1
2
3
4
5
6
7
8
9
10
11
12
13
14#include <linux/mm.h>
15#include <linux/export.h>
16#include <linux/sysctl.h>
17#include <linux/nsproxy.h>
18
19#include <net/sock.h>
20
21#ifdef CONFIG_INET
22#include <net/ip.h>
23#endif
24
25#ifdef CONFIG_NET
26#include <linux/if_ether.h>
27#endif
28
29static struct ctl_table_set *
30net_ctl_header_lookup(struct ctl_table_root *root, struct nsproxy *namespaces)
31{
32 return &namespaces->net_ns->sysctls;
33}
34
35static int is_seen(struct ctl_table_set *set)
36{
37 return ¤t->nsproxy->net_ns->sysctls == set;
38}
39
40
41static int net_ctl_permissions(struct ctl_table_root *root,
42 struct nsproxy *nsproxy,
43 struct ctl_table *table)
44{
45
46 if (capable(CAP_NET_ADMIN)) {
47 int mode = (table->mode >> 6) & 7;
48 return (mode << 6) | (mode << 3) | mode;
49 }
50 return table->mode;
51}
52
53static struct ctl_table_root net_sysctl_root = {
54 .lookup = net_ctl_header_lookup,
55 .permissions = net_ctl_permissions,
56};
57
58static int __net_init sysctl_net_init(struct net *net)
59{
60 setup_sysctl_set(&net->sysctls, &net_sysctl_root, is_seen);
61 return 0;
62}
63
64static void __net_exit sysctl_net_exit(struct net *net)
65{
66 retire_sysctl_set(&net->sysctls);
67}
68
69static struct pernet_operations sysctl_pernet_ops = {
70 .init = sysctl_net_init,
71 .exit = sysctl_net_exit,
72};
73
74static struct ctl_table_header *net_header;
75__init int net_sysctl_init(void)
76{
77 static struct ctl_table empty[1];
78 int ret = -ENOMEM;
79
80
81
82
83 net_header = register_sysctl("net", empty);
84 if (!net_header)
85 goto out;
86 ret = register_pernet_subsys(&sysctl_pernet_ops);
87 if (ret)
88 goto out;
89 register_sysctl_root(&net_sysctl_root);
90out:
91 return ret;
92}
93
94struct ctl_table_header *register_net_sysctl(struct net *net,
95 const char *path, struct ctl_table *table)
96{
97 return __register_sysctl_table(&net->sysctls, path, table);
98}
99EXPORT_SYMBOL_GPL(register_net_sysctl);
100
101void unregister_net_sysctl_table(struct ctl_table_header *header)
102{
103 unregister_sysctl_table(header);
104}
105EXPORT_SYMBOL_GPL(unregister_net_sysctl_table);
106