[NETNS][IPV6]: Make icmpv6_time sysctl per namespace.
[pandora-kernel.git] / net / ipv6 / sysctl_net_ipv6.c
1 /*
2  * sysctl_net_ipv6.c: sysctl interface to net IPV6 subsystem.
3  *
4  * Changes:
5  * YOSHIFUJI Hideaki @USAGI:    added icmp sysctl table.
6  */
7
8 #include <linux/mm.h>
9 #include <linux/sysctl.h>
10 #include <linux/in6.h>
11 #include <linux/ipv6.h>
12 #include <net/ndisc.h>
13 #include <net/ipv6.h>
14 #include <net/addrconf.h>
15 #include <net/inet_frag.h>
16
17 extern struct ctl_table *ipv6_route_sysctl_init(struct net *net);
18 extern struct ctl_table *ipv6_icmp_sysctl_init(struct net *net);
19
20 static ctl_table ipv6_table_template[] = {
21         {
22                 .ctl_name       = NET_IPV6_ROUTE,
23                 .procname       = "route",
24                 .maxlen         = 0,
25                 .mode           = 0555,
26                 .child          = ipv6_route_table_template
27         },
28         {
29                 .ctl_name       = NET_IPV6_ICMP,
30                 .procname       = "icmp",
31                 .maxlen         = 0,
32                 .mode           = 0555,
33                 .child          = ipv6_icmp_table_template
34         },
35         {
36                 .ctl_name       = NET_IPV6_BINDV6ONLY,
37                 .procname       = "bindv6only",
38                 .data           = &init_net.ipv6.sysctl.bindv6only,
39                 .maxlen         = sizeof(int),
40                 .mode           = 0644,
41                 .proc_handler   = &proc_dointvec
42         },
43         {
44                 .ctl_name       = NET_IPV6_IP6FRAG_HIGH_THRESH,
45                 .procname       = "ip6frag_high_thresh",
46                 .data           = &init_net.ipv6.sysctl.frags.high_thresh,
47                 .maxlen         = sizeof(int),
48                 .mode           = 0644,
49                 .proc_handler   = &proc_dointvec
50         },
51         {
52                 .ctl_name       = NET_IPV6_IP6FRAG_LOW_THRESH,
53                 .procname       = "ip6frag_low_thresh",
54                 .data           = &init_net.ipv6.sysctl.frags.low_thresh,
55                 .maxlen         = sizeof(int),
56                 .mode           = 0644,
57                 .proc_handler   = &proc_dointvec
58         },
59         {
60                 .ctl_name       = NET_IPV6_IP6FRAG_TIME,
61                 .procname       = "ip6frag_time",
62                 .data           = &init_net.ipv6.sysctl.frags.timeout,
63                 .maxlen         = sizeof(int),
64                 .mode           = 0644,
65                 .proc_handler   = &proc_dointvec_jiffies,
66                 .strategy       = &sysctl_jiffies,
67         },
68         {
69                 .ctl_name       = NET_IPV6_IP6FRAG_SECRET_INTERVAL,
70                 .procname       = "ip6frag_secret_interval",
71                 .data           = &init_net.ipv6.sysctl.frags.secret_interval,
72                 .maxlen         = sizeof(int),
73                 .mode           = 0644,
74                 .proc_handler   = &proc_dointvec_jiffies,
75                 .strategy       = &sysctl_jiffies
76         },
77         {
78                 .ctl_name       = NET_IPV6_MLD_MAX_MSF,
79                 .procname       = "mld_max_msf",
80                 .data           = &sysctl_mld_max_msf,
81                 .maxlen         = sizeof(int),
82                 .mode           = 0644,
83                 .proc_handler   = &proc_dointvec
84         },
85         { .ctl_name = 0 }
86 };
87
88 struct ctl_path net_ipv6_ctl_path[] = {
89         { .procname = "net", .ctl_name = CTL_NET, },
90         { .procname = "ipv6", .ctl_name = NET_IPV6, },
91         { },
92 };
93 EXPORT_SYMBOL_GPL(net_ipv6_ctl_path);
