[RFC PATCH v1 14/30] sysctl: net: use sysctl_field in 6lowpan fragment sysctls

From: Alexey Gladkov

Date: Wed Aug 26 2026 - 15:50:46 EST


The 6lowpan fragment sysctl table is cloned for every non-init network
namespace only to bind the entries to that namespace's fqdir. The clone
also has to patch the low/high threshold limits through extra1 and
extra2 before registration.

Use sysctl_field descriptors so the data and limit pointers are derived
from the registration context. This keeps the table const and removes
the per-net allocation, pointer patching, and free path while preserving
the existing unprivileged net namespace visibility rule.

Signed-off-by: Alexey Gladkov <legion@xxxxxxxxxx>
---
net/ieee802154/6lowpan/reassembly.c | 84 ++++++++++++-----------------
1 file changed, 33 insertions(+), 51 deletions(-)

diff --git a/net/ieee802154/6lowpan/reassembly.c b/net/ieee802154/6lowpan/reassembly.c
index ddb6a5817d09..c54e50a213f4 100644
--- a/net/ieee802154/6lowpan/reassembly.c
+++ b/net/ieee802154/6lowpan/reassembly.c
@@ -326,25 +326,30 @@ int lowpan_frag_rcv(struct sk_buff *skb, u8 frag_type)

#ifdef CONFIG_SYSCTL

-static struct ctl_table lowpan_frags_ns_ctl_table[] = {
- {
- .procname = "6lowpanfrag_high_thresh",
- .maxlen = sizeof(unsigned long),
- .mode = 0644,
- .proc_handler = proc_doulongvec_minmax,
- },
- {
- .procname = "6lowpanfrag_low_thresh",
- .maxlen = sizeof(unsigned long),
- .mode = 0644,
- .proc_handler = proc_doulongvec_minmax,
- },
- {
- .procname = "6lowpanfrag_time",
- .maxlen = sizeof(int),
- .mode = 0644,
- .proc_handler = proc_dointvec_jiffies,
- },
+static unsigned long *lowpan_frags_high_thresh_data(const struct sysctl_context *ctx)
+{
+ return &net_ieee802154_lowpan(ctx->ns.net_ns)->fqdir->high_thresh;
+}
+
+static unsigned long *lowpan_frags_low_thresh_data(const struct sysctl_context *ctx)
+{
+ return &net_ieee802154_lowpan(ctx->ns.net_ns)->fqdir->low_thresh;
+}
+
+static void *lowpan_frags_timeout_data(const struct sysctl_context *ctx)
+{
+ return &net_ieee802154_lowpan(ctx->ns.net_ns)->fqdir->timeout;
+}
+
+static const struct sysctl_field lowpan_frags_ns_ctl_table[] = {
+ SYSCTL_FIELD_ULONG_MINMAX("6lowpanfrag_high_thresh", 0644,
+ lowpan_frags_high_thresh_data,
+ lowpan_frags_low_thresh_data, NULL),
+ SYSCTL_FIELD_ULONG_MINMAX("6lowpanfrag_low_thresh", 0644,
+ lowpan_frags_low_thresh_data,
+ NULL, lowpan_frags_high_thresh_data),
+ SYSCTL_FIELD_CUSTOM("6lowpanfrag_time", 0644, sizeof(int),
+ lowpan_frags_timeout_data, proc_dointvec_jiffies),
};

/* secret interval has been deprecated */
@@ -361,55 +366,32 @@ static struct ctl_table lowpan_frags_ctl_table[] = {

static int __net_init lowpan_frags_ns_sysctl_register(struct net *net)
{
- struct ctl_table *table;
+ struct sysctl_context ctx = {
+ .ns.net_ns = net,
+ };
struct ctl_table_header *hdr;
struct netns_ieee802154_lowpan *ieee802154_lowpan =
net_ieee802154_lowpan(net);
- size_t table_size = ARRAY_SIZE(lowpan_frags_ns_ctl_table);
-
- table = lowpan_frags_ns_ctl_table;
- if (!net_eq(net, &init_net)) {
- table = kmemdup(table, sizeof(lowpan_frags_ns_ctl_table),
- GFP_KERNEL);
- if (table == NULL)
- goto err_alloc;
-
- /* Don't export sysctls to unprivileged users */
- if (net->user_ns != &init_user_ns)
- table_size = 0;
- }

- table[0].data = &ieee802154_lowpan->fqdir->high_thresh;
- table[0].extra1 = &ieee802154_lowpan->fqdir->low_thresh;
- table[1].data = &ieee802154_lowpan->fqdir->low_thresh;
- table[1].extra2 = &ieee802154_lowpan->fqdir->high_thresh;
- table[2].data = &ieee802154_lowpan->fqdir->timeout;
+ /* Don't export sysctls to unprivileged users */
+ if (!net_eq(net, &init_net) && net->user_ns != &init_user_ns)
+ return 0;

- hdr = register_net_sysctl_sz(net, "net/ieee802154/6lowpan", table,
- table_size);
+ hdr = register_sysctl_fields(&net->sysctls, "net/ieee802154/6lowpan",
+ lowpan_frags_ns_ctl_table, &ctx);
if (hdr == NULL)
- goto err_reg;
+ return -ENOMEM;

ieee802154_lowpan->sysctl.frags_hdr = hdr;
return 0;
-
-err_reg:
- if (!net_eq(net, &init_net))
- kfree(table);
-err_alloc:
- return -ENOMEM;
}

static void __net_exit lowpan_frags_ns_sysctl_unregister(struct net *net)
{
- const struct ctl_table *table;
struct netns_ieee802154_lowpan *ieee802154_lowpan =
net_ieee802154_lowpan(net);

- table = ieee802154_lowpan->sysctl.frags_hdr->ctl_table_arg;
unregister_net_sysctl_table(ieee802154_lowpan->sysctl.frags_hdr);
- if (!net_eq(net, &init_net))
- kfree(table);
}

static struct ctl_table_header *lowpan_ctl_header;
--
2.55.0