Netdev List
 help / color / mirror / Atom feed
From: Ido Schimmel <idosch@nvidia.com>
To: netdev@vger.kernel.org
Cc: dsahern@kernel.org, stephen@networkplumber.org, petrm@nvidia.com,
	daniel@iogearbox.net, ferenc@fejes.dev,
	Ido Schimmel <idosch@nvidia.com>
Subject: [PATCH iproute2-next 0/3] ip: netns: report the network namespace cookie
Date: Wed, 23 Sep 2026 19:17:53 +0300	[thread overview]
Message-ID: <20260923161756.2914560-1-idosch@nvidia.com> (raw)

The kernel identifies a network namespace by a 64-bit cookie that is
assigned when the namespace is created and never changes.

The cookie is reported by a growing number of trace events such as the
TCP-MD5 and TCP-AO events and the net device events (e.g.,
net:net_dev_xmit). This allows filtering events that occur in a specific
network namespace, for example:

 # perf record -a -e net:net_dev_xmit --filter 'net_cookie == 12'

It is also available to tracing BPF programs that can access
'net_cookie' in 'struct net'.

However, no utility currently reports the cookie of a given network
namespace, so mapping a cookie in a trace to a namespace requires a
custom program that calls getsockopt(SO_NETNS_COOKIE) from within the
namespace.

Since Linux 6.18, the cookie is also the generic namespace ID and can be
retrieved via the NS_GET_ID ioctl on a network namespace file
descriptor. Unlike SO_NETNS_COOKIE, this does not require entering the
namespace, so the cookie of any namespace whose file can be opened can
be retrieved without privileges. A kernel selftest [1] ensures that both
interfaces report the same value for a given network namespace.

This patchset extends ip-netns to display the network namespace cookie.

Patch #1 imports the nsfs.h header that defines the NS_GET_ID ioctl.

Patch #2 reports the cookie in "ip netns list". It is always reported in
JSON mode and only reported with "-d" in plain text mode to avoid
breaking scripts that rely on the current output format.

Patch #3 adds "ip netns cookie [ NETNSNAME | PID ]" to report the cookie
of a single network namespace, including namespaces that are not bind
mounted under /var/run/netns, such as those created by container
runtimes.

[1] nsid_netns_basic in tools/testing/selftests/namespaces/nsid_test.c

Ido Schimmel (3):
  uapi: import nsfs.h from last sync point
  ip: netns: report the network namespace cookie
  ip: netns: add "ip netns cookie" command

 include/uapi/linux/nsfs.h | 122 ++++++++++++++++++++++++++++++++++++++
 ip/ipnetns.c              |  71 ++++++++++++++++++++++
 man/man8/ip-netns.8.in    |  30 +++++++++-
 3 files changed, 222 insertions(+), 1 deletion(-)
 create mode 100644 include/uapi/linux/nsfs.h

-- 
2.55.0


             reply	other threads:[~2026-09-23 16:18 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-23 16:17 Ido Schimmel [this message]
2026-09-23 16:17 ` [PATCH iproute2-next 1/3] uapi: import nsfs.h from last sync point Ido Schimmel
2026-09-23 16:17 ` [PATCH iproute2-next 2/3] ip: netns: report the network namespace cookie Ido Schimmel
2026-09-23 16:17 ` [PATCH iproute2-next 3/3] ip: netns: add "ip netns cookie" command Ido Schimmel
2026-09-23 21:10 ` [PATCH iproute2-next 0/3] ip: netns: report the network namespace cookie patchwork-bot+netdevbpf
2026-09-24  5:30 ` GMail

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260923161756.2914560-1-idosch@nvidia.com \
    --to=idosch@nvidia.com \
    --cc=daniel@iogearbox.net \
    --cc=dsahern@kernel.org \
    --cc=ferenc@fejes.dev \
    --cc=netdev@vger.kernel.org \
    --cc=petrm@nvidia.com \
    --cc=stephen@networkplumber.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox