BPF List
 help / color / mirror / Atom feed
* [PATCH RFC v3 00/13] sysctl: add module aliases
@ 2026-08-19 18:16 Mauricio Faria de Oliveira
  2026-08-19 18:16 ` [PATCH RFC v3 01/13] keys, pidns, fs/verity, riscv/vector: reorder '#include <linux/sysctl.h>' Mauricio Faria de Oliveira
                   ` (12 more replies)
  0 siblings, 13 replies; 27+ messages in thread
From: Mauricio Faria de Oliveira @ 2026-08-19 18:16 UTC (permalink / raw)
  To: Kees Cook, Joel Granados, Nathan Chancellor, Nicolas Schier,
	David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
	Simon Horman
  Cc: kernel-dev, linux-riscv, linux-kernel, fsverity, keyrings, bpf,
	linux-fsdevel, linux-kbuild, netdev, linux-wpan, lvs-devel,
	netfilter-devel, coreteam, linux-sctp, linux-rdma, linux-s390,
	bridge, mptcp, rds-devel, virtualization,
	Mauricio Faria de Oliveira

This series adds 'sysctl:' aliases to modules that register sysctl tables; e.g.:

        $ modinfo ./mpls_router.ko  | grep sysctl:
        alias:          sysctl:*/net/mpls/conf/*/input
        alias:          sysctl:*/net/mpls/default_ttl
        alias:          sysctl:*/net/mpls/ip_ttl_propagate
        alias:          sysctl:*/net/mpls/platform_labels

It provides a trivial way to map /proc/sys files to modules (not trivial today),
and for userspace to handle nonexistent /proc/sys files (e.g., procps's sysctl
and systemd-sysctl applying tunables) with "modprobe sysctl:<...>" and a retry.

This is done almost automatically with register_sysctl(), register_net_sysctl()
and friends as wrappers of MODULE_SYSCTL_TABLE (similar to MODULE_DEVICE_TABLE),
which emits symbols for file2alias/modpost to find and parse the sysctl tables.

The big exception to 'almost' are sysctl tables and paths allocated or defined
at runtime (e.g., per-namespace or per-device), as all information is required
at build-time. Fortunately, such tables and paths are often based on 'templates'
which are static and can be used.

This is done by plumbing the template table/path as optional arguments (macros
with default values as default_gfp()), so not to create functions for all cases:

        register_sysctl(path, table [, table_tmpl [, path_tmpl]]);
        register_net_sysctl(net, path, table [, table_tmpl[, path_tmpl]]);
        register_net_sysctl_sz(net, path, table, size [, table_tmpl[, path_tmpl]]);

In this series:
- Patch 1 prevents a build error later.
- Patch 2 adds CONFIG_SYSCTL_MODULE_ALIASES.
- Patch 3 adds MODULE_SYSCTL_TABLE().
- Patches 4-5 add register_sysctl() wrapper and update some callers.
- Patches 6-10 add register_net_sysctl[_sz]() wrappers and update some callers.
- Patches 11-13 add file2alias support.

Not all maintainers/reviewers (specially for the many changes in net/) are
in To/Cc in respect of their time, as this RFC probably needs more general
and earlier feedback before settling on specific changes for their review.
All lists are included for visibility, though.

Example
=======

To put it all together, 'mpls_router.ko' (used above) from 'net/mpls/af_mpls.c':
        
- Tables:

        static const struct ctl_table mpls_table[] = {
                {
                        .procname       = "platform_labels",
                ...
                        .procname       = "ip_ttl_propagate",
                ...
                        .procname       = "default_ttl",
                },
        };
        
        static const struct ctl_table mpls_dev_table[] = {
                {
                        .procname       = "input",
                ...
                },
        };

- Registration:

        net->mpls.ctl = register_net_sysctl_sz(net, "net/mpls", table,
                                               table_size, mpls_table);

