2 * Copyright (c) 2012-2016 Apple Inc. All rights reserved.
4 * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. The rights granted to you under the License
10 * may not be used to create, or enable the creation or redistribution of,
11 * unlawful or unlicensed copies of an Apple operating system, or to
12 * circumvent, violate, or enable the circumvention or violation of, any
13 * terms of an Apple operating system software license agreement.
15 * Please obtain a copy of the License at
16 * http://www.opensource.apple.com/apsl/ and read it before using this file.
18 * The Original Code and all software distributed under the License are
19 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23 * Please see the License for the specific language governing rights and
24 * limitations under the License.
26 * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
29 #include <sys/param.h>
31 #include <sys/systm.h>
32 #include <sys/kernel.h>
34 #include <sys/mcache.h>
35 #include <sys/resourcevar.h>
36 #include <sys/socket.h>
37 #include <sys/socketvar.h>
38 #include <sys/syslog.h>
39 #include <sys/domain.h>
40 #include <sys/protosw.h>
41 #include <sys/sysctl.h>
43 #include <kern/zalloc.h>
44 #include <kern/locks.h>
46 #include <mach/thread_act.h>
50 #include <net/if_var.h>
51 #include <netinet/in.h>
52 #include <netinet/in_pcb.h>
53 #include <netinet/in_var.h>
54 #include <netinet/tcp.h>
55 #include <netinet/tcp_fsm.h>
56 #include <netinet/tcp_seq.h>
57 #include <netinet/tcp_var.h>
58 #include <netinet/mptcp_var.h>
59 #include <netinet/mptcp.h>
60 #include <netinet/mptcp_seq.h>
61 #include <netinet/mptcp_timer.h>
62 #include <libkern/crypto/sha1.h>
64 #include <netinet6/in6_pcb.h>
65 #include <netinet6/ip6protosw.h>
67 #include <dev/random/randomdev.h>
69 extern char *proc_best_name(proc_t
);
72 * Notes on MPTCP implementation.
74 * MPTCP is implemented as <SOCK_STREAM,IPPROTO_TCP> protocol in PF_MULTIPATH
75 * communication domain. The structure mtcbinfo describes the MPTCP instance
76 * of a Multipath protocol in that domain. It is used to keep track of all
77 * MPTCP PCB instances in the system, and is protected by the global lock
80 * An MPTCP socket is opened by calling socket(PF_MULTIPATH, SOCK_STREAM,
81 * IPPROTO_TCP). Upon success, a Multipath PCB gets allocated and along with
82 * it comes an MPTCP Session and an MPTCP PCB. All three structures are
83 * allocated from the same memory block, and each structure has a pointer
84 * to the adjacent ones. The layout is defined by the mpp_mtp structure.
85 * The socket lock (mpp_lock) is used to protect accesses to the Multipath
86 * PCB (mppcb) as well as the MPTCP Session (mptses).
88 * The MPTCP Session is an MPTCP-specific extension to the Multipath PCB;
89 * in particular, the list of subflows as well as the MPTCP thread.
91 * A functioning MPTCP Session consists of one or more subflow sockets. Each
92 * subflow socket is essentially a regular PF_INET/PF_INET6 TCP socket, and is
93 * represented by the mptsub structure. Because each subflow requires access
94 * to the MPTCP Session, the MPTCP socket's so_usecount is bumped up for each
95 * subflow. This gets decremented prior to the subflow's destruction. The
96 * subflow lock (mpts_lock) is used to protect accesses to the subflow.
98 * To handle events (read, write, control) from the subflows, an MPTCP thread
99 * is created; currently, there is one thread per MPTCP Session. In order to
100 * prevent the MPTCP socket from being destroyed while being accessed by the
101 * MPTCP thread, we bump up the MPTCP socket's so_usecount for the thread,
102 * which will be decremented prior to the thread's termination. The thread
103 * lock (mpte_thread_lock) is used to synchronize its signalling.
105 * Lock ordering is defined as follows:
107 * mtcbinfo (mppi_lock)
113 * It is not a requirement that all of the above locks need to be acquired
114 * in succession, but the correct lock ordering must be followed when there
115 * are more than one locks that need to be held. The MPTCP thread lock is
116 * is not constrained by this arrangement, because none of the other locks
117 * is ever acquired while holding mpte_thread_lock; therefore it may be called
118 * at any moment to signal the thread.
120 * An MPTCP socket will be destroyed when its so_usecount drops to zero; this
121 * work is done by the MPTCP garbage collector which is invoked on demand by
122 * the PF_MULTIPATH garbage collector. This process will take place once all
123 * of the subflows have been destroyed, and the MPTCP thread be instructed to
127 static void mptcp_sesdestroy(struct mptses
*);
128 static void mptcp_thread_signal_locked(struct mptses
*);
129 static void mptcp_thread_terminate_signal(struct mptses
*);
130 static void mptcp_thread_dowork(struct mptses
*);
131 static void mptcp_thread_func(void *, wait_result_t
);
132 static void mptcp_thread_destroy(struct mptses
*);
133 static void mptcp_key_pool_init(void);
134 static void mptcp_attach_to_subf(struct socket
*, struct mptcb
*, uint8_t);
135 static void mptcp_detach_mptcb_from_subf(struct mptcb
*, struct socket
*);
137 static uint32_t mptcp_gc(struct mppcbinfo
*);
138 static int mptcp_subflow_soclose(struct mptsub
*, struct socket
*);
139 static int mptcp_subflow_soconnectx(struct mptses
*, struct mptsub
*);
140 static int mptcp_subflow_soreceive(struct socket
*, struct sockaddr
**,
141 struct uio
*, struct mbuf
**, struct mbuf
**, int *);
142 static void mptcp_subflow_rupcall(struct socket
*, void *, int);
143 static void mptcp_subflow_input(struct mptses
*, struct mptsub
*);
144 static void mptcp_subflow_wupcall(struct socket
*, void *, int);
145 static void mptcp_subflow_eupcall(struct socket
*, void *, uint32_t);
146 static void mptcp_update_last_owner(struct mptsub
*, struct socket
*);
147 static void mptcp_output_needed(struct mptses
*mpte
, struct mptsub
*to_mpts
);
148 static void mptcp_get_rtt_measurement(struct mptsub
*, struct mptses
*);
149 static void mptcp_drop_tfo_data(struct mptses
*, struct mptsub
*, int *);
152 * Possible return values for subflow event handlers. Note that success
153 * values must be greater or equal than MPTS_EVRET_OK. Values less than that
154 * indicate errors or actions which require immediate attention; they will
155 * prevent the rest of the handlers from processing their respective events
156 * until the next round of events processing.
159 MPTS_EVRET_DELETE
= 1, /* delete this subflow */
160 MPTS_EVRET_OK
= 2, /* OK */
161 MPTS_EVRET_CONNECT_PENDING
= 3, /* resume pended connects */
162 MPTS_EVRET_DISCONNECT_FALLBACK
= 4, /* abort all but preferred */
165 static ev_ret_t
mptcp_subflow_events(struct mptses
*, struct mptsub
*, uint64_t *);
166 static ev_ret_t
mptcp_subflow_connreset_ev(struct mptses
*, struct mptsub
*, uint64_t *);
167 static ev_ret_t
mptcp_subflow_cantrcvmore_ev(struct mptses
*, struct mptsub
*, uint64_t *);
168 static ev_ret_t
mptcp_subflow_cantsendmore_ev(struct mptses
*, struct mptsub
*, uint64_t *);
169 static ev_ret_t
mptcp_subflow_timeout_ev(struct mptses
*, struct mptsub
*, uint64_t *);
170 static ev_ret_t
mptcp_subflow_nosrcaddr_ev(struct mptses
*, struct mptsub
*, uint64_t *);
171 static ev_ret_t
mptcp_subflow_failover_ev(struct mptses
*, struct mptsub
*, uint64_t *);
172 static ev_ret_t
mptcp_subflow_ifdenied_ev(struct mptses
*, struct mptsub
*, uint64_t *);
173 static ev_ret_t
mptcp_subflow_suspend_ev(struct mptses
*, struct mptsub
*, uint64_t *);
174 static ev_ret_t
mptcp_subflow_resume_ev(struct mptses
*, struct mptsub
*, uint64_t *);
175 static ev_ret_t
mptcp_subflow_connected_ev(struct mptses
*, struct mptsub
*, uint64_t *);
176 static ev_ret_t
mptcp_subflow_disconnected_ev(struct mptses
*, struct mptsub
*, uint64_t *);
177 static ev_ret_t
mptcp_subflow_mpstatus_ev(struct mptses
*, struct mptsub
*, uint64_t *);
178 static ev_ret_t
mptcp_subflow_mustrst_ev(struct mptses
*, struct mptsub
*, uint64_t *);
179 static ev_ret_t
mptcp_fastjoin_ev(struct mptses
*, struct mptsub
*, uint64_t *);
180 static ev_ret_t
mptcp_deleteok_ev(struct mptses
*, struct mptsub
*, uint64_t *);
181 static ev_ret_t
mptcp_subflow_mpcantrcvmore_ev(struct mptses
*, struct mptsub
*, uint64_t *);
183 static const char *mptcp_evret2str(ev_ret_t
);
185 static mptcp_key_t
*mptcp_reserve_key(void);
186 static int mptcp_do_sha1(mptcp_key_t
*, char *, int);
187 static void mptcp_init_local_parms(struct mptcb
*);
189 static unsigned int mptsub_zone_size
; /* size of mptsub */
190 static struct zone
*mptsub_zone
; /* zone for mptsub */
192 static unsigned int mptopt_zone_size
; /* size of mptopt */
193 static struct zone
*mptopt_zone
; /* zone for mptopt */
195 static unsigned int mpt_subauth_entry_size
; /* size of subf auth entry */
196 static struct zone
*mpt_subauth_zone
; /* zone of subf auth entry */
198 struct mppcbinfo mtcbinfo
;
200 static struct mptcp_keys_pool_head mptcp_keys_pool
;
202 #define MPTCP_SUBFLOW_WRITELEN (8 * 1024) /* bytes to write each time */
203 #define MPTCP_SUBFLOW_READLEN (8 * 1024) /* bytes to read each time */
205 SYSCTL_DECL(_net_inet
);
207 SYSCTL_NODE(_net_inet
, OID_AUTO
, mptcp
, CTLFLAG_RW
|CTLFLAG_LOCKED
, 0, "MPTCP");
209 uint32_t mptcp_dbg_area
= 0; /* more noise if greater than 1 */
210 SYSCTL_UINT(_net_inet_mptcp
, OID_AUTO
, dbg_area
, CTLFLAG_RW
|CTLFLAG_LOCKED
,
211 &mptcp_dbg_area
, 0, "MPTCP debug area");
213 uint32_t mptcp_dbg_level
= 0;
214 SYSCTL_INT(_net_inet_mptcp
, OID_AUTO
, dbg_level
, CTLFLAG_RW
| CTLFLAG_LOCKED
,
215 &mptcp_dbg_level
, 0, "MPTCP debug level");
218 SYSCTL_UINT(_net_inet_mptcp
, OID_AUTO
, pcbcount
, CTLFLAG_RD
|CTLFLAG_LOCKED
,
219 &mtcbinfo
.mppi_count
, 0, "Number of active PCBs");
222 * Since there is one kernel thread per mptcp socket, imposing an artificial
223 * limit on number of allowed mptcp sockets.
225 uint32_t mptcp_socket_limit
= MPPCB_LIMIT
;
226 SYSCTL_UINT(_net_inet_mptcp
, OID_AUTO
, sk_lim
, CTLFLAG_RW
|CTLFLAG_LOCKED
,
227 &mptcp_socket_limit
, 0, "MPTCP socket limit");
230 * SYSCTL to turn on delayed cellular subflow start.
232 uint32_t mptcp_delayed_subf_start
= 0;
233 SYSCTL_UINT(_net_inet_mptcp
, OID_AUTO
, delayed
, CTLFLAG_RW
|CTLFLAG_LOCKED
,
234 &mptcp_delayed_subf_start
, 0, "MPTCP Delayed Subflow start");
237 * sysctl to use network status hints from symptomsd
239 uint32_t mptcp_use_symptomsd
= 1;
240 SYSCTL_UINT(_net_inet_mptcp
, OID_AUTO
, usesymptoms
, CTLFLAG_RW
|CTLFLAG_LOCKED
,
241 &mptcp_use_symptomsd
, 0, "MPTCP Use SymptomsD");
243 static struct protosw mptcp_subflow_protosw
;
244 static struct pr_usrreqs mptcp_subflow_usrreqs
;
246 static struct ip6protosw mptcp_subflow_protosw6
;
247 static struct pr_usrreqs mptcp_subflow_usrreqs6
;
250 typedef struct mptcp_subflow_event_entry
{
251 uint64_t sofilt_hint_mask
;
252 ev_ret_t (*sofilt_hint_ev_hdlr
)(
255 uint64_t *p_mpsofilt_hint
);
259 * XXX The order of the event handlers below is really
261 * SO_FILT_HINT_DELETEOK event has to be handled first,
262 * else we may end up missing on this event.
263 * Please read radar://24043716 for more details.
265 static mptsub_ev_entry_t mpsub_ev_entry_tbl
[] = {
267 .sofilt_hint_mask
= SO_FILT_HINT_DELETEOK
,
268 .sofilt_hint_ev_hdlr
= mptcp_deleteok_ev
,
271 .sofilt_hint_mask
= SO_FILT_HINT_MPCANTRCVMORE
,
272 .sofilt_hint_ev_hdlr
= mptcp_subflow_mpcantrcvmore_ev
,
275 .sofilt_hint_mask
= SO_FILT_HINT_MPFAILOVER
,
276 .sofilt_hint_ev_hdlr
= mptcp_subflow_failover_ev
,
279 .sofilt_hint_mask
= SO_FILT_HINT_CONNRESET
,
280 .sofilt_hint_ev_hdlr
= mptcp_subflow_connreset_ev
,
283 .sofilt_hint_mask
= SO_FILT_HINT_MUSTRST
,
284 .sofilt_hint_ev_hdlr
= mptcp_subflow_mustrst_ev
,
287 .sofilt_hint_mask
= SO_FILT_HINT_CANTRCVMORE
,
288 .sofilt_hint_ev_hdlr
= mptcp_subflow_cantrcvmore_ev
,
290 { .sofilt_hint_mask
= SO_FILT_HINT_CANTSENDMORE
,
291 .sofilt_hint_ev_hdlr
= mptcp_subflow_cantsendmore_ev
,
294 .sofilt_hint_mask
= SO_FILT_HINT_TIMEOUT
,
295 .sofilt_hint_ev_hdlr
= mptcp_subflow_timeout_ev
,
298 .sofilt_hint_mask
= SO_FILT_HINT_NOSRCADDR
,
299 .sofilt_hint_ev_hdlr
= mptcp_subflow_nosrcaddr_ev
,
302 .sofilt_hint_mask
= SO_FILT_HINT_IFDENIED
,
303 .sofilt_hint_ev_hdlr
= mptcp_subflow_ifdenied_ev
,
306 .sofilt_hint_mask
= SO_FILT_HINT_SUSPEND
,
307 .sofilt_hint_ev_hdlr
= mptcp_subflow_suspend_ev
,
310 .sofilt_hint_mask
= SO_FILT_HINT_RESUME
,
311 .sofilt_hint_ev_hdlr
= mptcp_subflow_resume_ev
,
314 .sofilt_hint_mask
= SO_FILT_HINT_CONNECTED
,
315 .sofilt_hint_ev_hdlr
= mptcp_subflow_connected_ev
,
318 .sofilt_hint_mask
= SO_FILT_HINT_MPSTATUS
,
319 .sofilt_hint_ev_hdlr
= mptcp_subflow_mpstatus_ev
,
322 .sofilt_hint_mask
= SO_FILT_HINT_DISCONNECTED
,
323 .sofilt_hint_ev_hdlr
= mptcp_subflow_disconnected_ev
,
326 .sofilt_hint_mask
= SO_FILT_HINT_MPFASTJ
,
327 .sofilt_hint_ev_hdlr
= mptcp_fastjoin_ev
,
332 * Protocol pr_init callback.
335 mptcp_init(struct protosw
*pp
, struct domain
*dp
)
338 static int mptcp_initialized
= 0;
341 struct ip6protosw
*prp6
;
344 VERIFY((pp
->pr_flags
& (PR_INITIALIZED
|PR_ATTACHED
)) == PR_ATTACHED
);
346 /* do this only once */
347 if (mptcp_initialized
)
349 mptcp_initialized
= 1;
352 * Since PF_MULTIPATH gets initialized after PF_INET/INET6,
353 * we must be able to find IPPROTO_TCP entries for both.
355 prp
= pffindproto_locked(PF_INET
, IPPROTO_TCP
, SOCK_STREAM
);
357 bcopy(prp
, &mptcp_subflow_protosw
, sizeof (*prp
));
358 bcopy(prp
->pr_usrreqs
, &mptcp_subflow_usrreqs
,
359 sizeof (mptcp_subflow_usrreqs
));
360 mptcp_subflow_protosw
.pr_entry
.tqe_next
= NULL
;
361 mptcp_subflow_protosw
.pr_entry
.tqe_prev
= NULL
;
362 mptcp_subflow_protosw
.pr_usrreqs
= &mptcp_subflow_usrreqs
;
363 mptcp_subflow_usrreqs
.pru_soreceive
= mptcp_subflow_soreceive
;
364 mptcp_subflow_usrreqs
.pru_rcvoob
= pru_rcvoob_notsupp
;
366 * Socket filters shouldn't attach/detach to/from this protosw
367 * since pr_protosw is to be used instead, which points to the
368 * real protocol; if they do, it is a bug and we should panic.
370 mptcp_subflow_protosw
.pr_filter_head
.tqh_first
=
371 (struct socket_filter
*)(uintptr_t)0xdeadbeefdeadbeef;
372 mptcp_subflow_protosw
.pr_filter_head
.tqh_last
=
373 (struct socket_filter
**)(uintptr_t)0xdeadbeefdeadbeef;
376 prp6
= (struct ip6protosw
*)pffindproto_locked(PF_INET6
,
377 IPPROTO_TCP
, SOCK_STREAM
);
378 VERIFY(prp6
!= NULL
);
379 bcopy(prp6
, &mptcp_subflow_protosw6
, sizeof (*prp6
));
380 bcopy(prp6
->pr_usrreqs
, &mptcp_subflow_usrreqs6
,
381 sizeof (mptcp_subflow_usrreqs6
));
382 mptcp_subflow_protosw6
.pr_entry
.tqe_next
= NULL
;
383 mptcp_subflow_protosw6
.pr_entry
.tqe_prev
= NULL
;
384 mptcp_subflow_protosw6
.pr_usrreqs
= &mptcp_subflow_usrreqs6
;
385 mptcp_subflow_usrreqs6
.pru_soreceive
= mptcp_subflow_soreceive
;
386 mptcp_subflow_usrreqs6
.pru_rcvoob
= pru_rcvoob_notsupp
;
388 * Socket filters shouldn't attach/detach to/from this protosw
389 * since pr_protosw is to be used instead, which points to the
390 * real protocol; if they do, it is a bug and we should panic.
392 mptcp_subflow_protosw6
.pr_filter_head
.tqh_first
=
393 (struct socket_filter
*)(uintptr_t)0xdeadbeefdeadbeef;
394 mptcp_subflow_protosw6
.pr_filter_head
.tqh_last
=
395 (struct socket_filter
**)(uintptr_t)0xdeadbeefdeadbeef;
398 bzero(&mtcbinfo
, sizeof (mtcbinfo
));
399 TAILQ_INIT(&mtcbinfo
.mppi_pcbs
);
400 mtcbinfo
.mppi_size
= sizeof (struct mpp_mtp
);
401 if ((mtcbinfo
.mppi_zone
= zinit(mtcbinfo
.mppi_size
,
402 1024 * mtcbinfo
.mppi_size
, 8192, "mptcb")) == NULL
) {
403 panic("%s: unable to allocate MPTCP PCB zone\n", __func__
);
406 zone_change(mtcbinfo
.mppi_zone
, Z_CALLERACCT
, FALSE
);
407 zone_change(mtcbinfo
.mppi_zone
, Z_EXPAND
, TRUE
);
409 mtcbinfo
.mppi_lock_grp_attr
= lck_grp_attr_alloc_init();
410 mtcbinfo
.mppi_lock_grp
= lck_grp_alloc_init("mppcb",
411 mtcbinfo
.mppi_lock_grp_attr
);
412 mtcbinfo
.mppi_lock_attr
= lck_attr_alloc_init();
413 lck_mtx_init(&mtcbinfo
.mppi_lock
, mtcbinfo
.mppi_lock_grp
,
414 mtcbinfo
.mppi_lock_attr
);
416 mtcbinfo
.mppi_gc
= mptcp_gc
;
417 mtcbinfo
.mppi_timer
= mptcp_timer
;
418 mtcbinfo
.mppi_pcbe_create
= mptcp_sescreate
;
420 /* attach to MP domain for garbage collection to take place */
421 mp_pcbinfo_attach(&mtcbinfo
);
423 mptsub_zone_size
= sizeof (struct mptsub
);
424 if ((mptsub_zone
= zinit(mptsub_zone_size
, 1024 * mptsub_zone_size
,
425 8192, "mptsub")) == NULL
) {
426 panic("%s: unable to allocate MPTCP subflow zone\n", __func__
);
429 zone_change(mptsub_zone
, Z_CALLERACCT
, FALSE
);
430 zone_change(mptsub_zone
, Z_EXPAND
, TRUE
);
432 mptopt_zone_size
= sizeof (struct mptopt
);
433 if ((mptopt_zone
= zinit(mptopt_zone_size
, 128 * mptopt_zone_size
,
434 1024, "mptopt")) == NULL
) {
435 panic("%s: unable to allocate MPTCP option zone\n", __func__
);
438 zone_change(mptopt_zone
, Z_CALLERACCT
, FALSE
);
439 zone_change(mptopt_zone
, Z_EXPAND
, TRUE
);
441 mpt_subauth_entry_size
= sizeof (struct mptcp_subf_auth_entry
);
442 if ((mpt_subauth_zone
= zinit(mpt_subauth_entry_size
,
443 1024 * mpt_subauth_entry_size
, 8192, "mptauth")) == NULL
) {
444 panic("%s: unable to allocate MPTCP address auth zone \n",
448 zone_change(mpt_subauth_zone
, Z_CALLERACCT
, FALSE
);
449 zone_change(mpt_subauth_zone
, Z_EXPAND
, TRUE
);
451 /* Set up a list of unique keys */
452 mptcp_key_pool_init();
456 * Create an MPTCP session, called as a result of opening a MPTCP socket.
459 mptcp_sescreate(struct socket
*mp_so
, struct mppcb
*mpp
)
461 struct mppcbinfo
*mppi
;
467 mppi
= mpp
->mpp_pcbinfo
;
468 VERIFY(mppi
!= NULL
);
470 __IGNORE_WCASTALIGN(mpte
= &((struct mpp_mtp
*)mpp
)->mpp_ses
);
471 __IGNORE_WCASTALIGN(mp_tp
= &((struct mpp_mtp
*)mpp
)->mtcb
);
473 /* MPTCP Multipath PCB Extension */
474 bzero(mpte
, sizeof (*mpte
));
475 VERIFY(mpp
->mpp_pcbe
== NULL
);
476 mpp
->mpp_pcbe
= mpte
;
477 mpte
->mpte_mppcb
= mpp
;
478 mpte
->mpte_mptcb
= mp_tp
;
480 TAILQ_INIT(&mpte
->mpte_sopts
);
481 TAILQ_INIT(&mpte
->mpte_subflows
);
482 mpte
->mpte_associd
= SAE_ASSOCID_ANY
;
483 mpte
->mpte_connid_last
= SAE_CONNID_ANY
;
485 lck_mtx_init(&mpte
->mpte_thread_lock
, mppi
->mppi_lock_grp
,
486 mppi
->mppi_lock_attr
);
491 * This can be rather expensive if we have lots of MPTCP sockets,
492 * but we need a kernel thread for this model to work. Perhaps we
493 * could amortize the costs by having one worker thread per a group
496 if (kernel_thread_start(mptcp_thread_func
, mpte
,
497 &mpte
->mpte_thread
) != KERN_SUCCESS
) {
501 mp_so
->so_usecount
++; /* for thread */
503 /* MPTCP Protocol Control Block */
504 bzero(mp_tp
, sizeof (*mp_tp
));
505 lck_mtx_init(&mp_tp
->mpt_lock
, mppi
->mppi_lock_grp
,
506 mppi
->mppi_lock_attr
);
507 mp_tp
->mpt_mpte
= mpte
;
508 mp_tp
->mpt_state
= MPTCPS_CLOSED
;
511 lck_mtx_destroy(&mpte
->mpte_thread_lock
, mppi
->mppi_lock_grp
);
512 DTRACE_MPTCP5(session__create
, struct socket
*, mp_so
,
513 struct sockbuf
*, &mp_so
->so_rcv
,
514 struct sockbuf
*, &mp_so
->so_snd
,
515 struct mppcb
*, mpp
, int, error
);
517 return ((error
!= 0) ? NULL
: mpte
);
521 * Destroy an MPTCP session.
524 mptcp_sesdestroy(struct mptses
*mpte
)
528 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
530 mp_tp
= mpte
->mpte_mptcb
;
531 VERIFY(mp_tp
!= NULL
);
534 * MPTCP Multipath PCB Extension section
536 mptcp_flush_sopts(mpte
);
537 VERIFY(TAILQ_EMPTY(&mpte
->mpte_subflows
) && mpte
->mpte_numflows
== 0);
539 lck_mtx_destroy(&mpte
->mpte_thread_lock
,
540 mpte
->mpte_mppcb
->mpp_pcbinfo
->mppi_lock_grp
);
543 * MPTCP Protocol Control Block section
545 lck_mtx_destroy(&mp_tp
->mpt_lock
,
546 mpte
->mpte_mppcb
->mpp_pcbinfo
->mppi_lock_grp
);
548 DTRACE_MPTCP2(session__destroy
, struct mptses
*, mpte
,
549 struct mptcb
*, mp_tp
);
553 * Allocate an MPTCP socket option structure.
556 mptcp_sopt_alloc(int how
)
560 mpo
= (how
== M_WAITOK
) ? zalloc(mptopt_zone
) :
561 zalloc_noblock(mptopt_zone
);
563 bzero(mpo
, mptopt_zone_size
);
570 * Free an MPTCP socket option structure.
573 mptcp_sopt_free(struct mptopt
*mpo
)
575 VERIFY(!(mpo
->mpo_flags
& MPOF_ATTACHED
));
577 zfree(mptopt_zone
, mpo
);
581 * Add a socket option to the MPTCP socket option list.
584 mptcp_sopt_insert(struct mptses
*mpte
, struct mptopt
*mpo
)
586 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
587 VERIFY(!(mpo
->mpo_flags
& MPOF_ATTACHED
));
588 mpo
->mpo_flags
|= MPOF_ATTACHED
;
589 TAILQ_INSERT_TAIL(&mpte
->mpte_sopts
, mpo
, mpo_entry
);
593 * Remove a socket option from the MPTCP socket option list.
596 mptcp_sopt_remove(struct mptses
*mpte
, struct mptopt
*mpo
)
598 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
599 VERIFY(mpo
->mpo_flags
& MPOF_ATTACHED
);
600 mpo
->mpo_flags
&= ~MPOF_ATTACHED
;
601 TAILQ_REMOVE(&mpte
->mpte_sopts
, mpo
, mpo_entry
);
605 * Search for an existing <sopt_level,sopt_name> socket option.
608 mptcp_sopt_find(struct mptses
*mpte
, struct sockopt
*sopt
)
612 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
614 TAILQ_FOREACH(mpo
, &mpte
->mpte_sopts
, mpo_entry
) {
615 if (mpo
->mpo_level
== sopt
->sopt_level
&&
616 mpo
->mpo_name
== sopt
->sopt_name
)
619 VERIFY(mpo
== NULL
|| sopt
->sopt_valsize
== sizeof (int));
625 * Flushes all recorded socket options from an MP socket.
628 mptcp_flush_sopts(struct mptses
*mpte
)
630 struct mptopt
*mpo
, *tmpo
;
632 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
634 TAILQ_FOREACH_SAFE(mpo
, &mpte
->mpte_sopts
, mpo_entry
, tmpo
) {
635 mptcp_sopt_remove(mpte
, mpo
);
636 mptcp_sopt_free(mpo
);
638 VERIFY(TAILQ_EMPTY(&mpte
->mpte_sopts
));
642 * Allocate a MPTCP subflow structure.
645 mptcp_subflow_alloc(int how
)
649 mpts
= (how
== M_WAITOK
) ? zalloc(mptsub_zone
) :
650 zalloc_noblock(mptsub_zone
);
652 bzero(mpts
, mptsub_zone_size
);
653 lck_mtx_init(&mpts
->mpts_lock
, mtcbinfo
.mppi_lock_grp
,
654 mtcbinfo
.mppi_lock_attr
);
661 * Deallocate a subflow structure, called when all of the references held
662 * on it have been released. This implies that the subflow has been deleted.
665 mptcp_subflow_free(struct mptsub
*mpts
)
667 MPTS_LOCK_ASSERT_HELD(mpts
);
669 VERIFY(mpts
->mpts_refcnt
== 0);
670 VERIFY(!(mpts
->mpts_flags
& MPTSF_ATTACHED
));
671 VERIFY(mpts
->mpts_mpte
== NULL
);
672 VERIFY(mpts
->mpts_socket
== NULL
);
674 if (mpts
->mpts_src
!= NULL
) {
675 FREE(mpts
->mpts_src
, M_SONAME
);
676 mpts
->mpts_src
= NULL
;
678 if (mpts
->mpts_dst
!= NULL
) {
679 FREE(mpts
->mpts_dst
, M_SONAME
);
680 mpts
->mpts_dst
= NULL
;
683 lck_mtx_destroy(&mpts
->mpts_lock
, mtcbinfo
.mppi_lock_grp
);
685 zfree(mptsub_zone
, mpts
);
689 * Create an MPTCP subflow socket.
692 mptcp_subflow_socreate(struct mptses
*mpte
, struct mptsub
*mpts
, int dom
,
693 struct proc
*p
, struct socket
**so
)
695 struct mptopt smpo
, *mpo
, *tmpo
;
696 struct socket
*mp_so
;
700 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
701 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
704 * Create the subflow socket (multipath subflow, non-blocking.)
706 * This will cause SOF_MP_SUBFLOW socket flag to be set on the subflow
707 * socket; it will be cleared when the socket is peeled off or closed.
708 * It also indicates to the underlying TCP to handle MPTCP options.
709 * A multipath subflow socket implies SS_NOFDREF state.
711 if ((error
= socreate_internal(dom
, so
, SOCK_STREAM
,
712 IPPROTO_TCP
, p
, SOCF_ASYNC
| SOCF_MP_SUBFLOW
, PROC_NULL
)) != 0) {
713 mptcplog((LOG_ERR
, "MPTCP Socket: subflow socreate mp_so 0x%llx"
714 " unable to create subflow socket error %d\n",
715 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
), error
),
716 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_ERR
);
721 VERIFY((*so
)->so_flags
& SOF_MP_SUBFLOW
);
722 VERIFY(((*so
)->so_state
& (SS_NBIO
|SS_NOFDREF
)) ==
723 (SS_NBIO
|SS_NOFDREF
));
725 /* prevent the socket buffers from being compressed */
726 (*so
)->so_rcv
.sb_flags
|= SB_NOCOMPRESS
;
727 (*so
)->so_snd
.sb_flags
|= SB_NOCOMPRESS
;
729 /* Inherit preconnect and TFO data flags */
730 if (mp_so
->so_flags1
& SOF1_PRECONNECT_DATA
)
731 (*so
)->so_flags1
|= SOF1_PRECONNECT_DATA
;
733 if (mp_so
->so_flags1
& SOF1_DATA_IDEMPOTENT
)
734 (*so
)->so_flags1
|= SOF1_DATA_IDEMPOTENT
;
736 bzero(&smpo
, sizeof (smpo
));
737 smpo
.mpo_flags
|= MPOF_SUBFLOW_OK
;
738 smpo
.mpo_level
= SOL_SOCKET
;
741 /* disable SIGPIPE */
742 smpo
.mpo_name
= SO_NOSIGPIPE
;
743 if ((error
= mptcp_subflow_sosetopt(mpte
, *so
, &smpo
)) != 0)
746 /* find out if the subflow's source address goes away */
747 smpo
.mpo_name
= SO_NOADDRERR
;
748 if ((error
= mptcp_subflow_sosetopt(mpte
, *so
, &smpo
)) != 0)
751 /* enable keepalive */
752 smpo
.mpo_name
= SO_KEEPALIVE
;
753 if ((error
= mptcp_subflow_sosetopt(mpte
, *so
, &smpo
)) != 0)
757 * Limit the receive socket buffer size to 64k.
759 * We need to take into consideration the window scale option
760 * which could be negotiated in one subflow but disabled in
762 * XXX This can be improved in the future.
764 smpo
.mpo_name
= SO_RCVBUF
;
765 smpo
.mpo_intval
= MPTCP_RWIN_MAX
;
766 if ((error
= mptcp_subflow_sosetopt(mpte
, *so
, &smpo
)) != 0)
769 /* N.B.: set by sosetopt */
770 VERIFY(!((*so
)->so_rcv
.sb_flags
& SB_AUTOSIZE
));
771 /* Prevent automatic socket buffer sizing. */
772 (*so
)->so_snd
.sb_flags
&= ~SB_AUTOSIZE
;
774 smpo
.mpo_level
= IPPROTO_TCP
;
775 smpo
.mpo_intval
= mptcp_subflow_keeptime
;
776 smpo
.mpo_name
= TCP_KEEPALIVE
;
777 if ((error
= mptcp_subflow_sosetopt(mpte
, *so
, &smpo
)) != 0)
780 /* replay setsockopt(2) on the subflow sockets for eligible options */
781 TAILQ_FOREACH_SAFE(mpo
, &mpte
->mpte_sopts
, mpo_entry
, tmpo
) {
784 if (!(mpo
->mpo_flags
& MPOF_SUBFLOW_OK
))
788 * Skip those that are handled internally; these options
789 * should not have been recorded and marked with the
790 * MPOF_SUBFLOW_OK by mptcp_setopt(), but just in case.
792 if (mpo
->mpo_level
== SOL_SOCKET
&&
793 (mpo
->mpo_name
== SO_NOSIGPIPE
||
794 mpo
->mpo_name
== SO_NOADDRERR
||
795 mpo
->mpo_name
== SO_KEEPALIVE
))
798 interim
= (mpo
->mpo_flags
& MPOF_INTERIM
);
799 if (mptcp_subflow_sosetopt(mpte
, *so
, mpo
) != 0 && interim
) {
801 mptcplog((LOG_ERR
, "MPTCP Socket: subflow socreate"
803 " sopt %s val %d interim record removed\n",
804 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
),
805 mptcp_sopt2str(mpo
->mpo_level
, mpo
->mpo_name
,
806 buf
, sizeof (buf
)), mpo
->mpo_intval
),
807 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_ERR
);
808 mptcp_sopt_remove(mpte
, mpo
);
809 mptcp_sopt_free(mpo
);
815 * We need to receive everything that the subflow socket has,
816 * so use a customized socket receive function. We will undo
817 * this when the socket is peeled off or closed.
819 mpts
->mpts_oprotosw
= (*so
)->so_proto
;
822 (*so
)->so_proto
= &mptcp_subflow_protosw
;
826 (*so
)->so_proto
= (struct protosw
*)&mptcp_subflow_protosw6
;
835 socket_unlock(*so
, 0);
837 DTRACE_MPTCP4(subflow__create
, struct mptses
*, mpte
,
838 struct mptsub
*, mpts
, int, dom
, int, error
);
844 * Close an MPTCP subflow socket.
846 * Note that this may be called on an embryonic subflow, and the only
847 * thing that is guaranteed valid is the protocol-user request.
850 mptcp_subflow_soclose(struct mptsub
*mpts
, struct socket
*so
)
852 MPTS_LOCK_ASSERT_HELD(mpts
);
855 VERIFY(so
->so_flags
& SOF_MP_SUBFLOW
);
856 VERIFY((so
->so_state
& (SS_NBIO
|SS_NOFDREF
)) == (SS_NBIO
|SS_NOFDREF
));
858 /* restore protocol-user requests */
859 VERIFY(mpts
->mpts_oprotosw
!= NULL
);
860 so
->so_proto
= mpts
->mpts_oprotosw
;
861 socket_unlock(so
, 0);
863 mpts
->mpts_socket
= NULL
; /* may already be NULL */
865 DTRACE_MPTCP5(subflow__close
, struct mptsub
*, mpts
,
867 struct sockbuf
*, &so
->so_rcv
,
868 struct sockbuf
*, &so
->so_snd
,
869 struct mptses
*, mpts
->mpts_mpte
);
871 return (soclose(so
));
875 * Connect an MPTCP subflow socket.
877 * This may be called inline as part of adding a subflow, or asynchronously
878 * by the thread (upon progressing to MPTCPF_JOIN_READY). Note that in the
879 * pending connect case, the subflow socket may have been bound to an interface
880 * and/or a source IP address which may no longer be around by the time this
881 * routine is called; in that case the connect attempt will most likely fail.
884 mptcp_subflow_soconnectx(struct mptses
*mpte
, struct mptsub
*mpts
)
889 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
890 MPTS_LOCK_ASSERT_HELD(mpts
);
892 VERIFY((mpts
->mpts_flags
& (MPTSF_CONNECTING
|MPTSF_CONNECTED
)) ==
894 VERIFY(mpts
->mpts_socket
!= NULL
);
895 so
= mpts
->mpts_socket
;
896 af
= mpts
->mpts_family
;
898 if (af
== AF_INET
|| af
== AF_INET6
) {
899 struct sockaddr
*dst
;
900 char dbuf
[MAX_IPv6_STR_LEN
];
902 dst
= mpts
->mpts_dst
;
904 mptcplog((LOG_DEBUG
, "MPTCP Socket: connectx mp_so 0x%llx "
905 "dst %s[%d] cid %d [pended %s]\n",
906 (u_int64_t
)VM_KERNEL_ADDRPERM(mpte
->mpte_mppcb
->mpp_socket
),
907 inet_ntop(af
, ((af
== AF_INET
) ?
908 (void *)&SIN(dst
)->sin_addr
.s_addr
:
909 (void *)&SIN6(dst
)->sin6_addr
),
910 dbuf
, sizeof (dbuf
)), ((af
== AF_INET
) ?
911 ntohs(SIN(dst
)->sin_port
) :
912 ntohs(SIN6(dst
)->sin6_port
)),
914 ((mpts
->mpts_flags
& MPTSF_CONNECT_PENDING
) ?
916 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_LOG
);
919 mpts
->mpts_flags
&= ~MPTSF_CONNECT_PENDING
;
922 mptcp_attach_to_subf(so
, mpte
->mpte_mptcb
, mpte
->mpte_addrid_last
);
924 /* connect the subflow socket */
925 error
= soconnectxlocked(so
, mpts
->mpts_src
, mpts
->mpts_dst
,
926 mpts
->mpts_mpcr
.mpcr_proc
, mpts
->mpts_mpcr
.mpcr_ifscope
,
927 mpte
->mpte_associd
, NULL
, CONNREQF_MPTCP
,
928 &mpts
->mpts_mpcr
, sizeof (mpts
->mpts_mpcr
), NULL
, NULL
);
929 socket_unlock(so
, 0);
931 /* Allocate a unique address id per subflow */
932 mpte
->mpte_addrid_last
++;
933 if (mpte
->mpte_addrid_last
== 0)
934 mpte
->mpte_addrid_last
++;
936 DTRACE_MPTCP3(subflow__connect
, struct mptses
*, mpte
,
937 struct mptsub
*, mpts
, int, error
);
943 * MPTCP subflow socket receive routine, derived from soreceive().
946 mptcp_subflow_soreceive(struct socket
*so
, struct sockaddr
**psa
,
947 struct uio
*uio
, struct mbuf
**mp0
, struct mbuf
**controlp
, int *flagsp
)
950 int flags
, error
= 0;
951 struct proc
*p
= current_proc();
952 struct mbuf
*m
, **mp
= mp0
;
953 struct mbuf
*nextrecord
;
956 VERIFY(so
->so_proto
->pr_flags
& PR_CONNREQUIRED
);
958 #ifdef MORE_LOCKING_DEBUG
959 if (so
->so_usecount
== 1) {
960 panic("%s: so=%x no other reference on socket\n", __func__
, so
);
965 * We return all that is there in the subflow's socket receive buffer
966 * to the MPTCP layer, so we require that the caller passes in the
967 * expected parameters.
969 if (mp
== NULL
|| controlp
!= NULL
) {
970 socket_unlock(so
, 1);
977 flags
= *flagsp
&~ MSG_EOR
;
981 if (flags
& (MSG_PEEK
|MSG_OOB
|MSG_NEEDSA
|MSG_WAITALL
|MSG_WAITSTREAM
)) {
982 socket_unlock(so
, 1);
985 flags
|= (MSG_DONTWAIT
|MSG_NBIO
);
988 * If a recv attempt is made on a previously-accepted socket
989 * that has been marked as inactive (disconnected), reject
992 if (so
->so_flags
& SOF_DEFUNCT
) {
993 struct sockbuf
*sb
= &so
->so_rcv
;
996 SODEFUNCTLOG("%s[%d, %s]: defunct so 0x%llx [%d,%d] (%d)\n",
997 __func__
, proc_pid(p
), proc_best_name(p
),
998 (uint64_t)VM_KERNEL_ADDRPERM(so
),
999 SOCK_DOM(so
), SOCK_TYPE(so
), error
);
1001 * This socket should have been disconnected and flushed
1002 * prior to being returned from sodefunct(); there should
1003 * be no data on its receive list, so panic otherwise.
1005 if (so
->so_state
& SS_DEFUNCT
)
1006 sb_empty_assert(sb
, __func__
);
1007 socket_unlock(so
, 1);
1012 * See if the socket has been closed (SS_NOFDREF|SS_CANTRCVMORE)
1013 * and if so just return to the caller. This could happen when
1014 * soreceive() is called by a socket upcall function during the
1015 * time the socket is freed. The socket buffer would have been
1016 * locked across the upcall, therefore we cannot put this thread
1017 * to sleep (else we will deadlock) or return EWOULDBLOCK (else
1018 * we may livelock), because the lock on the socket buffer will
1019 * only be released when the upcall routine returns to its caller.
1020 * Because the socket has been officially closed, there can be
1021 * no further read on it.
1023 * A multipath subflow socket would have its SS_NOFDREF set by
1024 * default, so check for SOF_MP_SUBFLOW socket flag; when the
1025 * socket is closed for real, SOF_MP_SUBFLOW would be cleared.
1027 if ((so
->so_state
& (SS_NOFDREF
| SS_CANTRCVMORE
)) ==
1028 (SS_NOFDREF
| SS_CANTRCVMORE
) && !(so
->so_flags
& SOF_MP_SUBFLOW
)) {
1029 socket_unlock(so
, 1);
1034 * For consistency with soreceive() semantics, we need to obey
1035 * SB_LOCK in case some other code path has locked the buffer.
1037 error
= sblock(&so
->so_rcv
, 0);
1039 socket_unlock(so
, 1);
1043 m
= so
->so_rcv
.sb_mb
;
1046 * Panic if we notice inconsistencies in the socket's
1047 * receive list; both sb_mb and sb_cc should correctly
1048 * reflect the contents of the list, otherwise we may
1049 * end up with false positives during select() or poll()
1050 * which could put the application in a bad state.
1052 SB_MB_CHECK(&so
->so_rcv
);
1054 if (so
->so_error
!= 0) {
1055 error
= so
->so_error
;
1060 if (so
->so_state
& SS_CANTRCVMORE
) {
1064 if (!(so
->so_state
& (SS_ISCONNECTED
|SS_ISCONNECTING
))) {
1070 * MSG_DONTWAIT is implicitly defined and this routine will
1071 * never block, so return EWOULDBLOCK when there is nothing.
1073 error
= EWOULDBLOCK
;
1077 OSIncrementAtomicLong(&p
->p_stats
->p_ru
.ru_msgrcv
);
1078 SBLASTRECORDCHK(&so
->so_rcv
, "mptcp_subflow_soreceive 1");
1079 SBLASTMBUFCHK(&so
->so_rcv
, "mptcp_subflow_soreceive 1");
1082 nextrecord
= m
->m_nextpkt
;
1083 sbfree(&so
->so_rcv
, m
);
1088 so
->so_rcv
.sb_mb
= m
= m
->m_next
;
1093 m
->m_nextpkt
= nextrecord
;
1094 if (nextrecord
== NULL
)
1095 so
->so_rcv
.sb_lastrecord
= m
;
1097 m
= so
->so_rcv
.sb_mb
= nextrecord
;
1098 SB_EMPTY_FIXUP(&so
->so_rcv
);
1100 SBLASTRECORDCHK(&so
->so_rcv
, "mptcp_subflow_soreceive 2");
1101 SBLASTMBUFCHK(&so
->so_rcv
, "mptcp_subflow_soreceive 2");
1104 DTRACE_MPTCP3(subflow__receive
, struct socket
*, so
,
1105 struct sockbuf
*, &so
->so_rcv
, struct sockbuf
*, &so
->so_snd
);
1106 /* notify protocol that we drained all the data */
1107 if ((so
->so_proto
->pr_flags
& PR_WANTRCVD
) && so
->so_pcb
!= NULL
)
1108 (*so
->so_proto
->pr_usrreqs
->pru_rcvd
)(so
, flags
);
1114 sbunlock(&so
->so_rcv
, FALSE
); /* will unlock socket */
1121 * Prepare an MPTCP subflow socket for peeloff(2); basically undo
1122 * the work done earlier when the subflow socket was created.
1125 mptcp_subflow_sopeeloff(struct mptses
*mpte
, struct mptsub
*mpts
,
1129 struct socket
*mp_so
;
1132 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
1133 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
1134 MPTS_LOCK_ASSERT_HELD(mpts
);
1137 VERIFY(so
->so_flags
& SOF_MP_SUBFLOW
);
1138 VERIFY((so
->so_state
& (SS_NBIO
|SS_NOFDREF
)) == (SS_NBIO
|SS_NOFDREF
));
1140 /* inherit MPTCP socket states */
1141 if (!(mp_so
->so_state
& SS_NBIO
))
1142 so
->so_state
&= ~SS_NBIO
;
1145 * At this point, the socket is not yet closed, as there is at least
1146 * one outstanding usecount previously held by mpts_socket from
1147 * socreate(). Atomically clear SOF_MP_SUBFLOW and SS_NOFDREF here.
1149 so
->so_flags
&= ~SOF_MP_SUBFLOW
;
1150 so
->so_state
&= ~SS_NOFDREF
;
1151 so
->so_flags
&= ~SOF_MPTCP_TRUE
;
1153 /* allow socket buffers to be compressed */
1154 so
->so_rcv
.sb_flags
&= ~SB_NOCOMPRESS
;
1155 so
->so_snd
.sb_flags
&= ~SB_NOCOMPRESS
;
1158 * Allow socket buffer auto sizing.
1160 * This will increase the current 64k buffer size to whatever is best.
1162 if (!(so
->so_rcv
.sb_flags
& SB_USRSIZE
))
1163 so
->so_rcv
.sb_flags
|= SB_AUTOSIZE
;
1164 if (!(so
->so_snd
.sb_flags
& SB_USRSIZE
))
1165 so
->so_snd
.sb_flags
|= SB_AUTOSIZE
;
1167 /* restore protocol-user requests */
1168 VERIFY(mpts
->mpts_oprotosw
!= NULL
);
1169 so
->so_proto
= mpts
->mpts_oprotosw
;
1171 bzero(&smpo
, sizeof (smpo
));
1172 smpo
.mpo_flags
|= MPOF_SUBFLOW_OK
;
1173 smpo
.mpo_level
= SOL_SOCKET
;
1175 /* inherit SOF_NOSIGPIPE from parent MP socket */
1176 p
= (mp_so
->so_flags
& SOF_NOSIGPIPE
);
1177 c
= (so
->so_flags
& SOF_NOSIGPIPE
);
1178 smpo
.mpo_intval
= ((p
- c
) > 0) ? 1 : 0;
1179 smpo
.mpo_name
= SO_NOSIGPIPE
;
1181 (void) mptcp_subflow_sosetopt(mpte
, so
, &smpo
);
1183 /* inherit SOF_NOADDRAVAIL from parent MP socket */
1184 p
= (mp_so
->so_flags
& SOF_NOADDRAVAIL
);
1185 c
= (so
->so_flags
& SOF_NOADDRAVAIL
);
1186 smpo
.mpo_intval
= ((p
- c
) > 0) ? 1 : 0;
1187 smpo
.mpo_name
= SO_NOADDRERR
;
1189 (void) mptcp_subflow_sosetopt(mpte
, so
, &smpo
);
1191 /* inherit SO_KEEPALIVE from parent MP socket */
1192 p
= (mp_so
->so_options
& SO_KEEPALIVE
);
1193 c
= (so
->so_options
& SO_KEEPALIVE
);
1194 smpo
.mpo_intval
= ((p
- c
) > 0) ? 1 : 0;
1195 smpo
.mpo_name
= SO_KEEPALIVE
;
1197 (void) mptcp_subflow_sosetopt(mpte
, so
, &smpo
);
1199 /* unset TCP level default keepalive option */
1200 p
= (intotcpcb(sotoinpcb(mp_so
)))->t_keepidle
;
1201 c
= (intotcpcb(sotoinpcb(so
)))->t_keepidle
;
1202 smpo
.mpo_level
= IPPROTO_TCP
;
1203 smpo
.mpo_intval
= 0;
1204 smpo
.mpo_name
= TCP_KEEPALIVE
;
1206 (void) mptcp_subflow_sosetopt(mpte
, so
, &smpo
);
1207 socket_unlock(so
, 0);
1209 DTRACE_MPTCP5(subflow__peeloff
, struct mptses
*, mpte
,
1210 struct mptsub
*, mpts
, struct socket
*, so
,
1211 struct sockbuf
*, &so
->so_rcv
, struct sockbuf
*, &so
->so_snd
);
1215 * Establish an initial MPTCP connection (if first subflow and not yet
1216 * connected), or add a subflow to an existing MPTCP connection.
1219 mptcp_subflow_add(struct mptses
*mpte
, struct mptsub
*mpts
,
1220 struct proc
*p
, uint32_t ifscope
)
1222 struct socket
*mp_so
, *so
= NULL
;
1223 struct mptsub_connreq mpcr
;
1224 struct mptcb
*mp_tp
;
1227 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
1228 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
1229 mp_tp
= mpte
->mpte_mptcb
;
1232 if (mp_tp
->mpt_state
>= MPTCPS_CLOSE_WAIT
) {
1233 /* If the remote end sends Data FIN, refuse subflow adds */
1241 VERIFY(!(mpts
->mpts_flags
& (MPTSF_CONNECTING
|MPTSF_CONNECTED
)));
1242 VERIFY(mpts
->mpts_mpte
== NULL
);
1243 VERIFY(mpts
->mpts_socket
== NULL
);
1244 VERIFY(mpts
->mpts_dst
!= NULL
);
1245 VERIFY(mpts
->mpts_connid
== SAE_CONNID_ANY
);
1247 af
= mpts
->mpts_family
= mpts
->mpts_dst
->sa_family
;
1250 * If the source address is not specified, allocate a storage for
1251 * it, so that later on we can fill it in with the actual source
1252 * IP address chosen by the underlying layer for the subflow after
1255 if (mpts
->mpts_src
== NULL
) {
1256 int len
= mpts
->mpts_dst
->sa_len
;
1258 MALLOC(mpts
->mpts_src
, struct sockaddr
*, len
, M_SONAME
,
1260 if (mpts
->mpts_src
== NULL
) {
1264 bzero(mpts
->mpts_src
, len
);
1265 mpts
->mpts_src
->sa_len
= len
;
1266 mpts
->mpts_src
->sa_family
= mpts
->mpts_dst
->sa_family
;
1269 /* create the subflow socket */
1270 if ((error
= mptcp_subflow_socreate(mpte
, mpts
, af
, p
, &so
)) != 0)
1274 * Increment the counter, while avoiding 0 (SAE_CONNID_ANY) and
1275 * -1 (SAE_CONNID_ALL).
1277 mpte
->mpte_connid_last
++;
1278 if (mpte
->mpte_connid_last
== SAE_CONNID_ALL
||
1279 mpte
->mpte_connid_last
== SAE_CONNID_ANY
)
1280 mpte
->mpte_connid_last
++;
1282 mpts
->mpts_connid
= mpte
->mpte_connid_last
;
1283 VERIFY(mpts
->mpts_connid
!= SAE_CONNID_ANY
&&
1284 mpts
->mpts_connid
!= SAE_CONNID_ALL
);
1286 mpts
->mpts_rel_seq
= 1;
1288 /* Allocate a unique address id per subflow */
1289 mpte
->mpte_addrid_last
++;
1290 if (mpte
->mpte_addrid_last
== 0)
1291 mpte
->mpte_addrid_last
++;
1293 /* bind subflow socket to the specified interface */
1294 if (ifscope
!= IFSCOPE_NONE
) {
1296 error
= inp_bindif(sotoinpcb(so
), ifscope
, &mpts
->mpts_outif
);
1298 socket_unlock(so
, 0);
1299 (void) mptcp_subflow_soclose(mpts
, so
);
1302 VERIFY(mpts
->mpts_outif
!= NULL
);
1303 mpts
->mpts_flags
|= MPTSF_BOUND_IF
;
1305 if (IFNET_IS_EXPENSIVE(mpts
->mpts_outif
)) {
1306 sototcpcb(so
)->t_mpflags
|= TMPF_BACKUP_PATH
;
1308 mpts
->mpts_flags
|= MPTSF_PREFERRED
;
1311 mptcplog((LOG_DEBUG
, "MPTCP Socket: subflow_add mp_so 0x%llx "
1312 "bindif %s[%d] cid %d expensive %d\n",
1313 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
),
1314 mpts
->mpts_outif
->if_xname
,
1315 ifscope
, mpts
->mpts_connid
,
1316 IFNET_IS_EXPENSIVE(mpts
->mpts_outif
)),
1317 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_VERBOSE
);
1318 socket_unlock(so
, 0);
1321 /* if source address and/or port is specified, bind to it */
1322 if (mpts
->mpts_src
!= NULL
) {
1323 struct sockaddr
*sa
= mpts
->mpts_src
;
1324 uint32_t mpts_flags
= 0;
1329 if (SIN(sa
)->sin_addr
.s_addr
!= INADDR_ANY
)
1330 mpts_flags
|= MPTSF_BOUND_IP
;
1331 if ((lport
= SIN(sa
)->sin_port
) != 0)
1332 mpts_flags
|= MPTSF_BOUND_PORT
;
1336 VERIFY(af
== AF_INET6
);
1337 if (!IN6_IS_ADDR_UNSPECIFIED(&SIN6(sa
)->sin6_addr
))
1338 mpts_flags
|= MPTSF_BOUND_IP
;
1339 if ((lport
= SIN6(sa
)->sin6_port
) != 0)
1340 mpts_flags
|= MPTSF_BOUND_PORT
;
1345 error
= sobindlock(so
, sa
, 1); /* will lock/unlock socket */
1347 (void) mptcp_subflow_soclose(mpts
, so
);
1350 mpts
->mpts_flags
|= mpts_flags
;
1352 if (af
== AF_INET
|| af
== AF_INET6
) {
1353 char sbuf
[MAX_IPv6_STR_LEN
];
1355 mptcplog((LOG_DEBUG
, "MPTCP Socket: subflow_add "
1356 "mp_so 0x%llx bindip %s[%d] cid %d\n",
1357 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
),
1358 inet_ntop(af
, ((af
== AF_INET
) ?
1359 (void *)&SIN(sa
)->sin_addr
.s_addr
:
1360 (void *)&SIN6(sa
)->sin6_addr
), sbuf
, sizeof (sbuf
)),
1361 ntohs(lport
), mpts
->mpts_connid
),
1362 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_LOG
);
1367 * Insert the subflow into the list, and associate the MPTCP PCB
1368 * as well as the the subflow socket. From this point on, removing
1369 * the subflow needs to be done via mptcp_subflow_del().
1371 TAILQ_INSERT_TAIL(&mpte
->mpte_subflows
, mpts
, mpts_entry
);
1372 mpte
->mpte_numflows
++;
1374 atomic_bitset_32(&mpts
->mpts_flags
, MPTSF_ATTACHED
);
1375 mpts
->mpts_mpte
= mpte
;
1376 mpts
->mpts_socket
= so
;
1377 MPTS_ADDREF_LOCKED(mpts
); /* for being in MPTCP subflow list */
1378 MPTS_ADDREF_LOCKED(mpts
); /* for subflow socket */
1379 mp_so
->so_usecount
++; /* for subflow socket */
1381 /* register for subflow socket read/write events */
1382 (void) sock_setupcalls(so
, mptcp_subflow_rupcall
, mpts
,
1383 mptcp_subflow_wupcall
, mpts
);
1386 * Register for subflow socket control events; ignore
1387 * SO_FILT_HINT_CONNINFO_UPDATED from below since we
1388 * will generate it here.
1390 (void) sock_catchevents(so
, mptcp_subflow_eupcall
, mpts
,
1391 SO_FILT_HINT_CONNRESET
| SO_FILT_HINT_CANTRCVMORE
|
1392 SO_FILT_HINT_CANTSENDMORE
| SO_FILT_HINT_TIMEOUT
|
1393 SO_FILT_HINT_NOSRCADDR
| SO_FILT_HINT_IFDENIED
|
1394 SO_FILT_HINT_SUSPEND
| SO_FILT_HINT_RESUME
|
1395 SO_FILT_HINT_CONNECTED
| SO_FILT_HINT_DISCONNECTED
|
1396 SO_FILT_HINT_MPFAILOVER
| SO_FILT_HINT_MPSTATUS
|
1397 SO_FILT_HINT_MUSTRST
| SO_FILT_HINT_MPFASTJ
|
1398 SO_FILT_HINT_DELETEOK
| SO_FILT_HINT_MPCANTRCVMORE
);
1401 VERIFY(!(mpts
->mpts_flags
&
1402 (MPTSF_CONNECTING
|MPTSF_CONNECTED
|MPTSF_CONNECT_PENDING
)));
1404 bzero(&mpcr
, sizeof (mpcr
));
1406 mpcr
.mpcr_ifscope
= ifscope
;
1408 * Indicate to the TCP subflow whether or not it should establish
1409 * the initial MPTCP connection, or join an existing one. Fill
1410 * in the connection request structure with additional info needed
1411 * by the underlying TCP (to be used in the TCP options, etc.)
1414 if (mp_tp
->mpt_state
< MPTCPS_ESTABLISHED
&& mpte
->mpte_numflows
== 1) {
1415 if (mp_tp
->mpt_state
== MPTCPS_CLOSED
) {
1416 mptcp_init_local_parms(mp_tp
);
1419 soisconnecting(mp_so
);
1420 mpcr
.mpcr_type
= MPTSUB_CONNREQ_MP_ENABLE
;
1422 if (!(mp_tp
->mpt_flags
& MPTCPF_JOIN_READY
))
1423 mpts
->mpts_flags
|= MPTSF_CONNECT_PENDING
;
1425 /* avoid starting up cellular subflow unless required */
1426 if ((mptcp_delayed_subf_start
) &&
1427 (IFNET_IS_CELLULAR(mpts
->mpts_outif
))) {
1428 mpts
->mpts_flags
|= MPTSF_CONNECT_PENDING
;
1431 mpcr
.mpcr_type
= MPTSUB_CONNREQ_MP_ADD
;
1434 /* If fastjoin or fastopen is requested, set state in mpts */
1435 if (mpte
->mpte_nummpcapflows
== 0) {
1436 if (so
->so_flags1
& SOF1_PRECONNECT_DATA
) {
1438 if (mp_tp
->mpt_state
< MPTCPS_ESTABLISHED
) {
1439 mpts
->mpts_flags
|= MPTSF_TFO_REQD
;
1440 mpts
->mpts_sndnxt
= mp_tp
->mpt_snduna
;
1445 if (so
->so_flags
& SOF_MPTCP_FASTJOIN
) {
1447 if (mp_tp
->mpt_state
== MPTCPS_ESTABLISHED
) {
1448 mpts
->mpts_flags
|= MPTSF_FASTJ_REQD
;
1449 mpts
->mpts_sndnxt
= mp_tp
->mpt_snduna
;
1455 mpts
->mpts_mpcr
= mpcr
;
1456 mpts
->mpts_flags
|= MPTSF_CONNECTING
;
1458 if (af
== AF_INET
|| af
== AF_INET6
) {
1459 char dbuf
[MAX_IPv6_STR_LEN
];
1461 mptcplog((LOG_DEBUG
, "MPTCP Socket: %s "
1462 "mp_so 0x%llx dst %s[%d] cid %d "
1463 "[pending %s]\n", __func__
,
1464 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
),
1465 inet_ntop(af
, ((af
== AF_INET
) ?
1466 (void *)&SIN(mpts
->mpts_dst
)->sin_addr
.s_addr
:
1467 (void *)&SIN6(mpts
->mpts_dst
)->sin6_addr
),
1468 dbuf
, sizeof (dbuf
)), ((af
== AF_INET
) ?
1469 ntohs(SIN(mpts
->mpts_dst
)->sin_port
) :
1470 ntohs(SIN6(mpts
->mpts_dst
)->sin6_port
)),
1472 ((mpts
->mpts_flags
& MPTSF_CONNECT_PENDING
) ?
1474 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_LOG
);
1477 /* connect right away if first attempt, or if join can be done now */
1478 if (!(mpts
->mpts_flags
& MPTSF_CONNECT_PENDING
))
1479 error
= mptcp_subflow_soconnectx(mpte
, mpts
);
1484 soevent(mp_so
, SO_FILT_HINT_LOCKED
|
1485 SO_FILT_HINT_CONNINFO_UPDATED
);
1491 * Delete/remove a subflow from an MPTCP. The underlying subflow socket
1492 * will no longer be accessible after a subflow is deleted, thus this
1493 * should occur only after the subflow socket has been disconnected.
1494 * If peeloff(2) is called, leave the socket open.
1497 mptcp_subflow_del(struct mptses
*mpte
, struct mptsub
*mpts
, boolean_t close
)
1499 struct socket
*mp_so
, *so
;
1501 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
1502 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
1505 so
= mpts
->mpts_socket
;
1508 if (close
&& !((mpts
->mpts_flags
& MPTSF_DELETEOK
) &&
1509 (mpts
->mpts_flags
& MPTSF_USER_DISCONNECT
))) {
1511 mptcplog((LOG_DEBUG
, "MPTCP Socket: subflow_del returning"
1512 " mp_so 0x%llx flags %x\n",
1513 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
), mpts
->mpts_flags
),
1514 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_LOG
);
1518 mptcplog((LOG_DEBUG
, "MPTCP Socket: subflow_del mp_so 0x%llx "
1519 "[u=%d,r=%d] cid %d [close %s] %d %x error %d\n",
1520 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
),
1522 mp_so
->so_retaincnt
, mpts
->mpts_connid
,
1523 (close
? "YES" : "NO"), mpts
->mpts_soerror
,
1526 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_LOG
);
1528 VERIFY(mpts
->mpts_mpte
== mpte
);
1529 VERIFY(mpts
->mpts_connid
!= SAE_CONNID_ANY
&&
1530 mpts
->mpts_connid
!= SAE_CONNID_ALL
);
1532 VERIFY(mpts
->mpts_flags
& MPTSF_ATTACHED
);
1533 atomic_bitclear_32(&mpts
->mpts_flags
, MPTSF_ATTACHED
);
1534 TAILQ_REMOVE(&mpte
->mpte_subflows
, mpts
, mpts_entry
);
1535 VERIFY(mpte
->mpte_numflows
!= 0);
1536 mpte
->mpte_numflows
--;
1537 if (mpte
->mpte_active_sub
== mpts
)
1538 mpte
->mpte_active_sub
= NULL
;
1541 * Drop references held by this subflow socket; there
1542 * will be no further upcalls made from this point.
1544 (void) sock_setupcalls(so
, NULL
, NULL
, NULL
, NULL
);
1545 (void) sock_catchevents(so
, NULL
, NULL
, 0);
1547 mptcp_detach_mptcb_from_subf(mpte
->mpte_mptcb
, so
);
1550 (void) mptcp_subflow_soclose(mpts
, so
);
1552 VERIFY(mp_so
->so_usecount
> 0);
1553 mp_so
->so_usecount
--; /* for subflow socket */
1554 mpts
->mpts_mpte
= NULL
;
1555 mpts
->mpts_socket
= NULL
;
1558 MPTS_REMREF(mpts
); /* for MPTCP subflow list */
1559 MPTS_REMREF(mpts
); /* for subflow socket */
1561 soevent(mp_so
, SO_FILT_HINT_LOCKED
| SO_FILT_HINT_CONNINFO_UPDATED
);
1565 * Disconnect a subflow socket.
1568 mptcp_subflow_disconnect(struct mptses
*mpte
, struct mptsub
*mpts
,
1572 struct mptcb
*mp_tp
;
1575 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
1576 MPTS_LOCK_ASSERT_HELD(mpts
);
1578 VERIFY(mpts
->mpts_mpte
== mpte
);
1579 VERIFY(mpts
->mpts_socket
!= NULL
);
1580 VERIFY(mpts
->mpts_connid
!= SAE_CONNID_ANY
&&
1581 mpts
->mpts_connid
!= SAE_CONNID_ALL
);
1583 if (mpts
->mpts_flags
& (MPTSF_DISCONNECTING
|MPTSF_DISCONNECTED
))
1586 mpts
->mpts_flags
|= MPTSF_DISCONNECTING
;
1589 * If this is coming from disconnectx(2) or issued as part of
1590 * closing the MPTCP socket, the subflow shouldn't stick around.
1591 * Otherwise let it linger around in case the upper layers need
1592 * to retrieve its conninfo.
1595 mpts
->mpts_flags
|= MPTSF_DELETEOK
;
1597 so
= mpts
->mpts_socket
;
1598 mp_tp
= mpte
->mpte_mptcb
;
1600 if (mp_tp
->mpt_state
> MPTCPS_ESTABLISHED
)
1605 if (!(so
->so_state
& (SS_ISDISCONNECTING
| SS_ISDISCONNECTED
)) &&
1606 (so
->so_state
& SS_ISCONNECTED
)) {
1607 mptcplog((LOG_DEBUG
, "MPTCP Socket %s: cid %d fin %d "
1608 "[linger %s]\n", __func__
, mpts
->mpts_connid
, send_dfin
,
1609 (deleteok
? "NO" : "YES")),
1610 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_LOG
);
1613 mptcp_send_dfin(so
);
1614 (void) soshutdownlock(so
, SHUT_RD
);
1615 (void) soshutdownlock(so
, SHUT_WR
);
1616 (void) sodisconnectlocked(so
);
1618 socket_unlock(so
, 0);
1620 * Generate a disconnect event for this subflow socket, in case
1621 * the lower layer doesn't do it; this is needed because the
1622 * subflow socket deletion relies on it. This will also end up
1623 * generating SO_FILT_HINT_CONNINFO_UPDATED on the MPTCP socket;
1624 * we cannot do that here because subflow lock is currently held.
1626 mptcp_subflow_eupcall(so
, mpts
, SO_FILT_HINT_DISCONNECTED
);
1630 * Subflow socket read upcall.
1632 * Called when the associated subflow socket posted a read event. The subflow
1633 * socket lock has been released prior to invoking the callback. Note that the
1634 * upcall may occur synchronously as a result of MPTCP performing an action on
1635 * it, or asynchronously as a result of an event happening at the subflow layer.
1636 * Therefore, to maintain lock ordering, the only lock that can be acquired
1637 * here is the thread lock, for signalling purposes.
1640 mptcp_subflow_rupcall(struct socket
*so
, void *arg
, int waitf
)
1642 #pragma unused(so, waitf)
1643 struct mptsub
*mpts
= arg
;
1644 struct mptses
*mpte
= mpts
->mpts_mpte
;
1647 * mpte should never be NULL, except in a race with
1653 lck_mtx_lock(&mpte
->mpte_thread_lock
);
1654 mptcp_thread_signal_locked(mpte
);
1655 lck_mtx_unlock(&mpte
->mpte_thread_lock
);
1659 * Subflow socket input.
1661 * Called in the context of the MPTCP thread, for reading data from the
1662 * underlying subflow socket and delivering it to MPTCP.
1665 mptcp_subflow_input(struct mptses
*mpte
, struct mptsub
*mpts
)
1667 struct mbuf
*m
= NULL
;
1670 struct mptsub
*mpts_alt
= NULL
;
1672 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
1673 MPTS_LOCK_ASSERT_HELD(mpts
);
1675 DTRACE_MPTCP2(subflow__input
, struct mptses
*, mpte
,
1676 struct mptsub
*, mpts
);
1678 if (!(mpts
->mpts_flags
& MPTSF_CONNECTED
))
1681 so
= mpts
->mpts_socket
;
1683 error
= sock_receive_internal(so
, NULL
, &m
, 0, NULL
);
1684 if (error
!= 0 && error
!= EWOULDBLOCK
) {
1685 mptcplog((LOG_ERR
, "MPTCP Receiver: %s cid %d error %d\n",
1686 __func__
, mpts
->mpts_connid
, error
),
1687 MPTCP_RECEIVER_DBG
, MPTCP_LOGLVL_ERR
);
1689 mpts_alt
= mptcp_get_subflow(mpte
, mpts
, NULL
);
1690 if (mpts_alt
== NULL
) {
1691 if (mptcp_delayed_subf_start
) {
1692 mpts_alt
= mptcp_get_pending_subflow(mpte
,
1695 mptcplog((LOG_DEBUG
,"MPTCP Receiver:"
1696 " %s: pending %d\n",
1697 __func__
, mpts_alt
->mpts_connid
),
1698 MPTCP_RECEIVER_DBG
, MPTCP_LOGLVL_ERR
);
1700 mptcplog((LOG_ERR
, "MPTCP Receiver:"
1701 " %s: no pending flow for cid %d",
1702 __func__
, mpts
->mpts_connid
),
1703 MPTCP_RECEIVER_DBG
, MPTCP_LOGLVL_ERR
);
1706 mptcplog((LOG_ERR
, "MPTCP Receiver: %s: no alt"
1707 " path for cid %d\n", __func__
,
1709 MPTCP_RECEIVER_DBG
, MPTCP_LOGLVL_ERR
);
1711 if (error
== ENODATA
) {
1713 * Don't ignore ENODATA so as to discover
1714 * nasty middleboxes.
1716 struct socket
*mp_so
=
1717 mpte
->mpte_mppcb
->mpp_socket
;
1718 mp_so
->so_error
= ENODATA
;
1723 } else if (error
== 0) {
1724 mptcplog((LOG_DEBUG
, "MPTCP Receiver: %s: cid %d \n",
1725 __func__
, mpts
->mpts_connid
),
1726 MPTCP_RECEIVER_DBG
, MPTCP_LOGLVL_VERBOSE
);
1729 /* In fallback, make sure to accept data on all but one subflow */
1730 if ((mpts
->mpts_flags
& MPTSF_MP_DEGRADED
) &&
1731 (!(mpts
->mpts_flags
& MPTSF_ACTIVE
))) {
1738 /* Did we receive data on the backup subflow? */
1739 if (!(mpts
->mpts_flags
& MPTSF_ACTIVE
))
1740 mpts
->mpts_peerswitch
++;
1742 mpts
->mpts_peerswitch
= 0;
1745 * Release subflow lock since this may trigger MPTCP to send,
1746 * possibly on a different subflow. An extra reference has
1747 * been held on the subflow by the MPTCP thread before coming
1748 * here, so we can be sure that it won't go away, in the event
1749 * the MP socket lock gets released.
1752 mptcp_input(mpte
, m
);
1758 * Subflow socket write upcall.
1760 * Called when the associated subflow socket posted a read event. The subflow
1761 * socket lock has been released prior to invoking the callback. Note that the
1762 * upcall may occur synchronously as a result of MPTCP performing an action on
1763 * it, or asynchronously as a result of an event happening at the subflow layer.
1764 * Therefore, to maintain lock ordering, the only lock that can be acquired
1765 * here is the thread lock, for signalling purposes.
1768 mptcp_subflow_wupcall(struct socket
*so
, void *arg
, int waitf
)
1770 #pragma unused(so, waitf)
1771 struct mptsub
*mpts
= arg
;
1772 struct mptses
*mpte
= mpts
->mpts_mpte
;
1775 * mpte should never be NULL except in a race with
1776 * mptcp_subflow_del which doesn't hold socket lock across critical
1777 * section. This upcall is made after releasing the socket lock.
1778 * Interleaving of socket operations becomes possible therefore.
1783 lck_mtx_lock(&mpte
->mpte_thread_lock
);
1784 mptcp_thread_signal_locked(mpte
);
1785 lck_mtx_unlock(&mpte
->mpte_thread_lock
);
1789 * Subflow socket output.
1791 * Called for sending data from MPTCP to the underlying subflow socket.
1794 mptcp_subflow_output(struct mptses
*mpte
, struct mptsub
*mpts
)
1796 struct socket
*mp_so
, *so
;
1797 size_t sb_cc
= 0, tot_sent
= 0;
1799 int error
= 0, wakeup
= 0;
1800 u_int64_t mpt_dsn
= 0;
1801 struct mptcb
*mp_tp
= mpte
->mpte_mptcb
;
1802 struct mbuf
*mpt_mbuf
= NULL
;
1804 struct mbuf
*head
, *tail
;
1805 int tcp_zero_len_write
= 0;
1807 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
1808 MPTS_LOCK_ASSERT_HELD(mpts
);
1809 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
1810 so
= mpts
->mpts_socket
;
1812 DTRACE_MPTCP2(subflow__output
, struct mptses
*, mpte
,
1813 struct mptsub
*, mpts
);
1815 /* subflow socket is suspended? */
1816 if (mpts
->mpts_flags
& MPTSF_SUSPENDED
) {
1817 mptcplog((LOG_ERR
, "MPTCP Sender: %s mp_so 0x%llx cid %d is "
1818 "flow controlled\n", __func__
,
1819 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
), mpts
->mpts_connid
),
1820 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_ERR
);
1824 /* subflow socket is not MPTCP capable? */
1825 if (!(mpts
->mpts_flags
& MPTSF_MP_CAPABLE
) &&
1826 !(mpts
->mpts_flags
& MPTSF_MP_DEGRADED
) &&
1827 !(mpts
->mpts_flags
& MPTSF_FASTJ_SEND
) &&
1828 !(mpts
->mpts_flags
& MPTSF_TFO_REQD
)) {
1829 mptcplog((LOG_ERR
, "MPTCP Sender: %s mp_so 0x%llx cid %d not "
1830 "MPTCP capable\n", __func__
,
1831 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
), mpts
->mpts_connid
),
1832 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_ERR
);
1836 /* Remove Addr Option is not sent reliably as per I-D */
1837 if (mpte
->mpte_flags
& MPTE_SND_REM_ADDR
) {
1838 struct tcpcb
*tp
= intotcpcb(sotoinpcb(so
));
1839 tp
->t_rem_aid
= mpte
->mpte_lost_aid
;
1840 if (mptcp_remaddr_enable
)
1841 tp
->t_mpflags
|= TMPF_SND_REM_ADDR
;
1842 mpte
->mpte_flags
&= ~MPTE_SND_REM_ADDR
;
1845 if (mpts
->mpts_flags
& MPTSF_TFO_REQD
) {
1846 mptcp_drop_tfo_data(mpte
, mpts
, &wakeup
);
1850 * The mbuf chains containing the metadata (as well as pointing to
1851 * the user data sitting at the MPTCP output queue) would then be
1852 * sent down to the subflow socket.
1854 * Some notes on data sequencing:
1856 * a. Each mbuf must be a M_PKTHDR.
1857 * b. MPTCP metadata is stored in the mptcp_pktinfo structure
1858 * in the mbuf pkthdr structure.
1859 * c. Each mbuf containing the MPTCP metadata must have its
1860 * pkt_flags marked with the PKTF_MPTCP flag.
1863 /* First, drop acknowledged data */
1864 sb_mb
= mp_so
->so_snd
.sb_mb
;
1865 if (sb_mb
== NULL
) {
1869 VERIFY(sb_mb
->m_pkthdr
.pkt_flags
& PKTF_MPTCP
);
1872 while (mpt_mbuf
&& mpt_mbuf
->m_pkthdr
.mp_rlen
== 0) {
1873 if (((so
->so_state
& SS_ISCONNECTED
) == 0) &&
1874 (mpt_mbuf
->m_next
== NULL
) &&
1875 (so
->so_flags1
& SOF1_PRECONNECT_DATA
)) {
1877 * If TFO, allow connection establishment with zero
1880 tcp_zero_len_write
= 1;
1881 goto zero_len_write
;
1883 mpt_mbuf
= mpt_mbuf
->m_next
;
1885 if (mpt_mbuf
&& (mpt_mbuf
->m_pkthdr
.pkt_flags
& PKTF_MPTCP
)) {
1886 mpt_dsn
= mpt_mbuf
->m_pkthdr
.mp_dsn
;
1892 if (MPTCP_SEQ_LT(mpt_dsn
, mp_tp
->mpt_snduna
)) {
1894 len
= mp_tp
->mpt_snduna
- mpt_dsn
;
1896 sbdrop(&mp_so
->so_snd
, (int)len
);
1902 * In degraded mode, we don't receive data acks, so force free
1903 * mbufs less than snd_nxt
1905 if (mp_so
->so_snd
.sb_mb
== NULL
) {
1910 mpt_dsn
= mp_so
->so_snd
.sb_mb
->m_pkthdr
.mp_dsn
;
1911 if ((mpts
->mpts_flags
& MPTSF_MP_DEGRADED
) &&
1912 (mp_tp
->mpt_flags
& MPTCPF_POST_FALLBACK_SYNC
) &&
1913 MPTCP_SEQ_LT(mpt_dsn
, mp_tp
->mpt_sndnxt
)) {
1915 len
= mp_tp
->mpt_sndnxt
- mpt_dsn
;
1916 sbdrop(&mp_so
->so_snd
, (int)len
);
1918 mp_tp
->mpt_snduna
= mp_tp
->mpt_sndnxt
;
1921 if ((mpts
->mpts_flags
& MPTSF_MP_DEGRADED
) &&
1922 !(mp_tp
->mpt_flags
& MPTCPF_POST_FALLBACK_SYNC
)) {
1923 mp_tp
->mpt_flags
|= MPTCPF_POST_FALLBACK_SYNC
;
1924 so
->so_flags1
|= SOF1_POST_FALLBACK_SYNC
;
1925 if (mp_tp
->mpt_flags
& MPTCPF_RECVD_MPFAIL
)
1926 mpts
->mpts_sndnxt
= mp_tp
->mpt_dsn_at_csum_fail
;
1930 * Adjust the subflow's notion of next byte to send based on
1931 * the last unacknowledged byte
1933 if (MPTCP_SEQ_LT(mpts
->mpts_sndnxt
, mp_tp
->mpt_snduna
)) {
1934 mpts
->mpts_sndnxt
= mp_tp
->mpt_snduna
;
1938 * Adjust the top level notion of next byte used for retransmissions
1941 if (MPTCP_SEQ_LT(mp_tp
->mpt_sndnxt
, mp_tp
->mpt_snduna
)) {
1942 mp_tp
->mpt_sndnxt
= mp_tp
->mpt_snduna
;
1946 /* Now determine the offset from which to start transmitting data */
1947 sb_mb
= mp_so
->so_snd
.sb_mb
;
1948 sb_cc
= mp_so
->so_snd
.sb_cc
;
1949 if (sb_mb
== NULL
) {
1953 if (MPTCP_SEQ_LT(mpts
->mpts_sndnxt
, mp_tp
->mpt_sndmax
)) {
1954 off
= mpts
->mpts_sndnxt
- mp_tp
->mpt_snduna
;
1955 sb_cc
-= (size_t)off
;
1964 while (mpt_mbuf
&& ((mpt_mbuf
->m_pkthdr
.mp_rlen
== 0) ||
1965 (mpt_mbuf
->m_pkthdr
.mp_rlen
<= (u_int32_t
)off
))) {
1966 off
-= mpt_mbuf
->m_pkthdr
.mp_rlen
;
1967 mpt_mbuf
= mpt_mbuf
->m_next
;
1969 if (mpts
->mpts_flags
& MPTSF_MP_DEGRADED
)
1970 mptcplog((LOG_DEBUG
, "MPTCP Sender: %s cid = %d "
1971 "snduna = %llu sndnxt = %llu probe %d\n",
1972 __func__
, mpts
->mpts_connid
,
1973 mp_tp
->mpt_snduna
, mpts
->mpts_sndnxt
,
1974 mpts
->mpts_probecnt
),
1975 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_LOG
);
1977 VERIFY((mpt_mbuf
== NULL
) || (mpt_mbuf
->m_pkthdr
.pkt_flags
& PKTF_MPTCP
));
1981 while (tot_sent
< sb_cc
) {
1985 mlen
= mpt_mbuf
->m_pkthdr
.mp_rlen
;
1991 panic("%s: unexpected %lu %lu \n", __func__
,
1995 m
= m_copym_mode(mpt_mbuf
, (int)off
, mlen
, M_DONTWAIT
,
1996 M_COPYM_MUST_COPY_HDR
);
2002 /* Create a DSN mapping for the data (m_copym does it) */
2003 mpt_dsn
= mpt_mbuf
->m_pkthdr
.mp_dsn
;
2004 VERIFY(m
->m_flags
& M_PKTHDR
);
2005 m
->m_pkthdr
.pkt_flags
|= PKTF_MPTCP
;
2006 m
->m_pkthdr
.pkt_flags
&= ~PKTF_MPSO
;
2007 m
->m_pkthdr
.mp_dsn
= mpt_dsn
+ off
;
2008 m
->m_pkthdr
.mp_rseq
= mpts
->mpts_rel_seq
;
2009 m
->m_pkthdr
.mp_rlen
= mlen
;
2010 mpts
->mpts_rel_seq
+= mlen
;
2011 m
->m_pkthdr
.len
= mlen
;
2022 mpt_mbuf
= mpt_mbuf
->m_next
;
2026 struct tcpcb
*tp
= intotcpcb(sotoinpcb(so
));
2028 if ((mpts
->mpts_flags
& MPTSF_TFO_REQD
) &&
2029 (tp
->t_tfo_stats
== 0)) {
2030 tp
->t_mpflags
|= TMPF_TFO_REQUEST
;
2031 } else if (mpts
->mpts_flags
& MPTSF_FASTJ_SEND
) {
2032 tp
->t_mpflags
|= TMPF_FASTJOIN_SEND
;
2035 error
= sock_sendmbuf(so
, NULL
, head
, 0, NULL
);
2037 DTRACE_MPTCP7(send
, struct mbuf
*, head
, struct socket
*, so
,
2038 struct sockbuf
*, &so
->so_rcv
,
2039 struct sockbuf
*, &so
->so_snd
,
2040 struct mptses
*, mpte
, struct mptsub
*, mpts
,
2042 } else if (tcp_zero_len_write
== 1) {
2045 /* Opting to call pru_send as no mbuf at subflow level */
2046 error
= (*so
->so_proto
->pr_usrreqs
->pru_send
)
2047 (so
, 0, NULL
, NULL
, NULL
, current_proc());
2048 socket_unlock(so
, 1);
2051 if ((error
== 0) || (error
== EWOULDBLOCK
)) {
2052 mpts
->mpts_sndnxt
+= tot_sent
;
2054 if (mpts
->mpts_probesoon
&& mpts
->mpts_maxseg
&& tot_sent
) {
2055 tcpstat
.tcps_mp_num_probes
++;
2056 if (tot_sent
< mpts
->mpts_maxseg
)
2057 mpts
->mpts_probecnt
+= 1;
2059 mpts
->mpts_probecnt
+=
2060 tot_sent
/mpts
->mpts_maxseg
;
2065 if (MPTCP_SEQ_LT(mp_tp
->mpt_sndnxt
, mpts
->mpts_sndnxt
)) {
2066 if (MPTCP_DATASEQ_HIGH32(mpts
->mpts_sndnxt
) >
2067 MPTCP_DATASEQ_HIGH32(mp_tp
->mpt_sndnxt
))
2068 mp_tp
->mpt_flags
|= MPTCPF_SND_64BITDSN
;
2069 mp_tp
->mpt_sndnxt
= mpts
->mpts_sndnxt
;
2071 mptcp_cancel_timer(mp_tp
, MPTT_REXMT
);
2074 if (so
->so_flags1
& SOF1_PRECONNECT_DATA
)
2075 so
->so_flags1
&= ~SOF1_PRECONNECT_DATA
;
2077 /* Send once in SYN_SENT state to avoid sending SYN spam */
2078 if (mpts
->mpts_flags
& MPTSF_FASTJ_SEND
) {
2079 so
->so_flags
&= ~SOF_MPTCP_FASTJOIN
;
2080 mpts
->mpts_flags
&= ~MPTSF_FASTJ_SEND
;
2083 if ((mpts
->mpts_flags
& MPTSF_MP_DEGRADED
) ||
2084 (mpts
->mpts_probesoon
!= 0))
2085 mptcplog((LOG_DEBUG
, "MPTCP Sender: %s cid %d "
2086 "wrote %d %d probe %d probedelta %d\n",
2087 __func__
, mpts
->mpts_connid
, (int)tot_sent
,
2088 (int) sb_cc
, mpts
->mpts_probecnt
,
2089 (tcp_now
- mpts
->mpts_probesoon
)),
2090 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_LOG
);
2092 mptcplog((LOG_ERR
, "MPTCP Sender: %s cid %d error %d len %zd\n",
2093 __func__
, mpts
->mpts_connid
, error
, tot_sent
),
2094 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_ERR
);
2104 * Subflow socket control event upcall.
2106 * Called when the associated subflow socket posted one or more control events.
2107 * The subflow socket lock has been released prior to invoking the callback.
2108 * Note that the upcall may occur synchronously as a result of MPTCP performing
2109 * an action on it, or asynchronously as a result of an event happening at the
2110 * subflow layer. Therefore, to maintain lock ordering, the only lock that can
2111 * be acquired here is the thread lock, for signalling purposes.
2114 mptcp_subflow_eupcall(struct socket
*so
, void *arg
, uint32_t events
)
2117 struct mptsub
*mpts
= arg
;
2118 struct mptses
*mpte
= mpts
->mpts_mpte
;
2120 VERIFY(mpte
!= NULL
);
2122 lck_mtx_lock(&mpte
->mpte_thread_lock
);
2123 atomic_bitset_32(&mpts
->mpts_evctl
, events
);
2124 mptcp_thread_signal_locked(mpte
);
2125 lck_mtx_unlock(&mpte
->mpte_thread_lock
);
2129 * Subflow socket control events.
2131 * Called for handling events related to the underlying subflow socket.
2134 mptcp_subflow_events(struct mptses
*mpte
, struct mptsub
*mpts
,
2135 uint64_t *p_mpsofilt_hint
)
2137 uint32_t events
, save_events
;
2138 ev_ret_t ret
= MPTS_EVRET_OK
;
2140 int mpsub_ev_entry_count
= sizeof(mpsub_ev_entry_tbl
)/
2141 sizeof(mpsub_ev_entry_tbl
[0]);
2142 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
2143 MPTS_LOCK_ASSERT_HELD(mpts
);
2145 /* bail if there's nothing to process */
2146 if ((events
= mpts
->mpts_evctl
) == 0)
2149 if (events
& (SO_FILT_HINT_CONNRESET
|SO_FILT_HINT_MUSTRST
|
2150 SO_FILT_HINT_CANTRCVMORE
|SO_FILT_HINT_CANTSENDMORE
|
2151 SO_FILT_HINT_TIMEOUT
|SO_FILT_HINT_NOSRCADDR
|
2152 SO_FILT_HINT_IFDENIED
|SO_FILT_HINT_SUSPEND
|
2153 SO_FILT_HINT_DISCONNECTED
)) {
2154 events
|= SO_FILT_HINT_MPFAILOVER
;
2157 save_events
= events
;
2159 DTRACE_MPTCP3(subflow__events
, struct mptses
*, mpte
,
2160 struct mptsub
*, mpts
, uint32_t, events
);
2162 mptcplog((LOG_DEBUG
, "MPTCP Events: %s cid %d events=%b\n", __func__
,
2163 mpts
->mpts_connid
, events
, SO_FILT_HINT_BITS
),
2164 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_VERBOSE
);
2167 * Process all the socket filter hints and reset the hint
2168 * once it is handled
2170 for (i
= 0; (i
< mpsub_ev_entry_count
) && events
; i
++) {
2172 * Always execute the DISCONNECTED event, because it will wakeup
2175 if ((events
& mpsub_ev_entry_tbl
[i
].sofilt_hint_mask
) &&
2176 (ret
>= MPTS_EVRET_OK
||
2177 mpsub_ev_entry_tbl
[i
].sofilt_hint_mask
== SO_FILT_HINT_DISCONNECTED
)) {
2179 mpsub_ev_entry_tbl
[i
].sofilt_hint_ev_hdlr(mpte
, mpts
, p_mpsofilt_hint
);
2180 events
&= ~mpsub_ev_entry_tbl
[i
].sofilt_hint_mask
;
2181 ret
= ((error
>= MPTS_EVRET_OK
) ? MAX(error
, ret
) : error
);
2186 * We should be getting only events specified via sock_catchevents(),
2187 * so loudly complain if we have any unprocessed one(s).
2189 if (events
!= 0 || ret
< MPTS_EVRET_OK
) {
2190 mptcplog((LOG_ERR
, "MPTCP Events %s%s: cid %d evret %s (%d)"
2191 " unhandled events=%b\n",
2192 (events
!= 0) && (ret
== MPTS_EVRET_OK
) ? "MPTCP_ERROR " : "",
2193 __func__
, mpts
->mpts_connid
,
2194 mptcp_evret2str(ret
), ret
, events
, SO_FILT_HINT_BITS
),
2195 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_ERR
);
2198 /* clear the ones we've processed */
2199 atomic_bitclear_32(&mpts
->mpts_evctl
, save_events
);
2204 * Handle SO_FILT_HINT_CONNRESET subflow socket event.
2207 mptcp_subflow_connreset_ev(struct mptses
*mpte
, struct mptsub
*mpts
,
2208 uint64_t *p_mpsofilt_hint
)
2210 struct socket
*mp_so
, *so
;
2211 struct mptcb
*mp_tp
;
2214 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
2215 MPTS_LOCK_ASSERT_HELD(mpts
);
2216 VERIFY(mpte
->mpte_mppcb
!= NULL
);
2217 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
2218 mp_tp
= mpte
->mpte_mptcb
;
2219 so
= mpts
->mpts_socket
;
2221 linger
= (!(mpts
->mpts_flags
& MPTSF_DELETEOK
) &&
2222 !(mp_so
->so_flags
& SOF_PCBCLEARING
));
2224 mptcplog((LOG_DEBUG
, "MPTCP Events: "
2225 "%s: cid %d [linger %s]\n", __func__
,
2226 mpts
->mpts_connid
, (linger
? "YES" : "NO")),
2227 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
2230 * We got a TCP RST for this subflow connection.
2232 * Right now, we simply propagate ECONNREFUSED to the MPTCP socket
2233 * client if the MPTCP connection has not been established or
2234 * if the connection has only one subflow and is a connection being
2235 * resumed. Otherwise we close the socket.
2237 mptcp_subflow_disconnect(mpte
, mpts
, !linger
);
2240 if (mp_tp
->mpt_state
< MPTCPS_ESTABLISHED
) {
2241 mpts
->mpts_soerror
= mp_so
->so_error
= ECONNREFUSED
;
2242 } else if (mpte
->mpte_nummpcapflows
< 1 ||
2243 ((mp_tp
->mpt_flags
& MPTCPF_FALLBACK_TO_TCP
) &&
2244 (mpts
->mpts_flags
& MPTSF_ACTIVE
))) {
2245 mpts
->mpts_soerror
= mp_so
->so_error
= ECONNRESET
;
2246 *p_mpsofilt_hint
|= SO_FILT_HINT_LOCKED
| SO_FILT_HINT_CONNRESET
;
2251 * Keep the subflow socket around, unless the MPTCP socket has
2252 * been detached or the subflow has been disconnected explicitly,
2253 * in which case it should be deleted right away.
2255 return (linger
? MPTS_EVRET_OK
: MPTS_EVRET_DELETE
);
2259 * Handle SO_FILT_HINT_CANTRCVMORE subflow socket event.
2262 mptcp_subflow_cantrcvmore_ev(struct mptses
*mpte
, struct mptsub
*mpts
,
2263 uint64_t *p_mpsofilt_hint
)
2265 struct mptcb
*mp_tp
;
2268 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
2269 MPTS_LOCK_ASSERT_HELD(mpts
);
2271 mp_tp
= mpte
->mpte_mptcb
;
2272 so
= mpts
->mpts_socket
;
2274 mptcplog((LOG_DEBUG
, "MPTCP Events: "
2275 "%s: cid %d\n", __func__
, mpts
->mpts_connid
),
2276 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
2279 * A FIN on a fallen back MPTCP-connection should be treated like a
2283 if ((mp_tp
->mpt_flags
& MPTCPF_FALLBACK_TO_TCP
) &&
2284 (mpts
->mpts_flags
& MPTSF_ACTIVE
)) {
2285 mptcp_close_fsm(mp_tp
, MPCE_RECV_DATA_FIN
);
2286 if (mp_tp
->mpt_state
== MPTCPS_CLOSE_WAIT
) {
2287 *p_mpsofilt_hint
|= SO_FILT_HINT_LOCKED
| SO_FILT_HINT_CANTRCVMORE
;
2292 return (MPTS_EVRET_OK
); /* keep the subflow socket around */
2296 * Handle SO_FILT_HINT_CANTSENDMORE subflow socket event.
2299 mptcp_subflow_cantsendmore_ev(struct mptses
*mpte
, struct mptsub
*mpts
,
2300 uint64_t *p_mpsofilt_hint
)
2302 #pragma unused(p_mpsofilt_hint)
2305 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
2306 MPTS_LOCK_ASSERT_HELD(mpts
);
2308 so
= mpts
->mpts_socket
;
2310 mptcplog((LOG_DEBUG
, "MPTCP Events: "
2311 "%s: cid %d\n", __func__
, mpts
->mpts_connid
),
2312 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
2314 return (MPTS_EVRET_OK
); /* keep the subflow socket around */
2318 * Handle SO_FILT_HINT_TIMEOUT subflow socket event.
2321 mptcp_subflow_timeout_ev(struct mptses
*mpte
, struct mptsub
*mpts
,
2322 uint64_t *p_mpsofilt_hint
)
2324 #pragma unused(p_mpsofilt_hint)
2325 struct socket
*mp_so
, *so
;
2326 struct mptcb
*mp_tp
;
2329 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
2330 MPTS_LOCK_ASSERT_HELD(mpts
);
2331 VERIFY(mpte
->mpte_mppcb
!= NULL
);
2332 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
2333 mp_tp
= mpte
->mpte_mptcb
;
2334 so
= mpts
->mpts_socket
;
2336 linger
= (!(mpts
->mpts_flags
& MPTSF_DELETEOK
) &&
2337 !(mp_so
->so_flags
& SOF_PCBCLEARING
));
2339 mptcplog((LOG_NOTICE
, "MPTCP Events: "
2340 "%s: cid %d [linger %s]\n", __func__
,
2341 mpts
->mpts_connid
, (linger
? "YES" : "NO")),
2342 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
2344 if (mpts
->mpts_soerror
== 0)
2345 mpts
->mpts_soerror
= ETIMEDOUT
;
2348 * The subflow connection has timed out.
2350 * Right now, we simply propagate ETIMEDOUT to the MPTCP socket
2351 * client if the MPTCP connection has not been established. Otherwise
2354 mptcp_subflow_disconnect(mpte
, mpts
, !linger
);
2357 if (mp_tp
->mpt_state
< MPTCPS_ESTABLISHED
) {
2358 mp_so
->so_error
= ETIMEDOUT
;
2363 * Keep the subflow socket around, unless the MPTCP socket has
2364 * been detached or the subflow has been disconnected explicitly,
2365 * in which case it should be deleted right away.
2367 return (linger
? MPTS_EVRET_OK
: MPTS_EVRET_DELETE
);
2371 * Handle SO_FILT_HINT_NOSRCADDR subflow socket event.
2374 mptcp_subflow_nosrcaddr_ev(struct mptses
*mpte
, struct mptsub
*mpts
,
2375 uint64_t *p_mpsofilt_hint
)
2377 #pragma unused(p_mpsofilt_hint)
2378 struct socket
*mp_so
, *so
;
2379 struct mptcb
*mp_tp
;
2381 struct tcpcb
*tp
= NULL
;
2383 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
2384 MPTS_LOCK_ASSERT_HELD(mpts
);
2386 VERIFY(mpte
->mpte_mppcb
!= NULL
);
2387 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
2388 mp_tp
= mpte
->mpte_mptcb
;
2389 so
= mpts
->mpts_socket
;
2391 /* Not grabbing socket lock as t_local_aid is write once only */
2392 tp
= intotcpcb(sotoinpcb(so
));
2394 * This overwrites any previous mpte_lost_aid to avoid storing
2395 * too much state when the typical case has only two subflows.
2397 mpte
->mpte_flags
|= MPTE_SND_REM_ADDR
;
2398 mpte
->mpte_lost_aid
= tp
->t_local_aid
;
2400 linger
= (!(mpts
->mpts_flags
& MPTSF_DELETEOK
) &&
2401 !(mp_so
->so_flags
& SOF_PCBCLEARING
));
2403 mptcplog((LOG_DEBUG
, "MPTCP Events: "
2404 "%s cid %d [linger %s]\n", __func__
,
2405 mpts
->mpts_connid
, (linger
? "YES" : "NO")),
2406 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
2408 if (mpts
->mpts_soerror
== 0)
2409 mpts
->mpts_soerror
= EADDRNOTAVAIL
;
2412 * The subflow connection has lost its source address.
2414 * Right now, we simply propagate EADDRNOTAVAIL to the MPTCP socket
2415 * client if the MPTCP connection has not been established. If it
2416 * has been established with one subflow , we keep the MPTCP
2417 * connection valid without any subflows till closed by application.
2418 * This lets tcp connection manager decide whether to close this or
2419 * not as it reacts to reachability changes too.
2421 mptcp_subflow_disconnect(mpte
, mpts
, !linger
);
2424 if ((mp_tp
->mpt_state
< MPTCPS_ESTABLISHED
) &&
2425 (mp_so
->so_flags
& SOF_NOADDRAVAIL
)) {
2426 mp_so
->so_error
= EADDRNOTAVAIL
;
2431 * Keep the subflow socket around, unless the MPTCP socket has
2432 * been detached or the subflow has been disconnected explicitly,
2433 * in which case it should be deleted right away.
2435 return (linger
? MPTS_EVRET_OK
: MPTS_EVRET_DELETE
);
2439 * Handle SO_FILT_HINT_MPCANTRCVMORE subflow socket event that
2440 * indicates that the remote side sent a Data FIN
2443 mptcp_subflow_mpcantrcvmore_ev(struct mptses
*mpte
, struct mptsub
*mpts
,
2444 uint64_t *p_mpsofilt_hint
)
2446 struct socket
*so
, *mp_so
;
2447 struct mptcb
*mp_tp
;
2449 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
2450 MPTS_LOCK_ASSERT_HELD(mpts
);
2451 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
2452 so
= mpts
->mpts_socket
;
2453 mp_tp
= mpte
->mpte_mptcb
;
2455 mptcplog((LOG_DEBUG
, "MPTCP Events: "
2456 "%s: cid %d\n", __func__
, mpts
->mpts_connid
),
2457 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
2460 * We got a Data FIN for the MPTCP connection.
2461 * The FIN may arrive with data. The data is handed up to the
2462 * mptcp socket and the user is notified so that it may close
2463 * the socket if needed.
2466 if (mp_tp
->mpt_state
== MPTCPS_CLOSE_WAIT
)
2467 *p_mpsofilt_hint
|= SO_FILT_HINT_LOCKED
| SO_FILT_HINT_CANTRCVMORE
;
2470 return (MPTS_EVRET_OK
); /* keep the subflow socket around */
2474 * Handle SO_FILT_HINT_MPFAILOVER subflow socket event
2477 mptcp_subflow_failover_ev(struct mptses
*mpte
, struct mptsub
*mpts
,
2478 uint64_t *p_mpsofilt_hint
)
2480 struct mptsub
*mpts_alt
= NULL
;
2481 struct socket
*so
= NULL
;
2482 struct socket
*mp_so
;
2483 int altpath_exists
= 0;
2485 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
2486 MPTS_LOCK_ASSERT_HELD(mpts
);
2487 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
2488 mptcplog((LOG_NOTICE
, "MPTCP Events: "
2489 "%s: mp_so 0x%llx\n", __func__
,
2490 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
)),
2491 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
2494 mpts_alt
= mptcp_get_subflow(mpte
, mpts
, NULL
);
2497 * If there is no alternate eligible subflow, ignore the
2500 if (mpts_alt
== NULL
) {
2501 mptcplog((LOG_WARNING
, "MPTCP Events: "
2502 "%s: no alternate path\n", __func__
),
2503 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_ERR
);
2505 if (mptcp_delayed_subf_start
) {
2506 mpts_alt
= mptcp_get_pending_subflow(mpte
, mpts
);
2507 if (mpts_alt
!= NULL
) {
2508 MPTS_LOCK(mpts_alt
);
2509 (void) mptcp_subflow_soconnectx(mpte
,
2511 MPTS_UNLOCK(mpts_alt
);
2517 MPTS_LOCK(mpts_alt
);
2519 so
= mpts_alt
->mpts_socket
;
2520 if (mpts_alt
->mpts_flags
& MPTSF_FAILINGOVER
) {
2522 /* All data acknowledged and no RTT spike */
2523 if ((so
->so_snd
.sb_cc
== 0) &&
2524 (mptcp_no_rto_spike(so
))) {
2525 so
->so_flags
&= ~SOF_MP_TRYFAILOVER
;
2526 mpts_alt
->mpts_flags
&= ~MPTSF_FAILINGOVER
;
2528 /* no alternate path available */
2531 socket_unlock(so
, 1);
2533 if (altpath_exists
) {
2534 mptcplog((LOG_INFO
, "MPTCP Events: "
2536 __func__
, mpts_alt
->mpts_connid
),
2537 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
2538 mpts_alt
->mpts_flags
|= MPTSF_ACTIVE
;
2539 mpts_alt
->mpts_peerswitch
= 0;
2540 struct mptcb
*mp_tp
= mpte
->mpte_mptcb
;
2541 /* Bring the subflow's notion of snd_nxt into the send window */
2543 mpts_alt
->mpts_sndnxt
= mp_tp
->mpt_snduna
;
2545 mpte
->mpte_active_sub
= mpts_alt
;
2548 socket_unlock(so
, 1);
2550 MPTS_UNLOCK(mpts_alt
);
2552 if (altpath_exists
) {
2553 *p_mpsofilt_hint
|= SO_FILT_HINT_LOCKED
| SO_FILT_HINT_CONNINFO_UPDATED
;
2554 mptcplog((LOG_NOTICE
, "MPTCP Events: "
2555 "%s: mp_so 0x%llx switched from "
2556 "%d to %d\n", __func__
,
2557 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
),
2558 mpts
->mpts_connid
, mpts_alt
->mpts_connid
),
2559 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
2560 tcpstat
.tcps_mp_switches
++;
2564 if (altpath_exists
) {
2565 mpts
->mpts_flags
|= MPTSF_FAILINGOVER
;
2566 mpts
->mpts_flags
&= ~MPTSF_ACTIVE
;
2568 mptcplog((LOG_DEBUG
, "MPTCP Events %s: no alt cid = %d\n",
2569 __func__
, mpts
->mpts_connid
),
2570 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
2572 so
= mpts
->mpts_socket
;
2574 so
->so_flags
&= ~SOF_MP_TRYFAILOVER
;
2575 socket_unlock(so
, 1);
2577 MPTS_LOCK_ASSERT_HELD(mpts
);
2578 return (MPTS_EVRET_OK
);
2582 * Handle SO_FILT_HINT_IFDENIED subflow socket event.
2585 mptcp_subflow_ifdenied_ev(struct mptses
*mpte
, struct mptsub
*mpts
,
2586 uint64_t *p_mpsofilt_hint
)
2588 struct socket
*mp_so
, *so
;
2589 struct mptcb
*mp_tp
;
2592 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
2593 MPTS_LOCK_ASSERT_HELD(mpts
);
2594 VERIFY(mpte
->mpte_mppcb
!= NULL
);
2595 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
2596 mp_tp
= mpte
->mpte_mptcb
;
2597 so
= mpts
->mpts_socket
;
2599 linger
= (!(mpts
->mpts_flags
& MPTSF_DELETEOK
) &&
2600 !(mp_so
->so_flags
& SOF_PCBCLEARING
));
2602 mptcplog((LOG_DEBUG
, "MPTCP Events: "
2603 "%s: cid %d [linger %s]\n", __func__
,
2604 mpts
->mpts_connid
, (linger
? "YES" : "NO")),
2605 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
2607 if (mpts
->mpts_soerror
== 0)
2608 mpts
->mpts_soerror
= EHOSTUNREACH
;
2611 * The subflow connection cannot use the outgoing interface.
2613 * Right now, we simply propagate EHOSTUNREACH to the MPTCP socket
2614 * client if the MPTCP connection has not been established. If it
2615 * has been established, let the upper layer call disconnectx.
2617 mptcp_subflow_disconnect(mpte
, mpts
, !linger
);
2618 *p_mpsofilt_hint
|= SO_FILT_HINT_LOCKED
| SO_FILT_HINT_IFDENIED
;
2621 if (mp_tp
->mpt_state
< MPTCPS_ESTABLISHED
) {
2622 mp_so
->so_error
= EHOSTUNREACH
;
2627 * Keep the subflow socket around, unless the MPTCP socket has
2628 * been detached or the subflow has been disconnected explicitly,
2629 * in which case it should be deleted right away.
2631 return (linger
? MPTS_EVRET_OK
: MPTS_EVRET_DELETE
);
2635 * Handle SO_FILT_HINT_SUSPEND subflow socket event.
2638 mptcp_subflow_suspend_ev(struct mptses
*mpte
, struct mptsub
*mpts
,
2639 uint64_t *p_mpsofilt_hint
)
2641 #pragma unused(p_mpsofilt_hint)
2644 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
2645 MPTS_LOCK_ASSERT_HELD(mpts
);
2647 so
= mpts
->mpts_socket
;
2649 /* the subflow connection is being flow controlled */
2650 mpts
->mpts_flags
|= MPTSF_SUSPENDED
;
2652 mptcplog((LOG_DEBUG
, "MPTCP Events: "
2653 "%s: cid %d\n", __func__
,
2654 mpts
->mpts_connid
), MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
2656 return (MPTS_EVRET_OK
); /* keep the subflow socket around */
2660 * Handle SO_FILT_HINT_RESUME subflow socket event.
2663 mptcp_subflow_resume_ev(struct mptses
*mpte
, struct mptsub
*mpts
,
2664 uint64_t *p_mpsofilt_hint
)
2666 #pragma unused(p_mpsofilt_hint)
2669 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
2670 MPTS_LOCK_ASSERT_HELD(mpts
);
2672 so
= mpts
->mpts_socket
;
2674 /* the subflow connection is no longer flow controlled */
2675 mpts
->mpts_flags
&= ~MPTSF_SUSPENDED
;
2677 mptcplog((LOG_DEBUG
, "MPTCP Events: "
2678 "%s: cid %d\n", __func__
, mpts
->mpts_connid
),
2679 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
2681 return (MPTS_EVRET_OK
); /* keep the subflow socket around */
2685 * Handle SO_FILT_HINT_CONNECTED subflow socket event.
2688 mptcp_subflow_connected_ev(struct mptses
*mpte
, struct mptsub
*mpts
,
2689 uint64_t *p_mpsofilt_hint
)
2691 char buf0
[MAX_IPv6_STR_LEN
], buf1
[MAX_IPv6_STR_LEN
];
2692 struct sockaddr_storage src
;
2693 struct socket
*mp_so
, *so
;
2694 struct mptcb
*mp_tp
;
2695 struct ifnet
*outifp
;
2697 boolean_t mpok
= FALSE
;
2698 boolean_t cell
= FALSE
;
2699 boolean_t wifi
= FALSE
;
2700 boolean_t wired
= FALSE
;
2702 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
2703 VERIFY(mpte
->mpte_mppcb
!= NULL
);
2704 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
2705 mp_tp
= mpte
->mpte_mptcb
;
2707 MPTS_LOCK_ASSERT_HELD(mpts
);
2708 so
= mpts
->mpts_socket
;
2709 af
= mpts
->mpts_family
;
2711 if (mpts
->mpts_flags
& MPTSF_CONNECTED
)
2712 return (MPTS_EVRET_OK
);
2714 if ((mpts
->mpts_flags
& MPTSF_DISCONNECTED
) ||
2715 (mpts
->mpts_flags
& MPTSF_DISCONNECTING
)) {
2717 if (!(so
->so_state
& (SS_ISDISCONNECTING
| SS_ISDISCONNECTED
)) &&
2718 (so
->so_state
& SS_ISCONNECTED
)) {
2719 mptcplog((LOG_DEBUG
, "MPTCP Events: "
2720 "%s: cid %d disconnect before tcp connect\n",
2721 __func__
, mpts
->mpts_connid
),
2722 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
2723 (void) soshutdownlock(so
, SHUT_RD
);
2724 (void) soshutdownlock(so
, SHUT_WR
);
2725 (void) sodisconnectlocked(so
);
2727 socket_unlock(so
, 0);
2728 return (MPTS_EVRET_OK
);
2732 * The subflow connection has been connected. Find out whether it
2733 * is connected as a regular TCP or as a MPTCP subflow. The idea is:
2735 * a. If MPTCP connection is not yet established, then this must be
2736 * the first subflow connection. If MPTCP failed to negotiate,
2737 * indicate to the MPTCP socket client via EPROTO, that the
2738 * underlying TCP connection may be peeled off via peeloff(2).
2739 * Otherwise, mark the MPTCP socket as connected.
2741 * b. If MPTCP connection has been established, then this must be
2742 * one of the subsequent subflow connections. If MPTCP failed
2743 * to negotiate, disconnect the connection since peeloff(2)
2744 * is no longer possible.
2746 * Right now, we simply unblock any waiters at the MPTCP socket layer
2747 * if the MPTCP connection has not been established.
2751 if (so
->so_state
& SS_ISDISCONNECTED
) {
2753 * With MPTCP joins, a connection is connected at the subflow
2754 * level, but the 4th ACK from the server elevates the MPTCP
2755 * subflow to connected state. So there is a small window
2756 * where the subflow could get disconnected before the
2757 * connected event is processed.
2759 socket_unlock(so
, 0);
2760 return (MPTS_EVRET_OK
);
2763 mpts
->mpts_soerror
= 0;
2764 mpts
->mpts_flags
&= ~MPTSF_CONNECTING
;
2765 mpts
->mpts_flags
|= MPTSF_CONNECTED
;
2767 if (!(so
->so_flags1
& SOF1_DATA_IDEMPOTENT
))
2768 mpts
->mpts_flags
&= ~MPTSF_TFO_REQD
;
2770 struct tcpcb
*tp
= sototcpcb(so
);
2771 if (tp
->t_mpflags
& TMPF_MPTCP_TRUE
)
2772 mpts
->mpts_flags
|= MPTSF_MP_CAPABLE
;
2774 tp
->t_mpflags
&= ~TMPF_TFO_REQUEST
;
2776 VERIFY(mpts
->mpts_dst
!= NULL
);
2778 VERIFY(mpts
->mpts_src
!= NULL
);
2780 /* get/check source IP address */
2783 error
= in_getsockaddr_s(so
, &src
);
2785 struct sockaddr_in
*ms
= SIN(mpts
->mpts_src
);
2786 struct sockaddr_in
*s
= SIN(&src
);
2788 VERIFY(s
->sin_len
== ms
->sin_len
);
2789 VERIFY(ms
->sin_family
== AF_INET
);
2791 if ((mpts
->mpts_flags
& MPTSF_BOUND_IP
) &&
2792 bcmp(&ms
->sin_addr
, &s
->sin_addr
,
2793 sizeof (ms
->sin_addr
)) != 0) {
2794 mptcplog((LOG_ERR
, "MPTCP Events: "
2796 "address %s (expected %s)\n", __func__
,
2797 mpts
->mpts_connid
, inet_ntop(AF_INET
,
2798 (void *)&s
->sin_addr
.s_addr
, buf0
,
2799 sizeof (buf0
)), inet_ntop(AF_INET
,
2800 (void *)&ms
->sin_addr
.s_addr
, buf1
,
2802 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_ERR
);
2804 bcopy(s
, ms
, sizeof (*s
));
2810 error
= in6_getsockaddr_s(so
, &src
);
2812 struct sockaddr_in6
*ms
= SIN6(mpts
->mpts_src
);
2813 struct sockaddr_in6
*s
= SIN6(&src
);
2815 VERIFY(s
->sin6_len
== ms
->sin6_len
);
2816 VERIFY(ms
->sin6_family
== AF_INET6
);
2818 if ((mpts
->mpts_flags
& MPTSF_BOUND_IP
) &&
2819 bcmp(&ms
->sin6_addr
, &s
->sin6_addr
,
2820 sizeof (ms
->sin6_addr
)) != 0) {
2821 mptcplog((LOG_ERR
, "MPTCP Events: "
2823 "address %s (expected %s)\n", __func__
,
2824 mpts
->mpts_connid
, inet_ntop(AF_INET6
,
2825 (void *)&s
->sin6_addr
, buf0
,
2826 sizeof (buf0
)), inet_ntop(AF_INET6
,
2827 (void *)&ms
->sin6_addr
, buf1
,
2829 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_ERR
);
2831 bcopy(s
, ms
, sizeof (*s
));
2842 mptcplog((LOG_ERR
, "MPTCP Events "
2843 "%s: cid %d getsockaddr failed (%d)\n",
2844 __func__
, mpts
->mpts_connid
, error
),
2845 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_ERR
);
2848 /* get/verify the outbound interface */
2849 outifp
= sotoinpcb(so
)->inp_last_outifp
; /* could be NULL */
2850 if (mpts
->mpts_flags
& MPTSF_BOUND_IF
) {
2851 VERIFY(mpts
->mpts_outif
!= NULL
);
2852 if (mpts
->mpts_outif
!= outifp
) {
2853 mptcplog((LOG_ERR
, "MPTCP Events: %s: cid %d outif %s "
2854 "(expected %s)\n", __func__
, mpts
->mpts_connid
,
2855 ((outifp
!= NULL
) ? outifp
->if_xname
: "NULL"),
2856 mpts
->mpts_outif
->if_xname
),
2857 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_ERR
);
2860 outifp
= mpts
->mpts_outif
;
2863 mpts
->mpts_outif
= outifp
;
2866 mpts
->mpts_srtt
= (intotcpcb(sotoinpcb(so
)))->t_srtt
;
2867 mpts
->mpts_rxtcur
= (intotcpcb(sotoinpcb(so
)))->t_rxtcur
;
2868 mpts
->mpts_maxseg
= (intotcpcb(sotoinpcb(so
)))->t_maxseg
;
2870 cell
= IFNET_IS_CELLULAR(mpts
->mpts_outif
);
2871 wifi
= (!cell
&& IFNET_IS_WIFI(mpts
->mpts_outif
));
2872 wired
= (!wifi
&& IFNET_IS_WIRED(mpts
->mpts_outif
));
2875 mpts
->mpts_linktype
|= MPTSL_CELL
;
2877 mpts
->mpts_linktype
|= MPTSL_WIFI
;
2879 mpts
->mpts_linktype
|= MPTSL_WIRED
;
2881 socket_unlock(so
, 0);
2883 mptcplog((LOG_DEBUG
, "MPTCP Sender: %s: cid %d "
2884 "establishment srtt %d \n", __func__
,
2885 mpts
->mpts_connid
, (mpts
->mpts_srtt
>> 5)),
2886 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_LOG
);
2889 mptcplog((LOG_DEBUG
, "MPTCP Socket: "
2890 "%s: cid %d outif %s %s[%d] -> %s[%d] "
2891 "is %s\n", __func__
, mpts
->mpts_connid
, ((outifp
!= NULL
) ?
2892 outifp
->if_xname
: "NULL"), inet_ntop(af
, (af
== AF_INET
) ?
2893 (void *)&SIN(mpts
->mpts_src
)->sin_addr
.s_addr
:
2894 (void *)&SIN6(mpts
->mpts_src
)->sin6_addr
, buf0
, sizeof (buf0
)),
2895 ((af
== AF_INET
) ? ntohs(SIN(mpts
->mpts_src
)->sin_port
) :
2896 ntohs(SIN6(mpts
->mpts_src
)->sin6_port
)),
2897 inet_ntop(af
, ((af
== AF_INET
) ?
2898 (void *)&SIN(mpts
->mpts_dst
)->sin_addr
.s_addr
:
2899 (void *)&SIN6(mpts
->mpts_dst
)->sin6_addr
), buf1
, sizeof (buf1
)),
2900 ((af
== AF_INET
) ? ntohs(SIN(mpts
->mpts_dst
)->sin_port
) :
2901 ntohs(SIN6(mpts
->mpts_dst
)->sin6_port
)),
2902 ((mpts
->mpts_flags
& MPTSF_MP_CAPABLE
) ?
2903 "MPTCP capable" : "a regular TCP")),
2904 (MPTCP_SOCKET_DBG
| MPTCP_EVENTS_DBG
), MPTCP_LOGLVL_LOG
);
2906 mpok
= (mpts
->mpts_flags
& MPTSF_MP_CAPABLE
);
2909 *p_mpsofilt_hint
|= SO_FILT_HINT_LOCKED
| SO_FILT_HINT_CONNINFO_UPDATED
;
2912 if (mp_tp
->mpt_state
< MPTCPS_ESTABLISHED
) {
2913 /* case (a) above */
2915 mp_tp
->mpt_flags
|= MPTCPF_PEEL_OFF
;
2916 (void) mptcp_drop(mpte
, mp_tp
, EPROTO
);
2920 mptcplog((LOG_DEBUG
, "MPTCP State: "
2921 "MPTCPS_ESTABLISHED for mp_so 0x%llx \n",
2922 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
)),
2923 MPTCP_STATE_DBG
, MPTCP_LOGLVL_LOG
);
2924 mp_tp
->mpt_state
= MPTCPS_ESTABLISHED
;
2925 mpte
->mpte_associd
= mpts
->mpts_connid
;
2926 DTRACE_MPTCP2(state__change
,
2927 struct mptcb
*, mp_tp
,
2928 uint32_t, 0 /* event */);
2930 if (mpts
->mpts_outif
&&
2931 IFNET_IS_EXPENSIVE(mpts
->mpts_outif
)) {
2932 sototcpcb(so
)->t_mpflags
|= (TMPF_BACKUP_PATH
| TMPF_SND_MPPRIO
);
2934 mpts
->mpts_flags
|= MPTSF_PREFERRED
;
2936 mpts
->mpts_flags
|= MPTSF_ACTIVE
;
2937 soisconnected(mp_so
);
2941 mpts
->mpts_flags
|= MPTSF_MPCAP_CTRSET
;
2942 mpte
->mpte_nummpcapflows
++;
2943 MPT_LOCK_SPIN(mp_tp
);
2944 /* With TFO, sndnxt may be initialized earlier */
2945 if (mpts
->mpts_sndnxt
== 0)
2946 mpts
->mpts_sndnxt
= mp_tp
->mpt_snduna
;
2951 if (mptcp_rwnotify
&& (mpte
->mpte_nummpcapflows
== 0)) {
2952 /* Experimental code, disabled by default. */
2958 * In case of additional flows, the MPTCP socket is not
2959 * MPTSF_MP_CAPABLE until an ACK is received from server
2960 * for 3-way handshake. TCP would have guaranteed that this
2961 * is an MPTCP subflow.
2964 mpts
->mpts_flags
|= MPTSF_MPCAP_CTRSET
;
2965 mpts
->mpts_flags
&= ~MPTSF_FASTJ_REQD
;
2966 mpte
->mpte_nummpcapflows
++;
2967 MPT_LOCK_SPIN(mp_tp
);
2968 /* With Fastjoin, sndnxt is updated before connected_ev */
2969 if (mpts
->mpts_sndnxt
== 0) {
2970 mpts
->mpts_sndnxt
= mp_tp
->mpt_snduna
;
2971 mpts
->mpts_rel_seq
= 1;
2974 mptcp_output_needed(mpte
, mpts
);
2980 MPTS_LOCK_ASSERT_HELD(mpts
);
2982 return (MPTS_EVRET_OK
); /* keep the subflow socket around */
2986 * Handle SO_FILT_HINT_DISCONNECTED subflow socket event.
2989 mptcp_subflow_disconnected_ev(struct mptses
*mpte
, struct mptsub
*mpts
,
2990 uint64_t *p_mpsofilt_hint
)
2992 struct socket
*mp_so
, *so
;
2993 struct mptcb
*mp_tp
;
2996 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
2997 MPTS_LOCK_ASSERT_HELD(mpts
);
2998 VERIFY(mpte
->mpte_mppcb
!= NULL
);
2999 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
3000 mp_tp
= mpte
->mpte_mptcb
;
3001 so
= mpts
->mpts_socket
;
3003 linger
= (!(mpts
->mpts_flags
& MPTSF_DELETEOK
) &&
3004 !(mp_so
->so_flags
& SOF_PCBCLEARING
));
3006 mptcplog((LOG_DEBUG
, "MPTCP Events: "
3007 "%s: cid %d [linger %s]\n", __func__
,
3008 mpts
->mpts_connid
, (linger
? "YES" : "NO")),
3009 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
3011 if (mpts
->mpts_flags
& MPTSF_DISCONNECTED
)
3012 return (linger
? MPTS_EVRET_OK
: MPTS_EVRET_DELETE
);
3015 * Clear flags that are used by getconninfo to return state.
3016 * Retain like MPTSF_DELETEOK for internal purposes.
3018 mpts
->mpts_flags
&= ~(MPTSF_CONNECTING
|MPTSF_CONNECT_PENDING
|
3019 MPTSF_CONNECTED
|MPTSF_DISCONNECTING
|MPTSF_PREFERRED
|
3020 MPTSF_MP_CAPABLE
|MPTSF_MP_READY
|MPTSF_MP_DEGRADED
|
3021 MPTSF_SUSPENDED
|MPTSF_ACTIVE
);
3022 mpts
->mpts_flags
|= MPTSF_DISCONNECTED
;
3025 * The subflow connection has been disconnected.
3027 * Right now, we simply unblock any waiters at the MPTCP socket layer
3028 * if the MPTCP connection has not been established.
3030 *p_mpsofilt_hint
|= SO_FILT_HINT_LOCKED
| SO_FILT_HINT_CONNINFO_UPDATED
;
3032 if (mpts
->mpts_flags
& MPTSF_MPCAP_CTRSET
) {
3033 mpte
->mpte_nummpcapflows
--;
3034 if (mpte
->mpte_active_sub
== mpts
) {
3035 mpte
->mpte_active_sub
= NULL
;
3036 mptcplog((LOG_DEBUG
, "MPTCP Events: "
3037 "%s: resetting active subflow \n",
3038 __func__
), MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
3040 mpts
->mpts_flags
&= ~MPTSF_MPCAP_CTRSET
;
3044 if (mp_tp
->mpt_state
< MPTCPS_ESTABLISHED
) {
3047 soisdisconnected(mp_so
);
3054 * The underlying subflow socket has been disconnected;
3055 * it is no longer useful to us. Keep the subflow socket
3056 * around, unless the MPTCP socket has been detached or
3057 * the subflow has been disconnected explicitly, in which
3058 * case it should be deleted right away.
3060 return (linger
? MPTS_EVRET_OK
: MPTS_EVRET_DELETE
);
3064 * Handle SO_FILT_HINT_MPSTATUS subflow socket event
3067 mptcp_subflow_mpstatus_ev(struct mptses
*mpte
, struct mptsub
*mpts
,
3068 uint64_t *p_mpsofilt_hint
)
3070 struct socket
*mp_so
, *so
;
3071 struct mptcb
*mp_tp
;
3072 ev_ret_t ret
= MPTS_EVRET_OK
;
3074 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
3075 VERIFY(mpte
->mpte_mppcb
!= NULL
);
3076 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
3077 mp_tp
= mpte
->mpte_mptcb
;
3079 MPTS_LOCK_ASSERT_HELD(mpts
);
3080 so
= mpts
->mpts_socket
;
3085 if (sototcpcb(so
)->t_mpflags
& TMPF_MPTCP_TRUE
)
3086 mpts
->mpts_flags
|= MPTSF_MP_CAPABLE
;
3088 mpts
->mpts_flags
&= ~MPTSF_MP_CAPABLE
;
3090 if (sototcpcb(so
)->t_mpflags
& TMPF_TCP_FALLBACK
) {
3091 if (mpts
->mpts_flags
& MPTSF_MP_DEGRADED
)
3093 mpts
->mpts_flags
|= MPTSF_MP_DEGRADED
;
3096 mpts
->mpts_flags
&= ~MPTSF_MP_DEGRADED
;
3098 if (sototcpcb(so
)->t_mpflags
& TMPF_MPTCP_READY
)
3099 mpts
->mpts_flags
|= MPTSF_MP_READY
;
3101 mpts
->mpts_flags
&= ~MPTSF_MP_READY
;
3103 if (mpts
->mpts_flags
& MPTSF_MP_DEGRADED
) {
3104 mp_tp
->mpt_flags
|= MPTCPF_FALLBACK_TO_TCP
;
3105 mp_tp
->mpt_flags
&= ~MPTCPF_JOIN_READY
;
3108 if (mp_tp
->mpt_flags
& MPTCPF_FALLBACK_TO_TCP
) {
3109 VERIFY(!(mp_tp
->mpt_flags
& MPTCPF_JOIN_READY
));
3110 ret
= MPTS_EVRET_DISCONNECT_FALLBACK
;
3111 *p_mpsofilt_hint
|= SO_FILT_HINT_LOCKED
|
3112 SO_FILT_HINT_CONNINFO_UPDATED
;
3113 } else if (mpts
->mpts_flags
& MPTSF_MP_READY
) {
3114 mp_tp
->mpt_flags
|= MPTCPF_JOIN_READY
;
3115 ret
= MPTS_EVRET_CONNECT_PENDING
;
3117 *p_mpsofilt_hint
|= SO_FILT_HINT_LOCKED
|
3118 SO_FILT_HINT_CONNINFO_UPDATED
;
3121 mptcplog((LOG_DEBUG
, "MPTCP Events: "
3122 "%s: mp_so 0x%llx mpt_flags=%b cid %d "
3123 "mptsf=%b\n", __func__
,
3124 (u_int64_t
)VM_KERNEL_ADDRPERM(mpte
->mpte_mppcb
->mpp_socket
),
3125 mp_tp
->mpt_flags
, MPTCPF_BITS
, mpts
->mpts_connid
,
3126 mpts
->mpts_flags
, MPTSF_BITS
),
3127 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
3131 socket_unlock(so
, 0);
3136 * Handle SO_FILT_HINT_MUSTRST subflow socket event
3139 mptcp_subflow_mustrst_ev(struct mptses
*mpte
, struct mptsub
*mpts
,
3140 uint64_t *p_mpsofilt_hint
)
3142 struct socket
*mp_so
, *so
;
3143 struct mptcb
*mp_tp
;
3144 boolean_t linger
, is_fastclose
;
3147 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
3148 MPTS_LOCK_ASSERT_HELD(mpts
);
3149 VERIFY(mpte
->mpte_mppcb
!= NULL
);
3150 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
3151 mp_tp
= mpte
->mpte_mptcb
;
3152 so
= mpts
->mpts_socket
;
3154 linger
= (!(mpts
->mpts_flags
& MPTSF_DELETEOK
) &&
3155 !(mp_so
->so_flags
& SOF_PCBCLEARING
));
3157 if (mpts
->mpts_soerror
== 0)
3158 mpts
->mpts_soerror
= ECONNABORTED
;
3160 /* We got an invalid option or a fast close */
3162 struct tcptemp
*t_template
;
3163 struct inpcb
*inp
= sotoinpcb(so
);
3164 struct tcpcb
*tp
= NULL
;
3166 tp
= intotcpcb(inp
);
3167 so
->so_error
= ECONNABORTED
;
3169 is_fastclose
= !!(tp
->t_mpflags
& TMPF_FASTCLOSERCV
);
3171 t_template
= tcp_maketemplate(tp
);
3173 struct tcp_respond_args tra
;
3175 bzero(&tra
, sizeof(tra
));
3176 if (inp
->inp_flags
& INP_BOUND_IF
)
3177 tra
.ifscope
= inp
->inp_boundifp
->if_index
;
3179 tra
.ifscope
= IFSCOPE_NONE
;
3180 tra
.awdl_unrestricted
= 1;
3182 tcp_respond(tp
, t_template
->tt_ipgen
,
3183 &t_template
->tt_t
, (struct mbuf
*)NULL
,
3184 tp
->rcv_nxt
, tp
->snd_una
, TH_RST
, &tra
);
3185 (void) m_free(dtom(t_template
));
3186 mptcplog((LOG_DEBUG
, "MPTCP Events: "
3187 "%s: mp_so 0x%llx cid %d \n",
3188 __func__
, (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
),
3189 so
, mpts
->mpts_connid
),
3190 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
3192 socket_unlock(so
, 0);
3193 mptcp_subflow_disconnect(mpte
, mpts
, !linger
);
3195 *p_mpsofilt_hint
|= (SO_FILT_HINT_LOCKED
| SO_FILT_HINT_CONNINFO_UPDATED
);
3199 if (!(mp_tp
->mpt_flags
& MPTCPF_FALLBACK_TO_TCP
) && is_fastclose
) {
3200 *p_mpsofilt_hint
|= SO_FILT_HINT_CONNRESET
;
3202 if (mp_tp
->mpt_state
< MPTCPS_ESTABLISHED
)
3203 mp_so
->so_error
= ECONNABORTED
;
3205 mp_so
->so_error
= ECONNRESET
;
3208 * mptcp_drop is being called after processing the events, to fully
3209 * close the MPTCP connection
3213 if (mp_tp
->mpt_gc_ticks
== MPT_GC_TICKS
)
3214 mp_tp
->mpt_gc_ticks
= MPT_GC_TICKS_FAST
;
3218 * Keep the subflow socket around unless the subflow has been
3219 * disconnected explicitly.
3221 return (linger
? MPTS_EVRET_OK
: MPTS_EVRET_DELETE
);
3225 mptcp_fastjoin_ev(struct mptses
*mpte
, struct mptsub
*mpts
,
3226 uint64_t *p_mpsofilt_hint
)
3228 #pragma unused(p_mpsofilt_hint)
3229 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
3230 MPTS_LOCK_ASSERT_HELD(mpts
);
3231 VERIFY(mpte
->mpte_mppcb
!= NULL
);
3233 if (mpte
->mpte_nummpcapflows
== 0) {
3234 struct mptcb
*mp_tp
= mpte
->mpte_mptcb
;
3235 mptcplog((LOG_DEBUG
,"MPTCP Events: %s: %llx %llx \n",
3236 __func__
, mp_tp
->mpt_snduna
, mpts
->mpts_sndnxt
),
3237 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
3239 mpte
->mpte_active_sub
= mpts
;
3240 mpts
->mpts_flags
|= (MPTSF_FASTJ_SEND
| MPTSF_ACTIVE
);
3243 * If mptcp_subflow_output is called before fastjoin_ev
3244 * then mpts->mpts_sndnxt is initialized to mp_tp->mpt_snduna
3245 * and further mpts->mpts_sndnxt is incremented by len copied.
3247 if (mpts
->mpts_sndnxt
== 0) {
3248 mpts
->mpts_sndnxt
= mp_tp
->mpt_snduna
;
3253 return (MPTS_EVRET_OK
);
3257 mptcp_deleteok_ev(struct mptses
*mpte
, struct mptsub
*mpts
,
3258 uint64_t *p_mpsofilt_hint
)
3260 #pragma unused(p_mpsofilt_hint)
3261 MPTE_LOCK_ASSERT_HELD(mpte
);
3262 MPTS_LOCK_ASSERT_HELD(mpts
);
3263 VERIFY(mpte
->mpte_mppcb
!= NULL
);
3265 mptcplog((LOG_DEBUG
, "MPTCP Events: "
3266 "%s cid %d\n", __func__
, mpts
->mpts_connid
),
3267 MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
3269 mpts
->mpts_flags
|= MPTSF_DELETEOK
;
3270 if (mpts
->mpts_flags
& MPTSF_DISCONNECTED
)
3271 return (MPTS_EVRET_DELETE
);
3273 return (MPTS_EVRET_OK
);
3277 mptcp_evret2str(ev_ret_t ret
)
3279 const char *c
= "UNKNOWN";
3282 case MPTS_EVRET_DELETE
:
3283 c
= "MPTS_EVRET_DELETE";
3285 case MPTS_EVRET_CONNECT_PENDING
:
3286 c
= "MPTS_EVRET_CONNECT_PENDING";
3288 case MPTS_EVRET_DISCONNECT_FALLBACK
:
3289 c
= "MPTS_EVRET_DISCONNECT_FALLBACK";
3292 c
= "MPTS_EVRET_OK";
3301 * Add a reference to a subflow structure; used by MPTS_ADDREF().
3304 mptcp_subflow_addref(struct mptsub
*mpts
, int locked
)
3309 MPTS_LOCK_ASSERT_HELD(mpts
);
3311 if (++mpts
->mpts_refcnt
== 0) {
3312 panic("%s: mpts %p wraparound refcnt\n", __func__
, mpts
);
3320 * Remove a reference held on a subflow structure; used by MPTS_REMREF();
3323 mptcp_subflow_remref(struct mptsub
*mpts
)
3326 if (mpts
->mpts_refcnt
== 0) {
3327 panic("%s: mpts %p negative refcnt\n", __func__
, mpts
);
3330 if (--mpts
->mpts_refcnt
> 0) {
3334 /* callee will unlock and destroy lock */
3335 mptcp_subflow_free(mpts
);
3339 * Issues SOPT_SET on an MPTCP subflow socket; socket must already be locked,
3340 * caller must ensure that the option can be issued on subflow sockets, via
3341 * MPOF_SUBFLOW_OK flag.
3344 mptcp_subflow_sosetopt(struct mptses
*mpte
, struct socket
*so
,
3347 struct socket
*mp_so
;
3348 struct sockopt sopt
;
3352 VERIFY(mpo
->mpo_flags
& MPOF_SUBFLOW_OK
);
3353 mpo
->mpo_flags
&= ~MPOF_INTERIM
;
3355 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
3356 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
3358 bzero(&sopt
, sizeof (sopt
));
3359 sopt
.sopt_dir
= SOPT_SET
;
3360 sopt
.sopt_level
= mpo
->mpo_level
;
3361 sopt
.sopt_name
= mpo
->mpo_name
;
3362 sopt
.sopt_val
= CAST_USER_ADDR_T(&mpo
->mpo_intval
);
3363 sopt
.sopt_valsize
= sizeof (int);
3364 sopt
.sopt_p
= kernproc
;
3366 error
= sosetoptlock(so
, &sopt
, 0); /* already locked */
3368 mptcplog((LOG_DEBUG
, "MPTCP Socket: "
3369 "%s: mp_so 0x%llx sopt %s "
3370 "val %d set successful\n", __func__
,
3371 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
),
3372 mptcp_sopt2str(mpo
->mpo_level
, mpo
->mpo_name
,
3373 buf
, sizeof (buf
)), mpo
->mpo_intval
),
3374 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_VERBOSE
);
3376 mptcplog((LOG_ERR
, "MPTCP Socket: "
3377 "%s: mp_so 0x%llx sopt %s "
3378 "val %d set error %d\n", __func__
,
3379 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
),
3380 mptcp_sopt2str(mpo
->mpo_level
, mpo
->mpo_name
,
3381 buf
, sizeof (buf
)), mpo
->mpo_intval
, error
),
3382 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_VERBOSE
);
3388 * Issues SOPT_GET on an MPTCP subflow socket; socket must already be locked,
3389 * caller must ensure that the option can be issued on subflow sockets, via
3390 * MPOF_SUBFLOW_OK flag.
3393 mptcp_subflow_sogetopt(struct mptses
*mpte
, struct socket
*so
,
3396 struct socket
*mp_so
;
3397 struct sockopt sopt
;
3401 VERIFY(mpo
->mpo_flags
& MPOF_SUBFLOW_OK
);
3402 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
3403 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
3405 bzero(&sopt
, sizeof (sopt
));
3406 sopt
.sopt_dir
= SOPT_GET
;
3407 sopt
.sopt_level
= mpo
->mpo_level
;
3408 sopt
.sopt_name
= mpo
->mpo_name
;
3409 sopt
.sopt_val
= CAST_USER_ADDR_T(&mpo
->mpo_intval
);
3410 sopt
.sopt_valsize
= sizeof (int);
3411 sopt
.sopt_p
= kernproc
;
3413 error
= sogetoptlock(so
, &sopt
, 0); /* already locked */
3415 mptcplog((LOG_DEBUG
, "MPTCP Socket: "
3416 "%s: mp_so 0x%llx sopt %s "
3417 "val %d get successful\n", __func__
,
3418 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
),
3419 mptcp_sopt2str(mpo
->mpo_level
, mpo
->mpo_name
,
3420 buf
, sizeof (buf
)), mpo
->mpo_intval
),
3421 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_VERBOSE
);
3423 mptcplog((LOG_ERR
, "MPTCP Socket: "
3424 "%s: mp_so 0x%llx sopt %s get error %d\n",
3425 __func__
, (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
),
3426 mptcp_sopt2str(mpo
->mpo_level
,
3427 mpo
->mpo_name
, buf
, sizeof (buf
)), error
),
3428 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_ERR
);
3435 * MPTCP garbage collector.
3437 * This routine is called by the MP domain on-demand, periodic callout,
3438 * which is triggered when a MPTCP socket is closed. The callout will
3439 * repeat as long as this routine returns a non-zero value.
3442 mptcp_gc(struct mppcbinfo
*mppi
)
3444 struct mppcb
*mpp
, *tmpp
;
3445 uint32_t active
= 0;
3447 lck_mtx_assert(&mppi
->mppi_lock
, LCK_MTX_ASSERT_OWNED
);
3449 TAILQ_FOREACH_SAFE(mpp
, &mppi
->mppi_pcbs
, mpp_entry
, tmpp
) {
3450 struct socket
*mp_so
;
3451 struct mptses
*mpte
;
3452 struct mptcb
*mp_tp
;
3454 VERIFY(mpp
->mpp_flags
& MPP_ATTACHED
);
3455 mp_so
= mpp
->mpp_socket
;
3456 VERIFY(mp_so
!= NULL
);
3457 mpte
= mptompte(mpp
);
3458 VERIFY(mpte
!= NULL
);
3459 mp_tp
= mpte
->mpte_mptcb
;
3460 VERIFY(mp_tp
!= NULL
);
3462 mptcplog((LOG_DEBUG
, "MPTCP Socket: "
3463 "%s: mp_so 0x%llx found "
3464 "(u=%d,r=%d,s=%d)\n", __func__
,
3465 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
), mp_so
->so_usecount
,
3466 mp_so
->so_retaincnt
, mpp
->mpp_state
),
3467 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_VERBOSE
);
3469 if (!lck_mtx_try_lock(&mpp
->mpp_lock
)) {
3470 mptcplog((LOG_DEBUG
, "MPTCP Socket: "
3471 "%s: mp_so 0x%llx skipped "
3472 "(u=%d,r=%d)\n", __func__
,
3473 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
),
3474 mp_so
->so_usecount
, mp_so
->so_retaincnt
),
3475 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_VERBOSE
);
3480 /* check again under the lock */
3481 if (mp_so
->so_usecount
> 1) {
3482 boolean_t wakeup
= FALSE
;
3483 struct mptsub
*mpts
, *tmpts
;
3485 mptcplog((LOG_DEBUG
, "MPTCP Socket: "
3486 "%s: mp_so 0x%llx skipped "
3487 "[u=%d,r=%d] %d %d\n", __func__
,
3488 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
),
3489 mp_so
->so_usecount
, mp_so
->so_retaincnt
,
3490 mp_tp
->mpt_gc_ticks
,
3492 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_VERBOSE
);
3495 if (mp_tp
->mpt_state
>= MPTCPS_FIN_WAIT_1
) {
3496 if (mp_tp
->mpt_gc_ticks
> 0)
3497 mp_tp
->mpt_gc_ticks
--;
3498 if (mp_tp
->mpt_gc_ticks
== 0) {
3500 if (mp_tp
->mpt_localkey
!= NULL
) {
3502 mp_tp
->mpt_localkey
);
3503 mp_tp
->mpt_localkey
= NULL
;
3509 TAILQ_FOREACH_SAFE(mpts
,
3510 &mpte
->mpte_subflows
, mpts_entry
, tmpts
) {
3512 mpts
->mpts_flags
|= MPTSF_DELETEOK
;
3513 if (mpts
->mpts_soerror
== 0)
3514 mpts
->mpts_soerror
= ETIMEDOUT
;
3515 mptcp_subflow_eupcall(mpts
->mpts_socket
,
3516 mpts
, SO_FILT_HINT_DISCONNECTED
);
3520 lck_mtx_unlock(&mpp
->mpp_lock
);
3525 if (mpp
->mpp_state
!= MPPCB_STATE_DEAD
) {
3526 mptcplog((LOG_DEBUG
, "MPTCP Socket: "
3527 "%s: mp_so 0x%llx skipped "
3528 "[u=%d,r=%d,s=%d]\n", __func__
,
3529 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
),
3530 mp_so
->so_usecount
, mp_so
->so_retaincnt
,
3532 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_VERBOSE
);
3533 lck_mtx_unlock(&mpp
->mpp_lock
);
3539 * The PCB has been detached, and there is exactly 1 refnct
3540 * held by the MPTCP thread. Signal that thread to terminate,
3541 * after which the last refcnt will be released. That will
3542 * allow it to be destroyed below during the next round.
3544 if (mp_so
->so_usecount
== 1) {
3545 mptcplog((LOG_DEBUG
, "MPTCP Socket: "
3546 "%s: mp_so 0x%llx scheduled for "
3547 "termination [u=%d,r=%d]\n", __func__
,
3548 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
),
3549 mp_so
->so_usecount
, mp_so
->so_retaincnt
),
3550 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_VERBOSE
);
3552 /* signal MPTCP thread to terminate */
3553 mptcp_thread_terminate_signal(mpte
);
3554 lck_mtx_unlock(&mpp
->mpp_lock
);
3559 mptcplog((LOG_DEBUG
, "MPTCP Socket: "
3560 "%s: mp_so 0x%llx destroyed [u=%d,r=%d]\n",
3561 __func__
, (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
),
3562 mp_so
->so_usecount
, mp_so
->so_retaincnt
),
3563 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_VERBOSE
);
3565 DTRACE_MPTCP4(dispose
, struct socket
*, mp_so
,
3566 struct sockbuf
*, &mp_so
->so_rcv
,
3567 struct sockbuf
*, &mp_so
->so_snd
,
3568 struct mppcb
*, mpp
);
3578 * Drop a MPTCP connection, reporting the specified error.
3581 mptcp_drop(struct mptses
*mpte
, struct mptcb
*mp_tp
, int errno
)
3583 struct socket
*mp_so
;
3585 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
3586 MPT_LOCK_ASSERT_HELD(mp_tp
);
3587 VERIFY(mpte
->mpte_mptcb
== mp_tp
);
3588 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
3590 mp_tp
->mpt_state
= MPTCPS_TERMINATE
;
3591 DTRACE_MPTCP2(state__change
, struct mptcb
*, mp_tp
,
3592 uint32_t, 0 /* event */);
3594 if (errno
== ETIMEDOUT
&& mp_tp
->mpt_softerror
!= 0)
3595 errno
= mp_tp
->mpt_softerror
;
3596 mp_so
->so_error
= errno
;
3598 return (mptcp_close(mpte
, mp_tp
));
3602 * Close a MPTCP control block.
3605 mptcp_close(struct mptses
*mpte
, struct mptcb
*mp_tp
)
3607 struct socket
*mp_so
= NULL
;
3608 struct mptsub
*mpts
= NULL
, *tmpts
= NULL
;
3610 MPTE_LOCK_ASSERT_HELD(mpte
); /* same as MP socket lock */
3611 MPT_LOCK_ASSERT_HELD(mp_tp
);
3612 VERIFY(mpte
->mpte_mptcb
== mp_tp
);
3613 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
3614 if (mp_tp
->mpt_localkey
!= NULL
) {
3615 mptcp_free_key(mp_tp
->mpt_localkey
);
3616 mp_tp
->mpt_localkey
= NULL
;
3620 soisdisconnected(mp_so
);
3623 if (mp_tp
->mpt_flags
& MPTCPF_PEEL_OFF
) {
3628 /* Clean up all subflows */
3629 TAILQ_FOREACH_SAFE(mpts
, &mpte
->mpte_subflows
, mpts_entry
, tmpts
) {
3631 mpts
->mpts_flags
|= MPTSF_USER_DISCONNECT
;
3632 mptcp_subflow_disconnect(mpte
, mpts
, TRUE
);
3634 mptcp_subflow_del(mpte
, mpts
, TRUE
);
3642 mptcp_notify_close(struct socket
*so
)
3644 soevent(so
, (SO_FILT_HINT_LOCKED
| SO_FILT_HINT_DISCONNECTED
));
3648 * Signal MPTCP thread to wake up.
3651 mptcp_thread_signal(struct mptses
*mpte
)
3653 lck_mtx_lock(&mpte
->mpte_thread_lock
);
3654 mptcp_thread_signal_locked(mpte
);
3655 lck_mtx_unlock(&mpte
->mpte_thread_lock
);
3659 * Signal MPTCP thread to wake up (locked version)
3662 mptcp_thread_signal_locked(struct mptses
*mpte
)
3664 lck_mtx_assert(&mpte
->mpte_thread_lock
, LCK_MTX_ASSERT_OWNED
);
3666 mpte
->mpte_thread_reqs
++;
3667 if (!mpte
->mpte_thread_active
&& mpte
->mpte_thread
!= THREAD_NULL
)
3668 wakeup_one((caddr_t
)&mpte
->mpte_thread
);
3672 * Signal MPTCP thread to terminate.
3675 mptcp_thread_terminate_signal(struct mptses
*mpte
)
3677 lck_mtx_lock(&mpte
->mpte_thread_lock
);
3678 if (mpte
->mpte_thread
!= THREAD_NULL
) {
3679 mpte
->mpte_thread
= THREAD_NULL
;
3680 mpte
->mpte_thread_reqs
++;
3681 if (!mpte
->mpte_thread_active
)
3682 wakeup_one((caddr_t
)&mpte
->mpte_thread
);
3684 lck_mtx_unlock(&mpte
->mpte_thread_lock
);
3688 * MPTCP thread workloop.
3691 mptcp_thread_dowork(struct mptses
*mpte
)
3693 struct socket
*mp_so
;
3694 struct mptsub
*mpts
, *tmpts
;
3695 boolean_t connect_pending
= FALSE
, disconnect_fallback
= FALSE
;
3696 uint64_t mpsofilt_hint_mask
= 0;
3698 MPTE_LOCK(mpte
); /* same as MP socket lock */
3699 VERIFY(mpte
->mpte_mppcb
!= NULL
);
3700 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
3701 VERIFY(mp_so
!= NULL
);
3703 TAILQ_FOREACH_SAFE(mpts
, &mpte
->mpte_subflows
, mpts_entry
, tmpts
) {
3707 MPTS_ADDREF_LOCKED(mpts
); /* for us */
3709 /* Update process ownership based on parent mptcp socket */
3710 mptcp_update_last_owner(mpts
, mp_so
);
3712 mptcp_subflow_input(mpte
, mpts
);
3714 mptcp_get_rtt_measurement(mpts
, mpte
);
3716 ret
= mptcp_subflow_events(mpte
, mpts
, &mpsofilt_hint_mask
);
3718 if (mpts
->mpts_flags
& MPTSF_ACTIVE
) {
3719 mptcplog((LOG_DEBUG
, "MPTCP Socket: "
3720 "%s: cid %d \n", __func__
,
3722 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_VERBOSE
);
3723 (void) mptcp_subflow_output(mpte
, mpts
);
3727 * If MPTCP socket is closed, disconnect all subflows.
3728 * This will generate a disconnect event which will
3729 * be handled during the next iteration, causing a
3730 * non-zero error to be returned above.
3732 if (mp_so
->so_flags
& SOF_PCBCLEARING
)
3733 mptcp_subflow_disconnect(mpte
, mpts
, FALSE
);
3740 case MPTS_EVRET_DELETE
:
3741 mptcp_subflow_del(mpte
, mpts
, TRUE
);
3743 case MPTS_EVRET_CONNECT_PENDING
:
3744 connect_pending
= TRUE
;
3746 case MPTS_EVRET_DISCONNECT_FALLBACK
:
3747 disconnect_fallback
= TRUE
;
3750 mptcplog((LOG_DEBUG
,
3751 "MPTCP Socket: %s: mptcp_subflow_events "
3752 "returned invalid value: %d\n", __func__
,
3754 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_VERBOSE
);
3757 MPTS_REMREF(mpts
); /* ours */
3760 if (mpsofilt_hint_mask
) {
3761 if (mpsofilt_hint_mask
& SO_FILT_HINT_CANTRCVMORE
) {
3762 socantrcvmore(mp_so
);
3763 mpsofilt_hint_mask
&= ~SO_FILT_HINT_CANTRCVMORE
;
3766 if (mpsofilt_hint_mask
& SO_FILT_HINT_CONNRESET
) {
3767 struct mptcb
*mp_tp
= mpte
->mpte_mptcb
;
3770 mptcp_drop(mpte
, mp_tp
, ECONNRESET
);
3774 soevent(mp_so
, mpsofilt_hint_mask
);
3777 if (!connect_pending
&& !disconnect_fallback
) {
3782 TAILQ_FOREACH_SAFE(mpts
, &mpte
->mpte_subflows
, mpts_entry
, tmpts
) {
3784 if (disconnect_fallback
) {
3785 struct socket
*so
= NULL
;
3786 struct inpcb
*inp
= NULL
;
3787 struct tcpcb
*tp
= NULL
;
3789 if (mpts
->mpts_flags
& MPTSF_MP_DEGRADED
) {
3794 mpts
->mpts_flags
|= MPTSF_MP_DEGRADED
;
3796 if (mpts
->mpts_flags
& (MPTSF_DISCONNECTING
|
3797 MPTSF_DISCONNECTED
|MPTSF_CONNECT_PENDING
)) {
3802 if (mpts
->mpts_flags
& MPTSF_TFO_REQD
)
3803 mptcp_drop_tfo_data(mpte
, mpts
, NULL
);
3805 so
= mpts
->mpts_socket
;
3808 * The MPTCP connection has degraded to a fallback
3809 * mode, so there is no point in keeping this subflow
3810 * regardless of its MPTCP-readiness state, unless it
3811 * is the primary one which we use for fallback. This
3812 * assumes that the subflow used for fallback is the
3817 inp
= sotoinpcb(so
);
3818 tp
= intotcpcb(inp
);
3820 ~(TMPF_MPTCP_READY
|TMPF_MPTCP_TRUE
);
3821 tp
->t_mpflags
|= TMPF_TCP_FALLBACK
;
3823 if (mpts
->mpts_flags
& MPTSF_ACTIVE
) {
3824 socket_unlock(so
, 1);
3828 tp
->t_mpflags
|= TMPF_RESET
;
3829 soevent(so
, SO_FILT_HINT_LOCKED
| SO_FILT_HINT_MUSTRST
);
3830 socket_unlock(so
, 1);
3832 } else if (connect_pending
) {
3834 * If delayed subflow start is set and cellular,
3835 * delay the connect till a retransmission timeout
3838 if ((mptcp_delayed_subf_start
) &&
3839 (IFNET_IS_CELLULAR(mpts
->mpts_outif
))) {
3845 * The MPTCP connection has progressed to a state
3846 * where it supports full multipath semantics; allow
3847 * additional joins to be attempted for all subflows
3848 * that are in the PENDING state.
3850 if (mpts
->mpts_flags
& MPTSF_CONNECT_PENDING
) {
3851 (void) mptcp_subflow_soconnectx(mpte
, mpts
);
3864 mptcp_thread_func(void *v
, wait_result_t w
)
3867 struct mptses
*mpte
= v
;
3868 struct timespec
*ts
= NULL
;
3870 VERIFY(mpte
!= NULL
);
3872 lck_mtx_lock_spin(&mpte
->mpte_thread_lock
);
3875 lck_mtx_assert(&mpte
->mpte_thread_lock
, LCK_MTX_ASSERT_OWNED
);
3877 if (mpte
->mpte_thread
!= THREAD_NULL
) {
3878 (void) msleep(&mpte
->mpte_thread
,
3879 &mpte
->mpte_thread_lock
, (PZERO
- 1) | PSPIN
,
3883 /* MPTCP socket is closed? */
3884 if (mpte
->mpte_thread
== THREAD_NULL
) {
3885 lck_mtx_unlock(&mpte
->mpte_thread_lock
);
3886 /* callee will destroy thread lock */
3887 mptcp_thread_destroy(mpte
);
3892 mpte
->mpte_thread_active
= 1;
3894 uint32_t reqs
= mpte
->mpte_thread_reqs
;
3896 lck_mtx_unlock(&mpte
->mpte_thread_lock
);
3897 mptcp_thread_dowork(mpte
);
3898 lck_mtx_lock_spin(&mpte
->mpte_thread_lock
);
3900 /* if there's no pending request, we're done */
3901 if (reqs
== mpte
->mpte_thread_reqs
||
3902 mpte
->mpte_thread
== THREAD_NULL
)
3905 mpte
->mpte_thread_reqs
= 0;
3906 mpte
->mpte_thread_active
= 0;
3911 * Destroy a MTCP thread, to be called in the MPTCP thread context
3912 * upon receiving an indication to self-terminate. This routine
3913 * will not return, as the current thread is terminated at the end.
3916 mptcp_thread_destroy(struct mptses
*mpte
)
3918 struct socket
*mp_so
;
3920 MPTE_LOCK(mpte
); /* same as MP socket lock */
3921 VERIFY(mpte
->mpte_thread
== THREAD_NULL
);
3922 VERIFY(mpte
->mpte_mppcb
!= NULL
);
3924 mptcp_sesdestroy(mpte
);
3926 mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
3927 VERIFY(mp_so
!= NULL
);
3928 VERIFY(mp_so
->so_usecount
> 0);
3929 mp_so
->so_usecount
--; /* for thread */
3930 mpte
->mpte_mppcb
->mpp_flags
|= MPP_DEFUNCT
;
3933 /* for the extra refcnt from kernel_thread_start() */
3934 thread_deallocate(current_thread());
3935 /* this is the end */
3936 thread_terminate(current_thread());
3941 * Protocol pr_lock callback.
3944 mptcp_lock(struct socket
*mp_so
, int refcount
, void *lr
)
3946 struct mppcb
*mpp
= sotomppcb(mp_so
);
3950 lr_saved
= __builtin_return_address(0);
3955 panic("%s: so=%p NO PCB! lr=%p lrh= %s\n", __func__
,
3956 mp_so
, lr_saved
, solockhistory_nr(mp_so
));
3959 lck_mtx_lock(&mpp
->mpp_lock
);
3961 if (mp_so
->so_usecount
< 0) {
3962 panic("%s: so=%p so_pcb=%p lr=%p ref=%x lrh= %s\n", __func__
,
3963 mp_so
, mp_so
->so_pcb
, lr_saved
, mp_so
->so_usecount
,
3964 solockhistory_nr(mp_so
));
3968 mp_so
->so_usecount
++;
3969 mp_so
->lock_lr
[mp_so
->next_lock_lr
] = lr_saved
;
3970 mp_so
->next_lock_lr
= (mp_so
->next_lock_lr
+ 1) % SO_LCKDBG_MAX
;
3976 * Protocol pr_unlock callback.
3979 mptcp_unlock(struct socket
*mp_so
, int refcount
, void *lr
)
3981 struct mppcb
*mpp
= sotomppcb(mp_so
);
3985 lr_saved
= __builtin_return_address(0);
3990 panic("%s: so=%p NO PCB usecount=%x lr=%p lrh= %s\n", __func__
,
3991 mp_so
, mp_so
->so_usecount
, lr_saved
,
3992 solockhistory_nr(mp_so
));
3995 lck_mtx_assert(&mpp
->mpp_lock
, LCK_MTX_ASSERT_OWNED
);
3998 mp_so
->so_usecount
--;
4000 if (mp_so
->so_usecount
< 0) {
4001 panic("%s: so=%p usecount=%x lrh= %s\n", __func__
,
4002 mp_so
, mp_so
->so_usecount
, solockhistory_nr(mp_so
));
4005 mp_so
->unlock_lr
[mp_so
->next_unlock_lr
] = lr_saved
;
4006 mp_so
->next_unlock_lr
= (mp_so
->next_unlock_lr
+ 1) % SO_LCKDBG_MAX
;
4007 lck_mtx_unlock(&mpp
->mpp_lock
);
4013 * Protocol pr_getlock callback.
4016 mptcp_getlock(struct socket
*mp_so
, int locktype
)
4018 #pragma unused(locktype)
4019 struct mppcb
*mpp
= sotomppcb(mp_so
);
4022 panic("%s: so=%p NULL so_pcb %s\n", __func__
, mp_so
,
4023 solockhistory_nr(mp_so
));
4026 if (mp_so
->so_usecount
< 0) {
4027 panic("%s: so=%p usecount=%x lrh= %s\n", __func__
,
4028 mp_so
, mp_so
->so_usecount
, solockhistory_nr(mp_so
));
4031 return (&mpp
->mpp_lock
);
4035 * Key generation functions
4038 mptcp_generate_unique_key(struct mptcp_key_entry
*key_entry
)
4040 struct mptcp_key_entry
*key_elm
;
4042 read_random(&key_entry
->mkey_value
, sizeof (key_entry
->mkey_value
));
4043 if (key_entry
->mkey_value
== 0)
4045 mptcp_do_sha1(&key_entry
->mkey_value
, key_entry
->mkey_digest
,
4046 sizeof (key_entry
->mkey_digest
));
4048 LIST_FOREACH(key_elm
, &mptcp_keys_pool
, mkey_next
) {
4049 if (key_elm
->mkey_value
== key_entry
->mkey_value
) {
4052 if (bcmp(key_elm
->mkey_digest
, key_entry
->mkey_digest
, 4) ==
4059 static mptcp_key_t
*
4060 mptcp_reserve_key(void)
4062 struct mptcp_key_entry
*key_elm
;
4063 struct mptcp_key_entry
*found_elm
= NULL
;
4065 lck_mtx_lock(&mptcp_keys_pool
.mkph_lock
);
4066 LIST_FOREACH(key_elm
, &mptcp_keys_pool
, mkey_next
) {
4067 if (key_elm
->mkey_flags
== MKEYF_FREE
) {
4068 key_elm
->mkey_flags
= MKEYF_INUSE
;
4069 found_elm
= key_elm
;
4073 lck_mtx_unlock(&mptcp_keys_pool
.mkph_lock
);
4076 return (&found_elm
->mkey_value
);
4079 key_elm
= (struct mptcp_key_entry
*)
4080 zalloc(mptcp_keys_pool
.mkph_key_entry_zone
);
4081 key_elm
->mkey_flags
= MKEYF_INUSE
;
4083 lck_mtx_lock(&mptcp_keys_pool
.mkph_lock
);
4084 mptcp_generate_unique_key(key_elm
);
4085 LIST_INSERT_HEAD(&mptcp_keys_pool
, key_elm
, mkey_next
);
4086 mptcp_keys_pool
.mkph_count
+= 1;
4087 lck_mtx_unlock(&mptcp_keys_pool
.mkph_lock
);
4088 return (&key_elm
->mkey_value
);
4092 mptcp_get_stored_digest(mptcp_key_t
*key
)
4094 struct mptcp_key_entry
*key_holder
;
4095 caddr_t digest
= NULL
;
4097 lck_mtx_lock(&mptcp_keys_pool
.mkph_lock
);
4098 key_holder
= (struct mptcp_key_entry
*)(void *)((caddr_t
)key
-
4099 offsetof(struct mptcp_key_entry
, mkey_value
));
4100 if (key_holder
->mkey_flags
!= MKEYF_INUSE
)
4101 panic_plain("%s", __func__
);
4102 digest
= &key_holder
->mkey_digest
[0];
4103 lck_mtx_unlock(&mptcp_keys_pool
.mkph_lock
);
4108 mptcp_free_key(mptcp_key_t
*key
)
4110 struct mptcp_key_entry
*key_holder
;
4111 struct mptcp_key_entry
*key_elm
;
4112 int pt
= RandomULong();
4114 lck_mtx_lock(&mptcp_keys_pool
.mkph_lock
);
4115 key_holder
= (struct mptcp_key_entry
*)(void*)((caddr_t
)key
-
4116 offsetof(struct mptcp_key_entry
, mkey_value
));
4117 key_holder
->mkey_flags
= MKEYF_FREE
;
4119 LIST_REMOVE(key_holder
, mkey_next
);
4120 mptcp_keys_pool
.mkph_count
-= 1;
4122 /* Free half the time */
4124 zfree(mptcp_keys_pool
.mkph_key_entry_zone
, key_holder
);
4126 /* Insert it at random point to avoid early reuse */
4128 if (mptcp_keys_pool
.mkph_count
> 1) {
4129 pt
= pt
% (mptcp_keys_pool
.mkph_count
- 1);
4130 LIST_FOREACH(key_elm
, &mptcp_keys_pool
, mkey_next
) {
4132 LIST_INSERT_AFTER(key_elm
, key_holder
,
4138 panic("missed insertion");
4140 LIST_INSERT_HEAD(&mptcp_keys_pool
, key_holder
,
4143 mptcp_keys_pool
.mkph_count
+= 1;
4145 lck_mtx_unlock(&mptcp_keys_pool
.mkph_lock
);
4149 mptcp_key_pool_init(void)
4152 struct mptcp_key_entry
*key_entry
;
4154 LIST_INIT(&mptcp_keys_pool
);
4155 mptcp_keys_pool
.mkph_count
= 0;
4157 mptcp_keys_pool
.mkph_key_elm_sz
= (vm_size_t
)
4158 (sizeof (struct mptcp_key_entry
));
4159 mptcp_keys_pool
.mkph_key_entry_zone
= zinit(
4160 mptcp_keys_pool
.mkph_key_elm_sz
,
4161 MPTCP_MX_KEY_ALLOCS
* mptcp_keys_pool
.mkph_key_elm_sz
,
4162 MPTCP_MX_PREALLOC_ZONE_SZ
, "mptkeys");
4163 if (mptcp_keys_pool
.mkph_key_entry_zone
== NULL
) {
4164 panic("%s: unable to allocate MPTCP keys zone \n", __func__
);
4167 zone_change(mptcp_keys_pool
.mkph_key_entry_zone
, Z_CALLERACCT
, FALSE
);
4168 zone_change(mptcp_keys_pool
.mkph_key_entry_zone
, Z_EXPAND
, TRUE
);
4170 for (i
= 0; i
< MPTCP_KEY_PREALLOCS_MX
; i
++) {
4171 key_entry
= (struct mptcp_key_entry
*)
4172 zalloc(mptcp_keys_pool
.mkph_key_entry_zone
);
4173 key_entry
->mkey_flags
= MKEYF_FREE
;
4174 mptcp_generate_unique_key(key_entry
);
4175 LIST_INSERT_HEAD(&mptcp_keys_pool
, key_entry
, mkey_next
);
4176 mptcp_keys_pool
.mkph_count
+= 1;
4178 lck_mtx_init(&mptcp_keys_pool
.mkph_lock
, mtcbinfo
.mppi_lock_grp
,
4179 mtcbinfo
.mppi_lock_attr
);
4183 * MPTCP Join support
4187 mptcp_attach_to_subf(struct socket
*so
, struct mptcb
*mp_tp
,
4190 struct tcpcb
*tp
= sototcpcb(so
);
4191 struct mptcp_subf_auth_entry
*sauth_entry
;
4192 MPT_LOCK_ASSERT_NOTHELD(mp_tp
);
4194 MPT_LOCK_SPIN(mp_tp
);
4195 tp
->t_mptcb
= mp_tp
;
4197 * The address ID of the first flow is implicitly 0.
4199 if (mp_tp
->mpt_state
== MPTCPS_CLOSED
) {
4200 tp
->t_local_aid
= 0;
4202 tp
->t_local_aid
= addr_id
;
4203 tp
->t_mpflags
|= (TMPF_PREESTABLISHED
| TMPF_JOINED_FLOW
);
4204 so
->so_flags
|= SOF_MP_SEC_SUBFLOW
;
4207 sauth_entry
= zalloc(mpt_subauth_zone
);
4208 sauth_entry
->msae_laddr_id
= tp
->t_local_aid
;
4209 sauth_entry
->msae_raddr_id
= 0;
4210 sauth_entry
->msae_raddr_rand
= 0;
4212 sauth_entry
->msae_laddr_rand
= RandomULong();
4213 if (sauth_entry
->msae_laddr_rand
== 0)
4215 MPT_LOCK_SPIN(mp_tp
);
4216 LIST_INSERT_HEAD(&mp_tp
->mpt_subauth_list
, sauth_entry
, msae_next
);
4221 mptcp_detach_mptcb_from_subf(struct mptcb
*mp_tp
, struct socket
*so
)
4223 struct mptcp_subf_auth_entry
*sauth_entry
;
4224 struct tcpcb
*tp
= NULL
;
4230 socket_unlock(so
, 0);
4235 LIST_FOREACH(sauth_entry
, &mp_tp
->mpt_subauth_list
, msae_next
) {
4236 if (sauth_entry
->msae_laddr_id
== tp
->t_local_aid
) {
4242 LIST_REMOVE(sauth_entry
, msae_next
);
4247 zfree(mpt_subauth_zone
, sauth_entry
);
4250 socket_unlock(so
, 0);
4254 mptcp_get_rands(mptcp_addr_id addr_id
, struct mptcb
*mp_tp
, u_int32_t
*lrand
,
4257 struct mptcp_subf_auth_entry
*sauth_entry
;
4258 MPT_LOCK_ASSERT_NOTHELD(mp_tp
);
4261 LIST_FOREACH(sauth_entry
, &mp_tp
->mpt_subauth_list
, msae_next
) {
4262 if (sauth_entry
->msae_laddr_id
== addr_id
) {
4264 *lrand
= sauth_entry
->msae_laddr_rand
;
4266 *rrand
= sauth_entry
->msae_raddr_rand
;
4274 mptcp_set_raddr_rand(mptcp_addr_id laddr_id
, struct mptcb
*mp_tp
,
4275 mptcp_addr_id raddr_id
, u_int32_t raddr_rand
)
4277 struct mptcp_subf_auth_entry
*sauth_entry
;
4278 MPT_LOCK_ASSERT_NOTHELD(mp_tp
);
4281 LIST_FOREACH(sauth_entry
, &mp_tp
->mpt_subauth_list
, msae_next
) {
4282 if (sauth_entry
->msae_laddr_id
== laddr_id
) {
4283 if ((sauth_entry
->msae_raddr_id
!= 0) &&
4284 (sauth_entry
->msae_raddr_id
!= raddr_id
)) {
4285 mptcplog((LOG_ERR
, "MPTCP Socket: %s mismatched"
4286 " address ids %d %d \n", __func__
, raddr_id
,
4287 sauth_entry
->msae_raddr_id
),
4288 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_LOG
);
4292 sauth_entry
->msae_raddr_id
= raddr_id
;
4293 if ((sauth_entry
->msae_raddr_rand
!= 0) &&
4294 (sauth_entry
->msae_raddr_rand
!= raddr_rand
)) {
4295 mptcplog((LOG_ERR
, "MPTCP Socket: "
4296 "%s: dup SYN_ACK %d %d \n",
4297 __func__
, raddr_rand
,
4298 sauth_entry
->msae_raddr_rand
),
4299 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_LOG
);
4303 sauth_entry
->msae_raddr_rand
= raddr_rand
;
4312 * SHA1 support for MPTCP
4315 mptcp_do_sha1(mptcp_key_t
*key
, char *sha_digest
, int digest_len
)
4318 const unsigned char *sha1_base
;
4321 if (digest_len
!= SHA1_RESULTLEN
) {
4325 sha1_base
= (const unsigned char *) key
;
4326 sha1_size
= sizeof (mptcp_key_t
);
4327 SHA1Init(&sha1ctxt
);
4328 SHA1Update(&sha1ctxt
, sha1_base
, sha1_size
);
4329 SHA1Final(sha_digest
, &sha1ctxt
);
4334 mptcp_hmac_sha1(mptcp_key_t key1
, mptcp_key_t key2
,
4335 u_int32_t rand1
, u_int32_t rand2
, u_char
*digest
, int digest_len
)
4338 mptcp_key_t key_ipad
[8] = {0}; /* key XOR'd with inner pad */
4339 mptcp_key_t key_opad
[8] = {0}; /* key XOR'd with outer pad */
4343 bzero(digest
, digest_len
);
4345 /* Set up the Key for HMAC */
4352 /* Set up the message for HMAC */
4356 /* Key is 512 block length, so no need to compute hash */
4358 /* Compute SHA1(Key XOR opad, SHA1(Key XOR ipad, data)) */
4360 for (i
= 0; i
< 8; i
++) {
4361 key_ipad
[i
] ^= 0x3636363636363636;
4362 key_opad
[i
] ^= 0x5c5c5c5c5c5c5c5c;
4365 /* Perform inner SHA1 */
4366 SHA1Init(&sha1ctxt
);
4367 SHA1Update(&sha1ctxt
, (unsigned char *)key_ipad
, sizeof (key_ipad
));
4368 SHA1Update(&sha1ctxt
, (unsigned char *)data
, sizeof (data
));
4369 SHA1Final(digest
, &sha1ctxt
);
4371 /* Perform outer SHA1 */
4372 SHA1Init(&sha1ctxt
);
4373 SHA1Update(&sha1ctxt
, (unsigned char *)key_opad
, sizeof (key_opad
));
4374 SHA1Update(&sha1ctxt
, (unsigned char *)digest
, SHA1_RESULTLEN
);
4375 SHA1Final(digest
, &sha1ctxt
);
4379 * corresponds to MAC-B = MAC (Key=(Key-B+Key-A), Msg=(R-B+R-A))
4380 * corresponds to MAC-A = MAC (Key=(Key-A+Key-B), Msg=(R-A+R-B))
4383 mptcp_get_hmac(mptcp_addr_id aid
, struct mptcb
*mp_tp
, u_char
*digest
,
4386 uint32_t lrand
, rrand
;
4387 mptcp_key_t localkey
, remotekey
;
4388 MPT_LOCK_ASSERT_NOTHELD(mp_tp
);
4390 if (digest_len
!= SHA1_RESULTLEN
)
4394 mptcp_get_rands(aid
, mp_tp
, &lrand
, &rrand
);
4395 MPT_LOCK_SPIN(mp_tp
);
4396 localkey
= *mp_tp
->mpt_localkey
;
4397 remotekey
= mp_tp
->mpt_remotekey
;
4399 mptcp_hmac_sha1(localkey
, remotekey
, lrand
, rrand
, digest
,
4404 mptcp_get_trunced_hmac(mptcp_addr_id aid
, struct mptcb
*mp_tp
)
4406 u_char digest
[SHA1_RESULTLEN
];
4407 u_int64_t trunced_digest
;
4409 mptcp_get_hmac(aid
, mp_tp
, &digest
[0], sizeof (digest
));
4410 bcopy(digest
, &trunced_digest
, 8);
4411 return (trunced_digest
);
4415 * Authentication data generation
4418 mptcp_generate_token(char *sha_digest
, int sha_digest_len
, caddr_t token
,
4421 VERIFY(token_len
== sizeof (u_int32_t
));
4422 VERIFY(sha_digest_len
== SHA1_RESULTLEN
);
4424 /* Most significant 32 bits of the SHA1 hash */
4425 bcopy(sha_digest
, token
, sizeof (u_int32_t
));
4430 mptcp_generate_idsn(char *sha_digest
, int sha_digest_len
, caddr_t idsn
,
4433 VERIFY(idsn_len
== sizeof (u_int64_t
));
4434 VERIFY(sha_digest_len
== SHA1_RESULTLEN
);
4437 * Least significant 64 bits of the SHA1 hash
4440 idsn
[7] = sha_digest
[12];
4441 idsn
[6] = sha_digest
[13];
4442 idsn
[5] = sha_digest
[14];
4443 idsn
[4] = sha_digest
[15];
4444 idsn
[3] = sha_digest
[16];
4445 idsn
[2] = sha_digest
[17];
4446 idsn
[1] = sha_digest
[18];
4447 idsn
[0] = sha_digest
[19];
4452 mptcp_conn_properties(struct mptcb
*mp_tp
)
4454 /* There is only Version 0 at this time */
4455 mp_tp
->mpt_version
= MPTCP_STD_VERSION_0
;
4457 /* Set DSS checksum flag */
4459 mp_tp
->mpt_flags
|= MPTCPF_CHECKSUM
;
4461 /* Set up receive window */
4462 mp_tp
->mpt_rcvwnd
= mptcp_sbspace(mp_tp
);
4464 /* Set up gc ticks */
4465 mp_tp
->mpt_gc_ticks
= MPT_GC_TICKS
;
4469 mptcp_init_local_parms(struct mptcb
*mp_tp
)
4471 caddr_t local_digest
= NULL
;
4473 mp_tp
->mpt_localkey
= mptcp_reserve_key();
4474 local_digest
= mptcp_get_stored_digest(mp_tp
->mpt_localkey
);
4475 mptcp_generate_token(local_digest
, SHA1_RESULTLEN
,
4476 (caddr_t
)&mp_tp
->mpt_localtoken
, sizeof (mp_tp
->mpt_localtoken
));
4477 mptcp_generate_idsn(local_digest
, SHA1_RESULTLEN
,
4478 (caddr_t
)&mp_tp
->mpt_local_idsn
, sizeof (u_int64_t
));
4480 /* The subflow SYN is also first MPTCP byte */
4481 mp_tp
->mpt_snduna
= mp_tp
->mpt_sndmax
= mp_tp
->mpt_local_idsn
+ 1;
4482 mp_tp
->mpt_sndnxt
= mp_tp
->mpt_snduna
;
4484 mptcp_conn_properties(mp_tp
);
4488 mptcp_init_remote_parms(struct mptcb
*mp_tp
)
4490 char remote_digest
[MPTCP_SHA1_RESULTLEN
];
4491 MPT_LOCK_ASSERT_HELD(mp_tp
);
4493 /* Only Version 0 is supported for auth purposes */
4494 if (mp_tp
->mpt_version
!= MPTCP_STD_VERSION_0
)
4497 /* Setup local and remote tokens and Initial DSNs */
4499 if (!mptcp_do_sha1(&mp_tp
->mpt_remotekey
, remote_digest
,
4501 mptcplog((LOG_ERR
, "MPTCP Socket: %s: unexpected failure",
4502 __func__
), MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_LOG
);
4505 mptcp_generate_token(remote_digest
, SHA1_RESULTLEN
,
4506 (caddr_t
)&mp_tp
->mpt_remotetoken
, sizeof (mp_tp
->mpt_remotetoken
));
4507 mptcp_generate_idsn(remote_digest
, SHA1_RESULTLEN
,
4508 (caddr_t
)&mp_tp
->mpt_remote_idsn
, sizeof (u_int64_t
));
4509 mp_tp
->mpt_rcvatmark
= mp_tp
->mpt_rcvnxt
= mp_tp
->mpt_remote_idsn
+ 1;
4518 mptcp_get_localtoken(void* mptcb_arg
)
4520 struct mptcb
*mp_tp
= (struct mptcb
*)mptcb_arg
;
4521 return (mp_tp
->mpt_localtoken
);
4525 mptcp_get_remotetoken(void* mptcb_arg
)
4527 struct mptcb
*mp_tp
= (struct mptcb
*)mptcb_arg
;
4528 return (mp_tp
->mpt_remotetoken
);
4532 mptcp_get_localkey(void* mptcb_arg
)
4534 struct mptcb
*mp_tp
= (struct mptcb
*)mptcb_arg
;
4535 if (mp_tp
->mpt_localkey
!= NULL
)
4536 return (*mp_tp
->mpt_localkey
);
4542 mptcp_get_remotekey(void* mptcb_arg
)
4544 struct mptcb
*mp_tp
= (struct mptcb
*)mptcb_arg
;
4545 return (mp_tp
->mpt_remotekey
);
4549 mptcp_send_dfin(struct socket
*so
)
4551 struct tcpcb
*tp
= NULL
;
4552 struct inpcb
*inp
= NULL
;
4554 inp
= sotoinpcb(so
);
4558 tp
= intotcpcb(inp
);
4562 if (!(tp
->t_mpflags
& TMPF_RESET
))
4563 tp
->t_mpflags
|= TMPF_SEND_DFIN
;
4567 * Data Sequence Mapping routines
4570 mptcp_insert_dsn(struct mppcb
*mpp
, struct mbuf
*m
)
4572 struct mptcb
*mp_tp
;
4577 __IGNORE_WCASTALIGN(mp_tp
= &((struct mpp_mtp
*)mpp
)->mtcb
);
4580 VERIFY(m
->m_flags
& M_PKTHDR
);
4581 m
->m_pkthdr
.pkt_flags
|= (PKTF_MPTCP
| PKTF_MPSO
);
4582 m
->m_pkthdr
.mp_dsn
= mp_tp
->mpt_sndmax
;
4583 m
->m_pkthdr
.mp_rlen
= m_pktlen(m
);
4584 mp_tp
->mpt_sndmax
+= m_pktlen(m
);
4591 mptcp_preproc_sbdrop(struct socket
*so
, struct mbuf
*m
, unsigned int len
)
4593 u_int32_t sub_len
= 0;
4596 if (so
->so_flags1
& SOF1_DATA_IDEMPOTENT
) {
4597 /* TFO makes things complicated. */
4598 if (so
->so_flags1
& SOF1_TFO_REWIND
) {
4600 so
->so_flags1
&= ~SOF1_TFO_REWIND
;
4605 VERIFY(m
->m_flags
& M_PKTHDR
);
4607 if (m
->m_pkthdr
.pkt_flags
& PKTF_MPTCP
) {
4608 sub_len
= m
->m_pkthdr
.mp_rlen
;
4610 if (sub_len
< len
) {
4611 m
->m_pkthdr
.mp_dsn
+= sub_len
;
4612 if (!(m
->m_pkthdr
.pkt_flags
& PKTF_MPSO
)) {
4613 m
->m_pkthdr
.mp_rseq
+= sub_len
;
4615 m
->m_pkthdr
.mp_rlen
= 0;
4618 /* sub_len >= len */
4620 m
->m_pkthdr
.mp_dsn
+= len
;
4621 if (!(m
->m_pkthdr
.pkt_flags
& PKTF_MPSO
)) {
4623 m
->m_pkthdr
.mp_rseq
+= len
;
4625 mptcplog((LOG_DEBUG
, "MPTCP Sender: "
4626 "%s: dsn 0x%llx ssn %u len %d %d\n",
4628 m
->m_pkthdr
.mp_dsn
, m
->m_pkthdr
.mp_rseq
,
4629 m
->m_pkthdr
.mp_rlen
, len
),
4630 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_VERBOSE
);
4631 m
->m_pkthdr
.mp_rlen
-= len
;
4635 panic("%s: MPTCP tag not set", __func__
);
4641 if (so
->so_flags
& SOF_MP_SUBFLOW
&&
4642 !(sototcpcb(so
)->t_mpflags
& TMPF_TFO_REQUEST
) &&
4643 !(sototcpcb(so
)->t_mpflags
& TMPF_RCVD_DACK
)) {
4645 * Received an ack without receiving a DATA_ACK.
4646 * Need to fallback to regular TCP (or destroy this subflow).
4648 mptcp_notify_mpfail(so
);
4652 /* Obtain the DSN mapping stored in the mbuf */
4654 mptcp_output_getm_dsnmap32(struct socket
*so
, int off
, uint32_t datalen
,
4655 u_int32_t
*dsn
, u_int32_t
*relseq
, u_int16_t
*data_len
, u_int64_t
*dsn64p
)
4659 mptcp_output_getm_dsnmap64(so
, off
, datalen
, &dsn64
, relseq
, data_len
);
4660 *dsn
= (u_int32_t
)MPTCP_DATASEQ_LOW32(dsn64
);
4665 mptcp_output_getm_dsnmap64(struct socket
*so
, int off
, uint32_t datalen
,
4666 u_int64_t
*dsn
, u_int32_t
*relseq
, u_int16_t
*data_len
)
4668 struct mbuf
*m
= so
->so_snd
.sb_mb
;
4669 struct mbuf
*mnext
= NULL
;
4670 uint32_t runlen
= 0;
4672 uint32_t contig_len
= 0;
4680 * In the subflow socket, the DSN sequencing can be discontiguous,
4681 * but the subflow sequence mapping is contiguous. Use the subflow
4682 * sequence property to find the right mbuf and corresponding dsn
4687 VERIFY(m
->m_pkthdr
.pkt_flags
& PKTF_MPTCP
);
4688 VERIFY(m
->m_flags
& M_PKTHDR
);
4690 if ((unsigned int)off
>= m
->m_pkthdr
.mp_rlen
) {
4691 off
-= m
->m_pkthdr
.mp_rlen
;
4699 panic("%s: bad offset", __func__
);
4703 dsn64
= m
->m_pkthdr
.mp_dsn
+ off
;
4705 *relseq
= m
->m_pkthdr
.mp_rseq
+ off
;
4708 * Now find the last contiguous byte and its length from
4711 runlen
= m
->m_pkthdr
.mp_rlen
- off
;
4712 contig_len
= runlen
;
4714 /* If datalen does not span multiple mbufs, return */
4715 if (datalen
<= runlen
) {
4716 *data_len
= min(datalen
, UINT16_MAX
);
4721 while (datalen
> runlen
) {
4722 if (mnext
== NULL
) {
4723 panic("%s: bad datalen = %d, %d %d", __func__
, datalen
,
4727 VERIFY(mnext
->m_flags
& M_PKTHDR
);
4728 VERIFY(mnext
->m_pkthdr
.pkt_flags
& PKTF_MPTCP
);
4731 * case A. contiguous DSN stream
4732 * case B. discontiguous DSN stream
4734 if (mnext
->m_pkthdr
.mp_dsn
== (dsn64
+ runlen
)) {
4736 runlen
+= mnext
->m_pkthdr
.mp_rlen
;
4737 contig_len
+= mnext
->m_pkthdr
.mp_rlen
;
4738 mptcplog((LOG_DEBUG
, "MPTCP Sender: %s: contig \n",
4739 __func__
), MPTCP_SENDER_DBG
, MPTCP_LOGLVL_VERBOSE
);
4742 mptcplog((LOG_DEBUG
, "MPTCP Sender: "
4743 "%s: discontig datalen %d contig_len %d cc %d \n",
4744 __func__
, datalen
, contig_len
, so
->so_snd
.sb_cc
),
4745 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_VERBOSE
);
4748 mnext
= mnext
->m_next
;
4750 datalen
= min(datalen
, UINT16_MAX
);
4751 *data_len
= min(datalen
, contig_len
);
4752 mptcplog((LOG_DEBUG
, "MPTCP Sender: "
4753 "%s: %llu %u %d %d \n", __func__
,
4754 *dsn
, *relseq
, *data_len
, off
),
4755 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_VERBOSE
);
4759 * MPTCP's notion of the next insequence Data Sequence number is adjusted
4760 * here. It must be called from mptcp_adj_rmap() which is called only after
4761 * reassembly of out of order data. The rcvnxt variable must
4762 * be updated only when atleast some insequence new data is received.
4765 mptcp_adj_rcvnxt(struct tcpcb
*tp
, struct mbuf
*m
)
4767 struct mptcb
*mp_tp
= tptomptp(tp
);
4772 if ((MPTCP_SEQ_GEQ(mp_tp
->mpt_rcvnxt
, m
->m_pkthdr
.mp_dsn
)) &&
4773 (MPTCP_SEQ_LEQ(mp_tp
->mpt_rcvnxt
, (m
->m_pkthdr
.mp_dsn
+
4774 m
->m_pkthdr
.mp_rlen
)))) {
4775 mp_tp
->mpt_rcvnxt
= m
->m_pkthdr
.mp_dsn
+ m
->m_pkthdr
.mp_rlen
;
4781 * Note that this is called only from tcp_input() via mptcp_input_preproc()
4782 * tcp_input() may trim data after the dsn mapping is inserted into the mbuf.
4783 * When it trims data tcp_input calls m_adj() which does not remove the
4784 * m_pkthdr even if the m_len becomes 0 as a result of trimming the mbuf.
4785 * The dsn map insertion cannot be delayed after trim, because data can be in
4786 * the reassembly queue for a while and the DSN option info in tp will be
4787 * overwritten for every new packet received.
4788 * The dsn map will be adjusted just prior to appending to subflow sockbuf
4789 * with mptcp_adj_rmap()
4792 mptcp_insert_rmap(struct tcpcb
*tp
, struct mbuf
*m
)
4794 VERIFY(!(m
->m_pkthdr
.pkt_flags
& PKTF_MPTCP
));
4796 if (tp
->t_mpflags
& TMPF_EMBED_DSN
) {
4797 VERIFY(m
->m_flags
& M_PKTHDR
);
4798 m
->m_pkthdr
.mp_dsn
= tp
->t_rcv_map
.mpt_dsn
;
4799 m
->m_pkthdr
.mp_rseq
= tp
->t_rcv_map
.mpt_sseq
;
4800 m
->m_pkthdr
.mp_rlen
= tp
->t_rcv_map
.mpt_len
;
4801 m
->m_pkthdr
.pkt_flags
|= PKTF_MPTCP
;
4802 tp
->t_mpflags
&= ~TMPF_EMBED_DSN
;
4803 tp
->t_mpflags
|= TMPF_MPTCP_ACKNOW
;
4808 mptcp_adj_rmap(struct socket
*so
, struct mbuf
*m
)
4811 u_int32_t sseq
, datalen
;
4812 struct tcpcb
*tp
= intotcpcb(sotoinpcb(so
));
4813 u_int32_t old_rcvnxt
= 0;
4815 if (m_pktlen(m
) == 0)
4818 if (m
->m_pkthdr
.pkt_flags
& PKTF_MPTCP
) {
4819 VERIFY(m
->m_flags
& M_PKTHDR
);
4821 dsn
= m
->m_pkthdr
.mp_dsn
;
4822 sseq
= m
->m_pkthdr
.mp_rseq
+ tp
->irs
;
4823 datalen
= m
->m_pkthdr
.mp_rlen
;
4825 /* data arrived without an DSS option mapping */
4827 /* initial subflow can fallback right after SYN handshake */
4828 mptcp_notify_mpfail(so
);
4832 /* In the common case, data is in window and in sequence */
4833 if (m
->m_pkthdr
.len
== (int)datalen
) {
4834 mptcp_adj_rcvnxt(tp
, m
);
4838 old_rcvnxt
= tp
->rcv_nxt
- m
->m_pkthdr
.len
;
4839 if (SEQ_GT(old_rcvnxt
, sseq
)) {
4840 /* data trimmed from the left */
4841 int off
= old_rcvnxt
- sseq
;
4842 m
->m_pkthdr
.mp_dsn
+= off
;
4843 m
->m_pkthdr
.mp_rseq
+= off
;
4844 m
->m_pkthdr
.mp_rlen
= m
->m_pkthdr
.len
;
4845 } else if (old_rcvnxt
== sseq
) {
4847 * data was trimmed from the right
4849 m
->m_pkthdr
.mp_rlen
= m
->m_pkthdr
.len
;
4851 mptcp_notify_mpfail(so
);
4854 mptcp_adj_rcvnxt(tp
, m
);
4859 * Following routines help with failure detection and failover of data
4860 * transfer from one subflow to another.
4863 mptcp_act_on_txfail(struct socket
*so
)
4865 struct tcpcb
*tp
= NULL
;
4866 struct inpcb
*inp
= sotoinpcb(so
);
4871 tp
= intotcpcb(inp
);
4875 if (so
->so_flags
& SOF_MP_TRYFAILOVER
) {
4879 so
->so_flags
|= SOF_MP_TRYFAILOVER
;
4880 soevent(so
, (SO_FILT_HINT_LOCKED
| SO_FILT_HINT_MPFAILOVER
));
4884 * Support for MP_FAIL option
4887 mptcp_get_map_for_dsn(struct socket
*so
, u_int64_t dsn_fail
, u_int32_t
*tcp_seq
)
4889 struct mbuf
*m
= so
->so_snd
.sb_mb
;
4898 VERIFY(m
->m_pkthdr
.pkt_flags
& PKTF_MPTCP
);
4899 VERIFY(m
->m_flags
& M_PKTHDR
);
4900 dsn
= m
->m_pkthdr
.mp_dsn
;
4901 datalen
= m
->m_pkthdr
.mp_rlen
;
4902 if (MPTCP_SEQ_LEQ(dsn
, dsn_fail
) &&
4903 (MPTCP_SEQ_GEQ(dsn
+ datalen
, dsn_fail
))) {
4904 off
= dsn_fail
- dsn
;
4905 *tcp_seq
= m
->m_pkthdr
.mp_rseq
+ off
;
4906 mptcplog((LOG_DEBUG
, "MPTCP Sender: %s: %llu %llu \n",
4907 __func__
, dsn
, dsn_fail
),
4908 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_LOG
);
4916 * If there was no mbuf data and a fallback to TCP occurred, there's
4917 * not much else to do.
4920 mptcplog((LOG_ERR
, "MPTCP Sender: "
4921 "%s: %llu not found \n", __func__
, dsn_fail
),
4922 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_LOG
);
4927 * Support for sending contiguous MPTCP bytes in subflow
4928 * Also for preventing sending data with ACK in 3-way handshake
4931 mptcp_adj_sendlen(struct socket
*so
, int32_t off
, int32_t len
)
4933 u_int64_t mdss_dsn
= 0;
4934 u_int32_t mdss_subflow_seq
= 0;
4935 u_int16_t mdss_data_len
= 0;
4940 mptcp_output_getm_dsnmap64(so
, off
, (u_int32_t
)len
,
4941 &mdss_dsn
, &mdss_subflow_seq
, &mdss_data_len
);
4944 * Special case handling for Fast Join. We want to send data right
4945 * after ACK of the 3-way handshake, but not piggyback the data
4946 * with the 3rd ACK of the 3WHS. TMPF_FASTJOINBY2_SEND and
4947 * mdss_data_len control this.
