...

Package netns

import "github.com/vishvananda/netns"
Overview
Index

Overview ▾

Package netns allows ultra-simple network namespace handling. NsHandles can be retrieved and set. Note that the current namespace is thread local so actions that set and reset namespaces should use LockOSThread to make sure the namespace doesn't change due to a goroutine switch. It is best to close NsHandles when you are done with them. This can be accomplished via a `defer ns.Close()` on the handle. Changing namespaces requires elevated privileges, so in most cases this code needs to be run as root.

Constants

Deprecated: use golang.org/x/sys/unix pkg instead.

const (
    CLONE_NEWUTS  = unix.CLONE_NEWUTS  /* New utsname group? */
    CLONE_NEWIPC  = unix.CLONE_NEWIPC  /* New ipcs */
    CLONE_NEWUSER = unix.CLONE_NEWUSER /* New user namespace */
    CLONE_NEWPID  = unix.CLONE_NEWPID  /* New pid namespace */
    CLONE_NEWNET  = unix.CLONE_NEWNET  /* New network namespace */
    CLONE_IO      = unix.CLONE_IO      /* Get io context */
)

func DeleteNamed

func DeleteNamed(name string) error

DeleteNamed deletes a named network namespace

func Set

func Set(ns NsHandle) (err error)

Set sets the current network namespace to the namespace represented by NsHandle.

func Setns

func Setns(ns NsHandle, nstype int) (err error)

Setns sets namespace using golang.org/x/sys/unix.Setns.

Deprecated: Use golang.org/x/sys/unix.Setns instead.

type NsHandle

NsHandle is a handle to a network namespace. It can be cast directly to an int and used as a file descriptor.

type NsHandle int

func Get

func Get() (NsHandle, error)

Get gets a handle to the current threads network namespace.

func GetFromDocker

func GetFromDocker(id string) (NsHandle, error)

GetFromDocker gets a handle to the network namespace of a docker container. Id is prefixed matched against the running docker containers, so a short identifier can be used as long as it isn't ambiguous.

func GetFromName

func GetFromName(name string) (NsHandle, error)

GetFromName gets a handle to a named network namespace such as one created by `ip netns add`.

func GetFromPath

func GetFromPath(path string) (NsHandle, error)

GetFromPath gets a handle to a network namespace identified by the path

func GetFromPid

func GetFromPid(pid int) (NsHandle, error)

GetFromPid gets a handle to the network namespace of a given pid.

func GetFromThread

func GetFromThread(pid, tid int) (NsHandle, error)

GetFromThread gets a handle to the network namespace of a given pid and tid.

func New

func New() (ns NsHandle, err error)

New creates a new network namespace, sets it as current and returns a handle to it.

func NewNamed

func NewNamed(name string) (NsHandle, error)

NewNamed creates a new named network namespace, sets it as current, and returns a handle to it

func None

func None() NsHandle

None gets an empty (closed) NsHandle.

func (*NsHandle) Close

func (ns *NsHandle) Close() error

Close closes the NsHandle and resets its file descriptor to -1. It is not safe to use an NsHandle after Close() is called.

func (NsHandle) Equal

func (ns NsHandle) Equal(other NsHandle) bool

Equal determines if two network handles refer to the same network namespace. This is done by comparing the device and inode that the file descriptors point to.

func (NsHandle) IsOpen

func (ns NsHandle) IsOpen() bool

IsOpen returns true if Close() has not been called.

func (NsHandle) String

func (ns NsHandle) String() string

String shows the file descriptor number and its dev and inode.

func (NsHandle) UniqueId

func (ns NsHandle) UniqueId() string

UniqueId returns a string which uniquely identifies the namespace associated with the network handle.