Netdev List
 help / color / mirror / Atom feed
From: GMail <primalgamer@gmail.com>
To: Ido Schimmel <idosch@nvidia.com>, netdev@vger.kernel.org
Cc: dsahern@kernel.org, stephen@networkplumber.org, petrm@nvidia.com,
	 daniel@iogearbox.net, ferenc@fejes.dev
Subject: Re: [PATCH iproute2-next 0/3] ip: netns: report the network namespace cookie
Date: Thu, 24 Sep 2026 07:30:19 +0200	[thread overview]
Message-ID: <7f82e52d5495cf61f7debf860ab5585d03ebfb66.camel@gmail.com> (raw)
In-Reply-To: <20260923161756.2914560-1-idosch@nvidia.com>

On Wed, 2026-09-23 at 19:17 +0300, Ido Schimmel wrote:
> The kernel identifies a network namespace by a 64-bit cookie that is
> assigned when the namespace is created and never changes.
> 
> The cookie is reported by a growing number of trace events such as
> the
> TCP-MD5 and TCP-AO events and the net device events (e.g.,
> net:net_dev_xmit). This allows filtering events that occur in a
> specific
> network namespace, for example:
> 
>  # perf record -a -e net:net_dev_xmit --filter 'net_cookie == 12'
> 
> It is also available to tracing BPF programs that can access
> 'net_cookie' in 'struct net'.
> 
> However, no utility currently reports the cookie of a given network
> namespace, so mapping a cookie in a trace to a namespace requires a
> custom program that calls getsockopt(SO_NETNS_COOKIE) from within the
> namespace.
> 
> Since Linux 6.18, the cookie is also the generic namespace ID and can
> be
> retrieved via the NS_GET_ID ioctl on a network namespace file
> descriptor. Unlike SO_NETNS_COOKIE, this does not require entering
> the
> namespace, so the cookie of any namespace whose file can be opened
> can
> be retrieved without privileges. A kernel selftest [1] ensures that
> both
> interfaces report the same value for a given network namespace.
> 
> This patchset extends ip-netns to display the network namespace
> cookie.

Super useful, thank you!

> 
> Patch #1 imports the nsfs.h header that defines the NS_GET_ID ioctl.
> 
> Patch #2 reports the cookie in "ip netns list". It is always reported
> in
> JSON mode and only reported with "-d" in plain text mode to avoid
> breaking scripts that rely on the current output format.
> 
> Patch #3 adds "ip netns cookie [ NETNSNAME | PID ]" to report the
> cookie
> of a single network namespace, including namespaces that are not bind
> mounted under /var/run/netns, such as those created by container
> runtimes.
> 
> [1] nsid_netns_basic in
> tools/testing/selftests/namespaces/nsid_test.c
> 
> Ido Schimmel (3):
>   uapi: import nsfs.h from last sync point
>   ip: netns: report the network namespace cookie
>   ip: netns: add "ip netns cookie" command
> 
>  include/uapi/linux/nsfs.h | 122
> ++++++++++++++++++++++++++++++++++++++
>  ip/ipnetns.c              |  71 ++++++++++++++++++++++
>  man/man8/ip-netns.8.in    |  30 +++++++++-
>  3 files changed, 222 insertions(+), 1 deletion(-)
>  create mode 100644 include/uapi/linux/nsfs.h

Ferenc

      parent reply	other threads:[~2026-09-24  5:30 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-23 16:17 [PATCH iproute2-next 0/3] ip: netns: report the network namespace cookie Ido Schimmel
2026-09-23 16:17 ` [PATCH iproute2-next 1/3] uapi: import nsfs.h from last sync point Ido Schimmel
2026-09-23 16:17 ` [PATCH iproute2-next 2/3] ip: netns: report the network namespace cookie Ido Schimmel
2026-09-23 16:17 ` [PATCH iproute2-next 3/3] ip: netns: add "ip netns cookie" command Ido Schimmel
2026-09-23 21:10 ` [PATCH iproute2-next 0/3] ip: netns: report the network namespace cookie patchwork-bot+netdevbpf
2026-09-24  5:30 ` GMail [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=7f82e52d5495cf61f7debf860ab5585d03ebfb66.camel@gmail.com \
    --to=primalgamer@gmail.com \
    --cc=daniel@iogearbox.net \
    --cc=dsahern@kernel.org \
    --cc=ferenc@fejes.dev \
    --cc=idosch@nvidia.com \
    --cc=netdev@vger.kernel.org \
    --cc=petrm@nvidia.com \
    --cc=stephen@networkplumber.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox