sysctl_net_ipv4.c 21 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880
  1. /*
  2. * sysctl_net_ipv4.c: sysctl interface to net IPV4 subsystem.
  3. *
  4. * $Id: sysctl_net_ipv4.c,v 1.50 2001/10/20 00:00:11 davem Exp $
  5. *
  6. * Begun April 1, 1996, Mike Shaver.
  7. * Added /proc/sys/net/ipv4 directory entry (empty =) ). [MS]
  8. */
  9. #include <linux/mm.h>
  10. #include <linux/module.h>
  11. #include <linux/sysctl.h>
  12. #include <linux/igmp.h>
  13. #include <linux/inetdevice.h>
  14. #include <linux/seqlock.h>
  15. #include <net/snmp.h>
  16. #include <net/icmp.h>
  17. #include <net/ip.h>
  18. #include <net/route.h>
  19. #include <net/tcp.h>
  20. #include <net/cipso_ipv4.h>
  21. #include <net/inet_frag.h>
  22. static int zero;
  23. static int tcp_retr1_max = 255;
  24. static int ip_local_port_range_min[] = { 1, 1 };
  25. static int ip_local_port_range_max[] = { 65535, 65535 };
  26. static
  27. int ipv4_sysctl_forward(ctl_table *ctl, int write, struct file * filp,
  28. void __user *buffer, size_t *lenp, loff_t *ppos)
  29. {
  30. int val = IPV4_DEVCONF_ALL(FORWARDING);
  31. int ret;
  32. ret = proc_dointvec(ctl, write, filp, buffer, lenp, ppos);
  33. if (write && IPV4_DEVCONF_ALL(FORWARDING) != val)
  34. inet_forward_change();
  35. return ret;
  36. }
  37. static int ipv4_sysctl_forward_strategy(ctl_table *table,
  38. int __user *name, int nlen,
  39. void __user *oldval, size_t __user *oldlenp,
  40. void __user *newval, size_t newlen)
  41. {
  42. int *valp = table->data;
  43. int new;
  44. if (!newval || !newlen)
  45. return 0;
  46. if (newlen != sizeof(int))
  47. return -EINVAL;
  48. if (get_user(new, (int __user *)newval))
  49. return -EFAULT;
  50. if (new == *valp)
  51. return 0;
  52. if (oldval && oldlenp) {
  53. size_t len;
  54. if (get_user(len, oldlenp))
  55. return -EFAULT;
  56. if (len) {
  57. if (len > table->maxlen)
  58. len = table->maxlen;
  59. if (copy_to_user(oldval, valp, len))
  60. return -EFAULT;
  61. if (put_user(len, oldlenp))
  62. return -EFAULT;
  63. }
  64. }
  65. *valp = new;
  66. inet_forward_change();
  67. return 1;
  68. }
  69. extern seqlock_t sysctl_port_range_lock;
  70. extern int sysctl_local_port_range[2];
  71. /* Update system visible IP port range */
  72. static void set_local_port_range(int range[2])
  73. {
  74. write_seqlock(&sysctl_port_range_lock);
  75. sysctl_local_port_range[0] = range[0];
  76. sysctl_local_port_range[1] = range[1];
  77. write_sequnlock(&sysctl_port_range_lock);
  78. }
  79. /* Validate changes from /proc interface. */
  80. static int ipv4_local_port_range(ctl_table *table, int write, struct file *filp,
  81. void __user *buffer,
  82. size_t *lenp, loff_t *ppos)
  83. {
  84. int ret;
  85. int range[2] = { sysctl_local_port_range[0],
  86. sysctl_local_port_range[1] };
  87. ctl_table tmp = {
  88. .data = &range,
  89. .maxlen = sizeof(range),
  90. .mode = table->mode,
  91. .extra1 = &ip_local_port_range_min,
  92. .extra2 = &ip_local_port_range_max,
  93. };
  94. ret = proc_dointvec_minmax(&tmp, write, filp, buffer, lenp, ppos);
  95. if (write && ret == 0) {
  96. if (range[1] < range[0])
  97. ret = -EINVAL;
  98. else
  99. set_local_port_range(range);
  100. }
  101. return ret;
  102. }
  103. /* Validate changes from sysctl interface. */
  104. static int ipv4_sysctl_local_port_range(ctl_table *table, int __user *name,
  105. int nlen, void __user *oldval,
  106. size_t __user *oldlenp,
  107. void __user *newval, size_t newlen)
  108. {
  109. int ret;
  110. int range[2] = { sysctl_local_port_range[0],
  111. sysctl_local_port_range[1] };
  112. ctl_table tmp = {
  113. .data = &range,
  114. .maxlen = sizeof(range),
  115. .mode = table->mode,
  116. .extra1 = &ip_local_port_range_min,
  117. .extra2 = &ip_local_port_range_max,
  118. };
  119. ret = sysctl_intvec(&tmp, name, nlen, oldval, oldlenp, newval, newlen);
  120. if (ret == 0 && newval && newlen) {
  121. if (range[1] < range[0])
  122. ret = -EINVAL;
  123. else
  124. set_local_port_range(range);
  125. }
  126. return ret;
  127. }
  128. static int proc_tcp_congestion_control(ctl_table *ctl, int write, struct file * filp,
  129. void __user *buffer, size_t *lenp, loff_t *ppos)
  130. {
  131. char val[TCP_CA_NAME_MAX];
  132. ctl_table tbl = {
  133. .data = val,
  134. .maxlen = TCP_CA_NAME_MAX,
  135. };
  136. int ret;
  137. tcp_get_default_congestion_control(val);
  138. ret = proc_dostring(&tbl, write, filp, buffer, lenp, ppos);
  139. if (write && ret == 0)
  140. ret = tcp_set_default_congestion_control(val);
  141. return ret;
  142. }
  143. static int sysctl_tcp_congestion_control(ctl_table *table, int __user *name,
  144. int nlen, void __user *oldval,
  145. size_t __user *oldlenp,
  146. void __user *newval, size_t newlen)
  147. {
  148. char val[TCP_CA_NAME_MAX];
  149. ctl_table tbl = {
  150. .data = val,
  151. .maxlen = TCP_CA_NAME_MAX,
  152. };
  153. int ret;
  154. tcp_get_default_congestion_control(val);
  155. ret = sysctl_string(&tbl, name, nlen, oldval, oldlenp, newval, newlen);
  156. if (ret == 1 && newval && newlen)
  157. ret = tcp_set_default_congestion_control(val);
  158. return ret;
  159. }
  160. static int proc_tcp_available_congestion_control(ctl_table *ctl,
  161. int write, struct file * filp,
  162. void __user *buffer, size_t *lenp,
  163. loff_t *ppos)
  164. {
  165. ctl_table tbl = { .maxlen = TCP_CA_BUF_MAX, };
  166. int ret;
  167. tbl.data = kmalloc(tbl.maxlen, GFP_USER);
  168. if (!tbl.data)
  169. return -ENOMEM;
  170. tcp_get_available_congestion_control(tbl.data, TCP_CA_BUF_MAX);
  171. ret = proc_dostring(&tbl, write, filp, buffer, lenp, ppos);
  172. kfree(tbl.data);
  173. return ret;
  174. }
  175. static int proc_allowed_congestion_control(ctl_table *ctl,
  176. int write, struct file * filp,
  177. void __user *buffer, size_t *lenp,
  178. loff_t *ppos)
  179. {
  180. ctl_table tbl = { .maxlen = TCP_CA_BUF_MAX };
  181. int ret;
  182. tbl.data = kmalloc(tbl.maxlen, GFP_USER);
  183. if (!tbl.data)
  184. return -ENOMEM;
  185. tcp_get_allowed_congestion_control(tbl.data, tbl.maxlen);
  186. ret = proc_dostring(&tbl, write, filp, buffer, lenp, ppos);
  187. if (write && ret == 0)
  188. ret = tcp_set_allowed_congestion_control(tbl.data);
  189. kfree(tbl.data);
  190. return ret;
  191. }
  192. static int strategy_allowed_congestion_control(ctl_table *table, int __user *name,
  193. int nlen, void __user *oldval,
  194. size_t __user *oldlenp,
  195. void __user *newval,
  196. size_t newlen)
  197. {
  198. ctl_table tbl = { .maxlen = TCP_CA_BUF_MAX };
  199. int ret;
  200. tbl.data = kmalloc(tbl.maxlen, GFP_USER);
  201. if (!tbl.data)
  202. return -ENOMEM;
  203. tcp_get_available_congestion_control(tbl.data, tbl.maxlen);
  204. ret = sysctl_string(&tbl, name, nlen, oldval, oldlenp, newval, newlen);
  205. if (ret == 0 && newval && newlen)
  206. ret = tcp_set_allowed_congestion_control(tbl.data);
  207. kfree(tbl.data);
  208. return ret;
  209. }
  210. ctl_table ipv4_table[] = {
  211. {
  212. .ctl_name = NET_IPV4_TCP_TIMESTAMPS,
  213. .procname = "tcp_timestamps",
  214. .data = &sysctl_tcp_timestamps,
  215. .maxlen = sizeof(int),
  216. .mode = 0644,
  217. .proc_handler = &proc_dointvec
  218. },
  219. {
  220. .ctl_name = NET_IPV4_TCP_WINDOW_SCALING,
  221. .procname = "tcp_window_scaling",
  222. .data = &sysctl_tcp_window_scaling,
  223. .maxlen = sizeof(int),
  224. .mode = 0644,
  225. .proc_handler = &proc_dointvec
  226. },
  227. {
  228. .ctl_name = NET_IPV4_TCP_SACK,
  229. .procname = "tcp_sack",
  230. .data = &sysctl_tcp_sack,
  231. .maxlen = sizeof(int),
  232. .mode = 0644,
  233. .proc_handler = &proc_dointvec
  234. },
  235. {
  236. .ctl_name = NET_IPV4_TCP_RETRANS_COLLAPSE,
  237. .procname = "tcp_retrans_collapse",
  238. .data = &sysctl_tcp_retrans_collapse,
  239. .maxlen = sizeof(int),
  240. .mode = 0644,
  241. .proc_handler = &proc_dointvec
  242. },
  243. {
  244. .ctl_name = NET_IPV4_FORWARD,
  245. .procname = "ip_forward",
  246. .data = &IPV4_DEVCONF_ALL(FORWARDING),
  247. .maxlen = sizeof(int),
  248. .mode = 0644,
  249. .proc_handler = &ipv4_sysctl_forward,
  250. .strategy = &ipv4_sysctl_forward_strategy
  251. },
  252. {
  253. .ctl_name = NET_IPV4_DEFAULT_TTL,
  254. .procname = "ip_default_ttl",
  255. .data = &sysctl_ip_default_ttl,
  256. .maxlen = sizeof(int),
  257. .mode = 0644,
  258. .proc_handler = &ipv4_doint_and_flush,
  259. .strategy = &ipv4_doint_and_flush_strategy,
  260. },
  261. {
  262. .ctl_name = NET_IPV4_NO_PMTU_DISC,
  263. .procname = "ip_no_pmtu_disc",
  264. .data = &ipv4_config.no_pmtu_disc,
  265. .maxlen = sizeof(int),
  266. .mode = 0644,
  267. .proc_handler = &proc_dointvec
  268. },
  269. {
  270. .ctl_name = NET_IPV4_NONLOCAL_BIND,
  271. .procname = "ip_nonlocal_bind",
  272. .data = &sysctl_ip_nonlocal_bind,
  273. .maxlen = sizeof(int),
  274. .mode = 0644,
  275. .proc_handler = &proc_dointvec
  276. },
  277. {
  278. .ctl_name = NET_IPV4_TCP_SYN_RETRIES,
  279. .procname = "tcp_syn_retries",
  280. .data = &sysctl_tcp_syn_retries,
  281. .maxlen = sizeof(int),
  282. .mode = 0644,
  283. .proc_handler = &proc_dointvec
  284. },
  285. {
  286. .ctl_name = NET_TCP_SYNACK_RETRIES,
  287. .procname = "tcp_synack_retries",
  288. .data = &sysctl_tcp_synack_retries,
  289. .maxlen = sizeof(int),
  290. .mode = 0644,
  291. .proc_handler = &proc_dointvec
  292. },
  293. {
  294. .ctl_name = NET_TCP_MAX_ORPHANS,
  295. .procname = "tcp_max_orphans",
  296. .data = &sysctl_tcp_max_orphans,
  297. .maxlen = sizeof(int),
  298. .mode = 0644,
  299. .proc_handler = &proc_dointvec
  300. },
  301. {
  302. .ctl_name = NET_TCP_MAX_TW_BUCKETS,
  303. .procname = "tcp_max_tw_buckets",
  304. .data = &tcp_death_row.sysctl_max_tw_buckets,
  305. .maxlen = sizeof(int),
  306. .mode = 0644,
  307. .proc_handler = &proc_dointvec
  308. },
  309. {
  310. .ctl_name = NET_IPV4_IPFRAG_HIGH_THRESH,
  311. .procname = "ipfrag_high_thresh",
  312. .data = &ip4_frags_ctl.high_thresh,
  313. .maxlen = sizeof(int),
  314. .mode = 0644,
  315. .proc_handler = &proc_dointvec
  316. },
  317. {
  318. .ctl_name = NET_IPV4_IPFRAG_LOW_THRESH,
  319. .procname = "ipfrag_low_thresh",
  320. .data = &ip4_frags_ctl.low_thresh,
  321. .maxlen = sizeof(int),
  322. .mode = 0644,
  323. .proc_handler = &proc_dointvec
  324. },
  325. {
  326. .ctl_name = NET_IPV4_DYNADDR,
  327. .procname = "ip_dynaddr",
  328. .data = &sysctl_ip_dynaddr,
  329. .maxlen = sizeof(int),
  330. .mode = 0644,
  331. .proc_handler = &proc_dointvec
  332. },
  333. {
  334. .ctl_name = NET_IPV4_IPFRAG_TIME,
  335. .procname = "ipfrag_time",
  336. .data = &ip4_frags_ctl.timeout,
  337. .maxlen = sizeof(int),
  338. .mode = 0644,
  339. .proc_handler = &proc_dointvec_jiffies,
  340. .strategy = &sysctl_jiffies
  341. },
  342. {
  343. .ctl_name = NET_IPV4_TCP_KEEPALIVE_TIME,
  344. .procname = "tcp_keepalive_time",
  345. .data = &sysctl_tcp_keepalive_time,
  346. .maxlen = sizeof(int),
  347. .mode = 0644,
  348. .proc_handler = &proc_dointvec_jiffies,
  349. .strategy = &sysctl_jiffies
  350. },
  351. {
  352. .ctl_name = NET_IPV4_TCP_KEEPALIVE_PROBES,
  353. .procname = "tcp_keepalive_probes",
  354. .data = &sysctl_tcp_keepalive_probes,
  355. .maxlen = sizeof(int),
  356. .mode = 0644,
  357. .proc_handler = &proc_dointvec
  358. },
  359. {
  360. .ctl_name = NET_IPV4_TCP_KEEPALIVE_INTVL,
  361. .procname = "tcp_keepalive_intvl",
  362. .data = &sysctl_tcp_keepalive_intvl,
  363. .maxlen = sizeof(int),
  364. .mode = 0644,
  365. .proc_handler = &proc_dointvec_jiffies,
  366. .strategy = &sysctl_jiffies
  367. },
  368. {
  369. .ctl_name = NET_IPV4_TCP_RETRIES1,
  370. .procname = "tcp_retries1",
  371. .data = &sysctl_tcp_retries1,
  372. .maxlen = sizeof(int),
  373. .mode = 0644,
  374. .proc_handler = &proc_dointvec_minmax,
  375. .strategy = &sysctl_intvec,
  376. .extra2 = &tcp_retr1_max
  377. },
  378. {
  379. .ctl_name = NET_IPV4_TCP_RETRIES2,
  380. .procname = "tcp_retries2",
  381. .data = &sysctl_tcp_retries2,
  382. .maxlen = sizeof(int),
  383. .mode = 0644,
  384. .proc_handler = &proc_dointvec
  385. },
  386. {
  387. .ctl_name = NET_IPV4_TCP_FIN_TIMEOUT,
  388. .procname = "tcp_fin_timeout",
  389. .data = &sysctl_tcp_fin_timeout,
  390. .maxlen = sizeof(int),
  391. .mode = 0644,
  392. .proc_handler = &proc_dointvec_jiffies,
  393. .strategy = &sysctl_jiffies
  394. },
  395. #ifdef CONFIG_SYN_COOKIES
  396. {
  397. .ctl_name = NET_TCP_SYNCOOKIES,
  398. .procname = "tcp_syncookies",
  399. .data = &sysctl_tcp_syncookies,
  400. .maxlen = sizeof(int),
  401. .mode = 0644,
  402. .proc_handler = &proc_dointvec
