blob: 622d2da27135586d164c228b81e71afb922d5d8c [file] [log] [blame]
Pavel Emelyanov8afd3512007-12-16 13:29:36 -08001/*
2 * ipv4 in net namespaces
3 */
4
5#ifndef __NETNS_IPV4_H__
6#define __NETNS_IPV4_H__
Denis V. Luneve4e49712008-01-10 03:27:51 -08007
Eric W. Biederman7064d162012-05-24 10:34:21 -06008#include <linux/uidgid.h>
Pavel Emelyanovac18e752008-01-22 06:02:14 -08009#include <net/inet_frag.h>
Alexander Duycka7e53532015-03-04 15:02:44 -080010#include <linux/rcupdate.h>
Pavel Emelyanovac18e752008-01-22 06:02:14 -080011
David S. Miller51c5d0c2012-07-10 00:49:14 -070012struct tcpm_hash_bucket;
Pavel Emelyanov752d14d2007-12-16 13:31:47 -080013struct ctl_table_header;
14struct ipv4_devconf;
Denis V. Luneve4e49712008-01-10 03:27:51 -080015struct fib_rules_ops;
Denis V. Luneve4aef8a2008-01-10 03:28:24 -080016struct hlist_head;
David S. Millerf4530fa2012-07-05 22:13:13 -070017struct fib_table;
Denis V. Lunev6bd48fc2008-01-10 03:28:55 -080018struct sock;
Eric W. Biederman0bbf87d2013-09-28 14:10:59 -070019struct local_ports {
20 seqlock_t lock;
21 int range[2];
Eric Dumazeted2dfd92015-05-27 11:34:37 -070022 bool warned;
Eric W. Biederman0bbf87d2013-09-28 14:10:59 -070023};
Pavel Emelyanov752d14d2007-12-16 13:31:47 -080024
Cong Wangba6b9182014-05-06 11:02:50 -070025struct ping_group_range {
26 seqlock_t lock;
27 kgid_t range[2];
28};
29
Haishuang Yan1946e672016-12-28 17:52:32 +080030struct inet_hashinfo;
31
32struct inet_timewait_death_row {
33 atomic_t tw_count;
34
35 struct inet_hashinfo *hashinfo ____cacheline_aligned_in_smp;
36 int sysctl_tw_recycle;
37 int sysctl_max_tw_buckets;
38};
39
Pavel Emelyanov8afd3512007-12-16 13:29:36 -080040struct netns_ipv4 {
Eric Dumazet2a75de02008-01-05 23:08:49 -080041#ifdef CONFIG_SYSCTL
Pavel Emelyanov752d14d2007-12-16 13:31:47 -080042 struct ctl_table_header *forw_hdr;
Pavel Emelyanove4a2d5c2008-01-22 06:08:36 -080043 struct ctl_table_header *frags_hdr;
Pavel Emelyanov68528f02008-03-26 01:56:24 -070044 struct ctl_table_header *ipv4_hdr;
Denis V. Lunev39a23e72008-07-05 19:02:33 -070045 struct ctl_table_header *route_hdr;
Michal Kubecek8d068872013-02-06 10:46:33 +010046 struct ctl_table_header *xfrm4_hdr;
Eric Dumazet2a75de02008-01-05 23:08:49 -080047#endif
Pavel Emelyanov752d14d2007-12-16 13:31:47 -080048 struct ipv4_devconf *devconf_all;
49 struct ipv4_devconf *devconf_dflt;
Denis V. Luneve4e49712008-01-10 03:27:51 -080050#ifdef CONFIG_IP_MULTIPLE_TABLES
51 struct fib_rules_ops *rules_ops;
David S. Millerf4530fa2012-07-05 22:13:13 -070052 bool fib_has_custom_rules;
Alexander Duycka7e53532015-03-04 15:02:44 -080053 struct fib_table __rcu *fib_main;
54 struct fib_table __rcu *fib_default;
David S. Millerf4530fa2012-07-05 22:13:13 -070055#endif
56#ifdef CONFIG_IP_ROUTE_CLASSID
57 int fib_num_tclassid_users;
Denis V. Luneve4e49712008-01-10 03:27:51 -080058#endif
Denis V. Luneve4aef8a2008-01-10 03:28:24 -080059 struct hlist_head *fib_table_hash;
Scott Feldman448b1282015-03-05 21:21:18 -080060 bool fib_offload_disabled;
Denis V. Lunev6bd48fc2008-01-10 03:28:55 -080061 struct sock *fibnl;
Pavel Emelyanovac18e752008-01-22 06:02:14 -080062
Eric Dumazet349c9e32015-01-29 15:58:09 -080063 struct sock * __percpu *icmp_sk;
Madhu Challa93a714d2015-02-25 09:58:35 -080064 struct sock *mc_autojoin_sk;
Eric Dumazet349c9e32015-01-29 15:58:09 -080065
Gao fengc8a627e2012-06-08 01:20:41 +000066 struct inet_peer_base *peers;
Eric Dumazetbdbbb852015-01-29 21:35:05 -080067 struct sock * __percpu *tcp_sk;
Pavel Emelyanovac18e752008-01-22 06:02:14 -080068 struct netns_frags frags;
Alexey Dobriyan9335f042008-01-31 04:03:23 -080069#ifdef CONFIG_NETFILTER
70 struct xt_table *iptable_filter;
71 struct xt_table *iptable_mangle;
72 struct xt_table *iptable_raw;
Alexey Dobriyan9ea0cb22008-01-31 04:05:09 -080073 struct xt_table *arptable_filter;
Alexey Dobriyane9d38972010-01-18 08:08:37 +010074#ifdef CONFIG_SECURITY
James Morris560ee652008-06-09 15:57:24 -070075 struct xt_table *iptable_security;
Alexey Dobriyane9d38972010-01-18 08:08:37 +010076#endif
Alexey Dobriyane099a172008-10-08 11:35:10 +020077 struct xt_table *nat_table;
Alexey Dobriyan9335f042008-01-31 04:03:23 -080078#endif
Pavel Emelyanova24022e2008-03-26 01:55:37 -070079
80 int sysctl_icmp_echo_ignore_all;
81 int sysctl_icmp_echo_ignore_broadcasts;
82 int sysctl_icmp_ignore_bogus_error_responses;
83 int sysctl_icmp_ratelimit;
84 int sysctl_icmp_ratemask;
85 int sysctl_icmp_errors_use_inbound_ifaddr;
Denis V. Lunev9f5e97e2008-07-05 19:02:59 -070086
Cong Wangc9d8f1a2014-05-06 11:02:49 -070087 struct local_ports ip_local_ports;
Eric W. Biederman0bbf87d2013-09-28 14:10:59 -070088
Hannes Frederic Sowa5d134f12013-01-05 16:10:48 +000089 int sysctl_tcp_ecn;
Daniel Borkmann49213552015-05-19 21:04:22 +020090 int sysctl_tcp_ecn_fallback;
91
Nikolay Borisovfa50d972016-02-15 12:11:27 +020092 int sysctl_ip_default_ttl;
Hannes Frederic Sowa974eda12013-12-14 05:13:38 +010093 int sysctl_ip_no_pmtu_disc;
Hannes Frederic Sowaf87c10a2014-01-09 10:01:15 +010094 int sysctl_ip_fwd_use_pmtu;
Vincent Bernat49a60152014-09-05 15:09:03 +020095 int sysctl_ip_nonlocal_bind;
Nikolay Borisov287b7f32016-02-15 12:11:29 +020096 /* Shall we try to damage output packets if routing dev changes? */
97 int sysctl_ip_dynaddr;
Nikolay Borisove21145a2016-02-15 12:11:30 +020098 int sysctl_ip_early_demux;
Hannes Frederic Sowa5d134f12013-01-05 16:10:48 +000099
Lorenzo Colittie1108612014-05-13 10:17:33 -0700100 int sysctl_fwmark_reflect;
Lorenzo Colitti84f39b02014-05-13 10:17:35 -0700101 int sysctl_tcp_fwmark_accept;
David Ahern6dd9a142015-12-16 13:20:44 -0800102#ifdef CONFIG_NET_L3_MASTER_DEV
103 int sysctl_tcp_l3mdev_accept;
104#endif
Fan Dub0f9ca52015-02-10 09:53:16 +0800105 int sysctl_tcp_mtu_probing;
106 int sysctl_tcp_base_mss;
Fan Du6b58e0a2015-03-06 11:18:23 +0800107 int sysctl_tcp_probe_threshold;
Fan Du05cbc0d2015-03-06 11:18:24 +0800108 u32 sysctl_tcp_probe_interval;
Lorenzo Colittie1108612014-05-13 10:17:33 -0700109
Nikolay Borisov13b287e2016-01-07 16:38:43 +0200110 int sysctl_tcp_keepalive_time;
Nikolay Borisov9bd68612016-01-07 16:38:44 +0200111 int sysctl_tcp_keepalive_probes;
Nikolay Borisovb840d152016-01-07 16:38:45 +0200112 int sysctl_tcp_keepalive_intvl;
Nikolay Borisov13b287e2016-01-07 16:38:43 +0200113
Nikolay Borisov6fa25162016-02-03 09:46:49 +0200114 int sysctl_tcp_syn_retries;
Nikolay Borisov7c083ec2016-02-03 09:46:50 +0200115 int sysctl_tcp_synack_retries;
Nikolay Borisov12ed8242016-02-03 09:46:51 +0200116 int sysctl_tcp_syncookies;
Nikolay Borisov1043e252016-02-03 09:46:52 +0200117 int sysctl_tcp_reordering;
Nikolay Borisovae5c3f42016-02-03 09:46:53 +0200118 int sysctl_tcp_retries1;
Nikolay Borisovc6214a92016-02-03 09:46:54 +0200119 int sysctl_tcp_retries2;
Nikolay Borisovc402d9b2016-02-03 09:46:55 +0200120 int sysctl_tcp_orphan_retries;
Nikolay Borisov1e579ca2016-02-03 09:46:56 +0200121 int sysctl_tcp_fin_timeout;
Nikolay Borisov4979f2d2016-02-03 09:46:57 +0200122 unsigned int sysctl_tcp_notsent_lowat;
Haishuang Yan56ab6b92016-12-25 14:33:16 +0800123 int sysctl_tcp_tw_reuse;
Haishuang Yan1946e672016-12-28 17:52:32 +0800124 struct inet_timewait_death_row tcp_death_row;
Haishuang Yanfee83d02016-12-28 17:52:33 +0800125 int sysctl_max_syn_backlog;
Nikolay Borisov12ed8242016-02-03 09:46:51 +0200126
Robert Shearman63a6fff2017-01-26 18:02:24 +0000127#ifdef CONFIG_NET_L3_MASTER_DEV
128 int sysctl_udp_l3mdev_accept;
129#endif
130
Nikolay Borisov815c5272016-02-08 23:29:21 +0200131 int sysctl_igmp_max_memberships;
Nikolay Borisov166b6b22016-02-08 23:29:22 +0200132 int sysctl_igmp_max_msf;
Nikolay Borisov87a8a2a2016-02-09 00:13:50 +0200133 int sysctl_igmp_llm_reports;
Nikolay Borisov165094a2016-02-08 23:29:24 +0200134 int sysctl_igmp_qrv;
Nikolay Borisov815c5272016-02-08 23:29:21 +0200135
Cong Wangba6b9182014-05-06 11:02:50 -0700136 struct ping_group_range ping_group_range;
Vasiliy Kulikovc319b4d2011-05-13 10:01:00 +0000137
David S. Miller436c3b62011-03-24 17:42:21 -0700138 atomic_t dev_addr_genid;
Benjamin Thery70a269e2009-01-22 04:56:15 +0000139
WANG Cong122ff242014-05-12 16:04:53 -0700140#ifdef CONFIG_SYSCTL
141 unsigned long *sysctl_local_reserved_ports;
Krister Johansen4548b682017-01-20 17:49:11 -0800142 int sysctl_ip_prot_sock;
WANG Cong122ff242014-05-12 16:04:53 -0700143#endif
144
Benjamin Thery70a269e2009-01-22 04:56:15 +0000145#ifdef CONFIG_IP_MROUTE
Patrick McHardyf0ad0862010-04-13 05:03:23 +0000146#ifndef CONFIG_IP_MROUTE_MULTIPLE_TABLES
Patrick McHardy0c122952010-04-13 05:03:22 +0000147 struct mr_table *mrt;
Patrick McHardyf0ad0862010-04-13 05:03:23 +0000148#else
149 struct list_head mr_tables;
150 struct fib_rules_ops *mr_rules_ops;
151#endif
Benjamin Thery70a269e2009-01-22 04:56:15 +0000152#endif
David Aherna6db4492016-04-07 07:21:00 -0700153#ifdef CONFIG_IP_ROUTE_MULTIPATH
154 int sysctl_fib_multipath_use_neigh;
155#endif
Ido Schimmelcacaad12016-12-03 16:45:06 +0100156
157 unsigned int fib_seq; /* protected by rtnl_mutex */
158
fan.duca4c3fc2013-07-30 08:33:53 +0800159 atomic_t rt_genid;
Pavel Emelyanov8afd3512007-12-16 13:29:36 -0800160};
161#endif