Commit | Line | Data |
---|---|---|
b2441318 | 1 | // SPDX-License-Identifier: GPL-2.0 |
b27aeadb | 2 | #include <linux/sysctl.h> |
5a0e3ad6 | 3 | #include <linux/slab.h> |
b27aeadb AD |
4 | #include <net/net_namespace.h> |
5 | #include <net/xfrm.h> | |
6 | ||
2c8c1e72 | 7 | static void __net_init __xfrm_sysctl_init(struct net *net) |
b27aeadb AD |
8 | { |
9 | net->xfrm.sysctl_aevent_etime = XFRM_AE_ETIME; | |
10 | net->xfrm.sysctl_aevent_rseqth = XFRM_AE_SEQT_SIZE; | |
11 | net->xfrm.sysctl_larval_drop = 1; | |
12 | net->xfrm.sysctl_acq_expires = 30; | |
13 | } | |
14 | ||
15 | #ifdef CONFIG_SYSCTL | |
16 | static struct ctl_table xfrm_table[] = { | |
17 | { | |
b27aeadb AD |
18 | .procname = "xfrm_aevent_etime", |
19 | .maxlen = sizeof(u32), | |
20 | .mode = 0644, | |
0f76d256 | 21 | .proc_handler = proc_douintvec |
b27aeadb AD |
22 | }, |
23 | { | |
b27aeadb AD |
24 | .procname = "xfrm_aevent_rseqth", |
25 | .maxlen = sizeof(u32), | |
26 | .mode = 0644, | |
0f76d256 | 27 | .proc_handler = proc_douintvec |
b27aeadb AD |
28 | }, |
29 | { | |
b27aeadb AD |
30 | .procname = "xfrm_larval_drop", |
31 | .maxlen = sizeof(int), | |
32 | .mode = 0644, | |
33 | .proc_handler = proc_dointvec | |
34 | }, | |
35 | { | |
b27aeadb AD |
36 | .procname = "xfrm_acq_expires", |
37 | .maxlen = sizeof(int), | |
38 | .mode = 0644, | |
39 | .proc_handler = proc_dointvec | |
40 | }, | |
b27aeadb AD |
41 | }; |
42 | ||
43 | int __net_init xfrm_sysctl_init(struct net *net) | |
44 | { | |
45 | struct ctl_table *table; | |
c899710f | 46 | size_t table_size = ARRAY_SIZE(xfrm_table); |
b27aeadb AD |
47 | |
48 | __xfrm_sysctl_init(net); | |
49 | ||
50 | table = kmemdup(xfrm_table, sizeof(xfrm_table), GFP_KERNEL); | |
51 | if (!table) | |
52 | goto out_kmemdup; | |
53 | table[0].data = &net->xfrm.sysctl_aevent_etime; | |
54 | table[1].data = &net->xfrm.sysctl_aevent_rseqth; | |
55 | table[2].data = &net->xfrm.sysctl_larval_drop; | |
56 | table[3].data = &net->xfrm.sysctl_acq_expires; | |
57 | ||
464dc801 | 58 | /* Don't export sysctls to unprivileged users */ |
73dbd8cf | 59 | if (net->user_ns != &init_user_ns) |
c899710f | 60 | table_size = 0; |
464dc801 | 61 | |
c899710f JG |
62 | net->xfrm.sysctl_hdr = register_net_sysctl_sz(net, "net/core", table, |
63 | table_size); | |
b27aeadb AD |
64 | if (!net->xfrm.sysctl_hdr) |
65 | goto out_register; | |
66 | return 0; | |
67 | ||
68 | out_register: | |
69 | kfree(table); | |
70 | out_kmemdup: | |
71 | return -ENOMEM; | |
72 | } | |
73 | ||
2c8c1e72 | 74 | void __net_exit xfrm_sysctl_fini(struct net *net) |
b27aeadb | 75 | { |
bfa858f2 | 76 | const struct ctl_table *table; |
b27aeadb AD |
77 | |
78 | table = net->xfrm.sysctl_hdr->ctl_table_arg; | |
79 | unregister_net_sysctl_table(net->xfrm.sysctl_hdr); | |
80 | kfree(table); | |
81 | } | |
82 | #else | |
83 | int __net_init xfrm_sysctl_init(struct net *net) | |
84 | { | |
85 | __xfrm_sysctl_init(net); | |
86 | return 0; | |
87 | } | |
88 | #endif |