xref: /minix3/sys/netinet/tcp_var.h (revision 37274f3cdbc3af02276b244b5057910ba92f7082)
1*37274f3cSDavid van Moolenbroek /*	$NetBSD: tcp_var.h,v 1.177 2015/02/14 22:09:53 he Exp $	*/
2*37274f3cSDavid van Moolenbroek 
3*37274f3cSDavid van Moolenbroek /*
4*37274f3cSDavid van Moolenbroek  * Copyright (C) 1995, 1996, 1997, and 1998 WIDE Project.
5*37274f3cSDavid van Moolenbroek  * All rights reserved.
6*37274f3cSDavid van Moolenbroek  *
7*37274f3cSDavid van Moolenbroek  * Redistribution and use in source and binary forms, with or without
8*37274f3cSDavid van Moolenbroek  * modification, are permitted provided that the following conditions
9*37274f3cSDavid van Moolenbroek  * are met:
10*37274f3cSDavid van Moolenbroek  * 1. Redistributions of source code must retain the above copyright
11*37274f3cSDavid van Moolenbroek  *    notice, this list of conditions and the following disclaimer.
12*37274f3cSDavid van Moolenbroek  * 2. Redistributions in binary form must reproduce the above copyright
13*37274f3cSDavid van Moolenbroek  *    notice, this list of conditions and the following disclaimer in the
14*37274f3cSDavid van Moolenbroek  *    documentation and/or other materials provided with the distribution.
15*37274f3cSDavid van Moolenbroek  * 3. Neither the name of the project nor the names of its contributors
16*37274f3cSDavid van Moolenbroek  *    may be used to endorse or promote products derived from this software
17*37274f3cSDavid van Moolenbroek  *    without specific prior written permission.
18*37274f3cSDavid van Moolenbroek  *
19*37274f3cSDavid van Moolenbroek  * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
20*37274f3cSDavid van Moolenbroek  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
21*37274f3cSDavid van Moolenbroek  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
22*37274f3cSDavid van Moolenbroek  * ARE DISCLAIMED.  IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
23*37274f3cSDavid van Moolenbroek  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
24*37274f3cSDavid van Moolenbroek  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
25*37274f3cSDavid van Moolenbroek  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
26*37274f3cSDavid van Moolenbroek  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
27*37274f3cSDavid van Moolenbroek  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
28*37274f3cSDavid van Moolenbroek  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
29*37274f3cSDavid van Moolenbroek  * SUCH DAMAGE.
30*37274f3cSDavid van Moolenbroek  */
31*37274f3cSDavid van Moolenbroek 
32*37274f3cSDavid van Moolenbroek /*
33*37274f3cSDavid van Moolenbroek  *      @(#)COPYRIGHT   1.1 (NRL) 17 January 1995
34*37274f3cSDavid van Moolenbroek  *
35*37274f3cSDavid van Moolenbroek  * NRL grants permission for redistribution and use in source and binary
36*37274f3cSDavid van Moolenbroek  * forms, with or without modification, of the software and documentation
37*37274f3cSDavid van Moolenbroek  * created at NRL provided that the following conditions are met:
38*37274f3cSDavid van Moolenbroek  *
39*37274f3cSDavid van Moolenbroek  * 1. Redistributions of source code must retain the above copyright
40*37274f3cSDavid van Moolenbroek  *    notice, this list of conditions and the following disclaimer.
41*37274f3cSDavid van Moolenbroek  * 2. Redistributions in binary form must reproduce the above copyright
42*37274f3cSDavid van Moolenbroek  *    notice, this list of conditions and the following disclaimer in the
43*37274f3cSDavid van Moolenbroek  *    documentation and/or other materials provided with the distribution.
44*37274f3cSDavid van Moolenbroek  * 3. All advertising materials mentioning features or use of this software
45*37274f3cSDavid van Moolenbroek  *    must display the following acknowledgements:
46*37274f3cSDavid van Moolenbroek  *      This product includes software developed by the University of
47*37274f3cSDavid van Moolenbroek  *      California, Berkeley and its contributors.
48*37274f3cSDavid van Moolenbroek  *      This product includes software developed at the Information
49*37274f3cSDavid van Moolenbroek  *      Technology Division, US Naval Research Laboratory.
50*37274f3cSDavid van Moolenbroek  * 4. Neither the name of the NRL nor the names of its contributors
51*37274f3cSDavid van Moolenbroek  *    may be used to endorse or promote products derived from this software
52*37274f3cSDavid van Moolenbroek  *    without specific prior written permission.
53*37274f3cSDavid van Moolenbroek  *
54*37274f3cSDavid van Moolenbroek  * THE SOFTWARE PROVIDED BY NRL IS PROVIDED BY NRL AND CONTRIBUTORS ``AS
55*37274f3cSDavid van Moolenbroek  * IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
56*37274f3cSDavid van Moolenbroek  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
57*37274f3cSDavid van Moolenbroek  * PARTICULAR PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL NRL OR
58*37274f3cSDavid van Moolenbroek  * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
59*37274f3cSDavid van Moolenbroek  * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
60*37274f3cSDavid van Moolenbroek  * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
61*37274f3cSDavid van Moolenbroek  * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
62*37274f3cSDavid van Moolenbroek  * LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
63*37274f3cSDavid van Moolenbroek  * NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
64*37274f3cSDavid van Moolenbroek  * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
65*37274f3cSDavid van Moolenbroek  *
66*37274f3cSDavid van Moolenbroek  * The views and conclusions contained in the software and documentation
67*37274f3cSDavid van Moolenbroek  * are those of the authors and should not be interpreted as representing
68*37274f3cSDavid van Moolenbroek  * official policies, either expressed or implied, of the US Naval
69*37274f3cSDavid van Moolenbroek  * Research Laboratory (NRL).
70*37274f3cSDavid van Moolenbroek  */
71*37274f3cSDavid van Moolenbroek 
72*37274f3cSDavid van Moolenbroek /*-
73*37274f3cSDavid van Moolenbroek  * Copyright (c) 1997, 1998, 1999, 2001, 2005 The NetBSD Foundation, Inc.
74*37274f3cSDavid van Moolenbroek  * All rights reserved.
75*37274f3cSDavid van Moolenbroek  *
76*37274f3cSDavid van Moolenbroek  * This code is derived from software contributed to The NetBSD Foundation
77*37274f3cSDavid van Moolenbroek  * by Jason R. Thorpe of the Numerical Aerospace Simulation Facility,
78*37274f3cSDavid van Moolenbroek  * NASA Ames Research Center.
79*37274f3cSDavid van Moolenbroek  * This code is derived from software contributed to The NetBSD Foundation
80*37274f3cSDavid van Moolenbroek  * by Charles M. Hannum.
81*37274f3cSDavid van Moolenbroek  *
82*37274f3cSDavid van Moolenbroek  * Redistribution and use in source and binary forms, with or without
83*37274f3cSDavid van Moolenbroek  * modification, are permitted provided that the following conditions
84*37274f3cSDavid van Moolenbroek  * are met:
85*37274f3cSDavid van Moolenbroek  * 1. Redistributions of source code must retain the above copyright
86*37274f3cSDavid van Moolenbroek  *    notice, this list of conditions and the following disclaimer.
87*37274f3cSDavid van Moolenbroek  * 2. Redistributions in binary form must reproduce the above copyright
88*37274f3cSDavid van Moolenbroek  *    notice, this list of conditions and the following disclaimer in the
89*37274f3cSDavid van Moolenbroek  *    documentation and/or other materials provided with the distribution.
90*37274f3cSDavid van Moolenbroek  *
91*37274f3cSDavid van Moolenbroek  * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
92*37274f3cSDavid van Moolenbroek  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
93*37274f3cSDavid van Moolenbroek  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
94*37274f3cSDavid van Moolenbroek  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
95*37274f3cSDavid van Moolenbroek  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
96*37274f3cSDavid van Moolenbroek  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
97*37274f3cSDavid van Moolenbroek  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
98*37274f3cSDavid van Moolenbroek  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
99*37274f3cSDavid van Moolenbroek  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
100*37274f3cSDavid van Moolenbroek  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
101*37274f3cSDavid van Moolenbroek  * POSSIBILITY OF SUCH DAMAGE.
102*37274f3cSDavid van Moolenbroek  */
103*37274f3cSDavid van Moolenbroek 
104*37274f3cSDavid van Moolenbroek /*
105*37274f3cSDavid van Moolenbroek  * Copyright (c) 1982, 1986, 1993, 1994, 1995
106*37274f3cSDavid van Moolenbroek  *	The Regents of the University of California.  All rights reserved.
107*37274f3cSDavid van Moolenbroek  *
108*37274f3cSDavid van Moolenbroek  * Redistribution and use in source and binary forms, with or without
109*37274f3cSDavid van Moolenbroek  * modification, are permitted provided that the following conditions
110*37274f3cSDavid van Moolenbroek  * are met:
111*37274f3cSDavid van Moolenbroek  * 1. Redistributions of source code must retain the above copyright
112*37274f3cSDavid van Moolenbroek  *    notice, this list of conditions and the following disclaimer.
113*37274f3cSDavid van Moolenbroek  * 2. Redistributions in binary form must reproduce the above copyright
114*37274f3cSDavid van Moolenbroek  *    notice, this list of conditions and the following disclaimer in the
115*37274f3cSDavid van Moolenbroek  *    documentation and/or other materials provided with the distribution.
116*37274f3cSDavid van Moolenbroek  * 3. Neither the name of the University nor the names of its contributors
117*37274f3cSDavid van Moolenbroek  *    may be used to endorse or promote products derived from this software
118*37274f3cSDavid van Moolenbroek  *    without specific prior written permission.
119*37274f3cSDavid van Moolenbroek  *
120*37274f3cSDavid van Moolenbroek  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
121*37274f3cSDavid van Moolenbroek  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
122*37274f3cSDavid van Moolenbroek  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
123*37274f3cSDavid van Moolenbroek  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
124*37274f3cSDavid van Moolenbroek  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
125*37274f3cSDavid van Moolenbroek  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
126*37274f3cSDavid van Moolenbroek  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
127*37274f3cSDavid van Moolenbroek  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
128*37274f3cSDavid van Moolenbroek  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
129*37274f3cSDavid van Moolenbroek  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
130*37274f3cSDavid van Moolenbroek  * SUCH DAMAGE.
131*37274f3cSDavid van Moolenbroek  *
132*37274f3cSDavid van Moolenbroek  *	@(#)tcp_var.h	8.4 (Berkeley) 5/24/95
133*37274f3cSDavid van Moolenbroek  */
134*37274f3cSDavid van Moolenbroek 
135*37274f3cSDavid van Moolenbroek #ifndef _NETINET_TCP_VAR_H_
136*37274f3cSDavid van Moolenbroek #define _NETINET_TCP_VAR_H_
137*37274f3cSDavid van Moolenbroek 
138*37274f3cSDavid van Moolenbroek #if defined(_KERNEL_OPT)
139*37274f3cSDavid van Moolenbroek #include "opt_inet.h"
140*37274f3cSDavid van Moolenbroek #include "opt_mbuftrace.h"
141*37274f3cSDavid van Moolenbroek 
142*37274f3cSDavid van Moolenbroek #endif
143*37274f3cSDavid van Moolenbroek 
144*37274f3cSDavid van Moolenbroek /*
145*37274f3cSDavid van Moolenbroek  * Kernel variables for tcp.
