10Sstevel@tonic-gate /* 20Sstevel@tonic-gate * CDDL HEADER START 30Sstevel@tonic-gate * 40Sstevel@tonic-gate * The contents of this file are subject to the terms of the 51735Skcpoon * Common Development and Distribution License (the "License"). 61735Skcpoon * You may not use this file except in compliance with the License. 70Sstevel@tonic-gate * 80Sstevel@tonic-gate * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 90Sstevel@tonic-gate * or http://www.opensolaris.org/os/licensing. 100Sstevel@tonic-gate * See the License for the specific language governing permissions 110Sstevel@tonic-gate * and limitations under the License. 120Sstevel@tonic-gate * 130Sstevel@tonic-gate * When distributing Covered Code, include this CDDL HEADER in each 140Sstevel@tonic-gate * file and include the License file at usr/src/OPENSOLARIS.LICENSE. 150Sstevel@tonic-gate * If applicable, add the following below this CDDL HEADER, with the 160Sstevel@tonic-gate * fields enclosed by brackets "[]" replaced with your own identifying 170Sstevel@tonic-gate * information: Portions Copyright [yyyy] [name of copyright owner] 180Sstevel@tonic-gate * 190Sstevel@tonic-gate * CDDL HEADER END 200Sstevel@tonic-gate */ 211735Skcpoon 220Sstevel@tonic-gate /* 23*11042SErik.Nordmark@Sun.COM * Copyright 2009 Sun Microsystems, Inc. All rights reserved. 240Sstevel@tonic-gate * Use is subject to license terms. 250Sstevel@tonic-gate */ 260Sstevel@tonic-gate 270Sstevel@tonic-gate #include <sys/types.h> 280Sstevel@tonic-gate #include <sys/systm.h> 290Sstevel@tonic-gate #include <sys/stream.h> 300Sstevel@tonic-gate #include <sys/ddi.h> 310Sstevel@tonic-gate #include <sys/sunddi.h> 320Sstevel@tonic-gate #include <sys/strsubr.h> 330Sstevel@tonic-gate #include <sys/strsun.h> 340Sstevel@tonic-gate 350Sstevel@tonic-gate #include <netinet/in.h> 360Sstevel@tonic-gate #include <netinet/ip6.h> 370Sstevel@tonic-gate 38*11042SErik.Nordmark@Sun.COM #include <inet/ipsec_impl.h> 390Sstevel@tonic-gate #include <inet/common.h> 400Sstevel@tonic-gate #include <inet/ip.h> 410Sstevel@tonic-gate #include <inet/ip6.h> 420Sstevel@tonic-gate #include <inet/mib2.h> 430Sstevel@tonic-gate #include <inet/nd.h> 440Sstevel@tonic-gate #include <inet/optcom.h> 450Sstevel@tonic-gate #include <inet/sctp_ip.h> 463448Sdh155122 #include <inet/ipclassifier.h> 470Sstevel@tonic-gate #include "sctp_impl.h" 480Sstevel@tonic-gate 490Sstevel@tonic-gate void 500Sstevel@tonic-gate sctp_send_shutdown(sctp_t *sctp, int rexmit) 510Sstevel@tonic-gate { 520Sstevel@tonic-gate mblk_t *smp; 530Sstevel@tonic-gate mblk_t *sendmp; 540Sstevel@tonic-gate sctp_chunk_hdr_t *sch; 550Sstevel@tonic-gate uint32_t *ctsn; 560Sstevel@tonic-gate sctp_faddr_t *fp; 573448Sdh155122 sctp_stack_t *sctps = sctp->sctp_sctps; 580Sstevel@tonic-gate 590Sstevel@tonic-gate if (sctp->sctp_state != SCTPS_ESTABLISHED && 600Sstevel@tonic-gate sctp->sctp_state != SCTPS_SHUTDOWN_PENDING && 610Sstevel@tonic-gate sctp->sctp_state != SCTPS_SHUTDOWN_SENT) { 620Sstevel@tonic-gate return; 630Sstevel@tonic-gate } 640Sstevel@tonic-gate 650Sstevel@tonic-gate if (sctp->sctp_state == SCTPS_ESTABLISHED) { 660Sstevel@tonic-gate sctp->sctp_state = SCTPS_SHUTDOWN_PENDING; 670Sstevel@tonic-gate /* 680Sstevel@tonic-gate * We set an upper bound on how long we will 690Sstevel@tonic-gate * wait for a shutdown-ack from the peer. This 700Sstevel@tonic-gate * is to prevent the receiver from attempting 710Sstevel@tonic-gate * to create a half-closed state indefinately. 720Sstevel@tonic-gate * See archive from IETF TSVWG mailing list 730Sstevel@tonic-gate * for June 2001 for more information. 740Sstevel@tonic-gate * Since we will not be calculating RTTs after 750Sstevel@tonic-gate * sending the shutdown, we can overload out_time 760Sstevel@tonic-gate * to track how long we have waited. 770Sstevel@tonic-gate */ 780Sstevel@tonic-gate sctp->sctp_out_time = lbolt64; 790Sstevel@tonic-gate } 800Sstevel@tonic-gate 810Sstevel@tonic-gate /* 820Sstevel@tonic-gate * If there is unsent (or unacked) data, wait for it to get ack'd 830Sstevel@tonic-gate */ 840Sstevel@tonic-gate if (sctp->sctp_xmit_head != NULL || sctp->sctp_xmit_unsent != NULL) { 850Sstevel@tonic-gate return; 860Sstevel@tonic-gate } 870Sstevel@tonic-gate 880Sstevel@tonic-gate /* rotate faddrs if we are retransmitting */ 890Sstevel@tonic-gate if (!rexmit) { 900Sstevel@tonic-gate fp = sctp->sctp_current; 910Sstevel@tonic-gate } else { 920Sstevel@tonic-gate fp = sctp_rotate_faddr(sctp, sctp->sctp_shutdown_faddr); 930Sstevel@tonic-gate } 940Sstevel@tonic-gate 950Sstevel@tonic-gate sctp->sctp_shutdown_faddr = fp; 960Sstevel@tonic-gate 970Sstevel@tonic-gate /* Link in a SACK if resending the shutdown */ 980Sstevel@tonic-gate if (sctp->sctp_state > SCTPS_SHUTDOWN_PENDING && 990Sstevel@tonic-gate (sendmp = sctp_make_sack(sctp, fp, NULL)) != NULL) { 1000Sstevel@tonic-gate 1010Sstevel@tonic-gate smp = allocb(sizeof (*sch) + sizeof (*ctsn), BPRI_MED); 1020Sstevel@tonic-gate if (smp == NULL) { 1030Sstevel@tonic-gate freemsg(sendmp); 1040Sstevel@tonic-gate goto done; 1050Sstevel@tonic-gate } 1060Sstevel@tonic-gate linkb(sendmp, smp); 1070Sstevel@tonic-gate 1080Sstevel@tonic-gate sch = (sctp_chunk_hdr_t *)smp->b_rptr; 1090Sstevel@tonic-gate smp->b_wptr = smp->b_rptr + sizeof (*sch) + sizeof (*ctsn); 1100Sstevel@tonic-gate } else { 1110Sstevel@tonic-gate sendmp = sctp_make_mp(sctp, fp, 1120Sstevel@tonic-gate sizeof (*sch) + sizeof (*ctsn)); 1130Sstevel@tonic-gate if (sendmp == NULL) { 1143448Sdh155122 SCTP_KSTAT(sctps, sctp_send_shutdown_failed); 1150Sstevel@tonic-gate goto done; 1160Sstevel@tonic-gate } 1170Sstevel@tonic-gate sch = (sctp_chunk_hdr_t *)sendmp->b_wptr; 1180Sstevel@tonic-gate sendmp->b_wptr += sizeof (*sch) + sizeof (*ctsn); 1190Sstevel@tonic-gate 1200Sstevel@tonic-gate /* shutdown w/o sack, update lastacked */ 1210Sstevel@tonic-gate sctp->sctp_lastacked = sctp->sctp_ftsn - 1; 1220Sstevel@tonic-gate } 1230Sstevel@tonic-gate 1240Sstevel@tonic-gate sch->sch_id = CHUNK_SHUTDOWN; 1250Sstevel@tonic-gate sch->sch_flags = 0; 1260Sstevel@tonic-gate sch->sch_len = htons(sizeof (*sch) + sizeof (*ctsn)); 1270Sstevel@tonic-gate 1280Sstevel@tonic-gate ctsn = (uint32_t *)(sch + 1); 1290Sstevel@tonic-gate *ctsn = htonl(sctp->sctp_lastacked); 1300Sstevel@tonic-gate 1310Sstevel@tonic-gate /* Link the shutdown chunk in after the IP/SCTP header */ 1320Sstevel@tonic-gate 1330Sstevel@tonic-gate BUMP_LOCAL(sctp->sctp_obchunks); 1340Sstevel@tonic-gate 1350Sstevel@tonic-gate /* Send the shutdown and restart the timer */ 136*11042SErik.Nordmark@Sun.COM sctp_set_iplen(sctp, sendmp, fp->ixa); 137*11042SErik.Nordmark@Sun.COM (void) conn_ip_output(sendmp, fp->ixa); 138*11042SErik.Nordmark@Sun.COM BUMP_LOCAL(sctp->sctp_opkts); 1390Sstevel@tonic-gate 1400Sstevel@tonic-gate done: 1410Sstevel@tonic-gate sctp->sctp_state = SCTPS_SHUTDOWN_SENT; 1420Sstevel@tonic-gate SCTP_FADDR_TIMER_RESTART(sctp, sctp->sctp_current, 1430Sstevel@tonic-gate sctp->sctp_current->rto); 1440Sstevel@tonic-gate } 1450Sstevel@tonic-gate 1460Sstevel@tonic-gate int 1471735Skcpoon sctp_shutdown_received(sctp_t *sctp, sctp_chunk_hdr_t *sch, boolean_t crwsd, 1481735Skcpoon boolean_t rexmit, sctp_faddr_t *fp) 1490Sstevel@tonic-gate { 1500Sstevel@tonic-gate mblk_t *samp; 1510Sstevel@tonic-gate sctp_chunk_hdr_t *sach; 1520Sstevel@tonic-gate uint32_t *tsn; 1530Sstevel@tonic-gate int trysend = 0; 1543448Sdh155122 sctp_stack_t *sctps = sctp->sctp_sctps; 1550Sstevel@tonic-gate 1560Sstevel@tonic-gate if (sctp->sctp_state != SCTPS_SHUTDOWN_ACK_SENT) 1570Sstevel@tonic-gate sctp->sctp_state = SCTPS_SHUTDOWN_RECEIVED; 1580Sstevel@tonic-gate 1590Sstevel@tonic-gate /* Extract and process the TSN in the shutdown chunk */ 1600Sstevel@tonic-gate if (sch != NULL) { 1610Sstevel@tonic-gate tsn = (uint32_t *)(sch + 1); 1620Sstevel@tonic-gate trysend = sctp_cumack(sctp, ntohl(*tsn), &samp); 1630Sstevel@tonic-gate } 1640Sstevel@tonic-gate 1650Sstevel@tonic-gate /* Don't allow sending new data */ 1664818Skcpoon if (!SCTP_IS_DETACHED(sctp) && !sctp->sctp_ulp_discon_done) { 1678348SEric.Yu@Sun.COM sctp->sctp_ulp_opctl(sctp->sctp_ulpd, SOCK_OPCTL_SHUT_SEND, 0); 1684818Skcpoon sctp->sctp_ulp_discon_done = B_TRUE; 1694818Skcpoon } 1700Sstevel@tonic-gate 1710Sstevel@tonic-gate /* 1720Sstevel@tonic-gate * If there is unsent or unacked data, try sending them out now. 1730Sstevel@tonic-gate * The other side should acknowledge them. After we have flushed 1740Sstevel@tonic-gate * the transmit queue, we can complete the shutdown sequence. 1750Sstevel@tonic-gate */ 1760Sstevel@tonic-gate if (sctp->sctp_xmit_head != NULL || sctp->sctp_xmit_unsent != NULL) 1770Sstevel@tonic-gate return (1); 1780Sstevel@tonic-gate 1791735Skcpoon if (fp == NULL) { 1801735Skcpoon /* rotate faddrs if we are retransmitting */ 1811735Skcpoon if (!rexmit) 1821735Skcpoon fp = sctp->sctp_current; 1831735Skcpoon else 1841735Skcpoon fp = sctp_rotate_faddr(sctp, sctp->sctp_shutdown_faddr); 1851735Skcpoon } 1861735Skcpoon sctp->sctp_shutdown_faddr = fp; 1870Sstevel@tonic-gate 1880Sstevel@tonic-gate samp = sctp_make_mp(sctp, fp, sizeof (*sach)); 1891735Skcpoon if (samp == NULL) { 1903448Sdh155122 SCTP_KSTAT(sctps, sctp_send_shutdown_ack_failed); 1910Sstevel@tonic-gate goto dotimer; 1921735Skcpoon } 1930Sstevel@tonic-gate 1940Sstevel@tonic-gate sach = (sctp_chunk_hdr_t *)samp->b_wptr; 1950Sstevel@tonic-gate sach->sch_id = CHUNK_SHUTDOWN_ACK; 1960Sstevel@tonic-gate sach->sch_flags = 0; 1970Sstevel@tonic-gate sach->sch_len = htons(sizeof (*sach)); 1980Sstevel@tonic-gate 1990Sstevel@tonic-gate samp->b_wptr += sizeof (*sach); 2000Sstevel@tonic-gate 2010Sstevel@tonic-gate /* 2020Sstevel@tonic-gate * bundle a "cookie received while shutting down" error if 2030Sstevel@tonic-gate * the caller asks for it. 2040Sstevel@tonic-gate */ 2050Sstevel@tonic-gate if (crwsd) { 2060Sstevel@tonic-gate mblk_t *errmp; 2070Sstevel@tonic-gate 2080Sstevel@tonic-gate errmp = sctp_make_err(sctp, SCTP_ERR_COOKIE_SHUT, NULL, 0); 2090Sstevel@tonic-gate if (errmp != NULL) { 2100Sstevel@tonic-gate linkb(samp, errmp); 2110Sstevel@tonic-gate BUMP_LOCAL(sctp->sctp_obchunks); 2120Sstevel@tonic-gate } 2130Sstevel@tonic-gate } 2140Sstevel@tonic-gate 2150Sstevel@tonic-gate BUMP_LOCAL(sctp->sctp_obchunks); 2160Sstevel@tonic-gate 217*11042SErik.Nordmark@Sun.COM sctp_set_iplen(sctp, samp, fp->ixa); 218*11042SErik.Nordmark@Sun.COM (void) conn_ip_output(samp, fp->ixa); 219*11042SErik.Nordmark@Sun.COM BUMP_LOCAL(sctp->sctp_opkts); 2200Sstevel@tonic-gate 2210Sstevel@tonic-gate dotimer: 2220Sstevel@tonic-gate sctp->sctp_state = SCTPS_SHUTDOWN_ACK_SENT; 2230Sstevel@tonic-gate SCTP_FADDR_TIMER_RESTART(sctp, sctp->sctp_current, 2240Sstevel@tonic-gate sctp->sctp_current->rto); 2250Sstevel@tonic-gate 2260Sstevel@tonic-gate return (trysend); 2270Sstevel@tonic-gate } 2280Sstevel@tonic-gate 2290Sstevel@tonic-gate void 2300Sstevel@tonic-gate sctp_shutdown_complete(sctp_t *sctp) 2310Sstevel@tonic-gate { 2320Sstevel@tonic-gate mblk_t *scmp; 2330Sstevel@tonic-gate sctp_chunk_hdr_t *scch; 2343448Sdh155122 sctp_stack_t *sctps = sctp->sctp_sctps; 2350Sstevel@tonic-gate 236*11042SErik.Nordmark@Sun.COM scmp = sctp_make_mp(sctp, sctp->sctp_current, sizeof (*scch)); 2370Sstevel@tonic-gate if (scmp == NULL) { 2380Sstevel@tonic-gate /* XXX use timer approach */ 2393448Sdh155122 SCTP_KSTAT(sctps, sctp_send_shutdown_comp_failed); 2400Sstevel@tonic-gate return; 2410Sstevel@tonic-gate } 2420Sstevel@tonic-gate 2430Sstevel@tonic-gate scch = (sctp_chunk_hdr_t *)scmp->b_wptr; 2440Sstevel@tonic-gate scch->sch_id = CHUNK_SHUTDOWN_COMPLETE; 2450Sstevel@tonic-gate scch->sch_flags = 0; 2460Sstevel@tonic-gate scch->sch_len = htons(sizeof (*scch)); 2470Sstevel@tonic-gate 2480Sstevel@tonic-gate scmp->b_wptr += sizeof (*scch); 2490Sstevel@tonic-gate 2500Sstevel@tonic-gate BUMP_LOCAL(sctp->sctp_obchunks); 2510Sstevel@tonic-gate 252*11042SErik.Nordmark@Sun.COM sctp_set_iplen(sctp, scmp, sctp->sctp_current->ixa); 253*11042SErik.Nordmark@Sun.COM (void) conn_ip_output(scmp, sctp->sctp_current->ixa); 254*11042SErik.Nordmark@Sun.COM BUMP_LOCAL(sctp->sctp_opkts); 2550Sstevel@tonic-gate } 2560Sstevel@tonic-gate 2570Sstevel@tonic-gate /* 2580Sstevel@tonic-gate * Similar to sctp_shutdown_complete(), except that since this 2590Sstevel@tonic-gate * is out-of-the-blue, we can't use an sctp's association information, 2600Sstevel@tonic-gate * and instead must draw all necessary info from the incoming packet. 2610Sstevel@tonic-gate */ 2620Sstevel@tonic-gate void 263*11042SErik.Nordmark@Sun.COM sctp_ootb_shutdown_ack(mblk_t *mp, uint_t ip_hdr_len, ip_recv_attr_t *ira, 264*11042SErik.Nordmark@Sun.COM ip_stack_t *ipst) 2650Sstevel@tonic-gate { 2660Sstevel@tonic-gate boolean_t isv4; 267*11042SErik.Nordmark@Sun.COM ipha_t *ipha = NULL; 268*11042SErik.Nordmark@Sun.COM ip6_t *ip6h = NULL; 2690Sstevel@tonic-gate sctp_hdr_t *insctph; 2700Sstevel@tonic-gate sctp_chunk_hdr_t *scch; 2710Sstevel@tonic-gate int i; 2720Sstevel@tonic-gate uint16_t port; 2730Sstevel@tonic-gate mblk_t *mp1; 274*11042SErik.Nordmark@Sun.COM netstack_t *ns = ipst->ips_netstack; 275*11042SErik.Nordmark@Sun.COM sctp_stack_t *sctps = ns->netstack_sctp; 276*11042SErik.Nordmark@Sun.COM ip_xmit_attr_t ixas; 2770Sstevel@tonic-gate 278*11042SErik.Nordmark@Sun.COM bzero(&ixas, sizeof (ixas)); 279*11042SErik.Nordmark@Sun.COM 280*11042SErik.Nordmark@Sun.COM isv4 = (IPH_HDR_VERSION(mp->b_rptr) == IPV4_VERSION); 281*11042SErik.Nordmark@Sun.COM 282*11042SErik.Nordmark@Sun.COM ASSERT(MBLKL(mp) >= sizeof (*insctph) + sizeof (*scch) + 283*11042SErik.Nordmark@Sun.COM (isv4 ? sizeof (ipha_t) : sizeof (ip6_t))); 2840Sstevel@tonic-gate 2850Sstevel@tonic-gate /* 2860Sstevel@tonic-gate * Check to see if we can reuse the incoming mblk. There should 287*11042SErik.Nordmark@Sun.COM * not be other reference. Since this packet comes from below, 2880Sstevel@tonic-gate * there should be enough header space to fill in what the lower 289*11042SErik.Nordmark@Sun.COM * layers want to add. 2900Sstevel@tonic-gate */ 291*11042SErik.Nordmark@Sun.COM if (DB_REF(mp) != 1) { 292*11042SErik.Nordmark@Sun.COM mp1 = allocb(MBLKL(mp) + sctps->sctps_wroff_xtra, BPRI_MED); 2930Sstevel@tonic-gate if (mp1 == NULL) { 294*11042SErik.Nordmark@Sun.COM freeb(mp); 2950Sstevel@tonic-gate return; 2960Sstevel@tonic-gate } 2973448Sdh155122 mp1->b_rptr += sctps->sctps_wroff_xtra; 298*11042SErik.Nordmark@Sun.COM mp1->b_wptr = mp1->b_rptr + MBLKL(mp); 299*11042SErik.Nordmark@Sun.COM bcopy(mp->b_rptr, mp1->b_rptr, MBLKL(mp)); 300*11042SErik.Nordmark@Sun.COM freeb(mp); 301*11042SErik.Nordmark@Sun.COM mp = mp1; 3021932Svi117747 } else { 303*11042SErik.Nordmark@Sun.COM DB_CKSUMFLAGS(mp) = 0; 3040Sstevel@tonic-gate } 3050Sstevel@tonic-gate 306*11042SErik.Nordmark@Sun.COM ixas.ixa_pktlen = ip_hdr_len + sizeof (*insctph) + sizeof (*scch); 307*11042SErik.Nordmark@Sun.COM ixas.ixa_ip_hdr_length = ip_hdr_len; 3080Sstevel@tonic-gate /* 3090Sstevel@tonic-gate * We follow the logic in tcp_xmit_early_reset() in that we skip 310*11042SErik.Nordmark@Sun.COM * reversing source route (i.e. replace all IP options with EOL). 3110Sstevel@tonic-gate */ 3120Sstevel@tonic-gate if (isv4) { 3130Sstevel@tonic-gate ipaddr_t v4addr; 3140Sstevel@tonic-gate 315*11042SErik.Nordmark@Sun.COM ipha = (ipha_t *)mp->b_rptr; 3160Sstevel@tonic-gate for (i = IP_SIMPLE_HDR_LENGTH; i < (int)ip_hdr_len; i++) 317*11042SErik.Nordmark@Sun.COM mp->b_rptr[i] = IPOPT_EOL; 3180Sstevel@tonic-gate /* Swap addresses */ 319*11042SErik.Nordmark@Sun.COM ipha->ipha_length = htons(ixas.ixa_pktlen); 320*11042SErik.Nordmark@Sun.COM v4addr = ipha->ipha_src; 321*11042SErik.Nordmark@Sun.COM ipha->ipha_src = ipha->ipha_dst; 322*11042SErik.Nordmark@Sun.COM ipha->ipha_dst = v4addr; 323*11042SErik.Nordmark@Sun.COM ipha->ipha_ident = 0; 324*11042SErik.Nordmark@Sun.COM ipha->ipha_ttl = (uchar_t)sctps->sctps_ipv4_ttl; 325*11042SErik.Nordmark@Sun.COM 326*11042SErik.Nordmark@Sun.COM ixas.ixa_flags = IXAF_BASIC_SIMPLE_V4; 3270Sstevel@tonic-gate } else { 3280Sstevel@tonic-gate in6_addr_t v6addr; 3290Sstevel@tonic-gate 330*11042SErik.Nordmark@Sun.COM ip6h = (ip6_t *)mp->b_rptr; 3310Sstevel@tonic-gate /* Remove any extension headers assuming partial overlay */ 3320Sstevel@tonic-gate if (ip_hdr_len > IPV6_HDR_LEN) { 3330Sstevel@tonic-gate uint8_t *to; 3340Sstevel@tonic-gate 335*11042SErik.Nordmark@Sun.COM to = mp->b_rptr + ip_hdr_len - IPV6_HDR_LEN; 336*11042SErik.Nordmark@Sun.COM ovbcopy(ip6h, to, IPV6_HDR_LEN); 337*11042SErik.Nordmark@Sun.COM mp->b_rptr += ip_hdr_len - IPV6_HDR_LEN; 3380Sstevel@tonic-gate ip_hdr_len = IPV6_HDR_LEN; 339*11042SErik.Nordmark@Sun.COM ip6h = (ip6_t *)mp->b_rptr; 340*11042SErik.Nordmark@Sun.COM ip6h->ip6_nxt = IPPROTO_SCTP; 3410Sstevel@tonic-gate } 342*11042SErik.Nordmark@Sun.COM ip6h->ip6_plen = htons(ixas.ixa_pktlen - IPV6_HDR_LEN); 343*11042SErik.Nordmark@Sun.COM v6addr = ip6h->ip6_src; 344*11042SErik.Nordmark@Sun.COM ip6h->ip6_src = ip6h->ip6_dst; 345*11042SErik.Nordmark@Sun.COM ip6h->ip6_dst = v6addr; 346*11042SErik.Nordmark@Sun.COM ip6h->ip6_hops = (uchar_t)sctps->sctps_ipv6_hoplimit; 347*11042SErik.Nordmark@Sun.COM 348*11042SErik.Nordmark@Sun.COM ixas.ixa_flags = IXAF_BASIC_SIMPLE_V6; 349*11042SErik.Nordmark@Sun.COM if (IN6_IS_ADDR_LINKSCOPE(&ip6h->ip6_dst)) { 350*11042SErik.Nordmark@Sun.COM ixas.ixa_flags |= IXAF_SCOPEID_SET; 351*11042SErik.Nordmark@Sun.COM ixas.ixa_scopeid = ira->ira_ruifindex; 352*11042SErik.Nordmark@Sun.COM } 3530Sstevel@tonic-gate } 354*11042SErik.Nordmark@Sun.COM 355*11042SErik.Nordmark@Sun.COM insctph = (sctp_hdr_t *)(mp->b_rptr + ip_hdr_len); 3560Sstevel@tonic-gate 3570Sstevel@tonic-gate /* Swap ports. Verification tag is reused. */ 3580Sstevel@tonic-gate port = insctph->sh_sport; 3590Sstevel@tonic-gate insctph->sh_sport = insctph->sh_dport; 3600Sstevel@tonic-gate insctph->sh_dport = port; 3610Sstevel@tonic-gate 3620Sstevel@tonic-gate /* Lay in the shutdown complete chunk */ 3630Sstevel@tonic-gate scch = (sctp_chunk_hdr_t *)(insctph + 1); 3640Sstevel@tonic-gate scch->sch_id = CHUNK_SHUTDOWN_COMPLETE; 3650Sstevel@tonic-gate scch->sch_len = htons(sizeof (*scch)); 3660Sstevel@tonic-gate scch->sch_flags = 0; 3670Sstevel@tonic-gate 3680Sstevel@tonic-gate /* Set the T-bit */ 3690Sstevel@tonic-gate SCTP_SET_TBIT(scch); 3700Sstevel@tonic-gate 371*11042SErik.Nordmark@Sun.COM ixas.ixa_protocol = IPPROTO_SCTP; 372*11042SErik.Nordmark@Sun.COM ixas.ixa_zoneid = ira->ira_zoneid; 373*11042SErik.Nordmark@Sun.COM ixas.ixa_ipst = ipst; 374*11042SErik.Nordmark@Sun.COM ixas.ixa_ifindex = 0; 3750Sstevel@tonic-gate 376*11042SErik.Nordmark@Sun.COM if (ira->ira_flags & IRAF_IPSEC_SECURE) { 377*11042SErik.Nordmark@Sun.COM /* 378*11042SErik.Nordmark@Sun.COM * Apply IPsec based on how IPsec was applied to 379*11042SErik.Nordmark@Sun.COM * the packet that was out of the blue. 380*11042SErik.Nordmark@Sun.COM */ 381*11042SErik.Nordmark@Sun.COM if (!ipsec_in_to_out(ira, &ixas, mp, ipha, ip6h)) { 382*11042SErik.Nordmark@Sun.COM BUMP_MIB(&ipst->ips_ip_mib, ipIfStatsOutDiscards); 383*11042SErik.Nordmark@Sun.COM /* Note: mp already consumed and ip_drop_packet done */ 384*11042SErik.Nordmark@Sun.COM return; 385*11042SErik.Nordmark@Sun.COM } 386*11042SErik.Nordmark@Sun.COM } else { 387*11042SErik.Nordmark@Sun.COM /* 388*11042SErik.Nordmark@Sun.COM * This is in clear. The message we are building 389*11042SErik.Nordmark@Sun.COM * here should go out in clear, independent of our policy. 390*11042SErik.Nordmark@Sun.COM */ 391*11042SErik.Nordmark@Sun.COM ixas.ixa_flags |= IXAF_NO_IPSEC; 392*11042SErik.Nordmark@Sun.COM } 393*11042SErik.Nordmark@Sun.COM 394*11042SErik.Nordmark@Sun.COM (void) ip_output_simple(mp, &ixas); 395*11042SErik.Nordmark@Sun.COM ixa_cleanup(&ixas); 3960Sstevel@tonic-gate } 397