]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blob - include/net/net_namespace.h
UBUNTU: [Debian] Only run regression-suite, if requested to.
[mirror_ubuntu-bionic-kernel.git] / include / net / net_namespace.h
1 /* SPDX-License-Identifier: GPL-2.0 */
2 /*
3 * Operations on the network namespace
4 */
5 #ifndef __NET_NET_NAMESPACE_H
6 #define __NET_NET_NAMESPACE_H
7
8 #include <linux/atomic.h>
9 #include <linux/refcount.h>
10 #include <linux/workqueue.h>
11 #include <linux/list.h>
12 #include <linux/sysctl.h>
13 #include <linux/uidgid.h>
14
15 #include <net/flow.h>
16 #include <net/netns/core.h>
17 #include <net/netns/mib.h>
18 #include <net/netns/unix.h>
19 #include <net/netns/packet.h>
20 #include <net/netns/ipv4.h>
21 #include <net/netns/ipv6.h>
22 #include <net/netns/ieee802154_6lowpan.h>
23 #include <net/netns/sctp.h>
24 #include <net/netns/dccp.h>
25 #include <net/netns/netfilter.h>
26 #include <net/netns/x_tables.h>
27 #if defined(CONFIG_NF_CONNTRACK) || defined(CONFIG_NF_CONNTRACK_MODULE)
28 #include <net/netns/conntrack.h>
29 #endif
30 #include <net/netns/nftables.h>
31 #include <net/netns/xfrm.h>
32 #include <net/netns/mpls.h>
33 #include <net/netns/can.h>
34 #include <linux/ns_common.h>
35 #include <linux/idr.h>
36 #include <linux/skbuff.h>
37
38 struct user_namespace;
39 struct proc_dir_entry;
40 struct net_device;
41 struct sock;
42 struct ctl_table_header;
43 struct net_generic;
44 struct sock;
45 struct netns_ipvs;
46
47
48 #define NETDEV_HASHBITS 8
49 #define NETDEV_HASHENTRIES (1 << NETDEV_HASHBITS)
50
51 struct net {
52 refcount_t passive; /* To decided when the network
53 * namespace should be freed.
54 */
55 atomic_t count; /* To decided when the network
56 * namespace should be shut down.
57 */
58 spinlock_t rules_mod_lock;
59
60 atomic64_t cookie_gen;
61
62 struct list_head list; /* list of network namespaces */
63 struct list_head cleanup_list; /* namespaces on death row */
64 struct list_head exit_list; /* Use only net_mutex */
65
66 struct user_namespace *user_ns; /* Owning user namespace */
67 struct ucounts *ucounts;
68 spinlock_t nsid_lock;
69 struct idr netns_ids;
70
71 struct ns_common ns;
72
73 struct proc_dir_entry *proc_net;
74 struct proc_dir_entry *proc_net_stat;
75
76 #ifdef CONFIG_SYSCTL
77 struct ctl_table_set sysctls;
78 #endif
79
80 struct sock *rtnl; /* rtnetlink socket */
81 struct sock *genl_sock;
82
83 struct list_head dev_base_head;
84 struct hlist_head *dev_name_head;
85 struct hlist_head *dev_index_head;
86 unsigned int dev_base_seq; /* protected by rtnl_mutex */
87 int ifindex;
88 unsigned int dev_unreg_count;
89
90 /* core fib_rules */
91 struct list_head rules_ops;
92
93 struct list_head fib_notifier_ops; /* protected by net_mutex */
94
95 struct net_device *loopback_dev; /* The loopback */
96 struct netns_core core;
97 struct netns_mib mib;
98 struct netns_packet packet;
99 struct netns_unix unx;
100 struct netns_ipv4 ipv4;
101 #if IS_ENABLED(CONFIG_IPV6)
102 struct netns_ipv6 ipv6;
103 #endif
104 #if IS_ENABLED(CONFIG_IEEE802154_6LOWPAN)
105 struct netns_ieee802154_lowpan ieee802154_lowpan;
106 #endif
107 #if defined(CONFIG_IP_SCTP) || defined(CONFIG_IP_SCTP_MODULE)
108 struct netns_sctp sctp;
109 #endif
110 #if defined(CONFIG_IP_DCCP) || defined(CONFIG_IP_DCCP_MODULE)
111 struct netns_dccp dccp;
112 #endif
113 #ifdef CONFIG_NETFILTER
114 struct netns_nf nf;
115 struct netns_xt xt;
116 #if defined(CONFIG_NF_CONNTRACK) || defined(CONFIG_NF_CONNTRACK_MODULE)
117 struct netns_ct ct;
118 #endif
119 #if defined(CONFIG_NF_TABLES) || defined(CONFIG_NF_TABLES_MODULE)
120 struct netns_nftables nft;
121 #endif
122 #if IS_ENABLED(CONFIG_NF_DEFRAG_IPV6)
123 struct netns_nf_frag nf_frag;
124 #endif
125 struct sock *nfnl;
126 struct sock *nfnl_stash;
127 #if IS_ENABLED(CONFIG_NETFILTER_NETLINK_ACCT)
128 struct list_head nfnl_acct_list;
129 #endif
130 #if IS_ENABLED(CONFIG_NF_CT_NETLINK_TIMEOUT)
131 struct list_head nfct_timeout_list;
132 #endif
133 #endif
134 #ifdef CONFIG_WEXT_CORE
135 struct sk_buff_head wext_nlevents;
136 #endif
137 struct net_generic __rcu *gen;
138
139 /* Note : following structs are cache line aligned */
140 #ifdef CONFIG_XFRM
141 struct netns_xfrm xfrm;
142 #endif
143 #if IS_ENABLED(CONFIG_IP_VS)
144 struct netns_ipvs *ipvs;
145 #endif
146 #if IS_ENABLED(CONFIG_MPLS)
147 struct netns_mpls mpls;
148 #endif
149 #if IS_ENABLED(CONFIG_CAN)
150 struct netns_can can;
151 #endif
152 struct sock *diag_nlsk;
153 atomic_t fnhe_genid;
154 } __randomize_layout;
155
156 #include <linux/seq_file_net.h>
157
158 /* Init's network namespace */
159 extern struct net init_net;
160
161 #ifdef CONFIG_NET_NS
162 struct net *copy_net_ns(unsigned long flags, struct user_namespace *user_ns,
163 struct net *old_net);
164
165 void net_ns_get_ownership(const struct net *net, kuid_t *uid, kgid_t *gid);
166
167 void net_ns_barrier(void);
168 #else /* CONFIG_NET_NS */
169 #include <linux/sched.h>
170 #include <linux/nsproxy.h>
171 static inline struct net *copy_net_ns(unsigned long flags,
172 struct user_namespace *user_ns, struct net *old_net)
173 {
174 if (flags & CLONE_NEWNET)
175 return ERR_PTR(-EINVAL);
176 return old_net;
177 }
178
179 static inline void net_ns_get_ownership(const struct net *net,
180 kuid_t *uid, kgid_t *gid)
181 {
182 *uid = GLOBAL_ROOT_UID;
183 *gid = GLOBAL_ROOT_GID;
184 }
185
186 static inline void net_ns_barrier(void) {}
187 #endif /* CONFIG_NET_NS */
188
189
190 extern struct list_head net_namespace_list;
191
192 struct net *get_net_ns_by_pid(pid_t pid);
193 struct net *get_net_ns_by_fd(int fd);
194
195 #ifdef CONFIG_SYSCTL
196 void ipx_register_sysctl(void);
197 void ipx_unregister_sysctl(void);
198 #else
199 #define ipx_register_sysctl()
200 #define ipx_unregister_sysctl()
201 #endif
202
203 #ifdef CONFIG_NET_NS
204 void __put_net(struct net *net);
205
206 static inline struct net *get_net(struct net *net)
207 {
208 atomic_inc(&net->count);
209 return net;
210 }
211
212 static inline struct net *maybe_get_net(struct net *net)
213 {
214 /* Used when we know struct net exists but we
215 * aren't guaranteed a previous reference count
216 * exists. If the reference count is zero this
217 * function fails and returns NULL.
218 */
219 if (!atomic_inc_not_zero(&net->count))
220 net = NULL;
221 return net;
222 }
223
224 static inline void put_net(struct net *net)
225 {
226 if (atomic_dec_and_test(&net->count))
227 __put_net(net);
228 }
229
230 static inline
231 int net_eq(const struct net *net1, const struct net *net2)
232 {
233 return net1 == net2;
234 }
235
236 static inline int check_net(const struct net *net)
237 {
238 return atomic_read(&net->count) != 0;
239 }
240
241 void net_drop_ns(void *);
242
243 #else
244
245 static inline struct net *get_net(struct net *net)
246 {
247 return net;
248 }
249
250 static inline void put_net(struct net *net)
251 {
252 }
253
254 static inline struct net *maybe_get_net(struct net *net)
255 {
256 return net;
257 }
258
259 static inline
260 int net_eq(const struct net *net1, const struct net *net2)
261 {
262 return 1;
263 }
264
265 static inline int check_net(const struct net *net)
266 {
267 return 1;
268 }
269
270 #define net_drop_ns NULL
271 #endif
272
273
274 typedef struct {
275 #ifdef CONFIG_NET_NS
276 struct net *net;
277 #endif
278 } possible_net_t;
279
280 static inline void write_pnet(possible_net_t *pnet, struct net *net)
281 {
282 #ifdef CONFIG_NET_NS
283 pnet->net = net;
284 #endif
285 }
286
287 static inline struct net *read_pnet(const possible_net_t *pnet)
288 {
289 #ifdef CONFIG_NET_NS
290 return pnet->net;
291 #else
292 return &init_net;
293 #endif
294 }
295
296 #define for_each_net(VAR) \
297 list_for_each_entry(VAR, &net_namespace_list, list)
298
299 #define for_each_net_rcu(VAR) \
300 list_for_each_entry_rcu(VAR, &net_namespace_list, list)
301
302 #ifdef CONFIG_NET_NS
303 #define __net_init
304 #define __net_exit
305 #define __net_initdata
306 #define __net_initconst
307 #else
308 #define __net_init __init
309 #define __net_exit __ref
310 #define __net_initdata __initdata
311 #define __net_initconst __initconst
312 #endif
313
314 int peernet2id_alloc(struct net *net, struct net *peer);
315 int peernet2id(struct net *net, struct net *peer);
316 bool peernet_has_id(struct net *net, struct net *peer);
317 struct net *get_net_ns_by_id(struct net *net, int id);
318
319 struct pernet_operations {
320 struct list_head list;
321 int (*init)(struct net *net);
322 void (*exit)(struct net *net);
323 void (*exit_batch)(struct list_head *net_exit_list);
324 unsigned int *id;
325 size_t size;
326 };
327
328 /*
329 * Use these carefully. If you implement a network device and it
330 * needs per network namespace operations use device pernet operations,
331 * otherwise use pernet subsys operations.
332 *
333 * Network interfaces need to be removed from a dying netns _before_
334 * subsys notifiers can be called, as most of the network code cleanup
335 * (which is done from subsys notifiers) runs with the assumption that
336 * dev_remove_pack has been called so no new packets will arrive during
337 * and after the cleanup functions have been called. dev_remove_pack
338 * is not per namespace so instead the guarantee of no more packets
339 * arriving in a network namespace is provided by ensuring that all
340 * network devices and all sockets have left the network namespace
341 * before the cleanup methods are called.
342 *
343 * For the longest time the ipv4 icmp code was registered as a pernet
344 * device which caused kernel oops, and panics during network
345 * namespace cleanup. So please don't get this wrong.
346 */
347 int register_pernet_subsys(struct pernet_operations *);
348 void unregister_pernet_subsys(struct pernet_operations *);
349 int register_pernet_device(struct pernet_operations *);
350 void unregister_pernet_device(struct pernet_operations *);
351
352 struct ctl_table;
353 struct ctl_table_header;
354
355 #ifdef CONFIG_SYSCTL
356 int net_sysctl_init(void);
357 struct ctl_table_header *register_net_sysctl(struct net *net, const char *path,
358 struct ctl_table *table);
359 void unregister_net_sysctl_table(struct ctl_table_header *header);
360 #else
361 static inline int net_sysctl_init(void) { return 0; }
362 static inline struct ctl_table_header *register_net_sysctl(struct net *net,
363 const char *path, struct ctl_table *table)
364 {
365 return NULL;
366 }
367 static inline void unregister_net_sysctl_table(struct ctl_table_header *header)
368 {
369 }
370 #endif
371
372 static inline int rt_genid_ipv4(struct net *net)
373 {
374 return atomic_read(&net->ipv4.rt_genid);
375 }
376
377 static inline void rt_genid_bump_ipv4(struct net *net)
378 {
379 atomic_inc(&net->ipv4.rt_genid);
380 }
381
382 extern void (*__fib6_flush_trees)(struct net *net);
383 static inline void rt_genid_bump_ipv6(struct net *net)
384 {
385 if (__fib6_flush_trees)
386 __fib6_flush_trees(net);
387 }
388
389 #if IS_ENABLED(CONFIG_IEEE802154_6LOWPAN)
390 static inline struct netns_ieee802154_lowpan *
391 net_ieee802154_lowpan(struct net *net)
392 {
393 return &net->ieee802154_lowpan;
394 }
395 #endif
396
397 /* For callers who don't really care about whether it's IPv4 or IPv6 */
398 static inline void rt_genid_bump_all(struct net *net)
399 {
400 rt_genid_bump_ipv4(net);
401 rt_genid_bump_ipv6(net);
402 }
403
404 static inline int fnhe_genid(struct net *net)
405 {
406 return atomic_read(&net->fnhe_genid);
407 }
408
409 static inline void fnhe_genid_bump(struct net *net)
410 {
411 atomic_inc(&net->fnhe_genid);
412 }
413
414 #endif /* __NET_NET_NAMESPACE_H */