        #define path_template "net/mpls/conf/%s"
        ...
        mdev->sysctl = register_net_sysctl_sz(net, path, table, table_size,
                                              mpls_dev_table, path_template);

- Symbols:

        $ objdump -t net/mpls/mpls_router.ko \
          | grep '__mod_device_table__.*__sysctl__'
        0000000000000900 l     O .data  0000000000000018
                __mod_device_table__kmod_mpls_router__sysctl__mpls_table.177
        0000000000000940 l     O .data  0000000000000018
                __mod_device_table__kmod_mpls_router__sysctl__mpls_dev_table.174

- file2alias:

        $ grep '^MODULE_ALIAS("sysctl:' net/mpls/mpls_router.mod.c
        MODULE_ALIAS("sysctl:*/net/mpls/platform_labels");
        MODULE_ALIAS("sysctl:*/net/mpls/ip_ttl_propagate");
        MODULE_ALIAS("sysctl:*/net/mpls/default_ttl");
        MODULE_ALIAS("sysctl:*/net/mpls/conf/*/input");

- modinfo:

        $ modinfo ./mpls_router.ko  | grep sysctl:
        alias:          sysctl:*/net/mpls/conf/*/input
        alias:          sysctl:*/net/mpls/default_ttl
        alias:          sysctl:*/net/mpls/ip_ttl_propagate
        alias:          sysctl:*/net/mpls/platform_labels

Testing
=======

Configurations:
- allmodconfig with the option enabled (check for 'MODULE_ALIAS("sysctl:' lines)
- allmodconfig with the option disabled (check for code errors)
- allyesconfig with the option enabled (check for include errors)

Architectures (test different bitness, endianness, and ELF handling)
- x86_64, i386
- arm, arm64
- arc
- alpha
- loongarch
- m68k
- mips(64)(el)
- parisc(64)
- powerpc(64(le))
- riscv
- sparc64
- s390

The resulting '.mod.c' files of allmodconfig with the option enabled was checked
for consistency across all architectures, and that the new aliases lines are the
difference to allmodconfig with the option disabled.

Disabling
=========

- Per-call:

  Use 'register_sysctl_sz()' or '__register_net_sysctl_sz()' directly.

- Per-file:

  Use '#define SYSCTL_MODULE_ALIASES_DISABLE'.

- System-wide:

  Maybe something along these lines:

        # cat /etc/modprobe.d/no-sysctl.conf
        alias sysctl:* no-sysctl
        install no-sysctl /bin/false

        # modinfo -F name sysctl:/proc/net/mpls/default_ttl
        mpls_router

        # modprobe sysctl:/proc/net/mpls/default_ttl
        modprobe: ERROR: Error running install command '/bin/false' for module no_sysctl: retcode 1
        modprobe: ERROR: could not insert 'no_sysctl': Invalid argument

P.S.
====

I wrote proof-of-concept patches for procps sysctl and systemd-sysctl some time
ago, which worked as expected, i.e., successfully set sysctl tunables which did
not exist in /proc/sys, by running 'modprobe sysctl:/proc/sys/...' and retrying.

Should this series eventually be merged, the patches will be submitted upstream
as well, for userspace to start consuming it.

Signed-off-by: Mauricio Faria de Oliveira <mfo@igalia.com>

Changes in v3:
- All issues were reported by sashiko-bot@kernel.org.
- Tested allmodconfig with option enabled on x86_64.
- Patch 2:
  - Fix typo ('s/options/option/').
- Patch 3:
  - Fix usage of __UNIQUE_ID().
  - Add __must_be_array() in MODULE_SYSCTL_TABLE().
- Patch 4:
  - Remove trailing backslash in register_sysctl().
- Patch 6:
  - Fix missing __register_net_sysctl_sz() in !CONFIG_SYSCTL.
- Patch 13:
  - Fix potential out-of-bounds read in do_sysctl_entry().
  - Add check for entry size of zero.
- Link to v2: https://lore.kernel.org/r/20260818-sysctl-module-aliases-v2-0-d5a69dae5798@igalia.com

