xref: /linux/net/ipv6/sysctl_net_ipv6.c (revision c411ed854584a71b0e86ac3019b60e4789d88086)
1 /*
2  * sysctl_net_ipv6.c: sysctl interface to net IPV6 subsystem.
3  *
4  * Changes:
5  * YOSHIFUJI Hideaki @USAGI:	added icmp sysctl table.
6  */
7 
8 #include <linux/mm.h>
9 #include <linux/sysctl.h>
10 #include <linux/in6.h>
11 #include <linux/ipv6.h>
12 #include <linux/slab.h>
13 #include <linux/export.h>
14 #include <net/ndisc.h>
15 #include <net/ipv6.h>
16 #include <net/addrconf.h>
17 #include <net/inet_frag.h>
18 #ifdef CONFIG_NETLABEL
19 #include <net/calipso.h>
20 #endif
21 
22 static int one = 1;
23 static int auto_flowlabels_min;
24 static int auto_flowlabels_max = IP6_AUTO_FLOW_LABEL_MAX;
25 
26 
27 static struct ctl_table ipv6_table_template[] = {
28 	{
29 		.procname	= "bindv6only",
30 		.data		= &init_net.ipv6.sysctl.bindv6only,
31 		.maxlen		= sizeof(int),
32 		.mode		= 0644,
33 		.proc_handler	= proc_dointvec
34 	},
35 	{
36 		.procname	= "anycast_src_echo_reply",
37 		.data		= &init_net.ipv6.sysctl.anycast_src_echo_reply,
38 		.maxlen		= sizeof(int),
39 		.mode		= 0644,
40 		.proc_handler	= proc_dointvec
41 	},
42 	{
43 		.procname	= "flowlabel_consistency",
44 		.data		= &init_net.ipv6.sysctl.flowlabel_consistency,
45 		.maxlen		= sizeof(int),
46 		.mode		= 0644,
47 		.proc_handler	= proc_dointvec
48 	},
49 	{
50 		.procname	= "auto_flowlabels",
51 		.data		= &init_net.ipv6.sysctl.auto_flowlabels,
52 		.maxlen		= sizeof(int),
53 		.mode		= 0644,
54 		.proc_handler	= proc_dointvec_minmax,
55 		.extra1		= &auto_flowlabels_min,
56 		.extra2		= &auto_flowlabels_max
57 	},
58 	{
59 		.procname	= "fwmark_reflect",
60 		.data		= &init_net.ipv6.sysctl.fwmark_reflect,
61 		.maxlen		= sizeof(int),
62 		.mode		= 0644,
63 		.proc_handler	= proc_dointvec
64 	},
65 	{
66 		.procname	= "idgen_retries",
67 		.data		= &init_net.ipv6.sysctl.idgen_retries,
68 		.maxlen		= sizeof(int),
69 		.mode		= 0644,
70 		.proc_handler	= proc_dointvec,
71 	},
72 	{
73 		.procname	= "idgen_delay",
74 		.data		= &init_net.ipv6.sysctl.idgen_delay,
75 		.maxlen		= sizeof(int),
76 		.mode		= 0644,
77 		.proc_handler	= proc_dointvec_jiffies,
78 	},
79 	{
80 		.procname	= "flowlabel_state_ranges",
81 		.data		= &init_net.ipv6.sysctl.flowlabel_state_ranges,
82 		.maxlen		= sizeof(int),
83 		.mode		= 0644,
84 		.proc_handler	= proc_dointvec
85 	},
86 	{
87 		.procname	= "ip_nonlocal_bind",
88 		.data		= &init_net.ipv6.sysctl.ip_nonlocal_bind,
89 		.maxlen		= sizeof(int),
90 		.mode		= 0644,
91 		.proc_handler	= proc_dointvec
92 	},
93 	{
94 		.procname	= "flowlabel_reflect",
95 		.data		= &init_net.ipv6.sysctl.flowlabel_reflect,
96 		.maxlen		= sizeof(int),
97 		.mode		= 0644,
98 		.proc_handler	= proc_dointvec,
99 	},
100 	{ }
101 };
102 
103 static struct ctl_table ipv6_rotable[] = {
104 	{
105 		.procname	= "mld_max_msf",
106 		.data		= &sysctl_mld_max_msf,
107 		.maxlen		= sizeof(int),
108 		.mode		= 0644,
109 		.proc_handler	= proc_dointvec
110 	},
111 	{
112 		.procname	= "mld_qrv",
113 		.data		= &sysctl_mld_qrv,
114 		.maxlen		= sizeof(int),
115 		.mode		= 0644,
116 		.proc_handler	= proc_dointvec_minmax,
117 		.extra1		= &one
118 	},
119 #ifdef CONFIG_NETLABEL
120 	{
121 		.procname	= "calipso_cache_enable",
122 		.data		= &calipso_cache_enabled,
123 		.maxlen		= sizeof(int),
124 		.mode		= 0644,
125 		.proc_handler	= proc_dointvec,
126 	},
127 	{
128 		.procname	= "calipso_cache_bucket_size",
129 		.data		= &calipso_cache_bucketsize,
130 		.maxlen		= sizeof(int),
131 		.mode		= 0644,
132 		.proc_handler	= proc_dointvec,
133 	},
134 #endif /* CONFIG_NETLABEL */
135 	{ }
136 };
137 
138 static int __net_init ipv6_sysctl_net_init(struct net *net)
139 {
140 	struct ctl_table *ipv6_table;
141 	struct ctl_table *ipv6_route_table;
142 	struct ctl_table *ipv6_icmp_table;
143 	int err;
144 
145 	err = -ENOMEM;
146 	ipv6_table = kmemdup(ipv6_table_template, sizeof(ipv6_table_template),
147 			     GFP_KERNEL);
148 	if (!ipv6_table)
149 		goto out;
150 	ipv6_table[0].data = &net->ipv6.sysctl.bindv6only;
151 	ipv6_table[1].data = &net->ipv6.sysctl.anycast_src_echo_reply;
152 	ipv6_table[2].data = &net->ipv6.sysctl.flowlabel_consistency;
153 	ipv6_table[3].data = &net->ipv6.sysctl.auto_flowlabels;
154 	ipv6_table[4].data = &net->ipv6.sysctl.fwmark_reflect;
155 	ipv6_table[5].data = &net->ipv6.sysctl.idgen_retries;
156 	ipv6_table[6].data = &net->ipv6.sysctl.idgen_delay;
157 	ipv6_table[7].data = &net->ipv6.sysctl.flowlabel_state_ranges;
158 	ipv6_table[8].data = &net->ipv6.sysctl.ip_nonlocal_bind;
159 	ipv6_table[9].data = &net->ipv6.sysctl.flowlabel_reflect;
160 
161 	ipv6_route_table = ipv6_route_sysctl_init(net);
162 	if (!ipv6_route_table)
163 		goto out_ipv6_table;
164 
165 	ipv6_icmp_table = ipv6_icmp_sysctl_init(net);
166 	if (!ipv6_icmp_table)
167 		goto out_ipv6_route_table;
168 
169 	net->ipv6.sysctl.hdr = register_net_sysctl(net, "net/ipv6", ipv6_table);
170 	if (!net->ipv6.sysctl.hdr)
171 		goto out_ipv6_icmp_table;
172 
173 	net->ipv6.sysctl.route_hdr =
174 		register_net_sysctl(net, "net/ipv6/route", ipv6_route_table);
175 	if (!net->ipv6.sysctl.route_hdr)
176 		goto out_unregister_ipv6_table;
177 
178 	net->ipv6.sysctl.icmp_hdr =
179 		register_net_sysctl(net, "net/ipv6/icmp", ipv6_icmp_table);
180 	if (!net->ipv6.sysctl.icmp_hdr)
181 		goto out_unregister_route_table;
182 
183 	err = 0;
184 out:
185 	return err;
186 out_unregister_route_table:
187 	unregister_net_sysctl_table(net->ipv6.sysctl.route_hdr);
188 out_unregister_ipv6_table:
189 	unregister_net_sysctl_table(net->ipv6.sysctl.hdr);
190 out_ipv6_icmp_table:
191 	kfree(ipv6_icmp_table);
192 out_ipv6_route_table:
193 	kfree(ipv6_route_table);
194 out_ipv6_table:
195 	kfree(ipv6_table);
196 	goto out;
197 }
198 
199 static void __net_exit ipv6_sysctl_net_exit(struct net *net)
200 {
201 	struct ctl_table *ipv6_table;
202 	struct ctl_table *ipv6_route_table;
203 	struct ctl_table *ipv6_icmp_table;
204 
205 	ipv6_table = net->ipv6.sysctl.hdr->ctl_table_arg;
206 	ipv6_route_table = net->ipv6.sysctl.route_hdr->ctl_table_arg;
207 	ipv6_icmp_table = net->ipv6.sysctl.icmp_hdr->ctl_table_arg;
208 
209 	unregister_net_sysctl_table(net->ipv6.sysctl.icmp_hdr);
210 	unregister_net_sysctl_table(net->ipv6.sysctl.route_hdr);
211 	unregister_net_sysctl_table(net->ipv6.sysctl.hdr);
212 
213 	kfree(ipv6_table);
214 	kfree(ipv6_route_table);
215 	kfree(ipv6_icmp_table);
216 }
217 
218 static struct pernet_operations ipv6_sysctl_net_ops = {
219 	.init = ipv6_sysctl_net_init,
220 	.exit = ipv6_sysctl_net_exit,
221 };
222 
223 static struct ctl_table_header *ip6_header;
224 
225 int ipv6_sysctl_register(void)
226 {
227 	int err = -ENOMEM;
228 
229 	ip6_header = register_net_sysctl(&init_net, "net/ipv6", ipv6_rotable);
230 	if (!ip6_header)
231 		goto out;
232 
233 	err = register_pernet_subsys(&ipv6_sysctl_net_ops);
234 	if (err)
235 		goto err_pernet;
236 out:
237 	return err;
238 
239 err_pernet:
240 	unregister_net_sysctl_table(ip6_header);
241 	goto out;
242 }
243 
244 void ipv6_sysctl_unregister(void)
245 {
246 	unregister_net_sysctl_table(ip6_header);
247 	unregister_pernet_subsys(&ipv6_sysctl_net_ops);
248 }
249