sysctl_net.c 3.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130
  1. /* -*- linux-c -*-
  2. * sysctl_net.c: sysctl interface to net subsystem.
  3. *
  4. * Begun April 1, 1996, Mike Shaver.
  5. * Added /proc/sys/net directories for each protocol family. [MS]
  6. *
  7. * Revision 1.2 1996/05/08 20:24:40 shaver
  8. * Added bits for NET_BRIDGE and the NET_IPV4_ARP stuff and
  9. * NET_IPV4_IP_FORWARD.
  10. *
  11. *
  12. */
  13. #include <linux/mm.h>
  14. #include <linux/sysctl.h>
  15. #include <linux/nsproxy.h>
  16. #include <net/sock.h>
  17. #ifdef CONFIG_INET
  18. #include <net/ip.h>
  19. #endif
  20. #ifdef CONFIG_NET
  21. #include <linux/if_ether.h>
  22. #endif
  23. #ifdef CONFIG_TR
  24. #include <linux/if_tr.h>
  25. #endif
  26. static struct ctl_table_set *
  27. net_ctl_header_lookup(struct ctl_table_root *root, struct nsproxy *namespaces)
  28. {
  29. return &namespaces->net_ns->sysctls;
  30. }
  31. static int is_seen(struct ctl_table_set *set)
  32. {
  33. return &current->nsproxy->net_ns->sysctls == set;
  34. }
  35. /* Return standard mode bits for table entry. */
  36. static int net_ctl_permissions(struct ctl_table_root *root,
  37. struct nsproxy *nsproxy,
  38. struct ctl_table *table)
  39. {
  40. /* Allow network administrator to have same access as root. */
  41. if (capable(CAP_NET_ADMIN)) {
  42. int mode = (table->mode >> 6) & 7;
  43. return (mode << 6) | (mode << 3) | mode;
  44. }
  45. return table->mode;
  46. }
  47. static struct ctl_table_root net_sysctl_root = {
  48. .lookup = net_ctl_header_lookup,
  49. .permissions = net_ctl_permissions,
  50. };
  51. static int net_ctl_ro_header_perms(struct ctl_table_root *root,
  52. struct nsproxy *namespaces, struct ctl_table *table)
  53. {
  54. if (net_eq(namespaces->net_ns, &init_net))
  55. return table->mode;
  56. else
  57. return table->mode & ~0222;
  58. }
  59. static struct ctl_table_root net_sysctl_ro_root = {
  60. .permissions = net_ctl_ro_header_perms,
  61. };
  62. static int __net_init sysctl_net_init(struct net *net)
  63. {
  64. setup_sysctl_set(&net->sysctls,
  65. &net_sysctl_ro_root.default_set,
  66. is_seen);
  67. return 0;
  68. }
  69. static void __net_exit sysctl_net_exit(struct net *net)
  70. {
  71. WARN_ON(!list_empty(&net->sysctls.list));
  72. }
  73. static struct pernet_operations sysctl_pernet_ops = {
  74. .init = sysctl_net_init,
  75. .exit = sysctl_net_exit,
  76. };
  77. static __init int sysctl_init(void)
  78. {
  79. int ret;
  80. ret = register_pernet_subsys(&sysctl_pernet_ops);
  81. if (ret)
  82. goto out;
  83. register_sysctl_root(&net_sysctl_root);
  84. setup_sysctl_set(&net_sysctl_ro_root.default_set, NULL, NULL);
  85. register_sysctl_root(&net_sysctl_ro_root);
  86. out:
  87. return ret;
  88. }
  89. subsys_initcall(sysctl_init);
  90. struct ctl_table_header *register_net_sysctl_table(struct net *net,
  91. const struct ctl_path *path, struct ctl_table *table)
  92. {
  93. struct nsproxy namespaces;
  94. namespaces = *current->nsproxy;
  95. namespaces.net_ns = net;
  96. return __register_sysctl_paths(&net_sysctl_root,
  97. &namespaces, path, table);
  98. }
  99. EXPORT_SYMBOL_GPL(register_net_sysctl_table);
  100. struct ctl_table_header *register_net_sysctl_rotable(const
  101. struct ctl_path *path, struct ctl_table *table)
  102. {
  103. return __register_sysctl_paths(&net_sysctl_ro_root,
  104. &init_nsproxy, path, table);
  105. }
  106. EXPORT_SYMBOL_GPL(register_net_sysctl_rotable);
  107. void unregister_net_sysctl_table(struct ctl_table_header *header)
  108. {
  109. unregister_sysctl_table(header);
  110. }
  111. EXPORT_SYMBOL_GPL(unregister_net_sysctl_table);