Changes in v2:
- This is based on the series submitted 4 years ago,
  with Originally-by: tags added in related patches.
- Link to v1: https://lore.kernel.org/linux-fsdevel/20220722022416.137548-1-mfo@canonical.com/

---
Mauricio Faria de Oliveira (13):
      keys, pidns, fs/verity, riscv/vector: reorder '#include <linux/sysctl.h>'
      proc: add config option SYSCTL_MODULE_ALIASES
      sysctl, mod_devicetable: add macro MODULE_SYSCTL_TABLE
      sysctl: add register_sysctl() wrapper for MODULE_SYSCTL_TABLE
      sysctl, parport: update register_sysctl() callers with template arguments
      sysctl, net: add register_net_sysctl{_sz}() wrappers for MODULE_SYSCTL_TABLE
      sysctl, net: update register_net_sysctl{_sz}() callers with template arguments
      sysctl, net: update register_net_sysctl_sz(ARRAY_SIZE(table_tmpl)) with template arguments
      sysctl, ipv6: update register_net_sysctl{_sz}() callers with template arguments
      sysctl, net: update register_net_sysctl_sz() edge case
      sysctl: unrandomize struct ctl_table.procname
      modpost: move addend_*_rel() calls into addend_rel()
      modpost: handle MODULE_SYSCTL_TABLE symbols

 arch/riscv/kernel/vector.c              |   1 +
 drivers/net/vrf.c                       |   3 +-
 drivers/parport/procfs.c                |  26 +++-
 fs/proc/Kconfig                         |  13 ++
 fs/verity/init.c                        |   1 +
 include/linux/key.h                     |   1 -
 include/linux/mod_devicetable.h         |   7 +
 include/linux/pid_namespace.h           |   1 +
 include/linux/sysctl.h                  | 110 ++++++++++++++-
 include/net/ipv6.h                      |   6 +-
 include/net/net_namespace.h             |  47 ++++++-
 net/bridge/br_netfilter_hooks.c         |   3 +-
 net/core/neighbour.c                    |  11 +-
 net/core/sysctl_net_core.c              |   3 +-
 net/ieee802154/6lowpan/reassembly.c     |   2 +-
 net/ipv4/devinet.c                      |  12 +-
 net/ipv4/ip_fragment.c                  |   3 +-
 net/ipv4/route.c                        |   3 +-
 net/ipv4/sysctl_net_ipv4.c              |   2 +-
 net/ipv4/xfrm4_policy.c                 |   3 +-
 net/ipv6/addrconf.c                     |   7 +-
 net/ipv6/icmp.c                         |   6 +-
 net/ipv6/netfilter/nf_conntrack_reasm.c |   4 +-
 net/ipv6/reassembly.c                   |   3 +-
 net/ipv6/route.c                        |  10 +-
 net/ipv6/sysctl_net_ipv6.c              |  13 +-
 net/ipv6/xfrm6_policy.c                 |   3 +-
 net/mpls/af_mpls.c                      |   9 +-
 net/mptcp/ctrl.c                        |   3 +-
 net/netfilter/ipvs/ip_vs_ctl.c          |   4 +-
 net/netfilter/ipvs/ip_vs_lblc.c         |   3 +-
 net/netfilter/ipvs/ip_vs_lblcr.c        |   3 +-
 net/netfilter/nf_conntrack_standalone.c |   5 +-
 net/netfilter/nf_log.c                  |   9 +-
 net/rds/tcp.c                           |   4 +-
 net/sctp/sysctl.c                       |   3 +-
 net/smc/smc_sysctl.c                    |   2 +-
 net/sysctl_net.c                        |  10 +-
 net/unix/sysctl_net_unix.c              |   3 +-
 net/vmw_vsock/af_vsock.c                |   4 +-
 net/xfrm/xfrm_sysctl.c                  |   2 +-
 scripts/mod/devicetable-offsets.c       |   6 +
 scripts/mod/file2alias.c                | 237 ++++++++++++++++++++++++++++++++
 scripts/mod/modpost.c                   |  46 ++++---
 scripts/mod/modpost.h                   |  25 ++++
 45 files changed, 575 insertions(+), 107 deletions(-)
---
base-commit: 2697ef8943c9985c14708a6429e21812693857b2
change-id: 20260818-sysctl-module-aliases-2f5801b1eb71

