Commit | Line | Data |
---|---|---|
5f256bec EB |
1 | /* |
2 | * Operations on the network namespace | |
3 | */ | |
4 | #ifndef __NET_NET_NAMESPACE_H | |
5 | #define __NET_NET_NAMESPACE_H | |
6 | ||
60063497 | 7 | #include <linux/atomic.h> |
5f256bec EB |
8 | #include <linux/workqueue.h> |
9 | #include <linux/list.h> | |
bee95250 | 10 | #include <linux/sysctl.h> |
5f256bec | 11 | |
6a662719 | 12 | #include <net/flow.h> |
8efa6e93 | 13 | #include <net/netns/core.h> |
852566f5 | 14 | #include <net/netns/mib.h> |
a0a53c8b | 15 | #include <net/netns/unix.h> |
2aaef4e4 | 16 | #include <net/netns/packet.h> |
8afd351c | 17 | #include <net/netns/ipv4.h> |
b0f159db | 18 | #include <net/netns/ipv6.h> |
633fc86f | 19 | #include <net/netns/ieee802154_6lowpan.h> |
4db67e80 | 20 | #include <net/netns/sctp.h> |
67019cc9 | 21 | #include <net/netns/dccp.h> |
f3c1a44a | 22 | #include <net/netns/netfilter.h> |
8d870052 | 23 | #include <net/netns/x_tables.h> |
dfdb8d79 AD |
24 | #if defined(CONFIG_NF_CONNTRACK) || defined(CONFIG_NF_CONNTRACK_MODULE) |
25 | #include <net/netns/conntrack.h> | |
26 | #endif | |
99633ab2 | 27 | #include <net/netns/nftables.h> |
d62ddc21 | 28 | #include <net/netns/xfrm.h> |
a0a53c8b | 29 | |
038e7332 | 30 | struct user_namespace; |
457c4cbc | 31 | struct proc_dir_entry; |
2774c7ab | 32 | struct net_device; |
97c53cac | 33 | struct sock; |
1597fbc0 | 34 | struct ctl_table_header; |
dec827d1 | 35 | struct net_generic; |
134e6375 | 36 | struct sock; |
2553d064 | 37 | struct netns_ipvs; |
1597fbc0 | 38 | |
7c28bd0b ED |
39 | |
40 | #define NETDEV_HASHBITS 8 | |
41 | #define NETDEV_HASHENTRIES (1 << NETDEV_HASHBITS) | |
42 | ||
5f256bec | 43 | struct net { |
a685e089 AV |
44 | atomic_t passive; /* To decided when the network |
45 | * namespace should be freed. | |
46 | */ | |
5f256bec | 47 | atomic_t count; /* To decided when the network |
a685e089 | 48 | * namespace should be shut down. |
5f256bec | 49 | */ |
5d1e4468 | 50 | #ifdef NETNS_REFCNT_DEBUG |
5f256bec EB |
51 | atomic_t use_count; /* To track references we |
52 | * destroy on demand | |
53 | */ | |
5d1e4468 | 54 | #endif |
8e602ce2 ED |
55 | spinlock_t rules_mod_lock; |
56 | ||
5f256bec | 57 | struct list_head list; /* list of network namespaces */ |
2b035b39 | 58 | struct list_head cleanup_list; /* namespaces on death row */ |
72ad937a | 59 | struct list_head exit_list; /* Use only net_mutex */ |
457c4cbc | 60 | |
038e7332 EB |
61 | struct user_namespace *user_ns; /* Owning user namespace */ |
62 | ||
98f842e6 EB |
63 | unsigned int proc_inum; |
64 | ||
457c4cbc EB |
65 | struct proc_dir_entry *proc_net; |
66 | struct proc_dir_entry *proc_net_stat; | |
881d966b | 67 | |
73455092 AV |
68 | #ifdef CONFIG_SYSCTL |
69 | struct ctl_table_set sysctls; | |
70 | #endif | |
95bdfccb | 71 | |
8e602ce2 ED |
72 | struct sock *rtnl; /* rtnetlink socket */ |
73 | struct sock *genl_sock; | |
2774c7ab | 74 | |
881d966b EB |
75 | struct list_head dev_base_head; |
76 | struct hlist_head *dev_name_head; | |
77 | struct hlist_head *dev_index_head; | |
4e985ada | 78 | unsigned int dev_base_seq; /* protected by rtnl_mutex */ |
aa79e66e | 79 | int ifindex; |
50624c93 | 80 | unsigned int dev_unreg_count; |
97c53cac | 81 | |
5fd30ee7 DL |
82 | /* core fib_rules */ |
83 | struct list_head rules_ops; | |
5fd30ee7 | 84 | |
d12d01d6 | 85 | |
8e602ce2 | 86 | struct net_device *loopback_dev; /* The loopback */ |
8efa6e93 | 87 | struct netns_core core; |
852566f5 | 88 | struct netns_mib mib; |
2aaef4e4 | 89 | struct netns_packet packet; |
a0a53c8b | 90 | struct netns_unix unx; |
8afd351c | 91 | struct netns_ipv4 ipv4; |
dfd56b8b | 92 | #if IS_ENABLED(CONFIG_IPV6) |
b0f159db DL |
93 | struct netns_ipv6 ipv6; |
94 | #endif | |
633fc86f AA |
95 | #if IS_ENABLED(CONFIG_IEEE802154_6LOWPAN) |
96 | struct netns_ieee802154_lowpan ieee802154_lowpan; | |
97 | #endif | |
4db67e80 EB |
98 | #if defined(CONFIG_IP_SCTP) || defined(CONFIG_IP_SCTP_MODULE) |
99 | struct netns_sctp sctp; | |
100 | #endif | |
67019cc9 PE |
101 | #if defined(CONFIG_IP_DCCP) || defined(CONFIG_IP_DCCP_MODULE) |
102 | struct netns_dccp dccp; | |
103 | #endif | |
8d870052 | 104 | #ifdef CONFIG_NETFILTER |
f3c1a44a | 105 | struct netns_nf nf; |
8d870052 | 106 | struct netns_xt xt; |
dfdb8d79 AD |
107 | #if defined(CONFIG_NF_CONNTRACK) || defined(CONFIG_NF_CONNTRACK_MODULE) |
108 | struct netns_ct ct; | |
c038a767 | 109 | #endif |
99633ab2 PNA |
110 | #if defined(CONFIG_NF_TABLES) || defined(CONFIG_NF_TABLES_MODULE) |
111 | struct netns_nftables nft; | |
112 | #endif | |
c038a767 AW |
113 | #if IS_ENABLED(CONFIG_NF_DEFRAG_IPV6) |
114 | struct netns_nf_frag nf_frag; | |
dfdb8d79 | 115 | #endif |
cd8c20b6 AD |
116 | struct sock *nfnl; |
117 | struct sock *nfnl_stash; | |
d62ddc21 | 118 | #endif |
3d23e349 | 119 | #ifdef CONFIG_WEXT_CORE |
b333b3d2 | 120 | struct sk_buff_head wext_nlevents; |
8d870052 | 121 | #endif |
1c87733d | 122 | struct net_generic __rcu *gen; |
8e602ce2 ED |
123 | |
124 | /* Note : following structs are cache line aligned */ | |
125 | #ifdef CONFIG_XFRM | |
126 | struct netns_xfrm xfrm; | |
127 | #endif | |
8b4d14d8 | 128 | #if IS_ENABLED(CONFIG_IP_VS) |
61b1ab45 | 129 | struct netns_ipvs *ipvs; |
8b4d14d8 | 130 | #endif |
51d7cccf | 131 | struct sock *diag_nlsk; |
5aad1de5 | 132 | atomic_t fnhe_genid; |
5f256bec EB |
133 | }; |
134 | ||
c0f39322 DL |
135 | #include <linux/seq_file_net.h> |
136 | ||
4fabcd71 | 137 | /* Init's network namespace */ |
5f256bec | 138 | extern struct net init_net; |
a4aa834a | 139 | |
d727abcb | 140 | #ifdef CONFIG_NET_NS |
e67e16ea JP |
141 | struct net *copy_net_ns(unsigned long flags, struct user_namespace *user_ns, |
142 | struct net *old_net); | |
225c0a01 | 143 | |
d727abcb EB |
144 | #else /* CONFIG_NET_NS */ |
145 | #include <linux/sched.h> | |
146 | #include <linux/nsproxy.h> | |
038e7332 EB |
147 | static inline struct net *copy_net_ns(unsigned long flags, |
148 | struct user_namespace *user_ns, struct net *old_net) | |
9dd776b6 | 149 | { |
d727abcb EB |
150 | if (flags & CLONE_NEWNET) |
151 | return ERR_PTR(-EINVAL); | |
152 | return old_net; | |
9dd776b6 | 153 | } |
d727abcb | 154 | #endif /* CONFIG_NET_NS */ |
225c0a01 DL |
155 | |
156 | ||
157 | extern struct list_head net_namespace_list; | |
9dd776b6 | 158 | |
e67e16ea JP |
159 | struct net *get_net_ns_by_pid(pid_t pid); |
160 | struct net *get_net_ns_by_fd(int pid); | |
30ffee84 | 161 | |
535d3ae9 RK |
162 | #ifdef CONFIG_SYSCTL |
163 | void ipx_register_sysctl(void); | |
164 | void ipx_unregister_sysctl(void); | |
165 | #else | |
166 | #define ipx_register_sysctl() | |
167 | #define ipx_unregister_sysctl() | |
168 | #endif | |
169 | ||
d4655795 | 170 | #ifdef CONFIG_NET_NS |
e67e16ea | 171 | void __put_net(struct net *net); |
5f256bec EB |
172 | |
173 | static inline struct net *get_net(struct net *net) | |
174 | { | |
175 | atomic_inc(&net->count); | |
176 | return net; | |
177 | } | |
178 | ||
077130c0 EB |
179 | static inline struct net *maybe_get_net(struct net *net) |
180 | { | |
181 | /* Used when we know struct net exists but we | |
182 | * aren't guaranteed a previous reference count | |
183 | * exists. If the reference count is zero this | |
184 | * function fails and returns NULL. | |
185 | */ | |
186 | if (!atomic_inc_not_zero(&net->count)) | |
187 | net = NULL; | |
188 | return net; | |
189 | } | |
190 | ||
5f256bec EB |
191 | static inline void put_net(struct net *net) |
192 | { | |
193 | if (atomic_dec_and_test(&net->count)) | |
194 | __put_net(net); | |
195 | } | |
196 | ||
878628fb YH |
197 | static inline |
198 | int net_eq(const struct net *net1, const struct net *net2) | |
199 | { | |
200 | return net1 == net2; | |
201 | } | |
a685e089 | 202 | |
e67e16ea | 203 | void net_drop_ns(void *); |
a685e089 | 204 | |
d4655795 | 205 | #else |
b9f75f45 | 206 | |
d4655795 PE |
207 | static inline struct net *get_net(struct net *net) |
208 | { | |
209 | return net; | |
210 | } | |
211 | ||
212 | static inline void put_net(struct net *net) | |
213 | { | |
214 | } | |
215 | ||
5d1e4468 DL |
216 | static inline struct net *maybe_get_net(struct net *net) |
217 | { | |
218 | return net; | |
219 | } | |
220 | ||
221 | static inline | |
222 | int net_eq(const struct net *net1, const struct net *net2) | |
223 | { | |
224 | return 1; | |
225 | } | |
a685e089 AV |
226 | |
227 | #define net_drop_ns NULL | |
5d1e4468 DL |
228 | #endif |
229 | ||
230 | ||
231 | #ifdef NETNS_REFCNT_DEBUG | |
d4655795 PE |
232 | static inline struct net *hold_net(struct net *net) |
233 | { | |
5d1e4468 DL |
234 | if (net) |
235 | atomic_inc(&net->use_count); | |
d4655795 PE |
236 | return net; |
237 | } | |
238 | ||
239 | static inline void release_net(struct net *net) | |
240 | { | |
5d1e4468 DL |
241 | if (net) |
242 | atomic_dec(&net->use_count); | |
d4655795 | 243 | } |
5d1e4468 DL |
