On Wed, Sep 02, 2026 at 04:00:46PM -0700, Bobby Eshleman wrote:
vsock network namespaces let a host put each VM in a namespace of its
own. A guest has no equivalent yet. It has a single G2H device that
cannot be assigned to a network namespace.

Thanks for this, I'll do a proper review next week, in the mean time some comments below:


This series lets a guest move that device into a network namespace. A
new ioctl on /dev/vsock, IOCTL_VM_SOCKETS_ASSIGN_G2H_NETNS, assigns the
device to the namespace of the calling process. The namespace's existing

Why an ioctl?

I'm asking because I'd like to know if you've already considered any alternatives (sysfs, netlink, etc.)

How do you think the ioctl should be used? Should we provide an userspace tool, or extending some existing tools?

Thanks,
Stefano

ns_mode then decides who may use it: a "global" namespace shares the
device with every other global namespace, and a "local" namespace keeps
the host connection to itself. The device starts out in the initial
namespace, so until the ioctl is issued nothing has moved and no mode
has changed. There is no explicit unassign as assigning the device back
to the initial namespace is equivalent.

The ioctl requires CAP_NET_ADMIN in the initial user namespace.

Connections that can no longer reach the device after a move are reset,
so that a namespace which has lost access cannot keep using a socket it
opened while it still had access. Following netdevs, the device returns
to the initial namespace when the namespace it was moved to is deleted.

Transports opt in through a new netns_assign_allow callback. Only
virtio-vsock implements it here.

Why? (Not asking to support all the others, asking to explain the reason or ask helps from others to extend it)

Thanks,
Stefano


Patch 1 is just a const cleanup that patch 2 needs. The remaining
patches are actual implementation and tests.

Based off of Stefano's original series:
https://lore.kernel.org/all/[email protected]/

Suggested-by: Stefano Garzarella <[email protected]>
Link: https://lore.kernel.org/all/20200427142518.uwssa6dtasrp3bfc@steredhat/

Signed-off-by: Bobby Eshleman <[email protected]>
---
Bobby Eshleman (6):
     vsock: constify the transport in vsock_for_each_connected_socket()
     vsock: add IOCTL_VM_SOCKETS_ASSIGN_G2H_NETNS
     vsock/virtio: support guest device network namespace
     selftests/vsock: add a helper to assign the g2h device to a netns
     selftests/vsock: test the guest vsock device network namespace
     selftests/vsock: test the assign ioctl privilege checks

Documentation/admin-guide/sysctl/net.rst           |  18 +
include/linux/virtio_vsock.h                       |   2 +
include/net/af_vsock.h                             |   9 +-
include/uapi/linux/vm_sockets.h                    |   6 +
net/vmw_vsock/af_vsock.c                           | 200 ++++++++-
net/vmw_vsock/virtio_transport.c                   |  28 +-
net/vmw_vsock/virtio_transport_common.c            |  28 +-
tools/testing/selftests/vsock/.gitignore           |   1 +
tools/testing/selftests/vsock/Makefile             |   3 +-
tools/testing/selftests/vsock/config               |   1 +
tools/testing/selftests/vsock/vmtest.sh            | 461 ++++++++++++++++++++-
.../selftests/vsock/vsock_assign_g2h_netns.c       |  45 ++
12 files changed, 774 insertions(+), 28 deletions(-)
---
base-commit: d0ec95a8a4e79f2fd6063fc8932415db8c227689
change-id: 20260831-vsock-guest-ns-d06af451da67

Best regards,
--
Bobby Eshleman <[email protected]>



Reply via email to