10Sstevel@tonic-gate /*
20Sstevel@tonic-gate  * CDDL HEADER START
30Sstevel@tonic-gate  *
40Sstevel@tonic-gate  * The contents of this file are subject to the terms of the
51735Skcpoon  * Common Development and Distribution License (the "License").
61735Skcpoon  * You may not use this file except in compliance with the License.
70Sstevel@tonic-gate  *
80Sstevel@tonic-gate  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
90Sstevel@tonic-gate  * or http://www.opensolaris.org/os/licensing.
100Sstevel@tonic-gate  * See the License for the specific language governing permissions
110Sstevel@tonic-gate  * and limitations under the License.
120Sstevel@tonic-gate  *
130Sstevel@tonic-gate  * When distributing Covered Code, include this CDDL HEADER in each
140Sstevel@tonic-gate  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
150Sstevel@tonic-gate  * If applicable, add the following below this CDDL HEADER, with the
160Sstevel@tonic-gate  * fields enclosed by brackets "[]" replaced with your own identifying
170Sstevel@tonic-gate  * information: Portions Copyright [yyyy] [name of copyright owner]
180Sstevel@tonic-gate  *
190Sstevel@tonic-gate  * CDDL HEADER END
200Sstevel@tonic-gate  */
211735Skcpoon 
220Sstevel@tonic-gate /*
23*11858SChandrasekar.Marimuthu@Sun.COM  * Copyright 2010 Sun Microsystems, Inc.  All rights reserved.
240Sstevel@tonic-gate  * Use is subject to license terms.
250Sstevel@tonic-gate  */
260Sstevel@tonic-gate 
270Sstevel@tonic-gate #include <sys/types.h>
280Sstevel@tonic-gate #include <sys/systm.h>
290Sstevel@tonic-gate #include <sys/stream.h>
300Sstevel@tonic-gate #include <sys/ddi.h>
310Sstevel@tonic-gate #include <sys/sunddi.h>
320Sstevel@tonic-gate #include <sys/strsubr.h>
330Sstevel@tonic-gate #include <sys/strsun.h>
340Sstevel@tonic-gate 
350Sstevel@tonic-gate #include <netinet/in.h>
360Sstevel@tonic-gate #include <netinet/ip6.h>
370Sstevel@tonic-gate 
3811042SErik.Nordmark@Sun.COM #include <inet/ipsec_impl.h>
390Sstevel@tonic-gate #include <inet/common.h>
400Sstevel@tonic-gate #include <inet/ip.h>
410Sstevel@tonic-gate #include <inet/ip6.h>
420Sstevel@tonic-gate #include <inet/mib2.h>
430Sstevel@tonic-gate #include <inet/nd.h>
440Sstevel@tonic-gate #include <inet/optcom.h>
450Sstevel@tonic-gate #include <inet/sctp_ip.h>
463448Sdh155122 #include <inet/ipclassifier.h>
470Sstevel@tonic-gate #include "sctp_impl.h"
480Sstevel@tonic-gate 
490Sstevel@tonic-gate void
500Sstevel@tonic-gate sctp_send_shutdown(sctp_t *sctp, int rexmit)
510Sstevel@tonic-gate {
520Sstevel@tonic-gate 	mblk_t *smp;
530Sstevel@tonic-gate 	mblk_t *sendmp;
540Sstevel@tonic-gate 	sctp_chunk_hdr_t *sch;
550Sstevel@tonic-gate 	uint32_t *ctsn;
560Sstevel@tonic-gate 	sctp_faddr_t *fp;
573448Sdh155122 	sctp_stack_t	*sctps = sctp->sctp_sctps;
580Sstevel@tonic-gate 
590Sstevel@tonic-gate 	if (sctp->sctp_state != SCTPS_ESTABLISHED &&
600Sstevel@tonic-gate 	    sctp->sctp_state != SCTPS_SHUTDOWN_PENDING &&
610Sstevel@tonic-gate 	    sctp->sctp_state != SCTPS_SHUTDOWN_SENT) {
620Sstevel@tonic-gate 		return;
630Sstevel@tonic-gate 	}
640Sstevel@tonic-gate 
650Sstevel@tonic-gate 	if (sctp->sctp_state == SCTPS_ESTABLISHED) {
660Sstevel@tonic-gate 		sctp->sctp_state = SCTPS_SHUTDOWN_PENDING;
670Sstevel@tonic-gate 		/*
680Sstevel@tonic-gate 		 * We set an upper bound on how long we will
690Sstevel@tonic-gate 		 * wait for a shutdown-ack from the peer. This
700Sstevel@tonic-gate 		 * is to prevent the receiver from attempting
710Sstevel@tonic-gate 		 * to create a half-closed state indefinately.
720Sstevel@tonic-gate 		 * See archive from IETF TSVWG mailing list
730Sstevel@tonic-gate 		 * for June 2001 for more information.
740Sstevel@tonic-gate 		 * Since we will not be calculating RTTs after
750Sstevel@tonic-gate 		 * sending the shutdown, we can overload out_time
760Sstevel@tonic-gate 		 * to track how long we have waited.
770Sstevel@tonic-gate 		 */
7811066Srafael.vanoni@sun.com 		sctp->sctp_out_time = ddi_get_lbolt64();
790Sstevel@tonic-gate 	}
800Sstevel@tonic-gate 
810Sstevel@tonic-gate 	/*
820Sstevel@tonic-gate 	 * If there is unsent (or unacked) data, wait for it to get ack'd
830Sstevel@tonic-gate 	 */
840Sstevel@tonic-gate 	if (sctp->sctp_xmit_head != NULL || sctp->sctp_xmit_unsent != NULL) {
850Sstevel@tonic-gate 		return;
860Sstevel@tonic-gate 	}
870Sstevel@tonic-gate 
880Sstevel@tonic-gate 	/* rotate faddrs if we are retransmitting */
890Sstevel@tonic-gate 	if (!rexmit) {
900Sstevel@tonic-gate 		fp = sctp->sctp_current;
910Sstevel@tonic-gate 	} else {
920Sstevel@tonic-gate 		fp = sctp_rotate_faddr(sctp, sctp->sctp_shutdown_faddr);
930Sstevel@tonic-gate 	}
940Sstevel@tonic-gate 
950Sstevel@tonic-gate 	sctp->sctp_shutdown_faddr = fp;
960Sstevel@tonic-gate 
970Sstevel@tonic-gate 	/* Link in a SACK if resending the shutdown */
980Sstevel@tonic-gate 	if (sctp->sctp_state > SCTPS_SHUTDOWN_PENDING &&
990Sstevel@tonic-gate 	    (sendmp = sctp_make_sack(sctp, fp, NULL)) != NULL) {
1000Sstevel@tonic-gate 
1010Sstevel@tonic-gate 		smp = allocb(sizeof (*sch) + sizeof (*ctsn), BPRI_MED);
1020Sstevel@tonic-gate 		if (smp == NULL) {
1030Sstevel@tonic-gate 			freemsg(sendmp);
1040Sstevel@tonic-gate 			goto done;
1050Sstevel@tonic-gate 		}
1060Sstevel@tonic-gate 		linkb(sendmp, smp);
1070Sstevel@tonic-gate 
1080Sstevel@tonic-gate 		sch = (sctp_chunk_hdr_t *)smp->b_rptr;
1090Sstevel@tonic-gate 		smp->b_wptr = smp->b_rptr + sizeof (*sch) + sizeof (*ctsn);
1100Sstevel@tonic-gate 	} else {
1110Sstevel@tonic-gate 		sendmp = sctp_make_mp(sctp, fp,
1120Sstevel@tonic-gate 		    sizeof (*sch) + sizeof (*ctsn));
1130Sstevel@tonic-gate 		if (sendmp == NULL) {
1143448Sdh155122 			SCTP_KSTAT(sctps, sctp_send_shutdown_failed);
1150Sstevel@tonic-gate 			goto done;
1160Sstevel@tonic-gate 		}
1170Sstevel@tonic-gate 		sch = (sctp_chunk_hdr_t *)sendmp->b_wptr;
1180Sstevel@tonic-gate 		sendmp->b_wptr += sizeof (*sch) + sizeof (*ctsn);
1190Sstevel@tonic-gate 
1200Sstevel@tonic-gate 		/* shutdown w/o sack, update lastacked */
1210Sstevel@tonic-gate 		sctp->sctp_lastacked = sctp->sctp_ftsn - 1;
1220Sstevel@tonic-gate 	}
1230Sstevel@tonic-gate 
1240Sstevel@tonic-gate 	sch->sch_id = CHUNK_SHUTDOWN;
1250Sstevel@tonic-gate 	sch->sch_flags = 0;
1260Sstevel@tonic-gate 	sch->sch_len = htons(sizeof (*sch) + sizeof (*ctsn));
1270Sstevel@tonic-gate 
1280Sstevel@tonic-gate 	ctsn = (uint32_t *)(sch + 1);
1290Sstevel@tonic-gate 	*ctsn = htonl(sctp->sctp_lastacked);
1300Sstevel@tonic-gate 
1310Sstevel@tonic-gate 	/* Link the shutdown chunk in after the IP/SCTP header */
1320Sstevel@tonic-gate 
1330Sstevel@tonic-gate 	BUMP_LOCAL(sctp->sctp_obchunks);
1340Sstevel@tonic-gate 
1350Sstevel@tonic-gate 	/* Send the shutdown and restart the timer */
13611042SErik.Nordmark@Sun.COM 	sctp_set_iplen(sctp, sendmp, fp->ixa);
13711042SErik.Nordmark@Sun.COM 	(void) conn_ip_output(sendmp, fp->ixa);
13811042SErik.Nordmark@Sun.COM 	BUMP_LOCAL(sctp->sctp_opkts);
1390Sstevel@tonic-gate 
1400Sstevel@tonic-gate done:
1410Sstevel@tonic-gate 	sctp->sctp_state = SCTPS_SHUTDOWN_SENT;
1420Sstevel@tonic-gate 	SCTP_FADDR_TIMER_RESTART(sctp, sctp->sctp_current,
1430Sstevel@tonic-gate 	    sctp->sctp_current->rto);
1440Sstevel@tonic-gate }
1450Sstevel@tonic-gate 
1460Sstevel@tonic-gate int
1471735Skcpoon sctp_shutdown_received(sctp_t *sctp, sctp_chunk_hdr_t *sch, boolean_t crwsd,
1481735Skcpoon     boolean_t rexmit, sctp_faddr_t *fp)
1490Sstevel@tonic-gate {
1500Sstevel@tonic-gate 	mblk_t *samp;
1510Sstevel@tonic-gate 	sctp_chunk_hdr_t *sach;
1520Sstevel@tonic-gate 	uint32_t *tsn;
1530Sstevel@tonic-gate 	int trysend = 0;
1543448Sdh155122 	sctp_stack_t	*sctps = sctp->sctp_sctps;
1550Sstevel@tonic-gate 
1560Sstevel@tonic-gate 	if (sctp->sctp_state != SCTPS_SHUTDOWN_ACK_SENT)
1570Sstevel@tonic-gate 		sctp->sctp_state = SCTPS_SHUTDOWN_RECEIVED;
1580Sstevel@tonic-gate 
1590Sstevel@tonic-gate 	/* Extract and process the TSN in the shutdown chunk */
1600Sstevel@tonic-gate 	if (sch != NULL) {
1610Sstevel@tonic-gate 		tsn = (uint32_t *)(sch + 1);
162*11858SChandrasekar.Marimuthu@Sun.COM 		/* not already acked */
163*11858SChandrasekar.Marimuthu@Sun.COM 		if (!SEQ_LT(ntohl(*tsn), sctp->sctp_lastack_rxd))
164*11858SChandrasekar.Marimuthu@Sun.COM 			trysend = sctp_cumack(sctp, ntohl(*tsn), &samp);
1650Sstevel@tonic-gate 	}
1660Sstevel@tonic-gate 
1670Sstevel@tonic-gate 	/* Don't allow sending new data */
1684818Skcpoon 	if (!SCTP_IS_DETACHED(sctp) && !sctp->sctp_ulp_discon_done) {
1698348SEric.Yu@Sun.COM 		sctp->sctp_ulp_opctl(sctp->sctp_ulpd, SOCK_OPCTL_SHUT_SEND, 0);
1704818Skcpoon 		sctp->sctp_ulp_discon_done = B_TRUE;
1714818Skcpoon 	}
1720Sstevel@tonic-gate 
1730Sstevel@tonic-gate 	/*
1740Sstevel@tonic-gate 	 * If there is unsent or unacked data, try sending them out now.
1750Sstevel@tonic-gate 	 * The other side should acknowledge them.  After we have flushed
1760Sstevel@tonic-gate 	 * the transmit queue, we can complete the shutdown sequence.
1770Sstevel@tonic-gate 	 */
1780Sstevel@tonic-gate 	if (sctp->sctp_xmit_head != NULL || sctp->sctp_xmit_unsent != NULL)
1790Sstevel@tonic-gate 		return (1);
1800Sstevel@tonic-gate 
1811735Skcpoon 	if (fp == NULL) {
1821735Skcpoon 		/* rotate faddrs if we are retransmitting */
1831735Skcpoon 		if (!rexmit)
1841735Skcpoon 			fp = sctp->sctp_current;
1851735Skcpoon 		else
1861735Skcpoon 			fp = sctp_rotate_faddr(sctp, sctp->sctp_shutdown_faddr);
1871735Skcpoon 	}
1881735Skcpoon 	sctp->sctp_shutdown_faddr = fp;
1890Sstevel@tonic-gate 
1900Sstevel@tonic-gate 	samp = sctp_make_mp(sctp, fp, sizeof (*sach));
1911735Skcpoon 	if (samp == NULL) {
1923448Sdh155122 		SCTP_KSTAT(sctps, sctp_send_shutdown_ack_failed);
1930Sstevel@tonic-gate 		goto dotimer;
1941735Skcpoon 	}
1950Sstevel@tonic-gate 
1960Sstevel@tonic-gate 	sach = (sctp_chunk_hdr_t *)samp->b_wptr;
1970Sstevel@tonic-gate 	sach->sch_id = CHUNK_SHUTDOWN_ACK;
1980Sstevel@tonic-gate 	sach->sch_flags = 0;
1990Sstevel@tonic-gate 	sach->sch_len = htons(sizeof (*sach));
2000Sstevel@tonic-gate 
2010Sstevel@tonic-gate 	samp->b_wptr += sizeof (*sach);
2020Sstevel@tonic-gate 
2030Sstevel@tonic-gate 	/*
2040Sstevel@tonic-gate 	 * bundle a "cookie received while shutting down" error if
2050Sstevel@tonic-gate 	 * the caller asks for it.
2060Sstevel@tonic-gate 	 */
2070Sstevel@tonic-gate 	if (crwsd) {
2080Sstevel@tonic-gate 		mblk_t *errmp;
2090Sstevel@tonic-gate 
2100Sstevel@tonic-gate 		errmp = sctp_make_err(sctp, SCTP_ERR_COOKIE_SHUT, NULL, 0);
2110Sstevel@tonic-gate 		if (errmp != NULL) {
2120Sstevel@tonic-gate 			linkb(samp, errmp);
2130Sstevel@tonic-gate 			BUMP_LOCAL(sctp->sctp_obchunks);
2140Sstevel@tonic-gate 		}
2150Sstevel@tonic-gate 	}
2160Sstevel@tonic-gate 
2170Sstevel@tonic-gate 	BUMP_LOCAL(sctp->sctp_obchunks);
2180Sstevel@tonic-gate 
21911042SErik.Nordmark@Sun.COM 	sctp_set_iplen(sctp, samp, fp->ixa);
22011042SErik.Nordmark@Sun.COM 	(void) conn_ip_output(samp, fp->ixa);
22111042SErik.Nordmark@Sun.COM 	BUMP_LOCAL(sctp->sctp_opkts);
2220Sstevel@tonic-gate 
2230Sstevel@tonic-gate dotimer:
2240Sstevel@tonic-gate 	sctp->sctp_state = SCTPS_SHUTDOWN_ACK_SENT;
2250Sstevel@tonic-gate 	SCTP_FADDR_TIMER_RESTART(sctp, sctp->sctp_current,
2260Sstevel@tonic-gate 	    sctp->sctp_current->rto);
2270Sstevel@tonic-gate 
2280Sstevel@tonic-gate 	return (trysend);
2290Sstevel@tonic-gate }
2300Sstevel@tonic-gate 
2310Sstevel@tonic-gate void
2320Sstevel@tonic-gate sctp_shutdown_complete(sctp_t *sctp)
2330Sstevel@tonic-gate {
2340Sstevel@tonic-gate 	mblk_t *scmp;
2350Sstevel@tonic-gate 	sctp_chunk_hdr_t *scch;
2363448Sdh155122 	sctp_stack_t	*sctps = sctp->sctp_sctps;
2370Sstevel@tonic-gate 
23811042SErik.Nordmark@Sun.COM 	scmp = sctp_make_mp(sctp, sctp->sctp_current, sizeof (*scch));
2390Sstevel@tonic-gate 	if (scmp == NULL) {
2400Sstevel@tonic-gate 		/* XXX use timer approach */
2413448Sdh155122 		SCTP_KSTAT(sctps, sctp_send_shutdown_comp_failed);
2420Sstevel@tonic-gate 		return;
2430Sstevel@tonic-gate 	}
2440Sstevel@tonic-gate 
2450Sstevel@tonic-gate 	scch = (sctp_chunk_hdr_t *)scmp->b_wptr;
2460Sstevel@tonic-gate 	scch->sch_id = CHUNK_SHUTDOWN_COMPLETE;
2470Sstevel@tonic-gate 	scch->sch_flags = 0;
2480Sstevel@tonic-gate 	scch->sch_len = htons(sizeof (*scch));
2490Sstevel@tonic-gate 
2500Sstevel@tonic-gate 	scmp->b_wptr += sizeof (*scch);
2510Sstevel@tonic-gate 
2520Sstevel@tonic-gate 	BUMP_LOCAL(sctp->sctp_obchunks);
2530Sstevel@tonic-gate 
25411042SErik.Nordmark@Sun.COM 	sctp_set_iplen(sctp, scmp, sctp->sctp_current->ixa);
25511042SErik.Nordmark@Sun.COM 	(void) conn_ip_output(scmp, sctp->sctp_current->ixa);
25611042SErik.Nordmark@Sun.COM 	BUMP_LOCAL(sctp->sctp_opkts);
2570Sstevel@tonic-gate }
2580Sstevel@tonic-gate 
2590Sstevel@tonic-gate /*
2600Sstevel@tonic-gate  * Similar to sctp_shutdown_complete(), except that since this
2610Sstevel@tonic-gate  * is out-of-the-blue, we can't use an sctp's association information,
2620Sstevel@tonic-gate  * and instead must draw all necessary info from the incoming packet.
2630Sstevel@tonic-gate  */
2640Sstevel@tonic-gate void
26511042SErik.Nordmark@Sun.COM sctp_ootb_shutdown_ack(mblk_t *mp, uint_t ip_hdr_len, ip_recv_attr_t *ira,
26611042SErik.Nordmark@Sun.COM     ip_stack_t *ipst)
2670Sstevel@tonic-gate {
2680Sstevel@tonic-gate 	boolean_t		isv4;
26911042SErik.Nordmark@Sun.COM 	ipha_t			*ipha = NULL;
27011042SErik.Nordmark@Sun.COM 	ip6_t			*ip6h = NULL;
2710Sstevel@tonic-gate 	sctp_hdr_t		*insctph;
2720Sstevel@tonic-gate 	sctp_chunk_hdr_t	*scch;
2730Sstevel@tonic-gate 	int			i;
2740Sstevel@tonic-gate 	uint16_t		port;
2750Sstevel@tonic-gate 	mblk_t			*mp1;
27611042SErik.Nordmark@Sun.COM 	netstack_t		*ns = ipst->ips_netstack;
27711042SErik.Nordmark@Sun.COM 	sctp_stack_t		*sctps = ns->netstack_sctp;
27811042SErik.Nordmark@Sun.COM 	ip_xmit_attr_t		ixas;
2790Sstevel@tonic-gate 
28011042SErik.Nordmark@Sun.COM 	bzero(&ixas, sizeof (ixas));
28111042SErik.Nordmark@Sun.COM 
28211042SErik.Nordmark@Sun.COM 	isv4 = (IPH_HDR_VERSION(mp->b_rptr) == IPV4_VERSION);
28311042SErik.Nordmark@Sun.COM 
28411042SErik.Nordmark@Sun.COM 	ASSERT(MBLKL(mp) >= sizeof (*insctph) + sizeof (*scch) +
28511042SErik.Nordmark@Sun.COM 	    (isv4 ? sizeof (ipha_t) : sizeof (ip6_t)));
2860Sstevel@tonic-gate 
2870Sstevel@tonic-gate 	/*
2880Sstevel@tonic-gate 	 * Check to see if we can reuse the incoming mblk.  There should
28911042SErik.Nordmark@Sun.COM 	 * not be other reference. Since this packet comes from below,
2900Sstevel@tonic-gate 	 * there should be enough header space to fill in what the lower
29111042SErik.Nordmark@Sun.COM 	 * layers want to add.
2920Sstevel@tonic-gate 	 */
29311042SErik.Nordmark@Sun.COM 	if (DB_REF(mp) != 1) {
29411042SErik.Nordmark@Sun.COM 		mp1 = allocb(MBLKL(mp) + sctps->sctps_wroff_xtra, BPRI_MED);
2950Sstevel@tonic-gate 		if (mp1 == NULL) {
29611042SErik.Nordmark@Sun.COM 			freeb(mp);
2970Sstevel@tonic-gate 			return;
2980Sstevel@tonic-gate 		}
2993448Sdh155122 		mp1->b_rptr += sctps->sctps_wroff_xtra;
30011042SErik.Nordmark@Sun.COM 		mp1->b_wptr = mp1->b_rptr + MBLKL(mp);
30111042SErik.Nordmark@Sun.COM 		bcopy(mp->b_rptr, mp1->b_rptr, MBLKL(mp));
30211042SErik.Nordmark@Sun.COM 		freeb(mp);
30311042SErik.Nordmark@Sun.COM 		mp = mp1;
3041932Svi117747 	} else {
30511042SErik.Nordmark@Sun.COM 		DB_CKSUMFLAGS(mp) = 0;
3060Sstevel@tonic-gate 	}
3070Sstevel@tonic-gate 
30811042SErik.Nordmark@Sun.COM 	ixas.ixa_pktlen = ip_hdr_len + sizeof (*insctph) + sizeof (*scch);
30911042SErik.Nordmark@Sun.COM 	ixas.ixa_ip_hdr_length = ip_hdr_len;
3100Sstevel@tonic-gate 	/*
3110Sstevel@tonic-gate 	 * We follow the logic in tcp_xmit_early_reset() in that we skip
31211042SErik.Nordmark@Sun.COM 	 * reversing source route (i.e. replace all IP options with EOL).
3130Sstevel@tonic-gate 	 */
3140Sstevel@tonic-gate 	if (isv4) {
3150Sstevel@tonic-gate 		ipaddr_t	v4addr;
3160Sstevel@tonic-gate 
31711042SErik.Nordmark@Sun.COM 		ipha = (ipha_t *)mp->b_rptr;
3180Sstevel@tonic-gate 		for (i = IP_SIMPLE_HDR_LENGTH; i < (int)ip_hdr_len; i++)
31911042SErik.Nordmark@Sun.COM 			mp->b_rptr[i] = IPOPT_EOL;
3200Sstevel@tonic-gate 		/* Swap addresses */
32111042SErik.Nordmark@Sun.COM 		ipha->ipha_length = htons(ixas.ixa_pktlen);
32211042SErik.Nordmark@Sun.COM 		v4addr = ipha->ipha_src;
32311042SErik.Nordmark@Sun.COM 		ipha->ipha_src = ipha->ipha_dst;
32411042SErik.Nordmark@Sun.COM 		ipha->ipha_dst = v4addr;
32511042SErik.Nordmark@Sun.COM 		ipha->ipha_ident = 0;
32611042SErik.Nordmark@Sun.COM 		ipha->ipha_ttl = (uchar_t)sctps->sctps_ipv4_ttl;
32711042SErik.Nordmark@Sun.COM 
32811042SErik.Nordmark@Sun.COM 		ixas.ixa_flags = IXAF_BASIC_SIMPLE_V4;
3290Sstevel@tonic-gate 	} else {
3300Sstevel@tonic-gate 		in6_addr_t	v6addr;
3310Sstevel@tonic-gate 
33211042SErik.Nordmark@Sun.COM 		ip6h = (ip6_t *)mp->b_rptr;
3330Sstevel@tonic-gate 		/* Remove any extension headers assuming partial overlay */
3340Sstevel@tonic-gate 		if (ip_hdr_len > IPV6_HDR_LEN) {
3350Sstevel@tonic-gate 			uint8_t	*to;
3360Sstevel@tonic-gate 
33711042SErik.Nordmark@Sun.COM 			to = mp->b_rptr + ip_hdr_len - IPV6_HDR_LEN;
33811042SErik.Nordmark@Sun.COM 			ovbcopy(ip6h, to, IPV6_HDR_LEN);
33911042SErik.Nordmark@Sun.COM 			mp->b_rptr += ip_hdr_len - IPV6_HDR_LEN;
3400Sstevel@tonic-gate 			ip_hdr_len = IPV6_HDR_LEN;
34111042SErik.Nordmark@Sun.COM 			ip6h = (ip6_t *)mp->b_rptr;
34211042SErik.Nordmark@Sun.COM 			ip6h->ip6_nxt = IPPROTO_SCTP;
3430Sstevel@tonic-gate 		}
34411042SErik.Nordmark@Sun.COM 		ip6h->ip6_plen = htons(ixas.ixa_pktlen - IPV6_HDR_LEN);
34511042SErik.Nordmark@Sun.COM 		v6addr = ip6h->ip6_src;
34611042SErik.Nordmark@Sun.COM 		ip6h->ip6_src = ip6h->ip6_dst;
34711042SErik.Nordmark@Sun.COM 		ip6h->ip6_dst = v6addr;
34811042SErik.Nordmark@Sun.COM 		ip6h->ip6_hops = (uchar_t)sctps->sctps_ipv6_hoplimit;
34911042SErik.Nordmark@Sun.COM 
35011042SErik.Nordmark@Sun.COM 		ixas.ixa_flags = IXAF_BASIC_SIMPLE_V6;
35111042SErik.Nordmark@Sun.COM 		if (IN6_IS_ADDR_LINKSCOPE(&ip6h->ip6_dst)) {
35211042SErik.Nordmark@Sun.COM 			ixas.ixa_flags |= IXAF_SCOPEID_SET;
35311042SErik.Nordmark@Sun.COM 			ixas.ixa_scopeid = ira->ira_ruifindex;
