1 /* 2 * sysctl_net_ipv6.c: sysctl interface to net IPV6 subsystem. 3 * 4 * Changes: 5 * YOSHIFUJI Hideaki @USAGI: added icmp sysctl table. 6 */ 7 8 #include <linux/mm.h> 9 #include <linux/sysctl.h> 10 #include <linux/in6.h> 11 #include <linux/ipv6.h> 12 #include <linux/slab.h> 13 #include <linux/export.h> 14 #include <net/ndisc.h> 15 #include <net/ipv6.h> 16 #include <net/addrconf.h> 17 #include <net/inet_frag.h> 18 #ifdef CONFIG_NETLABEL 19 #include <net/calipso.h> 20 #endif 21 22 static int one = 1; 23 static int auto_flowlabels_min; 24 static int auto_flowlabels_max = IP6_AUTO_FLOW_LABEL_MAX; 25 26 27 static struct ctl_table ipv6_table_template[] = { 28 { 29 .procname = "bindv6only", 30 .data = &init_net.ipv6.sysctl.bindv6only, 31 .maxlen = sizeof(int), 32 .mode = 0644, 33 .proc_handler = proc_dointvec 34 }, 35 { 36 .procname = "anycast_src_echo_reply", 37 .data = &init_net.ipv6.sysctl.anycast_src_echo_reply, 38 .maxlen = sizeof(int), 39 .mode = 0644, 40 .proc_handler = proc_dointvec 41 }, 42 { 43 .procname = "flowlabel_consistency", 44 .data = &init_net.ipv6.sysctl.flowlabel_consistency, 45 .maxlen = sizeof(int), 46 .mode = 0644, 47 .proc_handler = proc_dointvec 48 }, 49 { 50 .procname = "auto_flowlabels", 51 .data = &init_net.ipv6.sysctl.auto_flowlabels, 52 .maxlen = sizeof(int), 53 .mode = 0644, 54 .proc_handler = proc_dointvec_minmax, 55 .extra1 = &auto_flowlabels_min, 56 .extra2 = &auto_flowlabels_max 57 }, 58 { 59 .procname = "fwmark_reflect", 60 .data = &init_net.ipv6.sysctl.fwmark_reflect, 61 .maxlen = sizeof(int), 62 .mode = 0644, 63 .proc_handler = proc_dointvec 64 }, 65 { 66 .procname = "idgen_retries", 67 .data = &init_net.ipv6.sysctl.idgen_retries, 68 .maxlen = sizeof(int), 69 .mode = 0644, 70 .proc_handler = proc_dointvec, 71 }, 72 { 73 .procname = "idgen_delay", 74 .data = &init_net.ipv6.sysctl.idgen_delay, 75 .maxlen = sizeof(int), 76 .mode = 0644, 77 .proc_handler = proc_dointvec_jiffies, 78 }, 79 { 80 .procname = "flowlabel_state_ranges", 81 .data = &init_net.ipv6.sysctl.flowlabel_state_ranges, 82 .maxlen = sizeof(int), 83 .mode = 0644, 84 .proc_handler = proc_dointvec 85 }, 86 { 87 .procname = "ip_nonlocal_bind", 88 .data = &init_net.ipv6.sysctl.ip_nonlocal_bind, 89 .maxlen = sizeof(int), 90 .mode = 0644, 91 .proc_handler = proc_dointvec 92 }, 93 { 94 .procname = "flowlabel_reflect", 95 .data = &init_net.ipv6.sysctl.flowlabel_reflect, 96 .maxlen = sizeof(int), 97 .mode = 0644, 98 .proc_handler = proc_dointvec, 99 }, 100 { } 101 }; 102 103 static struct ctl_table ipv6_rotable[] = { 104 { 105 .procname = "mld_max_msf", 106 .data = &sysctl_mld_max_msf, 107 .maxlen = sizeof(int), 108 .mode = 0644, 109 .proc_handler = proc_dointvec 110 }, 111 { 112 .procname = "mld_qrv", 113 .data = &sysctl_mld_qrv, 114 .maxlen = sizeof(int), 115 .mode = 0644, 116 .proc_handler = proc_dointvec_minmax, 117 .extra1 = &one 118 }, 119 #ifdef CONFIG_NETLABEL 120 { 121 .procname = "calipso_cache_enable", 122 .data = &calipso_cache_enabled, 123 .maxlen = sizeof(int), 124 .mode = 0644, 125 .proc_handler = proc_dointvec, 126 }, 127 { 128 .procname = "calipso_cache_bucket_size", 129 .data = &calipso_cache_bucketsize, 130 .maxlen = sizeof(int), 131 .mode = 0644, 132 .proc_handler = proc_dointvec, 133 }, 134 #endif /* CONFIG_NETLABEL */ 135 { } 136 }; 137 138 static int __net_init ipv6_sysctl_net_init(struct net *net) 139 { 140 struct ctl_table *ipv6_table; 141 struct ctl_table *ipv6_route_table; 142 struct ctl_table *ipv6_icmp_table; 143 int err; 144 145 err = -ENOMEM; 146 ipv6_table = kmemdup(ipv6_table_template, sizeof(ipv6_table_template), 147 GFP_KERNEL); 148 if (!ipv6_table) 149 goto out; 150 ipv6_table[0].data = &net->ipv6.sysctl.bindv6only; 151 ipv6_table[1].data = &net->ipv6.sysctl.anycast_src_echo_reply; 152 ipv6_table[2].data = &net->ipv6.sysctl.flowlabel_consistency; 153 ipv6_table[3].data = &net->ipv6.sysctl.auto_flowlabels; 154 ipv6_table[4].data = &net->ipv6.sysctl.fwmark_reflect; 155 ipv6_table[5].data = &net->ipv6.sysctl.idgen_retries; 156 ipv6_table[6].data = &net->ipv6.sysctl.idgen_delay; 157 ipv6_table[7].data = &net->ipv6.sysctl.flowlabel_state_ranges; 158 ipv6_table[8].data = &net->ipv6.sysctl.ip_nonlocal_bind; 159 ipv6_table[9].data = &net->ipv6.sysctl.flowlabel_reflect; 160 161 ipv6_route_table = ipv6_route_sysctl_init(net); 162 if (!ipv6_route_table) 163 goto out_ipv6_table; 164 165 ipv6_icmp_table = ipv6_icmp_sysctl_init(net); 166 if (!ipv6_icmp_table) 167 goto out_ipv6_route_table; 168 169 net->ipv6.sysctl.hdr = register_net_sysctl(net, "net/ipv6", ipv6_table); 170 if (!net->ipv6.sysctl.hdr) 171 goto out_ipv6_icmp_table; 172 173 net->ipv6.sysctl.route_hdr = 174 register_net_sysctl(net, "net/ipv6/route", ipv6_route_table); 175 if (!net->ipv6.sysctl.route_hdr) 176 goto out_unregister_ipv6_table; 177 178 net->ipv6.sysctl.icmp_hdr = 179 register_net_sysctl(net, "net/ipv6/icmp", ipv6_icmp_table); 180 if (!net->ipv6.sysctl.icmp_hdr) 181 goto out_unregister_route_table; 182 183 err = 0; 184 out: 185 return err; 186 out_unregister_route_table: 187 unregister_net_sysctl_table(net->ipv6.sysctl.route_hdr); 188 out_unregister_ipv6_table: 189 unregister_net_sysctl_table(net->ipv6.sysctl.hdr); 190 out_ipv6_icmp_table: 191 kfree(ipv6_icmp_table); 192 out_ipv6_route_table: 193 kfree(ipv6_route_table); 194 out_ipv6_table: 195 kfree(ipv6_table); 196 goto out; 197 } 198 199 static void __net_exit ipv6_sysctl_net_exit(struct net *net) 200 { 201 struct ctl_table *ipv6_table; 202 struct ctl_table *ipv6_route_table; 203 struct ctl_table *ipv6_icmp_table; 204 205 ipv6_table = net->ipv6.sysctl.hdr->ctl_table_arg; 206 ipv6_route_table = net->ipv6.sysctl.route_hdr->ctl_table_arg; 207 ipv6_icmp_table = net->ipv6.sysctl.icmp_hdr->ctl_table_arg; 208 209 unregister_net_sysctl_table(net->ipv6.sysctl.icmp_hdr); 210 unregister_net_sysctl_table(net->ipv6.sysctl.route_hdr); 211 unregister_net_sysctl_table(net->ipv6.sysctl.hdr); 212 213 kfree(ipv6_table); 214 kfree(ipv6_route_table); 215 kfree(ipv6_icmp_table); 216 } 217 218 static struct pernet_operations ipv6_sysctl_net_ops = { 219 .init = ipv6_sysctl_net_init, 220 .exit = ipv6_sysctl_net_exit, 221 }; 222 223 static struct ctl_table_header *ip6_header; 224 225 int ipv6_sysctl_register(void) 226 { 227 int err = -ENOMEM; 228 229 ip6_header = register_net_sysctl(&init_net, "net/ipv6", ipv6_rotable); 230 if (!ip6_header) 231 goto out; 232 233 err = register_pernet_subsys(&ipv6_sysctl_net_ops); 234 if (err) 235 goto err_pernet; 236 out: 237 return err; 238 239 err_pernet: 240 unregister_net_sysctl_table(ip6_header); 241 goto out; 242 } 243 244 void ipv6_sysctl_unregister(void) 245 { 246 unregister_net_sysctl_table(ip6_header); 247 unregister_pernet_subsys(&ipv6_sysctl_net_ops); 248 } 249