1 /* 2 * CDDL HEADER START 3 * 4 * The contents of this file are subject to the terms of the 5 * Common Development and Distribution License (the "License"). 6 * You may not use this file except in compliance with the License. 7 * 8 * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 9 * or http://www.opensolaris.org/os/licensing. 10 * See the License for the specific language governing permissions 11 * and limitations under the License. 12 * 13 * When distributing Covered Code, include this CDDL HEADER in each 14 * file and include the License file at usr/src/OPENSOLARIS.LICENSE. 15 * If applicable, add the following below this CDDL HEADER, with the 16 * fields enclosed by brackets "[]" replaced with your own identifying 17 * information: Portions Copyright [yyyy] [name of copyright owner] 18 * 19 * CDDL HEADER END 20 */ 21 22 /* 23 * Copyright 2009 Sun Microsystems, Inc. All rights reserved. 24 * Use is subject to license terms. 25 */ 26 27 #include <sys/types.h> 28 #include <sys/stream.h> 29 #include <sys/strsubr.h> 30 #include <sys/stropts.h> 31 #include <sys/strsun.h> 32 #define _SUN_TPI_VERSION 2 33 #include <sys/tihdr.h> 34 #include <sys/ddi.h> 35 #include <sys/sunddi.h> 36 #include <sys/xti_inet.h> 37 #include <sys/cmn_err.h> 38 #include <sys/debug.h> 39 #include <sys/vtrace.h> 40 #include <sys/kmem.h> 41 #include <sys/cpuvar.h> 42 #include <sys/random.h> 43 #include <sys/priv.h> 44 #include <sys/sunldi.h> 45 46 #include <sys/errno.h> 47 #include <sys/signal.h> 48 #include <sys/socket.h> 49 #include <sys/isa_defs.h> 50 #include <netinet/in.h> 51 #include <netinet/tcp.h> 52 #include <netinet/ip6.h> 53 #include <netinet/icmp6.h> 54 #include <netinet/sctp.h> 55 #include <net/if.h> 56 57 #include <inet/common.h> 58 #include <inet/ip.h> 59 #include <inet/ip_if.h> 60 #include <inet/ip_ire.h> 61 #include <inet/ip6.h> 62 #include <inet/mi.h> 63 #include <inet/mib2.h> 64 #include <inet/kstatcom.h> 65 #include <inet/nd.h> 66 #include <inet/optcom.h> 67 #include <inet/ipclassifier.h> 68 #include <inet/ipsec_impl.h> 69 #include <inet/sctp_ip.h> 70 #include <inet/sctp_crc32.h> 71 72 #include "sctp_impl.h" 73 #include "sctp_addr.h" 74 #include "sctp_asconf.h" 75 76 int sctpdebug; 77 sin6_t sctp_sin6_null; /* Zero address for quick clears */ 78 79 static void sctp_closei_local(sctp_t *sctp); 80 static int sctp_init_values(sctp_t *, sctp_t *, int); 81 static void sctp_icmp_error_ipv6(sctp_t *sctp, mblk_t *mp); 82 static void sctp_process_recvq(void *); 83 static void sctp_rq_tq_init(sctp_stack_t *); 84 static void sctp_rq_tq_fini(sctp_stack_t *); 85 static void sctp_conn_cache_init(); 86 static void sctp_conn_cache_fini(); 87 static int sctp_conn_cache_constructor(); 88 static void sctp_conn_cache_destructor(); 89 static void sctp_conn_clear(conn_t *); 90 static void sctp_notify(void *, ip_xmit_attr_t *, ixa_notify_type_t, 91 ixa_notify_arg_t); 92 93 static void *sctp_stack_init(netstackid_t stackid, netstack_t *ns); 94 static void sctp_stack_fini(netstackid_t stackid, void *arg); 95 96 /* 97 * SCTP receive queue taskq 98 * 99 * At SCTP initialization time, a default taskq is created for 100 * servicing packets received when the interrupt thread cannot 101 * get a hold on the sctp_t. The number of taskq can be increased in 102 * sctp_find_next_tq() when an existing taskq cannot be dispatched. 103 * The taskqs are never removed. But the max number of taskq which 104 * can be created is controlled by sctp_recvq_tq_list_max_sz. Note 105 * that SCTP recvq taskq is not tied to any specific CPU or ill. 106 * 107 * Those taskqs are stored in an array recvq_tq_list. And they are 108 * used in a round robin fashion. The current taskq being used is 109 * determined by recvq_tq_list_cur. 110 */ 111 112 /* /etc/system variables */ 113 /* The minimum number of threads for each taskq. */ 114 int sctp_recvq_tq_thr_min = 4; 115 /* The maximum number of threads for each taskq. */ 116 int sctp_recvq_tq_thr_max = 16; 117 /* The minimum number of tasks for each taskq. */ 118 int sctp_recvq_tq_task_min = 5; 119 /* The maxiimum number of tasks for each taskq. */ 120 int sctp_recvq_tq_task_max = 50; 121 122 /* sctp_t/conn_t kmem cache */ 123 struct kmem_cache *sctp_conn_cache; 124 125 #define SCTP_CONDEMNED(sctp) \ 126 mutex_enter(&(sctp)->sctp_reflock); \ 127 ((sctp)->sctp_condemned = B_TRUE); \ 128 mutex_exit(&(sctp)->sctp_reflock); 129 130 /* Link/unlink a sctp_t to/from the global list. */ 131 #define SCTP_LINK(sctp, sctps) \ 132 mutex_enter(&(sctps)->sctps_g_lock); \ 133 list_insert_tail(&sctps->sctps_g_list, (sctp)); \ 134 mutex_exit(&(sctps)->sctps_g_lock); 135 136 #define SCTP_UNLINK(sctp, sctps) \ 137 mutex_enter(&(sctps)->sctps_g_lock); \ 138 ASSERT((sctp)->sctp_condemned); \ 139 list_remove(&(sctps)->sctps_g_list, (sctp)); \ 140 mutex_exit(&(sctps)->sctps_g_lock); 141 142 /* 143 * Hooks for Sun Cluster. On non-clustered nodes these will remain NULL. 144 * PSARC/2005/602. 145 */ 146 void (*cl_sctp_listen)(sa_family_t, uchar_t *, uint_t, in_port_t) = NULL; 147 void (*cl_sctp_unlisten)(sa_family_t, uchar_t *, uint_t, in_port_t) = NULL; 148 void (*cl_sctp_connect)(sa_family_t, uchar_t *, uint_t, in_port_t, 149 uchar_t *, uint_t, in_port_t, boolean_t, cl_sctp_handle_t) = NULL; 150 void (*cl_sctp_disconnect)(sa_family_t, cl_sctp_handle_t) = NULL; 151 void (*cl_sctp_assoc_change)(sa_family_t, uchar_t *, size_t, uint_t, 152 uchar_t *, size_t, uint_t, int, cl_sctp_handle_t) = NULL; 153 void (*cl_sctp_check_addrs)(sa_family_t, in_port_t, uchar_t **, size_t, 154 uint_t *, boolean_t) = NULL; 155 /* 156 * Return the version number of the SCTP kernel interface. 157 */ 158 int 159 sctp_itf_ver(int cl_ver) 160 { 161 if (cl_ver != SCTP_ITF_VER) 162 return (-1); 163 return (SCTP_ITF_VER); 164 } 165 166 /* 167 * Called when we need a new sctp instantiation but don't really have a 168 * new q to hang it off of. Copy the priv flag from the passed in structure. 169 */ 170 sctp_t * 171 sctp_create_eager(sctp_t *psctp) 172 { 173 sctp_t *sctp; 174 mblk_t *ack_mp, *hb_mp; 175 conn_t *connp; 176 cred_t *credp; 177 sctp_stack_t *sctps = psctp->sctp_sctps; 178 179 if ((connp = ipcl_conn_create(IPCL_SCTPCONN, KM_NOSLEEP, 180 sctps->sctps_netstack)) == NULL) { 181 return (NULL); 182 } 183 184 sctp = CONN2SCTP(connp); 185 sctp->sctp_sctps = sctps; 186 187 if ((ack_mp = sctp_timer_alloc(sctp, sctp_ack_timer, 188 KM_NOSLEEP)) == NULL || 189 (hb_mp = sctp_timer_alloc(sctp, sctp_heartbeat_timer, 190 KM_NOSLEEP)) == NULL) { 191 if (ack_mp != NULL) 192 freeb(ack_mp); 193 sctp_conn_clear(connp); 194 sctp->sctp_sctps = NULL; 195 kmem_cache_free(sctp_conn_cache, connp); 196 return (NULL); 197 } 198 199 sctp->sctp_ack_mp = ack_mp; 200 sctp->sctp_heartbeat_mp = hb_mp; 201 202 if (sctp_init_values(sctp, psctp, KM_NOSLEEP) != 0) { 203 freeb(ack_mp); 204 freeb(hb_mp); 205 sctp_conn_clear(connp); 206 sctp->sctp_sctps = NULL; 207 kmem_cache_free(sctp_conn_cache, connp); 208 return (NULL); 209 } 210 211 if ((credp = psctp->sctp_connp->conn_cred) != NULL) { 212 connp->conn_cred = credp; 213 crhold(credp); 214 } 215 216 sctp->sctp_mss = psctp->sctp_mss; 217 sctp->sctp_detached = B_TRUE; 218 /* 219 * Link to the global as soon as possible so that this sctp_t 220 * can be found. 221 */ 222 SCTP_LINK(sctp, sctps); 223 224 return (sctp); 225 } 226 227 /* 228 * We are dying for some reason. Try to do it gracefully. 229 */ 230 void 231 sctp_clean_death(sctp_t *sctp, int err) 232 { 233 ASSERT(sctp != NULL); 234 235 dprint(3, ("sctp_clean_death %p, state %d\n", (void *)sctp, 236 sctp->sctp_state)); 237 238 sctp->sctp_client_errno = err; 239 /* 240 * Check to see if we need to notify upper layer. 241 */ 242 if ((sctp->sctp_state >= SCTPS_COOKIE_WAIT) && 243 !SCTP_IS_DETACHED(sctp)) { 244 if (sctp->sctp_xmit_head || sctp->sctp_xmit_unsent) { 245 sctp_regift_xmitlist(sctp); 246 } 247 if (sctp->sctp_ulp_disconnected(sctp->sctp_ulpd, 0, err)) { 248 /* 249 * Socket is gone, detach. 250 */ 251 sctp->sctp_detached = B_TRUE; 252 sctp->sctp_ulpd = NULL; 253 sctp->sctp_upcalls = NULL; 254 } 255 } 256 257 /* Remove this sctp from all hashes. */ 258 sctp_closei_local(sctp); 259 260 /* 261 * If the sctp_t is detached, we need to finish freeing up 262 * the resources. At this point, ip_fanout_sctp() should have 263 * a hold on this sctp_t. Some thread doing snmp stuff can 264 * have a hold. And a taskq can also have a hold waiting to 265 * work. sctp_unlink() the sctp_t from the global list so 266 * that no new thread can find it. Then do a SCTP_REFRELE(). 267 * The sctp_t will be freed after all those threads are done. 268 */ 269 if (SCTP_IS_DETACHED(sctp)) { 270 SCTP_CONDEMNED(sctp); 271 SCTP_REFRELE(sctp); 272 } 273 } 274 275 /* 276 * Called by upper layer when it wants to close this association. 277 * Depending on the state of this assoication, we need to do 278 * different things. 279 * 280 * If the state is below COOKIE_ECHOED or it is COOKIE_ECHOED but with 281 * no sent data, just remove this sctp from all the hashes. This 282 * makes sure that all packets from the other end will go to the default 283 * sctp handling. The upper layer will then do a sctp_close() to clean 284 * up. 285 * 286 * Otherwise, check and see if SO_LINGER is set. If it is set, check 287 * the value. If the value is 0, consider this an abortive close. Send 288 * an ABORT message and kill the associatiion. 289 * 290 */ 291 int 292 sctp_disconnect(sctp_t *sctp) 293 { 294 int error = 0; 295 conn_t *connp = sctp->sctp_connp; 296 297 dprint(3, ("sctp_disconnect %p, state %d\n", (void *)sctp, 298 sctp->sctp_state)); 299 300 RUN_SCTP(sctp); 301 302 switch (sctp->sctp_state) { 303 case SCTPS_IDLE: 304 case SCTPS_BOUND: 305 case SCTPS_LISTEN: 306 break; 307 case SCTPS_COOKIE_WAIT: 308 case SCTPS_COOKIE_ECHOED: 309 /* 310 * Close during the connect 3-way handshake 311 * but here there may or may not be pending data 312 * already on queue. Process almost same as in 313 * the ESTABLISHED state. 314 */ 315 if (sctp->sctp_xmit_head == NULL && 316 sctp->sctp_xmit_unsent == NULL) { 317 break; 318 } 319 /* FALLTHRU */ 320 default: 321 /* 322 * If SO_LINGER has set a zero linger time, terminate the 323 * association and send an ABORT. 324 */ 325 if (connp->conn_linger && connp->conn_lingertime == 0) { 326 sctp_user_abort(sctp, NULL); 327 WAKE_SCTP(sctp); 328 return (error); 329 } 330 331 /* 332 * In there is unread data, send an ABORT and terminate the 333 * association. 334 */ 335 if (sctp->sctp_rxqueued > 0 || sctp->sctp_irwnd > 336 sctp->sctp_rwnd) { 337 sctp_user_abort(sctp, NULL); 338 WAKE_SCTP(sctp); 339 return (error); 340 } 341 /* 342 * Transmit the shutdown before detaching the sctp_t. 343 * After sctp_detach returns this queue/perimeter 344 * no longer owns the sctp_t thus others can modify it. 345 */ 346 sctp_send_shutdown(sctp, 0); 347 348 /* Pass gathered wisdom to IP for keeping */ 349 sctp_update_dce(sctp); 350 351 /* 352 * If lingering on close then wait until the shutdown 353 * is complete, or the SO_LINGER time passes, or an 354 * ABORT is sent/received. Note that sctp_disconnect() 355 * can be called more than once. Make sure that only 356 * one thread waits. 357 */ 358 if (connp->conn_linger && connp->conn_lingertime > 0 && 359 sctp->sctp_state >= SCTPS_ESTABLISHED && 360 !sctp->sctp_lingering) { 361 clock_t stoptime; /* in ticks */ 362 clock_t ret; 363 364 sctp->sctp_lingering = 1; 365 sctp->sctp_client_errno = 0; 366 stoptime = lbolt + connp->conn_lingertime * hz; 367 368 mutex_enter(&sctp->sctp_lock); 369 sctp->sctp_running = B_FALSE; 370 while (sctp->sctp_state >= SCTPS_ESTABLISHED && 371 sctp->sctp_client_errno == 0) { 372 cv_broadcast(&sctp->sctp_cv); 373 ret = cv_timedwait_sig(&sctp->sctp_cv, 374 &sctp->sctp_lock, stoptime); 375 if (ret < 0) { 376 /* Stoptime has reached. */ 377 sctp->sctp_client_errno = EWOULDBLOCK; 378 break; 379 } else if (ret == 0) { 380 /* Got a signal. */ 381 break; 382 } 383 } 384 error = sctp->sctp_client_errno; 385 sctp->sctp_client_errno = 0; 386 mutex_exit(&sctp->sctp_lock); 387 } 388 389 WAKE_SCTP(sctp); 390 return (error); 391 } 392 393 394 /* Remove this sctp from all hashes so nobody can find it. */ 395 sctp_closei_local(sctp); 396 WAKE_SCTP(sctp); 397 return (error); 398 } 399 400 void 401 sctp_close(sctp_t *sctp) 402 { 403 dprint(3, ("sctp_close %p, state %d\n", (void *)sctp, 404 sctp->sctp_state)); 405 406 RUN_SCTP(sctp); 407 sctp->sctp_detached = 1; 408 sctp->sctp_ulpd = NULL; 409 sctp->sctp_upcalls = NULL; 410 bzero(&sctp->sctp_events, sizeof (sctp->sctp_events)); 411 412 /* If the graceful shutdown has not been completed, just return. */ 413 if (sctp->sctp_state != SCTPS_IDLE) { 414 WAKE_SCTP(sctp); 415 return; 416 } 417 418 /* 419 * Since sctp_t is in SCTPS_IDLE state, so the only thread which 420 * can have a hold on the sctp_t is doing snmp stuff. Just do 421 * a SCTP_REFRELE() here after the SCTP_UNLINK(). It will 422 * be freed when the other thread is done. 423 */ 424 SCTP_CONDEMNED(sctp); 425 WAKE_SCTP(sctp); 426 SCTP_REFRELE(sctp); 427 } 428 429 /* 430 * Unlink from global list and do the eager close. 431 * Remove the refhold implicit in being on the global list. 432 */ 433 void 434 sctp_close_eager(sctp_t *sctp) 435 { 436 SCTP_CONDEMNED(sctp); 437 sctp_closei_local(sctp); 438 SCTP_REFRELE(sctp); 439 } 440 441 /* 442 * The sctp_t is going away. Remove it from all lists and set it 443 * to SCTPS_IDLE. The caller has to remove it from the 444 * global list. The freeing up of memory is deferred until 445 * sctp_free(). This is needed since a thread in sctp_input() might have 446 * done a SCTP_REFHOLD on this structure before it was removed from the 447 * hashes. 448 */ 449 static void 450 sctp_closei_local(sctp_t *sctp) 451 { 452 mblk_t *mp; 453 conn_t *connp = sctp->sctp_connp; 454 455 /* Sanity check, don't do the same thing twice. */ 456 if (connp->conn_state_flags & CONN_CLOSING) { 457 ASSERT(sctp->sctp_state == SCTPS_IDLE); 458 return; 459 } 460 461 /* Stop and free the timers */ 462 sctp_free_faddr_timers(sctp); 463 if ((mp = sctp->sctp_heartbeat_mp) != NULL) { 464 sctp_timer_free(mp); 465 sctp->sctp_heartbeat_mp = NULL; 466 } 467 if ((mp = sctp->sctp_ack_mp) != NULL) { 468 sctp_timer_free(mp); 469 sctp->sctp_ack_mp = NULL; 470 } 471 472 /* Set the CONN_CLOSING flag so that IP will not cache IRE again. */ 473 mutex_enter(&connp->conn_lock); 474 connp->conn_state_flags |= CONN_CLOSING; 475 mutex_exit(&connp->conn_lock); 476 477 /* Remove from all hashes. */ 478 sctp_bind_hash_remove(sctp); 479 sctp_conn_hash_remove(sctp); 480 sctp_listen_hash_remove(sctp); 481 sctp->sctp_state = SCTPS_IDLE; 482 483 /* 484 * Clean up the recvq as much as possible. All those packets 485 * will be silently dropped as this sctp_t is now in idle state. 486 */ 487 mutex_enter(&sctp->sctp_recvq_lock); 488 while ((mp = sctp->sctp_recvq) != NULL) { 489 sctp->sctp_recvq = mp->b_next; 490 mp->b_next = NULL; 491 492 if (ip_recv_attr_is_mblk(mp)) 493 mp = ip_recv_attr_free_mblk(mp); 494 495 freemsg(mp); 496 } 497 mutex_exit(&sctp->sctp_recvq_lock); 498 } 499 500 /* 501 * Free memory associated with the sctp/ip header template. 502 */ 503 static void 504 sctp_headers_free(sctp_t *sctp) 505 { 506 if (sctp->sctp_iphc != NULL) { 507 kmem_free(sctp->sctp_iphc, sctp->sctp_iphc_len); 508 sctp->sctp_iphc = NULL; 509 sctp->sctp_ipha = NULL; 510 sctp->sctp_hdr_len = 0; 511 sctp->sctp_ip_hdr_len = 0; 512 sctp->sctp_iphc_len = 0; 513 sctp->sctp_sctph = NULL; 514 sctp->sctp_hdr_len = 0; 515 } 516 if (sctp->sctp_iphc6 != NULL) { 517 kmem_free(sctp->sctp_iphc6, sctp->sctp_iphc6_len); 518 sctp->sctp_iphc6 = NULL; 519 sctp->sctp_ip6h = NULL; 520 sctp->sctp_hdr6_len = 0; 521 sctp->sctp_ip_hdr6_len = 0; 522 sctp->sctp_iphc6_len = 0; 523 sctp->sctp_sctph6 = NULL; 524 sctp->sctp_hdr6_len = 0; 525 } 526 } 527 528 static void 529 sctp_free_xmit_data(sctp_t *sctp) 530 { 531 mblk_t *ump = NULL; 532 mblk_t *nump; 533 mblk_t *mp; 534 mblk_t *nmp; 535 536 sctp->sctp_xmit_unacked = NULL; 537 ump = sctp->sctp_xmit_head; 538 sctp->sctp_xmit_tail = sctp->sctp_xmit_head = NULL; 539 free_unsent: 540 for (; ump != NULL; ump = nump) { 541 for (mp = ump->b_cont; mp != NULL; mp = nmp) { 542 nmp = mp->b_next; 543 mp->b_next = NULL; 544 mp->b_prev = NULL; 545 freemsg(mp); 546 } 547 ASSERT(DB_REF(ump) == 1); 548 nump = ump->b_next; 549 ump->b_next = NULL; 550 ump->b_prev = NULL; 551 ump->b_cont = NULL; 552 freeb(ump); 553 } 554 if ((ump = sctp->sctp_xmit_unsent) == NULL) { 555 ASSERT(sctp->sctp_xmit_unsent_tail == NULL); 556 return; 557 } 558 sctp->sctp_xmit_unsent = sctp->sctp_xmit_unsent_tail = NULL; 559 goto free_unsent; 560 } 561 562 /* 563 * Cleanup all the messages in the stream queue and the reassembly lists. 564 * If 'free' is true, then delete the streams as well. 565 */ 566 void 567 sctp_instream_cleanup(sctp_t *sctp, boolean_t free) 568 { 569 int i; 570 mblk_t *mp; 571 mblk_t *mp1; 572 573 if (sctp->sctp_instr != NULL) { 574 /* walk thru and flush out anything remaining in the Q */ 575 for (i = 0; i < sctp->sctp_num_istr; i++) { 576 mp = sctp->sctp_instr[i].istr_msgs; 577 while (mp != NULL) { 578 mp1 = mp->b_next; 579 mp->b_next = mp->b_prev = NULL; 580 freemsg(mp); 581 mp = mp1; 582 } 583 sctp->sctp_instr[i].istr_msgs = NULL; 584 sctp->sctp_instr[i].istr_nmsgs = 0; 585 sctp_free_reass((sctp->sctp_instr) + i); 586 sctp->sctp_instr[i].nextseq = 0; 587 } 588 if (free) { 589 kmem_free(sctp->sctp_instr, 590 sizeof (*sctp->sctp_instr) * sctp->sctp_num_istr); 591 sctp->sctp_instr = NULL; 592 sctp->sctp_num_istr = 0; 593 } 594 } 595 /* un-ordered fragments */ 596 if (sctp->sctp_uo_frags != NULL) { 597 for (mp = sctp->sctp_uo_frags; mp != NULL; mp = mp1) { 598 mp1 = mp->b_next; 599 mp->b_next = mp->b_prev = NULL; 600 freemsg(mp); 601 } 602 } 603 } 604 605 /* 606 * Last reference to the sctp_t is gone. Free all memory associated with it. 607 * Called from SCTP_REFRELE. Called inline in sctp_close() 608 */ 609 void 610 sctp_free(conn_t *connp) 611 { 612 sctp_t *sctp = CONN2SCTP(connp); 613 int cnt; 614 sctp_stack_t *sctps = sctp->sctp_sctps; 615 616 ASSERT(sctps != NULL); 617 /* Unlink it from the global list */ 618 SCTP_UNLINK(sctp, sctps); 619 620 ASSERT(connp->conn_ref == 0); 621 ASSERT(connp->conn_proto == IPPROTO_SCTP); 622 ASSERT(!MUTEX_HELD(&sctp->sctp_reflock)); 623 ASSERT(sctp->sctp_refcnt == 0); 624 625 ASSERT(sctp->sctp_ptpbhn == NULL && sctp->sctp_bind_hash == NULL); 626 ASSERT(sctp->sctp_conn_hash_next == NULL && 627 sctp->sctp_conn_hash_prev == NULL); 628 629 630 /* Free up all the resources. */ 631 632 /* blow away sctp stream management */ 633 if (sctp->sctp_ostrcntrs != NULL) { 634 kmem_free(sctp->sctp_ostrcntrs, 635 sizeof (uint16_t) * sctp->sctp_num_ostr); 636 sctp->sctp_ostrcntrs = NULL; 637 } 638 sctp_instream_cleanup(sctp, B_TRUE); 639 640 /* Remove all data transfer resources. */ 641 sctp->sctp_istr_nmsgs = 0; 642 sctp->sctp_rxqueued = 0; 643 sctp_free_xmit_data(sctp); 644 sctp->sctp_unacked = 0; 645 sctp->sctp_unsent = 0; 646 if (sctp->sctp_cxmit_list != NULL) 647 sctp_asconf_free_cxmit(sctp, NULL); 648 649 sctp->sctp_lastdata = NULL; 650 651 /* Clear out default xmit settings */ 652 sctp->sctp_def_stream = 0; 653 sctp->sctp_def_flags = 0; 654 sctp->sctp_def_ppid = 0; 655 sctp->sctp_def_context = 0; 656 sctp->sctp_def_timetolive = 0; 657 658 if (sctp->sctp_sack_info != NULL) { 659 sctp_free_set(sctp->sctp_sack_info); 660 sctp->sctp_sack_info = NULL; 661 } 662 sctp->sctp_sack_gaps = 0; 663 664 if (sctp->sctp_cookie_mp != NULL) { 665 freemsg(sctp->sctp_cookie_mp); 666 sctp->sctp_cookie_mp = NULL; 667 } 668 669 /* Remove all the address resources. */ 670 sctp_zap_addrs(sctp); 671 for (cnt = 0; cnt < SCTP_IPIF_HASH; cnt++) { 672 ASSERT(sctp->sctp_saddrs[cnt].ipif_count == 0); 673 list_destroy(&sctp->sctp_saddrs[cnt].sctp_ipif_list); 674 } 675 676 if (sctp->sctp_hopopts != NULL) { 677 mi_free(sctp->sctp_hopopts); 678 sctp->sctp_hopopts = NULL; 679 sctp->sctp_hopoptslen = 0; 680 } 681 ASSERT(sctp->sctp_hopoptslen == 0); 682 if (sctp->sctp_dstopts != NULL) { 683 mi_free(sctp->sctp_dstopts); 684 sctp->sctp_dstopts = NULL; 685 sctp->sctp_dstoptslen = 0; 686 } 687 ASSERT(sctp->sctp_dstoptslen == 0); 688 if (sctp->sctp_rthdrdstopts != NULL) { 689 mi_free(sctp->sctp_rthdrdstopts); 690 sctp->sctp_rthdrdstopts = NULL; 691 sctp->sctp_rthdrdstoptslen = 0; 692 } 693 ASSERT(sctp->sctp_rthdrdstoptslen == 0); 694 if (sctp->sctp_rthdr != NULL) { 695 mi_free(sctp->sctp_rthdr); 696 sctp->sctp_rthdr = NULL; 697 sctp->sctp_rthdrlen = 0; 698 } 699 ASSERT(sctp->sctp_rthdrlen == 0); 700 sctp_headers_free(sctp); 701 702 sctp->sctp_shutdown_faddr = NULL; 703 704 if (sctp->sctp_err_chunks != NULL) { 705 freemsg(sctp->sctp_err_chunks); 706 sctp->sctp_err_chunks = NULL; 707 sctp->sctp_err_len = 0; 708 } 709 710 /* Clear all the bitfields. */ 711 bzero(&sctp->sctp_bits, sizeof (sctp->sctp_bits)); 712 713 /* It is time to update the global statistics. */ 714 UPDATE_MIB(&sctps->sctps_mib, sctpOutSCTPPkts, sctp->sctp_opkts); 715 UPDATE_MIB(&sctps->sctps_mib, sctpOutCtrlChunks, sctp->sctp_obchunks); 716 UPDATE_MIB(&sctps->sctps_mib, sctpOutOrderChunks, sctp->sctp_odchunks); 717 UPDATE_MIB(&sctps->sctps_mib, 718 sctpOutUnorderChunks, sctp->sctp_oudchunks); 719 UPDATE_MIB(&sctps->sctps_mib, sctpRetransChunks, sctp->sctp_rxtchunks); 720 UPDATE_MIB(&sctps->sctps_mib, sctpInSCTPPkts, sctp->sctp_ipkts); 721 UPDATE_MIB(&sctps->sctps_mib, sctpInCtrlChunks, sctp->sctp_ibchunks); 722 UPDATE_MIB(&sctps->sctps_mib, sctpInOrderChunks, sctp->sctp_idchunks); 723 UPDATE_MIB(&sctps->sctps_mib, 724 sctpInUnorderChunks, sctp->sctp_iudchunks); 725 UPDATE_MIB(&sctps->sctps_mib, sctpFragUsrMsgs, sctp->sctp_fragdmsgs); 726 UPDATE_MIB(&sctps->sctps_mib, sctpReasmUsrMsgs, sctp->sctp_reassmsgs); 727 sctp->sctp_opkts = 0; 728 sctp->sctp_obchunks = 0; 729 sctp->sctp_odchunks = 0; 730 sctp->sctp_oudchunks = 0; 731 sctp->sctp_rxtchunks = 0; 732 sctp->sctp_ipkts = 0; 733 sctp->sctp_ibchunks = 0; 734 sctp->sctp_idchunks = 0; 735 sctp->sctp_iudchunks = 0; 736 sctp->sctp_fragdmsgs = 0; 737 sctp->sctp_reassmsgs = 0; 738 sctp->sctp_outseqtsns = 0; 739 sctp->sctp_osacks = 0; 740 sctp->sctp_isacks = 0; 741 sctp->sctp_idupchunks = 0; 742 sctp->sctp_gapcnt = 0; 743 sctp->sctp_cum_obchunks = 0; 744 sctp->sctp_cum_odchunks = 0; 745 sctp->sctp_cum_oudchunks = 0; 746 sctp->sctp_cum_rxtchunks = 0; 747 sctp->sctp_cum_ibchunks = 0; 748 sctp->sctp_cum_idchunks = 0; 749 sctp->sctp_cum_iudchunks = 0; 750 751 sctp->sctp_autoclose = 0; 752 sctp->sctp_tx_adaptation_code = 0; 753 754 sctp->sctp_v6label_len = 0; 755 sctp->sctp_v4label_len = 0; 756 757 sctp->sctp_sctps = NULL; 758 759 sctp_conn_clear(connp); 760 kmem_cache_free(sctp_conn_cache, connp); 761 } 762 763 /* Diagnostic routine used to return a string associated with the sctp state. */ 764 char * 765 sctp_display(sctp_t *sctp, char *sup_buf) 766 { 767 char *buf; 768 char buf1[30]; 769 static char priv_buf[INET6_ADDRSTRLEN * 2 + 80]; 770 char *cp; 771 conn_t *connp; 772 773 if (sctp == NULL) 774 return ("NULL_SCTP"); 775 776 connp = sctp->sctp_connp; 777 buf = (sup_buf != NULL) ? sup_buf : priv_buf; 778 779 switch (sctp->sctp_state) { 780 case SCTPS_IDLE: 781 cp = "SCTP_IDLE"; 782 break; 783 case SCTPS_BOUND: 784 cp = "SCTP_BOUND"; 785 break; 786 case SCTPS_LISTEN: 787 cp = "SCTP_LISTEN"; 788 break; 789 case SCTPS_COOKIE_WAIT: 790 cp = "SCTP_COOKIE_WAIT"; 791 break; 792 case SCTPS_COOKIE_ECHOED: 793 cp = "SCTP_COOKIE_ECHOED"; 794 break; 795 case SCTPS_ESTABLISHED: 796 cp = "SCTP_ESTABLISHED"; 797 break; 798 case SCTPS_SHUTDOWN_PENDING: 799 cp = "SCTP_SHUTDOWN_PENDING"; 800 break; 801 case SCTPS_SHUTDOWN_SENT: 802 cp = "SCTPS_SHUTDOWN_SENT"; 803 break; 804 case SCTPS_SHUTDOWN_RECEIVED: 805 cp = "SCTPS_SHUTDOWN_RECEIVED"; 806 break; 807 case SCTPS_SHUTDOWN_ACK_SENT: 808 cp = "SCTPS_SHUTDOWN_ACK_SENT"; 809 break; 810 default: 811 (void) mi_sprintf(buf1, "SCTPUnkState(%d)", sctp->sctp_state); 812 cp = buf1; 813 break; 814 } 815 (void) mi_sprintf(buf, "[%u, %u] %s", 816 ntohs(connp->conn_lport), ntohs(connp->conn_fport), cp); 817 818 return (buf); 819 } 820 821 /* 822 * Initialize protocol control block. If a parent exists, inherit 823 * all values set through setsockopt(). 824 */ 825 static int 826 sctp_init_values(sctp_t *sctp, sctp_t *psctp, int sleep) 827 { 828 int err; 829 int cnt; 830 sctp_stack_t *sctps = sctp->sctp_sctps; 831 conn_t *connp; 832 833 connp = sctp->sctp_connp; 834 835 sctp->sctp_nsaddrs = 0; 836 for (cnt = 0; cnt < SCTP_IPIF_HASH; cnt++) { 837 sctp->sctp_saddrs[cnt].ipif_count = 0; 838 list_create(&sctp->sctp_saddrs[cnt].sctp_ipif_list, 839 sizeof (sctp_saddr_ipif_t), offsetof(sctp_saddr_ipif_t, 840 saddr_ipif)); 841 } 842 connp->conn_ports = 0; 843 sctp->sctp_running = B_FALSE; 844 sctp->sctp_state = SCTPS_IDLE; 845 846 sctp->sctp_refcnt = 1; 847 848 sctp->sctp_strikes = 0; 849 850 sctp->sctp_last_mtu_probe = lbolt64; 851 sctp->sctp_mtu_probe_intvl = sctps->sctps_mtu_probe_interval; 852 853 sctp->sctp_sack_gaps = 0; 854 sctp->sctp_sack_toggle = 2; 855 856 /* Only need to do the allocation if there is no "cached" one. */ 857 if (sctp->sctp_pad_mp == NULL) { 858 if (sleep == KM_SLEEP) { 859 sctp->sctp_pad_mp = allocb_wait(SCTP_ALIGN, BPRI_MED, 860 STR_NOSIG, NULL); 861 } else { 862 sctp->sctp_pad_mp = allocb(SCTP_ALIGN, BPRI_MED); 863 if (sctp->sctp_pad_mp == NULL) 864 return (ENOMEM); 865 } 866 bzero(sctp->sctp_pad_mp->b_rptr, SCTP_ALIGN); 867 } 868 869 if (psctp != NULL) { 870 /* 871 * Inherit from parent 872 * 873 * Start by inheriting from the conn_t, including conn_ixa and 874 * conn_xmit_ipp. 875 */ 876 err = conn_inherit_parent(psctp->sctp_connp, connp); 877 if (err != 0) 878 goto failure; 879 880 sctp->sctp_cookie_lifetime = psctp->sctp_cookie_lifetime; 881 882 sctp->sctp_cwnd_max = psctp->sctp_cwnd_max; 883 sctp->sctp_rwnd = psctp->sctp_rwnd; 884 sctp->sctp_irwnd = psctp->sctp_rwnd; 885 sctp->sctp_pd_point = psctp->sctp_pd_point; 886 sctp->sctp_rto_max = psctp->sctp_rto_max; 887 sctp->sctp_init_rto_max = psctp->sctp_init_rto_max; 888 sctp->sctp_rto_min = psctp->sctp_rto_min; 889 sctp->sctp_rto_initial = psctp->sctp_rto_initial; 890 sctp->sctp_pa_max_rxt = psctp->sctp_pa_max_rxt; 891 sctp->sctp_pp_max_rxt = psctp->sctp_pp_max_rxt; 892 sctp->sctp_max_init_rxt = psctp->sctp_max_init_rxt; 893 894 sctp->sctp_def_stream = psctp->sctp_def_stream; 895 sctp->sctp_def_flags = psctp->sctp_def_flags; 896 sctp->sctp_def_ppid = psctp->sctp_def_ppid; 897 sctp->sctp_def_context = psctp->sctp_def_context; 898 sctp->sctp_def_timetolive = psctp->sctp_def_timetolive; 899 900 sctp->sctp_num_istr = psctp->sctp_num_istr; 901 sctp->sctp_num_ostr = psctp->sctp_num_ostr; 902 903 sctp->sctp_hb_interval = psctp->sctp_hb_interval; 904 sctp->sctp_autoclose = psctp->sctp_autoclose; 905 sctp->sctp_tx_adaptation_code = psctp->sctp_tx_adaptation_code; 906 907 /* xxx should be a better way to copy these flags xxx */ 908 sctp->sctp_bound_to_all = psctp->sctp_bound_to_all; 909 sctp->sctp_cansleep = psctp->sctp_cansleep; 910 sctp->sctp_send_adaptation = psctp->sctp_send_adaptation; 911 sctp->sctp_ndelay = psctp->sctp_ndelay; 912 sctp->sctp_events = psctp->sctp_events; 913 } else { 914 /* 915 * Set to system defaults 916 */ 917 sctp->sctp_cookie_lifetime = 918 MSEC_TO_TICK(sctps->sctps_cookie_life); 919 connp->conn_sndlowat = sctps->sctps_xmit_lowat; 920 connp->conn_sndbuf = sctps->sctps_xmit_hiwat; 921 connp->conn_rcvbuf = sctps->sctps_recv_hiwat; 922 923 sctp->sctp_cwnd_max = sctps->sctps_cwnd_max_; 924 sctp->sctp_rwnd = connp->conn_rcvbuf; 925 sctp->sctp_irwnd = sctp->sctp_rwnd; 926 sctp->sctp_pd_point = sctp->sctp_rwnd; 927 sctp->sctp_rto_max = MSEC_TO_TICK(sctps->sctps_rto_maxg); 928 sctp->sctp_init_rto_max = sctp->sctp_rto_max; 929 sctp->sctp_rto_min = MSEC_TO_TICK(sctps->sctps_rto_ming); 930 sctp->sctp_rto_initial = MSEC_TO_TICK( 931 sctps->sctps_rto_initialg); 932 sctp->sctp_pa_max_rxt = sctps->sctps_pa_max_retr; 933 sctp->sctp_pp_max_rxt = sctps->sctps_pp_max_retr; 934 sctp->sctp_max_init_rxt = sctps->sctps_max_init_retr; 935 936 sctp->sctp_num_istr = sctps->sctps_max_in_streams; 937 sctp->sctp_num_ostr = sctps->sctps_initial_out_streams; 938 939 sctp->sctp_hb_interval = 940 MSEC_TO_TICK(sctps->sctps_heartbeat_interval); 941 942 if (connp->conn_family == AF_INET) 943 connp->conn_default_ttl = sctps->sctps_ipv4_ttl; 944 else 945 connp->conn_default_ttl = sctps->sctps_ipv6_hoplimit; 946 947 connp->conn_xmit_ipp.ipp_unicast_hops = 948 connp->conn_default_ttl; 949 950 /* 951 * Initialize the header template 952 */ 953 if ((err = sctp_build_hdrs(sctp, sleep)) != 0) { 954 goto failure; 955 } 956 } 957 958 sctp->sctp_understands_asconf = B_TRUE; 959 sctp->sctp_understands_addip = B_TRUE; 960 sctp->sctp_prsctp_aware = B_FALSE; 961 962 sctp->sctp_connp->conn_ref = 1; 963 964 sctp->sctp_prsctpdrop = 0; 965 sctp->sctp_msgcount = 0; 966 967 return (0); 968 969 failure: 970 sctp_headers_free(sctp); 971 return (err); 972 } 973 974 /* 975 * Extracts the init tag from an INIT chunk and checks if it matches 976 * the sctp's verification tag. Returns 0 if it doesn't match, 1 if 977 * it does. 978 */ 979 static boolean_t 980 sctp_icmp_verf(sctp_t *sctp, sctp_hdr_t *sh, mblk_t *mp) 981 { 982 sctp_chunk_hdr_t *sch; 983 uint32_t verf, *vp; 984 985 sch = (sctp_chunk_hdr_t *)(sh + 1); 986 vp = (uint32_t *)(sch + 1); 987 988 /* Need at least the data chunk hdr and the first 4 bytes of INIT */ 989 if ((unsigned char *)(vp + 1) > mp->b_wptr) { 990 return (B_FALSE); 991 } 992 993 bcopy(vp, &verf, sizeof (verf)); 994 995 if (verf == sctp->sctp_lvtag) { 996 return (B_TRUE); 997 } 998 return (B_FALSE); 999 } 1000 1001 /* 1002 * Update the SCTP state according to change of PMTU. 1003 * 1004 * Path MTU might have changed by either increase or decrease, so need to 1005 * adjust the MSS based on the value of ixa_pmtu. 1006 */ 1007 static void 1008 sctp_update_pmtu(sctp_t *sctp, sctp_faddr_t *fp, boolean_t decrease_only) 1009 { 1010 uint32_t pmtu; 1011 int32_t mss; 1012 ip_xmit_attr_t *ixa = fp->ixa; 1013 1014 if (sctp->sctp_state < SCTPS_ESTABLISHED) 1015 return; 1016 1017 /* 1018 * Always call ip_get_pmtu() to make sure that IP has updated 1019 * ixa_flags properly. 1020 */ 1021 pmtu = ip_get_pmtu(ixa); 1022 1023 /* 1024 * Calculate the MSS by decreasing the PMTU by sctp_hdr_len and 1025 * IPsec overhead if applied. Make sure to use the most recent 1026 * IPsec information. 1027 */ 1028 mss = pmtu - conn_ipsec_length(sctp->sctp_connp); 1029 if (ixa->ixa_flags & IXAF_IS_IPV4) 1030 mss -= sctp->sctp_hdr_len; 1031 else 1032 mss -= sctp->sctp_hdr6_len; 1033 1034 /* 1035 * Nothing to change, so just return. 1036 */ 1037 if (mss == fp->sfa_pmss) 1038 return; 1039 1040 /* 1041 * Currently, for ICMP errors, only PMTU decrease is handled. 1042 */ 1043 if (mss > fp->sfa_pmss && decrease_only) 1044 return; 1045 1046 #ifdef DEBUG 1047 (void) printf("sctp_update_pmtu mss from %d to %d\n", 1048 fp->sfa_pmss, mss); 1049 #endif 1050 DTRACE_PROBE2(sctp_update_pmtu, int32_t, fp->sfa_pmss, uint32_t, mss); 1051 1052 /* 1053 * Update ixa_fragsize and ixa_pmtu. 1054 */ 1055 ixa->ixa_fragsize = ixa->ixa_pmtu = pmtu; 1056 1057 /* 1058 * Make sure that sfa_pmss is a multiple of 1059 * SCTP_ALIGN. 1060 */ 1061 fp->sfa_pmss = mss & ~(SCTP_ALIGN - 1); 1062 fp->pmtu_discovered = 1; 1063 1064 #ifdef notyet 1065 if (mss < sctp->sctp_sctps->sctps_mss_min) 1066 ixa->ixa_flags |= IXAF_PMTU_TOO_SMALL; 1067 #endif 1068 if (ixa->ixa_flags & IXAF_PMTU_TOO_SMALL) 1069 ixa->ixa_flags &= ~(IXAF_DONTFRAG | IXAF_PMTU_IPV4_DF); 1070 1071 /* 1072 * If below the min size then ip_get_pmtu cleared IXAF_PMTU_IPV4_DF. 1073 * Make sure to clear IXAF_DONTFRAG, which is used by IP to decide 1074 * whether to fragment the packet. 1075 */ 1076 if (ixa->ixa_flags & IXAF_IS_IPV4) { 1077 if (!(ixa->ixa_flags & IXAF_PMTU_IPV4_DF)) { 1078 fp->df = B_FALSE; 1079 if (fp == sctp->sctp_current) { 1080 sctp->sctp_ipha-> 1081 ipha_fragment_offset_and_flags = 0; 1082 } 1083 } 1084 } 1085 } 1086 1087 /* 1088 * Notify function registered with ip_xmit_attr_t. It's called in the context 1089 * of conn_ip_output so it's safe to update the SCTP state. 1090 * Currently only used for pmtu changes. 1091 */ 1092 /* ARGSUSED1 */ 1093 static void 1094 sctp_notify(void *arg, ip_xmit_attr_t *ixa, ixa_notify_type_t ntype, 1095 ixa_notify_arg_t narg) 1096 { 1097 sctp_t *sctp = (sctp_t *)arg; 1098 sctp_faddr_t *fp; 1099 1100 switch (ntype) { 1101 case IXAN_PMTU: 1102 /* Find the faddr based on the ip_xmit_attr_t pointer */ 1103 for (fp = sctp->sctp_faddrs; fp != NULL; fp = fp->next) { 1104 if (fp->ixa == ixa) 1105 break; 1106 } 1107 if (fp != NULL) 1108 sctp_update_pmtu(sctp, fp, B_FALSE); 1109 break; 1110 default: 1111 break; 1112 } 1113 } 1114 1115 /* 1116 * sctp_icmp_error is called by sctp_input() to process ICMP error messages 1117 * passed up by IP. We need to find a sctp_t 1118 * that corresponds to the returned datagram. Passes the message back in on 1119 * the correct queue once it has located the connection. 1120 * Assumes that IP has pulled up everything up to and including 1121 * the ICMP header. 1122 */ 1123 void 1124 sctp_icmp_error(sctp_t *sctp, mblk_t *mp) 1125 { 1126 icmph_t *icmph; 1127 ipha_t *ipha; 1128 int iph_hdr_length; 1129 sctp_hdr_t *sctph; 1130 in6_addr_t dst; 1131 sctp_faddr_t *fp; 1132 sctp_stack_t *sctps = sctp->sctp_sctps; 1133 1134 dprint(1, ("sctp_icmp_error: sctp=%p, mp=%p\n", (void *)sctp, 1135 (void *)mp)); 1136 1137 ipha = (ipha_t *)mp->b_rptr; 1138 if (IPH_HDR_VERSION(ipha) != IPV4_VERSION) { 1139 ASSERT(IPH_HDR_VERSION(ipha) == IPV6_VERSION); 1140 sctp_icmp_error_ipv6(sctp, mp); 1141 return; 1142 } 1143 1144 /* account for the ip hdr from the icmp message */ 1145 iph_hdr_length = IPH_HDR_LENGTH(ipha); 1146 icmph = (icmph_t *)&mp->b_rptr[iph_hdr_length]; 1147 /* now the ip hdr of message resulting in this icmp */ 1148 ipha = (ipha_t *)&icmph[1]; 1149 iph_hdr_length = IPH_HDR_LENGTH(ipha); 1150 sctph = (sctp_hdr_t *)((char *)ipha + iph_hdr_length); 1151 /* first_mp must expose the full sctp header. */ 1152 if ((uchar_t *)(sctph + 1) >= mp->b_wptr) { 1153 /* not enough data for SCTP header */ 1154 freemsg(mp); 1155 return; 1156 } 1157 1158 switch (icmph->icmph_type) { 1159 case ICMP_DEST_UNREACHABLE: 1160 switch (icmph->icmph_code) { 1161 case ICMP_FRAGMENTATION_NEEDED: 1162 /* 1163 * Reduce the MSS based on the new MTU. This will 1164 * eliminate any fragmentation locally. 1165 * N.B. There may well be some funny side-effects on 1166 * the local send policy and the remote receive policy. 1167 * Pending further research, we provide 1168 * sctp_ignore_path_mtu just in case this proves 1169 * disastrous somewhere. 1170 * 1171 * After updating the MSS, retransmit part of the 1172 * dropped segment using the new mss by calling 1173 * sctp_wput_slow(). Need to adjust all those 1174 * params to make sure sctp_wput_slow() work properly. 1175 */ 1176 if (sctps->sctps_ignore_path_mtu) 1177 break; 1178 1179 /* find the offending faddr */ 1180 IN6_IPADDR_TO_V4MAPPED(ipha->ipha_dst, &dst); 1181 fp = sctp_lookup_faddr(sctp, &dst); 1182 if (fp == NULL) { 1183 break; 1184 } 1185 sctp_update_pmtu(sctp, fp, B_TRUE); 1186 /* 1187 * It is possible, even likely that a fast retransmit 1188 * attempt has been dropped by ip as a result of this 1189 * error, retransmission bundles as much as possible. 1190 * A retransmit here prevents significant delays waiting 1191 * on the timer. Analogous to behaviour of TCP after 1192 * ICMP too big. 1193 */ 1194 sctp_rexmit(sctp, fp); 1195 break; 1196 case ICMP_PORT_UNREACHABLE: 1197 case ICMP_PROTOCOL_UNREACHABLE: 1198 switch (sctp->sctp_state) { 1199 case SCTPS_COOKIE_WAIT: 1200 case SCTPS_COOKIE_ECHOED: 1201 /* make sure the verification tag matches */ 1202 if (!sctp_icmp_verf(sctp, sctph, mp)) { 1203 break; 1204 } 1205 BUMP_MIB(&sctps->sctps_mib, sctpAborted); 1206 sctp_assoc_event(sctp, SCTP_CANT_STR_ASSOC, 0, 1207 NULL); 1208 sctp_clean_death(sctp, ECONNREFUSED); 1209 break; 1210 } 1211 break; 1212 case ICMP_HOST_UNREACHABLE: 1213 case ICMP_NET_UNREACHABLE: 1214 /* Record the error in case we finally time out. */ 1215 sctp->sctp_client_errno = (icmph->icmph_code == 1216 ICMP_HOST_UNREACHABLE) ? EHOSTUNREACH : ENETUNREACH; 1217 break; 1218 default: 1219 break; 1220 } 1221 break; 1222 case ICMP_SOURCE_QUENCH: { 1223 /* Reduce the sending rate as if we got a retransmit timeout */ 1224 break; 1225 } 1226 } 1227 freemsg(mp); 1228 } 1229 1230 /* 1231 * sctp_icmp_error_ipv6() is called by sctp_icmp_error() to process ICMPv6 1232 * error messages passed up by IP. 1233 * Assumes that IP has pulled up all the extension headers as well 1234 * as the ICMPv6 header. 1235 */ 1236 static void 1237 sctp_icmp_error_ipv6(sctp_t *sctp, mblk_t *mp) 1238 { 1239 icmp6_t *icmp6; 1240 ip6_t *ip6h; 1241 uint16_t iph_hdr_length; 1242 sctp_hdr_t *sctpha; 1243 uint8_t *nexthdrp; 1244 sctp_faddr_t *fp; 1245 sctp_stack_t *sctps = sctp->sctp_sctps; 1246 1247 ip6h = (ip6_t *)mp->b_rptr; 1248 iph_hdr_length = (ip6h->ip6_nxt != IPPROTO_SCTP) ? 1249 ip_hdr_length_v6(mp, ip6h) : IPV6_HDR_LEN; 1250 1251 icmp6 = (icmp6_t *)&mp->b_rptr[iph_hdr_length]; 1252 ip6h = (ip6_t *)&icmp6[1]; 1253 if (!ip_hdr_length_nexthdr_v6(mp, ip6h, &iph_hdr_length, &nexthdrp)) { 1254 freemsg(mp); 1255 return; 1256 } 1257 ASSERT(*nexthdrp == IPPROTO_SCTP); 1258 1259 /* XXX need ifindex to find connection */ 1260 sctpha = (sctp_hdr_t *)((char *)ip6h + iph_hdr_length); 1261 if ((uchar_t *)sctpha >= mp->b_wptr) { 1262 /* not enough data for SCTP header */ 1263 freemsg(mp); 1264 return; 1265 } 1266 switch (icmp6->icmp6_type) { 1267 case ICMP6_PACKET_TOO_BIG: 1268 /* 1269 * Reduce the MSS based on the new MTU. This will 1270 * eliminate any fragmentation locally. 1271 * N.B. There may well be some funny side-effects on 1272 * the local send policy and the remote receive policy. 1273 * Pending further research, we provide 1274 * sctp_ignore_path_mtu just in case this proves 1275 * disastrous somewhere. 1276 * 1277 * After updating the MSS, retransmit part of the 1278 * dropped segment using the new mss by calling 1279 * sctp_wput_slow(). Need to adjust all those 1280 * params to make sure sctp_wput_slow() work properly. 1281 */ 1282 if (sctps->sctps_ignore_path_mtu) 1283 break; 1284 1285 /* find the offending faddr */ 1286 fp = sctp_lookup_faddr(sctp, &ip6h->ip6_dst); 1287 if (fp == NULL) { 1288 break; 1289 } 1290 1291 sctp_update_pmtu(sctp, fp, B_TRUE); 1292 /* 1293 * It is possible, even likely that a fast retransmit 1294 * attempt has been dropped by ip as a result of this 1295 * error, retransmission bundles as much as possible. 1296 * A retransmit here prevents significant delays waiting 1297 * on the timer. Analogous to behaviour of TCP after 1298 * ICMP too big. 1299 */ 1300 sctp_rexmit(sctp, fp); 1301 break; 1302 1303 case ICMP6_DST_UNREACH: 1304 switch (icmp6->icmp6_code) { 1305 case ICMP6_DST_UNREACH_NOPORT: 1306 /* make sure the verification tag matches */ 1307 if (!sctp_icmp_verf(sctp, sctpha, mp)) { 1308 break; 1309 } 1310 if (sctp->sctp_state == SCTPS_COOKIE_WAIT || 1311 sctp->sctp_state == SCTPS_COOKIE_ECHOED) { 1312 BUMP_MIB(&sctps->sctps_mib, sctpAborted); 1313 sctp_assoc_event(sctp, SCTP_CANT_STR_ASSOC, 0, 1314 NULL); 1315 sctp_clean_death(sctp, ECONNREFUSED); 1316 } 1317 break; 1318 1319 case ICMP6_DST_UNREACH_ADMIN: 1320 case ICMP6_DST_UNREACH_NOROUTE: 1321 case ICMP6_DST_UNREACH_NOTNEIGHBOR: 1322 case ICMP6_DST_UNREACH_ADDR: 1323 /* Record the error in case we finally time out. */ 1324 sctp->sctp_client_errno = EHOSTUNREACH; 1325 break; 1326 default: 1327 break; 1328 } 1329 break; 1330 1331 case ICMP6_PARAM_PROB: 1332 /* If this corresponds to an ICMP_PROTOCOL_UNREACHABLE */ 1333 if (icmp6->icmp6_code == ICMP6_PARAMPROB_NEXTHEADER && 1334 (uchar_t *)ip6h + icmp6->icmp6_pptr == 1335 (uchar_t *)nexthdrp) { 1336 /* make sure the verification tag matches */ 1337 if (!sctp_icmp_verf(sctp, sctpha, mp)) { 1338 break; 1339 } 1340 if (sctp->sctp_state == SCTPS_COOKIE_WAIT) { 1341 BUMP_MIB(&sctps->sctps_mib, sctpAborted); 1342 sctp_assoc_event(sctp, SCTP_CANT_STR_ASSOC, 0, 1343 NULL); 1344 sctp_clean_death(sctp, ECONNREFUSED); 1345 } 1346 break; 1347 } 1348 break; 1349 1350 case ICMP6_TIME_EXCEEDED: 1351 default: 1352 break; 1353 } 1354 freemsg(mp); 1355 } 1356 1357 /* 1358 * Called by sockfs to create a new sctp instance. 1359 * 1360 * If parent pointer is passed in, inherit settings from it. 1361 */ 1362 sctp_t * 1363 sctp_create(void *ulpd, sctp_t *parent, int family, int type, int flags, 1364 sock_upcalls_t *upcalls, sctp_sockbuf_limits_t *sbl, 1365 cred_t *credp) 1366 { 1367 sctp_t *sctp, *psctp; 1368 conn_t *connp; 1369 mblk_t *ack_mp, *hb_mp; 1370 int sleep = flags & SCTP_CAN_BLOCK ? KM_SLEEP : KM_NOSLEEP; 1371 zoneid_t zoneid; 1372 sctp_stack_t *sctps; 1373 1374 /* User must supply a credential. */ 1375 if (credp == NULL) 1376 return (NULL); 1377 1378 psctp = (sctp_t *)parent; 1379 if (psctp != NULL) { 1380 sctps = psctp->sctp_sctps; 1381 /* Increase here to have common decrease at end */ 1382 netstack_hold(sctps->sctps_netstack); 1383 } else { 1384 netstack_t *ns; 1385 1386 ns = netstack_find_by_cred(credp); 1387 ASSERT(ns != NULL); 1388 sctps = ns->netstack_sctp; 1389 ASSERT(sctps != NULL); 1390 1391 /* 1392 * For exclusive stacks we set the zoneid to zero 1393 * to make SCTP operate as if in the global zone. 1394 */ 1395 if (sctps->sctps_netstack->netstack_stackid != 1396 GLOBAL_NETSTACKID) 1397 zoneid = GLOBAL_ZONEID; 1398 else 1399 zoneid = crgetzoneid(credp); 1400 } 1401 if ((connp = ipcl_conn_create(IPCL_SCTPCONN, sleep, 1402 sctps->sctps_netstack)) == NULL) { 1403 netstack_rele(sctps->sctps_netstack); 1404 SCTP_KSTAT(sctps, sctp_conn_create); 1405 return (NULL); 1406 } 1407 /* 1408 * ipcl_conn_create did a netstack_hold. Undo the hold that was 1409 * done at top of sctp_create. 1410 */ 1411 netstack_rele(sctps->sctps_netstack); 1412 sctp = CONN2SCTP(connp); 1413 sctp->sctp_sctps = sctps; 1414 1415 if ((ack_mp = sctp_timer_alloc(sctp, sctp_ack_timer, sleep)) == NULL || 1416 (hb_mp = sctp_timer_alloc(sctp, sctp_heartbeat_timer, 1417 sleep)) == NULL) { 1418 if (ack_mp != NULL) 1419 freeb(ack_mp); 1420 sctp_conn_clear(connp); 1421 sctp->sctp_sctps = NULL; 1422 kmem_cache_free(sctp_conn_cache, connp); 1423 return (NULL); 1424 } 1425 1426 sctp->sctp_ack_mp = ack_mp; 1427 sctp->sctp_heartbeat_mp = hb_mp; 1428 1429 /* 1430 * Have conn_ip_output drop packets should our outer source 1431 * go invalid, and tell us about mtu changes. 1432 */ 1433 connp->conn_ixa->ixa_flags |= IXAF_SET_ULP_CKSUM | IXAF_VERIFY_SOURCE | 1434 IXAF_VERIFY_PMTU; 1435 connp->conn_family = family; 1436 connp->conn_so_type = type; 1437 1438 if (sctp_init_values(sctp, psctp, sleep) != 0) { 1439 freeb(ack_mp); 1440 freeb(hb_mp); 1441 sctp_conn_clear(connp); 1442 sctp->sctp_sctps = NULL; 1443 kmem_cache_free(sctp_conn_cache, connp); 1444 return (NULL); 1445 } 1446 sctp->sctp_cansleep = ((flags & SCTP_CAN_BLOCK) == SCTP_CAN_BLOCK); 1447 1448 sctp->sctp_mss = sctps->sctps_initial_mtu - ((family == AF_INET6) ? 1449 sctp->sctp_hdr6_len : sctp->sctp_hdr_len); 1450 1451 if (psctp != NULL) { 1452 conn_t *pconnp = psctp->sctp_connp; 1453 1454 RUN_SCTP(psctp); 1455 /* 1456 * Inherit local address list, local port. Parent is either 1457 * in SCTPS_BOUND, or SCTPS_LISTEN state. 1458 */ 1459 ASSERT((psctp->sctp_state == SCTPS_BOUND) || 1460 (psctp->sctp_state == SCTPS_LISTEN)); 1461 if (sctp_dup_saddrs(psctp, sctp, sleep)) { 1462 WAKE_SCTP(psctp); 1463 freeb(ack_mp); 1464 freeb(hb_mp); 1465 sctp_headers_free(sctp); 1466 sctp_conn_clear(connp); 1467 sctp->sctp_sctps = NULL; 1468 kmem_cache_free(sctp_conn_cache, connp); 1469 return (NULL); 1470 } 1471 1472 /* 1473 * If the parent is specified, it'll be immediatelly 1474 * followed by sctp_connect(). So don't add this guy to 1475 * bind hash. 1476 */ 1477 connp->conn_lport = pconnp->conn_lport; 1478 sctp->sctp_state = SCTPS_BOUND; 1479 WAKE_SCTP(psctp); 1480 } else { 1481 ASSERT(connp->conn_cred == NULL); 1482 connp->conn_zoneid = zoneid; 1483 /* 1484 * conn_allzones can not be set this early, hence 1485 * no IPCL_ZONEID 1486 */ 1487 connp->conn_ixa->ixa_zoneid = zoneid; 1488 connp->conn_open_time = lbolt64; 1489 connp->conn_cred = credp; 1490 crhold(credp); 1491 connp->conn_cpid = curproc->p_pid; 1492 1493 /* 1494 * If the caller has the process-wide flag set, then default to 1495 * MAC exempt mode. This allows read-down to unlabeled hosts. 1496 */ 1497 if (getpflags(NET_MAC_AWARE, credp) != 0) 1498 connp->conn_mac_mode = CONN_MAC_AWARE; 1499 1500 connp->conn_zone_is_global = 1501 (crgetzoneid(credp) == GLOBAL_ZONEID); 1502 } 1503 1504 /* Initialize SCTP instance values, our verf tag must never be 0 */ 1505 (void) random_get_pseudo_bytes((uint8_t *)&sctp->sctp_lvtag, 1506 sizeof (sctp->sctp_lvtag)); 1507 if (sctp->sctp_lvtag == 0) 1508 sctp->sctp_lvtag = (uint32_t)gethrtime(); 1509 ASSERT(sctp->sctp_lvtag != 0); 1510 1511 sctp->sctp_ltsn = sctp->sctp_lvtag + 1; 1512 sctp->sctp_lcsn = sctp->sctp_ltsn; 1513 sctp->sctp_recovery_tsn = sctp->sctp_lastack_rxd = sctp->sctp_ltsn - 1; 1514 sctp->sctp_adv_pap = sctp->sctp_lastack_rxd; 1515 1516 /* Information required by upper layer */ 1517 ASSERT(ulpd != NULL); 1518 sctp->sctp_ulpd = ulpd; 1519 1520 ASSERT(upcalls != NULL); 1521 sctp->sctp_upcalls = upcalls; 1522 ASSERT(sbl != NULL); 1523 /* Fill in the socket buffer limits for sctpsockfs */ 1524 sbl->sbl_txlowat = connp->conn_sndlowat; 1525 sbl->sbl_txbuf = connp->conn_sndbuf; 1526 sbl->sbl_rxbuf = sctp->sctp_rwnd; 1527 sbl->sbl_rxlowat = SCTP_RECV_LOWATER; 1528 1529 /* Insert this in the global list. */ 1530 SCTP_LINK(sctp, sctps); 1531 1532 return (sctp); 1533 } 1534 1535 /* Run at module load time */ 1536 void 1537 sctp_ddi_g_init(void) 1538 { 1539 /* Create sctp_t/conn_t cache */ 1540 sctp_conn_cache_init(); 1541 1542 /* Create the faddr cache */ 1543 sctp_faddr_init(); 1544 1545 /* Create the sets cache */ 1546 sctp_sets_init(); 1547 1548 /* Create the PR-SCTP sets cache */ 1549 sctp_ftsn_sets_init(); 1550 1551 /* Initialize tables used for CRC calculation */ 1552 sctp_crc32_init(); 1553 1554 /* 1555 * We want to be informed each time a stack is created or 1556 * destroyed in the kernel, so we can maintain the 1557 * set of sctp_stack_t's. 1558 */ 1559 netstack_register(NS_SCTP, sctp_stack_init, NULL, sctp_stack_fini); 1560 } 1561 1562 static void * 1563 sctp_stack_init(netstackid_t stackid, netstack_t *ns) 1564 { 1565 sctp_stack_t *sctps; 1566 1567 sctps = kmem_zalloc(sizeof (*sctps), KM_SLEEP); 1568 sctps->sctps_netstack = ns; 1569 1570 /* Initialize locks */ 1571 mutex_init(&sctps->sctps_g_lock, NULL, MUTEX_DEFAULT, NULL); 1572 mutex_init(&sctps->sctps_epriv_port_lock, NULL, MUTEX_DEFAULT, NULL); 1573 sctps->sctps_g_num_epriv_ports = SCTP_NUM_EPRIV_PORTS; 1574 sctps->sctps_g_epriv_ports[0] = 2049; 1575 sctps->sctps_g_epriv_ports[1] = 4045; 1576 1577 /* Initialize SCTP hash arrays. */ 1578 sctp_hash_init(sctps); 1579 1580 if (!sctp_nd_init(sctps)) { 1581 sctp_nd_free(sctps); 1582 } 1583 1584 /* Initialize the recvq taskq. */ 1585 sctp_rq_tq_init(sctps); 1586 1587 /* saddr init */ 1588 sctp_saddr_init(sctps); 1589 1590 /* Global SCTP PCB list. */ 1591 list_create(&sctps->sctps_g_list, sizeof (sctp_t), 1592 offsetof(sctp_t, sctp_list)); 1593 1594 /* Initialize sctp kernel stats. */ 1595 sctps->sctps_mibkp = sctp_kstat_init(stackid); 1596 sctps->sctps_kstat = 1597 sctp_kstat2_init(stackid, &sctps->sctps_statistics); 1598 1599 return (sctps); 1600 } 1601 1602 /* 1603 * Called when the module is about to be unloaded. 1604 */ 1605 void 1606 sctp_ddi_g_destroy(void) 1607 { 1608 /* Destroy sctp_t/conn_t caches */ 1609 sctp_conn_cache_fini(); 1610 1611 /* Destroy the faddr cache */ 1612 sctp_faddr_fini(); 1613 1614 /* Destroy the sets cache */ 1615 sctp_sets_fini(); 1616 1617 /* Destroy the PR-SCTP sets cache */ 1618 sctp_ftsn_sets_fini(); 1619 1620 netstack_unregister(NS_SCTP); 1621 } 1622 1623 /* 1624 * Free the SCTP stack instance. 1625 */ 1626 static void 1627 sctp_stack_fini(netstackid_t stackid, void *arg) 1628 { 1629 sctp_stack_t *sctps = (sctp_stack_t *)arg; 1630 1631 sctp_nd_free(sctps); 1632 1633 /* Destroy the recvq taskqs. */ 1634 sctp_rq_tq_fini(sctps); 1635 1636 /* Destroy saddr */ 1637 sctp_saddr_fini(sctps); 1638 1639 /* Global SCTP PCB list. */ 1640 list_destroy(&sctps->sctps_g_list); 1641 1642 /* Destroy SCTP hash arrays. */ 1643 sctp_hash_destroy(sctps); 1644 1645 /* Destroy SCTP kernel stats. */ 1646 sctp_kstat2_fini(stackid, sctps->sctps_kstat); 1647 sctps->sctps_kstat = NULL; 1648 bzero(&sctps->sctps_statistics, sizeof (sctps->sctps_statistics)); 1649 1650 sctp_kstat_fini(stackid, sctps->sctps_mibkp); 1651 sctps->sctps_mibkp = NULL; 1652 1653 mutex_destroy(&sctps->sctps_g_lock); 1654 mutex_destroy(&sctps->sctps_epriv_port_lock); 1655 1656 kmem_free(sctps, sizeof (*sctps)); 1657 } 1658 1659 void 1660 sctp_display_all(sctp_stack_t *sctps) 1661 { 1662 sctp_t *sctp_walker; 1663 1664 mutex_enter(&sctps->sctps_g_lock); 1665 for (sctp_walker = list_head(&sctps->sctps_g_list); 1666 sctp_walker != NULL; 1667 sctp_walker = (sctp_t *)list_next(&sctps->sctps_g_list, 1668 sctp_walker)) { 1669 (void) sctp_display(sctp_walker, NULL); 1670 } 1671 mutex_exit(&sctps->sctps_g_lock); 1672 } 1673 1674 static void 1675 sctp_rq_tq_init(sctp_stack_t *sctps) 1676 { 1677 sctps->sctps_recvq_tq_list_max_sz = 16; 1678 sctps->sctps_recvq_tq_list_cur_sz = 1; 1679 /* 1680 * Initialize the recvq_tq_list and create the first recvq taskq. 1681 * What to do if it fails? 1682 */ 1683 sctps->sctps_recvq_tq_list = 1684 kmem_zalloc(sctps->sctps_recvq_tq_list_max_sz * sizeof (taskq_t *), 1685 KM_SLEEP); 1686 sctps->sctps_recvq_tq_list[0] = taskq_create("sctp_def_recvq_taskq", 1687 MIN(sctp_recvq_tq_thr_max, MAX(sctp_recvq_tq_thr_min, ncpus)), 1688 minclsyspri, sctp_recvq_tq_task_min, sctp_recvq_tq_task_max, 1689 TASKQ_PREPOPULATE); 1690 mutex_init(&sctps->sctps_rq_tq_lock, NULL, MUTEX_DEFAULT, NULL); 1691 } 1692 1693 static void 1694 sctp_rq_tq_fini(sctp_stack_t *sctps) 1695 { 1696 int i; 1697 1698 for (i = 0; i < sctps->sctps_recvq_tq_list_cur_sz; i++) { 1699 ASSERT(sctps->sctps_recvq_tq_list[i] != NULL); 1700 taskq_destroy(sctps->sctps_recvq_tq_list[i]); 1701 } 1702 kmem_free(sctps->sctps_recvq_tq_list, 1703 sctps->sctps_recvq_tq_list_max_sz * sizeof (taskq_t *)); 1704 sctps->sctps_recvq_tq_list = NULL; 1705 } 1706 1707 /* Add another taskq for a new ill. */ 1708 void 1709 sctp_inc_taskq(sctp_stack_t *sctps) 1710 { 1711 taskq_t *tq; 1712 char tq_name[TASKQ_NAMELEN]; 1713 1714 mutex_enter(&sctps->sctps_rq_tq_lock); 1715 if (sctps->sctps_recvq_tq_list_cur_sz + 1 > 1716 sctps->sctps_recvq_tq_list_max_sz) { 1717 mutex_exit(&sctps->sctps_rq_tq_lock); 1718 cmn_err(CE_NOTE, "Cannot create more SCTP recvq taskq"); 1719 return; 1720 } 1721 1722 (void) snprintf(tq_name, sizeof (tq_name), "sctp_recvq_taskq_%u", 1723 sctps->sctps_recvq_tq_list_cur_sz); 1724 tq = taskq_create(tq_name, 1725 MIN(sctp_recvq_tq_thr_max, MAX(sctp_recvq_tq_thr_min, ncpus)), 1726 minclsyspri, sctp_recvq_tq_task_min, sctp_recvq_tq_task_max, 1727 TASKQ_PREPOPULATE); 1728 if (tq == NULL) { 1729 mutex_exit(&sctps->sctps_rq_tq_lock); 1730 cmn_err(CE_NOTE, "SCTP recvq taskq creation failed"); 1731 return; 1732 } 1733 ASSERT(sctps->sctps_recvq_tq_list[ 1734 sctps->sctps_recvq_tq_list_cur_sz] == NULL); 1735 sctps->sctps_recvq_tq_list[sctps->sctps_recvq_tq_list_cur_sz] = tq; 1736 atomic_add_32(&sctps->sctps_recvq_tq_list_cur_sz, 1); 1737 mutex_exit(&sctps->sctps_rq_tq_lock); 1738 } 1739 1740 #ifdef DEBUG 1741 uint32_t recvq_loop_cnt = 0; 1742 uint32_t recvq_call = 0; 1743 #endif 1744 1745 /* 1746 * Find the next recvq_tq to use. This routine will go thru all the 1747 * taskqs until it can dispatch a job for the sctp. If this fails, 1748 * it will create a new taskq and try it. 1749 */ 1750 static boolean_t 1751 sctp_find_next_tq(sctp_t *sctp) 1752 { 1753 int next_tq, try; 1754 taskq_t *tq; 1755 sctp_stack_t *sctps = sctp->sctp_sctps; 1756 1757 /* 1758 * Note that since we don't hold a lock on sctp_rq_tq_lock for 1759 * performance reason, recvq_ta_list_cur_sz can be changed during 1760 * this loop. The problem this will create is that the loop may 1761 * not have tried all the recvq_tq. This should be OK. 1762 */ 1763 next_tq = atomic_add_32_nv(&sctps->sctps_recvq_tq_list_cur, 1) % 1764 sctps->sctps_recvq_tq_list_cur_sz; 1765 for (try = 0; try < sctps->sctps_recvq_tq_list_cur_sz; try++) { 1766 tq = sctps->sctps_recvq_tq_list[next_tq]; 1767 if (taskq_dispatch(tq, sctp_process_recvq, sctp, 1768 TQ_NOSLEEP) != NULL) { 1769 sctp->sctp_recvq_tq = tq; 1770 return (B_TRUE); 1771 } 1772 next_tq = (next_tq + 1) % sctps->sctps_recvq_tq_list_cur_sz; 1773 } 1774 1775 /* 1776 * Create one more taskq and try it. Note that sctp_inc_taskq() 1777 * may not have created another taskq if the number of recvq 1778 * taskqs is at the maximum. We are probably in a pretty bad 1779 * shape if this actually happens... 1780 */ 1781 sctp_inc_taskq(sctps); 1782 tq = sctps->sctps_recvq_tq_list[sctps->sctps_recvq_tq_list_cur_sz - 1]; 1783 if (taskq_dispatch(tq, sctp_process_recvq, sctp, TQ_NOSLEEP) != NULL) { 1784 sctp->sctp_recvq_tq = tq; 1785 return (B_TRUE); 1786 } 1787 SCTP_KSTAT(sctps, sctp_find_next_tq); 1788 return (B_FALSE); 1789 } 1790 1791 /* 1792 * To add a message to the recvq. Note that the sctp_timer_fire() 1793 * routine also uses this function to add the timer message to the 1794 * receive queue for later processing. And it should be the only 1795 * caller of sctp_add_recvq() which sets the try_harder argument 1796 * to B_TRUE. 1797 * 1798 * If the try_harder argument is B_TRUE, this routine sctp_find_next_tq() 1799 * will try very hard to dispatch the task. Refer to the comment 1800 * for that routine on how it does that. 1801 * 1802 * On failure the message has been freed i.e., this routine always consumes the 1803 * message. It bumps ipIfStatsInDiscards and and uses ip_drop_input to drop. 1804 */ 1805 void 1806 sctp_add_recvq(sctp_t *sctp, mblk_t *mp, boolean_t caller_hold_lock, 1807 ip_recv_attr_t *ira) 1808 { 1809 mblk_t *attrmp; 1810 ip_stack_t *ipst = sctp->sctp_sctps->sctps_netstack->netstack_ip; 1811 1812 ASSERT(ira->ira_ill == NULL); 1813 1814 if (!caller_hold_lock) 1815 mutex_enter(&sctp->sctp_recvq_lock); 1816 1817 /* If the taskq dispatch has not been scheduled, do it now. */ 1818 if (sctp->sctp_recvq_tq == NULL) { 1819 ASSERT(sctp->sctp_recvq == NULL); 1820 if (!sctp_find_next_tq(sctp)) { 1821 if (!caller_hold_lock) 1822 mutex_exit(&sctp->sctp_recvq_lock); 1823 BUMP_MIB(&ipst->ips_ip_mib, ipIfStatsInDiscards); 1824 ip_drop_input("ipIfStatsInDiscards", mp, NULL); 1825 freemsg(mp); 1826 return; 1827 } 1828 /* Make sure the sctp_t will not go away. */ 1829 SCTP_REFHOLD(sctp); 1830 } 1831 1832 attrmp = ip_recv_attr_to_mblk(ira); 1833 if (attrmp == NULL) { 1834 if (!caller_hold_lock) 1835 mutex_exit(&sctp->sctp_recvq_lock); 1836 BUMP_MIB(&ipst->ips_ip_mib, ipIfStatsInDiscards); 1837 ip_drop_input("ipIfStatsInDiscards", mp, NULL); 1838 freemsg(mp); 1839 return; 1840 } 1841 ASSERT(attrmp->b_cont == NULL); 1842 attrmp->b_cont = mp; 1843 mp = attrmp; 1844 1845 if (sctp->sctp_recvq == NULL) { 1846 sctp->sctp_recvq = mp; 1847 sctp->sctp_recvq_tail = mp; 1848 } else { 1849 sctp->sctp_recvq_tail->b_next = mp; 1850 sctp->sctp_recvq_tail = mp; 1851 } 1852 1853 if (!caller_hold_lock) 1854 mutex_exit(&sctp->sctp_recvq_lock); 1855 } 1856 1857 static void 1858 sctp_process_recvq(void *arg) 1859 { 1860 sctp_t *sctp = (sctp_t *)arg; 1861 mblk_t *mp; 1862 #ifdef DEBUG 1863 uint32_t loop_cnt = 0; 1864 #endif 1865 ip_recv_attr_t iras; 1866 1867 #ifdef _BIG_ENDIAN 1868 #define IPVER(ip6h) ((((uint32_t *)ip6h)[0] >> 28) & 0x7) 1869 #else 1870 #define IPVER(ip6h) ((((uint32_t *)ip6h)[0] >> 4) & 0x7) 1871 #endif 1872 1873 RUN_SCTP(sctp); 1874 mutex_enter(&sctp->sctp_recvq_lock); 1875 1876 #ifdef DEBUG 1877 recvq_call++; 1878 #endif 1879 /* 1880 * Note that while we are in this loop, other thread can put 1881 * new packets in the receive queue. We may be looping for 1882 * quite a while. 