Netdev List
 help / color / mirror / Atom feed
From: Ido Schimmel <idosch@nvidia.com>
To: netdev@vger.kernel.org
Cc: dsahern@kernel.org, stephen@networkplumber.org, petrm@nvidia.com,
	daniel@iogearbox.net, ferenc@fejes.dev,
	Ido Schimmel <idosch@nvidia.com>
Subject: [PATCH iproute2-next 3/3] ip: netns: add "ip netns cookie" command
Date: Wed, 23 Sep 2026 19:17:56 +0300	[thread overview]
Message-ID: <20260923161756.2914560-4-idosch@nvidia.com> (raw)
In-Reply-To: <20260923161756.2914560-1-idosch@nvidia.com>

"ip netns list" only reports named network namespaces, i.e., those that
are bind mounted under /var/run/netns. Network namespaces created by
container runtimes are usually not named, but there is still a need to
retrieve their cookie, for example, in order to correlate the records
in a trace to a container.

Add a command that reports the cookie of a single network namespace,
referenced either by name or by the PID of a process running in it. If
neither is specified, the cookie of the current network namespace is
reported:

 # ip netns add red
 # ip netns cookie red
 11
 # ip -j netns cookie red
 [{"cookie":11}]
 # ip netns exec red ip netns cookie
 11
 # ip netns cookie $$
 7
 # ip netns cookie
 7

An error is returned when the kernel does not support the NS_GET_ID
ioctl:

 # uname -r
 6.12.109-virtme-g39a867754a8a
 # ip netns add red
 # ip netns cookie red
 Cannot get cookie of network namespace "red": Inappropriate ioctl for device

Assisted-by: LLM
Reviewed-by: Petr Machata <petrm@nvidia.com>
Signed-off-by: Ido Schimmel <idosch@nvidia.com>
---
 ip/ipnetns.c           | 46 ++++++++++++++++++++++++++++++++++++++++++
 man/man8/ip-netns.8.in | 16 +++++++++++++++
 2 files changed, 62 insertions(+)

diff --git a/ip/ipnetns.c b/ip/ipnetns.c
index b62d2b0f57bf..165317b14c1c 100644
--- a/ip/ipnetns.c
+++ b/ip/ipnetns.c
@@ -36,6 +36,7 @@ static int usage(void)
 		"	ip [-all] netns delete [NAME]\n"
 		"	ip netns identify [PID]\n"
 		"	ip netns pids NAME\n"
+		"	ip netns cookie [NAME | PID]\n"
 		"	ip [-all] netns exec [NAME] cmd ...\n"
 		"	ip netns monitor\n"
 		"	ip netns list-id [target-nsid POSITIVE-INT] [nsid POSITIVE-INT]\n"
@@ -710,6 +711,48 @@ static int netns_identify(int argc, char **argv)
 	return rc;
 }
 
+static int netns_cookie(int argc, char **argv)
+{
+	const char *str;
+	__u64 cookie;
+	int fd;
+
+	if (argc > 1) {
+		fprintf(stderr, "extra arguments specified\n");
+		return -1;
+	}
+
+	if (argc == 1) {
+		str = argv[0];
+		fd = netns_get_fd(str);
+	} else {
+		str = "/proc/self/ns/net";
+		fd = open(str, O_RDONLY);
+	}
+	if (fd < 0) {
+		fprintf(stderr, "Cannot open network namespace \"%s\": %s\n",
+			str, strerror(errno));
+		return -1;
+	}
+
+	if (ioctl(fd, NS_GET_ID, &cookie) < 0) {
+		fprintf(stderr,
+			"Cannot get cookie of network namespace \"%s\": %s\n",
+			str, strerror(errno));
+		close(fd);
+		return -1;
+	}
+	close(fd);
+
+	new_json_obj(json);
+	open_json_object(NULL);
+	print_u64(PRINT_ANY, "cookie", "%llu\n", cookie);
+	close_json_object();
+	delete_json_obj();
+
+	return 0;
+}
+
 static int on_netns_del(char *nsname, void *arg)
 {
 	char netns_path[PATH_MAX];
@@ -1055,6 +1098,9 @@ int do_netns(int argc, char **argv)
 	if (matches(*argv, "pids") == 0)
 		return netns_pids(argc-1, argv+1);
 
+	if (strcmp(*argv, "cookie") == 0)
+		return netns_cookie(argc-1, argv+1);
+
 	if (matches(*argv, "exec") == 0)
 		return netns_exec(argc-1, argv+1);
 
diff --git a/man/man8/ip-netns.8.in b/man/man8/ip-netns.8.in
index 597a2602b32c..9b3ad14de677 100644
--- a/man/man8/ip-netns.8.in
+++ b/man/man8/ip-netns.8.in
@@ -42,6 +42,10 @@ ip-netns \- process network namespace management
 .BR "ip netns pids"
 .I NETNSNAME
 
+.ti -8
+.BR "ip netns cookie"
+.RI "[ " NETNSNAME " | " PID " ]"
+
 .ti -8
 .BR "ip [-all] netns exec "
 .RI "[ " NETNSNAME " ] " command ...
@@ -182,6 +186,18 @@ not specified then the current process will be used.
 This command walks through proc and finds all of the process who have
 the named network namespace as their primary network namespace.
 
+.TP
+.B ip netns cookie [ NETNSNAME | PID ] - Report the cookie of a network namespace
+.sp
+This command displays the cookie of the named network namespace or of
+the network namespace of the process PID. If neither is specified, the
+cookie of the current network namespace is displayed. See
+.B ip netns list
+for a description of the cookie. Unlike
+.BR "ip netns list" ,
+this command can also be used with network namespaces that are not
+named, such as those created by container runtimes.
+
 .TP
 .B ip [-all] netns exec [ NAME ] cmd ... - Run cmd in the named network namespace
 .sp
-- 
2.55.0


  parent reply	other threads:[~2026-09-23 16:18 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-23 16:17 [PATCH iproute2-next 0/3] ip: netns: report the network namespace cookie Ido Schimmel
2026-09-23 16:17 ` [PATCH iproute2-next 1/3] uapi: import nsfs.h from last sync point Ido Schimmel
2026-09-23 16:17 ` [PATCH iproute2-next 2/3] ip: netns: report the network namespace cookie Ido Schimmel
2026-09-23 16:17 ` Ido Schimmel [this message]
2026-09-23 21:10 ` [PATCH iproute2-next 0/3] " patchwork-bot+netdevbpf
2026-09-24  5:30 ` GMail

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260923161756.2914560-4-idosch@nvidia.com \
    --to=idosch@nvidia.com \
    --cc=daniel@iogearbox.net \
    --cc=dsahern@kernel.org \
    --cc=ferenc@fejes.dev \
    --cc=netdev@vger.kernel.org \
    --cc=petrm@nvidia.com \
    --cc=stephen@networkplumber.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox