[PATCH net-next 0/6] vsock: assign the guest vsock device to a network namespace
From: Bobby Eshleman <hidden>
Date: 2026-09-02 23:01:10
Also in:
kvm, linux-doc, linux-kselftest, lkml, netdev
vsock network namespaces let a host put each VM in a namespace of its own. A guest has no equivalent yet. It has a single G2H device that cannot be assigned to a network namespace. This series lets a guest move that device into a network namespace. A new ioctl on /dev/vsock, IOCTL_VM_SOCKETS_ASSIGN_G2H_NETNS, assigns the device to the namespace of the calling process. The namespace's existing ns_mode then decides who may use it: a "global" namespace shares the device with every other global namespace, and a "local" namespace keeps the host connection to itself. The device starts out in the initial namespace, so until the ioctl is issued nothing has moved and no mode has changed. There is no explicit unassign as assigning the device back to the initial namespace is equivalent. The ioctl requires CAP_NET_ADMIN in the initial user namespace. Connections that can no longer reach the device after a move are reset, so that a namespace which has lost access cannot keep using a socket it opened while it still had access. Following netdevs, the device returns to the initial namespace when the namespace it was moved to is deleted. Transports opt in through a new netns_assign_allow callback. Only virtio-vsock implements it here. Patch 1 is just a const cleanup that patch 2 needs. The remaining patches are actual implementation and tests. Based off of Stefano's original series: https://lore.kernel.org/all/20200116172428.311437-1-sgarzare@redhat.com/ (local) Suggested-by: Stefano Garzarella <sgarzare@redhat.com> Link: https://lore.kernel.org/all/20200427142518.uwssa6dtasrp3bfc@steredhat/ (local) Signed-off-by: Bobby Eshleman <redacted> --- Bobby Eshleman (6): vsock: constify the transport in vsock_for_each_connected_socket() vsock: add IOCTL_VM_SOCKETS_ASSIGN_G2H_NETNS vsock/virtio: support guest device network namespace selftests/vsock: add a helper to assign the g2h device to a netns selftests/vsock: test the guest vsock device network namespace selftests/vsock: test the assign ioctl privilege checks Documentation/admin-guide/sysctl/net.rst | 18 + include/linux/virtio_vsock.h | 2 + include/net/af_vsock.h | 9 +- include/uapi/linux/vm_sockets.h | 6 + net/vmw_vsock/af_vsock.c | 200 ++++++++- net/vmw_vsock/virtio_transport.c | 28 +- net/vmw_vsock/virtio_transport_common.c | 28 +- tools/testing/selftests/vsock/.gitignore | 1 + tools/testing/selftests/vsock/Makefile | 3 +- tools/testing/selftests/vsock/config | 1 + tools/testing/selftests/vsock/vmtest.sh | 461 ++++++++++++++++++++- .../selftests/vsock/vsock_assign_g2h_netns.c | 45 ++ 12 files changed, 774 insertions(+), 28 deletions(-) --- base-commit: d0ec95a8a4e79f2fd6063fc8932415db8c227689 change-id: 20260831-vsock-guest-ns-d06af451da67 Best regards, -- Bobby Eshleman [off-list ref]