From: Mauricio Faria de Oliveira <mfo@igalia.com>
To: Kees Cook <kees@kernel.org>,
Joel Granados <joel.granados@kernel.org>,
Nathan Chancellor <nathan@kernel.org>,
Nicolas Schier <nsc@kernel.org>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>,
Paolo Abeni <pabeni@redhat.com>, Simon Horman <horms@kernel.org>
Cc: kernel-dev@igalia.com, linux-riscv@lists.infradead.org,
linux-kernel@vger.kernel.org, fsverity@lists.linux.dev,
keyrings@vger.kernel.org, bpf@vger.kernel.org,
linux-fsdevel@vger.kernel.org, linux-kbuild@vger.kernel.org,
netdev@vger.kernel.org, linux-wpan@vger.kernel.org,
lvs-devel@vger.kernel.org, netfilter-devel@vger.kernel.org,
coreteam@netfilter.org, linux-sctp@vger.kernel.org,
linux-rdma@vger.kernel.org, linux-s390@vger.kernel.org,
bridge@lists.linux.dev, mptcp@lists.linux.dev,
rds-devel@oss.oracle.com, virtualization@lists.linux.dev,
Mauricio Faria de Oliveira <mfo@igalia.com>
Subject: [PATCH RFC v2 00/13] sysctl: add module aliases
Date: Tue, 18 Aug 2026 23:27:59 -0300 [thread overview]
Message-ID: <20260818-sysctl-module-aliases-v2-0-d5a69dae5798@igalia.com> (raw)
This series adds 'sysctl:' aliases to modules that register sysctl tables; e.g.:
$ modinfo ./mpls_router.ko | grep sysctl:
alias: sysctl:*/net/mpls/conf/*/input
alias: sysctl:*/net/mpls/default_ttl
alias: sysctl:*/net/mpls/ip_ttl_propagate
alias: sysctl:*/net/mpls/platform_labels
It provides a trivial way to map /proc/sys files to modules (not trivial today),
and for userspace to handle nonexistent /proc/sys files (e.g., procps's sysctl
and systemd-sysctl applying tunables) with "modprobe sysctl:<...>" and a retry.
This is done almost automatically with register_sysctl(), register_net_sysctl()
and friends as wrappers of MODULE_SYSCTL_TABLE (similar to MODULE_DEVICE_TABLE),
which emits symbols for file2alias/modpost to find and parse the sysctl tables.
The big exception to 'almost' are sysctl tables and paths allocated or defined
at runtime (e.g., per-namespace or per-device), as all information is required
at build-time. Fortunately, such tables and paths are often based on 'templates'
which are static and can be used.
This is done by plumbing the template table/path as optional arguments (macros
with default values as default_gfp()), so not to create functions for all cases:
register_sysctl(path, table [, table_tmpl [, path_tmpl]]);
register_net_sysctl(net, path, table [, table_tmpl[, path_tmpl]]);
register_net_sysctl_sz(net, path, table, size [, table_tmpl[, path_tmpl]]);
In this series:
- Patch 1 prevents a build error later.
- Patch 2 adds CONFIG_SYSCTL_MODULE_ALIASES.
- Patch 3 adds MODULE_SYSCTL_TABLE().
- Patches 4-5 add register_sysctl() wrapper and update some callers.
- Patches 6-10 add register_net_sysctl[_sz]() wrappers and update some callers.
- Patches 11-13 add file2alias support.
Not all maintainers/reviewers (specially for the many changes in net/) are
in To/Cc in respect of their time, as this RFC probably needs more general
and earlier feedback before settling on specific changes for their review.
All lists are included for visibility, though.
Example
=======
To put it all together, 'mpls_router.ko' (used above) from 'net/mpls/af_mpls.c':
- Tables:
static const struct ctl_table mpls_table[] = {
{
.procname = "platform_labels",
...
.procname = "ip_ttl_propagate",
...
.procname = "default_ttl",
},
};
static const struct ctl_table mpls_dev_table[] = {
{
.procname = "input",
...
},
};
- Registration:
net->mpls.ctl = register_net_sysctl_sz(net, "net/mpls", table,
table_size, mpls_table);
#define path_template "net/mpls/conf/%s"
...
mdev->sysctl = register_net_sysctl_sz(net, path, table, table_size,
mpls_dev_table, path_template);
- Symbols:
$ objdump -t net/mpls/mpls_router.ko \
| grep '__mod_device_table__.*__sysctl__'
0000000000000900 l O .data 0000000000000018
__mod_device_table__kmod_mpls_router__sysctl__mpls_table.177
0000000000000940 l O .data 0000000000000018
__mod_device_table__kmod_mpls_router__sysctl__mpls_dev_table.174
- file2alias:
$ grep '^MODULE_ALIAS("sysctl:' net/mpls/mpls_router.mod.c
MODULE_ALIAS("sysctl:*/net/mpls/platform_labels");
MODULE_ALIAS("sysctl:*/net/mpls/ip_ttl_propagate");
MODULE_ALIAS("sysctl:*/net/mpls/default_ttl");
MODULE_ALIAS("sysctl:*/net/mpls/conf/*/input");
- modinfo:
$ modinfo ./mpls_router.ko | grep sysctl:
alias: sysctl:*/net/mpls/conf/*/input
alias: sysctl:*/net/mpls/default_ttl
alias: sysctl:*/net/mpls/ip_ttl_propagate
alias: sysctl:*/net/mpls/platform_labels
Testing
=======
Configurations:
- allmodconfig with the option enabled (check for 'MODULE_ALIAS("sysctl:' lines)
- allmodconfig with the option disabled (check for code errors)
- allyesconfig with the option enabled (check for include errors)
Architectures (test different bitness, endianness, and ELF handling)
- x86_64, i386
- arm, arm64
- arc
- alpha
- loongarch
- m68k
- mips(64)(el)
- parisc(64)
- powerpc(64(le))
- riscv
- sparc64
- s390
The resulting '.mod.c' files of allmodconfig with the option enabled was checked
for consistency across all architectures, and that the new aliases lines are the
difference to allmodconfig with the option disabled.
Disabling
=========
- Per-call:
Use 'register_sysctl_sz()' or '__register_net_sysctl_sz()' directly.
- Per-file:
Use '#define SYSCTL_MODULE_ALIASES_DISABLE'.
- System-wide:
Maybe something along these lines:
# cat /etc/modprobe.d/no-sysctl.conf
alias sysctl:* no-sysctl
install no-sysctl /bin/false
# modinfo -F name sysctl:/proc/net/mpls/default_ttl
mpls_router
# modprobe sysctl:/proc/net/mpls/default_ttl
modprobe: ERROR: Error running install command '/bin/false' for module no_sysctl: retcode 1
modprobe: ERROR: could not insert 'no_sysctl': Invalid argument
P.S.
====
I wrote proof-of-concept patches for procps sysctl and systemd-sysctl some time
ago, which worked as expected, i.e., successfully set sysctl tunables which did
not exist in /proc/sys, by running 'modprobe sysctl:/proc/sys/...' and retrying.
Signed-off-by: Mauricio Faria de Oliveira <mfo@igalia.com>
Changes in v2:
- This is based on the series submitted 4 years ago,
with Originally-by: tags added in related patches.
- Link to v1: https://lore.kernel.org/linux-fsdevel/20220722022416.137548-1-mfo@canonical.com/
---
Mauricio Faria de Oliveira (13):
keys, pidns, fs/verity, riscv/vector: reorder '#include <linux/sysctl.h>'
proc: add config option SYSCTL_MODULE_ALIASES
sysctl, mod_devicetable: add macro MODULE_SYSCTL_TABLE
sysctl: add register_sysctl() wrapper for MODULE_SYSCTL_TABLE
sysctl, parport: update register_sysctl() callers with template arguments
sysctl, net: add register_net_sysctl{_sz}() wrappers for MODULE_SYSCTL_TABLE
sysctl, net: update register_net_sysctl{_sz}() callers with template arguments
sysctl, net: update register_net_sysctl_sz(ARRAY_SIZE(table_tmpl)) with template arguments
sysctl, ipv6: update register_net_sysctl{_sz}() callers with template arguments
sysctl, net: update register_net_sysctl_sz() edge case
sysctl: unrandomize struct ctl_table.procname
modpost: move addend_*_rel() calls into addend_rel()
modpost: handle MODULE_SYSCTL_TABLE symbols
arch/riscv/kernel/vector.c | 1 +
drivers/net/vrf.c | 3 +-
drivers/parport/procfs.c | 26 +++-
fs/proc/Kconfig | 13 ++
fs/verity/init.c | 1 +
include/linux/key.h | 1 -
include/linux/mod_devicetable.h | 7 +
include/linux/pid_namespace.h | 1 +
include/linux/sysctl.h | 110 ++++++++++++++-
include/net/ipv6.h | 6 +-
include/net/net_namespace.h | 45 ++++++-
net/bridge/br_netfilter_hooks.c | 3 +-
net/core/neighbour.c | 11 +-
net/core/sysctl_net_core.c | 3 +-
net/ieee802154/6lowpan/reassembly.c | 2 +-
net/ipv4/devinet.c | 12 +-
net/ipv4/ip_fragment.c | 3 +-
net/ipv4/route.c | 3 +-
net/ipv4/sysctl_net_ipv4.c | 2 +-
net/ipv4/xfrm4_policy.c | 3 +-
net/ipv6/addrconf.c | 7 +-
net/ipv6/icmp.c | 6 +-
net/ipv6/netfilter/nf_conntrack_reasm.c | 4 +-
net/ipv6/reassembly.c | 3 +-
net/ipv6/route.c | 10 +-
net/ipv6/sysctl_net_ipv6.c | 13 +-
net/ipv6/xfrm6_policy.c | 3 +-
net/mpls/af_mpls.c | 9 +-
net/mptcp/ctrl.c | 3 +-
net/netfilter/ipvs/ip_vs_ctl.c | 4 +-
net/netfilter/ipvs/ip_vs_lblc.c | 3 +-
net/netfilter/ipvs/ip_vs_lblcr.c | 3 +-
net/netfilter/nf_conntrack_standalone.c | 5 +-
net/netfilter/nf_log.c | 9 +-
net/rds/tcp.c | 4 +-
net/sctp/sysctl.c | 3 +-
net/smc/smc_sysctl.c | 2 +-
net/sysctl_net.c | 10 +-
net/unix/sysctl_net_unix.c | 3 +-
net/vmw_vsock/af_vsock.c | 4 +-
net/xfrm/xfrm_sysctl.c | 2 +-
scripts/mod/devicetable-offsets.c | 6 +
scripts/mod/file2alias.c | 230 ++++++++++++++++++++++++++++++++
scripts/mod/modpost.c | 46 ++++---
scripts/mod/modpost.h | 25 ++++
45 files changed, 567 insertions(+), 106 deletions(-)
---
base-commit: 2697ef8943c9985c14708a6429e21812693857b2
change-id: 20260818-sysctl-module-aliases-2f5801b1eb71
Best regards,
--
Mauricio Faria de Oliveira <mfo@igalia.com>
next reply other threads:[~2026-08-19 2:29 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-19 2:27 Mauricio Faria de Oliveira [this message]
2026-08-19 2:28 ` [PATCH RFC v2 01/13] keys, pidns, fs/verity, riscv/vector: reorder '#include <linux/sysctl.h>' Mauricio Faria de Oliveira
2026-08-19 2:28 ` [PATCH RFC v2 02/13] proc: add config option SYSCTL_MODULE_ALIASES Mauricio Faria de Oliveira
2026-08-19 2:28 ` [PATCH RFC v2 03/13] sysctl, mod_devicetable: add macro MODULE_SYSCTL_TABLE Mauricio Faria de Oliveira
2026-08-19 2:28 ` [PATCH RFC v2 04/13] sysctl: add register_sysctl() wrapper for MODULE_SYSCTL_TABLE Mauricio Faria de Oliveira
2026-08-19 2:28 ` [PATCH RFC v2 05/13] sysctl, parport: update register_sysctl() callers with template arguments Mauricio Faria de Oliveira
2026-08-19 2:28 ` [PATCH RFC v2 06/13] sysctl, net: add register_net_sysctl{_sz}() wrappers for MODULE_SYSCTL_TABLE Mauricio Faria de Oliveira
2026-08-19 2:28 ` [PATCH RFC v2 07/13] sysctl, net: update register_net_sysctl{_sz}() callers with template arguments Mauricio Faria de Oliveira
2026-08-19 2:28 ` [PATCH RFC v2 08/13] sysctl, net: update register_net_sysctl_sz(ARRAY_SIZE(table_tmpl)) " Mauricio Faria de Oliveira
2026-08-19 2:28 ` [PATCH RFC v2 09/13] sysctl, ipv6: update register_net_sysctl{_sz}() callers " Mauricio Faria de Oliveira
2026-08-19 2:28 ` [PATCH RFC v2 10/13] sysctl, net: update register_net_sysctl_sz() edge case Mauricio Faria de Oliveira
2026-08-19 2:28 ` [PATCH RFC v2 11/13] sysctl: unrandomize struct ctl_table.procname Mauricio Faria de Oliveira
2026-08-19 2:28 ` [PATCH RFC v2 12/13] modpost: move addend_*_rel() calls into addend_rel() Mauricio Faria de Oliveira
2026-08-19 2:28 ` [PATCH RFC v2 13/13] modpost: handle MODULE_SYSCTL_TABLE symbols Mauricio Faria de Oliveira
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260818-sysctl-module-aliases-v2-0-d5a69dae5798@igalia.com \
--to=mfo@igalia.com \
--cc=bpf@vger.kernel.org \
--cc=bridge@lists.linux.dev \
--cc=coreteam@netfilter.org \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=fsverity@lists.linux.dev \
--cc=horms@kernel.org \
--cc=joel.granados@kernel.org \
--cc=kees@kernel.org \
--cc=kernel-dev@igalia.com \
--cc=keyrings@vger.kernel.org \
--cc=kuba@kernel.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kbuild@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-rdma@vger.kernel.org \
--cc=linux-riscv@lists.infradead.org \
--cc=linux-s390@vger.kernel.org \
--cc=linux-sctp@vger.kernel.org \
--cc=linux-wpan@vger.kernel.org \
--cc=lvs-devel@vger.kernel.org \
--cc=mptcp@lists.linux.dev \
--cc=nathan@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=netfilter-devel@vger.kernel.org \
--cc=nsc@kernel.org \
--cc=pabeni@redhat.com \
--cc=rds-devel@oss.oracle.com \
--cc=virtualization@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox