1*4882a593Smuzhiyun /* SPDX-License-Identifier: GPL-2.0 */ 2*4882a593Smuzhiyun /* 3*4882a593Smuzhiyun * ipv4 in net namespaces 4*4882a593Smuzhiyun */ 5*4882a593Smuzhiyun 6*4882a593Smuzhiyun #ifndef __NETNS_IPV4_H__ 7*4882a593Smuzhiyun #define __NETNS_IPV4_H__ 8*4882a593Smuzhiyun 9*4882a593Smuzhiyun #include <linux/uidgid.h> 10*4882a593Smuzhiyun #include <net/inet_frag.h> 11*4882a593Smuzhiyun #include <linux/rcupdate.h> 12*4882a593Smuzhiyun #include <linux/siphash.h> 13*4882a593Smuzhiyun #include <linux/android_kabi.h> 14*4882a593Smuzhiyun 15*4882a593Smuzhiyun struct tcpm_hash_bucket; 16*4882a593Smuzhiyun struct ctl_table_header; 17*4882a593Smuzhiyun struct ipv4_devconf; 18*4882a593Smuzhiyun struct fib_rules_ops; 19*4882a593Smuzhiyun struct hlist_head; 20*4882a593Smuzhiyun struct fib_table; 21*4882a593Smuzhiyun struct sock; 22*4882a593Smuzhiyun struct local_ports { 23*4882a593Smuzhiyun seqlock_t lock; 24*4882a593Smuzhiyun int range[2]; 25*4882a593Smuzhiyun bool warned; 26*4882a593Smuzhiyun }; 27*4882a593Smuzhiyun 28*4882a593Smuzhiyun struct ping_group_range { 29*4882a593Smuzhiyun seqlock_t lock; 30*4882a593Smuzhiyun kgid_t range[2]; 31*4882a593Smuzhiyun }; 32*4882a593Smuzhiyun 33*4882a593Smuzhiyun struct inet_hashinfo; 34*4882a593Smuzhiyun 35*4882a593Smuzhiyun struct inet_timewait_death_row { 36*4882a593Smuzhiyun atomic_t tw_count; 37*4882a593Smuzhiyun 38*4882a593Smuzhiyun struct inet_hashinfo *hashinfo ____cacheline_aligned_in_smp; 39*4882a593Smuzhiyun int sysctl_max_tw_buckets; 40*4882a593Smuzhiyun }; 41*4882a593Smuzhiyun 42*4882a593Smuzhiyun struct tcp_fastopen_context; 43*4882a593Smuzhiyun 44*4882a593Smuzhiyun struct netns_ipv4 { 45*4882a593Smuzhiyun #ifdef CONFIG_SYSCTL 46*4882a593Smuzhiyun struct ctl_table_header *forw_hdr; 47*4882a593Smuzhiyun struct ctl_table_header *frags_hdr; 48*4882a593Smuzhiyun struct ctl_table_header *ipv4_hdr; 49*4882a593Smuzhiyun struct ctl_table_header *route_hdr; 50*4882a593Smuzhiyun struct ctl_table_header *xfrm4_hdr; 51*4882a593Smuzhiyun #endif 52*4882a593Smuzhiyun struct ipv4_devconf *devconf_all; 53*4882a593Smuzhiyun struct ipv4_devconf *devconf_dflt; 54*4882a593Smuzhiyun struct ip_ra_chain __rcu *ra_chain; 55*4882a593Smuzhiyun struct mutex ra_mutex; 56*4882a593Smuzhiyun #ifdef CONFIG_IP_MULTIPLE_TABLES 57*4882a593Smuzhiyun struct fib_rules_ops *rules_ops; 58*4882a593Smuzhiyun bool fib_has_custom_rules; 59*4882a593Smuzhiyun unsigned int fib_rules_require_fldissect; 60*4882a593Smuzhiyun struct fib_table __rcu *fib_main; 61*4882a593Smuzhiyun struct fib_table __rcu *fib_default; 62*4882a593Smuzhiyun #endif 63*4882a593Smuzhiyun bool fib_has_custom_local_routes; 64*4882a593Smuzhiyun #ifdef CONFIG_IP_ROUTE_CLASSID 65*4882a593Smuzhiyun atomic_t fib_num_tclassid_users; 66*4882a593Smuzhiyun #endif 67*4882a593Smuzhiyun struct hlist_head *fib_table_hash; 68*4882a593Smuzhiyun bool fib_offload_disabled; 69*4882a593Smuzhiyun struct sock *fibnl; 70*4882a593Smuzhiyun 71*4882a593Smuzhiyun struct sock * __percpu *icmp_sk; 72*4882a593Smuzhiyun struct sock *mc_autojoin_sk; 73*4882a593Smuzhiyun 74*4882a593Smuzhiyun struct inet_peer_base *peers; 75*4882a593Smuzhiyun struct sock * __percpu *tcp_sk; 76*4882a593Smuzhiyun struct fqdir *fqdir; 77*4882a593Smuzhiyun #ifdef CONFIG_NETFILTER 78*4882a593Smuzhiyun struct xt_table *iptable_filter; 79*4882a593Smuzhiyun struct xt_table *iptable_mangle; 80*4882a593Smuzhiyun struct xt_table *iptable_raw; 81*4882a593Smuzhiyun struct xt_table *arptable_filter; 82*4882a593Smuzhiyun #ifdef CONFIG_SECURITY 83*4882a593Smuzhiyun struct xt_table *iptable_security; 84*4882a593Smuzhiyun #endif 85*4882a593Smuzhiyun struct xt_table *nat_table; 86*4882a593Smuzhiyun #endif 87*4882a593Smuzhiyun 88*4882a593Smuzhiyun int sysctl_icmp_echo_ignore_all; 89*4882a593Smuzhiyun int sysctl_icmp_echo_ignore_broadcasts; 90*4882a593Smuzhiyun int sysctl_icmp_ignore_bogus_error_responses; 91*4882a593Smuzhiyun int sysctl_icmp_ratelimit; 92*4882a593Smuzhiyun int sysctl_icmp_ratemask; 93*4882a593Smuzhiyun int sysctl_icmp_errors_use_inbound_ifaddr; 94*4882a593Smuzhiyun 95*4882a593Smuzhiyun struct local_ports ip_local_ports; 96*4882a593Smuzhiyun 97*4882a593Smuzhiyun int sysctl_tcp_ecn; 98*4882a593Smuzhiyun int sysctl_tcp_ecn_fallback; 99*4882a593Smuzhiyun 100*4882a593Smuzhiyun int sysctl_ip_default_ttl; 101*4882a593Smuzhiyun int sysctl_ip_no_pmtu_disc; 102*4882a593Smuzhiyun int sysctl_ip_fwd_use_pmtu; 103*4882a593Smuzhiyun int sysctl_ip_fwd_update_priority; 104*4882a593Smuzhiyun int sysctl_ip_nonlocal_bind; 105*4882a593Smuzhiyun int sysctl_ip_autobind_reuse; 106*4882a593Smuzhiyun /* Shall we try to damage output packets if routing dev changes? */ 107*4882a593Smuzhiyun int sysctl_ip_dynaddr; 108*4882a593Smuzhiyun int sysctl_ip_early_demux; 109*4882a593Smuzhiyun #ifdef CONFIG_NET_L3_MASTER_DEV 110*4882a593Smuzhiyun int sysctl_raw_l3mdev_accept; 111*4882a593Smuzhiyun #endif 112*4882a593Smuzhiyun int sysctl_tcp_early_demux; 113*4882a593Smuzhiyun int sysctl_udp_early_demux; 114*4882a593Smuzhiyun 115*4882a593Smuzhiyun int sysctl_nexthop_compat_mode; 116*4882a593Smuzhiyun 117*4882a593Smuzhiyun int sysctl_fwmark_reflect; 118*4882a593Smuzhiyun int sysctl_tcp_fwmark_accept; 119*4882a593Smuzhiyun #ifdef CONFIG_NET_L3_MASTER_DEV 120*4882a593Smuzhiyun int sysctl_tcp_l3mdev_accept; 121*4882a593Smuzhiyun #endif 122*4882a593Smuzhiyun int sysctl_tcp_mtu_probing; 123*4882a593Smuzhiyun int sysctl_tcp_mtu_probe_floor; 124*4882a593Smuzhiyun int sysctl_tcp_base_mss; 125*4882a593Smuzhiyun int sysctl_tcp_min_snd_mss; 126*4882a593Smuzhiyun int sysctl_tcp_probe_threshold; 127*4882a593Smuzhiyun u32 sysctl_tcp_probe_interval; 128*4882a593Smuzhiyun 129*4882a593Smuzhiyun int sysctl_tcp_keepalive_time; 130*4882a593Smuzhiyun int sysctl_tcp_keepalive_probes; 131*4882a593Smuzhiyun int sysctl_tcp_keepalive_intvl; 132*4882a593Smuzhiyun 133*4882a593Smuzhiyun int sysctl_tcp_syn_retries; 134*4882a593Smuzhiyun int sysctl_tcp_synack_retries; 135*4882a593Smuzhiyun int sysctl_tcp_syncookies; 136*4882a593Smuzhiyun int sysctl_tcp_reordering; 137*4882a593Smuzhiyun int sysctl_tcp_retries1; 138*4882a593Smuzhiyun int sysctl_tcp_retries2; 139*4882a593Smuzhiyun int sysctl_tcp_orphan_retries; 140*4882a593Smuzhiyun int sysctl_tcp_fin_timeout; 141*4882a593Smuzhiyun unsigned int sysctl_tcp_notsent_lowat; 142*4882a593Smuzhiyun int sysctl_tcp_tw_reuse; 143*4882a593Smuzhiyun int sysctl_tcp_sack; 144*4882a593Smuzhiyun int sysctl_tcp_window_scaling; 145*4882a593Smuzhiyun int sysctl_tcp_timestamps; 146*4882a593Smuzhiyun int sysctl_tcp_early_retrans; 147*4882a593Smuzhiyun int sysctl_tcp_recovery; 148*4882a593Smuzhiyun int sysctl_tcp_thin_linear_timeouts; 149*4882a593Smuzhiyun int sysctl_tcp_slow_start_after_idle; 150*4882a593Smuzhiyun int sysctl_tcp_retrans_collapse; 151*4882a593Smuzhiyun int sysctl_tcp_stdurg; 152*4882a593Smuzhiyun int sysctl_tcp_rfc1337; 153*4882a593Smuzhiyun int sysctl_tcp_abort_on_overflow; 154*4882a593Smuzhiyun int sysctl_tcp_fack; 155*4882a593Smuzhiyun int sysctl_tcp_max_reordering; 156*4882a593Smuzhiyun int sysctl_tcp_dsack; 157*4882a593Smuzhiyun int sysctl_tcp_app_win; 158*4882a593Smuzhiyun int sysctl_tcp_adv_win_scale; 159*4882a593Smuzhiyun int sysctl_tcp_frto; 160*4882a593Smuzhiyun int sysctl_tcp_nometrics_save; 161*4882a593Smuzhiyun int sysctl_tcp_no_ssthresh_metrics_save; 162*4882a593Smuzhiyun int sysctl_tcp_moderate_rcvbuf; 163*4882a593Smuzhiyun int sysctl_tcp_tso_win_divisor; 164*4882a593Smuzhiyun int sysctl_tcp_workaround_signed_windows; 165*4882a593Smuzhiyun int sysctl_tcp_limit_output_bytes; 166*4882a593Smuzhiyun int sysctl_tcp_challenge_ack_limit; 167*4882a593Smuzhiyun int sysctl_tcp_min_tso_segs; 168*4882a593Smuzhiyun int sysctl_tcp_min_rtt_wlen; 169*4882a593Smuzhiyun int sysctl_tcp_autocorking; 170*4882a593Smuzhiyun int sysctl_tcp_invalid_ratelimit; 171*4882a593Smuzhiyun int sysctl_tcp_pacing_ss_ratio; 172*4882a593Smuzhiyun int sysctl_tcp_pacing_ca_ratio; 173*4882a593Smuzhiyun int sysctl_tcp_wmem[3]; 174*4882a593Smuzhiyun int sysctl_tcp_rmem[3]; 175*4882a593Smuzhiyun int sysctl_tcp_comp_sack_nr; 176*4882a593Smuzhiyun unsigned long sysctl_tcp_comp_sack_delay_ns; 177*4882a593Smuzhiyun unsigned long sysctl_tcp_comp_sack_slack_ns; 178*4882a593Smuzhiyun struct inet_timewait_death_row tcp_death_row; 179*4882a593Smuzhiyun int sysctl_max_syn_backlog; 180*4882a593Smuzhiyun int sysctl_tcp_fastopen; 181*4882a593Smuzhiyun const struct tcp_congestion_ops __rcu *tcp_congestion_control; 182*4882a593Smuzhiyun struct tcp_fastopen_context __rcu *tcp_fastopen_ctx; 183*4882a593Smuzhiyun spinlock_t tcp_fastopen_ctx_lock; 184*4882a593Smuzhiyun unsigned int sysctl_tcp_fastopen_blackhole_timeout; 185*4882a593Smuzhiyun atomic_t tfo_active_disable_times; 186*4882a593Smuzhiyun unsigned long tfo_active_disable_stamp; 187*4882a593Smuzhiyun int sysctl_tcp_reflect_tos; 188*4882a593Smuzhiyun 189*4882a593Smuzhiyun int sysctl_udp_wmem_min; 190*4882a593Smuzhiyun int sysctl_udp_rmem_min; 191*4882a593Smuzhiyun 192*4882a593Smuzhiyun #ifdef CONFIG_NET_L3_MASTER_DEV 193*4882a593Smuzhiyun int sysctl_udp_l3mdev_accept; 194*4882a593Smuzhiyun #endif 195*4882a593Smuzhiyun 196*4882a593Smuzhiyun int sysctl_igmp_max_memberships; 197*4882a593Smuzhiyun int sysctl_igmp_max_msf; 198*4882a593Smuzhiyun int sysctl_igmp_llm_reports; 199*4882a593Smuzhiyun int sysctl_igmp_qrv; 200*4882a593Smuzhiyun 201*4882a593Smuzhiyun struct ping_group_range ping_group_range; 202*4882a593Smuzhiyun 203*4882a593Smuzhiyun atomic_t dev_addr_genid; 204*4882a593Smuzhiyun 205*4882a593Smuzhiyun #ifdef CONFIG_SYSCTL 206*4882a593Smuzhiyun unsigned long *sysctl_local_reserved_ports; 207*4882a593Smuzhiyun unsigned long *sysctl_local_unbindable_ports; 208*4882a593Smuzhiyun int sysctl_ip_prot_sock; 209*4882a593Smuzhiyun #endif 210*4882a593Smuzhiyun 211*4882a593Smuzhiyun #ifdef CONFIG_IP_MROUTE 212*4882a593Smuzhiyun #ifndef CONFIG_IP_MROUTE_MULTIPLE_TABLES 213*4882a593Smuzhiyun struct mr_table *mrt; 214*4882a593Smuzhiyun #else 215*4882a593Smuzhiyun struct list_head mr_tables; 216*4882a593Smuzhiyun struct fib_rules_ops *mr_rules_ops; 217*4882a593Smuzhiyun #endif 218*4882a593Smuzhiyun #endif 219*4882a593Smuzhiyun #ifdef CONFIG_IP_ROUTE_MULTIPATH 220*4882a593Smuzhiyun int sysctl_fib_multipath_use_neigh; 221*4882a593Smuzhiyun int sysctl_fib_multipath_hash_policy; 222*4882a593Smuzhiyun #endif 223*4882a593Smuzhiyun 224*4882a593Smuzhiyun struct fib_notifier_ops *notifier_ops; 225*4882a593Smuzhiyun unsigned int fib_seq; /* protected by rtnl_mutex */ 226*4882a593Smuzhiyun 227*4882a593Smuzhiyun struct fib_notifier_ops *ipmr_notifier_ops; 228*4882a593Smuzhiyun unsigned int ipmr_seq; /* protected by rtnl_mutex */ 229*4882a593Smuzhiyun 230*4882a593Smuzhiyun atomic_t rt_genid; 231*4882a593Smuzhiyun siphash_key_t ip_id_key; 232*4882a593Smuzhiyun 233*4882a593Smuzhiyun ANDROID_KABI_RESERVE(1); 234*4882a593Smuzhiyun }; 235*4882a593Smuzhiyun #endif 236