sysctl_net.c 2.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118
  1. /* -*- linux-c -*-
  2. * sysctl_net.c: sysctl interface to net subsystem.
  3. *
  4. * Begun April 1, 1996, Mike Shaver.
  5. * Added /proc/sys/net directories for each protocol family. [MS]
  6. *
  7. * Revision 1.2 1996/05/08 20:24:40 shaver
  8. * Added bits for NET_BRIDGE and the NET_IPV4_ARP stuff and
  9. * NET_IPV4_IP_FORWARD.
  10. *
  11. *
  12. */
  13. #include <linux/mm.h>
  14. #include <linux/export.h>
  15. #include <linux/sysctl.h>
  16. #include <linux/nsproxy.h>
  17. #include <net/sock.h>
  18. #ifdef CONFIG_INET
  19. #include <net/ip.h>
  20. #endif
  21. #ifdef CONFIG_NET
  22. #include <linux/if_ether.h>
  23. #endif
  24. static struct ctl_table_set *
  25. net_ctl_header_lookup(struct ctl_table_root *root, struct nsproxy *namespaces)
  26. {
  27. return &namespaces->net_ns->sysctls;
  28. }
  29. static int is_seen(struct ctl_table_set *set)
  30. {
  31. return &current->nsproxy->net_ns->sysctls == set;
  32. }
  33. /* Return standard mode bits for table entry. */
  34. static int net_ctl_permissions(struct ctl_table_header *head,
  35. struct ctl_table *table)
  36. {
  37. struct net *net = container_of(head->set, struct net, sysctls);
  38. kuid_t root_uid = make_kuid(net->user_ns, 0);
  39. kgid_t root_gid = make_kgid(net->user_ns, 0);
  40. /* Allow network administrator to have same access as root. */
  41. if (ns_capable_noaudit(net->user_ns, CAP_NET_ADMIN) ||
  42. uid_eq(root_uid, current_euid())) {
  43. int mode = (table->mode >> 6) & 7;
  44. return (mode << 6) | (mode << 3) | mode;
  45. }
  46. /* Allow netns root group to have the same access as the root group */
  47. if (in_egroup_p(root_gid)) {
  48. int mode = (table->mode >> 3) & 7;
  49. return (mode << 3) | mode;
  50. }
  51. return table->mode;
  52. }
  53. static struct ctl_table_root net_sysctl_root = {
  54. .lookup = net_ctl_header_lookup,
  55. .permissions = net_ctl_permissions,
  56. };
  57. static int __net_init sysctl_net_init(struct net *net)
  58. {
  59. setup_sysctl_set(&net->sysctls, &net_sysctl_root, is_seen);
  60. return 0;
  61. }
  62. static void __net_exit sysctl_net_exit(struct net *net)
  63. {
  64. retire_sysctl_set(&net->sysctls);
  65. }
  66. static struct pernet_operations sysctl_pernet_ops = {
  67. .init = sysctl_net_init,
  68. .exit = sysctl_net_exit,
  69. };
  70. static struct ctl_table_header *net_header;
  71. __init int net_sysctl_init(void)
  72. {
  73. static struct ctl_table empty[1];
  74. int ret = -ENOMEM;
  75. /* Avoid limitations in the sysctl implementation by
  76. * registering "/proc/sys/net" as an empty directory not in a
  77. * network namespace.
  78. */
  79. net_header = register_sysctl("net", empty);
  80. if (!net_header)
  81. goto out;
  82. ret = register_pernet_subsys(&sysctl_pernet_ops);
  83. if (ret)
  84. goto out1;
  85. register_sysctl_root(&net_sysctl_root);
  86. out:
  87. return ret;
  88. out1:
  89. unregister_sysctl_table(net_header);
  90. net_header = NULL;
  91. goto out;
  92. }
  93. struct ctl_table_header *register_net_sysctl(struct net *net,
  94. const char *path, struct ctl_table *table)
  95. {
  96. return __register_sysctl_table(&net->sysctls, path, table);
  97. }
  98. EXPORT_SYMBOL_GPL(register_net_sysctl);
  99. void unregister_net_sysctl_table(struct ctl_table_header *header)
  100. {
  101. unregister_sysctl_table(header);
  102. }
  103. EXPORT_SYMBOL_GPL(unregister_net_sysctl_table);