2 * Copyright (c) 2012-2018 Apple Inc. All rights reserved.
4 * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. The rights granted to you under the License
10 * may not be used to create, or enable the creation or redistribution of,
11 * unlawful or unlicensed copies of an Apple operating system, or to
12 * circumvent, violate, or enable the circumvention or violation of, any
13 * terms of an Apple operating system software license agreement.
15 * Please obtain a copy of the License at
16 * http://www.opensource.apple.com/apsl/ and read it before using this file.
18 * The Original Code and all software distributed under the License are
19 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23 * Please see the License for the specific language governing rights and
24 * limitations under the License.
26 * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
30 * A note on the MPTCP/NECP-interactions:
32 * MPTCP uses NECP-callbacks to get notified of interface/policy events.
33 * MPTCP registers to these events at the MPTCP-layer for interface-events
34 * through a call to necp_client_register_multipath_cb.
35 * To get per-flow events (aka per TCP-subflow), we register to it with
36 * necp_client_register_socket_flow. Both registrations happen by using the
37 * necp-client-uuid that comes from the app.
39 * The locking is rather tricky. In general, we expect the lock-ordering to
40 * happen from necp-fd -> necp->client -> mpp_lock.
42 * There are however some subtleties.
44 * 1. When registering the multipath_cb, we are holding the mpp_lock. This is
45 * safe, because it is the very first time this MPTCP-connection goes into NECP.
46 * As we go into NECP we take the NECP-locks and thus are guaranteed that no
47 * NECP-locks will deadlock us. Because these NECP-events will also first take
48 * the NECP-locks. Either they win the race and thus won't find our
49 * MPTCP-connection. Or, MPTCP wins the race and thus it will safely install
50 * the callbacks while holding the NECP lock.
52 * 2. When registering the subflow-callbacks we must unlock the mpp_lock. This,
53 * because we have already registered callbacks and we might race against an
54 * NECP-event that will match on our socket. So, we have to unlock to be safe.
56 * 3. When removing the multipath_cb, we do it in mp_pcbdispose(). The
57 * so_usecount has reached 0. We must be careful to not remove the mpp_socket
58 * pointers before we unregistered the callback. Because, again we might be
59 * racing against an NECP-event. Unregistering must happen with an unlocked
60 * mpp_lock, because of the lock-ordering constraint. It could be that
61 * before we had a chance to unregister an NECP-event triggers. That's why
62 * we need to check for the so_usecount in mptcp_session_necp_cb. If we get
63 * there while the socket is being garbage-collected, the use-count will go
64 * down to 0 and we exit. Removal of the multipath_cb again happens by taking
65 * the NECP-locks so any running NECP-events will finish first and exit cleanly.
67 * 4. When removing the subflow-callback, we do it in in_pcbdispose(). Again,
68 * the socket-lock must be unlocked for lock-ordering constraints. This gets a
69 * bit tricky here, as in tcp_garbage_collect we hold the mp_so and so lock.
70 * So, we drop the mp_so-lock as soon as the subflow is unlinked with
71 * mptcp_subflow_del. Then, in in_pcbdispose we drop the subflow-lock.
72 * If an NECP-event was waiting on the lock in mptcp_subflow_necp_cb, when it
73 * gets it, it will realize that the subflow became non-MPTCP and retry (see
74 * tcp_lock). Then it waits again on the subflow-lock. When we drop this lock
75 * in in_pcbdispose, and enter necp_inpcb_dispose, this one will have to wait
76 * for the NECP-lock (held by the other thread that is taking care of the NECP-
77 * event). So, the event now finally gets the subflow-lock and then hits an
78 * so_usecount that is 0 and exits. Eventually, we can remove the subflow from
82 #include <sys/param.h>
83 #include <sys/systm.h>
84 #include <sys/kernel.h>
86 #include <sys/mcache.h>
87 #include <sys/socket.h>
88 #include <sys/socketvar.h>
89 #include <sys/syslog.h>
90 #include <sys/protosw.h>
92 #include <kern/zalloc.h>
93 #include <kern/locks.h>
98 #include <netinet/in.h>
99 #include <netinet/in_var.h>
100 #include <netinet/tcp.h>
101 #include <netinet/tcp_fsm.h>
102 #include <netinet/tcp_seq.h>
103 #include <netinet/tcp_var.h>
104 #include <netinet/mptcp_var.h>
105 #include <netinet/mptcp.h>
106 #include <netinet/mptcp_seq.h>
107 #include <netinet/mptcp_opt.h>
108 #include <netinet/mptcp_timer.h>
110 int mptcp_enable
= 1;
111 SYSCTL_INT(_net_inet_mptcp
, OID_AUTO
, enable
, CTLFLAG_RW
| CTLFLAG_LOCKED
,
112 &mptcp_enable
, 0, "Enable Multipath TCP Support");
115 * Number of times to try negotiating MPTCP on SYN retransmissions.
116 * We haven't seen any reports of a middlebox that is dropping all SYN-segments
117 * that have an MPTCP-option. Thus, let's be generous and retransmit it 4 times.
119 int mptcp_mpcap_retries
= 4;
120 SYSCTL_INT(_net_inet_mptcp
, OID_AUTO
, mptcp_cap_retr
,
121 CTLFLAG_RW
| CTLFLAG_LOCKED
,
122 &mptcp_mpcap_retries
, 0, "Number of MP Capable SYN Retries");
125 * By default, DSS checksum is turned off, revisit if we ever do
126 * MPTCP for non SSL Traffic.
128 int mptcp_dss_csum
= 0;
129 SYSCTL_INT(_net_inet_mptcp
, OID_AUTO
, dss_csum
, CTLFLAG_RW
| CTLFLAG_LOCKED
,
130 &mptcp_dss_csum
, 0, "Enable DSS checksum");
133 * When mptcp_fail_thresh number of retransmissions are sent, subflow failover
134 * is attempted on a different path.
136 int mptcp_fail_thresh
= 1;
137 SYSCTL_INT(_net_inet_mptcp
, OID_AUTO
, fail
, CTLFLAG_RW
| CTLFLAG_LOCKED
,
138 &mptcp_fail_thresh
, 0, "Failover threshold");
142 * MPTCP subflows have TCP keepalives set to ON. Set a conservative keeptime
143 * as carrier networks mostly have a 30 minute to 60 minute NAT Timeout.
144 * Some carrier networks have a timeout of 10 or 15 minutes.
146 int mptcp_subflow_keeptime
= 60 * 14;
147 SYSCTL_INT(_net_inet_mptcp
, OID_AUTO
, keepalive
, CTLFLAG_RW
| CTLFLAG_LOCKED
,
148 &mptcp_subflow_keeptime
, 0, "Keepalive in seconds");
150 int mptcp_rtthist_rtthresh
= 600;
151 SYSCTL_INT(_net_inet_mptcp
, OID_AUTO
, rtthist_thresh
, CTLFLAG_RW
| CTLFLAG_LOCKED
,
152 &mptcp_rtthist_rtthresh
, 0, "Rtt threshold");
155 * Use RTO history for sending new data
157 int mptcp_use_rto
= 1;
158 SYSCTL_INT(_net_inet_mptcp
, OID_AUTO
, userto
, CTLFLAG_RW
| CTLFLAG_LOCKED
,
159 &mptcp_use_rto
, 0, "Disable RTO for subflow selection");
161 int mptcp_rtothresh
= 1500;
162 SYSCTL_INT(_net_inet_mptcp
, OID_AUTO
, rto_thresh
, CTLFLAG_RW
| CTLFLAG_LOCKED
,
163 &mptcp_rtothresh
, 0, "RTO threshold");
166 * Probe the preferred path, when it is not in use
168 uint32_t mptcp_probeto
= 1000;
169 SYSCTL_UINT(_net_inet_mptcp
, OID_AUTO
, probeto
, CTLFLAG_RW
| CTLFLAG_LOCKED
,
170 &mptcp_probeto
, 0, "Disable probing by setting to 0");
172 uint32_t mptcp_probecnt
= 5;
173 SYSCTL_UINT(_net_inet_mptcp
, OID_AUTO
, probecnt
, CTLFLAG_RW
| CTLFLAG_LOCKED
,
174 &mptcp_probecnt
, 0, "Number of probe writes");
177 * Static declarations
179 static uint16_t mptcp_input_csum(struct tcpcb
*, struct mbuf
*, uint64_t,
180 uint32_t, uint16_t, uint16_t, uint16_t);
183 mptcp_reass_present(struct socket
*mp_so
)
185 struct mptses
*mpte
= mpsotompte(mp_so
);
186 struct mptcb
*mp_tp
= mpte
->mpte_mptcb
;
192 * Present data to user, advancing rcv_nxt through
193 * completed sequence space.
195 if (mp_tp
->mpt_state
< MPTCPS_ESTABLISHED
) {
198 q
= LIST_FIRST(&mp_tp
->mpt_segq
);
199 if (!q
|| q
->tqe_m
->m_pkthdr
.mp_dsn
!= mp_tp
->mpt_rcvnxt
) {
204 * If there is already another thread doing reassembly for this
205 * connection, it is better to let it finish the job --
208 if (mp_tp
->mpt_flags
& MPTCPF_REASS_INPROG
) {
212 mp_tp
->mpt_flags
|= MPTCPF_REASS_INPROG
;
215 mp_tp
->mpt_rcvnxt
+= q
->tqe_len
;
216 LIST_REMOVE(q
, tqe_q
);
217 if (mp_so
->so_state
& SS_CANTRCVMORE
) {
220 flags
= !!(q
->tqe_m
->m_pkthdr
.pkt_flags
& PKTF_MPTCP_DFIN
);
221 if (sbappendstream_rcvdemux(mp_so
, q
->tqe_m
, 0, 0)) {
225 zfree(tcp_reass_zone
, q
);
226 mp_tp
->mpt_reassqlen
--;
227 q
= LIST_FIRST(&mp_tp
->mpt_segq
);
228 } while (q
&& q
->tqe_m
->m_pkthdr
.mp_dsn
== mp_tp
->mpt_rcvnxt
);
229 mp_tp
->mpt_flags
&= ~MPTCPF_REASS_INPROG
;
232 sorwakeup(mp_so
); /* done with socket lock held */
238 mptcp_reass(struct socket
*mp_so
, struct pkthdr
*phdr
, int *tlenp
, struct mbuf
*m
)
240 struct mptcb
*mp_tp
= mpsotomppcb(mp_so
)->mpp_pcbe
->mpte_mptcb
;
241 u_int64_t mb_dsn
= phdr
->mp_dsn
;
243 struct tseg_qent
*p
= NULL
;
244 struct tseg_qent
*nq
;
245 struct tseg_qent
*te
= NULL
;
249 * Limit the number of segments in the reassembly queue to prevent
250 * holding on to too many segments (and thus running out of mbufs).
251 * Make sure to let the missing segment through which caused this
252 * queue. Always keep one global queue entry spare to be able to
253 * process the missing segment.
255 qlimit
= min(max(100, mp_so
->so_rcv
.sb_hiwat
>> 10),
256 (tcp_autorcvbuf_max
>> 10));
257 if (mb_dsn
!= mp_tp
->mpt_rcvnxt
&&
258 (mp_tp
->mpt_reassqlen
+ 1) >= qlimit
) {
259 tcpstat
.tcps_mptcp_rcvmemdrop
++;
265 /* Allocate a new queue entry. If we can't, just drop the pkt. XXX */
266 te
= (struct tseg_qent
*) zalloc(tcp_reass_zone
);
268 tcpstat
.tcps_mptcp_rcvmemdrop
++;
273 mp_tp
->mpt_reassqlen
++;
276 * Find a segment which begins after this one does.
278 LIST_FOREACH(q
, &mp_tp
->mpt_segq
, tqe_q
) {
279 if (MPTCP_SEQ_GT(q
->tqe_m
->m_pkthdr
.mp_dsn
, mb_dsn
)) {
286 * If there is a preceding segment, it may provide some of
287 * our data already. If so, drop the data from the incoming
288 * segment. If it provides all of our data, drop us.
292 /* conversion to int (in i) handles seq wraparound */
293 i
= p
->tqe_m
->m_pkthdr
.mp_dsn
+ p
->tqe_len
- mb_dsn
;
296 tcpstat
.tcps_mptcp_rcvduppack
++;
298 zfree(tcp_reass_zone
, te
);
300 mp_tp
->mpt_reassqlen
--;
302 * Try to present any queued data
303 * at the left window edge to the user.
304 * This is needed after the 3-WHS
315 tcpstat
.tcps_mp_oodata
++;
318 * While we overlap succeeding segments trim them or,
319 * if they are completely covered, dequeue them.
322 int64_t i
= (mb_dsn
+ *tlenp
) - q
->tqe_m
->m_pkthdr
.mp_dsn
;
327 if (i
< q
->tqe_len
) {
328 q
->tqe_m
->m_pkthdr
.mp_dsn
+= i
;
334 nq
= LIST_NEXT(q
, tqe_q
);
335 LIST_REMOVE(q
, tqe_q
);
337 zfree(tcp_reass_zone
, q
);
338 mp_tp
->mpt_reassqlen
--;
342 /* Insert the new segment queue entry into place. */
345 te
->tqe_len
= *tlenp
;
348 LIST_INSERT_HEAD(&mp_tp
->mpt_segq
, te
, tqe_q
);
350 LIST_INSERT_AFTER(p
, te
, tqe_q
);
354 return mptcp_reass_present(mp_so
);
358 * MPTCP input, called when data has been read from a subflow socket.
361 mptcp_input(struct mptses
*mpte
, struct mbuf
*m
)
363 struct socket
*mp_so
;
364 struct mptcb
*mp_tp
= NULL
;
365 int count
= 0, wakeup
= 0;
366 struct mbuf
*save
= NULL
, *prev
= NULL
;
367 struct mbuf
*freelist
= NULL
, *tail
= NULL
;
369 VERIFY(m
->m_flags
& M_PKTHDR
);
371 mp_so
= mptetoso(mpte
);
372 mp_tp
= mpte
->mpte_mptcb
;
374 socket_lock_assert_owned(mp_so
);
378 mp_tp
->mpt_rcvwnd
= mptcp_sbspace(mp_tp
);
381 * Each mbuf contains MPTCP Data Sequence Map
382 * Process the data for reassembly, delivery to MPTCP socket
386 count
= mp_so
->so_rcv
.sb_cc
;
389 * In the degraded fallback case, data is accepted without DSS map
391 if (mp_tp
->mpt_flags
& MPTCPF_FALLBACK_TO_TCP
) {
395 mptcp_sbrcv_grow(mp_tp
);
399 if ((iter
->m_flags
& M_PKTHDR
) &&
400 (iter
->m_pkthdr
.pkt_flags
& PKTF_MPTCP_DFIN
)) {
404 if ((iter
->m_flags
& M_PKTHDR
) && m_pktlen(iter
) == 0) {
405 /* Don't add zero-length packets, so jump it! */
411 prev
->m_next
= iter
->m_next
;
416 /* It was a zero-length packet so next one must be a pkthdr */
417 VERIFY(iter
== NULL
|| iter
->m_flags
& M_PKTHDR
);
425 * assume degraded flow as this may be the first packet
426 * without DSS, and the subflow state is not updated yet.
428 if (sbappendstream_rcvdemux(mp_so
, m
, 0, 0)) {
432 DTRACE_MPTCP5(receive__degraded
, struct mbuf
*, m
,
433 struct socket
*, mp_so
,
434 struct sockbuf
*, &mp_so
->so_rcv
,
435 struct sockbuf
*, &mp_so
->so_snd
,
436 struct mptses
*, mpte
);
437 count
= mp_so
->so_rcv
.sb_cc
- count
;
439 mp_tp
->mpt_rcvnxt
+= count
;
442 mptcp_close_fsm(mp_tp
, MPCE_RECV_DATA_FIN
);
443 socantrcvmore(mp_so
);
454 VERIFY(m
->m_flags
& M_PKTHDR
);
456 /* If fallback occurs, mbufs will not have PKTF_MPTCP set */
457 if (!(m
->m_pkthdr
.pkt_flags
& PKTF_MPTCP
)) {
463 * A single TCP packet formed of multiple mbufs
464 * holds DSS mapping in the first mbuf of the chain.
465 * Other mbufs in the chain may have M_PKTHDR set
466 * even though they belong to the same TCP packet
467 * and therefore use the DSS mapping stored in the
468 * first mbuf of the mbuf chain. mptcp_input() can
469 * get an mbuf chain with multiple TCP packets.
471 while (save
&& (!(save
->m_flags
& M_PKTHDR
) ||
472 !(save
->m_pkthdr
.pkt_flags
& PKTF_MPTCP
))) {
482 mb_dsn
= m
->m_pkthdr
.mp_dsn
;
483 mb_datalen
= m
->m_pkthdr
.mp_rlen
;
485 todrop
= (mb_dsn
+ mb_datalen
) - (mp_tp
->mpt_rcvnxt
+ mp_tp
->mpt_rcvwnd
);
487 tcpstat
.tcps_mptcp_rcvpackafterwin
++;
489 os_log_info(mptcp_log_handle
, "%s - %lx: dropping dsn %u dlen %u rcvnxt %u rcvwnd %u todrop %lld\n",
490 __func__
, (unsigned long)VM_KERNEL_ADDRPERM(mpte
),
491 (uint32_t)mb_dsn
, mb_datalen
, (uint32_t)mp_tp
->mpt_rcvnxt
,
492 mp_tp
->mpt_rcvwnd
, todrop
);
494 if (todrop
>= mb_datalen
) {
495 if (freelist
== NULL
) {
512 mb_datalen
-= todrop
;
513 m
->m_pkthdr
.mp_rlen
-= todrop
;
517 * We drop from the right edge of the mbuf, thus the
518 * DATA_FIN is dropped as well
520 m
->m_pkthdr
.pkt_flags
&= ~PKTF_MPTCP_DFIN
;
523 if (MPTCP_SEQ_LT(mb_dsn
, mp_tp
->mpt_rcvnxt
)) {
524 if (MPTCP_SEQ_LEQ((mb_dsn
+ mb_datalen
),
525 mp_tp
->mpt_rcvnxt
)) {
526 if (freelist
== NULL
) {
542 m_adj(m
, (mp_tp
->mpt_rcvnxt
- mb_dsn
));
543 mb_datalen
-= (mp_tp
->mpt_rcvnxt
- mb_dsn
);
544 mb_dsn
= mp_tp
->mpt_rcvnxt
;
545 m
->m_pkthdr
.mp_rlen
= mb_datalen
;
546 m
->m_pkthdr
.mp_dsn
= mb_dsn
;
550 if (MPTCP_SEQ_GT(mb_dsn
, mp_tp
->mpt_rcvnxt
) ||
551 !LIST_EMPTY(&mp_tp
->mpt_segq
)) {
552 mb_dfin
= mptcp_reass(mp_so
, &m
->m_pkthdr
, &mb_datalen
, m
);
556 mb_dfin
= !!(m
->m_pkthdr
.pkt_flags
& PKTF_MPTCP_DFIN
);
558 mptcp_sbrcv_grow(mp_tp
);
560 if (sbappendstream_rcvdemux(mp_so
, m
, 0, 0)) {
564 DTRACE_MPTCP6(receive
, struct mbuf
*, m
, struct socket
*, mp_so
,
565 struct sockbuf
*, &mp_so
->so_rcv
,
566 struct sockbuf
*, &mp_so
->so_snd
,
567 struct mptses
*, mpte
,
568 struct mptcb
*, mp_tp
);
569 count
= mp_so
->so_rcv
.sb_cc
- count
;
570 tcpstat
.tcps_mp_rcvtotal
++;
571 tcpstat
.tcps_mp_rcvbytes
+= count
;
573 mp_tp
->mpt_rcvnxt
+= count
;
577 mptcp_close_fsm(mp_tp
, MPCE_RECV_DATA_FIN
);
578 socantrcvmore(mp_so
);
582 count
= mp_so
->so_rcv
.sb_cc
;
595 mptcp_can_send_more(struct mptcb
*mp_tp
, boolean_t ignore_reinject
)
597 struct socket
*mp_so
= mptetoso(mp_tp
->mpt_mpte
);
600 * Always send if there is data in the reinject-queue.
602 if (!ignore_reinject
&& mp_tp
->mpt_mpte
->mpte_reinjectq
) {
609 * 1. snd_nxt >= snd_max : Means, basically everything has been sent.
610 * Except when using TFO, we might be doing a 0-byte write.
611 * 2. snd_una + snd_wnd <= snd_nxt: No space in the receiver's window
612 * 3. snd_nxt + 1 == snd_max and we are closing: A DATA_FIN is scheduled.
615 if (!(mp_so
->so_flags1
& SOF1_PRECONNECT_DATA
) && MPTCP_SEQ_GEQ(mp_tp
->mpt_sndnxt
, mp_tp
->mpt_sndmax
)) {
619 if (MPTCP_SEQ_LEQ(mp_tp
->mpt_snduna
+ mp_tp
->mpt_sndwnd
, mp_tp
->mpt_sndnxt
)) {
623 if (mp_tp
->mpt_sndnxt
+ 1 == mp_tp
->mpt_sndmax
&& mp_tp
->mpt_state
> MPTCPS_CLOSE_WAIT
) {
627 if (mp_tp
->mpt_state
>= MPTCPS_FIN_WAIT_2
) {
638 mptcp_output(struct mptses
*mpte
)
642 struct mptsub
*mpts_tried
= NULL
;
643 struct socket
*mp_so
;
644 struct mptsub
*preferred_mpts
= NULL
;
645 uint64_t old_snd_nxt
;
648 mp_so
= mptetoso(mpte
);
649 socket_lock_assert_owned(mp_so
);
650 mp_tp
= mpte
->mpte_mptcb
;
652 VERIFY(!(mpte
->mpte_mppcb
->mpp_flags
& MPP_WUPCALL
));
653 mpte
->mpte_mppcb
->mpp_flags
|= MPP_WUPCALL
;
655 old_snd_nxt
= mp_tp
->mpt_sndnxt
;
656 while (mptcp_can_send_more(mp_tp
, FALSE
)) {
657 /* get the "best" subflow to be used for transmission */
658 mpts
= mptcp_get_subflow(mpte
, &preferred_mpts
);
660 mptcplog((LOG_INFO
, "%s: no subflow\n", __func__
),
661 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_LOG
);
665 /* In case there's just one flow, we reattempt later */
666 if (mpts_tried
!= NULL
&&
667 (mpts
== mpts_tried
|| (mpts
->mpts_flags
& MPTSF_FAILINGOVER
))) {
668 mpts_tried
->mpts_flags
&= ~MPTSF_FAILINGOVER
;
669 mpts_tried
->mpts_flags
|= MPTSF_ACTIVE
;
670 mptcp_start_timer(mpte
, MPTT_REXMT
);
675 * Automatic sizing of send socket buffer. Increase the send
676 * socket buffer size if all of the following criteria are met
677 * 1. the receiver has enough buffer space for this data
678 * 2. send buffer is filled to 7/8th with data (so we actually
679 * have data to make use of it);
681 if (tcp_do_autosendbuf
== 1 &&
682 (mp_so
->so_snd
.sb_flags
& (SB_AUTOSIZE
| SB_TRIM
)) == SB_AUTOSIZE
&&
683 tcp_cansbgrow(&mp_so
->so_snd
)) {
684 if ((mp_tp
->mpt_sndwnd
/ 4 * 5) >= mp_so
->so_snd
.sb_hiwat
&&
685 mp_so
->so_snd
.sb_cc
>= (mp_so
->so_snd
.sb_hiwat
/ 8 * 7)) {
686 if (sbreserve(&mp_so
->so_snd
,
687 min(mp_so
->so_snd
.sb_hiwat
+ tcp_autosndbuf_inc
,
688 tcp_autosndbuf_max
)) == 1) {
689 mp_so
->so_snd
.sb_idealsize
= mp_so
->so_snd
.sb_hiwat
;
694 DTRACE_MPTCP3(output
, struct mptses
*, mpte
, struct mptsub
*, mpts
,
695 struct socket
*, mp_so
);
696 error
= mptcp_subflow_output(mpte
, mpts
, 0);
698 /* can be a temporary loss of source address or other error */
699 mpts
->mpts_flags
|= MPTSF_FAILINGOVER
;
700 mpts
->mpts_flags
&= ~MPTSF_ACTIVE
;
702 if (error
!= ECANCELED
) {
703 os_log_error(mptcp_log_handle
, "%s - %lx: Error = %d mpts_flags %#x\n",
704 __func__
, (unsigned long)VM_KERNEL_ADDRPERM(mpte
),
705 error
, mpts
->mpts_flags
);
709 /* The model is to have only one active flow at a time */
710 mpts
->mpts_flags
|= MPTSF_ACTIVE
;
711 mpts
->mpts_probesoon
= mpts
->mpts_probecnt
= 0;
713 /* Allows us to update the smoothed rtt */
714 if (mptcp_probeto
&& mpts
!= preferred_mpts
&& preferred_mpts
!= NULL
) {
715 if (preferred_mpts
->mpts_probesoon
) {
716 if ((tcp_now
- preferred_mpts
->mpts_probesoon
) > mptcp_probeto
) {
717 mptcp_subflow_output(mpte
, preferred_mpts
, MPTCP_SUBOUT_PROBING
);
718 if (preferred_mpts
->mpts_probecnt
>= mptcp_probecnt
) {
719 preferred_mpts
->mpts_probesoon
= 0;
720 preferred_mpts
->mpts_probecnt
= 0;
724 preferred_mpts
->mpts_probesoon
= tcp_now
;
725 preferred_mpts
->mpts_probecnt
= 0;
729 if (mpte
->mpte_active_sub
== NULL
) {
730 mpte
->mpte_active_sub
= mpts
;
731 } else if (mpte
->mpte_active_sub
!= mpts
) {
732 mpte
->mpte_active_sub
->mpts_flags
&= ~MPTSF_ACTIVE
;
733 mpte
->mpte_active_sub
= mpts
;
735 mptcpstats_inc_switch(mpte
, mpts
);
739 if (mp_tp
->mpt_state
> MPTCPS_CLOSE_WAIT
) {
740 if (mp_tp
->mpt_sndnxt
+ 1 == mp_tp
->mpt_sndmax
&&
741 mp_tp
->mpt_snduna
== mp_tp
->mpt_sndnxt
) {
742 mptcp_finish_usrclosed(mpte
);
746 mptcp_handle_deferred_upcalls(mpte
->mpte_mppcb
, MPP_WUPCALL
);
748 /* subflow errors should not be percolated back up */
753 static struct mptsub
*
754 mptcp_choose_subflow(struct mptsub
*mpts
, struct mptsub
*curbest
, int *currtt
)
756 struct tcpcb
*tp
= sototcpcb(mpts
->mpts_socket
);
759 * Lower RTT? Take it, if it's our first one, or
760 * it doesn't has any loss, or the current one has
763 if (tp
->t_srtt
&& *currtt
> tp
->t_srtt
&&
764 (curbest
== NULL
|| tp
->t_rxtshift
== 0 ||
765 sototcpcb(curbest
->mpts_socket
)->t_rxtshift
)) {
766 *currtt
= tp
->t_srtt
;
771 * If we find a subflow without loss, take it always!
774 sototcpcb(curbest
->mpts_socket
)->t_rxtshift
&&
775 tp
->t_rxtshift
== 0) {
776 *currtt
= tp
->t_srtt
;
780 return curbest
!= NULL
? curbest
: mpts
;
783 static struct mptsub
*
784 mptcp_return_subflow(struct mptsub
*mpts
)
786 if (mpts
&& mptcp_subflow_cwnd_space(mpts
->mpts_socket
) <= 0) {
794 mptcp_subflow_is_slow(struct mptses
*mpte
, struct mptsub
*mpts
)
796 struct tcpcb
*tp
= sototcpcb(mpts
->mpts_socket
);
797 int fail_thresh
= mptcp_fail_thresh
;
799 if (mpte
->mpte_svctype
== MPTCP_SVCTYPE_HANDOVER
) {
803 return tp
->t_rxtshift
>= fail_thresh
&&
804 (mptetoso(mpte
)->so_snd
.sb_cc
|| mpte
->mpte_reinjectq
);
808 * Return the most eligible subflow to be used for sending data.
811 mptcp_get_subflow(struct mptses
*mpte
, struct mptsub
**preferred
)
813 struct tcpcb
*besttp
, *secondtp
;
814 struct inpcb
*bestinp
, *secondinp
;
816 struct mptsub
*best
= NULL
;
817 struct mptsub
*second_best
= NULL
;
818 int exp_rtt
= INT_MAX
, cheap_rtt
= INT_MAX
;
822 * Choose the best subflow for cellular and non-cellular interfaces.
825 TAILQ_FOREACH(mpts
, &mpte
->mpte_subflows
, mpts_entry
) {
826 struct socket
*so
= mpts
->mpts_socket
;
827 struct tcpcb
*tp
= sototcpcb(so
);
828 struct inpcb
*inp
= sotoinpcb(so
);
830 mptcplog((LOG_DEBUG
, "%s mpts %u mpts_flags %#x, suspended %u sostate %#x tpstate %u cellular %d rtt %u rxtshift %u cheap %u exp %u cwnd %d\n",
831 __func__
, mpts
->mpts_connid
, mpts
->mpts_flags
,
832 INP_WAIT_FOR_IF_FEEDBACK(inp
), so
->so_state
, tp
->t_state
,
833 inp
->inp_last_outifp
? IFNET_IS_CELLULAR(inp
->inp_last_outifp
) : -1,
834 tp
->t_srtt
, tp
->t_rxtshift
, cheap_rtt
, exp_rtt
,
835 mptcp_subflow_cwnd_space(so
)),
836 MPTCP_SOCKET_DBG
, MPTCP_LOGLVL_VERBOSE
);
839 * First, the hard conditions to reject subflows
840 * (e.g., not connected,...)
842 if (inp
->inp_last_outifp
== NULL
) {
846 if (INP_WAIT_FOR_IF_FEEDBACK(inp
)) {
850 /* There can only be one subflow in degraded state */
851 if (mpts
->mpts_flags
& MPTSF_MP_DEGRADED
) {
857 * If this subflow is waiting to finally send, do it!
859 if (so
->so_flags1
& SOF1_PRECONNECT_DATA
) {
860 return mptcp_return_subflow(mpts
);
864 * Only send if the subflow is MP_CAPABLE. The exceptions to
865 * this rule (degraded or TFO) have been taken care of above.
867 if (!(mpts
->mpts_flags
& MPTSF_MP_CAPABLE
)) {
871 if ((so
->so_state
& SS_ISDISCONNECTED
) ||
872 !(so
->so_state
& SS_ISCONNECTED
) ||
873 !TCPS_HAVEESTABLISHED(tp
->t_state
) ||
874 tp
->t_state
> TCPS_CLOSE_WAIT
) {
879 * Second, the soft conditions to find the subflow with best
880 * conditions for each set (aka cellular vs non-cellular)
882 if (IFNET_IS_CELLULAR(inp
->inp_last_outifp
)) {
883 second_best
= mptcp_choose_subflow(mpts
, second_best
,
886 best
= mptcp_choose_subflow(mpts
, best
, &cheap_rtt
);
891 * If there is no preferred or backup subflow, and there is no active
892 * subflow use the last usable subflow.
895 return mptcp_return_subflow(second_best
);
898 if (second_best
== NULL
) {
899 return mptcp_return_subflow(best
);
902 besttp
= sototcpcb(best
->mpts_socket
);
903 bestinp
= sotoinpcb(best
->mpts_socket
);
904 secondtp
= sototcpcb(second_best
->mpts_socket
);
905 secondinp
= sotoinpcb(second_best
->mpts_socket
);
907 if (preferred
!= NULL
) {
908 *preferred
= mptcp_return_subflow(best
);
912 * Second Step: Among best and second_best. Choose the one that is
913 * most appropriate for this particular service-type.
915 if (mpte
->mpte_svctype
== MPTCP_SVCTYPE_HANDOVER
) {
917 * Only handover if Symptoms tells us to do so.
919 if (!IFNET_IS_CELLULAR(bestinp
->inp_last_outifp
) &&
920 mptcp_is_wifi_unusable_for_session(mpte
) != 0 && mptcp_subflow_is_slow(mpte
, best
)) {
921 return mptcp_return_subflow(second_best
);
924 return mptcp_return_subflow(best
);
925 } else if (mpte
->mpte_svctype
== MPTCP_SVCTYPE_INTERACTIVE
) {
926 int rtt_thresh
= mptcp_rtthist_rtthresh
<< TCP_RTT_SHIFT
;
927 int rto_thresh
= mptcp_rtothresh
;
929 /* Adjust with symptoms information */
930 if (!IFNET_IS_CELLULAR(bestinp
->inp_last_outifp
) &&
931 mptcp_is_wifi_unusable_for_session(mpte
) != 0) {
936 if (besttp
->t_srtt
&& secondtp
->t_srtt
&&
937 besttp
->t_srtt
>= rtt_thresh
&&
938 secondtp
->t_srtt
< rtt_thresh
) {
939 tcpstat
.tcps_mp_sel_rtt
++;
940 mptcplog((LOG_DEBUG
, "%s: best cid %d at rtt %d, second cid %d at rtt %d\n", __func__
,
941 best
->mpts_connid
, besttp
->t_srtt
>> TCP_RTT_SHIFT
,
942 second_best
->mpts_connid
,
943 secondtp
->t_srtt
>> TCP_RTT_SHIFT
),
944 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_LOG
);
945 return mptcp_return_subflow(second_best
);
948 if (mptcp_subflow_is_slow(mpte
, best
) &&
949 secondtp
->t_rxtshift
== 0) {
950 return mptcp_return_subflow(second_best
);
953 /* Compare RTOs, select second_best if best's rto exceeds rtothresh */
954 if (besttp
->t_rxtcur
&& secondtp
->t_rxtcur
&&
955 besttp
->t_rxtcur
>= rto_thresh
&&
956 secondtp
->t_rxtcur
< rto_thresh
) {
957 tcpstat
.tcps_mp_sel_rto
++;
958 mptcplog((LOG_DEBUG
, "%s: best cid %d at rto %d, second cid %d at rto %d\n", __func__
,
959 best
->mpts_connid
, besttp
->t_rxtcur
,
960 second_best
->mpts_connid
, secondtp
->t_rxtcur
),
961 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_LOG
);
963 return mptcp_return_subflow(second_best
);
967 * None of the above conditions for sending on the secondary
968 * were true. So, let's schedule on the best one, if he still
969 * has some space in the congestion-window.
971 return mptcp_return_subflow(best
);
972 } else if (mpte
->mpte_svctype
>= MPTCP_SVCTYPE_AGGREGATE
) {
976 * We only care about RTT when aggregating
978 if (besttp
->t_srtt
> secondtp
->t_srtt
) {
985 secondtp
= sototcpcb(second_best
->mpts_socket
);
986 secondinp
= sotoinpcb(second_best
->mpts_socket
);
989 /* Is there still space in the congestion window? */
990 if (mptcp_subflow_cwnd_space(bestinp
->inp_socket
) <= 0) {
991 return mptcp_return_subflow(second_best
);
994 return mptcp_return_subflow(best
);
996 panic("Unknown service-type configured for MPTCP");
1003 mptcp_event_to_str(uint32_t event
)
1005 const char *c
= "UNDEFINED";
1010 case MPCE_RECV_DATA_ACK
:
1011 c
= "MPCE_RECV_DATA_ACK";
1013 case MPCE_RECV_DATA_FIN
:
1014 c
= "MPCE_RECV_DATA_FIN";
1021 mptcp_state_to_str(mptcp_state_t state
)
1023 const char *c
= "UNDEFINED";
1026 c
= "MPTCPS_CLOSED";
1029 c
= "MPTCPS_LISTEN";
1031 case MPTCPS_ESTABLISHED
:
1032 c
= "MPTCPS_ESTABLISHED";
1034 case MPTCPS_CLOSE_WAIT
:
1035 c
= "MPTCPS_CLOSE_WAIT";
1037 case MPTCPS_FIN_WAIT_1
:
1038 c
= "MPTCPS_FIN_WAIT_1";
1040 case MPTCPS_CLOSING
:
1041 c
= "MPTCPS_CLOSING";
1043 case MPTCPS_LAST_ACK
:
1044 c
= "MPTCPS_LAST_ACK";
1046 case MPTCPS_FIN_WAIT_2
:
1047 c
= "MPTCPS_FIN_WAIT_2";
1049 case MPTCPS_TIME_WAIT
:
1050 c
= "MPTCPS_TIME_WAIT";
1052 case MPTCPS_TERMINATE
:
1053 c
= "MPTCPS_TERMINATE";
1060 mptcp_close_fsm(struct mptcb
*mp_tp
, uint32_t event
)
1062 struct socket
*mp_so
= mptetoso(mp_tp
->mpt_mpte
);
1064 socket_lock_assert_owned(mp_so
);
1066 mptcp_state_t old_state
= mp_tp
->mpt_state
;
1068 DTRACE_MPTCP2(state__change
, struct mptcb
*, mp_tp
,
1071 switch (mp_tp
->mpt_state
) {
1074 mp_tp
->mpt_state
= MPTCPS_TERMINATE
;
1077 case MPTCPS_ESTABLISHED
:
1078 if (event
== MPCE_CLOSE
) {
1079 mp_tp
->mpt_state
= MPTCPS_FIN_WAIT_1
;
1080 mp_tp
->mpt_sndmax
+= 1; /* adjust for Data FIN */
1081 } else if (event
== MPCE_RECV_DATA_FIN
) {
1082 mp_tp
->mpt_rcvnxt
+= 1; /* adj remote data FIN */
1083 mp_tp
->mpt_state
= MPTCPS_CLOSE_WAIT
;
1087 case MPTCPS_CLOSE_WAIT
:
1088 if (event
== MPCE_CLOSE
) {
1089 mp_tp
->mpt_state
= MPTCPS_LAST_ACK
;
1090 mp_tp
->mpt_sndmax
+= 1; /* adjust for Data FIN */
1094 case MPTCPS_FIN_WAIT_1
:
1095 if (event
== MPCE_RECV_DATA_ACK
) {
1096 mp_tp
->mpt_state
= MPTCPS_FIN_WAIT_2
;
1097 } else if (event
== MPCE_RECV_DATA_FIN
) {
1098 mp_tp
->mpt_rcvnxt
+= 1; /* adj remote data FIN */
1099 mp_tp
->mpt_state
= MPTCPS_CLOSING
;
1103 case MPTCPS_CLOSING
:
1104 if (event
== MPCE_RECV_DATA_ACK
) {
1105 mp_tp
->mpt_state
= MPTCPS_TIME_WAIT
;
1109 case MPTCPS_LAST_ACK
:
1110 if (event
== MPCE_RECV_DATA_ACK
) {
1111 mptcp_close(mp_tp
->mpt_mpte
, mp_tp
);
1115 case MPTCPS_FIN_WAIT_2
:
1116 if (event
== MPCE_RECV_DATA_FIN
) {
1117 mp_tp
->mpt_rcvnxt
+= 1; /* adj remote data FIN */
1118 mp_tp
->mpt_state
= MPTCPS_TIME_WAIT
;
1122 case MPTCPS_TIME_WAIT
:
1123 case MPTCPS_TERMINATE
:
1130 DTRACE_MPTCP2(state__change
, struct mptcb
*, mp_tp
,
1132 mptcplog((LOG_INFO
, "%s: %s to %s on event %s\n", __func__
,
1133 mptcp_state_to_str(old_state
),
1134 mptcp_state_to_str(mp_tp
->mpt_state
),
1135 mptcp_event_to_str(event
)),
1136 MPTCP_STATE_DBG
, MPTCP_LOGLVL_LOG
);
1139 /* If you change this function, match up mptcp_update_rcv_state_f */
1141 mptcp_update_dss_rcv_state(struct mptcp_dsn_opt
*dss_info
, struct tcpcb
*tp
,
1144 struct mptcb
*mp_tp
= tptomptp(tp
);
1145 u_int64_t full_dsn
= 0;
1147 NTOHL(dss_info
->mdss_dsn
);
1148 NTOHL(dss_info
->mdss_subflow_seqn
);
1149 NTOHS(dss_info
->mdss_data_len
);
1151 /* XXX for autosndbuf grow sb here */
1152 MPTCP_EXTEND_DSN(mp_tp
->mpt_rcvnxt
, dss_info
->mdss_dsn
, full_dsn
);
1153 mptcp_update_rcv_state_meat(mp_tp
, tp
,
1154 full_dsn
, dss_info
->mdss_subflow_seqn
, dss_info
->mdss_data_len
,
1159 mptcp_update_rcv_state_meat(struct mptcb
*mp_tp
, struct tcpcb
*tp
,
1160 u_int64_t full_dsn
, u_int32_t seqn
, u_int16_t mdss_data_len
,
1163 if (mdss_data_len
== 0) {
1164 os_log_error(mptcp_log_handle
, "%s - %lx: Infinite Mapping.\n",
1165 __func__
, (unsigned long)VM_KERNEL_ADDRPERM(mp_tp
->mpt_mpte
));
1167 if ((mp_tp
->mpt_flags
& MPTCPF_CHECKSUM
) && (csum
!= 0)) {
1168 os_log_error(mptcp_log_handle
, "%s - %lx: Bad checksum %x \n",
1169 __func__
, (unsigned long)VM_KERNEL_ADDRPERM(mp_tp
->mpt_mpte
), csum
);
1171 mptcp_notify_mpfail(tp
->t_inpcb
->inp_socket
);
1175 mptcp_notify_mpready(tp
->t_inpcb
->inp_socket
);
1177 tp
->t_rcv_map
.mpt_dsn
= full_dsn
;
1178 tp
->t_rcv_map
.mpt_sseq
= seqn
;
1179 tp
->t_rcv_map
.mpt_len
= mdss_data_len
;
1180 tp
->t_rcv_map
.mpt_csum
= csum
;
1181 tp
->t_mpflags
|= TMPF_EMBED_DSN
;
1186 mptcp_validate_dss_map(struct socket
*so
, struct tcpcb
*tp
, struct mbuf
*m
,
1191 if (!(m
->m_pkthdr
.pkt_flags
& PKTF_MPTCP
)) {
1195 datalen
= m
->m_pkthdr
.mp_rlen
;
1197 /* unacceptable DSS option, fallback to TCP */
1198 if (m
->m_pkthdr
.len
> ((int) datalen
+ hdrlen
)) {
1199 os_log_error(mptcp_log_handle
, "%s - %lx: mbuf len %d, MPTCP expected %d",
1200 __func__
, (unsigned long)VM_KERNEL_ADDRPERM(tptomptp(tp
)->mpt_mpte
), m
->m_pkthdr
.len
, datalen
);
1204 tp
->t_mpflags
|= TMPF_SND_MPFAIL
;
1205 mptcp_notify_mpfail(so
);
1211 mptcp_input_preproc(struct tcpcb
*tp
, struct mbuf
*m
, struct tcphdr
*th
,
1214 mptcp_insert_rmap(tp
, m
, th
);
1215 if (mptcp_validate_dss_map(tp
->t_inpcb
->inp_socket
, tp
, m
,
1216 drop_hdrlen
) != 0) {
1223 * MPTCP Checksum support
1224 * The checksum is calculated whenever the MPTCP DSS option is included
1225 * in the TCP packet. The checksum includes the sum of the MPTCP psuedo
1226 * header and the actual data indicated by the length specified in the
1231 mptcp_validate_csum(struct tcpcb
*tp
, struct mbuf
*m
, uint64_t dsn
,
1232 uint32_t sseq
, uint16_t dlen
, uint16_t csum
, uint16_t dfin
)
1234 uint16_t mptcp_csum
;
1236 mptcp_csum
= mptcp_input_csum(tp
, m
, dsn
, sseq
, dlen
, csum
, dfin
);
1238 tp
->t_mpflags
|= TMPF_SND_MPFAIL
;
1239 mptcp_notify_mpfail(tp
->t_inpcb
->inp_socket
);
1241 tcpstat
.tcps_mp_badcsum
++;
1248 mptcp_input_csum(struct tcpcb
*tp
, struct mbuf
*m
, uint64_t dsn
, uint32_t sseq
,
1249 uint16_t dlen
, uint16_t csum
, uint16_t dfin
)
1251 struct mptcb
*mp_tp
= tptomptp(tp
);
1252 uint16_t real_len
= dlen
- dfin
;
1255 if (mp_tp
== NULL
) {
1259 if (!(mp_tp
->mpt_flags
& MPTCPF_CHECKSUM
)) {
1263 if (tp
->t_mpflags
& TMPF_TCP_FALLBACK
) {
1268 * The remote side may send a packet with fewer bytes than the
1269 * claimed DSS checksum length.
1271 if ((int)m_length2(m
, NULL
) < real_len
) {
1275 if (real_len
!= 0) {
1276 sum
= m_sum16(m
, 0, real_len
);
1279 sum
+= in_pseudo64(htonll(dsn
), htonl(sseq
), htons(dlen
) + csum
);
1281 DTRACE_MPTCP3(checksum__result
, struct tcpcb
*, tp
, struct mbuf
*, m
,
1284 mptcplog((LOG_DEBUG
, "%s: sum = %x \n", __func__
, sum
),
1285 MPTCP_RECEIVER_DBG
, MPTCP_LOGLVL_VERBOSE
);
1286 return ~sum
& 0xffff;
1290 mptcp_output_csum(struct mbuf
*m
, uint64_t dss_val
, uint32_t sseq
, uint16_t dlen
)
1295 sum
= m_sum16(m
, 0, dlen
);
1298 dss_val
= mptcp_hton64(dss_val
);
1301 sum
+= in_pseudo64(dss_val
, sseq
, dlen
);
1304 sum
= ~sum
& 0xffff;
1305 DTRACE_MPTCP2(checksum__result
, struct mbuf
*, m
, uint32_t, sum
);
1306 mptcplog((LOG_DEBUG
, "%s: sum = %x \n", __func__
, sum
),
1307 MPTCP_SENDER_DBG
, MPTCP_LOGLVL_VERBOSE
);
1313 * When WiFi signal starts fading, there's more loss and RTT spikes.
1314 * Check if there has been a large spike by comparing against
1315 * a tolerable RTT spike threshold.
1318 mptcp_no_rto_spike(struct socket
*so
)
1320 struct tcpcb
*tp
= intotcpcb(sotoinpcb(so
));
1323 if (tp
->t_rxtcur
> mptcp_rtothresh
) {
1324 spike
= tp
->t_rxtcur
- mptcp_rtothresh
;
1326 mptcplog((LOG_DEBUG
, "%s: spike = %d rto = %d best = %d cur = %d\n",
1328 tp
->t_rxtcur
, tp
->t_rttbest
>> TCP_RTT_SHIFT
,
1330 (MPTCP_SOCKET_DBG
| MPTCP_SENDER_DBG
), MPTCP_LOGLVL_LOG
);
1341 mptcp_handle_deferred_upcalls(struct mppcb
*mpp
, uint32_t flag
)
1343 VERIFY(mpp
->mpp_flags
& flag
);
1344 mpp
->mpp_flags
&= ~flag
;
1346 if (mptcp_should_defer_upcall(mpp
)) {
1350 if (mpp
->mpp_flags
& MPP_SHOULD_WORKLOOP
) {
1351 mpp
->mpp_flags
&= ~MPP_SHOULD_WORKLOOP
;
1353 mptcp_subflow_workloop(mpp
->mpp_pcbe
);
1356 if (mpp
->mpp_flags
& MPP_SHOULD_RWAKEUP
) {
1357 mpp
->mpp_flags
&= ~MPP_SHOULD_RWAKEUP
;
1359 sorwakeup(mpp
->mpp_socket
);
1362 if (mpp
->mpp_flags
& MPP_SHOULD_WWAKEUP
) {
1363 mpp
->mpp_flags
&= ~MPP_SHOULD_WWAKEUP
;
1365 sowwakeup(mpp
->mpp_socket
);
1370 mptcp_ask_for_nat64(struct ifnet
*ifp
)
1372 in6_post_msg(ifp
, KEV_INET6_REQUEST_NAT64_PREFIX
, NULL
, NULL
);
1374 os_log_info(mptcp_log_handle
,
1375 "%s: asked for NAT64-prefix on %s\n", __func__
,
1380 mptcp_reset_itfinfo(struct mpt_itf_info
*info
)
1382 memset(info
, 0, sizeof(*info
));
1386 mptcp_session_necp_cb(void *handle
, int action
, uint32_t interface_index
,
1387 uint32_t necp_flags
, __unused
bool *viable
)
1389 boolean_t has_v4
= !!(necp_flags
& NECP_CLIENT_RESULT_FLAG_HAS_IPV4
);
1390 boolean_t has_v6
= !!(necp_flags
& NECP_CLIENT_RESULT_FLAG_HAS_IPV6
);
1391 boolean_t has_nat64
= !!(necp_flags
& NECP_CLIENT_RESULT_FLAG_HAS_NAT64
);
1392 boolean_t low_power
= !!(necp_flags
& NECP_CLIENT_RESULT_FLAG_INTERFACE_LOW_POWER
);
1393 struct mppcb
*mp
= (struct mppcb
*)handle
;
1394 struct mptses
*mpte
= mptompte(mp
);
1395 struct socket
*mp_so
;
1396 struct mptcb
*mp_tp
;
1398 uint32_t i
, ifindex
;
1400 ifindex
= interface_index
;
1401 VERIFY(ifindex
!= IFSCOPE_NONE
);
1403 /* About to be garbage-collected (see note about MPTCP/NECP interactions) */
1404 if (mp
->mpp_socket
->so_usecount
== 0) {
1408 mp_so
= mptetoso(mpte
);
1410 if (action
!= NECP_CLIENT_CBACTION_INITIAL
) {
1411 socket_lock(mp_so
, 1);
1414 /* Check again, because it might have changed while waiting */
1415 if (mp
->mpp_socket
->so_usecount
== 0) {
1420 socket_lock_assert_owned(mp_so
);
1422 mp_tp
= mpte
->mpte_mptcb
;
1424 os_log_info(mptcp_log_handle
, "%s - %lx: action: %u ifindex %u usecount %u mpt_flags %#x state %u v4 %u v6 %u nat64 %u power %u\n",
1425 __func__
, (unsigned long)VM_KERNEL_ADDRPERM(mpte
), action
, ifindex
,
1426 mp
->mpp_socket
->so_usecount
, mp_tp
->mpt_flags
, mp_tp
->mpt_state
,
1427 has_v4
, has_v6
, has_nat64
, low_power
);
1429 /* No need on fallen back sockets */
1430 if (mp_tp
->mpt_flags
& MPTCPF_FALLBACK_TO_TCP
) {
1435 * When the interface goes in low-power mode we don't want to establish
1436 * new subflows on it. Thus, mark it internally as non-viable.
1439 action
= NECP_CLIENT_CBACTION_NONVIABLE
;
1442 if (action
== NECP_CLIENT_CBACTION_NONVIABLE
) {
1443 for (i
= 0; i
< mpte
->mpte_itfinfo_size
; i
++) {
1444 if (mpte
->mpte_itfinfo
[i
].ifindex
== IFSCOPE_NONE
) {
1448 if (mpte
->mpte_itfinfo
[i
].ifindex
== ifindex
) {
1449 mptcp_reset_itfinfo(&mpte
->mpte_itfinfo
[i
]);
1453 mptcp_sched_create_subflows(mpte
);
1454 } else if (action
== NECP_CLIENT_CBACTION_VIABLE
||
1455 action
== NECP_CLIENT_CBACTION_INITIAL
) {
1456 int found_slot
= 0, slot_index
= -1;
1457 struct sockaddr
*dst
;
1460 ifnet_head_lock_shared();
1461 ifp
= ifindex2ifnet
[ifindex
];
1468 if (IFNET_IS_EXPENSIVE(ifp
) &&
1469 (mp_so
->so_restrictions
& SO_RESTRICT_DENY_EXPENSIVE
)) {
1473 if (IFNET_IS_CONSTRAINED(ifp
) &&
1474 (mp_so
->so_restrictions
& SO_RESTRICT_DENY_CONSTRAINED
)) {
1478 if (IFNET_IS_CELLULAR(ifp
) &&
1479 (mp_so
->so_restrictions
& SO_RESTRICT_DENY_CELLULAR
)) {
1483 if (IS_INTF_CLAT46(ifp
)) {
1487 /* Look for the slot on where to store/update the interface-info. */
1488 for (i
= 0; i
< mpte
->mpte_itfinfo_size
; i
++) {
1489 /* Found a potential empty slot where we can put it */
1490 if (mpte
->mpte_itfinfo
[i
].ifindex
== 0) {
1496 * The interface is already in our array. Check if we
1497 * need to update it.
1499 if (mpte
->mpte_itfinfo
[i
].ifindex
== ifindex
&&
1500 (mpte
->mpte_itfinfo
[i
].has_v4_conn
!= has_v4
||
1501 mpte
->mpte_itfinfo
[i
].has_v6_conn
!= has_v6
||
1502 mpte
->mpte_itfinfo
[i
].has_nat64_conn
!= has_nat64
)) {
1508 if (mpte
->mpte_itfinfo
[i
].ifindex
== ifindex
) {
1510 * Ok, it's already there and we don't need
1517 dst
= mptcp_get_session_dst(mpte
, has_v6
, has_v4
);
1518 if (dst
&& (dst
->sa_family
== AF_INET
|| dst
->sa_family
== 0) &&
1519 has_v6
&& !has_nat64
&& !has_v4
) {
1521 mpte
->mpte_itfinfo
[slot_index
].has_v4_conn
= has_v4
;
1522 mpte
->mpte_itfinfo
[slot_index
].has_v6_conn
= has_v6
;
1523 mpte
->mpte_itfinfo
[slot_index
].has_nat64_conn
= has_nat64
;
1525 mptcp_ask_for_nat64(ifp
);
1529 if (found_slot
== 0) {
1530 int new_size
= mpte
->mpte_itfinfo_size
* 2;
1531 struct mpt_itf_info
*info
= _MALLOC(sizeof(*info
) * new_size
, M_TEMP
, M_ZERO
);
1534 os_log_error(mptcp_log_handle
, "%s - %lx: malloc failed for %u\n",
1535 __func__
, (unsigned long)VM_KERNEL_ADDRPERM(mpte
), new_size
);
1539 memcpy(info
, mpte
->mpte_itfinfo
, mpte
->mpte_itfinfo_size
* sizeof(*info
));
1541 if (mpte
->mpte_itfinfo_size
> MPTE_ITFINFO_SIZE
) {
1542 _FREE(mpte
->mpte_itfinfo
, M_TEMP
);
1545 /* We allocated a new one, thus the first must be empty */
1546 slot_index
= mpte
->mpte_itfinfo_size
;
1548 mpte
->mpte_itfinfo
= info
;
1549 mpte
->mpte_itfinfo_size
= new_size
;
1552 VERIFY(slot_index
>= 0 && slot_index
< (int)mpte
->mpte_itfinfo_size
);
1553 mpte
->mpte_itfinfo
[slot_index
].ifindex
= ifindex
;
1554 mpte
->mpte_itfinfo
[slot_index
].has_v4_conn
= has_v4
;
1555 mpte
->mpte_itfinfo
[slot_index
].has_v6_conn
= has_v6
;
1556 mpte
->mpte_itfinfo
[slot_index
].has_nat64_conn
= has_nat64
;
1558 mptcp_sched_create_subflows(mpte
);
1563 socket_unlock(mp_so
, 1);
1568 mptcp_set_restrictions(struct socket
*mp_so
)
1570 struct mptses
*mpte
= mpsotompte(mp_so
);
1573 socket_lock_assert_owned(mp_so
);
1575 ifnet_head_lock_shared();
1577 for (i
= 0; i
< mpte
->mpte_itfinfo_size
; i
++) {
1578 struct mpt_itf_info
*info
= &mpte
->mpte_itfinfo
[i
];
1579 uint32_t ifindex
= info
->ifindex
;
1582 if (ifindex
== IFSCOPE_NONE
) {
1586 ifp
= ifindex2ifnet
[ifindex
];
1591 if (IFNET_IS_EXPENSIVE(ifp
) &&
1592 (mp_so
->so_restrictions
& SO_RESTRICT_DENY_EXPENSIVE
)) {
1593 info
->ifindex
= IFSCOPE_NONE
;
1596 if (IFNET_IS_CONSTRAINED(ifp
) &&
1597 (mp_so
->so_restrictions
& SO_RESTRICT_DENY_CONSTRAINED
)) {
1598 info
->ifindex
= IFSCOPE_NONE
;
1601 if (IFNET_IS_CELLULAR(ifp
) &&
1602 (mp_so
->so_restrictions
& SO_RESTRICT_DENY_CELLULAR
)) {
1603 info
->ifindex
= IFSCOPE_NONE
;