146*37274f3cSDavid van Moolenbroek  */
147*37274f3cSDavid van Moolenbroek 
148*37274f3cSDavid van Moolenbroek #include <sys/callout.h>
149*37274f3cSDavid van Moolenbroek 
150*37274f3cSDavid van Moolenbroek #ifdef TCP_SIGNATURE
151*37274f3cSDavid van Moolenbroek /*
152*37274f3cSDavid van Moolenbroek  * Defines which are needed by the xform_tcp module and tcp_[in|out]put
153*37274f3cSDavid van Moolenbroek  * for SADB verification and lookup.
154*37274f3cSDavid van Moolenbroek  */
155*37274f3cSDavid van Moolenbroek #define	TCP_SIGLEN	16	/* length of computed digest in bytes */
156*37274f3cSDavid van Moolenbroek #define	TCP_KEYLEN_MIN	1	/* minimum length of TCP-MD5 key */
157*37274f3cSDavid van Moolenbroek #define	TCP_KEYLEN_MAX	80	/* maximum length of TCP-MD5 key */
158*37274f3cSDavid van Moolenbroek /*
159*37274f3cSDavid van Moolenbroek  * Only a single SA per host may be specified at this time. An SPI is
160*37274f3cSDavid van Moolenbroek  * needed in order for the KEY_ALLOCSA() lookup to work.
161*37274f3cSDavid van Moolenbroek  */
162*37274f3cSDavid van Moolenbroek #define	TCP_SIG_SPI	0x1000
163*37274f3cSDavid van Moolenbroek #endif /* TCP_SIGNATURE */
164*37274f3cSDavid van Moolenbroek 
165*37274f3cSDavid van Moolenbroek /*
166*37274f3cSDavid van Moolenbroek  * SACK option block.
167*37274f3cSDavid van Moolenbroek  */
168*37274f3cSDavid van Moolenbroek struct sackblk {
169*37274f3cSDavid van Moolenbroek 	tcp_seq left;		/* Left edge of sack block. */
170*37274f3cSDavid van Moolenbroek 	tcp_seq right;		/* Right edge of sack block. */
171*37274f3cSDavid van Moolenbroek };
172*37274f3cSDavid van Moolenbroek 
173*37274f3cSDavid van Moolenbroek TAILQ_HEAD(sackhead, sackhole);
174*37274f3cSDavid van Moolenbroek struct sackhole {
175*37274f3cSDavid van Moolenbroek 	tcp_seq start;
176*37274f3cSDavid van Moolenbroek 	tcp_seq end;
177*37274f3cSDavid van Moolenbroek 	tcp_seq rxmit;
178*37274f3cSDavid van Moolenbroek 
179*37274f3cSDavid van Moolenbroek 	TAILQ_ENTRY(sackhole) sackhole_q;
180*37274f3cSDavid van Moolenbroek };
181*37274f3cSDavid van Moolenbroek 
182*37274f3cSDavid van Moolenbroek /*
183*37274f3cSDavid van Moolenbroek  * Tcp control block, one per tcp; fields:
184*37274f3cSDavid van Moolenbroek  */
185*37274f3cSDavid van Moolenbroek struct tcpcb {
186*37274f3cSDavid van Moolenbroek 	int	t_family;		/* address family on the wire */
187*37274f3cSDavid van Moolenbroek 	struct ipqehead segq;		/* sequencing queue */
188*37274f3cSDavid van Moolenbroek 	int	t_segqlen;		/* length of the above */
189*37274f3cSDavid van Moolenbroek 	callout_t t_timer[TCPT_NTIMERS];/* tcp timers */
190*37274f3cSDavid van Moolenbroek 	short	t_state;		/* state of this connection */
191*37274f3cSDavid van Moolenbroek 	short	t_rxtshift;		/* log(2) of rexmt exp. backoff */
192*37274f3cSDavid van Moolenbroek 	uint32_t t_rxtcur;		/* current retransmit value */
193*37274f3cSDavid van Moolenbroek 	short	t_dupacks;		/* consecutive dup acks recd */
194*37274f3cSDavid van Moolenbroek 	/*
195*37274f3cSDavid van Moolenbroek 	 * t_partialacks:
196*37274f3cSDavid van Moolenbroek 	 *	<0	not in fast recovery.
197*37274f3cSDavid van Moolenbroek 	 *	==0	in fast recovery.  has not received partial acks
198*37274f3cSDavid van Moolenbroek 	 *	>0	in fast recovery.  has received partial acks
199*37274f3cSDavid van Moolenbroek 	 */
200*37274f3cSDavid van Moolenbroek 	short	t_partialacks;		/* partials acks during fast rexmit */
201*37274f3cSDavid van Moolenbroek 	u_short	t_peermss;		/* peer's maximum segment size */
202*37274f3cSDavid van Moolenbroek 	u_short	t_ourmss;		/* our's maximum segment size */
203*37274f3cSDavid van Moolenbroek 	u_short t_segsz;		/* current segment size in use */
204*37274f3cSDavid van Moolenbroek 	char	t_force;		/* 1 if forcing out a byte */
205*37274f3cSDavid van Moolenbroek 	u_int	t_flags;
206*37274f3cSDavid van Moolenbroek #define	TF_ACKNOW	0x0001		/* ack peer immediately */
207*37274f3cSDavid van Moolenbroek #define	TF_DELACK	0x0002		/* ack, but try to delay it */
208*37274f3cSDavid van Moolenbroek #define	TF_NODELAY	0x0004		/* don't delay packets to coalesce */
209*37274f3cSDavid van Moolenbroek #define	TF_NOOPT	0x0008		/* don't use tcp options */
210*37274f3cSDavid van Moolenbroek #define	TF_REQ_SCALE	0x0020		/* have/will request window scaling */
211*37274f3cSDavid van Moolenbroek #define	TF_RCVD_SCALE	0x0040		/* other side has requested scaling */
212*37274f3cSDavid van Moolenbroek #define	TF_REQ_TSTMP	0x0080		/* have/will request timestamps */
213*37274f3cSDavid van Moolenbroek #define	TF_RCVD_TSTMP	0x0100		/* a timestamp was received in SYN */
214*37274f3cSDavid van Moolenbroek #define	TF_SACK_PERMIT	0x0200		/* other side said I could SACK */
215*37274f3cSDavid van Moolenbroek #define	TF_SYN_REXMT	0x0400		/* rexmit timer fired on SYN */
216*37274f3cSDavid van Moolenbroek #define	TF_WILL_SACK	0x0800		/* try to use SACK */
217*37274f3cSDavid van Moolenbroek #define	TF_REASSEMBLING	0x1000		/* we're busy reassembling */
218*37274f3cSDavid van Moolenbroek #define	TF_DEAD		0x2000		/* dead and to-be-released */
219*37274f3cSDavid van Moolenbroek #define	TF_PMTUD_PEND	0x4000		/* Path MTU Discovery pending */
220*37274f3cSDavid van Moolenbroek #define	TF_ECN_PERMIT	0x10000		/* other side said is ECN-ready */
221*37274f3cSDavid van Moolenbroek #define	TF_ECN_SND_CWR	0x20000		/* ECN CWR in queue */
222*37274f3cSDavid van Moolenbroek #define	TF_ECN_SND_ECE	0x40000		/* ECN ECE in queue */
223*37274f3cSDavid van Moolenbroek #define	TF_SIGNATURE	0x400000	/* require MD5 digests (RFC2385) */
224*37274f3cSDavid van Moolenbroek 
225*37274f3cSDavid van Moolenbroek 
226*37274f3cSDavid van Moolenbroek 	struct	mbuf *t_template;	/* skeletal packet for transmit */
227*37274f3cSDavid van Moolenbroek 	struct	inpcb *t_inpcb;		/* back pointer to internet pcb */
228*37274f3cSDavid van Moolenbroek 	struct	in6pcb *t_in6pcb;	/* back pointer to internet pcb */
229*37274f3cSDavid van Moolenbroek 	callout_t t_delack_ch;		/* delayed ACK callout */
230*37274f3cSDavid van Moolenbroek /*
231*37274f3cSDavid van Moolenbroek  * The following fields are used as in the protocol specification.
232*37274f3cSDavid van Moolenbroek  * See RFC793, Dec. 1981, page 21.
233*37274f3cSDavid van Moolenbroek  */
234*37274f3cSDavid van Moolenbroek /* send sequence variables */
235*37274f3cSDavid van Moolenbroek 	tcp_seq	snd_una;		/* send unacknowledged */
236*37274f3cSDavid van Moolenbroek 	tcp_seq	snd_nxt;		/* send next */
237*37274f3cSDavid van Moolenbroek 	tcp_seq	snd_up;			/* send urgent pointer */
238*37274f3cSDavid van Moolenbroek 	tcp_seq	snd_wl1;		/* window update seg seq number */
239*37274f3cSDavid van Moolenbroek 	tcp_seq	snd_wl2;		/* window update seg ack number */
240*37274f3cSDavid van Moolenbroek 	tcp_seq	iss;			/* initial send sequence number */
241*37274f3cSDavid van Moolenbroek 	u_long	snd_wnd;		/* send window */
242*37274f3cSDavid van Moolenbroek /*
243*37274f3cSDavid van Moolenbroek  * snd_recover
244*37274f3cSDavid van Moolenbroek  * 	it's basically same as the "recover" variable in RFC 2852 (NewReno).
245*37274f3cSDavid van Moolenbroek  * 	when entering fast retransmit, it's set to snd_max.
246*37274f3cSDavid van Moolenbroek  * 	newreno uses this to detect partial ack.
247*37274f3cSDavid van Moolenbroek  * snd_high
248*37274f3cSDavid van Moolenbroek  * 	it's basically same as the "send_high" variable in RFC 2852 (NewReno).
249*37274f3cSDavid van Moolenbroek  * 	on each RTO, it's set to snd_max.
250*37274f3cSDavid van Moolenbroek  * 	newreno uses this to avoid false fast retransmits.
251*37274f3cSDavid van Moolenbroek  */
252*37274f3cSDavid van Moolenbroek 	tcp_seq snd_recover;
253*37274f3cSDavid van Moolenbroek 	tcp_seq	snd_high;
254*37274f3cSDavid van Moolenbroek /* receive sequence variables */
255*37274f3cSDavid van Moolenbroek 	u_long	rcv_wnd;		/* receive window */
256*37274f3cSDavid van Moolenbroek 	tcp_seq	rcv_nxt;		/* receive next */
257*37274f3cSDavid van Moolenbroek 	tcp_seq	rcv_up;			/* receive urgent pointer */
258*37274f3cSDavid van Moolenbroek 	tcp_seq	irs;			/* initial receive sequence number */
259*37274f3cSDavid van Moolenbroek /*
260*37274f3cSDavid van Moolenbroek  * Additional variables for this implementation.
261*37274f3cSDavid van Moolenbroek  */
262*37274f3cSDavid van Moolenbroek /* receive variables */
263*37274f3cSDavid van Moolenbroek 	tcp_seq	rcv_adv;		/* advertised window */
264*37274f3cSDavid van Moolenbroek 
265*37274f3cSDavid van Moolenbroek /*
266*37274f3cSDavid van Moolenbroek  * retransmit variables
267*37274f3cSDavid van Moolenbroek  *
268*37274f3cSDavid van Moolenbroek  * snd_max
269*37274f3cSDavid van Moolenbroek  * 	the highest sequence number we've ever sent.