35411042SErik.Nordmark@Sun.COM 		}
3550Sstevel@tonic-gate 	}
35611042SErik.Nordmark@Sun.COM 
35711042SErik.Nordmark@Sun.COM 	insctph = (sctp_hdr_t *)(mp->b_rptr + ip_hdr_len);
3580Sstevel@tonic-gate 
3590Sstevel@tonic-gate 	/* Swap ports.  Verification tag is reused. */
3600Sstevel@tonic-gate 	port = insctph->sh_sport;
3610Sstevel@tonic-gate 	insctph->sh_sport = insctph->sh_dport;
3620Sstevel@tonic-gate 	insctph->sh_dport = port;
3630Sstevel@tonic-gate 
3640Sstevel@tonic-gate 	/* Lay in the shutdown complete chunk */
3650Sstevel@tonic-gate 	scch = (sctp_chunk_hdr_t *)(insctph + 1);
3660Sstevel@tonic-gate 	scch->sch_id = CHUNK_SHUTDOWN_COMPLETE;
3670Sstevel@tonic-gate 	scch->sch_len = htons(sizeof (*scch));
3680Sstevel@tonic-gate 	scch->sch_flags = 0;
3690Sstevel@tonic-gate 
3700Sstevel@tonic-gate 	/* Set the T-bit */
3710Sstevel@tonic-gate 	SCTP_SET_TBIT(scch);
3720Sstevel@tonic-gate 
37311042SErik.Nordmark@Sun.COM 	ixas.ixa_protocol = IPPROTO_SCTP;
37411042SErik.Nordmark@Sun.COM 	ixas.ixa_zoneid = ira->ira_zoneid;
37511042SErik.Nordmark@Sun.COM 	ixas.ixa_ipst = ipst;
37611042SErik.Nordmark@Sun.COM 	ixas.ixa_ifindex = 0;
3770Sstevel@tonic-gate 
37811042SErik.Nordmark@Sun.COM 	if (ira->ira_flags & IRAF_IPSEC_SECURE) {
37911042SErik.Nordmark@Sun.COM 		/*
38011042SErik.Nordmark@Sun.COM 		 * Apply IPsec based on how IPsec was applied to
38111042SErik.Nordmark@Sun.COM 		 * the packet that was out of the blue.
38211042SErik.Nordmark@Sun.COM 		 */
38311042SErik.Nordmark@Sun.COM 		if (!ipsec_in_to_out(ira, &ixas, mp, ipha, ip6h)) {
38411042SErik.Nordmark@Sun.COM 			BUMP_MIB(&ipst->ips_ip_mib, ipIfStatsOutDiscards);
38511042SErik.Nordmark@Sun.COM 			/* Note: mp already consumed and ip_drop_packet done */
38611042SErik.Nordmark@Sun.COM 			return;
38711042SErik.Nordmark@Sun.COM 		}
38811042SErik.Nordmark@Sun.COM 	} else {
38911042SErik.Nordmark@Sun.COM 		/*
39011042SErik.Nordmark@Sun.COM 		 * This is in clear. The message we are building
39111042SErik.Nordmark@Sun.COM 		 * here should go out in clear, independent of our policy.
39211042SErik.Nordmark@Sun.COM 		 */
39311042SErik.Nordmark@Sun.COM 		ixas.ixa_flags |= IXAF_NO_IPSEC;
39411042SErik.Nordmark@Sun.COM 	}
39511042SErik.Nordmark@Sun.COM 
39611042SErik.Nordmark@Sun.COM 	(void) ip_output_simple(mp, &ixas);
39711042SErik.Nordmark@Sun.COM 	ixa_cleanup(&ixas);
3980Sstevel@tonic-gate }
399