xref: /freebsd/sys/netinet6/in6_proto.c (revision 5861f9665471e98e544f6fa3ce73c4912229ff82)
1 /*-
2  * Copyright (C) 1995, 1996, 1997, and 1998 WIDE Project.
3  * All rights reserved.
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  * 1. Redistributions of source code must retain the above copyright
9  *    notice, this list of conditions and the following disclaimer.
10  * 2. Redistributions in binary form must reproduce the above copyright
11  *    notice, this list of conditions and the following disclaimer in the
12  *    documentation and/or other materials provided with the distribution.
13  * 3. Neither the name of the project nor the names of its contributors
14  *    may be used to endorse or promote products derived from this software
15  *    without specific prior written permission.
16  *
17  * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
18  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
19  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
20  * ARE DISCLAIMED.  IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
21  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
22  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
23  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
24  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
25  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
26  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
27  * SUCH DAMAGE.
28  *
29  *	$KAME: in6_proto.c,v 1.91 2001/05/27 13:28:35 itojun Exp $
30  */
31 
32 /*-
33  * Copyright (c) 1982, 1986, 1993
34  *	The Regents of the University of California.  All rights reserved.
35  *
36  * Redistribution and use in source and binary forms, with or without
37  * modification, are permitted provided that the following conditions
38  * are met:
39  * 1. Redistributions of source code must retain the above copyright
40  *    notice, this list of conditions and the following disclaimer.
41  * 2. Redistributions in binary form must reproduce the above copyright
42  *    notice, this list of conditions and the following disclaimer in the
43  *    documentation and/or other materials provided with the distribution.
44  * 4. Neither the name of the University nor the names of its contributors
45  *    may be used to endorse or promote products derived from this software
46  *    without specific prior written permission.
47  *
48  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
49  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
50  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
51  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
52  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
53  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
54  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
55  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
56  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
57  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
58  * SUCH DAMAGE.
59  *
60  *	@(#)in_proto.c	8.1 (Berkeley) 6/10/93
61  */
62 
63 #include <sys/cdefs.h>
64 __FBSDID("$FreeBSD$");
65 
66 #include "opt_inet.h"
67 #include "opt_inet6.h"
68 #include "opt_ipsec.h"
69 #include "opt_ipstealth.h"
70 #include "opt_carp.h"
71 #include "opt_sctp.h"
72 #include "opt_mpath.h"
73 
74 #include <sys/param.h>
75 #include <sys/socket.h>
76 #include <sys/socketvar.h>
77 #include <sys/proc.h>
78 #include <sys/protosw.h>
79 #include <sys/jail.h>
80 #include <sys/kernel.h>
81 #include <sys/domain.h>
82 #include <sys/mbuf.h>
83 #include <sys/systm.h>
84 #include <sys/sysctl.h>
85 #include <sys/vimage.h>
86 
87 #include <net/if.h>
88 #include <net/radix.h>
89 #include <net/route.h>
90 #ifdef RADIX_MPATH
91 #include <net/radix_mpath.h>
92 #endif
93 
94 #include <netinet/in.h>
95 #include <netinet/in_systm.h>
96 #include <netinet/in_var.h>
97 #include <netinet/ip_encap.h>
98 #include <netinet/ip.h>
99 #include <netinet/ip_var.h>
100 #include <netinet/ip6.h>
101 #include <netinet6/ip6_var.h>
102 #include <netinet/icmp6.h>
103 
104 #include <netinet/tcp.h>
105 #include <netinet/tcp_timer.h>
106 #include <netinet/tcp_var.h>
107 #include <netinet/udp.h>
108 #include <netinet/udp_var.h>
109 #include <netinet6/tcp6_var.h>
110 #include <netinet6/raw_ip6.h>
111 #include <netinet6/udp6_var.h>
112 #include <netinet6/pim6_var.h>
113 #include <netinet6/nd6.h>
114 
115 #ifdef DEV_CARP
116 #include <netinet/ip_carp.h>
117 #endif
118 
119 #ifdef SCTP
120 #include <netinet/in_pcb.h>
121 #include <netinet/sctp_pcb.h>
122 #include <netinet/sctp.h>
123 #include <netinet/sctp_var.h>
124 #include <netinet6/sctp6_var.h>
125 #endif /* SCTP */
126 
127 #ifdef IPSEC
128 #include <netipsec/ipsec.h>
129 #include <netipsec/ipsec6.h>
130 #endif /* IPSEC */
131 
132 #include <netinet6/ip6protosw.h>
133 #include <netinet6/vinet6.h>
134 
135 /*
136  * TCP/IP protocol family: IP6, ICMP6, UDP, TCP.
137  */
138 
139 extern	struct domain inet6domain;
140 static	struct pr_usrreqs nousrreqs;
141 
142 #define PR_LISTEN	0
143 #define PR_ABRTACPTDIS	0
144 
145 struct ip6protosw inet6sw[] = {
146 {
147 	.pr_type =		0,
148 	.pr_domain =		&inet6domain,
149 	.pr_protocol =		IPPROTO_IPV6,
150 	.pr_init =		ip6_init,
151 #ifdef VIMAGE
152 	.pr_destroy =		ip6_destroy,
153 #endif
154 	.pr_slowtimo =		frag6_slowtimo,
155 	.pr_drain =		frag6_drain,
156 	.pr_usrreqs =		&nousrreqs,
157 },
158 {
159 	.pr_type =		SOCK_DGRAM,
160 	.pr_domain =		&inet6domain,
161 	.pr_protocol =		IPPROTO_UDP,
162 	.pr_flags =		PR_ATOMIC|PR_ADDR,
163 	.pr_input =		udp6_input,
164 	.pr_ctlinput =		udp6_ctlinput,
165 	.pr_ctloutput =		ip6_ctloutput,
166 	.pr_usrreqs =		&udp6_usrreqs,
167 },
168 {
169 	.pr_type =		SOCK_STREAM,
170 	.pr_domain =		&inet6domain,
171 	.pr_protocol =		IPPROTO_TCP,
172 	.pr_flags =		PR_CONNREQUIRED|PR_WANTRCVD|PR_LISTEN,
173 	.pr_input =		tcp6_input,
174 	.pr_ctlinput =		tcp6_ctlinput,
175 	.pr_ctloutput =		tcp_ctloutput,
176 #ifndef INET	/* don't call initialization and timeout routines twice */
177 	.pr_init =		tcp_init,
178 	.pr_fasttimo =		tcp_fasttimo,
179 	.pr_slowtimo =		tcp_slowtimo,
180 #endif
181 	.pr_drain =		tcp_drain,
182 	.pr_usrreqs =		&tcp6_usrreqs,
183 },
184 #ifdef SCTP
185 {
186 	.pr_type =	SOCK_DGRAM,
187 	.pr_domain =	&inet6domain,
188         .pr_protocol =	IPPROTO_SCTP,
189         .pr_flags =	PR_WANTRCVD,
190         .pr_input =	sctp6_input,
191         .pr_ctlinput =  sctp6_ctlinput,
192         .pr_ctloutput = sctp_ctloutput,
193         .pr_drain =	sctp_drain,
194         .pr_usrreqs =	&sctp6_usrreqs
195 },
196 {
197 	.pr_type =	SOCK_SEQPACKET,
198 	.pr_domain =	&inet6domain,
199         .pr_protocol =	IPPROTO_SCTP,
200         .pr_flags =	PR_WANTRCVD,
201         .pr_input =	sctp6_input,
202         .pr_ctlinput =  sctp6_ctlinput,
203         .pr_ctloutput = sctp_ctloutput,
204         .pr_drain =	sctp_drain,
205         .pr_usrreqs =	&sctp6_usrreqs
206 },
207 
208 {
209 	.pr_type =	SOCK_STREAM,
210 	.pr_domain =	&inet6domain,
211         .pr_protocol =	IPPROTO_SCTP,
212         .pr_flags =	PR_WANTRCVD,
213         .pr_input =	sctp6_input,
214         .pr_ctlinput =  sctp6_ctlinput,
215         .pr_ctloutput = sctp_ctloutput,
216         .pr_drain =	sctp_drain,
217         .pr_usrreqs =	&sctp6_usrreqs
218 },
219 #endif /* SCTP */
220 {
221 	.pr_type =		SOCK_RAW,
222 	.pr_domain =		&inet6domain,
223 	.pr_protocol =		IPPROTO_RAW,
224 	.pr_flags =		PR_ATOMIC|PR_ADDR,
225 	.pr_input =		rip6_input,
226 	.pr_output =		rip6_output,
227 	.pr_ctlinput =		rip6_ctlinput,
228 	.pr_ctloutput =		rip6_ctloutput,
229 	.pr_usrreqs =		&rip6_usrreqs
230 },
231 {
