1 /*- 2 * SPDX-License-Identifier: BSD-3-Clause 3 * 4 * Copyright (c) 1982, 1986, 1988, 1990, 1993, 1995 5 * The Regents of the University of California. All rights reserved. 6 * Copyright (c) 2004 The FreeBSD Foundation. All rights reserved. 7 * Copyright (c) 2004-2008 Robert N. M. Watson. All rights reserved. 8 * 9 * Redistribution and use in source and binary forms, with or without 10 * modification, are permitted provided that the following conditions 11 * are met: 12 * 1. Redistributions of source code must retain the above copyright 13 * notice, this list of conditions and the following disclaimer. 14 * 2. Redistributions in binary form must reproduce the above copyright 15 * notice, this list of conditions and the following disclaimer in the 16 * documentation and/or other materials provided with the distribution. 17 * 3. Neither the name of the University nor the names of its contributors 18 * may be used to endorse or promote products derived from this software 19 * without specific prior written permission. 20 * 21 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND 22 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 23 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 24 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE 25 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 26 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 27 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 28 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 29 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 30 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 31 * SUCH DAMAGE. 32 * 33 * Excerpts taken from tcp_subr.c, tcp_usrreq.c, uipc_socket.c 34 */ 35 36 /* 37 * 38 * Copyright (c) 2010 Isilon Systems, Inc. 39 * Copyright (c) 2010 iX Systems, Inc. 40 * Copyright (c) 2010 Panasas, Inc. 41 * All rights reserved. 42 * 43 * Redistribution and use in source and binary forms, with or without 44 * modification, are permitted provided that the following conditions 45 * are met: 46 * 1. Redistributions of source code must retain the above copyright 47 * notice unmodified, this list of conditions, and the following 48 * disclaimer. 49 * 2. Redistributions in binary form must reproduce the above copyright 50 * notice, this list of conditions and the following disclaimer in the 51 * documentation and/or other materials provided with the distribution. 52 * 53 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR 54 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES 55 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. 56 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, 57 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT 58 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, 59 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY 60 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 61 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF 62 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 63 * 64 */ 65 #include <sys/cdefs.h> 66 __FBSDID("$FreeBSD$"); 67 68 #include <sys/param.h> 69 #include <sys/eventhandler.h> 70 #include <sys/kernel.h> 71 #include <sys/malloc.h> 72 73 #include "sdp.h" 74 75 #include <net/if.h> 76 #include <net/route.h> 77 #include <net/vnet.h> 78 #include <sys/sysctl.h> 79 80 uma_zone_t sdp_zone; 81 struct rwlock sdp_lock; 82 LIST_HEAD(, sdp_sock) sdp_list; 83 84 struct workqueue_struct *rx_comp_wq; 85 86 RW_SYSINIT(sdplockinit, &sdp_lock, "SDP lock"); 87 #define SDP_LIST_WLOCK() rw_wlock(&sdp_lock) 88 #define SDP_LIST_RLOCK() rw_rlock(&sdp_lock) 89 #define SDP_LIST_WUNLOCK() rw_wunlock(&sdp_lock) 90 #define SDP_LIST_RUNLOCK() rw_runlock(&sdp_lock) 91 #define SDP_LIST_WLOCK_ASSERT() rw_assert(&sdp_lock, RW_WLOCKED) 92 #define SDP_LIST_RLOCK_ASSERT() rw_assert(&sdp_lock, RW_RLOCKED) 93 #define SDP_LIST_LOCK_ASSERT() rw_assert(&sdp_lock, RW_LOCKED) 94 95 MALLOC_DEFINE(M_SDP, "sdp", "Sockets Direct Protocol"); 96 97 static void sdp_stop_keepalive_timer(struct socket *so); 98 99 /* 100 * SDP protocol interface to socket abstraction. 101 */ 102 /* 103 * sdp_sendspace and sdp_recvspace are the default send and receive window 104 * sizes, respectively. 105 */ 106 u_long sdp_sendspace = 1024*32; 107 u_long sdp_recvspace = 1024*64; 108 109 static int sdp_count; 110 111 /* 112 * Disable async. CMA events for sockets which are being torn down. 113 */ 114 static void 115 sdp_destroy_cma(struct sdp_sock *ssk) 116 { 117 118 if (ssk->id == NULL) 119 return; 120 rdma_destroy_id(ssk->id); 121 ssk->id = NULL; 122 } 123 124 static int 125 sdp_pcbbind(struct sdp_sock *ssk, struct sockaddr *nam, struct ucred *cred) 126 { 127 struct sockaddr_in *sin; 128 struct sockaddr_in null; 129 int error; 130 131 SDP_WLOCK_ASSERT(ssk); 132 133 if (ssk->lport != 0 || ssk->laddr != INADDR_ANY) 134 return (EINVAL); 135 /* rdma_bind_addr handles bind races. */ 136 SDP_WUNLOCK(ssk); 137 if (ssk->id == NULL) 138 ssk->id = rdma_create_id(&init_net, sdp_cma_handler, ssk, RDMA_PS_SDP, IB_QPT_RC); 139 if (ssk->id == NULL) { 140 SDP_WLOCK(ssk); 141 return (ENOMEM); 142 } 143 if (nam == NULL) { 144 null.sin_family = AF_INET; 145 null.sin_len = sizeof(null); 146 null.sin_addr.s_addr = INADDR_ANY; 147 null.sin_port = 0; 148 bzero(&null.sin_zero, sizeof(null.sin_zero)); 149 nam = (struct sockaddr *)&null; 150 } 151 error = -rdma_bind_addr(ssk->id, nam); 152 SDP_WLOCK(ssk); 153 if (error == 0) { 154 sin = (struct sockaddr_in *)&ssk->id->route.addr.src_addr; 155 ssk->laddr = sin->sin_addr.s_addr; 156 ssk->lport = sin->sin_port; 157 } else 158 sdp_destroy_cma(ssk); 159 return (error); 160 } 161 162 static void 163 sdp_pcbfree(struct sdp_sock *ssk) 164 { 165 166 KASSERT(ssk->socket == NULL, ("ssk %p socket still attached", ssk)); 167 KASSERT((ssk->flags & SDP_DESTROY) == 0, 168 ("ssk %p already destroyed", ssk)); 169 170 sdp_dbg(ssk->socket, "Freeing pcb"); 171 SDP_WLOCK_ASSERT(ssk); 172 ssk->flags |= SDP_DESTROY; 173 SDP_WUNLOCK(ssk); 174 SDP_LIST_WLOCK(); 175 sdp_count--; 176 LIST_REMOVE(ssk, list); 177 SDP_LIST_WUNLOCK(); 178 crfree(ssk->cred); 179 ssk->qp_active = 0; 180 if (ssk->qp) { 181 ib_destroy_qp(ssk->qp); 182 ssk->qp = NULL; 183 } 184 sdp_tx_ring_destroy(ssk); 185 sdp_rx_ring_destroy(ssk); 186 sdp_destroy_cma(ssk); 187 rw_destroy(&ssk->rx_ring.destroyed_lock); 188 rw_destroy(&ssk->lock); 189 uma_zfree(sdp_zone, ssk); 190 } 191 192 /* 193 * Common routines to return a socket address. 194 */ 195 static struct sockaddr * 196 sdp_sockaddr(in_port_t port, struct in_addr *addr_p) 197 { 198 struct sockaddr_in *sin; 199 200 sin = malloc(sizeof *sin, M_SONAME, 201 M_WAITOK | M_ZERO); 202 sin->sin_family = AF_INET; 203 sin->sin_len = sizeof(*sin); 204 sin->sin_addr = *addr_p; 205 sin->sin_port = port; 206 207 return (struct sockaddr *)sin; 208 } 209 210 static int 211 sdp_getsockaddr(struct socket *so, struct sockaddr **nam) 212 { 213 struct sdp_sock *ssk; 214 struct in_addr addr; 215 in_port_t port; 216 217 ssk = sdp_sk(so); 218 SDP_RLOCK(ssk); 219 port = ssk->lport; 220 addr.s_addr = ssk->laddr; 221 SDP_RUNLOCK(ssk); 222 223 *nam = sdp_sockaddr(port, &addr); 224 return 0; 225 } 226 227 static int 228 sdp_getpeeraddr(struct socket *so, struct sockaddr **nam) 229 { 230 struct sdp_sock *ssk; 231 struct in_addr addr; 232 in_port_t port; 233 234 ssk = sdp_sk(so); 235 SDP_RLOCK(ssk); 236 port = ssk->fport; 237 addr.s_addr = ssk->faddr; 238 SDP_RUNLOCK(ssk); 239 240 *nam = sdp_sockaddr(port, &addr); 241 return 0; 242 } 243 244 static void 245 sdp_pcbnotifyall(struct in_addr faddr, int errno, 246 struct sdp_sock *(*notify)(struct sdp_sock *, int)) 247 { 248 struct sdp_sock *ssk, *ssk_temp; 249 250 SDP_LIST_WLOCK(); 251 LIST_FOREACH_SAFE(ssk, &sdp_list, list, ssk_temp) { 252 SDP_WLOCK(ssk); 253 if (ssk->faddr != faddr.s_addr || ssk->socket == NULL) { 254 SDP_WUNLOCK(ssk); 255 continue; 256 } 257 if ((ssk->flags & SDP_DESTROY) == 0) 258 if ((*notify)(ssk, errno)) 259 SDP_WUNLOCK(ssk); 260 } 261 SDP_LIST_WUNLOCK(); 262 } 263 264 #if 0 265 static void 266 sdp_apply_all(void (*func)(struct sdp_sock *, void *), void *arg) 267 { 268 struct sdp_sock *ssk; 269 270 SDP_LIST_RLOCK(); 271 LIST_FOREACH(ssk, &sdp_list, list) { 272 SDP_WLOCK(ssk); 273 func(ssk, arg); 274 SDP_WUNLOCK(ssk); 275 } 276 SDP_LIST_RUNLOCK(); 277 } 278 #endif 279 280 static void 281 sdp_output_reset(struct sdp_sock *ssk) 282 { 283 struct rdma_cm_id *id; 284 285 SDP_WLOCK_ASSERT(ssk); 286 if (ssk->id) { 287 id = ssk->id; 288 ssk->qp_active = 0; 289 SDP_WUNLOCK(ssk); 290 rdma_disconnect(id); 291 SDP_WLOCK(ssk); 292 } 293 ssk->state = TCPS_CLOSED; 294 } 295 296 /* 297 * Attempt to close a SDP socket, marking it as dropped, and freeing 298 * the socket if we hold the only reference. 299 */ 300 static struct sdp_sock * 301 sdp_closed(struct sdp_sock *ssk) 302 { 303 struct socket *so; 304 305 SDP_WLOCK_ASSERT(ssk); 306 307 ssk->flags |= SDP_DROPPED; 308 so = ssk->socket; 309 soisdisconnected(so); 310 if (ssk->flags & SDP_SOCKREF) { 311 KASSERT(so->so_state & SS_PROTOREF, 312 ("sdp_closed: !SS_PROTOREF")); 313 ssk->flags &= ~SDP_SOCKREF; 314 SDP_WUNLOCK(ssk); 315 SOCK_LOCK(so); 316 so->so_state &= ~SS_PROTOREF; 317 sofree(so); 318 return (NULL); 319 } 320 return (ssk); 321 } 322 323 /* 324 * Perform timer based shutdowns which can not operate in 325 * callout context. 326 */ 327 static void 328 sdp_shutdown_task(void *data, int pending) 329 { 330 struct sdp_sock *ssk; 331 332 ssk = data; 333 SDP_WLOCK(ssk); 334 /* 335 * I don't think this can race with another call to pcbfree() 336 * because SDP_TIMEWAIT protects it. SDP_DESTROY may be redundant. 337 */ 338 if (ssk->flags & SDP_DESTROY) 339 panic("sdp_shutdown_task: Racing with pcbfree for ssk %p", 340 ssk); 341 if (ssk->flags & SDP_DISCON) 342 sdp_output_reset(ssk); 343 /* We have to clear this so sdp_detach() will call pcbfree(). */ 344 ssk->flags &= ~(SDP_TIMEWAIT | SDP_DREQWAIT); 345 if ((ssk->flags & SDP_DROPPED) == 0 && 346 sdp_closed(ssk) == NULL) 347 return; 348 if (ssk->socket == NULL) { 349 sdp_pcbfree(ssk); 350 return; 351 } 352 SDP_WUNLOCK(ssk); 353 } 354 355 /* 356 * 2msl has expired, schedule the shutdown task. 357 */ 358 static void 359 sdp_2msl_timeout(void *data) 360 { 361 struct sdp_sock *ssk; 362 363 ssk = data; 364 /* Callout canceled. */ 365 if (!callout_active(&ssk->keep2msl)) 366 goto out; 367 callout_deactivate(&ssk->keep2msl); 368 /* Should be impossible, defensive programming. */ 369 if ((ssk->flags & SDP_TIMEWAIT) == 0) 370 goto out; 371 taskqueue_enqueue(taskqueue_thread, &ssk->shutdown_task); 372 out: 373 SDP_WUNLOCK(ssk); 374 return; 375 } 376 377 /* 378 * Schedule the 2msl wait timer. 379 */ 380 static void 381 sdp_2msl_wait(struct sdp_sock *ssk) 382 { 383 384 SDP_WLOCK_ASSERT(ssk); 385 ssk->flags |= SDP_TIMEWAIT; 386 ssk->state = TCPS_TIME_WAIT; 387 soisdisconnected(ssk->socket); 388 callout_reset(&ssk->keep2msl, TCPTV_MSL, sdp_2msl_timeout, ssk); 389 } 390 391 /* 392 * Timed out waiting for the final fin/ack from rdma_disconnect(). 393 */ 394 static void 395 sdp_dreq_timeout(void *data) 396 { 397 struct sdp_sock *ssk; 398 399 ssk = data; 400 /* Callout canceled. */ 401 if (!callout_active(&ssk->keep2msl)) 402 goto out; 403 /* Callout rescheduled, probably as a different timer. */ 404 if (callout_pending(&ssk->keep2msl)) 405 goto out; 406 callout_deactivate(&ssk->keep2msl); 407 if (ssk->state != TCPS_FIN_WAIT_1 && ssk->state != TCPS_LAST_ACK) 408 goto out; 409 if ((ssk->flags & SDP_DREQWAIT) == 0) 410 goto out; 411 ssk->flags &= ~SDP_DREQWAIT; 412 ssk->flags |= SDP_DISCON; 413 sdp_2msl_wait(ssk); 414 ssk->qp_active = 0; 415 out: 416 SDP_WUNLOCK(ssk); 417 } 418 419 /* 420 * Received the final fin/ack. Cancel the 2msl. 421 */ 422 void 423 sdp_cancel_dreq_wait_timeout(struct sdp_sock *ssk) 424 { 425 sdp_dbg(ssk->socket, "cancelling dreq wait timeout\n"); 426 ssk->flags &= ~SDP_DREQWAIT; 427 sdp_2msl_wait(ssk); 428 } 429 430 static int 431 sdp_init_sock(struct socket *sk) 432 { 433 struct sdp_sock *ssk = sdp_sk(sk); 434 435 sdp_dbg(sk, "%s\n", __func__); 436 437 callout_init_rw(&ssk->keep2msl, &ssk->lock, CALLOUT_RETURNUNLOCKED); 438 TASK_INIT(&ssk->shutdown_task, 0, sdp_shutdown_task, ssk); 439 #ifdef SDP_ZCOPY 440 INIT_DELAYED_WORK(&ssk->srcavail_cancel_work, srcavail_cancel_timeout); 441 ssk->zcopy_thresh = -1; /* use global sdp_zcopy_thresh */ 442 ssk->tx_ring.rdma_inflight = NULL; 443 #endif 444 atomic_set(&ssk->mseq_ack, 0); 445 sdp_rx_ring_init(ssk); 446 ssk->tx_ring.buffer = NULL; 447 448 return 0; 449 } 450 451 /* 452 * Allocate an sdp_sock for the socket and reserve socket buffer space. 453 */ 454 static int 455 sdp_attach(struct socket *so, int proto, struct thread *td) 456 { 457 struct sdp_sock *ssk; 458 int error; 459 460 ssk = sdp_sk(so); 461 KASSERT(ssk == NULL, ("sdp_attach: ssk already set on so %p", so)); 462 if (so->so_snd.sb_hiwat == 0 || so->so_rcv.sb_hiwat == 0) { 463 error = soreserve(so, sdp_sendspace, sdp_recvspace); 464 if (error) 465 return (error); 466 } 467 so->so_rcv.sb_flags |= SB_AUTOSIZE; 468 so->so_snd.sb_flags |= SB_AUTOSIZE; 469 ssk = uma_zalloc(sdp_zone, M_NOWAIT | M_ZERO); 470 if (ssk == NULL) 471 return (ENOBUFS); 472 rw_init(&ssk->lock, "sdpsock"); 473 ssk->socket = so; 474 ssk->cred = crhold(so->so_cred); 475 so->so_pcb = (caddr_t)ssk; 476 sdp_init_sock(so); 477 ssk->flags = 0; 478 ssk->qp_active = 0; 479 ssk->state = TCPS_CLOSED; 480 mbufq_init(&ssk->rxctlq, INT_MAX); 481 SDP_LIST_WLOCK(); 482 LIST_INSERT_HEAD(&sdp_list, ssk, list); 483 sdp_count++; 484 SDP_LIST_WUNLOCK(); 485 486 return (0); 487 } 488 489 /* 490 * Detach SDP from the socket, potentially leaving it around for the 491 * timewait to expire. 492 */ 493 static void 494 sdp_detach(struct socket *so) 495 { 496 struct sdp_sock *ssk; 497 498 ssk = sdp_sk(so); 499 SDP_WLOCK(ssk); 500 KASSERT(ssk->socket != NULL, ("sdp_detach: socket is NULL")); 501 ssk->socket->so_pcb = NULL; 502 ssk->socket = NULL; 503 if (ssk->flags & (SDP_TIMEWAIT | SDP_DREQWAIT)) 504 SDP_WUNLOCK(ssk); 505 else if (ssk->flags & SDP_DROPPED || ssk->state < TCPS_SYN_SENT) 506 sdp_pcbfree(ssk); 507 else 508 panic("sdp_detach: Unexpected state, ssk %p.\n", ssk); 509 } 510 511 /* 512 * Allocate a local address for the socket. 513 */ 514 static int 515 sdp_bind(struct socket *so, struct sockaddr *nam, struct thread *td) 516 { 517 int error = 0; 518 struct sdp_sock *ssk; 519 struct sockaddr_in *sin; 520 521 sin = (struct sockaddr_in *)nam; 522 if (nam->sa_len != sizeof (*sin)) 523 return (EINVAL); 524 if (sin->sin_family != AF_INET) 525 return (EINVAL); 526 if (IN_MULTICAST(ntohl(sin->sin_addr.s_addr))) 527 return (EAFNOSUPPORT); 528 529 ssk = sdp_sk(so); 530 SDP_WLOCK(ssk); 531 if (ssk->flags & (SDP_TIMEWAIT | SDP_DROPPED)) { 532 error = EINVAL; 533 goto out; 534 } 535 error = sdp_pcbbind(ssk, nam, td->td_ucred); 536 out: 537 SDP_WUNLOCK(ssk); 538 539 return (error); 540 } 541 542 /* 543 * Prepare to accept connections. 544 */ 545 static int 546 sdp_listen(struct socket *so, int backlog, struct thread *td) 547 { 548 int error = 0; 549 struct sdp_sock *ssk; 550 551 ssk = sdp_sk(so); 552 SDP_WLOCK(ssk); 553 if (ssk->flags & (SDP_TIMEWAIT | SDP_DROPPED)) { 554 error = EINVAL; 555 goto out; 556 } 557 if (error == 0 && ssk->lport == 0) 558 error = sdp_pcbbind(ssk, (struct sockaddr *)0, td->td_ucred); 559 SOCK_LOCK(so); 560 if (error == 0) 561 error = solisten_proto_check(so); 562 if (error == 0) { 563 solisten_proto(so, backlog); 564 ssk->state = TCPS_LISTEN; 565 } 566 SOCK_UNLOCK(so); 567 568 out: 569 SDP_WUNLOCK(ssk); 570 if (error == 0) 571 error = -rdma_listen(ssk->id, backlog); 572 return (error); 573 } 574 575 /* 576 * Initiate a SDP connection to nam. 577 */ 578 static int 579 sdp_start_connect(struct sdp_sock *ssk, struct sockaddr *nam, struct thread *td) 580 { 581 struct sockaddr_in src; 582 struct socket *so; 583 int error; 584 585 so = ssk->socket; 586 587 SDP_WLOCK_ASSERT(ssk); 588 if (ssk->lport == 0) { 589 error = sdp_pcbbind(ssk, (struct sockaddr *)0, td->td_ucred); 590 if (error) 591 return error; 592 } 593 src.sin_family = AF_INET; 594 src.sin_len = sizeof(src); 595 bzero(&src.sin_zero, sizeof(src.sin_zero)); 596 src.sin_port = ssk->lport; 597 src.sin_addr.s_addr = ssk->laddr; 598 soisconnecting(so); 599 SDP_WUNLOCK(ssk); 600 error = -rdma_resolve_addr(ssk->id, (struct sockaddr *)&src, nam, 601 SDP_RESOLVE_TIMEOUT); 602 SDP_WLOCK(ssk); 603 if (error == 0) 604 ssk->state = TCPS_SYN_SENT; 605 606 return 0; 607 } 608 609 /* 610 * Initiate SDP connection. 611 */ 612 static int 613 sdp_connect(struct socket *so, struct sockaddr *nam, struct thread *td) 614 { 615 int error = 0; 616 struct sdp_sock *ssk; 617 struct sockaddr_in *sin; 618 619 sin = (struct sockaddr_in *)nam; 620 if (nam->sa_len != sizeof (*sin)) 621 return (EINVAL); 622 if (sin->sin_family != AF_INET) 623 return (EINVAL); 624 if (IN_MULTICAST(ntohl(sin->sin_addr.s_addr))) 625 return (EAFNOSUPPORT); 626 if ((error = prison_remote_ip4(td->td_ucred, &sin->sin_addr)) != 0) 627 return (error); 628 ssk = sdp_sk(so); 629 SDP_WLOCK(ssk); 630 if (ssk->flags & (SDP_TIMEWAIT | SDP_DROPPED)) 631 error = EINVAL; 632 else 633 error = sdp_start_connect(ssk, nam, td); 634 SDP_WUNLOCK(ssk); 635 return (error); 636 } 637 638 /* 639 * Drop a SDP socket, reporting 640 * the specified error. If connection is synchronized, 641 * then send a RST to peer. 642 */ 643 static struct sdp_sock * 644 sdp_drop(struct sdp_sock *ssk, int errno) 645 { 646 struct socket *so; 647 648 SDP_WLOCK_ASSERT(ssk); 649 so = ssk->socket; 650 if (TCPS_HAVERCVDSYN(ssk->state)) 651 sdp_output_reset(ssk); 652 if (errno == ETIMEDOUT && ssk->softerror) 653 errno = ssk->softerror; 654 so->so_error = errno; 655 return (sdp_closed(ssk)); 656 } 657 658 /* 659 * User issued close, and wish to trail through shutdown states: 660 * if never received SYN, just forget it. If got a SYN from peer, 661 * but haven't sent FIN, then go to FIN_WAIT_1 state to send peer a FIN. 662 * If already got a FIN from peer, then almost done; go to LAST_ACK 663 * state. In all other cases, have already sent FIN to peer (e.g. 664 * after PRU_SHUTDOWN), and just have to play tedious game waiting 665 * for peer to send FIN or not respond to keep-alives, etc. 666 * We can let the user exit from the close as soon as the FIN is acked. 667 */ 668 static void 669 sdp_usrclosed(struct sdp_sock *ssk) 670 { 671 672 SDP_WLOCK_ASSERT(ssk); 673 674 switch (ssk->state) { 675 case TCPS_LISTEN: 676 ssk->state = TCPS_CLOSED; 677 SDP_WUNLOCK(ssk); 678 sdp_destroy_cma(ssk); 679 SDP_WLOCK(ssk); 680 /* FALLTHROUGH */ 681 case TCPS_CLOSED: 682 ssk = sdp_closed(ssk); 683 /* 684 * sdp_closed() should never return NULL here as the socket is 685 * still open. 686 */ 687 KASSERT(ssk != NULL, 688 ("sdp_usrclosed: sdp_closed() returned NULL")); 689 break; 690 691 case TCPS_SYN_SENT: 692 /* FALLTHROUGH */ 693 case TCPS_SYN_RECEIVED: 694 ssk->flags |= SDP_NEEDFIN; 695 break; 696 697 case TCPS_ESTABLISHED: 698 ssk->flags |= SDP_NEEDFIN; 699 ssk->state = TCPS_FIN_WAIT_1; 700 break; 701 702 case TCPS_CLOSE_WAIT: 703 ssk->state = TCPS_LAST_ACK; 704 break; 705 } 706 if (ssk->state >= TCPS_FIN_WAIT_2) { 707 /* Prevent the connection hanging in FIN_WAIT_2 forever. */ 708 if (ssk->state == TCPS_FIN_WAIT_2) 709 sdp_2msl_wait(ssk); 710 else 711 soisdisconnected(ssk->socket); 712 } 713 } 714 715 static void 716 sdp_output_disconnect(struct sdp_sock *ssk) 717 { 718 719 SDP_WLOCK_ASSERT(ssk); 720 callout_reset(&ssk->keep2msl, SDP_FIN_WAIT_TIMEOUT, 721 sdp_dreq_timeout, ssk); 722 ssk->flags |= SDP_NEEDFIN | SDP_DREQWAIT; 723 sdp_post_sends(ssk, M_NOWAIT); 724 } 725 726 /* 727 * Initiate or continue a disconnect. 728 * If embryonic state, just send reset (once). 729 * If in ``let data drain'' option and linger null, just drop. 730 * Otherwise (hard), mark socket disconnecting and drop 731 * current input data; switch states based on user close, and 732 * send segment to peer (with FIN). 733 */ 734 static void 735 sdp_start_disconnect(struct sdp_sock *ssk) 736 { 737 struct socket *so; 738 int unread; 739 740 so = ssk->socket; 741 SDP_WLOCK_ASSERT(ssk); 742 sdp_stop_keepalive_timer(so); 743 /* 744 * Neither sdp_closed() nor sdp_drop() should return NULL, as the 745 * socket is still open. 746 */ 747 if (ssk->state < TCPS_ESTABLISHED) { 748 ssk = sdp_closed(ssk); 749 KASSERT(ssk != NULL, 750 ("sdp_start_disconnect: sdp_close() returned NULL")); 751 } else if ((so->so_options & SO_LINGER) && so->so_linger == 0) { 752 ssk = sdp_drop(ssk, 0); 753 KASSERT(ssk != NULL, 754 ("sdp_start_disconnect: sdp_drop() returned NULL")); 755 } else { 756 soisdisconnecting(so); 757 unread = sbused(&so->so_rcv); 758 sbflush(&so->so_rcv); 759 sdp_usrclosed(ssk); 760 if (!(ssk->flags & SDP_DROPPED)) { 761 if (unread) 762 sdp_output_reset(ssk); 763 else 764 sdp_output_disconnect(ssk); 765 } 766 } 767 } 768 769 /* 770 * User initiated disconnect. 771 */ 772 static int 773 sdp_disconnect(struct socket *so) 774 { 775 struct sdp_sock *ssk; 776 int error = 0; 777 778 ssk = sdp_sk(so); 779 SDP_WLOCK(ssk); 780 if (ssk->flags & (SDP_TIMEWAIT | SDP_DROPPED)) { 781 error = ECONNRESET; 782 goto out; 783 } 784 sdp_start_disconnect(ssk); 785 out: 786 SDP_WUNLOCK(ssk); 787 return (error); 788 } 789 790 /* 791 * Accept a connection. Essentially all the work is done at higher levels; 792 * just return the address of the peer, storing through addr. 793 * 794 * 795 * XXX This is broken XXX 796 * 797 * The rationale for acquiring the sdp lock here is somewhat complicated, 798 * and is described in detail in the commit log entry for r175612. Acquiring 799 * it delays an accept(2) racing with sonewconn(), which inserts the socket 800 * before the address/port fields are initialized. A better fix would 801 * prevent the socket from being placed in the listen queue until all fields 802 * are fully initialized. 803 */ 804 static int 805 sdp_accept(struct socket *so, struct sockaddr **nam) 806 { 807 struct sdp_sock *ssk = NULL; 808 struct in_addr addr; 809 in_port_t port; 810 int error; 811 812 if (so->so_state & SS_ISDISCONNECTED) 813 return (ECONNABORTED); 814 815 port = 0; 816 addr.s_addr = 0; 817 error = 0; 818 ssk = sdp_sk(so); 819 SDP_WLOCK(ssk); 820 if (ssk->flags & (SDP_TIMEWAIT | SDP_DROPPED)) { 821 error = ECONNABORTED; 822 goto out; 823 } 824 port = ssk->fport; 825 addr.s_addr = ssk->faddr; 826 out: 827 SDP_WUNLOCK(ssk); 828 if (error == 0) 829 *nam = sdp_sockaddr(port, &addr); 830 return error; 831 } 832 833 /* 834 * Mark the connection as being incapable of further output. 835 */ 836 static int 837 sdp_shutdown(struct socket *so) 838 { 839 int error = 0; 840 struct sdp_sock *ssk; 841 842 ssk = sdp_sk(so); 843 SDP_WLOCK(ssk); 844 if (ssk->flags & (SDP_TIMEWAIT | SDP_DROPPED)) { 845 error = ECONNRESET; 846 goto out; 847 } 848 socantsendmore(so); 849 sdp_usrclosed(ssk); 850 if (!(ssk->flags & SDP_DROPPED)) 851 sdp_output_disconnect(ssk); 852 853 out: 854 SDP_WUNLOCK(ssk); 855 856 return (error); 857 } 858 859 static void 860 sdp_append(struct sdp_sock *ssk, struct sockbuf *sb, struct mbuf *mb, int cnt) 861 { 862 struct mbuf *n; 863 int ncnt; 864 865 SOCKBUF_LOCK_ASSERT(sb); 866 SBLASTRECORDCHK(sb); 867 KASSERT(mb->m_flags & M_PKTHDR, 868 ("sdp_append: %p Missing packet header.\n", mb)); 869 n = sb->sb_lastrecord; 870 /* 871 * If the queue is empty just set all pointers and proceed. 872 */ 873 if (n == NULL) { 874 sb->sb_lastrecord = sb->sb_mb = sb->sb_sndptr = mb; 875 for (; mb; mb = mb->m_next) { 876 sb->sb_mbtail = mb; 877 sballoc(sb, mb); 878 } 879 return; 880 } 881 /* 882 * Count the number of mbufs in the current tail. 883 */ 884 for (ncnt = 0; n->m_next; n = n->m_next) 885 ncnt++; 886 n = sb->sb_lastrecord; 887 /* 888 * If the two chains can fit in a single sdp packet and 889 * the last record has not been sent yet (WRITABLE) coalesce 890 * them. The lastrecord remains the same but we must strip the 891 * packet header and then let sbcompress do the hard part. 892 */ 893 if (M_WRITABLE(n) && ncnt + cnt < SDP_MAX_SEND_SGES && 894 n->m_pkthdr.len + mb->m_pkthdr.len - SDP_HEAD_SIZE < 895 ssk->xmit_size_goal) { 896 m_adj(mb, SDP_HEAD_SIZE); 897 n->m_pkthdr.len += mb->m_pkthdr.len; 898 n->m_flags |= mb->m_flags & (M_PUSH | M_URG); 899 m_demote(mb, 1, 0); 900 sbcompress(sb, mb, sb->sb_mbtail); 901 return; 902 } 903 /* 904 * Not compressible, just append to the end and adjust counters. 905 */ 906 sb->sb_lastrecord->m_flags |= M_PUSH; 907 sb->sb_lastrecord->m_nextpkt = mb; 908 sb->sb_lastrecord = mb; 909 if (sb->sb_sndptr == NULL) 910 sb->sb_sndptr = mb; 911 for (; mb; mb = mb->m_next) { 912 sb->sb_mbtail = mb; 913 sballoc(sb, mb); 914 } 915 } 916 917 /* 918 * Do a send by putting data in output queue and updating urgent 919 * marker if URG set. Possibly send more data. Unlike the other 920 * pru_*() routines, the mbuf chains are our responsibility. We 921 * must either enqueue them or free them. The other pru_* routines 922 * generally are caller-frees. 923 * 924 * This comes from sendfile, normal sends will come from sdp_sosend(). 925 */ 926 static int 927 sdp_send(struct socket *so, int flags, struct mbuf *m, 928 struct sockaddr *nam, struct mbuf *control, struct thread *td) 929 { 930 struct sdp_sock *ssk; 931 struct mbuf *n; 932 int error; 933 int cnt; 934 935 error = 0; 936 ssk = sdp_sk(so); 937 KASSERT(m->m_flags & M_PKTHDR, 938 ("sdp_send: %p no packet header", m)); 939 M_PREPEND(m, SDP_HEAD_SIZE, M_WAITOK); 940 mtod(m, struct sdp_bsdh *)->mid = SDP_MID_DATA; 941 for (n = m, cnt = 0; n->m_next; n = n->m_next) 942 cnt++; 943 if (cnt > SDP_MAX_SEND_SGES) { 944 n = m_collapse(m, M_WAITOK, SDP_MAX_SEND_SGES); 945 if (n == NULL) { 946 m_freem(m); 947 return (EMSGSIZE); 948 } 949 m = n; 950 for (cnt = 0; n->m_next; n = n->m_next) 951 cnt++; 952 } 953 SDP_WLOCK(ssk); 954 if (ssk->flags & (SDP_TIMEWAIT | SDP_DROPPED)) { 955 if (control) 956 m_freem(control); 957 if (m) 958 m_freem(m); 959 error = ECONNRESET; 960 goto out; 961 } 962 if (control) { 963 /* SDP doesn't support control messages. */ 964 if (control->m_len) { 965 m_freem(control); 966 if (m) 967 m_freem(m); 968 error = EINVAL; 969 goto out; 970 } 971 m_freem(control); /* empty control, just free it */ 972 } 973 if (!(flags & PRUS_OOB)) { 974 SOCKBUF_LOCK(&so->so_snd); 975 sdp_append(ssk, &so->so_snd, m, cnt); 976 SOCKBUF_UNLOCK(&so->so_snd); 977 if (nam && ssk->state < TCPS_SYN_SENT) { 978 /* 979 * Do implied connect if not yet connected. 980 */ 981 error = sdp_start_connect(ssk, nam, td); 982 if (error) 983 goto out; 984 } 985 if (flags & PRUS_EOF) { 986 /* 987 * Close the send side of the connection after 988 * the data is sent. 989 */ 990 socantsendmore(so); 991 sdp_usrclosed(ssk); 992 if (!(ssk->flags & SDP_DROPPED)) 993 sdp_output_disconnect(ssk); 994 } else if (!(ssk->flags & SDP_DROPPED) && 995 !(flags & PRUS_MORETOCOME)) 996 sdp_post_sends(ssk, M_NOWAIT); 997 SDP_WUNLOCK(ssk); 998 return (0); 999 } else { 1000 SOCKBUF_LOCK(&so->so_snd); 1001 if (sbspace(&so->so_snd) < -512) { 1002 SOCKBUF_UNLOCK(&so->so_snd); 1003 m_freem(m); 1004 error = ENOBUFS; 1005 goto out; 1006 } 1007 /* 1008 * According to RFC961 (Assigned Protocols), 1009 * the urgent pointer points to the last octet 1010 * of urgent data. We continue, however, 1011 * to consider it to indicate the first octet 1012 * of data past the urgent section. 1013 * Otherwise, snd_up should be one lower. 1014 */ 1015 m->m_flags |= M_URG | M_PUSH; 1016 sdp_append(ssk, &so->so_snd, m, cnt); 1017 SOCKBUF_UNLOCK(&so->so_snd); 1018 if (nam && ssk->state < TCPS_SYN_SENT) { 1019 /* 1020 * Do implied connect if not yet connected. 1021 */ 1022 error = sdp_start_connect(ssk, nam, td); 1023 if (error) 1024 goto out; 1025 } 1026 sdp_post_sends(ssk, M_NOWAIT); 1027 SDP_WUNLOCK(ssk); 1028 return (0); 1029 } 1030 out: 1031 SDP_WUNLOCK(ssk); 1032 return (error); 1033 } 1034 1035 #define SBLOCKWAIT(f) (((f) & MSG_DONTWAIT) ? 0 : SBL_WAIT) 1036 1037 /* 1038 * Send on a socket. If send must go all at once and message is larger than 1039 * send buffering, then hard error. Lock against other senders. If must go 1040 * all at once and not enough room now, then inform user that this would 1041 * block and do nothing. Otherwise, if nonblocking, send as much as 1042 * possible. The data to be sent is described by "uio" if nonzero, otherwise 1043 * by the mbuf chain "top" (which must be null if uio is not). Data provided 1044 * in mbuf chain must be small enough to send all at once. 1045 * 1046 * Returns nonzero on error, timeout or signal; callers must check for short 1047 * counts if EINTR/ERESTART are returned. Data and control buffers are freed 1048 * on return. 1049 */ 1050 static int 1051 sdp_sosend(struct socket *so, struct sockaddr *addr, struct uio *uio, 1052 struct mbuf *top, struct mbuf *control, int flags, struct thread *td) 1053 { 1054 struct sdp_sock *ssk; 1055 long space, resid; 1056 int atomic; 1057 int error; 1058 int copy; 1059 1060 if (uio != NULL) 1061 resid = uio->uio_resid; 1062 else 1063 resid = top->m_pkthdr.len; 1064 atomic = top != NULL; 1065 if (control != NULL) { 1066 if (control->m_len) { 1067 m_freem(control); 1068 if (top) 1069 m_freem(top); 1070 return (EINVAL); 1071 } 1072 m_freem(control); 1073 control = NULL; 1074 } 1075 /* 1076 * In theory resid should be unsigned. However, space must be 1077 * signed, as it might be less than 0 if we over-committed, and we 1078 * must use a signed comparison of space and resid. On the other 1079 * hand, a negative resid causes us to loop sending 0-length 1080 * segments to the protocol. 1081 * 1082 * Also check to make sure that MSG_EOR isn't used on SOCK_STREAM 1083 * type sockets since that's an error. 1084 */ 1085 if (resid < 0 || (so->so_type == SOCK_STREAM && (flags & MSG_EOR))) { 1086 error = EINVAL; 1087 goto out; 1088 } 1089 if (td != NULL) 1090 td->td_ru.ru_msgsnd++; 1091 1092 ssk = sdp_sk(so); 1093 error = sblock(&so->so_snd, SBLOCKWAIT(flags)); 1094 if (error) 1095 goto out; 1096 1097 restart: 1098 do { 1099 SOCKBUF_LOCK(&so->so_snd); 1100 if (so->so_snd.sb_state & SBS_CANTSENDMORE) { 1101 SOCKBUF_UNLOCK(&so->so_snd); 1102 error = EPIPE; 1103 goto release; 1104 } 1105 if (so->so_error) { 1106 error = so->so_error; 1107 so->so_error = 0; 1108 SOCKBUF_UNLOCK(&so->so_snd); 1109 goto release; 1110 } 1111 if ((so->so_state & SS_ISCONNECTED) == 0 && addr == NULL) { 1112 SOCKBUF_UNLOCK(&so->so_snd); 1113 error = ENOTCONN; 1114 goto release; 1115 } 1116 space = sbspace(&so->so_snd); 1117 if (flags & MSG_OOB) 1118 space += 1024; 1119 if (atomic && resid > ssk->xmit_size_goal - SDP_HEAD_SIZE) { 1120 SOCKBUF_UNLOCK(&so->so_snd); 1121 error = EMSGSIZE; 1122 goto release; 1123 } 1124 if (space < resid && 1125 (atomic || space < so->so_snd.sb_lowat)) { 1126 if ((so->so_state & SS_NBIO) || 1127 (flags & (MSG_NBIO | MSG_DONTWAIT)) != 0) { 1128 SOCKBUF_UNLOCK(&so->so_snd); 1129 error = EWOULDBLOCK; 1130 goto release; 1131 } 1132 error = sbwait(&so->so_snd); 1133 SOCKBUF_UNLOCK(&so->so_snd); 1134 if (error) 1135 goto release; 1136 goto restart; 1137 } 1138 SOCKBUF_UNLOCK(&so->so_snd); 1139 do { 1140 if (uio == NULL) { 1141 resid = 0; 1142 if (flags & MSG_EOR) 1143 top->m_flags |= M_EOR; 1144 } else { 1145 /* 1146 * Copy the data from userland into a mbuf 1147 * chain. If no data is to be copied in, 1148 * a single empty mbuf is returned. 1149 */ 1150 copy = min(space, 1151 ssk->xmit_size_goal - SDP_HEAD_SIZE); 1152 top = m_uiotombuf(uio, M_WAITOK, copy, 1153 0, M_PKTHDR | 1154 ((flags & MSG_EOR) ? M_EOR : 0)); 1155 if (top == NULL) { 1156 /* only possible error */ 1157 error = EFAULT; 1158 goto release; 1159 } 1160 space -= resid - uio->uio_resid; 1161 resid = uio->uio_resid; 1162 } 1163 /* 1164 * XXX all the SBS_CANTSENDMORE checks previously 1165 * done could be out of date after dropping the 1166 * socket lock. 1167 */ 1168 error = sdp_send(so, (flags & MSG_OOB) ? PRUS_OOB : 1169 /* 1170 * Set EOF on the last send if the user specified 1171 * MSG_EOF. 1172 */ 1173 ((flags & MSG_EOF) && (resid <= 0)) ? PRUS_EOF : 1174 /* If there is more to send set PRUS_MORETOCOME. */ 1175 (resid > 0 && space > 0) ? PRUS_MORETOCOME : 0, 1176 top, addr, NULL, td); 1177 top = NULL; 1178 if (error) 1179 goto release; 1180 } while (resid && space > 0); 1181 } while (resid); 1182 1183 release: 1184 sbunlock(&so->so_snd); 1185 out: 1186 if (top != NULL) 1187 m_freem(top); 1188 return (error); 1189 } 1190 1191 /* 1192 * The part of soreceive() that implements reading non-inline out-of-band 1193 * data from a socket. For more complete comments, see soreceive(), from 1194 * which this code originated. 1195 * 1196 * Note that soreceive_rcvoob(), unlike the remainder of soreceive(), is 1197 * unable to return an mbuf chain to the caller. 1198 */ 1199 static int 1200 soreceive_rcvoob(struct socket *so, struct uio *uio, int flags) 1201 { 1202 struct protosw *pr = so->so_proto; 1203 struct mbuf *m; 1204 int error; 1205 1206 KASSERT(flags & MSG_OOB, ("soreceive_rcvoob: (flags & MSG_OOB) == 0")); 1207 1208 m = m_get(M_WAITOK, MT_DATA); 1209 error = (*pr->pr_usrreqs->pru_rcvoob)(so, m, flags & MSG_PEEK); 1210 if (error) 1211 goto bad; 1212 do { 1213 error = uiomove(mtod(m, void *), 1214 (int) min(uio->uio_resid, m->m_len), uio); 1215 m = m_free(m); 1216 } while (uio->uio_resid && error == 0 && m); 1217 bad: 1218 if (m != NULL) 1219 m_freem(m); 1220 return (error); 1221 } 1222 1223 /* 1224 * Optimized version of soreceive() for stream (TCP) sockets. 1225 */ 1226 static int 1227 sdp_sorecv(struct socket *so, struct sockaddr **psa, struct uio *uio, 1228 struct mbuf **mp0, struct mbuf **controlp, int *flagsp) 1229 { 1230 int len = 0, error = 0, flags, oresid; 1231 struct sockbuf *sb; 1232 struct mbuf *m, *n = NULL; 1233 struct sdp_sock *ssk; 1234 1235 /* We only do stream sockets. */ 1236 if (so->so_type != SOCK_STREAM) 1237 return (EINVAL); 1238 if (psa != NULL) 1239 *psa = NULL; 1240 if (controlp != NULL) 1241 return (EINVAL); 1242 if (flagsp != NULL) 1243 flags = *flagsp &~ MSG_EOR; 1244 else 1245 flags = 0; 1246 if (flags & MSG_OOB) 1247 return (soreceive_rcvoob(so, uio, flags)); 1248 if (mp0 != NULL) 1249 *mp0 = NULL; 1250 1251 sb = &so->so_rcv; 1252 ssk = sdp_sk(so); 1253 1254 /* Prevent other readers from entering the socket. */ 1255 error = sblock(sb, SBLOCKWAIT(flags)); 1256 if (error) 1257 goto out; 1258 SOCKBUF_LOCK(sb); 1259 1260 /* Easy one, no space to copyout anything. */ 1261 if (uio->uio_resid == 0) { 1262 error = EINVAL; 1263 goto out; 1264 } 1265 oresid = uio->uio_resid; 1266 1267 /* We will never ever get anything unless we are connected. */ 1268 if (!(so->so_state & (SS_ISCONNECTED|SS_ISDISCONNECTED))) { 1269 /* When disconnecting there may be still some data left. */ 1270 if (sbavail(sb)) 1271 goto deliver; 1272 if (!(so->so_state & SS_ISDISCONNECTED)) 1273 error = ENOTCONN; 1274 goto out; 1275 } 1276 1277 /* Socket buffer is empty and we shall not block. */ 1278 if (sbavail(sb) == 0 && 1279 ((so->so_state & SS_NBIO) || (flags & (MSG_DONTWAIT|MSG_NBIO)))) { 1280 error = EAGAIN; 1281 goto out; 1282 } 1283 1284 restart: 1285 SOCKBUF_LOCK_ASSERT(&so->so_rcv); 1286 1287 /* Abort if socket has reported problems. */ 1288 if (so->so_error) { 1289 if (sbavail(sb)) 1290 goto deliver; 1291 if (oresid > uio->uio_resid) 1292 goto out; 1293 error = so->so_error; 1294 if (!(flags & MSG_PEEK)) 1295 so->so_error = 0; 1296 goto out; 1297 } 1298 1299 /* Door is closed. Deliver what is left, if any. */ 1300 if (sb->sb_state & SBS_CANTRCVMORE) { 1301 if (sbavail(sb)) 1302 goto deliver; 1303 else 1304 goto out; 1305 } 1306 1307 /* Socket buffer got some data that we shall deliver now. */ 1308 if (sbavail(sb) && !(flags & MSG_WAITALL) && 1309 ((so->so_state & SS_NBIO) || 1310 (flags & (MSG_DONTWAIT|MSG_NBIO)) || 1311 sbavail(sb) >= sb->sb_lowat || 1312 sbavail(sb) >= uio->uio_resid || 1313 sbavail(sb) >= sb->sb_hiwat) ) { 1314 goto deliver; 1315 } 1316 1317 /* On MSG_WAITALL we must wait until all data or error arrives. */ 1318 if ((flags & MSG_WAITALL) && 1319 (sbavail(sb) >= uio->uio_resid || sbavail(sb) >= sb->sb_lowat)) 1320 goto deliver; 1321 1322 /* 1323 * Wait and block until (more) data comes in. 1324 * NB: Drops the sockbuf lock during wait. 1325 */ 1326 error = sbwait(sb); 1327 if (error) 1328 goto out; 1329 goto restart; 1330 1331 deliver: 1332 SOCKBUF_LOCK_ASSERT(&so->so_rcv); 1333 KASSERT(sbavail(sb), ("%s: sockbuf empty", __func__)); 1334 KASSERT(sb->sb_mb != NULL, ("%s: sb_mb == NULL", __func__)); 1335 1336 /* Statistics. */ 1337 if (uio->uio_td) 1338 uio->uio_td->td_ru.ru_msgrcv++; 1339 1340 /* Fill uio until full or current end of socket buffer is reached. */ 1341 len = min(uio->uio_resid, sbavail(sb)); 1342 if (mp0 != NULL) { 1343 /* Dequeue as many mbufs as possible. */ 1344 if (!(flags & MSG_PEEK) && len >= sb->sb_mb->m_len) { 1345 for (*mp0 = m = sb->sb_mb; 1346 m != NULL && m->m_len <= len; 1347 m = m->m_next) { 1348 len -= m->m_len; 1349 uio->uio_resid -= m->m_len; 1350 sbfree(sb, m); 1351 n = m; 1352 } 1353 sb->sb_mb = m; 1354 if (sb->sb_mb == NULL) 1355 SB_EMPTY_FIXUP(sb); 1356 n->m_next = NULL; 1357 } 1358 /* Copy the remainder. */ 1359 if (len > 0) { 1360 KASSERT(sb->sb_mb != NULL, 1361 ("%s: len > 0 && sb->sb_mb empty", __func__)); 1362 1363 m = m_copym(sb->sb_mb, 0, len, M_NOWAIT); 1364 if (m == NULL) 1365 len = 0; /* Don't flush data from sockbuf. */ 1366 else 1367 uio->uio_resid -= m->m_len; 1368 if (*mp0 != NULL) 1369 n->m_next = m; 1370 else 1371 *mp0 = m; 1372 if (*mp0 == NULL) { 1373 error = ENOBUFS; 1374 goto out; 1375 } 1376 } 1377 } else { 1378 /* NB: Must unlock socket buffer as uiomove may sleep. */ 1379 SOCKBUF_UNLOCK(sb); 1380 error = m_mbuftouio(uio, sb->sb_mb, len); 1381 SOCKBUF_LOCK(sb); 1382 if (error) 1383 goto out; 1384 } 1385 SBLASTRECORDCHK(sb); 1386 SBLASTMBUFCHK(sb); 1387 1388 /* 1389 * Remove the delivered data from the socket buffer unless we 1390 * were only peeking. 1391 */ 1392 if (!(flags & MSG_PEEK)) { 1393 if (len > 0) 1394 sbdrop_locked(sb, len); 1395 1396 /* Notify protocol that we drained some data. */ 1397 SOCKBUF_UNLOCK(sb); 1398 SDP_WLOCK(ssk); 1399 sdp_do_posts(ssk); 1400 SDP_WUNLOCK(ssk); 1401 SOCKBUF_LOCK(sb); 1402 } 1403 1404 /* 1405 * For MSG_WAITALL we may have to loop again and wait for 1406 * more data to come in. 1407 */ 1408 if ((flags & MSG_WAITALL) && uio->uio_resid > 0) 1409 goto restart; 1410 out: 1411 SOCKBUF_LOCK_ASSERT(sb); 1412 SBLASTRECORDCHK(sb); 1413 SBLASTMBUFCHK(sb); 1414 SOCKBUF_UNLOCK(sb); 1415 sbunlock(sb); 1416 return (error); 1417 } 1418 1419 /* 1420 * Abort is used to teardown a connection typically while sitting in 1421 * the accept queue. 1422 */ 1423 void 1424 sdp_abort(struct socket *so) 1425 { 1426 struct sdp_sock *ssk; 1427 1428 ssk = sdp_sk(so); 1429 SDP_WLOCK(ssk); 1430 /* 1431 * If we have not yet dropped, do it now. 1432 */ 1433 if (!(ssk->flags & SDP_TIMEWAIT) && 1434 !(ssk->flags & SDP_DROPPED)) 1435 sdp_drop(ssk, ECONNABORTED); 1436 KASSERT(ssk->flags & SDP_DROPPED, ("sdp_abort: %p not dropped 0x%X", 1437 ssk, ssk->flags)); 1438 SDP_WUNLOCK(ssk); 1439 } 1440 1441 /* 1442 * Close a SDP socket and initiate a friendly disconnect. 1443 */ 1444 static void 1445 sdp_close(struct socket *so) 1446 { 1447 struct sdp_sock *ssk; 1448 1449 ssk = sdp_sk(so); 1450 SDP_WLOCK(ssk); 1451 /* 1452 * If we have not yet dropped, do it now. 1453 */ 1454 if (!(ssk->flags & SDP_TIMEWAIT) && 1455 !(ssk->flags & SDP_DROPPED)) 1456 sdp_start_disconnect(ssk); 1457 1458 /* 1459 * If we've still not dropped let the socket layer know we're 1460 * holding on to the socket and pcb for a while. 1461 */ 1462 if (!(ssk->flags & SDP_DROPPED)) { 1463 SOCK_LOCK(so); 1464 so->so_state |= SS_PROTOREF; 1465 SOCK_UNLOCK(so); 1466 ssk->flags |= SDP_SOCKREF; 1467 } 1468 SDP_WUNLOCK(ssk); 1469 } 1470 1471 /* 1472 * User requests out-of-band data. 1473 */ 1474 static int 1475 sdp_rcvoob(struct socket *so, struct mbuf *m, int flags) 1476 { 1477 int error = 0; 1478 struct sdp_sock *ssk; 1479 1480 ssk = sdp_sk(so); 1481 SDP_WLOCK(ssk); 1482 if (!rx_ring_trylock(&ssk->rx_ring)) { 1483 SDP_WUNLOCK(ssk); 1484 return (ECONNRESET); 1485 } 1486 if (ssk->flags & (SDP_TIMEWAIT | SDP_DROPPED)) { 1487 error = ECONNRESET; 1488 goto out; 1489 } 1490 if ((so->so_oobmark == 0 && 1491 (so->so_rcv.sb_state & SBS_RCVATMARK) == 0) || 1492 so->so_options & SO_OOBINLINE || 1493 ssk->oobflags & SDP_HADOOB) { 1494 error = EINVAL; 1495 goto out; 1496 } 1497 if ((ssk->oobflags & SDP_HAVEOOB) == 0) { 1498 error = EWOULDBLOCK; 1499 goto out; 1500 } 1501 m->m_len = 1; 1502 *mtod(m, caddr_t) = ssk->iobc; 1503 if ((flags & MSG_PEEK) == 0) 1504 ssk->oobflags ^= (SDP_HAVEOOB | SDP_HADOOB); 1505 out: 1506 rx_ring_unlock(&ssk->rx_ring); 1507 SDP_WUNLOCK(ssk); 1508 return (error); 1509 } 1510 1511 void 1512 sdp_urg(struct sdp_sock *ssk, struct mbuf *mb) 1513 { 1514 struct mbuf *m; 1515 struct socket *so; 1516 1517 so = ssk->socket; 1518 if (so == NULL) 1519 return; 1520 1521 so->so_oobmark = sbused(&so->so_rcv) + mb->m_pkthdr.len - 1; 1522 sohasoutofband(so); 1523 ssk->oobflags &= ~(SDP_HAVEOOB | SDP_HADOOB); 1524 if (!(so->so_options & SO_OOBINLINE)) { 1525 for (m = mb; m->m_next != NULL; m = m->m_next); 1526 ssk->iobc = *(mtod(m, char *) + m->m_len - 1); 1527 ssk->oobflags |= SDP_HAVEOOB; 1528 m->m_len--; 1529 mb->m_pkthdr.len--; 1530 } 1531 } 1532 1533 /* 1534 * Notify a sdp socket of an asynchronous error. 1535 * 1536 * Do not wake up user since there currently is no mechanism for 1537 * reporting soft errors (yet - a kqueue filter may be added). 1538 */ 1539 struct sdp_sock * 1540 sdp_notify(struct sdp_sock *ssk, int error) 1541 { 1542 1543 SDP_WLOCK_ASSERT(ssk); 1544 1545 if ((ssk->flags & SDP_TIMEWAIT) || 1546 (ssk->flags & SDP_DROPPED)) 1547 return (ssk); 1548 1549 /* 1550 * Ignore some errors if we are hooked up. 1551 */ 1552 if (ssk->state == TCPS_ESTABLISHED && 1553 (error == EHOSTUNREACH || error == ENETUNREACH || 1554 error == EHOSTDOWN)) 1555 return (ssk); 1556 ssk->softerror = error; 1557 return sdp_drop(ssk, error); 1558 } 1559 1560 static void 1561 sdp_ctlinput(int cmd, struct sockaddr *sa, void *vip) 1562 { 1563 struct in_addr faddr; 1564 1565 faddr = ((struct sockaddr_in *)sa)->sin_addr; 1566 if (sa->sa_family != AF_INET || faddr.s_addr == INADDR_ANY) 1567 return; 1568 1569 sdp_pcbnotifyall(faddr, inetctlerrmap[cmd], sdp_notify); 1570 } 1571 1572 static int 1573 sdp_control(struct socket *so, u_long cmd, caddr_t data, struct ifnet *ifp, 1574 struct thread *td) 1575 { 1576 return (EOPNOTSUPP); 1577 } 1578 1579 static void 1580 sdp_keepalive_timeout(void *data) 1581 { 1582 struct sdp_sock *ssk; 1583 1584 ssk = data; 1585 /* Callout canceled. */ 1586 if (!callout_active(&ssk->keep2msl)) 1587 return; 1588 /* Callout rescheduled as a different kind of timer. */ 1589 if (callout_pending(&ssk->keep2msl)) 1590 goto out; 1591 callout_deactivate(&ssk->keep2msl); 1592 if (ssk->flags & SDP_DROPPED || 1593 (ssk->socket->so_options & SO_KEEPALIVE) == 0) 1594 goto out; 1595 sdp_post_keepalive(ssk); 1596 callout_reset(&ssk->keep2msl, SDP_KEEPALIVE_TIME, 1597 sdp_keepalive_timeout, ssk); 1598 out: 1599 SDP_WUNLOCK(ssk); 1600 } 1601 1602 1603 void 1604 sdp_start_keepalive_timer(struct socket *so) 1605 { 1606 struct sdp_sock *ssk; 1607 1608 ssk = sdp_sk(so); 1609 if (!callout_pending(&ssk->keep2msl)) 1610 callout_reset(&ssk->keep2msl, SDP_KEEPALIVE_TIME, 1611 sdp_keepalive_timeout, ssk); 1612 } 1613 1614 static void 1615 sdp_stop_keepalive_timer(struct socket *so) 1616 { 1617 struct sdp_sock *ssk; 1618 1619 ssk = sdp_sk(so); 1620 callout_stop(&ssk->keep2msl); 1621 } 1622 1623 /* 1624 * sdp_ctloutput() must drop the inpcb lock before performing copyin on 1625 * socket option arguments. When it re-acquires the lock after the copy, it 1626 * has to revalidate that the connection is still valid for the socket 1627 * option. 1628 */ 1629 #define SDP_WLOCK_RECHECK(inp) do { \ 1630 SDP_WLOCK(ssk); \ 1631 if (ssk->flags & (SDP_TIMEWAIT | SDP_DROPPED)) { \ 1632 SDP_WUNLOCK(ssk); \ 1633 return (ECONNRESET); \ 1634 } \ 1635 } while(0) 1636 1637 static int 1638 sdp_ctloutput(struct socket *so, struct sockopt *sopt) 1639 { 1640 int error, opt, optval; 1641 struct sdp_sock *ssk; 1642 1643 error = 0; 1644 ssk = sdp_sk(so); 1645 if (sopt->sopt_level == SOL_SOCKET && sopt->sopt_name == SO_KEEPALIVE) { 1646 SDP_WLOCK(ssk); 1647 if (so->so_options & SO_KEEPALIVE) 1648 sdp_start_keepalive_timer(so); 1649 else 1650 sdp_stop_keepalive_timer(so); 1651 SDP_WUNLOCK(ssk); 1652 } 1653 if (sopt->sopt_level != IPPROTO_TCP) 1654 return (error); 1655 1656 SDP_WLOCK(ssk); 1657 if (ssk->flags & (SDP_TIMEWAIT | SDP_DROPPED)) { 1658 SDP_WUNLOCK(ssk); 1659 return (ECONNRESET); 1660 } 1661 1662 switch (sopt->sopt_dir) { 1663 case SOPT_SET: 1664 switch (sopt->sopt_name) { 1665 case TCP_NODELAY: 1666 SDP_WUNLOCK(ssk); 1667 error = sooptcopyin(sopt, &optval, sizeof optval, 1668 sizeof optval); 1669 if (error) 1670 return (error); 1671 1672 SDP_WLOCK_RECHECK(ssk); 1673 opt = SDP_NODELAY; 1674 if (optval) 1675 ssk->flags |= opt; 1676 else 1677 ssk->flags &= ~opt; 1678 sdp_do_posts(ssk); 1679 SDP_WUNLOCK(ssk); 1680 break; 1681 1682 default: 1683 SDP_WUNLOCK(ssk); 1684 error = ENOPROTOOPT; 1685 break; 1686 } 1687 break; 1688 1689 case SOPT_GET: 1690 switch (sopt->sopt_name) { 1691 case TCP_NODELAY: 1692 optval = ssk->flags & SDP_NODELAY; 1693 SDP_WUNLOCK(ssk); 1694 error = sooptcopyout(sopt, &optval, sizeof optval); 1695 break; 1696 default: 1697 SDP_WUNLOCK(ssk); 1698 error = ENOPROTOOPT; 1699 break; 1700 } 1701 break; 1702 } 1703 return (error); 1704 } 1705 #undef SDP_WLOCK_RECHECK 1706 1707 int sdp_mod_count = 0; 1708 int sdp_mod_usec = 0; 1709 1710 void 1711 sdp_set_default_moderation(struct sdp_sock *ssk) 1712 { 1713 if (sdp_mod_count <= 0 || sdp_mod_usec <= 0) 1714 return; 1715 ib_modify_cq(ssk->rx_ring.cq, sdp_mod_count, sdp_mod_usec); 1716 } 1717 1718 static void 1719 sdp_dev_add(struct ib_device *device) 1720 { 1721 struct ib_fmr_pool_param param; 1722 struct sdp_device *sdp_dev; 1723 1724 sdp_dev = malloc(sizeof(*sdp_dev), M_SDP, M_WAITOK | M_ZERO); 1725 sdp_dev->pd = ib_alloc_pd(device, 0); 1726 if (IS_ERR(sdp_dev->pd)) 1727 goto out_pd; 1728 memset(¶m, 0, sizeof param); 1729 param.max_pages_per_fmr = SDP_FMR_SIZE; 1730 param.page_shift = PAGE_SHIFT; 1731 param.access = (IB_ACCESS_LOCAL_WRITE | IB_ACCESS_REMOTE_READ); 1732 param.pool_size = SDP_FMR_POOL_SIZE; 1733 param.dirty_watermark = SDP_FMR_DIRTY_SIZE; 1734 param.cache = 1; 1735 sdp_dev->fmr_pool = ib_create_fmr_pool(sdp_dev->pd, ¶m); 1736 if (IS_ERR(sdp_dev->fmr_pool)) 1737 goto out_fmr; 1738 ib_set_client_data(device, &sdp_client, sdp_dev); 1739 return; 1740 1741 out_fmr: 1742 ib_dealloc_pd(sdp_dev->pd); 1743 out_pd: 1744 free(sdp_dev, M_SDP); 1745 } 1746 1747 static void 1748 sdp_dev_rem(struct ib_device *device, void *client_data) 1749 { 1750 struct sdp_device *sdp_dev; 1751 struct sdp_sock *ssk; 1752 1753 SDP_LIST_WLOCK(); 1754 LIST_FOREACH(ssk, &sdp_list, list) { 1755 if (ssk->ib_device != device) 1756 continue; 1757 SDP_WLOCK(ssk); 1758 if ((ssk->flags & SDP_DESTROY) == 0) 1759 ssk = sdp_notify(ssk, ECONNRESET); 1760 if (ssk) 1761 SDP_WUNLOCK(ssk); 1762 } 1763 SDP_LIST_WUNLOCK(); 1764 /* 1765 * XXX Do I need to wait between these two? 1766 */ 1767 sdp_dev = ib_get_client_data(device, &sdp_client); 1768 if (!sdp_dev) 1769 return; 1770 ib_flush_fmr_pool(sdp_dev->fmr_pool); 1771 ib_destroy_fmr_pool(sdp_dev->fmr_pool); 1772 ib_dealloc_pd(sdp_dev->pd); 1773 free(sdp_dev, M_SDP); 1774 } 1775 1776 struct ib_client sdp_client = 1777 { .name = "sdp", .add = sdp_dev_add, .remove = sdp_dev_rem }; 1778 1779 1780 static int 1781 sdp_pcblist(SYSCTL_HANDLER_ARGS) 1782 { 1783 int error, n, i; 1784 struct sdp_sock *ssk; 1785 struct xinpgen xig; 1786 1787 /* 1788 * The process of preparing the TCB list is too time-consuming and 1789 * resource-intensive to repeat twice on every request. 1790 */ 1791 if (req->oldptr == NULL) { 1792 n = sdp_count; 1793 n += imax(n / 8, 10); 1794 req->oldidx = 2 * (sizeof xig) + n * sizeof(struct xtcpcb); 1795 return (0); 1796 } 1797 1798 if (req->newptr != NULL) 1799 return (EPERM); 1800 1801 /* 1802 * OK, now we're committed to doing something. 1803 */ 1804 SDP_LIST_RLOCK(); 1805 n = sdp_count; 1806 SDP_LIST_RUNLOCK(); 1807 1808 error = sysctl_wire_old_buffer(req, 2 * (sizeof xig) 1809 + n * sizeof(struct xtcpcb)); 1810 if (error != 0) 1811 return (error); 1812 1813 bzero(&xig, sizeof(xig)); 1814 xig.xig_len = sizeof xig; 1815 xig.xig_count = n; 1816 xig.xig_gen = 0; 1817 xig.xig_sogen = so_gencnt; 1818 error = SYSCTL_OUT(req, &xig, sizeof xig); 1819 if (error) 1820 return (error); 1821 1822 SDP_LIST_RLOCK(); 1823 for (ssk = LIST_FIRST(&sdp_list), i = 0; 1824 ssk != NULL && i < n; ssk = LIST_NEXT(ssk, list)) { 1825 struct xtcpcb xt; 1826 1827 SDP_RLOCK(ssk); 1828 if (ssk->flags & SDP_TIMEWAIT) { 1829 if (ssk->cred != NULL) 1830 error = cr_cansee(req->td->td_ucred, 1831 ssk->cred); 1832 else 1833 error = EINVAL; /* Skip this inp. */ 1834 } else if (ssk->socket) 1835 error = cr_canseesocket(req->td->td_ucred, 1836 ssk->socket); 1837 else 1838 error = EINVAL; 1839 if (error) { 1840 error = 0; 1841 goto next; 1842 } 1843 1844 bzero(&xt, sizeof(xt)); 1845 xt.xt_len = sizeof xt; 1846 xt.xt_inp.inp_gencnt = 0; 1847 xt.xt_inp.inp_vflag = INP_IPV4; 1848 memcpy(&xt.xt_inp.inp_laddr, &ssk->laddr, sizeof(ssk->laddr)); 1849 xt.xt_inp.inp_lport = ssk->lport; 1850 memcpy(&xt.xt_inp.inp_faddr, &ssk->faddr, sizeof(ssk->faddr)); 1851 xt.xt_inp.inp_fport = ssk->fport; 1852 xt.t_state = ssk->state; 1853 if (ssk->socket != NULL) 1854 sotoxsocket(ssk->socket, &xt.xt_inp.xi_socket); 1855 xt.xt_inp.xi_socket.xso_protocol = IPPROTO_TCP; 1856 SDP_RUNLOCK(ssk); 1857 error = SYSCTL_OUT(req, &xt, sizeof xt); 1858 if (error) 1859 break; 1860 i++; 1861 continue; 1862 next: 1863 SDP_RUNLOCK(ssk); 1864 } 1865 if (!error) { 1866 /* 1867 * Give the user an updated idea of our state. 1868 * If the generation differs from what we told 1869 * her before, she knows that something happened 1870 * while we were processing this request, and it 1871 * might be necessary to retry. 1872 */ 1873 xig.xig_gen = 0; 1874 xig.xig_sogen = so_gencnt; 1875 xig.xig_count = sdp_count; 1876 error = SYSCTL_OUT(req, &xig, sizeof xig); 1877 } 1878 SDP_LIST_RUNLOCK(); 1879 return (error); 1880 } 1881 1882 SYSCTL_NODE(_net_inet, -1, sdp, CTLFLAG_RW | CTLFLAG_MPSAFE, 0, 1883 "SDP"); 1884 1885 SYSCTL_PROC(_net_inet_sdp, TCPCTL_PCBLIST, pcblist, 1886 CTLFLAG_RD | CTLTYPE_STRUCT | CTLFLAG_MPSAFE, 1887 0, 0, sdp_pcblist, "S,xtcpcb", 1888 "List of active SDP connections"); 1889 1890 static void 1891 sdp_zone_change(void *tag) 1892 { 1893 1894 uma_zone_set_max(sdp_zone, maxsockets); 1895 } 1896 1897 static void 1898 sdp_init(void) 1899 { 1900 1901 LIST_INIT(&sdp_list); 1902 sdp_zone = uma_zcreate("sdp_sock", sizeof(struct sdp_sock), 1903 NULL, NULL, NULL, NULL, UMA_ALIGN_PTR, UMA_ZONE_NOFREE); 1904 uma_zone_set_max(sdp_zone, maxsockets); 1905 EVENTHANDLER_REGISTER(maxsockets_change, sdp_zone_change, NULL, 1906 EVENTHANDLER_PRI_ANY); 1907 rx_comp_wq = create_singlethread_workqueue("rx_comp_wq"); 1908 ib_register_client(&sdp_client); 1909 } 1910 1911 extern struct domain sdpdomain; 1912 1913 struct pr_usrreqs sdp_usrreqs = { 1914 .pru_abort = sdp_abort, 1915 .pru_accept = sdp_accept, 1916 .pru_attach = sdp_attach, 1917 .pru_bind = sdp_bind, 1918 .pru_connect = sdp_connect, 1919 .pru_control = sdp_control, 1920 .pru_detach = sdp_detach, 1921 .pru_disconnect = sdp_disconnect, 1922 .pru_listen = sdp_listen, 1923 .pru_peeraddr = sdp_getpeeraddr, 1924 .pru_rcvoob = sdp_rcvoob, 1925 .pru_send = sdp_send, 1926 .pru_sosend = sdp_sosend, 1927 .pru_soreceive = sdp_sorecv, 1928 .pru_shutdown = sdp_shutdown, 1929 .pru_sockaddr = sdp_getsockaddr, 1930 .pru_close = sdp_close, 1931 }; 1932 1933 struct protosw sdpsw[] = { 1934 { 1935 .pr_type = SOCK_STREAM, 1936 .pr_domain = &sdpdomain, 1937 .pr_protocol = IPPROTO_IP, 1938 .pr_flags = PR_CONNREQUIRED|PR_IMPLOPCL|PR_WANTRCVD, 1939 .pr_ctlinput = sdp_ctlinput, 1940 .pr_ctloutput = sdp_ctloutput, 1941 .pr_usrreqs = &sdp_usrreqs 1942 }, 1943 { 1944 .pr_type = SOCK_STREAM, 1945 .pr_domain = &sdpdomain, 1946 .pr_protocol = IPPROTO_TCP, 1947 .pr_flags = PR_CONNREQUIRED|PR_IMPLOPCL|PR_WANTRCVD, 1948 .pr_ctlinput = sdp_ctlinput, 1949 .pr_ctloutput = sdp_ctloutput, 1950 .pr_usrreqs = &sdp_usrreqs 1951 }, 1952 }; 1953 1954 struct domain sdpdomain = { 1955 .dom_family = AF_INET_SDP, 1956 .dom_name = "SDP", 1957 .dom_init = sdp_init, 1958 .dom_protosw = sdpsw, 1959 .dom_protoswNPROTOSW = &sdpsw[sizeof(sdpsw)/sizeof(sdpsw[0])], 1960 }; 1961 1962 DOMAIN_SET(sdp); 1963 1964 int sdp_debug_level = 1; 1965 int sdp_data_debug_level = 0; 1966