  403. },
  404. #endif
  405. {
  406. .ctl_name = NET_TCP_TW_RECYCLE,
  407. .procname = "tcp_tw_recycle",
  408. .data = &tcp_death_row.sysctl_tw_recycle,
  409. .maxlen = sizeof(int),
  410. .mode = 0644,
  411. .proc_handler = &proc_dointvec
  412. },
  413. {
  414. .ctl_name = NET_TCP_ABORT_ON_OVERFLOW,
  415. .procname = "tcp_abort_on_overflow",
  416. .data = &sysctl_tcp_abort_on_overflow,
  417. .maxlen = sizeof(int),
  418. .mode = 0644,
  419. .proc_handler = &proc_dointvec
  420. },
  421. {
  422. .ctl_name = NET_TCP_STDURG,
  423. .procname = "tcp_stdurg",
  424. .data = &sysctl_tcp_stdurg,
  425. .maxlen = sizeof(int),
  426. .mode = 0644,
  427. .proc_handler = &proc_dointvec
  428. },
  429. {
  430. .ctl_name = NET_TCP_RFC1337,
  431. .procname = "tcp_rfc1337",
  432. .data = &sysctl_tcp_rfc1337,
  433. .maxlen = sizeof(int),
  434. .mode = 0644,
  435. .proc_handler = &proc_dointvec
  436. },
  437. {
  438. .ctl_name = NET_TCP_MAX_SYN_BACKLOG,
  439. .procname = "tcp_max_syn_backlog",
  440. .data = &sysctl_max_syn_backlog,
  441. .maxlen = sizeof(int),
  442. .mode = 0644,
  443. .proc_handler = &proc_dointvec
  444. },
  445. {
  446. .ctl_name = NET_IPV4_LOCAL_PORT_RANGE,
  447. .procname = "ip_local_port_range",
  448. .data = &sysctl_local_port_range,
  449. .maxlen = sizeof(sysctl_local_port_range),
  450. .mode = 0644,
  451. .proc_handler = &ipv4_local_port_range,
  452. .strategy = &ipv4_sysctl_local_port_range,
  453. },
  454. {
  455. .ctl_name = NET_IPV4_ICMP_ECHO_IGNORE_ALL,
  456. .procname = "icmp_echo_ignore_all",
  457. .data = &sysctl_icmp_echo_ignore_all,
  458. .maxlen = sizeof(int),
  459. .mode = 0644,
  460. .proc_handler = &proc_dointvec
  461. },
  462. {
  463. .ctl_name = NET_IPV4_ICMP_ECHO_IGNORE_BROADCASTS,
  464. .procname = "icmp_echo_ignore_broadcasts",
  465. .data = &sysctl_icmp_echo_ignore_broadcasts,
  466. .maxlen = sizeof(int),
  467. .mode = 0644,
  468. .proc_handler = &proc_dointvec
  469. },
  470. {
  471. .ctl_name = NET_IPV4_ICMP_IGNORE_BOGUS_ERROR_RESPONSES,
  472. .procname = "icmp_ignore_bogus_error_responses",
  473. .data = &sysctl_icmp_ignore_bogus_error_responses,
  474. .maxlen = sizeof(int),
  475. .mode = 0644,
  476. .proc_handler = &proc_dointvec
  477. },
  478. {
  479. .ctl_name = NET_IPV4_ICMP_ERRORS_USE_INBOUND_IFADDR,
  480. .procname = "icmp_errors_use_inbound_ifaddr",
  481. .data = &sysctl_icmp_errors_use_inbound_ifaddr,
  482. .maxlen = sizeof(int),
  483. .mode = 0644,
  484. .proc_handler = &proc_dointvec
  485. },
  486. {
  487. .ctl_name = NET_IPV4_ROUTE,
  488. .procname = "route",
  489. .maxlen = 0,
  490. .mode = 0555,
  491. .child = ipv4_route_table
  492. },
  493. #ifdef CONFIG_IP_MULTICAST
  494. {
  495. .ctl_name = NET_IPV4_IGMP_MAX_MEMBERSHIPS,
  496. .procname = "igmp_max_memberships",
  497. .data = &sysctl_igmp_max_memberships,
  498. .maxlen = sizeof(int),
  499. .mode = 0644,
  500. .proc_handler = &proc_dointvec
  501. },
  502. #endif
  503. {
  504. .ctl_name = NET_IPV4_IGMP_MAX_MSF,
  505. .procname = "igmp_max_msf",
  506. .data = &sysctl_igmp_max_msf,
  507. .maxlen = sizeof(int),
  508. .mode = 0644,
  509. .proc_handler = &proc_dointvec
  510. },
  511. {
  512. .ctl_name = NET_IPV4_INET_PEER_THRESHOLD,
  513. .procname = "inet_peer_threshold",
  514. .data = &inet_peer_threshold,
  515. .maxlen = sizeof(int),
  516. .mode = 0644,
  517. .proc_handler = &proc_dointvec
  518. },
  519. {
  520. .ctl_name = NET_IPV4_INET_PEER_MINTTL,
  521. .procname = "inet_peer_minttl",
  522. .data = &inet_peer_minttl,
  523. .maxlen = sizeof(int),
  524. .mode = 0644,
  525. .proc_handler = &proc_dointvec_jiffies,
  526. .strategy = &sysctl_jiffies
  527. },
  528. {
  529. .ctl_name = NET_IPV4_INET_PEER_MAXTTL,
  530. .procname = "inet_peer_maxttl",
  531. .data = &inet_peer_maxttl,
  532. .maxlen = sizeof(int),
  533. .mode = 0644,
  534. .proc_handler = &proc_dointvec_jiffies,
  535. .strategy = &sysctl_jiffies
  536. },
  537. {
  538. .ctl_name = NET_IPV4_INET_PEER_GC_MINTIME,
  539. .procname = "inet_peer_gc_mintime",
  540. .data = &inet_peer_gc_mintime,
  541. .maxlen = sizeof(int),
  542. .mode = 0644,
  543. .proc_handler = &proc_dointvec_jiffies,
  544. .strategy = &sysctl_jiffies
  545. },
  546. {
  547. .ctl_name = NET_IPV4_INET_PEER_GC_MAXTIME,
  548. .procname = "inet_peer_gc_maxtime",
  549. .data = &inet_peer_gc_maxtime,
  550. .maxlen = sizeof(int),
  551. .mode = 0644,
  552. .proc_handler = &proc_dointvec_jiffies,
  553. .strategy = &sysctl_jiffies
  554. },
  555. {
  556. .ctl_name = NET_TCP_ORPHAN_RETRIES,
  557. .procname = "tcp_orphan_retries",
  558. .data = &sysctl_tcp_orphan_retries,
  559. .maxlen = sizeof(int),
  560. .mode = 0644,
  561. .proc_handler = &proc_dointvec
  562. },
  563. {
  564. .ctl_name = NET_TCP_FACK,
  565. .procname = "tcp_fack",
  566. .data = &sysctl_tcp_fack,
  567. .maxlen = sizeof(int),
  568. .mode = 0644,
  569. .proc_handler = &proc_dointvec
  570. },
  571. {
  572. .ctl_name = NET_TCP_REORDERING,
  573. .procname = "tcp_reordering",
  574. .data = &sysctl_tcp_reordering,
  575. .maxlen = sizeof(int),
  576. .mode = 0644,
  577. .proc_handler = &proc_dointvec
  578. },
  579. {
  580. .ctl_name = NET_TCP_ECN,
  581. .procname = "tcp_ecn",
  582. .data = &sysctl_tcp_ecn,
  583. .maxlen = sizeof(int),
  584. .mode = 0644,
  585. .proc_handler = &proc_dointvec
  586. },
  587. {
  588. .ctl_name = NET_TCP_DSACK,
  589. .procname = "tcp_dsack",
  590. .data = &sysctl_tcp_dsack,
  591. .maxlen = sizeof(int),
  592. .mode = 0644,
  593. .proc_handler = &proc_dointvec
  594. },
  595. {
  596. .ctl_name = NET_TCP_MEM,
  597. .procname = "tcp_mem",
  598. .data = &sysctl_tcp_mem,
  599. .maxlen = sizeof(sysctl_tcp_mem),
  600. .mode = 0644,
  601. .proc_handler = &proc_dointvec
  602. },
  603. {
  604. .ctl_name = NET_TCP_WMEM,
  605. .procname = "tcp_wmem",
  606. .data = &sysctl_tcp_wmem,
  607. .maxlen = sizeof(sysctl_tcp_wmem),
  608. .mode = 0644,
  609. .proc_handler = &proc_dointvec
  610. },
  611. {
  612. .ctl_name = NET_TCP_RMEM,
  613. .procname = "tcp_rmem",
  614. .data = &sysctl_tcp_rmem,
  615. .maxlen = sizeof(sysctl_tcp_rmem),
  616. .mode = 0644,
  617. .proc_handler = &proc_dointvec
  618. },
  619. {
  620. .ctl_name = NET_TCP_APP_WIN,
  621. .procname = "tcp_app_win",
  622. .data = &sysctl_tcp_app_win,
  623. .maxlen = sizeof(int),
  624. .mode = 0644,
  625. .proc_handler = &proc_dointvec
  626. },
  627. {
  628. .ctl_name = NET_TCP_ADV_WIN_SCALE,
  629. .procname = "tcp_adv_win_scale",
  630. .data = &sysctl_tcp_adv_win_scale,
  631. .maxlen = sizeof(int),
  632. .mode = 0644,
  633. .proc_handler = &proc_dointvec
  634. },
  635. {
  636. .ctl_name = NET_IPV4_ICMP_RATELIMIT,
  637. .procname = "icmp_ratelimit",
  638. .data = &sysctl_icmp_ratelimit,
  639. .maxlen = sizeof(int),
  640. .mode = 0644,
  641. .proc_handler = &proc_dointvec
  642. },
  643. {
  644. .ctl_name = NET_IPV4_ICMP_RATEMASK,
  645. .procname = "icmp_ratemask",
  646. .data = &sysctl_icmp_ratemask,
  647. .maxlen = sizeof(int),
  648. .mode = 0644,
  649. .proc_handler = &proc_dointvec
  650. },
  651. {
  652. .ctl_name = NET_TCP_TW_REUSE,
  653. .procname = "tcp_tw_reuse",
  654. .data = &sysctl_tcp_tw_reuse,
  655. .maxlen = sizeof(int),
  656. .mode = 0644,
  657. .proc_handler = &proc_dointvec
  658. },
  659. {
  660. .ctl_name = NET_TCP_FRTO,
  661. .procname = "tcp_frto",
  662. .data = &sysctl_tcp_frto,
  663. .maxlen = sizeof(int),
  664. .mode = 0644,
  665. .proc_handler = &proc_dointvec
  666. },
  667. {
  668. .ctl_name = NET_TCP_FRTO_RESPONSE,
  669. .procname = "tcp_frto_response",
  670. .data = &sysctl_tcp_frto_response,
  671. .maxlen = sizeof(int),
  672. .mode = 0644,
  673. .proc_handler = &proc_dointvec
  674. },
  675. {
  676. .ctl_name = NET_TCP_LOW_LATENCY,
  677. .procname = "tcp_low_latency",
  678. .data = &sysctl_tcp_low_latency,
  679. .maxlen = sizeof(int),
  680. .mode = 0644,
  681. .proc_handler = &proc_dointvec
  682. },
  683. {
  684. .ctl_name = NET_IPV4_IPFRAG_SECRET_INTERVAL,
  685. .procname = "ipfrag_secret_interval",
  686. .data = &ip4_frags_ctl.secret_interval,
  687. .maxlen = sizeof(int),
  688. .mode = 0644,
  689. .proc_handler = &proc_dointvec_jiffies,
  690. .strategy = &sysctl_jiffies
  691. },
  692. {
  693. .procname = "ipfrag_max_dist",
  694. .data = &sysctl_ipfrag_max_dist,
  695. .maxlen = sizeof(int),
  696. .mode = 0644,
  697. .proc_handler = &proc_dointvec_minmax,
  698. .extra1 = &zero
  699. },
  700. {
  701. .ctl_name = NET_TCP_NO_METRICS_SAVE,
  702. .procname = "tcp_no_metrics_save",
  703. .data = &sysctl_tcp_nometrics_save,
  704. .maxlen = sizeof(int),
  705. .mode = 0644,
  706. .proc_handler = &proc_dointvec,
  707. },
  708. {
  709. .ctl_name = NET_TCP_MODERATE_RCVBUF,
  710. .procname = "tcp_moderate_rcvbuf",
  711. .data = &sysctl_tcp_moderate_rcvbuf,
  712. .maxlen = sizeof(int),
  713. .mode = 0644,
  714. .proc_handler = &proc_dointvec,
  715. },
  716. {
  717. .ctl_name = NET_TCP_TSO_WIN_DIVISOR,
  718. .procname = "tcp_tso_win_divisor",
  719. .data = &sysctl_tcp_tso_win_divisor,
  720. .maxlen = sizeof(int),
  721. .mode = 0644,
  722. .proc_handler = &proc_dointvec,
  723. },
  724. {
  725. .ctl_name = NET_TCP_CONG_CONTROL,
  726. .procname = "tcp_congestion_control",
  727. .mode = 0644,
  728. .maxlen = TCP_CA_NAME_MAX,
  729. .proc_handler = &proc_tcp_congestion_control,
  730. .strategy = &sysctl_tcp_congestion_control,
  731. },
  732. {
  733. .ctl_name = NET_TCP_ABC,
  734. .procname = "tcp_abc",
  735. .data = &sysctl_tcp_abc,
  736. .maxlen = sizeof(int),
  737. .mode = 0644,
  738. .proc_handler = &proc_dointvec,
  739. },
  740. {
  741. .ctl_name = NET_TCP_MTU_PROBING,
  742. .procname = "tcp_mtu_probing",
  743. .data = &sysctl_tcp_mtu_probing,
  744. .maxlen = sizeof(int),
  745. .mode = 0644,
  746. .proc_handler = &proc_dointvec,
  747. },
  748. {
  749. .ctl_name = NET_TCP_BASE_MSS,
  750. .procname = "tcp_base_mss",
  751. .data = &sysctl_tcp_base_mss,
  752. .maxlen = sizeof(int),
  753. .mode = 0644,
  754. .proc_handler = &proc_dointvec,
  755. },
  756. {
  757. .ctl_name = NET_IPV4_TCP_WORKAROUND_SIGNED_WINDOWS,
  758. .procname = "tcp_workaround_signed_windows",
  759. .data = &sysctl_tcp_workaround_signed_windows,
  760. .maxlen = sizeof(int),
  761. .mode = 0644,
  762. .proc_handler = &proc_dointvec
  763. },
  764. #ifdef CONFIG_NET_DMA
  765. {
  766. .ctl_name = NET_TCP_DMA_COPYBREAK,
  767. .procname = "tcp_dma_copybreak",
  768. .data = &sysctl_tcp_dma_copybreak,
  769. .maxlen = sizeof(int),
  770. .mode = 0644,
  771. .proc_handler = &proc_dointvec
  772. },
  773. #endif
  774. {
  775. .ctl_name = NET_TCP_SLOW_START_AFTER_IDLE,
  776. .procname = "tcp_slow_start_after_idle",
  777. .data = &sysctl_tcp_slow_start_after_idle,
  778. .maxlen = sizeof(int),
  779. .mode = 0644,
  780. .proc_handler = &proc_dointvec
  781. },
  782. #ifdef CONFIG_NETLABEL
  783. {
  784. .ctl_name = NET_CIPSOV4_CACHE_ENABLE,
  785. .procname = "cipso_cache_enable",
  786. .data = &cipso_v4_cache_enabled,
  787. .maxlen = sizeof(int),
  788. .mode = 0644,
  789. .proc_handler = &proc_dointvec,
  790. },
  791. {
  792. .ctl_name = NET_CIPSOV4_CACHE_BUCKET_SIZE,
  793. .procname = "cipso_cache_bucket_size",
  794. .data = &cipso_v4_cache_bucketsize,
  795. .maxlen = sizeof(int),
  796. .mode = 0644,
  797. .proc_handler = &proc_dointvec,
  798. },
  799. {
  800. .ctl_name = NET_CIPSOV4_RBM_OPTFMT,
  801. .procname = "cipso_rbm_optfmt",
  802. .data = &cipso_v4_rbm_optfmt,
  803. .maxlen = sizeof(int),
  804. .mode = 0644,
  805. .proc_handler = &proc_dointvec,
  806. },
  807. {
  808. .ctl_name = NET_CIPSOV4_RBM_STRICTVALID,
  809. .procname = "cipso_rbm_strictvalid",
  810. .data = &cipso_v4_rbm_strictvalid,
  811. .maxlen = sizeof(int),
  812. .mode = 0644,
  813. .proc_handler = &proc_dointvec,
  814. },
  815. #endif /* CONFIG_NETLABEL */
  816. {
  817. .procname = "tcp_available_congestion_control",
  818. .maxlen = TCP_CA_BUF_MAX,
  819. .mode = 0444,
  820. .proc_handler = &proc_tcp_available_congestion_control,
  821. },
  822. {
  823. .ctl_name = NET_TCP_ALLOWED_CONG_CONTROL,
  824. .procname = "tcp_allowed_congestion_control",
  825. .maxlen = TCP_CA_BUF_MAX,
  826. .mode = 0644,
  827. .proc_handler = &proc_allowed_congestion_control,
  828. .strategy = &strategy_allowed_congestion_control,
  829. },
  830. {
  831. .ctl_name = NET_TCP_MAX_SSTHRESH,
  832. .procname = "tcp_max_ssthresh",
  833. .data = &sysctl_tcp_max_ssthresh,
  834. .maxlen = sizeof(int),
  835. .mode = 0644,
  836. .proc_handler = &proc_dointvec,
  837. },
  838. { .ctl_name = 0 }
  839. };