From: Ido Schimmel <idosch@nvidia.com>
To: netdev@vger.kernel.org
Cc: dsahern@kernel.org, stephen@networkplumber.org, petrm@nvidia.com,
daniel@iogearbox.net, ferenc@fejes.dev,
Ido Schimmel <idosch@nvidia.com>
Subject: [PATCH iproute2-next 0/3] ip: netns: report the network namespace cookie
Date: Wed, 23 Sep 2026 19:17:53 +0300 [thread overview]
Message-ID: <20260923161756.2914560-1-idosch@nvidia.com> (raw)
The kernel identifies a network namespace by a 64-bit cookie that is
assigned when the namespace is created and never changes.
The cookie is reported by a growing number of trace events such as the
TCP-MD5 and TCP-AO events and the net device events (e.g.,
net:net_dev_xmit). This allows filtering events that occur in a specific
network namespace, for example:
# perf record -a -e net:net_dev_xmit --filter 'net_cookie == 12'
It is also available to tracing BPF programs that can access
'net_cookie' in 'struct net'.
However, no utility currently reports the cookie of a given network
namespace, so mapping a cookie in a trace to a namespace requires a
custom program that calls getsockopt(SO_NETNS_COOKIE) from within the
namespace.
Since Linux 6.18, the cookie is also the generic namespace ID and can be
retrieved via the NS_GET_ID ioctl on a network namespace file
descriptor. Unlike SO_NETNS_COOKIE, this does not require entering the
namespace, so the cookie of any namespace whose file can be opened can
be retrieved without privileges. A kernel selftest [1] ensures that both
interfaces report the same value for a given network namespace.
This patchset extends ip-netns to display the network namespace cookie.
Patch #1 imports the nsfs.h header that defines the NS_GET_ID ioctl.
Patch #2 reports the cookie in "ip netns list". It is always reported in
JSON mode and only reported with "-d" in plain text mode to avoid
breaking scripts that rely on the current output format.
Patch #3 adds "ip netns cookie [ NETNSNAME | PID ]" to report the cookie
of a single network namespace, including namespaces that are not bind
mounted under /var/run/netns, such as those created by container
runtimes.
[1] nsid_netns_basic in tools/testing/selftests/namespaces/nsid_test.c
Ido Schimmel (3):
uapi: import nsfs.h from last sync point
ip: netns: report the network namespace cookie
ip: netns: add "ip netns cookie" command
include/uapi/linux/nsfs.h | 122 ++++++++++++++++++++++++++++++++++++++
ip/ipnetns.c | 71 ++++++++++++++++++++++
man/man8/ip-netns.8.in | 30 +++++++++-
3 files changed, 222 insertions(+), 1 deletion(-)
create mode 100644 include/uapi/linux/nsfs.h
--
2.55.0
next reply other threads:[~2026-09-23 16:18 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-23 16:17 Ido Schimmel [this message]
2026-09-23 16:17 ` [PATCH iproute2-next 1/3] uapi: import nsfs.h from last sync point Ido Schimmel
2026-09-23 16:17 ` [PATCH iproute2-next 2/3] ip: netns: report the network namespace cookie Ido Schimmel
2026-09-23 16:17 ` [PATCH iproute2-next 3/3] ip: netns: add "ip netns cookie" command Ido Schimmel
2026-09-23 21:10 ` [PATCH iproute2-next 0/3] ip: netns: report the network namespace cookie patchwork-bot+netdevbpf
2026-09-24 5:30 ` GMail
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260923161756.2914560-1-idosch@nvidia.com \
--to=idosch@nvidia.com \
--cc=daniel@iogearbox.net \
--cc=dsahern@kernel.org \
--cc=ferenc@fejes.dev \
--cc=netdev@vger.kernel.org \
--cc=petrm@nvidia.com \
--cc=stephen@networkplumber.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox