xref: /freebsd/usr.bin/sockstat/sockstat.c (revision 32723a3ba9611d7947ccf639fcdef5fa0b330571)
1ca007d91SDag-Erling Smørgrav /*-
21de7b4b8SPedro F. Giffuni  * SPDX-License-Identifier: BSD-2-Clause-FreeBSD
31de7b4b8SPedro F. Giffuni  *
4fb2ad9d3SUlrich Spörlein  * Copyright (c) 2002 Dag-Erling Coïdan Smørgrav
5ca007d91SDag-Erling Smørgrav  * All rights reserved.
6ca007d91SDag-Erling Smørgrav  *
7ca007d91SDag-Erling Smørgrav  * Redistribution and use in source and binary forms, with or without
8ca007d91SDag-Erling Smørgrav  * modification, are permitted provided that the following conditions
9ca007d91SDag-Erling Smørgrav  * are met:
10ca007d91SDag-Erling Smørgrav  * 1. Redistributions of source code must retain the above copyright
11ca007d91SDag-Erling Smørgrav  *    notice, this list of conditions and the following disclaimer
12ca007d91SDag-Erling Smørgrav  *    in this position and unchanged.
13ca007d91SDag-Erling Smørgrav  * 2. Redistributions in binary form must reproduce the above copyright
14ca007d91SDag-Erling Smørgrav  *    notice, this list of conditions and the following disclaimer in the
15ca007d91SDag-Erling Smørgrav  *    documentation and/or other materials provided with the distribution.
16ca007d91SDag-Erling Smørgrav  * 3. The name of the author may not be used to endorse or promote products
17ca007d91SDag-Erling Smørgrav  *    derived from this software without specific prior written permission.
18ca007d91SDag-Erling Smørgrav  *
19ca007d91SDag-Erling Smørgrav  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
20ca007d91SDag-Erling Smørgrav  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
21ca007d91SDag-Erling Smørgrav  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
22ca007d91SDag-Erling Smørgrav  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
23ca007d91SDag-Erling Smørgrav  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
24ca007d91SDag-Erling Smørgrav  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
25ca007d91SDag-Erling Smørgrav  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
26ca007d91SDag-Erling Smørgrav  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
27ca007d91SDag-Erling Smørgrav  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
28ca007d91SDag-Erling Smørgrav  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
29ca007d91SDag-Erling Smørgrav  */
30ca007d91SDag-Erling Smørgrav 
31ca007d91SDag-Erling Smørgrav #include <sys/cdefs.h>
32ca007d91SDag-Erling Smørgrav __FBSDID("$FreeBSD$");
33ca007d91SDag-Erling Smørgrav 
34ca007d91SDag-Erling Smørgrav #include <sys/param.h>
35f1cd4902SRyan Moeller #include <sys/file.h>
36ca007d91SDag-Erling Smørgrav #include <sys/socket.h>
37ca007d91SDag-Erling Smørgrav #include <sys/socketvar.h>
38ca007d91SDag-Erling Smørgrav #include <sys/sysctl.h>
39f1cd4902SRyan Moeller #include <sys/jail.h>
40ca007d91SDag-Erling Smørgrav #include <sys/user.h>
41ca007d91SDag-Erling Smørgrav 
42ca007d91SDag-Erling Smørgrav #include <sys/un.h>
430e229f34SGleb Smirnoff #define	_WANT_UNPCB
44ca007d91SDag-Erling Smørgrav #include <sys/unpcb.h>
45ca007d91SDag-Erling Smørgrav 
4602bd9db0SDag-Erling Smørgrav #include <net/route.h>
4702bd9db0SDag-Erling Smørgrav 
48ca007d91SDag-Erling Smørgrav #include <netinet/in.h>
49ca007d91SDag-Erling Smørgrav #include <netinet/in_pcb.h>
50d5b4aa90SMichael Tuexen #include <netinet/sctp.h>
51ca007d91SDag-Erling Smørgrav #include <netinet/tcp.h>
527a5642b3SDag-Erling Smørgrav #define TCPSTATES /* load state names */
537a5642b3SDag-Erling Smørgrav #include <netinet/tcp_fsm.h>
54ca007d91SDag-Erling Smørgrav #include <netinet/tcp_seq.h>
55ca007d91SDag-Erling Smørgrav #include <netinet/tcp_var.h>
56ca007d91SDag-Erling Smørgrav #include <arpa/inet.h>
57ca007d91SDag-Erling Smørgrav 
58c5a2d8c5SRyan Moeller #include <capsicum_helpers.h>
59ca007d91SDag-Erling Smørgrav #include <ctype.h>
60ca007d91SDag-Erling Smørgrav #include <err.h>
61ca007d91SDag-Erling Smørgrav #include <errno.h>
62de68a320SJamie Gritton #include <jail.h>
63ca007d91SDag-Erling Smørgrav #include <netdb.h>
64ca007d91SDag-Erling Smørgrav #include <pwd.h>
65ca007d91SDag-Erling Smørgrav #include <stdarg.h>
66ca007d91SDag-Erling Smørgrav #include <stdio.h>
67ca007d91SDag-Erling Smørgrav #include <stdlib.h>
68ca007d91SDag-Erling Smørgrav #include <string.h>
69ca007d91SDag-Erling Smørgrav #include <unistd.h>
70ca007d91SDag-Erling Smørgrav 
71c5a2d8c5SRyan Moeller #include <libcasper.h>
72c5a2d8c5SRyan Moeller #include <casper/cap_net.h>
73c5a2d8c5SRyan Moeller #include <casper/cap_netdb.h>
747ad30f58SMariusz Zaborski #include <casper/cap_pwd.h>
75c5a2d8c5SRyan Moeller #include <casper/cap_sysctl.h>
76c5a2d8c5SRyan Moeller 
77b8e20e2dSHiroki Sato #define	sstosin(ss)	((struct sockaddr_in *)(ss))
78b8e20e2dSHiroki Sato #define	sstosin6(ss)	((struct sockaddr_in6 *)(ss))
79b8e20e2dSHiroki Sato #define	sstosun(ss)	((struct sockaddr_un *)(ss))
80b8e20e2dSHiroki Sato #define	sstosa(ss)	((struct sockaddr *)(ss))
81b8e20e2dSHiroki Sato 
82ca007d91SDag-Erling Smørgrav static int	 opt_4;		/* Show IPv4 sockets */
83ca007d91SDag-Erling Smørgrav static int	 opt_6;		/* Show IPv6 sockets */
842ac089d0SMichael Tuexen static int	 opt_C;		/* Show congestion control */
85ca007d91SDag-Erling Smørgrav static int	 opt_c;		/* Show connected sockets */
8600feaafdSAndrew Thompson static int	 opt_j;		/* Show specified jail */
879b6ca892SBruce M Simpson static int	 opt_L;		/* Don't show IPv4 or IPv6 loopback sockets */
88ca007d91SDag-Erling Smørgrav static int	 opt_l;		/* Show listening sockets */
89ccdd2b2bSAlexander Motin static int	 opt_n;		/* Don't resolve UIDs to user names */
90ee0afaa9SEmmanuel Vadot static int	 opt_q;		/* Don't show header */
91e5cccc35SMichael Tuexen static int	 opt_S;		/* Show protocol stack if applicable */
927a5642b3SDag-Erling Smørgrav static int	 opt_s;		/* Show protocol state if applicable */
9349b836f2SMichael Tuexen static int	 opt_U;		/* Show remote UDP encapsulation port number */
94ca007d91SDag-Erling Smørgrav static int	 opt_u;		/* Show Unix domain sockets */
95ca007d91SDag-Erling Smørgrav static int	 opt_v;		/* Verbose mode */
9683f60cb2SMichael Tuexen static int	 opt_w;		/* Wide print area for addresses */
97ca007d91SDag-Erling Smørgrav 
981f3d67aaSGiorgos Keramidas /*
991f3d67aaSGiorgos Keramidas  * Default protocols to use if no -P was defined.
1001f3d67aaSGiorgos Keramidas  */
101d5b4aa90SMichael Tuexen static const char *default_protos[] = {"sctp", "tcp", "udp", "divert" };
102b8e20e2dSHiroki Sato static size_t	   default_numprotos = nitems(default_protos);
1031f3d67aaSGiorgos Keramidas 
1041f3d67aaSGiorgos Keramidas static int	*protos;	/* protocols to use */
1051f3d67aaSGiorgos Keramidas static size_t	 numprotos;	/* allocated size of protos[] */
1061f3d67aaSGiorgos Keramidas 
107ca007d91SDag-Erling Smørgrav static int	*ports;
108ca007d91SDag-Erling Smørgrav 
109ca007d91SDag-Erling Smørgrav #define	INT_BIT (sizeof(int)*CHAR_BIT)
110ca007d91SDag-Erling Smørgrav #define	SET_PORT(p) do { ports[p / INT_BIT] |= 1 << (p % INT_BIT); } while (0)
111ca007d91SDag-Erling Smørgrav #define	CHK_PORT(p) (ports[p / INT_BIT] & (1 << (p % INT_BIT)))
112ca007d91SDag-Erling Smørgrav 
113e6f718c7SMichael Tuexen struct addr {
114e6f718c7SMichael Tuexen 	struct sockaddr_storage address;
11549b836f2SMichael Tuexen 	unsigned int encaps_port;
116e389705eSMichael Tuexen 	int state;
117e6f718c7SMichael Tuexen 	struct addr *next;
118e6f718c7SMichael Tuexen };
119e6f718c7SMichael Tuexen 
120ca007d91SDag-Erling Smørgrav struct sock {
121f38b68aeSBrooks Davis 	kvaddr_t socket;
122f38b68aeSBrooks Davis 	kvaddr_t pcb;
12361149f8dSJilles Tjoelker 	int shown;
124ca007d91SDag-Erling Smørgrav 	int vflag;
125ca007d91SDag-Erling Smørgrav 	int family;
126ca007d91SDag-Erling Smørgrav 	int proto;
1277a5642b3SDag-Erling Smørgrav 	int state;
128ca007d91SDag-Erling Smørgrav 	const char *protoname;
129e5cccc35SMichael Tuexen 	char stack[TCP_FUNCTION_NAME_LEN_MAX];
1302ac089d0SMichael Tuexen 	char cc[TCP_CA_NAME_MAX];
131e6f718c7SMichael Tuexen 	struct addr *laddr;
132e6f718c7SMichael Tuexen 	struct addr *faddr;
133ca007d91SDag-Erling Smørgrav 	struct sock *next;
134ca007d91SDag-Erling Smørgrav };
135ca007d91SDag-Erling Smørgrav 
136ca007d91SDag-Erling Smørgrav #define	HASHSIZE 1009
137ca007d91SDag-Erling Smørgrav static struct sock *sockhash[HASHSIZE];
138ca007d91SDag-Erling Smørgrav 
139ca007d91SDag-Erling Smørgrav static struct xfile *xfiles;
140ca007d91SDag-Erling Smørgrav static int nxfiles;
141ca007d91SDag-Erling Smørgrav 
142c5a2d8c5SRyan Moeller static cap_channel_t *capnet;
143c5a2d8c5SRyan Moeller static cap_channel_t *capnetdb;
144c5a2d8c5SRyan Moeller static cap_channel_t *capsysctl;
1457ad30f58SMariusz Zaborski static cap_channel_t *cappwd;
146c5a2d8c5SRyan Moeller 
147ca007d91SDag-Erling Smørgrav static int
148ca007d91SDag-Erling Smørgrav xprintf(const char *fmt, ...)
149ca007d91SDag-Erling Smørgrav {
150ca007d91SDag-Erling Smørgrav 	va_list ap;
151ca007d91SDag-Erling Smørgrav 	int len;
152ca007d91SDag-Erling Smørgrav 
153ca007d91SDag-Erling Smørgrav 	va_start(ap, fmt);
154ca007d91SDag-Erling Smørgrav 	len = vprintf(fmt, ap);
155ca007d91SDag-Erling Smørgrav 	va_end(ap);
156ca007d91SDag-Erling Smørgrav 	if (len < 0)
157ca007d91SDag-Erling Smørgrav 		err(1, "printf()");
158ca007d91SDag-Erling Smørgrav 	return (len);
159ca007d91SDag-Erling Smørgrav }
160ca007d91SDag-Erling Smørgrav 
1611f3d67aaSGiorgos Keramidas static int
1621f3d67aaSGiorgos Keramidas get_proto_type(const char *proto)
1631f3d67aaSGiorgos Keramidas {
1641f3d67aaSGiorgos Keramidas 	struct protoent *pent;
1651f3d67aaSGiorgos Keramidas 
1661f3d67aaSGiorgos Keramidas 	if (strlen(proto) == 0)
1671f3d67aaSGiorgos Keramidas 		return (0);
168bfb5947bSMariusz Zaborski 	if (capnetdb != NULL)
169c5a2d8c5SRyan Moeller 		pent = cap_getprotobyname(capnetdb, proto);
170bfb5947bSMariusz Zaborski 	else
171bfb5947bSMariusz Zaborski 		pent = getprotobyname(proto);
1721f3d67aaSGiorgos Keramidas 	if (pent == NULL) {
173c5a2d8c5SRyan Moeller 		warn("cap_getprotobyname");
1741f3d67aaSGiorgos Keramidas 		return (-1);
1751f3d67aaSGiorgos Keramidas 	}
1761f3d67aaSGiorgos Keramidas 	return (pent->p_proto);
1771f3d67aaSGiorgos Keramidas }
1781f3d67aaSGiorgos Keramidas 
179b8e20e2dSHiroki Sato static void
180b8e20e2dSHiroki Sato init_protos(int num)
1811f3d67aaSGiorgos Keramidas {
1821f3d67aaSGiorgos Keramidas 	int proto_count = 0;
1831f3d67aaSGiorgos Keramidas 
1841f3d67aaSGiorgos Keramidas 	if (num > 0) {
1851f3d67aaSGiorgos Keramidas 		proto_count = num;
1861f3d67aaSGiorgos Keramidas 	} else {
1871f3d67aaSGiorgos Keramidas 		/* Find the maximum number of possible protocols. */
1881f3d67aaSGiorgos Keramidas 		while (getprotoent() != NULL)
1891f3d67aaSGiorgos Keramidas 			proto_count++;
1901f3d67aaSGiorgos Keramidas 		endprotoent();
1911f3d67aaSGiorgos Keramidas 	}
1921f3d67aaSGiorgos Keramidas 
1931f3d67aaSGiorgos Keramidas 	if ((protos = malloc(sizeof(int) * proto_count)) == NULL)
1941f3d67aaSGiorgos Keramidas 		err(1, "malloc");
1951f3d67aaSGiorgos Keramidas 	numprotos = proto_count;
1961f3d67aaSGiorgos Keramidas }
1971f3d67aaSGiorgos Keramidas 
1981f3d67aaSGiorgos Keramidas static int
1991f3d67aaSGiorgos Keramidas parse_protos(char *protospec)
2001f3d67aaSGiorgos Keramidas {
2011f3d67aaSGiorgos Keramidas 	char *prot;
2021f3d67aaSGiorgos Keramidas 	int proto_type, proto_index;
2031f3d67aaSGiorgos Keramidas 
2041f3d67aaSGiorgos Keramidas 	if (protospec == NULL)
2051f3d67aaSGiorgos Keramidas 		return (-1);
2061f3d67aaSGiorgos Keramidas 
2071f3d67aaSGiorgos Keramidas 	init_protos(0);
2081f3d67aaSGiorgos Keramidas 	proto_index = 0;
209b8e20e2dSHiroki Sato 	while ((prot = strsep(&protospec, ",")) != NULL) {
2101f3d67aaSGiorgos Keramidas 		if (strlen(prot) == 0)
2111f3d67aaSGiorgos Keramidas 			continue;
2121f3d67aaSGiorgos Keramidas 		proto_type = get_proto_type(prot);
2131f3d67aaSGiorgos Keramidas 		if (proto_type != -1)
2141f3d67aaSGiorgos Keramidas 			protos[proto_index++] = proto_type;
2151f3d67aaSGiorgos Keramidas 	}
2161f3d67aaSGiorgos Keramidas 	numprotos = proto_index;
2171f3d67aaSGiorgos Keramidas 	return (proto_index);
2181f3d67aaSGiorgos Keramidas }
2191f3d67aaSGiorgos Keramidas 
220ca007d91SDag-Erling Smørgrav static void
221ca007d91SDag-Erling Smørgrav parse_ports(const char *portspec)
222ca007d91SDag-Erling Smørgrav {
223ca007d91SDag-Erling Smørgrav 	const char *p, *q;
224ca007d91SDag-Erling Smørgrav 	int port, end;
225ca007d91SDag-Erling Smørgrav 
226ca007d91SDag-Erling Smørgrav 	if (ports == NULL)
2279efed1e6SRobert Drehmel 		if ((ports = calloc(65536 / INT_BIT, sizeof(int))) == NULL)
228ca007d91SDag-Erling Smørgrav 			err(1, "calloc()");
229ca007d91SDag-Erling Smørgrav 	p = portspec;
230ca007d91SDag-Erling Smørgrav 	while (*p != '\0') {
231ca007d91SDag-Erling Smørgrav 		if (!isdigit(*p))
232ca007d91SDag-Erling Smørgrav 			errx(1, "syntax error in port range");
233ca007d91SDag-Erling Smørgrav 		for (q = p; *q != '\0' && isdigit(*q); ++q)
234ca007d91SDag-Erling Smørgrav 			/* nothing */ ;
235ca007d91SDag-Erling Smørgrav 		for (port = 0; p < q; ++p)
236ca007d91SDag-Erling Smørgrav 			port = port * 10 + digittoint(*p);
237ca007d91SDag-Erling Smørgrav 		if (port < 0 || port > 65535)
238ca007d91SDag-Erling Smørgrav 			errx(1, "invalid port number");
239ca007d91SDag-Erling Smørgrav 		SET_PORT(port);
240ca007d91SDag-Erling Smørgrav 		switch (*p) {
241ca007d91SDag-Erling Smørgrav 		case '-':
242ca007d91SDag-Erling Smørgrav 			++p;
243ca007d91SDag-Erling Smørgrav 			break;
244ca007d91SDag-Erling Smørgrav 		case ',':
245ca007d91SDag-Erling Smørgrav 			++p;
246ca007d91SDag-Erling Smørgrav 			/* fall through */
247ca007d91SDag-Erling Smørgrav 		case '\0':
248ca007d91SDag-Erling Smørgrav 		default:
249ca007d91SDag-Erling Smørgrav 			continue;
250ca007d91SDag-Erling Smørgrav 		}
251ca007d91SDag-Erling Smørgrav 		for (q = p; *q != '\0' && isdigit(*q); ++q)
252ca007d91SDag-Erling Smørgrav 			/* nothing */ ;
253ca007d91SDag-Erling Smørgrav 		for (end = 0; p < q; ++p)
254ca007d91SDag-Erling Smørgrav 			end = end * 10 + digittoint(*p);
255ca007d91SDag-Erling Smørgrav 		if (end < port || end > 65535)
256ca007d91SDag-Erling Smørgrav 			errx(1, "invalid port number");
257ca007d91SDag-Erling Smørgrav 		while (port++ < end)
258ca007d91SDag-Erling Smørgrav 			SET_PORT(port);
259ca007d91SDag-Erling Smørgrav 		if (*p == ',')
260ca007d91SDag-Erling Smørgrav 			++p;
261ca007d91SDag-Erling Smørgrav 	}
262ca007d91SDag-Erling Smørgrav }
263ca007d91SDag-Erling Smørgrav 
264ca007d91SDag-Erling Smørgrav static void
265b8e20e2dSHiroki Sato sockaddr(struct sockaddr_storage *ss, int af, void *addr, int port)
266ca007d91SDag-Erling Smørgrav {
267ca007d91SDag-Erling Smørgrav 	struct sockaddr_in *sin4;
268ca007d91SDag-Erling Smørgrav 	struct sockaddr_in6 *sin6;
269ca007d91SDag-Erling Smørgrav 
270b8e20e2dSHiroki Sato 	bzero(ss, sizeof(*ss));
271ca007d91SDag-Erling Smørgrav 	switch (af) {
272ca007d91SDag-Erling Smørgrav 	case AF_INET:
273b8e20e2dSHiroki Sato 		sin4 = sstosin(ss);
274b8e20e2dSHiroki Sato 		sin4->sin_len = sizeof(*sin4);
275ca007d91SDag-Erling Smørgrav 		sin4->sin_family = af;
276ca007d91SDag-Erling Smørgrav 		sin4->sin_port = port;
277ca007d91SDag-Erling Smørgrav 		sin4->sin_addr = *(struct in_addr *)addr;
278ca007d91SDag-Erling Smørgrav 		break;
279ca007d91SDag-Erling Smørgrav 	case AF_INET6:
280b8e20e2dSHiroki Sato 		sin6 = sstosin6(ss);
281b8e20e2dSHiroki Sato 		sin6->sin6_len = sizeof(*sin6);
282ca007d91SDag-Erling Smørgrav 		sin6->sin6_family = af;
283ca007d91SDag-Erling Smørgrav 		sin6->sin6_port = port;
284ca007d91SDag-Erling Smørgrav 		sin6->sin6_addr = *(struct in6_addr *)addr;
285b8e20e2dSHiroki Sato #define	s6_addr16	__u6_addr.__u6_addr16
286b8e20e2dSHiroki Sato 		if (IN6_IS_ADDR_LINKLOCAL(&sin6->sin6_addr)) {
287b8e20e2dSHiroki Sato 			sin6->sin6_scope_id =
288b8e20e2dSHiroki Sato 			    ntohs(sin6->sin6_addr.s6_addr16[1]);
289b8e20e2dSHiroki Sato 			sin6->sin6_addr.s6_addr16[1] = 0;
290b8e20e2dSHiroki Sato 		}
291ca007d91SDag-Erling Smørgrav 		break;
292ca007d91SDag-Erling Smørgrav 	default:
293ca007d91SDag-Erling Smørgrav 		abort();
294ca007d91SDag-Erling Smørgrav 	}
295ca007d91SDag-Erling Smørgrav }
296ca007d91SDag-Erling Smørgrav 
297ca007d91SDag-Erling Smørgrav static void
298bedcf91dSMichael Tuexen free_socket(struct sock *sock)
299bedcf91dSMichael Tuexen {
300bedcf91dSMichael Tuexen 	struct addr *cur, *next;
301bedcf91dSMichael Tuexen 
302bedcf91dSMichael Tuexen 	cur = sock->laddr;
303bedcf91dSMichael Tuexen 	while (cur != NULL) {
304bedcf91dSMichael Tuexen 		next = cur->next;
305bedcf91dSMichael Tuexen 		free(cur);
306bedcf91dSMichael Tuexen 		cur = next;
307bedcf91dSMichael Tuexen 	}
308bedcf91dSMichael Tuexen 	cur = sock->faddr;
309bedcf91dSMichael Tuexen 	while (cur != NULL) {
310bedcf91dSMichael Tuexen 		next = cur->next;
311bedcf91dSMichael Tuexen 		free(cur);
312bedcf91dSMichael Tuexen 		cur = next;
313bedcf91dSMichael Tuexen 	}
314bedcf91dSMichael Tuexen 	free(sock);
315bedcf91dSMichael Tuexen }
316bedcf91dSMichael Tuexen 
317bedcf91dSMichael Tuexen static void
318d5b4aa90SMichael Tuexen gather_sctp(void)
319d5b4aa90SMichael Tuexen {
320d5b4aa90SMichael Tuexen 	struct sock *sock;
321d5b4aa90SMichael Tuexen 	struct addr *laddr, *prev_laddr, *faddr, *prev_faddr;
322d5b4aa90SMichael Tuexen 	struct xsctp_inpcb *xinpcb;
323d5b4aa90SMichael Tuexen 	struct xsctp_tcb *xstcb;
324d5b4aa90SMichael Tuexen 	struct xsctp_raddr *xraddr;
325d5b4aa90SMichael Tuexen 	struct xsctp_laddr *xladdr;
326d5b4aa90SMichael Tuexen 	const char *varname;
327d5b4aa90SMichael Tuexen 	size_t len, offset;
328d5b4aa90SMichael Tuexen 	char *buf;
329d5b4aa90SMichael Tuexen 	int hash, vflag;
330d5b4aa90SMichael Tuexen 	int no_stcb, local_all_loopback, foreign_all_loopback;
331d5b4aa90SMichael Tuexen 
332d5b4aa90SMichael Tuexen 	vflag = 0;
333d5b4aa90SMichael Tuexen 	if (opt_4)
334d5b4aa90SMichael Tuexen 		vflag |= INP_IPV4;
335d5b4aa90SMichael Tuexen 	if (opt_6)
336d5b4aa90SMichael Tuexen 		vflag |= INP_IPV6;
337d5b4aa90SMichael Tuexen 
338d5b4aa90SMichael Tuexen 	varname = "net.inet.sctp.assoclist";
339c5a2d8c5SRyan Moeller 	if (cap_sysctlbyname(capsysctl, varname, 0, &len, 0, 0) < 0) {
340d5b4aa90SMichael Tuexen 		if (errno != ENOENT)
341c5a2d8c5SRyan Moeller 			err(1, "cap_sysctlbyname()");
342d5b4aa90SMichael Tuexen 		return;
343d5b4aa90SMichael Tuexen 	}
344d5b4aa90SMichael Tuexen 	if ((buf = (char *)malloc(len)) == NULL) {
345d5b4aa90SMichael Tuexen 		err(1, "malloc()");
346d5b4aa90SMichael Tuexen 		return;
347d5b4aa90SMichael Tuexen 	}
348c5a2d8c5SRyan Moeller 	if (cap_sysctlbyname(capsysctl, varname, buf, &len, 0, 0) < 0) {
349c5a2d8c5SRyan Moeller 		err(1, "cap_sysctlbyname()");
350d5b4aa90SMichael Tuexen 		free(buf);
351d5b4aa90SMichael Tuexen 		return;
352d5b4aa90SMichael Tuexen 	}
353d5b4aa90SMichael Tuexen 	xinpcb = (struct xsctp_inpcb *)(void *)buf;
354d5b4aa90SMichael Tuexen 	offset = sizeof(struct xsctp_inpcb);
355d5b4aa90SMichael Tuexen 	while ((offset < len) && (xinpcb->last == 0)) {
356d5b4aa90SMichael Tuexen 		if ((sock = calloc(1, sizeof *sock)) == NULL)
357d5b4aa90SMichael Tuexen 			err(1, "malloc()");
358d5b4aa90SMichael Tuexen 		sock->socket = xinpcb->socket;
359d5b4aa90SMichael Tuexen 		sock->proto = IPPROTO_SCTP;
360d5b4aa90SMichael Tuexen 		sock->protoname = "sctp";
361c1eb13c7SMichael Tuexen 		if (xinpcb->maxqlen == 0)
3626414db1bSMichael Tuexen 			sock->state = SCTP_CLOSED;
3636414db1bSMichael Tuexen 		else
3646414db1bSMichael Tuexen 			sock->state = SCTP_LISTEN;
365d5b4aa90SMichael Tuexen 		if (xinpcb->flags & SCTP_PCB_FLAGS_BOUND_V6) {
366d5b4aa90SMichael Tuexen 			sock->family = AF_INET6;
367edc9c7fcSMichael Tuexen 			/*
368edc9c7fcSMichael Tuexen 			 * Currently there is no way to distinguish between
369edc9c7fcSMichael Tuexen 			 * IPv6 only sockets or dual family sockets.
370edc9c7fcSMichael Tuexen 			 * So mark it as dual socket.
371edc9c7fcSMichael Tuexen 			 */
372edc9c7fcSMichael Tuexen 			sock->vflag = INP_IPV6 | INP_IPV4;
373d5b4aa90SMichael Tuexen 		} else {
374d5b4aa90SMichael Tuexen 			sock->family = AF_INET;
375d5b4aa90SMichael Tuexen 			sock->vflag = INP_IPV4;
376d5b4aa90SMichael Tuexen 		}
377d5b4aa90SMichael Tuexen 		prev_laddr = NULL;
378d5b4aa90SMichael Tuexen 		local_all_loopback = 1;
379d5b4aa90SMichael Tuexen 		while (offset < len) {
380d5b4aa90SMichael Tuexen 			xladdr = (struct xsctp_laddr *)(void *)(buf + offset);
381d5b4aa90SMichael Tuexen 			offset += sizeof(struct xsctp_laddr);
382d5b4aa90SMichael Tuexen 			if (xladdr->last == 1)
383d5b4aa90SMichael Tuexen 				break;
384d5b4aa90SMichael Tuexen 			if ((laddr = calloc(1, sizeof(struct addr))) == NULL)
385d5b4aa90SMichael Tuexen 				err(1, "malloc()");
386d5b4aa90SMichael Tuexen 			switch (xladdr->address.sa.sa_family) {
387d5b4aa90SMichael Tuexen 			case AF_INET:
388d5b4aa90SMichael Tuexen #define	__IN_IS_ADDR_LOOPBACK(pina) \
389d5b4aa90SMichael Tuexen 	((ntohl((pina)->s_addr) >> IN_CLASSA_NSHIFT) == IN_LOOPBACKNET)
39027569d01SRenato Botelho 				if (!__IN_IS_ADDR_LOOPBACK(
39127569d01SRenato Botelho 				    &xladdr->address.sin.sin_addr))
392d5b4aa90SMichael Tuexen 					local_all_loopback = 0;
393d5b4aa90SMichael Tuexen #undef	__IN_IS_ADDR_LOOPBACK
39427569d01SRenato Botelho 				sockaddr(&laddr->address, AF_INET,
395d5b4aa90SMichael Tuexen 				    &xladdr->address.sin.sin_addr,
396d5b4aa90SMichael Tuexen 				    htons(xinpcb->local_port));
397d5b4aa90SMichael Tuexen 				break;
398d5b4aa90SMichael Tuexen 			case AF_INET6:
39927569d01SRenato Botelho 				if (!IN6_IS_ADDR_LOOPBACK(
40027569d01SRenato Botelho 				    &xladdr->address.sin6.sin6_addr))
401d5b4aa90SMichael Tuexen 					local_all_loopback = 0;
40227569d01SRenato Botelho 				sockaddr(&laddr->address, AF_INET6,
403d5b4aa90SMichael Tuexen 				    &xladdr->address.sin6.sin6_addr,
404d5b4aa90SMichael Tuexen 				    htons(xinpcb->local_port));
405d5b4aa90SMichael Tuexen 				break;
406d5b4aa90SMichael Tuexen 			default:
407463a577bSEitan Adler 				errx(1, "address family %d not supported",
408d5b4aa90SMichael Tuexen 				    xladdr->address.sa.sa_family);
409d5b4aa90SMichael Tuexen 			}
410d5b4aa90SMichael Tuexen 			laddr->next = NULL;
411d5b4aa90SMichael Tuexen 			if (prev_laddr == NULL)
412d5b4aa90SMichael Tuexen 				sock->laddr = laddr;
413d5b4aa90SMichael Tuexen 			else
414d5b4aa90SMichael Tuexen 				prev_laddr->next = laddr;
415d5b4aa90SMichael Tuexen 			prev_laddr = laddr;
416d5b4aa90SMichael Tuexen 		}
417d5b4aa90SMichael Tuexen 		if (sock->laddr == NULL) {
41827569d01SRenato Botelho 			if ((sock->laddr =
41927569d01SRenato Botelho 			    calloc(1, sizeof(struct addr))) == NULL)
420d5b4aa90SMichael Tuexen 				err(1, "malloc()");
421d5b4aa90SMichael Tuexen 			sock->laddr->address.ss_family = sock->family;
422d5b4aa90SMichael Tuexen 			if (sock->family == AF_INET)
42327569d01SRenato Botelho 				sock->laddr->address.ss_len =
42427569d01SRenato Botelho 				    sizeof(struct sockaddr_in);
425d5b4aa90SMichael Tuexen 			else
42627569d01SRenato Botelho 				sock->laddr->address.ss_len =
42727569d01SRenato Botelho 				    sizeof(struct sockaddr_in6);
428d5b4aa90SMichael Tuexen 			local_all_loopback = 0;
429d5b4aa90SMichael Tuexen 		}
430d5b4aa90SMichael Tuexen 		if ((sock->faddr = calloc(1, sizeof(struct addr))) == NULL)
431d5b4aa90SMichael Tuexen 			err(1, "malloc()");
432d5b4aa90SMichael Tuexen 		sock->faddr->address.ss_family = sock->family;
433d5b4aa90SMichael Tuexen 		if (sock->family == AF_INET)
43427569d01SRenato Botelho 			sock->faddr->address.ss_len =
43527569d01SRenato Botelho 			    sizeof(struct sockaddr_in);
436d5b4aa90SMichael Tuexen 		else
43727569d01SRenato Botelho 			sock->faddr->address.ss_len =
43827569d01SRenato Botelho 			    sizeof(struct sockaddr_in6);
439d5b4aa90SMichael Tuexen 		no_stcb = 1;
440d5b4aa90SMichael Tuexen 		while (offset < len) {
441d5b4aa90SMichael Tuexen 			xstcb = (struct xsctp_tcb *)(void *)(buf + offset);
442d5b4aa90SMichael Tuexen 			offset += sizeof(struct xsctp_tcb);
443bedcf91dSMichael Tuexen 			if (no_stcb) {
44427569d01SRenato Botelho 				if (opt_l && (sock->vflag & vflag) &&
445d5b4aa90SMichael Tuexen 				    (!opt_L || !local_all_loopback) &&
446d5b4aa90SMichael Tuexen 				    ((xinpcb->flags & SCTP_PCB_FLAGS_UDPTYPE) ||
447d5b4aa90SMichael Tuexen 				     (xstcb->last == 1))) {
44827569d01SRenato Botelho 					hash = (int)((uintptr_t)sock->socket %
44927569d01SRenato Botelho 					    HASHSIZE);
450d5b4aa90SMichael Tuexen 					sock->next = sockhash[hash];
451d5b4aa90SMichael Tuexen 					sockhash[hash] = sock;
452bedcf91dSMichael Tuexen 				} else {
453bedcf91dSMichael Tuexen 					free_socket(sock);
454bedcf91dSMichael Tuexen 				}
455d5b4aa90SMichael Tuexen 			}
456d5b4aa90SMichael Tuexen 			if (xstcb->last == 1)
457d5b4aa90SMichael Tuexen 				break;
458d5b4aa90SMichael Tuexen 			no_stcb = 0;
459d5b4aa90SMichael Tuexen 			if (opt_c) {
460d5b4aa90SMichael Tuexen 				if ((sock = calloc(1, sizeof *sock)) == NULL)
461d5b4aa90SMichael Tuexen 					err(1, "malloc()");
462d5b4aa90SMichael Tuexen 				sock->socket = xinpcb->socket;
463d5b4aa90SMichael Tuexen 				sock->proto = IPPROTO_SCTP;
464d5b4aa90SMichael Tuexen 				sock->protoname = "sctp";
4656414db1bSMichael Tuexen 				sock->state = (int)xstcb->state;
466d5b4aa90SMichael Tuexen 				if (xinpcb->flags & SCTP_PCB_FLAGS_BOUND_V6) {
467d5b4aa90SMichael Tuexen 					sock->family = AF_INET6;
468edc9c7fcSMichael Tuexen 				/*
469edc9c7fcSMichael Tuexen 				 * Currently there is no way to distinguish
470edc9c7fcSMichael Tuexen 				 * between IPv6 only sockets or dual family
471edc9c7fcSMichael Tuexen 				 *  sockets. So mark it as dual socket.
472edc9c7fcSMichael Tuexen 				 */
473edc9c7fcSMichael Tuexen 					sock->vflag = INP_IPV6 | INP_IPV4;
474d5b4aa90SMichael Tuexen 				} else {
475d5b4aa90SMichael Tuexen 					sock->family = AF_INET;
476d5b4aa90SMichael Tuexen 					sock->vflag = INP_IPV4;
477d5b4aa90SMichael Tuexen 				}
478d5b4aa90SMichael Tuexen 			}
479d5b4aa90SMichael Tuexen 			prev_laddr = NULL;
480d5b4aa90SMichael Tuexen 			local_all_loopback = 1;
481d5b4aa90SMichael Tuexen 			while (offset < len) {
48227569d01SRenato Botelho 				xladdr = (struct xsctp_laddr *)(void *)(buf +
48327569d01SRenato Botelho 				    offset);
484d5b4aa90SMichael Tuexen 				offset += sizeof(struct xsctp_laddr);
485d5b4aa90SMichael Tuexen 				if (xladdr->last == 1)
486d5b4aa90SMichael Tuexen 					break;
487d5b4aa90SMichael Tuexen 				if (!opt_c)
488d5b4aa90SMichael Tuexen 					continue;
48927569d01SRenato Botelho 				laddr = calloc(1, sizeof(struct addr));
49027569d01SRenato Botelho 				if (laddr == NULL)
491d5b4aa90SMichael Tuexen 					err(1, "malloc()");
492d5b4aa90SMichael Tuexen 				switch (xladdr->address.sa.sa_family) {
493d5b4aa90SMichael Tuexen 				case AF_INET:
494d5b4aa90SMichael Tuexen #define	__IN_IS_ADDR_LOOPBACK(pina) \
495d5b4aa90SMichael Tuexen 	((ntohl((pina)->s_addr) >> IN_CLASSA_NSHIFT) == IN_LOOPBACKNET)
49627569d01SRenato Botelho 					if (!__IN_IS_ADDR_LOOPBACK(
49727569d01SRenato Botelho 					    &xladdr->address.sin.sin_addr))
498d5b4aa90SMichael Tuexen 						local_all_loopback = 0;
499d5b4aa90SMichael Tuexen #undef	__IN_IS_ADDR_LOOPBACK
50027569d01SRenato Botelho 					sockaddr(&laddr->address, AF_INET,
501d5b4aa90SMichael Tuexen 					    &xladdr->address.sin.sin_addr,
502d5b4aa90SMichael Tuexen 					    htons(xstcb->local_port));
503d5b4aa90SMichael Tuexen 					break;
504d5b4aa90SMichael Tuexen 				case AF_INET6:
50527569d01SRenato Botelho 					if (!IN6_IS_ADDR_LOOPBACK(
50627569d01SRenato Botelho 					    &xladdr->address.sin6.sin6_addr))
507d5b4aa90SMichael Tuexen 						local_all_loopback = 0;
50827569d01SRenato Botelho 					sockaddr(&laddr->address, AF_INET6,
509d5b4aa90SMichael Tuexen 					    &xladdr->address.sin6.sin6_addr,
510d5b4aa90SMichael Tuexen 					    htons(xstcb->local_port));
511d5b4aa90SMichael Tuexen 					break;
512d5b4aa90SMichael Tuexen 				default:
51327569d01SRenato Botelho 					errx(1,
51427569d01SRenato Botelho 					    "address family %d not supported",
515d5b4aa90SMichael Tuexen 					    xladdr->address.sa.sa_family);
516d5b4aa90SMichael Tuexen 				}
517d5b4aa90SMichael Tuexen 				laddr->next = NULL;
518d5b4aa90SMichael Tuexen 				if (prev_laddr == NULL)
519d5b4aa90SMichael Tuexen 					sock->laddr = laddr;
520d5b4aa90SMichael Tuexen 				else
521d5b4aa90SMichael Tuexen 					prev_laddr->next = laddr;
522d5b4aa90SMichael Tuexen 				prev_laddr = laddr;
523d5b4aa90SMichael Tuexen 			}
524d5b4aa90SMichael Tuexen 			prev_faddr = NULL;
525d5b4aa90SMichael Tuexen 			foreign_all_loopback = 1;
526d5b4aa90SMichael Tuexen 			while (offset < len) {
52727569d01SRenato Botelho 				xraddr = (struct xsctp_raddr *)(void *)(buf +
52827569d01SRenato Botelho 				    offset);
529d5b4aa90SMichael Tuexen 				offset += sizeof(struct xsctp_raddr);
530d5b4aa90SMichael Tuexen 				if (xraddr->last == 1)
531d5b4aa90SMichael Tuexen 					break;
532d5b4aa90SMichael Tuexen 				if (!opt_c)
533d5b4aa90SMichael Tuexen 					continue;
53427569d01SRenato Botelho 				faddr = calloc(1, sizeof(struct addr));
53527569d01SRenato Botelho 				if (faddr == NULL)
536d5b4aa90SMichael Tuexen 					err(1, "malloc()");
537d5b4aa90SMichael Tuexen 				switch (xraddr->address.sa.sa_family) {
538d5b4aa90SMichael Tuexen 				case AF_INET:
539d5b4aa90SMichael Tuexen #define	__IN_IS_ADDR_LOOPBACK(pina) \
540d5b4aa90SMichael Tuexen 	((ntohl((pina)->s_addr) >> IN_CLASSA_NSHIFT) == IN_LOOPBACKNET)
54127569d01SRenato Botelho 					if (!__IN_IS_ADDR_LOOPBACK(
54227569d01SRenato Botelho 					    &xraddr->address.sin.sin_addr))
543d5b4aa90SMichael Tuexen 						foreign_all_loopback = 0;
544d5b4aa90SMichael Tuexen #undef	__IN_IS_ADDR_LOOPBACK
54527569d01SRenato Botelho 					sockaddr(&faddr->address, AF_INET,
546d5b4aa90SMichael Tuexen 					    &xraddr->address.sin.sin_addr,
547d5b4aa90SMichael Tuexen 					    htons(xstcb->remote_port));
548d5b4aa90SMichael Tuexen 					break;
549d5b4aa90SMichael Tuexen 				case AF_INET6:
55027569d01SRenato Botelho 					if (!IN6_IS_ADDR_LOOPBACK(
55127569d01SRenato Botelho 					    &xraddr->address.sin6.sin6_addr))
552d5b4aa90SMichael Tuexen 						foreign_all_loopback = 0;
55327569d01SRenato Botelho 					sockaddr(&faddr->address, AF_INET6,
554d5b4aa90SMichael Tuexen 					    &xraddr->address.sin6.sin6_addr,
555d5b4aa90SMichael Tuexen 					    htons(xstcb->remote_port));
556d5b4aa90SMichael Tuexen 					break;
557d5b4aa90SMichael Tuexen 				default:
55827569d01SRenato Botelho 					errx(1,
55927569d01SRenato Botelho 					    "address family %d not supported",
560d5b4aa90SMichael Tuexen 					    xraddr->address.sa.sa_family);
561d5b4aa90SMichael Tuexen 				}
56249b836f2SMichael Tuexen 				faddr->encaps_port = xraddr->encaps_port;
563e389705eSMichael Tuexen 				faddr->state = xraddr->state;
564d5b4aa90SMichael Tuexen 				faddr->next = NULL;
565d5b4aa90SMichael Tuexen 				if (prev_faddr == NULL)
566d5b4aa90SMichael Tuexen 					sock->faddr = faddr;
567d5b4aa90SMichael Tuexen 				else
568d5b4aa90SMichael Tuexen 					prev_faddr->next = faddr;
569d5b4aa90SMichael Tuexen 				prev_faddr = faddr;
570d5b4aa90SMichael Tuexen 			}
571bedcf91dSMichael Tuexen 			if (opt_c) {
572edc9c7fcSMichael Tuexen 				if ((sock->vflag & vflag) &&
573edc9c7fcSMichael Tuexen 				    (!opt_L ||
57427569d01SRenato Botelho 				     !(local_all_loopback ||
57527569d01SRenato Botelho 				     foreign_all_loopback))) {
57627569d01SRenato Botelho 					hash = (int)((uintptr_t)sock->socket %
57727569d01SRenato Botelho 					    HASHSIZE);
578d5b4aa90SMichael Tuexen 					sock->next = sockhash[hash];
579d5b4aa90SMichael Tuexen 					sockhash[hash] = sock;
580bedcf91dSMichael Tuexen 				} else {
581bedcf91dSMichael Tuexen 					free_socket(sock);
582bedcf91dSMichael Tuexen 				}
583d5b4aa90SMichael Tuexen 			}
584d5b4aa90SMichael Tuexen 		}
585d5b4aa90SMichael Tuexen 		xinpcb = (struct xsctp_inpcb *)(void *)(buf + offset);
586d5b4aa90SMichael Tuexen 		offset += sizeof(struct xsctp_inpcb);
587d5b4aa90SMichael Tuexen 	}
588d5b4aa90SMichael Tuexen 	free(buf);
589d5b4aa90SMichael Tuexen }
590d5b4aa90SMichael Tuexen 
591d5b4aa90SMichael Tuexen static void
592ca007d91SDag-Erling Smørgrav gather_inet(int proto)
593ca007d91SDag-Erling Smørgrav {
594ca007d91SDag-Erling Smørgrav 	struct xinpgen *xig, *exig;
595ca007d91SDag-Erling Smørgrav 	struct xinpcb *xip;
596bf40d2caSGleb Smirnoff 	struct xtcpcb *xtp = NULL;
597ca007d91SDag-Erling Smørgrav 	struct xsocket *so;
598ca007d91SDag-Erling Smørgrav 	struct sock *sock;
599e6f718c7SMichael Tuexen 	struct addr *laddr, *faddr;
600ca007d91SDag-Erling Smørgrav 	const char *varname, *protoname;
601ca007d91SDag-Erling Smørgrav 	size_t len, bufsize;
602ca007d91SDag-Erling Smørgrav 	void *buf;
6036eb1d5baSMichael Tuexen 	int hash, retry, vflag;
604ca007d91SDag-Erling Smørgrav 
6056eb1d5baSMichael Tuexen 	vflag = 0;
606ca007d91SDag-Erling Smørgrav 	if (opt_4)
607ca007d91SDag-Erling Smørgrav 		vflag |= INP_IPV4;
608ca007d91SDag-Erling Smørgrav 	if (opt_6)
609ca007d91SDag-Erling Smørgrav 		vflag |= INP_IPV6;
610ca007d91SDag-Erling Smørgrav 
611ca007d91SDag-Erling Smørgrav 	switch (proto) {
612ca007d91SDag-Erling Smørgrav 	case IPPROTO_TCP:
613ca007d91SDag-Erling Smørgrav 		varname = "net.inet.tcp.pcblist";
614ca007d91SDag-Erling Smørgrav 		protoname = "tcp";
615ca007d91SDag-Erling Smørgrav 		break;
616ca007d91SDag-Erling Smørgrav 	case IPPROTO_UDP:
617ca007d91SDag-Erling Smørgrav 		varname = "net.inet.udp.pcblist";
618ca007d91SDag-Erling Smørgrav 		protoname = "udp";
619ca007d91SDag-Erling Smørgrav 		break;
6202cfbdf89SRuslan Ermilov 	case IPPROTO_DIVERT:
6212cfbdf89SRuslan Ermilov 		varname = "net.inet.divert.pcblist";
6222cfbdf89SRuslan Ermilov 		protoname = "div";
6232cfbdf89SRuslan Ermilov 		break;
624ca007d91SDag-Erling Smørgrav 	default:
6251f3d67aaSGiorgos Keramidas 		errx(1, "protocol %d not supported", proto);
626ca007d91SDag-Erling Smørgrav 	}
627ca007d91SDag-Erling Smørgrav 
628ca007d91SDag-Erling Smørgrav 	buf = NULL;
629ca007d91SDag-Erling Smørgrav 	bufsize = 8192;
630ca007d91SDag-Erling Smørgrav 	retry = 5;
631ca007d91SDag-Erling Smørgrav 	do {
632ca007d91SDag-Erling Smørgrav 		for (;;) {
633ca007d91SDag-Erling Smørgrav 			if ((buf = realloc(buf, bufsize)) == NULL)
634ca007d91SDag-Erling Smørgrav 				err(1, "realloc()");
635ca007d91SDag-Erling Smørgrav 			len = bufsize;
636c5a2d8c5SRyan Moeller 			if (cap_sysctlbyname(capsysctl, varname, buf, &len,
637c5a2d8c5SRyan Moeller 			    NULL, 0) == 0)
638ca007d91SDag-Erling Smørgrav 				break;
6394b2a3d41SRuslan Ermilov 			if (errno == ENOENT)
6404b2a3d41SRuslan Ermilov 				goto out;
641003e7e49SMikolaj Golub 			if (errno != ENOMEM || len != bufsize)
642c5a2d8c5SRyan Moeller 				err(1, "cap_sysctlbyname()");
643ca007d91SDag-Erling Smørgrav 			bufsize *= 2;
644ca007d91SDag-Erling Smørgrav 		}
645ca007d91SDag-Erling Smørgrav 		xig = (struct xinpgen *)buf;
6466dbe8d53SRobert Drehmel 		exig = (struct xinpgen *)(void *)
6476dbe8d53SRobert Drehmel 		    ((char *)buf + len - sizeof *exig);
648ca007d91SDag-Erling Smørgrav 		if (xig->xig_len != sizeof *xig ||
649ca007d91SDag-Erling Smørgrav 		    exig->xig_len != sizeof *exig)
650ca007d91SDag-Erling Smørgrav 			errx(1, "struct xinpgen size mismatch");
651ca007d91SDag-Erling Smørgrav 	} while (xig->xig_gen != exig->xig_gen && retry--);
652ca007d91SDag-Erling Smørgrav 
653ca007d91SDag-Erling Smørgrav 	if (xig->xig_gen != exig->xig_gen && opt_v)
654ca007d91SDag-Erling Smørgrav 		warnx("warning: data may be inconsistent");
655ca007d91SDag-Erling Smørgrav 
656ca007d91SDag-Erling Smørgrav 	for (;;) {
6576dbe8d53SRobert Drehmel 		xig = (struct xinpgen *)(void *)((char *)xig + xig->xig_len);
658ca007d91SDag-Erling Smørgrav 		if (xig >= exig)
659ca007d91SDag-Erling Smørgrav 			break;
660ca007d91SDag-Erling Smørgrav 		switch (proto) {
661ca007d91SDag-Erling Smørgrav 		case IPPROTO_TCP:
662cc65eb4eSGleb Smirnoff 			xtp = (struct xtcpcb *)xig;
663cc65eb4eSGleb Smirnoff 			xip = &xtp->xt_inp;
664b8e20e2dSHiroki Sato 			if (xtp->xt_len != sizeof(*xtp)) {
665ca007d91SDag-Erling Smørgrav 				warnx("struct xtcpcb size mismatch");
666ca007d91SDag-Erling Smørgrav 				goto out;
667ca007d91SDag-Erling Smørgrav 			}
668cc65eb4eSGleb Smirnoff 			protoname = xtp->t_flags & TF_TOE ? "toe" : "tcp";
669ca007d91SDag-Erling Smørgrav 			break;
670ca007d91SDag-Erling Smørgrav 		case IPPROTO_UDP:
6712cfbdf89SRuslan Ermilov 		case IPPROTO_DIVERT:
672cc65eb4eSGleb Smirnoff 			xip = (struct xinpcb *)xig;
673b8e20e2dSHiroki Sato 			if (xip->xi_len != sizeof(*xip)) {
674ca007d91SDag-Erling Smørgrav 				warnx("struct xinpcb size mismatch");
675ca007d91SDag-Erling Smørgrav 				goto out;
676ca007d91SDag-Erling Smørgrav 			}
677ca007d91SDag-Erling Smørgrav 			break;
678ca007d91SDag-Erling Smørgrav 		default:
6791f3d67aaSGiorgos Keramidas 			errx(1, "protocol %d not supported", proto);
680ca007d91SDag-Erling Smørgrav 		}
681cc65eb4eSGleb Smirnoff 		so = &xip->xi_socket;
682cc65eb4eSGleb Smirnoff 		if ((xip->inp_vflag & vflag) == 0)
683ca007d91SDag-Erling Smørgrav 			continue;
684cc65eb4eSGleb Smirnoff 		if (xip->inp_vflag & INP_IPV4) {
685cc65eb4eSGleb Smirnoff 			if ((xip->inp_fport == 0 && !opt_l) ||
686cc65eb4eSGleb Smirnoff 			    (xip->inp_fport != 0 && !opt_c))
6871e6690e5SDag-Erling Smørgrav 				continue;
6889b6ca892SBruce M Simpson #define	__IN_IS_ADDR_LOOPBACK(pina) \
6899b6ca892SBruce M Simpson 	((ntohl((pina)->s_addr) >> IN_CLASSA_NSHIFT) == IN_LOOPBACKNET)
6909b6ca892SBruce M Simpson 			if (opt_L &&
691cc65eb4eSGleb Smirnoff 			    (__IN_IS_ADDR_LOOPBACK(&xip->inp_faddr) ||
692cc65eb4eSGleb Smirnoff 			     __IN_IS_ADDR_LOOPBACK(&xip->inp_laddr)))
6939b6ca892SBruce M Simpson 				continue;
6949b6ca892SBruce M Simpson #undef	__IN_IS_ADDR_LOOPBACK
695cc65eb4eSGleb Smirnoff 		} else if (xip->inp_vflag & INP_IPV6) {
696cc65eb4eSGleb Smirnoff 			if ((xip->inp_fport == 0 && !opt_l) ||
697cc65eb4eSGleb Smirnoff 			    (xip->inp_fport != 0 && !opt_c))
6981e6690e5SDag-Erling Smørgrav 				continue;
6999b6ca892SBruce M Simpson 			if (opt_L &&
700cc65eb4eSGleb Smirnoff 			    (IN6_IS_ADDR_LOOPBACK(&xip->in6p_faddr) ||
701cc65eb4eSGleb Smirnoff 			     IN6_IS_ADDR_LOOPBACK(&xip->in6p_laddr)))
7029b6ca892SBruce M Simpson 				continue;
7031e6690e5SDag-Erling Smørgrav 		} else {
7041e6690e5SDag-Erling Smørgrav 			if (opt_v)
705cc65eb4eSGleb Smirnoff 				warnx("invalid vflag 0x%x", xip->inp_vflag);
7061e6690e5SDag-Erling Smørgrav 			continue;
7071e6690e5SDag-Erling Smørgrav 		}
708b8e20e2dSHiroki Sato 		if ((sock = calloc(1, sizeof(*sock))) == NULL)
709ca007d91SDag-Erling Smørgrav 			err(1, "malloc()");
710e6f718c7SMichael Tuexen 		if ((laddr = calloc(1, sizeof *laddr)) == NULL)
711e6f718c7SMichael Tuexen 			err(1, "malloc()");
712e6f718c7SMichael Tuexen 		if ((faddr = calloc(1, sizeof *faddr)) == NULL)
713e6f718c7SMichael Tuexen 			err(1, "malloc()");
714ca007d91SDag-Erling Smørgrav 		sock->socket = so->xso_so;
715ca007d91SDag-Erling Smørgrav 		sock->proto = proto;
716cc65eb4eSGleb Smirnoff 		if (xip->inp_vflag & INP_IPV4) {
717ca007d91SDag-Erling Smørgrav 			sock->family = AF_INET;
718e6f718c7SMichael Tuexen 			sockaddr(&laddr->address, sock->family,
719cc65eb4eSGleb Smirnoff 			    &xip->inp_laddr, xip->inp_lport);
720e6f718c7SMichael Tuexen 			sockaddr(&faddr->address, sock->family,
721cc65eb4eSGleb Smirnoff 			    &xip->inp_faddr, xip->inp_fport);
722cc65eb4eSGleb Smirnoff 		} else if (xip->inp_vflag & INP_IPV6) {
723ca007d91SDag-Erling Smørgrav 			sock->family = AF_INET6;
724e6f718c7SMichael Tuexen 			sockaddr(&laddr->address, sock->family,
725cc65eb4eSGleb Smirnoff 			    &xip->in6p_laddr, xip->inp_lport);
726e6f718c7SMichael Tuexen 			sockaddr(&faddr->address, sock->family,
727cc65eb4eSGleb Smirnoff 			    &xip->in6p_faddr, xip->inp_fport);
728ca007d91SDag-Erling Smørgrav 		}
7299e644c23SMichael Tuexen 		if (proto == IPPROTO_TCP)
7309e644c23SMichael Tuexen 			faddr->encaps_port = xtp->xt_encaps_port;
731e6f718c7SMichael Tuexen 		laddr->next = NULL;
732e6f718c7SMichael Tuexen 		faddr->next = NULL;
733e6f718c7SMichael Tuexen 		sock->laddr = laddr;
734e6f718c7SMichael Tuexen 		sock->faddr = faddr;
735cc65eb4eSGleb Smirnoff 		sock->vflag = xip->inp_vflag;
736e5cccc35SMichael Tuexen 		if (proto == IPPROTO_TCP) {
737cc65eb4eSGleb Smirnoff 			sock->state = xtp->t_state;
738e5cccc35SMichael Tuexen 			memcpy(sock->stack, xtp->xt_stack,
739e5cccc35SMichael Tuexen 			    TCP_FUNCTION_NAME_LEN_MAX);
7402ac089d0SMichael Tuexen 			memcpy(sock->cc, xtp->xt_cc, TCP_CA_NAME_MAX);
741e5cccc35SMichael Tuexen 		}
742ca007d91SDag-Erling Smørgrav 		sock->protoname = protoname;
743ca007d91SDag-Erling Smørgrav 		hash = (int)((uintptr_t)sock->socket % HASHSIZE);
744ca007d91SDag-Erling Smørgrav 		sock->next = sockhash[hash];
745ca007d91SDag-Erling Smørgrav 		sockhash[hash] = sock;
746ca007d91SDag-Erling Smørgrav 	}
747ca007d91SDag-Erling Smørgrav out:
748ca007d91SDag-Erling Smørgrav 	free(buf);
749ca007d91SDag-Erling Smørgrav }
750ca007d91SDag-Erling Smørgrav 
751ca007d91SDag-Erling Smørgrav static void
752ca007d91SDag-Erling Smørgrav gather_unix(int proto)
753ca007d91SDag-Erling Smørgrav {
754ca007d91SDag-Erling Smørgrav 	struct xunpgen *xug, *exug;
755ca007d91SDag-Erling Smørgrav 	struct xunpcb *xup;
756ca007d91SDag-Erling Smørgrav 	struct sock *sock;
757e6f718c7SMichael Tuexen 	struct addr *laddr, *faddr;
758ca007d91SDag-Erling Smørgrav 	const char *varname, *protoname;
759ca007d91SDag-Erling Smørgrav 	size_t len, bufsize;
760ca007d91SDag-Erling Smørgrav 	void *buf;
761ca007d91SDag-Erling Smørgrav 	int hash, retry;
762ca007d91SDag-Erling Smørgrav 
763ca007d91SDag-Erling Smørgrav 	switch (proto) {
764ca007d91SDag-Erling Smørgrav 	case SOCK_STREAM:
765ca007d91SDag-Erling Smørgrav 		varname = "net.local.stream.pcblist";
766ca007d91SDag-Erling Smørgrav 		protoname = "stream";
767ca007d91SDag-Erling Smørgrav 		break;
768ca007d91SDag-Erling Smørgrav 	case SOCK_DGRAM:
769ca007d91SDag-Erling Smørgrav 		varname = "net.local.dgram.pcblist";
770ca007d91SDag-Erling Smørgrav 		protoname = "dgram";
771ca007d91SDag-Erling Smørgrav 		break;
772b8e20e2dSHiroki Sato 	case SOCK_SEQPACKET:
773b8e20e2dSHiroki Sato 		varname = "net.local.seqpacket.pcblist";
774b8e20e2dSHiroki Sato 		protoname = "seqpac";
775b8e20e2dSHiroki Sato 		break;
776ca007d91SDag-Erling Smørgrav 	default:
777ca007d91SDag-Erling Smørgrav 		abort();
778ca007d91SDag-Erling Smørgrav 	}
779ca007d91SDag-Erling Smørgrav 	buf = NULL;
780ca007d91SDag-Erling Smørgrav 	bufsize = 8192;
781ca007d91SDag-Erling Smørgrav 	retry = 5;
782ca007d91SDag-Erling Smørgrav 	do {
783ca007d91SDag-Erling Smørgrav 		for (;;) {
784ca007d91SDag-Erling Smørgrav 			if ((buf = realloc(buf, bufsize)) == NULL)
785ca007d91SDag-Erling Smørgrav 				err(1, "realloc()");
786ca007d91SDag-Erling Smørgrav 			len = bufsize;
787c5a2d8c5SRyan Moeller 			if (cap_sysctlbyname(capsysctl, varname, buf, &len,
788c5a2d8c5SRyan Moeller 			    NULL, 0) == 0)
789ca007d91SDag-Erling Smørgrav 				break;
790003e7e49SMikolaj Golub 			if (errno != ENOMEM || len != bufsize)
791c5a2d8c5SRyan Moeller 				err(1, "cap_sysctlbyname()");
792ca007d91SDag-Erling Smørgrav 			bufsize *= 2;
793ca007d91SDag-Erling Smørgrav 		}
794ca007d91SDag-Erling Smørgrav 		xug = (struct xunpgen *)buf;
7956dbe8d53SRobert Drehmel 		exug = (struct xunpgen *)(void *)
796b8e20e2dSHiroki Sato 		    ((char *)buf + len - sizeof(*exug));
797b8e20e2dSHiroki Sato 		if (xug->xug_len != sizeof(*xug) ||
798b8e20e2dSHiroki Sato 		    exug->xug_len != sizeof(*exug)) {
799ca007d91SDag-Erling Smørgrav 			warnx("struct xinpgen size mismatch");
800ca007d91SDag-Erling Smørgrav 			goto out;
801ca007d91SDag-Erling Smørgrav 		}
802ca007d91SDag-Erling Smørgrav 	} while (xug->xug_gen != exug->xug_gen && retry--);
803ca007d91SDag-Erling Smørgrav 
804ca007d91SDag-Erling Smørgrav 	if (xug->xug_gen != exug->xug_gen && opt_v)
805ca007d91SDag-Erling Smørgrav 		warnx("warning: data may be inconsistent");
806ca007d91SDag-Erling Smørgrav 
807ca007d91SDag-Erling Smørgrav 	for (;;) {
8086dbe8d53SRobert Drehmel 		xug = (struct xunpgen *)(void *)((char *)xug + xug->xug_len);
809ca007d91SDag-Erling Smørgrav 		if (xug >= exug)
810ca007d91SDag-Erling Smørgrav 			break;
811ca007d91SDag-Erling Smørgrav 		xup = (struct xunpcb *)xug;
812b8e20e2dSHiroki Sato 		if (xup->xu_len != sizeof(*xup)) {
813ca007d91SDag-Erling Smørgrav 			warnx("struct xunpcb size mismatch");
814ca007d91SDag-Erling Smørgrav 			goto out;
815ca007d91SDag-Erling Smørgrav 		}
816f38b68aeSBrooks Davis 		if ((xup->unp_conn == 0 && !opt_l) ||
817f38b68aeSBrooks Davis 		    (xup->unp_conn != 0 && !opt_c))
8181e6690e5SDag-Erling Smørgrav 			continue;
819b8e20e2dSHiroki Sato 		if ((sock = calloc(1, sizeof(*sock))) == NULL)
820ca007d91SDag-Erling Smørgrav 			err(1, "malloc()");
821e6f718c7SMichael Tuexen 		if ((laddr = calloc(1, sizeof *laddr)) == NULL)
822e6f718c7SMichael Tuexen 			err(1, "malloc()");
823e6f718c7SMichael Tuexen 		if ((faddr = calloc(1, sizeof *faddr)) == NULL)
824e6f718c7SMichael Tuexen 			err(1, "malloc()");
825ca007d91SDag-Erling Smørgrav 		sock->socket = xup->xu_socket.xso_so;
826ca007d91SDag-Erling Smørgrav 		sock->pcb = xup->xu_unpp;
827ca007d91SDag-Erling Smørgrav 		sock->proto = proto;
828ca007d91SDag-Erling Smørgrav 		sock->family = AF_UNIX;
829ca007d91SDag-Erling Smørgrav 		sock->protoname = protoname;
8300e229f34SGleb Smirnoff 		if (xup->xu_addr.sun_family == AF_UNIX)
831e6f718c7SMichael Tuexen 			laddr->address =
8326dbe8d53SRobert Drehmel 			    *(struct sockaddr_storage *)(void *)&xup->xu_addr;
833f38b68aeSBrooks Davis 		else if (xup->unp_conn != 0)
834f38b68aeSBrooks Davis 			*(kvaddr_t*)&(faddr->address) = xup->unp_conn;
835e6f718c7SMichael Tuexen 		laddr->next = NULL;
836e6f718c7SMichael Tuexen 		faddr->next = NULL;
837e6f718c7SMichael Tuexen 		sock->laddr = laddr;
838e6f718c7SMichael Tuexen 		sock->faddr = faddr;
839ca007d91SDag-Erling Smørgrav 		hash = (int)((uintptr_t)sock->socket % HASHSIZE);
840ca007d91SDag-Erling Smørgrav 		sock->next = sockhash[hash];
841ca007d91SDag-Erling Smørgrav 		sockhash[hash] = sock;
842ca007d91SDag-Erling Smørgrav 	}
843ca007d91SDag-Erling Smørgrav out:
844ca007d91SDag-Erling Smørgrav 	free(buf);
845ca007d91SDag-Erling Smørgrav }
846ca007d91SDag-Erling Smørgrav 
847ca007d91SDag-Erling Smørgrav static void
848ca007d91SDag-Erling Smørgrav getfiles(void)
849ca007d91SDag-Erling Smørgrav {
850003e7e49SMikolaj Golub 	size_t len, olen;
851ca007d91SDag-Erling Smørgrav 
852b8e20e2dSHiroki Sato 	olen = len = sizeof(*xfiles);
853003e7e49SMikolaj Golub 	if ((xfiles = malloc(len)) == NULL)
854ca007d91SDag-Erling Smørgrav 		err(1, "malloc()");
855c5a2d8c5SRyan Moeller 	while (cap_sysctlbyname(capsysctl, "kern.file", xfiles, &len, 0, 0)
856c5a2d8c5SRyan Moeller 	    == -1) {
857003e7e49SMikolaj Golub 		if (errno != ENOMEM || len != olen)
858c5a2d8c5SRyan Moeller 			err(1, "cap_sysctlbyname()");
859003e7e49SMikolaj Golub 		olen = len *= 2;
860ca007d91SDag-Erling Smørgrav 		if ((xfiles = realloc(xfiles, len)) == NULL)
861ca007d91SDag-Erling Smørgrav 			err(1, "realloc()");
862ca007d91SDag-Erling Smørgrav 	}
863b8e20e2dSHiroki Sato 	if (len > 0 && xfiles->xf_size != sizeof(*xfiles))
864ca007d91SDag-Erling Smørgrav 		errx(1, "struct xfile size mismatch");
865b8e20e2dSHiroki Sato 	nxfiles = len / sizeof(*xfiles);
866ca007d91SDag-Erling Smørgrav }
867ca007d91SDag-Erling Smørgrav 
868ca007d91SDag-Erling Smørgrav static int
869baa7f281SMichael Tuexen printaddr(struct sockaddr_storage *ss)
870ca007d91SDag-Erling Smørgrav {
871ca007d91SDag-Erling Smørgrav 	struct sockaddr_un *sun;
872b8e20e2dSHiroki Sato 	char addrstr[NI_MAXHOST] = { '\0', '\0' };
873b8e20e2dSHiroki Sato 	int error, off, port = 0;
874ca007d91SDag-Erling Smørgrav 
875baa7f281SMichael Tuexen 	switch (ss->ss_family) {
876ca007d91SDag-Erling Smørgrav 	case AF_INET:
877b8e20e2dSHiroki Sato 		if (inet_lnaof(sstosin(ss)->sin_addr) == INADDR_ANY)
878ca007d91SDag-Erling Smørgrav 			addrstr[0] = '*';
879b8e20e2dSHiroki Sato 		port = ntohs(sstosin(ss)->sin_port);
880ca007d91SDag-Erling Smørgrav 		break;
881ca007d91SDag-Erling Smørgrav 	case AF_INET6:
882b8e20e2dSHiroki Sato 		if (IN6_IS_ADDR_UNSPECIFIED(&sstosin6(ss)->sin6_addr))
883ca007d91SDag-Erling Smørgrav 			addrstr[0] = '*';
884b8e20e2dSHiroki Sato 		port = ntohs(sstosin6(ss)->sin6_port);
885ca007d91SDag-Erling Smørgrav 		break;
886ca007d91SDag-Erling Smørgrav 	case AF_UNIX:
887b8e20e2dSHiroki Sato 		sun = sstosun(ss);
888ca007d91SDag-Erling Smørgrav 		off = (int)((char *)&sun->sun_path - (char *)sun);
889ca007d91SDag-Erling Smørgrav 		return (xprintf("%.*s", sun->sun_len - off, sun->sun_path));
890ca007d91SDag-Erling Smørgrav 	}
891b8e20e2dSHiroki Sato 	if (addrstr[0] == '\0') {
892c5a2d8c5SRyan Moeller 		error = cap_getnameinfo(capnet, sstosa(ss), ss->ss_len,
893c5a2d8c5SRyan Moeller 		    addrstr, sizeof(addrstr), NULL, 0, NI_NUMERICHOST);
894b8e20e2dSHiroki Sato 		if (error)
895c5a2d8c5SRyan Moeller 			errx(1, "cap_getnameinfo()");
896b8e20e2dSHiroki Sato 	}
897ca007d91SDag-Erling Smørgrav 	if (port == 0)
898ca007d91SDag-Erling Smørgrav 		return xprintf("%s:*", addrstr);
899ca007d91SDag-Erling Smørgrav 	else
900ca007d91SDag-Erling Smørgrav 		return xprintf("%s:%d", addrstr, port);
901ca007d91SDag-Erling Smørgrav }
902ca007d91SDag-Erling Smørgrav 
903ca007d91SDag-Erling Smørgrav static const char *
904ca007d91SDag-Erling Smørgrav getprocname(pid_t pid)
905ca007d91SDag-Erling Smørgrav {
906ca007d91SDag-Erling Smørgrav 	static struct kinfo_proc proc;
907ca007d91SDag-Erling Smørgrav 	size_t len;
908ca007d91SDag-Erling Smørgrav 	int mib[4];
909ca007d91SDag-Erling Smørgrav 
910ca007d91SDag-Erling Smørgrav 	mib[0] = CTL_KERN;
911ca007d91SDag-Erling Smørgrav 	mib[1] = KERN_PROC;
912ca007d91SDag-Erling Smørgrav 	mib[2] = KERN_PROC_PID;
913ca007d91SDag-Erling Smørgrav 	mib[3] = (int)pid;
914b8e20e2dSHiroki Sato 	len = sizeof(proc);
915c5a2d8c5SRyan Moeller 	if (cap_sysctl(capsysctl, mib, nitems(mib), &proc, &len, NULL, 0)
916c5a2d8c5SRyan Moeller 	    == -1) {
91748c513e0SMaxim Konovalov 		/* Do not warn if the process exits before we get its name. */
91848c513e0SMaxim Konovalov 		if (errno != ESRCH)
919c5a2d8c5SRyan Moeller 			warn("cap_sysctl()");
920ca007d91SDag-Erling Smørgrav 		return ("??");
921ca007d91SDag-Erling Smørgrav 	}
922f487a6a8SEd Maste 	return (proc.ki_comm);
923ca007d91SDag-Erling Smørgrav }
924ca007d91SDag-Erling Smørgrav 
925ae94787dSMaxime Henrion static int
92600feaafdSAndrew Thompson getprocjid(pid_t pid)
92700feaafdSAndrew Thompson {
92800feaafdSAndrew Thompson 	static struct kinfo_proc proc;
92900feaafdSAndrew Thompson 	size_t len;
93000feaafdSAndrew Thompson 	int mib[4];
93100feaafdSAndrew Thompson 
93200feaafdSAndrew Thompson 	mib[0] = CTL_KERN;
93300feaafdSAndrew Thompson 	mib[1] = KERN_PROC;
93400feaafdSAndrew Thompson 	mib[2] = KERN_PROC_PID;
93500feaafdSAndrew Thompson 	mib[3] = (int)pid;
936b8e20e2dSHiroki Sato 	len = sizeof(proc);
937c5a2d8c5SRyan Moeller 	if (cap_sysctl(capsysctl, mib, nitems(mib), &proc, &len, NULL, 0)
938c5a2d8c5SRyan Moeller 	    == -1) {
93900feaafdSAndrew Thompson 		/* Do not warn if the process exits before we get its jid. */
94000feaafdSAndrew Thompson 		if (errno != ESRCH)
941c5a2d8c5SRyan Moeller 			warn("cap_sysctl()");
94200feaafdSAndrew Thompson 		return (-1);
94300feaafdSAndrew Thompson 	}
94400feaafdSAndrew Thompson 	return (proc.ki_jid);
94500feaafdSAndrew Thompson }
94600feaafdSAndrew Thompson 
94700feaafdSAndrew Thompson static int
948ae94787dSMaxime Henrion check_ports(struct sock *s)
949ae94787dSMaxime Henrion {
950ae94787dSMaxime Henrion 	int port;
951e6f718c7SMichael Tuexen 	struct addr *addr;
952ae94787dSMaxime Henrion 
953ae94787dSMaxime Henrion 	if (ports == NULL)
954ae94787dSMaxime Henrion 		return (1);
955ae94787dSMaxime Henrion 	if ((s->family != AF_INET) && (s->family != AF_INET6))
956ae94787dSMaxime Henrion 		return (1);
957e6f718c7SMichael Tuexen 	for (addr = s->laddr; addr != NULL; addr = addr->next) {
958b8e20e2dSHiroki Sato 		if (s->family == AF_INET)
959b8e20e2dSHiroki Sato 			port = ntohs(sstosin(&addr->address)->sin_port);
960ae94787dSMaxime Henrion 		else
961b8e20e2dSHiroki Sato 			port = ntohs(sstosin6(&addr->address)->sin6_port);
962ae94787dSMaxime Henrion 		if (CHK_PORT(port))
963ae94787dSMaxime Henrion 			return (1);
964e6f718c7SMichael Tuexen 	}
965e6f718c7SMichael Tuexen 	for (addr = s->faddr; addr != NULL; addr = addr->next) {
966b8e20e2dSHiroki Sato 		if (s->family == AF_INET)
967b8e20e2dSHiroki Sato 			port = ntohs(sstosin(&addr->address)->sin_port);
968ae94787dSMaxime Henrion 		else
969b8e20e2dSHiroki Sato 			port = ntohs(sstosin6(&addr->address)->sin6_port);
970ae94787dSMaxime Henrion 		if (CHK_PORT(port))
971ae94787dSMaxime Henrion 			return (1);
972e6f718c7SMichael Tuexen 	}
973ae94787dSMaxime Henrion 	return (0);
974ae94787dSMaxime Henrion }
975ae94787dSMaxime Henrion 
9766414db1bSMichael Tuexen static const char *
977e389705eSMichael Tuexen sctp_conn_state(int state)
9786414db1bSMichael Tuexen {
9796414db1bSMichael Tuexen 	switch (state) {
9806414db1bSMichael Tuexen 	case SCTP_CLOSED:
9816414db1bSMichael Tuexen 		return "CLOSED";
9826414db1bSMichael Tuexen 		break;
9836414db1bSMichael Tuexen 	case SCTP_BOUND:
9846414db1bSMichael Tuexen 		return "BOUND";
9856414db1bSMichael Tuexen 		break;
9866414db1bSMichael Tuexen 	case SCTP_LISTEN:
9876414db1bSMichael Tuexen 		return "LISTEN";
9886414db1bSMichael Tuexen 		break;
9896414db1bSMichael Tuexen 	case SCTP_COOKIE_WAIT:
9906414db1bSMichael Tuexen 		return "COOKIE_WAIT";
9916414db1bSMichael Tuexen 		break;
9926414db1bSMichael Tuexen 	case SCTP_COOKIE_ECHOED:
9936414db1bSMichael Tuexen 		return "COOKIE_ECHOED";
9946414db1bSMichael Tuexen 		break;
9956414db1bSMichael Tuexen 	case SCTP_ESTABLISHED:
9966414db1bSMichael Tuexen 		return "ESTABLISHED";
9976414db1bSMichael Tuexen 		break;
9986414db1bSMichael Tuexen 	case SCTP_SHUTDOWN_SENT:
9996414db1bSMichael Tuexen 		return "SHUTDOWN_SENT";
10006414db1bSMichael Tuexen 		break;
10016414db1bSMichael Tuexen 	case SCTP_SHUTDOWN_RECEIVED:
10026414db1bSMichael Tuexen 		return "SHUTDOWN_RECEIVED";
10036414db1bSMichael Tuexen 		break;
10046414db1bSMichael Tuexen 	case SCTP_SHUTDOWN_ACK_SENT:
10056414db1bSMichael Tuexen 		return "SHUTDOWN_ACK_SENT";
10066414db1bSMichael Tuexen 		break;
10076414db1bSMichael Tuexen 	case SCTP_SHUTDOWN_PENDING:
10086414db1bSMichael Tuexen 		return "SHUTDOWN_PENDING";
10096414db1bSMichael Tuexen 		break;
10106414db1bSMichael Tuexen 	default:
10116414db1bSMichael Tuexen 		return "UNKNOWN";
10126414db1bSMichael Tuexen 		break;
10136414db1bSMichael Tuexen 	}
10146414db1bSMichael Tuexen }
10156414db1bSMichael Tuexen 
1016e389705eSMichael Tuexen static const char *
1017e389705eSMichael Tuexen sctp_path_state(int state)
1018e389705eSMichael Tuexen {
1019e389705eSMichael Tuexen 	switch (state) {
1020e389705eSMichael Tuexen 	case SCTP_UNCONFIRMED:
1021e389705eSMichael Tuexen 		return "UNCONFIRMED";
1022e389705eSMichael Tuexen 		break;
1023e389705eSMichael Tuexen 	case SCTP_ACTIVE:
1024e389705eSMichael Tuexen 		return "ACTIVE";
1025e389705eSMichael Tuexen 		break;
1026e389705eSMichael Tuexen 	case SCTP_INACTIVE:
1027e389705eSMichael Tuexen 		return "INACTIVE";
1028e389705eSMichael Tuexen 		break;
1029e389705eSMichael Tuexen 	default:
1030e389705eSMichael Tuexen 		return "UNKNOWN";
1031e389705eSMichael Tuexen 		break;
1032e389705eSMichael Tuexen 	}
1033e389705eSMichael Tuexen }
1034e389705eSMichael Tuexen 
1035ca007d91SDag-Erling Smørgrav static void
103661149f8dSJilles Tjoelker displaysock(struct sock *s, int pos)
1037ca007d91SDag-Erling Smørgrav {
1038f38b68aeSBrooks Davis 	kvaddr_t p;
103949b836f2SMichael Tuexen 	int hash, first, offset;
1040e6f718c7SMichael Tuexen 	struct addr *laddr, *faddr;
104181091202SMichael Tuexen 	struct sock *s_tmp;
1042ca007d91SDag-Erling Smørgrav 
1043ca007d91SDag-Erling Smørgrav 	while (pos < 29)
1044ca007d91SDag-Erling Smørgrav 		pos += xprintf(" ");
1045ca007d91SDag-Erling Smørgrav 	pos += xprintf("%s", s->protoname);
1046ca007d91SDag-Erling Smørgrav 	if (s->vflag & INP_IPV4)
1047ca007d91SDag-Erling Smørgrav 		pos += xprintf("4");
1048ca007d91SDag-Erling Smørgrav 	if (s->vflag & INP_IPV6)
1049ca007d91SDag-Erling Smørgrav 		pos += xprintf("6");
1050edc9c7fcSMichael Tuexen 	if (s->vflag & (INP_IPV4 | INP_IPV6))
1051edc9c7fcSMichael Tuexen 		pos += xprintf(" ");
1052e6f718c7SMichael Tuexen 	laddr = s->laddr;
1053e6f718c7SMichael Tuexen 	faddr = s->faddr;
10544e13a5b0SMichael Tuexen 	first = 1;
1055e6f718c7SMichael Tuexen 	while (laddr != NULL || faddr != NULL) {
105683f60cb2SMichael Tuexen 		offset = 36;
105783f60cb2SMichael Tuexen 		while (pos < offset)
1058ca007d91SDag-Erling Smørgrav 			pos += xprintf(" ");
1059ca007d91SDag-Erling Smørgrav 		switch (s->family) {
1060ca007d91SDag-Erling Smørgrav 		case AF_INET:
1061ca007d91SDag-Erling Smørgrav 		case AF_INET6:
1062e6f718c7SMichael Tuexen 			if (laddr != NULL) {
1063e6f718c7SMichael Tuexen 				pos += printaddr(&laddr->address);
106409bbda21SMaxim Konovalov 				if (s->family == AF_INET6 && pos >= 58)
106509bbda21SMaxim Konovalov 					pos += xprintf(" ");
1066e6f718c7SMichael Tuexen 			}
106783f60cb2SMichael Tuexen 			offset += opt_w ? 46 : 22;
106883f60cb2SMichael Tuexen 			while (pos < offset)
1069ca007d91SDag-Erling Smørgrav 				pos += xprintf(" ");
1070e6f718c7SMichael Tuexen 			if (faddr != NULL)
1071e6f718c7SMichael Tuexen 				pos += printaddr(&faddr->address);
107283f60cb2SMichael Tuexen 			offset += opt_w ? 46 : 22;
1073ca007d91SDag-Erling Smørgrav 			break;
1074ca007d91SDag-Erling Smørgrav 		case AF_UNIX:
1075e6f718c7SMichael Tuexen 			if ((laddr == NULL) || (faddr == NULL))
1076e6f718c7SMichael Tuexen 				errx(1, "laddr = %p or faddr = %p is NULL",
1077e6f718c7SMichael Tuexen 				    (void *)laddr, (void *)faddr);
1078ca007d91SDag-Erling Smørgrav 			/* server */
1079e6f718c7SMichael Tuexen 			if (laddr->address.ss_len > 0) {
1080e6f718c7SMichael Tuexen 				pos += printaddr(&laddr->address);
1081ca007d91SDag-Erling Smørgrav 				break;
1082ca007d91SDag-Erling Smørgrav 			}
1083ca007d91SDag-Erling Smørgrav 			/* client */
1084f38b68aeSBrooks Davis 			p = *(kvaddr_t*)&(faddr->address);
1085f38b68aeSBrooks Davis 			if (p == 0) {
1086b4eb37c6SJohn-Mark Gurney 				pos += xprintf("(not connected)");
108783f60cb2SMichael Tuexen 				offset += opt_w ? 92 : 44;
1088b4eb37c6SJohn-Mark Gurney 				break;
1089b4eb37c6SJohn-Mark Gurney 			}
1090b4eb37c6SJohn-Mark Gurney 			pos += xprintf("-> ");
1091ca007d91SDag-Erling Smørgrav 			for (hash = 0; hash < HASHSIZE; ++hash) {
109281091202SMichael Tuexen 				for (s_tmp = sockhash[hash];
109381091202SMichael Tuexen 				    s_tmp != NULL;
109481091202SMichael Tuexen 				    s_tmp = s_tmp->next)
109581091202SMichael Tuexen 					if (s_tmp->pcb == p)
1096ca007d91SDag-Erling Smørgrav 						break;
109781091202SMichael Tuexen 				if (s_tmp != NULL)
1098ca007d91SDag-Erling Smørgrav 					break;
1099ca007d91SDag-Erling Smørgrav 			}
110027569d01SRenato Botelho 			if (s_tmp == NULL || s_tmp->laddr == NULL ||
110181091202SMichael Tuexen 			    s_tmp->laddr->address.ss_len == 0)
1102ca007d91SDag-Erling Smørgrav 				pos += xprintf("??");
1103ca007d91SDag-Erling Smørgrav 			else
110481091202SMichael Tuexen 				pos += printaddr(&s_tmp->laddr->address);
110583f60cb2SMichael Tuexen 			offset += opt_w ? 92 : 44;
1106ca007d91SDag-Erling Smørgrav 			break;
1107ca007d91SDag-Erling Smørgrav 		default:
1108ca007d91SDag-Erling Smørgrav 			abort();
1109ca007d91SDag-Erling Smørgrav 		}
111049b836f2SMichael Tuexen 		if (opt_U) {
111149b836f2SMichael Tuexen 			if (faddr != NULL &&
11129e644c23SMichael Tuexen 			    ((s->proto == IPPROTO_SCTP &&
111349b836f2SMichael Tuexen 			      s->state != SCTP_CLOSED &&
111449b836f2SMichael Tuexen 			      s->state != SCTP_BOUND &&
11159e644c23SMichael Tuexen 			      s->state != SCTP_LISTEN) ||
11169e644c23SMichael Tuexen 			     (s->proto == IPPROTO_TCP &&
11179e644c23SMichael Tuexen 			      s->state != TCPS_CLOSED &&
11189e644c23SMichael Tuexen 			      s->state != TCPS_LISTEN))) {
111949b836f2SMichael Tuexen 				while (pos < offset)
112049b836f2SMichael Tuexen 					pos += xprintf(" ");
112149b836f2SMichael Tuexen 				pos += xprintf("%u",
112249b836f2SMichael Tuexen 				    ntohs(faddr->encaps_port));
112349b836f2SMichael Tuexen 			}
112449b836f2SMichael Tuexen 			offset += 7;
112549b836f2SMichael Tuexen 		}
1126e389705eSMichael Tuexen 		if (opt_s) {
1127e389705eSMichael Tuexen 			if (faddr != NULL &&
1128e389705eSMichael Tuexen 			    s->proto == IPPROTO_SCTP &&
1129e389705eSMichael Tuexen 			    s->state != SCTP_CLOSED &&
1130e389705eSMichael Tuexen 			    s->state != SCTP_BOUND &&
1131e389705eSMichael Tuexen 			    s->state != SCTP_LISTEN) {
1132e389705eSMichael Tuexen 				while (pos < offset)
1133e389705eSMichael Tuexen 					pos += xprintf(" ");
1134e389705eSMichael Tuexen 				pos += xprintf("%s",
1135e389705eSMichael Tuexen 				    sctp_path_state(faddr->state));
1136e389705eSMichael Tuexen 			}
1137e389705eSMichael Tuexen 			offset += 13;
1138e389705eSMichael Tuexen 		}
1139e5cccc35SMichael Tuexen 		if (first) {
114049b836f2SMichael Tuexen 			if (opt_s) {
114149b836f2SMichael Tuexen 				if (s->proto == IPPROTO_SCTP ||
114249b836f2SMichael Tuexen 				    s->proto == IPPROTO_TCP) {
114349b836f2SMichael Tuexen 					while (pos < offset)
11444e13a5b0SMichael Tuexen 						pos += xprintf(" ");
11456414db1bSMichael Tuexen 					switch (s->proto) {
11466414db1bSMichael Tuexen 					case IPPROTO_SCTP:
1147e5cccc35SMichael Tuexen 						pos += xprintf("%s",
1148e389705eSMichael Tuexen 						    sctp_conn_state(s->state));
11496414db1bSMichael Tuexen 						break;
11506414db1bSMichael Tuexen 					case IPPROTO_TCP:
1151e5cccc35SMichael Tuexen 						if (s->state >= 0 &&
1152e5cccc35SMichael Tuexen 						    s->state < TCP_NSTATES)
115349b836f2SMichael Tuexen 							pos += xprintf("%s",
1154e5cccc35SMichael Tuexen 							    tcpstates[s->state]);
11554e13a5b0SMichael Tuexen 						else
11564e13a5b0SMichael Tuexen 							pos += xprintf("?");
11576414db1bSMichael Tuexen 						break;
11586414db1bSMichael Tuexen 					}
11594e13a5b0SMichael Tuexen 				}
116049b836f2SMichael Tuexen 				offset += 13;
116149b836f2SMichael Tuexen 			}
11622ac089d0SMichael Tuexen 			if (opt_S) {
11632ac089d0SMichael Tuexen 				if (s->proto == IPPROTO_TCP) {
116449b836f2SMichael Tuexen 					while (pos < offset)
1165e5cccc35SMichael Tuexen 						pos += xprintf(" ");
11662ac089d0SMichael Tuexen 					pos += xprintf("%.*s",
11672ac089d0SMichael Tuexen 					    TCP_FUNCTION_NAME_LEN_MAX,
1168e5cccc35SMichael Tuexen 					    s->stack);
1169e5cccc35SMichael Tuexen 				}
11702ac089d0SMichael Tuexen 				offset += TCP_FUNCTION_NAME_LEN_MAX + 1;
11712ac089d0SMichael Tuexen 			}
11722ac089d0SMichael Tuexen 			if (opt_C) {
11732ac089d0SMichael Tuexen 				if (s->proto == IPPROTO_TCP) {
11742ac089d0SMichael Tuexen 					while (pos < offset)
11752ac089d0SMichael Tuexen 						pos += xprintf(" ");
11762ac089d0SMichael Tuexen 					xprintf("%.*s", TCP_CA_NAME_MAX, s->cc);
11772ac089d0SMichael Tuexen 				}
11782ac089d0SMichael Tuexen 				offset += TCP_CA_NAME_MAX + 1;
11792ac089d0SMichael Tuexen 			}
1180e5cccc35SMichael Tuexen 		}
1181e6f718c7SMichael Tuexen 		if (laddr != NULL)
1182e6f718c7SMichael Tuexen 			laddr = laddr->next;
1183e6f718c7SMichael Tuexen 		if (faddr != NULL)
1184e6f718c7SMichael Tuexen 			faddr = faddr->next;
1185e6f718c7SMichael Tuexen 		if ((laddr != NULL) || (faddr != NULL)) {
1186e6f718c7SMichael Tuexen 			xprintf("\n");
1187e6f718c7SMichael Tuexen 			pos = 0;
1188e6f718c7SMichael Tuexen 		}
11894e13a5b0SMichael Tuexen 		first = 0;
1190e6f718c7SMichael Tuexen 	}
11914e13a5b0SMichael Tuexen 	xprintf("\n");
1192ca007d91SDag-Erling Smørgrav }
119361149f8dSJilles Tjoelker 
119461149f8dSJilles Tjoelker static void
119561149f8dSJilles Tjoelker display(void)
119661149f8dSJilles Tjoelker {
119761149f8dSJilles Tjoelker 	struct passwd *pwd;
119861149f8dSJilles Tjoelker 	struct xfile *xf;
119961149f8dSJilles Tjoelker 	struct sock *s;
120061149f8dSJilles Tjoelker 	int hash, n, pos;
120161149f8dSJilles Tjoelker 
1202ee0afaa9SEmmanuel Vadot 	if (opt_q != 1) {
120383f60cb2SMichael Tuexen 		printf("%-8s %-10s %-5s %-2s %-6s %-*s %-*s",
120461149f8dSJilles Tjoelker 		    "USER", "COMMAND", "PID", "FD", "PROTO",
120583f60cb2SMichael Tuexen 		    opt_w ? 45 : 21, "LOCAL ADDRESS",
120683f60cb2SMichael Tuexen 		    opt_w ? 45 : 21, "FOREIGN ADDRESS");
120749b836f2SMichael Tuexen 		if (opt_U)
120849b836f2SMichael Tuexen 			printf(" %-6s", "ENCAPS");
1209e389705eSMichael Tuexen 		if (opt_s) {
1210e389705eSMichael Tuexen 			printf(" %-12s", "PATH STATE");
1211e389705eSMichael Tuexen 			printf(" %-12s", "CONN STATE");
1212e389705eSMichael Tuexen 		}
1213e5cccc35SMichael Tuexen 		if (opt_S)
12142ac089d0SMichael Tuexen 			printf(" %-*.*s", TCP_FUNCTION_NAME_LEN_MAX,
12152ac089d0SMichael Tuexen 			    TCP_FUNCTION_NAME_LEN_MAX, "STACK");
12162ac089d0SMichael Tuexen 		if (opt_C)
12172ac089d0SMichael Tuexen 			printf(" %-.*s", TCP_CA_NAME_MAX, "CC");
12187a5642b3SDag-Erling Smørgrav 		printf("\n");
1219ee0afaa9SEmmanuel Vadot 	}
12207ad30f58SMariusz Zaborski 	cap_setpassent(cappwd, 1);
122161149f8dSJilles Tjoelker 	for (xf = xfiles, n = 0; n < nxfiles; ++n, ++xf) {
1222f38b68aeSBrooks Davis 		if (xf->xf_data == 0)
122361149f8dSJilles Tjoelker 			continue;
122400feaafdSAndrew Thompson 		if (opt_j >= 0 && opt_j != getprocjid(xf->xf_pid))
122500feaafdSAndrew Thompson 			continue;
122661149f8dSJilles Tjoelker 		hash = (int)((uintptr_t)xf->xf_data % HASHSIZE);
12277e80c6b0SMichael Tuexen 		for (s = sockhash[hash]; s != NULL; s = s->next) {
1228f38b68aeSBrooks Davis 			if (s->socket != xf->xf_data)
122961149f8dSJilles Tjoelker 				continue;
123061149f8dSJilles Tjoelker 			if (!check_ports(s))
123161149f8dSJilles Tjoelker 				continue;
123261149f8dSJilles Tjoelker 			s->shown = 1;
123361149f8dSJilles Tjoelker 			pos = 0;
12347ad30f58SMariusz Zaborski 			if (opt_n ||
12357ad30f58SMariusz Zaborski 			    (pwd = cap_getpwuid(cappwd, xf->xf_uid)) == NULL)
123661149f8dSJilles Tjoelker 				pos += xprintf("%lu ", (u_long)xf->xf_uid);
123761149f8dSJilles Tjoelker 			else
123861149f8dSJilles Tjoelker 				pos += xprintf("%s ", pwd->pw_name);
123961149f8dSJilles Tjoelker 			while (pos < 9)
124061149f8dSJilles Tjoelker 				pos += xprintf(" ");
124161149f8dSJilles Tjoelker 			pos += xprintf("%.10s", getprocname(xf->xf_pid));
124261149f8dSJilles Tjoelker 			while (pos < 20)
124361149f8dSJilles Tjoelker 				pos += xprintf(" ");
124461149f8dSJilles Tjoelker 			pos += xprintf("%lu ", (u_long)xf->xf_pid);
124561149f8dSJilles Tjoelker 			while (pos < 26)
124661149f8dSJilles Tjoelker 				pos += xprintf(" ");
124761149f8dSJilles Tjoelker 			pos += xprintf("%d ", xf->xf_fd);
124861149f8dSJilles Tjoelker 			displaysock(s, pos);
124961149f8dSJilles Tjoelker 		}
12507e80c6b0SMichael Tuexen 	}
125100feaafdSAndrew Thompson 	if (opt_j >= 0)
125200feaafdSAndrew Thompson 		return;
125361149f8dSJilles Tjoelker 	for (hash = 0; hash < HASHSIZE; hash++) {
125461149f8dSJilles Tjoelker 		for (s = sockhash[hash]; s != NULL; s = s->next) {
125561149f8dSJilles Tjoelker 			if (s->shown)
125661149f8dSJilles Tjoelker 				continue;
125761149f8dSJilles Tjoelker 			if (!check_ports(s))
125861149f8dSJilles Tjoelker 				continue;
125961149f8dSJilles Tjoelker 			pos = 0;
126061149f8dSJilles Tjoelker 			pos += xprintf("%-8s %-10s %-5s %-2s ",
126161149f8dSJilles Tjoelker 			    "?", "?", "?", "?");
126261149f8dSJilles Tjoelker 			displaysock(s, pos);
126361149f8dSJilles Tjoelker 		}
126461149f8dSJilles Tjoelker 	}
1265ca007d91SDag-Erling Smørgrav }
1266ca007d91SDag-Erling Smørgrav 
1267f1cd4902SRyan Moeller static int
1268f1cd4902SRyan Moeller set_default_protos(void)
12691f3d67aaSGiorgos Keramidas {
12701f3d67aaSGiorgos Keramidas 	struct protoent *prot;
12711f3d67aaSGiorgos Keramidas 	const char *pname;
12721f3d67aaSGiorgos Keramidas 	size_t pindex;
12731f3d67aaSGiorgos Keramidas 
12741f3d67aaSGiorgos Keramidas 	init_protos(default_numprotos);
12751f3d67aaSGiorgos Keramidas 
12761f3d67aaSGiorgos Keramidas 	for (pindex = 0; pindex < default_numprotos; pindex++) {
12771f3d67aaSGiorgos Keramidas 		pname = default_protos[pindex];
1278c5a2d8c5SRyan Moeller 		prot = cap_getprotobyname(capnetdb, pname);
12791f3d67aaSGiorgos Keramidas 		if (prot == NULL)
1280c5a2d8c5SRyan Moeller 			err(1, "cap_getprotobyname: %s", pname);
12811f3d67aaSGiorgos Keramidas 		protos[pindex] = prot->p_proto;
12821f3d67aaSGiorgos Keramidas 	}
12831f3d67aaSGiorgos Keramidas 	numprotos = pindex;
12841f3d67aaSGiorgos Keramidas 	return (pindex);
12851f3d67aaSGiorgos Keramidas }
12861f3d67aaSGiorgos Keramidas 
1287f1cd4902SRyan Moeller /*
1288f1cd4902SRyan Moeller  * Return the vnet property of the jail, or -1 on error.
1289f1cd4902SRyan Moeller  */
1290f1cd4902SRyan Moeller static int
1291f1cd4902SRyan Moeller jail_getvnet(int jid)
1292f1cd4902SRyan Moeller {
1293f1cd4902SRyan Moeller 	struct iovec jiov[6];
1294f1cd4902SRyan Moeller 	int vnet;
1295f1cd4902SRyan Moeller 
1296f1cd4902SRyan Moeller 	vnet = -1;
1297f1cd4902SRyan Moeller 	jiov[0].iov_base = __DECONST(char *, "jid");
1298f1cd4902SRyan Moeller 	jiov[0].iov_len = sizeof("jid");
1299f1cd4902SRyan Moeller 	jiov[1].iov_base = &jid;
1300f1cd4902SRyan Moeller 	jiov[1].iov_len = sizeof(jid);
1301f1cd4902SRyan Moeller 	jiov[2].iov_base = __DECONST(char *, "vnet");
1302f1cd4902SRyan Moeller 	jiov[2].iov_len = sizeof("vnet");
1303f1cd4902SRyan Moeller 	jiov[3].iov_base = &vnet;
1304f1cd4902SRyan Moeller 	jiov[3].iov_len = sizeof(vnet);
1305f1cd4902SRyan Moeller 	jiov[4].iov_base = __DECONST(char *, "errmsg");
1306f1cd4902SRyan Moeller 	jiov[4].iov_len = sizeof("errmsg");
1307f1cd4902SRyan Moeller 	jiov[5].iov_base = jail_errmsg;
1308f1cd4902SRyan Moeller 	jiov[5].iov_len = JAIL_ERRMSGLEN;
1309f1cd4902SRyan Moeller 	jail_errmsg[0] = '\0';
1310f1cd4902SRyan Moeller 	if (jail_get(jiov, nitems(jiov), 0) < 0) {
1311f1cd4902SRyan Moeller 		if (!jail_errmsg[0])
1312f1cd4902SRyan Moeller 			snprintf(jail_errmsg, JAIL_ERRMSGLEN,
1313f1cd4902SRyan Moeller 			    "jail_get: %s", strerror(errno));
1314f1cd4902SRyan Moeller 		return (-1);
1315f1cd4902SRyan Moeller 	}
1316f1cd4902SRyan Moeller 	return (vnet);
1317f1cd4902SRyan Moeller }
1318f1cd4902SRyan Moeller 
1319ca007d91SDag-Erling Smørgrav static void
1320ca007d91SDag-Erling Smørgrav usage(void)
1321ca007d91SDag-Erling Smørgrav {
13221f3d67aaSGiorgos Keramidas 	fprintf(stderr,
132383f60cb2SMichael Tuexen 	    "usage: sockstat [-46cLlSsUuvw] [-j jid] [-p ports] [-P protocols]\n");
1324ca007d91SDag-Erling Smørgrav 	exit(1);
1325ca007d91SDag-Erling Smørgrav }
1326ca007d91SDag-Erling Smørgrav 
1327ca007d91SDag-Erling Smørgrav int
1328ca007d91SDag-Erling Smørgrav main(int argc, char *argv[])
1329ca007d91SDag-Erling Smørgrav {
1330c5a2d8c5SRyan Moeller 	cap_channel_t *capcas;
1331c5a2d8c5SRyan Moeller 	cap_net_limit_t *limit;
13327ad30f58SMariusz Zaborski 	const char *pwdcmds[] = { "setpassent", "getpwuid" };
13337ad30f58SMariusz Zaborski 	const char *pwdfields[] = { "pw_name" };
13341f3d67aaSGiorgos Keramidas 	int protos_defined = -1;
13351f3d67aaSGiorgos Keramidas 	int o, i;
1336ca007d91SDag-Erling Smørgrav 
133700feaafdSAndrew Thompson 	opt_j = -1;
1338ccdd2b2bSAlexander Motin 	while ((o = getopt(argc, argv, "46Ccj:Llnp:P:qSsUuvw")) != -1)
1339ca007d91SDag-Erling Smørgrav 		switch (o) {
1340ca007d91SDag-Erling Smørgrav 		case '4':
1341ca007d91SDag-Erling Smørgrav 			opt_4 = 1;
1342ca007d91SDag-Erling Smørgrav 			break;
1343ca007d91SDag-Erling Smørgrav 		case '6':
1344ca007d91SDag-Erling Smørgrav 			opt_6 = 1;
1345ca007d91SDag-Erling Smørgrav 			break;
13462ac089d0SMichael Tuexen 		case 'C':
13472ac089d0SMichael Tuexen 			opt_C = 1;
13482ac089d0SMichael Tuexen 			break;
1349ca007d91SDag-Erling Smørgrav 		case 'c':
1350ca007d91SDag-Erling Smørgrav 			opt_c = 1;
1351ca007d91SDag-Erling Smørgrav 			break;
135200feaafdSAndrew Thompson 		case 'j':
1353de68a320SJamie Gritton 			opt_j = jail_getid(optarg);
1354de68a320SJamie Gritton 			if (opt_j < 0)
1355*32723a3bSGleb Smirnoff 				errx(1, "jail_getid: %s", jail_errmsg);
135600feaafdSAndrew Thompson 			break;
13579b6ca892SBruce M Simpson 		case 'L':
13589b6ca892SBruce M Simpson 			opt_L = 1;
13599b6ca892SBruce M Simpson 			break;
1360ca007d91SDag-Erling Smørgrav 		case 'l':
1361ca007d91SDag-Erling Smørgrav 			opt_l = 1;
1362ca007d91SDag-Erling Smørgrav 			break;
1363ccdd2b2bSAlexander Motin 		case 'n':
1364ccdd2b2bSAlexander Motin 			opt_n = 1;
1365ccdd2b2bSAlexander Motin 			break;
1366ca007d91SDag-Erling Smørgrav 		case 'p':
1367ca007d91SDag-Erling Smørgrav 			parse_ports(optarg);
1368ca007d91SDag-Erling Smørgrav 			break;
13691f3d67aaSGiorgos Keramidas 		case 'P':
13701f3d67aaSGiorgos Keramidas 			protos_defined = parse_protos(optarg);
13711f3d67aaSGiorgos Keramidas 			break;
1372ee0afaa9SEmmanuel Vadot 		case 'q':
1373ee0afaa9SEmmanuel Vadot 			opt_q = 1;
137462de7037SEmmanuel Vadot 			break;
1375e5cccc35SMichael Tuexen 		case 'S':
1376e5cccc35SMichael Tuexen 			opt_S = 1;
1377e5cccc35SMichael Tuexen 			break;
13787a5642b3SDag-Erling Smørgrav 		case 's':
13797a5642b3SDag-Erling Smørgrav 			opt_s = 1;
13807a5642b3SDag-Erling Smørgrav 			break;
138149b836f2SMichael Tuexen 		case 'U':
138249b836f2SMichael Tuexen 			opt_U = 1;
138349b836f2SMichael Tuexen 			break;
1384ca007d91SDag-Erling Smørgrav 		case 'u':
1385ca007d91SDag-Erling Smørgrav 			opt_u = 1;
1386ca007d91SDag-Erling Smørgrav 			break;
1387ca007d91SDag-Erling Smørgrav 		case 'v':
1388ca007d91SDag-Erling Smørgrav 			++opt_v;
1389ca007d91SDag-Erling Smørgrav 			break;
139083f60cb2SMichael Tuexen 		case 'w':
139183f60cb2SMichael Tuexen 			opt_w = 1;
139283f60cb2SMichael Tuexen 			break;
1393ca007d91SDag-Erling Smørgrav 		default:
1394ca007d91SDag-Erling Smørgrav 			usage();
1395ca007d91SDag-Erling Smørgrav 		}
1396ca007d91SDag-Erling Smørgrav 
1397ca007d91SDag-Erling Smørgrav 	argc -= optind;
1398ca007d91SDag-Erling Smørgrav 	argv += optind;
1399ca007d91SDag-Erling Smørgrav 
1400ca007d91SDag-Erling Smørgrav 	if (argc > 0)
1401ca007d91SDag-Erling Smørgrav 		usage();
1402ca007d91SDag-Erling Smørgrav 
1403f1cd4902SRyan Moeller 	if (opt_j > 0) {
1404f1cd4902SRyan Moeller 		switch (jail_getvnet(opt_j)) {
1405f1cd4902SRyan Moeller 		case -1:
1406*32723a3bSGleb Smirnoff 			errx(2, "jail_getvnet: %s", jail_errmsg);
1407f1cd4902SRyan Moeller 		case JAIL_SYS_NEW:
1408f1cd4902SRyan Moeller 			if (jail_attach(opt_j) < 0)
1409ae37905bSRyan Moeller 				err(3, "jail_attach()");
1410f1cd4902SRyan Moeller 			/* Set back to -1 for normal output in vnet jail. */
1411f1cd4902SRyan Moeller 			opt_j = -1;
1412f1cd4902SRyan Moeller 			break;
1413f1cd4902SRyan Moeller 		default:
1414f1cd4902SRyan Moeller 			break;
1415f1cd4902SRyan Moeller 		}
1416f1cd4902SRyan Moeller 	}
1417f1cd4902SRyan Moeller 
1418c5a2d8c5SRyan Moeller 	capcas = cap_init();
1419c5a2d8c5SRyan Moeller 	if (capcas == NULL)
1420c5a2d8c5SRyan Moeller 		err(1, "Unable to contact Casper");
1421c5a2d8c5SRyan Moeller 	if (caph_enter_casper() < 0)
1422c5a2d8c5SRyan Moeller 		err(1, "Unable to enter capability mode");
1423c5a2d8c5SRyan Moeller 	capnet = cap_service_open(capcas, "system.net");
1424c5a2d8c5SRyan Moeller 	if (capnet == NULL)
1425c5a2d8c5SRyan Moeller 		err(1, "Unable to open system.net service");
1426c5a2d8c5SRyan Moeller 	capnetdb = cap_service_open(capcas, "system.netdb");
1427c5a2d8c5SRyan Moeller 	if (capnetdb == NULL)
1428c5a2d8c5SRyan Moeller 		err(1, "Unable to open system.netdb service");
1429c5a2d8c5SRyan Moeller 	capsysctl = cap_service_open(capcas, "system.sysctl");
1430c5a2d8c5SRyan Moeller 	if (capsysctl == NULL)
1431c5a2d8c5SRyan Moeller 		err(1, "Unable to open system.sysctl service");
14327ad30f58SMariusz Zaborski 	cappwd = cap_service_open(capcas, "system.pwd");
14337ad30f58SMariusz Zaborski 	if (cappwd == NULL)
14347ad30f58SMariusz Zaborski 		err(1, "Unable to open system.pwd service");
1435c5a2d8c5SRyan Moeller 	cap_close(capcas);
1436c5a2d8c5SRyan Moeller 	limit = cap_net_limit_init(capnet, CAPNET_ADDR2NAME);
1437c5a2d8c5SRyan Moeller 	if (limit == NULL)
1438c5a2d8c5SRyan Moeller 		err(1, "Unable to init cap_net limits");
1439c5a2d8c5SRyan Moeller 	if (cap_net_limit(limit) < 0)
1440c5a2d8c5SRyan Moeller 		err(1, "Unable to apply limits");
14417ad30f58SMariusz Zaborski 	if (cap_pwd_limit_cmds(cappwd, pwdcmds, nitems(pwdcmds)) < 0)
14427ad30f58SMariusz Zaborski 		err(1, "Unable to apply pwd commands limits");
14437ad30f58SMariusz Zaborski 	if (cap_pwd_limit_fields(cappwd, pwdfields, nitems(pwdfields)) < 0)
14447ad30f58SMariusz Zaborski 		err(1, "Unable to apply pwd commands limits");
1445c5a2d8c5SRyan Moeller 
1446d2d77d2aSGiorgos Keramidas 	if ((!opt_4 && !opt_6) && protos_defined != -1)
14471f3d67aaSGiorgos Keramidas 		opt_4 = opt_6 = 1;
1448d2d77d2aSGiorgos Keramidas 	if (!opt_4 && !opt_6 && !opt_u)
1449d2d77d2aSGiorgos Keramidas 		opt_4 = opt_6 = opt_u = 1;
1450d2d77d2aSGiorgos Keramidas 	if ((opt_4 || opt_6) && protos_defined == -1)
1451d2d77d2aSGiorgos Keramidas 		protos_defined = set_default_protos();
1452ca007d91SDag-Erling Smørgrav 	if (!opt_c && !opt_l)
1453ca007d91SDag-Erling Smørgrav 		opt_c = opt_l = 1;
1454ca007d91SDag-Erling Smørgrav 
1455ca007d91SDag-Erling Smørgrav 	if (opt_4 || opt_6) {
14561f3d67aaSGiorgos Keramidas 		for (i = 0; i < protos_defined; i++)
1457d5b4aa90SMichael Tuexen 			if (protos[i] == IPPROTO_SCTP)
1458d5b4aa90SMichael Tuexen 				gather_sctp();
1459d5b4aa90SMichael Tuexen 			else
14601f3d67aaSGiorgos Keramidas 				gather_inet(protos[i]);
1461ca007d91SDag-Erling Smørgrav 	}
14621f3d67aaSGiorgos Keramidas 
14631f3d67aaSGiorgos Keramidas 	if (opt_u || (protos_defined == -1 && !opt_4 && !opt_6)) {
1464ca007d91SDag-Erling Smørgrav 		gather_unix(SOCK_STREAM);
1465ca007d91SDag-Erling Smørgrav 		gather_unix(SOCK_DGRAM);
1466b8e20e2dSHiroki Sato 		gather_unix(SOCK_SEQPACKET);
1467ca007d91SDag-Erling Smørgrav 	}
1468ca007d91SDag-Erling Smørgrav 	getfiles();
1469ca007d91SDag-Erling Smørgrav 	display();
1470ca007d91SDag-Erling Smørgrav 	exit(0);
1471ca007d91SDag-Erling Smørgrav }
1472