Best regards,
-- 
Mauricio Faria de Oliveira <mfo@igalia.com>


^ permalink raw reply	[flat|nested] 27+ messages in thread

end of thread, other threads:[~2026-08-19 18:35 UTC | newest]

Thread overview: 27+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-19 18:16 [PATCH RFC v3 00/13] sysctl: add module aliases Mauricio Faria de Oliveira
2026-08-19 18:16 ` [PATCH RFC v3 01/13] keys, pidns, fs/verity, riscv/vector: reorder '#include <linux/sysctl.h>' Mauricio Faria de Oliveira
2026-08-19 18:20   ` sashiko-bot
2026-08-19 18:16 ` [PATCH RFC v3 02/13] proc: add config option SYSCTL_MODULE_ALIASES Mauricio Faria de Oliveira
2026-08-19 18:24   ` sashiko-bot
2026-08-19 18:16 ` [PATCH RFC v3 03/13] sysctl, mod_devicetable: add macro MODULE_SYSCTL_TABLE Mauricio Faria de Oliveira
2026-08-19 18:32   ` sashiko-bot
2026-08-19 18:16 ` [PATCH RFC v3 04/13] sysctl: add register_sysctl() wrapper for MODULE_SYSCTL_TABLE Mauricio Faria de Oliveira
2026-08-19 18:34   ` sashiko-bot
2026-08-19 18:16 ` [PATCH RFC v3 05/13] sysctl, parport: update register_sysctl() callers with template arguments Mauricio Faria de Oliveira
2026-08-19 18:24   ` sashiko-bot
2026-08-19 18:16 ` [PATCH RFC v3 06/13] sysctl, net: add register_net_sysctl{_sz}() wrappers for MODULE_SYSCTL_TABLE Mauricio Faria de Oliveira
2026-08-19 18:25   ` sashiko-bot
2026-08-19 18:16 ` [PATCH RFC v3 07/13] sysctl, net: update register_net_sysctl{_sz}() callers with template arguments Mauricio Faria de Oliveira
2026-08-19 18:33   ` sashiko-bot
2026-08-19 18:16 ` [PATCH RFC v3 08/13] sysctl, net: update register_net_sysctl_sz(ARRAY_SIZE(table_tmpl)) " Mauricio Faria de Oliveira
2026-08-19 18:26   ` sashiko-bot
2026-08-19 18:16 ` [PATCH RFC v3 09/13] sysctl, ipv6: update register_net_sysctl{_sz}() callers " Mauricio Faria de Oliveira
2026-08-19 18:24   ` sashiko-bot
2026-08-19 18:16 ` [PATCH RFC v3 10/13] sysctl, net: update register_net_sysctl_sz() edge case Mauricio Faria de Oliveira
2026-08-19 18:24   ` sashiko-bot
2026-08-19 18:16 ` [PATCH RFC v3 11/13] sysctl: unrandomize struct ctl_table.procname Mauricio Faria de Oliveira
2026-08-19 18:26   ` sashiko-bot
2026-08-19 18:16 ` [PATCH RFC v3 12/13] modpost: move addend_*_rel() calls into addend_rel() Mauricio Faria de Oliveira
2026-08-19 18:26   ` sashiko-bot
2026-08-19 18:16 ` [PATCH RFC v3 13/13] modpost: handle MODULE_SYSCTL_TABLE symbols Mauricio Faria de Oliveira
2026-08-19 18:35   ` sashiko-bot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox