blob: 7197eb74a7554a7305c5a8b0f9e7620e81e8571e [file] [log] [blame]
Linus Torvalds1da177e2005-04-16 15:20:36 -07001/*
2 * sysctl_net_ipv6.c: sysctl interface to net IPV6 subsystem.
3 *
4 * Changes:
5 * YOSHIFUJI Hideaki @USAGI: added icmp sysctl table.
6 */
7
8#include <linux/mm.h>
9#include <linux/sysctl.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070010#include <linux/in6.h>
11#include <linux/ipv6.h>
12#include <net/ndisc.h>
13#include <net/ipv6.h>
14#include <net/addrconf.h>
Pavel Emelyanov04128f22007-10-15 02:33:45 -070015#include <net/inet_frag.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070016
Daniel Lezcano760f2d02008-01-10 02:53:43 -080017static ctl_table ipv6_table_template[] = {
Linus Torvalds1da177e2005-04-16 15:20:36 -070018 {
19 .ctl_name = NET_IPV6_ROUTE,
20 .procname = "route",
21 .maxlen = 0,
22 .mode = 0555,
Daniel Lezcano760f2d02008-01-10 02:53:43 -080023 .child = ipv6_route_table_template
Linus Torvalds1da177e2005-04-16 15:20:36 -070024 },
25 {
26 .ctl_name = NET_IPV6_ICMP,
27 .procname = "icmp",
28 .maxlen = 0,
29 .mode = 0555,
Daniel Lezcano760f2d02008-01-10 02:53:43 -080030 .child = ipv6_icmp_table_template
Linus Torvalds1da177e2005-04-16 15:20:36 -070031 },
32 {
33 .ctl_name = NET_IPV6_BINDV6ONLY,
34 .procname = "bindv6only",
Daniel Lezcano99bc9c42008-01-10 02:54:53 -080035 .data = &init_net.ipv6.sysctl.bindv6only,
Linus Torvalds1da177e2005-04-16 15:20:36 -070036 .maxlen = sizeof(int),
37 .mode = 0644,
38 .proc_handler = &proc_dointvec
39 },
40 {
41 .ctl_name = NET_IPV6_IP6FRAG_HIGH_THRESH,
42 .procname = "ip6frag_high_thresh",
Daniel Lezcanoe71e0342008-01-10 02:56:03 -080043 .data = &init_net.ipv6.sysctl.frags.high_thresh,
Linus Torvalds1da177e2005-04-16 15:20:36 -070044 .maxlen = sizeof(int),
45 .mode = 0644,
46 .proc_handler = &proc_dointvec
47 },
48 {
49 .ctl_name = NET_IPV6_IP6FRAG_LOW_THRESH,
50 .procname = "ip6frag_low_thresh",
Daniel Lezcanoe71e0342008-01-10 02:56:03 -080051 .data = &init_net.ipv6.sysctl.frags.low_thresh,
Linus Torvalds1da177e2005-04-16 15:20:36 -070052 .maxlen = sizeof(int),
53 .mode = 0644,
54 .proc_handler = &proc_dointvec
55 },
56 {
57 .ctl_name = NET_IPV6_IP6FRAG_TIME,
58 .procname = "ip6frag_time",
Daniel Lezcanoe71e0342008-01-10 02:56:03 -080059 .data = &init_net.ipv6.sysctl.frags.timeout,
Linus Torvalds1da177e2005-04-16 15:20:36 -070060 .maxlen = sizeof(int),
61 .mode = 0644,
62 .proc_handler = &proc_dointvec_jiffies,
63 .strategy = &sysctl_jiffies,
64 },
65 {
66 .ctl_name = NET_IPV6_IP6FRAG_SECRET_INTERVAL,
67 .procname = "ip6frag_secret_interval",
Daniel Lezcanoe71e0342008-01-10 02:56:03 -080068 .data = &init_net.ipv6.sysctl.frags.secret_interval,
Linus Torvalds1da177e2005-04-16 15:20:36 -070069 .maxlen = sizeof(int),
70 .mode = 0644,
71 .proc_handler = &proc_dointvec_jiffies,
72 .strategy = &sysctl_jiffies
73 },
74 {
75 .ctl_name = NET_IPV6_MLD_MAX_MSF,
76 .procname = "mld_max_msf",
77 .data = &sysctl_mld_max_msf,
78 .maxlen = sizeof(int),
79 .mode = 0644,
80 .proc_handler = &proc_dointvec
81 },
82 { .ctl_name = 0 }
83};
84
Pavel Emelyanov3d7cc2b2008-01-09 00:33:11 -080085struct ctl_path net_ipv6_ctl_path[] = {
Pavel Emelyanov4d43b782007-12-05 01:44:02 -080086 { .procname = "net", .ctl_name = CTL_NET, },
87 { .procname = "ipv6", .ctl_name = NET_IPV6, },
88 { },
89};
Pavel Emelyanov3d7cc2b2008-01-09 00:33:11 -080090EXPORT_SYMBOL_GPL(net_ipv6_ctl_path);
Pavel Emelyanov4d43b782007-12-05 01:44:02 -080091
Daniel Lezcano89918fc2008-01-10 02:49:34 -080092static int ipv6_sysctl_net_init(struct net *net)
Linus Torvalds1da177e2005-04-16 15:20:36 -070093{
Daniel Lezcano760f2d02008-01-10 02:53:43 -080094 struct ctl_table *ipv6_table;
95 struct ctl_table *ipv6_route_table;
96 struct ctl_table *ipv6_icmp_table;
97 int err;
98
99 err = -ENOMEM;
100 ipv6_table = kmemdup(ipv6_table_template, sizeof(ipv6_table_template),
101 GFP_KERNEL);
102 if (!ipv6_table)
103 goto out;
104
105 ipv6_route_table = ipv6_route_sysctl_init(net);
106 if (!ipv6_route_table)
107 goto out_ipv6_table;
108
109 ipv6_icmp_table = ipv6_icmp_sysctl_init(net);
110 if (!ipv6_icmp_table)
111 goto out_ipv6_route_table;
112
Daniel Lezcano49905092008-01-10 03:01:01 -0800113 ipv6_route_table[0].data = &net->ipv6.sysctl.flush_delay;
114 /* ipv6_route_table[1].data will be handled when we have
115 routes per namespace */
116 ipv6_route_table[2].data = &net->ipv6.sysctl.ip6_rt_max_size;
117 ipv6_route_table[3].data = &net->ipv6.sysctl.ip6_rt_gc_min_interval;
118 ipv6_route_table[4].data = &net->ipv6.sysctl.ip6_rt_gc_timeout;
119 ipv6_route_table[5].data = &net->ipv6.sysctl.ip6_rt_gc_interval;
120 ipv6_route_table[6].data = &net->ipv6.sysctl.ip6_rt_gc_elasticity;
121 ipv6_route_table[7].data = &net->ipv6.sysctl.ip6_rt_mtu_expires;
122 ipv6_route_table[8].data = &net->ipv6.sysctl.ip6_rt_min_advmss;
Daniel Lezcano760f2d02008-01-10 02:53:43 -0800123 ipv6_table[0].child = ipv6_route_table;
Daniel Lezcano49905092008-01-10 03:01:01 -0800124
Daniel Lezcano41a76902008-01-10 03:02:40 -0800125 ipv6_icmp_table[0].data = &net->ipv6.sysctl.icmpv6_time;
Daniel Lezcano760f2d02008-01-10 02:53:43 -0800126 ipv6_table[1].child = ipv6_icmp_table;
127
Daniel Lezcano99bc9c42008-01-10 02:54:53 -0800128 ipv6_table[2].data = &net->ipv6.sysctl.bindv6only;
Daniel Lezcanoe71e0342008-01-10 02:56:03 -0800129 ipv6_table[3].data = &net->ipv6.sysctl.frags.high_thresh;
130 ipv6_table[4].data = &net->ipv6.sysctl.frags.low_thresh;
131 ipv6_table[5].data = &net->ipv6.sysctl.frags.timeout;
132 ipv6_table[6].data = &net->ipv6.sysctl.frags.secret_interval;
Daniel Lezcano99bc9c42008-01-10 02:54:53 -0800133
Daniel Lezcano7c765092008-01-10 02:57:43 -0800134 /* We don't want this value to be per namespace, it should be global
135 to all namespaces, so make it read-only when we are not in the
136 init network namespace */
137 if (net != &init_net)
138 ipv6_table[7].mode = 0444;
139
Daniel Lezcano760f2d02008-01-10 02:53:43 -0800140 net->ipv6.sysctl.table = register_net_sysctl_table(net, net_ipv6_ctl_path,
141 ipv6_table);
142 if (!net->ipv6.sysctl.table)
Daniel Lezcano291480c2008-01-10 02:47:55 -0800143 return -ENOMEM;
144
Daniel Lezcano760f2d02008-01-10 02:53:43 -0800145 if (!net->ipv6.sysctl.table)
146 goto out_ipv6_icmp_table;
Daniel Lezcano291480c2008-01-10 02:47:55 -0800147
Daniel Lezcano760f2d02008-01-10 02:53:43 -0800148 err = 0;
149out:
150 return err;
151
152out_ipv6_icmp_table:
153 kfree(ipv6_icmp_table);
154out_ipv6_route_table:
155 kfree(ipv6_route_table);
156out_ipv6_table:
157 kfree(ipv6_table);
158 goto out;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700159}
160
Daniel Lezcano89918fc2008-01-10 02:49:34 -0800161static void ipv6_sysctl_net_exit(struct net *net)
162{
Daniel Lezcano760f2d02008-01-10 02:53:43 -0800163 struct ctl_table *ipv6_table;
164 struct ctl_table *ipv6_route_table;
165 struct ctl_table *ipv6_icmp_table;
166
167 ipv6_table = net->ipv6.sysctl.table->ctl_table_arg;
168 ipv6_route_table = ipv6_table[0].child;
169 ipv6_icmp_table = ipv6_table[1].child;
170
171 unregister_net_sysctl_table(net->ipv6.sysctl.table);
172
173 kfree(ipv6_table);
174 kfree(ipv6_route_table);
175 kfree(ipv6_icmp_table);
Daniel Lezcano89918fc2008-01-10 02:49:34 -0800176}
177
178static struct pernet_operations ipv6_sysctl_net_ops = {
179 .init = ipv6_sysctl_net_init,
180 .exit = ipv6_sysctl_net_exit,
181};
182
183int ipv6_sysctl_register(void)
184{
185 return register_pernet_subsys(&ipv6_sysctl_net_ops);
186}
187
Linus Torvalds1da177e2005-04-16 15:20:36 -0700188void ipv6_sysctl_unregister(void)
189{
Daniel Lezcano89918fc2008-01-10 02:49:34 -0800190 unregister_pernet_subsys(&ipv6_sysctl_net_ops);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700191}