2005-04-16 15:20:36 -07:00
/* -*- linux-c -*-
* sysctl_net . c : sysctl interface to net subsystem .
*
* Begun April 1 , 1996 , Mike Shaver .
* Added / proc / sys / net directories for each protocol family . [ MS ]
*
* Revision 1.2 1996 / 05 / 08 20 : 24 : 40 shaver
* Added bits for NET_BRIDGE and the NET_IPV4_ARP stuff and
* NET_IPV4_IP_FORWARD .
*
*
*/
# include <linux/mm.h>
2011-07-15 11:47:34 -04:00
# include <linux/export.h>
2005-04-16 15:20:36 -07:00
# include <linux/sysctl.h>
2007-11-30 23:55:42 +11:00
# include <linux/nsproxy.h>
2005-04-16 15:20:36 -07:00
2005-10-03 14:16:34 -07:00
# include <net/sock.h>
2005-04-16 15:20:36 -07:00
# ifdef CONFIG_INET
2005-08-16 02:18:02 -03:00
# include <net/ip.h>
2005-04-16 15:20:36 -07:00
# endif
# ifdef CONFIG_NET
2005-08-16 02:18:02 -03:00
# include <linux/if_ether.h>
2005-04-16 15:20:36 -07:00
# endif
2008-07-14 21:22:20 -04:00
static struct ctl_table_set *
2007-11-30 23:55:42 +11:00
net_ctl_header_lookup ( struct ctl_table_root * root , struct nsproxy * namespaces )
{
2008-07-14 21:22:20 -04:00
return & namespaces - > net_ns - > sysctls ;
}
static int is_seen ( struct ctl_table_set * set )
{
return & current - > nsproxy - > net_ns - > sysctls = = set ;
2007-11-30 23:55:42 +11:00
}
2008-07-25 01:48:32 -07:00
/* Return standard mode bits for table entry. */
2012-11-16 03:02:58 +00:00
static int net_ctl_permissions ( struct ctl_table_header * head ,
2008-07-25 01:48:32 -07:00
struct ctl_table * table )
{
2012-11-16 03:03:01 +00:00
struct net * net = container_of ( head - > set , struct net , sysctls ) ;
kuid_t root_uid = make_kuid ( net - > user_ns , 0 ) ;
kgid_t root_gid = make_kgid ( net - > user_ns , 0 ) ;
2008-07-25 01:48:32 -07:00
/* Allow network administrator to have same access as root. */
2012-11-16 03:03:01 +00:00
if ( ns_capable ( net - > user_ns , CAP_NET_ADMIN ) | |
2013-10-05 13:15:30 -07:00
uid_eq ( root_uid , current_euid ( ) ) ) {
2008-07-25 01:48:32 -07:00
int mode = ( table - > mode > > 6 ) & 7 ;
return ( mode < < 6 ) | ( mode < < 3 ) | mode ;
}
2012-11-16 03:03:02 +00:00
/* Allow netns root group to have the same access as the root group */
2013-10-05 13:15:30 -07:00
if ( in_egroup_p ( root_gid ) ) {
2012-11-16 03:03:01 +00:00
int mode = ( table - > mode > > 3 ) & 7 ;
2012-11-16 03:03:02 +00:00
return ( mode < < 3 ) | mode ;
2012-11-16 03:03:01 +00:00
}
2008-07-25 01:48:32 -07:00
return table - > mode ;
}
2007-11-30 23:55:42 +11:00
static struct ctl_table_root net_sysctl_root = {
. lookup = net_ctl_header_lookup ,
2008-07-25 01:48:32 -07:00
. permissions = net_ctl_permissions ,
2007-11-30 23:55:42 +11:00
} ;
2010-01-17 03:35:32 +00:00
static int __net_init sysctl_net_init ( struct net * net )
2007-11-30 23:55:42 +11:00
{
2012-01-22 21:26:00 -08:00
setup_sysctl_set ( & net - > sysctls , & net_sysctl_root , is_seen ) ;
2007-11-30 23:55:42 +11:00
return 0 ;
}
2010-01-17 03:35:32 +00:00
static void __net_exit sysctl_net_exit ( struct net * net )
2007-11-30 23:55:42 +11:00
{
2012-01-09 22:19:13 -08:00
retire_sysctl_set ( & net - > sysctls ) ;
2007-11-30 23:55:42 +11:00
}
static struct pernet_operations sysctl_pernet_ops = {
. init = sysctl_net_init ,
. exit = sysctl_net_exit ,
} ;
2012-04-19 13:19:46 +00:00
static struct ctl_table_header * net_header ;
2012-04-19 13:20:32 +00:00
__init int net_sysctl_init ( void )
2007-11-30 23:55:42 +11:00
{
2012-04-19 13:19:46 +00:00
static struct ctl_table empty [ 1 ] ;
int ret = - ENOMEM ;
/* Avoid limitations in the sysctl implementation by
* registering " /proc/sys/net " as an empty directory not in a
* network namespace .
*/
net_header = register_sysctl ( " net " , empty ) ;
if ( ! net_header )
goto out ;
2007-11-30 23:55:42 +11:00
ret = register_pernet_subsys ( & sysctl_pernet_ops ) ;
if ( ret )
goto out ;
2012-01-22 21:10:21 -08:00
register_sysctl_root ( & net_sysctl_root ) ;
2007-11-30 23:55:42 +11:00
out :
return ret ;
}
2012-04-19 13:18:47 +00:00
struct ctl_table_header * register_net_sysctl ( struct net * net ,
const char * path , struct ctl_table * table )
{
return __register_sysctl_table ( & net - > sysctls , path , table ) ;
}
EXPORT_SYMBOL_GPL ( register_net_sysctl ) ;
2007-11-30 23:55:42 +11:00
void unregister_net_sysctl_table ( struct ctl_table_header * header )
{
2008-05-01 02:47:38 -07:00
unregister_sysctl_table ( header ) ;
2007-11-30 23:55:42 +11:00
}
EXPORT_SYMBOL_GPL ( unregister_net_sysctl_table ) ;