232 	.pr_type =		SOCK_RAW,
233 	.pr_domain =		&inet6domain,
234 	.pr_protocol =		IPPROTO_ICMPV6,
235 	.pr_flags =		PR_ATOMIC|PR_ADDR|PR_LASTHDR,
236 	.pr_input =		icmp6_input,
237 	.pr_output =		rip6_output,
238 	.pr_ctlinput =		rip6_ctlinput,
239 	.pr_ctloutput =		rip6_ctloutput,
240 	.pr_init =		icmp6_init,
241 	.pr_fasttimo =		icmp6_fasttimo,
242 	.pr_slowtimo =		icmp6_slowtimo,
243 	.pr_usrreqs =		&rip6_usrreqs
244 },
245 {
246 	.pr_type =		SOCK_RAW,
247 	.pr_domain =		&inet6domain,
248 	.pr_protocol =		IPPROTO_DSTOPTS,
249 	.pr_flags =		PR_ATOMIC|PR_ADDR,
250 	.pr_input =		dest6_input,
251 	.pr_usrreqs =		&nousrreqs
252 },
253 {
254 	.pr_type =		SOCK_RAW,
255 	.pr_domain =		&inet6domain,
256 	.pr_protocol =		IPPROTO_ROUTING,
257 	.pr_flags =		PR_ATOMIC|PR_ADDR,
258 	.pr_input =		route6_input,
259 	.pr_usrreqs =		&nousrreqs
260 },
261 {
262 	.pr_type =		SOCK_RAW,
263 	.pr_domain =		&inet6domain,
264 	.pr_protocol =		IPPROTO_FRAGMENT,
265 	.pr_flags =		PR_ATOMIC|PR_ADDR,
266 	.pr_input =		frag6_input,
267 	.pr_usrreqs =		&nousrreqs
268 },
269 #ifdef IPSEC
270 {
271 	.pr_type =		SOCK_RAW,
272 	.pr_domain =		&inet6domain,
273 	.pr_protocol =		IPPROTO_AH,
274 	.pr_flags =		PR_ATOMIC|PR_ADDR,
275 	.pr_input =		ipsec6_common_input,
276 	.pr_usrreqs =		&nousrreqs,
277 },
278 {
279 	.pr_type =		SOCK_RAW,
280 	.pr_domain =		&inet6domain,
281 	.pr_protocol =		IPPROTO_ESP,
282 	.pr_flags =		PR_ATOMIC|PR_ADDR,
283         .pr_input =		ipsec6_common_input,
284 	.pr_ctlinput =		esp6_ctlinput,
285 	.pr_usrreqs =		&nousrreqs,
286 },
287 {
288 	.pr_type =		SOCK_RAW,
289 	.pr_domain =		&inet6domain,
290 	.pr_protocol =		IPPROTO_IPCOMP,
291 	.pr_flags =		PR_ATOMIC|PR_ADDR,
292         .pr_input =		ipsec6_common_input,
293 	.pr_usrreqs =		&nousrreqs,
294 },
295 #endif /* IPSEC */
296 #ifdef INET
297 {
298 	.pr_type =		SOCK_RAW,
299 	.pr_domain =		&inet6domain,
300 	.pr_protocol =		IPPROTO_IPV4,
301 	.pr_flags =		PR_ATOMIC|PR_ADDR|PR_LASTHDR,
302 	.pr_input =		encap6_input,
303 	.pr_output =		rip6_output,
304 	.pr_ctloutput =		rip6_ctloutput,
305 	.pr_init =		encap_init,
306 	.pr_usrreqs =		&rip6_usrreqs
307 },
308 #endif /* INET */
309 {
310 	.pr_type =		SOCK_RAW,
311 	.pr_domain =		&inet6domain,
312 	.pr_protocol =		IPPROTO_IPV6,
313 	.pr_flags =		PR_ATOMIC|PR_ADDR|PR_LASTHDR,
314 	.pr_input =		encap6_input,
315 	.pr_output =		rip6_output,
316 	.pr_ctloutput =		rip6_ctloutput,
317 	.pr_init =		encap_init,
318 	.pr_usrreqs =		&rip6_usrreqs
319 },
320 {
321 	.pr_type =		SOCK_RAW,
322 	.pr_domain =		&inet6domain,
323 	.pr_protocol =		IPPROTO_PIM,
324 	.pr_flags =		PR_ATOMIC|PR_ADDR|PR_LASTHDR,
325 	.pr_input =		encap6_input,
326 	.pr_output =		rip6_output,
327 	.pr_ctloutput =		rip6_ctloutput,
328 	.pr_usrreqs =		&rip6_usrreqs
329 },
330 #ifdef DEV_CARP
331 {
332 	.pr_type =		SOCK_RAW,
333 	.pr_domain =		&inet6domain,
334 	.pr_protocol =		IPPROTO_CARP,
335 	.pr_flags =		PR_ATOMIC|PR_ADDR,
336 	.pr_input =		carp6_input,
337 	.pr_output =		rip6_output,
338 	.pr_ctloutput =		rip6_ctloutput,
339 	.pr_usrreqs =		&rip6_usrreqs
340 },
341 #endif /* DEV_CARP */
342 /* raw wildcard */
343 {
344 	.pr_type =		SOCK_RAW,
345 	.pr_domain =		&inet6domain,
346 	.pr_flags =		PR_ATOMIC|PR_ADDR,
347 	.pr_input =		rip6_input,
348 	.pr_output =		rip6_output,
349 	.pr_ctloutput =		rip6_ctloutput,
350 	.pr_usrreqs =		&rip6_usrreqs
351 },
352 };
353 
354 extern int in6_inithead(void **, int);
355 #ifdef VIMAGE
356 extern int in6_detachhead(void **, int);
357 #endif
358 
359 struct domain inet6domain = {
360 	.dom_family =		AF_INET6,
361 	.dom_name =		"internet6",
362 	.dom_protosw =		(struct protosw *)inet6sw,
363 	.dom_protoswNPROTOSW =	(struct protosw *)
364 				&inet6sw[sizeof(inet6sw)/sizeof(inet6sw[0])],
365 #ifdef RADIX_MPATH
366 	.dom_rtattach =		rn6_mpath_inithead,
367 #else
368 	.dom_rtattach =		in6_inithead,
369 #endif
370 #ifdef VIMAGE
371 	.dom_rtdetach =		in6_detachhead,
372 #endif
373 	.dom_rtoffset =		offsetof(struct sockaddr_in6, sin6_addr) << 3,
374 	.dom_maxrtkey =		sizeof(struct sockaddr_in6),
375 	.dom_ifattach =		in6_domifattach,
376 	.dom_ifdetach =		in6_domifdetach
377 };
378 
379 DOMAIN_SET(inet6);
380 
381 /*
382  * Internet configuration info
383  */
384 #ifdef VIMAGE_GLOBALS
385 int	ip6_forwarding;
386 int	ip6_sendredirects;
387 int	ip6_defhlim;
388 int	ip6_defmcasthlim;
389 int	ip6_accept_rtadv;
390 int	ip6_maxfragpackets;
391 int	ip6_maxfrags;
392 int	ip6_log_interval;
393 int	ip6_hdrnestlimit;
394 int	ip6_dad_count;
395 int	ip6_auto_flowlabel;
396 int	ip6_use_deprecated;
397 int	ip6_rr_prune;
398 int	ip6_mcast_pmtu;
399 int	ip6_v6only;
400 int	ip6_keepfaith;
401 time_t	ip6_log_time;
402 int	ip6stealth;
403 int	nd6_onlink_ns_rfc4861;
404 
405 /* icmp6 */
406 /*
407  * BSDI4 defines these variables in in_proto.c...
408  * XXX: what if we don't define INET? Should we define pmtu6_expire
409  * or so? (jinmei@kame.net 19990310)
410  */
411 int pmtu_expire;
412 int pmtu_probe;
413 
414 /* raw IP6 parameters */
415 /*
416  * Nominal space allocated to a raw ip socket.
417  */
418 u_long	rip6_sendspace;
419 u_long	rip6_recvspace;
420 
421 /* ICMPV6 parameters */
422 int	icmp6_rediraccept;
423 int	icmp6_redirtimeout;
424 int	icmp6errppslim;
425 /* control how to respond to NI queries */
426 int	icmp6_nodeinfo;
427 
428 /* UDP on IP6 parameters */
429 int	udp6_sendspace;
430 int	udp6_recvspace;
431 #endif /* VIMAGE_GLOBALS */
432 
433 /*
434  * sysctl related items.
435  */
436 SYSCTL_NODE(_net,	PF_INET6,	inet6,	CTLFLAG_RW,	0,
437 	"Internet6 Family");
438 
439 /* net.inet6 */
440 SYSCTL_NODE(_net_inet6,	IPPROTO_IPV6,	ip6,	CTLFLAG_RW, 0,	"IP6");
441 SYSCTL_NODE(_net_inet6,	IPPROTO_ICMPV6,	icmp6,	CTLFLAG_RW, 0,	"ICMP6");
442 SYSCTL_NODE(_net_inet6,	IPPROTO_UDP,	udp6,	CTLFLAG_RW, 0,	"UDP6");
443 SYSCTL_NODE(_net_inet6,	IPPROTO_TCP,	tcp6,	CTLFLAG_RW, 0,	"TCP6");
444 #ifdef SCTP
445 SYSCTL_NODE(_net_inet6,	IPPROTO_SCTP,	sctp6,	CTLFLAG_RW, 0,	"SCTP6");
446 #endif
447 #ifdef IPSEC
448 SYSCTL_NODE(_net_inet6,	IPPROTO_ESP,	ipsec6,	CTLFLAG_RW, 0,	"IPSEC6");
449 #endif /* IPSEC */
450 
451 /* net.inet6.ip6 */
452 static int
453 sysctl_ip6_temppltime(SYSCTL_HANDLER_ARGS)
454 {
455 	INIT_VNET_INET6(curvnet);
456 	int error = 0;
457 	int old;
458 
459 	SYSCTL_RESOLVE_V_ARG1();
460 
461 	error = SYSCTL_OUT(req, arg1, sizeof(int));
462 	if (error || !req->newptr)
463 		return (error);
464 	old = V_ip6_temp_preferred_lifetime;
465 	error = SYSCTL_IN(req, arg1, sizeof(int));
466 	if (V_ip6_temp_preferred_lifetime <
467 	    V_ip6_desync_factor + V_ip6_temp_regen_advance) {
468 		V_ip6_temp_preferred_lifetime = old;
469 		return (EINVAL);
470 	}
471 	return (error);
472 }
473 
474 static int
475 sysctl_ip6_tempvltime(SYSCTL_HANDLER_ARGS)
476 {
477 	INIT_VNET_INET6(curvnet);
478 	int error = 0;
479 	int old;
480 
481 	SYSCTL_RESOLVE_V_ARG1();
482 
483 	error = SYSCTL_OUT(req, arg1, sizeof(int));
484 	if (error || !req->newptr)
485 		return (error);
486 	old = V_ip6_temp_valid_lifetime;
487 	error = SYSCTL_IN(req, arg1, sizeof(int));
488 	if (V_ip6_temp_valid_lifetime < V_ip6_temp_preferred_lifetime) {
489 		V_ip6_temp_preferred_lifetime = old;
490 		return (EINVAL);
491 	}
492 	return (error);
493 }
494 
495 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_FORWARDING,
496 	forwarding, CTLFLAG_RW,		ip6_forwarding,	0, "");
497 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_SENDREDIRECTS,
498 	redirect, CTLFLAG_RW,		ip6_sendredirects,	0, "");
499 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_DEFHLIM,
500 	hlim, CTLFLAG_RW,		ip6_defhlim,	0, "");
501 SYSCTL_V_STRUCT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_STATS, stats,
502 	CTLFLAG_RD, ip6stat, ip6stat, "");
503 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_MAXFRAGPACKETS,
504 	maxfragpackets, CTLFLAG_RW,	ip6_maxfragpackets,	0, "");
505 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_ACCEPT_RTADV,
506 	accept_rtadv, CTLFLAG_RW,	ip6_accept_rtadv,	0, "");
507 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_KEEPFAITH,
508 	keepfaith, CTLFLAG_RW,		ip6_keepfaith,	0, "");
509 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_LOG_INTERVAL,
510 	log_interval, CTLFLAG_RW,	ip6_log_interval,	0, "");
511 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_HDRNESTLIMIT,
512 	hdrnestlimit, CTLFLAG_RW,	ip6_hdrnestlimit,	0, "");
513 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_DAD_COUNT,
514 	dad_count, CTLFLAG_RW,	ip6_dad_count,	0, "");
515 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_AUTO_FLOWLABEL,
516 	auto_flowlabel, CTLFLAG_RW,	ip6_auto_flowlabel,	0, "");
517 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_DEFMCASTHLIM,
518 	defmcasthlim, CTLFLAG_RW,	ip6_defmcasthlim,	0, "");
519 SYSCTL_STRING(_net_inet6_ip6, IPV6CTL_KAME_VERSION,
520 	kame_version, CTLFLAG_RD,	__KAME_VERSION,		0, "");
521 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_USE_DEPRECATED,
522 	use_deprecated, CTLFLAG_RW,	ip6_use_deprecated,	0, "");
523 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_RR_PRUNE,
524 	rr_prune, CTLFLAG_RW,	ip6_rr_prune,			0, "");
525 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_USETEMPADDR,
526 	use_tempaddr, CTLFLAG_RW, ip6_use_tempaddr,		0, "");
527 SYSCTL_V_OID(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_TEMPPLTIME, temppltime,
528 	CTLTYPE_INT|CTLFLAG_RW, ip6_temp_preferred_lifetime, 0,
529    	sysctl_ip6_temppltime, "I", "");
530 SYSCTL_V_OID(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_TEMPVLTIME, tempvltime,
531 	CTLTYPE_INT|CTLFLAG_RW, ip6_temp_valid_lifetime, 0,
532    	sysctl_ip6_tempvltime, "I", "");
533 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_V6ONLY,
534 	v6only,	CTLFLAG_RW,	ip6_v6only,			0, "");
535 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_AUTO_LINKLOCAL,
536 	auto_linklocal, CTLFLAG_RW, ip6_auto_linklocal,	0, "");
537 SYSCTL_V_STRUCT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_RIP6STATS,
538 	rip6stats, CTLFLAG_RD, rip6stat, rip6stat, "");
539 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_PREFER_TEMPADDR,
540 	prefer_tempaddr, CTLFLAG_RW, ip6_prefer_tempaddr, 0, "");
541 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_USE_DEFAULTZONE,
542 	use_defaultzone, CTLFLAG_RW, ip6_use_defzone, 0,"");
543 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_MAXFRAGS,
544 	maxfrags, CTLFLAG_RW, ip6_maxfrags, 0, "");
545 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_MCAST_PMTU,
546 	mcast_pmtu, CTLFLAG_RW, ip6_mcast_pmtu, 0, "");
547 #ifdef IPSTEALTH
548 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_ip6, IPV6CTL_STEALTH,
549 	stealth, CTLFLAG_RW, ip6stealth, 0, "");
550 #endif
551 
552 /* net.inet6.icmp6 */
553 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_icmp6, ICMPV6CTL_REDIRACCEPT,
554 	rediraccept, CTLFLAG_RW,	icmp6_rediraccept,	0, "");
555 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_icmp6, ICMPV6CTL_REDIRTIMEOUT,
556 	redirtimeout, CTLFLAG_RW,	icmp6_redirtimeout,	0, "");
557 SYSCTL_V_STRUCT(V_NET, vnet_inet6, _net_inet6_icmp6, ICMPV6CTL_STATS,
558 	stats, CTLFLAG_RD, icmp6stat, icmp6stat, "");
559 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_icmp6, ICMPV6CTL_ND6_PRUNE,
560 	nd6_prune, CTLFLAG_RW,		nd6_prune,	0, "");
561 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_icmp6, ICMPV6CTL_ND6_DELAY,
562 	nd6_delay, CTLFLAG_RW,		nd6_delay,	0, "");
563 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_icmp6, ICMPV6CTL_ND6_UMAXTRIES,
564 	nd6_umaxtries, CTLFLAG_RW,	nd6_umaxtries,	0, "");
565 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_icmp6, ICMPV6CTL_ND6_MMAXTRIES,
566 	nd6_mmaxtries, CTLFLAG_RW,	nd6_mmaxtries,	0, "");
567 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_icmp6, ICMPV6CTL_ND6_USELOOPBACK,
568 	nd6_useloopback, CTLFLAG_RW,	nd6_useloopback, 0, "");
569 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_icmp6, ICMPV6CTL_NODEINFO,
570 	nodeinfo, CTLFLAG_RW,	icmp6_nodeinfo,	0, "");
571 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_icmp6, ICMPV6CTL_ERRPPSLIMIT,
572 	errppslimit, CTLFLAG_RW,	icmp6errppslim,	0, "");
573 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_icmp6, ICMPV6CTL_ND6_MAXNUDHINT,
574 	nd6_maxnudhint, CTLFLAG_RW,	nd6_maxnudhint, 0, "");
575 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_icmp6, ICMPV6CTL_ND6_DEBUG,
576 	nd6_debug, CTLFLAG_RW,	nd6_debug,		0, "");
577 
578 SYSCTL_V_INT(V_NET, vnet_inet6, _net_inet6_icmp6, ICMPV6CTL_ND6_ONLINKNSRFC4861,
579 	nd6_onlink_ns_rfc4861, CTLFLAG_RW, nd6_onlink_ns_rfc4861, 0,
580 	"Accept 'on-link' nd6 NS in compliance with RFC 4861.");
581