94
95 static int ipv6_sysctl_net_init(struct net *net)
96 {
97         struct ctl_table *ipv6_table;
98         struct ctl_table *ipv6_route_table;
99         struct ctl_table *ipv6_icmp_table;
100         int err;
101
102         err = -ENOMEM;
103         ipv6_table = kmemdup(ipv6_table_template, sizeof(ipv6_table_template),
104                              GFP_KERNEL);
105         if (!ipv6_table)
106                 goto out;
107
108         ipv6_route_table = ipv6_route_sysctl_init(net);
109         if (!ipv6_route_table)
110                 goto out_ipv6_table;
111
112         ipv6_icmp_table = ipv6_icmp_sysctl_init(net);
113         if (!ipv6_icmp_table)
114                 goto out_ipv6_route_table;
115
116         ipv6_route_table[0].data = &net->ipv6.sysctl.flush_delay;
117         /* ipv6_route_table[1].data will be handled when we have
118            routes per namespace */
119         ipv6_route_table[2].data = &net->ipv6.sysctl.ip6_rt_max_size;
120         ipv6_route_table[3].data = &net->ipv6.sysctl.ip6_rt_gc_min_interval;
121         ipv6_route_table[4].data = &net->ipv6.sysctl.ip6_rt_gc_timeout;
122         ipv6_route_table[5].data = &net->ipv6.sysctl.ip6_rt_gc_interval;
123         ipv6_route_table[6].data = &net->ipv6.sysctl.ip6_rt_gc_elasticity;
124         ipv6_route_table[7].data = &net->ipv6.sysctl.ip6_rt_mtu_expires;
125         ipv6_route_table[8].data = &net->ipv6.sysctl.ip6_rt_min_advmss;
126         ipv6_table[0].child = ipv6_route_table;
127
128         ipv6_icmp_table[0].data = &net->ipv6.sysctl.icmpv6_time;
129         ipv6_table[1].child = ipv6_icmp_table;
130
131         ipv6_table[2].data = &net->ipv6.sysctl.bindv6only;
132         ipv6_table[3].data = &net->ipv6.sysctl.frags.high_thresh;
133         ipv6_table[4].data = &net->ipv6.sysctl.frags.low_thresh;
134         ipv6_table[5].data = &net->ipv6.sysctl.frags.timeout;
135         ipv6_table[6].data = &net->ipv6.sysctl.frags.secret_interval;
136
137         /* We don't want this value to be per namespace, it should be global
138            to all namespaces, so make it read-only when we are not in the
139            init network namespace */
140         if (net != &init_net)
141                 ipv6_table[7].mode = 0444;
142
143         net->ipv6.sysctl.table = register_net_sysctl_table(net, net_ipv6_ctl_path,
144                                                            ipv6_table);
145         if (!net->ipv6.sysctl.table)
146                 return -ENOMEM;
147
148         if (!net->ipv6.sysctl.table)
149                 goto out_ipv6_icmp_table;
150
151         err = 0;
152 out:
153         return err;
154
155 out_ipv6_icmp_table:
156         kfree(ipv6_icmp_table);
157 out_ipv6_route_table:
158         kfree(ipv6_route_table);
159 out_ipv6_table:
160         kfree(ipv6_table);
161         goto out;
162 }
163
164 static void ipv6_sysctl_net_exit(struct net *net)
165 {
166         struct ctl_table *ipv6_table;
167         struct ctl_table *ipv6_route_table;
168         struct ctl_table *ipv6_icmp_table;
169
170         ipv6_table = net->ipv6.sysctl.table->ctl_table_arg;
171         ipv6_route_table = ipv6_table[0].child;
172         ipv6_icmp_table = ipv6_table[1].child;
173
174         unregister_net_sysctl_table(net->ipv6.sysctl.table);
175
176         kfree(ipv6_table);
177         kfree(ipv6_route_table);
178         kfree(ipv6_icmp_table);
179 }
180
181 static struct pernet_operations ipv6_sysctl_net_ops = {
182         .init = ipv6_sysctl_net_init,
183         .exit = ipv6_sysctl_net_exit,
184 };
185
186 int ipv6_sysctl_register(void)
187 {
188         return register_pernet_subsys(&ipv6_sysctl_net_ops);
189 }
190
191 void ipv6_sysctl_unregister(void)
192 {
193         unregister_pernet_subsys(&ipv6_sysctl_net_ops);
194 }