4949 struct tcpcb
*tp
= NULL
;
4950 tp
= intotcpcb(sotoinpcb(so
));
4951 if ((tp
->t_mpflags
& TMPF_JOINED_FLOW
) &&
4952 (tp
->t_mpflags
& TMPF_PREESTABLISHED
) &&
4953 (!(tp
->t_mpflags
& TMPF_RECVD_JOIN
)) &&
4954 (tp
->t_mpflags
& TMPF_SENT_JOIN
) &&
4955 (!(tp
->t_mpflags
& TMPF_MPTCP_TRUE
)) &&
4956 (!(tp
->t_mpflags
& TMPF_FASTJOINBY2_SEND
))) {
4958 tp
->t_mpflags
|= TMPF_FASTJOINBY2_SEND
;
4961 if ((tp
->t_state
> TCPS_SYN_SENT
) &&
4962 (tp
->t_mpflags
& TMPF_TFO_REQUEST
)) {
4964 tp
->t_mpflags
&= ~TMPF_TFO_REQUEST
;
4966 return (mdss_data_len
);
4970 mptcp_sbspace(struct mptcb
*mpt
)
4976 MPT_LOCK_ASSERT_HELD(mpt
);
4977 MPTE_LOCK_ASSERT_HELD(mpt
->mpt_mpte
);
4979 sb
= &mpt
->mpt_mpte
->mpte_mppcb
->mpp_socket
->so_rcv
;
4980 rcvbuf
= sb
->sb_hiwat
;
4981 space
= ((int32_t)imin((rcvbuf
- sb
->sb_cc
),
4982 (sb
->sb_mbmax
- sb
->sb_mbcnt
)));
4985 /* XXX check if it's too small? */
4991 * Support Fallback to Regular TCP
4994 mptcp_notify_mpready(struct socket
*so
)
4996 struct tcpcb
*tp
= NULL
;
5001 tp
= intotcpcb(sotoinpcb(so
));
5006 DTRACE_MPTCP4(multipath__ready
, struct socket
*, so
,
5007 struct sockbuf
*, &so
->so_rcv
, struct sockbuf
*, &so
->so_snd
,
5008 struct tcpcb
*, tp
);
5010 if (!(tp
->t_mpflags
& TMPF_MPTCP_TRUE
))
5013 if (tp
->t_mpflags
& TMPF_MPTCP_READY
)
5016 tp
->t_mpflags
&= ~TMPF_TCP_FALLBACK
;
5017 tp
->t_mpflags
|= TMPF_MPTCP_READY
;
5019 soevent(so
, (SO_FILT_HINT_LOCKED
| SO_FILT_HINT_MPSTATUS
));
5023 mptcp_notify_mpfail(struct socket
*so
)
5025 struct tcpcb
*tp
= NULL
;
5030 tp
= intotcpcb(sotoinpcb(so
));
5035 DTRACE_MPTCP4(multipath__failed
, struct socket
*, so
,
5036 struct sockbuf
*, &so
->so_rcv
, struct sockbuf
*, &so
->so_snd
,
5037 struct tcpcb
*, tp
);
5039 if (tp
->t_mpflags
& TMPF_TCP_FALLBACK
)
5042 tp
->t_mpflags
&= ~(TMPF_MPTCP_READY
|TMPF_MPTCP_TRUE
);
5043 tp
->t_mpflags
|= TMPF_TCP_FALLBACK
;
5045 soevent(so
, (SO_FILT_HINT_LOCKED
| SO_FILT_HINT_MPSTATUS
));
5049 * Keepalive helper function
5052 mptcp_ok_to_keepalive(struct mptcb
*mp_tp
)
5055 VERIFY(mp_tp
!= NULL
);
5057 if (mp_tp
->mpt_state
>= MPTCPS_CLOSE_WAIT
) {
5065 * MPTCP t_maxseg adjustment function
5068 mptcp_adj_mss(struct tcpcb
*tp
, boolean_t mtudisc
)
5071 struct mptcb
*mp_tp
= tptomptp(tp
);
5073 #define MPTCP_COMPUTE_LEN { \
5074 mss_lower = sizeof (struct mptcp_dss_ack_opt); \
5076 if (mp_tp->mpt_flags & MPTCPF_CHECKSUM) \
5079 /* adjust to 32-bit boundary + EOL */ \
5081 MPT_UNLOCK(mp_tp); \
5087 * For the first subflow and subsequent subflows, adjust mss for
5088 * most common MPTCP option size, for case where tcp_mss is called
5089 * during option processing and MTU discovery.
5091 if ((tp
->t_mpflags
& TMPF_PREESTABLISHED
) &&
5092 (!(tp
->t_mpflags
& TMPF_JOINED_FLOW
))) {
5096 if ((tp
->t_mpflags
& TMPF_PREESTABLISHED
) &&
5097 (tp
->t_mpflags
& TMPF_SENT_JOIN
)) {
5101 if ((mtudisc
) && (tp
->t_mpflags
& TMPF_MPTCP_TRUE
)) {
5109 * Update the pid, upid, uuid of the subflow so, based on parent so
5112 mptcp_update_last_owner(struct mptsub
*mpts
, struct socket
*parent_mpso
)
5114 struct socket
*subflow_so
= mpts
->mpts_socket
;
5116 MPTS_LOCK_ASSERT_HELD(mpts
);
5118 socket_lock(subflow_so
, 0);
5119 if ((subflow_so
->last_pid
!= parent_mpso
->last_pid
) ||
5120 (subflow_so
->last_upid
!= parent_mpso
->last_upid
)) {
5121 subflow_so
->last_upid
= parent_mpso
->last_upid
;
5122 subflow_so
->last_pid
= parent_mpso
->last_pid
;
5123 uuid_copy(subflow_so
->last_uuid
, parent_mpso
->last_uuid
);
5125 so_update_policy(subflow_so
);
5126 socket_unlock(subflow_so
, 0);
5130 fill_mptcp_subflow(struct socket
*so
, mptcp_flow_t
*flow
, struct mptsub
*mpts
)
5134 tcp_getconninfo(so
, &flow
->flow_ci
);
5135 inp
= sotoinpcb(so
);
5137 if ((inp
->inp_vflag
& INP_IPV6
) != 0) {
5138 flow
->flow_src
.ss_family
= AF_INET6
;
5139 flow
->flow_dst
.ss_family
= AF_INET6
;
5140 flow
->flow_src
.ss_len
= sizeof(struct sockaddr_in6
);
5141 flow
->flow_dst
.ss_len
= sizeof(struct sockaddr_in6
);
5142 SIN6(&flow
->flow_src
)->sin6_port
= inp
->in6p_lport
;
5143 SIN6(&flow
->flow_dst
)->sin6_port
= inp
->in6p_fport
;
5144 SIN6(&flow
->flow_src
)->sin6_addr
= inp
->in6p_laddr
;
5145 SIN6(&flow
->flow_dst
)->sin6_addr
= inp
->in6p_faddr
;
5148 if ((inp
->inp_vflag
& INP_IPV4
) != 0) {
5149 flow
->flow_src
.ss_family
= AF_INET
;
5150 flow
->flow_dst
.ss_family
= AF_INET
;
5151 flow
->flow_src
.ss_len
= sizeof(struct sockaddr_in
);
5152 flow
->flow_dst
.ss_len
= sizeof(struct sockaddr_in
);
5153 SIN(&flow
->flow_src
)->sin_port
= inp
->inp_lport
;
5154 SIN(&flow
->flow_dst
)->sin_port
= inp
->inp_fport
;
5155 SIN(&flow
->flow_src
)->sin_addr
= inp
->inp_laddr
;
5156 SIN(&flow
->flow_dst
)->sin_addr
= inp
->inp_faddr
;
5158 flow
->flow_len
= sizeof(*flow
);
5159 flow
->flow_tcpci_offset
= offsetof(mptcp_flow_t
, flow_ci
);
5160 flow
->flow_flags
= mpts
->mpts_flags
;
5161 flow
->flow_cid
= mpts
->mpts_connid
;
5162 flow
->flow_sndnxt
= mpts
->mpts_sndnxt
;
5163 flow
->flow_relseq
= mpts
->mpts_rel_seq
;
5164 flow
->flow_soerror
= mpts
->mpts_soerror
;
5165 flow
->flow_probecnt
= mpts
->mpts_probecnt
;
5166 flow
->flow_peerswitch
= mpts
->mpts_peerswitch
;
5170 mptcp_pcblist SYSCTL_HANDLER_ARGS
5172 #pragma unused(oidp, arg1, arg2)
5176 struct mptses
*mpte
;
5177 struct mptcb
*mp_tp
;
5178 struct mptsub
*mpts
;
5180 conninfo_mptcp_t mptcpci
;
5181 mptcp_flow_t
*flows
= NULL
;
5183 if (req
->newptr
!= USER_ADDR_NULL
)
5186 lck_mtx_lock(&mtcbinfo
.mppi_lock
);
5187 n
= mtcbinfo
.mppi_count
;
5188 if (req
->oldptr
== USER_ADDR_NULL
) {
5189 lck_mtx_unlock(&mtcbinfo
.mppi_lock
);
5190 req
->oldidx
= (n
+ n
/8) * sizeof(conninfo_mptcp_t
) +
5191 4 * (n
+ n
/8) * sizeof(mptcp_flow_t
);
5194 TAILQ_FOREACH(mpp
, &mtcbinfo
.mppi_pcbs
, mpp_entry
) {
5196 lck_mtx_lock(&mpp
->mpp_lock
);
5197 VERIFY(mpp
->mpp_flags
& MPP_ATTACHED
);
5198 if (mpp
->mpp_flags
& MPP_DEFUNCT
) {
5199 lck_mtx_unlock(&mpp
->mpp_lock
);
5202 mpte
= mptompte(mpp
);
5203 VERIFY(mpte
!= NULL
);
5204 mp_tp
= mpte
->mpte_mptcb
;
5205 VERIFY(mp_tp
!= NULL
);
5207 bzero(&mptcpci
, sizeof(mptcpci
));
5209 mptcpci
.mptcpci_state
= mp_tp
->mpt_state
;
5210 mptcpci
.mptcpci_flags
= mp_tp
->mpt_flags
;
5211 mptcpci
.mptcpci_ltoken
= mp_tp
->mpt_localtoken
;
5212 mptcpci
.mptcpci_rtoken
= mp_tp
->mpt_remotetoken
;
5213 mptcpci
.mptcpci_notsent_lowat
= mp_tp
->mpt_notsent_lowat
;
5214 mptcpci
.mptcpci_snduna
= mp_tp
->mpt_snduna
;
5215 mptcpci
.mptcpci_sndnxt
= mp_tp
->mpt_sndnxt
;
5216 mptcpci
.mptcpci_sndmax
= mp_tp
->mpt_sndmax
;
5217 mptcpci
.mptcpci_lidsn
= mp_tp
->mpt_local_idsn
;
5218 mptcpci
.mptcpci_sndwnd
= mp_tp
->mpt_sndwnd
;
5219 mptcpci
.mptcpci_rcvnxt
= mp_tp
->mpt_rcvnxt
;
5220 mptcpci
.mptcpci_rcvatmark
= mp_tp
->mpt_rcvatmark
;
5221 mptcpci
.mptcpci_ridsn
= mp_tp
->mpt_remote_idsn
;
5222 mptcpci
.mptcpci_rcvwnd
= mp_tp
->mpt_rcvwnd
;
5225 mptcpci
.mptcpci_nflows
= mpte
->mpte_numflows
;
5226 mptcpci
.mptcpci_mpte_flags
= mpte
->mpte_flags
;
5227 mptcpci
.mptcpci_mpte_addrid
= mpte
->mpte_addrid_last
;
5228 mptcpci
.mptcpci_flow_offset
=
5229 offsetof(conninfo_mptcp_t
, mptcpci_flows
);
5231 len
= sizeof(*flows
) * mpte
->mpte_numflows
;
5232 if (mpte
->mpte_numflows
!= 0) {
5233 flows
= _MALLOC(len
, M_TEMP
, M_WAITOK
| M_ZERO
);
5234 if (flows
== NULL
) {
5235 lck_mtx_unlock(&mpp
->mpp_lock
);
5238 mptcpci
.mptcpci_len
= sizeof(mptcpci
) +
5239 sizeof(*flows
) * (mptcpci
.mptcpci_nflows
- 1);
5240 error
= SYSCTL_OUT(req
, &mptcpci
,
5241 sizeof(mptcpci
) - sizeof(mptcp_flow_t
));
5243 mptcpci
.mptcpci_len
= sizeof(mptcpci
);
5244 error
= SYSCTL_OUT(req
, &mptcpci
, sizeof(mptcpci
));
5247 lck_mtx_unlock(&mpp
->mpp_lock
);
5248 FREE(flows
, M_TEMP
);
5252 TAILQ_FOREACH(mpts
, &mpte
->mpte_subflows
, mpts_entry
) {
5254 so
= mpts
->mpts_socket
;
5256 fill_mptcp_subflow(so
, &flows
[f
], mpts
);
5257 socket_unlock(so
, 0);
5261 lck_mtx_unlock(&mpp
->mpp_lock
);
5263 error
= SYSCTL_OUT(req
, flows
, len
);
5264 FREE(flows
, M_TEMP
);
5269 lck_mtx_unlock(&mtcbinfo
.mppi_lock
);
5274 SYSCTL_PROC(_net_inet_mptcp
, OID_AUTO
, pcblist
, CTLFLAG_RD
| CTLFLAG_LOCKED
,
5275 0, 0, mptcp_pcblist
, "S,conninfo_mptcp_t",
5276 "List of active MPTCP connections");
5279 * Check the health of the other subflows and do an mptcp_output if
5280 * there is no other active or functional subflow at the time of
5281 * call of this function.
5284 mptcp_output_needed(struct mptses
*mpte
, struct mptsub
*to_mpts
)
5286 struct mptsub
*from_mpts
= NULL
;
5288 MPTE_LOCK_ASSERT_HELD(mpte
);
5290 MPTS_UNLOCK(to_mpts
);
5292 from_mpts
= mpte
->mpte_active_sub
;
5294 if (from_mpts
== NULL
)
5297 MPTS_LOCK(from_mpts
);
5299 if ((from_mpts
->mpts_flags
& MPTSF_DISCONNECTED
) ||
5300 (from_mpts
->mpts_flags
& MPTSF_DISCONNECTING
)) {
5301 MPTS_UNLOCK(from_mpts
);
5305 MPTS_UNLOCK(from_mpts
);
5315 * Set notsent lowat mark on the MPTCB
5318 mptcp_set_notsent_lowat(struct mptses
*mpte
, int optval
)
5320 struct mptcb
*mp_tp
= NULL
;
5323 if (mpte
->mpte_mppcb
->mpp_flags
& MPP_ATTACHED
)
5324 mp_tp
= mpte
->mpte_mptcb
;
5327 mp_tp
->mpt_notsent_lowat
= optval
;
5335 mptcp_get_notsent_lowat(struct mptses
*mpte
)
5337 struct mptcb
*mp_tp
= NULL
;
5339 if (mpte
->mpte_mppcb
->mpp_flags
& MPP_ATTACHED
)
5340 mp_tp
= mpte
->mpte_mptcb
;
5343 return mp_tp
->mpt_notsent_lowat
;
5349 mptcp_notsent_lowat_check(struct socket
*so
) {
5350 struct mptses
*mpte
;
5352 struct mptcb
*mp_tp
;
5353 struct mptsub
*mpts
;
5357 mpp
= sotomppcb(so
);
5358 if (mpp
== NULL
|| mpp
->mpp_state
== MPPCB_STATE_DEAD
) {
5362 mpte
= mptompte(mpp
);
5363 mp_tp
= mpte
->mpte_mptcb
;
5366 notsent
= so
->so_snd
.sb_cc
;
5368 if ((notsent
== 0) ||
5369 ((notsent
- (mp_tp
->mpt_sndnxt
- mp_tp
->mpt_snduna
)) <=
5370 mp_tp
->mpt_notsent_lowat
)) {
5371 mptcplog((LOG_DEBUG
, "MPTCP Sender: "
5372 "lowat %d notsent %d actual %d \n",
5373 mp_tp
->mpt_notsent_lowat
, notsent
,
5374 notsent
- (mp_tp
->mpt_sndnxt
- mp_tp
->mpt_snduna
)),
5375 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_VERBOSE
);
5381 /* When Nagle's algorithm is not disabled, it is better
5382 * to wakeup the client even before there is atleast one
5383 * maxseg of data to write.
5385 TAILQ_FOREACH(mpts
, &mpte
->mpte_subflows
, mpts_entry
) {
5388 if (mpts
->mpts_flags
& MPTSF_ACTIVE
) {
5389 struct socket
*subf_so
= mpts
->mpts_socket
;
5390 socket_lock(subf_so
, 0);
5391 struct tcpcb
*tp
= intotcpcb(sotoinpcb(subf_so
));
5393 notsent
= so
->so_snd
.sb_cc
-
5394 (tp
->snd_nxt
- tp
->snd_una
);
5396 if ((tp
->t_flags
& TF_NODELAY
) == 0 &&
5397 notsent
> 0 && (notsent
<= (int)tp
->t_maxseg
)) {
5400 mptcplog((LOG_DEBUG
, "MPTCP Sender: lowat %d notsent %d"
5401 " nodelay false \n",
5402 mp_tp
->mpt_notsent_lowat
, notsent
),
5403 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_VERBOSE
);
5404 socket_unlock(subf_so
, 0);
5414 mptcp_get_rtt_measurement(struct mptsub
*mpts
, struct mptses
*mpte
)
5416 MPTE_LOCK_ASSERT_HELD(mpte
);
5417 MPTS_LOCK_ASSERT_HELD(mpts
);
5419 struct socket
*subflow_so
= mpts
->mpts_socket
;
5420 socket_lock(subflow_so
, 0);
5421 mpts
->mpts_srtt
= (intotcpcb(sotoinpcb(subflow_so
)))->t_srtt
;
5422 mpts
->mpts_rxtcur
= (intotcpcb(sotoinpcb(subflow_so
)))->t_rxtcur
;
5423 socket_unlock(subflow_so
, 0);
5426 /* Using Symptoms Advisory to detect poor WiFi or poor Cell */
5427 static kern_ctl_ref mptcp_kern_ctrl_ref
= NULL
;
5428 static uint32_t mptcp_kern_skt_inuse
= 0;
5429 symptoms_advisory_t mptcp_advisory
;
5432 mptcp_symptoms_ctl_connect(kern_ctl_ref kctlref
, struct sockaddr_ctl
*sac
,
5435 #pragma unused(kctlref, sac, unitinfo)
5437 * We don't need to do anything here. But we can atleast ensure
5438 * only one user opens the MPTCP_KERN_CTL_NAME control socket.
5440 if (OSCompareAndSwap(0, 1, &mptcp_kern_skt_inuse
))
5447 mptcp_symptoms_ctl_disconnect(kern_ctl_ref kctlref
, u_int32_t kcunit
,
5450 #pragma unused(kctlref, kcunit, unitinfo)
5451 if (OSCompareAndSwap(1, 0, &mptcp_kern_skt_inuse
)) {
5452 /* TBD needs to be locked if the size grows more than an int */
5453 bzero(&mptcp_advisory
, sizeof(mptcp_advisory
));
5462 mptcp_symptoms_ctl_send(kern_ctl_ref kctlref
, u_int32_t kcunit
, void *unitinfo
,
5463 mbuf_t m
, int flags
)
5465 #pragma unused(kctlref, kcunit, unitinfo, flags)
5466 symptoms_advisory_t
*sa
= NULL
;
5468 if (mbuf_pkthdr_len(m
) < sizeof(*sa
)) {
5473 if (mbuf_len(m
) >= sizeof(*sa
))
5478 if (mptcp_advisory
.sa_nwk_status_int
!= sa
->sa_nwk_status_int
) {
5480 * we could use this notification to notify all mptcp pcbs
5481 * of the change in network status. But its difficult to
5482 * define if sending REMOVE_ADDR or MP_PRIO is appropriate
5483 * given that these are only soft indicators of the network
5484 * state. Leaving this as TBD for now.
5488 if (sa
->sa_nwk_status
!= SYMPTOMS_ADVISORY_NOCOMMENT
) {
5489 mptcplog((LOG_DEBUG
, "MPTCP Events: %s wifi %d,%d cell %d,%d\n",
5490 __func__
, sa
->sa_wifi_status
, mptcp_advisory
.sa_wifi_status
,
5491 sa
->sa_cell_status
, mptcp_advisory
.sa_cell_status
),
5492 MPTCP_SOCKET_DBG
| MPTCP_EVENTS_DBG
,
5495 if ((sa
->sa_wifi_status
&
5496 (SYMPTOMS_ADVISORY_WIFI_BAD
| SYMPTOMS_ADVISORY_WIFI_OK
)) !=
5497 (SYMPTOMS_ADVISORY_WIFI_BAD
| SYMPTOMS_ADVISORY_WIFI_OK
)) {
5498 mptcp_advisory
.sa_wifi_status
= sa
->sa_wifi_status
;
5501 if ((sa
->sa_cell_status
&
5502 (SYMPTOMS_ADVISORY_CELL_BAD
| SYMPTOMS_ADVISORY_CELL_OK
)) !=
5503 (SYMPTOMS_ADVISORY_CELL_BAD
| SYMPTOMS_ADVISORY_CELL_OK
)) {
5504 mptcp_advisory
.sa_cell_status
= sa
->sa_cell_status
;
5507 mptcplog((LOG_DEBUG
, "MPTCP Events: %s NOCOMMENT "
5508 "wifi %d cell %d\n", __func__
,
5509 mptcp_advisory
.sa_wifi_status
,
5510 mptcp_advisory
.sa_cell_status
),
5511 MPTCP_SOCKET_DBG
| MPTCP_EVENTS_DBG
, MPTCP_LOGLVL_LOG
);
5517 mptcp_control_register(void)
5519 /* Set up the advisory control socket */
5520 struct kern_ctl_reg mptcp_kern_ctl
;
5522 bzero(&mptcp_kern_ctl
, sizeof(mptcp_kern_ctl
));
5523 strlcpy(mptcp_kern_ctl
.ctl_name
, MPTCP_KERN_CTL_NAME
,
5524 sizeof(mptcp_kern_ctl
.ctl_name
));
5525 mptcp_kern_ctl
.ctl_connect
= mptcp_symptoms_ctl_connect
;
5526 mptcp_kern_ctl
.ctl_disconnect
= mptcp_symptoms_ctl_disconnect
;
5527 mptcp_kern_ctl
.ctl_send
= mptcp_symptoms_ctl_send
;
5528 mptcp_kern_ctl
.ctl_flags
= CTL_FLAG_PRIVILEGED
;
5530 (void)ctl_register(&mptcp_kern_ctl
, &mptcp_kern_ctrl_ref
);
5534 mptcp_is_wifi_unusable(void)
5536 /* a false return val indicates there is no info or wifi is ok */
5537 return (mptcp_advisory
.sa_wifi_status
& SYMPTOMS_ADVISORY_WIFI_BAD
);
5541 mptcp_is_cell_unusable(void)
5543 /* a false return val indicates there is no info or cell is ok */
5544 return (mptcp_advisory
.sa_cell_status
& SYMPTOMS_ADVISORY_CELL_BAD
);
5548 mptcp_use_symptoms_hints(struct mptsub
* best
, struct mptsub
*second_best
)
5550 struct mptsub
*cellsub
= NULL
;
5551 struct mptsub
*wifisub
= NULL
;
5552 struct mptsub
*wiredsub
= NULL
;
5554 VERIFY ((best
!= NULL
) && (second_best
!= NULL
));
5556 if (!mptcp_use_symptomsd
)
5559 if (!mptcp_kern_skt_inuse
)
5563 * There could be devices with more than one wifi interface or
5564 * more than one wired or cell interfaces.
5565 * TBD: SymptomsD is unavailable on such platforms as of now.
5566 * Try to prefer best when possible in general.
5567 * Also, SymptomsD sends notifications about wifi only when it
5570 if (best
->mpts_linktype
& MPTSL_WIFI
)
5572 else if (best
->mpts_linktype
& MPTSL_CELL
)
5574 else if (best
->mpts_linktype
& MPTSL_WIRED
)
5578 * On platforms with wired paths, don't use hints about wifi or cell.
5579 * Currently, SymptomsD is not available on platforms with wired paths.
5584 if ((wifisub
== NULL
) && (second_best
->mpts_linktype
& MPTSL_WIFI
))
5585 wifisub
= second_best
;
5587 if ((cellsub
== NULL
) && (second_best
->mpts_linktype
& MPTSL_CELL
))
5588 cellsub
= second_best
;
5590 if ((wiredsub
== NULL
) && (second_best
->mpts_linktype
& MPTSL_WIRED
))
5591 wiredsub
= second_best
;
5593 if ((wifisub
== best
) && mptcp_is_wifi_unusable()) {
5594 tcpstat
.tcps_mp_sel_symtomsd
++;
5595 if (mptcp_is_cell_unusable()) {
5596 mptcplog((LOG_DEBUG
, "MPTCP Sender: SymptomsD hint"
5597 " suggests both Wifi and Cell are bad. Wired %s.",
5598 (wiredsub
== NULL
) ? "none" : "present"),
5599 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_LOG
);
5602 mptcplog((LOG_DEBUG
, "MPTCP Sender: SymptomsD hint"
5603 " suggests Wifi bad, Cell good. Wired %s.",
5604 (wiredsub
== NULL
) ? "none" : "present"),
5605 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_LOG
);
5606 return ((wiredsub
!= NULL
) ? wiredsub
: cellsub
);
5610 if ((cellsub
== best
) && (mptcp_is_cell_unusable())) {
5611 tcpstat
.tcps_mp_sel_symtomsd
++;
5612 if (mptcp_is_wifi_unusable()) {
5613 mptcplog((LOG_DEBUG
, "MPTCP Sender: SymptomsD hint"
5614 " suggests both Cell and Wifi are bad. Wired %s.",
5615 (wiredsub
== NULL
) ? "none" : "present"),
5616 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_LOG
);
5619 mptcplog((LOG_DEBUG
, "MPTCP Sender: SymptomsD hint"
5620 " suggests Cell bad, Wifi good. Wired %s.",
5621 (wiredsub
== NULL
) ? "none" : "present"),
5622 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_LOG
);
5623 return ((wiredsub
!= NULL
) ? wiredsub
: wifisub
);
5627 /* little is known about the state of the network or wifi is good */
5631 /* If TFO data is succesfully acked, it must be dropped from the mptcp so */
5633 mptcp_drop_tfo_data(struct mptses
*mpte
, struct mptsub
*mpts
, int *wakeup
)
5635 struct socket
*mp_so
= mpte
->mpte_mppcb
->mpp_socket
;
5636 struct socket
*so
= mpts
->mpts_socket
;
5637 struct tcpcb
*tp
= intotcpcb(sotoinpcb(so
));
5638 struct mptcb
*mp_tp
= mpte
->mpte_mptcb
;
5640 /* If data was sent with SYN, rewind state */
5641 if (tp
->t_tfo_stats
& TFO_S_SYN_DATA_ACKED
) {
5642 mpts
->mpts_flags
&= ~MPTSF_TFO_REQD
;
5643 tp
->t_mpflags
&= ~TMPF_TFO_REQUEST
;
5645 u_int64_t mp_droplen
= mpts
->mpts_sndnxt
- mp_tp
->mpt_snduna
;
5646 unsigned int tcp_droplen
= tp
->snd_una
- tp
->iss
- 1;
5647 VERIFY(mp_droplen
<= (UINT_MAX
));
5648 VERIFY(mp_droplen
>= tcp_droplen
);
5650 if (mp_droplen
> tcp_droplen
) {
5651 /* handle partial TCP ack */
5652 mp_so
->so_flags1
|= SOF1_TFO_REWIND
;
5653 mp_tp
->mpt_sndnxt
= mp_tp
->mpt_snduna
+ (mp_droplen
- tcp_droplen
);
5654 mpts
->mpts_sndnxt
= mp_tp
->mpt_sndnxt
;
5655 mp_droplen
= tcp_droplen
;
5657 /* all data on SYN was acked */
5658 mpts
->mpts_rel_seq
= 1;
5659 mp_tp
->mpt_sndnxt
= mp_tp
->mpt_snduna
;
5660 mpts
->mpts_sndnxt
= mp_tp
->mpt_snduna
;
5662 mp_tp
->mpt_sndmax
-= tcp_droplen
;
5665 if (mp_droplen
!= 0) {
5666 VERIFY(mp_so
->so_snd
.sb_mb
!= NULL
);
5667 sbdrop(&mp_so
->so_snd
, (int)mp_droplen
);
5671 mptcplog((LOG_ERR
, "MPTCP Sender: %s mp_so 0x%llx cid %d "
5672 "TFO tcp len %d mptcp len %d\n", __func__
,
5673 (u_int64_t
)VM_KERNEL_ADDRPERM(mp_so
), mpts
->mpts_connid
,
5674 tcp_droplen
, mp_droplen
),
5675 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_LOG
);