net: Don't export sysctls to unprivileged users
[GitHub/mt8127/android_kernel_alcatel_ttab.git] / net / ipv6 / sysctl_net_ipv6.c
CommitLineData
1da177e4
LT
1/*
2 * sysctl_net_ipv6.c: sysctl interface to net IPV6 subsystem.
3 *
4 * Changes:
5 * YOSHIFUJI Hideaki @USAGI: added icmp sysctl table.
6 */
7
8#include <linux/mm.h>
9#include <linux/sysctl.h>
1da177e4
LT
10#include <linux/in6.h>
11#include <linux/ipv6.h>
5a0e3ad6 12#include <linux/slab.h>
bc3b2d7f 13#include <linux/export.h>
1da177e4
LT
14#include <net/ndisc.h>
15#include <net/ipv6.h>
16#include <net/addrconf.h>
04128f23 17#include <net/inet_frag.h>
1da177e4 18
760f2d01 19static ctl_table ipv6_table_template[] = {
1da177e4 20 {
1da177e4 21 .procname = "bindv6only",
99bc9c4e 22 .data = &init_net.ipv6.sysctl.bindv6only,
1da177e4
LT
23 .maxlen = sizeof(int),
24 .mode = 0644,
6d9f239a 25 .proc_handler = proc_dointvec
1da177e4 26 },
f8572d8f 27 { }
34ac2573
PE
28};
29
81e43213 30static ctl_table ipv6_rotable[] = {
1da177e4 31 {
1da177e4
LT
32 .procname = "mld_max_msf",
33 .data = &sysctl_mld_max_msf,
34 .maxlen = sizeof(int),
35 .mode = 0644,
6d9f239a 36 .proc_handler = proc_dointvec
1da177e4 37 },
f8572d8f 38 { }
1da177e4
LT
39};
40
2c8c1e72 41static int __net_init ipv6_sysctl_net_init(struct net *net)
1da177e4 42{
760f2d01
DL
43 struct ctl_table *ipv6_table;
44 struct ctl_table *ipv6_route_table;
45 struct ctl_table *ipv6_icmp_table;
46 int err;
47
48 err = -ENOMEM;
49 ipv6_table = kmemdup(ipv6_table_template, sizeof(ipv6_table_template),
50 GFP_KERNEL);
51 if (!ipv6_table)
52 goto out;
6dceb036 53 ipv6_table[0].data = &net->ipv6.sysctl.bindv6only;
760f2d01 54
464dc801
EB
55 /* Don't export sysctls to unprivileged users */
56 if (net->user_ns != &init_user_ns)
57 ipv6_table[0].procname = NULL;
58
760f2d01
DL
59 ipv6_route_table = ipv6_route_sysctl_init(net);
60 if (!ipv6_route_table)
61 goto out_ipv6_table;
62
63 ipv6_icmp_table = ipv6_icmp_sysctl_init(net);
64 if (!ipv6_icmp_table)
65 goto out_ipv6_route_table;
760f2d01 66
6dceb036
EB
67 net->ipv6.sysctl.hdr = register_net_sysctl(net, "net/ipv6", ipv6_table);
68 if (!net->ipv6.sysctl.hdr)
760f2d01
DL
69 goto out_ipv6_icmp_table;
70
6dceb036
EB
71 net->ipv6.sysctl.route_hdr =
72 register_net_sysctl(net, "net/ipv6/route", ipv6_route_table);
73 if (!net->ipv6.sysctl.route_hdr)
74 goto out_unregister_ipv6_table;
75
76 net->ipv6.sysctl.icmp_hdr =
77 register_net_sysctl(net, "net/ipv6/icmp", ipv6_icmp_table);
78 if (!net->ipv6.sysctl.icmp_hdr)
79 goto out_unregister_route_table;
80
760f2d01
DL
81 err = 0;
82out:
83 return err;
6dceb036
EB
84out_unregister_route_table:
85 unregister_net_sysctl_table(net->ipv6.sysctl.route_hdr);
86out_unregister_ipv6_table:
87 unregister_net_sysctl_table(net->ipv6.sysctl.hdr);
760f2d01
DL
88out_ipv6_icmp_table:
89 kfree(ipv6_icmp_table);
90out_ipv6_route_table:
91 kfree(ipv6_route_table);
92out_ipv6_table:
93 kfree(ipv6_table);
94 goto out;
1da177e4
LT
95}
96
2c8c1e72 97static void __net_exit ipv6_sysctl_net_exit(struct net *net)
89918fc2 98{
760f2d01
DL
99 struct ctl_table *ipv6_table;
100 struct ctl_table *ipv6_route_table;
101 struct ctl_table *ipv6_icmp_table;
102
6dceb036
EB
103 ipv6_table = net->ipv6.sysctl.hdr->ctl_table_arg;
104 ipv6_route_table = net->ipv6.sysctl.route_hdr->ctl_table_arg;
105 ipv6_icmp_table = net->ipv6.sysctl.icmp_hdr->ctl_table_arg;
760f2d01 106
6dceb036
EB
107 unregister_net_sysctl_table(net->ipv6.sysctl.icmp_hdr);
108 unregister_net_sysctl_table(net->ipv6.sysctl.route_hdr);
109 unregister_net_sysctl_table(net->ipv6.sysctl.hdr);
760f2d01
DL
110
111 kfree(ipv6_table);
112 kfree(ipv6_route_table);
113 kfree(ipv6_icmp_table);
89918fc2
DL
114}
115
116static struct pernet_operations ipv6_sysctl_net_ops = {
117 .init = ipv6_sysctl_net_init,
118 .exit = ipv6_sysctl_net_exit,
119};
120
34ac2573
PE
121static struct ctl_table_header *ip6_header;
122
89918fc2
DL
123int ipv6_sysctl_register(void)
124{
c19a28e1 125 int err = -ENOMEM;
34ac2573 126
43444757 127 ip6_header = register_net_sysctl(&init_net, "net/ipv6", ipv6_rotable);
34ac2573
PE
128 if (ip6_header == NULL)
129 goto out;
130
131 err = register_pernet_subsys(&ipv6_sysctl_net_ops);
132 if (err)
133 goto err_pernet;
134out:
135 return err;
136
137err_pernet:
138 unregister_net_sysctl_table(ip6_header);
139 goto out;
89918fc2
DL
140}
141
1da177e4
LT
142void ipv6_sysctl_unregister(void)
143{
34ac2573 144 unregister_net_sysctl_table(ip6_header);
89918fc2 145 unregister_pernet_subsys(&ipv6_sysctl_net_ops);
1da177e4 146}