270*37274f3cSDavid van Moolenbroek  *	used to recognize retransmits.
271*37274f3cSDavid van Moolenbroek  */
272*37274f3cSDavid van Moolenbroek 	tcp_seq	snd_max;
273*37274f3cSDavid van Moolenbroek 
274*37274f3cSDavid van Moolenbroek /* congestion control (for slow start, source quench, retransmit after loss) */
275*37274f3cSDavid van Moolenbroek 	u_long	snd_cwnd;		/* congestion-controlled window */
276*37274f3cSDavid van Moolenbroek 	u_long	snd_ssthresh;		/* snd_cwnd size threshhold for
277*37274f3cSDavid van Moolenbroek 					 * for slow start exponential to
278*37274f3cSDavid van Moolenbroek 					 * linear switch
279*37274f3cSDavid van Moolenbroek 					 */
280*37274f3cSDavid van Moolenbroek /* auto-sizing variables */
281*37274f3cSDavid van Moolenbroek 	u_int rfbuf_cnt;		/* recv buffer autoscaling byte count */
282*37274f3cSDavid van Moolenbroek 	uint32_t rfbuf_ts;		/* recv buffer autoscaling timestamp */
283*37274f3cSDavid van Moolenbroek 
284*37274f3cSDavid van Moolenbroek /*
285*37274f3cSDavid van Moolenbroek  * transmit timing stuff.  See below for scale of srtt and rttvar.
286*37274f3cSDavid van Moolenbroek  * "Variance" is actually smoothed difference.
287*37274f3cSDavid van Moolenbroek  */
288*37274f3cSDavid van Moolenbroek 	uint32_t t_rcvtime;		/* time last segment received */
289*37274f3cSDavid van Moolenbroek 	uint32_t t_rtttime;		/* time we started measuring rtt */
290*37274f3cSDavid van Moolenbroek 	tcp_seq	t_rtseq;		/* sequence number being timed */
291*37274f3cSDavid van Moolenbroek 	int32_t	t_srtt;			/* smoothed round-trip time */
292*37274f3cSDavid van Moolenbroek 	int32_t	t_rttvar;		/* variance in round-trip time */
293*37274f3cSDavid van Moolenbroek 	uint32_t t_rttmin;		/* minimum rtt allowed */
294*37274f3cSDavid van Moolenbroek 	u_long	max_sndwnd;		/* largest window peer has offered */
295*37274f3cSDavid van Moolenbroek 
296*37274f3cSDavid van Moolenbroek /* out-of-band data */
297*37274f3cSDavid van Moolenbroek 	char	t_oobflags;		/* have some */
298*37274f3cSDavid van Moolenbroek 	char	t_iobc;			/* input character */
299*37274f3cSDavid van Moolenbroek #define	TCPOOB_HAVEDATA	0x01
300*37274f3cSDavid van Moolenbroek #define	TCPOOB_HADDATA	0x02
301*37274f3cSDavid van Moolenbroek 	short	t_softerror;		/* possible error not yet reported */
302*37274f3cSDavid van Moolenbroek 
303*37274f3cSDavid van Moolenbroek /* RFC 1323 variables */
304*37274f3cSDavid van Moolenbroek 	u_char	snd_scale;		/* window scaling for send window */
305*37274f3cSDavid van Moolenbroek 	u_char	rcv_scale;		/* window scaling for recv window */
306*37274f3cSDavid van Moolenbroek 	u_char	request_r_scale;	/* pending window scaling */
307*37274f3cSDavid van Moolenbroek 	u_char	requested_s_scale;
308*37274f3cSDavid van Moolenbroek 	u_int32_t ts_recent;		/* timestamp echo data */
309*37274f3cSDavid van Moolenbroek 	u_int32_t ts_recent_age;	/* when last updated */
310*37274f3cSDavid van Moolenbroek 	u_int32_t ts_timebase;		/* our timebase */
311*37274f3cSDavid van Moolenbroek 	tcp_seq	last_ack_sent;
312*37274f3cSDavid van Moolenbroek 
313*37274f3cSDavid van Moolenbroek /* RFC 3465 variables */
314*37274f3cSDavid van Moolenbroek 	u_long	t_bytes_acked;		/* ABC "bytes_acked" parameter */
315*37274f3cSDavid van Moolenbroek 
316*37274f3cSDavid van Moolenbroek /* SACK stuff */
317*37274f3cSDavid van Moolenbroek #define TCP_SACK_MAX 3
318*37274f3cSDavid van Moolenbroek #define TCPSACK_NONE 0
319*37274f3cSDavid van Moolenbroek #define TCPSACK_HAVED 1
320*37274f3cSDavid van Moolenbroek 	u_char rcv_sack_flags;		/* SACK flags. */
321*37274f3cSDavid van Moolenbroek 	struct sackblk rcv_dsack_block;	/* RX D-SACK block. */
322*37274f3cSDavid van Moolenbroek 	struct ipqehead timeq;		/* time sequenced queue. */
323*37274f3cSDavid van Moolenbroek 	struct sackhead snd_holes;	/* TX SACK holes. */
324*37274f3cSDavid van Moolenbroek 	int	snd_numholes;		/* Number of TX SACK holes. */
325*37274f3cSDavid van Moolenbroek 	tcp_seq rcv_lastsack;		/* last seq number(+1) sack'd by rcv'r*/
326*37274f3cSDavid van Moolenbroek 	tcp_seq sack_newdata;		/* New data xmitted in this recovery
327*37274f3cSDavid van Moolenbroek 					   episode starts at this seq number*/
328*37274f3cSDavid van Moolenbroek 	tcp_seq snd_fack;		/* FACK TCP.  Forward-most data held by
329*37274f3cSDavid van Moolenbroek 					   peer. */
330*37274f3cSDavid van Moolenbroek 
331*37274f3cSDavid van Moolenbroek /* CUBIC variables */
332*37274f3cSDavid van Moolenbroek 	ulong snd_cubic_wmax;		/* W_max */
333*37274f3cSDavid van Moolenbroek 	ulong snd_cubic_wmax_last;	/* Used for fast convergence */
334*37274f3cSDavid van Moolenbroek 	ulong snd_cubic_ctime;		/* Last congestion time */
335*37274f3cSDavid van Moolenbroek 
336*37274f3cSDavid van Moolenbroek /* pointer for syn cache entries*/
337*37274f3cSDavid van Moolenbroek 	LIST_HEAD(, syn_cache) t_sc;	/* list of entries by this tcb */
338*37274f3cSDavid van Moolenbroek 
339*37274f3cSDavid van Moolenbroek /* prediction of next mbuf when using large window sizes */
340*37274f3cSDavid van Moolenbroek 	struct	mbuf *t_lastm;		/* last mbuf that data was sent from */
341*37274f3cSDavid van Moolenbroek 	int	t_inoff;		/* data offset in previous mbuf */
342*37274f3cSDavid van Moolenbroek 	int	t_lastoff;		/* last data address in mbuf chain */
343*37274f3cSDavid van Moolenbroek 	int	t_lastlen;		/* last length read from mbuf chain */
344*37274f3cSDavid van Moolenbroek 
345*37274f3cSDavid van Moolenbroek /* Path-MTU discovery blackhole detection */
346*37274f3cSDavid van Moolenbroek 	int t_mtudisc;			/* perform mtudisc for this tcb */
347*37274f3cSDavid van Moolenbroek /* Path-MTU Discovery Information */
348*37274f3cSDavid van Moolenbroek 	u_int	t_pmtud_mss_acked;	/* MSS acked, lower bound for MTU */
349*37274f3cSDavid van Moolenbroek 	u_int	t_pmtud_mtu_sent;	/* MTU used, upper bound for MTU */
350*37274f3cSDavid van Moolenbroek 	tcp_seq	t_pmtud_th_seq;		/* TCP SEQ from ICMP payload */
351*37274f3cSDavid van Moolenbroek 	u_int	t_pmtud_nextmtu;	/* Advertised Next-Hop MTU from ICMP */
352*37274f3cSDavid van Moolenbroek 	u_short	t_pmtud_ip_len;		/* IP length from ICMP payload */
353*37274f3cSDavid van Moolenbroek 	u_short	t_pmtud_ip_hl;		/* IP header length from ICMP payload */
354*37274f3cSDavid van Moolenbroek 
355*37274f3cSDavid van Moolenbroek 	uint8_t t_ecn_retries;		/* # of ECN setup retries */
356*37274f3cSDavid van Moolenbroek 
357*37274f3cSDavid van Moolenbroek 	const struct tcp_congctl *t_congctl;	/* per TCB congctl algorithm */
358*37274f3cSDavid van Moolenbroek 
359*37274f3cSDavid van Moolenbroek 	/* Keepalive per socket */
360*37274f3cSDavid van Moolenbroek 	u_int	t_keepinit;
361*37274f3cSDavid van Moolenbroek 	u_int	t_keepidle;
362*37274f3cSDavid van Moolenbroek 	u_int	t_keepintvl;
363*37274f3cSDavid van Moolenbroek 	u_int	t_keepcnt;
364*37274f3cSDavid van Moolenbroek 	u_int	t_maxidle;		/* t_keepcnt * t_keepintvl */
365*37274f3cSDavid van Moolenbroek 
366*37274f3cSDavid van Moolenbroek 	u_int	t_msl;			/* MSL to use for this connexion */
367*37274f3cSDavid van Moolenbroek 
368*37274f3cSDavid van Moolenbroek 	/* maintain a few stats per connection: */
369*37274f3cSDavid van Moolenbroek 	uint32_t t_rcvoopack;	 	/* out-of-order packets received */
370*37274f3cSDavid van Moolenbroek 	uint32_t t_sndrexmitpack; 	/* retransmit packets sent */
371*37274f3cSDavid van Moolenbroek 	uint32_t t_sndzerowin;		/* zero-window updates sent */
372*37274f3cSDavid van Moolenbroek };
373*37274f3cSDavid van Moolenbroek 
374*37274f3cSDavid van Moolenbroek /*
375*37274f3cSDavid van Moolenbroek  * Macros to aid ECN TCP.
376*37274f3cSDavid van Moolenbroek  */
377*37274f3cSDavid van Moolenbroek #define TCP_ECN_ALLOWED(tp)	(tp->t_flags & TF_ECN_PERMIT)
378*37274f3cSDavid van Moolenbroek 
379*37274f3cSDavid van Moolenbroek /*
380*37274f3cSDavid van Moolenbroek  * Macros to aid SACK/FACK TCP.
381*37274f3cSDavid van Moolenbroek  */
382*37274f3cSDavid van Moolenbroek #define TCP_SACK_ENABLED(tp)	(tp->t_flags & TF_WILL_SACK)
383*37274f3cSDavid van Moolenbroek #define TCP_FACK_FASTRECOV(tp)	\
384*37274f3cSDavid van Moolenbroek 	(TCP_SACK_ENABLED(tp) && \
385*37274f3cSDavid van Moolenbroek 	(SEQ_GT(tp->snd_fack, tp->snd_una + tcprexmtthresh * tp->t_segsz)))
386*37274f3cSDavid van Moolenbroek 
387*37274f3cSDavid van Moolenbroek #ifdef _KERNEL
388*37274f3cSDavid van Moolenbroek /*
389*37274f3cSDavid van Moolenbroek  * TCP reassembly queue locks.
390*37274f3cSDavid van Moolenbroek  */
391*37274f3cSDavid van Moolenbroek static __inline int tcp_reass_lock_try (struct tcpcb *)
392*37274f3cSDavid van Moolenbroek 	__unused;
393*37274f3cSDavid van Moolenbroek static __inline void tcp_reass_unlock (struct tcpcb *)
394*37274f3cSDavid van Moolenbroek 	__unused;
395*37274f3cSDavid van Moolenbroek 
396*37274f3cSDavid van Moolenbroek static __inline int
tcp_reass_lock_try(struct tcpcb * tp)397*37274f3cSDavid van Moolenbroek tcp_reass_lock_try(struct tcpcb *tp)
398*37274f3cSDavid van Moolenbroek {
399*37274f3cSDavid van Moolenbroek 	int s;
400*37274f3cSDavid van Moolenbroek 
401*37274f3cSDavid van Moolenbroek 	/*
402*37274f3cSDavid van Moolenbroek 	 * Use splvm() -- we're blocking things that would cause
403*37274f3cSDavid van Moolenbroek 	 * mbuf allocation.
404*37274f3cSDavid van Moolenbroek 	 */
405*37274f3cSDavid van Moolenbroek 	s = splvm();
406*37274f3cSDavid van Moolenbroek 	if (tp->t_flags & TF_REASSEMBLING) {
407*37274f3cSDavid van Moolenbroek 		splx(s);
408*37274f3cSDavid van Moolenbroek 		return (0);
409*37274f3cSDavid van Moolenbroek 	}
410*37274f3cSDavid van Moolenbroek 	tp->t_flags |= TF_REASSEMBLING;
411*37274f3cSDavid van Moolenbroek 	splx(s);
412*37274f3cSDavid van Moolenbroek 	return (1);
413*37274f3cSDavid van Moolenbroek }
414*37274f3cSDavid van Moolenbroek 
415*37274f3cSDavid van Moolenbroek static __inline void
tcp_reass_unlock(struct tcpcb * tp)416*37274f3cSDavid van Moolenbroek tcp_reass_unlock(struct tcpcb *tp)
417*37274f3cSDavid van Moolenbroek {
418*37274f3cSDavid van Moolenbroek 	int s;
419*37274f3cSDavid van Moolenbroek 
420*37274f3cSDavid van Moolenbroek 	s = splvm();
421*37274f3cSDavid van Moolenbroek 	KASSERT((tp->t_flags & TF_REASSEMBLING) != 0);
422*37274f3cSDavid van Moolenbroek 	tp->t_flags &= ~TF_REASSEMBLING;
423*37274f3cSDavid van Moolenbroek 	splx(s);
424*37274f3cSDavid van Moolenbroek }
425*37274f3cSDavid van Moolenbroek 
426*37274f3cSDavid van Moolenbroek #ifdef DIAGNOSTIC
427*37274f3cSDavid van Moolenbroek #define	TCP_REASS_LOCK(tp)						\
428*37274f3cSDavid van Moolenbroek do {									\
429*37274f3cSDavid van Moolenbroek 	if (tcp_reass_lock_try(tp) == 0) {				\
430*37274f3cSDavid van Moolenbroek 		printf("%s:%d: tcpcb %p reass already locked\n",	\
431*37274f3cSDavid van Moolenbroek 		    __FILE__, __LINE__, tp);				\
432*37274f3cSDavid van Moolenbroek 		panic("tcp_reass_lock");				\
433*37274f3cSDavid van Moolenbroek 	}								\
434*37274f3cSDavid van Moolenbroek } while (/*CONSTCOND*/ 0)
435*37274f3cSDavid van Moolenbroek #define	TCP_REASS_LOCK_CHECK(tp)					\
436*37274f3cSDavid van Moolenbroek do {									\
437*37274f3cSDavid van Moolenbroek 	if (((tp)->t_flags & TF_REASSEMBLING) == 0) {			\
438*37274f3cSDavid van Moolenbroek 		printf("%s:%d: tcpcb %p reass lock not held\n",		\
439*37274f3cSDavid van Moolenbroek 		    __FILE__, __LINE__, tp);				\
440*37274f3cSDavid van Moolenbroek 		panic("tcp reass lock check");				\
441*37274f3cSDavid van Moolenbroek 	}								\
442*37274f3cSDavid van Moolenbroek } while (/*CONSTCOND*/ 0)
443*37274f3cSDavid van Moolenbroek #else
444*37274f3cSDavid van Moolenbroek #define	TCP_REASS_LOCK(tp)	(void) tcp_reass_lock_try((tp))
445*37274f3cSDavid van Moolenbroek #define	TCP_REASS_LOCK_CHECK(tp) /* nothing */
446*37274f3cSDavid van Moolenbroek #endif
447*37274f3cSDavid van Moolenbroek 
448*37274f3cSDavid van Moolenbroek #define	TCP_REASS_UNLOCK(tp)	tcp_reass_unlock((tp))
449*37274f3cSDavid van Moolenbroek #endif /* _KERNEL */
450*37274f3cSDavid van Moolenbroek 
451*37274f3cSDavid van Moolenbroek /*
452*37274f3cSDavid van Moolenbroek  * Queue for delayed ACK processing.
453*37274f3cSDavid van Moolenbroek  */
454*37274f3cSDavid van Moolenbroek #ifdef _KERNEL
455*37274f3cSDavid van Moolenbroek extern int tcp_delack_ticks;
456*37274f3cSDavid van Moolenbroek void	tcp_delack(void *);
457*37274f3cSDavid van Moolenbroek 
458*37274f3cSDavid van Moolenbroek #define TCP_RESTART_DELACK(tp)						\
459*37274f3cSDavid van Moolenbroek 	callout_reset(&(tp)->t_delack_ch, tcp_delack_ticks,		\
460*37274f3cSDavid van Moolenbroek 	    tcp_delack, tp)
461*37274f3cSDavid van Moolenbroek 
462*37274f3cSDavid van Moolenbroek #define	TCP_SET_DELACK(tp)						\
463*37274f3cSDavid van Moolenbroek do {									\
464*37274f3cSDavid van Moolenbroek 	if (((tp)->t_flags & TF_DELACK) == 0) {				\
465*37274f3cSDavid van Moolenbroek 		(tp)->t_flags |= TF_DELACK;				\
466*37274f3cSDavid van Moolenbroek 		TCP_RESTART_DELACK(tp);					\
467*37274f3cSDavid van Moolenbroek 	}								\
468*37274f3cSDavid van Moolenbroek } while (/*CONSTCOND*/0)
469*37274f3cSDavid van Moolenbroek 
470*37274f3cSDavid van Moolenbroek #define	TCP_CLEAR_DELACK(tp)						\
471*37274f3cSDavid van Moolenbroek do {									\
472*37274f3cSDavid van Moolenbroek 	if ((tp)->t_flags & TF_DELACK) {				\
473*37274f3cSDavid van Moolenbroek 		(tp)->t_flags &= ~TF_DELACK;				\
474*37274f3cSDavid van Moolenbroek 		callout_stop(&(tp)->t_delack_ch);			\
475*37274f3cSDavid van Moolenbroek 	}								\
476*37274f3cSDavid van Moolenbroek } while (/*CONSTCOND*/0)
477*37274f3cSDavid van Moolenbroek #endif /* _KERNEL */
478*37274f3cSDavid van Moolenbroek 
479*37274f3cSDavid van Moolenbroek /*
480*37274f3cSDavid van Moolenbroek  * Compute the current timestamp for a connection.
481*37274f3cSDavid van Moolenbroek  */
482*37274f3cSDavid van Moolenbroek #define	TCP_TIMESTAMP(tp)	(tcp_now - (tp)->ts_timebase)
483*37274f3cSDavid van Moolenbroek 
484*37274f3cSDavid van Moolenbroek /*
485*37274f3cSDavid van Moolenbroek  * Handy way of passing around TCP option info.
486*37274f3cSDavid van Moolenbroek  */
487*37274f3cSDavid van Moolenbroek struct tcp_opt_info {
488*37274f3cSDavid van Moolenbroek 	int		ts_present;
489*37274f3cSDavid van Moolenbroek 	u_int32_t	ts_val;
490*37274f3cSDavid van Moolenbroek 	u_int32_t	ts_ecr;
491*37274f3cSDavid van Moolenbroek 	u_int16_t	maxseg;
492*37274f3cSDavid van Moolenbroek };
493*37274f3cSDavid van Moolenbroek 
494*37274f3cSDavid van Moolenbroek #define	TOF_SIGNATURE	0x0040		/* signature option present */
495*37274f3cSDavid van Moolenbroek #define	TOF_SIGLEN	0x0080		/* sigature length valid (RFC2385) */
496*37274f3cSDavid van Moolenbroek 
497*37274f3cSDavid van Moolenbroek /*
498*37274f3cSDavid van Moolenbroek  * Data for the TCP compressed state engine.
499*37274f3cSDavid van Moolenbroek  */
500*37274f3cSDavid van Moolenbroek union syn_cache_sa {
501*37274f3cSDavid van Moolenbroek 	struct sockaddr sa;
502*37274f3cSDavid van Moolenbroek 	struct sockaddr_in sin;
503*37274f3cSDavid van Moolenbroek #if 1 /*def INET6*/
504*37274f3cSDavid van Moolenbroek 	struct sockaddr_in6 sin6;
505*37274f3cSDavid van Moolenbroek #endif
506*37274f3cSDavid van Moolenbroek };
507*37274f3cSDavid van Moolenbroek 
508*37274f3cSDavid van Moolenbroek struct syn_cache {
509*37274f3cSDavid van Moolenbroek 	TAILQ_ENTRY(syn_cache) sc_bucketq;	/* link on bucket list */
510*37274f3cSDavid van Moolenbroek 	callout_t sc_timer;			/* rexmt timer */
511*37274f3cSDavid van Moolenbroek 	struct route sc_route;
512*37274f3cSDavid van Moolenbroek 	long sc_win;				/* advertised window */
513*37274f3cSDavid van Moolenbroek 	int sc_bucketidx;			/* our bucket index */
514*37274f3cSDavid van Moolenbroek 	u_int32_t sc_hash;
515*37274f3cSDavid van Moolenbroek 	u_int32_t sc_timestamp;			/* timestamp from SYN */
516*37274f3cSDavid van Moolenbroek 	u_int32_t sc_timebase;			/* our local timebase */
517*37274f3cSDavid van Moolenbroek 	union syn_cache_sa sc_src;
518*37274f3cSDavid van Moolenbroek 	union syn_cache_sa sc_dst;
519*37274f3cSDavid van Moolenbroek 	tcp_seq sc_irs;
520*37274f3cSDavid van Moolenbroek 	tcp_seq sc_iss;
521*37274f3cSDavid van Moolenbroek 	u_int sc_rxtcur;			/* current rxt timeout */
522*37274f3cSDavid van Moolenbroek 	u_int sc_rxttot;			/* total time spend on queues */
523*37274f3cSDavid van Moolenbroek 	u_short sc_rxtshift;			/* for computing backoff */
524*37274f3cSDavid van Moolenbroek 	u_short sc_flags;
525*37274f3cSDavid van Moolenbroek 
526*37274f3cSDavid van Moolenbroek #define	SCF_UNREACH		0x0001		/* we've had an unreach error */
527*37274f3cSDavid van Moolenbroek #define	SCF_TIMESTAMP		0x0002		/* peer will do timestamps */
528*37274f3cSDavid van Moolenbroek #define	SCF_DEAD		0x0004		/* this entry to be released */
529*37274f3cSDavid van Moolenbroek #define SCF_SACK_PERMIT		0x0008		/* peer will do SACK */
530*37274f3cSDavid van Moolenbroek #define SCF_ECN_PERMIT		0x0010		/* peer will do ECN */
531*37274f3cSDavid van Moolenbroek #define SCF_SIGNATURE	0x40			/* send MD5 digests */
532*37274f3cSDavid van Moolenbroek 
533*37274f3cSDavid van Moolenbroek 	struct mbuf *sc_ipopts;			/* IP options */
534*37274f3cSDavid van Moolenbroek 	u_int16_t sc_peermaxseg;
535*37274f3cSDavid van Moolenbroek 	u_int16_t sc_ourmaxseg;
536*37274f3cSDavid van Moolenbroek 	u_int8_t sc_request_r_scale	: 4,
537*37274f3cSDavid van Moolenbroek 		 sc_requested_s_scale	: 4;
538*37274f3cSDavid van Moolenbroek 
539*37274f3cSDavid van Moolenbroek 	struct tcpcb *sc_tp;			/* tcb for listening socket */
540*37274f3cSDavid van Moolenbroek 	LIST_ENTRY(syn_cache) sc_tpq;		/* list of entries by same tp */
541*37274f3cSDavid van Moolenbroek };
542*37274f3cSDavid van Moolenbroek 
543*37274f3cSDavid van Moolenbroek struct syn_cache_head {
544*37274f3cSDavid van Moolenbroek 	TAILQ_HEAD(, syn_cache) sch_bucket;	/* bucket entries */
545*37274f3cSDavid van Moolenbroek 	u_short sch_length;			/* # entries in bucket */
546*37274f3cSDavid van Moolenbroek };
547*37274f3cSDavid van Moolenbroek 
548*37274f3cSDavid van Moolenbroek #define	intotcpcb(ip)	((struct tcpcb *)(ip)->inp_ppcb)
549*37274f3cSDavid van Moolenbroek #ifdef INET6
550*37274f3cSDavid van Moolenbroek #define	in6totcpcb(ip)	((struct tcpcb *)(ip)->in6p_ppcb)
551*37274f3cSDavid van Moolenbroek #endif
552*37274f3cSDavid van Moolenbroek #ifndef INET6
553*37274f3cSDavid van Moolenbroek #define	sototcpcb(so)	(intotcpcb(sotoinpcb(so)))
554*37274f3cSDavid van Moolenbroek #else
555*37274f3cSDavid van Moolenbroek #define	sototcpcb(so)	(((so)->so_proto->pr_domain->dom_family == AF_INET) \
556*37274f3cSDavid van Moolenbroek 				? intotcpcb(sotoinpcb(so)) \
557*37274f3cSDavid van Moolenbroek 				: in6totcpcb(sotoin6pcb(so)))
558*37274f3cSDavid van Moolenbroek #endif
559*37274f3cSDavid van Moolenbroek 
560*37274f3cSDavid van Moolenbroek /*
561*37274f3cSDavid van Moolenbroek  * See RFC2988 for a discussion of RTO calculation; comments assume
562*37274f3cSDavid van Moolenbroek  * familiarity with that document.
563*37274f3cSDavid van Moolenbroek  *
564*37274f3cSDavid van Moolenbroek  * The smoothed round-trip time and estimated variance are stored as
565*37274f3cSDavid van Moolenbroek  * fixed point numbers.  Historically, srtt was scaled by
566*37274f3cSDavid van Moolenbroek  * TCP_RTT_SHIFT bits, and rttvar by TCP_RTTVAR_SHIFT bits.  Because
567*37274f3cSDavid van Moolenbroek  * the values coincide with the alpha and beta parameters suggested
568*37274f3cSDavid van Moolenbroek  * for RTO calculation (1/8 for srtt, 1/4 for rttvar), the combination
569*37274f3cSDavid van Moolenbroek  * of computing 1/8 of the new value and transforming it to the
570*37274f3cSDavid van Moolenbroek  * fixed-point representation required zero instructions.  However,
571*37274f3cSDavid van Moolenbroek  * the storage representations no longer coincide with the alpha/beta
572*37274f3cSDavid van Moolenbroek  * shifts; instead, more fractional bits are present.
573*37274f3cSDavid van Moolenbroek  *
574*37274f3cSDavid van Moolenbroek  * The storage representation of srtt is 1/32 slow ticks, or 1/64 s.
575*37274f3cSDavid van Moolenbroek  * (The assumption that a slow tick is 500 ms should not be present in
576*37274f3cSDavid van Moolenbroek  * the code.)
577*37274f3cSDavid van Moolenbroek  *
578*37274f3cSDavid van Moolenbroek  * The storage representation of rttvar is 1/16 slow ticks, or 1/32 s.
579*37274f3cSDavid van Moolenbroek  * There may be some confusion about this in the code.
580*37274f3cSDavid van Moolenbroek  *
581*37274f3cSDavid van Moolenbroek  * For historical reasons, these scales are also used in smoothing the
582*37274f3cSDavid van Moolenbroek  * average (smoothed = (1/scale)sample + ((scale-1)/scale)smoothed).
583*37274f3cSDavid van Moolenbroek  * This results in alpha of 0.125 and beta of 0.25, following RFC2988
584*37274f3cSDavid van Moolenbroek  * section 2.3
585*37274f3cSDavid van Moolenbroek  *
586*37274f3cSDavid van Moolenbroek  * XXX Change SHIFT values to LGWEIGHT and REP_SHIFT, and adjust
587*37274f3cSDavid van Moolenbroek  * the code to use the correct ones.
588*37274f3cSDavid van Moolenbroek  */
589*37274f3cSDavid van Moolenbroek #define	TCP_RTT_SHIFT		3	/* shift for srtt; 3 bits frac. */
590*37274f3cSDavid van Moolenbroek #define	TCP_RTTVAR_SHIFT	2	/* multiplier for rttvar; 2 bits */
591*37274f3cSDavid van Moolenbroek 
592*37274f3cSDavid van Moolenbroek /*
593*37274f3cSDavid van Moolenbroek  * Compute TCP retransmission timer, following RFC2988.
594*37274f3cSDavid van Moolenbroek  * This macro returns a value in slow timeout ticks.
595*37274f3cSDavid van Moolenbroek  *
596*37274f3cSDavid van Moolenbroek  * Section 2.2 requires that the RTO value be
597*37274f3cSDavid van Moolenbroek  *  srtt + max(G, 4*RTTVAR)
598*37274f3cSDavid van Moolenbroek  * where G is the clock granularity.
599*37274f3cSDavid van Moolenbroek  *
600*37274f3cSDavid van Moolenbroek  * This comment has not necessarily been updated for the new storage
601*37274f3cSDavid van Moolenbroek  * representation:
602*37274f3cSDavid van Moolenbroek  *
603*37274f3cSDavid van Moolenbroek  * Because of the way we do the smoothing, srtt and rttvar
604*37274f3cSDavid van Moolenbroek  * will each average +1/2 tick of bias.  When we compute
605*37274f3cSDavid van Moolenbroek  * the retransmit timer, we want 1/2 tick of rounding and
606*37274f3cSDavid van Moolenbroek  * 1 extra tick because of +-1/2 tick uncertainty in the
607*37274f3cSDavid van Moolenbroek  * firing of the timer.  The bias will give us exactly the
608*37274f3cSDavid van Moolenbroek  * 1.5 tick we need.  But, because the bias is
609*37274f3cSDavid van Moolenbroek  * statistical, we have to test that we don't drop below
610*37274f3cSDavid van Moolenbroek  * the minimum feasible timer (which is 2 ticks).
611*37274f3cSDavid van Moolenbroek  * This macro assumes that the value of 1<<TCP_RTTVAR_SHIFT
612*37274f3cSDavid van Moolenbroek  * is the same as the multiplier for rttvar.
613*37274f3cSDavid van Moolenbroek  *
614*37274f3cSDavid van Moolenbroek  * This macro appears to be wrong; it should be checking rttvar*4 in
615*37274f3cSDavid van Moolenbroek  * ticks and making sure we use 1 instead if rttvar*4 rounds to 0.  It
616*37274f3cSDavid van Moolenbroek  * appears to be treating srtt as being in the old storage
617*37274f3cSDavid van Moolenbroek  * representation, resulting in a factor of 4 extra.
618*37274f3cSDavid van Moolenbroek  */
619*37274f3cSDavid van Moolenbroek #define	TCP_REXMTVAL(tp) \
620*37274f3cSDavid van Moolenbroek 	((((tp)->t_srtt >> TCP_RTT_SHIFT) + (tp)->t_rttvar) >> 2)
621*37274f3cSDavid van Moolenbroek 
622*37274f3cSDavid van Moolenbroek /*
623*37274f3cSDavid van Moolenbroek  * Compute the initial window for slow start.
624*37274f3cSDavid van Moolenbroek  */
625*37274f3cSDavid van Moolenbroek #define	TCP_INITIAL_WINDOW(iw, segsz) \
626*37274f3cSDavid van Moolenbroek 	min((iw) * (segsz), max(2 * (segsz), tcp_init_win_max[(iw)]))
627*37274f3cSDavid van Moolenbroek 
628*37274f3cSDavid van Moolenbroek /*
629*37274f3cSDavid van Moolenbroek  * TCP statistics.
630*37274f3cSDavid van Moolenbroek  * Each counter is an unsigned 64-bit value.
631*37274f3cSDavid van Moolenbroek  *
632*37274f3cSDavid van Moolenbroek  * Many of these should be kept per connection, but that's inconvenient
633*37274f3cSDavid van Moolenbroek  * at the moment.
634*37274f3cSDavid van Moolenbroek  */
635*37274f3cSDavid van Moolenbroek #define	TCP_STAT_CONNATTEMPT	0	/* connections initiated */
636*37274f3cSDavid van Moolenbroek #define	TCP_STAT_ACCEPTS	1	/* connections accepted */
637*37274f3cSDavid van Moolenbroek #define	TCP_STAT_CONNECTS	2	/* connections established */
638*37274f3cSDavid van Moolenbroek #define	TCP_STAT_DROPS		3	/* connections dropped */
639*37274f3cSDavid van Moolenbroek #define	TCP_STAT_CONNDROPS	4	/* embryonic connections dropped */
640*37274f3cSDavid van Moolenbroek #define	TCP_STAT_CLOSED		5	/* conn. closed (includes drops) */
641*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SEGSTIMED	6	/* segs where we tried to get rtt */
642*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RTTUPDATED	7	/* times we succeeded */
643*37274f3cSDavid van Moolenbroek #define	TCP_STAT_DELACK		8	/* delayed ACKs sent */
644*37274f3cSDavid van Moolenbroek #define	TCP_STAT_TIMEOUTDROP	9	/* conn. dropped in rxmt timeout */
645*37274f3cSDavid van Moolenbroek #define	TCP_STAT_REXMTTIMEO	10	/* retransmit timeouts */
646*37274f3cSDavid van Moolenbroek #define	TCP_STAT_PERSISTTIMEO	11	/* persist timeouts */
647*37274f3cSDavid van Moolenbroek #define	TCP_STAT_KEEPTIMEO	12	/* keepalive timeouts */
648*37274f3cSDavid van Moolenbroek #define	TCP_STAT_KEEPPROBE	13	/* keepalive probes sent */
649*37274f3cSDavid van Moolenbroek #define	TCP_STAT_KEEPDROPS	14	/* connections dropped in keepalive */
650*37274f3cSDavid van Moolenbroek #define	TCP_STAT_PERSISTDROPS	15	/* connections dropped in persist */
651*37274f3cSDavid van Moolenbroek #define	TCP_STAT_CONNSDRAINED	16	/* connections drained due to memory
652*37274f3cSDavid van Moolenbroek 					   shortage */
653*37274f3cSDavid van Moolenbroek #define	TCP_STAT_PMTUBLACKHOLE	17	/* PMTUD blackhole detected */
654*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SNDTOTAL	18	/* total packets sent */
655*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SNDPACK	19	/* data packlets sent */
656*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SNDBYTE	20	/* data bytes sent */
657*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SNDREXMITPACK	21	/* data packets retransmitted */
658*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SNDREXMITBYTE	22	/* data bytes retransmitted */
659*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SNDACKS	23	/* ACK-only packets sent */
660*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SNDPROBE	24	/* window probes sent */
661*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SNDURG		25	/* packets sent with URG only */
662*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SNDWINUP	26	/* window update-only packets sent */
663*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SNDCTRL	27	/* control (SYN|FIN|RST) packets sent */
664*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVTOTAL	28	/* total packets received */
665*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVPACK	29	/* packets received in sequence */
666*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVBYTE	30	/* bytes received in sequence */
667*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVBADSUM	31	/* packets received with cksum errs */
668*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVBADOFF	32	/* packets received with bad offset */
669*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVMEMDROP	33	/* packets dropped for lack of memory */
670*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVSHORT	34	/* packets received too short */
671*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVDUPPACK	35	/* duplicate-only packets received */
672*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVDUPBYTE	36	/* duplicate-only bytes received */
673*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVPARTDUPPACK	37	/* packets with some duplicate data */
674*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVPARTDUPBYTE	38	/* dup. bytes in part-dup. packets */
675*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVOOPACK	39	/* out-of-order packets received */
676*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVOOBYTE	40	/* out-of-order bytes received */
677*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVPACKAFTERWIN 41	/* packets with data after window */
678*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVBYTEAFTERWIN 42	/* bytes received after window */
679*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVAFTERCLOSE	43	/* packets received after "close" */
680*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVWINPROBE	44	/* rcvd window probe packets */
681*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVDUPACK	45	/* rcvd duplicate ACKs */
682*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVACKTOOMUCH	46	/* rcvd ACKs for unsent data */
683*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVACKPACK	47	/* rcvd ACK packets */
684*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVACKBYTE	48	/* bytes ACKed by rcvd ACKs */
685*37274f3cSDavid van Moolenbroek #define	TCP_STAT_RCVWINUPD	49	/* rcvd window update packets */
686*37274f3cSDavid van Moolenbroek #define	TCP_STAT_PAWSDROP	50	/* segments dropped due to PAWS */
687*37274f3cSDavid van Moolenbroek #define	TCP_STAT_PREDACK	51	/* times hdr predict OK for ACKs */
688*37274f3cSDavid van Moolenbroek #define	TCP_STAT_PREDDAT	52	/* times hdr predict OK for data pkts */
689*37274f3cSDavid van Moolenbroek #define	TCP_STAT_PCBHASHMISS	53	/* input packets missing PCB hash */
690*37274f3cSDavid van Moolenbroek #define	TCP_STAT_NOPORT		54	/* no socket on port */
691*37274f3cSDavid van Moolenbroek #define	TCP_STAT_BADSYN		55	/* received ACK for which we have
692*37274f3cSDavid van Moolenbroek 					   no SYN in compressed state */
693*37274f3cSDavid van Moolenbroek #define	TCP_STAT_DELAYED_FREE	56	/* delayed pool_put() of tcpcb */
694*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SC_ADDED	57	/* # of sc entries added */
695*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SC_COMPLETED	58	/* # of sc connections completed */
696*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SC_TIMED_OUT	59	/* # of sc entries timed out */
697*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SC_OVERFLOWED	60	/* # of sc drops due to overflow */
698*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SC_RESET	61	/* # of sc drops due to RST */
699*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SC_UNREACH	62	/* # of sc drops due to ICMP unreach */
700*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SC_BUCKETOVERFLOW 63	/* # of sc drops due to bucket ovflow */
701*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SC_ABORTED	64	/* # of sc entries aborted (no mem) */
702*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SC_DUPESYN	65	/* # of duplicate SYNs received */
703*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SC_DROPPED	66	/* # of SYNs dropped (no route/mem) */
704*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SC_COLLISIONS	67	/* # of sc hash collisions */
705*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SC_RETRANSMITTED 68	/* # of sc retransmissions */
706*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SC_DELAYED_FREE 69	/* # of delayed pool_put()s */
707*37274f3cSDavid van Moolenbroek #define	TCP_STAT_SELFQUENCH	70	/* # of ENOBUFS we get on output */
708*37274f3cSDavid van Moolenbroek #define	TCP_STAT_BADSIG		71	/* # of drops due to bad signature */
709*37274f3cSDavid van Moolenbroek #define	TCP_STAT_GOODSIG	72	/* # of packets with good signature */
710*37274f3cSDavid van Moolenbroek #define	TCP_STAT_ECN_SHS	73	/* # of successful ECN handshakes */
711*37274f3cSDavid van Moolenbroek #define	TCP_STAT_ECN_CE		74	/* # of packets with CE bit */
712*37274f3cSDavid van Moolenbroek #define	TCP_STAT_ECN_ECT	75	/* # of packets with ECT(0) bit */
713*37274f3cSDavid van Moolenbroek 
714*37274f3cSDavid van Moolenbroek #define	TCP_NSTATS		76
715*37274f3cSDavid van Moolenbroek 
716*37274f3cSDavid van Moolenbroek /*
717*37274f3cSDavid van Moolenbroek  * Names for TCP sysctl objects.
718*37274f3cSDavid van Moolenbroek  */
719*37274f3cSDavid van Moolenbroek #define	TCPCTL_RFC1323		1	/* RFC1323 timestamps/scaling */
720*37274f3cSDavid van Moolenbroek #define	TCPCTL_SENDSPACE	2	/* default send buffer */
721*37274f3cSDavid van Moolenbroek #define	TCPCTL_RECVSPACE	3	/* default recv buffer */
722*37274f3cSDavid van Moolenbroek #define	TCPCTL_MSSDFLT		4	/* default seg size */
723*37274f3cSDavid van Moolenbroek #define	TCPCTL_SYN_CACHE_LIMIT	5	/* max size of comp. state engine */
724*37274f3cSDavid van Moolenbroek #define	TCPCTL_SYN_BUCKET_LIMIT	6	/* max size of hash bucket */
725*37274f3cSDavid van Moolenbroek #if 0	/*obsoleted*/
726*37274f3cSDavid van Moolenbroek #define	TCPCTL_SYN_CACHE_INTER	7	/* interval of comp. state timer */
727*37274f3cSDavid van Moolenbroek #endif
728*37274f3cSDavid van Moolenbroek #define	TCPCTL_INIT_WIN		8	/* initial window */
729*37274f3cSDavid van Moolenbroek #define	TCPCTL_MSS_IFMTU	9	/* mss from interface, not in_maxmtu */
730*37274f3cSDavid van Moolenbroek #define	TCPCTL_SACK		10	/* RFC2018 selective acknowledgement */
731*37274f3cSDavid van Moolenbroek #define	TCPCTL_WSCALE		11	/* RFC1323 window scaling */
732*37274f3cSDavid van Moolenbroek #define	TCPCTL_TSTAMP		12	/* RFC1323 timestamps */
733*37274f3cSDavid van Moolenbroek #define	TCPCTL_COMPAT_42	13	/* 4.2BSD TCP bug work-arounds */
734*37274f3cSDavid van Moolenbroek #define	TCPCTL_CWM		14	/* Congestion Window Monitoring */
735*37274f3cSDavid van Moolenbroek #define	TCPCTL_CWM_BURSTSIZE	15	/* burst size allowed by CWM */
736*37274f3cSDavid van Moolenbroek #define	TCPCTL_ACK_ON_PUSH	16	/* ACK immediately on PUSH */
737*37274f3cSDavid van Moolenbroek #define	TCPCTL_KEEPIDLE		17	/* keepalive idle time */
738*37274f3cSDavid van Moolenbroek #define	TCPCTL_KEEPINTVL	18	/* keepalive probe interval */
739*37274f3cSDavid van Moolenbroek #define	TCPCTL_KEEPCNT		19	/* keepalive count */
740*37274f3cSDavid van Moolenbroek #define	TCPCTL_SLOWHZ		20	/* PR_SLOWHZ (read-only) */
741*37274f3cSDavid van Moolenbroek #define	TCPCTL_NEWRENO		21	/* NewReno Congestion Control */
742*37274f3cSDavid van Moolenbroek #define TCPCTL_LOG_REFUSED	22	/* Log refused connections */
743*37274f3cSDavid van Moolenbroek #if 0	/*obsoleted*/
744*37274f3cSDavid van Moolenbroek #define	TCPCTL_RSTRATELIMIT	23	/* RST rate limit */
745*37274f3cSDavid van Moolenbroek #endif
746*37274f3cSDavid van Moolenbroek #define	TCPCTL_RSTPPSLIMIT	24	/* RST pps limit */
747*37274f3cSDavid van Moolenbroek #define	TCPCTL_DELACK_TICKS	25	/* # ticks to delay ACK */
748*37274f3cSDavid van Moolenbroek #define	TCPCTL_INIT_WIN_LOCAL	26	/* initial window for local nets */
749*37274f3cSDavid van Moolenbroek #define	TCPCTL_IDENT		27	/* rfc 931 identd */
750*37274f3cSDavid van Moolenbroek #define	TCPCTL_ACKDROPRATELIMIT	28	/* SYN/RST -> ACK rate limit */
751*37274f3cSDavid van Moolenbroek #define	TCPCTL_LOOPBACKCKSUM	29	/* do TCP checksum on loopback */
752*37274f3cSDavid van Moolenbroek #define	TCPCTL_STATS		30	/* TCP statistics */
753*37274f3cSDavid van Moolenbroek #define	TCPCTL_DEBUG		31	/* TCP debug sockets */
754*37274f3cSDavid van Moolenbroek #define	TCPCTL_DEBX		32	/* # of tcp debug sockets */
755*37274f3cSDavid van Moolenbroek #define	TCPCTL_DROP		33	/* drop tcp connection */
756*37274f3cSDavid van Moolenbroek #define	TCPCTL_MSL		34	/* Max Segment Life */
757*37274f3cSDavid van Moolenbroek #define	TCPCTL_MAXID		35
758*37274f3cSDavid van Moolenbroek 
759*37274f3cSDavid van Moolenbroek #define	TCPCTL_NAMES { \
760*37274f3cSDavid van Moolenbroek 	{ 0, 0 }, \
761*37274f3cSDavid van Moolenbroek 	{ "rfc1323",	CTLTYPE_INT }, \
762*37274f3cSDavid van Moolenbroek 	{ "sendspace",	CTLTYPE_INT }, \
763*37274f3cSDavid van Moolenbroek 	{ "recvspace",	CTLTYPE_INT }, \
764*37274f3cSDavid van Moolenbroek 	{ "mssdflt",	CTLTYPE_INT }, \
765*37274f3cSDavid van Moolenbroek 	{ "syn_cache_limit", CTLTYPE_INT }, \
766*37274f3cSDavid van Moolenbroek 	{ "syn_bucket_limit", CTLTYPE_INT }, \
767*37274f3cSDavid van Moolenbroek 	{ 0, 0 },\
768*37274f3cSDavid van Moolenbroek 	{ "init_win", CTLTYPE_INT }, \
769*37274f3cSDavid van Moolenbroek 	{ "mss_ifmtu", CTLTYPE_INT }, \
770*37274f3cSDavid van Moolenbroek 	{ "sack", CTLTYPE_INT }, \
771*37274f3cSDavid van Moolenbroek 	{ "win_scale", CTLTYPE_INT }, \
772*37274f3cSDavid van Moolenbroek 	{ "timestamps", CTLTYPE_INT }, \
773*37274f3cSDavid van Moolenbroek 	{ "compat_42", CTLTYPE_INT }, \
774*37274f3cSDavid van Moolenbroek 	{ "cwm", CTLTYPE_INT }, \
775*37274f3cSDavid van Moolenbroek 	{ "cwm_burstsize", CTLTYPE_INT }, \
776*37274f3cSDavid van Moolenbroek 	{ "ack_on_push", CTLTYPE_INT }, \
777*37274f3cSDavid van Moolenbroek 	{ "keepidle",	CTLTYPE_INT }, \
778*37274f3cSDavid van Moolenbroek 	{ "keepintvl",	CTLTYPE_INT }, \
779*37274f3cSDavid van Moolenbroek 	{ "keepcnt",	CTLTYPE_INT }, \
780*37274f3cSDavid van Moolenbroek 	{ "slowhz",	CTLTYPE_INT }, \
781*37274f3cSDavid van Moolenbroek 	{ 0, 0 }, \
782*37274f3cSDavid van Moolenbroek 	{ "log_refused",CTLTYPE_INT }, \
783*37274f3cSDavid van Moolenbroek 	{ 0, 0 }, \
784*37274f3cSDavid van Moolenbroek 	{ "rstppslimit", CTLTYPE_INT }, \
785*37274f3cSDavid van Moolenbroek 	{ "delack_ticks", CTLTYPE_INT }, \
786*37274f3cSDavid van Moolenbroek 	{ "init_win_local", CTLTYPE_INT }, \
787*37274f3cSDavid van Moolenbroek 	{ "ident", CTLTYPE_STRUCT }, \
788*37274f3cSDavid van Moolenbroek 	{ "ackdropppslimit", CTLTYPE_INT }, \
789*37274f3cSDavid van Moolenbroek 	{ "do_loopback_cksum", CTLTYPE_INT }, \
790*37274f3cSDavid van Moolenbroek 	{ "stats", CTLTYPE_STRUCT }, \
791*37274f3cSDavid van Moolenbroek 	{ "debug", CTLTYPE_STRUCT }, \
792*37274f3cSDavid van Moolenbroek 	{ "debx", CTLTYPE_INT }, \
793*37274f3cSDavid van Moolenbroek 	{ "drop", CTLTYPE_STRUCT }, \
794*37274f3cSDavid van Moolenbroek 	{ "msl", CTLTYPE_INT }, \
795*37274f3cSDavid van Moolenbroek }
796*37274f3cSDavid van Moolenbroek 
797*37274f3cSDavid van Moolenbroek #ifdef _KERNEL
798*37274f3cSDavid van Moolenbroek 
799*37274f3cSDavid van Moolenbroek extern	struct inpcbtable tcbtable;	/* head of queue of active tcpcb's */
800*37274f3cSDavid van Moolenbroek extern	const struct pr_usrreqs tcp_usrreqs;
801*37274f3cSDavid van Moolenbroek 
802*37274f3cSDavid van Moolenbroek extern	u_int32_t tcp_now;	/* for RFC 1323 timestamps */
803*37274f3cSDavid van Moolenbroek extern	int tcp_do_rfc1323;	/* enabled/disabled? */
804*37274f3cSDavid van Moolenbroek extern	int tcp_do_sack;	/* SACK enabled/disabled? */
805*37274f3cSDavid van Moolenbroek extern	int tcp_do_win_scale;	/* RFC1323 window scaling enabled/disabled? */
806*37274f3cSDavid van Moolenbroek extern	int tcp_do_timestamps;	/* RFC1323 timestamps enabled/disabled? */
807*37274f3cSDavid van Moolenbroek extern	int tcp_mssdflt;	/* default seg size */
808*37274f3cSDavid van Moolenbroek extern	int tcp_minmss;		/* minimal seg size */
809*37274f3cSDavid van Moolenbroek extern  int tcp_msl;		/* max segment life */
810*37274f3cSDavid van Moolenbroek extern	int tcp_init_win;	/* initial window */
811*37274f3cSDavid van Moolenbroek extern	int tcp_init_win_local;	/* initial window for local nets */
812*37274f3cSDavid van Moolenbroek extern	int tcp_init_win_max[11];/* max sizes for values of tcp_init_win_* */
813*37274f3cSDavid van Moolenbroek extern	int tcp_mss_ifmtu;	/* take MSS from interface, not in_maxmtu */
814*37274f3cSDavid van Moolenbroek extern	int tcp_compat_42;	/* work around ancient broken TCP peers */
815*37274f3cSDavid van Moolenbroek extern	int tcp_cwm;		/* enable Congestion Window Monitoring */
816*37274f3cSDavid van Moolenbroek extern	int tcp_cwm_burstsize;	/* burst size allowed by CWM */
817*37274f3cSDavid van Moolenbroek extern	int tcp_ack_on_push;	/* ACK immediately on PUSH */
818*37274f3cSDavid van Moolenbroek extern	int tcp_syn_cache_limit; /* max entries for compressed state engine */
819*37274f3cSDavid van Moolenbroek extern	int tcp_syn_bucket_limit;/* max entries per hash bucket */
820*37274f3cSDavid van Moolenbroek extern	int tcp_log_refused;	/* log refused connections */
821*37274f3cSDavid van Moolenbroek extern	int tcp_do_ecn;		/* TCP ECN enabled/disabled? */
822*37274f3cSDavid van Moolenbroek extern	int tcp_ecn_maxretries;	/* Max ECN setup retries */
823*37274f3cSDavid van Moolenbroek extern	int tcp_do_rfc1948;	/* ISS by cryptographic hash */
824*37274f3cSDavid van Moolenbroek extern int tcp_sack_tp_maxholes;	/* Max holes per connection. */
825*37274f3cSDavid van Moolenbroek extern int tcp_sack_globalmaxholes;	/* Max holes per system. */
826*37274f3cSDavid van Moolenbroek extern int tcp_sack_globalholes;	/* Number of holes present. */
827*37274f3cSDavid van Moolenbroek extern int tcp_do_abc;			/* RFC3465 ABC enabled/disabled? */
828*37274f3cSDavid van Moolenbroek extern int tcp_abc_aggressive;		/* 1: L=2*SMSS  0: L=1*SMSS */
829*37274f3cSDavid van Moolenbroek 
830*37274f3cSDavid van Moolenbroek extern int tcp_msl_enable;		/* enable TIME_WAIT truncation	*/
831*37274f3cSDavid van Moolenbroek extern int tcp_msl_loop;		/* MSL for loopback		*/
832*37274f3cSDavid van Moolenbroek extern int tcp_msl_local;		/* MSL for 'local'		*/
833*37274f3cSDavid van Moolenbroek extern int tcp_msl_remote;		/* MSL otherwise		*/
834*37274f3cSDavid van Moolenbroek extern int tcp_msl_remote_threshold;	/* RTT threshold		*/
835*37274f3cSDavid van Moolenbroek extern int tcp_rttlocal;		/* Use RTT to decide who's 'local' */
836*37274f3cSDavid van Moolenbroek extern int tcp4_vtw_enable;
837*37274f3cSDavid van Moolenbroek extern int tcp6_vtw_enable;
838*37274f3cSDavid van Moolenbroek extern int tcp_vtw_was_enabled;
839*37274f3cSDavid van Moolenbroek extern int tcp_vtw_entries;
840*37274f3cSDavid van Moolenbroek 
841*37274f3cSDavid van Moolenbroek extern	int tcp_rst_ppslim;
842*37274f3cSDavid van Moolenbroek extern	int tcp_ackdrop_ppslim;
843*37274f3cSDavid van Moolenbroek 
844*37274f3cSDavid van Moolenbroek extern	int tcp_syn_cache_size;
845*37274f3cSDavid van Moolenbroek extern	struct syn_cache_head tcp_syn_cache[];
846*37274f3cSDavid van Moolenbroek extern	u_long syn_cache_count;
847*37274f3cSDavid van Moolenbroek 
848*37274f3cSDavid van Moolenbroek #ifdef MBUFTRACE
849*37274f3cSDavid van Moolenbroek extern	struct mowner tcp_rx_mowner;
850*37274f3cSDavid van Moolenbroek extern	struct mowner tcp_tx_mowner;
851*37274f3cSDavid van Moolenbroek extern	struct mowner tcp_reass_mowner;
852*37274f3cSDavid van Moolenbroek extern	struct mowner tcp_sock_mowner;
853*37274f3cSDavid van Moolenbroek extern	struct mowner tcp_sock_rx_mowner;
854*37274f3cSDavid van Moolenbroek extern	struct mowner tcp_sock_tx_mowner;
855*37274f3cSDavid van Moolenbroek extern	struct mowner tcp_mowner;
856*37274f3cSDavid van Moolenbroek #endif
857*37274f3cSDavid van Moolenbroek 
858*37274f3cSDavid van Moolenbroek extern int tcp_do_autorcvbuf;
859*37274f3cSDavid van Moolenbroek extern int tcp_autorcvbuf_inc;
860*37274f3cSDavid van Moolenbroek extern int tcp_autorcvbuf_max;
861*37274f3cSDavid van Moolenbroek extern int tcp_do_autosndbuf;
862*37274f3cSDavid van Moolenbroek extern int tcp_autosndbuf_inc;
863*37274f3cSDavid van Moolenbroek extern int tcp_autosndbuf_max;
864*37274f3cSDavid van Moolenbroek 
865*37274f3cSDavid van Moolenbroek 
866*37274f3cSDavid van Moolenbroek #define	TCPCTL_VARIABLES { \
867*37274f3cSDavid van Moolenbroek 	{ 0 },					\
868*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_do_rfc1323 },		\
869*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_sendspace },		\
870*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_recvspace },		\
871*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_mssdflt },			\
872*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_syn_cache_limit },		\
873*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_syn_bucket_limit },	\
874*37274f3cSDavid van Moolenbroek 	{ 0 },					\
875*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_init_win },		\
876*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_mss_ifmtu },		\
877*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_do_sack },			\
878*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_do_win_scale },		\
879*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_do_timestamps },		\
880*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_compat_42 },		\
881*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_cwm },			\
882*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_cwm_burstsize },		\
883*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_ack_on_push },		\
884*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_keepidle },		\
885*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_keepintvl },		\
886*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_keepcnt },			\
887*37274f3cSDavid van Moolenbroek 	{ 1, 1, 0, PR_SLOWHZ },			\
888*37274f3cSDavid van Moolenbroek 	{ 0 },					\
889*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_log_refused },		\
890*37274f3cSDavid van Moolenbroek 	{ 0 },					\
891*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_rst_ppslim },		\
892*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_delack_ticks },		\
893*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_init_win_local },		\
894*37274f3cSDavid van Moolenbroek 	{ 1, 0, &tcp_ackdrop_ppslim },		\
895*37274f3cSDavid van Moolenbroek }
896*37274f3cSDavid van Moolenbroek 
897*37274f3cSDavid van Moolenbroek struct secasvar;
898*37274f3cSDavid van Moolenbroek 
899*37274f3cSDavid van Moolenbroek void	 tcp_canceltimers(struct tcpcb *);
900*37274f3cSDavid van Moolenbroek struct tcpcb *
901*37274f3cSDavid van Moolenbroek 	 tcp_close(struct tcpcb *);
902*37274f3cSDavid van Moolenbroek int	 tcp_isdead(struct tcpcb *);
903*37274f3cSDavid van Moolenbroek #ifdef INET6
904*37274f3cSDavid van Moolenbroek void	 *tcp6_ctlinput(int, const struct sockaddr *, void *);
905*37274f3cSDavid van Moolenbroek #endif
906*37274f3cSDavid van Moolenbroek void	 *tcp_ctlinput(int, const struct sockaddr *, void *);
907*37274f3cSDavid van Moolenbroek int	 tcp_ctloutput(int, struct socket *, struct sockopt *);
908*37274f3cSDavid van Moolenbroek struct tcpcb *
909*37274f3cSDavid van Moolenbroek 	 tcp_disconnect1(struct tcpcb *);
910*37274f3cSDavid van Moolenbroek struct tcpcb *
911*37274f3cSDavid van Moolenbroek 	 tcp_drop(struct tcpcb *, int);
912*37274f3cSDavid van Moolenbroek #ifdef TCP_SIGNATURE
913*37274f3cSDavid van Moolenbroek int	 tcp_signature_apply(void *, void *, u_int);
914*37274f3cSDavid van Moolenbroek struct secasvar *tcp_signature_getsav(struct mbuf *, struct tcphdr *);
915*37274f3cSDavid van Moolenbroek int	 tcp_signature(struct mbuf *, struct tcphdr *, int, struct secasvar *,
916*37274f3cSDavid van Moolenbroek 	    char *);
917*37274f3cSDavid van Moolenbroek #endif
918*37274f3cSDavid van Moolenbroek void	 tcp_drain(void);
919*37274f3cSDavid van Moolenbroek void	 tcp_drainstub(void);
920*37274f3cSDavid van Moolenbroek void	 tcp_established(struct tcpcb *);
921*37274f3cSDavid van Moolenbroek void	 tcp_init(void);
922*37274f3cSDavid van Moolenbroek void	 tcp_init_common(unsigned);
923*37274f3cSDavid van Moolenbroek #ifdef INET6
924*37274f3cSDavid van Moolenbroek int	 tcp6_input(struct mbuf **, int *, int);
925*37274f3cSDavid van Moolenbroek #endif
926*37274f3cSDavid van Moolenbroek void	 tcp_input(struct mbuf *, ...);
927*37274f3cSDavid van Moolenbroek u_int	 tcp_hdrsz(struct tcpcb *);
928*37274f3cSDavid van Moolenbroek u_long	 tcp_mss_to_advertise(const struct ifnet *, int);
929*37274f3cSDavid van Moolenbroek void	 tcp_mss_from_peer(struct tcpcb *, int);
930*37274f3cSDavid van Moolenbroek void	 tcp_tcpcb_template(void);
931*37274f3cSDavid van Moolenbroek struct tcpcb *
932*37274f3cSDavid van Moolenbroek 	 tcp_newtcpcb(int, void *);
933*37274f3cSDavid van Moolenbroek void	 tcp_notify(struct inpcb *, int);
934*37274f3cSDavid van Moolenbroek #ifdef INET6
935*37274f3cSDavid van Moolenbroek void	 tcp6_notify(struct in6pcb *, int);
936*37274f3cSDavid van Moolenbroek #endif
937*37274f3cSDavid van Moolenbroek u_int	 tcp_optlen(struct tcpcb *);
938*37274f3cSDavid van Moolenbroek int	 tcp_output(struct tcpcb *);
939*37274f3cSDavid van Moolenbroek void	 tcp_pulloutofband(struct socket *,
940*37274f3cSDavid van Moolenbroek 	    struct tcphdr *, struct mbuf *, int);
941*37274f3cSDavid van Moolenbroek void	 tcp_quench(struct inpcb *, int);
942*37274f3cSDavid van Moolenbroek #ifdef INET6
943*37274f3cSDavid van Moolenbroek void	 tcp6_quench(struct in6pcb *, int);
944*37274f3cSDavid van Moolenbroek #endif
945*37274f3cSDavid van Moolenbroek void	 tcp_mtudisc(struct inpcb *, int);
946*37274f3cSDavid van Moolenbroek #ifdef INET6
947*37274f3cSDavid van Moolenbroek void	 tcp6_mtudisc_callback(struct in6_addr *);
948*37274f3cSDavid van Moolenbroek #endif
949*37274f3cSDavid van Moolenbroek 
950*37274f3cSDavid van Moolenbroek void	tcpipqent_init(void);
951*37274f3cSDavid van Moolenbroek struct ipqent *tcpipqent_alloc(void);
952*37274f3cSDavid van Moolenbroek void	 tcpipqent_free(struct ipqent *);
953*37274f3cSDavid van Moolenbroek 
954*37274f3cSDavid van Moolenbroek int	 tcp_respond(struct tcpcb *, struct mbuf *, struct mbuf *,
955*37274f3cSDavid van Moolenbroek 	    struct tcphdr *, tcp_seq, tcp_seq, int);
956*37274f3cSDavid van Moolenbroek void	 tcp_rmx_rtt(struct tcpcb *);
957*37274f3cSDavid van Moolenbroek void	 tcp_setpersist(struct tcpcb *);
958*37274f3cSDavid van Moolenbroek #ifdef TCP_SIGNATURE
959*37274f3cSDavid van Moolenbroek int	 tcp_signature_compute(struct mbuf *, struct tcphdr *, int, int,
960*37274f3cSDavid van Moolenbroek 	    int, u_char *, u_int);
961*37274f3cSDavid van Moolenbroek #endif
962*37274f3cSDavid van Moolenbroek void	 tcp_slowtimo(void *);
963*37274f3cSDavid van Moolenbroek extern callout_t tcp_slowtimo_ch;
964*37274f3cSDavid van Moolenbroek void	 tcp_fasttimo(void);
965*37274f3cSDavid van Moolenbroek struct mbuf *
966*37274f3cSDavid van Moolenbroek 	 tcp_template(struct tcpcb *);
967*37274f3cSDavid van Moolenbroek void	 tcp_trace(short, short, struct tcpcb *, struct mbuf *, int);
968*37274f3cSDavid van Moolenbroek struct tcpcb *
969*37274f3cSDavid van Moolenbroek 	 tcp_usrclosed(struct tcpcb *);
970*37274f3cSDavid van Moolenbroek void	 tcp_usrreq_init(void);
971*37274f3cSDavid van Moolenbroek void	 tcp_xmit_timer(struct tcpcb *, uint32_t);
972*37274f3cSDavid van Moolenbroek tcp_seq	 tcp_new_iss(struct tcpcb *, tcp_seq);
973*37274f3cSDavid van Moolenbroek tcp_seq  tcp_new_iss1(void *, void *, u_int16_t, u_int16_t, size_t,
974*37274f3cSDavid van Moolenbroek 	    tcp_seq);
975*37274f3cSDavid van Moolenbroek 
976*37274f3cSDavid van Moolenbroek void	 tcp_sack_init(void);
977*37274f3cSDavid van Moolenbroek void	 tcp_new_dsack(struct tcpcb *, tcp_seq, u_int32_t);
978*37274f3cSDavid van Moolenbroek void	 tcp_sack_option(struct tcpcb *, const struct tcphdr *,
979*37274f3cSDavid van Moolenbroek 	    const u_char *, int);
980*37274f3cSDavid van Moolenbroek void	 tcp_del_sackholes(struct tcpcb *, const struct tcphdr *);
981*37274f3cSDavid van Moolenbroek void	 tcp_free_sackholes(struct tcpcb *);
982*37274f3cSDavid van Moolenbroek void	 tcp_sack_adjust(struct tcpcb *tp);
983*37274f3cSDavid van Moolenbroek struct sackhole *tcp_sack_output(struct tcpcb *tp, int *sack_bytes_rexmt);
984*37274f3cSDavid van Moolenbroek int	 tcp_sack_numblks(const struct tcpcb *);
985*37274f3cSDavid van Moolenbroek #define	TCP_SACK_OPTLEN(nblks)	((nblks) * 8 + 2 + 2)
986*37274f3cSDavid van Moolenbroek 
987*37274f3cSDavid van Moolenbroek void	 tcp_statinc(u_int);
988*37274f3cSDavid van Moolenbroek void	 tcp_statadd(u_int, uint64_t);
989*37274f3cSDavid van Moolenbroek 
990*37274f3cSDavid van Moolenbroek int	 syn_cache_add(struct sockaddr *, struct sockaddr *,
991*37274f3cSDavid van Moolenbroek 		struct tcphdr *, unsigned int, struct socket *,
992*37274f3cSDavid van Moolenbroek 		struct mbuf *, u_char *, int, struct tcp_opt_info *);
993*37274f3cSDavid van Moolenbroek void	 syn_cache_unreach(const struct sockaddr *, const struct sockaddr *,
994*37274f3cSDavid van Moolenbroek 	   struct tcphdr *);
995*37274f3cSDavid van Moolenbroek struct socket *syn_cache_get(struct sockaddr *, struct sockaddr *,
996*37274f3cSDavid van Moolenbroek 		struct tcphdr *, unsigned int, unsigned int,
997*37274f3cSDavid van Moolenbroek 		struct socket *so, struct mbuf *);
998*37274f3cSDavid van Moolenbroek void	 syn_cache_init(void);
999*37274f3cSDavid van Moolenbroek void	 syn_cache_insert(struct syn_cache *, struct tcpcb *);
1000*37274f3cSDavid van Moolenbroek struct syn_cache *syn_cache_lookup(const struct sockaddr *, const struct sockaddr *,
1001*37274f3cSDavid van Moolenbroek 		struct syn_cache_head **);
1002*37274f3cSDavid van Moolenbroek void	 syn_cache_reset(struct sockaddr *, struct sockaddr *,
1003*37274f3cSDavid van Moolenbroek 		struct tcphdr *);
1004*37274f3cSDavid van Moolenbroek int	 syn_cache_respond(struct syn_cache *, struct mbuf *);
1005*37274f3cSDavid van Moolenbroek void	 syn_cache_timer(void *);
1006*37274f3cSDavid van Moolenbroek void	 syn_cache_cleanup(struct tcpcb *);
1007*37274f3cSDavid van Moolenbroek 
1008*37274f3cSDavid van Moolenbroek int	 tcp_input_checksum(int, struct mbuf *, const struct tcphdr *, int, int,
1009*37274f3cSDavid van Moolenbroek     int);
1010*37274f3cSDavid van Moolenbroek #endif
1011*37274f3cSDavid van Moolenbroek 
1012*37274f3cSDavid van Moolenbroek #endif /* !_NETINET_TCP_VAR_H_ */
1013