From: Ido Schimmel <idosch@nvidia.com>
To: netdev@vger.kernel.org
Cc: dsahern@kernel.org, stephen@networkplumber.org, petrm@nvidia.com,
daniel@iogearbox.net, ferenc@fejes.dev,
Ido Schimmel <idosch@nvidia.com>
Subject: [PATCH iproute2-next 2/3] ip: netns: report the network namespace cookie
Date: Wed, 23 Sep 2026 19:17:55 +0300 [thread overview]
Message-ID: <20260923161756.2914560-3-idosch@nvidia.com> (raw)
In-Reply-To: <20260923161756.2914560-1-idosch@nvidia.com>
The kernel identifies a network namespace by a 64-bit cookie that is
assigned when the namespace is created and never changes. User space can
query the cookie using the SO_NETNS_COOKIE socket option and since Linux
6.18, the cookie is also the generic namespace ID and can be retrieved
via the NS_GET_ID ioctl on a network namespace file descriptor.
Report the cookie in "ip netns list". In JSON mode it is always
reported. In plain text mode it is only reported when details are
requested ("-d") to avoid breaking scripts that rely on the current
output format:
# ip netns add red
# ip netns add blue
# ip netns list
blue
red
# ip -d netns list
blue (cookie: 12)
red (cookie: 11)
# ip -j netns list
[{"name":"blue","cookie":12},{"name":"red","cookie":11}]
The cookie is not reported on kernels that do not support the NS_GET_ID
ioctl:
# uname -r
6.12.109-virtme-g39a867754a8a
# ip netns add red
# ip netns add blue
# ip -d netns list
blue
red
# ip -j netns list
[{"name":"blue"},{"name":"red"}]
The new functionality can be used to filter networking events that occur
in a specific network namespace:
# perf record -a -e net:net_dev_xmit --filter 'net_cookie == 12'
Assisted-by: LLM
Reviewed-by: Petr Machata <petrm@nvidia.com>
Signed-off-by: Ido Schimmel <idosch@nvidia.com>
---
ip/ipnetns.c | 25 +++++++++++++++++++++++++
man/man8/ip-netns.8.in | 14 +++++++++++++-
2 files changed, 38 insertions(+), 1 deletion(-)
diff --git a/ip/ipnetns.c b/ip/ipnetns.c
index 587534ae016b..b62d2b0f57bf 100644
--- a/ip/ipnetns.c
+++ b/ip/ipnetns.c
@@ -16,8 +16,10 @@
#include <sys/stat.h>
#include <sys/inotify.h>
#include <sys/mount.h>
+#include <sys/ioctl.h>
#include <linux/net_namespace.h>
+#include <linux/nsfs.h>
#include "utils.h"
#include "list.h"
@@ -444,9 +446,26 @@ static int netns_list_id(int argc, char **argv)
return 0;
}
+static int netns_get_cookie(const char *name, __u64 *cookie)
+{
+ char net_path[PATH_MAX];
+ int fd, ret;
+
+ snprintf(net_path, sizeof(net_path), "%s/%s", NETNS_RUN_DIR, name);
+ fd = open(net_path, O_RDONLY);
+ if (fd < 0)
+ return -1;
+
+ ret = ioctl(fd, NS_GET_ID, cookie);
+ close(fd);
+
+ return ret;
+}
+
static int netns_list(int argc, char **argv)
{
struct dirent *entry;
+ __u64 cookie;
DIR *dir;
int id;
@@ -469,6 +488,12 @@ static int netns_list(int argc, char **argv)
if (id >= 0)
print_int(PRINT_ANY, "id", " (id: %d)", id);
}
+ if (netns_get_cookie(entry->d_name, &cookie) == 0) {
+ print_u64(PRINT_JSON, "cookie", NULL, cookie);
+ if (show_details)
+ print_u64(PRINT_FP, NULL, " (cookie: %llu)",
+ cookie);
+ }
print_string(PRINT_FP, NULL, "\n", NULL);
close_json_object();
}
diff --git a/man/man8/ip-netns.8.in b/man/man8/ip-netns.8.in
index 2e12e28bbb2f..597a2602b32c 100644
--- a/man/man8/ip-netns.8.in
+++ b/man/man8/ip-netns.8.in
@@ -89,7 +89,19 @@ their traditional location in /etc.
.TP
.B ip netns list - show all of the named network namespaces
.sp
-This command displays all of the network namespaces in @NETNS_RUN_DIR@
+This command displays all of the network namespaces in @NETNS_RUN_DIR@.
+If the
+.B -details
+option is specified, the cookie of each network namespace is also
+displayed. The cookie is a 64-bit identifier that the kernel assigns to
+a network namespace when it is created and that never changes. Unlike
+the nsid, it is not relative to a peer network namespace. It is the same
+value that is reported by the
+.B SO_NETNS_COOKIE
+socket option and by trace events that identify a network namespace.
+The cookie is only displayed on kernels that support the
+.B NS_GET_ID
+ioctl (Linux 6.18 and later).
.TP
.B ip netns add NAME - create a new named network namespace
--
2.55.0
next prev parent reply other threads:[~2026-09-23 16:18 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-23 16:17 [PATCH iproute2-next 0/3] ip: netns: report the network namespace cookie Ido Schimmel
2026-09-23 16:17 ` [PATCH iproute2-next 1/3] uapi: import nsfs.h from last sync point Ido Schimmel
2026-09-23 16:17 ` Ido Schimmel [this message]
2026-09-23 16:17 ` [PATCH iproute2-next 3/3] ip: netns: add "ip netns cookie" command Ido Schimmel
2026-09-23 21:10 ` [PATCH iproute2-next 0/3] ip: netns: report the network namespace cookie patchwork-bot+netdevbpf
2026-09-24 5:30 ` GMail
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260923161756.2914560-3-idosch@nvidia.com \
--to=idosch@nvidia.com \
--cc=daniel@iogearbox.net \
--cc=dsahern@kernel.org \
--cc=ferenc@fejes.dev \
--cc=netdev@vger.kernel.org \
--cc=petrm@nvidia.com \
--cc=stephen@networkplumber.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox