1 /* 2 * CDDL HEADER START 3 * 4 * The contents of this file are subject to the terms of the 5 * Common Development and Distribution License (the "License"). 6 * You may not use this file except in compliance with the License. 7 * 8 * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 9 * or http://www.opensolaris.org/os/licensing. 10 * See the License for the specific language governing permissions 11 * and limitations under the License. 12 * 13 * When distributing Covered Code, include this CDDL HEADER in each 14 * file and include the License file at usr/src/OPENSOLARIS.LICENSE. 15 * If applicable, add the following below this CDDL HEADER, with the 16 * fields enclosed by brackets "[]" replaced with your own identifying 17 * information: Portions Copyright [yyyy] [name of copyright owner] 18 * 19 * CDDL HEADER END 20 */ 21 22 /* 23 * Copyright 2009 Sun Microsystems, Inc. All rights reserved. 24 * Use is subject to license terms. 25 */ 26 27 #include <sys/types.h> 28 #include <sys/stream.h> 29 #include <sys/strsubr.h> 30 #include <sys/stropts.h> 31 #include <sys/strsun.h> 32 #define _SUN_TPI_VERSION 2 33 #include <sys/tihdr.h> 34 #include <sys/ddi.h> 35 #include <sys/sunddi.h> 36 #include <sys/xti_inet.h> 37 #include <sys/cmn_err.h> 38 #include <sys/debug.h> 39 #include <sys/vtrace.h> 40 #include <sys/kmem.h> 41 #include <sys/cpuvar.h> 42 #include <sys/random.h> 43 #include <sys/priv.h> 44 #include <sys/sunldi.h> 45 46 #include <sys/errno.h> 47 #include <sys/signal.h> 48 #include <sys/socket.h> 49 #include <sys/isa_defs.h> 50 #include <netinet/in.h> 51 #include <netinet/tcp.h> 52 #include <netinet/ip6.h> 53 #include <netinet/icmp6.h> 54 #include <netinet/sctp.h> 55 #include <net/if.h> 56 57 #include <inet/common.h> 58 #include <inet/ip.h> 59 #include <inet/ip_if.h> 60 #include <inet/ip_ire.h> 61 #include <inet/ip6.h> 62 #include <inet/mi.h> 63 #include <inet/mib2.h> 64 #include <inet/kstatcom.h> 65 #include <inet/nd.h> 66 #include <inet/optcom.h> 67 #include <inet/ipclassifier.h> 68 #include <inet/ipsec_impl.h> 69 #include <inet/sctp_ip.h> 70 #include <inet/sctp_crc32.h> 71 72 #include "sctp_impl.h" 73 #include "sctp_addr.h" 74 #include "sctp_asconf.h" 75 76 int sctpdebug; 77 sin6_t sctp_sin6_null; /* Zero address for quick clears */ 78 79 static void sctp_closei_local(sctp_t *sctp); 80 static int sctp_init_values(sctp_t *, sctp_t *, int); 81 static void sctp_icmp_error_ipv6(sctp_t *sctp, mblk_t *mp); 82 static void sctp_process_recvq(void *); 83 static void sctp_rq_tq_init(sctp_stack_t *); 84 static void sctp_rq_tq_fini(sctp_stack_t *); 85 static void sctp_conn_cache_init(); 86 static void sctp_conn_cache_fini(); 87 static int sctp_conn_cache_constructor(); 88 static void sctp_conn_cache_destructor(); 89 static void sctp_conn_clear(conn_t *); 90 static void sctp_notify(void *, ip_xmit_attr_t *, ixa_notify_type_t, 91 ixa_notify_arg_t); 92 93 static void *sctp_stack_init(netstackid_t stackid, netstack_t *ns); 94 static void sctp_stack_fini(netstackid_t stackid, void *arg); 95 96 /* 97 * SCTP receive queue taskq 98 * 99 * At SCTP initialization time, a default taskq is created for 100 * servicing packets received when the interrupt thread cannot 101 * get a hold on the sctp_t. The number of taskq can be increased in 102 * sctp_find_next_tq() when an existing taskq cannot be dispatched. 103 * The taskqs are never removed. But the max number of taskq which 104 * can be created is controlled by sctp_recvq_tq_list_max_sz. Note 105 * that SCTP recvq taskq is not tied to any specific CPU or ill. 106 * 107 * Those taskqs are stored in an array recvq_tq_list. And they are 108 * used in a round robin fashion. The current taskq being used is 109 * determined by recvq_tq_list_cur. 110 */ 111 112 /* /etc/system variables */ 113 /* The minimum number of threads for each taskq. */ 114 int sctp_recvq_tq_thr_min = 4; 115 /* The maximum number of threads for each taskq. */ 116 int sctp_recvq_tq_thr_max = 16; 117 /* The minimum number of tasks for each taskq. */ 118 int sctp_recvq_tq_task_min = 5; 119 /* The maxiimum number of tasks for each taskq. */ 120 int sctp_recvq_tq_task_max = 50; 121 122 /* sctp_t/conn_t kmem cache */ 123 struct kmem_cache *sctp_conn_cache; 124 125 #define SCTP_CONDEMNED(sctp) \ 126 mutex_enter(&(sctp)->sctp_reflock); \ 127 ((sctp)->sctp_condemned = B_TRUE); \ 128 mutex_exit(&(sctp)->sctp_reflock); 129 130 /* Link/unlink a sctp_t to/from the global list. */ 131 #define SCTP_LINK(sctp, sctps) \ 132 mutex_enter(&(sctps)->sctps_g_lock); \ 133 list_insert_tail(&sctps->sctps_g_list, (sctp)); \ 134 mutex_exit(&(sctps)->sctps_g_lock); 135 136 #define SCTP_UNLINK(sctp, sctps) \ 137 mutex_enter(&(sctps)->sctps_g_lock); \ 138 ASSERT((sctp)->sctp_condemned); \ 139 list_remove(&(sctps)->sctps_g_list, (sctp)); \ 140 mutex_exit(&(sctps)->sctps_g_lock); 141 142 /* 143 * Hooks for Sun Cluster. On non-clustered nodes these will remain NULL. 144 * PSARC/2005/602. 145 */ 146 void (*cl_sctp_listen)(sa_family_t, uchar_t *, uint_t, in_port_t) = NULL; 147 void (*cl_sctp_unlisten)(sa_family_t, uchar_t *, uint_t, in_port_t) = NULL; 148 void (*cl_sctp_connect)(sa_family_t, uchar_t *, uint_t, in_port_t, 149 uchar_t *, uint_t, in_port_t, boolean_t, cl_sctp_handle_t) = NULL; 150 void (*cl_sctp_disconnect)(sa_family_t, cl_sctp_handle_t) = NULL; 151 void (*cl_sctp_assoc_change)(sa_family_t, uchar_t *, size_t, uint_t, 152 uchar_t *, size_t, uint_t, int, cl_sctp_handle_t) = NULL; 153 void (*cl_sctp_check_addrs)(sa_family_t, in_port_t, uchar_t **, size_t, 154 uint_t *, boolean_t) = NULL; 155 /* 156 * Return the version number of the SCTP kernel interface. 157 */ 158 int 159 sctp_itf_ver(int cl_ver) 160 { 161 if (cl_ver != SCTP_ITF_VER) 162 return (-1); 163 return (SCTP_ITF_VER); 164 } 165 166 /* 167 * Called when we need a new sctp instantiation but don't really have a 168 * new q to hang it off of. Copy the priv flag from the passed in structure. 169 */ 170 sctp_t * 171 sctp_create_eager(sctp_t *psctp) 172 { 173 sctp_t *sctp; 174 mblk_t *ack_mp, *hb_mp; 175 conn_t *connp; 176 cred_t *credp; 177 sctp_stack_t *sctps = psctp->sctp_sctps; 178 179 if ((connp = ipcl_conn_create(IPCL_SCTPCONN, KM_NOSLEEP, 180 sctps->sctps_netstack)) == NULL) { 181 return (NULL); 182 } 183 184 sctp = CONN2SCTP(connp); 185 sctp->sctp_sctps = sctps; 186 187 if ((ack_mp = sctp_timer_alloc(sctp, sctp_ack_timer, 188 KM_NOSLEEP)) == NULL || 189 (hb_mp = sctp_timer_alloc(sctp, sctp_heartbeat_timer, 190 KM_NOSLEEP)) == NULL) { 191 if (ack_mp != NULL) 192 freeb(ack_mp); 193 sctp_conn_clear(connp); 194 sctp->sctp_sctps = NULL; 195 kmem_cache_free(sctp_conn_cache, connp); 196 return (NULL); 197 } 198 199 sctp->sctp_ack_mp = ack_mp; 200 sctp->sctp_heartbeat_mp = hb_mp; 201 202 if (sctp_init_values(sctp, psctp, KM_NOSLEEP) != 0) { 203 freeb(ack_mp); 204 freeb(hb_mp); 205 sctp_conn_clear(connp); 206 sctp->sctp_sctps = NULL; 207 kmem_cache_free(sctp_conn_cache, connp); 208 return (NULL); 209 } 210 211 if ((credp = psctp->sctp_connp->conn_cred) != NULL) { 212 connp->conn_cred = credp; 213 crhold(credp); 214 } 215 216 sctp->sctp_mss = psctp->sctp_mss; 217 sctp->sctp_detached = B_TRUE; 218 /* 219 * Link to the global as soon as possible so that this sctp_t 220 * can be found. 221 */ 222 SCTP_LINK(sctp, sctps); 223 224 return (sctp); 225 } 226 227 /* 228 * We are dying for some reason. Try to do it gracefully. 229 */ 230 void 231 sctp_clean_death(sctp_t *sctp, int err) 232 { 233 ASSERT(sctp != NULL); 234 235 dprint(3, ("sctp_clean_death %p, state %d\n", (void *)sctp, 236 sctp->sctp_state)); 237 238 sctp->sctp_client_errno = err; 239 /* 240 * Check to see if we need to notify upper layer. 241 */ 242 if ((sctp->sctp_state >= SCTPS_COOKIE_WAIT) && 243 !SCTP_IS_DETACHED(sctp)) { 244 if (sctp->sctp_xmit_head || sctp->sctp_xmit_unsent) { 245 sctp_regift_xmitlist(sctp); 246 } 247 if (sctp->sctp_ulp_disconnected(sctp->sctp_ulpd, 0, err)) { 248 /* 249 * Socket is gone, detach. 250 */ 251 sctp->sctp_detached = B_TRUE; 252 sctp->sctp_ulpd = NULL; 253 sctp->sctp_upcalls = NULL; 254 } 255 } 256 257 /* Remove this sctp from all hashes. */ 258 sctp_closei_local(sctp); 259 260 /* 261 * If the sctp_t is detached, we need to finish freeing up 262 * the resources. At this point, ip_fanout_sctp() should have 263 * a hold on this sctp_t. Some thread doing snmp stuff can 264 * have a hold. And a taskq can also have a hold waiting to 265 * work. sctp_unlink() the sctp_t from the global list so 266 * that no new thread can find it. Then do a SCTP_REFRELE(). 267 * The sctp_t will be freed after all those threads are done. 268 */ 269 if (SCTP_IS_DETACHED(sctp)) { 270 SCTP_CONDEMNED(sctp); 271 SCTP_REFRELE(sctp); 272 } 273 } 274 275 /* 276 * Called by upper layer when it wants to close this association. 277 * Depending on the state of this assoication, we need to do 278 * different things. 279 * 280 * If the state is below COOKIE_ECHOED or it is COOKIE_ECHOED but with 281 * no sent data, just remove this sctp from all the hashes. This 282 * makes sure that all packets from the other end will go to the default 283 * sctp handling. The upper layer will then do a sctp_close() to clean 284 * up. 285 * 286 * Otherwise, check and see if SO_LINGER is set. If it is set, check 287 * the value. If the value is 0, consider this an abortive close. Send 288 * an ABORT message and kill the associatiion. 289 * 290 */ 291 int 292 sctp_disconnect(sctp_t *sctp) 293 { 294 int error = 0; 295 conn_t *connp = sctp->sctp_connp; 296 297 dprint(3, ("sctp_disconnect %p, state %d\n", (void *)sctp, 298 sctp->sctp_state)); 299 300 RUN_SCTP(sctp); 301 302 switch (sctp->sctp_state) { 303 case SCTPS_IDLE: 304 case SCTPS_BOUND: 305 case SCTPS_LISTEN: 306 break; 307 case SCTPS_COOKIE_WAIT: 308 case SCTPS_COOKIE_ECHOED: 309 /* 310 * Close during the connect 3-way handshake 311 * but here there may or may not be pending data 312 * already on queue. Process almost same as in 313 * the ESTABLISHED state. 314 */ 315 if (sctp->sctp_xmit_head == NULL && 316 sctp->sctp_xmit_unsent == NULL) { 317 break; 318 } 319 /* FALLTHRU */ 320 default: 321 /* 322 * If SO_LINGER has set a zero linger time, terminate the 323 * association and send an ABORT. 324 */ 325 if (connp->conn_linger && connp->conn_lingertime == 0) { 326 sctp_user_abort(sctp, NULL); 327 WAKE_SCTP(sctp); 328 return (error); 329 } 330 331 /* 332 * In there is unread data, send an ABORT and terminate the 333 * association. 334 */ 335 if (sctp->sctp_rxqueued > 0 || sctp->sctp_irwnd > 336 sctp->sctp_rwnd) { 337 sctp_user_abort(sctp, NULL); 338 WAKE_SCTP(sctp); 339 return (error); 340 } 341 /* 342 * Transmit the shutdown before detaching the sctp_t. 343 * After sctp_detach returns this queue/perimeter 344 * no longer owns the sctp_t thus others can modify it. 345 */ 346 sctp_send_shutdown(sctp, 0); 347 348 /* Pass gathered wisdom to IP for keeping */ 349 sctp_update_dce(sctp); 350 351 /* 352 * If lingering on close then wait until the shutdown 353 * is complete, or the SO_LINGER time passes, or an 354 * ABORT is sent/received. Note that sctp_disconnect() 355 * can be called more than once. Make sure that only 356 * one thread waits. 357 */ 358 if (connp->conn_linger && connp->conn_lingertime > 0 && 359 sctp->sctp_state >= SCTPS_ESTABLISHED && 360 !sctp->sctp_lingering) { 361 clock_t stoptime; /* in ticks */ 362 clock_t ret; 363 364 sctp->sctp_lingering = 1; 365 sctp->sctp_client_errno = 0; 366 stoptime = ddi_get_lbolt() + 367 connp->conn_lingertime * hz; 368 369 mutex_enter(&sctp->sctp_lock); 370 sctp->sctp_running = B_FALSE; 371 while (sctp->sctp_state >= SCTPS_ESTABLISHED && 372 sctp->sctp_client_errno == 0) { 373 cv_broadcast(&sctp->sctp_cv); 374 ret = cv_timedwait_sig(&sctp->sctp_cv, 375 &sctp->sctp_lock, stoptime); 376 if (ret < 0) { 377 /* Stoptime has reached. */ 378 sctp->sctp_client_errno = EWOULDBLOCK; 379 break; 380 } else if (ret == 0) { 381 /* Got a signal. */ 382 break; 383 } 384 } 385 error = sctp->sctp_client_errno; 386 sctp->sctp_client_errno = 0; 387 mutex_exit(&sctp->sctp_lock); 388 } 389 390 WAKE_SCTP(sctp); 391 return (error); 392 } 393 394 395 /* Remove this sctp from all hashes so nobody can find it. */ 396 sctp_closei_local(sctp); 397 WAKE_SCTP(sctp); 398 return (error); 399 } 400 401 void 402 sctp_close(sctp_t *sctp) 403 { 404 dprint(3, ("sctp_close %p, state %d\n", (void *)sctp, 405 sctp->sctp_state)); 406 407 RUN_SCTP(sctp); 408 sctp->sctp_detached = 1; 409 sctp->sctp_ulpd = NULL; 410 sctp->sctp_upcalls = NULL; 411 bzero(&sctp->sctp_events, sizeof (sctp->sctp_events)); 412 413 /* If the graceful shutdown has not been completed, just return. */ 414 if (sctp->sctp_state != SCTPS_IDLE) { 415 WAKE_SCTP(sctp); 416 return; 417 } 418 419 /* 420 * Since sctp_t is in SCTPS_IDLE state, so the only thread which 421 * can have a hold on the sctp_t is doing snmp stuff. Just do 422 * a SCTP_REFRELE() here after the SCTP_UNLINK(). It will 423 * be freed when the other thread is done. 424 */ 425 SCTP_CONDEMNED(sctp); 426 WAKE_SCTP(sctp); 427 SCTP_REFRELE(sctp); 428 } 429 430 /* 431 * Unlink from global list and do the eager close. 432 * Remove the refhold implicit in being on the global list. 433 */ 434 void 435 sctp_close_eager(sctp_t *sctp) 436 { 437 SCTP_CONDEMNED(sctp); 438 sctp_closei_local(sctp); 439 SCTP_REFRELE(sctp); 440 } 441 442 /* 443 * The sctp_t is going away. Remove it from all lists and set it 444 * to SCTPS_IDLE. The caller has to remove it from the 445 * global list. The freeing up of memory is deferred until 446 * sctp_free(). This is needed since a thread in sctp_input() might have 447 * done a SCTP_REFHOLD on this structure before it was removed from the 448 * hashes. 449 */ 450 static void 451 sctp_closei_local(sctp_t *sctp) 452 { 453 mblk_t *mp; 454 conn_t *connp = sctp->sctp_connp; 455 456 /* Sanity check, don't do the same thing twice. */ 457 if (connp->conn_state_flags & CONN_CLOSING) { 458 ASSERT(sctp->sctp_state == SCTPS_IDLE); 459 return; 460 } 461 462 /* Stop and free the timers */ 463 sctp_free_faddr_timers(sctp); 464 if ((mp = sctp->sctp_heartbeat_mp) != NULL) { 465 sctp_timer_free(mp); 466 sctp->sctp_heartbeat_mp = NULL; 467 } 468 if ((mp = sctp->sctp_ack_mp) != NULL) { 469 sctp_timer_free(mp); 470 sctp->sctp_ack_mp = NULL; 471 } 472 473 /* Set the CONN_CLOSING flag so that IP will not cache IRE again. */ 474 mutex_enter(&connp->conn_lock); 475 connp->conn_state_flags |= CONN_CLOSING; 476 mutex_exit(&connp->conn_lock); 477 478 /* Remove from all hashes. */ 479 sctp_bind_hash_remove(sctp); 480 sctp_conn_hash_remove(sctp); 481 sctp_listen_hash_remove(sctp); 482 sctp->sctp_state = SCTPS_IDLE; 483 484 /* 485 * Clean up the recvq as much as possible. All those packets 486 * will be silently dropped as this sctp_t is now in idle state. 487 */ 488 mutex_enter(&sctp->sctp_recvq_lock); 489 while ((mp = sctp->sctp_recvq) != NULL) { 490 sctp->sctp_recvq = mp->b_next; 491 mp->b_next = NULL; 492 493 if (ip_recv_attr_is_mblk(mp)) 494 mp = ip_recv_attr_free_mblk(mp); 495 496 freemsg(mp); 497 } 498 mutex_exit(&sctp->sctp_recvq_lock); 499 } 500 501 /* 502 * Free memory associated with the sctp/ip header template. 503 */ 504 static void 505 sctp_headers_free(sctp_t *sctp) 506 { 507 if (sctp->sctp_iphc != NULL) { 508 kmem_free(sctp->sctp_iphc, sctp->sctp_iphc_len); 509 sctp->sctp_iphc = NULL; 510 sctp->sctp_ipha = NULL; 511 sctp->sctp_hdr_len = 0; 512 sctp->sctp_ip_hdr_len = 0; 513 sctp->sctp_iphc_len = 0; 514 sctp->sctp_sctph = NULL; 515 sctp->sctp_hdr_len = 0; 516 } 517 if (sctp->sctp_iphc6 != NULL) { 518 kmem_free(sctp->sctp_iphc6, sctp->sctp_iphc6_len); 519 sctp->sctp_iphc6 = NULL; 520 sctp->sctp_ip6h = NULL; 521 sctp->sctp_hdr6_len = 0; 522 sctp->sctp_ip_hdr6_len = 0; 523 sctp->sctp_iphc6_len = 0; 524 sctp->sctp_sctph6 = NULL; 525 sctp->sctp_hdr6_len = 0; 526 } 527 } 528 529 static void 530 sctp_free_xmit_data(sctp_t *sctp) 531 { 532 mblk_t *ump = NULL; 533 mblk_t *nump; 534 mblk_t *mp; 535 mblk_t *nmp; 536 537 sctp->sctp_xmit_unacked = NULL; 538 ump = sctp->sctp_xmit_head; 539 sctp->sctp_xmit_tail = sctp->sctp_xmit_head = NULL; 540 free_unsent: 541 for (; ump != NULL; ump = nump) { 542 for (mp = ump->b_cont; mp != NULL; mp = nmp) { 543 nmp = mp->b_next; 544 mp->b_next = NULL; 545 mp->b_prev = NULL; 546 freemsg(mp); 547 } 548 ASSERT(DB_REF(ump) == 1); 549 nump = ump->b_next; 550 ump->b_next = NULL; 551 ump->b_prev = NULL; 552 ump->b_cont = NULL; 553 freeb(ump); 554 } 555 if ((ump = sctp->sctp_xmit_unsent) == NULL) { 556 ASSERT(sctp->sctp_xmit_unsent_tail == NULL); 557 return; 558 } 559 sctp->sctp_xmit_unsent = sctp->sctp_xmit_unsent_tail = NULL; 560 goto free_unsent; 561 } 562 563 /* 564 * Cleanup all the messages in the stream queue and the reassembly lists. 565 * If 'free' is true, then delete the streams as well. 566 */ 567 void 568 sctp_instream_cleanup(sctp_t *sctp, boolean_t free) 569 { 570 int i; 571 mblk_t *mp; 572 mblk_t *mp1; 573 574 if (sctp->sctp_instr != NULL) { 575 /* walk thru and flush out anything remaining in the Q */ 576 for (i = 0; i < sctp->sctp_num_istr; i++) { 577 mp = sctp->sctp_instr[i].istr_msgs; 578 while (mp != NULL) { 579 mp1 = mp->b_next; 580 mp->b_next = mp->b_prev = NULL; 581 freemsg(mp); 582 mp = mp1; 583 } 584 sctp->sctp_instr[i].istr_msgs = NULL; 585 sctp->sctp_instr[i].istr_nmsgs = 0; 586 sctp_free_reass((sctp->sctp_instr) + i); 587 sctp->sctp_instr[i].nextseq = 0; 588 } 589 if (free) { 590 kmem_free(sctp->sctp_instr, 591 sizeof (*sctp->sctp_instr) * sctp->sctp_num_istr); 592 sctp->sctp_instr = NULL; 593 sctp->sctp_num_istr = 0; 594 } 595 } 596 /* un-ordered fragments */ 597 if (sctp->sctp_uo_frags != NULL) { 598 for (mp = sctp->sctp_uo_frags; mp != NULL; mp = mp1) { 599 mp1 = mp->b_next; 600 mp->b_next = mp->b_prev = NULL; 601 freemsg(mp); 602 } 603 sctp->sctp_uo_frags = NULL; 604 } 605 } 606 607 /* 608 * Last reference to the sctp_t is gone. Free all memory associated with it. 609 * Called from SCTP_REFRELE. Called inline in sctp_close() 610 */ 611 void 612 sctp_free(conn_t *connp) 613 { 614 sctp_t *sctp = CONN2SCTP(connp); 615 int cnt; 616 sctp_stack_t *sctps = sctp->sctp_sctps; 617 618 ASSERT(sctps != NULL); 619 /* Unlink it from the global list */ 620 SCTP_UNLINK(sctp, sctps); 621 622 ASSERT(connp->conn_ref == 0); 623 ASSERT(connp->conn_proto == IPPROTO_SCTP); 624 ASSERT(!MUTEX_HELD(&sctp->sctp_reflock)); 625 ASSERT(sctp->sctp_refcnt == 0); 626 627 ASSERT(sctp->sctp_ptpbhn == NULL && sctp->sctp_bind_hash == NULL); 628 ASSERT(sctp->sctp_conn_hash_next == NULL && 629 sctp->sctp_conn_hash_prev == NULL); 630 631 632 /* Free up all the resources. */ 633 634 /* blow away sctp stream management */ 635 if (sctp->sctp_ostrcntrs != NULL) { 636 kmem_free(sctp->sctp_ostrcntrs, 637 sizeof (uint16_t) * sctp->sctp_num_ostr); 638 sctp->sctp_ostrcntrs = NULL; 639 } 640 sctp_instream_cleanup(sctp, B_TRUE); 641 642 /* Remove all data transfer resources. */ 643 sctp->sctp_istr_nmsgs = 0; 644 sctp->sctp_rxqueued = 0; 645 sctp_free_xmit_data(sctp); 646 sctp->sctp_unacked = 0; 647 sctp->sctp_unsent = 0; 648 if (sctp->sctp_cxmit_list != NULL) 649 sctp_asconf_free_cxmit(sctp, NULL); 650 651 sctp->sctp_lastdata = NULL; 652 653 /* Clear out default xmit settings */ 654 sctp->sctp_def_stream = 0; 655 sctp->sctp_def_flags = 0; 656 sctp->sctp_def_ppid = 0; 657 sctp->sctp_def_context = 0; 658 sctp->sctp_def_timetolive = 0; 659 660 if (sctp->sctp_sack_info != NULL) { 661 sctp_free_set(sctp->sctp_sack_info); 662 sctp->sctp_sack_info = NULL; 663 } 664 sctp->sctp_sack_gaps = 0; 665 666 if (sctp->sctp_cookie_mp != NULL) { 667 freemsg(sctp->sctp_cookie_mp); 668 sctp->sctp_cookie_mp = NULL; 669 } 670 671 /* Remove all the address resources. */ 672 sctp_zap_addrs(sctp); 673 for (cnt = 0; cnt < SCTP_IPIF_HASH; cnt++) { 674 ASSERT(sctp->sctp_saddrs[cnt].ipif_count == 0); 675 list_destroy(&sctp->sctp_saddrs[cnt].sctp_ipif_list); 676 } 677 678 if (sctp->sctp_hopopts != NULL) { 679 mi_free(sctp->sctp_hopopts); 680 sctp->sctp_hopopts = NULL; 681 sctp->sctp_hopoptslen = 0; 682 } 683 ASSERT(sctp->sctp_hopoptslen == 0); 684 if (sctp->sctp_dstopts != NULL) { 685 mi_free(sctp->sctp_dstopts); 686 sctp->sctp_dstopts = NULL; 687 sctp->sctp_dstoptslen = 0; 688 } 689 ASSERT(sctp->sctp_dstoptslen == 0); 690 if (sctp->sctp_rthdrdstopts != NULL) { 691 mi_free(sctp->sctp_rthdrdstopts); 692 sctp->sctp_rthdrdstopts = NULL; 693 sctp->sctp_rthdrdstoptslen = 0; 694 } 695 ASSERT(sctp->sctp_rthdrdstoptslen == 0); 696 if (sctp->sctp_rthdr != NULL) { 697 mi_free(sctp->sctp_rthdr); 698 sctp->sctp_rthdr = NULL; 699 sctp->sctp_rthdrlen = 0; 700 } 701 ASSERT(sctp->sctp_rthdrlen == 0); 702 sctp_headers_free(sctp); 703 704 sctp->sctp_shutdown_faddr = NULL; 705 706 if (sctp->sctp_err_chunks != NULL) { 707 freemsg(sctp->sctp_err_chunks); 708 sctp->sctp_err_chunks = NULL; 709 sctp->sctp_err_len = 0; 710 } 711 712 /* Clear all the bitfields. */ 713 bzero(&sctp->sctp_bits, sizeof (sctp->sctp_bits)); 714 715 /* It is time to update the global statistics. */ 716 UPDATE_MIB(&sctps->sctps_mib, sctpOutSCTPPkts, sctp->sctp_opkts); 717 UPDATE_MIB(&sctps->sctps_mib, sctpOutCtrlChunks, sctp->sctp_obchunks); 718 UPDATE_MIB(&sctps->sctps_mib, sctpOutOrderChunks, sctp->sctp_odchunks); 719 UPDATE_MIB(&sctps->sctps_mib, 720 sctpOutUnorderChunks, sctp->sctp_oudchunks); 721 UPDATE_MIB(&sctps->sctps_mib, sctpRetransChunks, sctp->sctp_rxtchunks); 722 UPDATE_MIB(&sctps->sctps_mib, sctpInSCTPPkts, sctp->sctp_ipkts); 723 UPDATE_MIB(&sctps->sctps_mib, sctpInCtrlChunks, sctp->sctp_ibchunks); 724 UPDATE_MIB(&sctps->sctps_mib, sctpInOrderChunks, sctp->sctp_idchunks); 725 UPDATE_MIB(&sctps->sctps_mib, 726 sctpInUnorderChunks, sctp->sctp_iudchunks); 727 UPDATE_MIB(&sctps->sctps_mib, sctpFragUsrMsgs, sctp->sctp_fragdmsgs); 728 UPDATE_MIB(&sctps->sctps_mib, sctpReasmUsrMsgs, sctp->sctp_reassmsgs); 729 sctp->sctp_opkts = 0; 730 sctp->sctp_obchunks = 0; 731 sctp->sctp_odchunks = 0; 732 sctp->sctp_oudchunks = 0; 733 sctp->sctp_rxtchunks = 0; 734 sctp->sctp_ipkts = 0; 735 sctp->sctp_ibchunks = 0; 736 sctp->sctp_idchunks = 0; 737 sctp->sctp_iudchunks = 0; 738 sctp->sctp_fragdmsgs = 0; 739 sctp->sctp_reassmsgs = 0; 740 sctp->sctp_outseqtsns = 0; 741 sctp->sctp_osacks = 0; 742 sctp->sctp_isacks = 0; 743 sctp->sctp_idupchunks = 0; 744 sctp->sctp_gapcnt = 0; 745 sctp->sctp_cum_obchunks = 0; 746 sctp->sctp_cum_odchunks = 0; 747 sctp->sctp_cum_oudchunks = 0; 748 sctp->sctp_cum_rxtchunks = 0; 749 sctp->sctp_cum_ibchunks = 0; 750 sctp->sctp_cum_idchunks = 0; 751 sctp->sctp_cum_iudchunks = 0; 752 753 sctp->sctp_autoclose = 0; 754 sctp->sctp_tx_adaptation_code = 0; 755 756 sctp->sctp_v6label_len = 0; 757 sctp->sctp_v4label_len = 0; 758 759 sctp->sctp_sctps = NULL; 760 761 sctp_conn_clear(connp); 762 kmem_cache_free(sctp_conn_cache, connp); 763 } 764 765 /* Diagnostic routine used to return a string associated with the sctp state. */ 766 char * 767 sctp_display(sctp_t *sctp, char *sup_buf) 768 { 769 char *buf; 770 char buf1[30]; 771 static char priv_buf[INET6_ADDRSTRLEN * 2 + 80]; 772 char *cp; 773 conn_t *connp; 774 775 if (sctp == NULL) 776 return ("NULL_SCTP"); 777 778 connp = sctp->sctp_connp; 779 buf = (sup_buf != NULL) ? sup_buf : priv_buf; 780 781 switch (sctp->sctp_state) { 782 case SCTPS_IDLE: 783 cp = "SCTP_IDLE"; 784 break; 785 case SCTPS_BOUND: 786 cp = "SCTP_BOUND"; 787 break; 788 case SCTPS_LISTEN: 789 cp = "SCTP_LISTEN"; 790 break; 791 case SCTPS_COOKIE_WAIT: 792 cp = "SCTP_COOKIE_WAIT"; 793 break; 794 case SCTPS_COOKIE_ECHOED: 795 cp = "SCTP_COOKIE_ECHOED"; 796 break; 797 case SCTPS_ESTABLISHED: 798 cp = "SCTP_ESTABLISHED"; 799 break; 800 case SCTPS_SHUTDOWN_PENDING: 801 cp = "SCTP_SHUTDOWN_PENDING"; 802 break; 803 case SCTPS_SHUTDOWN_SENT: 804 cp = "SCTPS_SHUTDOWN_SENT"; 805 break; 806 case SCTPS_SHUTDOWN_RECEIVED: 807 cp = "SCTPS_SHUTDOWN_RECEIVED"; 808 break; 809 case SCTPS_SHUTDOWN_ACK_SENT: 810 cp = "SCTPS_SHUTDOWN_ACK_SENT"; 811 break; 812 default: 813 (void) mi_sprintf(buf1, "SCTPUnkState(%d)", sctp->sctp_state); 814 cp = buf1; 815 break; 816 } 817 (void) mi_sprintf(buf, "[%u, %u] %s", 818 ntohs(connp->conn_lport), ntohs(connp->conn_fport), cp); 819 820 return (buf); 821 } 822 823 /* 824 * Initialize protocol control block. If a parent exists, inherit 825 * all values set through setsockopt(). 826 */ 827 static int 828 sctp_init_values(sctp_t *sctp, sctp_t *psctp, int sleep) 829 { 830 int err; 831 int cnt; 832 sctp_stack_t *sctps = sctp->sctp_sctps; 833 conn_t *connp; 834 835 connp = sctp->sctp_connp; 836 837 sctp->sctp_nsaddrs = 0; 838 for (cnt = 0; cnt < SCTP_IPIF_HASH; cnt++) { 839 sctp->sctp_saddrs[cnt].ipif_count = 0; 840 list_create(&sctp->sctp_saddrs[cnt].sctp_ipif_list, 841 sizeof (sctp_saddr_ipif_t), offsetof(sctp_saddr_ipif_t, 842 saddr_ipif)); 843 } 844 connp->conn_ports = 0; 845 sctp->sctp_running = B_FALSE; 846 sctp->sctp_state = SCTPS_IDLE; 847 848 sctp->sctp_refcnt = 1; 849 850 sctp->sctp_strikes = 0; 851 852 sctp->sctp_last_mtu_probe = ddi_get_lbolt64(); 853 sctp->sctp_mtu_probe_intvl = sctps->sctps_mtu_probe_interval; 854 855 sctp->sctp_sack_gaps = 0; 856 sctp->sctp_sack_toggle = 2; 857 858 /* Only need to do the allocation if there is no "cached" one. */ 859 if (sctp->sctp_pad_mp == NULL) { 860 if (sleep == KM_SLEEP) { 861 sctp->sctp_pad_mp = allocb_wait(SCTP_ALIGN, BPRI_MED, 862 STR_NOSIG, NULL); 863 } else { 864 sctp->sctp_pad_mp = allocb(SCTP_ALIGN, BPRI_MED); 865 if (sctp->sctp_pad_mp == NULL) 866 return (ENOMEM); 867 } 868 bzero(sctp->sctp_pad_mp->b_rptr, SCTP_ALIGN); 869 } 870 871 if (psctp != NULL) { 872 /* 873 * Inherit from parent 874 * 875 * Start by inheriting from the conn_t, including conn_ixa and 876 * conn_xmit_ipp. 877 */ 878 err = conn_inherit_parent(psctp->sctp_connp, connp); 879 if (err != 0) 880 goto failure; 881 882 sctp->sctp_cookie_lifetime = psctp->sctp_cookie_lifetime; 883 884 sctp->sctp_cwnd_max = psctp->sctp_cwnd_max; 885 sctp->sctp_rwnd = psctp->sctp_rwnd; 886 sctp->sctp_irwnd = psctp->sctp_rwnd; 887 sctp->sctp_pd_point = psctp->sctp_pd_point; 888 sctp->sctp_rto_max = psctp->sctp_rto_max; 889 sctp->sctp_init_rto_max = psctp->sctp_init_rto_max; 890 sctp->sctp_rto_min = psctp->sctp_rto_min; 891 sctp->sctp_rto_initial = psctp->sctp_rto_initial; 892 sctp->sctp_pa_max_rxt = psctp->sctp_pa_max_rxt; 893 sctp->sctp_pp_max_rxt = psctp->sctp_pp_max_rxt; 894 sctp->sctp_max_init_rxt = psctp->sctp_max_init_rxt; 895 896 sctp->sctp_def_stream = psctp->sctp_def_stream; 897 sctp->sctp_def_flags = psctp->sctp_def_flags; 898 sctp->sctp_def_ppid = psctp->sctp_def_ppid; 899 sctp->sctp_def_context = psctp->sctp_def_context; 900 sctp->sctp_def_timetolive = psctp->sctp_def_timetolive; 901 902 sctp->sctp_num_istr = psctp->sctp_num_istr; 903 sctp->sctp_num_ostr = psctp->sctp_num_ostr; 904 905 sctp->sctp_hb_interval = psctp->sctp_hb_interval; 906 sctp->sctp_autoclose = psctp->sctp_autoclose; 907 sctp->sctp_tx_adaptation_code = psctp->sctp_tx_adaptation_code; 908 909 /* xxx should be a better way to copy these flags xxx */ 910 sctp->sctp_bound_to_all = psctp->sctp_bound_to_all; 911 sctp->sctp_cansleep = psctp->sctp_cansleep; 912 sctp->sctp_send_adaptation = psctp->sctp_send_adaptation; 913 sctp->sctp_ndelay = psctp->sctp_ndelay; 914 sctp->sctp_events = psctp->sctp_events; 915 } else { 916 /* 917 * Set to system defaults 918 */ 919 sctp->sctp_cookie_lifetime = 920 MSEC_TO_TICK(sctps->sctps_cookie_life); 921 connp->conn_sndlowat = sctps->sctps_xmit_lowat; 922 connp->conn_sndbuf = sctps->sctps_xmit_hiwat; 923 connp->conn_rcvbuf = sctps->sctps_recv_hiwat; 924 925 sctp->sctp_cwnd_max = sctps->sctps_cwnd_max_; 926 sctp->sctp_rwnd = connp->conn_rcvbuf; 927 sctp->sctp_irwnd = sctp->sctp_rwnd; 928 sctp->sctp_pd_point = sctp->sctp_rwnd; 929 sctp->sctp_rto_max = MSEC_TO_TICK(sctps->sctps_rto_maxg); 930 sctp->sctp_init_rto_max = sctp->sctp_rto_max; 931 sctp->sctp_rto_min = MSEC_TO_TICK(sctps->sctps_rto_ming); 932 sctp->sctp_rto_initial = MSEC_TO_TICK( 933 sctps->sctps_rto_initialg); 934 sctp->sctp_pa_max_rxt = sctps->sctps_pa_max_retr; 935 sctp->sctp_pp_max_rxt = sctps->sctps_pp_max_retr; 936 sctp->sctp_max_init_rxt = sctps->sctps_max_init_retr; 937 938 sctp->sctp_num_istr = sctps->sctps_max_in_streams; 939 sctp->sctp_num_ostr = sctps->sctps_initial_out_streams; 940 941 sctp->sctp_hb_interval = 942 MSEC_TO_TICK(sctps->sctps_heartbeat_interval); 943 944 if (connp->conn_family == AF_INET) 945 connp->conn_default_ttl = sctps->sctps_ipv4_ttl; 946 else 947 connp->conn_default_ttl = sctps->sctps_ipv6_hoplimit; 948 949 connp->conn_xmit_ipp.ipp_unicast_hops = 950 connp->conn_default_ttl; 951 952 /* 953 * Initialize the header template 954 */ 955 if ((err = sctp_build_hdrs(sctp, sleep)) != 0) { 956 goto failure; 957 } 958 } 959 960 sctp->sctp_understands_asconf = B_TRUE; 961 sctp->sctp_understands_addip = B_TRUE; 962 sctp->sctp_prsctp_aware = B_FALSE; 963 964 sctp->sctp_connp->conn_ref = 1; 965 966 sctp->sctp_prsctpdrop = 0; 967 sctp->sctp_msgcount = 0; 968 969 return (0); 970 971 failure: 972 sctp_headers_free(sctp); 973 return (err); 974 } 975 976 /* 977 * Extracts the init tag from an INIT chunk and checks if it matches 978 * the sctp's verification tag. Returns 0 if it doesn't match, 1 if 979 * it does. 980 */ 981 static boolean_t 982 sctp_icmp_verf(sctp_t *sctp, sctp_hdr_t *sh, mblk_t *mp) 983 { 984 sctp_chunk_hdr_t *sch; 985 uint32_t verf, *vp; 986 987 sch = (sctp_chunk_hdr_t *)(sh + 1); 988 vp = (uint32_t *)(sch + 1); 989 990 /* Need at least the data chunk hdr and the first 4 bytes of INIT */ 991 if ((unsigned char *)(vp + 1) > mp->b_wptr) { 992 return (B_FALSE); 993 } 994 995 bcopy(vp, &verf, sizeof (verf)); 996 997 if (verf == sctp->sctp_lvtag) { 998 return (B_TRUE); 999 } 1000 return (B_FALSE); 1001 } 1002 1003 /* 1004 * Update the SCTP state according to change of PMTU. 1005 * 1006 * Path MTU might have changed by either increase or decrease, so need to 1007 * adjust the MSS based on the value of ixa_pmtu. 1008 */ 1009 static void 1010 sctp_update_pmtu(sctp_t *sctp, sctp_faddr_t *fp, boolean_t decrease_only) 1011 { 1012 uint32_t pmtu; 1013 int32_t mss; 1014 ip_xmit_attr_t *ixa = fp->ixa; 1015 1016 if (sctp->sctp_state < SCTPS_ESTABLISHED) 1017 return; 1018 1019 /* 1020 * Always call ip_get_pmtu() to make sure that IP has updated 1021 * ixa_flags properly. 1022 */ 1023 pmtu = ip_get_pmtu(ixa); 1024 1025 /* 1026 * Calculate the MSS by decreasing the PMTU by sctp_hdr_len and 1027 * IPsec overhead if applied. Make sure to use the most recent 1028 * IPsec information. 1029 */ 1030 mss = pmtu - conn_ipsec_length(sctp->sctp_connp); 1031 if (ixa->ixa_flags & IXAF_IS_IPV4) 1032 mss -= sctp->sctp_hdr_len; 1033 else 1034 mss -= sctp->sctp_hdr6_len; 1035 1036 /* 1037 * Nothing to change, so just return. 1038 */ 1039 if (mss == fp->sfa_pmss) 1040 return; 1041 1042 /* 1043 * Currently, for ICMP errors, only PMTU decrease is handled. 1044 */ 1045 if (mss > fp->sfa_pmss && decrease_only) 1046 return; 1047 1048 #ifdef DEBUG 1049 (void) printf("sctp_update_pmtu mss from %d to %d\n", 1050 fp->sfa_pmss, mss); 1051 #endif 1052 DTRACE_PROBE2(sctp_update_pmtu, int32_t, fp->sfa_pmss, uint32_t, mss); 1053 1054 /* 1055 * Update ixa_fragsize and ixa_pmtu. 1056 */ 1057 ixa->ixa_fragsize = ixa->ixa_pmtu = pmtu; 1058 1059 /* 1060 * Make sure that sfa_pmss is a multiple of 1061 * SCTP_ALIGN. 1062 */ 1063 fp->sfa_pmss = mss & ~(SCTP_ALIGN - 1); 1064 fp->pmtu_discovered = 1; 1065 1066 #ifdef notyet 1067 if (mss < sctp->sctp_sctps->sctps_mss_min) 1068 ixa->ixa_flags |= IXAF_PMTU_TOO_SMALL; 1069 #endif 1070 if (ixa->ixa_flags & IXAF_PMTU_TOO_SMALL) 1071 ixa->ixa_flags &= ~(IXAF_DONTFRAG | IXAF_PMTU_IPV4_DF); 1072 1073 /* 1074 * If below the min size then ip_get_pmtu cleared IXAF_PMTU_IPV4_DF. 1075 * Make sure to clear IXAF_DONTFRAG, which is used by IP to decide 1076 * whether to fragment the packet. 1077 */ 1078 if (ixa->ixa_flags & IXAF_IS_IPV4) { 1079 if (!(ixa->ixa_flags & IXAF_PMTU_IPV4_DF)) { 1080 fp->df = B_FALSE; 1081 if (fp == sctp->sctp_current) { 1082 sctp->sctp_ipha-> 1083 ipha_fragment_offset_and_flags = 0; 1084 } 1085 } 1086 } 1087 } 1088 1089 /* 1090 * Notify function registered with ip_xmit_attr_t. It's called in the context 1091 * of conn_ip_output so it's safe to update the SCTP state. 1092 * Currently only used for pmtu changes. 1093 */ 1094 /* ARGSUSED1 */ 1095 static void 1096 sctp_notify(void *arg, ip_xmit_attr_t *ixa, ixa_notify_type_t ntype, 1097 ixa_notify_arg_t narg) 1098 { 1099 sctp_t *sctp = (sctp_t *)arg; 1100 sctp_faddr_t *fp; 1101 1102 switch (ntype) { 1103 case IXAN_PMTU: 1104 /* Find the faddr based on the ip_xmit_attr_t pointer */ 1105 for (fp = sctp->sctp_faddrs; fp != NULL; fp = fp->next) { 1106 if (fp->ixa == ixa) 1107 break; 1108 } 1109 if (fp != NULL) 1110 sctp_update_pmtu(sctp, fp, B_FALSE); 1111 break; 1112 default: 1113 break; 1114 } 1115 } 1116 1117 /* 1118 * sctp_icmp_error is called by sctp_input() to process ICMP error messages 1119 * passed up by IP. We need to find a sctp_t 1120 * that corresponds to the returned datagram. Passes the message back in on 1121 * the correct queue once it has located the connection. 1122 * Assumes that IP has pulled up everything up to and including 1123 * the ICMP header. 1124 */ 1125 void 1126 sctp_icmp_error(sctp_t *sctp, mblk_t *mp) 1127 { 1128 icmph_t *icmph; 1129 ipha_t *ipha; 1130 int iph_hdr_length; 1131 sctp_hdr_t *sctph; 1132 in6_addr_t dst; 1133 sctp_faddr_t *fp; 1134 sctp_stack_t *sctps = sctp->sctp_sctps; 1135 1136 dprint(1, ("sctp_icmp_error: sctp=%p, mp=%p\n", (void *)sctp, 1137 (void *)mp)); 1138 1139 ipha = (ipha_t *)mp->b_rptr; 1140 if (IPH_HDR_VERSION(ipha) != IPV4_VERSION) { 1141 ASSERT(IPH_HDR_VERSION(ipha) == IPV6_VERSION); 1142 sctp_icmp_error_ipv6(sctp, mp); 1143 return; 1144 } 1145 1146 /* account for the ip hdr from the icmp message */ 1147 iph_hdr_length = IPH_HDR_LENGTH(ipha); 1148 icmph = (icmph_t *)&mp->b_rptr[iph_hdr_length]; 1149 /* now the ip hdr of message resulting in this icmp */ 1150 ipha = (ipha_t *)&icmph[1]; 1151 iph_hdr_length = IPH_HDR_LENGTH(ipha); 1152 sctph = (sctp_hdr_t *)((char *)ipha + iph_hdr_length); 1153 /* first_mp must expose the full sctp header. */ 1154 if ((uchar_t *)(sctph + 1) >= mp->b_wptr) { 1155 /* not enough data for SCTP header */ 1156 freemsg(mp); 1157 return; 1158 } 1159 1160 switch (icmph->icmph_type) { 1161 case ICMP_DEST_UNREACHABLE: 1162 switch (icmph->icmph_code) { 1163 case ICMP_FRAGMENTATION_NEEDED: 1164 /* 1165 * Reduce the MSS based on the new MTU. This will 1166 * eliminate any fragmentation locally. 1167 * N.B. There may well be some funny side-effects on 1168 * the local send policy and the remote receive policy. 1169 * Pending further research, we provide 1170 * sctp_ignore_path_mtu just in case this proves 1171 * disastrous somewhere. 1172 * 1173 * After updating the MSS, retransmit part of the 1174 * dropped segment using the new mss by calling 1175 * sctp_wput_slow(). Need to adjust all those 1176 * params to make sure sctp_wput_slow() work properly. 1177 */ 1178 if (sctps->sctps_ignore_path_mtu) 1179 break; 1180 1181 /* find the offending faddr */ 1182 IN6_IPADDR_TO_V4MAPPED(ipha->ipha_dst, &dst); 1183 fp = sctp_lookup_faddr(sctp, &dst); 1184 if (fp == NULL) { 1185 break; 1186 } 1187 sctp_update_pmtu(sctp, fp, B_TRUE); 1188 /* 1189 * It is possible, even likely that a fast retransmit 1190 * attempt has been dropped by ip as a result of this 1191 * error, retransmission bundles as much as possible. 1192 * A retransmit here prevents significant delays waiting 1193 * on the timer. Analogous to behaviour of TCP after 1194 * ICMP too big. 1195 */ 1196 sctp_rexmit(sctp, fp); 1197 break; 1198 case ICMP_PORT_UNREACHABLE: 1199 case ICMP_PROTOCOL_UNREACHABLE: 1200 switch (sctp->sctp_state) { 1201 case SCTPS_COOKIE_WAIT: 1202 case SCTPS_COOKIE_ECHOED: 1203 /* make sure the verification tag matches */ 1204 if (!sctp_icmp_verf(sctp, sctph, mp)) { 1205 break; 1206 } 1207 BUMP_MIB(&sctps->sctps_mib, sctpAborted); 1208 sctp_assoc_event(sctp, SCTP_CANT_STR_ASSOC, 0, 1209 NULL); 1210 sctp_clean_death(sctp, ECONNREFUSED); 1211 break; 1212 } 1213 break; 1214 case ICMP_HOST_UNREACHABLE: 1215 case ICMP_NET_UNREACHABLE: 1216 /* Record the error in case we finally time out. */ 1217 sctp->sctp_client_errno = (icmph->icmph_code == 1218 ICMP_HOST_UNREACHABLE) ? EHOSTUNREACH : ENETUNREACH; 1219 break; 1220 default: 1221 break; 1222 } 1223 break; 1224 case ICMP_SOURCE_QUENCH: { 1225 /* Reduce the sending rate as if we got a retransmit timeout */ 1226 break; 1227 } 1228 } 1229 freemsg(mp); 1230 } 1231 1232 /* 1233 * sctp_icmp_error_ipv6() is called by sctp_icmp_error() to process ICMPv6 1234 * error messages passed up by IP. 1235 * Assumes that IP has pulled up all the extension headers as well 1236 * as the ICMPv6 header. 1237 */ 1238 static void 1239 sctp_icmp_error_ipv6(sctp_t *sctp, mblk_t *mp) 1240 { 1241 icmp6_t *icmp6; 1242 ip6_t *ip6h; 1243 uint16_t iph_hdr_length; 1244 sctp_hdr_t *sctpha; 1245 uint8_t *nexthdrp; 1246 sctp_faddr_t *fp; 1247 sctp_stack_t *sctps = sctp->sctp_sctps; 1248 1249 ip6h = (ip6_t *)mp->b_rptr; 1250 iph_hdr_length = (ip6h->ip6_nxt != IPPROTO_SCTP) ? 1251 ip_hdr_length_v6(mp, ip6h) : IPV6_HDR_LEN; 1252 1253 icmp6 = (icmp6_t *)&mp->b_rptr[iph_hdr_length]; 1254 ip6h = (ip6_t *)&icmp6[1]; 1255 if (!ip_hdr_length_nexthdr_v6(mp, ip6h, &iph_hdr_length, &nexthdrp)) { 1256 freemsg(mp); 1257 return; 1258 } 1259 ASSERT(*nexthdrp == IPPROTO_SCTP); 1260 1261 /* XXX need ifindex to find connection */ 1262 sctpha = (sctp_hdr_t *)((char *)ip6h + iph_hdr_length); 1263 if ((uchar_t *)sctpha >= mp->b_wptr) { 1264 /* not enough data for SCTP header */ 1265 freemsg(mp); 1266 return; 1267 } 1268 switch (icmp6->icmp6_type) { 1269 case ICMP6_PACKET_TOO_BIG: 1270 /* 1271 * Reduce the MSS based on the new MTU. This will 1272 * eliminate any fragmentation locally. 1273 * N.B. There may well be some funny side-effects on 1274 * the local send policy and the remote receive policy. 1275 * Pending further research, we provide 1276 * sctp_ignore_path_mtu just in case this proves 1277 * disastrous somewhere. 1278 * 1279 * After updating the MSS, retransmit part of the 1280 * dropped segment using the new mss by calling 1281 * sctp_wput_slow(). Need to adjust all those 1282 * params to make sure sctp_wput_slow() work properly. 1283 */ 1284 if (sctps->sctps_ignore_path_mtu) 1285 break; 1286 1287 /* find the offending faddr */ 1288 fp = sctp_lookup_faddr(sctp, &ip6h->ip6_dst); 1289 if (fp == NULL) { 1290 break; 1291 } 1292 1293 sctp_update_pmtu(sctp, fp, B_TRUE); 1294 /* 1295 * It is possible, even likely that a fast retransmit 1296 * attempt has been dropped by ip as a result of this 1297 * error, retransmission bundles as much as possible. 1298 * A retransmit here prevents significant delays waiting 1299 * on the timer. Analogous to behaviour of TCP after 1300 * ICMP too big. 1301 */ 1302 sctp_rexmit(sctp, fp); 1303 break; 1304 1305 case ICMP6_DST_UNREACH: 1306 switch (icmp6->icmp6_code) { 1307 case ICMP6_DST_UNREACH_NOPORT: 1308 /* make sure the verification tag matches */ 1309 if (!sctp_icmp_verf(sctp, sctpha, mp)) { 1310 break; 1311 } 1312 if (sctp->sctp_state == SCTPS_COOKIE_WAIT || 1313 sctp->sctp_state == SCTPS_COOKIE_ECHOED) { 1314 BUMP_MIB(&sctps->sctps_mib, sctpAborted); 1315 sctp_assoc_event(sctp, SCTP_CANT_STR_ASSOC, 0, 1316 NULL); 1317 sctp_clean_death(sctp, ECONNREFUSED); 1318 } 1319 break; 1320 1321 case ICMP6_DST_UNREACH_ADMIN: 1322 case ICMP6_DST_UNREACH_NOROUTE: 1323 case ICMP6_DST_UNREACH_NOTNEIGHBOR: 1324 case ICMP6_DST_UNREACH_ADDR: 1325 /* Record the error in case we finally time out. */ 1326 sctp->sctp_client_errno = EHOSTUNREACH; 1327 break; 1328 default: 1329 break; 1330 } 1331 break; 1332 1333 case ICMP6_PARAM_PROB: 1334 /* If this corresponds to an ICMP_PROTOCOL_UNREACHABLE */ 1335 if (icmp6->icmp6_code == ICMP6_PARAMPROB_NEXTHEADER && 1336 (uchar_t *)ip6h + icmp6->icmp6_pptr == 1337 (uchar_t *)nexthdrp) { 1338 /* make sure the verification tag matches */ 1339 if (!sctp_icmp_verf(sctp, sctpha, mp)) { 1340 break; 1341 } 1342 if (sctp->sctp_state == SCTPS_COOKIE_WAIT) { 1343 BUMP_MIB(&sctps->sctps_mib, sctpAborted); 1344 sctp_assoc_event(sctp, SCTP_CANT_STR_ASSOC, 0, 1345 NULL); 1346 sctp_clean_death(sctp, ECONNREFUSED); 1347 } 1348 break; 1349 } 1350 break; 1351 1352 case ICMP6_TIME_EXCEEDED: 1353 default: 1354 break; 1355 } 1356 freemsg(mp); 1357 } 1358 1359 /* 1360 * Called by sockfs to create a new sctp instance. 1361 * 1362 * If parent pointer is passed in, inherit settings from it. 1363 */ 1364 sctp_t * 1365 sctp_create(void *ulpd, sctp_t *parent, int family, int type, int flags, 1366 sock_upcalls_t *upcalls, sctp_sockbuf_limits_t *sbl, 1367 cred_t *credp) 1368 { 1369 sctp_t *sctp, *psctp; 1370 conn_t *connp; 1371 mblk_t *ack_mp, *hb_mp; 1372 int sleep = flags & SCTP_CAN_BLOCK ? KM_SLEEP : KM_NOSLEEP; 1373 zoneid_t zoneid; 1374 sctp_stack_t *sctps; 1375 1376 /* User must supply a credential. */ 1377 if (credp == NULL) 1378 return (NULL); 1379 1380 psctp = (sctp_t *)parent; 1381 if (psctp != NULL) { 1382 sctps = psctp->sctp_sctps; 1383 /* Increase here to have common decrease at end */ 1384 netstack_hold(sctps->sctps_netstack); 1385 } else { 1386 netstack_t *ns; 1387 1388 ns = netstack_find_by_cred(credp); 1389 ASSERT(ns != NULL); 1390 sctps = ns->netstack_sctp; 1391 ASSERT(sctps != NULL); 1392 1393 /* 1394 * For exclusive stacks we set the zoneid to zero 1395 * to make SCTP operate as if in the global zone. 1396 */ 1397 if (sctps->sctps_netstack->netstack_stackid != 1398 GLOBAL_NETSTACKID) 1399 zoneid = GLOBAL_ZONEID; 1400 else 1401 zoneid = crgetzoneid(credp); 1402 } 1403 if ((connp = ipcl_conn_create(IPCL_SCTPCONN, sleep, 1404 sctps->sctps_netstack)) == NULL) { 1405 netstack_rele(sctps->sctps_netstack); 1406 SCTP_KSTAT(sctps, sctp_conn_create); 1407 return (NULL); 1408 } 1409 /* 1410 * ipcl_conn_create did a netstack_hold. Undo the hold that was 1411 * done at top of sctp_create. 1412 */ 1413 netstack_rele(sctps->sctps_netstack); 1414 sctp = CONN2SCTP(connp); 1415 sctp->sctp_sctps = sctps; 1416 1417 if ((ack_mp = sctp_timer_alloc(sctp, sctp_ack_timer, sleep)) == NULL || 1418 (hb_mp = sctp_timer_alloc(sctp, sctp_heartbeat_timer, 1419 sleep)) == NULL) { 1420 if (ack_mp != NULL) 1421 freeb(ack_mp); 1422 sctp_conn_clear(connp); 1423 sctp->sctp_sctps = NULL; 1424 kmem_cache_free(sctp_conn_cache, connp); 1425 return (NULL); 1426 } 1427 1428 sctp->sctp_ack_mp = ack_mp; 1429 sctp->sctp_heartbeat_mp = hb_mp; 1430 1431 /* 1432 * Have conn_ip_output drop packets should our outer source 1433 * go invalid, and tell us about mtu changes. 1434 */ 1435 connp->conn_ixa->ixa_flags |= IXAF_SET_ULP_CKSUM | IXAF_VERIFY_SOURCE | 1436 IXAF_VERIFY_PMTU; 1437 connp->conn_family = family; 1438 connp->conn_so_type = type; 1439 1440 if (sctp_init_values(sctp, psctp, sleep) != 0) { 1441 freeb(ack_mp); 1442 freeb(hb_mp); 1443 sctp_conn_clear(connp); 1444 sctp->sctp_sctps = NULL; 1445 kmem_cache_free(sctp_conn_cache, connp); 1446 return (NULL); 1447 } 1448 sctp->sctp_cansleep = ((flags & SCTP_CAN_BLOCK) == SCTP_CAN_BLOCK); 1449 1450 sctp->sctp_mss = sctps->sctps_initial_mtu - ((family == AF_INET6) ? 1451 sctp->sctp_hdr6_len : sctp->sctp_hdr_len); 1452 1453 if (psctp != NULL) { 1454 conn_t *pconnp = psctp->sctp_connp; 1455 1456 RUN_SCTP(psctp); 1457 /* 1458 * Inherit local address list, local port. Parent is either 1459 * in SCTPS_BOUND, or SCTPS_LISTEN state. 1460 */ 1461 ASSERT((psctp->sctp_state == SCTPS_BOUND) || 1462 (psctp->sctp_state == SCTPS_LISTEN)); 1463 if (sctp_dup_saddrs(psctp, sctp, sleep)) { 1464 WAKE_SCTP(psctp); 1465 freeb(ack_mp); 1466 freeb(hb_mp); 1467 sctp_headers_free(sctp); 1468 sctp_conn_clear(connp); 1469 sctp->sctp_sctps = NULL; 1470 kmem_cache_free(sctp_conn_cache, connp); 1471 return (NULL); 1472 } 1473 1474 /* 1475 * If the parent is specified, it'll be immediatelly 1476 * followed by sctp_connect(). So don't add this guy to 1477 * bind hash. 1478 */ 1479 connp->conn_lport = pconnp->conn_lport; 1480 sctp->sctp_state = SCTPS_BOUND; 1481 WAKE_SCTP(psctp); 1482 } else { 1483 ASSERT(connp->conn_cred == NULL); 1484 connp->conn_zoneid = zoneid; 1485 /* 1486 * conn_allzones can not be set this early, hence 1487 * no IPCL_ZONEID 1488 */ 1489 connp->conn_ixa->ixa_zoneid = zoneid; 1490 connp->conn_open_time = ddi_get_lbolt64(); 1491 connp->conn_cred = credp; 1492 crhold(credp); 1493 connp->conn_cpid = curproc->p_pid; 1494 1495 /* 1496 * If the caller has the process-wide flag set, then default to 1497 * MAC exempt mode. This allows read-down to unlabeled hosts. 1498 */ 1499 if (getpflags(NET_MAC_AWARE, credp) != 0) 1500 connp->conn_mac_mode = CONN_MAC_AWARE; 1501 1502 connp->conn_zone_is_global = 1503 (crgetzoneid(credp) == GLOBAL_ZONEID); 1504 } 1505 1506 /* Initialize SCTP instance values, our verf tag must never be 0 */ 1507 (void) random_get_pseudo_bytes((uint8_t *)&sctp->sctp_lvtag, 1508 sizeof (sctp->sctp_lvtag)); 1509 if (sctp->sctp_lvtag == 0) 1510 sctp->sctp_lvtag = (uint32_t)gethrtime(); 1511 ASSERT(sctp->sctp_lvtag != 0); 1512 1513 sctp->sctp_ltsn = sctp->sctp_lvtag + 1; 1514 sctp->sctp_lcsn = sctp->sctp_ltsn; 1515 sctp->sctp_recovery_tsn = sctp->sctp_lastack_rxd = sctp->sctp_ltsn - 1; 1516 sctp->sctp_adv_pap = sctp->sctp_lastack_rxd; 1517 1518 /* Information required by upper layer */ 1519 ASSERT(ulpd != NULL); 1520 sctp->sctp_ulpd = ulpd; 1521 1522 ASSERT(upcalls != NULL); 1523 sctp->sctp_upcalls = upcalls; 1524 ASSERT(sbl != NULL); 1525 /* Fill in the socket buffer limits for sctpsockfs */ 1526 sbl->sbl_txlowat = connp->conn_sndlowat; 1527 sbl->sbl_txbuf = connp->conn_sndbuf; 1528 sbl->sbl_rxbuf = sctp->sctp_rwnd; 1529 sbl->sbl_rxlowat = SCTP_RECV_LOWATER; 1530 1531 /* Insert this in the global list. */ 1532 SCTP_LINK(sctp, sctps); 1533 1534 return (sctp); 1535 } 1536 1537 /* Run at module load time */ 1538 void 1539 sctp_ddi_g_init(void) 1540 { 1541 /* Create sctp_t/conn_t cache */ 1542 sctp_conn_cache_init(); 1543 1544 /* Create the faddr cache */ 1545 sctp_faddr_init(); 1546 1547 /* Create the sets cache */ 1548 sctp_sets_init(); 1549 1550 /* Create the PR-SCTP sets cache */ 1551 sctp_ftsn_sets_init(); 1552 1553 /* Initialize tables used for CRC calculation */ 1554 sctp_crc32_init(); 1555 1556 /* 1557 * We want to be informed each time a stack is created or 1558 * destroyed in the kernel, so we can maintain the 1559 * set of sctp_stack_t's. 1560 */ 1561 netstack_register(NS_SCTP, sctp_stack_init, NULL, sctp_stack_fini); 1562 } 1563 1564 static void * 1565 sctp_stack_init(netstackid_t stackid, netstack_t *ns) 1566 { 1567 sctp_stack_t *sctps; 1568 1569 sctps = kmem_zalloc(sizeof (*sctps), KM_SLEEP); 1570 sctps->sctps_netstack = ns; 1571 1572 /* Initialize locks */ 1573 mutex_init(&sctps->sctps_g_lock, NULL, MUTEX_DEFAULT, NULL); 1574 mutex_init(&sctps->sctps_epriv_port_lock, NULL, MUTEX_DEFAULT, NULL); 1575 sctps->sctps_g_num_epriv_ports = SCTP_NUM_EPRIV_PORTS; 1576 sctps->sctps_g_epriv_ports[0] = 2049; 1577 sctps->sctps_g_epriv_ports[1] = 4045; 1578 1579 /* Initialize SCTP hash arrays. */ 1580 sctp_hash_init(sctps); 1581 1582 if (!sctp_nd_init(sctps)) { 1583 sctp_nd_free(sctps); 1584 } 1585 1586 /* Initialize the recvq taskq. */ 1587 sctp_rq_tq_init(sctps); 1588 1589 /* saddr init */ 1590 sctp_saddr_init(sctps); 1591 1592 /* Global SCTP PCB list. */ 1593 list_create(&sctps->sctps_g_list, sizeof (sctp_t), 1594 offsetof(sctp_t, sctp_list)); 1595 1596 /* Initialize sctp kernel stats. */ 1597 sctps->sctps_mibkp = sctp_kstat_init(stackid); 1598 sctps->sctps_kstat = 1599 sctp_kstat2_init(stackid, &sctps->sctps_statistics); 1600 1601 return (sctps); 1602 } 1603 1604 /* 1605 * Called when the module is about to be unloaded. 1606 */ 1607 void 1608 sctp_ddi_g_destroy(void) 1609 { 1610 /* Destroy sctp_t/conn_t caches */ 1611 sctp_conn_cache_fini(); 1612 1613 /* Destroy the faddr cache */ 1614 sctp_faddr_fini(); 1615 1616 /* Destroy the sets cache */ 1617 sctp_sets_fini(); 1618 1619 /* Destroy the PR-SCTP sets cache */ 1620 sctp_ftsn_sets_fini(); 1621 1622 netstack_unregister(NS_SCTP); 1623 } 1624 1625 /* 1626 * Free the SCTP stack instance. 1627 */ 1628 static void 1629 sctp_stack_fini(netstackid_t stackid, void *arg) 1630 { 1631 sctp_stack_t *sctps = (sctp_stack_t *)arg; 1632 1633 sctp_nd_free(sctps); 1634 1635 /* Destroy the recvq taskqs. */ 1636 sctp_rq_tq_fini(sctps); 1637 1638 /* Destroy saddr */ 1639 sctp_saddr_fini(sctps); 1640 1641 /* Global SCTP PCB list. */ 1642 list_destroy(&sctps->sctps_g_list); 1643 1644 /* Destroy SCTP hash arrays. */ 1645 sctp_hash_destroy(sctps); 1646 1647 /* Destroy SCTP kernel stats. */ 1648 sctp_kstat2_fini(stackid, sctps->sctps_kstat); 1649 sctps->sctps_kstat = NULL; 1650 bzero(&sctps->sctps_statistics, sizeof (sctps->sctps_statistics)); 1651 1652 sctp_kstat_fini(stackid, sctps->sctps_mibkp); 1653 sctps->sctps_mibkp = NULL; 1654 1655 mutex_destroy(&sctps->sctps_g_lock); 1656 mutex_destroy(&sctps->sctps_epriv_port_lock); 1657 1658 kmem_free(sctps, sizeof (*sctps)); 1659 } 1660 1661 void 1662 sctp_display_all(sctp_stack_t *sctps) 1663 { 1664 sctp_t *sctp_walker; 1665 1666 mutex_enter(&sctps->sctps_g_lock); 1667 for (sctp_walker = list_head(&sctps->sctps_g_list); 1668 sctp_walker != NULL; 1669 sctp_walker = (sctp_t *)list_next(&sctps->sctps_g_list, 1670 sctp_walker)) { 1671 (void) sctp_display(sctp_walker, NULL); 1672 } 1673 mutex_exit(&sctps->sctps_g_lock); 1674 } 1675 1676 static void 1677 sctp_rq_tq_init(sctp_stack_t *sctps) 1678 { 1679 sctps->sctps_recvq_tq_list_max_sz = 16; 1680 sctps->sctps_recvq_tq_list_cur_sz = 1; 1681 /* 1682 * Initialize the recvq_tq_list and create the first recvq taskq. 1683 * What to do if it fails? 1684 */ 1685 sctps->sctps_recvq_tq_list = 1686 kmem_zalloc(sctps->sctps_recvq_tq_list_max_sz * sizeof (taskq_t *), 1687 KM_SLEEP); 1688 sctps->sctps_recvq_tq_list[0] = taskq_create("sctp_def_recvq_taskq", 1689 MIN(sctp_recvq_tq_thr_max, MAX(sctp_recvq_tq_thr_min, ncpus)), 1690 minclsyspri, sctp_recvq_tq_task_min, sctp_recvq_tq_task_max, 1691 TASKQ_PREPOPULATE); 1692 mutex_init(&sctps->sctps_rq_tq_lock, NULL, MUTEX_DEFAULT, NULL); 1693 } 1694 1695 static void 1696 sctp_rq_tq_fini(sctp_stack_t *sctps) 1697 { 1698 int i; 1699 1700 for (i = 0; i < sctps->sctps_recvq_tq_list_cur_sz; i++) { 1701 ASSERT(sctps->sctps_recvq_tq_list[i] != NULL); 1702 taskq_destroy(sctps->sctps_recvq_tq_list[i]); 1703 } 1704 kmem_free(sctps->sctps_recvq_tq_list, 1705 sctps->sctps_recvq_tq_list_max_sz * sizeof (taskq_t *)); 1706 sctps->sctps_recvq_tq_list = NULL; 1707 } 1708 1709 /* Add another taskq for a new ill. */ 1710 void 1711 sctp_inc_taskq(sctp_stack_t *sctps) 1712 { 1713 taskq_t *tq; 1714 char tq_name[TASKQ_NAMELEN]; 1715 1716 mutex_enter(&sctps->sctps_rq_tq_lock); 1717 if (sctps->sctps_recvq_tq_list_cur_sz + 1 > 1718 sctps->sctps_recvq_tq_list_max_sz) { 1719 mutex_exit(&sctps->sctps_rq_tq_lock); 1720 cmn_err(CE_NOTE, "Cannot create more SCTP recvq taskq"); 1721 return; 1722 } 1723 1724 (void) snprintf(tq_name, sizeof (tq_name), "sctp_recvq_taskq_%u", 1725 sctps->sctps_recvq_tq_list_cur_sz); 1726 tq = taskq_create(tq_name, 1727 MIN(sctp_recvq_tq_thr_max, MAX(sctp_recvq_tq_thr_min, ncpus)), 1728 minclsyspri, sctp_recvq_tq_task_min, sctp_recvq_tq_task_max, 1729 TASKQ_PREPOPULATE); 1730 if (tq == NULL) { 1731 mutex_exit(&sctps->sctps_rq_tq_lock); 1732 cmn_err(CE_NOTE, "SCTP recvq taskq creation failed"); 1733 return; 1734 } 1735 ASSERT(sctps->sctps_recvq_tq_list[ 1736 sctps->sctps_recvq_tq_list_cur_sz] == NULL); 1737 sctps->sctps_recvq_tq_list[sctps->sctps_recvq_tq_list_cur_sz] = tq; 1738 atomic_add_32(&sctps->sctps_recvq_tq_list_cur_sz, 1); 1739 mutex_exit(&sctps->sctps_rq_tq_lock); 1740 } 1741 1742 #ifdef DEBUG 1743 uint32_t recvq_loop_cnt = 0; 1744 uint32_t recvq_call = 0; 1745 #endif 1746 1747 /* 1748 * Find the next recvq_tq to use. This routine will go thru all the 1749 * taskqs until it can dispatch a job for the sctp. If this fails, 1750 * it will create a new taskq and try it. 1751 */ 1752 static boolean_t 1753 sctp_find_next_tq(sctp_t *sctp) 1754 { 1755 int next_tq, try; 1756 taskq_t *tq; 1757 sctp_stack_t *sctps = sctp->sctp_sctps; 1758 1759 /* 1760 * Note that since we don't hold a lock on sctp_rq_tq_lock for 1761 * performance reason, recvq_ta_list_cur_sz can be changed during 1762 * this loop. The problem this will create is that the loop may 1763 * not have tried all the recvq_tq. This should be OK. 1764 */ 1765 next_tq = atomic_add_32_nv(&sctps->sctps_recvq_tq_list_cur, 1) % 1766 sctps->sctps_recvq_tq_list_cur_sz; 1767 for (try = 0; try < sctps->sctps_recvq_tq_list_cur_sz; try++) { 1768 tq = sctps->sctps_recvq_tq_list[next_tq]; 1769 if (taskq_dispatch(tq, sctp_process_recvq, sctp, 1770 TQ_NOSLEEP) != NULL) { 1771 sctp->sctp_recvq_tq = tq; 1772 return (B_TRUE); 1773 } 1774 next_tq = (next_tq + 1) % sctps->sctps_recvq_tq_list_cur_sz; 1775 } 1776 1777 /* 1778 * Create one more taskq and try it. Note that sctp_inc_taskq() 1779 * may not have created another taskq if the number of recvq 1780 * taskqs is at the maximum. We are probably in a pretty bad 1781 * shape if this actually happens... 1782 */ 1783 sctp_inc_taskq(sctps); 1784 tq = sctps->sctps_recvq_tq_list[sctps->sctps_recvq_tq_list_cur_sz - 1]; 1785 if (taskq_dispatch(tq, sctp_process_recvq, sctp, TQ_NOSLEEP) != NULL) { 1786 sctp->sctp_recvq_tq = tq; 1787 return (B_TRUE); 1788 } 1789 SCTP_KSTAT(sctps, sctp_find_next_tq); 1790 return (B_FALSE); 1791 } 1792 1793 /* 1794 * To add a message to the recvq. Note that the sctp_timer_fire() 1795 * routine also uses this function to add the timer message to the 1796 * receive queue for later processing. And it should be the only 1797 * caller of sctp_add_recvq() which sets the try_harder argument 1798 * to B_TRUE. 1799 * 1800 * If the try_harder argument is B_TRUE, this routine sctp_find_next_tq() 1801 * will try very hard to dispatch the task. Refer to the comment 1802 * for that routine on how it does that. 1803 * 1804 * On failure the message has been freed i.e., this routine always consumes the 1805 * message. It bumps ipIfStatsInDiscards and and uses ip_drop_input to drop. 1806 */ 1807 void 1808 sctp_add_recvq(sctp_t *sctp, mblk_t *mp, boolean_t caller_hold_lock, 1809 ip_recv_attr_t *ira) 1810 { 1811 mblk_t *attrmp; 1812 ip_stack_t *ipst = sctp->sctp_sctps->sctps_netstack->netstack_ip; 1813 1814 ASSERT(ira->ira_ill == NULL); 1815 1816 if (!caller_hold_lock) 1817 mutex_enter(&sctp->sctp_recvq_lock); 1818 1819 /* If the taskq dispatch has not been scheduled, do it now. */ 1820 if (sctp->sctp_recvq_tq == NULL) { 1821 ASSERT(sctp->sctp_recvq == NULL); 1822 if (!sctp_find_next_tq(sctp)) { 1823 if (!caller_hold_lock) 1824 mutex_exit(&sctp->sctp_recvq_lock); 1825 BUMP_MIB(&ipst->ips_ip_mib, ipIfStatsInDiscards); 1826 ip_drop_input("ipIfStatsInDiscards", mp, NULL); 1827 freemsg(mp); 1828 return; 1829 } 1830 /* Make sure the sctp_t will not go away. */ 1831 SCTP_REFHOLD(sctp); 1832 } 1833 1834 attrmp = ip_recv_attr_to_mblk(ira); 1835 if (attrmp == NULL) { 1836 if (!caller_hold_lock) 1837 mutex_exit(&sctp->sctp_recvq_lock); 1838 BUMP_MIB(&ipst->ips_ip_mib, ipIfStatsInDiscards); 1839 ip_drop_input("ipIfStatsInDiscards", mp, NULL); 1840 freemsg(mp); 1841 return; 1842 } 1843 ASSERT(attrmp->b_cont == NULL); 1844 attrmp->b_cont = mp; 1845 mp = attrmp; 1846 1847 if (sctp->sctp_recvq == NULL) { 1848 sctp->sctp_recvq = mp; 1849 sctp->sctp_recvq_tail = mp; 1850 } else { 1851 sctp->sctp_recvq_tail->b_next = mp; 1852 sctp->sctp_recvq_tail = mp; 1853 } 1854 1855 if (!caller_hold_lock) 1856 mutex_exit(&sctp->sctp_recvq_lock); 1857 } 1858 1859 static void 1860 sctp_process_recvq(void *arg) 1861 { 1862 sctp_t *sctp = (sctp_t *)arg; 1863 mblk_t *mp; 1864 #ifdef DEBUG 1865 uint32_t loop_cnt = 0; 1866 #endif 1867 ip_recv_attr_t iras; 1868 1869 #ifdef _BIG_ENDIAN 1870 #define IPVER(ip6h) ((((uint32_t *)ip6h)[0] >> 28) & 0x7) 1871 #else 1872 #define IPVER(ip6h) ((((uint32_t *)ip6h)[0] >> 4) & 0x7) 1873 #endif 1874 1875 RUN_SCTP(sctp); 1876 mutex_enter(&sctp->sctp_recvq_lock); 1877 1878 #ifdef DEBUG 1879 recvq_call++; 1880 #endif 1881 /* 1882 * Note that while we are in this loop, other thread can put 1883 * new packets in the receive queue. We may be looping for 1884 * quite a while. 1885 */ 1886 while ((mp = sctp->sctp_recvq) != NULL) { 1887 mblk_t *data_mp; 1888 1889 sctp->sctp_recvq = mp->b_next; 1890 mutex_exit(&sctp->sctp_recvq_lock); 1891 mp->b_next = NULL; 1892 #ifdef DEBUG 1893 loop_cnt++; 1894 #endif 1895 mp->b_prev = NULL; 1896 1897 data_mp = mp->b_cont; 1898 mp->b_cont = NULL; 1899 if (!ip_recv_attr_from_mblk(mp, &iras)) { 1900 ip_drop_input("ip_recv_attr_from_mblk", mp, NULL); 1901 freemsg(mp); 1902 ira_cleanup(&iras, B_TRUE); 1903 continue; 1904 } 1905 1906 if (iras.ira_flags & IRAF_ICMP_ERROR) 1907 sctp_icmp_error(sctp, data_mp); 1908 else 1909 sctp_input_data(sctp, data_mp, &iras); 1910 1911 ira_cleanup(&iras, B_TRUE); 1912 mutex_enter(&sctp->sctp_recvq_lock); 1913 } 1914 1915 sctp->sctp_recvq_tail = NULL; 1916 sctp->sctp_recvq_tq = NULL; 1917 1918 mutex_exit(&sctp->sctp_recvq_lock); 1919 1920 WAKE_SCTP(sctp); 1921 1922 #ifdef DEBUG 1923 if (loop_cnt > recvq_loop_cnt) 1924 recvq_loop_cnt = loop_cnt; 1925 #endif 1926 /* Now it can go away. */ 1927 SCTP_REFRELE(sctp); 1928 } 1929 1930 /* ARGSUSED */ 1931 static int 1932 sctp_conn_cache_constructor(void *buf, void *cdrarg, int kmflags) 1933 { 1934 conn_t *connp = (conn_t *)buf; 1935 sctp_t *sctp = (sctp_t *)&connp[1]; 1936 int cnt; 1937 1938 bzero(connp, sizeof (conn_t)); 1939 bzero(buf, (char *)&sctp[1] - (char *)buf); 1940 1941 mutex_init(&sctp->sctp_reflock, NULL, MUTEX_DEFAULT, NULL); 1942 mutex_init(&sctp->sctp_lock, NULL, MUTEX_DEFAULT, NULL); 1943 mutex_init(&sctp->sctp_recvq_lock, NULL, MUTEX_DEFAULT, NULL); 1944 cv_init(&sctp->sctp_cv, NULL, CV_DEFAULT, NULL); 1945 for (cnt = 0; cnt < SCTP_IPIF_HASH; cnt++) { 1946 rw_init(&sctp->sctp_saddrs[cnt].ipif_hash_lock, NULL, 1947 RW_DEFAULT, NULL); 1948 } 1949 1950 mutex_init(&connp->conn_lock, NULL, MUTEX_DEFAULT, NULL); 1951 cv_init(&connp->conn_cv, NULL, CV_DEFAULT, NULL); 1952 connp->conn_flags = IPCL_SCTPCONN; 1953 connp->conn_proto = IPPROTO_SCTP; 1954 connp->conn_sctp = sctp; 1955 sctp->sctp_connp = connp; 1956 rw_init(&connp->conn_ilg_lock, NULL, RW_DEFAULT, NULL); 1957 1958 connp->conn_ixa = kmem_zalloc(sizeof (ip_xmit_attr_t), kmflags); 1959 if (connp->conn_ixa == NULL) { 1960 return (ENOMEM); 1961 } 1962 connp->conn_ixa->ixa_refcnt = 1; 1963 connp->conn_ixa->ixa_protocol = connp->conn_proto; 1964 connp->conn_ixa->ixa_xmit_hint = CONN_TO_XMIT_HINT(connp); 1965 return (0); 1966 } 1967 1968 /* ARGSUSED */ 1969 static void 1970 sctp_conn_cache_destructor(void *buf, void *cdrarg) 1971 { 1972 conn_t *connp = (conn_t *)buf; 1973 sctp_t *sctp = (sctp_t *)&connp[1]; 1974 int cnt; 1975 1976 ASSERT(sctp->sctp_connp == connp); 1977 ASSERT(!MUTEX_HELD(&sctp->sctp_lock)); 1978 ASSERT(!MUTEX_HELD(&sctp->sctp_reflock)); 1979 ASSERT(!MUTEX_HELD(&sctp->sctp_recvq_lock)); 1980 1981 ASSERT(sctp->sctp_conn_hash_next == NULL); 1982 ASSERT(sctp->sctp_conn_hash_prev == NULL); 1983 ASSERT(sctp->sctp_listen_hash_next == NULL); 1984 ASSERT(sctp->sctp_listen_hash_prev == NULL); 1985 ASSERT(sctp->sctp_listen_tfp == NULL); 1986 ASSERT(sctp->sctp_conn_tfp == NULL); 1987 1988 ASSERT(sctp->sctp_faddrs == NULL); 1989 ASSERT(sctp->sctp_nsaddrs == 0); 1990 1991 ASSERT(sctp->sctp_ulpd == NULL); 1992 1993 ASSERT(sctp->sctp_lastfaddr == NULL); 1994 ASSERT(sctp->sctp_primary == NULL); 1995 ASSERT(sctp->sctp_current == NULL); 1996 ASSERT(sctp->sctp_lastdata == NULL); 1997 1998 ASSERT(sctp->sctp_xmit_head == NULL); 1999 ASSERT(sctp->sctp_xmit_tail == NULL); 2000 ASSERT(sctp->sctp_xmit_unsent == NULL); 2001 ASSERT(sctp->sctp_xmit_unsent_tail == NULL); 2002 2003 ASSERT(sctp->sctp_ostrcntrs == NULL); 2004 2005 ASSERT(sctp->sctp_sack_info == NULL); 2006 ASSERT(sctp->sctp_ack_mp == NULL); 2007 ASSERT(sctp->sctp_instr == NULL); 2008 2009 ASSERT(sctp->sctp_iphc == NULL); 2010 ASSERT(sctp->sctp_iphc6 == NULL); 2011 ASSERT(sctp->sctp_ipha == NULL); 2012 ASSERT(sctp->sctp_ip6h == NULL); 2013 ASSERT(sctp->sctp_sctph == NULL); 2014 ASSERT(sctp->sctp_sctph6 == NULL); 2015 2016 ASSERT(sctp->sctp_cookie_mp == NULL); 2017 2018 ASSERT(sctp->sctp_refcnt == 0); 2019 ASSERT(sctp->sctp_timer_mp == NULL); 2020 ASSERT(sctp->sctp_connp->conn_ref == 0); 2021 ASSERT(sctp->sctp_heartbeat_mp == NULL); 2022 ASSERT(sctp->sctp_ptpbhn == NULL && sctp->sctp_bind_hash == NULL); 2023 2024 ASSERT(sctp->sctp_shutdown_faddr == NULL); 2025 2026 ASSERT(sctp->sctp_cxmit_list == NULL); 2027 2028 ASSERT(sctp->sctp_recvq == NULL); 2029 ASSERT(sctp->sctp_recvq_tail == NULL); 2030 ASSERT(sctp->sctp_recvq_tq == NULL); 2031 2032 /* 2033 * sctp_pad_mp can be NULL if the memory allocation fails 2034 * in sctp_init_values() and the conn_t is freed. 2035 */ 2036 if (sctp->sctp_pad_mp != NULL) { 2037 freeb(sctp->sctp_pad_mp); 2038 sctp->sctp_pad_mp = NULL; 2039 } 2040 2041 mutex_destroy(&sctp->sctp_reflock); 2042 mutex_destroy(&sctp->sctp_lock); 2043 mutex_destroy(&sctp->sctp_recvq_lock); 2044 cv_destroy(&sctp->sctp_cv); 2045 for (cnt = 0; cnt < SCTP_IPIF_HASH; cnt++) { 2046 rw_destroy(&sctp->sctp_saddrs[cnt].ipif_hash_lock); 2047 } 2048 2049 mutex_destroy(&connp->conn_lock); 2050 cv_destroy(&connp->conn_cv); 2051 rw_destroy(&connp->conn_ilg_lock); 2052 2053 /* Can be NULL if constructor failed */ 2054 if (connp->conn_ixa != NULL) { 2055 ASSERT(connp->conn_ixa->ixa_refcnt == 1); 2056 ASSERT(connp->conn_ixa->ixa_ire == NULL); 2057 ASSERT(connp->conn_ixa->ixa_nce == NULL); 2058 ixa_refrele(connp->conn_ixa); 2059 } 2060 } 2061 2062 static void 2063 sctp_conn_cache_init() 2064 { 2065 sctp_conn_cache = kmem_cache_create("sctp_conn_cache", 2066 sizeof (sctp_t) + sizeof (conn_t), 0, sctp_conn_cache_constructor, 2067 sctp_conn_cache_destructor, NULL, NULL, NULL, 0); 2068 } 2069 2070 static void 2071 sctp_conn_cache_fini() 2072 { 2073 kmem_cache_destroy(sctp_conn_cache); 2074 } 2075 2076 void 2077 sctp_conn_init(conn_t *connp) 2078 { 2079 ASSERT(connp->conn_flags == IPCL_SCTPCONN); 2080 connp->conn_rq = connp->conn_wq = NULL; 2081 connp->conn_ixa->ixa_flags |= IXAF_SET_ULP_CKSUM | IXAF_VERIFY_SOURCE | 2082 IXAF_VERIFY_PMTU; 2083 2084 ASSERT(connp->conn_proto == IPPROTO_SCTP); 2085 ASSERT(connp->conn_ixa->ixa_protocol == connp->conn_proto); 2086 connp->conn_state_flags |= CONN_INCIPIENT; 2087 2088 ASSERT(connp->conn_sctp != NULL); 2089 2090 /* 2091 * Register sctp_notify to listen to capability changes detected by IP. 2092 * This upcall is made in the context of the call to conn_ip_output 2093 * thus it holds whatever locks sctp holds across conn_ip_output. 2094 */ 2095 connp->conn_ixa->ixa_notify = sctp_notify; 2096 connp->conn_ixa->ixa_notify_cookie = connp->conn_sctp; 2097 } 2098 2099 static void 2100 sctp_conn_clear(conn_t *connp) 2101 { 2102 /* Clean up conn_t stuff */ 2103 if (connp->conn_latch != NULL) { 2104 IPLATCH_REFRELE(connp->conn_latch); 2105 connp->conn_latch = NULL; 2106 } 2107 if (connp->conn_latch_in_policy != NULL) { 2108 IPPOL_REFRELE(connp->conn_latch_in_policy); 2109 connp->conn_latch_in_policy = NULL; 2110 } 2111 if (connp->conn_latch_in_action != NULL) { 2112 IPACT_REFRELE(connp->conn_latch_in_action); 2113 connp->conn_latch_in_action = NULL; 2114 } 2115 if (connp->conn_policy != NULL) { 2116 IPPH_REFRELE(connp->conn_policy, connp->conn_netstack); 2117 connp->conn_policy = NULL; 2118 } 2119 if (connp->conn_ipsec_opt_mp != NULL) { 2120 freemsg(connp->conn_ipsec_opt_mp); 2121 connp->conn_ipsec_opt_mp = NULL; 2122 } 2123 netstack_rele(connp->conn_netstack); 2124 connp->conn_netstack = NULL; 2125 2126 /* Leave conn_ixa and other constructed fields in place */ 2127 ipcl_conn_cleanup(connp); 2128 } 2129