f8829a4aSRandall Stewart 			    chk->whoTo);
1640f8829a4aSRandall Stewart 		}
1641f8829a4aSRandall Stewart 		break;
1642f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
1643ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1644ad81507eSRandall Stewart 			break;
1645ad81507eSRandall Stewart 		}
1646f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoinit);
1647f42a358aSRandall Stewart 		stcb->asoc.timoinit++;
1648f8829a4aSRandall Stewart 		if (sctp_t1init_timer(inp, stcb, net)) {
1649f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1650f8829a4aSRandall Stewart 			goto out_decr;
1651f8829a4aSRandall Stewart 		}
1652f8829a4aSRandall Stewart 		/* We do output but not here */
1653f8829a4aSRandall Stewart 		did_output = 0;
1654f8829a4aSRandall Stewart 		break;
1655f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
1656ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1657ad81507eSRandall Stewart 			break;
1658c4739e2fSRandall Stewart 		} {
1659c4739e2fSRandall Stewart 			int abort_flag;
1660c4739e2fSRandall Stewart 
1661f8829a4aSRandall Stewart 			SCTP_STAT_INCR(sctps_timosack);
1662f42a358aSRandall Stewart 			stcb->asoc.timosack++;
1663c4739e2fSRandall Stewart 			if (stcb->asoc.cumulative_tsn != stcb->asoc.highest_tsn_inside_map)
1664c4739e2fSRandall Stewart 				sctp_sack_check(stcb, 0, 0, &abort_flag);
1665830d754dSRandall Stewart 
1666830d754dSRandall Stewart 			/*
1667830d754dSRandall Stewart 			 * EY if nr_sacks used then send an nr-sack , a sack
1668830d754dSRandall Stewart 			 * otherwise
1669830d754dSRandall Stewart 			 */
1670830d754dSRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_nr_sack_on_off) && stcb->asoc.peer_supports_nr_sack)
1671830d754dSRandall Stewart 				sctp_send_nr_sack(stcb);
1672830d754dSRandall Stewart 			else
1673f8829a4aSRandall Stewart 				sctp_send_sack(stcb);
1674c4739e2fSRandall Stewart 		}
1675f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1676f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1677f8829a4aSRandall Stewart #endif
1678ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SACK_TMR, SCTP_SO_NOT_LOCKED);
1679f8829a4aSRandall Stewart 		break;
1680f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
1681ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1682ad81507eSRandall Stewart 			break;
1683ad81507eSRandall Stewart 		}
1684f8829a4aSRandall Stewart 		if (sctp_shutdown_timer(inp, stcb, net)) {
1685f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1686f8829a4aSRandall Stewart 			goto out_decr;
1687f8829a4aSRandall Stewart 		}
1688f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoshutdown);
1689f42a358aSRandall Stewart 		stcb->asoc.timoshutdown++;
1690f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1691f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1692f8829a4aSRandall Stewart #endif
1693ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SHUT_TMR, SCTP_SO_NOT_LOCKED);
1694f8829a4aSRandall Stewart 		break;
1695f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
1696f8829a4aSRandall Stewart 		{
16974c9179adSRandall Stewart 			struct sctp_nets *lnet;
1698f8829a4aSRandall Stewart 			int cnt_of_unconf = 0;
1699f8829a4aSRandall Stewart 
1700ad81507eSRandall Stewart 			if ((stcb == NULL) || (inp == NULL)) {
1701ad81507eSRandall Stewart 				break;
1702ad81507eSRandall Stewart 			}
1703f8829a4aSRandall Stewart 			SCTP_STAT_INCR(sctps_timoheartbeat);
1704f42a358aSRandall Stewart 			stcb->asoc.timoheartbeat++;
17054c9179adSRandall Stewart 			TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
17064c9179adSRandall Stewart 				if ((lnet->dest_state & SCTP_ADDR_UNCONFIRMED) &&
17074c9179adSRandall Stewart 				    (lnet->dest_state & SCTP_ADDR_REACHABLE)) {
1708f8829a4aSRandall Stewart 					cnt_of_unconf++;
1709f8829a4aSRandall Stewart 				}
1710f8829a4aSRandall Stewart 			}
1711f8829a4aSRandall Stewart 			if (cnt_of_unconf == 0) {
17124c9179adSRandall Stewart 				if (sctp_heartbeat_timer(inp, stcb, lnet,
17134c9179adSRandall Stewart 				    cnt_of_unconf)) {
1714f8829a4aSRandall Stewart 					/* no need to unlock on tcb its gone */
1715f8829a4aSRandall Stewart 					goto out_decr;
1716f8829a4aSRandall Stewart 				}
1717f8829a4aSRandall Stewart 			}
1718f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
17194c9179adSRandall Stewart 			sctp_auditing(4, inp, stcb, lnet);
1720f8829a4aSRandall Stewart #endif
17214c9179adSRandall Stewart 			sctp_timer_start(SCTP_TIMER_TYPE_HEARTBEAT,
17224c9179adSRandall Stewart 			    stcb->sctp_ep, stcb, lnet);
1723ceaad40aSRandall Stewart 			sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_HB_TMR, SCTP_SO_NOT_LOCKED);
1724f8829a4aSRandall Stewart 		}
1725f8829a4aSRandall Stewart 		break;
1726f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
1727ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1728ad81507eSRandall Stewart 			break;
1729ad81507eSRandall Stewart 		}
1730f8829a4aSRandall Stewart 		if (sctp_cookie_timer(inp, stcb, net)) {
1731f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1732f8829a4aSRandall Stewart 			goto out_decr;
1733f8829a4aSRandall Stewart 		}
1734f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timocookie);
1735f42a358aSRandall Stewart 		stcb->asoc.timocookie++;
1736f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1737f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1738f8829a4aSRandall Stewart #endif
1739f8829a4aSRandall Stewart 		/*
1740f8829a4aSRandall Stewart 		 * We consider T3 and Cookie timer pretty much the same with
1741f8829a4aSRandall Stewart 		 * respect to where from in chunk_output.
1742f8829a4aSRandall Stewart 		 */
1743ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_T3, SCTP_SO_NOT_LOCKED);
1744f8829a4aSRandall Stewart 		break;
1745f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
1746f8829a4aSRandall Stewart 		{
1747f8829a4aSRandall Stewart 			struct timeval tv;
1748f8829a4aSRandall Stewart 			int i, secret;
1749f8829a4aSRandall Stewart 
1750ad81507eSRandall Stewart 			if (inp == NULL) {
1751ad81507eSRandall Stewart 				break;
1752ad81507eSRandall Stewart 			}
1753f8829a4aSRandall Stewart 			SCTP_STAT_INCR(sctps_timosecret);
17546e55db54SRandall Stewart 			(void)SCTP_GETTIME_TIMEVAL(&tv);
1755f8829a4aSRandall Stewart 			SCTP_INP_WLOCK(inp);
1756f8829a4aSRandall Stewart 			inp->sctp_ep.time_of_secret_change = tv.tv_sec;
1757f8829a4aSRandall Stewart 			inp->sctp_ep.last_secret_number =
1758f8829a4aSRandall Stewart 			    inp->sctp_ep.current_secret_number;
1759f8829a4aSRandall Stewart 			inp->sctp_ep.current_secret_number++;
1760f8829a4aSRandall Stewart 			if (inp->sctp_ep.current_secret_number >=
1761f8829a4aSRandall Stewart 			    SCTP_HOW_MANY_SECRETS) {
1762f8829a4aSRandall Stewart 				inp->sctp_ep.current_secret_number = 0;
1763f8829a4aSRandall Stewart 			}
1764f8829a4aSRandall Stewart 			secret = (int)inp->sctp_ep.current_secret_number;
1765f8829a4aSRandall Stewart 			for (i = 0; i < SCTP_NUMBER_OF_SECRETS; i++) {
1766f8829a4aSRandall Stewart 				inp->sctp_ep.secret_key[secret][i] =
1767f8829a4aSRandall Stewart 				    sctp_select_initial_TSN(&inp->sctp_ep);
1768f8829a4aSRandall Stewart 			}
1769f8829a4aSRandall Stewart 			SCTP_INP_WUNLOCK(inp);
1770f8829a4aSRandall Stewart 			sctp_timer_start(SCTP_TIMER_TYPE_NEWCOOKIE, inp, stcb, net);
1771f8829a4aSRandall Stewart 		}
1772f8829a4aSRandall Stewart 		did_output = 0;
1773f8829a4aSRandall Stewart 		break;
1774f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
1775ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1776ad81507eSRandall Stewart 			break;
1777ad81507eSRandall Stewart 		}
1778f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timopathmtu);
1779f8829a4aSRandall Stewart 		sctp_pathmtu_timer(inp, stcb, net);
1780f8829a4aSRandall Stewart 		did_output = 0;
1781f8829a4aSRandall Stewart 		break;
1782f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
1783ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1784ad81507eSRandall Stewart 			break;
1785ad81507eSRandall Stewart 		}
1786f8829a4aSRandall Stewart 		if (sctp_shutdownack_timer(inp, stcb, net)) {
1787f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1788f8829a4aSRandall Stewart 			goto out_decr;
1789f8829a4aSRandall Stewart 		}
1790f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoshutdownack);
1791f42a358aSRandall Stewart 		stcb->asoc.timoshutdownack++;
1792f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1793f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1794f8829a4aSRandall Stewart #endif
1795ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_SHUT_ACK_TMR, SCTP_SO_NOT_LOCKED);
1796f8829a4aSRandall Stewart 		break;
1797f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
1798ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1799ad81507eSRandall Stewart 			break;
1800ad81507eSRandall Stewart 		}
1801f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoshutdownguard);
1802f8829a4aSRandall Stewart 		sctp_abort_an_association(inp, stcb,
1803ceaad40aSRandall Stewart 		    SCTP_SHUTDOWN_GUARD_EXPIRES, NULL, SCTP_SO_NOT_LOCKED);
1804f8829a4aSRandall Stewart 		/* no need to unlock on tcb its gone */
1805f8829a4aSRandall Stewart 		goto out_decr;
1806f8829a4aSRandall Stewart 
1807f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_STRRESET:
1808ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1809ad81507eSRandall Stewart 			break;
1810ad81507eSRandall Stewart 		}
1811f8829a4aSRandall Stewart 		if (sctp_strreset_timer(inp, stcb, net)) {
1812f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1813f8829a4aSRandall Stewart 			goto out_decr;
1814f8829a4aSRandall Stewart 		}
1815f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timostrmrst);
1816ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_STRRST_TMR, SCTP_SO_NOT_LOCKED);
1817f8829a4aSRandall Stewart 		break;
1818f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_EARLYFR:
1819f8829a4aSRandall Stewart 		/* Need to do FR of things for net */
1820ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1821ad81507eSRandall Stewart 			break;
1822ad81507eSRandall Stewart 		}
1823f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoearlyfr);
1824f8829a4aSRandall Stewart 		sctp_early_fr_timer(inp, stcb, net);
1825f8829a4aSRandall Stewart 		break;
1826f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASCONF:
1827ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1828ad81507eSRandall Stewart 			break;
1829ad81507eSRandall Stewart 		}
1830f8829a4aSRandall Stewart 		if (sctp_asconf_timer(inp, stcb, net)) {
1831f8829a4aSRandall Stewart 			/* no need to unlock on tcb its gone */
1832f8829a4aSRandall Stewart 			goto out_decr;
1833f8829a4aSRandall Stewart 		}
1834f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoasconf);
1835f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1836f8829a4aSRandall Stewart 		sctp_auditing(4, inp, stcb, net);
1837f8829a4aSRandall Stewart #endif
1838ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_ASCONF_TMR, SCTP_SO_NOT_LOCKED);
1839f8829a4aSRandall Stewart 		break;
1840851b7298SRandall Stewart 	case SCTP_TIMER_TYPE_PRIM_DELETED:
1841851b7298SRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1842851b7298SRandall Stewart 			break;
1843851b7298SRandall Stewart 		}
184404ee05e8SRandall Stewart 		sctp_delete_prim_timer(inp, stcb, net);
1845851b7298SRandall Stewart 		SCTP_STAT_INCR(sctps_timodelprim);
1846851b7298SRandall Stewart 		break;
1847f8829a4aSRandall Stewart 
1848f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_AUTOCLOSE:
1849ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1850ad81507eSRandall Stewart 			break;
1851ad81507eSRandall Stewart 		}
1852f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoautoclose);
1853f8829a4aSRandall Stewart 		sctp_autoclose_timer(inp, stcb, net);
1854ceaad40aSRandall Stewart 		sctp_chunk_output(inp, stcb, SCTP_OUTPUT_FROM_AUTOCLOSE_TMR, SCTP_SO_NOT_LOCKED);
1855f8829a4aSRandall Stewart 		did_output = 0;
1856f8829a4aSRandall Stewart 		break;
1857f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASOCKILL:
1858ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
1859ad81507eSRandall Stewart 			break;
1860ad81507eSRandall Stewart 		}
1861f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoassockill);
1862f8829a4aSRandall Stewart 		/* Can we free it yet? */
1863f8829a4aSRandall Stewart 		SCTP_INP_DECR_REF(inp);
1864a5d547adSRandall Stewart 		sctp_timer_stop(SCTP_TIMER_TYPE_ASOCKILL, inp, stcb, NULL, SCTP_FROM_SCTPUTIL + SCTP_LOC_1);
1865ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
1866ceaad40aSRandall Stewart 		so = SCTP_INP_SO(inp);
1867ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
1868ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
1869ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
1870ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
1871ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
1872ceaad40aSRandall Stewart #endif
1873c4739e2fSRandall Stewart 		(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC, SCTP_FROM_SCTPUTIL + SCTP_LOC_2);
1874ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
1875ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
1876ceaad40aSRandall Stewart #endif
1877f8829a4aSRandall Stewart 		/*
1878f8829a4aSRandall Stewart 		 * free asoc, always unlocks (or destroy's) so prevent
1879f8829a4aSRandall Stewart 		 * duplicate unlock or unlock of a free mtx :-0
1880f8829a4aSRandall Stewart 		 */
1881f8829a4aSRandall Stewart 		stcb = NULL;
1882f8829a4aSRandall Stewart 		goto out_no_decr;
1883f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INPKILL:
1884f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_timoinpkill);
1885ad81507eSRandall Stewart 		if (inp == NULL) {
1886ad81507eSRandall Stewart 			break;
1887ad81507eSRandall Stewart 		}
1888f8829a4aSRandall Stewart 		/*
1889f8829a4aSRandall Stewart 		 * special case, take away our increment since WE are the
1890f8829a4aSRandall Stewart 		 * killer
1891f8829a4aSRandall Stewart 		 */
1892f8829a4aSRandall Stewart 		SCTP_INP_DECR_REF(inp);
1893a5d547adSRandall Stewart 		sctp_timer_stop(SCTP_TIMER_TYPE_INPKILL, inp, NULL, NULL, SCTP_FROM_SCTPUTIL + SCTP_LOC_3);
1894b0552ae2SRandall Stewart 		sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
1895b0552ae2SRandall Stewart 		    SCTP_CALLED_DIRECTLY_NOCMPSET);
1896d61374e1SRandall Stewart 		inp = NULL;
1897f8829a4aSRandall Stewart 		goto out_no_decr;
1898f8829a4aSRandall Stewart 	default:
1899ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_TIMER1, "sctp_timeout_handler:unknown timer %d\n",
1900f8829a4aSRandall Stewart 		    tmr->type);
1901f8829a4aSRandall Stewart 		break;
1902f8829a4aSRandall Stewart 	};
1903f8829a4aSRandall Stewart #ifdef SCTP_AUDITING_ENABLED
1904f8829a4aSRandall Stewart 	sctp_audit_log(0xF1, (uint8_t) tmr->type);
1905f8829a4aSRandall Stewart 	if (inp)
1906f8829a4aSRandall Stewart 		sctp_auditing(5, inp, stcb, net);
1907f8829a4aSRandall Stewart #endif
1908f8829a4aSRandall Stewart 	if ((did_output) && stcb) {
1909f8829a4aSRandall Stewart 		/*
1910f8829a4aSRandall Stewart 		 * Now we need to clean up the control chunk chain if an
1911f8829a4aSRandall Stewart 		 * ECNE is on it. It must be marked as UNSENT again so next
1912f8829a4aSRandall Stewart 		 * call will continue to send it until such time that we get
1913f8829a4aSRandall Stewart 		 * a CWR, to remove it. It is, however, less likely that we
1914f8829a4aSRandall Stewart 		 * will find a ecn echo on the chain though.
1915f8829a4aSRandall Stewart 		 */
1916f8829a4aSRandall Stewart 		sctp_fix_ecn_echo(&stcb->asoc);
1917f8829a4aSRandall Stewart 	}
191844b7479bSRandall Stewart get_out:
1919f8829a4aSRandall Stewart 	if (stcb) {
1920f8829a4aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
1921f8829a4aSRandall Stewart 	}
1922f8829a4aSRandall Stewart out_decr:
1923f8829a4aSRandall Stewart 	if (inp) {
1924f8829a4aSRandall Stewart 		SCTP_INP_DECR_REF(inp);
1925f8829a4aSRandall Stewart 	}
1926f8829a4aSRandall Stewart out_no_decr:
1927ad81507eSRandall Stewart 	SCTPDBG(SCTP_DEBUG_TIMER1, "Timer now complete (type %d)\n",
1928d61374e1SRandall Stewart 	    type);
1929f8829a4aSRandall Stewart }
1930f8829a4aSRandall Stewart 
1931ad81507eSRandall Stewart void
1932f8829a4aSRandall Stewart sctp_timer_start(int t_type, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
1933f8829a4aSRandall Stewart     struct sctp_nets *net)
1934f8829a4aSRandall Stewart {
1935f8829a4aSRandall Stewart 	int to_ticks;
1936f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
1937f8829a4aSRandall Stewart 
1938139bc87fSRandall Stewart 	if ((t_type != SCTP_TIMER_TYPE_ADDR_WQ) && (inp == NULL))
1939ad81507eSRandall Stewart 		return;
1940f8829a4aSRandall Stewart 
1941f8829a4aSRandall Stewart 	to_ticks = 0;
1942f8829a4aSRandall Stewart 
1943f8829a4aSRandall Stewart 	tmr = NULL;
1944f8829a4aSRandall Stewart 	if (stcb) {
1945f8829a4aSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
1946f8829a4aSRandall Stewart 	}
1947f8829a4aSRandall Stewart 	switch (t_type) {
1948d61a0ae0SRandall Stewart 	case SCTP_TIMER_TYPE_ZERO_COPY:
1949d61a0ae0SRandall Stewart 		tmr = &inp->sctp_ep.zero_copy_timer;
1950d61a0ae0SRandall Stewart 		to_ticks = SCTP_ZERO_COPY_TICK_DELAY;
1951d61a0ae0SRandall Stewart 		break;
1952ad21a364SRandall Stewart 	case SCTP_TIMER_TYPE_ZCOPY_SENDQ:
1953ad21a364SRandall Stewart 		tmr = &inp->sctp_ep.zero_copy_sendq_timer;
1954ad21a364SRandall Stewart 		to_ticks = SCTP_ZERO_COPY_SENDQ_TICK_DELAY;
1955ad21a364SRandall Stewart 		break;
1956f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ADDR_WQ:
1957f8829a4aSRandall Stewart 		/* Only 1 tick away :-) */
1958b3f1ea41SRandall Stewart 		tmr = &SCTP_BASE_INFO(addr_wq_timer);
195942551e99SRandall Stewart 		to_ticks = SCTP_ADDRESS_TICK_DELAY;
1960f8829a4aSRandall Stewart 		break;
1961f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ITERATOR:
1962f8829a4aSRandall Stewart 		{
1963f8829a4aSRandall Stewart 			struct sctp_iterator *it;
1964f8829a4aSRandall Stewart 
1965f8829a4aSRandall Stewart 			it = (struct sctp_iterator *)inp;
1966f8829a4aSRandall Stewart 			tmr = &it->tmr;
1967f8829a4aSRandall Stewart 			to_ticks = SCTP_ITERATOR_TICKS;
1968f8829a4aSRandall Stewart 		}
1969f8829a4aSRandall Stewart 		break;
1970f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
1971f8829a4aSRandall Stewart 		/* Here we use the RTO timer */
1972f8829a4aSRandall Stewart 		{
1973f8829a4aSRandall Stewart 			int rto_val;
1974f8829a4aSRandall Stewart 
1975f8829a4aSRandall Stewart 			if ((stcb == NULL) || (net == NULL)) {
1976ad81507eSRandall Stewart 				return;
1977f8829a4aSRandall Stewart 			}
1978f8829a4aSRandall Stewart 			tmr = &net->rxt_timer;
1979f8829a4aSRandall Stewart 			if (net->RTO == 0) {
1980f8829a4aSRandall Stewart 				rto_val = stcb->asoc.initial_rto;
1981f8829a4aSRandall Stewart 			} else {
1982f8829a4aSRandall Stewart 				rto_val = net->RTO;
1983f8829a4aSRandall Stewart 			}
1984f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(rto_val);
1985f8829a4aSRandall Stewart 		}
1986f8829a4aSRandall Stewart 		break;
1987f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
1988f8829a4aSRandall Stewart 		/*
1989f8829a4aSRandall Stewart 		 * Here we use the INIT timer default usually about 1
1990f8829a4aSRandall Stewart 		 * minute.
1991f8829a4aSRandall Stewart 		 */
1992f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
1993ad81507eSRandall Stewart 			return;
1994f8829a4aSRandall Stewart 		}
1995f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
1996f8829a4aSRandall Stewart 		if (net->RTO == 0) {
1997f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
1998f8829a4aSRandall Stewart 		} else {
1999f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2000f8829a4aSRandall Stewart 		}
2001f8829a4aSRandall Stewart 		break;
2002f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
2003f8829a4aSRandall Stewart 		/*
2004f8829a4aSRandall Stewart 		 * Here we use the Delayed-Ack timer value from the inp
2005f8829a4aSRandall Stewart 		 * ususually about 200ms.
2006f8829a4aSRandall Stewart 		 */
2007f8829a4aSRandall Stewart 		if (stcb == NULL) {
2008ad81507eSRandall Stewart 			return;
2009f8829a4aSRandall Stewart 		}
2010f8829a4aSRandall Stewart 		tmr = &stcb->asoc.dack_timer;
2011f8829a4aSRandall Stewart 		to_ticks = MSEC_TO_TICKS(stcb->asoc.delayed_ack);
2012f8829a4aSRandall Stewart 		break;
2013f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
2014f8829a4aSRandall Stewart 		/* Here we use the RTO of the destination. */
2015f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2016ad81507eSRandall Stewart 			return;
2017f8829a4aSRandall Stewart 		}
2018f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2019f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2020f8829a4aSRandall Stewart 		} else {
2021f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2022f8829a4aSRandall Stewart 		}
2023f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2024f8829a4aSRandall Stewart 		break;
2025f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
2026f8829a4aSRandall Stewart 		/*
2027f8829a4aSRandall Stewart 		 * the net is used here so that we can add in the RTO. Even
2028f8829a4aSRandall Stewart 		 * though we use a different timer. We also add the HB timer
2029f8829a4aSRandall Stewart 		 * PLUS a random jitter.
2030f8829a4aSRandall Stewart 		 */
2031ad81507eSRandall Stewart 		if ((inp == NULL) || (stcb == NULL)) {
2032ad81507eSRandall Stewart 			return;
2033ad81507eSRandall Stewart 		} else {
2034f8829a4aSRandall Stewart 			uint32_t rndval;
2035f8829a4aSRandall Stewart 			uint8_t this_random;
2036f8829a4aSRandall Stewart 			int cnt_of_unconf = 0;
2037f8829a4aSRandall Stewart 			struct sctp_nets *lnet;
2038f8829a4aSRandall Stewart 
2039f8829a4aSRandall Stewart 			TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
2040f8829a4aSRandall Stewart 				if ((lnet->dest_state & SCTP_ADDR_UNCONFIRMED) &&
2041f8829a4aSRandall Stewart 				    (lnet->dest_state & SCTP_ADDR_REACHABLE)) {
2042f8829a4aSRandall Stewart 					cnt_of_unconf++;
2043f8829a4aSRandall Stewart 				}
2044f8829a4aSRandall Stewart 			}
2045f8829a4aSRandall Stewart 			if (cnt_of_unconf) {
20463c503c28SRandall Stewart 				net = lnet = NULL;
2047ad81507eSRandall Stewart 				(void)sctp_heartbeat_timer(inp, stcb, lnet, cnt_of_unconf);
2048f8829a4aSRandall Stewart 			}
2049f8829a4aSRandall Stewart 			if (stcb->asoc.hb_random_idx > 3) {
2050f8829a4aSRandall Stewart 				rndval = sctp_select_initial_TSN(&inp->sctp_ep);
2051f8829a4aSRandall Stewart 				memcpy(stcb->asoc.hb_random_values, &rndval,
2052f8829a4aSRandall Stewart 				    sizeof(stcb->asoc.hb_random_values));
2053f8829a4aSRandall Stewart 				stcb->asoc.hb_random_idx = 0;
205442551e99SRandall Stewart 			}
2055f8829a4aSRandall Stewart 			this_random = stcb->asoc.hb_random_values[stcb->asoc.hb_random_idx];
2056f8829a4aSRandall Stewart 			stcb->asoc.hb_random_idx++;
2057f8829a4aSRandall Stewart 			stcb->asoc.hb_ect_randombit = 0;
2058f8829a4aSRandall Stewart 			/*
2059f8829a4aSRandall Stewart 			 * this_random will be 0 - 256 ms RTO is in ms.
2060f8829a4aSRandall Stewart 			 */
2061f8829a4aSRandall Stewart 			if ((stcb->asoc.hb_is_disabled) &&
2062f8829a4aSRandall Stewart 			    (cnt_of_unconf == 0)) {
2063ad81507eSRandall Stewart 				return;
2064f8829a4aSRandall Stewart 			}
2065f8829a4aSRandall Stewart 			if (net) {
2066f8829a4aSRandall Stewart 				int delay;
2067f8829a4aSRandall Stewart 
2068f8829a4aSRandall Stewart 				delay = stcb->asoc.heart_beat_delay;
2069f8829a4aSRandall Stewart 				TAILQ_FOREACH(lnet, &stcb->asoc.nets, sctp_next) {
2070f8829a4aSRandall Stewart 					if ((lnet->dest_state & SCTP_ADDR_UNCONFIRMED) &&
2071f8829a4aSRandall Stewart 					    ((lnet->dest_state & SCTP_ADDR_OUT_OF_SCOPE) == 0) &&
2072f8829a4aSRandall Stewart 					    (lnet->dest_state & SCTP_ADDR_REACHABLE)) {
2073f8829a4aSRandall Stewart 						delay = 0;
2074f8829a4aSRandall Stewart 					}
2075f8829a4aSRandall Stewart 				}
2076f8829a4aSRandall Stewart 				if (net->RTO == 0) {
2077f8829a4aSRandall Stewart 					/* Never been checked */
2078f8829a4aSRandall Stewart 					to_ticks = this_random + stcb->asoc.initial_rto + delay;
2079f8829a4aSRandall Stewart 				} else {
2080f8829a4aSRandall Stewart 					/* set rto_val to the ms */
2081f8829a4aSRandall Stewart 					to_ticks = delay + net->RTO + this_random;
2082f8829a4aSRandall Stewart 				}
2083f8829a4aSRandall Stewart 			} else {
2084f8829a4aSRandall Stewart 				if (cnt_of_unconf) {
2085f8829a4aSRandall Stewart 					to_ticks = this_random + stcb->asoc.initial_rto;
2086f8829a4aSRandall Stewart 				} else {
2087f8829a4aSRandall Stewart 					to_ticks = stcb->asoc.heart_beat_delay + this_random + stcb->asoc.initial_rto;
2088f8829a4aSRandall Stewart 				}
2089f8829a4aSRandall Stewart 			}
2090f8829a4aSRandall Stewart 			/*
2091f8829a4aSRandall Stewart 			 * Now we must convert the to_ticks that are now in
2092f8829a4aSRandall Stewart 			 * ms to ticks.
2093f8829a4aSRandall Stewart 			 */
2094f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(to_ticks);
2095f8829a4aSRandall Stewart 			tmr = &stcb->asoc.hb_timer;
2096f8829a4aSRandall Stewart 		}
2097f8829a4aSRandall Stewart 		break;
2098f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
2099f8829a4aSRandall Stewart 		/*
2100f8829a4aSRandall Stewart 		 * Here we can use the RTO timer from the network since one
2101f8829a4aSRandall Stewart 		 * RTT was compelete. If a retran happened then we will be
2102f8829a4aSRandall Stewart 		 * using the RTO initial value.
2103f8829a4aSRandall Stewart 		 */
2104f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2105ad81507eSRandall Stewart 			return;
2106f8829a4aSRandall Stewart 		}
2107f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2108f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2109f8829a4aSRandall Stewart 		} else {
2110f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2111f8829a4aSRandall Stewart 		}
2112f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2113f8829a4aSRandall Stewart 		break;
2114f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
2115f8829a4aSRandall Stewart 		/*
2116f8829a4aSRandall Stewart 		 * nothing needed but the endpoint here ususually about 60
2117f8829a4aSRandall Stewart 		 * minutes.
2118f8829a4aSRandall Stewart 		 */
2119ad81507eSRandall Stewart 		if (inp == NULL) {
2120ad81507eSRandall Stewart 			return;
2121ad81507eSRandall Stewart 		}
2122f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2123f8829a4aSRandall Stewart 		to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_SIGNATURE];
2124f8829a4aSRandall Stewart 		break;
2125f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASOCKILL:
2126f8829a4aSRandall Stewart 		if (stcb == NULL) {
2127ad81507eSRandall Stewart 			return;
2128f8829a4aSRandall Stewart 		}
2129f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2130f8829a4aSRandall Stewart 		to_ticks = MSEC_TO_TICKS(SCTP_ASOC_KILL_TIMEOUT);
2131f8829a4aSRandall Stewart 		break;
2132f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INPKILL:
2133f8829a4aSRandall Stewart 		/*
2134f8829a4aSRandall Stewart 		 * The inp is setup to die. We re-use the signature_chage
2135f8829a4aSRandall Stewart 		 * timer since that has stopped and we are in the GONE
2136f8829a4aSRandall Stewart 		 * state.
2137f8829a4aSRandall Stewart 		 */
2138ad81507eSRandall Stewart 		if (inp == NULL) {
2139ad81507eSRandall Stewart 			return;
2140ad81507eSRandall Stewart 		}
2141f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2142f8829a4aSRandall Stewart 		to_ticks = MSEC_TO_TICKS(SCTP_INP_KILL_TIMEOUT);
2143f8829a4aSRandall Stewart 		break;
2144f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
2145f8829a4aSRandall Stewart 		/*
2146f8829a4aSRandall Stewart 		 * Here we use the value found in the EP for PMTU ususually
2147f8829a4aSRandall Stewart 		 * about 10 minutes.
2148f8829a4aSRandall Stewart 		 */
2149ad81507eSRandall Stewart 		if ((stcb == NULL) || (inp == NULL)) {
2150ad81507eSRandall Stewart 			return;
2151f8829a4aSRandall Stewart 		}
2152f8829a4aSRandall Stewart 		if (net == NULL) {
2153ad81507eSRandall Stewart 			return;
2154f8829a4aSRandall Stewart 		}
2155f8829a4aSRandall Stewart 		to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_PMTU];
2156f8829a4aSRandall Stewart 		tmr = &net->pmtu_timer;
2157f8829a4aSRandall Stewart 		break;
2158f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
2159f8829a4aSRandall Stewart 		/* Here we use the RTO of the destination */
2160f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2161ad81507eSRandall Stewart 			return;
2162f8829a4aSRandall Stewart 		}
2163f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2164f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2165f8829a4aSRandall Stewart 		} else {
2166f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2167f8829a4aSRandall Stewart 		}
2168f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2169f8829a4aSRandall Stewart 		break;
2170f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
2171f8829a4aSRandall Stewart 		/*
2172f8829a4aSRandall Stewart 		 * Here we use the endpoints shutdown guard timer usually
2173f8829a4aSRandall Stewart 		 * about 3 minutes.
2174f8829a4aSRandall Stewart 		 */
2175ad81507eSRandall Stewart 		if ((inp == NULL) || (stcb == NULL)) {
2176ad81507eSRandall Stewart 			return;
2177f8829a4aSRandall Stewart 		}
2178f8829a4aSRandall Stewart 		to_ticks = inp->sctp_ep.sctp_timeoutticks[SCTP_TIMER_MAXSHUTDOWN];
2179f8829a4aSRandall Stewart 		tmr = &stcb->asoc.shut_guard_timer;
2180f8829a4aSRandall Stewart 		break;
2181f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_STRRESET:
2182f8829a4aSRandall Stewart 		/*
21831b649582SRandall Stewart 		 * Here the timer comes from the stcb but its value is from
21841b649582SRandall Stewart 		 * the net's RTO.
2185f8829a4aSRandall Stewart 		 */
2186f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2187ad81507eSRandall Stewart 			return;
2188f8829a4aSRandall Stewart 		}
2189f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2190f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2191f8829a4aSRandall Stewart 		} else {
2192f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2193f8829a4aSRandall Stewart 		}
2194f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2195f8829a4aSRandall Stewart 		break;
2196f8829a4aSRandall Stewart 
2197f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_EARLYFR:
2198f8829a4aSRandall Stewart 		{
2199f8829a4aSRandall Stewart 			unsigned int msec;
2200f8829a4aSRandall Stewart 
2201f8829a4aSRandall Stewart 			if ((stcb == NULL) || (net == NULL)) {
2202ad81507eSRandall Stewart 				return;
2203f8829a4aSRandall Stewart 			}
2204f8829a4aSRandall Stewart 			if (net->flight_size > net->cwnd) {
2205f8829a4aSRandall Stewart 				/* no need to start */
2206ad81507eSRandall Stewart 				return;
2207f8829a4aSRandall Stewart 			}
2208f8829a4aSRandall Stewart 			SCTP_STAT_INCR(sctps_earlyfrstart);
2209f8829a4aSRandall Stewart 			if (net->lastsa == 0) {
2210f8829a4aSRandall Stewart 				/* Hmm no rtt estimate yet? */
2211f8829a4aSRandall Stewart 				msec = stcb->asoc.initial_rto >> 2;
2212f8829a4aSRandall Stewart 			} else {
2213f8829a4aSRandall Stewart 				msec = ((net->lastsa >> 2) + net->lastsv) >> 1;
2214f8829a4aSRandall Stewart 			}
2215b3f1ea41SRandall Stewart 			if (msec < SCTP_BASE_SYSCTL(sctp_early_fr_msec)) {
2216b3f1ea41SRandall Stewart 				msec = SCTP_BASE_SYSCTL(sctp_early_fr_msec);
2217f8829a4aSRandall Stewart 				if (msec < SCTP_MINFR_MSEC_FLOOR) {
2218f8829a4aSRandall Stewart 					msec = SCTP_MINFR_MSEC_FLOOR;
2219f8829a4aSRandall Stewart 				}
2220f8829a4aSRandall Stewart 			}
2221f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(msec);
2222f8829a4aSRandall Stewart 			tmr = &net->fr_timer;
2223f8829a4aSRandall Stewart 		}
2224f8829a4aSRandall Stewart 		break;
2225f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASCONF:
2226f8829a4aSRandall Stewart 		/*
22271b649582SRandall Stewart 		 * Here the timer comes from the stcb but its value is from
22281b649582SRandall Stewart 		 * the net's RTO.
2229f8829a4aSRandall Stewart 		 */
2230f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
2231ad81507eSRandall Stewart 			return;
2232f8829a4aSRandall Stewart 		}
2233f8829a4aSRandall Stewart 		if (net->RTO == 0) {
2234f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2235f8829a4aSRandall Stewart 		} else {
2236f8829a4aSRandall Stewart 			to_ticks = MSEC_TO_TICKS(net->RTO);
2237f8829a4aSRandall Stewart 		}
2238f8829a4aSRandall Stewart 		tmr = &stcb->asoc.asconf_timer;
2239f8829a4aSRandall Stewart 		break;
2240851b7298SRandall Stewart 	case SCTP_TIMER_TYPE_PRIM_DELETED:
2241851b7298SRandall Stewart 		if ((stcb == NULL) || (net != NULL)) {
2242851b7298SRandall Stewart 			return;
2243851b7298SRandall Stewart 		}
2244851b7298SRandall Stewart 		to_ticks = MSEC_TO_TICKS(stcb->asoc.initial_rto);
2245851b7298SRandall Stewart 		tmr = &stcb->asoc.delete_prim_timer;
2246851b7298SRandall Stewart 		break;
2247f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_AUTOCLOSE:
2248f8829a4aSRandall Stewart 		if (stcb == NULL) {
2249ad81507eSRandall Stewart 			return;
2250f8829a4aSRandall Stewart 		}
2251f8829a4aSRandall Stewart 		if (stcb->asoc.sctp_autoclose_ticks == 0) {
2252f8829a4aSRandall Stewart 			/*
2253f8829a4aSRandall Stewart 			 * Really an error since stcb is NOT set to
2254f8829a4aSRandall Stewart 			 * autoclose
2255f8829a4aSRandall Stewart 			 */
2256ad81507eSRandall Stewart 			return;
2257f8829a4aSRandall Stewart 		}
2258f8829a4aSRandall Stewart 		to_ticks = stcb->asoc.sctp_autoclose_ticks;
2259f8829a4aSRandall Stewart 		tmr = &stcb->asoc.autoclose_timer;
2260f8829a4aSRandall Stewart 		break;
2261f8829a4aSRandall Stewart 	default:
2262ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_TIMER1, "%s: Unknown timer type %d\n",
2263ad81507eSRandall Stewart 		    __FUNCTION__, t_type);
2264ad81507eSRandall Stewart 		return;
2265f8829a4aSRandall Stewart 		break;
2266f8829a4aSRandall Stewart 	};
2267f8829a4aSRandall Stewart 	if ((to_ticks <= 0) || (tmr == NULL)) {
2268ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_TIMER1, "%s: %d:software error to_ticks:%d tmr:%p not set ??\n",
2269ad81507eSRandall Stewart 		    __FUNCTION__, t_type, to_ticks, tmr);
2270ad81507eSRandall Stewart 		return;
2271f8829a4aSRandall Stewart 	}
2272139bc87fSRandall Stewart 	if (SCTP_OS_TIMER_PENDING(&tmr->timer)) {
2273f8829a4aSRandall Stewart 		/*
2274f8829a4aSRandall Stewart 		 * we do NOT allow you to have it already running. if it is
2275f8829a4aSRandall Stewart 		 * we leave the current one up unchanged
2276f8829a4aSRandall Stewart 		 */
2277ad81507eSRandall Stewart 		return;
2278f8829a4aSRandall Stewart 	}
2279f8829a4aSRandall Stewart 	/* At this point we can proceed */
2280f8829a4aSRandall Stewart 	if (t_type == SCTP_TIMER_TYPE_SEND) {
2281f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up++;
2282f8829a4aSRandall Stewart 	}
2283a5d547adSRandall Stewart 	tmr->stopped_from = 0;
2284f8829a4aSRandall Stewart 	tmr->type = t_type;
2285f8829a4aSRandall Stewart 	tmr->ep = (void *)inp;
2286f8829a4aSRandall Stewart 	tmr->tcb = (void *)stcb;
2287f8829a4aSRandall Stewart 	tmr->net = (void *)net;
2288f8829a4aSRandall Stewart 	tmr->self = (void *)tmr;
2289c4739e2fSRandall Stewart 	tmr->ticks = sctp_get_tick_count();
2290ad81507eSRandall Stewart 	(void)SCTP_OS_TIMER_START(&tmr->timer, to_ticks, sctp_timeout_handler, tmr);
2291ad81507eSRandall Stewart 	return;
2292f8829a4aSRandall Stewart }
2293f8829a4aSRandall Stewart 
22946e55db54SRandall Stewart void
2295f8829a4aSRandall Stewart sctp_timer_stop(int t_type, struct sctp_inpcb *inp, struct sctp_tcb *stcb,
2296a5d547adSRandall Stewart     struct sctp_nets *net, uint32_t from)
2297f8829a4aSRandall Stewart {
2298f8829a4aSRandall Stewart 	struct sctp_timer *tmr;
2299f8829a4aSRandall Stewart 
2300f8829a4aSRandall Stewart 	if ((t_type != SCTP_TIMER_TYPE_ADDR_WQ) &&
2301f8829a4aSRandall Stewart 	    (inp == NULL))
23026e55db54SRandall Stewart 		return;
2303f8829a4aSRandall Stewart 
2304f8829a4aSRandall Stewart 	tmr = NULL;
2305f8829a4aSRandall Stewart 	if (stcb) {
2306f8829a4aSRandall Stewart 		SCTP_TCB_LOCK_ASSERT(stcb);
2307f8829a4aSRandall Stewart 	}
2308f8829a4aSRandall Stewart 	switch (t_type) {
2309d61a0ae0SRandall Stewart 	case SCTP_TIMER_TYPE_ZERO_COPY:
2310d61a0ae0SRandall Stewart 		tmr = &inp->sctp_ep.zero_copy_timer;
2311d61a0ae0SRandall Stewart 		break;
2312ad21a364SRandall Stewart 	case SCTP_TIMER_TYPE_ZCOPY_SENDQ:
2313ad21a364SRandall Stewart 		tmr = &inp->sctp_ep.zero_copy_sendq_timer;
2314ad21a364SRandall Stewart 		break;
2315f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ADDR_WQ:
2316b3f1ea41SRandall Stewart 		tmr = &SCTP_BASE_INFO(addr_wq_timer);
2317f8829a4aSRandall Stewart 		break;
2318f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_EARLYFR:
2319f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23206e55db54SRandall Stewart 			return;
2321f8829a4aSRandall Stewart 		}
2322f8829a4aSRandall Stewart 		tmr = &net->fr_timer;
2323f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_earlyfrstop);
2324f8829a4aSRandall Stewart 		break;
2325f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ITERATOR:
2326f8829a4aSRandall Stewart 		{
2327f8829a4aSRandall Stewart 			struct sctp_iterator *it;
2328f8829a4aSRandall Stewart 
2329f8829a4aSRandall Stewart 			it = (struct sctp_iterator *)inp;
2330f8829a4aSRandall Stewart 			tmr = &it->tmr;
2331f8829a4aSRandall Stewart 		}
2332f8829a4aSRandall Stewart 		break;
2333f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SEND:
2334f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23356e55db54SRandall Stewart 			return;
2336f8829a4aSRandall Stewart 		}
2337f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2338f8829a4aSRandall Stewart 		break;
2339f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INIT:
2340f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23416e55db54SRandall Stewart 			return;
2342f8829a4aSRandall Stewart 		}
2343f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2344f8829a4aSRandall Stewart 		break;
2345f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_RECV:
2346f8829a4aSRandall Stewart 		if (stcb == NULL) {
23476e55db54SRandall Stewart 			return;
2348f8829a4aSRandall Stewart 		}
2349f8829a4aSRandall Stewart 		tmr = &stcb->asoc.dack_timer;
2350f8829a4aSRandall Stewart 		break;
2351f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWN:
2352f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23536e55db54SRandall Stewart 			return;
2354f8829a4aSRandall Stewart 		}
2355f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2356f8829a4aSRandall Stewart 		break;
2357f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_HEARTBEAT:
2358f8829a4aSRandall Stewart 		if (stcb == NULL) {
23596e55db54SRandall Stewart 			return;
2360f8829a4aSRandall Stewart 		}
2361f8829a4aSRandall Stewart 		tmr = &stcb->asoc.hb_timer;
2362f8829a4aSRandall Stewart 		break;
2363f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_COOKIE:
2364f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23656e55db54SRandall Stewart 			return;
2366f8829a4aSRandall Stewart 		}
2367f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2368f8829a4aSRandall Stewart 		break;
2369f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_NEWCOOKIE:
2370f8829a4aSRandall Stewart 		/* nothing needed but the endpoint here */
2371f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2372f8829a4aSRandall Stewart 		/*
2373f8829a4aSRandall Stewart 		 * We re-use the newcookie timer for the INP kill timer. We
2374f8829a4aSRandall Stewart 		 * must assure that we do not kill it by accident.
2375f8829a4aSRandall Stewart 		 */
2376f8829a4aSRandall Stewart 		break;
2377f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASOCKILL:
2378f8829a4aSRandall Stewart 		/*
2379f8829a4aSRandall Stewart 		 * Stop the asoc kill timer.
2380f8829a4aSRandall Stewart 		 */
2381f8829a4aSRandall Stewart 		if (stcb == NULL) {
23826e55db54SRandall Stewart 			return;
2383f8829a4aSRandall Stewart 		}
2384f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2385f8829a4aSRandall Stewart 		break;
2386f8829a4aSRandall Stewart 
2387f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_INPKILL:
2388f8829a4aSRandall Stewart 		/*
2389f8829a4aSRandall Stewart 		 * The inp is setup to die. We re-use the signature_chage
2390f8829a4aSRandall Stewart 		 * timer since that has stopped and we are in the GONE
2391f8829a4aSRandall Stewart 		 * state.
2392f8829a4aSRandall Stewart 		 */
2393f8829a4aSRandall Stewart 		tmr = &inp->sctp_ep.signature_change;
2394f8829a4aSRandall Stewart 		break;
2395f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_PATHMTURAISE:
2396f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
23976e55db54SRandall Stewart 			return;
2398f8829a4aSRandall Stewart 		}
2399f8829a4aSRandall Stewart 		tmr = &net->pmtu_timer;
2400f8829a4aSRandall Stewart 		break;
2401f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNACK:
2402f8829a4aSRandall Stewart 		if ((stcb == NULL) || (net == NULL)) {
24036e55db54SRandall Stewart 			return;
2404f8829a4aSRandall Stewart 		}
2405f8829a4aSRandall Stewart 		tmr = &net->rxt_timer;
2406f8829a4aSRandall Stewart 		break;
2407f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_SHUTDOWNGUARD:
2408f8829a4aSRandall Stewart 		if (stcb == NULL) {
24096e55db54SRandall Stewart 			return;
2410f8829a4aSRandall Stewart 		}
2411f8829a4aSRandall Stewart 		tmr = &stcb->asoc.shut_guard_timer;
2412f8829a4aSRandall Stewart 		break;
2413f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_STRRESET:
2414f8829a4aSRandall Stewart 		if (stcb == NULL) {
24156e55db54SRandall Stewart 			return;
2416f8829a4aSRandall Stewart 		}
2417f8829a4aSRandall Stewart 		tmr = &stcb->asoc.strreset_timer;
2418f8829a4aSRandall Stewart 		break;
2419f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_ASCONF:
2420f8829a4aSRandall Stewart 		if (stcb == NULL) {
24216e55db54SRandall Stewart 			return;
2422f8829a4aSRandall Stewart 		}
2423f8829a4aSRandall Stewart 		tmr = &stcb->asoc.asconf_timer;
2424f8829a4aSRandall Stewart 		break;
2425851b7298SRandall Stewart 	case SCTP_TIMER_TYPE_PRIM_DELETED:
2426851b7298SRandall Stewart 		if (stcb == NULL) {
2427851b7298SRandall Stewart 			return;
2428851b7298SRandall Stewart 		}
2429851b7298SRandall Stewart 		tmr = &stcb->asoc.delete_prim_timer;
2430851b7298SRandall Stewart 		break;
2431f8829a4aSRandall Stewart 	case SCTP_TIMER_TYPE_AUTOCLOSE:
2432f8829a4aSRandall Stewart 		if (stcb == NULL) {
24336e55db54SRandall Stewart 			return;
2434f8829a4aSRandall Stewart 		}
2435f8829a4aSRandall Stewart 		tmr = &stcb->asoc.autoclose_timer;
2436f8829a4aSRandall Stewart 		break;
2437f8829a4aSRandall Stewart 	default:
2438ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_TIMER1, "%s: Unknown timer type %d\n",
2439ad81507eSRandall Stewart 		    __FUNCTION__, t_type);
2440f8829a4aSRandall Stewart 		break;
2441f8829a4aSRandall Stewart 	};
2442f8829a4aSRandall Stewart 	if (tmr == NULL) {
24436e55db54SRandall Stewart 		return;
2444f8829a4aSRandall Stewart 	}
2445f8829a4aSRandall Stewart 	if ((tmr->type != t_type) && tmr->type) {
2446f8829a4aSRandall Stewart 		/*
2447f8829a4aSRandall Stewart 		 * Ok we have a timer that is under joint use. Cookie timer
2448f8829a4aSRandall Stewart 		 * per chance with the SEND timer. We therefore are NOT
2449f8829a4aSRandall Stewart 		 * running the timer that the caller wants stopped.  So just
2450f8829a4aSRandall Stewart 		 * return.
2451f8829a4aSRandall Stewart 		 */
24526e55db54SRandall Stewart 		return;
2453f8829a4aSRandall Stewart 	}
2454ad81507eSRandall Stewart 	if ((t_type == SCTP_TIMER_TYPE_SEND) && (stcb != NULL)) {
2455f8829a4aSRandall Stewart 		stcb->asoc.num_send_timers_up--;
2456f8829a4aSRandall Stewart 		if (stcb->asoc.num_send_timers_up < 0) {
2457f8829a4aSRandall Stewart 			stcb->asoc.num_send_timers_up = 0;
2458f8829a4aSRandall Stewart 		}
2459f8829a4aSRandall Stewart 	}
2460f8829a4aSRandall Stewart 	tmr->self = NULL;
2461a5d547adSRandall Stewart 	tmr->stopped_from = from;
24626e55db54SRandall Stewart 	(void)SCTP_OS_TIMER_STOP(&tmr->timer);
24636e55db54SRandall Stewart 	return;
2464f8829a4aSRandall Stewart }
2465f8829a4aSRandall Stewart 
2466f8829a4aSRandall Stewart uint32_t
2467f8829a4aSRandall Stewart sctp_calculate_len(struct mbuf *m)
2468f8829a4aSRandall Stewart {
2469f8829a4aSRandall Stewart 	uint32_t tlen = 0;
2470f8829a4aSRandall Stewart 	struct mbuf *at;
2471f8829a4aSRandall Stewart 
2472f8829a4aSRandall Stewart 	at = m;
2473f8829a4aSRandall Stewart 	while (at) {
2474139bc87fSRandall Stewart 		tlen += SCTP_BUF_LEN(at);
2475139bc87fSRandall Stewart 		at = SCTP_BUF_NEXT(at);
2476f8829a4aSRandall Stewart 	}
2477f8829a4aSRandall Stewart 	return (tlen);
2478f8829a4aSRandall Stewart }
2479f8829a4aSRandall Stewart 
2480f8829a4aSRandall Stewart void
2481f8829a4aSRandall Stewart sctp_mtu_size_reset(struct sctp_inpcb *inp,
248244b7479bSRandall Stewart     struct sctp_association *asoc, uint32_t mtu)
2483f8829a4aSRandall Stewart {
2484f8829a4aSRandall Stewart 	/*
2485f8829a4aSRandall Stewart 	 * Reset the P-MTU size on this association, this involves changing
2486f8829a4aSRandall Stewart 	 * the asoc MTU, going through ANY chunk+overhead larger than mtu to
2487f8829a4aSRandall Stewart 	 * allow the DF flag to be cleared.
2488f8829a4aSRandall Stewart 	 */
2489f8829a4aSRandall Stewart 	struct sctp_tmit_chunk *chk;
2490f8829a4aSRandall Stewart 	unsigned int eff_mtu, ovh;
2491f8829a4aSRandall Stewart 
249217205eccSRandall Stewart #ifdef SCTP_PRINT_FOR_B_AND_M
2493ad81507eSRandall Stewart 	SCTP_PRINTF("sctp_mtu_size_reset(%p, asoc:%p mtu:%d\n",
249417205eccSRandall Stewart 	    inp, asoc, mtu);
249517205eccSRandall Stewart #endif
2496f8829a4aSRandall Stewart 	asoc->smallest_mtu = mtu;
2497f8829a4aSRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) {
2498f8829a4aSRandall Stewart 		ovh = SCTP_MIN_OVERHEAD;
2499f8829a4aSRandall Stewart 	} else {
2500f8829a4aSRandall Stewart 		ovh = SCTP_MIN_V4_OVERHEAD;
2501f8829a4aSRandall Stewart 	}
2502f8829a4aSRandall Stewart 	eff_mtu = mtu - ovh;
2503f8829a4aSRandall Stewart 	TAILQ_FOREACH(chk, &asoc->send_queue, sctp_next) {
2504f8829a4aSRandall Stewart 
2505f8829a4aSRandall Stewart 		if (chk->send_size > eff_mtu) {
2506f8829a4aSRandall Stewart 			chk->flags |= CHUNK_FLAGS_FRAGMENT_OK;
2507f8829a4aSRandall Stewart 		}
2508f8829a4aSRandall Stewart 	}
2509f8829a4aSRandall Stewart 	TAILQ_FOREACH(chk, &asoc->sent_queue, sctp_next) {
2510f8829a4aSRandall Stewart 		if (chk->send_size > eff_mtu) {
2511f8829a4aSRandall Stewart 			chk->flags |= CHUNK_FLAGS_FRAGMENT_OK;
2512f8829a4aSRandall Stewart 		}
2513f8829a4aSRandall Stewart 	}
2514f8829a4aSRandall Stewart }
2515f8829a4aSRandall Stewart 
2516f8829a4aSRandall Stewart 
2517f8829a4aSRandall Stewart /*
2518f8829a4aSRandall Stewart  * given an association and starting time of the current RTT period return
2519f42a358aSRandall Stewart  * RTO in number of msecs net should point to the current network
2520f8829a4aSRandall Stewart  */
2521f8829a4aSRandall Stewart uint32_t
2522f8829a4aSRandall Stewart sctp_calculate_rto(struct sctp_tcb *stcb,
2523f8829a4aSRandall Stewart     struct sctp_association *asoc,
2524f8829a4aSRandall Stewart     struct sctp_nets *net,
252518e198d3SRandall Stewart     struct timeval *told,
252618e198d3SRandall Stewart     int safe)
2527f8829a4aSRandall Stewart {
252818e198d3SRandall Stewart 	/*-
2529f8829a4aSRandall Stewart 	 * given an association and the starting time of the current RTT
2530f42a358aSRandall Stewart 	 * period (in value1/value2) return RTO in number of msecs.
2531f8829a4aSRandall Stewart 	 */
2532f8829a4aSRandall Stewart 	int calc_time = 0;
2533f8829a4aSRandall Stewart 	int o_calctime;
25345e54f665SRandall Stewart 	uint32_t new_rto = 0;
2535f8829a4aSRandall Stewart 	int first_measure = 0;
253618e198d3SRandall Stewart 	struct timeval now, then, *old;
2537f8829a4aSRandall Stewart 
253818e198d3SRandall Stewart 	/* Copy it out for sparc64 */
253918e198d3SRandall Stewart 	if (safe == sctp_align_unsafe_makecopy) {
254018e198d3SRandall Stewart 		old = &then;
254118e198d3SRandall Stewart 		memcpy(&then, told, sizeof(struct timeval));
254218e198d3SRandall Stewart 	} else if (safe == sctp_align_safe_nocopy) {
254318e198d3SRandall Stewart 		old = told;
254418e198d3SRandall Stewart 	} else {
254518e198d3SRandall Stewart 		/* error */
254618e198d3SRandall Stewart 		SCTP_PRINTF("Huh, bad rto calc call\n");
254718e198d3SRandall Stewart 		return (0);
254818e198d3SRandall Stewart 	}
2549f8829a4aSRandall Stewart 	/************************/
2550f8829a4aSRandall Stewart 	/* 1. calculate new RTT */
2551f8829a4aSRandall Stewart 	/************************/
2552f8829a4aSRandall Stewart 	/* get the current time */
25536e55db54SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&now);
2554f8829a4aSRandall Stewart 	/* compute the RTT value */
2555f8829a4aSRandall Stewart 	if ((u_long)now.tv_sec > (u_long)old->tv_sec) {
2556f8829a4aSRandall Stewart 		calc_time = ((u_long)now.tv_sec - (u_long)old->tv_sec) * 1000;
2557f8829a4aSRandall Stewart 		if ((u_long)now.tv_usec > (u_long)old->tv_usec) {
2558f8829a4aSRandall Stewart 			calc_time += (((u_long)now.tv_usec -
2559f8829a4aSRandall Stewart 			    (u_long)old->tv_usec) / 1000);
2560f8829a4aSRandall Stewart 		} else if ((u_long)now.tv_usec < (u_long)old->tv_usec) {
2561f8829a4aSRandall Stewart 			/* Borrow 1,000ms from current calculation */
2562f8829a4aSRandall Stewart 			calc_time -= 1000;
2563f8829a4aSRandall Stewart 			/* Add in the slop over */
2564f8829a4aSRandall Stewart 			calc_time += ((int)now.tv_usec / 1000);
2565f8829a4aSRandall Stewart 			/* Add in the pre-second ms's */
2566f8829a4aSRandall Stewart 			calc_time += (((int)1000000 - (int)old->tv_usec) / 1000);
2567f8829a4aSRandall Stewart 		}
2568f8829a4aSRandall Stewart 	} else if ((u_long)now.tv_sec == (u_long)old->tv_sec) {
2569f8829a4aSRandall Stewart 		if ((u_long)now.tv_usec > (u_long)old->tv_usec) {
2570f8829a4aSRandall Stewart 			calc_time = ((u_long)now.tv_usec -
2571f8829a4aSRandall Stewart 			    (u_long)old->tv_usec) / 1000;
2572f8829a4aSRandall Stewart 		} else if ((u_long)now.tv_usec < (u_long)old->tv_usec) {
2573f8829a4aSRandall Stewart 			/* impossible .. garbage in nothing out */
25745e54f665SRandall Stewart 			goto calc_rto;
2575a5d547adSRandall Stewart 		} else if ((u_long)now.tv_usec == (u_long)old->tv_usec) {
2576a5d547adSRandall Stewart 			/*
2577a5d547adSRandall Stewart 			 * We have to have 1 usec :-D this must be the
2578a5d547adSRandall Stewart 			 * loopback.
2579a5d547adSRandall Stewart 			 */
2580a5d547adSRandall Stewart 			calc_time = 1;
2581f8829a4aSRandall Stewart 		} else {
2582f8829a4aSRandall Stewart 			/* impossible .. garbage in nothing out */
25835e54f665SRandall Stewart 			goto calc_rto;
2584f8829a4aSRandall Stewart 		}
2585f8829a4aSRandall Stewart 	} else {
2586f8829a4aSRandall Stewart 		/* Clock wrapped? */
25875e54f665SRandall Stewart 		goto calc_rto;
2588f8829a4aSRandall Stewart 	}
2589f8829a4aSRandall Stewart 	/***************************/
2590f8829a4aSRandall Stewart 	/* 2. update RTTVAR & SRTT */
2591f8829a4aSRandall Stewart 	/***************************/
2592f8829a4aSRandall Stewart 	o_calctime = calc_time;
2593f8829a4aSRandall Stewart 	/* this is Van Jacobson's integer version */
25949a972525SRandall Stewart 	if (net->RTO_measured) {
2595108df27cSRandall Stewart 		calc_time -= (net->lastsa >> SCTP_RTT_SHIFT);	/* take away 1/8th when
2596108df27cSRandall Stewart 								 * shift=3 */
2597b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RTTVAR_LOGGING_ENABLE) {
2598f8829a4aSRandall Stewart 			rto_logging(net, SCTP_LOG_RTTVAR);
259980fefe0aSRandall Stewart 		}
2600f8829a4aSRandall Stewart 		net->prev_rtt = o_calctime;
2601108df27cSRandall Stewart 		net->lastsa += calc_time;	/* add 7/8th into sa when
2602108df27cSRandall Stewart 						 * shift=3 */
2603f8829a4aSRandall Stewart 		if (calc_time < 0) {
2604f8829a4aSRandall Stewart 			calc_time = -calc_time;
2605f8829a4aSRandall Stewart 		}
2606108df27cSRandall Stewart 		calc_time -= (net->lastsv >> SCTP_RTT_VAR_SHIFT);	/* take away 1/4 when
2607108df27cSRandall Stewart 									 * VAR shift=2 */
2608f8829a4aSRandall Stewart 		net->lastsv += calc_time;
2609f8829a4aSRandall Stewart 		if (net->lastsv == 0) {
2610f8829a4aSRandall Stewart 			net->lastsv = SCTP_CLOCK_GRANULARITY;
2611f8829a4aSRandall Stewart 		}
2612f8829a4aSRandall Stewart 	} else {
2613f8829a4aSRandall Stewart 		/* First RTO measurment */
26149a972525SRandall Stewart 		net->RTO_measured = 1;
2615108df27cSRandall Stewart 		net->lastsa = calc_time << SCTP_RTT_SHIFT;	/* Multiply by 8 when
2616108df27cSRandall Stewart 								 * shift=3 */
2617108df27cSRandall Stewart 		net->lastsv = calc_time;
2618108df27cSRandall Stewart 		if (net->lastsv == 0) {
2619108df27cSRandall Stewart 			net->lastsv = SCTP_CLOCK_GRANULARITY;
2620108df27cSRandall Stewart 		}
2621f8829a4aSRandall Stewart 		first_measure = 1;
2622f8829a4aSRandall Stewart 		net->prev_rtt = o_calctime;
2623b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RTTVAR_LOGGING_ENABLE) {
2624f8829a4aSRandall Stewart 			rto_logging(net, SCTP_LOG_INITIAL_RTT);
262580fefe0aSRandall Stewart 		}
2626f8829a4aSRandall Stewart 	}
26275e54f665SRandall Stewart calc_rto:
2628108df27cSRandall Stewart 	new_rto = (net->lastsa >> SCTP_RTT_SHIFT) + net->lastsv;
2629f8829a4aSRandall Stewart 	if ((new_rto > SCTP_SAT_NETWORK_MIN) &&
2630f8829a4aSRandall Stewart 	    (stcb->asoc.sat_network_lockout == 0)) {
2631f8829a4aSRandall Stewart 		stcb->asoc.sat_network = 1;
2632f8829a4aSRandall Stewart 	} else if ((!first_measure) && stcb->asoc.sat_network) {
2633f8829a4aSRandall Stewart 		stcb->asoc.sat_network = 0;
2634f8829a4aSRandall Stewart 		stcb->asoc.sat_network_lockout = 1;
2635f8829a4aSRandall Stewart 	}
2636f8829a4aSRandall Stewart 	/* bound it, per C6/C7 in Section 5.3.1 */
2637f8829a4aSRandall Stewart 	if (new_rto < stcb->asoc.minrto) {
2638f8829a4aSRandall Stewart 		new_rto = stcb->asoc.minrto;
2639f8829a4aSRandall Stewart 	}
2640f8829a4aSRandall Stewart 	if (new_rto > stcb->asoc.maxrto) {
2641f8829a4aSRandall Stewart 		new_rto = stcb->asoc.maxrto;
2642f8829a4aSRandall Stewart 	}
26435e54f665SRandall Stewart 	/* we are now returning the RTO */
26445e54f665SRandall Stewart 	return (new_rto);
2645f8829a4aSRandall Stewart }
2646f8829a4aSRandall Stewart 
2647f8829a4aSRandall Stewart /*
2648f8829a4aSRandall Stewart  * return a pointer to a contiguous piece of data from the given mbuf chain
2649f8829a4aSRandall Stewart  * starting at 'off' for 'len' bytes.  If the desired piece spans more than
2650f8829a4aSRandall Stewart  * one mbuf, a copy is made at 'ptr'. caller must ensure that the buffer size
2651f8829a4aSRandall Stewart  * is >= 'len' returns NULL if there there isn't 'len' bytes in the chain.
2652f8829a4aSRandall Stewart  */
265372fb6fdbSRandall Stewart caddr_t
2654f8829a4aSRandall Stewart sctp_m_getptr(struct mbuf *m, int off, int len, uint8_t * in_ptr)
2655f8829a4aSRandall Stewart {
2656f8829a4aSRandall Stewart 	uint32_t count;
2657f8829a4aSRandall Stewart 	uint8_t *ptr;
2658f8829a4aSRandall Stewart 
2659f8829a4aSRandall Stewart 	ptr = in_ptr;
2660f8829a4aSRandall Stewart 	if ((off < 0) || (len <= 0))
2661f8829a4aSRandall Stewart 		return (NULL);
2662f8829a4aSRandall Stewart 
2663f8829a4aSRandall Stewart 	/* find the desired start location */
2664f8829a4aSRandall Stewart 	while ((m != NULL) && (off > 0)) {
2665139bc87fSRandall Stewart 		if (off < SCTP_BUF_LEN(m))
2666f8829a4aSRandall Stewart 			break;
2667139bc87fSRandall Stewart 		off -= SCTP_BUF_LEN(m);
2668139bc87fSRandall Stewart 		m = SCTP_BUF_NEXT(m);
2669f8829a4aSRandall Stewart 	}
2670f8829a4aSRandall Stewart 	if (m == NULL)
2671f8829a4aSRandall Stewart 		return (NULL);
2672f8829a4aSRandall Stewart 
2673f8829a4aSRandall Stewart 	/* is the current mbuf large enough (eg. contiguous)? */
2674139bc87fSRandall Stewart 	if ((SCTP_BUF_LEN(m) - off) >= len) {
2675f8829a4aSRandall Stewart 		return (mtod(m, caddr_t)+off);
2676f8829a4aSRandall Stewart 	} else {
2677f8829a4aSRandall Stewart 		/* else, it spans more than one mbuf, so save a temp copy... */
2678f8829a4aSRandall Stewart 		while ((m != NULL) && (len > 0)) {
2679139bc87fSRandall Stewart 			count = min(SCTP_BUF_LEN(m) - off, len);
2680f8829a4aSRandall Stewart 			bcopy(mtod(m, caddr_t)+off, ptr, count);
2681f8829a4aSRandall Stewart 			len -= count;
2682f8829a4aSRandall Stewart 			ptr += count;
2683f8829a4aSRandall Stewart 			off = 0;
2684139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
2685f8829a4aSRandall Stewart 		}
2686f8829a4aSRandall Stewart 		if ((m == NULL) && (len > 0))
2687f8829a4aSRandall Stewart 			return (NULL);
2688f8829a4aSRandall Stewart 		else
2689f8829a4aSRandall Stewart 			return ((caddr_t)in_ptr);
2690f8829a4aSRandall Stewart 	}
2691f8829a4aSRandall Stewart }
2692f8829a4aSRandall Stewart 
2693f8829a4aSRandall Stewart 
269444b7479bSRandall Stewart 
2695f8829a4aSRandall Stewart struct sctp_paramhdr *
2696f8829a4aSRandall Stewart sctp_get_next_param(struct mbuf *m,
2697f8829a4aSRandall Stewart     int offset,
2698f8829a4aSRandall Stewart     struct sctp_paramhdr *pull,
2699f8829a4aSRandall Stewart     int pull_limit)
2700f8829a4aSRandall Stewart {
2701f8829a4aSRandall Stewart 	/* This just provides a typed signature to Peter's Pull routine */
2702f8829a4aSRandall Stewart 	return ((struct sctp_paramhdr *)sctp_m_getptr(m, offset, pull_limit,
2703f8829a4aSRandall Stewart 	    (uint8_t *) pull));
2704f8829a4aSRandall Stewart }
2705f8829a4aSRandall Stewart 
2706f8829a4aSRandall Stewart 
2707f8829a4aSRandall Stewart int
2708f8829a4aSRandall Stewart sctp_add_pad_tombuf(struct mbuf *m, int padlen)
2709f8829a4aSRandall Stewart {
2710f8829a4aSRandall Stewart 	/*
2711f8829a4aSRandall Stewart 	 * add padlen bytes of 0 filled padding to the end of the mbuf. If
2712f8829a4aSRandall Stewart 	 * padlen is > 3 this routine will fail.
2713f8829a4aSRandall Stewart 	 */
2714f8829a4aSRandall Stewart 	uint8_t *dp;
2715f8829a4aSRandall Stewart 	int i;
2716f8829a4aSRandall Stewart 
2717f8829a4aSRandall Stewart 	if (padlen > 3) {
2718c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET_PKT(m, NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOBUFS);
2719f8829a4aSRandall Stewart 		return (ENOBUFS);
2720f8829a4aSRandall Stewart 	}
272141eee555SRandall Stewart 	if (padlen <= M_TRAILINGSPACE(m)) {
2722f8829a4aSRandall Stewart 		/*
2723f8829a4aSRandall Stewart 		 * The easy way. We hope the majority of the time we hit
2724f8829a4aSRandall Stewart 		 * here :)
2725f8829a4aSRandall Stewart 		 */
2726139bc87fSRandall Stewart 		dp = (uint8_t *) (mtod(m, caddr_t)+SCTP_BUF_LEN(m));
2727139bc87fSRandall Stewart 		SCTP_BUF_LEN(m) += padlen;
2728f8829a4aSRandall Stewart 	} else {
2729f8829a4aSRandall Stewart 		/* Hard way we must grow the mbuf */
2730f8829a4aSRandall Stewart 		struct mbuf *tmp;
2731f8829a4aSRandall Stewart 
2732f8829a4aSRandall Stewart 		tmp = sctp_get_mbuf_for_msg(padlen, 0, M_DONTWAIT, 1, MT_DATA);
2733f8829a4aSRandall Stewart 		if (tmp == NULL) {
2734f8829a4aSRandall Stewart 			/* Out of space GAK! we are in big trouble. */
2735c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET_PKT(m, NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
2736f8829a4aSRandall Stewart 			return (ENOSPC);
2737f8829a4aSRandall Stewart 		}
2738f8829a4aSRandall Stewart 		/* setup and insert in middle */
2739139bc87fSRandall Stewart 		SCTP_BUF_LEN(tmp) = padlen;
274041eee555SRandall Stewart 		SCTP_BUF_NEXT(tmp) = NULL;
2741139bc87fSRandall Stewart 		SCTP_BUF_NEXT(m) = tmp;
2742f8829a4aSRandall Stewart 		dp = mtod(tmp, uint8_t *);
2743f8829a4aSRandall Stewart 	}
2744f8829a4aSRandall Stewart 	/* zero out the pad */
2745f8829a4aSRandall Stewart 	for (i = 0; i < padlen; i++) {
2746f8829a4aSRandall Stewart 		*dp = 0;
2747f8829a4aSRandall Stewart 		dp++;
2748f8829a4aSRandall Stewart 	}
2749f8829a4aSRandall Stewart 	return (0);
2750f8829a4aSRandall Stewart }
2751f8829a4aSRandall Stewart 
2752f8829a4aSRandall Stewart int
2753f8829a4aSRandall Stewart sctp_pad_lastmbuf(struct mbuf *m, int padval, struct mbuf *last_mbuf)
2754f8829a4aSRandall Stewart {
2755f8829a4aSRandall Stewart 	/* find the last mbuf in chain and pad it */
2756f8829a4aSRandall Stewart 	struct mbuf *m_at;
2757f8829a4aSRandall Stewart 
2758f8829a4aSRandall Stewart 	m_at = m;
2759f8829a4aSRandall Stewart 	if (last_mbuf) {
2760f8829a4aSRandall Stewart 		return (sctp_add_pad_tombuf(last_mbuf, padval));
2761f8829a4aSRandall Stewart 	} else {
2762f8829a4aSRandall Stewart 		while (m_at) {
2763139bc87fSRandall Stewart 			if (SCTP_BUF_NEXT(m_at) == NULL) {
2764f8829a4aSRandall Stewart 				return (sctp_add_pad_tombuf(m_at, padval));
2765f8829a4aSRandall Stewart 			}
2766139bc87fSRandall Stewart 			m_at = SCTP_BUF_NEXT(m_at);
2767f8829a4aSRandall Stewart 		}
2768f8829a4aSRandall Stewart 	}
2769c4739e2fSRandall Stewart 	SCTP_LTRACE_ERR_RET_PKT(m, NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EFAULT);
2770f8829a4aSRandall Stewart 	return (EFAULT);
2771f8829a4aSRandall Stewart }
2772f8829a4aSRandall Stewart 
2773f8829a4aSRandall Stewart int sctp_asoc_change_wake = 0;
2774f8829a4aSRandall Stewart 
2775f8829a4aSRandall Stewart static void
2776f8829a4aSRandall Stewart sctp_notify_assoc_change(uint32_t event, struct sctp_tcb *stcb,
2777ceaad40aSRandall Stewart     uint32_t error, void *data, int so_locked
2778ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
2779ceaad40aSRandall Stewart     SCTP_UNUSED
2780ceaad40aSRandall Stewart #endif
2781ceaad40aSRandall Stewart )
2782f8829a4aSRandall Stewart {
2783f8829a4aSRandall Stewart 	struct mbuf *m_notify;
2784f8829a4aSRandall Stewart 	struct sctp_assoc_change *sac;
2785f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
2786f8829a4aSRandall Stewart 
2787ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2788ceaad40aSRandall Stewart 	struct socket *so;
2789ceaad40aSRandall Stewart 
2790ceaad40aSRandall Stewart #endif
2791ceaad40aSRandall Stewart 
2792f8829a4aSRandall Stewart 	/*
2793f8829a4aSRandall Stewart 	 * For TCP model AND UDP connected sockets we will send an error up
2794f8829a4aSRandall Stewart 	 * when an ABORT comes in.
2795f8829a4aSRandall Stewart 	 */
2796f8829a4aSRandall Stewart 	if (((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
2797f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) &&
27983c503c28SRandall Stewart 	    ((event == SCTP_COMM_LOST) || (event == SCTP_CANT_STR_ASSOC))) {
2799c4739e2fSRandall Stewart 		if (SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_COOKIE_WAIT) {
2800c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ECONNREFUSED);
280144b7479bSRandall Stewart 			stcb->sctp_socket->so_error = ECONNREFUSED;
2802c4739e2fSRandall Stewart 		} else {
2803c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ECONNRESET);
2804f8829a4aSRandall Stewart 			stcb->sctp_socket->so_error = ECONNRESET;
2805c4739e2fSRandall Stewart 		}
2806f8829a4aSRandall Stewart 		/* Wake ANY sleepers */
2807ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2808ceaad40aSRandall Stewart 		so = SCTP_INP_SO(stcb->sctp_ep);
2809ceaad40aSRandall Stewart 		if (!so_locked) {
2810ceaad40aSRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, 1);
2811ceaad40aSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
2812ceaad40aSRandall Stewart 			SCTP_SOCKET_LOCK(so, 1);
2813ceaad40aSRandall Stewart 			SCTP_TCB_LOCK(stcb);
2814ceaad40aSRandall Stewart 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
2815ceaad40aSRandall Stewart 			if (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET) {
2816ceaad40aSRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
2817ceaad40aSRandall Stewart 				return;
2818ceaad40aSRandall Stewart 			}
2819ceaad40aSRandall Stewart 		}
2820ceaad40aSRandall Stewart #endif
2821f8829a4aSRandall Stewart 		sorwakeup(stcb->sctp_socket);
2822f8829a4aSRandall Stewart 		sowwakeup(stcb->sctp_socket);
2823ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2824ceaad40aSRandall Stewart 		if (!so_locked) {
2825ceaad40aSRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
2826ceaad40aSRandall Stewart 		}
2827ceaad40aSRandall Stewart #endif
2828f8829a4aSRandall Stewart 		sctp_asoc_change_wake++;
2829f8829a4aSRandall Stewart 	}
2830f8829a4aSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_RECVASSOCEVNT)) {
2831f8829a4aSRandall Stewart 		/* event not enabled */
2832f8829a4aSRandall Stewart 		return;
2833f8829a4aSRandall Stewart 	}
2834139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_assoc_change), 0, M_DONTWAIT, 1, MT_DATA);
2835f8829a4aSRandall Stewart 	if (m_notify == NULL)
2836f8829a4aSRandall Stewart 		/* no space left */
2837f8829a4aSRandall Stewart 		return;
2838139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
2839f8829a4aSRandall Stewart 
2840f8829a4aSRandall Stewart 	sac = mtod(m_notify, struct sctp_assoc_change *);
2841f8829a4aSRandall Stewart 	sac->sac_type = SCTP_ASSOC_CHANGE;
2842f8829a4aSRandall Stewart 	sac->sac_flags = 0;
2843f8829a4aSRandall Stewart 	sac->sac_length = sizeof(struct sctp_assoc_change);
2844f8829a4aSRandall Stewart 	sac->sac_state = event;
2845f8829a4aSRandall Stewart 	sac->sac_error = error;
2846f8829a4aSRandall Stewart 	/* XXX verify these stream counts */
2847f8829a4aSRandall Stewart 	sac->sac_outbound_streams = stcb->asoc.streamoutcnt;
2848f8829a4aSRandall Stewart 	sac->sac_inbound_streams = stcb->asoc.streamincnt;
2849f8829a4aSRandall Stewart 	sac->sac_assoc_id = sctp_get_associd(stcb);
2850139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_assoc_change);
2851139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
2852f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
2853f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
2854f8829a4aSRandall Stewart 	    m_notify);
2855f8829a4aSRandall Stewart 	if (control == NULL) {
2856f8829a4aSRandall Stewart 		/* no memory */
2857f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
2858f8829a4aSRandall Stewart 		return;
2859f8829a4aSRandall Stewart 	}
2860139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
2861f8829a4aSRandall Stewart 	/* not that we need this */
2862f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
2863139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
2864f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
2865f8829a4aSRandall Stewart 	    control,
2866ceaad40aSRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, so_locked);
2867f8829a4aSRandall Stewart 	if (event == SCTP_COMM_LOST) {
2868f8829a4aSRandall Stewart 		/* Wake up any sleeper */
2869ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2870ceaad40aSRandall Stewart 		so = SCTP_INP_SO(stcb->sctp_ep);
2871ceaad40aSRandall Stewart 		if (!so_locked) {
2872ceaad40aSRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, 1);
2873ceaad40aSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
2874ceaad40aSRandall Stewart 			SCTP_SOCKET_LOCK(so, 1);
2875ceaad40aSRandall Stewart 			SCTP_TCB_LOCK(stcb);
2876ceaad40aSRandall Stewart 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
2877ceaad40aSRandall Stewart 			if (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET) {
2878ceaad40aSRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
2879ceaad40aSRandall Stewart 				return;
2880ceaad40aSRandall Stewart 			}
2881ceaad40aSRandall Stewart 		}
2882ceaad40aSRandall Stewart #endif
2883f8829a4aSRandall Stewart 		sctp_sowwakeup(stcb->sctp_ep, stcb->sctp_socket);
2884ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
2885ceaad40aSRandall Stewart 		if (!so_locked) {
2886ceaad40aSRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
2887ceaad40aSRandall Stewart 		}
2888ceaad40aSRandall Stewart #endif
2889f8829a4aSRandall Stewart 	}
2890f8829a4aSRandall Stewart }
2891f8829a4aSRandall Stewart 
2892f8829a4aSRandall Stewart static void
2893f8829a4aSRandall Stewart sctp_notify_peer_addr_change(struct sctp_tcb *stcb, uint32_t state,
2894f8829a4aSRandall Stewart     struct sockaddr *sa, uint32_t error)
2895f8829a4aSRandall Stewart {
2896f8829a4aSRandall Stewart 	struct mbuf *m_notify;
2897f8829a4aSRandall Stewart 	struct sctp_paddr_change *spc;
2898f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
2899f8829a4aSRandall Stewart 
2900830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_RECVPADDREVNT)) {
2901f8829a4aSRandall Stewart 		/* event not enabled */
2902f8829a4aSRandall Stewart 		return;
2903830d754dSRandall Stewart 	}
2904139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_paddr_change), 0, M_DONTWAIT, 1, MT_DATA);
2905f8829a4aSRandall Stewart 	if (m_notify == NULL)
2906f8829a4aSRandall Stewart 		return;
2907139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
2908f8829a4aSRandall Stewart 	spc = mtod(m_notify, struct sctp_paddr_change *);
2909f8829a4aSRandall Stewart 	spc->spc_type = SCTP_PEER_ADDR_CHANGE;
2910f8829a4aSRandall Stewart 	spc->spc_flags = 0;
2911f8829a4aSRandall Stewart 	spc->spc_length = sizeof(struct sctp_paddr_change);
29125e2c2d87SRandall Stewart 	switch (sa->sa_family) {
29135e2c2d87SRandall Stewart 	case AF_INET:
2914f8829a4aSRandall Stewart 		memcpy(&spc->spc_aaddr, sa, sizeof(struct sockaddr_in));
29155e2c2d87SRandall Stewart 		break;
29165e2c2d87SRandall Stewart #ifdef INET6
29175e2c2d87SRandall Stewart 	case AF_INET6:
29185e2c2d87SRandall Stewart 		{
2919f42a358aSRandall Stewart 			struct sockaddr_in6 *sin6;
2920f42a358aSRandall Stewart 
2921f8829a4aSRandall Stewart 			memcpy(&spc->spc_aaddr, sa, sizeof(struct sockaddr_in6));
2922f42a358aSRandall Stewart 
2923f42a358aSRandall Stewart 			sin6 = (struct sockaddr_in6 *)&spc->spc_aaddr;
2924f42a358aSRandall Stewart 			if (IN6_IS_SCOPE_LINKLOCAL(&sin6->sin6_addr)) {
292542551e99SRandall Stewart 				if (sin6->sin6_scope_id == 0) {
292642551e99SRandall Stewart 					/* recover scope_id for user */
2927f42a358aSRandall Stewart 					(void)sa6_recoverscope(sin6);
292842551e99SRandall Stewart 				} else {
292942551e99SRandall Stewart 					/* clear embedded scope_id for user */
293042551e99SRandall Stewart 					in6_clearscope(&sin6->sin6_addr);
293142551e99SRandall Stewart 				}
2932f42a358aSRandall Stewart 			}
29335e2c2d87SRandall Stewart 			break;
29345e2c2d87SRandall Stewart 		}
29355e2c2d87SRandall Stewart #endif
29365e2c2d87SRandall Stewart 	default:
29375e2c2d87SRandall Stewart 		/* TSNH */
29385e2c2d87SRandall Stewart 		break;
2939f8829a4aSRandall Stewart 	}
2940f8829a4aSRandall Stewart 	spc->spc_state = state;
2941f8829a4aSRandall Stewart 	spc->spc_error = error;
2942f8829a4aSRandall Stewart 	spc->spc_assoc_id = sctp_get_associd(stcb);
2943f8829a4aSRandall Stewart 
2944139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_paddr_change);
2945139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
2946f8829a4aSRandall Stewart 
2947f8829a4aSRandall Stewart 	/* append to socket */
2948f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
2949f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
2950f8829a4aSRandall Stewart 	    m_notify);
2951f8829a4aSRandall Stewart 	if (control == NULL) {
2952f8829a4aSRandall Stewart 		/* no memory */
2953f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
2954f8829a4aSRandall Stewart 		return;
2955f8829a4aSRandall Stewart 	}
2956139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
2957139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
2958f8829a4aSRandall Stewart 	/* not that we need this */
2959f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
2960f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
2961f8829a4aSRandall Stewart 	    control,
2962ceaad40aSRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_SO_NOT_LOCKED);
2963f8829a4aSRandall Stewart }
2964f8829a4aSRandall Stewart 
2965f8829a4aSRandall Stewart 
2966f8829a4aSRandall Stewart static void
2967f8829a4aSRandall Stewart sctp_notify_send_failed(struct sctp_tcb *stcb, uint32_t error,
2968ceaad40aSRandall Stewart     struct sctp_tmit_chunk *chk, int so_locked
2969ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
2970ceaad40aSRandall Stewart     SCTP_UNUSED
2971ceaad40aSRandall Stewart #endif
2972ceaad40aSRandall Stewart )
2973f8829a4aSRandall Stewart {
2974830d754dSRandall Stewart 	struct mbuf *m_notify;
2975f8829a4aSRandall Stewart 	struct sctp_send_failed *ssf;
2976f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
2977f8829a4aSRandall Stewart 	int length;
2978f8829a4aSRandall Stewart 
2979830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_RECVSENDFAILEVNT)) {
2980f8829a4aSRandall Stewart 		/* event not enabled */
2981f8829a4aSRandall Stewart 		return;
2982830d754dSRandall Stewart 	}
2983139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_send_failed), 0, M_DONTWAIT, 1, MT_DATA);
2984f8829a4aSRandall Stewart 	if (m_notify == NULL)
2985f8829a4aSRandall Stewart 		/* no space left */
2986f8829a4aSRandall Stewart 		return;
2987fc14de76SRandall Stewart 	length = sizeof(struct sctp_send_failed) + chk->send_size;
2988fc14de76SRandall Stewart 	length -= sizeof(struct sctp_data_chunk);
2989139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
2990f8829a4aSRandall Stewart 	ssf = mtod(m_notify, struct sctp_send_failed *);
2991f8829a4aSRandall Stewart 	ssf->ssf_type = SCTP_SEND_FAILED;
2992f8829a4aSRandall Stewart 	if (error == SCTP_NOTIFY_DATAGRAM_UNSENT)
2993f8829a4aSRandall Stewart 		ssf->ssf_flags = SCTP_DATA_UNSENT;
2994f8829a4aSRandall Stewart 	else
2995f8829a4aSRandall Stewart 		ssf->ssf_flags = SCTP_DATA_SENT;
2996f8829a4aSRandall Stewart 	ssf->ssf_length = length;
2997f8829a4aSRandall Stewart 	ssf->ssf_error = error;
2998f8829a4aSRandall Stewart 	/* not exactly what the user sent in, but should be close :) */
2999d00aff5dSRandall Stewart 	bzero(&ssf->ssf_info, sizeof(ssf->ssf_info));
3000f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_stream = chk->rec.data.stream_number;
3001f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_ssn = chk->rec.data.stream_seq;
3002f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_flags = chk->rec.data.rcv_flags;
3003f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_ppid = chk->rec.data.payloadtype;
3004f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_context = chk->rec.data.context;
3005f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_assoc_id = sctp_get_associd(stcb);
3006f8829a4aSRandall Stewart 	ssf->ssf_assoc_id = sctp_get_associd(stcb);
3007fc14de76SRandall Stewart 
3008139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = chk->data;
3009139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_send_failed);
3010830d754dSRandall Stewart 	if (chk->data) {
3011830d754dSRandall Stewart 		/*
3012830d754dSRandall Stewart 		 * trim off the sctp chunk header(it should be there)
3013830d754dSRandall Stewart 		 */
3014830d754dSRandall Stewart 		if (chk->send_size >= sizeof(struct sctp_data_chunk)) {
3015830d754dSRandall Stewart 			m_adj(chk->data, sizeof(struct sctp_data_chunk));
3016830d754dSRandall Stewart 			sctp_mbuf_crush(chk->data);
3017830d754dSRandall Stewart 			chk->send_size -= sizeof(struct sctp_data_chunk);
3018830d754dSRandall Stewart 		}
3019830d754dSRandall Stewart 	}
3020f8829a4aSRandall Stewart 	/* Steal off the mbuf */
3021f8829a4aSRandall Stewart 	chk->data = NULL;
3022f8829a4aSRandall Stewart 	/*
3023f8829a4aSRandall Stewart 	 * For this case, we check the actual socket buffer, since the assoc
3024f8829a4aSRandall Stewart 	 * is going away we don't want to overfill the socket buffer for a
3025f8829a4aSRandall Stewart 	 * non-reader
3026f8829a4aSRandall Stewart 	 */
3027139bc87fSRandall Stewart 	if (sctp_sbspace_failedmsgs(&stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3028f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3029f8829a4aSRandall Stewart 		return;
3030f8829a4aSRandall Stewart 	}
3031f8829a4aSRandall Stewart 	/* append to socket */
3032f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3033f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3034f8829a4aSRandall Stewart 	    m_notify);
3035f8829a4aSRandall Stewart 	if (control == NULL) {
3036f8829a4aSRandall Stewart 		/* no memory */
3037f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3038f8829a4aSRandall Stewart 		return;
3039f8829a4aSRandall Stewart 	}
3040139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3041f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3042f8829a4aSRandall Stewart 	    control,
3043ceaad40aSRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, so_locked);
3044f8829a4aSRandall Stewart }
3045f8829a4aSRandall Stewart 
3046f8829a4aSRandall Stewart 
3047f8829a4aSRandall Stewart static void
3048f8829a4aSRandall Stewart sctp_notify_send_failed2(struct sctp_tcb *stcb, uint32_t error,
3049ceaad40aSRandall Stewart     struct sctp_stream_queue_pending *sp, int so_locked
3050ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3051ceaad40aSRandall Stewart     SCTP_UNUSED
3052ceaad40aSRandall Stewart #endif
3053ceaad40aSRandall Stewart )
3054f8829a4aSRandall Stewart {
3055f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3056f8829a4aSRandall Stewart 	struct sctp_send_failed *ssf;
3057f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3058f8829a4aSRandall Stewart 	int length;
3059f8829a4aSRandall Stewart 
3060830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_RECVSENDFAILEVNT)) {
3061f8829a4aSRandall Stewart 		/* event not enabled */
3062f8829a4aSRandall Stewart 		return;
3063830d754dSRandall Stewart 	}
3064f8829a4aSRandall Stewart 	length = sizeof(struct sctp_send_failed) + sp->length;
3065d00aff5dSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_send_failed), 0, M_DONTWAIT, 1, MT_DATA);
3066f8829a4aSRandall Stewart 	if (m_notify == NULL)
3067f8829a4aSRandall Stewart 		/* no space left */
3068f8829a4aSRandall Stewart 		return;
3069139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3070f8829a4aSRandall Stewart 	ssf = mtod(m_notify, struct sctp_send_failed *);
3071f8829a4aSRandall Stewart 	ssf->ssf_type = SCTP_SEND_FAILED;
3072f8829a4aSRandall Stewart 	if (error == SCTP_NOTIFY_DATAGRAM_UNSENT)
3073f8829a4aSRandall Stewart 		ssf->ssf_flags = SCTP_DATA_UNSENT;
3074f8829a4aSRandall Stewart 	else
3075f8829a4aSRandall Stewart 		ssf->ssf_flags = SCTP_DATA_SENT;
3076f8829a4aSRandall Stewart 	ssf->ssf_length = length;
3077f8829a4aSRandall Stewart 	ssf->ssf_error = error;
3078f8829a4aSRandall Stewart 	/* not exactly what the user sent in, but should be close :) */
3079d00aff5dSRandall Stewart 	bzero(&ssf->ssf_info, sizeof(ssf->ssf_info));
3080f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_stream = sp->stream;
3081f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_ssn = sp->strseq;
3082fc14de76SRandall Stewart 	if (sp->some_taken) {
3083fc14de76SRandall Stewart 		ssf->ssf_info.sinfo_flags = SCTP_DATA_LAST_FRAG;
3084fc14de76SRandall Stewart 	} else {
3085fc14de76SRandall Stewart 		ssf->ssf_info.sinfo_flags = SCTP_DATA_NOT_FRAG;
3086fc14de76SRandall Stewart 	}
3087f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_ppid = sp->ppid;
3088f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_context = sp->context;
3089f8829a4aSRandall Stewart 	ssf->ssf_info.sinfo_assoc_id = sctp_get_associd(stcb);
3090f8829a4aSRandall Stewart 	ssf->ssf_assoc_id = sctp_get_associd(stcb);
3091139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = sp->data;
3092139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_send_failed);
3093f8829a4aSRandall Stewart 
3094f8829a4aSRandall Stewart 	/* Steal off the mbuf */
3095f8829a4aSRandall Stewart 	sp->data = NULL;
3096f8829a4aSRandall Stewart 	/*
3097f8829a4aSRandall Stewart 	 * For this case, we check the actual socket buffer, since the assoc
3098f8829a4aSRandall Stewart 	 * is going away we don't want to overfill the socket buffer for a
3099f8829a4aSRandall Stewart 	 * non-reader
3100f8829a4aSRandall Stewart 	 */
3101139bc87fSRandall Stewart 	if (sctp_sbspace_failedmsgs(&stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3102f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3103f8829a4aSRandall Stewart 		return;
3104f8829a4aSRandall Stewart 	}
3105f8829a4aSRandall Stewart 	/* append to socket */
3106f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3107f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3108f8829a4aSRandall Stewart 	    m_notify);
3109f8829a4aSRandall Stewart 	if (control == NULL) {
3110f8829a4aSRandall Stewart 		/* no memory */
3111f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3112f8829a4aSRandall Stewart 		return;
3113f8829a4aSRandall Stewart 	}
3114139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3115f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3116f8829a4aSRandall Stewart 	    control,
3117ceaad40aSRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, so_locked);
3118f8829a4aSRandall Stewart }
3119f8829a4aSRandall Stewart 
3120f8829a4aSRandall Stewart 
3121f8829a4aSRandall Stewart 
3122f8829a4aSRandall Stewart static void
3123f8829a4aSRandall Stewart sctp_notify_adaptation_layer(struct sctp_tcb *stcb,
3124f8829a4aSRandall Stewart     uint32_t error)
3125f8829a4aSRandall Stewart {
3126f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3127f8829a4aSRandall Stewart 	struct sctp_adaptation_event *sai;
3128f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3129f8829a4aSRandall Stewart 
3130830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_ADAPTATIONEVNT)) {
3131f8829a4aSRandall Stewart 		/* event not enabled */
3132f8829a4aSRandall Stewart 		return;
3133830d754dSRandall Stewart 	}
3134139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_adaption_event), 0, M_DONTWAIT, 1, MT_DATA);
3135f8829a4aSRandall Stewart 	if (m_notify == NULL)
3136f8829a4aSRandall Stewart 		/* no space left */
3137f8829a4aSRandall Stewart 		return;
3138139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3139f8829a4aSRandall Stewart 	sai = mtod(m_notify, struct sctp_adaptation_event *);
3140f8829a4aSRandall Stewart 	sai->sai_type = SCTP_ADAPTATION_INDICATION;
3141f8829a4aSRandall Stewart 	sai->sai_flags = 0;
3142f8829a4aSRandall Stewart 	sai->sai_length = sizeof(struct sctp_adaptation_event);
31432afb3e84SRandall Stewart 	sai->sai_adaptation_ind = stcb->asoc.peers_adaptation;
3144f8829a4aSRandall Stewart 	sai->sai_assoc_id = sctp_get_associd(stcb);
3145f8829a4aSRandall Stewart 
3146139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_adaptation_event);
3147139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3148f8829a4aSRandall Stewart 
3149f8829a4aSRandall Stewart 	/* append to socket */
3150f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3151f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3152f8829a4aSRandall Stewart 	    m_notify);
3153f8829a4aSRandall Stewart 	if (control == NULL) {
3154f8829a4aSRandall Stewart 		/* no memory */
3155f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3156f8829a4aSRandall Stewart 		return;
3157f8829a4aSRandall Stewart 	}
3158139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3159139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3160f8829a4aSRandall Stewart 	/* not that we need this */
3161f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
3162f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3163f8829a4aSRandall Stewart 	    control,
3164ceaad40aSRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_SO_NOT_LOCKED);
3165f8829a4aSRandall Stewart }
3166f8829a4aSRandall Stewart 
316703b0b021SRandall Stewart /* This always must be called with the read-queue LOCKED in the INP */
3168f8829a4aSRandall Stewart void
31692dad8a55SRandall Stewart sctp_notify_partial_delivery_indication(struct sctp_tcb *stcb, uint32_t error,
31702dad8a55SRandall Stewart     int nolock, uint32_t val)
3171f8829a4aSRandall Stewart {
3172f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3173f8829a4aSRandall Stewart 	struct sctp_pdapi_event *pdapi;
3174f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
317503b0b021SRandall Stewart 	struct sockbuf *sb;
3176f8829a4aSRandall Stewart 
3177830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_PDAPIEVNT)) {
3178f8829a4aSRandall Stewart 		/* event not enabled */
3179f8829a4aSRandall Stewart 		return;
3180830d754dSRandall Stewart 	}
3181139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_pdapi_event), 0, M_DONTWAIT, 1, MT_DATA);
3182f8829a4aSRandall Stewart 	if (m_notify == NULL)
3183f8829a4aSRandall Stewart 		/* no space left */
3184f8829a4aSRandall Stewart 		return;
3185139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3186f8829a4aSRandall Stewart 	pdapi = mtod(m_notify, struct sctp_pdapi_event *);
3187f8829a4aSRandall Stewart 	pdapi->pdapi_type = SCTP_PARTIAL_DELIVERY_EVENT;
3188f8829a4aSRandall Stewart 	pdapi->pdapi_flags = 0;
3189f8829a4aSRandall Stewart 	pdapi->pdapi_length = sizeof(struct sctp_pdapi_event);
3190f8829a4aSRandall Stewart 	pdapi->pdapi_indication = error;
31919a6142d8SRandall Stewart 	pdapi->pdapi_stream = (val >> 16);
31929a6142d8SRandall Stewart 	pdapi->pdapi_seq = (val & 0x0000ffff);
3193f8829a4aSRandall Stewart 	pdapi->pdapi_assoc_id = sctp_get_associd(stcb);
3194f8829a4aSRandall Stewart 
3195139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_pdapi_event);
3196139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3197f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3198f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3199f8829a4aSRandall Stewart 	    m_notify);
3200f8829a4aSRandall Stewart 	if (control == NULL) {
3201f8829a4aSRandall Stewart 		/* no memory */
3202f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3203f8829a4aSRandall Stewart 		return;
3204f8829a4aSRandall Stewart 	}
3205139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3206139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3207f8829a4aSRandall Stewart 	/* not that we need this */
3208f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
320903b0b021SRandall Stewart 	control->held_length = 0;
321003b0b021SRandall Stewart 	control->length = 0;
321103b0b021SRandall Stewart 	if (nolock == 0) {
321203b0b021SRandall Stewart 		SCTP_INP_READ_LOCK(stcb->sctp_ep);
321303b0b021SRandall Stewart 	}
321403b0b021SRandall Stewart 	sb = &stcb->sctp_socket->so_rcv;
3215b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
3216139bc87fSRandall Stewart 		sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m_notify));
321780fefe0aSRandall Stewart 	}
321803b0b021SRandall Stewart 	sctp_sballoc(stcb, sb, m_notify);
3219b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
322003b0b021SRandall Stewart 		sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
322180fefe0aSRandall Stewart 	}
3222139bc87fSRandall Stewart 	atomic_add_int(&control->length, SCTP_BUF_LEN(m_notify));
322303b0b021SRandall Stewart 	control->end_added = 1;
322403b0b021SRandall Stewart 	if (stcb->asoc.control_pdapi)
322503b0b021SRandall Stewart 		TAILQ_INSERT_AFTER(&stcb->sctp_ep->read_queue, stcb->asoc.control_pdapi, control, next);
322603b0b021SRandall Stewart 	else {
322703b0b021SRandall Stewart 		/* we really should not see this case */
322803b0b021SRandall Stewart 		TAILQ_INSERT_TAIL(&stcb->sctp_ep->read_queue, control, next);
322903b0b021SRandall Stewart 	}
323003b0b021SRandall Stewart 	if (nolock == 0) {
323103b0b021SRandall Stewart 		SCTP_INP_READ_UNLOCK(stcb->sctp_ep);
323203b0b021SRandall Stewart 	}
323303b0b021SRandall Stewart 	if (stcb->sctp_ep && stcb->sctp_socket) {
323403b0b021SRandall Stewart 		/* This should always be the case */
323503b0b021SRandall Stewart 		sctp_sorwakeup(stcb->sctp_ep, stcb->sctp_socket);
3236f8829a4aSRandall Stewart 	}
3237f8829a4aSRandall Stewart }
3238f8829a4aSRandall Stewart 
3239f8829a4aSRandall Stewart static void
3240f8829a4aSRandall Stewart sctp_notify_shutdown_event(struct sctp_tcb *stcb)
3241f8829a4aSRandall Stewart {
3242f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3243f8829a4aSRandall Stewart 	struct sctp_shutdown_event *sse;
3244f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3245f8829a4aSRandall Stewart 
3246f8829a4aSRandall Stewart 	/*
3247f8829a4aSRandall Stewart 	 * For TCP model AND UDP connected sockets we will send an error up
3248f8829a4aSRandall Stewart 	 * when an SHUTDOWN completes
3249f8829a4aSRandall Stewart 	 */
3250f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
3251f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
3252f8829a4aSRandall Stewart 		/* mark socket closed for read/write and wakeup! */
3253ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3254ceaad40aSRandall Stewart 		struct socket *so;
3255ceaad40aSRandall Stewart 
3256ceaad40aSRandall Stewart 		so = SCTP_INP_SO(stcb->sctp_ep);
3257ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
3258ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
3259ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
3260ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
3261ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
3262ceaad40aSRandall Stewart 		if (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET) {
3263ceaad40aSRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
3264ceaad40aSRandall Stewart 			return;
3265ceaad40aSRandall Stewart 		}
3266ceaad40aSRandall Stewart #endif
3267f8829a4aSRandall Stewart 		socantsendmore(stcb->sctp_socket);
3268ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3269ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
3270ceaad40aSRandall Stewart #endif
3271f8829a4aSRandall Stewart 	}
3272830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_RECVSHUTDOWNEVNT)) {
3273f8829a4aSRandall Stewart 		/* event not enabled */
3274f8829a4aSRandall Stewart 		return;
3275830d754dSRandall Stewart 	}
3276139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_shutdown_event), 0, M_DONTWAIT, 1, MT_DATA);
3277f8829a4aSRandall Stewart 	if (m_notify == NULL)
3278f8829a4aSRandall Stewart 		/* no space left */
3279f8829a4aSRandall Stewart 		return;
3280f8829a4aSRandall Stewart 	sse = mtod(m_notify, struct sctp_shutdown_event *);
3281f8829a4aSRandall Stewart 	sse->sse_type = SCTP_SHUTDOWN_EVENT;
3282f8829a4aSRandall Stewart 	sse->sse_flags = 0;
3283f8829a4aSRandall Stewart 	sse->sse_length = sizeof(struct sctp_shutdown_event);
3284f8829a4aSRandall Stewart 	sse->sse_assoc_id = sctp_get_associd(stcb);
3285f8829a4aSRandall Stewart 
3286139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_shutdown_event);
3287139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3288f8829a4aSRandall Stewart 
3289f8829a4aSRandall Stewart 	/* append to socket */
3290f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3291f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3292f8829a4aSRandall Stewart 	    m_notify);
3293f8829a4aSRandall Stewart 	if (control == NULL) {
3294f8829a4aSRandall Stewart 		/* no memory */
3295f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3296f8829a4aSRandall Stewart 		return;
3297f8829a4aSRandall Stewart 	}
3298139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3299139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3300f8829a4aSRandall Stewart 	/* not that we need this */
3301f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
3302f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3303f8829a4aSRandall Stewart 	    control,
3304ceaad40aSRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_SO_NOT_LOCKED);
3305f8829a4aSRandall Stewart }
3306f8829a4aSRandall Stewart 
3307f8829a4aSRandall Stewart static void
3308830d754dSRandall Stewart sctp_notify_sender_dry_event(struct sctp_tcb *stcb,
3309830d754dSRandall Stewart     int so_locked
3310830d754dSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3311830d754dSRandall Stewart     SCTP_UNUSED
3312830d754dSRandall Stewart #endif
3313830d754dSRandall Stewart )
3314830d754dSRandall Stewart {
3315830d754dSRandall Stewart 	struct mbuf *m_notify;
3316830d754dSRandall Stewart 	struct sctp_sender_dry_event *event;
3317830d754dSRandall Stewart 	struct sctp_queued_to_read *control;
3318830d754dSRandall Stewart 
3319830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_DRYEVNT)) {
3320830d754dSRandall Stewart 		/* event not enabled */
3321830d754dSRandall Stewart 		return;
3322830d754dSRandall Stewart 	}
3323830d754dSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(sizeof(struct sctp_sender_dry_event), 0, M_DONTWAIT, 1, MT_DATA);
3324830d754dSRandall Stewart 	if (m_notify == NULL) {
3325830d754dSRandall Stewart 		/* no space left */
3326830d754dSRandall Stewart 		return;
3327830d754dSRandall Stewart 	}
3328830d754dSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3329830d754dSRandall Stewart 	event = mtod(m_notify, struct sctp_sender_dry_event *);
3330830d754dSRandall Stewart 	event->sender_dry_type = SCTP_SENDER_DRY_EVENT;
3331830d754dSRandall Stewart 	event->sender_dry_flags = 0;
3332830d754dSRandall Stewart 	event->sender_dry_length = sizeof(struct sctp_sender_dry_event);
3333830d754dSRandall Stewart 	event->sender_dry_assoc_id = sctp_get_associd(stcb);
3334830d754dSRandall Stewart 
3335830d754dSRandall Stewart 	SCTP_BUF_LEN(m_notify) = sizeof(struct sctp_sender_dry_event);
3336830d754dSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3337830d754dSRandall Stewart 
3338830d754dSRandall Stewart 	/* append to socket */
3339830d754dSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3340830d754dSRandall Stewart 	    0, 0, 0, 0, 0, 0, m_notify);
3341830d754dSRandall Stewart 	if (control == NULL) {
3342830d754dSRandall Stewart 		/* no memory */
3343830d754dSRandall Stewart 		sctp_m_freem(m_notify);
3344830d754dSRandall Stewart 		return;
3345830d754dSRandall Stewart 	}
3346830d754dSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3347830d754dSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3348830d754dSRandall Stewart 	/* not that we need this */
3349830d754dSRandall Stewart 	control->tail_mbuf = m_notify;
3350830d754dSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb, control,
3351830d754dSRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, so_locked);
3352830d754dSRandall Stewart }
3353830d754dSRandall Stewart 
3354ea44232bSRandall Stewart 
3355ea44232bSRandall Stewart static void
3356ea44232bSRandall Stewart sctp_notify_stream_reset_add(struct sctp_tcb *stcb, int number_entries, int flag)
3357ea44232bSRandall Stewart {
3358ea44232bSRandall Stewart 	struct mbuf *m_notify;
3359ea44232bSRandall Stewart 	struct sctp_queued_to_read *control;
3360ea44232bSRandall Stewart 	struct sctp_stream_reset_event *strreset;
3361ea44232bSRandall Stewart 	int len;
3362ea44232bSRandall Stewart 
3363ea44232bSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_STREAM_RESETEVNT)) {
3364ea44232bSRandall Stewart 		/* event not enabled */
3365ea44232bSRandall Stewart 		return;
3366ea44232bSRandall Stewart 	}
3367ea44232bSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(MCLBYTES, 0, M_DONTWAIT, 1, MT_DATA);
3368ea44232bSRandall Stewart 	if (m_notify == NULL)
3369ea44232bSRandall Stewart 		/* no space left */
3370ea44232bSRandall Stewart 		return;
3371ea44232bSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3372ea44232bSRandall Stewart 	len = sizeof(struct sctp_stream_reset_event) + (number_entries * sizeof(uint16_t));
3373ea44232bSRandall Stewart 	if (len > M_TRAILINGSPACE(m_notify)) {
3374ea44232bSRandall Stewart 		/* never enough room */
3375ea44232bSRandall Stewart 		sctp_m_freem(m_notify);
3376ea44232bSRandall Stewart 		return;
3377ea44232bSRandall Stewart 	}
3378ea44232bSRandall Stewart 	strreset = mtod(m_notify, struct sctp_stream_reset_event *);
3379ea44232bSRandall Stewart 	strreset->strreset_type = SCTP_STREAM_RESET_EVENT;
3380ea44232bSRandall Stewart 	strreset->strreset_flags = SCTP_STRRESET_ADD_STREAM | flag;
3381ea44232bSRandall Stewart 	strreset->strreset_length = len;
3382ea44232bSRandall Stewart 	strreset->strreset_assoc_id = sctp_get_associd(stcb);
3383ea44232bSRandall Stewart 	strreset->strreset_list[0] = number_entries;
3384ea44232bSRandall Stewart 
3385ea44232bSRandall Stewart 	SCTP_BUF_LEN(m_notify) = len;
3386ea44232bSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3387ea44232bSRandall Stewart 	if (sctp_sbspace(&stcb->asoc, &stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3388ea44232bSRandall Stewart 		/* no space */
3389ea44232bSRandall Stewart 		sctp_m_freem(m_notify);
3390ea44232bSRandall Stewart 		return;
3391ea44232bSRandall Stewart 	}
3392ea44232bSRandall Stewart 	/* append to socket */
3393ea44232bSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3394ea44232bSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3395ea44232bSRandall Stewart 	    m_notify);
3396ea44232bSRandall Stewart 	if (control == NULL) {
3397ea44232bSRandall Stewart 		/* no memory */
3398ea44232bSRandall Stewart 		sctp_m_freem(m_notify);
3399ea44232bSRandall Stewart 		return;
3400ea44232bSRandall Stewart 	}
3401ea44232bSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3402ea44232bSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3403ea44232bSRandall Stewart 	/* not that we need this */
3404ea44232bSRandall Stewart 	control->tail_mbuf = m_notify;
3405ea44232bSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3406ea44232bSRandall Stewart 	    control,
3407ea44232bSRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_SO_NOT_LOCKED);
3408ea44232bSRandall Stewart }
3409ea44232bSRandall Stewart 
3410ea44232bSRandall Stewart 
3411830d754dSRandall Stewart static void
3412f8829a4aSRandall Stewart sctp_notify_stream_reset(struct sctp_tcb *stcb,
3413f8829a4aSRandall Stewart     int number_entries, uint16_t * list, int flag)
3414f8829a4aSRandall Stewart {
3415f8829a4aSRandall Stewart 	struct mbuf *m_notify;
3416f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control;
3417f8829a4aSRandall Stewart 	struct sctp_stream_reset_event *strreset;
3418f8829a4aSRandall Stewart 	int len;
3419f8829a4aSRandall Stewart 
3420830d754dSRandall Stewart 	if (sctp_is_feature_off(stcb->sctp_ep, SCTP_PCB_FLAGS_STREAM_RESETEVNT)) {
3421f8829a4aSRandall Stewart 		/* event not enabled */
3422f8829a4aSRandall Stewart 		return;
3423830d754dSRandall Stewart 	}
3424139bc87fSRandall Stewart 	m_notify = sctp_get_mbuf_for_msg(MCLBYTES, 0, M_DONTWAIT, 1, MT_DATA);
3425f8829a4aSRandall Stewart 	if (m_notify == NULL)
3426f8829a4aSRandall Stewart 		/* no space left */
3427f8829a4aSRandall Stewart 		return;
3428139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = 0;
3429f8829a4aSRandall Stewart 	len = sizeof(struct sctp_stream_reset_event) + (number_entries * sizeof(uint16_t));
3430f8829a4aSRandall Stewart 	if (len > M_TRAILINGSPACE(m_notify)) {
3431f8829a4aSRandall Stewart 		/* never enough room */
3432f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3433f8829a4aSRandall Stewart 		return;
3434f8829a4aSRandall Stewart 	}
3435f8829a4aSRandall Stewart 	strreset = mtod(m_notify, struct sctp_stream_reset_event *);
3436f8829a4aSRandall Stewart 	strreset->strreset_type = SCTP_STREAM_RESET_EVENT;
3437f8829a4aSRandall Stewart 	if (number_entries == 0) {
3438f8829a4aSRandall Stewart 		strreset->strreset_flags = flag | SCTP_STRRESET_ALL_STREAMS;
3439f8829a4aSRandall Stewart 	} else {
3440f8829a4aSRandall Stewart 		strreset->strreset_flags = flag | SCTP_STRRESET_STREAM_LIST;
3441f8829a4aSRandall Stewart 	}
3442f8829a4aSRandall Stewart 	strreset->strreset_length = len;
3443f8829a4aSRandall Stewart 	strreset->strreset_assoc_id = sctp_get_associd(stcb);
3444f8829a4aSRandall Stewart 	if (number_entries) {
3445f8829a4aSRandall Stewart 		int i;
3446f8829a4aSRandall Stewart 
3447f8829a4aSRandall Stewart 		for (i = 0; i < number_entries; i++) {
3448f8829a4aSRandall Stewart 			strreset->strreset_list[i] = ntohs(list[i]);
3449f8829a4aSRandall Stewart 		}
3450f8829a4aSRandall Stewart 	}
3451139bc87fSRandall Stewart 	SCTP_BUF_LEN(m_notify) = len;
3452139bc87fSRandall Stewart 	SCTP_BUF_NEXT(m_notify) = NULL;
3453139bc87fSRandall Stewart 	if (sctp_sbspace(&stcb->asoc, &stcb->sctp_socket->so_rcv) < SCTP_BUF_LEN(m_notify)) {
3454f8829a4aSRandall Stewart 		/* no space */
3455f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3456f8829a4aSRandall Stewart 		return;
3457f8829a4aSRandall Stewart 	}
3458f8829a4aSRandall Stewart 	/* append to socket */
3459f8829a4aSRandall Stewart 	control = sctp_build_readq_entry(stcb, stcb->asoc.primary_destination,
3460f8829a4aSRandall Stewart 	    0, 0, 0, 0, 0, 0,
3461f8829a4aSRandall Stewart 	    m_notify);
3462f8829a4aSRandall Stewart 	if (control == NULL) {
3463f8829a4aSRandall Stewart 		/* no memory */
3464f8829a4aSRandall Stewart 		sctp_m_freem(m_notify);
3465f8829a4aSRandall Stewart 		return;
3466f8829a4aSRandall Stewart 	}
3467139bc87fSRandall Stewart 	control->spec_flags = M_NOTIFICATION;
3468139bc87fSRandall Stewart 	control->length = SCTP_BUF_LEN(m_notify);
3469f8829a4aSRandall Stewart 	/* not that we need this */
3470f8829a4aSRandall Stewart 	control->tail_mbuf = m_notify;
3471f8829a4aSRandall Stewart 	sctp_add_to_readq(stcb->sctp_ep, stcb,
3472f8829a4aSRandall Stewart 	    control,
3473ceaad40aSRandall Stewart 	    &stcb->sctp_socket->so_rcv, 1, SCTP_SO_NOT_LOCKED);
3474f8829a4aSRandall Stewart }
3475f8829a4aSRandall Stewart 
3476f8829a4aSRandall Stewart 
3477f8829a4aSRandall Stewart void
3478f8829a4aSRandall Stewart sctp_ulp_notify(uint32_t notification, struct sctp_tcb *stcb,
3479ceaad40aSRandall Stewart     uint32_t error, void *data, int so_locked
3480ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3481ceaad40aSRandall Stewart     SCTP_UNUSED
3482ceaad40aSRandall Stewart #endif
3483ceaad40aSRandall Stewart )
3484f8829a4aSRandall Stewart {
3485830d754dSRandall Stewart 	if ((stcb == NULL) ||
3486830d754dSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
3487f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
3488830d754dSRandall Stewart 	    (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET)) {
3489830d754dSRandall Stewart 		/* If the socket is gone we are out of here */
3490f8829a4aSRandall Stewart 		return;
3491f8829a4aSRandall Stewart 	}
3492a99b6783SRandall Stewart 	if (stcb->sctp_socket->so_rcv.sb_state & SBS_CANTRCVMORE) {
3493a99b6783SRandall Stewart 		return;
3494a99b6783SRandall Stewart 	}
349517205eccSRandall Stewart 	if (stcb && ((stcb->asoc.state & SCTP_STATE_COOKIE_WAIT) ||
349617205eccSRandall Stewart 	    (stcb->asoc.state & SCTP_STATE_COOKIE_ECHOED))) {
349717205eccSRandall Stewart 		if ((notification == SCTP_NOTIFY_INTERFACE_DOWN) ||
349817205eccSRandall Stewart 		    (notification == SCTP_NOTIFY_INTERFACE_UP) ||
349917205eccSRandall Stewart 		    (notification == SCTP_NOTIFY_INTERFACE_CONFIRMED)) {
350017205eccSRandall Stewart 			/* Don't report these in front states */
350117205eccSRandall Stewart 			return;
350217205eccSRandall Stewart 		}
350317205eccSRandall Stewart 	}
3504f8829a4aSRandall Stewart 	switch (notification) {
3505f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_UP:
3506f8829a4aSRandall Stewart 		if (stcb->asoc.assoc_up_sent == 0) {
3507ceaad40aSRandall Stewart 			sctp_notify_assoc_change(SCTP_COMM_UP, stcb, error, NULL, so_locked);
3508f8829a4aSRandall Stewart 			stcb->asoc.assoc_up_sent = 1;
3509f8829a4aSRandall Stewart 		}
35102afb3e84SRandall Stewart 		if (stcb->asoc.adaptation_needed && (stcb->asoc.adaptation_sent == 0)) {
35112afb3e84SRandall Stewart 			sctp_notify_adaptation_layer(stcb, error);
35122afb3e84SRandall Stewart 		}
3513830d754dSRandall Stewart 		if (stcb->asoc.peer_supports_auth == 0) {
3514830d754dSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_NO_PEER_AUTH, stcb, 0,
3515830d754dSRandall Stewart 			    NULL, so_locked);
3516830d754dSRandall Stewart 		}
3517f8829a4aSRandall Stewart 		break;
3518f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_DOWN:
3519ceaad40aSRandall Stewart 		sctp_notify_assoc_change(SCTP_SHUTDOWN_COMP, stcb, error, NULL, so_locked);
3520f8829a4aSRandall Stewart 		break;
3521f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_DOWN:
3522f8829a4aSRandall Stewart 		{
3523f8829a4aSRandall Stewart 			struct sctp_nets *net;
3524f8829a4aSRandall Stewart 
3525f8829a4aSRandall Stewart 			net = (struct sctp_nets *)data;
3526f8829a4aSRandall Stewart 			sctp_notify_peer_addr_change(stcb, SCTP_ADDR_UNREACHABLE,
3527f8829a4aSRandall Stewart 			    (struct sockaddr *)&net->ro._l_addr, error);
3528f8829a4aSRandall Stewart 			break;
3529f8829a4aSRandall Stewart 		}
3530f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_UP:
3531f8829a4aSRandall Stewart 		{
3532f8829a4aSRandall Stewart 			struct sctp_nets *net;
3533f8829a4aSRandall Stewart 
3534f8829a4aSRandall Stewart 			net = (struct sctp_nets *)data;
3535f8829a4aSRandall Stewart 			sctp_notify_peer_addr_change(stcb, SCTP_ADDR_AVAILABLE,
3536f8829a4aSRandall Stewart 			    (struct sockaddr *)&net->ro._l_addr, error);
3537f8829a4aSRandall Stewart 			break;
3538f8829a4aSRandall Stewart 		}
3539f8829a4aSRandall Stewart 	case SCTP_NOTIFY_INTERFACE_CONFIRMED:
3540f8829a4aSRandall Stewart 		{
3541f8829a4aSRandall Stewart 			struct sctp_nets *net;
3542f8829a4aSRandall Stewart 
3543f8829a4aSRandall Stewart 			net = (struct sctp_nets *)data;
3544f8829a4aSRandall Stewart 			sctp_notify_peer_addr_change(stcb, SCTP_ADDR_CONFIRMED,
3545f8829a4aSRandall Stewart 			    (struct sockaddr *)&net->ro._l_addr, error);
3546f8829a4aSRandall Stewart 			break;
3547f8829a4aSRandall Stewart 		}
3548f8829a4aSRandall Stewart 	case SCTP_NOTIFY_SPECIAL_SP_FAIL:
3549f8829a4aSRandall Stewart 		sctp_notify_send_failed2(stcb, error,
3550ceaad40aSRandall Stewart 		    (struct sctp_stream_queue_pending *)data, so_locked);
3551f8829a4aSRandall Stewart 		break;
3552f8829a4aSRandall Stewart 	case SCTP_NOTIFY_DG_FAIL:
3553f8829a4aSRandall Stewart 		sctp_notify_send_failed(stcb, error,
3554ceaad40aSRandall Stewart 		    (struct sctp_tmit_chunk *)data, so_locked);
3555f8829a4aSRandall Stewart 		break;
3556f8829a4aSRandall Stewart 	case SCTP_NOTIFY_PARTIAL_DELVIERY_INDICATION:
35579a6142d8SRandall Stewart 		{
35589a6142d8SRandall Stewart 			uint32_t val;
35599a6142d8SRandall Stewart 
35609a6142d8SRandall Stewart 			val = *((uint32_t *) data);
35619a6142d8SRandall Stewart 
35629a6142d8SRandall Stewart 			sctp_notify_partial_delivery_indication(stcb, error, 0, val);
35639a6142d8SRandall Stewart 		}
3564f8829a4aSRandall Stewart 		break;
3565f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STRDATA_ERR:
3566f8829a4aSRandall Stewart 		break;
3567f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_ABORTED:
3568c105859eSRandall Stewart 		if ((stcb) && (((stcb->asoc.state & SCTP_STATE_MASK) == SCTP_STATE_COOKIE_WAIT) ||
3569c105859eSRandall Stewart 		    ((stcb->asoc.state & SCTP_STATE_MASK) == SCTP_STATE_COOKIE_ECHOED))) {
3570ceaad40aSRandall Stewart 			sctp_notify_assoc_change(SCTP_CANT_STR_ASSOC, stcb, error, NULL, so_locked);
3571c105859eSRandall Stewart 		} else {
3572ceaad40aSRandall Stewart 			sctp_notify_assoc_change(SCTP_COMM_LOST, stcb, error, NULL, so_locked);
3573c105859eSRandall Stewart 		}
3574f8829a4aSRandall Stewart 		break;
3575f8829a4aSRandall Stewart 	case SCTP_NOTIFY_PEER_OPENED_STREAM:
3576f8829a4aSRandall Stewart 		break;
3577f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STREAM_OPENED_OK:
3578f8829a4aSRandall Stewart 		break;
3579f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASSOC_RESTART:
3580ceaad40aSRandall Stewart 		sctp_notify_assoc_change(SCTP_RESTART, stcb, error, data, so_locked);
3581830d754dSRandall Stewart 		if (stcb->asoc.peer_supports_auth == 0) {
3582830d754dSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_NO_PEER_AUTH, stcb, 0,
3583830d754dSRandall Stewart 			    NULL, so_locked);
3584830d754dSRandall Stewart 		}
3585f8829a4aSRandall Stewart 		break;
3586f8829a4aSRandall Stewart 	case SCTP_NOTIFY_HB_RESP:
3587f8829a4aSRandall Stewart 		break;
3588ea44232bSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_INSTREAM_ADD_OK:
3589ea44232bSRandall Stewart 		sctp_notify_stream_reset_add(stcb, error, SCTP_STRRESET_INBOUND_STR);
3590ea44232bSRandall Stewart 		break;
3591ea44232bSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_ADD_OK:
3592ea44232bSRandall Stewart 		sctp_notify_stream_reset_add(stcb, error, SCTP_STRRESET_OUTBOUND_STR);
3593ea44232bSRandall Stewart 		break;
3594ea44232bSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_ADD_FAIL:
3595ea44232bSRandall Stewart 		sctp_notify_stream_reset_add(stcb, error, (SCTP_STRRESET_FAILED | SCTP_STRRESET_OUTBOUND_STR));
3596ea44232bSRandall Stewart 		break;
3597ea44232bSRandall Stewart 
3598f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_SEND:
3599f8829a4aSRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data), SCTP_STRRESET_OUTBOUND_STR);
3600f8829a4aSRandall Stewart 		break;
3601f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_RECV:
3602f8829a4aSRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data), SCTP_STRRESET_INBOUND_STR);
3603f8829a4aSRandall Stewart 		break;
3604f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_FAILED_OUT:
3605671d309cSRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data), (SCTP_STRRESET_OUTBOUND_STR | SCTP_STRRESET_FAILED));
3606f8829a4aSRandall Stewart 		break;
3607f8829a4aSRandall Stewart 
3608f8829a4aSRandall Stewart 	case SCTP_NOTIFY_STR_RESET_FAILED_IN:
3609671d309cSRandall Stewart 		sctp_notify_stream_reset(stcb, error, ((uint16_t *) data), (SCTP_STRRESET_INBOUND_STR | SCTP_STRRESET_FAILED));
3610f8829a4aSRandall Stewart 		break;
3611f8829a4aSRandall Stewart 
3612f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_ADD_IP:
3613f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_ADDED, data,
3614f8829a4aSRandall Stewart 		    error);
3615f8829a4aSRandall Stewart 		break;
3616f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_DELETE_IP:
3617f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_REMOVED, data,
3618f8829a4aSRandall Stewart 		    error);
3619f8829a4aSRandall Stewart 		break;
3620f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_SET_PRIMARY:
3621f8829a4aSRandall Stewart 		sctp_notify_peer_addr_change(stcb, SCTP_ADDR_MADE_PRIM, data,
3622f8829a4aSRandall Stewart 		    error);
3623f8829a4aSRandall Stewart 		break;
3624f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_SUCCESS:
3625f8829a4aSRandall Stewart 		break;
3626f8829a4aSRandall Stewart 	case SCTP_NOTIFY_ASCONF_FAILED:
3627f8829a4aSRandall Stewart 		break;
3628f8829a4aSRandall Stewart 	case SCTP_NOTIFY_PEER_SHUTDOWN:
3629f8829a4aSRandall Stewart 		sctp_notify_shutdown_event(stcb);
3630f8829a4aSRandall Stewart 		break;
3631f8829a4aSRandall Stewart 	case SCTP_NOTIFY_AUTH_NEW_KEY:
3632f8829a4aSRandall Stewart 		sctp_notify_authentication(stcb, SCTP_AUTH_NEWKEY, error,
3633830d754dSRandall Stewart 		    (uint16_t) (uintptr_t) data,
3634830d754dSRandall Stewart 		    so_locked);
3635f8829a4aSRandall Stewart 		break;
3636830d754dSRandall Stewart 	case SCTP_NOTIFY_AUTH_FREE_KEY:
3637830d754dSRandall Stewart 		sctp_notify_authentication(stcb, SCTP_AUTH_FREE_KEY, error,
3638830d754dSRandall Stewart 		    (uint16_t) (uintptr_t) data,
3639830d754dSRandall Stewart 		    so_locked);
3640f8829a4aSRandall Stewart 		break;
3641830d754dSRandall Stewart 	case SCTP_NOTIFY_NO_PEER_AUTH:
3642830d754dSRandall Stewart 		sctp_notify_authentication(stcb, SCTP_AUTH_NO_AUTH, error,
3643830d754dSRandall Stewart 		    (uint16_t) (uintptr_t) data,
3644830d754dSRandall Stewart 		    so_locked);
3645830d754dSRandall Stewart 		break;
3646830d754dSRandall Stewart 	case SCTP_NOTIFY_SENDER_DRY:
3647830d754dSRandall Stewart 		sctp_notify_sender_dry_event(stcb, so_locked);
3648830d754dSRandall Stewart 		break;
3649f8829a4aSRandall Stewart 	default:
3650ad81507eSRandall Stewart 		SCTPDBG(SCTP_DEBUG_UTIL1, "%s: unknown notification %xh (%u)\n",
3651ad81507eSRandall Stewart 		    __FUNCTION__, notification, notification);
3652f8829a4aSRandall Stewart 		break;
3653f8829a4aSRandall Stewart 	}			/* end switch */
3654f8829a4aSRandall Stewart }
3655f8829a4aSRandall Stewart 
3656f8829a4aSRandall Stewart void
3657ceaad40aSRandall Stewart sctp_report_all_outbound(struct sctp_tcb *stcb, int holds_lock, int so_locked
3658ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3659ceaad40aSRandall Stewart     SCTP_UNUSED
3660ceaad40aSRandall Stewart #endif
3661ceaad40aSRandall Stewart )
3662f8829a4aSRandall Stewart {
3663f8829a4aSRandall Stewart 	struct sctp_association *asoc;
3664f8829a4aSRandall Stewart 	struct sctp_stream_out *outs;
3665f8829a4aSRandall Stewart 	struct sctp_tmit_chunk *chk;
3666f8829a4aSRandall Stewart 	struct sctp_stream_queue_pending *sp;
36677f34832bSRandall Stewart 	int i;
3668f8829a4aSRandall Stewart 
3669f8829a4aSRandall Stewart 	asoc = &stcb->asoc;
3670f8829a4aSRandall Stewart 
3671ad81507eSRandall Stewart 	if (stcb == NULL) {
3672ad81507eSRandall Stewart 		return;
3673ad81507eSRandall Stewart 	}
3674f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
3675f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
3676f8829a4aSRandall Stewart 	    (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET)) {
3677f8829a4aSRandall Stewart 		return;
3678f8829a4aSRandall Stewart 	}
3679f8829a4aSRandall Stewart 	/* now through all the gunk freeing chunks */
3680ad81507eSRandall Stewart 	if (holds_lock == 0) {
36817f34832bSRandall Stewart 		SCTP_TCB_SEND_LOCK(stcb);
3682ad81507eSRandall Stewart 	}
3683d00aff5dSRandall Stewart 	/* sent queue SHOULD be empty */
3684d00aff5dSRandall Stewart 	if (!TAILQ_EMPTY(&asoc->sent_queue)) {
3685d00aff5dSRandall Stewart 		chk = TAILQ_FIRST(&asoc->sent_queue);
3686d00aff5dSRandall Stewart 		while (chk) {
3687d00aff5dSRandall Stewart 			TAILQ_REMOVE(&asoc->sent_queue, chk, sctp_next);
3688d00aff5dSRandall Stewart 			asoc->sent_queue_cnt--;
3689d00aff5dSRandall Stewart 			sctp_free_bufspace(stcb, asoc, chk, 1);
3690d00aff5dSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_DG_FAIL, stcb,
3691ceaad40aSRandall Stewart 			    SCTP_NOTIFY_DATAGRAM_SENT, chk, so_locked);
3692d00aff5dSRandall Stewart 			if (chk->data) {
3693d00aff5dSRandall Stewart 				sctp_m_freem(chk->data);
3694d00aff5dSRandall Stewart 				chk->data = NULL;
3695d00aff5dSRandall Stewart 			}
3696d00aff5dSRandall Stewart 			sctp_free_a_chunk(stcb, chk);
3697d00aff5dSRandall Stewart 			/* sa_ignore FREED_MEMORY */
3698d00aff5dSRandall Stewart 			chk = TAILQ_FIRST(&asoc->sent_queue);
3699d00aff5dSRandall Stewart 		}
3700d00aff5dSRandall Stewart 	}
3701d00aff5dSRandall Stewart 	/* pending send queue SHOULD be empty */
3702d00aff5dSRandall Stewart 	if (!TAILQ_EMPTY(&asoc->send_queue)) {
3703d00aff5dSRandall Stewart 		chk = TAILQ_FIRST(&asoc->send_queue);
3704d00aff5dSRandall Stewart 		while (chk) {
3705d00aff5dSRandall Stewart 			TAILQ_REMOVE(&asoc->send_queue, chk, sctp_next);
3706d00aff5dSRandall Stewart 			asoc->send_queue_cnt--;
3707d00aff5dSRandall Stewart 			sctp_free_bufspace(stcb, asoc, chk, 1);
3708ceaad40aSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_DG_FAIL, stcb, SCTP_NOTIFY_DATAGRAM_UNSENT, chk, so_locked);
3709d00aff5dSRandall Stewart 			if (chk->data) {
3710d00aff5dSRandall Stewart 				sctp_m_freem(chk->data);
3711d00aff5dSRandall Stewart 				chk->data = NULL;
3712d00aff5dSRandall Stewart 			}
3713d00aff5dSRandall Stewart 			sctp_free_a_chunk(stcb, chk);
3714d00aff5dSRandall Stewart 			/* sa_ignore FREED_MEMORY */
3715d00aff5dSRandall Stewart 			chk = TAILQ_FIRST(&asoc->send_queue);
3716d00aff5dSRandall Stewart 		}
3717d00aff5dSRandall Stewart 	}
37187f34832bSRandall Stewart 	for (i = 0; i < stcb->asoc.streamoutcnt; i++) {
37197f34832bSRandall Stewart 		/* For each stream */
37207f34832bSRandall Stewart 		outs = &stcb->asoc.strmout[i];
37217f34832bSRandall Stewart 		/* clean up any sends there */
3722f8829a4aSRandall Stewart 		stcb->asoc.locked_on_sending = NULL;
3723f8829a4aSRandall Stewart 		sp = TAILQ_FIRST(&outs->outqueue);
3724f8829a4aSRandall Stewart 		while (sp) {
3725f8829a4aSRandall Stewart 			stcb->asoc.stream_queue_cnt--;
3726f8829a4aSRandall Stewart 			TAILQ_REMOVE(&outs->outqueue, sp, next);
3727f8829a4aSRandall Stewart 			sctp_free_spbufspace(stcb, asoc, sp);
3728f8829a4aSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_SPECIAL_SP_FAIL, stcb,
3729ceaad40aSRandall Stewart 			    SCTP_NOTIFY_DATAGRAM_UNSENT, (void *)sp, so_locked);
3730f8829a4aSRandall Stewart 			if (sp->data) {
3731f8829a4aSRandall Stewart 				sctp_m_freem(sp->data);
3732f8829a4aSRandall Stewart 				sp->data = NULL;
3733f8829a4aSRandall Stewart 			}
3734f8829a4aSRandall Stewart 			if (sp->net)
3735f8829a4aSRandall Stewart 				sctp_free_remote_addr(sp->net);
3736f8829a4aSRandall Stewart 			sp->net = NULL;
3737f8829a4aSRandall Stewart 			/* Free the chunk */
3738f8829a4aSRandall Stewart 			sctp_free_a_strmoq(stcb, sp);
37393c503c28SRandall Stewart 			/* sa_ignore FREED_MEMORY */
3740f8829a4aSRandall Stewart 			sp = TAILQ_FIRST(&outs->outqueue);
3741f8829a4aSRandall Stewart 		}
3742f8829a4aSRandall Stewart 	}
3743f8829a4aSRandall Stewart 
3744ad81507eSRandall Stewart 	if (holds_lock == 0) {
37457f34832bSRandall Stewart 		SCTP_TCB_SEND_UNLOCK(stcb);
3746f8829a4aSRandall Stewart 	}
3747ad81507eSRandall Stewart }
3748f8829a4aSRandall Stewart 
3749f8829a4aSRandall Stewart void
3750ceaad40aSRandall Stewart sctp_abort_notification(struct sctp_tcb *stcb, int error, int so_locked
3751ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3752ceaad40aSRandall Stewart     SCTP_UNUSED
3753ceaad40aSRandall Stewart #endif
3754ceaad40aSRandall Stewart )
3755f8829a4aSRandall Stewart {
3756f8829a4aSRandall Stewart 
3757ad81507eSRandall Stewart 	if (stcb == NULL) {
3758ad81507eSRandall Stewart 		return;
3759ad81507eSRandall Stewart 	}
3760f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
3761f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) ||
3762f8829a4aSRandall Stewart 	    (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET)) {
3763f8829a4aSRandall Stewart 		return;
3764f8829a4aSRandall Stewart 	}
3765f8829a4aSRandall Stewart 	/* Tell them we lost the asoc */
3766ceaad40aSRandall Stewart 	sctp_report_all_outbound(stcb, 1, so_locked);
3767f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL) ||
3768f8829a4aSRandall Stewart 	    ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) &&
3769f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_CONNECTED))) {
3770f8829a4aSRandall Stewart 		stcb->sctp_ep->sctp_flags |= SCTP_PCB_FLAGS_WAS_ABORTED;
3771f8829a4aSRandall Stewart 	}
3772ceaad40aSRandall Stewart 	sctp_ulp_notify(SCTP_NOTIFY_ASSOC_ABORTED, stcb, error, NULL, so_locked);
3773f8829a4aSRandall Stewart }
3774f8829a4aSRandall Stewart 
3775f8829a4aSRandall Stewart void
3776f8829a4aSRandall Stewart sctp_abort_association(struct sctp_inpcb *inp, struct sctp_tcb *stcb,
377717205eccSRandall Stewart     struct mbuf *m, int iphlen, struct sctphdr *sh, struct mbuf *op_err,
3778c54a18d2SRandall Stewart     uint32_t vrf_id, uint16_t port)
3779f8829a4aSRandall Stewart {
3780f8829a4aSRandall Stewart 	uint32_t vtag;
3781f8829a4aSRandall Stewart 
3782ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3783ceaad40aSRandall Stewart 	struct socket *so;
3784ceaad40aSRandall Stewart 
3785ceaad40aSRandall Stewart #endif
3786ceaad40aSRandall Stewart 
3787f8829a4aSRandall Stewart 	vtag = 0;
3788f8829a4aSRandall Stewart 	if (stcb != NULL) {
3789f8829a4aSRandall Stewart 		/* We have a TCB to abort, send notification too */
3790f8829a4aSRandall Stewart 		vtag = stcb->asoc.peer_vtag;
3791ceaad40aSRandall Stewart 		sctp_abort_notification(stcb, 0, SCTP_SO_NOT_LOCKED);
379217205eccSRandall Stewart 		/* get the assoc vrf id and table id */
379317205eccSRandall Stewart 		vrf_id = stcb->asoc.vrf_id;
379463981c2bSRandall Stewart 		stcb->asoc.state |= SCTP_STATE_WAS_ABORTED;
3795f8829a4aSRandall Stewart 	}
3796c54a18d2SRandall Stewart 	sctp_send_abort(m, iphlen, sh, vtag, op_err, vrf_id, port);
3797f8829a4aSRandall Stewart 	if (stcb != NULL) {
3798f8829a4aSRandall Stewart 		/* Ok, now lets free it */
3799ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3800ceaad40aSRandall Stewart 		so = SCTP_INP_SO(inp);
3801ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
3802ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
3803ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
3804ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
3805ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
3806ceaad40aSRandall Stewart #endif
3807c4739e2fSRandall Stewart 		(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC, SCTP_FROM_SCTPUTIL + SCTP_LOC_4);
3808ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3809ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
3810ceaad40aSRandall Stewart #endif
3811f8829a4aSRandall Stewart 	} else {
3812f8829a4aSRandall Stewart 		if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
3813f8829a4aSRandall Stewart 			if (LIST_FIRST(&inp->sctp_asoc_list) == NULL) {
3814b0552ae2SRandall Stewart 				sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
3815b0552ae2SRandall Stewart 				    SCTP_CALLED_DIRECTLY_NOCMPSET);
3816f8829a4aSRandall Stewart 			}
3817f8829a4aSRandall Stewart 		}
3818f8829a4aSRandall Stewart 	}
3819f8829a4aSRandall Stewart }
3820f8829a4aSRandall Stewart 
3821f1f73e57SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
3822f1f73e57SRandall Stewart void
3823f1f73e57SRandall Stewart sctp_print_out_track_log(struct sctp_tcb *stcb)
3824f1f73e57SRandall Stewart {
382518e198d3SRandall Stewart #ifdef NOSIY_PRINTS
3826f1f73e57SRandall Stewart 	int i;
3827f1f73e57SRandall Stewart 
3828ad81507eSRandall Stewart 	SCTP_PRINTF("Last ep reason:%x\n", stcb->sctp_ep->last_abort_code);
3829ad81507eSRandall Stewart 	SCTP_PRINTF("IN bound TSN log-aaa\n");
3830f1f73e57SRandall Stewart 	if ((stcb->asoc.tsn_in_at == 0) && (stcb->asoc.tsn_in_wrapped == 0)) {
3831ad81507eSRandall Stewart 		SCTP_PRINTF("None rcvd\n");
3832f1f73e57SRandall Stewart 		goto none_in;
3833f1f73e57SRandall Stewart 	}
3834f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_in_wrapped) {
3835f1f73e57SRandall Stewart 		for (i = stcb->asoc.tsn_in_at; i < SCTP_TSN_LOG_SIZE; i++) {
3836ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
3837f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].tsn,
3838f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].strm,
3839f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].seq,
3840f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].flgs,
3841f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].sz);
3842f1f73e57SRandall Stewart 		}
3843f1f73e57SRandall Stewart 	}
3844f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_in_at) {
3845f1f73e57SRandall Stewart 		for (i = 0; i < stcb->asoc.tsn_in_at; i++) {
3846ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
3847f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].tsn,
3848f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].strm,
3849f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].seq,
3850f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].flgs,
3851f1f73e57SRandall Stewart 			    stcb->asoc.in_tsnlog[i].sz);
3852f1f73e57SRandall Stewart 		}
3853f1f73e57SRandall Stewart 	}
3854f1f73e57SRandall Stewart none_in:
3855ad81507eSRandall Stewart 	SCTP_PRINTF("OUT bound TSN log-aaa\n");
3856ad81507eSRandall Stewart 	if ((stcb->asoc.tsn_out_at == 0) &&
3857ad81507eSRandall Stewart 	    (stcb->asoc.tsn_out_wrapped == 0)) {
3858ad81507eSRandall Stewart 		SCTP_PRINTF("None sent\n");
3859f1f73e57SRandall Stewart 	}
3860f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_out_wrapped) {
3861f1f73e57SRandall Stewart 		for (i = stcb->asoc.tsn_out_at; i < SCTP_TSN_LOG_SIZE; i++) {
3862ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
3863f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].tsn,
3864f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].strm,
3865f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].seq,
3866f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].flgs,
3867f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].sz);
3868f1f73e57SRandall Stewart 		}
3869f1f73e57SRandall Stewart 	}
3870f1f73e57SRandall Stewart 	if (stcb->asoc.tsn_out_at) {
3871f1f73e57SRandall Stewart 		for (i = 0; i < stcb->asoc.tsn_out_at; i++) {
3872ad81507eSRandall Stewart 			SCTP_PRINTF("TSN:%x strm:%d seq:%d flags:%x sz:%d\n",
3873f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].tsn,
3874f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].strm,
3875f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].seq,
3876f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].flgs,
3877f1f73e57SRandall Stewart 			    stcb->asoc.out_tsnlog[i].sz);
3878f1f73e57SRandall Stewart 		}
3879f1f73e57SRandall Stewart 	}
388018e198d3SRandall Stewart #endif
3881f1f73e57SRandall Stewart }
3882f1f73e57SRandall Stewart 
3883f1f73e57SRandall Stewart #endif
3884f1f73e57SRandall Stewart 
3885f8829a4aSRandall Stewart void
3886f8829a4aSRandall Stewart sctp_abort_an_association(struct sctp_inpcb *inp, struct sctp_tcb *stcb,
3887ceaad40aSRandall Stewart     int error, struct mbuf *op_err,
3888ceaad40aSRandall Stewart     int so_locked
3889ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
3890ceaad40aSRandall Stewart     SCTP_UNUSED
3891ceaad40aSRandall Stewart #endif
3892ceaad40aSRandall Stewart )
3893f8829a4aSRandall Stewart {
3894f8829a4aSRandall Stewart 	uint32_t vtag;
3895f8829a4aSRandall Stewart 
3896ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3897ceaad40aSRandall Stewart 	struct socket *so;
3898ceaad40aSRandall Stewart 
3899ceaad40aSRandall Stewart #endif
3900ceaad40aSRandall Stewart 
3901ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3902ceaad40aSRandall Stewart 	so = SCTP_INP_SO(inp);
3903ceaad40aSRandall Stewart #endif
3904f8829a4aSRandall Stewart 	if (stcb == NULL) {
3905f8829a4aSRandall Stewart 		/* Got to have a TCB */
3906f8829a4aSRandall Stewart 		if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
3907f8829a4aSRandall Stewart 			if (LIST_FIRST(&inp->sctp_asoc_list) == NULL) {
3908b0552ae2SRandall Stewart 				sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
3909b0552ae2SRandall Stewart 				    SCTP_CALLED_DIRECTLY_NOCMPSET);
3910f8829a4aSRandall Stewart 			}
3911f8829a4aSRandall Stewart 		}
3912f8829a4aSRandall Stewart 		return;
391363981c2bSRandall Stewart 	} else {
391463981c2bSRandall Stewart 		stcb->asoc.state |= SCTP_STATE_WAS_ABORTED;
3915f8829a4aSRandall Stewart 	}
3916f8829a4aSRandall Stewart 	vtag = stcb->asoc.peer_vtag;
3917f8829a4aSRandall Stewart 	/* notify the ulp */
3918f8829a4aSRandall Stewart 	if ((inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) == 0)
3919ceaad40aSRandall Stewart 		sctp_abort_notification(stcb, error, so_locked);
3920f8829a4aSRandall Stewart 	/* notify the peer */
3921b201f536SRandall Stewart #if defined(SCTP_PANIC_ON_ABORT)
3922b201f536SRandall Stewart 	panic("aborting an association");
3923b201f536SRandall Stewart #endif
3924ceaad40aSRandall Stewart 	sctp_send_abort_tcb(stcb, op_err, so_locked);
3925f8829a4aSRandall Stewart 	SCTP_STAT_INCR_COUNTER32(sctps_aborted);
3926f8829a4aSRandall Stewart 	if ((SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_OPEN) ||
3927f8829a4aSRandall Stewart 	    (SCTP_GET_STATE(&stcb->asoc) == SCTP_STATE_SHUTDOWN_RECEIVED)) {
3928f8829a4aSRandall Stewart 		SCTP_STAT_DECR_GAUGE32(sctps_currestab);
3929f8829a4aSRandall Stewart 	}
3930f8829a4aSRandall Stewart 	/* now free the asoc */
3931f1f73e57SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
3932f1f73e57SRandall Stewart 	sctp_print_out_track_log(stcb);
3933f1f73e57SRandall Stewart #endif
3934ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3935ceaad40aSRandall Stewart 	if (!so_locked) {
3936ceaad40aSRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, 1);
3937ceaad40aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
3938ceaad40aSRandall Stewart 		SCTP_SOCKET_LOCK(so, 1);
3939ceaad40aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
3940ceaad40aSRandall Stewart 		atomic_subtract_int(&stcb->asoc.refcnt, 1);
3941ceaad40aSRandall Stewart 	}
3942ceaad40aSRandall Stewart #endif
3943c4739e2fSRandall Stewart 	(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC, SCTP_FROM_SCTPUTIL + SCTP_LOC_5);
3944ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
3945ceaad40aSRandall Stewart 	if (!so_locked) {
3946ceaad40aSRandall Stewart 		SCTP_SOCKET_UNLOCK(so, 1);
3947ceaad40aSRandall Stewart 	}
3948ceaad40aSRandall Stewart #endif
3949f8829a4aSRandall Stewart }
3950f8829a4aSRandall Stewart 
3951f8829a4aSRandall Stewart void
3952f8829a4aSRandall Stewart sctp_handle_ootb(struct mbuf *m, int iphlen, int offset, struct sctphdr *sh,
3953c54a18d2SRandall Stewart     struct sctp_inpcb *inp, struct mbuf *op_err, uint32_t vrf_id, uint16_t port)
3954f8829a4aSRandall Stewart {
3955f8829a4aSRandall Stewart 	struct sctp_chunkhdr *ch, chunk_buf;
3956f8829a4aSRandall Stewart 	unsigned int chk_length;
3957f8829a4aSRandall Stewart 
3958f8829a4aSRandall Stewart 	SCTP_STAT_INCR_COUNTER32(sctps_outoftheblue);
3959f8829a4aSRandall Stewart 	/* Generate a TO address for future reference */
3960f8829a4aSRandall Stewart 	if (inp && (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE)) {
3961f8829a4aSRandall Stewart 		if (LIST_FIRST(&inp->sctp_asoc_list) == NULL) {
3962b0552ae2SRandall Stewart 			sctp_inpcb_free(inp, SCTP_FREE_SHOULD_USE_ABORT,
3963b0552ae2SRandall Stewart 			    SCTP_CALLED_DIRECTLY_NOCMPSET);
3964f8829a4aSRandall Stewart 		}
3965f8829a4aSRandall Stewart 	}
3966f8829a4aSRandall Stewart 	ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
3967f8829a4aSRandall Stewart 	    sizeof(*ch), (uint8_t *) & chunk_buf);
3968f8829a4aSRandall Stewart 	while (ch != NULL) {
3969f8829a4aSRandall Stewart 		chk_length = ntohs(ch->chunk_length);
3970f8829a4aSRandall Stewart 		if (chk_length < sizeof(*ch)) {
3971f8829a4aSRandall Stewart 			/* break to abort land */
3972f8829a4aSRandall Stewart 			break;
3973f8829a4aSRandall Stewart 		}
3974f8829a4aSRandall Stewart 		switch (ch->chunk_type) {
3975d55b0b1bSRandall Stewart 		case SCTP_COOKIE_ECHO:
3976d55b0b1bSRandall Stewart 			/* We hit here only if the assoc is being freed */
3977d55b0b1bSRandall Stewart 			return;
3978f8829a4aSRandall Stewart 		case SCTP_PACKET_DROPPED:
3979f8829a4aSRandall Stewart 			/* we don't respond to pkt-dropped */
3980f8829a4aSRandall Stewart 			return;
3981f8829a4aSRandall Stewart 		case SCTP_ABORT_ASSOCIATION:
3982f8829a4aSRandall Stewart 			/* we don't respond with an ABORT to an ABORT */
3983f8829a4aSRandall Stewart 			return;
3984f8829a4aSRandall Stewart 		case SCTP_SHUTDOWN_COMPLETE:
3985f8829a4aSRandall Stewart 			/*
3986f8829a4aSRandall Stewart 			 * we ignore it since we are not waiting for it and
3987f8829a4aSRandall Stewart 			 * peer is gone
3988f8829a4aSRandall Stewart 			 */
3989f8829a4aSRandall Stewart 			return;
3990f8829a4aSRandall Stewart 		case SCTP_SHUTDOWN_ACK:
3991c54a18d2SRandall Stewart 			sctp_send_shutdown_complete2(m, iphlen, sh, vrf_id, port);
3992f8829a4aSRandall Stewart 			return;
3993f8829a4aSRandall Stewart 		default:
3994f8829a4aSRandall Stewart 			break;
3995f8829a4aSRandall Stewart 		}
3996f8829a4aSRandall Stewart 		offset += SCTP_SIZE32(chk_length);
3997f8829a4aSRandall Stewart 		ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
3998f8829a4aSRandall Stewart 		    sizeof(*ch), (uint8_t *) & chunk_buf);
3999f8829a4aSRandall Stewart 	}
4000c54a18d2SRandall Stewart 	sctp_send_abort(m, iphlen, sh, 0, op_err, vrf_id, port);
4001f8829a4aSRandall Stewart }
4002f8829a4aSRandall Stewart 
4003f8829a4aSRandall Stewart /*
4004f8829a4aSRandall Stewart  * check the inbound datagram to make sure there is not an abort inside it,
4005f8829a4aSRandall Stewart  * if there is return 1, else return 0.
4006f8829a4aSRandall Stewart  */
4007f8829a4aSRandall Stewart int
4008f8829a4aSRandall Stewart sctp_is_there_an_abort_here(struct mbuf *m, int iphlen, uint32_t * vtagfill)
4009f8829a4aSRandall Stewart {
4010f8829a4aSRandall Stewart 	struct sctp_chunkhdr *ch;
4011f8829a4aSRandall Stewart 	struct sctp_init_chunk *init_chk, chunk_buf;
4012f8829a4aSRandall Stewart 	int offset;
4013f8829a4aSRandall Stewart 	unsigned int chk_length;
4014f8829a4aSRandall Stewart 
4015f8829a4aSRandall Stewart 	offset = iphlen + sizeof(struct sctphdr);
4016f8829a4aSRandall Stewart 	ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset, sizeof(*ch),
4017f8829a4aSRandall Stewart 	    (uint8_t *) & chunk_buf);
4018f8829a4aSRandall Stewart 	while (ch != NULL) {
4019f8829a4aSRandall Stewart 		chk_length = ntohs(ch->chunk_length);
4020f8829a4aSRandall Stewart 		if (chk_length < sizeof(*ch)) {
4021f8829a4aSRandall Stewart 			/* packet is probably corrupt */
4022f8829a4aSRandall Stewart 			break;
4023f8829a4aSRandall Stewart 		}
4024f8829a4aSRandall Stewart 		/* we seem to be ok, is it an abort? */
4025f8829a4aSRandall Stewart 		if (ch->chunk_type == SCTP_ABORT_ASSOCIATION) {
4026f8829a4aSRandall Stewart 			/* yep, tell them */
4027f8829a4aSRandall Stewart 			return (1);
4028f8829a4aSRandall Stewart 		}
4029f8829a4aSRandall Stewart 		if (ch->chunk_type == SCTP_INITIATION) {
4030f8829a4aSRandall Stewart 			/* need to update the Vtag */
4031f8829a4aSRandall Stewart 			init_chk = (struct sctp_init_chunk *)sctp_m_getptr(m,
4032f8829a4aSRandall Stewart 			    offset, sizeof(*init_chk), (uint8_t *) & chunk_buf);
4033f8829a4aSRandall Stewart 			if (init_chk != NULL) {
4034f8829a4aSRandall Stewart 				*vtagfill = ntohl(init_chk->init.initiate_tag);
4035f8829a4aSRandall Stewart 			}
4036f8829a4aSRandall Stewart 		}
4037f8829a4aSRandall Stewart 		/* Nope, move to the next chunk */
4038f8829a4aSRandall Stewart 		offset += SCTP_SIZE32(chk_length);
4039f8829a4aSRandall Stewart 		ch = (struct sctp_chunkhdr *)sctp_m_getptr(m, offset,
4040f8829a4aSRandall Stewart 		    sizeof(*ch), (uint8_t *) & chunk_buf);
4041f8829a4aSRandall Stewart 	}
4042f8829a4aSRandall Stewart 	return (0);
4043f8829a4aSRandall Stewart }
4044f8829a4aSRandall Stewart 
4045f8829a4aSRandall Stewart /*
4046f8829a4aSRandall Stewart  * currently (2/02), ifa_addr embeds scope_id's and don't have sin6_scope_id
4047f8829a4aSRandall Stewart  * set (i.e. it's 0) so, create this function to compare link local scopes
4048f8829a4aSRandall Stewart  */
40495e2c2d87SRandall Stewart #ifdef INET6
4050f8829a4aSRandall Stewart uint32_t
4051f8829a4aSRandall Stewart sctp_is_same_scope(struct sockaddr_in6 *addr1, struct sockaddr_in6 *addr2)
4052f8829a4aSRandall Stewart {
4053f8829a4aSRandall Stewart 	struct sockaddr_in6 a, b;
4054f8829a4aSRandall Stewart 
4055f8829a4aSRandall Stewart 	/* save copies */
4056f8829a4aSRandall Stewart 	a = *addr1;
4057f8829a4aSRandall Stewart 	b = *addr2;
4058f8829a4aSRandall Stewart 
4059f8829a4aSRandall Stewart 	if (a.sin6_scope_id == 0)
4060f8829a4aSRandall Stewart 		if (sa6_recoverscope(&a)) {
4061f8829a4aSRandall Stewart 			/* can't get scope, so can't match */
4062f8829a4aSRandall Stewart 			return (0);
4063f8829a4aSRandall Stewart 		}
4064f8829a4aSRandall Stewart 	if (b.sin6_scope_id == 0)
4065f8829a4aSRandall Stewart 		if (sa6_recoverscope(&b)) {
4066f8829a4aSRandall Stewart 			/* can't get scope, so can't match */
4067f8829a4aSRandall Stewart 			return (0);
4068f8829a4aSRandall Stewart 		}
4069f8829a4aSRandall Stewart 	if (a.sin6_scope_id != b.sin6_scope_id)
4070f8829a4aSRandall Stewart 		return (0);
4071f8829a4aSRandall Stewart 
4072f8829a4aSRandall Stewart 	return (1);
4073f8829a4aSRandall Stewart }
4074f8829a4aSRandall Stewart 
4075f8829a4aSRandall Stewart /*
4076f8829a4aSRandall Stewart  * returns a sockaddr_in6 with embedded scope recovered and removed
4077f8829a4aSRandall Stewart  */
4078f8829a4aSRandall Stewart struct sockaddr_in6 *
4079f8829a4aSRandall Stewart sctp_recover_scope(struct sockaddr_in6 *addr, struct sockaddr_in6 *store)
4080f8829a4aSRandall Stewart {
4081f8829a4aSRandall Stewart 	/* check and strip embedded scope junk */
4082f8829a4aSRandall Stewart 	if (addr->sin6_family == AF_INET6) {
4083f8829a4aSRandall Stewart 		if (IN6_IS_SCOPE_LINKLOCAL(&addr->sin6_addr)) {
4084f8829a4aSRandall Stewart 			if (addr->sin6_scope_id == 0) {
4085f8829a4aSRandall Stewart 				*store = *addr;
4086f8829a4aSRandall Stewart 				if (!sa6_recoverscope(store)) {
4087f8829a4aSRandall Stewart 					/* use the recovered scope */
4088f8829a4aSRandall Stewart 					addr = store;
4089f8829a4aSRandall Stewart 				}
4090f42a358aSRandall Stewart 			} else {
4091f8829a4aSRandall Stewart 				/* else, return the original "to" addr */
4092f42a358aSRandall Stewart 				in6_clearscope(&addr->sin6_addr);
4093f8829a4aSRandall Stewart 			}
4094f8829a4aSRandall Stewart 		}
4095f8829a4aSRandall Stewart 	}
4096f8829a4aSRandall Stewart 	return (addr);
4097f8829a4aSRandall Stewart }
4098f8829a4aSRandall Stewart 
40995e2c2d87SRandall Stewart #endif
41005e2c2d87SRandall Stewart 
4101f8829a4aSRandall Stewart /*
4102f8829a4aSRandall Stewart  * are the two addresses the same?  currently a "scopeless" check returns: 1
4103f8829a4aSRandall Stewart  * if same, 0 if not
4104f8829a4aSRandall Stewart  */
410572fb6fdbSRandall Stewart int
4106f8829a4aSRandall Stewart sctp_cmpaddr(struct sockaddr *sa1, struct sockaddr *sa2)
4107f8829a4aSRandall Stewart {
4108f8829a4aSRandall Stewart 
4109f8829a4aSRandall Stewart 	/* must be valid */
4110f8829a4aSRandall Stewart 	if (sa1 == NULL || sa2 == NULL)
4111f8829a4aSRandall Stewart 		return (0);
4112f8829a4aSRandall Stewart 
4113f8829a4aSRandall Stewart 	/* must be the same family */
4114f8829a4aSRandall Stewart 	if (sa1->sa_family != sa2->sa_family)
4115f8829a4aSRandall Stewart 		return (0);
4116f8829a4aSRandall Stewart 
41175e2c2d87SRandall Stewart 	switch (sa1->sa_family) {
41185e2c2d87SRandall Stewart #ifdef INET6
41195e2c2d87SRandall Stewart 	case AF_INET6:
41205e2c2d87SRandall Stewart 		{
4121f8829a4aSRandall Stewart 			/* IPv6 addresses */
4122f8829a4aSRandall Stewart 			struct sockaddr_in6 *sin6_1, *sin6_2;
4123f8829a4aSRandall Stewart 
4124f8829a4aSRandall Stewart 			sin6_1 = (struct sockaddr_in6 *)sa1;
4125f8829a4aSRandall Stewart 			sin6_2 = (struct sockaddr_in6 *)sa2;
4126c54a18d2SRandall Stewart 			return (SCTP6_ARE_ADDR_EQUAL(sin6_1,
4127c54a18d2SRandall Stewart 			    sin6_2));
41285e2c2d87SRandall Stewart 		}
41295e2c2d87SRandall Stewart #endif
41305e2c2d87SRandall Stewart 	case AF_INET:
41315e2c2d87SRandall Stewart 		{
4132f8829a4aSRandall Stewart 			/* IPv4 addresses */
4133f8829a4aSRandall Stewart 			struct sockaddr_in *sin_1, *sin_2;
4134f8829a4aSRandall Stewart 
4135f8829a4aSRandall Stewart 			sin_1 = (struct sockaddr_in *)sa1;
4136f8829a4aSRandall Stewart 			sin_2 = (struct sockaddr_in *)sa2;
4137f8829a4aSRandall Stewart 			return (sin_1->sin_addr.s_addr == sin_2->sin_addr.s_addr);
41385e2c2d87SRandall Stewart 		}
41395e2c2d87SRandall Stewart 	default:
4140f8829a4aSRandall Stewart 		/* we don't do these... */
4141f8829a4aSRandall Stewart 		return (0);
4142f8829a4aSRandall Stewart 	}
4143f8829a4aSRandall Stewart }
4144f8829a4aSRandall Stewart 
4145f8829a4aSRandall Stewart void
4146f8829a4aSRandall Stewart sctp_print_address(struct sockaddr *sa)
4147f8829a4aSRandall Stewart {
41485e2c2d87SRandall Stewart #ifdef INET6
41497d32aa0cSBjoern A. Zeeb 	char ip6buf[INET6_ADDRSTRLEN];
4150f8829a4aSRandall Stewart 
4151ad81507eSRandall Stewart 	ip6buf[0] = 0;
41525e2c2d87SRandall Stewart #endif
41535e2c2d87SRandall Stewart 
41545e2c2d87SRandall Stewart 	switch (sa->sa_family) {
41555e2c2d87SRandall Stewart #ifdef INET6
41565e2c2d87SRandall Stewart 	case AF_INET6:
41575e2c2d87SRandall Stewart 		{
4158ad81507eSRandall Stewart 			struct sockaddr_in6 *sin6;
4159ad81507eSRandall Stewart 
4160f8829a4aSRandall Stewart 			sin6 = (struct sockaddr_in6 *)sa;
4161ad81507eSRandall Stewart 			SCTP_PRINTF("IPv6 address: %s:port:%d scope:%u\n",
41627d32aa0cSBjoern A. Zeeb 			    ip6_sprintf(ip6buf, &sin6->sin6_addr),
41637d32aa0cSBjoern A. Zeeb 			    ntohs(sin6->sin6_port),
4164f8829a4aSRandall Stewart 			    sin6->sin6_scope_id);
41655e2c2d87SRandall Stewart 			break;
41665e2c2d87SRandall Stewart 		}
41675e2c2d87SRandall Stewart #endif
41685e2c2d87SRandall Stewart 	case AF_INET:
41695e2c2d87SRandall Stewart 		{
4170f8829a4aSRandall Stewart 			struct sockaddr_in *sin;
4171f8829a4aSRandall Stewart 			unsigned char *p;
4172f8829a4aSRandall Stewart 
4173f8829a4aSRandall Stewart 			sin = (struct sockaddr_in *)sa;
4174f8829a4aSRandall Stewart 			p = (unsigned char *)&sin->sin_addr;
4175ad81507eSRandall Stewart 			SCTP_PRINTF("IPv4 address: %u.%u.%u.%u:%d\n",
4176f8829a4aSRandall Stewart 			    p[0], p[1], p[2], p[3], ntohs(sin->sin_port));
41775e2c2d87SRandall Stewart 			break;
41785e2c2d87SRandall Stewart 		}
41795e2c2d87SRandall Stewart 	default:
4180ad81507eSRandall Stewart 		SCTP_PRINTF("?\n");
41815e2c2d87SRandall Stewart 		break;
4182f8829a4aSRandall Stewart 	}
4183f8829a4aSRandall Stewart }
4184f8829a4aSRandall Stewart 
4185f8829a4aSRandall Stewart void
4186f8829a4aSRandall Stewart sctp_print_address_pkt(struct ip *iph, struct sctphdr *sh)
4187f8829a4aSRandall Stewart {
41885e2c2d87SRandall Stewart 	switch (iph->ip_v) {
41895e2c2d87SRandall Stewart 		case IPVERSION:
41905e2c2d87SRandall Stewart 		{
4191f8829a4aSRandall Stewart 			struct sockaddr_in lsa, fsa;
4192f8829a4aSRandall Stewart 
4193f8829a4aSRandall Stewart 			bzero(&lsa, sizeof(lsa));
4194f8829a4aSRandall Stewart 			lsa.sin_len = sizeof(lsa);
4195f8829a4aSRandall Stewart 			lsa.sin_family = AF_INET;
4196f8829a4aSRandall Stewart 			lsa.sin_addr = iph->ip_src;
4197f8829a4aSRandall Stewart 			lsa.sin_port = sh->src_port;
4198f8829a4aSRandall Stewart 			bzero(&fsa, sizeof(fsa));
4199f8829a4aSRandall Stewart 			fsa.sin_len = sizeof(fsa);
4200f8829a4aSRandall Stewart 			fsa.sin_family = AF_INET;
4201f8829a4aSRandall Stewart 			fsa.sin_addr = iph->ip_dst;
4202f8829a4aSRandall Stewart 			fsa.sin_port = sh->dest_port;
4203ad81507eSRandall Stewart 			SCTP_PRINTF("src: ");
4204f8829a4aSRandall Stewart 			sctp_print_address((struct sockaddr *)&lsa);
4205ad81507eSRandall Stewart 			SCTP_PRINTF("dest: ");
4206f8829a4aSRandall Stewart 			sctp_print_address((struct sockaddr *)&fsa);
42075e2c2d87SRandall Stewart 			break;
42085e2c2d87SRandall Stewart 		}
42095e2c2d87SRandall Stewart #ifdef INET6
42105e2c2d87SRandall Stewart 	case IPV6_VERSION >> 4:
42115e2c2d87SRandall Stewart 		{
4212f8829a4aSRandall Stewart 			struct ip6_hdr *ip6;
4213f8829a4aSRandall Stewart 			struct sockaddr_in6 lsa6, fsa6;
4214f8829a4aSRandall Stewart 
4215f8829a4aSRandall Stewart 			ip6 = (struct ip6_hdr *)iph;
4216f8829a4aSRandall Stewart 			bzero(&lsa6, sizeof(lsa6));
4217f8829a4aSRandall Stewart 			lsa6.sin6_len = sizeof(lsa6);
4218f8829a4aSRandall Stewart 			lsa6.sin6_family = AF_INET6;
4219f8829a4aSRandall Stewart 			lsa6.sin6_addr = ip6->ip6_src;
4220f8829a4aSRandall Stewart 			lsa6.sin6_port = sh->src_port;
4221f8829a4aSRandall Stewart 			bzero(&fsa6, sizeof(fsa6));
4222f8829a4aSRandall Stewart 			fsa6.sin6_len = sizeof(fsa6);
4223f8829a4aSRandall Stewart 			fsa6.sin6_family = AF_INET6;
4224f8829a4aSRandall Stewart 			fsa6.sin6_addr = ip6->ip6_dst;
4225f8829a4aSRandall Stewart 			fsa6.sin6_port = sh->dest_port;
4226ad81507eSRandall Stewart 			SCTP_PRINTF("src: ");
4227f8829a4aSRandall Stewart 			sctp_print_address((struct sockaddr *)&lsa6);
4228ad81507eSRandall Stewart 			SCTP_PRINTF("dest: ");
4229f8829a4aSRandall Stewart 			sctp_print_address((struct sockaddr *)&fsa6);
42305e2c2d87SRandall Stewart 			break;
42315e2c2d87SRandall Stewart 		}
42325e2c2d87SRandall Stewart #endif
42335e2c2d87SRandall Stewart 	default:
42345e2c2d87SRandall Stewart 		/* TSNH */
42355e2c2d87SRandall Stewart 		break;
4236f8829a4aSRandall Stewart 	}
4237f8829a4aSRandall Stewart }
4238f8829a4aSRandall Stewart 
4239f8829a4aSRandall Stewart void
4240f8829a4aSRandall Stewart sctp_pull_off_control_to_new_inp(struct sctp_inpcb *old_inp,
4241f8829a4aSRandall Stewart     struct sctp_inpcb *new_inp,
4242d06c82f1SRandall Stewart     struct sctp_tcb *stcb,
4243d06c82f1SRandall Stewart     int waitflags)
4244f8829a4aSRandall Stewart {
4245f8829a4aSRandall Stewart 	/*
4246f8829a4aSRandall Stewart 	 * go through our old INP and pull off any control structures that
4247f8829a4aSRandall Stewart 	 * belong to stcb and move then to the new inp.
4248f8829a4aSRandall Stewart 	 */
4249f8829a4aSRandall Stewart 	struct socket *old_so, *new_so;
4250f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control, *nctl;
4251f8829a4aSRandall Stewart 	struct sctp_readhead tmp_queue;
4252f8829a4aSRandall Stewart 	struct mbuf *m;
4253bff64a4dSRandall Stewart 	int error = 0;
4254f8829a4aSRandall Stewart 
4255f8829a4aSRandall Stewart 	old_so = old_inp->sctp_socket;
4256f8829a4aSRandall Stewart 	new_so = new_inp->sctp_socket;
4257f8829a4aSRandall Stewart 	TAILQ_INIT(&tmp_queue);
4258d06c82f1SRandall Stewart 	error = sblock(&old_so->so_rcv, waitflags);
4259f8829a4aSRandall Stewart 	if (error) {
4260f8829a4aSRandall Stewart 		/*
4261f8829a4aSRandall Stewart 		 * Gak, can't get sblock, we have a problem. data will be
4262f8829a4aSRandall Stewart 		 * left stranded.. and we don't dare look at it since the
4263f8829a4aSRandall Stewart 		 * other thread may be reading something. Oh well, its a
4264f8829a4aSRandall Stewart 		 * screwed up app that does a peeloff OR a accept while
4265f8829a4aSRandall Stewart 		 * reading from the main socket... actually its only the
4266f8829a4aSRandall Stewart 		 * peeloff() case, since I think read will fail on a
4267f8829a4aSRandall Stewart 		 * listening socket..
4268f8829a4aSRandall Stewart 		 */
4269f8829a4aSRandall Stewart 		return;
4270f8829a4aSRandall Stewart 	}
4271f8829a4aSRandall Stewart 	/* lock the socket buffers */
4272f8829a4aSRandall Stewart 	SCTP_INP_READ_LOCK(old_inp);
4273f8829a4aSRandall Stewart 	control = TAILQ_FIRST(&old_inp->read_queue);
4274f8829a4aSRandall Stewart 	/* Pull off all for out target stcb */
4275f8829a4aSRandall Stewart 	while (control) {
4276f8829a4aSRandall Stewart 		nctl = TAILQ_NEXT(control, next);
4277f8829a4aSRandall Stewart 		if (control->stcb == stcb) {
4278f8829a4aSRandall Stewart 			/* remove it we want it */
4279f8829a4aSRandall Stewart 			TAILQ_REMOVE(&old_inp->read_queue, control, next);
4280f8829a4aSRandall Stewart 			TAILQ_INSERT_TAIL(&tmp_queue, control, next);
4281f8829a4aSRandall Stewart 			m = control->data;
4282f8829a4aSRandall Stewart 			while (m) {
4283b3f1ea41SRandall Stewart 				if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4284139bc87fSRandall Stewart 					sctp_sblog(&old_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
428580fefe0aSRandall Stewart 				}
4286f8829a4aSRandall Stewart 				sctp_sbfree(control, stcb, &old_so->so_rcv, m);
4287b3f1ea41SRandall Stewart 				if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4288f8829a4aSRandall Stewart 					sctp_sblog(&old_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
428980fefe0aSRandall Stewart 				}
4290139bc87fSRandall Stewart 				m = SCTP_BUF_NEXT(m);
4291f8829a4aSRandall Stewart 			}
4292f8829a4aSRandall Stewart 		}
4293f8829a4aSRandall Stewart 		control = nctl;
4294f8829a4aSRandall Stewart 	}
4295f8829a4aSRandall Stewart 	SCTP_INP_READ_UNLOCK(old_inp);
4296f8829a4aSRandall Stewart 	/* Remove the sb-lock on the old socket */
4297f8829a4aSRandall Stewart 
4298f8829a4aSRandall Stewart 	sbunlock(&old_so->so_rcv);
4299f8829a4aSRandall Stewart 	/* Now we move them over to the new socket buffer */
4300f8829a4aSRandall Stewart 	control = TAILQ_FIRST(&tmp_queue);
4301f8829a4aSRandall Stewart 	SCTP_INP_READ_LOCK(new_inp);
4302f8829a4aSRandall Stewart 	while (control) {
4303f8829a4aSRandall Stewart 		nctl = TAILQ_NEXT(control, next);
4304f8829a4aSRandall Stewart 		TAILQ_INSERT_TAIL(&new_inp->read_queue, control, next);
4305f8829a4aSRandall Stewart 		m = control->data;
4306f8829a4aSRandall Stewart 		while (m) {
4307b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4308139bc87fSRandall Stewart 				sctp_sblog(&new_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m));
430980fefe0aSRandall Stewart 			}
4310f8829a4aSRandall Stewart 			sctp_sballoc(stcb, &new_so->so_rcv, m);
4311b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4312f8829a4aSRandall Stewart 				sctp_sblog(&new_so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
431380fefe0aSRandall Stewart 			}
4314139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
4315f8829a4aSRandall Stewart 		}
4316f8829a4aSRandall Stewart 		control = nctl;
4317f8829a4aSRandall Stewart 	}
4318f8829a4aSRandall Stewart 	SCTP_INP_READ_UNLOCK(new_inp);
4319f8829a4aSRandall Stewart }
4320f8829a4aSRandall Stewart 
4321f8829a4aSRandall Stewart void
4322f8829a4aSRandall Stewart sctp_add_to_readq(struct sctp_inpcb *inp,
4323f8829a4aSRandall Stewart     struct sctp_tcb *stcb,
4324f8829a4aSRandall Stewart     struct sctp_queued_to_read *control,
4325f8829a4aSRandall Stewart     struct sockbuf *sb,
4326ceaad40aSRandall Stewart     int end,
4327ceaad40aSRandall Stewart     int so_locked
4328ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
4329ceaad40aSRandall Stewart     SCTP_UNUSED
4330ceaad40aSRandall Stewart #endif
4331ceaad40aSRandall Stewart )
4332f8829a4aSRandall Stewart {
4333f8829a4aSRandall Stewart 	/*
4334f8829a4aSRandall Stewart 	 * Here we must place the control on the end of the socket read
4335f8829a4aSRandall Stewart 	 * queue AND increment sb_cc so that select will work properly on
4336f8829a4aSRandall Stewart 	 * read.
4337f8829a4aSRandall Stewart 	 */
4338f8829a4aSRandall Stewart 	struct mbuf *m, *prev = NULL;
4339f8829a4aSRandall Stewart 
434003b0b021SRandall Stewart 	if (inp == NULL) {
434103b0b021SRandall Stewart 		/* Gak, TSNH!! */
4342a5d547adSRandall Stewart #ifdef INVARIANTS
434303b0b021SRandall Stewart 		panic("Gak, inp NULL on add_to_readq");
434403b0b021SRandall Stewart #endif
434503b0b021SRandall Stewart 		return;
434603b0b021SRandall Stewart 	}
4347f8829a4aSRandall Stewart 	SCTP_INP_READ_LOCK(inp);
434842551e99SRandall Stewart 	if (!(control->spec_flags & M_NOTIFICATION)) {
4349a5d547adSRandall Stewart 		atomic_add_int(&inp->total_recvs, 1);
435042551e99SRandall Stewart 		if (!control->do_not_ref_stcb) {
4351a5d547adSRandall Stewart 			atomic_add_int(&stcb->total_recvs, 1);
435242551e99SRandall Stewart 		}
435342551e99SRandall Stewart 	}
4354f8829a4aSRandall Stewart 	m = control->data;
4355f8829a4aSRandall Stewart 	control->held_length = 0;
4356f8829a4aSRandall Stewart 	control->length = 0;
4357f8829a4aSRandall Stewart 	while (m) {
4358139bc87fSRandall Stewart 		if (SCTP_BUF_LEN(m) == 0) {
4359f8829a4aSRandall Stewart 			/* Skip mbufs with NO length */
4360f8829a4aSRandall Stewart 			if (prev == NULL) {
4361f8829a4aSRandall Stewart 				/* First one */
4362f8829a4aSRandall Stewart 				control->data = sctp_m_free(m);
4363f8829a4aSRandall Stewart 				m = control->data;
4364f8829a4aSRandall Stewart 			} else {
4365139bc87fSRandall Stewart 				SCTP_BUF_NEXT(prev) = sctp_m_free(m);
4366139bc87fSRandall Stewart 				m = SCTP_BUF_NEXT(prev);
4367f8829a4aSRandall Stewart 			}
4368f8829a4aSRandall Stewart 			if (m == NULL) {
4369f8829a4aSRandall Stewart 				control->tail_mbuf = prev;;
4370f8829a4aSRandall Stewart 			}
4371f8829a4aSRandall Stewart 			continue;
4372f8829a4aSRandall Stewart 		}
4373f8829a4aSRandall Stewart 		prev = m;
4374b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4375139bc87fSRandall Stewart 			sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(m));
437680fefe0aSRandall Stewart 		}
4377f8829a4aSRandall Stewart 		sctp_sballoc(stcb, sb, m);
4378b3f1ea41SRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4379f8829a4aSRandall Stewart 			sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
438080fefe0aSRandall Stewart 		}
4381139bc87fSRandall Stewart 		atomic_add_int(&control->length, SCTP_BUF_LEN(m));
4382139bc87fSRandall Stewart 		m = SCTP_BUF_NEXT(m);
4383f8829a4aSRandall Stewart 	}
4384f8829a4aSRandall Stewart 	if (prev != NULL) {
4385f8829a4aSRandall Stewart 		control->tail_mbuf = prev;
4386f8829a4aSRandall Stewart 	} else {
4387139bc87fSRandall Stewart 		/* Everything got collapsed out?? */
4388f8829a4aSRandall Stewart 		return;
4389f8829a4aSRandall Stewart 	}
4390f8829a4aSRandall Stewart 	if (end) {
4391f8829a4aSRandall Stewart 		control->end_added = 1;
4392f8829a4aSRandall Stewart 	}
4393f8829a4aSRandall Stewart 	TAILQ_INSERT_TAIL(&inp->read_queue, control, next);
4394f8829a4aSRandall Stewart 	SCTP_INP_READ_UNLOCK(inp);
4395f8829a4aSRandall Stewart 	if (inp && inp->sctp_socket) {
439617205eccSRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_ZERO_COPY_ACTIVE)) {
439717205eccSRandall Stewart 			SCTP_ZERO_COPY_EVENT(inp, inp->sctp_socket);
4398ceaad40aSRandall Stewart 		} else {
4399ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4400ceaad40aSRandall Stewart 			struct socket *so;
4401ceaad40aSRandall Stewart 
4402ceaad40aSRandall Stewart 			so = SCTP_INP_SO(inp);
4403ceaad40aSRandall Stewart 			if (!so_locked) {
4404ceaad40aSRandall Stewart 				atomic_add_int(&stcb->asoc.refcnt, 1);
4405ceaad40aSRandall Stewart 				SCTP_TCB_UNLOCK(stcb);
4406ceaad40aSRandall Stewart 				SCTP_SOCKET_LOCK(so, 1);
4407ceaad40aSRandall Stewart 				SCTP_TCB_LOCK(stcb);
4408ceaad40aSRandall Stewart 				atomic_subtract_int(&stcb->asoc.refcnt, 1);
4409ceaad40aSRandall Stewart 				if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
4410ceaad40aSRandall Stewart 					SCTP_SOCKET_UNLOCK(so, 1);
4411ceaad40aSRandall Stewart 					return;
4412ceaad40aSRandall Stewart 				}
4413ceaad40aSRandall Stewart 			}
4414ceaad40aSRandall Stewart #endif
4415f8829a4aSRandall Stewart 			sctp_sorwakeup(inp, inp->sctp_socket);
4416ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4417ceaad40aSRandall Stewart 			if (!so_locked) {
4418ceaad40aSRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
4419ceaad40aSRandall Stewart 			}
4420ceaad40aSRandall Stewart #endif
4421ceaad40aSRandall Stewart 		}
4422f8829a4aSRandall Stewart 	}
4423f8829a4aSRandall Stewart }
4424f8829a4aSRandall Stewart 
4425f8829a4aSRandall Stewart 
4426f8829a4aSRandall Stewart int
4427f8829a4aSRandall Stewart sctp_append_to_readq(struct sctp_inpcb *inp,
4428f8829a4aSRandall Stewart     struct sctp_tcb *stcb,
4429f8829a4aSRandall Stewart     struct sctp_queued_to_read *control,
4430f8829a4aSRandall Stewart     struct mbuf *m,
4431f8829a4aSRandall Stewart     int end,
4432f8829a4aSRandall Stewart     int ctls_cumack,
4433f8829a4aSRandall Stewart     struct sockbuf *sb)
4434f8829a4aSRandall Stewart {
4435f8829a4aSRandall Stewart 	/*
4436f8829a4aSRandall Stewart 	 * A partial delivery API event is underway. OR we are appending on
4437f8829a4aSRandall Stewart 	 * the reassembly queue.
4438f8829a4aSRandall Stewart 	 *
4439f8829a4aSRandall Stewart 	 * If PDAPI this means we need to add m to the end of the data.
4440f8829a4aSRandall Stewart 	 * Increase the length in the control AND increment the sb_cc.
4441f8829a4aSRandall Stewart 	 * Otherwise sb is NULL and all we need to do is put it at the end
4442f8829a4aSRandall Stewart 	 * of the mbuf chain.
4443f8829a4aSRandall Stewart 	 */
4444f8829a4aSRandall Stewart 	int len = 0;
4445f8829a4aSRandall Stewart 	struct mbuf *mm, *tail = NULL, *prev = NULL;
4446f8829a4aSRandall Stewart 
4447f8829a4aSRandall Stewart 	if (inp) {
4448f8829a4aSRandall Stewart 		SCTP_INP_READ_LOCK(inp);
4449f8829a4aSRandall Stewart 	}
4450f8829a4aSRandall Stewart 	if (control == NULL) {
4451f8829a4aSRandall Stewart get_out:
4452f8829a4aSRandall Stewart 		if (inp) {
4453f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
4454f8829a4aSRandall Stewart 		}
4455f8829a4aSRandall Stewart 		return (-1);
4456f8829a4aSRandall Stewart 	}
4457139bc87fSRandall Stewart 	if (control->end_added) {
4458f8829a4aSRandall Stewart 		/* huh this one is complete? */
4459f8829a4aSRandall Stewart 		goto get_out;
4460f8829a4aSRandall Stewart 	}
4461f8829a4aSRandall Stewart 	mm = m;
4462f8829a4aSRandall Stewart 	if (mm == NULL) {
4463f8829a4aSRandall Stewart 		goto get_out;
4464f8829a4aSRandall Stewart 	}
4465f8829a4aSRandall Stewart 	while (mm) {
4466139bc87fSRandall Stewart 		if (SCTP_BUF_LEN(mm) == 0) {
4467f8829a4aSRandall Stewart 			/* Skip mbufs with NO lenght */
4468f8829a4aSRandall Stewart 			if (prev == NULL) {
4469f8829a4aSRandall Stewart 				/* First one */
4470f8829a4aSRandall Stewart 				m = sctp_m_free(mm);
4471f8829a4aSRandall Stewart 				mm = m;
4472f8829a4aSRandall Stewart 			} else {
4473139bc87fSRandall Stewart 				SCTP_BUF_NEXT(prev) = sctp_m_free(mm);
4474139bc87fSRandall Stewart 				mm = SCTP_BUF_NEXT(prev);
4475f8829a4aSRandall Stewart 			}
4476f8829a4aSRandall Stewart 			continue;
4477f8829a4aSRandall Stewart 		}
4478f8829a4aSRandall Stewart 		prev = mm;
4479139bc87fSRandall Stewart 		len += SCTP_BUF_LEN(mm);
4480f8829a4aSRandall Stewart 		if (sb) {
4481b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4482139bc87fSRandall Stewart 				sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBALLOC, SCTP_BUF_LEN(mm));
448380fefe0aSRandall Stewart 			}
4484f8829a4aSRandall Stewart 			sctp_sballoc(stcb, sb, mm);
4485b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
4486f8829a4aSRandall Stewart 				sctp_sblog(sb, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
448780fefe0aSRandall Stewart 			}
4488f8829a4aSRandall Stewart 		}
4489139bc87fSRandall Stewart 		mm = SCTP_BUF_NEXT(mm);
4490f8829a4aSRandall Stewart 	}
4491f8829a4aSRandall Stewart 	if (prev) {
4492f8829a4aSRandall Stewart 		tail = prev;
4493f8829a4aSRandall Stewart 	} else {
4494f8829a4aSRandall Stewart 		/* Really there should always be a prev */
4495f8829a4aSRandall Stewart 		if (m == NULL) {
4496f8829a4aSRandall Stewart 			/* Huh nothing left? */
4497a5d547adSRandall Stewart #ifdef INVARIANTS
4498f8829a4aSRandall Stewart 			panic("Nothing left to add?");
4499f8829a4aSRandall Stewart #else
4500f8829a4aSRandall Stewart 			goto get_out;
4501f8829a4aSRandall Stewart #endif
4502f8829a4aSRandall Stewart 		}
4503f8829a4aSRandall Stewart 		tail = m;
4504f8829a4aSRandall Stewart 	}
4505f8829a4aSRandall Stewart 	if (control->tail_mbuf) {
4506f8829a4aSRandall Stewart 		/* append */
4507139bc87fSRandall Stewart 		SCTP_BUF_NEXT(control->tail_mbuf) = m;
4508f8829a4aSRandall Stewart 		control->tail_mbuf = tail;
4509f8829a4aSRandall Stewart 	} else {
4510f8829a4aSRandall Stewart 		/* nothing there */
4511a5d547adSRandall Stewart #ifdef INVARIANTS
4512f8829a4aSRandall Stewart 		if (control->data != NULL) {
4513f8829a4aSRandall Stewart 			panic("This should NOT happen");
4514f8829a4aSRandall Stewart 		}
4515f8829a4aSRandall Stewart #endif
4516f8829a4aSRandall Stewart 		control->data = m;
4517f8829a4aSRandall Stewart 		control->tail_mbuf = tail;
4518f8829a4aSRandall Stewart 	}
451918e198d3SRandall Stewart 	atomic_add_int(&control->length, len);
452018e198d3SRandall Stewart 	if (end) {
452118e198d3SRandall Stewart 		/* message is complete */
452218e198d3SRandall Stewart 		if (stcb && (control == stcb->asoc.control_pdapi)) {
452318e198d3SRandall Stewart 			stcb->asoc.control_pdapi = NULL;
452418e198d3SRandall Stewart 		}
452518e198d3SRandall Stewart 		control->held_length = 0;
452618e198d3SRandall Stewart 		control->end_added = 1;
452718e198d3SRandall Stewart 	}
4528ad81507eSRandall Stewart 	if (stcb == NULL) {
4529ad81507eSRandall Stewart 		control->do_not_ref_stcb = 1;
4530ad81507eSRandall Stewart 	}
4531f8829a4aSRandall Stewart 	/*
4532f8829a4aSRandall Stewart 	 * When we are appending in partial delivery, the cum-ack is used
4533f8829a4aSRandall Stewart 	 * for the actual pd-api highest tsn on this mbuf. The true cum-ack
4534f8829a4aSRandall Stewart 	 * is populated in the outbound sinfo structure from the true cumack
4535f8829a4aSRandall Stewart 	 * if the association exists...
4536f8829a4aSRandall Stewart 	 */
4537f8829a4aSRandall Stewart 	control->sinfo_tsn = control->sinfo_cumtsn = ctls_cumack;
4538f8829a4aSRandall Stewart 	if (inp) {
4539f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
4540f8829a4aSRandall Stewart 	}
4541f8829a4aSRandall Stewart 	if (inp && inp->sctp_socket) {
454217205eccSRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_ZERO_COPY_ACTIVE)) {
454317205eccSRandall Stewart 			SCTP_ZERO_COPY_EVENT(inp, inp->sctp_socket);
4544ceaad40aSRandall Stewart 		} else {
4545ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4546ceaad40aSRandall Stewart 			struct socket *so;
4547ceaad40aSRandall Stewart 
4548ceaad40aSRandall Stewart 			so = SCTP_INP_SO(inp);
4549ceaad40aSRandall Stewart 			atomic_add_int(&stcb->asoc.refcnt, 1);
4550ceaad40aSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
4551ceaad40aSRandall Stewart 			SCTP_SOCKET_LOCK(so, 1);
4552ceaad40aSRandall Stewart 			SCTP_TCB_LOCK(stcb);
4553ceaad40aSRandall Stewart 			atomic_subtract_int(&stcb->asoc.refcnt, 1);
4554ceaad40aSRandall Stewart 			if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
4555ceaad40aSRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
4556ceaad40aSRandall Stewart 				return (0);
4557ceaad40aSRandall Stewart 			}
4558ceaad40aSRandall Stewart #endif
4559f8829a4aSRandall Stewart 			sctp_sorwakeup(inp, inp->sctp_socket);
4560ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4561ceaad40aSRandall Stewart 			SCTP_SOCKET_UNLOCK(so, 1);
4562ceaad40aSRandall Stewart #endif
4563ceaad40aSRandall Stewart 		}
4564f8829a4aSRandall Stewart 	}
4565f8829a4aSRandall Stewart 	return (0);
4566f8829a4aSRandall Stewart }
4567f8829a4aSRandall Stewart 
4568f8829a4aSRandall Stewart 
4569f8829a4aSRandall Stewart 
4570f8829a4aSRandall Stewart /*************HOLD THIS COMMENT FOR PATCH FILE OF
4571f8829a4aSRandall Stewart  *************ALTERNATE ROUTING CODE
4572f8829a4aSRandall Stewart  */
4573f8829a4aSRandall Stewart 
4574f8829a4aSRandall Stewart /*************HOLD THIS COMMENT FOR END OF PATCH FILE OF
4575f8829a4aSRandall Stewart  *************ALTERNATE ROUTING CODE
4576f8829a4aSRandall Stewart  */
4577f8829a4aSRandall Stewart 
4578f8829a4aSRandall Stewart struct mbuf *
4579f8829a4aSRandall Stewart sctp_generate_invmanparam(int err)
4580f8829a4aSRandall Stewart {
4581f8829a4aSRandall Stewart 	/* Return a MBUF with a invalid mandatory parameter */
4582f8829a4aSRandall Stewart 	struct mbuf *m;
4583f8829a4aSRandall Stewart 
4584f8829a4aSRandall Stewart 	m = sctp_get_mbuf_for_msg(sizeof(struct sctp_paramhdr), 0, M_DONTWAIT, 1, MT_DATA);
4585f8829a4aSRandall Stewart 	if (m) {
4586f8829a4aSRandall Stewart 		struct sctp_paramhdr *ph;
4587f8829a4aSRandall Stewart 
4588139bc87fSRandall Stewart 		SCTP_BUF_LEN(m) = sizeof(struct sctp_paramhdr);
4589f8829a4aSRandall Stewart 		ph = mtod(m, struct sctp_paramhdr *);
4590f8829a4aSRandall Stewart 		ph->param_length = htons(sizeof(struct sctp_paramhdr));
4591f8829a4aSRandall Stewart 		ph->param_type = htons(err);
4592f8829a4aSRandall Stewart 	}
4593f8829a4aSRandall Stewart 	return (m);
4594f8829a4aSRandall Stewart }
4595f8829a4aSRandall Stewart 
4596f8829a4aSRandall Stewart #ifdef SCTP_MBCNT_LOGGING
4597f8829a4aSRandall Stewart void
4598f8829a4aSRandall Stewart sctp_free_bufspace(struct sctp_tcb *stcb, struct sctp_association *asoc,
4599f8829a4aSRandall Stewart     struct sctp_tmit_chunk *tp1, int chk_cnt)
4600f8829a4aSRandall Stewart {
4601f8829a4aSRandall Stewart 	if (tp1->data == NULL) {
4602f8829a4aSRandall Stewart 		return;
4603f8829a4aSRandall Stewart 	}
4604f8829a4aSRandall Stewart 	asoc->chunks_on_out_queue -= chk_cnt;
4605b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_MBCNT_LOGGING_ENABLE) {
4606f8829a4aSRandall Stewart 		sctp_log_mbcnt(SCTP_LOG_MBCNT_DECREASE,
4607f8829a4aSRandall Stewart 		    asoc->total_output_queue_size,
4608f8829a4aSRandall Stewart 		    tp1->book_size,
4609f8829a4aSRandall Stewart 		    0,
4610f8829a4aSRandall Stewart 		    tp1->mbcnt);
461180fefe0aSRandall Stewart 	}
4612f8829a4aSRandall Stewart 	if (asoc->total_output_queue_size >= tp1->book_size) {
461344b7479bSRandall Stewart 		atomic_add_int(&asoc->total_output_queue_size, -tp1->book_size);
4614f8829a4aSRandall Stewart 	} else {
4615f8829a4aSRandall Stewart 		asoc->total_output_queue_size = 0;
4616f8829a4aSRandall Stewart 	}
4617f8829a4aSRandall Stewart 
4618f8829a4aSRandall Stewart 	if (stcb->sctp_socket && (((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) ||
4619f8829a4aSRandall Stewart 	    ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE)))) {
4620f8829a4aSRandall Stewart 		if (stcb->sctp_socket->so_snd.sb_cc >= tp1->book_size) {
4621f8829a4aSRandall Stewart 			stcb->sctp_socket->so_snd.sb_cc -= tp1->book_size;
4622f8829a4aSRandall Stewart 		} else {
4623f8829a4aSRandall Stewart 			stcb->sctp_socket->so_snd.sb_cc = 0;
4624f8829a4aSRandall Stewart 
4625f8829a4aSRandall Stewart 		}
4626f8829a4aSRandall Stewart 	}
4627f8829a4aSRandall Stewart }
4628f8829a4aSRandall Stewart 
4629f8829a4aSRandall Stewart #endif
4630f8829a4aSRandall Stewart 
4631f8829a4aSRandall Stewart int
4632f8829a4aSRandall Stewart sctp_release_pr_sctp_chunk(struct sctp_tcb *stcb, struct sctp_tmit_chunk *tp1,
4633ceaad40aSRandall Stewart     int reason, struct sctpchunk_listhead *queue, int so_locked
4634ceaad40aSRandall Stewart #if !defined(__APPLE__) && !defined(SCTP_SO_LOCK_TESTING)
4635ceaad40aSRandall Stewart     SCTP_UNUSED
4636ceaad40aSRandall Stewart #endif
4637ceaad40aSRandall Stewart )
4638f8829a4aSRandall Stewart {
4639f8829a4aSRandall Stewart 	int ret_sz = 0;
4640f8829a4aSRandall Stewart 	int notdone;
4641f8829a4aSRandall Stewart 	uint8_t foundeom = 0;
4642f8829a4aSRandall Stewart 
4643f8829a4aSRandall Stewart 	do {
4644f8829a4aSRandall Stewart 		ret_sz += tp1->book_size;
4645f8829a4aSRandall Stewart 		tp1->sent = SCTP_FORWARD_TSN_SKIP;
4646f8829a4aSRandall Stewart 		if (tp1->data) {
4647ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4648ceaad40aSRandall Stewart 			struct socket *so;
4649ceaad40aSRandall Stewart 
4650ceaad40aSRandall Stewart #endif
4651f8829a4aSRandall Stewart 			sctp_free_bufspace(stcb, &stcb->asoc, tp1, 1);
4652830d754dSRandall Stewart 			sctp_flight_size_decrease(tp1);
4653830d754dSRandall Stewart 			sctp_total_flight_decrease(stcb, tp1);
4654830d754dSRandall Stewart 			sctp_ulp_notify(SCTP_NOTIFY_DG_FAIL, stcb, reason, tp1, so_locked);
4655f8829a4aSRandall Stewart 			sctp_m_freem(tp1->data);
4656f8829a4aSRandall Stewart 			tp1->data = NULL;
4657ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4658ceaad40aSRandall Stewart 			so = SCTP_INP_SO(stcb->sctp_ep);
4659ceaad40aSRandall Stewart 			if (!so_locked) {
4660ceaad40aSRandall Stewart 				atomic_add_int(&stcb->asoc.refcnt, 1);
4661ceaad40aSRandall Stewart 				SCTP_TCB_UNLOCK(stcb);
4662ceaad40aSRandall Stewart 				SCTP_SOCKET_LOCK(so, 1);
4663ceaad40aSRandall Stewart 				SCTP_TCB_LOCK(stcb);
4664ceaad40aSRandall Stewart 				atomic_subtract_int(&stcb->asoc.refcnt, 1);
4665ceaad40aSRandall Stewart 				if (stcb->asoc.state & SCTP_STATE_CLOSED_SOCKET) {
4666ceaad40aSRandall Stewart 					/*
4667ceaad40aSRandall Stewart 					 * assoc was freed while we were
4668ceaad40aSRandall Stewart 					 * unlocked
4669ceaad40aSRandall Stewart 					 */
4670ceaad40aSRandall Stewart 					SCTP_SOCKET_UNLOCK(so, 1);
4671ceaad40aSRandall Stewart 					return (ret_sz);
4672ceaad40aSRandall Stewart 				}
4673ceaad40aSRandall Stewart 			}
4674ceaad40aSRandall Stewart #endif
4675f8829a4aSRandall Stewart 			sctp_sowwakeup(stcb->sctp_ep, stcb->sctp_socket);
4676ceaad40aSRandall Stewart #if defined (__APPLE__) || defined(SCTP_SO_LOCK_TESTING)
4677ceaad40aSRandall Stewart 			if (!so_locked) {
4678ceaad40aSRandall Stewart 				SCTP_SOCKET_UNLOCK(so, 1);
4679ceaad40aSRandall Stewart 			}
4680ceaad40aSRandall Stewart #endif
4681f8829a4aSRandall Stewart 		}
4682f8829a4aSRandall Stewart 		if (PR_SCTP_BUF_ENABLED(tp1->flags)) {
4683f8829a4aSRandall Stewart 			stcb->asoc.sent_queue_cnt_removeable--;
4684f8829a4aSRandall Stewart 		}
4685f8829a4aSRandall Stewart 		if (queue == &stcb->asoc.send_queue) {
4686f8829a4aSRandall Stewart 			TAILQ_REMOVE(&stcb->asoc.send_queue, tp1, sctp_next);
4687f8829a4aSRandall Stewart 			/* on to the sent queue */
4688f8829a4aSRandall Stewart 			TAILQ_INSERT_TAIL(&stcb->asoc.sent_queue, tp1,
4689f8829a4aSRandall Stewart 			    sctp_next);
4690f8829a4aSRandall Stewart 			stcb->asoc.sent_queue_cnt++;
4691f8829a4aSRandall Stewart 		}
4692f8829a4aSRandall Stewart 		if ((tp1->rec.data.rcv_flags & SCTP_DATA_NOT_FRAG) ==
4693f8829a4aSRandall Stewart 		    SCTP_DATA_NOT_FRAG) {
4694f8829a4aSRandall Stewart 			/* not frag'ed we ae done   */
4695f8829a4aSRandall Stewart 			notdone = 0;
4696f8829a4aSRandall Stewart 			foundeom = 1;
4697f8829a4aSRandall Stewart 		} else if (tp1->rec.data.rcv_flags & SCTP_DATA_LAST_FRAG) {
4698f8829a4aSRandall Stewart 			/* end of frag, we are done */
4699f8829a4aSRandall Stewart 			notdone = 0;
4700f8829a4aSRandall Stewart 			foundeom = 1;
4701f8829a4aSRandall Stewart 		} else {
4702f8829a4aSRandall Stewart 			/*
4703f8829a4aSRandall Stewart 			 * Its a begin or middle piece, we must mark all of
4704f8829a4aSRandall Stewart 			 * it
4705f8829a4aSRandall Stewart 			 */
4706f8829a4aSRandall Stewart 			notdone = 1;
4707f8829a4aSRandall Stewart 			tp1 = TAILQ_NEXT(tp1, sctp_next);
4708f8829a4aSRandall Stewart 		}
4709f8829a4aSRandall Stewart 	} while (tp1 && notdone);
4710f8829a4aSRandall Stewart 	if ((foundeom == 0) && (queue == &stcb->asoc.sent_queue)) {
4711f8829a4aSRandall Stewart 		/*
4712f8829a4aSRandall Stewart 		 * The multi-part message was scattered across the send and
4713f8829a4aSRandall Stewart 		 * sent queue.
4714f8829a4aSRandall Stewart 		 */
4715f8829a4aSRandall Stewart 		tp1 = TAILQ_FIRST(&stcb->asoc.send_queue);
4716f8829a4aSRandall Stewart 		/*
4717f8829a4aSRandall Stewart 		 * recurse throught the send_queue too, starting at the
4718f8829a4aSRandall Stewart 		 * beginning.
4719f8829a4aSRandall Stewart 		 */
4720f8829a4aSRandall Stewart 		if (tp1) {
4721f8829a4aSRandall Stewart 			ret_sz += sctp_release_pr_sctp_chunk(stcb, tp1, reason,
4722ceaad40aSRandall Stewart 			    &stcb->asoc.send_queue, so_locked);
4723f8829a4aSRandall Stewart 		} else {
4724ad81507eSRandall Stewart 			SCTP_PRINTF("hmm, nothing on the send queue and no EOM?\n");
4725f8829a4aSRandall Stewart 		}
4726f8829a4aSRandall Stewart 	}
4727f8829a4aSRandall Stewart 	return (ret_sz);
4728f8829a4aSRandall Stewart }
4729f8829a4aSRandall Stewart 
4730f8829a4aSRandall Stewart /*
4731f8829a4aSRandall Stewart  * checks to see if the given address, sa, is one that is currently known by
4732f8829a4aSRandall Stewart  * the kernel note: can't distinguish the same address on multiple interfaces
4733f8829a4aSRandall Stewart  * and doesn't handle multiple addresses with different zone/scope id's note:
4734f8829a4aSRandall Stewart  * ifa_ifwithaddr() compares the entire sockaddr struct
4735f8829a4aSRandall Stewart  */
473642551e99SRandall Stewart struct sctp_ifa *
473780fefe0aSRandall Stewart sctp_find_ifa_in_ep(struct sctp_inpcb *inp, struct sockaddr *addr,
473880fefe0aSRandall Stewart     int holds_lock)
4739f8829a4aSRandall Stewart {
474042551e99SRandall Stewart 	struct sctp_laddr *laddr;
4741f8829a4aSRandall Stewart 
4742ad81507eSRandall Stewart 	if (holds_lock == 0) {
474342551e99SRandall Stewart 		SCTP_INP_RLOCK(inp);
4744ad81507eSRandall Stewart 	}
474542551e99SRandall Stewart 	LIST_FOREACH(laddr, &inp->sctp_addr_list, sctp_nxt_addr) {
474642551e99SRandall Stewart 		if (laddr->ifa == NULL)
4747f8829a4aSRandall Stewart 			continue;
474842551e99SRandall Stewart 		if (addr->sa_family != laddr->ifa->address.sa.sa_family)
474942551e99SRandall Stewart 			continue;
475042551e99SRandall Stewart 		if (addr->sa_family == AF_INET) {
475142551e99SRandall Stewart 			if (((struct sockaddr_in *)addr)->sin_addr.s_addr ==
475242551e99SRandall Stewart 			    laddr->ifa->address.sin.sin_addr.s_addr) {
475342551e99SRandall Stewart 				/* found him. */
4754ad81507eSRandall Stewart 				if (holds_lock == 0) {
475542551e99SRandall Stewart 					SCTP_INP_RUNLOCK(inp);
4756ad81507eSRandall Stewart 				}
475742551e99SRandall Stewart 				return (laddr->ifa);
475842551e99SRandall Stewart 				break;
475942551e99SRandall Stewart 			}
47605e2c2d87SRandall Stewart 		}
47615e2c2d87SRandall Stewart #ifdef INET6
47625e2c2d87SRandall Stewart 		if (addr->sa_family == AF_INET6) {
4763c54a18d2SRandall Stewart 			if (SCTP6_ARE_ADDR_EQUAL((struct sockaddr_in6 *)addr,
4764c54a18d2SRandall Stewart 			    &laddr->ifa->address.sin6)) {
476542551e99SRandall Stewart 				/* found him. */
4766ad81507eSRandall Stewart 				if (holds_lock == 0) {
476742551e99SRandall Stewart 					SCTP_INP_RUNLOCK(inp);
4768ad81507eSRandall Stewart 				}
476942551e99SRandall Stewart 				return (laddr->ifa);
477042551e99SRandall Stewart 				break;
477142551e99SRandall Stewart 			}
477242551e99SRandall Stewart 		}
47735e2c2d87SRandall Stewart #endif
477442551e99SRandall Stewart 	}
4775ad81507eSRandall Stewart 	if (holds_lock == 0) {
477642551e99SRandall Stewart 		SCTP_INP_RUNLOCK(inp);
4777ad81507eSRandall Stewart 	}
477842551e99SRandall Stewart 	return (NULL);
477942551e99SRandall Stewart }
4780f8829a4aSRandall Stewart 
47816a27c376SRandall Stewart uint32_t
47826a27c376SRandall Stewart sctp_get_ifa_hash_val(struct sockaddr *addr)
47836a27c376SRandall Stewart {
47846a27c376SRandall Stewart 	if (addr->sa_family == AF_INET) {
47856a27c376SRandall Stewart 		struct sockaddr_in *sin;
47866a27c376SRandall Stewart 
47876a27c376SRandall Stewart 		sin = (struct sockaddr_in *)addr;
47886a27c376SRandall Stewart 		return (sin->sin_addr.s_addr ^ (sin->sin_addr.s_addr >> 16));
47896a27c376SRandall Stewart 	} else if (addr->sa_family == AF_INET6) {
47906a27c376SRandall Stewart 		struct sockaddr_in6 *sin6;
47916a27c376SRandall Stewart 		uint32_t hash_of_addr;
47926a27c376SRandall Stewart 
47936a27c376SRandall Stewart 		sin6 = (struct sockaddr_in6 *)addr;
47946a27c376SRandall Stewart 		hash_of_addr = (sin6->sin6_addr.s6_addr32[0] +
47956a27c376SRandall Stewart 		    sin6->sin6_addr.s6_addr32[1] +
47966a27c376SRandall Stewart 		    sin6->sin6_addr.s6_addr32[2] +
47976a27c376SRandall Stewart 		    sin6->sin6_addr.s6_addr32[3]);
47986a27c376SRandall Stewart 		hash_of_addr = (hash_of_addr ^ (hash_of_addr >> 16));
47996a27c376SRandall Stewart 		return (hash_of_addr);
48006a27c376SRandall Stewart 	}
48016a27c376SRandall Stewart 	return (0);
48026a27c376SRandall Stewart }
48036a27c376SRandall Stewart 
480442551e99SRandall Stewart struct sctp_ifa *
480542551e99SRandall Stewart sctp_find_ifa_by_addr(struct sockaddr *addr, uint32_t vrf_id, int holds_lock)
480642551e99SRandall Stewart {
480742551e99SRandall Stewart 	struct sctp_ifa *sctp_ifap;
480842551e99SRandall Stewart 	struct sctp_vrf *vrf;
48096a27c376SRandall Stewart 	struct sctp_ifalist *hash_head;
48106a27c376SRandall Stewart 	uint32_t hash_of_addr;
481142551e99SRandall Stewart 
481242551e99SRandall Stewart 	if (holds_lock == 0)
4813c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RLOCK();
481442551e99SRandall Stewart 
4815bff64a4dSRandall Stewart 	vrf = sctp_find_vrf(vrf_id);
4816bff64a4dSRandall Stewart 	if (vrf == NULL) {
4817df6e0cc3SRandall Stewart stage_right:
4818bff64a4dSRandall Stewart 		if (holds_lock == 0)
4819c99efcf6SRandall Stewart 			SCTP_IPI_ADDR_RUNLOCK();
4820bff64a4dSRandall Stewart 		return (NULL);
4821bff64a4dSRandall Stewart 	}
4822bff64a4dSRandall Stewart 	hash_of_addr = sctp_get_ifa_hash_val(addr);
4823bff64a4dSRandall Stewart 
482417205eccSRandall Stewart 	hash_head = &vrf->vrf_addr_hash[(hash_of_addr & vrf->vrf_addr_hashmark)];
4825bff64a4dSRandall Stewart 	if (hash_head == NULL) {
4826ad81507eSRandall Stewart 		SCTP_PRINTF("hash_of_addr:%x mask:%x table:%x - ",
4827c99efcf6SRandall Stewart 		    hash_of_addr, (uint32_t) vrf->vrf_addr_hashmark,
4828c99efcf6SRandall Stewart 		    (uint32_t) (hash_of_addr & vrf->vrf_addr_hashmark));
4829bff64a4dSRandall Stewart 		sctp_print_address(addr);
4830ad81507eSRandall Stewart 		SCTP_PRINTF("No such bucket for address\n");
4831bff64a4dSRandall Stewart 		if (holds_lock == 0)
4832c99efcf6SRandall Stewart 			SCTP_IPI_ADDR_RUNLOCK();
4833bff64a4dSRandall Stewart 
4834bff64a4dSRandall Stewart 		return (NULL);
4835bff64a4dSRandall Stewart 	}
48366a27c376SRandall Stewart 	LIST_FOREACH(sctp_ifap, hash_head, next_bucket) {
4837bff64a4dSRandall Stewart 		if (sctp_ifap == NULL) {
4838df6e0cc3SRandall Stewart #ifdef INVARIANTS
4839bff64a4dSRandall Stewart 			panic("Huh LIST_FOREACH corrupt");
4840df6e0cc3SRandall Stewart 			goto stage_right;
4841df6e0cc3SRandall Stewart #else
4842df6e0cc3SRandall Stewart 			SCTP_PRINTF("LIST corrupt of sctp_ifap's?\n");
4843df6e0cc3SRandall Stewart 			goto stage_right;
4844df6e0cc3SRandall Stewart #endif
4845bff64a4dSRandall Stewart 		}
48466a27c376SRandall Stewart 		if (addr->sa_family != sctp_ifap->address.sa.sa_family)
48476a27c376SRandall Stewart 			continue;
48486a27c376SRandall Stewart 		if (addr->sa_family == AF_INET) {
48496a27c376SRandall Stewart 			if (((struct sockaddr_in *)addr)->sin_addr.s_addr ==
48506a27c376SRandall Stewart 			    sctp_ifap->address.sin.sin_addr.s_addr) {
48516a27c376SRandall Stewart 				/* found him. */
485242551e99SRandall Stewart 				if (holds_lock == 0)
4853c99efcf6SRandall Stewart 					SCTP_IPI_ADDR_RUNLOCK();
485442551e99SRandall Stewart 				return (sctp_ifap);
48556a27c376SRandall Stewart 				break;
48566a27c376SRandall Stewart 			}
48575e2c2d87SRandall Stewart 		}
48585e2c2d87SRandall Stewart #ifdef INET6
48595e2c2d87SRandall Stewart 		if (addr->sa_family == AF_INET6) {
4860c54a18d2SRandall Stewart 			if (SCTP6_ARE_ADDR_EQUAL((struct sockaddr_in6 *)addr,
4861c54a18d2SRandall Stewart 			    &sctp_ifap->address.sin6)) {
48626a27c376SRandall Stewart 				/* found him. */
48636a27c376SRandall Stewart 				if (holds_lock == 0)
4864c99efcf6SRandall Stewart 					SCTP_IPI_ADDR_RUNLOCK();
48656a27c376SRandall Stewart 				return (sctp_ifap);
48666a27c376SRandall Stewart 				break;
48676a27c376SRandall Stewart 			}
486842551e99SRandall Stewart 		}
48695e2c2d87SRandall Stewart #endif
487042551e99SRandall Stewart 	}
487142551e99SRandall Stewart 	if (holds_lock == 0)
4872c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RUNLOCK();
4873f8829a4aSRandall Stewart 	return (NULL);
4874f8829a4aSRandall Stewart }
4875f8829a4aSRandall Stewart 
4876f8829a4aSRandall Stewart static void
48774c9179adSRandall Stewart sctp_user_rcvd(struct sctp_tcb *stcb, uint32_t * freed_so_far, int hold_rlock,
4878f8829a4aSRandall Stewart     uint32_t rwnd_req)
4879f8829a4aSRandall Stewart {
4880f8829a4aSRandall Stewart 	/* User pulled some data, do we need a rwnd update? */
4881f8829a4aSRandall Stewart 	int r_unlocked = 0;
4882f8829a4aSRandall Stewart 	uint32_t dif, rwnd;
4883f8829a4aSRandall Stewart 	struct socket *so = NULL;
4884f8829a4aSRandall Stewart 
4885f8829a4aSRandall Stewart 	if (stcb == NULL)
4886f8829a4aSRandall Stewart 		return;
4887f8829a4aSRandall Stewart 
488850cec919SRandall Stewart 	atomic_add_int(&stcb->asoc.refcnt, 1);
4889f8829a4aSRandall Stewart 
489062c1ff9cSRandall Stewart 	if (stcb->asoc.state & (SCTP_STATE_ABOUT_TO_BE_FREED |
489162c1ff9cSRandall Stewart 	    SCTP_STATE_SHUTDOWN_RECEIVED |
48924c9179adSRandall Stewart 	    SCTP_STATE_SHUTDOWN_ACK_SENT)) {
4893f8829a4aSRandall Stewart 		/* Pre-check If we are freeing no update */
4894f8829a4aSRandall Stewart 		goto no_lock;
4895f8829a4aSRandall Stewart 	}
4896f8829a4aSRandall Stewart 	SCTP_INP_INCR_REF(stcb->sctp_ep);
4897f8829a4aSRandall Stewart 	if ((stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
4898f8829a4aSRandall Stewart 	    (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE)) {
4899f8829a4aSRandall Stewart 		goto out;
4900f8829a4aSRandall Stewart 	}
4901f8829a4aSRandall Stewart 	so = stcb->sctp_socket;
4902f8829a4aSRandall Stewart 	if (so == NULL) {
4903f8829a4aSRandall Stewart 		goto out;
4904f8829a4aSRandall Stewart 	}
4905f8829a4aSRandall Stewart 	atomic_add_int(&stcb->freed_by_sorcv_sincelast, *freed_so_far);
4906f8829a4aSRandall Stewart 	/* Have you have freed enough to look */
4907f8829a4aSRandall Stewart 	*freed_so_far = 0;
4908f8829a4aSRandall Stewart 	/* Yep, its worth a look and the lock overhead */
4909f8829a4aSRandall Stewart 
4910f8829a4aSRandall Stewart 	/* Figure out what the rwnd would be */
4911f8829a4aSRandall Stewart 	rwnd = sctp_calc_rwnd(stcb, &stcb->asoc);
4912f8829a4aSRandall Stewart 	if (rwnd >= stcb->asoc.my_last_reported_rwnd) {
4913f8829a4aSRandall Stewart 		dif = rwnd - stcb->asoc.my_last_reported_rwnd;
4914f8829a4aSRandall Stewart 	} else {
4915f8829a4aSRandall Stewart 		dif = 0;
4916f8829a4aSRandall Stewart 	}
4917f8829a4aSRandall Stewart 	if (dif >= rwnd_req) {
4918f8829a4aSRandall Stewart 		if (hold_rlock) {
4919f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(stcb->sctp_ep);
4920f8829a4aSRandall Stewart 			r_unlocked = 1;
4921f8829a4aSRandall Stewart 		}
4922f8829a4aSRandall Stewart 		if (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
4923f8829a4aSRandall Stewart 			/*
4924f8829a4aSRandall Stewart 			 * One last check before we allow the guy possibly
4925f8829a4aSRandall Stewart 			 * to get in. There is a race, where the guy has not
4926f8829a4aSRandall Stewart 			 * reached the gate. In that case
4927f8829a4aSRandall Stewart 			 */
4928f8829a4aSRandall Stewart 			goto out;
4929f8829a4aSRandall Stewart 		}
4930f8829a4aSRandall Stewart 		SCTP_TCB_LOCK(stcb);
4931f8829a4aSRandall Stewart 		if (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
4932f8829a4aSRandall Stewart 			/* No reports here */
4933f8829a4aSRandall Stewart 			SCTP_TCB_UNLOCK(stcb);
4934f8829a4aSRandall Stewart 			goto out;
4935f8829a4aSRandall Stewart 		}
4936f8829a4aSRandall Stewart 		SCTP_STAT_INCR(sctps_wu_sacks_sent);
4937830d754dSRandall Stewart 		/*
4938830d754dSRandall Stewart 		 * EY if nr_sacks used then send an nr-sack , a sack
4939830d754dSRandall Stewart 		 * otherwise
4940830d754dSRandall Stewart 		 */
4941830d754dSRandall Stewart 		if (SCTP_BASE_SYSCTL(sctp_nr_sack_on_off) && stcb->asoc.peer_supports_nr_sack)
4942830d754dSRandall Stewart 			sctp_send_nr_sack(stcb);
4943830d754dSRandall Stewart 		else
4944f8829a4aSRandall Stewart 			sctp_send_sack(stcb);
4945830d754dSRandall Stewart 
4946f8829a4aSRandall Stewart 		sctp_chunk_output(stcb->sctp_ep, stcb,
4947ceaad40aSRandall Stewart 		    SCTP_OUTPUT_FROM_USR_RCVD, SCTP_SO_LOCKED);
4948f8829a4aSRandall Stewart 		/* make sure no timer is running */
4949a5d547adSRandall Stewart 		sctp_timer_stop(SCTP_TIMER_TYPE_RECV, stcb->sctp_ep, stcb, NULL, SCTP_FROM_SCTPUTIL + SCTP_LOC_6);
4950f8829a4aSRandall Stewart 		SCTP_TCB_UNLOCK(stcb);
4951f8829a4aSRandall Stewart 	} else {
4952f8829a4aSRandall Stewart 		/* Update how much we have pending */
4953f8829a4aSRandall Stewart 		stcb->freed_by_sorcv_sincelast = dif;
4954f8829a4aSRandall Stewart 	}
4955f8829a4aSRandall Stewart out:
4956f8829a4aSRandall Stewart 	if (so && r_unlocked && hold_rlock) {
4957f8829a4aSRandall Stewart 		SCTP_INP_READ_LOCK(stcb->sctp_ep);
4958f8829a4aSRandall Stewart 	}
4959f8829a4aSRandall Stewart 	SCTP_INP_DECR_REF(stcb->sctp_ep);
4960f8829a4aSRandall Stewart no_lock:
496150cec919SRandall Stewart 	atomic_add_int(&stcb->asoc.refcnt, -1);
4962f8829a4aSRandall Stewart 	return;
4963f8829a4aSRandall Stewart }
4964f8829a4aSRandall Stewart 
4965f8829a4aSRandall Stewart int
4966f8829a4aSRandall Stewart sctp_sorecvmsg(struct socket *so,
4967f8829a4aSRandall Stewart     struct uio *uio,
4968f8829a4aSRandall Stewart     struct mbuf **mp,
4969f8829a4aSRandall Stewart     struct sockaddr *from,
4970f8829a4aSRandall Stewart     int fromlen,
4971f8829a4aSRandall Stewart     int *msg_flags,
4972f8829a4aSRandall Stewart     struct sctp_sndrcvinfo *sinfo,
4973f8829a4aSRandall Stewart     int filling_sinfo)
4974f8829a4aSRandall Stewart {
4975f8829a4aSRandall Stewart 	/*
4976f8829a4aSRandall Stewart 	 * MSG flags we will look at MSG_DONTWAIT - non-blocking IO.
4977f8829a4aSRandall Stewart 	 * MSG_PEEK - Look don't touch :-D (only valid with OUT mbuf copy
4978f8829a4aSRandall Stewart 	 * mp=NULL thus uio is the copy method to userland) MSG_WAITALL - ??
4979f8829a4aSRandall Stewart 	 * On the way out we may send out any combination of:
4980f8829a4aSRandall Stewart 	 * MSG_NOTIFICATION MSG_EOR
4981f8829a4aSRandall Stewart 	 *
4982f8829a4aSRandall Stewart 	 */
4983f8829a4aSRandall Stewart 	struct sctp_inpcb *inp = NULL;
4984f8829a4aSRandall Stewart 	int my_len = 0;
4985f8829a4aSRandall Stewart 	int cp_len = 0, error = 0;
4986f8829a4aSRandall Stewart 	struct sctp_queued_to_read *control = NULL, *ctl = NULL, *nxt = NULL;
4987f8829a4aSRandall Stewart 	struct mbuf *m = NULL, *embuf = NULL;
4988f8829a4aSRandall Stewart 	struct sctp_tcb *stcb = NULL;
4989f8829a4aSRandall Stewart 	int wakeup_read_socket = 0;
4990f8829a4aSRandall Stewart 	int freecnt_applied = 0;
4991f8829a4aSRandall Stewart 	int out_flags = 0, in_flags = 0;
4992f8829a4aSRandall Stewart 	int block_allowed = 1;
49934c9179adSRandall Stewart 	uint32_t freed_so_far = 0;
499481aca91aSRandall Stewart 	uint32_t copied_so_far = 0;
499593164cf9SRandall Stewart 	int in_eeor_mode = 0;
4996f8829a4aSRandall Stewart 	int no_rcv_needed = 0;
4997f8829a4aSRandall Stewart 	uint32_t rwnd_req = 0;
4998f8829a4aSRandall Stewart 	int hold_sblock = 0;
4999f8829a4aSRandall Stewart 	int hold_rlock = 0;
500042551e99SRandall Stewart 	int slen = 0;
50014c9179adSRandall Stewart 	uint32_t held_length = 0;
50027abab911SRobert Watson 	int sockbuf_lock = 0;
5003f8829a4aSRandall Stewart 
500417205eccSRandall Stewart 	if (uio == NULL) {
5005c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
500617205eccSRandall Stewart 		return (EINVAL);
500717205eccSRandall Stewart 	}
5008f8829a4aSRandall Stewart 	if (msg_flags) {
5009f8829a4aSRandall Stewart 		in_flags = *msg_flags;
5010c105859eSRandall Stewart 		if (in_flags & MSG_PEEK)
5011c105859eSRandall Stewart 			SCTP_STAT_INCR(sctps_read_peeks);
5012f8829a4aSRandall Stewart 	} else {
5013f8829a4aSRandall Stewart 		in_flags = 0;
5014f8829a4aSRandall Stewart 	}
5015f8829a4aSRandall Stewart 	slen = uio->uio_resid;
501617205eccSRandall Stewart 
5017f8829a4aSRandall Stewart 	/* Pull in and set up our int flags */
5018f8829a4aSRandall Stewart 	if (in_flags & MSG_OOB) {
5019f8829a4aSRandall Stewart 		/* Out of band's NOT supported */
5020f8829a4aSRandall Stewart 		return (EOPNOTSUPP);
5021f8829a4aSRandall Stewart 	}
5022f8829a4aSRandall Stewart 	if ((in_flags & MSG_PEEK) && (mp != NULL)) {
5023c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
5024f8829a4aSRandall Stewart 		return (EINVAL);
5025f8829a4aSRandall Stewart 	}
5026f8829a4aSRandall Stewart 	if ((in_flags & (MSG_DONTWAIT
5027f8829a4aSRandall Stewart 	    | MSG_NBIO
5028f8829a4aSRandall Stewart 	    )) ||
502942551e99SRandall Stewart 	    SCTP_SO_IS_NBIO(so)) {
5030f8829a4aSRandall Stewart 		block_allowed = 0;
5031f8829a4aSRandall Stewart 	}
5032f8829a4aSRandall Stewart 	/* setup the endpoint */
5033f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)so->so_pcb;
5034f8829a4aSRandall Stewart 	if (inp == NULL) {
5035c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EFAULT);
5036f8829a4aSRandall Stewart 		return (EFAULT);
5037f8829a4aSRandall Stewart 	}
503862c1ff9cSRandall Stewart 	rwnd_req = (SCTP_SB_LIMIT_RCV(so) >> SCTP_RWND_HIWAT_SHIFT);
5039f8829a4aSRandall Stewart 	/* Must be at least a MTU's worth */
5040f8829a4aSRandall Stewart 	if (rwnd_req < SCTP_MIN_RWND)
5041f8829a4aSRandall Stewart 		rwnd_req = SCTP_MIN_RWND;
5042f8829a4aSRandall Stewart 	in_eeor_mode = sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXPLICIT_EOR);
5043b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
5044f8829a4aSRandall Stewart 		sctp_misc_ints(SCTP_SORECV_ENTER,
504517205eccSRandall Stewart 		    rwnd_req, in_eeor_mode, so->so_rcv.sb_cc, uio->uio_resid);
504680fefe0aSRandall Stewart 	}
5047b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
5048f8829a4aSRandall Stewart 		sctp_misc_ints(SCTP_SORECV_ENTERPL,
504917205eccSRandall Stewart 		    rwnd_req, block_allowed, so->so_rcv.sb_cc, uio->uio_resid);
505080fefe0aSRandall Stewart 	}
5051265de5bbSRobert Watson 	error = sblock(&so->so_rcv, (block_allowed ? SBL_WAIT : 0));
50527abab911SRobert Watson 	sockbuf_lock = 1;
5053f8829a4aSRandall Stewart 	if (error) {
5054f8829a4aSRandall Stewart 		goto release_unlocked;
5055f8829a4aSRandall Stewart 	}
5056f8829a4aSRandall Stewart restart:
50577abab911SRobert Watson 
5058f8829a4aSRandall Stewart 
5059f8829a4aSRandall Stewart restart_nosblocks:
5060f8829a4aSRandall Stewart 	if (hold_sblock == 0) {
5061f8829a4aSRandall Stewart 		SOCKBUF_LOCK(&so->so_rcv);
5062f8829a4aSRandall Stewart 		hold_sblock = 1;
5063f8829a4aSRandall Stewart 	}
5064f8829a4aSRandall Stewart 	if ((inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) ||
5065f8829a4aSRandall Stewart 	    (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE)) {
5066f8829a4aSRandall Stewart 		goto out;
5067f8829a4aSRandall Stewart 	}
506844b7479bSRandall Stewart 	if (so->so_rcv.sb_state & SBS_CANTRCVMORE) {
5069f8829a4aSRandall Stewart 		if (so->so_error) {
5070f8829a4aSRandall Stewart 			error = so->so_error;
507144b7479bSRandall Stewart 			if ((in_flags & MSG_PEEK) == 0)
507244b7479bSRandall Stewart 				so->so_error = 0;
50739f22f500SRandall Stewart 			goto out;
5074f8829a4aSRandall Stewart 		} else {
50759f22f500SRandall Stewart 			if (so->so_rcv.sb_cc == 0) {
5076c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOTCONN);
50777924093fSRandall Stewart 				/* indicate EOF */
50787924093fSRandall Stewart 				error = 0;
5079f8829a4aSRandall Stewart 				goto out;
5080f8829a4aSRandall Stewart 			}
50819f22f500SRandall Stewart 		}
50829f22f500SRandall Stewart 	}
5083f8829a4aSRandall Stewart 	if ((so->so_rcv.sb_cc <= held_length) && block_allowed) {
5084f8829a4aSRandall Stewart 		/* we need to wait for data */
5085f8829a4aSRandall Stewart 		if ((so->so_rcv.sb_cc == 0) &&
5086f8829a4aSRandall Stewart 		    ((inp->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
5087f8829a4aSRandall Stewart 		    (inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL))) {
5088f8829a4aSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_CONNECTED) == 0) {
5089f8829a4aSRandall Stewart 				/*
5090f8829a4aSRandall Stewart 				 * For active open side clear flags for
5091f8829a4aSRandall Stewart 				 * re-use passive open is blocked by
5092f8829a4aSRandall Stewart 				 * connect.
5093f8829a4aSRandall Stewart 				 */
5094f8829a4aSRandall Stewart 				if (inp->sctp_flags & SCTP_PCB_FLAGS_WAS_ABORTED) {
5095f8829a4aSRandall Stewart 					/*
5096f8829a4aSRandall Stewart 					 * You were aborted, passive side
5097f8829a4aSRandall Stewart 					 * always hits here
5098f8829a4aSRandall Stewart 					 */
5099c4739e2fSRandall Stewart 					SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ECONNRESET);
5100f8829a4aSRandall Stewart 					error = ECONNRESET;
5101f8829a4aSRandall Stewart 					/*
5102f8829a4aSRandall Stewart 					 * You get this once if you are
5103f8829a4aSRandall Stewart 					 * active open side
5104f8829a4aSRandall Stewart 					 */
5105f8829a4aSRandall Stewart 					if (!(inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
5106f8829a4aSRandall Stewart 						/*
5107f8829a4aSRandall Stewart 						 * Remove flag if on the
5108f8829a4aSRandall Stewart 						 * active open side
5109f8829a4aSRandall Stewart 						 */
5110f8829a4aSRandall Stewart 						inp->sctp_flags &= ~SCTP_PCB_FLAGS_WAS_ABORTED;
5111f8829a4aSRandall Stewart 					}
5112f8829a4aSRandall Stewart 				}
5113f8829a4aSRandall Stewart 				so->so_state &= ~(SS_ISCONNECTING |
5114f8829a4aSRandall Stewart 				    SS_ISDISCONNECTING |
5115f8829a4aSRandall Stewart 				    SS_ISCONFIRMING |
5116f8829a4aSRandall Stewart 				    SS_ISCONNECTED);
5117f8829a4aSRandall Stewart 				if (error == 0) {
5118f8829a4aSRandall Stewart 					if ((inp->sctp_flags & SCTP_PCB_FLAGS_WAS_CONNECTED) == 0) {
5119c4739e2fSRandall Stewart 						SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOTCONN);
5120f8829a4aSRandall Stewart 						error = ENOTCONN;
5121f8829a4aSRandall Stewart 					} else {
5122f8829a4aSRandall Stewart 						inp->sctp_flags &= ~SCTP_PCB_FLAGS_WAS_CONNECTED;
5123f8829a4aSRandall Stewart 					}
5124f8829a4aSRandall Stewart 				}
5125f8829a4aSRandall Stewart 				goto out;
5126f8829a4aSRandall Stewart 			}
5127f8829a4aSRandall Stewart 		}
5128f8829a4aSRandall Stewart 		error = sbwait(&so->so_rcv);
5129f8829a4aSRandall Stewart 		if (error) {
5130f8829a4aSRandall Stewart 			goto out;
5131f8829a4aSRandall Stewart 		}
5132f8829a4aSRandall Stewart 		held_length = 0;
5133f8829a4aSRandall Stewart 		goto restart_nosblocks;
5134f8829a4aSRandall Stewart 	} else if (so->so_rcv.sb_cc == 0) {
513544b7479bSRandall Stewart 		if (so->so_error) {
513644b7479bSRandall Stewart 			error = so->so_error;
513744b7479bSRandall Stewart 			if ((in_flags & MSG_PEEK) == 0)
513844b7479bSRandall Stewart 				so->so_error = 0;
513944b7479bSRandall Stewart 		} else {
514044b7479bSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
514144b7479bSRandall Stewart 			    (inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
514244b7479bSRandall Stewart 				if ((inp->sctp_flags & SCTP_PCB_FLAGS_CONNECTED) == 0) {
514344b7479bSRandall Stewart 					/*
514444b7479bSRandall Stewart 					 * For active open side clear flags
514544b7479bSRandall Stewart 					 * for re-use passive open is
514644b7479bSRandall Stewart 					 * blocked by connect.
514744b7479bSRandall Stewart 					 */
514844b7479bSRandall Stewart 					if (inp->sctp_flags & SCTP_PCB_FLAGS_WAS_ABORTED) {
514944b7479bSRandall Stewart 						/*
515044b7479bSRandall Stewart 						 * You were aborted, passive
515144b7479bSRandall Stewart 						 * side always hits here
515244b7479bSRandall Stewart 						 */
5153c4739e2fSRandall Stewart 						SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ECONNRESET);
515444b7479bSRandall Stewart 						error = ECONNRESET;
515544b7479bSRandall Stewart 						/*
515644b7479bSRandall Stewart 						 * You get this once if you
515744b7479bSRandall Stewart 						 * are active open side
515844b7479bSRandall Stewart 						 */
515944b7479bSRandall Stewart 						if (!(inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
516044b7479bSRandall Stewart 							/*
516144b7479bSRandall Stewart 							 * Remove flag if on
516244b7479bSRandall Stewart 							 * the active open
516344b7479bSRandall Stewart 							 * side
516444b7479bSRandall Stewart 							 */
516544b7479bSRandall Stewart 							inp->sctp_flags &= ~SCTP_PCB_FLAGS_WAS_ABORTED;
516644b7479bSRandall Stewart 						}
516744b7479bSRandall Stewart 					}
516844b7479bSRandall Stewart 					so->so_state &= ~(SS_ISCONNECTING |
516944b7479bSRandall Stewart 					    SS_ISDISCONNECTING |
517044b7479bSRandall Stewart 					    SS_ISCONFIRMING |
517144b7479bSRandall Stewart 					    SS_ISCONNECTED);
517244b7479bSRandall Stewart 					if (error == 0) {
517344b7479bSRandall Stewart 						if ((inp->sctp_flags & SCTP_PCB_FLAGS_WAS_CONNECTED) == 0) {
5174c4739e2fSRandall Stewart 							SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOTCONN);
517544b7479bSRandall Stewart 							error = ENOTCONN;
517644b7479bSRandall Stewart 						} else {
517744b7479bSRandall Stewart 							inp->sctp_flags &= ~SCTP_PCB_FLAGS_WAS_CONNECTED;
517844b7479bSRandall Stewart 						}
517944b7479bSRandall Stewart 					}
518044b7479bSRandall Stewart 					goto out;
518144b7479bSRandall Stewart 				}
518244b7479bSRandall Stewart 			}
5183c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EWOULDBLOCK);
5184f8829a4aSRandall Stewart 			error = EWOULDBLOCK;
518544b7479bSRandall Stewart 		}
5186f8829a4aSRandall Stewart 		goto out;
5187f8829a4aSRandall Stewart 	}
5188d06c82f1SRandall Stewart 	if (hold_sblock == 1) {
5189d06c82f1SRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
5190d06c82f1SRandall Stewart 		hold_sblock = 0;
5191d06c82f1SRandall Stewart 	}
5192f8829a4aSRandall Stewart 	/* we possibly have data we can read */
51933c503c28SRandall Stewart 	/* sa_ignore FREED_MEMORY */
5194f8829a4aSRandall Stewart 	control = TAILQ_FIRST(&inp->read_queue);
5195f8829a4aSRandall Stewart 	if (control == NULL) {
5196f8829a4aSRandall Stewart 		/*
5197f8829a4aSRandall Stewart 		 * This could be happening since the appender did the
5198f8829a4aSRandall Stewart 		 * increment but as not yet did the tailq insert onto the
5199f8829a4aSRandall Stewart 		 * read_queue
5200f8829a4aSRandall Stewart 		 */
5201f8829a4aSRandall Stewart 		if (hold_rlock == 0) {
5202f8829a4aSRandall Stewart 			SCTP_INP_READ_LOCK(inp);
5203f8829a4aSRandall Stewart 			hold_rlock = 1;
5204f8829a4aSRandall Stewart 		}
5205f8829a4aSRandall Stewart 		control = TAILQ_FIRST(&inp->read_queue);
5206f8829a4aSRandall Stewart 		if ((control == NULL) && (so->so_rcv.sb_cc != 0)) {
5207a5d547adSRandall Stewart #ifdef INVARIANTS
5208f8829a4aSRandall Stewart 			panic("Huh, its non zero and nothing on control?");
5209f8829a4aSRandall Stewart #endif
5210f8829a4aSRandall Stewart 			so->so_rcv.sb_cc = 0;
5211f8829a4aSRandall Stewart 		}
5212f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
5213f8829a4aSRandall Stewart 		hold_rlock = 0;
5214f8829a4aSRandall Stewart 		goto restart;
5215f8829a4aSRandall Stewart 	}
5216f8829a4aSRandall Stewart 	if ((control->length == 0) &&
5217f8829a4aSRandall Stewart 	    (control->do_not_ref_stcb)) {
5218f8829a4aSRandall Stewart 		/*
5219f8829a4aSRandall Stewart 		 * Clean up code for freeing assoc that left behind a
5220f8829a4aSRandall Stewart 		 * pdapi.. maybe a peer in EEOR that just closed after
5221f8829a4aSRandall Stewart 		 * sending and never indicated a EOR.
5222f8829a4aSRandall Stewart 		 */
5223f8829a4aSRandall Stewart 		if (hold_rlock == 0) {
5224f8829a4aSRandall Stewart 			hold_rlock = 1;
5225f8829a4aSRandall Stewart 			SCTP_INP_READ_LOCK(inp);
5226f8829a4aSRandall Stewart 		}
5227f8829a4aSRandall Stewart 		control->held_length = 0;
5228f8829a4aSRandall Stewart 		if (control->data) {
5229f8829a4aSRandall Stewart 			/* Hmm there is data here .. fix */
52304c9179adSRandall Stewart 			struct mbuf *m_tmp;
5231f8829a4aSRandall Stewart 			int cnt = 0;
5232f8829a4aSRandall Stewart 
52334c9179adSRandall Stewart 			m_tmp = control->data;
52344c9179adSRandall Stewart 			while (m_tmp) {
52354c9179adSRandall Stewart 				cnt += SCTP_BUF_LEN(m_tmp);
52364c9179adSRandall Stewart 				if (SCTP_BUF_NEXT(m_tmp) == NULL) {
52374c9179adSRandall Stewart 					control->tail_mbuf = m_tmp;
5238f8829a4aSRandall Stewart 					control->end_added = 1;
5239f8829a4aSRandall Stewart 				}
52404c9179adSRandall Stewart 				m_tmp = SCTP_BUF_NEXT(m_tmp);
5241f8829a4aSRandall Stewart 			}
5242f8829a4aSRandall Stewart 			control->length = cnt;
5243f8829a4aSRandall Stewart 		} else {
5244f8829a4aSRandall Stewart 			/* remove it */
5245f8829a4aSRandall Stewart 			TAILQ_REMOVE(&inp->read_queue, control, next);
5246f8829a4aSRandall Stewart 			/* Add back any hiddend data */
5247f8829a4aSRandall Stewart 			sctp_free_remote_addr(control->whoFrom);
5248f8829a4aSRandall Stewart 			sctp_free_a_readq(stcb, control);
5249f8829a4aSRandall Stewart 		}
5250f8829a4aSRandall Stewart 		if (hold_rlock) {
5251f8829a4aSRandall Stewart 			hold_rlock = 0;
5252f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
5253f8829a4aSRandall Stewart 		}
5254f8829a4aSRandall Stewart 		goto restart;
5255f8829a4aSRandall Stewart 	}
5256f8829a4aSRandall Stewart 	if (control->length == 0) {
5257f8829a4aSRandall Stewart 		if ((sctp_is_feature_on(inp, SCTP_PCB_FLAGS_FRAG_INTERLEAVE)) &&
5258f8829a4aSRandall Stewart 		    (filling_sinfo)) {
5259f8829a4aSRandall Stewart 			/* find a more suitable one then this */
5260f8829a4aSRandall Stewart 			ctl = TAILQ_NEXT(control, next);
5261f8829a4aSRandall Stewart 			while (ctl) {
52629a6142d8SRandall Stewart 				if ((ctl->stcb != control->stcb) && (ctl->length) &&
52639a6142d8SRandall Stewart 				    (ctl->some_taken ||
52646114cd96SRandall Stewart 				    (ctl->spec_flags & M_NOTIFICATION) ||
52659a6142d8SRandall Stewart 				    ((ctl->do_not_ref_stcb == 0) &&
52669a6142d8SRandall Stewart 				    (ctl->stcb->asoc.strmin[ctl->sinfo_stream].delivery_started == 0)))
52679a6142d8SRandall Stewart 				    ) {
52689a6142d8SRandall Stewart 					/*-
52699a6142d8SRandall Stewart 					 * If we have a different TCB next, and there is data
52709a6142d8SRandall Stewart 					 * present. If we have already taken some (pdapi), OR we can
52719a6142d8SRandall Stewart 					 * ref the tcb and no delivery as started on this stream, we
527217205eccSRandall Stewart 					 * take it. Note we allow a notification on a different
527317205eccSRandall Stewart 					 * assoc to be delivered..
52749a6142d8SRandall Stewart 					 */
52759a6142d8SRandall Stewart 					control = ctl;
52769a6142d8SRandall Stewart 					goto found_one;
52779a6142d8SRandall Stewart 				} else if ((sctp_is_feature_on(inp, SCTP_PCB_FLAGS_INTERLEAVE_STRMS)) &&
52789a6142d8SRandall Stewart 					    (ctl->length) &&
52799a6142d8SRandall Stewart 					    ((ctl->some_taken) ||
52809a6142d8SRandall Stewart 					    ((ctl->do_not_ref_stcb == 0) &&
528117205eccSRandall Stewart 					    ((ctl->spec_flags & M_NOTIFICATION) == 0) &&
52829a6142d8SRandall Stewart 					    (ctl->stcb->asoc.strmin[ctl->sinfo_stream].delivery_started == 0)))
52839a6142d8SRandall Stewart 				    ) {
52849a6142d8SRandall Stewart 					/*-
52859a6142d8SRandall Stewart 					 * If we have the same tcb, and there is data present, and we
52869a6142d8SRandall Stewart 					 * have the strm interleave feature present. Then if we have
52879a6142d8SRandall Stewart 					 * taken some (pdapi) or we can refer to tht tcb AND we have
52889a6142d8SRandall Stewart 					 * not started a delivery for this stream, we can take it.
528917205eccSRandall Stewart 					 * Note we do NOT allow a notificaiton on the same assoc to
529017205eccSRandall Stewart 					 * be delivered.
52919a6142d8SRandall Stewart 					 */
5292f8829a4aSRandall Stewart 					control = ctl;
5293f8829a4aSRandall Stewart 					goto found_one;
5294f8829a4aSRandall Stewart 				}
5295f8829a4aSRandall Stewart 				ctl = TAILQ_NEXT(ctl, next);
5296f8829a4aSRandall Stewart 			}
5297f8829a4aSRandall Stewart 		}
5298f8829a4aSRandall Stewart 		/*
5299f8829a4aSRandall Stewart 		 * if we reach here, not suitable replacement is available
5300f8829a4aSRandall Stewart 		 * <or> fragment interleave is NOT on. So stuff the sb_cc
5301f8829a4aSRandall Stewart 		 * into the our held count, and its time to sleep again.
5302f8829a4aSRandall Stewart 		 */
5303f8829a4aSRandall Stewart 		held_length = so->so_rcv.sb_cc;
5304f8829a4aSRandall Stewart 		control->held_length = so->so_rcv.sb_cc;
5305f8829a4aSRandall Stewart 		goto restart;
5306f8829a4aSRandall Stewart 	}
5307f8829a4aSRandall Stewart 	/* Clear the held length since there is something to read */
5308f8829a4aSRandall Stewart 	control->held_length = 0;
5309f8829a4aSRandall Stewart 	if (hold_rlock) {
5310f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
5311f8829a4aSRandall Stewart 		hold_rlock = 0;
5312f8829a4aSRandall Stewart 	}
5313f8829a4aSRandall Stewart found_one:
5314f8829a4aSRandall Stewart 	/*
5315f8829a4aSRandall Stewart 	 * If we reach here, control has a some data for us to read off.
5316f8829a4aSRandall Stewart 	 * Note that stcb COULD be NULL.
5317f8829a4aSRandall Stewart 	 */
53189c04b296SRandall Stewart 	control->some_taken++;
5319f8829a4aSRandall Stewart 	if (hold_sblock) {
5320f8829a4aSRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
5321f8829a4aSRandall Stewart 		hold_sblock = 0;
5322f8829a4aSRandall Stewart 	}
5323f8829a4aSRandall Stewart 	stcb = control->stcb;
5324f8829a4aSRandall Stewart 	if (stcb) {
53250696e120SRandall Stewart 		if ((control->do_not_ref_stcb == 0) &&
53260696e120SRandall Stewart 		    (stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED)) {
532750cec919SRandall Stewart 			if (freecnt_applied == 0)
5328f8829a4aSRandall Stewart 				stcb = NULL;
5329f8829a4aSRandall Stewart 		} else if (control->do_not_ref_stcb == 0) {
5330f8829a4aSRandall Stewart 			/* you can't free it on me please */
5331f8829a4aSRandall Stewart 			/*
5332f8829a4aSRandall Stewart 			 * The lock on the socket buffer protects us so the
5333f8829a4aSRandall Stewart 			 * free code will stop. But since we used the
5334f8829a4aSRandall Stewart 			 * socketbuf lock and the sender uses the tcb_lock
5335f8829a4aSRandall Stewart 			 * to increment, we need to use the atomic add to
5336f8829a4aSRandall Stewart 			 * the refcnt
5337f8829a4aSRandall Stewart 			 */
5338d55b0b1bSRandall Stewart 			if (freecnt_applied) {
5339d55b0b1bSRandall Stewart #ifdef INVARIANTS
5340207304d4SRandall Stewart 				panic("refcnt already incremented");
5341d55b0b1bSRandall Stewart #else
5342d55b0b1bSRandall Stewart 				printf("refcnt already incremented?\n");
5343d55b0b1bSRandall Stewart #endif
5344d55b0b1bSRandall Stewart 			} else {
534550cec919SRandall Stewart 				atomic_add_int(&stcb->asoc.refcnt, 1);
5346f8829a4aSRandall Stewart 				freecnt_applied = 1;
5347d55b0b1bSRandall Stewart 			}
5348f8829a4aSRandall Stewart 			/*
5349f8829a4aSRandall Stewart 			 * Setup to remember how much we have not yet told
5350f8829a4aSRandall Stewart 			 * the peer our rwnd has opened up. Note we grab the
5351f8829a4aSRandall Stewart 			 * value from the tcb from last time. Note too that
53520696e120SRandall Stewart 			 * sack sending clears this when a sack is sent,
5353f8829a4aSRandall Stewart 			 * which is fine. Once we hit the rwnd_req, we then
5354f8829a4aSRandall Stewart 			 * will go to the sctp_user_rcvd() that will not
5355f8829a4aSRandall Stewart 			 * lock until it KNOWs it MUST send a WUP-SACK.
5356f8829a4aSRandall Stewart 			 */
5357f8829a4aSRandall Stewart 			freed_so_far = stcb->freed_by_sorcv_sincelast;
5358f8829a4aSRandall Stewart 			stcb->freed_by_sorcv_sincelast = 0;
5359f8829a4aSRandall Stewart 		}
5360f8829a4aSRandall Stewart 	}
53616114cd96SRandall Stewart 	if (stcb &&
53626114cd96SRandall Stewart 	    ((control->spec_flags & M_NOTIFICATION) == 0) &&
53636114cd96SRandall Stewart 	    control->do_not_ref_stcb == 0) {
5364d06c82f1SRandall Stewart 		stcb->asoc.strmin[control->sinfo_stream].delivery_started = 1;
5365d06c82f1SRandall Stewart 	}
5366f8829a4aSRandall Stewart 	/* First lets get off the sinfo and sockaddr info */
5367f8829a4aSRandall Stewart 	if ((sinfo) && filling_sinfo) {
5368f8829a4aSRandall Stewart 		memcpy(sinfo, control, sizeof(struct sctp_nonpad_sndrcvinfo));
5369f8829a4aSRandall Stewart 		nxt = TAILQ_NEXT(control, next);
5370f8829a4aSRandall Stewart 		if (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXT_RCVINFO)) {
5371f8829a4aSRandall Stewart 			struct sctp_extrcvinfo *s_extra;
5372f8829a4aSRandall Stewart 
5373f8829a4aSRandall Stewart 			s_extra = (struct sctp_extrcvinfo *)sinfo;
53749a6142d8SRandall Stewart 			if ((nxt) &&
53759a6142d8SRandall Stewart 			    (nxt->length)) {
53769a6142d8SRandall Stewart 				s_extra->sreinfo_next_flags = SCTP_NEXT_MSG_AVAIL;
5377f8829a4aSRandall Stewart 				if (nxt->sinfo_flags & SCTP_UNORDERED) {
53789a6142d8SRandall Stewart 					s_extra->sreinfo_next_flags |= SCTP_NEXT_MSG_IS_UNORDERED;
5379f8829a4aSRandall Stewart 				}
5380f42a358aSRandall Stewart 				if (nxt->spec_flags & M_NOTIFICATION) {
53819a6142d8SRandall Stewart 					s_extra->sreinfo_next_flags |= SCTP_NEXT_MSG_IS_NOTIFICATION;
5382f42a358aSRandall Stewart 				}
53839a6142d8SRandall Stewart 				s_extra->sreinfo_next_aid = nxt->sinfo_assoc_id;
53849a6142d8SRandall Stewart 				s_extra->sreinfo_next_length = nxt->length;
53859a6142d8SRandall Stewart 				s_extra->sreinfo_next_ppid = nxt->sinfo_ppid;
53869a6142d8SRandall Stewart 				s_extra->sreinfo_next_stream = nxt->sinfo_stream;
5387f8829a4aSRandall Stewart 				if (nxt->tail_mbuf != NULL) {
5388139bc87fSRandall Stewart 					if (nxt->end_added) {
53899a6142d8SRandall Stewart 						s_extra->sreinfo_next_flags |= SCTP_NEXT_MSG_ISCOMPLETE;
5390f8829a4aSRandall Stewart 					}
5391f8829a4aSRandall Stewart 				}
5392f8829a4aSRandall Stewart 			} else {
5393f8829a4aSRandall Stewart 				/*
5394f8829a4aSRandall Stewart 				 * we explicitly 0 this, since the memcpy
5395f8829a4aSRandall Stewart 				 * got some other things beyond the older
5396f8829a4aSRandall Stewart 				 * sinfo_ that is on the control's structure
5397f8829a4aSRandall Stewart 				 * :-D
5398f8829a4aSRandall Stewart 				 */
53999a6142d8SRandall Stewart 				nxt = NULL;
54009a6142d8SRandall Stewart 				s_extra->sreinfo_next_flags = SCTP_NO_NEXT_MSG;
54019a6142d8SRandall Stewart 				s_extra->sreinfo_next_aid = 0;
54029a6142d8SRandall Stewart 				s_extra->sreinfo_next_length = 0;
54039a6142d8SRandall Stewart 				s_extra->sreinfo_next_ppid = 0;
54049a6142d8SRandall Stewart 				s_extra->sreinfo_next_stream = 0;
5405f8829a4aSRandall Stewart 			}
5406f8829a4aSRandall Stewart 		}
5407f8829a4aSRandall Stewart 		/*
5408f8829a4aSRandall Stewart 		 * update off the real current cum-ack, if we have an stcb.
5409f8829a4aSRandall Stewart 		 */
54100696e120SRandall Stewart 		if ((control->do_not_ref_stcb == 0) && stcb)
5411f8829a4aSRandall Stewart 			sinfo->sinfo_cumtsn = stcb->asoc.cumulative_tsn;
5412f8829a4aSRandall Stewart 		/*
5413f8829a4aSRandall Stewart 		 * mask off the high bits, we keep the actual chunk bits in
5414f8829a4aSRandall Stewart 		 * there.
5415f8829a4aSRandall Stewart 		 */
5416f8829a4aSRandall Stewart 		sinfo->sinfo_flags &= 0x00ff;
54175f26a41dSRandall Stewart 		if ((control->sinfo_flags >> 8) & SCTP_DATA_UNORDERED) {
54185f26a41dSRandall Stewart 			sinfo->sinfo_flags |= SCTP_UNORDERED;
54195f26a41dSRandall Stewart 		}
5420f8829a4aSRandall Stewart 	}
542118e198d3SRandall Stewart #ifdef SCTP_ASOCLOG_OF_TSNS
542218e198d3SRandall Stewart 	{
542318e198d3SRandall Stewart 		int index, newindex;
542418e198d3SRandall Stewart 		struct sctp_pcbtsn_rlog *entry;
542518e198d3SRandall Stewart 
542618e198d3SRandall Stewart 		do {
542718e198d3SRandall Stewart 			index = inp->readlog_index;
542818e198d3SRandall Stewart 			newindex = index + 1;
542918e198d3SRandall Stewart 			if (newindex >= SCTP_READ_LOG_SIZE) {
543018e198d3SRandall Stewart 				newindex = 0;
543118e198d3SRandall Stewart 			}
543218e198d3SRandall Stewart 		} while (atomic_cmpset_int(&inp->readlog_index, index, newindex) == 0);
543318e198d3SRandall Stewart 		entry = &inp->readlog[index];
543418e198d3SRandall Stewart 		entry->vtag = control->sinfo_assoc_id;
543518e198d3SRandall Stewart 		entry->strm = control->sinfo_stream;
543618e198d3SRandall Stewart 		entry->seq = control->sinfo_ssn;
543718e198d3SRandall Stewart 		entry->sz = control->length;
543818e198d3SRandall Stewart 		entry->flgs = control->sinfo_flags;
543918e198d3SRandall Stewart 	}
544018e198d3SRandall Stewart #endif
5441f8829a4aSRandall Stewart 	if (fromlen && from) {
5442f8829a4aSRandall Stewart 		struct sockaddr *to;
5443f8829a4aSRandall Stewart 
544442551e99SRandall Stewart #ifdef INET
5445baf3da66SRandall Stewart 		cp_len = min((size_t)fromlen, (size_t)control->whoFrom->ro._l_addr.sin.sin_len);
5446f8829a4aSRandall Stewart 		memcpy(from, &control->whoFrom->ro._l_addr, cp_len);
5447f8829a4aSRandall Stewart 		((struct sockaddr_in *)from)->sin_port = control->port_from;
5448f8829a4aSRandall Stewart #else
5449f8829a4aSRandall Stewart 		/* No AF_INET use AF_INET6 */
5450baf3da66SRandall Stewart 		cp_len = min((size_t)fromlen, (size_t)control->whoFrom->ro._l_addr.sin6.sin6_len);
5451f8829a4aSRandall Stewart 		memcpy(from, &control->whoFrom->ro._l_addr, cp_len);
5452f8829a4aSRandall Stewart 		((struct sockaddr_in6 *)from)->sin6_port = control->port_from;
5453f8829a4aSRandall Stewart #endif
5454f8829a4aSRandall Stewart 
5455f8829a4aSRandall Stewart 		to = from;
545642551e99SRandall Stewart #if defined(INET) && defined(INET6)
54575e2c2d87SRandall Stewart 		if ((sctp_is_feature_on(inp, SCTP_PCB_FLAGS_NEEDS_MAPPED_V4)) &&
5458f8829a4aSRandall Stewart 		    (to->sa_family == AF_INET) &&
5459f8829a4aSRandall Stewart 		    ((size_t)fromlen >= sizeof(struct sockaddr_in6))) {
5460f8829a4aSRandall Stewart 			struct sockaddr_in *sin;
5461f8829a4aSRandall Stewart 			struct sockaddr_in6 sin6;
5462f8829a4aSRandall Stewart 
5463f8829a4aSRandall Stewart 			sin = (struct sockaddr_in *)to;
5464f8829a4aSRandall Stewart 			bzero(&sin6, sizeof(sin6));
5465f8829a4aSRandall Stewart 			sin6.sin6_family = AF_INET6;
5466f8829a4aSRandall Stewart 			sin6.sin6_len = sizeof(struct sockaddr_in6);
5467d6af161aSRandall Stewart 			sin6.sin6_addr.s6_addr32[2] = htonl(0xffff);
5468f8829a4aSRandall Stewart 			bcopy(&sin->sin_addr,
5469d6af161aSRandall Stewart 			    &sin6.sin6_addr.s6_addr32[3],
5470d6af161aSRandall Stewart 			    sizeof(sin6.sin6_addr.s6_addr32[3]));
5471f8829a4aSRandall Stewart 			sin6.sin6_port = sin->sin_port;
5472f8829a4aSRandall Stewart 			memcpy(from, (caddr_t)&sin6, sizeof(sin6));
5473f8829a4aSRandall Stewart 		}
5474f8829a4aSRandall Stewart #endif
547542551e99SRandall Stewart #if defined(INET6)
5476f8829a4aSRandall Stewart 		{
5477f8829a4aSRandall Stewart 			struct sockaddr_in6 lsa6, *to6;
5478f8829a4aSRandall Stewart 
5479f8829a4aSRandall Stewart 			to6 = (struct sockaddr_in6 *)to;
5480f8829a4aSRandall Stewart 			sctp_recover_scope_mac(to6, (&lsa6));
5481f8829a4aSRandall Stewart 		}
5482f8829a4aSRandall Stewart #endif
5483f8829a4aSRandall Stewart 	}
5484f8829a4aSRandall Stewart 	/* now copy out what data we can */
5485f8829a4aSRandall Stewart 	if (mp == NULL) {
5486f8829a4aSRandall Stewart 		/* copy out each mbuf in the chain up to length */
5487f8829a4aSRandall Stewart get_more_data:
5488f8829a4aSRandall Stewart 		m = control->data;
5489f8829a4aSRandall Stewart 		while (m) {
5490f8829a4aSRandall Stewart 			/* Move out all we can */
5491f8829a4aSRandall Stewart 			cp_len = (int)uio->uio_resid;
5492139bc87fSRandall Stewart 			my_len = (int)SCTP_BUF_LEN(m);
5493f8829a4aSRandall Stewart 			if (cp_len > my_len) {
5494f8829a4aSRandall Stewart 				/* not enough in this buf */
5495f8829a4aSRandall Stewart 				cp_len = my_len;
5496f8829a4aSRandall Stewart 			}
5497f8829a4aSRandall Stewart 			if (hold_rlock) {
5498f8829a4aSRandall Stewart 				SCTP_INP_READ_UNLOCK(inp);
5499f8829a4aSRandall Stewart 				hold_rlock = 0;
5500f8829a4aSRandall Stewart 			}
5501f8829a4aSRandall Stewart 			if (cp_len > 0)
5502f8829a4aSRandall Stewart 				error = uiomove(mtod(m, char *), cp_len, uio);
5503f8829a4aSRandall Stewart 			/* re-read */
5504f8829a4aSRandall Stewart 			if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE) {
5505f8829a4aSRandall Stewart 				goto release;
5506f8829a4aSRandall Stewart 			}
55070696e120SRandall Stewart 			if ((control->do_not_ref_stcb == 0) && stcb &&
5508f8829a4aSRandall Stewart 			    stcb->asoc.state & SCTP_STATE_ABOUT_TO_BE_FREED) {
5509f8829a4aSRandall Stewart 				no_rcv_needed = 1;
5510f8829a4aSRandall Stewart 			}
5511f8829a4aSRandall Stewart 			if (error) {
5512f8829a4aSRandall Stewart 				/* error we are out of here */
5513f8829a4aSRandall Stewart 				goto release;
5514f8829a4aSRandall Stewart 			}
5515139bc87fSRandall Stewart 			if ((SCTP_BUF_NEXT(m) == NULL) &&
5516139bc87fSRandall Stewart 			    (cp_len >= SCTP_BUF_LEN(m)) &&
5517f8829a4aSRandall Stewart 			    ((control->end_added == 0) ||
55180696e120SRandall Stewart 			    (control->end_added &&
55190696e120SRandall Stewart 			    (TAILQ_NEXT(control, next) == NULL)))
5520f8829a4aSRandall Stewart 			    ) {
5521f8829a4aSRandall Stewart 				SCTP_INP_READ_LOCK(inp);
5522f8829a4aSRandall Stewart 				hold_rlock = 1;
5523f8829a4aSRandall Stewart 			}
5524139bc87fSRandall Stewart 			if (cp_len == SCTP_BUF_LEN(m)) {
5525139bc87fSRandall Stewart 				if ((SCTP_BUF_NEXT(m) == NULL) &&
5526139bc87fSRandall Stewart 				    (control->end_added)) {
5527f8829a4aSRandall Stewart 					out_flags |= MSG_EOR;
55286114cd96SRandall Stewart 					if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
5529ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
5530f8829a4aSRandall Stewart 				}
5531139bc87fSRandall Stewart 				if (control->spec_flags & M_NOTIFICATION) {
5532f8829a4aSRandall Stewart 					out_flags |= MSG_NOTIFICATION;
5533f8829a4aSRandall Stewart 				}
5534f8829a4aSRandall Stewart 				/* we ate up the mbuf */
5535f8829a4aSRandall Stewart 				if (in_flags & MSG_PEEK) {
5536f8829a4aSRandall Stewart 					/* just looking */
5537139bc87fSRandall Stewart 					m = SCTP_BUF_NEXT(m);
5538f8829a4aSRandall Stewart 					copied_so_far += cp_len;
5539f8829a4aSRandall Stewart 				} else {
5540f8829a4aSRandall Stewart 					/* dispose of the mbuf */
5541b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5542f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv,
5543139bc87fSRandall Stewart 						    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
554480fefe0aSRandall Stewart 					}
5545f8829a4aSRandall Stewart 					sctp_sbfree(control, stcb, &so->so_rcv, m);
5546b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5547f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv,
5548f8829a4aSRandall Stewart 						    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
554980fefe0aSRandall Stewart 					}
5550f8829a4aSRandall Stewart 					embuf = m;
5551f8829a4aSRandall Stewart 					copied_so_far += cp_len;
5552f8829a4aSRandall Stewart 					freed_so_far += cp_len;
5553c4739e2fSRandall Stewart 					freed_so_far += MSIZE;
555418e198d3SRandall Stewart 					atomic_subtract_int(&control->length, cp_len);
5555f8829a4aSRandall Stewart 					control->data = sctp_m_free(m);
5556f8829a4aSRandall Stewart 					m = control->data;
5557f8829a4aSRandall Stewart 					/*
5558f8829a4aSRandall Stewart 					 * been through it all, must hold sb
5559f8829a4aSRandall Stewart 					 * lock ok to null tail
5560f8829a4aSRandall Stewart 					 */
5561f8829a4aSRandall Stewart 					if (control->data == NULL) {
5562a5d547adSRandall Stewart #ifdef INVARIANTS
5563f8829a4aSRandall Stewart 						if ((control->end_added == 0) ||
5564f8829a4aSRandall Stewart 						    (TAILQ_NEXT(control, next) == NULL)) {
5565f8829a4aSRandall Stewart 							/*
5566f8829a4aSRandall Stewart 							 * If the end is not
5567f8829a4aSRandall Stewart 							 * added, OR the
5568f8829a4aSRandall Stewart 							 * next is NOT null
5569f8829a4aSRandall Stewart 							 * we MUST have the
5570f8829a4aSRandall Stewart 							 * lock.
5571f8829a4aSRandall Stewart 							 */
5572f8829a4aSRandall Stewart 							if (mtx_owned(&inp->inp_rdata_mtx) == 0) {
5573f8829a4aSRandall Stewart 								panic("Hmm we don't own the lock?");
5574f8829a4aSRandall Stewart 							}
5575f8829a4aSRandall Stewart 						}
5576f8829a4aSRandall Stewart #endif
5577f8829a4aSRandall Stewart 						control->tail_mbuf = NULL;
5578a5d547adSRandall Stewart #ifdef INVARIANTS
5579f8829a4aSRandall Stewart 						if ((control->end_added) && ((out_flags & MSG_EOR) == 0)) {
5580f8829a4aSRandall Stewart 							panic("end_added, nothing left and no MSG_EOR");
5581f8829a4aSRandall Stewart 						}
5582f8829a4aSRandall Stewart #endif
5583f8829a4aSRandall Stewart 					}
5584f8829a4aSRandall Stewart 				}
5585f8829a4aSRandall Stewart 			} else {
5586f8829a4aSRandall Stewart 				/* Do we need to trim the mbuf? */
5587139bc87fSRandall Stewart 				if (control->spec_flags & M_NOTIFICATION) {
5588f8829a4aSRandall Stewart 					out_flags |= MSG_NOTIFICATION;
5589f8829a4aSRandall Stewart 				}
5590f8829a4aSRandall Stewart 				if ((in_flags & MSG_PEEK) == 0) {
5591139bc87fSRandall Stewart 					SCTP_BUF_RESV_UF(m, cp_len);
5592139bc87fSRandall Stewart 					SCTP_BUF_LEN(m) -= cp_len;
5593b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5594f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv, control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, cp_len);
559580fefe0aSRandall Stewart 					}
5596f8829a4aSRandall Stewart 					atomic_subtract_int(&so->so_rcv.sb_cc, cp_len);
55970696e120SRandall Stewart 					if ((control->do_not_ref_stcb == 0) &&
55980696e120SRandall Stewart 					    stcb) {
5599f8829a4aSRandall Stewart 						atomic_subtract_int(&stcb->asoc.sb_cc, cp_len);
5600f8829a4aSRandall Stewart 					}
5601f8829a4aSRandall Stewart 					copied_so_far += cp_len;
5602f8829a4aSRandall Stewart 					embuf = m;
5603f8829a4aSRandall Stewart 					freed_so_far += cp_len;
5604c4739e2fSRandall Stewart 					freed_so_far += MSIZE;
5605b3f1ea41SRandall Stewart 					if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5606f8829a4aSRandall Stewart 						sctp_sblog(&so->so_rcv, control->do_not_ref_stcb ? NULL : stcb,
5607f8829a4aSRandall Stewart 						    SCTP_LOG_SBRESULT, 0);
560880fefe0aSRandall Stewart 					}
560918e198d3SRandall Stewart 					atomic_subtract_int(&control->length, cp_len);
5610f8829a4aSRandall Stewart 				} else {
5611f8829a4aSRandall Stewart 					copied_so_far += cp_len;
5612f8829a4aSRandall Stewart 				}
5613f8829a4aSRandall Stewart 			}
5614d61a0ae0SRandall Stewart 			if ((out_flags & MSG_EOR) || (uio->uio_resid == 0)) {
5615f8829a4aSRandall Stewart 				break;
5616f8829a4aSRandall Stewart 			}
5617f8829a4aSRandall Stewart 			if (((stcb) && (in_flags & MSG_PEEK) == 0) &&
5618f8829a4aSRandall Stewart 			    (control->do_not_ref_stcb == 0) &&
5619f8829a4aSRandall Stewart 			    (freed_so_far >= rwnd_req)) {
5620f8829a4aSRandall Stewart 				sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
5621f8829a4aSRandall Stewart 			}
5622f8829a4aSRandall Stewart 		}		/* end while(m) */
5623f8829a4aSRandall Stewart 		/*
5624f8829a4aSRandall Stewart 		 * At this point we have looked at it all and we either have
5625f8829a4aSRandall Stewart 		 * a MSG_EOR/or read all the user wants... <OR>
5626f8829a4aSRandall Stewart 		 * control->length == 0.
5627f8829a4aSRandall Stewart 		 */
5628d61a0ae0SRandall Stewart 		if ((out_flags & MSG_EOR) && ((in_flags & MSG_PEEK) == 0)) {
5629f8829a4aSRandall Stewart 			/* we are done with this control */
5630f8829a4aSRandall Stewart 			if (control->length == 0) {
5631f8829a4aSRandall Stewart 				if (control->data) {
5632a5d547adSRandall Stewart #ifdef INVARIANTS
5633f8829a4aSRandall Stewart 					panic("control->data not null at read eor?");
5634f8829a4aSRandall Stewart #else
5635ad81507eSRandall Stewart 					SCTP_PRINTF("Strange, data left in the control buffer .. invarients would panic?\n");
5636f8829a4aSRandall Stewart 					sctp_m_freem(control->data);
5637f8829a4aSRandall Stewart 					control->data = NULL;
5638f8829a4aSRandall Stewart #endif
5639f8829a4aSRandall Stewart 				}
5640f8829a4aSRandall Stewart 		done_with_control:
5641f8829a4aSRandall Stewart 				if (TAILQ_NEXT(control, next) == NULL) {
5642f8829a4aSRandall Stewart 					/*
5643f8829a4aSRandall Stewart 					 * If we don't have a next we need a
5644b201f536SRandall Stewart 					 * lock, if there is a next
5645b201f536SRandall Stewart 					 * interrupt is filling ahead of us
5646b201f536SRandall Stewart 					 * and we don't need a lock to
5647b201f536SRandall Stewart 					 * remove this guy (which is the
5648b201f536SRandall Stewart 					 * head of the queue).
5649f8829a4aSRandall Stewart 					 */
5650f8829a4aSRandall Stewart 					if (hold_rlock == 0) {
5651f8829a4aSRandall Stewart 						SCTP_INP_READ_LOCK(inp);
5652f8829a4aSRandall Stewart 						hold_rlock = 1;
5653f8829a4aSRandall Stewart 					}
5654f8829a4aSRandall Stewart 				}
5655f8829a4aSRandall Stewart 				TAILQ_REMOVE(&inp->read_queue, control, next);
5656f8829a4aSRandall Stewart 				/* Add back any hiddend data */
5657f8829a4aSRandall Stewart 				if (control->held_length) {
5658f8829a4aSRandall Stewart 					held_length = 0;
5659f8829a4aSRandall Stewart 					control->held_length = 0;
5660f8829a4aSRandall Stewart 					wakeup_read_socket = 1;
5661f8829a4aSRandall Stewart 				}
566217205eccSRandall Stewart 				if (control->aux_data) {
566317205eccSRandall Stewart 					sctp_m_free(control->aux_data);
566417205eccSRandall Stewart 					control->aux_data = NULL;
566517205eccSRandall Stewart 				}
5666f8829a4aSRandall Stewart 				no_rcv_needed = control->do_not_ref_stcb;
5667f8829a4aSRandall Stewart 				sctp_free_remote_addr(control->whoFrom);
5668f8829a4aSRandall Stewart 				control->data = NULL;
5669f8829a4aSRandall Stewart 				sctp_free_a_readq(stcb, control);
5670f8829a4aSRandall Stewart 				control = NULL;
56710696e120SRandall Stewart 				if ((freed_so_far >= rwnd_req) &&
56720696e120SRandall Stewart 				    (no_rcv_needed == 0))
5673f8829a4aSRandall Stewart 					sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
5674f8829a4aSRandall Stewart 
5675f8829a4aSRandall Stewart 			} else {
5676f8829a4aSRandall Stewart 				/*
5677f8829a4aSRandall Stewart 				 * The user did not read all of this
5678f8829a4aSRandall Stewart 				 * message, turn off the returned MSG_EOR
5679f8829a4aSRandall Stewart 				 * since we are leaving more behind on the
5680f8829a4aSRandall Stewart 				 * control to read.
5681f8829a4aSRandall Stewart 				 */
5682a5d547adSRandall Stewart #ifdef INVARIANTS
56830696e120SRandall Stewart 				if (control->end_added &&
56840696e120SRandall Stewart 				    (control->data == NULL) &&
5685f8829a4aSRandall Stewart 				    (control->tail_mbuf == NULL)) {
5686f8829a4aSRandall Stewart 					panic("Gak, control->length is corrupt?");
5687f8829a4aSRandall Stewart 				}
5688f8829a4aSRandall Stewart #endif
5689f8829a4aSRandall Stewart 				no_rcv_needed = control->do_not_ref_stcb;
5690f8829a4aSRandall Stewart 				out_flags &= ~MSG_EOR;
5691f8829a4aSRandall Stewart 			}
5692f8829a4aSRandall Stewart 		}
5693f8829a4aSRandall Stewart 		if (out_flags & MSG_EOR) {
5694f8829a4aSRandall Stewart 			goto release;
5695f8829a4aSRandall Stewart 		}
5696f8829a4aSRandall Stewart 		if ((uio->uio_resid == 0) ||
5697f8829a4aSRandall Stewart 		    ((in_eeor_mode) && (copied_so_far >= max(so->so_rcv.sb_lowat, 1)))
5698f8829a4aSRandall Stewart 		    ) {
5699f8829a4aSRandall Stewart 			goto release;
5700f8829a4aSRandall Stewart 		}
5701f8829a4aSRandall Stewart 		/*
5702f8829a4aSRandall Stewart 		 * If I hit here the receiver wants more and this message is
5703f8829a4aSRandall Stewart 		 * NOT done (pd-api). So two questions. Can we block? if not
5704f8829a4aSRandall Stewart 		 * we are done. Did the user NOT set MSG_WAITALL?
5705f8829a4aSRandall Stewart 		 */
5706f8829a4aSRandall Stewart 		if (block_allowed == 0) {
5707f8829a4aSRandall Stewart 			goto release;
5708f8829a4aSRandall Stewart 		}
5709f8829a4aSRandall Stewart 		/*
5710f8829a4aSRandall Stewart 		 * We need to wait for more data a few things: - We don't
5711f8829a4aSRandall Stewart 		 * sbunlock() so we don't get someone else reading. - We
5712f8829a4aSRandall Stewart 		 * must be sure to account for the case where what is added
5713f8829a4aSRandall Stewart 		 * is NOT to our control when we wakeup.
5714f8829a4aSRandall Stewart 		 */
5715f8829a4aSRandall Stewart 
5716f8829a4aSRandall Stewart 		/*
5717f8829a4aSRandall Stewart 		 * Do we need to tell the transport a rwnd update might be
5718f8829a4aSRandall Stewart 		 * needed before we go to sleep?
5719f8829a4aSRandall Stewart 		 */
5720f8829a4aSRandall Stewart 		if (((stcb) && (in_flags & MSG_PEEK) == 0) &&
5721f8829a4aSRandall Stewart 		    ((freed_so_far >= rwnd_req) &&
5722f8829a4aSRandall Stewart 		    (control->do_not_ref_stcb == 0) &&
5723f8829a4aSRandall Stewart 		    (no_rcv_needed == 0))) {
5724f8829a4aSRandall Stewart 			sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
5725f8829a4aSRandall Stewart 		}
5726f8829a4aSRandall Stewart wait_some_more:
572744b7479bSRandall Stewart 		if (so->so_rcv.sb_state & SBS_CANTRCVMORE) {
5728f8829a4aSRandall Stewart 			goto release;
5729f8829a4aSRandall Stewart 		}
5730f8829a4aSRandall Stewart 		if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE)
5731f8829a4aSRandall Stewart 			goto release;
5732f8829a4aSRandall Stewart 
5733f8829a4aSRandall Stewart 		if (hold_rlock == 1) {
5734f8829a4aSRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
5735f8829a4aSRandall Stewart 			hold_rlock = 0;
5736f8829a4aSRandall Stewart 		}
5737f8829a4aSRandall Stewart 		if (hold_sblock == 0) {
5738f8829a4aSRandall Stewart 			SOCKBUF_LOCK(&so->so_rcv);
5739f8829a4aSRandall Stewart 			hold_sblock = 1;
5740f8829a4aSRandall Stewart 		}
5741851b7298SRandall Stewart 		if ((copied_so_far) && (control->length == 0) &&
5742851b7298SRandall Stewart 		    (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_FRAG_INTERLEAVE))
5743851b7298SRandall Stewart 		    ) {
5744851b7298SRandall Stewart 			goto release;
5745851b7298SRandall Stewart 		}
5746f8829a4aSRandall Stewart 		if (so->so_rcv.sb_cc <= control->held_length) {
5747f8829a4aSRandall Stewart 			error = sbwait(&so->so_rcv);
5748f8829a4aSRandall Stewart 			if (error) {
5749f8829a4aSRandall Stewart 				goto release;
5750f8829a4aSRandall Stewart 			}
5751f8829a4aSRandall Stewart 			control->held_length = 0;
5752f8829a4aSRandall Stewart 		}
5753f8829a4aSRandall Stewart 		if (hold_sblock) {
5754f8829a4aSRandall Stewart 			SOCKBUF_UNLOCK(&so->so_rcv);
5755f8829a4aSRandall Stewart 			hold_sblock = 0;
5756f8829a4aSRandall Stewart 		}
5757f8829a4aSRandall Stewart 		if (control->length == 0) {
5758f8829a4aSRandall Stewart 			/* still nothing here */
5759f8829a4aSRandall Stewart 			if (control->end_added == 1) {
5760f8829a4aSRandall Stewart 				/* he aborted, or is done i.e.did a shutdown */
5761f8829a4aSRandall Stewart 				out_flags |= MSG_EOR;
57629a6142d8SRandall Stewart 				if (control->pdapi_aborted) {
57636114cd96SRandall Stewart 					if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
5764ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
57659a6142d8SRandall Stewart 
576603b0b021SRandall Stewart 					out_flags |= MSG_TRUNC;
57679a6142d8SRandall Stewart 				} else {
57686114cd96SRandall Stewart 					if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
5769ee7f9857SRandall Stewart 						control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
57709a6142d8SRandall Stewart 				}
5771f8829a4aSRandall Stewart 				goto done_with_control;
5772f8829a4aSRandall Stewart 			}
5773f8829a4aSRandall Stewart 			if (so->so_rcv.sb_cc > held_length) {
5774f8829a4aSRandall Stewart 				control->held_length = so->so_rcv.sb_cc;
5775f8829a4aSRandall Stewart 				held_length = 0;
5776f8829a4aSRandall Stewart 			}
5777f8829a4aSRandall Stewart 			goto wait_some_more;
5778f8829a4aSRandall Stewart 		} else if (control->data == NULL) {
577950cec919SRandall Stewart 			/*
578050cec919SRandall Stewart 			 * we must re-sync since data is probably being
578150cec919SRandall Stewart 			 * added
578250cec919SRandall Stewart 			 */
578350cec919SRandall Stewart 			SCTP_INP_READ_LOCK(inp);
578450cec919SRandall Stewart 			if ((control->length > 0) && (control->data == NULL)) {
578550cec919SRandall Stewart 				/*
578650cec919SRandall Stewart 				 * big trouble.. we have the lock and its
578750cec919SRandall Stewart 				 * corrupt?
578850cec919SRandall Stewart 				 */
57899c04b296SRandall Stewart #ifdef INVARIANTS
5790f8829a4aSRandall Stewart 				panic("Impossible data==NULL length !=0");
57919c04b296SRandall Stewart #endif
57929c04b296SRandall Stewart 				out_flags |= MSG_EOR;
57939c04b296SRandall Stewart 				out_flags |= MSG_TRUNC;
57949c04b296SRandall Stewart 				control->length = 0;
57959c04b296SRandall Stewart 				SCTP_INP_READ_UNLOCK(inp);
57969c04b296SRandall Stewart 				goto done_with_control;
5797f8829a4aSRandall Stewart 			}
579850cec919SRandall Stewart 			SCTP_INP_READ_UNLOCK(inp);
579950cec919SRandall Stewart 			/* We will fall around to get more data */
580050cec919SRandall Stewart 		}
5801f8829a4aSRandall Stewart 		goto get_more_data;
5802f8829a4aSRandall Stewart 	} else {
580317205eccSRandall Stewart 		/*-
580417205eccSRandall Stewart 		 * Give caller back the mbuf chain,
580517205eccSRandall Stewart 		 * store in uio_resid the length
5806f8829a4aSRandall Stewart 		 */
580717205eccSRandall Stewart 		wakeup_read_socket = 0;
5808f8829a4aSRandall Stewart 		if ((control->end_added == 0) ||
5809f8829a4aSRandall Stewart 		    (TAILQ_NEXT(control, next) == NULL)) {
5810f8829a4aSRandall Stewart 			/* Need to get rlock */
5811f8829a4aSRandall Stewart 			if (hold_rlock == 0) {
5812f8829a4aSRandall Stewart 				SCTP_INP_READ_LOCK(inp);
5813f8829a4aSRandall Stewart 				hold_rlock = 1;
5814f8829a4aSRandall Stewart 			}
5815f8829a4aSRandall Stewart 		}
5816139bc87fSRandall Stewart 		if (control->end_added) {
5817f8829a4aSRandall Stewart 			out_flags |= MSG_EOR;
58186114cd96SRandall Stewart 			if ((control->do_not_ref_stcb == 0) && ((control->spec_flags & M_NOTIFICATION) == 0))
5819ee7f9857SRandall Stewart 				control->stcb->asoc.strmin[control->sinfo_stream].delivery_started = 0;
5820f8829a4aSRandall Stewart 		}
5821139bc87fSRandall Stewart 		if (control->spec_flags & M_NOTIFICATION) {
5822f8829a4aSRandall Stewart 			out_flags |= MSG_NOTIFICATION;
5823f8829a4aSRandall Stewart 		}
582417205eccSRandall Stewart 		uio->uio_resid = control->length;
5825f8829a4aSRandall Stewart 		*mp = control->data;
5826f8829a4aSRandall Stewart 		m = control->data;
5827f8829a4aSRandall Stewart 		while (m) {
5828b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5829f8829a4aSRandall Stewart 				sctp_sblog(&so->so_rcv,
5830139bc87fSRandall Stewart 				    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBFREE, SCTP_BUF_LEN(m));
583180fefe0aSRandall Stewart 			}
5832f8829a4aSRandall Stewart 			sctp_sbfree(control, stcb, &so->so_rcv, m);
5833139bc87fSRandall Stewart 			freed_so_far += SCTP_BUF_LEN(m);
5834c4739e2fSRandall Stewart 			freed_so_far += MSIZE;
5835b3f1ea41SRandall Stewart 			if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_SB_LOGGING_ENABLE) {
5836f8829a4aSRandall Stewart 				sctp_sblog(&so->so_rcv,
5837f8829a4aSRandall Stewart 				    control->do_not_ref_stcb ? NULL : stcb, SCTP_LOG_SBRESULT, 0);
583880fefe0aSRandall Stewart 			}
5839139bc87fSRandall Stewart 			m = SCTP_BUF_NEXT(m);
5840f8829a4aSRandall Stewart 		}
5841f8829a4aSRandall Stewart 		control->data = control->tail_mbuf = NULL;
5842f8829a4aSRandall Stewart 		control->length = 0;
5843f8829a4aSRandall Stewart 		if (out_flags & MSG_EOR) {
5844f8829a4aSRandall Stewart 			/* Done with this control */
5845f8829a4aSRandall Stewart 			goto done_with_control;
5846f8829a4aSRandall Stewart 		}
5847f8829a4aSRandall Stewart 	}
5848f8829a4aSRandall Stewart release:
5849f8829a4aSRandall Stewart 	if (hold_rlock == 1) {
5850f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
5851f8829a4aSRandall Stewart 		hold_rlock = 0;
5852f8829a4aSRandall Stewart 	}
58537abab911SRobert Watson 	if (hold_sblock == 1) {
58547abab911SRobert Watson 		SOCKBUF_UNLOCK(&so->so_rcv);
58557abab911SRobert Watson 		hold_sblock = 0;
5856f8829a4aSRandall Stewart 	}
5857f8829a4aSRandall Stewart 	sbunlock(&so->so_rcv);
58587abab911SRobert Watson 	sockbuf_lock = 0;
5859f8829a4aSRandall Stewart 
5860f8829a4aSRandall Stewart release_unlocked:
5861f8829a4aSRandall Stewart 	if (hold_sblock) {
5862f8829a4aSRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
5863f8829a4aSRandall Stewart 		hold_sblock = 0;
5864f8829a4aSRandall Stewart 	}
5865f8829a4aSRandall Stewart 	if ((stcb) && (in_flags & MSG_PEEK) == 0) {
5866f8829a4aSRandall Stewart 		if ((freed_so_far >= rwnd_req) &&
5867f8829a4aSRandall Stewart 		    (control && (control->do_not_ref_stcb == 0)) &&
5868f8829a4aSRandall Stewart 		    (no_rcv_needed == 0))
5869f8829a4aSRandall Stewart 			sctp_user_rcvd(stcb, &freed_so_far, hold_rlock, rwnd_req);
5870f8829a4aSRandall Stewart 	}
5871f8829a4aSRandall Stewart out:
58721b9f62a0SRandall Stewart 	if (msg_flags) {
58731b9f62a0SRandall Stewart 		*msg_flags = out_flags;
58741b9f62a0SRandall Stewart 	}
58759a6142d8SRandall Stewart 	if (((out_flags & MSG_EOR) == 0) &&
58769a6142d8SRandall Stewart 	    ((in_flags & MSG_PEEK) == 0) &&
58779a6142d8SRandall Stewart 	    (sinfo) &&
58789a6142d8SRandall Stewart 	    (sctp_is_feature_on(inp, SCTP_PCB_FLAGS_EXT_RCVINFO))) {
58799a6142d8SRandall Stewart 		struct sctp_extrcvinfo *s_extra;
58809a6142d8SRandall Stewart 
58819a6142d8SRandall Stewart 		s_extra = (struct sctp_extrcvinfo *)sinfo;
58829a6142d8SRandall Stewart 		s_extra->sreinfo_next_flags = SCTP_NO_NEXT_MSG;
58839a6142d8SRandall Stewart 	}
5884f8829a4aSRandall Stewart 	if (hold_rlock == 1) {
5885f8829a4aSRandall Stewart 		SCTP_INP_READ_UNLOCK(inp);
5886f8829a4aSRandall Stewart 		hold_rlock = 0;
5887f8829a4aSRandall Stewart 	}
5888f8829a4aSRandall Stewart 	if (hold_sblock) {
5889f8829a4aSRandall Stewart 		SOCKBUF_UNLOCK(&so->so_rcv);
5890f8829a4aSRandall Stewart 		hold_sblock = 0;
5891f8829a4aSRandall Stewart 	}
58927abab911SRobert Watson 	if (sockbuf_lock) {
58937abab911SRobert Watson 		sbunlock(&so->so_rcv);
58947abab911SRobert Watson 	}
589550cec919SRandall Stewart 	if (freecnt_applied) {
5896f8829a4aSRandall Stewart 		/*
5897f8829a4aSRandall Stewart 		 * The lock on the socket buffer protects us so the free
5898f8829a4aSRandall Stewart 		 * code will stop. But since we used the socketbuf lock and
5899f8829a4aSRandall Stewart 		 * the sender uses the tcb_lock to increment, we need to use
5900f8829a4aSRandall Stewart 		 * the atomic add to the refcnt.
5901f8829a4aSRandall Stewart 		 */
590250cec919SRandall Stewart 		if (stcb == NULL) {
5903df6e0cc3SRandall Stewart #ifdef INVARIANTS
590450cec919SRandall Stewart 			panic("stcb for refcnt has gone NULL?");
5905df6e0cc3SRandall Stewart 			goto stage_left;
5906df6e0cc3SRandall Stewart #else
5907df6e0cc3SRandall Stewart 			goto stage_left;
5908df6e0cc3SRandall Stewart #endif
590950cec919SRandall Stewart 		}
591050cec919SRandall Stewart 		atomic_add_int(&stcb->asoc.refcnt, -1);
5911f8829a4aSRandall Stewart 		freecnt_applied = 0;
5912f8829a4aSRandall Stewart 		/* Save the value back for next time */
5913f8829a4aSRandall Stewart 		stcb->freed_by_sorcv_sincelast = freed_so_far;
5914f8829a4aSRandall Stewart 	}
5915b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_RECV_RWND_LOGGING_ENABLE) {
5916f8829a4aSRandall Stewart 		if (stcb) {
5917f8829a4aSRandall Stewart 			sctp_misc_ints(SCTP_SORECV_DONE,
5918f8829a4aSRandall Stewart 			    freed_so_far,
5919f8829a4aSRandall Stewart 			    ((uio) ? (slen - uio->uio_resid) : slen),
5920f8829a4aSRandall Stewart 			    stcb->asoc.my_rwnd,
5921f8829a4aSRandall Stewart 			    so->so_rcv.sb_cc);
5922f8829a4aSRandall Stewart 		} else {
5923f8829a4aSRandall Stewart 			sctp_misc_ints(SCTP_SORECV_DONE,
5924f8829a4aSRandall Stewart 			    freed_so_far,
5925f8829a4aSRandall Stewart 			    ((uio) ? (slen - uio->uio_resid) : slen),
5926f8829a4aSRandall Stewart 			    0,
5927f8829a4aSRandall Stewart 			    so->so_rcv.sb_cc);
5928f8829a4aSRandall Stewart 		}
592980fefe0aSRandall Stewart 	}
5930df6e0cc3SRandall Stewart stage_left:
5931f8829a4aSRandall Stewart 	if (wakeup_read_socket) {
5932f8829a4aSRandall Stewart 		sctp_sorwakeup(inp, so);
5933f8829a4aSRandall Stewart 	}
5934f8829a4aSRandall Stewart 	return (error);
5935f8829a4aSRandall Stewart }
5936f8829a4aSRandall Stewart 
5937f8829a4aSRandall Stewart 
5938f8829a4aSRandall Stewart #ifdef SCTP_MBUF_LOGGING
5939f8829a4aSRandall Stewart struct mbuf *
5940f8829a4aSRandall Stewart sctp_m_free(struct mbuf *m)
5941f8829a4aSRandall Stewart {
5942b3f1ea41SRandall Stewart 	if (SCTP_BASE_SYSCTL(sctp_logging_level) & SCTP_MBUF_LOGGING_ENABLE) {
5943139bc87fSRandall Stewart 		if (SCTP_BUF_IS_EXTENDED(m)) {
5944f8829a4aSRandall Stewart 			sctp_log_mb(m, SCTP_MBUF_IFREE);
5945f8829a4aSRandall Stewart 		}
594680fefe0aSRandall Stewart 	}
5947f8829a4aSRandall Stewart 	return (m_free(m));
5948f8829a4aSRandall Stewart }
5949f8829a4aSRandall Stewart 
5950f8829a4aSRandall Stewart void
5951f8829a4aSRandall Stewart sctp_m_freem(struct mbuf *mb)
5952f8829a4aSRandall Stewart {
5953f8829a4aSRandall Stewart 	while (mb != NULL)
5954f8829a4aSRandall Stewart 		mb = sctp_m_free(mb);
5955f8829a4aSRandall Stewart }
5956f8829a4aSRandall Stewart 
5957f8829a4aSRandall Stewart #endif
5958f8829a4aSRandall Stewart 
595942551e99SRandall Stewart int
596042551e99SRandall Stewart sctp_dynamic_set_primary(struct sockaddr *sa, uint32_t vrf_id)
596142551e99SRandall Stewart {
596242551e99SRandall Stewart 	/*
596342551e99SRandall Stewart 	 * Given a local address. For all associations that holds the
596442551e99SRandall Stewart 	 * address, request a peer-set-primary.
596542551e99SRandall Stewart 	 */
596642551e99SRandall Stewart 	struct sctp_ifa *ifa;
596742551e99SRandall Stewart 	struct sctp_laddr *wi;
596842551e99SRandall Stewart 
596942551e99SRandall Stewart 	ifa = sctp_find_ifa_by_addr(sa, vrf_id, 0);
597042551e99SRandall Stewart 	if (ifa == NULL) {
5971c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, EADDRNOTAVAIL);
597242551e99SRandall Stewart 		return (EADDRNOTAVAIL);
597342551e99SRandall Stewart 	}
597442551e99SRandall Stewart 	/*
597542551e99SRandall Stewart 	 * Now that we have the ifa we must awaken the iterator with this
597642551e99SRandall Stewart 	 * message.
597742551e99SRandall Stewart 	 */
5978b3f1ea41SRandall Stewart 	wi = SCTP_ZONE_GET(SCTP_BASE_INFO(ipi_zone_laddr), struct sctp_laddr);
597942551e99SRandall Stewart 	if (wi == NULL) {
5980c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTPUTIL, ENOMEM);
598142551e99SRandall Stewart 		return (ENOMEM);
598242551e99SRandall Stewart 	}
598342551e99SRandall Stewart 	/* Now incr the count and int wi structure */
598442551e99SRandall Stewart 	SCTP_INCR_LADDR_COUNT();
598542551e99SRandall Stewart 	bzero(wi, sizeof(*wi));
5986d61a0ae0SRandall Stewart 	(void)SCTP_GETTIME_TIMEVAL(&wi->start_time);
598742551e99SRandall Stewart 	wi->ifa = ifa;
598842551e99SRandall Stewart 	wi->action = SCTP_SET_PRIM_ADDR;
598942551e99SRandall Stewart 	atomic_add_int(&ifa->refcount, 1);
599042551e99SRandall Stewart 
599142551e99SRandall Stewart 	/* Now add it to the work queue */
599242551e99SRandall Stewart 	SCTP_IPI_ITERATOR_WQ_LOCK();
599342551e99SRandall Stewart 	/*
599442551e99SRandall Stewart 	 * Should this really be a tailq? As it is we will process the
599542551e99SRandall Stewart 	 * newest first :-0
599642551e99SRandall Stewart 	 */
5997b3f1ea41SRandall Stewart 	LIST_INSERT_HEAD(&SCTP_BASE_INFO(addr_wq), wi, sctp_nxt_addr);
599842551e99SRandall Stewart 	sctp_timer_start(SCTP_TIMER_TYPE_ADDR_WQ,
599942551e99SRandall Stewart 	    (struct sctp_inpcb *)NULL,
600042551e99SRandall Stewart 	    (struct sctp_tcb *)NULL,
600142551e99SRandall Stewart 	    (struct sctp_nets *)NULL);
600242551e99SRandall Stewart 	SCTP_IPI_ITERATOR_WQ_UNLOCK();
600342551e99SRandall Stewart 	return (0);
600442551e99SRandall Stewart }
600542551e99SRandall Stewart 
600642551e99SRandall Stewart 
6007f8829a4aSRandall Stewart int
600817205eccSRandall Stewart sctp_soreceive(struct socket *so,
600917205eccSRandall Stewart     struct sockaddr **psa,
601017205eccSRandall Stewart     struct uio *uio,
601117205eccSRandall Stewart     struct mbuf **mp0,
601217205eccSRandall Stewart     struct mbuf **controlp,
601317205eccSRandall Stewart     int *flagsp)
6014f8829a4aSRandall Stewart {
6015f8829a4aSRandall Stewart 	int error, fromlen;
6016f8829a4aSRandall Stewart 	uint8_t sockbuf[256];
6017f8829a4aSRandall Stewart 	struct sockaddr *from;
6018f8829a4aSRandall Stewart 	struct sctp_extrcvinfo sinfo;
6019f8829a4aSRandall Stewart 	int filling_sinfo = 1;
6020f8829a4aSRandall Stewart 	struct sctp_inpcb *inp;
6021f8829a4aSRandall Stewart 
6022f8829a4aSRandall Stewart 	inp = (struct sctp_inpcb *)so->so_pcb;
6023f8829a4aSRandall Stewart 	/* pickup the assoc we are reading from */
6024f8829a4aSRandall Stewart 	if (inp == NULL) {
6025c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6026f8829a4aSRandall Stewart 		return (EINVAL);
6027f8829a4aSRandall Stewart 	}
6028f8829a4aSRandall Stewart 	if ((sctp_is_feature_off(inp,
6029f8829a4aSRandall Stewart 	    SCTP_PCB_FLAGS_RECVDATAIOEVNT)) ||
6030f8829a4aSRandall Stewart 	    (controlp == NULL)) {
6031f8829a4aSRandall Stewart 		/* user does not want the sndrcv ctl */
6032f8829a4aSRandall Stewart 		filling_sinfo = 0;
6033f8829a4aSRandall Stewart 	}
6034f8829a4aSRandall Stewart 	if (psa) {
6035f8829a4aSRandall Stewart 		from = (struct sockaddr *)sockbuf;
6036f8829a4aSRandall Stewart 		fromlen = sizeof(sockbuf);
6037f8829a4aSRandall Stewart 		from->sa_len = 0;
6038f8829a4aSRandall Stewart 	} else {
6039f8829a4aSRandall Stewart 		from = NULL;
6040f8829a4aSRandall Stewart 		fromlen = 0;
6041f8829a4aSRandall Stewart 	}
6042f8829a4aSRandall Stewart 
6043f8829a4aSRandall Stewart 	error = sctp_sorecvmsg(so, uio, mp0, from, fromlen, flagsp,
6044f8829a4aSRandall Stewart 	    (struct sctp_sndrcvinfo *)&sinfo, filling_sinfo);
6045f8829a4aSRandall Stewart 	if ((controlp) && (filling_sinfo)) {
6046f8829a4aSRandall Stewart 		/* copy back the sinfo in a CMSG format */
6047f8829a4aSRandall Stewart 		if (filling_sinfo)
6048f8829a4aSRandall Stewart 			*controlp = sctp_build_ctl_nchunk(inp,
6049f8829a4aSRandall Stewart 			    (struct sctp_sndrcvinfo *)&sinfo);
6050f8829a4aSRandall Stewart 		else
6051f8829a4aSRandall Stewart 			*controlp = NULL;
6052f8829a4aSRandall Stewart 	}
6053f8829a4aSRandall Stewart 	if (psa) {
6054f8829a4aSRandall Stewart 		/* copy back the address info */
6055f8829a4aSRandall Stewart 		if (from && from->sa_len) {
6056f8829a4aSRandall Stewart 			*psa = sodupsockaddr(from, M_NOWAIT);
6057f8829a4aSRandall Stewart 		} else {
6058f8829a4aSRandall Stewart 			*psa = NULL;
6059f8829a4aSRandall Stewart 		}
6060f8829a4aSRandall Stewart 	}
6061f8829a4aSRandall Stewart 	return (error);
6062f8829a4aSRandall Stewart }
606317205eccSRandall Stewart 
606417205eccSRandall Stewart 
606517205eccSRandall Stewart int
606617205eccSRandall Stewart sctp_l_soreceive(struct socket *so,
606717205eccSRandall Stewart     struct sockaddr **name,
606817205eccSRandall Stewart     struct uio *uio,
606917205eccSRandall Stewart     char **controlp,
607017205eccSRandall Stewart     int *controllen,
607117205eccSRandall Stewart     int *flag)
607217205eccSRandall Stewart {
607317205eccSRandall Stewart 	int error, fromlen;
607417205eccSRandall Stewart 	uint8_t sockbuf[256];
607517205eccSRandall Stewart 	struct sockaddr *from;
607617205eccSRandall Stewart 	struct sctp_extrcvinfo sinfo;
607717205eccSRandall Stewart 	int filling_sinfo = 1;
607817205eccSRandall Stewart 	struct sctp_inpcb *inp;
607917205eccSRandall Stewart 
608017205eccSRandall Stewart 	inp = (struct sctp_inpcb *)so->so_pcb;
608117205eccSRandall Stewart 	/* pickup the assoc we are reading from */
608217205eccSRandall Stewart 	if (inp == NULL) {
6083c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
608417205eccSRandall Stewart 		return (EINVAL);
608517205eccSRandall Stewart 	}
608617205eccSRandall Stewart 	if ((sctp_is_feature_off(inp,
608717205eccSRandall Stewart 	    SCTP_PCB_FLAGS_RECVDATAIOEVNT)) ||
608817205eccSRandall Stewart 	    (controlp == NULL)) {
608917205eccSRandall Stewart 		/* user does not want the sndrcv ctl */
609017205eccSRandall Stewart 		filling_sinfo = 0;
609117205eccSRandall Stewart 	}
609217205eccSRandall Stewart 	if (name) {
609317205eccSRandall Stewart 		from = (struct sockaddr *)sockbuf;
609417205eccSRandall Stewart 		fromlen = sizeof(sockbuf);
609517205eccSRandall Stewart 		from->sa_len = 0;
609617205eccSRandall Stewart 	} else {
609717205eccSRandall Stewart 		from = NULL;
609817205eccSRandall Stewart 		fromlen = 0;
609917205eccSRandall Stewart 	}
610017205eccSRandall Stewart 
610117205eccSRandall Stewart 	error = sctp_sorecvmsg(so, uio,
610217205eccSRandall Stewart 	    (struct mbuf **)NULL,
610317205eccSRandall Stewart 	    from, fromlen, flag,
610417205eccSRandall Stewart 	    (struct sctp_sndrcvinfo *)&sinfo,
610517205eccSRandall Stewart 	    filling_sinfo);
610617205eccSRandall Stewart 	if ((controlp) && (filling_sinfo)) {
610717205eccSRandall Stewart 		/*
610817205eccSRandall Stewart 		 * copy back the sinfo in a CMSG format note that the caller
610917205eccSRandall Stewart 		 * has reponsibility for freeing the memory.
611017205eccSRandall Stewart 		 */
611117205eccSRandall Stewart 		if (filling_sinfo)
611217205eccSRandall Stewart 			*controlp = sctp_build_ctl_cchunk(inp,
611317205eccSRandall Stewart 			    controllen,
611417205eccSRandall Stewart 			    (struct sctp_sndrcvinfo *)&sinfo);
611517205eccSRandall Stewart 	}
611617205eccSRandall Stewart 	if (name) {
611717205eccSRandall Stewart 		/* copy back the address info */
611817205eccSRandall Stewart 		if (from && from->sa_len) {
611917205eccSRandall Stewart 			*name = sodupsockaddr(from, M_WAIT);
612017205eccSRandall Stewart 		} else {
612117205eccSRandall Stewart 			*name = NULL;
612217205eccSRandall Stewart 		}
612317205eccSRandall Stewart 	}
612417205eccSRandall Stewart 	return (error);
612517205eccSRandall Stewart }
612617205eccSRandall Stewart 
612717205eccSRandall Stewart 
612817205eccSRandall Stewart 
612917205eccSRandall Stewart 
613017205eccSRandall Stewart 
613117205eccSRandall Stewart 
613217205eccSRandall Stewart 
613317205eccSRandall Stewart int
6134d61a0ae0SRandall Stewart sctp_connectx_helper_add(struct sctp_tcb *stcb, struct sockaddr *addr,
6135d61a0ae0SRandall Stewart     int totaddr, int *error)
613617205eccSRandall Stewart {
613717205eccSRandall Stewart 	int added = 0;
613817205eccSRandall Stewart 	int i;
613917205eccSRandall Stewart 	struct sctp_inpcb *inp;
614017205eccSRandall Stewart 	struct sockaddr *sa;
614117205eccSRandall Stewart 	size_t incr = 0;
614217205eccSRandall Stewart 
614317205eccSRandall Stewart 	sa = addr;
614417205eccSRandall Stewart 	inp = stcb->sctp_ep;
614517205eccSRandall Stewart 	*error = 0;
614617205eccSRandall Stewart 	for (i = 0; i < totaddr; i++) {
614717205eccSRandall Stewart 		if (sa->sa_family == AF_INET) {
614817205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in);
614917205eccSRandall Stewart 			if (sctp_add_remote_addr(stcb, sa, SCTP_DONOT_SETSCOPE, SCTP_ADDR_IS_CONFIRMED)) {
615017205eccSRandall Stewart 				/* assoc gone no un-lock */
6151c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOBUFS);
6152c4739e2fSRandall Stewart 				(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC, SCTP_FROM_SCTP_USRREQ + SCTP_LOC_7);
615317205eccSRandall Stewart 				*error = ENOBUFS;
615417205eccSRandall Stewart 				goto out_now;
615517205eccSRandall Stewart 			}
615617205eccSRandall Stewart 			added++;
615717205eccSRandall Stewart 		} else if (sa->sa_family == AF_INET6) {
615817205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in6);
615917205eccSRandall Stewart 			if (sctp_add_remote_addr(stcb, sa, SCTP_DONOT_SETSCOPE, SCTP_ADDR_IS_CONFIRMED)) {
616017205eccSRandall Stewart 				/* assoc gone no un-lock */
6161c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(NULL, stcb, NULL, SCTP_FROM_SCTPUTIL, ENOBUFS);
6162c4739e2fSRandall Stewart 				(void)sctp_free_assoc(inp, stcb, SCTP_NORMAL_PROC, SCTP_FROM_SCTP_USRREQ + SCTP_LOC_8);
616317205eccSRandall Stewart 				*error = ENOBUFS;
616417205eccSRandall Stewart 				goto out_now;
616517205eccSRandall Stewart 			}
616617205eccSRandall Stewart 			added++;
616717205eccSRandall Stewart 		}
616817205eccSRandall Stewart 		sa = (struct sockaddr *)((caddr_t)sa + incr);
616917205eccSRandall Stewart 	}
617017205eccSRandall Stewart out_now:
617117205eccSRandall Stewart 	return (added);
617217205eccSRandall Stewart }
617317205eccSRandall Stewart 
617417205eccSRandall Stewart struct sctp_tcb *
6175d61a0ae0SRandall Stewart sctp_connectx_helper_find(struct sctp_inpcb *inp, struct sockaddr *addr,
6176d61a0ae0SRandall Stewart     int *totaddr, int *num_v4, int *num_v6, int *error,
6177d61a0ae0SRandall Stewart     int limit, int *bad_addr)
617817205eccSRandall Stewart {
617917205eccSRandall Stewart 	struct sockaddr *sa;
618017205eccSRandall Stewart 	struct sctp_tcb *stcb = NULL;
618117205eccSRandall Stewart 	size_t incr, at, i;
618217205eccSRandall Stewart 
618317205eccSRandall Stewart 	at = incr = 0;
618417205eccSRandall Stewart 	sa = addr;
618517205eccSRandall Stewart 	*error = *num_v6 = *num_v4 = 0;
618617205eccSRandall Stewart 	/* account and validate addresses */
61874c9179adSRandall Stewart 	for (i = 0; i < (size_t)*totaddr; i++) {
618817205eccSRandall Stewart 		if (sa->sa_family == AF_INET) {
618917205eccSRandall Stewart 			(*num_v4) += 1;
619017205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in);
6191d61a0ae0SRandall Stewart 			if (sa->sa_len != incr) {
6192c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6193d61a0ae0SRandall Stewart 				*error = EINVAL;
6194d61a0ae0SRandall Stewart 				*bad_addr = 1;
6195d61a0ae0SRandall Stewart 				return (NULL);
6196d61a0ae0SRandall Stewart 			}
619717205eccSRandall Stewart 		} else if (sa->sa_family == AF_INET6) {
619817205eccSRandall Stewart 			struct sockaddr_in6 *sin6;
619917205eccSRandall Stewart 
620017205eccSRandall Stewart 			sin6 = (struct sockaddr_in6 *)sa;
620117205eccSRandall Stewart 			if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
620217205eccSRandall Stewart 				/* Must be non-mapped for connectx */
6203c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
620417205eccSRandall Stewart 				*error = EINVAL;
6205d61a0ae0SRandall Stewart 				*bad_addr = 1;
620617205eccSRandall Stewart 				return (NULL);
620717205eccSRandall Stewart 			}
620817205eccSRandall Stewart 			(*num_v6) += 1;
620917205eccSRandall Stewart 			incr = sizeof(struct sockaddr_in6);
6210d61a0ae0SRandall Stewart 			if (sa->sa_len != incr) {
6211c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6212d61a0ae0SRandall Stewart 				*error = EINVAL;
6213d61a0ae0SRandall Stewart 				*bad_addr = 1;
6214d61a0ae0SRandall Stewart 				return (NULL);
6215d61a0ae0SRandall Stewart 			}
621617205eccSRandall Stewart 		} else {
621717205eccSRandall Stewart 			*totaddr = i;
621817205eccSRandall Stewart 			/* we are done */
621917205eccSRandall Stewart 			break;
622017205eccSRandall Stewart 		}
6221d61a0ae0SRandall Stewart 		SCTP_INP_INCR_REF(inp);
622217205eccSRandall Stewart 		stcb = sctp_findassociation_ep_addr(&inp, sa, NULL, NULL, NULL);
622317205eccSRandall Stewart 		if (stcb != NULL) {
622417205eccSRandall Stewart 			/* Already have or am bring up an association */
622517205eccSRandall Stewart 			return (stcb);
6226d61a0ae0SRandall Stewart 		} else {
6227d61a0ae0SRandall Stewart 			SCTP_INP_DECR_REF(inp);
622817205eccSRandall Stewart 		}
62294c9179adSRandall Stewart 		if ((at + incr) > (size_t)limit) {
623017205eccSRandall Stewart 			*totaddr = i;
623117205eccSRandall Stewart 			break;
623217205eccSRandall Stewart 		}
623317205eccSRandall Stewart 		sa = (struct sockaddr *)((caddr_t)sa + incr);
623417205eccSRandall Stewart 	}
623517205eccSRandall Stewart 	return ((struct sctp_tcb *)NULL);
623617205eccSRandall Stewart }
623735918f85SRandall Stewart 
623835918f85SRandall Stewart /*
623935918f85SRandall Stewart  * sctp_bindx(ADD) for one address.
624035918f85SRandall Stewart  * assumes all arguments are valid/checked by caller.
624135918f85SRandall Stewart  */
624235918f85SRandall Stewart void
624335918f85SRandall Stewart sctp_bindx_add_address(struct socket *so, struct sctp_inpcb *inp,
624435918f85SRandall Stewart     struct sockaddr *sa, sctp_assoc_t assoc_id,
624535918f85SRandall Stewart     uint32_t vrf_id, int *error, void *p)
624635918f85SRandall Stewart {
624735918f85SRandall Stewart 	struct sockaddr *addr_touse;
62485e2c2d87SRandall Stewart 
62495e2c2d87SRandall Stewart #ifdef INET6
625035918f85SRandall Stewart 	struct sockaddr_in sin;
625135918f85SRandall Stewart 
62525e2c2d87SRandall Stewart #endif
62535e2c2d87SRandall Stewart 
625435918f85SRandall Stewart 	/* see if we're bound all already! */
625535918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
6256c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
625735918f85SRandall Stewart 		*error = EINVAL;
625835918f85SRandall Stewart 		return;
625935918f85SRandall Stewart 	}
626035918f85SRandall Stewart 	addr_touse = sa;
6261fc14de76SRandall Stewart #if defined(INET6) && !defined(__Userspace__)	/* TODO port in6_sin6_2_sin */
626235918f85SRandall Stewart 	if (sa->sa_family == AF_INET6) {
626335918f85SRandall Stewart 		struct sockaddr_in6 *sin6;
626435918f85SRandall Stewart 
626535918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in6)) {
6266c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
626735918f85SRandall Stewart 			*error = EINVAL;
626835918f85SRandall Stewart 			return;
626935918f85SRandall Stewart 		}
6270db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) == 0) {
6271db4fd95bSRandall Stewart 			/* can only bind v6 on PF_INET6 sockets */
6272c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6273db4fd95bSRandall Stewart 			*error = EINVAL;
6274db4fd95bSRandall Stewart 			return;
6275db4fd95bSRandall Stewart 		}
627635918f85SRandall Stewart 		sin6 = (struct sockaddr_in6 *)addr_touse;
627735918f85SRandall Stewart 		if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
6278db4fd95bSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6279db4fd95bSRandall Stewart 			    SCTP_IPV6_V6ONLY(inp)) {
6280db4fd95bSRandall Stewart 				/* can't bind v4-mapped on PF_INET sockets */
6281c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6282db4fd95bSRandall Stewart 				*error = EINVAL;
6283db4fd95bSRandall Stewart 				return;
6284db4fd95bSRandall Stewart 			}
628535918f85SRandall Stewart 			in6_sin6_2_sin(&sin, sin6);
628635918f85SRandall Stewart 			addr_touse = (struct sockaddr *)&sin;
628735918f85SRandall Stewart 		}
628835918f85SRandall Stewart 	}
628935918f85SRandall Stewart #endif
629035918f85SRandall Stewart 	if (sa->sa_family == AF_INET) {
629135918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in)) {
6292c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
629335918f85SRandall Stewart 			*error = EINVAL;
629435918f85SRandall Stewart 			return;
629535918f85SRandall Stewart 		}
6296db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6297db4fd95bSRandall Stewart 		    SCTP_IPV6_V6ONLY(inp)) {
6298db4fd95bSRandall Stewart 			/* can't bind v4 on PF_INET sockets */
6299c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6300db4fd95bSRandall Stewart 			*error = EINVAL;
6301db4fd95bSRandall Stewart 			return;
6302db4fd95bSRandall Stewart 		}
630335918f85SRandall Stewart 	}
630435918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_UNBOUND) {
630535918f85SRandall Stewart 		if (p == NULL) {
630635918f85SRandall Stewart 			/* Can't get proc for Net/Open BSD */
6307c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
630835918f85SRandall Stewart 			*error = EINVAL;
630935918f85SRandall Stewart 			return;
631035918f85SRandall Stewart 		}
63111b649582SRandall Stewart 		*error = sctp_inpcb_bind(so, addr_touse, NULL, p);
631235918f85SRandall Stewart 		return;
631335918f85SRandall Stewart 	}
631435918f85SRandall Stewart 	/*
631535918f85SRandall Stewart 	 * No locks required here since bind and mgmt_ep_sa all do their own
631635918f85SRandall Stewart 	 * locking. If we do something for the FIX: below we may need to
631735918f85SRandall Stewart 	 * lock in that case.
631835918f85SRandall Stewart 	 */
631935918f85SRandall Stewart 	if (assoc_id == 0) {
632035918f85SRandall Stewart 		/* add the address */
632135918f85SRandall Stewart 		struct sctp_inpcb *lep;
632297c76f10SRandall Stewart 		struct sockaddr_in *lsin = (struct sockaddr_in *)addr_touse;
632335918f85SRandall Stewart 
632497c76f10SRandall Stewart 		/* validate the incoming port */
632597c76f10SRandall Stewart 		if ((lsin->sin_port != 0) &&
632697c76f10SRandall Stewart 		    (lsin->sin_port != inp->sctp_lport)) {
6327c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
632897c76f10SRandall Stewart 			*error = EINVAL;
632997c76f10SRandall Stewart 			return;
633097c76f10SRandall Stewart 		} else {
633197c76f10SRandall Stewart 			/* user specified 0 port, set it to existing port */
633297c76f10SRandall Stewart 			lsin->sin_port = inp->sctp_lport;
633397c76f10SRandall Stewart 		}
633497c76f10SRandall Stewart 
633535918f85SRandall Stewart 		lep = sctp_pcb_findep(addr_touse, 1, 0, vrf_id);
633635918f85SRandall Stewart 		if (lep != NULL) {
633735918f85SRandall Stewart 			/*
633835918f85SRandall Stewart 			 * We must decrement the refcount since we have the
633935918f85SRandall Stewart 			 * ep already and are binding. No remove going on
634035918f85SRandall Stewart 			 * here.
634135918f85SRandall Stewart 			 */
63426d9e8f2bSRandall Stewart 			SCTP_INP_DECR_REF(lep);
634335918f85SRandall Stewart 		}
634435918f85SRandall Stewart 		if (lep == inp) {
634535918f85SRandall Stewart 			/* already bound to it.. ok */
634635918f85SRandall Stewart 			return;
634735918f85SRandall Stewart 		} else if (lep == NULL) {
634835918f85SRandall Stewart 			((struct sockaddr_in *)addr_touse)->sin_port = 0;
634935918f85SRandall Stewart 			*error = sctp_addr_mgmt_ep_sa(inp, addr_touse,
635035918f85SRandall Stewart 			    SCTP_ADD_IP_ADDRESS,
635180fefe0aSRandall Stewart 			    vrf_id, NULL);
635235918f85SRandall Stewart 		} else {
635335918f85SRandall Stewart 			*error = EADDRINUSE;
635435918f85SRandall Stewart 		}
635535918f85SRandall Stewart 		if (*error)
635635918f85SRandall Stewart 			return;
635735918f85SRandall Stewart 	} else {
635835918f85SRandall Stewart 		/*
635935918f85SRandall Stewart 		 * FIX: decide whether we allow assoc based bindx
636035918f85SRandall Stewart 		 */
636135918f85SRandall Stewart 	}
636235918f85SRandall Stewart }
636335918f85SRandall Stewart 
636435918f85SRandall Stewart /*
636535918f85SRandall Stewart  * sctp_bindx(DELETE) for one address.
636635918f85SRandall Stewart  * assumes all arguments are valid/checked by caller.
636735918f85SRandall Stewart  */
636835918f85SRandall Stewart void
636935918f85SRandall Stewart sctp_bindx_delete_address(struct socket *so, struct sctp_inpcb *inp,
637035918f85SRandall Stewart     struct sockaddr *sa, sctp_assoc_t assoc_id,
637135918f85SRandall Stewart     uint32_t vrf_id, int *error)
637235918f85SRandall Stewart {
637335918f85SRandall Stewart 	struct sockaddr *addr_touse;
63745e2c2d87SRandall Stewart 
63755e2c2d87SRandall Stewart #ifdef INET6
637635918f85SRandall Stewart 	struct sockaddr_in sin;
637735918f85SRandall Stewart 
63785e2c2d87SRandall Stewart #endif
63795e2c2d87SRandall Stewart 
638035918f85SRandall Stewart 	/* see if we're bound all already! */
638135918f85SRandall Stewart 	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
6382c4739e2fSRandall Stewart 		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
638335918f85SRandall Stewart 		*error = EINVAL;
638435918f85SRandall Stewart 		return;
638535918f85SRandall Stewart 	}
638635918f85SRandall Stewart 	addr_touse = sa;
6387fc14de76SRandall Stewart #if defined(INET6) && !defined(__Userspace__)	/* TODO port in6_sin6_2_sin */
638835918f85SRandall Stewart 	if (sa->sa_family == AF_INET6) {
638935918f85SRandall Stewart 		struct sockaddr_in6 *sin6;
639035918f85SRandall Stewart 
639135918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in6)) {
6392c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
639335918f85SRandall Stewart 			*error = EINVAL;
639435918f85SRandall Stewart 			return;
639535918f85SRandall Stewart 		}
6396db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) == 0) {
6397db4fd95bSRandall Stewart 			/* can only bind v6 on PF_INET6 sockets */
6398c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6399db4fd95bSRandall Stewart 			*error = EINVAL;
6400db4fd95bSRandall Stewart 			return;
6401db4fd95bSRandall Stewart 		}
640235918f85SRandall Stewart 		sin6 = (struct sockaddr_in6 *)addr_touse;
640335918f85SRandall Stewart 		if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
6404db4fd95bSRandall Stewart 			if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6405db4fd95bSRandall Stewart 			    SCTP_IPV6_V6ONLY(inp)) {
6406db4fd95bSRandall Stewart 				/* can't bind mapped-v4 on PF_INET sockets */
6407c4739e2fSRandall Stewart 				SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6408db4fd95bSRandall Stewart 				*error = EINVAL;
6409db4fd95bSRandall Stewart 				return;
6410db4fd95bSRandall Stewart 			}
641135918f85SRandall Stewart 			in6_sin6_2_sin(&sin, sin6);
641235918f85SRandall Stewart 			addr_touse = (struct sockaddr *)&sin;
641335918f85SRandall Stewart 		}
641435918f85SRandall Stewart 	}
641535918f85SRandall Stewart #endif
641635918f85SRandall Stewart 	if (sa->sa_family == AF_INET) {
641735918f85SRandall Stewart 		if (sa->sa_len != sizeof(struct sockaddr_in)) {
6418c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
641935918f85SRandall Stewart 			*error = EINVAL;
642035918f85SRandall Stewart 			return;
642135918f85SRandall Stewart 		}
6422db4fd95bSRandall Stewart 		if ((inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) &&
6423db4fd95bSRandall Stewart 		    SCTP_IPV6_V6ONLY(inp)) {
6424db4fd95bSRandall Stewart 			/* can't bind v4 on PF_INET sockets */
6425c4739e2fSRandall Stewart 			SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTPUTIL, EINVAL);
6426db4fd95bSRandall Stewart 			*error = EINVAL;
6427db4fd95bSRandall Stewart 			return;
6428db4fd95bSRandall Stewart 		}
642935918f85SRandall Stewart 	}
643035918f85SRandall Stewart 	/*
643135918f85SRandall Stewart 	 * No lock required mgmt_ep_sa does its own locking. If the FIX:
643235918f85SRandall Stewart 	 * below is ever changed we may need to lock before calling
643335918f85SRandall Stewart 	 * association level binding.
643435918f85SRandall Stewart 	 */
643535918f85SRandall Stewart 	if (assoc_id == 0) {
643635918f85SRandall Stewart 		/* delete the address */
643735918f85SRandall Stewart 		*error = sctp_addr_mgmt_ep_sa(inp, addr_touse,
643835918f85SRandall Stewart 		    SCTP_DEL_IP_ADDRESS,
643980fefe0aSRandall Stewart 		    vrf_id, NULL);
644035918f85SRandall Stewart 	} else {
644135918f85SRandall Stewart 		/*
644235918f85SRandall Stewart 		 * FIX: decide whether we allow assoc based bindx
644335918f85SRandall Stewart 		 */
644435918f85SRandall Stewart 	}
644535918f85SRandall Stewart }
64461b649582SRandall Stewart 
64471b649582SRandall Stewart /*
64481b649582SRandall Stewart  * returns the valid local address count for an assoc, taking into account
64491b649582SRandall Stewart  * all scoping rules
64501b649582SRandall Stewart  */
64511b649582SRandall Stewart int
64521b649582SRandall Stewart sctp_local_addr_count(struct sctp_tcb *stcb)
64531b649582SRandall Stewart {
64541b649582SRandall Stewart 	int loopback_scope, ipv4_local_scope, local_scope, site_scope;
64551b649582SRandall Stewart 	int ipv4_addr_legal, ipv6_addr_legal;
64561b649582SRandall Stewart 	struct sctp_vrf *vrf;
64571b649582SRandall Stewart 	struct sctp_ifn *sctp_ifn;
64581b649582SRandall Stewart 	struct sctp_ifa *sctp_ifa;
64591b649582SRandall Stewart 	int count = 0;
64601b649582SRandall Stewart 
64611b649582SRandall Stewart 	/* Turn on all the appropriate scopes */
64621b649582SRandall Stewart 	loopback_scope = stcb->asoc.loopback_scope;
64631b649582SRandall Stewart 	ipv4_local_scope = stcb->asoc.ipv4_local_scope;
64641b649582SRandall Stewart 	local_scope = stcb->asoc.local_scope;
64651b649582SRandall Stewart 	site_scope = stcb->asoc.site_scope;
64661b649582SRandall Stewart 	ipv4_addr_legal = ipv6_addr_legal = 0;
64671b649582SRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) {
64681b649582SRandall Stewart 		ipv6_addr_legal = 1;
64691b649582SRandall Stewart 		if (SCTP_IPV6_V6ONLY(stcb->sctp_ep) == 0) {
64701b649582SRandall Stewart 			ipv4_addr_legal = 1;
64711b649582SRandall Stewart 		}
64721b649582SRandall Stewart 	} else {
64731b649582SRandall Stewart 		ipv4_addr_legal = 1;
64741b649582SRandall Stewart 	}
64751b649582SRandall Stewart 
6476c99efcf6SRandall Stewart 	SCTP_IPI_ADDR_RLOCK();
64771b649582SRandall Stewart 	vrf = sctp_find_vrf(stcb->asoc.vrf_id);
64781b649582SRandall Stewart 	if (vrf == NULL) {
64791b649582SRandall Stewart 		/* no vrf, no addresses */
6480c99efcf6SRandall Stewart 		SCTP_IPI_ADDR_RUNLOCK();
64811b649582SRandall Stewart 		return (0);
64821b649582SRandall Stewart 	}
64831b649582SRandall Stewart 	if (stcb->sctp_ep->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
64841b649582SRandall Stewart 		/*
64851b649582SRandall Stewart 		 * bound all case: go through all ifns on the vrf
64861b649582SRandall Stewart 		 */
64871b649582SRandall Stewart 		LIST_FOREACH(sctp_ifn, &vrf->ifnlist, next_ifn) {
64881b649582SRandall Stewart 			if ((loopback_scope == 0) &&
64891b649582SRandall Stewart 			    SCTP_IFN_IS_IFT_LOOP(sctp_ifn)) {
64901b649582SRandall Stewart 				continue;
64911b649582SRandall Stewart 			}
64921b649582SRandall Stewart 			LIST_FOREACH(sctp_ifa, &sctp_ifn->ifalist, next_ifa) {
64931b649582SRandall Stewart 				if (sctp_is_addr_restricted(stcb, sctp_ifa))
64941b649582SRandall Stewart 					continue;
64955e2c2d87SRandall Stewart 				switch (sctp_ifa->address.sa.sa_family) {
64965e2c2d87SRandall Stewart 				case AF_INET:
64975e2c2d87SRandall Stewart 					if (ipv4_addr_legal) {
64981b649582SRandall Stewart 						struct sockaddr_in *sin;
64991b649582SRandall Stewart 
65001b649582SRandall Stewart 						sin = (struct sockaddr_in *)&sctp_ifa->address.sa;
65011b649582SRandall Stewart 						if (sin->sin_addr.s_addr == 0) {
65025e2c2d87SRandall Stewart 							/*
65035e2c2d87SRandall Stewart 							 * skip unspecified
65045e2c2d87SRandall Stewart 							 * addrs
65055e2c2d87SRandall Stewart 							 */
65061b649582SRandall Stewart 							continue;
65071b649582SRandall Stewart 						}
65081b649582SRandall Stewart 						if ((ipv4_local_scope == 0) &&
65091b649582SRandall Stewart 						    (IN4_ISPRIVATE_ADDRESS(&sin->sin_addr))) {
65101b649582SRandall Stewart 							continue;
65111b649582SRandall Stewart 						}
65121b649582SRandall Stewart 						/* count this one */
65131b649582SRandall Stewart 						count++;
65145e2c2d87SRandall Stewart 					} else {
65155e2c2d87SRandall Stewart 						continue;
65165e2c2d87SRandall Stewart 					}
65175e2c2d87SRandall Stewart 					break;
65185e2c2d87SRandall Stewart #ifdef INET6
65195e2c2d87SRandall Stewart 				case AF_INET6:
65205e2c2d87SRandall Stewart 					if (ipv6_addr_legal) {
65211b649582SRandall Stewart 						struct sockaddr_in6 *sin6;
65221b649582SRandall Stewart 
65231b649582SRandall Stewart 						sin6 = (struct sockaddr_in6 *)&sctp_ifa->address.sa;
65241b649582SRandall Stewart 						if (IN6_IS_ADDR_UNSPECIFIED(&sin6->sin6_addr)) {
65251b649582SRandall Stewart 							continue;
65261b649582SRandall Stewart 						}
65271b649582SRandall Stewart 						if (IN6_IS_ADDR_LINKLOCAL(&sin6->sin6_addr)) {
65281b649582SRandall Stewart 							if (local_scope == 0)
65291b649582SRandall Stewart 								continue;
65301b649582SRandall Stewart 							if (sin6->sin6_scope_id == 0) {
65311b649582SRandall Stewart 								if (sa6_recoverscope(sin6) != 0)
65321b649582SRandall Stewart 									/*
65335e2c2d87SRandall Stewart 									 *
65345e2c2d87SRandall Stewart 									 * bad
65355e2c2d87SRandall Stewart 									 *
65365e2c2d87SRandall Stewart 									 * li
65375e2c2d87SRandall Stewart 									 * nk
65385e2c2d87SRandall Stewart 									 *
65395e2c2d87SRandall Stewart 									 * loc
65405e2c2d87SRandall Stewart 									 * al
65415e2c2d87SRandall Stewart 									 *
65425e2c2d87SRandall Stewart 									 * add
65435e2c2d87SRandall Stewart 									 * re
65445e2c2d87SRandall Stewart 									 * ss
65455e2c2d87SRandall Stewart 									 * */
65461b649582SRandall Stewart 									continue;
65471b649582SRandall Stewart 							}
65481b649582SRandall Stewart 						}
65491b649582SRandall Stewart 						if ((site_scope == 0) &&
65501b649582SRandall Stewart 						    (IN6_IS_ADDR_SITELOCAL(&sin6->sin6_addr))) {
65511b649582SRandall Stewart 							continue;
65521b649582SRandall Stewart 						}
65531b649582SRandall Stewart 						/* count this one */
65541b649582SRandall Stewart 						count++;
65551b649582SRandall Stewart 					}
65565e2c2d87SRandall Stewart 					break;
65575e2c2d87SRandall Stewart #endif
65585e2c2d87SRandall Stewart 				default:
65595e2c2d87SRandall Stewart 					/* TSNH */
65605e2c2d87SRandall Stewart 					break;
65615e2c2d87SRandall Stewart 				}
65621b649582SRandall Stewart 			}
65631b649582SRandall Stewart 		}
65641b649582SRandall Stewart 	} else {
65651b649582SRandall Stewart 		/*
65661b649582SRandall Stewart 		 * subset bound case
65671b649582SRandall Stewart 		 */
65681b649582SRandall Stewart 		struct sctp_laddr *laddr;
65691b649582SRandall Stewart 
65701b649582SRandall Stewart 		LIST_FOREACH(laddr, &stcb->sctp_ep->sctp_addr_list,
65711b649582SRandall Stewart 		    sctp_nxt_addr) {
65721b649582SRandall Stewart 			if (sctp_is_addr_restricted(stcb, laddr->ifa)) {
65731b649582SRandall Stewart 				continue;
65741b649582SRandall Stewart 			}
65751b649582SRandall Stewart 			/* count this one */
65761b649582SRandall Stewart 			count++;
65771b649582SRandall Stewart 		}
65781b649582SRandall Stewart 	}
6579c99efcf6SRandall Stewart 	SCTP_IPI_ADDR_RUNLOCK();
65801b649582SRandall Stewart 	return (count);
65811b649582SRandall Stewart }
6582c4739e2fSRandall Stewart 
6583c4739e2fSRandall Stewart #if defined(SCTP_LOCAL_TRACE_BUF)
6584c4739e2fSRandall Stewart 
6585c4739e2fSRandall Stewart void
6586b27a6b7dSRandall Stewart sctp_log_trace(uint32_t subsys, const char *str SCTP_UNUSED, uint32_t a, uint32_t b, uint32_t c, uint32_t d, uint32_t e, uint32_t f)
6587c4739e2fSRandall Stewart {
6588b27a6b7dSRandall Stewart 	uint32_t saveindex, newindex;
6589c4739e2fSRandall Stewart 
6590c4739e2fSRandall Stewart 	do {
6591b3f1ea41SRandall Stewart 		saveindex = SCTP_BASE_SYSCTL(sctp_log).index;
6592c4739e2fSRandall Stewart 		if (saveindex >= SCTP_MAX_LOGGING_SIZE) {
6593c4739e2fSRandall Stewart 			newindex = 1;
6594c4739e2fSRandall Stewart 		} else {
6595c4739e2fSRandall Stewart 			newindex = saveindex + 1;
6596c4739e2fSRandall Stewart 		}
6597b3f1ea41SRandall Stewart 	} while (atomic_cmpset_int(&SCTP_BASE_SYSCTL(sctp_log).index, saveindex, newindex) == 0);
6598c4739e2fSRandall Stewart 	if (saveindex >= SCTP_MAX_LOGGING_SIZE) {
6599c4739e2fSRandall Stewart 		saveindex = 0;
6600c4739e2fSRandall Stewart 	}
6601b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].timestamp = SCTP_GET_CYCLECOUNT;
6602b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].subsys = subsys;
6603b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[0] = a;
6604b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[1] = b;
6605b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[2] = c;
6606b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[3] = d;
6607b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[4] = e;
6608b3f1ea41SRandall Stewart 	SCTP_BASE_SYSCTL(sctp_log).entry[saveindex].params[5] = f;
6609c4739e2fSRandall Stewart }
6610c4739e2fSRandall Stewart 
6611c4739e2fSRandall Stewart #endif
6612c54a18d2SRandall Stewart /* We will need to add support
6613c54a18d2SRandall Stewart  * to bind the ports and such here
6614c54a18d2SRandall Stewart  * so we can do UDP tunneling. In
6615c54a18d2SRandall Stewart  * the mean-time, we return error
6616c54a18d2SRandall Stewart  */
6617a99b6783SRandall Stewart #include <netinet/udp.h>
6618a99b6783SRandall Stewart #include <netinet/udp_var.h>
6619a99b6783SRandall Stewart #include <sys/proc.h>
6620a1f2f7a5SRandall Stewart #ifdef INET6
6621a99b6783SRandall Stewart #include <netinet6/sctp6_var.h>
6622a1f2f7a5SRandall Stewart #endif
6623a99b6783SRandall Stewart 
6624a99b6783SRandall Stewart static void
6625a99b6783SRandall Stewart sctp_recv_udp_tunneled_packet(struct mbuf *m, int off, struct inpcb *ignored)
6626a99b6783SRandall Stewart {
6627a99b6783SRandall Stewart 	struct ip *iph;
6628a99b6783SRandall Stewart 	struct mbuf *sp, *last;
6629a99b6783SRandall Stewart 	struct udphdr *uhdr;
6630a99b6783SRandall Stewart 	uint16_t port = 0, len;
6631a99b6783SRandall Stewart 	int header_size = sizeof(struct udphdr) + sizeof(struct sctphdr);
6632a99b6783SRandall Stewart 
6633a99b6783SRandall Stewart 	/*
6634a99b6783SRandall Stewart 	 * Split out the mbuf chain. Leave the IP header in m, place the
6635a99b6783SRandall Stewart 	 * rest in the sp.
6636a99b6783SRandall Stewart 	 */
6637a99b6783SRandall Stewart 	if ((m->m_flags & M_PKTHDR) == 0) {
6638a99b6783SRandall Stewart 		/* Can't handle one that is not a pkt hdr */
6639a99b6783SRandall Stewart 		goto out;
6640a99b6783SRandall Stewart 	}
6641a99b6783SRandall Stewart 	/* pull the src port */
6642a99b6783SRandall Stewart 	iph = mtod(m, struct ip *);
6643a99b6783SRandall Stewart 	uhdr = (struct udphdr *)((caddr_t)iph + off);
6644a99b6783SRandall Stewart 
6645a99b6783SRandall Stewart 	port = uhdr->uh_sport;
6646a99b6783SRandall Stewart 	sp = m_split(m, off, M_DONTWAIT);
6647a99b6783SRandall Stewart 	if (sp == NULL) {
6648a99b6783SRandall Stewart 		/* Gak, drop packet, we can't do a split */
6649a99b6783SRandall Stewart 		goto out;
6650a99b6783SRandall Stewart 	}
6651a99b6783SRandall Stewart 	if (sp->m_pkthdr.len < header_size) {
6652a99b6783SRandall Stewart 		/* Gak, packet can't have an SCTP header in it - to small */
6653a99b6783SRandall Stewart 		m_freem(sp);
6654a99b6783SRandall Stewart 		goto out;
6655a99b6783SRandall Stewart 	}
6656a99b6783SRandall Stewart 	/* ok now pull up the UDP header and SCTP header together */
6657a99b6783SRandall Stewart 	sp = m_pullup(sp, header_size);
6658a99b6783SRandall Stewart 	if (sp == NULL) {
6659a99b6783SRandall Stewart 		/* Gak pullup failed */
6660a99b6783SRandall Stewart 		goto out;
6661a99b6783SRandall Stewart 	}
6662a99b6783SRandall Stewart 	/* trim out the UDP header */
6663a99b6783SRandall Stewart 	m_adj(sp, sizeof(struct udphdr));
6664a99b6783SRandall Stewart 
6665a99b6783SRandall Stewart 	/* Now reconstruct the mbuf chain */
6666a99b6783SRandall Stewart 	/* 1) find last one */
6667a99b6783SRandall Stewart 	last = m;
6668a99b6783SRandall Stewart 	while (last->m_next != NULL) {
6669a99b6783SRandall Stewart 		last = last->m_next;
6670a99b6783SRandall Stewart 	}
6671a99b6783SRandall Stewart 	last->m_next = sp;
6672a99b6783SRandall Stewart 	m->m_pkthdr.len += sp->m_pkthdr.len;
6673a99b6783SRandall Stewart 	last = m;
6674a99b6783SRandall Stewart 	while (last != NULL) {
6675a99b6783SRandall Stewart 		last = last->m_next;
6676a99b6783SRandall Stewart 	}
6677a99b6783SRandall Stewart 	/* Now its ready for sctp_input or sctp6_input */
6678a99b6783SRandall Stewart 	iph = mtod(m, struct ip *);
6679a99b6783SRandall Stewart 	switch (iph->ip_v) {
6680a99b6783SRandall Stewart 	case IPVERSION:
6681a99b6783SRandall Stewart 		{
6682a99b6783SRandall Stewart 			/* its IPv4 */
6683a99b6783SRandall Stewart 			len = SCTP_GET_IPV4_LENGTH(iph);
6684a99b6783SRandall Stewart 			len -= sizeof(struct udphdr);
6685a99b6783SRandall Stewart 			SCTP_GET_IPV4_LENGTH(iph) = len;
6686a99b6783SRandall Stewart 			sctp_input_with_port(m, off, port);
6687a99b6783SRandall Stewart 			break;
6688a99b6783SRandall Stewart 		}
6689a99b6783SRandall Stewart #ifdef INET6
6690a99b6783SRandall Stewart 	case IPV6_VERSION >> 4:
6691a99b6783SRandall Stewart 		{
6692a99b6783SRandall Stewart 			/* its IPv6 - NOT supported */
6693a99b6783SRandall Stewart 			goto out;
6694a99b6783SRandall Stewart 			break;
6695a99b6783SRandall Stewart 
6696a99b6783SRandall Stewart 		}
6697a99b6783SRandall Stewart #endif
6698a99b6783SRandall Stewart 	default:
6699a99b6783SRandall Stewart 		{
6700a99b6783SRandall Stewart 			m_freem(m);
6701a99b6783SRandall Stewart 			break;
6702a99b6783SRandall Stewart 		}
6703a99b6783SRandall Stewart 	}
6704a99b6783SRandall Stewart 	return;
6705a99b6783SRandall Stewart out:
6706a99b6783SRandall Stewart 	m_freem(m);
6707a99b6783SRandall Stewart }
6708c54a18d2SRandall Stewart 
6709c54a18d2SRandall Stewart void
6710c54a18d2SRandall Stewart sctp_over_udp_stop(void)
6711c54a18d2SRandall Stewart {
6712a99b6783SRandall Stewart 	struct socket *sop;
6713a99b6783SRandall Stewart 
6714a99b6783SRandall Stewart 	/*
6715a99b6783SRandall Stewart 	 * This function assumes sysctl caller holds sctp_sysctl_info_lock()
6716a99b6783SRandall Stewart 	 * for writting!
6717a99b6783SRandall Stewart 	 */
6718a99b6783SRandall Stewart 	if (SCTP_BASE_INFO(udp_tun_socket) == NULL) {
6719a99b6783SRandall Stewart 		/* Nothing to do */
6720c54a18d2SRandall Stewart 		return;
6721c54a18d2SRandall Stewart 	}
6722a99b6783SRandall Stewart 	sop = SCTP_BASE_INFO(udp_tun_socket);
6723a99b6783SRandall Stewart 	soclose(sop);
6724a99b6783SRandall Stewart 	SCTP_BASE_INFO(udp_tun_socket) = NULL;
6725a99b6783SRandall Stewart }
6726c54a18d2SRandall Stewart int
6727c54a18d2SRandall Stewart sctp_over_udp_start(void)
6728c54a18d2SRandall Stewart {
6729a99b6783SRandall Stewart 	uint16_t port;
6730a99b6783SRandall Stewart 	int ret;
6731a99b6783SRandall Stewart 	struct sockaddr_in sin;
6732a99b6783SRandall Stewart 	struct socket *sop = NULL;
6733a99b6783SRandall Stewart 	struct thread *th;
6734a99b6783SRandall Stewart 	struct ucred *cred;
6735a99b6783SRandall Stewart 
6736a99b6783SRandall Stewart 	/*
6737a99b6783SRandall Stewart 	 * This function assumes sysctl caller holds sctp_sysctl_info_lock()
6738a99b6783SRandall Stewart 	 * for writting!
6739a99b6783SRandall Stewart 	 */
6740a99b6783SRandall Stewart 	port = SCTP_BASE_SYSCTL(sctp_udp_tunneling_port);
6741a99b6783SRandall Stewart 	if (port == 0) {
6742a99b6783SRandall Stewart 		/* Must have a port set */
6743a99b6783SRandall Stewart 		return (EINVAL);
6744a99b6783SRandall Stewart 	}
6745a99b6783SRandall Stewart 	if (SCTP_BASE_INFO(udp_tun_socket) != NULL) {
6746a99b6783SRandall Stewart 		/* Already running -- must stop first */
6747a99b6783SRandall Stewart 		return (EALREADY);
6748a99b6783SRandall Stewart 	}
6749a99b6783SRandall Stewart 	th = curthread;
6750a99b6783SRandall Stewart 	cred = th->td_ucred;
6751a99b6783SRandall Stewart 	if ((ret = socreate(PF_INET, &sop,
6752a99b6783SRandall Stewart 	    SOCK_DGRAM, IPPROTO_UDP, cred, th))) {
6753a99b6783SRandall Stewart 		return (ret);
6754a99b6783SRandall Stewart 	}
6755a99b6783SRandall Stewart 	SCTP_BASE_INFO(udp_tun_socket) = sop;
6756a99b6783SRandall Stewart 	/* call the special UDP hook */
6757a99b6783SRandall Stewart 	ret = udp_set_kernel_tunneling(sop, sctp_recv_udp_tunneled_packet);
6758a99b6783SRandall Stewart 	if (ret) {
6759a99b6783SRandall Stewart 		goto exit_stage_left;
6760a99b6783SRandall Stewart 	}
6761a99b6783SRandall Stewart 	/* Ok we have a socket, bind it to the port */
6762a99b6783SRandall Stewart 	memset(&sin, 0, sizeof(sin));
6763a99b6783SRandall Stewart 	sin.sin_len = sizeof(sin);
6764a99b6783SRandall Stewart 	sin.sin_family = AF_INET;
6765a99b6783SRandall Stewart 	sin.sin_port = htons(port);
6766a99b6783SRandall Stewart 	ret = sobind(sop, (struct sockaddr *)&sin, th);
6767a99b6783SRandall Stewart 	if (ret) {
6768a99b6783SRandall Stewart 		/* Close up we cant get the port */
6769a99b6783SRandall Stewart exit_stage_left:
6770a99b6783SRandall Stewart 		sctp_over_udp_stop();
6771a99b6783SRandall Stewart 		return (ret);
6772a99b6783SRandall Stewart 	}
6773a99b6783SRandall Stewart 	/*
6774a99b6783SRandall Stewart 	 * Ok we should now get UDP packets directly to our input routine
6775a99b6783SRandall Stewart 	 * sctp_recv_upd_tunneled_packet().
6776a99b6783SRandall Stewart 	 */
6777a99b6783SRandall Stewart 	return (0);
6778c54a18d2SRandall Stewart }
6779