1/*-
2 * SPDX-License-Identifier: BSD-3-Clause
3 *
4 * Copyright (c) 2001-2007, by Cisco Systems, Inc. All rights reserved.
5 * Copyright (c) 2008-2012, by Randall Stewart. All rights reserved.
6 * Copyright (c) 2008-2012, by Michael Tuexen. All rights reserved.
7 *
8 * Redistribution and use in source and binary forms, with or without
9 * modification, are permitted provided that the following conditions are met:
10 *
11 * a) Redistributions of source code must retain the above copyright notice,
12 *    this list of conditions and the following disclaimer.
13 *
14 * b) Redistributions in binary form must reproduce the above copyright
15 *    notice, this list of conditions and the following disclaimer in
16 *    the documentation and/or other materials provided with the distribution.
17 *
18 * c) Neither the name of Cisco Systems, Inc. nor the names of its
19 *    contributors may be used to endorse or promote products derived
20 *    from this software without specific prior written permission.
21 *
22 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
23 * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
24 * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25 * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
26 * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
27 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
28 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
29 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
30 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
31 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
32 * THE POSSIBILITY OF SUCH DAMAGE.
33 */
34
35#include <sys/cdefs.h>
36__FBSDID("$FreeBSD$");
37
38#include <netinet/sctp_os.h>
39#include <netinet/sctp_pcb.h>
40#include <netinet/sctputil.h>
41#include <netinet/sctp_var.h>
42#include <netinet/sctp_var.h>
43#include <netinet/sctp_sysctl.h>
44#include <netinet/sctp.h>
45#include <netinet/sctp_uio.h>
46#include <netinet/sctp_peeloff.h>
47#include <netinet/sctputil.h>
48#include <netinet/sctp_auth.h>
49
50int
51sctp_can_peel_off(struct socket *head, sctp_assoc_t assoc_id)
52{
53	struct sctp_inpcb *inp;
54	struct sctp_tcb *stcb;
55	uint32_t state;
56
57	if (head == NULL) {
58		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTP_PEELOFF, EBADF);
59		return (EBADF);
60	}
61	inp = (struct sctp_inpcb *)head->so_pcb;
62	if (inp == NULL) {
63		SCTP_LTRACE_ERR_RET(NULL, NULL, NULL, SCTP_FROM_SCTP_PEELOFF, EFAULT);
64		return (EFAULT);
65	}
66	if ((inp->sctp_flags & SCTP_PCB_FLAGS_TCPTYPE) ||
67	    (inp->sctp_flags & SCTP_PCB_FLAGS_IN_TCPPOOL)) {
68		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTP_PEELOFF, EOPNOTSUPP);
69		return (EOPNOTSUPP);
70	}
71	stcb = sctp_findassociation_ep_asocid(inp, assoc_id, 1);
72	if (stcb == NULL) {
73		SCTP_LTRACE_ERR_RET(inp, stcb, NULL, SCTP_FROM_SCTP_PEELOFF, ENOENT);
74		return (ENOENT);
75	}
76	state = SCTP_GET_STATE(stcb);
77	if ((state == SCTP_STATE_EMPTY) ||
78	    (state == SCTP_STATE_INUSE)) {
79		SCTP_TCB_UNLOCK(stcb);
80		SCTP_LTRACE_ERR_RET(inp, stcb, NULL, SCTP_FROM_SCTP_PEELOFF, ENOTCONN);
81		return (ENOTCONN);
82	}
83	SCTP_TCB_UNLOCK(stcb);
84	/* We are clear to peel this one off */
85	return (0);
86}
87
88int
89sctp_do_peeloff(struct socket *head, struct socket *so, sctp_assoc_t assoc_id)
90{
91	struct sctp_inpcb *inp, *n_inp;
92	struct sctp_tcb *stcb;
93	uint32_t state;
94
95	inp = (struct sctp_inpcb *)head->so_pcb;
96	if (inp == NULL) {
97		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTP_PEELOFF, EFAULT);
98		return (EFAULT);
99	}
100	stcb = sctp_findassociation_ep_asocid(inp, assoc_id, 1);
101	if (stcb == NULL) {
102		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTP_PEELOFF, ENOTCONN);
103		return (ENOTCONN);
104	}
105
106	state = SCTP_GET_STATE(stcb);
107	if ((state == SCTP_STATE_EMPTY) ||
108	    (state == SCTP_STATE_INUSE)) {
109		SCTP_TCB_UNLOCK(stcb);
110		SCTP_LTRACE_ERR_RET(inp, NULL, NULL, SCTP_FROM_SCTP_PEELOFF, ENOTCONN);
111		return (ENOTCONN);
112	}
113
114	n_inp = (struct sctp_inpcb *)so->so_pcb;
115	n_inp->sctp_flags = (SCTP_PCB_FLAGS_UDPTYPE |
116	    SCTP_PCB_FLAGS_CONNECTED |
117	    SCTP_PCB_FLAGS_IN_TCPPOOL |	/* Turn on Blocking IO */
118	    (SCTP_PCB_COPY_FLAGS & inp->sctp_flags));
119	n_inp->sctp_socket = so;
120	n_inp->sctp_features = inp->sctp_features;
121	n_inp->sctp_mobility_features = inp->sctp_mobility_features;
122	n_inp->sctp_frag_point = inp->sctp_frag_point;
123	n_inp->sctp_cmt_on_off = inp->sctp_cmt_on_off;
124	n_inp->ecn_supported = inp->ecn_supported;
125	n_inp->prsctp_supported = inp->prsctp_supported;
126	n_inp->auth_supported = inp->auth_supported;
127	n_inp->asconf_supported = inp->asconf_supported;
128	n_inp->reconfig_supported = inp->reconfig_supported;
129	n_inp->nrsack_supported = inp->nrsack_supported;
130	n_inp->pktdrop_supported = inp->pktdrop_supported;
131	n_inp->partial_delivery_point = inp->partial_delivery_point;
132	n_inp->sctp_context = inp->sctp_context;
133	n_inp->max_cwnd = inp->max_cwnd;
134	n_inp->local_strreset_support = inp->local_strreset_support;
135	n_inp->inp_starting_point_for_iterator = NULL;
136	/* copy in the authentication parameters from the original endpoint */
137	if (n_inp->sctp_ep.local_hmacs)
138		sctp_free_hmaclist(n_inp->sctp_ep.local_hmacs);
139	n_inp->sctp_ep.local_hmacs =
140	    sctp_copy_hmaclist(inp->sctp_ep.local_hmacs);
141	if (n_inp->sctp_ep.local_auth_chunks)
142		sctp_free_chunklist(n_inp->sctp_ep.local_auth_chunks);
143	n_inp->sctp_ep.local_auth_chunks =
144	    sctp_copy_chunklist(inp->sctp_ep.local_auth_chunks);
145	(void)sctp_copy_skeylist(&inp->sctp_ep.shared_keys,
146	    &n_inp->sctp_ep.shared_keys);
147	/*
148	 * Now we must move it from one hash table to another and get the
149	 * stcb in the right place.
150	 */
151	sctp_move_pcb_and_assoc(inp, n_inp, stcb);
152	atomic_add_int(&stcb->asoc.refcnt, 1);
153	SCTP_TCB_UNLOCK(stcb);
154
155	sctp_pull_off_control_to_new_inp(inp, n_inp, stcb, SBL_WAIT);
156	atomic_subtract_int(&stcb->asoc.refcnt, 1);
157
158	return (0);
159}
160