1883 */ 1884 while ((mp = sctp->sctp_recvq) != NULL) { 1885 mblk_t *data_mp; 1886 1887 sctp->sctp_recvq = mp->b_next; 1888 mutex_exit(&sctp->sctp_recvq_lock); 1889 mp->b_next = NULL; 1890 #ifdef DEBUG 1891 loop_cnt++; 1892 #endif 1893 mp->b_prev = NULL; 1894 1895 data_mp = mp->b_cont; 1896 mp->b_cont = NULL; 1897 if (!ip_recv_attr_from_mblk(mp, &iras)) { 1898 ip_drop_input("ip_recv_attr_from_mblk", mp, NULL); 1899 freemsg(mp); 1900 ira_cleanup(&iras, B_TRUE); 1901 continue; 1902 } 1903 1904 if (iras.ira_flags & IRAF_ICMP_ERROR) 1905 sctp_icmp_error(sctp, data_mp); 1906 else 1907 sctp_input_data(sctp, data_mp, &iras); 1908 1909 ira_cleanup(&iras, B_TRUE); 1910 mutex_enter(&sctp->sctp_recvq_lock); 1911 } 1912 1913 sctp->sctp_recvq_tail = NULL; 1914 sctp->sctp_recvq_tq = NULL; 1915 1916 mutex_exit(&sctp->sctp_recvq_lock); 1917 1918 WAKE_SCTP(sctp); 1919 1920 #ifdef DEBUG 1921 if (loop_cnt > recvq_loop_cnt) 1922 recvq_loop_cnt = loop_cnt; 1923 #endif 1924 /* Now it can go away. */ 1925 SCTP_REFRELE(sctp); 1926 } 1927 1928 /* ARGSUSED */ 1929 static int 1930 sctp_conn_cache_constructor(void *buf, void *cdrarg, int kmflags) 1931 { 1932 conn_t *connp = (conn_t *)buf; 1933 sctp_t *sctp = (sctp_t *)&connp[1]; 1934 1935 bzero(connp, sizeof (conn_t)); 1936 bzero(buf, (char *)&sctp[1] - (char *)buf); 1937 1938 mutex_init(&sctp->sctp_reflock, NULL, MUTEX_DEFAULT, NULL); 1939 mutex_init(&sctp->sctp_lock, NULL, MUTEX_DEFAULT, NULL); 1940 mutex_init(&sctp->sctp_recvq_lock, NULL, MUTEX_DEFAULT, NULL); 1941 cv_init(&sctp->sctp_cv, NULL, CV_DEFAULT, NULL); 1942 1943 mutex_init(&connp->conn_lock, NULL, MUTEX_DEFAULT, NULL); 1944 cv_init(&connp->conn_cv, NULL, CV_DEFAULT, NULL); 1945 connp->conn_flags = IPCL_SCTPCONN; 1946 connp->conn_proto = IPPROTO_SCTP; 1947 connp->conn_sctp = sctp; 1948 sctp->sctp_connp = connp; 1949 rw_init(&connp->conn_ilg_lock, NULL, RW_DEFAULT, NULL); 1950 1951 connp->conn_ixa = kmem_zalloc(sizeof (ip_xmit_attr_t), kmflags); 1952 if (connp->conn_ixa == NULL) { 1953 return (ENOMEM); 1954 } 1955 connp->conn_ixa->ixa_refcnt = 1; 1956 connp->conn_ixa->ixa_protocol = connp->conn_proto; 1957 connp->conn_ixa->ixa_xmit_hint = CONN_TO_XMIT_HINT(connp); 1958 return (0); 1959 } 1960 1961 /* ARGSUSED */ 1962 static void 1963 sctp_conn_cache_destructor(void *buf, void *cdrarg) 1964 { 1965 conn_t *connp = (conn_t *)buf; 1966 sctp_t *sctp = (sctp_t *)&connp[1]; 1967 1968 ASSERT(sctp->sctp_connp == connp); 1969 ASSERT(!MUTEX_HELD(&sctp->sctp_lock)); 1970 ASSERT(!MUTEX_HELD(&sctp->sctp_reflock)); 1971 ASSERT(!MUTEX_HELD(&sctp->sctp_recvq_lock)); 1972 1973 ASSERT(sctp->sctp_conn_hash_next == NULL); 1974 ASSERT(sctp->sctp_conn_hash_prev == NULL); 1975 ASSERT(sctp->sctp_listen_hash_next == NULL); 1976 ASSERT(sctp->sctp_listen_hash_prev == NULL); 1977 ASSERT(sctp->sctp_listen_tfp == NULL); 1978 ASSERT(sctp->sctp_conn_tfp == NULL); 1979 1980 ASSERT(sctp->sctp_faddrs == NULL); 1981 ASSERT(sctp->sctp_nsaddrs == 0); 1982 1983 ASSERT(sctp->sctp_ulpd == NULL); 1984 1985 ASSERT(sctp->sctp_lastfaddr == NULL); 1986 ASSERT(sctp->sctp_primary == NULL); 1987 ASSERT(sctp->sctp_current == NULL); 1988 ASSERT(sctp->sctp_lastdata == NULL); 1989 1990 ASSERT(sctp->sctp_xmit_head == NULL); 1991 ASSERT(sctp->sctp_xmit_tail == NULL); 1992 ASSERT(sctp->sctp_xmit_unsent == NULL); 1993 ASSERT(sctp->sctp_xmit_unsent_tail == NULL); 1994 1995 ASSERT(sctp->sctp_ostrcntrs == NULL); 1996 1997 ASSERT(sctp->sctp_sack_info == NULL); 1998 ASSERT(sctp->sctp_ack_mp == NULL); 1999 ASSERT(sctp->sctp_instr == NULL); 2000 2001 ASSERT(sctp->sctp_iphc == NULL); 2002 ASSERT(sctp->sctp_iphc6 == NULL); 2003 ASSERT(sctp->sctp_ipha == NULL); 2004 ASSERT(sctp->sctp_ip6h == NULL); 2005 ASSERT(sctp->sctp_sctph == NULL); 2006 ASSERT(sctp->sctp_sctph6 == NULL); 2007 2008 ASSERT(sctp->sctp_cookie_mp == NULL); 2009 2010 ASSERT(sctp->sctp_refcnt == 0); 2011 ASSERT(sctp->sctp_timer_mp == NULL); 2012 ASSERT(sctp->sctp_connp->conn_ref == 0); 2013 ASSERT(sctp->sctp_heartbeat_mp == NULL); 2014 ASSERT(sctp->sctp_ptpbhn == NULL && sctp->sctp_bind_hash == NULL); 2015 2016 ASSERT(sctp->sctp_shutdown_faddr == NULL); 2017 2018 ASSERT(sctp->sctp_cxmit_list == NULL); 2019 2020 ASSERT(sctp->sctp_recvq == NULL); 2021 ASSERT(sctp->sctp_recvq_tail == NULL); 2022 ASSERT(sctp->sctp_recvq_tq == NULL); 2023 2024 /* 2025 * sctp_pad_mp can be NULL if the memory allocation fails 2026 * in sctp_init_values() and the conn_t is freed. 2027 */ 2028 if (sctp->sctp_pad_mp != NULL) { 2029 freeb(sctp->sctp_pad_mp); 2030 sctp->sctp_pad_mp = NULL; 2031 } 2032 2033 mutex_destroy(&sctp->sctp_reflock); 2034 mutex_destroy(&sctp->sctp_lock); 2035 mutex_destroy(&sctp->sctp_recvq_lock); 2036 cv_destroy(&sctp->sctp_cv); 2037 2038 mutex_destroy(&connp->conn_lock); 2039 cv_destroy(&connp->conn_cv); 2040 rw_destroy(&connp->conn_ilg_lock); 2041 2042 /* Can be NULL if constructor failed */ 2043 if (connp->conn_ixa != NULL) { 2044 ASSERT(connp->conn_ixa->ixa_refcnt == 1); 2045 ASSERT(connp->conn_ixa->ixa_ire == NULL); 2046 ASSERT(connp->conn_ixa->ixa_nce == NULL); 2047 ixa_refrele(connp->conn_ixa); 2048 } 2049 } 2050 2051 static void 2052 sctp_conn_cache_init() 2053 { 2054 sctp_conn_cache = kmem_cache_create("sctp_conn_cache", 2055 sizeof (sctp_t) + sizeof (conn_t), 0, sctp_conn_cache_constructor, 2056 sctp_conn_cache_destructor, NULL, NULL, NULL, 0); 2057 } 2058 2059 static void 2060 sctp_conn_cache_fini() 2061 { 2062 kmem_cache_destroy(sctp_conn_cache); 2063 } 2064 2065 void 2066 sctp_conn_init(conn_t *connp) 2067 { 2068 ASSERT(connp->conn_flags == IPCL_SCTPCONN); 2069 connp->conn_rq = connp->conn_wq = NULL; 2070 connp->conn_ixa->ixa_flags |= IXAF_SET_ULP_CKSUM | IXAF_VERIFY_SOURCE | 2071 IXAF_VERIFY_PMTU; 2072 2073 ASSERT(connp->conn_proto == IPPROTO_SCTP); 2074 ASSERT(connp->conn_ixa->ixa_protocol == connp->conn_proto); 2075 connp->conn_state_flags |= CONN_INCIPIENT; 2076 2077 ASSERT(connp->conn_sctp != NULL); 2078 2079 /* 2080 * Register sctp_notify to listen to capability changes detected by IP. 2081 * This upcall is made in the context of the call to conn_ip_output 2082 * thus it holds whatever locks sctp holds across conn_ip_output. 2083 */ 2084 connp->conn_ixa->ixa_notify = sctp_notify; 2085 connp->conn_ixa->ixa_notify_cookie = connp->conn_sctp; 2086 } 2087 2088 static void 2089 sctp_conn_clear(conn_t *connp) 2090 { 2091 /* Clean up conn_t stuff */ 2092 if (connp->conn_latch != NULL) { 2093 IPLATCH_REFRELE(connp->conn_latch); 2094 connp->conn_latch = NULL; 2095 } 2096 if (connp->conn_latch_in_policy != NULL) { 2097 IPPOL_REFRELE(connp->conn_latch_in_policy); 2098 connp->conn_latch_in_policy = NULL; 2099 } 2100 if (connp->conn_latch_in_action != NULL) { 2101 IPACT_REFRELE(connp->conn_latch_in_action); 2102 connp->conn_latch_in_action = NULL; 2103 } 2104 if (connp->conn_policy != NULL) { 2105 IPPH_REFRELE(connp->conn_policy, connp->conn_netstack); 2106 connp->conn_policy = NULL; 2107 } 2108 if (connp->conn_ipsec_opt_mp != NULL) { 2109 freemsg(connp->conn_ipsec_opt_mp); 2110 connp->conn_ipsec_opt_mp = NULL; 2111 } 2112 netstack_rele(connp->conn_netstack); 2113 connp->conn_netstack = NULL; 2114 2115 /* Leave conn_ixa and other constructed fields in place */ 2116 ipcl_conn_cleanup(connp); 2117 } 2118