244 | #else |
245 | static inline struct net *hold_net(struct net *net) | |
d4655795 PE |
246 | { |
247 | return net; | |
248 | } | |
878628fb | 249 | |
5d1e4468 | 250 | static inline void release_net(struct net *net) |
878628fb | 251 | { |
878628fb | 252 | } |
d4655795 | 253 | #endif |
5f256bec | 254 | |
8f424b5f ED |
255 | #ifdef CONFIG_NET_NS |
256 | ||
257 | static inline void write_pnet(struct net **pnet, struct net *net) | |
258 | { | |
259 | *pnet = net; | |
260 | } | |
261 | ||
262 | static inline struct net *read_pnet(struct net * const *pnet) | |
263 | { | |
264 | return *pnet; | |
265 | } | |
266 | ||
267 | #else | |
268 | ||
269 | #define write_pnet(pnet, net) do { (void)(net);} while (0) | |
270 | #define read_pnet(pnet) (&init_net) | |
271 | ||
272 | #endif | |
5d1e4468 | 273 | |
5f256bec EB |
274 | #define for_each_net(VAR) \ |
275 | list_for_each_entry(VAR, &net_namespace_list, list) | |
276 | ||
11a28d37 JB |
277 | #define for_each_net_rcu(VAR) \ |
278 | list_for_each_entry_rcu(VAR, &net_namespace_list, list) | |
279 | ||
4665079c PE |
280 | #ifdef CONFIG_NET_NS |
281 | #define __net_init | |
282 | #define __net_exit | |
022cbae6 | 283 | #define __net_initdata |
04a6f82c | 284 | #define __net_initconst |
4665079c PE |
285 | #else |
286 | #define __net_init __init | |
287 | #define __net_exit __exit_refok | |
022cbae6 | 288 | #define __net_initdata __initdata |
04a6f82c | 289 | #define __net_initconst __initconst |
4665079c | 290 | #endif |
5f256bec EB |
291 | |
292 | struct pernet_operations { | |
293 | struct list_head list; | |
294 | int (*init)(struct net *net); | |
295 | void (*exit)(struct net *net); | |
72ad937a | 296 | void (*exit_batch)(struct list_head *net_exit_list); |
f875bae0 EB |
297 | int *id; |
298 | size_t size; | |
5f256bec EB |
299 | }; |
300 | ||
17edde52 EB |
301 | /* |
302 | * Use these carefully. If you implement a network device and it | |
303 | * needs per network namespace operations use device pernet operations, | |
304 | * otherwise use pernet subsys operations. | |
305 | * | |
4edf547b JB |
306 | * Network interfaces need to be removed from a dying netns _before_ |
307 | * subsys notifiers can be called, as most of the network code cleanup | |
308 | * (which is done from subsys notifiers) runs with the assumption that | |
309 | * dev_remove_pack has been called so no new packets will arrive during | |
310 | * and after the cleanup functions have been called. dev_remove_pack | |
311 | * is not per namespace so instead the guarantee of no more packets | |
312 | * arriving in a network namespace is provided by ensuring that all | |
313 | * network devices and all sockets have left the network namespace | |
314 | * before the cleanup methods are called. | |
17edde52 EB |
315 | * |
316 | * For the longest time the ipv4 icmp code was registered as a pernet | |
317 | * device which caused kernel oops, and panics during network | |
318 | * namespace cleanup. So please don't get this wrong. | |
319 | */ | |
e67e16ea JP |
320 | int register_pernet_subsys(struct pernet_operations *); |
321 | void unregister_pernet_subsys(struct pernet_operations *); | |
322 | int register_pernet_device(struct pernet_operations *); | |
323 | void unregister_pernet_device(struct pernet_operations *); | |
f875bae0 | 324 | |
95bdfccb EB |
325 | struct ctl_table; |
326 | struct ctl_table_header; | |
d62c612e | 327 | |
2ca794e5 | 328 | #ifdef CONFIG_SYSCTL |
e67e16ea JP |
329 | int net_sysctl_init(void); |
330 | struct ctl_table_header *register_net_sysctl(struct net *net, const char *path, | |
331 | struct ctl_table *table); | |
332 | void unregister_net_sysctl_table(struct ctl_table_header *header); | |
48c74958 EB |
333 | #else |
334 | static inline int net_sysctl_init(void) { return 0; } | |
335 | static inline struct ctl_table_header *register_net_sysctl(struct net *net, | |
336 | const char *path, struct ctl_table *table) | |
337 | { | |
338 | return NULL; | |
339 | } | |
340 | static inline void unregister_net_sysctl_table(struct ctl_table_header *header) | |
341 | { | |
342 | } | |
343 | #endif | |
344 | ||
ca4c3fc2 | 345 | static inline int rt_genid_ipv4(struct net *net) |
b42664f8 | 346 | { |
ca4c3fc2 | 347 | return atomic_read(&net->ipv4.rt_genid); |
b42664f8 ND |
348 | } |
349 | ||
ca4c3fc2 | 350 | static inline void rt_genid_bump_ipv4(struct net *net) |
b42664f8 | 351 | { |
ca4c3fc2 | 352 | atomic_inc(&net->ipv4.rt_genid); |
353 | } | |
354 | ||
355 | #if IS_ENABLED(CONFIG_IPV6) | |
356 | static inline int rt_genid_ipv6(struct net *net) | |
357 | { | |
358 | return atomic_read(&net->ipv6.rt_genid); | |
359 | } | |
360 | ||
361 | static inline void rt_genid_bump_ipv6(struct net *net) | |
362 | { | |
363 | atomic_inc(&net->ipv6.rt_genid); | |
364 | } | |
365 | #else | |
366 | static inline int rt_genid_ipv6(struct net *net) | |
367 | { | |
368 | return 0; | |
369 | } | |
370 | ||
371 | static inline void rt_genid_bump_ipv6(struct net *net) | |
372 | { | |
373 | } | |
374 | #endif | |
375 | ||
599018a7 LR |
376 | #if IS_ENABLED(CONFIG_IEEE802154_6LOWPAN) |
377 | static inline struct netns_ieee802154_lowpan * | |
378 | net_ieee802154_lowpan(struct net *net) | |
379 | { | |
380 | return &net->ieee802154_lowpan; | |
381 | } | |
599018a7 LR |
382 | #endif |
383 | ||
ca4c3fc2 | 384 | /* For callers who don't really care about whether it's IPv4 or IPv6 */ |
385 | static inline void rt_genid_bump_all(struct net *net) | |
386 | { | |
387 | rt_genid_bump_ipv4(net); | |
388 | rt_genid_bump_ipv6(net); | |
b42664f8 | 389 | } |
95bdfccb | 390 | |
5aad1de5 TT |
391 | static inline int fnhe_genid(struct net *net) |
392 | { | |
393 | return atomic_read(&net->fnhe_genid); | |
394 | } | |
395 | ||
396 | static inline void fnhe_genid_bump(struct net *net) | |
397 | { | |
398 | atomic_inc(&net->fnhe_genid); | |
399 | } | |
400 | ||
5f256bec | 401 | #endif /* __NET_NET_NAMESPACE_H */ |