1/*-
2 * SPDX-License-Identifier: BSD-3-Clause
3 *
4 * Copyright (c) 2007, by Cisco Systems, Inc. All rights reserved.
5 * Copyright (c) 2008-2012, by Randall Stewart. All rights reserved.
6 * Copyright (c) 2008-2012, by Michael Tuexen. All rights reserved.
7 *
8 * Redistribution and use in source and binary forms, with or without
9 * modification, are permitted provided that the following conditions are met:
10 *
11 * a) Redistributions of source code must retain the above copyright notice,
12 *    this list of conditions and the following disclaimer.
13 *
14 * b) Redistributions in binary form must reproduce the above copyright
15 *    notice, this list of conditions and the following disclaimer in
16 *    the documentation and/or other materials provided with the distribution.
17 *
18 * c) Neither the name of Cisco Systems, Inc. nor the names of its
19 *    contributors may be used to endorse or promote products derived
20 *    from this software without specific prior written permission.
21 *
22 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
23 * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
24 * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25 * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
26 * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
27 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
28 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
29 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
30 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
31 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
32 * THE POSSIBILITY OF SUCH DAMAGE.
33 */
34
35#include <netinet/sctp_os.h>
36#include <netinet/sctp.h>
37#include <netinet/sctp_constants.h>
38#include <netinet/sctp_sysctl.h>
39#include <netinet/sctp_pcb.h>
40#include <netinet/sctputil.h>
41#include <netinet/sctp_output.h>
42#include <sys/smp.h>
43#include <sys/sysctl.h>
44
45FEATURE(sctp, "Stream Control Transmission Protocol");
46
47/*
48 * sysctl tunable variables
49 */
50
51void
52sctp_init_sysctls(void)
53{
54	SCTP_BASE_SYSCTL(sctp_sendspace) = SCTPCTL_MAXDGRAM_DEFAULT;
55	SCTP_BASE_SYSCTL(sctp_recvspace) = SCTPCTL_RECVSPACE_DEFAULT;
56	SCTP_BASE_SYSCTL(sctp_auto_asconf) = SCTPCTL_AUTOASCONF_DEFAULT;
57	SCTP_BASE_SYSCTL(sctp_multiple_asconfs) = SCTPCTL_MULTIPLEASCONFS_DEFAULT;
58	SCTP_BASE_SYSCTL(sctp_ecn_enable) = SCTPCTL_ECN_ENABLE_DEFAULT;
59	SCTP_BASE_SYSCTL(sctp_pr_enable) = SCTPCTL_PR_ENABLE_DEFAULT;
60	SCTP_BASE_SYSCTL(sctp_auth_enable) = SCTPCTL_AUTH_ENABLE_DEFAULT;
61	SCTP_BASE_SYSCTL(sctp_asconf_enable) = SCTPCTL_ASCONF_ENABLE_DEFAULT;
62	SCTP_BASE_SYSCTL(sctp_reconfig_enable) = SCTPCTL_RECONFIG_ENABLE_DEFAULT;
63	SCTP_BASE_SYSCTL(sctp_nrsack_enable) = SCTPCTL_NRSACK_ENABLE_DEFAULT;
64	SCTP_BASE_SYSCTL(sctp_pktdrop_enable) = SCTPCTL_PKTDROP_ENABLE_DEFAULT;
65	SCTP_BASE_SYSCTL(sctp_peer_chunk_oh) = SCTPCTL_PEER_CHKOH_DEFAULT;
66	SCTP_BASE_SYSCTL(sctp_max_burst_default) = SCTPCTL_MAXBURST_DEFAULT;
67	SCTP_BASE_SYSCTL(sctp_fr_max_burst_default) = SCTPCTL_FRMAXBURST_DEFAULT;
68	SCTP_BASE_SYSCTL(sctp_max_chunks_on_queue) = SCTPCTL_MAXCHUNKS_DEFAULT;
69	SCTP_BASE_SYSCTL(sctp_hashtblsize) = SCTPCTL_TCBHASHSIZE_DEFAULT;
70	SCTP_BASE_SYSCTL(sctp_pcbtblsize) = SCTPCTL_PCBHASHSIZE_DEFAULT;
71	SCTP_BASE_SYSCTL(sctp_min_split_point) = SCTPCTL_MIN_SPLIT_POINT_DEFAULT;
72	SCTP_BASE_SYSCTL(sctp_chunkscale) = SCTPCTL_CHUNKSCALE_DEFAULT;
73	SCTP_BASE_SYSCTL(sctp_delayed_sack_time_default) = SCTPCTL_DELAYED_SACK_TIME_DEFAULT;
74	SCTP_BASE_SYSCTL(sctp_sack_freq_default) = SCTPCTL_SACK_FREQ_DEFAULT;
75	SCTP_BASE_SYSCTL(sctp_system_free_resc_limit) = SCTPCTL_SYS_RESOURCE_DEFAULT;
76	SCTP_BASE_SYSCTL(sctp_asoc_free_resc_limit) = SCTPCTL_ASOC_RESOURCE_DEFAULT;
77	SCTP_BASE_SYSCTL(sctp_heartbeat_interval_default) = SCTPCTL_HEARTBEAT_INTERVAL_DEFAULT;
78	SCTP_BASE_SYSCTL(sctp_pmtu_raise_time_default) = SCTPCTL_PMTU_RAISE_TIME_DEFAULT;
79	SCTP_BASE_SYSCTL(sctp_shutdown_guard_time_default) = SCTPCTL_SHUTDOWN_GUARD_TIME_DEFAULT;
80	SCTP_BASE_SYSCTL(sctp_secret_lifetime_default) = SCTPCTL_SECRET_LIFETIME_DEFAULT;
81	SCTP_BASE_SYSCTL(sctp_rto_max_default) = SCTPCTL_RTO_MAX_DEFAULT;
82	SCTP_BASE_SYSCTL(sctp_rto_min_default) = SCTPCTL_RTO_MIN_DEFAULT;
83	SCTP_BASE_SYSCTL(sctp_rto_initial_default) = SCTPCTL_RTO_INITIAL_DEFAULT;
84	SCTP_BASE_SYSCTL(sctp_init_rto_max_default) = SCTPCTL_INIT_RTO_MAX_DEFAULT;
85	SCTP_BASE_SYSCTL(sctp_valid_cookie_life_default) = SCTPCTL_VALID_COOKIE_LIFE_DEFAULT;
86	SCTP_BASE_SYSCTL(sctp_init_rtx_max_default) = SCTPCTL_INIT_RTX_MAX_DEFAULT;
87	SCTP_BASE_SYSCTL(sctp_assoc_rtx_max_default) = SCTPCTL_ASSOC_RTX_MAX_DEFAULT;
88	SCTP_BASE_SYSCTL(sctp_path_rtx_max_default) = SCTPCTL_PATH_RTX_MAX_DEFAULT;
89	SCTP_BASE_SYSCTL(sctp_path_pf_threshold) = SCTPCTL_PATH_PF_THRESHOLD_DEFAULT;
90	SCTP_BASE_SYSCTL(sctp_add_more_threshold) = SCTPCTL_ADD_MORE_ON_OUTPUT_DEFAULT;
91	SCTP_BASE_SYSCTL(sctp_nr_incoming_streams_default) = SCTPCTL_INCOMING_STREAMS_DEFAULT;
92	SCTP_BASE_SYSCTL(sctp_nr_outgoing_streams_default) = SCTPCTL_OUTGOING_STREAMS_DEFAULT;
93	SCTP_BASE_SYSCTL(sctp_cmt_on_off) = SCTPCTL_CMT_ON_OFF_DEFAULT;
94	SCTP_BASE_SYSCTL(sctp_cmt_use_dac) = SCTPCTL_CMT_USE_DAC_DEFAULT;
95	SCTP_BASE_SYSCTL(sctp_use_cwnd_based_maxburst) = SCTPCTL_CWND_MAXBURST_DEFAULT;
96	SCTP_BASE_SYSCTL(sctp_nat_friendly) = SCTPCTL_NAT_FRIENDLY_DEFAULT;
97	SCTP_BASE_SYSCTL(sctp_L2_abc_variable) = SCTPCTL_ABC_L_VAR_DEFAULT;
98	SCTP_BASE_SYSCTL(sctp_mbuf_threshold_count) = SCTPCTL_MAX_CHAINED_MBUFS_DEFAULT;
99	SCTP_BASE_SYSCTL(sctp_do_drain) = SCTPCTL_DO_SCTP_DRAIN_DEFAULT;
100	SCTP_BASE_SYSCTL(sctp_hb_maxburst) = SCTPCTL_HB_MAX_BURST_DEFAULT;
101	SCTP_BASE_SYSCTL(sctp_abort_if_one_2_one_hits_limit) = SCTPCTL_ABORT_AT_LIMIT_DEFAULT;
102	SCTP_BASE_SYSCTL(sctp_min_residual) = SCTPCTL_MIN_RESIDUAL_DEFAULT;
103	SCTP_BASE_SYSCTL(sctp_max_retran_chunk) = SCTPCTL_MAX_RETRAN_CHUNK_DEFAULT;
104	SCTP_BASE_SYSCTL(sctp_logging_level) = SCTPCTL_LOGGING_LEVEL_DEFAULT;
105	SCTP_BASE_SYSCTL(sctp_default_cc_module) = SCTPCTL_DEFAULT_CC_MODULE_DEFAULT;
106	SCTP_BASE_SYSCTL(sctp_default_ss_module) = SCTPCTL_DEFAULT_SS_MODULE_DEFAULT;
107	SCTP_BASE_SYSCTL(sctp_default_frag_interleave) = SCTPCTL_DEFAULT_FRAG_INTERLEAVE_DEFAULT;
108	SCTP_BASE_SYSCTL(sctp_mobility_base) = SCTPCTL_MOBILITY_BASE_DEFAULT;
109	SCTP_BASE_SYSCTL(sctp_mobility_fasthandoff) = SCTPCTL_MOBILITY_FASTHANDOFF_DEFAULT;
110	SCTP_BASE_SYSCTL(sctp_vtag_time_wait) = SCTPCTL_TIME_WAIT_DEFAULT;
111	SCTP_BASE_SYSCTL(sctp_buffer_splitting) = SCTPCTL_BUFFER_SPLITTING_DEFAULT;
112	SCTP_BASE_SYSCTL(sctp_initial_cwnd) = SCTPCTL_INITIAL_CWND_DEFAULT;
113	SCTP_BASE_SYSCTL(sctp_rttvar_bw) = SCTPCTL_RTTVAR_BW_DEFAULT;
114	SCTP_BASE_SYSCTL(sctp_rttvar_rtt) = SCTPCTL_RTTVAR_RTT_DEFAULT;
115	SCTP_BASE_SYSCTL(sctp_rttvar_eqret) = SCTPCTL_RTTVAR_EQRET_DEFAULT;
116	SCTP_BASE_SYSCTL(sctp_steady_step) = SCTPCTL_RTTVAR_STEADYS_DEFAULT;
117	SCTP_BASE_SYSCTL(sctp_use_dccc_ecn) = SCTPCTL_RTTVAR_DCCCECN_DEFAULT;
118	SCTP_BASE_SYSCTL(sctp_blackhole) = SCTPCTL_BLACKHOLE_DEFAULT;
119	SCTP_BASE_SYSCTL(sctp_sendall_limit) = SCTPCTL_SENDALL_LIMIT_DEFAULT;
120	SCTP_BASE_SYSCTL(sctp_diag_info_code) = SCTPCTL_DIAG_INFO_CODE_DEFAULT;
121	SCTP_BASE_SYSCTL(sctp_ootb_with_zero_cksum) = SCTPCTL_OOTB_WITH_ZERO_CKSUM_DEFAULT;
122#if defined(SCTP_LOCAL_TRACE_BUF)
123	memset(&SCTP_BASE_SYSCTL(sctp_log), 0, sizeof(struct sctp_log));
124#endif
125	SCTP_BASE_SYSCTL(sctp_udp_tunneling_port) = SCTPCTL_UDP_TUNNELING_PORT_DEFAULT;
126	SCTP_BASE_SYSCTL(sctp_enable_sack_immediately) = SCTPCTL_SACK_IMMEDIATELY_ENABLE_DEFAULT;
127	SCTP_BASE_SYSCTL(sctp_inits_include_nat_friendly) = SCTPCTL_NAT_FRIENDLY_INITS_DEFAULT;
128#if defined(SCTP_DEBUG)
129	SCTP_BASE_SYSCTL(sctp_debug_on) = SCTPCTL_DEBUG_DEFAULT;
130#endif
131}
132
133/* It returns an upper limit. No filtering is done here */
134static unsigned int
135sctp_sysctl_number_of_addresses(struct sctp_inpcb *inp)
136{
137	unsigned int cnt;
138	struct sctp_vrf *vrf;
139	struct sctp_ifn *sctp_ifn;
140	struct sctp_ifa *sctp_ifa;
141	struct sctp_laddr *laddr;
142
143	cnt = 0;
144	/* neither Mac OS X nor FreeBSD support multiple routing functions */
145	if ((vrf = sctp_find_vrf(inp->def_vrf_id)) == NULL) {
146		return (0);
147	}
148	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
149		LIST_FOREACH(sctp_ifn, &vrf->ifnlist, next_ifn) {
150			LIST_FOREACH(sctp_ifa, &sctp_ifn->ifalist, next_ifa) {
151				switch (sctp_ifa->address.sa.sa_family) {
152#ifdef INET
153				case AF_INET:
154#endif
155#ifdef INET6
156				case AF_INET6:
157#endif
158					cnt++;
159					break;
160				default:
161					break;
162				}
163			}
164		}
165	} else {
166		LIST_FOREACH(laddr, &inp->sctp_addr_list, sctp_nxt_addr) {
167			switch (laddr->ifa->address.sa.sa_family) {
168#ifdef INET
169			case AF_INET:
170#endif
171#ifdef INET6
172			case AF_INET6:
173#endif
174				cnt++;
175				break;
176			default:
177				break;
178			}
179		}
180	}
181	return (cnt);
182}
183
184static int
185sctp_sysctl_copy_out_local_addresses(struct sctp_inpcb *inp, struct sctp_tcb *stcb, struct sysctl_req *req)
186{
187	struct sctp_ifn *sctp_ifn;
188	struct sctp_ifa *sctp_ifa;
189	int loopback_scope;
190#ifdef INET
191	int ipv4_local_scope;
192	int ipv4_addr_legal;
193#endif
194#ifdef INET6
195	int local_scope, site_scope;
196	int ipv6_addr_legal;
197#endif
198	struct sctp_vrf *vrf;
199	struct xsctp_laddr xladdr;
200	struct sctp_laddr *laddr;
201	int error;
202
203	/* Turn on all the appropriate scope */
204	if (stcb != NULL) {
205		/* use association specific values */
206		loopback_scope = stcb->asoc.scope.loopback_scope;
207#ifdef INET
208		ipv4_local_scope = stcb->asoc.scope.ipv4_local_scope;
209		ipv4_addr_legal = stcb->asoc.scope.ipv4_addr_legal;
210#endif
211#ifdef INET6
212		local_scope = stcb->asoc.scope.local_scope;
213		site_scope = stcb->asoc.scope.site_scope;
214		ipv6_addr_legal = stcb->asoc.scope.ipv6_addr_legal;
215#endif
216	} else {
217		/* Use generic values for endpoints. */
218		loopback_scope = 1;
219#ifdef INET
220		ipv4_local_scope = 1;
221#endif
222#ifdef INET6
223		local_scope = 1;
224		site_scope = 1;
225#endif
226		if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUND_V6) {
227#ifdef INET6
228			ipv6_addr_legal = 1;
229#endif
230#ifdef INET
231			if (SCTP_IPV6_V6ONLY(inp)) {
232				ipv4_addr_legal = 0;
233			} else {
234				ipv4_addr_legal = 1;
235			}
236#endif
237		} else {
238#ifdef INET6
239			ipv6_addr_legal = 0;
240#endif
241#ifdef INET
242			ipv4_addr_legal = 1;
243#endif
244		}
245	}
246
247	/* Neither Mac OS X nor FreeBSD support multiple routing functions. */
248	if ((vrf = sctp_find_vrf(inp->def_vrf_id)) == NULL) {
249		SCTP_INP_RUNLOCK(inp);
250		SCTP_INP_INFO_RUNLOCK();
251		return (ENOENT);
252	}
253	if (inp->sctp_flags & SCTP_PCB_FLAGS_BOUNDALL) {
254		LIST_FOREACH(sctp_ifn, &vrf->ifnlist, next_ifn) {
255			if ((loopback_scope == 0) && SCTP_IFN_IS_IFT_LOOP(sctp_ifn)) {
256				/* Skip loopback if loopback_scope not set. */
257				continue;
258			}
259			LIST_FOREACH(sctp_ifa, &sctp_ifn->ifalist, next_ifa) {
260				if (stcb != NULL) {
261					/*
262					 * Ignore if blacklisted at
263					 * association level.
264					 */
265					if (sctp_is_addr_restricted(stcb, sctp_ifa)) {
266						continue;
267					}
268				}
269				switch (sctp_ifa->address.sa.sa_family) {
270#ifdef INET
271				case AF_INET:
272					if (ipv4_addr_legal) {
273						struct sockaddr_in *sin;
274
275						sin = &sctp_ifa->address.sin;
276						if (sin->sin_addr.s_addr == 0) {
277							continue;
278						}
279						if (prison_check_ip4(inp->ip_inp.inp.inp_cred,
280						    &sin->sin_addr) != 0) {
281							continue;
282						}
283						if ((ipv4_local_scope == 0) && (IN4_ISPRIVATE_ADDRESS(&sin->sin_addr))) {
284							continue;
285						}
286					} else {
287						continue;
288					}
289					break;
290#endif
291#ifdef INET6
292				case AF_INET6:
293					if (ipv6_addr_legal) {
294						struct sockaddr_in6 *sin6;
295
296						sin6 = &sctp_ifa->address.sin6;
297						if (IN6_IS_ADDR_UNSPECIFIED(&sin6->sin6_addr)) {
298							continue;
299						}
300						if (prison_check_ip6(inp->ip_inp.inp.inp_cred,
301						    &sin6->sin6_addr) != 0) {
302							continue;
303						}
304						if (IN6_IS_ADDR_LINKLOCAL(&sin6->sin6_addr)) {
305							if (local_scope == 0) {
306								continue;
307							}
308						}
309						if ((site_scope == 0) && (IN6_IS_ADDR_SITELOCAL(&sin6->sin6_addr))) {
310							continue;
311						}
312					} else {
313						continue;
314					}
315					break;
316#endif
317				default:
318					continue;
319				}
320				memset((void *)&xladdr, 0, sizeof(struct xsctp_laddr));
321				memcpy((void *)&xladdr.address, (const void *)&sctp_ifa->address, sizeof(union sctp_sockstore));
322				SCTP_INP_RUNLOCK(inp);
323				SCTP_INP_INFO_RUNLOCK();
324				error = SYSCTL_OUT(req, &xladdr, sizeof(struct xsctp_laddr));
325				if (error != 0) {
326					return (error);
327				} else {
328					SCTP_INP_INFO_RLOCK();
329					SCTP_INP_RLOCK(inp);
330				}
331			}
332		}
333	} else {
334		LIST_FOREACH(laddr, &inp->sctp_addr_list, sctp_nxt_addr) {
335			/* ignore if blacklisted at association level */
336			if (stcb != NULL && sctp_is_addr_restricted(stcb, laddr->ifa))
337				continue;
338			memset((void *)&xladdr, 0, sizeof(struct xsctp_laddr));
339			memcpy((void *)&xladdr.address, (const void *)&laddr->ifa->address, sizeof(union sctp_sockstore));
340			xladdr.start_time.tv_sec = (uint32_t)laddr->start_time.tv_sec;
341			xladdr.start_time.tv_usec = (uint32_t)laddr->start_time.tv_usec;
342			SCTP_INP_RUNLOCK(inp);
343			SCTP_INP_INFO_RUNLOCK();
344			error = SYSCTL_OUT(req, &xladdr, sizeof(struct xsctp_laddr));
345			if (error != 0) {
346				return (error);
347			} else {
348				SCTP_INP_INFO_RLOCK();
349				SCTP_INP_RLOCK(inp);
350			}
351		}
352	}
353	memset((void *)&xladdr, 0, sizeof(struct xsctp_laddr));
354	xladdr.last = 1;
355	SCTP_INP_RUNLOCK(inp);
356	SCTP_INP_INFO_RUNLOCK();
357	error = SYSCTL_OUT(req, &xladdr, sizeof(struct xsctp_laddr));
358
359	if (error != 0) {
360		return (error);
361	} else {
362		SCTP_INP_INFO_RLOCK();
363		SCTP_INP_RLOCK(inp);
364		return (0);
365	}
366}
367
368/*
369 * sysctl functions
370 */
371static int
372sctp_sysctl_handle_assoclist(SYSCTL_HANDLER_ARGS)
373{
374	unsigned int number_of_endpoints;
375	unsigned int number_of_local_addresses;
376	unsigned int number_of_associations;
377	unsigned int number_of_remote_addresses;
378	unsigned int n;
379	int error;
380	struct sctp_inpcb *inp;
381	struct sctp_tcb *stcb;
382	struct sctp_nets *net;
383	struct xsctp_inpcb xinpcb;
384	struct xsctp_tcb xstcb;
385	struct xsctp_raddr xraddr;
386	struct socket *so;
387
388	number_of_endpoints = 0;
389	number_of_local_addresses = 0;
390	number_of_associations = 0;
391	number_of_remote_addresses = 0;
392
393	SCTP_INP_INFO_RLOCK();
394	if (req->oldptr == NULL) {
395		LIST_FOREACH(inp, &SCTP_BASE_INFO(listhead), sctp_list) {
396			SCTP_INP_RLOCK(inp);
397			number_of_endpoints++;
398			number_of_local_addresses += sctp_sysctl_number_of_addresses(inp);
399			LIST_FOREACH(stcb, &inp->sctp_asoc_list, sctp_tcblist) {
400				number_of_associations++;
401				number_of_local_addresses += sctp_sysctl_number_of_addresses(inp);
402				TAILQ_FOREACH(net, &stcb->asoc.nets, sctp_next) {
403					number_of_remote_addresses++;
404				}
405			}
406			SCTP_INP_RUNLOCK(inp);
407		}
408		SCTP_INP_INFO_RUNLOCK();
409		n = (number_of_endpoints + 1) * sizeof(struct xsctp_inpcb) +
410		    (number_of_local_addresses + number_of_endpoints + number_of_associations) * sizeof(struct xsctp_laddr) +
411		    (number_of_associations + number_of_endpoints) * sizeof(struct xsctp_tcb) +
412		    (number_of_remote_addresses + number_of_associations) * sizeof(struct xsctp_raddr);
413
414		/* request some more memory than needed */
415		req->oldidx = (n + n / 8);
416		return (0);
417	}
418	if (req->newptr != NULL) {
419		SCTP_INP_INFO_RUNLOCK();
420		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTP_SYSCTL, EPERM);
421		return (EPERM);
422	}
423	memset(&xinpcb, 0, sizeof(xinpcb));
424	memset(&xstcb, 0, sizeof(xstcb));
425	memset(&xraddr, 0, sizeof(xraddr));
426	LIST_FOREACH(inp, &SCTP_BASE_INFO(listhead), sctp_list) {
427		SCTP_INP_RLOCK(inp);
428		if (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_ALLGONE) {
429			/* if its allgone it is being freed - skip it  */
430			goto skip;
431		}
432		xinpcb.last = 0;
433		xinpcb.local_port = ntohs(inp->sctp_lport);
434		xinpcb.flags = inp->sctp_flags;
435		xinpcb.features = inp->sctp_features;
436		xinpcb.total_sends = inp->total_sends;
437		xinpcb.total_recvs = inp->total_recvs;
438		xinpcb.total_nospaces = inp->total_nospaces;
439		xinpcb.fragmentation_point = inp->sctp_frag_point;
440		xinpcb.socket = (uintptr_t)inp->sctp_socket;
441		so = inp->sctp_socket;
442		if ((so == NULL) ||
443		    (!SCTP_IS_LISTENING(inp)) ||
444		    (inp->sctp_flags & SCTP_PCB_FLAGS_SOCKET_GONE)) {
445			xinpcb.qlen = 0;
446			xinpcb.maxqlen = 0;
447		} else {
448			xinpcb.qlen = so->sol_qlen;
449			xinpcb.qlen_old = so->sol_qlen > USHRT_MAX ?
450			    USHRT_MAX : (uint16_t)so->sol_qlen;
451			xinpcb.maxqlen = so->sol_qlimit;
452			xinpcb.maxqlen_old = so->sol_qlimit > USHRT_MAX ?
453			    USHRT_MAX : (uint16_t)so->sol_qlimit;
454		}
455		SCTP_INP_INCR_REF(inp);
456		SCTP_INP_RUNLOCK(inp);
457		SCTP_INP_INFO_RUNLOCK();
458		error = SYSCTL_OUT(req, &xinpcb, sizeof(struct xsctp_inpcb));
459		if (error) {
460			SCTP_INP_DECR_REF(inp);
461			return (error);
462		}
463		SCTP_INP_INFO_RLOCK();
464		SCTP_INP_RLOCK(inp);
465		error = sctp_sysctl_copy_out_local_addresses(inp, NULL, req);
466		if (error) {
467			SCTP_INP_DECR_REF(inp);
468			return (error);
469		}
470		LIST_FOREACH(stcb, &inp->sctp_asoc_list, sctp_tcblist) {
471			SCTP_TCB_LOCK(stcb);
472			atomic_add_int(&stcb->asoc.refcnt, 1);
473			SCTP_TCB_UNLOCK(stcb);
474			xstcb.last = 0;
475			xstcb.local_port = ntohs(inp->sctp_lport);
476			xstcb.remote_port = ntohs(stcb->rport);
477			if (stcb->asoc.primary_destination != NULL)
478				xstcb.primary_addr = stcb->asoc.primary_destination->ro._l_addr;
479			xstcb.heartbeat_interval = stcb->asoc.heart_beat_delay;
480			xstcb.state = (uint32_t)sctp_map_assoc_state(stcb->asoc.state);
481			xstcb.assoc_id = sctp_get_associd(stcb);
482			xstcb.peers_rwnd = stcb->asoc.peers_rwnd;
483			xstcb.in_streams = stcb->asoc.streamincnt;
484			xstcb.out_streams = stcb->asoc.streamoutcnt;
485			xstcb.max_nr_retrans = stcb->asoc.overall_error_count;
486			xstcb.primary_process = 0;	/* not really supported
487							 * yet */
488			xstcb.T1_expireries = stcb->asoc.timoinit + stcb->asoc.timocookie;
489			xstcb.T2_expireries = stcb->asoc.timoshutdown + stcb->asoc.timoshutdownack;
490			xstcb.retransmitted_tsns = stcb->asoc.marked_retrans;
491			xstcb.start_time.tv_sec = (uint32_t)stcb->asoc.start_time.tv_sec;
492			xstcb.start_time.tv_usec = (uint32_t)stcb->asoc.start_time.tv_usec;
493			xstcb.discontinuity_time.tv_sec = (uint32_t)stcb->asoc.discontinuity_time.tv_sec;
494			xstcb.discontinuity_time.tv_usec = (uint32_t)stcb->asoc.discontinuity_time.tv_usec;
495			xstcb.total_sends = stcb->total_sends;
496			xstcb.total_recvs = stcb->total_recvs;
497			xstcb.local_tag = stcb->asoc.my_vtag;
498			xstcb.remote_tag = stcb->asoc.peer_vtag;
499			xstcb.initial_tsn = stcb->asoc.init_seq_number;
500			xstcb.highest_tsn = stcb->asoc.sending_seq - 1;
501			xstcb.cumulative_tsn = stcb->asoc.last_acked_seq;
502			xstcb.cumulative_tsn_ack = stcb->asoc.cumulative_tsn;
503			xstcb.mtu = stcb->asoc.smallest_mtu;
504			xstcb.refcnt = stcb->asoc.refcnt;
505			SCTP_INP_RUNLOCK(inp);
506			SCTP_INP_INFO_RUNLOCK();
507			error = SYSCTL_OUT(req, &xstcb, sizeof(struct xsctp_tcb));
508			if (error) {
509				SCTP_INP_DECR_REF(inp);
510				atomic_subtract_int(&stcb->asoc.refcnt, 1);
511				return (error);
512			}
513			SCTP_INP_INFO_RLOCK();
514			SCTP_INP_RLOCK(inp);
515			error = sctp_sysctl_copy_out_local_addresses(inp, stcb, req);
516			if (error) {
517				SCTP_INP_DECR_REF(inp);
518				atomic_subtract_int(&stcb->asoc.refcnt, 1);
519				return (error);
520			}
521			TAILQ_FOREACH(net, &stcb->asoc.nets, sctp_next) {
522				xraddr.last = 0;
523				xraddr.address = net->ro._l_addr;
524				xraddr.active = ((net->dest_state & SCTP_ADDR_REACHABLE) == SCTP_ADDR_REACHABLE);
525				xraddr.confirmed = ((net->dest_state & SCTP_ADDR_UNCONFIRMED) == 0);
526				xraddr.heartbeat_enabled = ((net->dest_state & SCTP_ADDR_NOHB) == 0);
527				xraddr.potentially_failed = ((net->dest_state & SCTP_ADDR_PF) == SCTP_ADDR_PF);
528				xraddr.rto = net->RTO;
529				xraddr.max_path_rtx = net->failure_threshold;
530				xraddr.rtx = net->marked_retrans;
531				xraddr.error_counter = net->error_count;
532				xraddr.cwnd = net->cwnd;
533				xraddr.flight_size = net->flight_size;
534				xraddr.mtu = net->mtu;
535				xraddr.rtt = net->rtt / 1000;
536				xraddr.heartbeat_interval = net->heart_beat_delay;
537				xraddr.ssthresh = net->ssthresh;
538				xraddr.encaps_port = net->port;
539				if (net->dest_state & SCTP_ADDR_UNCONFIRMED) {
540					xraddr.state = SCTP_UNCONFIRMED;
541				} else if (net->dest_state & SCTP_ADDR_REACHABLE) {
542					xraddr.state = SCTP_ACTIVE;
543				} else {
544					xraddr.state = SCTP_INACTIVE;
545				}
546				xraddr.start_time.tv_sec = (uint32_t)net->start_time.tv_sec;
547				xraddr.start_time.tv_usec = (uint32_t)net->start_time.tv_usec;
548				SCTP_INP_RUNLOCK(inp);
549				SCTP_INP_INFO_RUNLOCK();
550				error = SYSCTL_OUT(req, &xraddr, sizeof(struct xsctp_raddr));
551				if (error) {
552					SCTP_INP_DECR_REF(inp);
553					atomic_subtract_int(&stcb->asoc.refcnt, 1);
554					return (error);
555				}
556				SCTP_INP_INFO_RLOCK();
557				SCTP_INP_RLOCK(inp);
558			}
559			atomic_subtract_int(&stcb->asoc.refcnt, 1);
560			memset((void *)&xraddr, 0, sizeof(struct xsctp_raddr));
561			xraddr.last = 1;
562			SCTP_INP_RUNLOCK(inp);
563			SCTP_INP_INFO_RUNLOCK();
564			error = SYSCTL_OUT(req, &xraddr, sizeof(struct xsctp_raddr));
565			if (error) {
566				SCTP_INP_DECR_REF(inp);
567				return (error);
568			}
569			SCTP_INP_INFO_RLOCK();
570			SCTP_INP_RLOCK(inp);
571		}
572		SCTP_INP_DECR_REF(inp);
573		SCTP_INP_RUNLOCK(inp);
574		SCTP_INP_INFO_RUNLOCK();
575		memset((void *)&xstcb, 0, sizeof(struct xsctp_tcb));
576		xstcb.last = 1;
577		error = SYSCTL_OUT(req, &xstcb, sizeof(struct xsctp_tcb));
578		if (error) {
579			return (error);
580		}
581skip:
582		SCTP_INP_INFO_RLOCK();
583	}
584	SCTP_INP_INFO_RUNLOCK();
585
586	memset((void *)&xinpcb, 0, sizeof(struct xsctp_inpcb));
587	xinpcb.last = 1;
588	error = SYSCTL_OUT(req, &xinpcb, sizeof(struct xsctp_inpcb));
589	return (error);
590}
591
592static int
593sctp_sysctl_handle_udp_tunneling(SYSCTL_HANDLER_ARGS)
594{
595	int error;
596	uint32_t old, new;
597
598	SCTP_INP_INFO_RLOCK();
599	old = SCTP_BASE_SYSCTL(sctp_udp_tunneling_port);
600	SCTP_INP_INFO_RUNLOCK();
601	new = old;
602	error = sysctl_handle_int(oidp, &new, 0, req);
603	if ((error == 0) &&
604	    (req->newptr != NULL)) {
605#if (SCTPCTL_UDP_TUNNELING_PORT_MIN == 0)
606		if (new > SCTPCTL_UDP_TUNNELING_PORT_MAX) {
607#else
608		if ((new < SCTPCTL_UDP_TUNNELING_PORT_MIN) ||
609		    (new > SCTPCTL_UDP_TUNNELING_PORT_MAX)) {
610#endif
611			error = EINVAL;
612		} else {
613			SCTP_INP_INFO_WLOCK();
614			SCTP_BASE_SYSCTL(sctp_udp_tunneling_port) = new;
615			if (old != 0) {
616				sctp_over_udp_stop();
617			}
618			if (new != 0) {
619				error = sctp_over_udp_start();
620			}
621			SCTP_INP_INFO_WUNLOCK();
622		}
623	}
624	return (error);
625}
626
627static int
628sctp_sysctl_handle_auth(SYSCTL_HANDLER_ARGS)
629{
630	int error;
631	uint32_t new;
632
633	new = SCTP_BASE_SYSCTL(sctp_auth_enable);
634	error = sysctl_handle_int(oidp, &new, 0, req);
635	if ((error == 0) &&
636	    (req->newptr != NULL)) {
637#if (SCTPCTL_AUTH_ENABLE_MIN == 0)
638		if ((new > SCTPCTL_AUTH_ENABLE_MAX) ||
639		    ((new == 0) && (SCTP_BASE_SYSCTL(sctp_asconf_enable) == 1))) {
640#else
641		if ((new < SCTPCTL_AUTH_ENABLE_MIN) ||
642		    (new > SCTPCTL_AUTH_ENABLE_MAX) ||
643		    ((new == 0) && (SCTP_BASE_SYSCTL(sctp_asconf_enable) == 1))) {
644#endif
645			error = EINVAL;
646		} else {
647			SCTP_BASE_SYSCTL(sctp_auth_enable) = new;
648		}
649	}
650	return (error);
651}
652
653static int
654sctp_sysctl_handle_asconf(SYSCTL_HANDLER_ARGS)
655{
656	int error;
657	uint32_t new;
658
659	new = SCTP_BASE_SYSCTL(sctp_asconf_enable);
660	error = sysctl_handle_int(oidp, &new, 0, req);
661	if ((error == 0) &&
662	    (req->newptr != NULL)) {
663#if (SCTPCTL_ASCONF_ENABLE_MIN == 0)
664		if ((new > SCTPCTL_ASCONF_ENABLE_MAX) ||
665		    ((new == 1) && (SCTP_BASE_SYSCTL(sctp_auth_enable) == 0))) {
666#else
667		if ((new < SCTPCTL_ASCONF_ENABLE_MIN) ||
668		    (new > SCTPCTL_ASCONF_ENABLE_MAX) ||
669		    ((new == 1) && (SCTP_BASE_SYSCTL(sctp_auth_enable) == 0))) {
670#endif
671			error = EINVAL;
672		} else {
673			SCTP_BASE_SYSCTL(sctp_asconf_enable) = new;
674		}
675	}
676	return (error);
677}
678
679static int
680sctp_sysctl_handle_stats(SYSCTL_HANDLER_ARGS)
681{
682	int error;
683#if defined(SMP) && defined(SCTP_USE_PERCPU_STAT)
684	struct sctpstat *sarry;
685	struct sctpstat sb;
686	int cpu;
687#endif
688	struct sctpstat sb_temp;
689
690	if ((req->newptr != NULL) &&
691	    (req->newlen != sizeof(struct sctpstat))) {
692		return (EINVAL);
693	}
694	memset(&sb_temp, 0, sizeof(struct sctpstat));
695
696	if (req->newptr != NULL) {
697		error = SYSCTL_IN(req, &sb_temp, sizeof(struct sctpstat));
698		if (error != 0) {
699			return (error);
700		}
701	}
702#if defined(SMP) && defined(SCTP_USE_PERCPU_STAT)
703	memset(&sb, 0, sizeof(sb));
704	for (cpu = 0; cpu < mp_maxid; cpu++) {
705		sarry = &SCTP_BASE_STATS[cpu];
706		if (sarry->sctps_discontinuitytime.tv_sec > sb.sctps_discontinuitytime.tv_sec) {
707			sb.sctps_discontinuitytime.tv_sec = sarry->sctps_discontinuitytime.tv_sec;
708			sb.sctps_discontinuitytime.tv_usec = sarry->sctps_discontinuitytime.tv_usec;
709		}
710		sb.sctps_currestab += sarry->sctps_currestab;
711		sb.sctps_activeestab += sarry->sctps_activeestab;
712		sb.sctps_restartestab += sarry->sctps_restartestab;
713		sb.sctps_collisionestab += sarry->sctps_collisionestab;
714		sb.sctps_passiveestab += sarry->sctps_passiveestab;
715		sb.sctps_aborted += sarry->sctps_aborted;
716		sb.sctps_shutdown += sarry->sctps_shutdown;
717		sb.sctps_outoftheblue += sarry->sctps_outoftheblue;
718		sb.sctps_checksumerrors += sarry->sctps_checksumerrors;
719		sb.sctps_outcontrolchunks += sarry->sctps_outcontrolchunks;
720		sb.sctps_outorderchunks += sarry->sctps_outorderchunks;
721		sb.sctps_outunorderchunks += sarry->sctps_outunorderchunks;
722		sb.sctps_incontrolchunks += sarry->sctps_incontrolchunks;
723		sb.sctps_inorderchunks += sarry->sctps_inorderchunks;
724		sb.sctps_inunorderchunks += sarry->sctps_inunorderchunks;
725		sb.sctps_fragusrmsgs += sarry->sctps_fragusrmsgs;
726		sb.sctps_reasmusrmsgs += sarry->sctps_reasmusrmsgs;
727		sb.sctps_outpackets += sarry->sctps_outpackets;
728		sb.sctps_inpackets += sarry->sctps_inpackets;
729		sb.sctps_recvpackets += sarry->sctps_recvpackets;
730		sb.sctps_recvdatagrams += sarry->sctps_recvdatagrams;
731		sb.sctps_recvpktwithdata += sarry->sctps_recvpktwithdata;
732		sb.sctps_recvsacks += sarry->sctps_recvsacks;
733		sb.sctps_recvdata += sarry->sctps_recvdata;
734		sb.sctps_recvdupdata += sarry->sctps_recvdupdata;
735		sb.sctps_recvheartbeat += sarry->sctps_recvheartbeat;
736		sb.sctps_recvheartbeatack += sarry->sctps_recvheartbeatack;
737		sb.sctps_recvecne += sarry->sctps_recvecne;
738		sb.sctps_recvauth += sarry->sctps_recvauth;
739		sb.sctps_recvauthmissing += sarry->sctps_recvauthmissing;
740		sb.sctps_recvivalhmacid += sarry->sctps_recvivalhmacid;
741		sb.sctps_recvivalkeyid += sarry->sctps_recvivalkeyid;
742		sb.sctps_recvauthfailed += sarry->sctps_recvauthfailed;
743		sb.sctps_recvexpress += sarry->sctps_recvexpress;
744		sb.sctps_recvexpressm += sarry->sctps_recvexpressm;
745		sb.sctps_recvswcrc += sarry->sctps_recvswcrc;
746		sb.sctps_recvhwcrc += sarry->sctps_recvhwcrc;
747		sb.sctps_sendpackets += sarry->sctps_sendpackets;
748		sb.sctps_sendsacks += sarry->sctps_sendsacks;
749		sb.sctps_senddata += sarry->sctps_senddata;
750		sb.sctps_sendretransdata += sarry->sctps_sendretransdata;
751		sb.sctps_sendfastretrans += sarry->sctps_sendfastretrans;
752		sb.sctps_sendmultfastretrans += sarry->sctps_sendmultfastretrans;
753		sb.sctps_sendheartbeat += sarry->sctps_sendheartbeat;
754		sb.sctps_sendecne += sarry->sctps_sendecne;
755		sb.sctps_sendauth += sarry->sctps_sendauth;
756		sb.sctps_senderrors += sarry->sctps_senderrors;
757		sb.sctps_sendswcrc += sarry->sctps_sendswcrc;
758		sb.sctps_sendhwcrc += sarry->sctps_sendhwcrc;
759		sb.sctps_pdrpfmbox += sarry->sctps_pdrpfmbox;
760		sb.sctps_pdrpfehos += sarry->sctps_pdrpfehos;
761		sb.sctps_pdrpmbda += sarry->sctps_pdrpmbda;
762		sb.sctps_pdrpmbct += sarry->sctps_pdrpmbct;
763		sb.sctps_pdrpbwrpt += sarry->sctps_pdrpbwrpt;
764		sb.sctps_pdrpcrupt += sarry->sctps_pdrpcrupt;
765		sb.sctps_pdrpnedat += sarry->sctps_pdrpnedat;
766		sb.sctps_pdrppdbrk += sarry->sctps_pdrppdbrk;
767		sb.sctps_pdrptsnnf += sarry->sctps_pdrptsnnf;
768		sb.sctps_pdrpdnfnd += sarry->sctps_pdrpdnfnd;
769		sb.sctps_pdrpdiwnp += sarry->sctps_pdrpdiwnp;
770		sb.sctps_pdrpdizrw += sarry->sctps_pdrpdizrw;
771		sb.sctps_pdrpbadd += sarry->sctps_pdrpbadd;
772		sb.sctps_pdrpmark += sarry->sctps_pdrpmark;
773		sb.sctps_timoiterator += sarry->sctps_timoiterator;
774		sb.sctps_timodata += sarry->sctps_timodata;
775		sb.sctps_timowindowprobe += sarry->sctps_timowindowprobe;
776		sb.sctps_timoinit += sarry->sctps_timoinit;
777		sb.sctps_timosack += sarry->sctps_timosack;
778		sb.sctps_timoshutdown += sarry->sctps_timoshutdown;
779		sb.sctps_timoheartbeat += sarry->sctps_timoheartbeat;
780		sb.sctps_timocookie += sarry->sctps_timocookie;
781		sb.sctps_timosecret += sarry->sctps_timosecret;
782		sb.sctps_timopathmtu += sarry->sctps_timopathmtu;
783		sb.sctps_timoshutdownack += sarry->sctps_timoshutdownack;
784		sb.sctps_timoshutdownguard += sarry->sctps_timoshutdownguard;
785		sb.sctps_timostrmrst += sarry->sctps_timostrmrst;
786		sb.sctps_timoearlyfr += sarry->sctps_timoearlyfr;
787		sb.sctps_timoasconf += sarry->sctps_timoasconf;
788		sb.sctps_timodelprim += sarry->sctps_timodelprim;
789		sb.sctps_timoautoclose += sarry->sctps_timoautoclose;
790		sb.sctps_timoassockill += sarry->sctps_timoassockill;
791		sb.sctps_timoinpkill += sarry->sctps_timoinpkill;
792		sb.sctps_hdrops += sarry->sctps_hdrops;
793		sb.sctps_badsum += sarry->sctps_badsum;
794		sb.sctps_noport += sarry->sctps_noport;
795		sb.sctps_badvtag += sarry->sctps_badvtag;
796		sb.sctps_badsid += sarry->sctps_badsid;
797		sb.sctps_nomem += sarry->sctps_nomem;
798		sb.sctps_fastretransinrtt += sarry->sctps_fastretransinrtt;
799		sb.sctps_markedretrans += sarry->sctps_markedretrans;
800		sb.sctps_naglesent += sarry->sctps_naglesent;
801		sb.sctps_naglequeued += sarry->sctps_naglequeued;
802		sb.sctps_maxburstqueued += sarry->sctps_maxburstqueued;
803		sb.sctps_ifnomemqueued += sarry->sctps_ifnomemqueued;
804		sb.sctps_windowprobed += sarry->sctps_windowprobed;
805		sb.sctps_lowlevelerr += sarry->sctps_lowlevelerr;
806		sb.sctps_lowlevelerrusr += sarry->sctps_lowlevelerrusr;
807		sb.sctps_datadropchklmt += sarry->sctps_datadropchklmt;
808		sb.sctps_datadroprwnd += sarry->sctps_datadroprwnd;
809		sb.sctps_ecnereducedcwnd += sarry->sctps_ecnereducedcwnd;
810		sb.sctps_vtagexpress += sarry->sctps_vtagexpress;
811		sb.sctps_vtagbogus += sarry->sctps_vtagbogus;
812		sb.sctps_primary_randry += sarry->sctps_primary_randry;
813		sb.sctps_cmt_randry += sarry->sctps_cmt_randry;
814		sb.sctps_slowpath_sack += sarry->sctps_slowpath_sack;
815		sb.sctps_wu_sacks_sent += sarry->sctps_wu_sacks_sent;
816		sb.sctps_sends_with_flags += sarry->sctps_sends_with_flags;
817		sb.sctps_sends_with_unord += sarry->sctps_sends_with_unord;
818		sb.sctps_sends_with_eof += sarry->sctps_sends_with_eof;
819		sb.sctps_sends_with_abort += sarry->sctps_sends_with_abort;
820		sb.sctps_protocol_drain_calls += sarry->sctps_protocol_drain_calls;
821		sb.sctps_protocol_drains_done += sarry->sctps_protocol_drains_done;
822		sb.sctps_read_peeks += sarry->sctps_read_peeks;
823		sb.sctps_cached_chk += sarry->sctps_cached_chk;
824		sb.sctps_cached_strmoq += sarry->sctps_cached_strmoq;
825		sb.sctps_left_abandon += sarry->sctps_left_abandon;
826		sb.sctps_send_burst_avoid += sarry->sctps_send_burst_avoid;
827		sb.sctps_send_cwnd_avoid += sarry->sctps_send_cwnd_avoid;
828		sb.sctps_fwdtsn_map_over += sarry->sctps_fwdtsn_map_over;
829		sb.sctps_queue_upd_ecne += sarry->sctps_queue_upd_ecne;
830		sb.sctps_recvzerocrc += sarry->sctps_recvzerocrc;
831		sb.sctps_sendzerocrc += sarry->sctps_sendzerocrc;
832		if (req->newptr != NULL) {
833			memcpy(sarry, &sb_temp, sizeof(struct sctpstat));
834		}
835	}
836	error = SYSCTL_OUT(req, &sb, sizeof(struct sctpstat));
837#else
838	error = SYSCTL_OUT(req, &SCTP_BASE_STATS, sizeof(struct sctpstat));
839	if (error != 0) {
840		return (error);
841	}
842	if (req->newptr != NULL) {
843		memcpy(&SCTP_BASE_STATS, &sb_temp, sizeof(struct sctpstat));
844	}
845#endif
846	return (error);
847}
848
849#if defined(SCTP_LOCAL_TRACE_BUF)
850static int
851sctp_sysctl_handle_trace_log(SYSCTL_HANDLER_ARGS)
852{
853	int error;
854
855	error = SYSCTL_OUT(req, &SCTP_BASE_SYSCTL(sctp_log), sizeof(struct sctp_log));
856	return (error);
857}
858
859static int
860sctp_sysctl_handle_trace_log_clear(SYSCTL_HANDLER_ARGS)
861{
862	int error = 0;
863
864	memset(&SCTP_BASE_SYSCTL(sctp_log), 0, sizeof(struct sctp_log));
865	return (error);
866}
867#endif
868
869#define SCTP_UINT_SYSCTL(mib_name, var_name, prefix)			\
870	SCTP_UINT_SYSCTL_FLAG(mib_name, var_name, prefix,		\
871	    CTLFLAG_VNET|CTLTYPE_UINT|CTLFLAG_RW)
872
873#define SCTP_UINT_SYSCTL_TUN(mib_name, var_name, prefix)		\
874	SCTP_UINT_SYSCTL_FLAG(mib_name, var_name, prefix,		\
875	    CTLFLAG_VNET|CTLTYPE_UINT|CTLFLAG_RWTUN|CTLFLAG_NOFETCH)
876
877#define SCTP_UINT_SYSCTL_FLAG(mib_name, var_name, prefix, flags)	\
878	static int							\
879	sctp_sysctl_handle_##mib_name(SYSCTL_HANDLER_ARGS)		\
880	{								\
881		int error;						\
882		uint32_t new;						\
883									\
884		new = SCTP_BASE_SYSCTL(var_name);			\
885		error = sysctl_handle_int(oidp, &new, 0, req);		\
886		if ((error == 0) && (req->newptr != NULL)) {		\
887			if ((new < prefix##_MIN) ||			\
888			    (new > prefix##_MAX)) {			\
889				error = EINVAL;				\
890			} else {					\
891				SCTP_BASE_SYSCTL(var_name) = new;	\
892			}						\
893		}							\
894		return (error);						\
895	}								\
896	SYSCTL_PROC(_net_inet_sctp, OID_AUTO, mib_name, flags, NULL, 0,	\
897	    sctp_sysctl_handle_##mib_name, "UI", prefix##_DESC)
898
899#define SCTP_UINT_SYSCTL_RDTUN(mib_name, var_name, prefix)		\
900	SYSCTL_UINT(_net_inet_sctp, OID_AUTO, mib_name,			\
901	    CTLFLAG_VNET|CTLFLAG_RDTUN|CTLFLAG_NOFETCH,			\
902	    &VNET_NAME(system_base_info.sctpsysctl.var_name), 0,	\
903	    prefix##_DESC)
904
905/*
906 * sysctl definitions
907 */
908
909SCTP_UINT_SYSCTL(sendspace, sctp_sendspace, SCTPCTL_MAXDGRAM);
910SCTP_UINT_SYSCTL(recvspace, sctp_recvspace, SCTPCTL_RECVSPACE);
911SCTP_UINT_SYSCTL(auto_asconf, sctp_auto_asconf, SCTPCTL_AUTOASCONF);
912SCTP_UINT_SYSCTL(ecn_enable, sctp_ecn_enable, SCTPCTL_ECN_ENABLE);
913SCTP_UINT_SYSCTL(pr_enable, sctp_pr_enable, SCTPCTL_PR_ENABLE);
914SYSCTL_PROC(_net_inet_sctp, OID_AUTO, auth_enable, CTLFLAG_VNET | CTLTYPE_UINT | CTLFLAG_RW,
915    NULL, 0, sctp_sysctl_handle_auth, "IU", SCTPCTL_AUTH_ENABLE_DESC);
916SYSCTL_PROC(_net_inet_sctp, OID_AUTO, asconf_enable, CTLFLAG_VNET | CTLTYPE_UINT | CTLFLAG_RW,
917    NULL, 0, sctp_sysctl_handle_asconf, "IU", SCTPCTL_ASCONF_ENABLE_DESC);
918SCTP_UINT_SYSCTL(reconfig_enable, sctp_reconfig_enable, SCTPCTL_RECONFIG_ENABLE);
919SCTP_UINT_SYSCTL(nrsack_enable, sctp_nrsack_enable, SCTPCTL_NRSACK_ENABLE);
920SCTP_UINT_SYSCTL(pktdrop_enable, sctp_pktdrop_enable, SCTPCTL_PKTDROP_ENABLE);
921SCTP_UINT_SYSCTL(peer_chkoh, sctp_peer_chunk_oh, SCTPCTL_PEER_CHKOH);
922SCTP_UINT_SYSCTL(maxburst, sctp_max_burst_default, SCTPCTL_MAXBURST);
923SCTP_UINT_SYSCTL(fr_maxburst, sctp_fr_max_burst_default, SCTPCTL_FRMAXBURST);
924SCTP_UINT_SYSCTL(maxchunks, sctp_max_chunks_on_queue, SCTPCTL_MAXCHUNKS);
925SCTP_UINT_SYSCTL_RDTUN(tcbhashsize, sctp_hashtblsize, SCTPCTL_TCBHASHSIZE);
926SCTP_UINT_SYSCTL_TUN(pcbhashsize, sctp_pcbtblsize, SCTPCTL_PCBHASHSIZE);
927SCTP_UINT_SYSCTL_RDTUN(chunkscale, sctp_chunkscale, SCTPCTL_CHUNKSCALE);
928SCTP_UINT_SYSCTL(min_split_point, sctp_min_split_point, SCTPCTL_MIN_SPLIT_POINT);
929SCTP_UINT_SYSCTL(delayed_sack_time, sctp_delayed_sack_time_default, SCTPCTL_DELAYED_SACK_TIME);
930SCTP_UINT_SYSCTL(sack_freq, sctp_sack_freq_default, SCTPCTL_SACK_FREQ);
931SCTP_UINT_SYSCTL(sys_resource, sctp_system_free_resc_limit, SCTPCTL_SYS_RESOURCE);
932SCTP_UINT_SYSCTL(asoc_resource, sctp_asoc_free_resc_limit, SCTPCTL_ASOC_RESOURCE);
933SCTP_UINT_SYSCTL(heartbeat_interval, sctp_heartbeat_interval_default, SCTPCTL_HEARTBEAT_INTERVAL);
934SCTP_UINT_SYSCTL(pmtu_raise_time, sctp_pmtu_raise_time_default, SCTPCTL_PMTU_RAISE_TIME);
935SCTP_UINT_SYSCTL(shutdown_guard_time, sctp_shutdown_guard_time_default, SCTPCTL_SHUTDOWN_GUARD_TIME);
936SCTP_UINT_SYSCTL(secret_lifetime, sctp_secret_lifetime_default, SCTPCTL_SECRET_LIFETIME);
937SCTP_UINT_SYSCTL(rto_max, sctp_rto_max_default, SCTPCTL_RTO_MAX);
938SCTP_UINT_SYSCTL(rto_min, sctp_rto_min_default, SCTPCTL_RTO_MIN);
939SCTP_UINT_SYSCTL(rto_initial, sctp_rto_initial_default, SCTPCTL_RTO_INITIAL);
940SCTP_UINT_SYSCTL(init_rto_max, sctp_init_rto_max_default, SCTPCTL_INIT_RTO_MAX);
941SCTP_UINT_SYSCTL(valid_cookie_life, sctp_valid_cookie_life_default, SCTPCTL_VALID_COOKIE_LIFE);
942SCTP_UINT_SYSCTL(init_rtx_max, sctp_init_rtx_max_default, SCTPCTL_INIT_RTX_MAX);
943SCTP_UINT_SYSCTL(assoc_rtx_max, sctp_assoc_rtx_max_default, SCTPCTL_ASSOC_RTX_MAX);
944SCTP_UINT_SYSCTL(path_rtx_max, sctp_path_rtx_max_default, SCTPCTL_PATH_RTX_MAX);
945SCTP_UINT_SYSCTL(path_pf_threshold, sctp_path_pf_threshold, SCTPCTL_PATH_PF_THRESHOLD);
946SCTP_UINT_SYSCTL(add_more_on_output, sctp_add_more_threshold, SCTPCTL_ADD_MORE_ON_OUTPUT);
947SCTP_UINT_SYSCTL(incoming_streams, sctp_nr_incoming_streams_default, SCTPCTL_INCOMING_STREAMS);
948SCTP_UINT_SYSCTL(outgoing_streams, sctp_nr_outgoing_streams_default, SCTPCTL_OUTGOING_STREAMS);
949SCTP_UINT_SYSCTL(cmt_on_off, sctp_cmt_on_off, SCTPCTL_CMT_ON_OFF);
950SCTP_UINT_SYSCTL(cmt_use_dac, sctp_cmt_use_dac, SCTPCTL_CMT_USE_DAC);
951SCTP_UINT_SYSCTL(cwnd_maxburst, sctp_use_cwnd_based_maxburst, SCTPCTL_CWND_MAXBURST);
952SCTP_UINT_SYSCTL(nat_friendly, sctp_nat_friendly, SCTPCTL_NAT_FRIENDLY);
953SCTP_UINT_SYSCTL(abc_l_var, sctp_L2_abc_variable, SCTPCTL_ABC_L_VAR);
954SCTP_UINT_SYSCTL(max_chained_mbufs, sctp_mbuf_threshold_count, SCTPCTL_MAX_CHAINED_MBUFS);
955SCTP_UINT_SYSCTL(do_sctp_drain, sctp_do_drain, SCTPCTL_DO_SCTP_DRAIN);
956SCTP_UINT_SYSCTL(hb_max_burst, sctp_hb_maxburst, SCTPCTL_HB_MAX_BURST);
957SCTP_UINT_SYSCTL(abort_at_limit, sctp_abort_if_one_2_one_hits_limit, SCTPCTL_ABORT_AT_LIMIT);
958SCTP_UINT_SYSCTL(min_residual, sctp_min_residual, SCTPCTL_MIN_RESIDUAL);
959SCTP_UINT_SYSCTL(max_retran_chunk, sctp_max_retran_chunk, SCTPCTL_MAX_RETRAN_CHUNK);
960SCTP_UINT_SYSCTL(log_level, sctp_logging_level, SCTPCTL_LOGGING_LEVEL);
961SCTP_UINT_SYSCTL(default_cc_module, sctp_default_cc_module, SCTPCTL_DEFAULT_CC_MODULE);
962SCTP_UINT_SYSCTL(default_ss_module, sctp_default_ss_module, SCTPCTL_DEFAULT_SS_MODULE);
963SCTP_UINT_SYSCTL(default_frag_interleave, sctp_default_frag_interleave, SCTPCTL_DEFAULT_FRAG_INTERLEAVE);
964SCTP_UINT_SYSCTL(mobility_base, sctp_mobility_base, SCTPCTL_MOBILITY_BASE);
965SCTP_UINT_SYSCTL(mobility_fasthandoff, sctp_mobility_fasthandoff, SCTPCTL_MOBILITY_FASTHANDOFF);
966#if defined(SCTP_LOCAL_TRACE_BUF)
967SYSCTL_PROC(_net_inet_sctp, OID_AUTO, log, CTLFLAG_VNET | CTLTYPE_STRUCT | CTLFLAG_RD,
968    NULL, 0, sctp_sysctl_handle_trace_log, "S,sctplog", "SCTP logging (struct sctp_log)");
969SYSCTL_PROC(_net_inet_sctp, OID_AUTO, clear_trace, CTLFLAG_VNET | CTLTYPE_UINT | CTLFLAG_RW,
970    NULL, 0, sctp_sysctl_handle_trace_log_clear, "IU", "Clear SCTP Logging buffer");
971#endif
972SYSCTL_PROC(_net_inet_sctp, OID_AUTO, udp_tunneling_port, CTLFLAG_VNET | CTLTYPE_UINT | CTLFLAG_RW,
973    NULL, 0, sctp_sysctl_handle_udp_tunneling, "IU", SCTPCTL_UDP_TUNNELING_PORT_DESC);
974SCTP_UINT_SYSCTL(enable_sack_immediately, sctp_enable_sack_immediately, SCTPCTL_SACK_IMMEDIATELY_ENABLE);
975SCTP_UINT_SYSCTL(nat_friendly_init, sctp_inits_include_nat_friendly, SCTPCTL_NAT_FRIENDLY_INITS);
976SCTP_UINT_SYSCTL(vtag_time_wait, sctp_vtag_time_wait, SCTPCTL_TIME_WAIT);
977SCTP_UINT_SYSCTL(buffer_splitting, sctp_buffer_splitting, SCTPCTL_BUFFER_SPLITTING);
978SCTP_UINT_SYSCTL(initial_cwnd, sctp_initial_cwnd, SCTPCTL_INITIAL_CWND);
979SCTP_UINT_SYSCTL(rttvar_bw, sctp_rttvar_bw, SCTPCTL_RTTVAR_BW);
980SCTP_UINT_SYSCTL(rttvar_rtt, sctp_rttvar_rtt, SCTPCTL_RTTVAR_RTT);
981SCTP_UINT_SYSCTL(rttvar_eqret, sctp_rttvar_eqret, SCTPCTL_RTTVAR_EQRET);
982SCTP_UINT_SYSCTL(rttvar_steady_step, sctp_steady_step, SCTPCTL_RTTVAR_STEADYS);
983SCTP_UINT_SYSCTL(use_dcccecn, sctp_use_dccc_ecn, SCTPCTL_RTTVAR_DCCCECN);
984SCTP_UINT_SYSCTL(blackhole, sctp_blackhole, SCTPCTL_BLACKHOLE);
985SCTP_UINT_SYSCTL(sendall_limit, sctp_sendall_limit, SCTPCTL_SENDALL_LIMIT);
986SCTP_UINT_SYSCTL(diag_info_code, sctp_diag_info_code, SCTPCTL_DIAG_INFO_CODE);
987SCTP_UINT_SYSCTL(ootb_with_zero_cksum, sctp_ootb_with_zero_cksum, SCTPCTL_OOTB_WITH_ZERO_CKSUM);
988#ifdef SCTP_DEBUG
989SCTP_UINT_SYSCTL(debug, sctp_debug_on, SCTPCTL_DEBUG);
990#endif
991SYSCTL_PROC(_net_inet_sctp, OID_AUTO, stats, CTLFLAG_VNET | CTLTYPE_STRUCT | CTLFLAG_RW,
992    NULL, 0, sctp_sysctl_handle_stats, "S,sctpstat", "SCTP statistics (struct sctp_stat)");
993SYSCTL_PROC(_net_inet_sctp, OID_AUTO, assoclist, CTLFLAG_VNET | CTLTYPE_OPAQUE | CTLFLAG_RD,
994    NULL, 0, sctp_sysctl_handle_assoclist, "S,xassoc", "List of active SCTP associations");
995