LINUXOR.SK ... open source notes ...

Linux Namespaces - from one process to connected network namespaces

category: learnz/namespaces · date: 2016-11-01 · updated: 2026-10-04 · author: LALA · theme: github

This Learning is about Linux namespaces: what they are, how a process gets its own, and how separated network namespaces are connected again with virtual cables and switches. In the first four levels you work as root on one Linux machine with the standard tools, unshare and ip netns; only the last two connection labs install anything, Open vSwitch. The fifth level completes the set with the IPC, user, cgroup and time namespaces, works as an ordinary user, and shows what is still missing before isolation becomes a sandbox.

noteArticles 1 to 10 were written in 2016 and 2017, and their mistakes have been corrected since. The kernel interfaces they use are still there. The practical parts of the MNT and PID articles and articles 11 to 15 were added in 2026, in English.

The levels

Each level ends with a small check. There is no time limit: when you can do what the check asks, go on to the next level.

LevelYou practiceYou have passed the level when
1 · UnderstandWhat a namespace is, the kinds there are, the three system callsYou can say what each namespace isolates and list the namespaces of a running process under /proc/<PID>/ns
2 · IsolateGiving a process its own MNT, UTS or PID namespaceYou can start a shell in a new UTS namespace, change the host name there, and show that the host kept its own
3 · NetworkCreating, entering, watching and removing NET namespacesYou can create a network namespace, run a command inside it, and remove it again
4 · Connectveth pairs, a Linux bridge, an Open vSwitch switchTwo namespaces answer each other's ping, once over a veth pair and once through a switch
5 · Without rootThe IPC, user, cgroup and time namespaces, UID maps, and what a sandbox needs beyond namespacesYou can become root inside a user namespace, say why that root cannot touch the host's files, and name two things that still get into a bwrap sandbox

Level 1 is the Introduction. Level 2 is articles 2 to 4, level 3 is article 5, level 4 is the five connection labs, articles 6 to 10, and level 5 is articles 11 to 15.

The articles

Read them in this order. Articles 1 to 10 also exist in Slovak, the language they were written in; the (SK) link is at the top of each. In the Slovak versions of articles 2 and 4 the practical part is still marked TODO; it is written in the English versions only.

#ArticleWhat it is
1IntroductionLevel 1: the concepts, the API, the default namespaces and the namespaces-info.sh script
2MNT namespaceLevel 2: mount points seen by a process, private mounts, propagation
3UTS namespaceLevel 2: host name and domain name, with the full walk-through
4PID namespaceLevel 2: process IDs, PID 1 of a namespace, the view from outside
5NET namespaceLevel 3: the network stack, and the life of a network namespace
6Connecting a network namespace to the host system - with a veth pairLevel 4: one namespace and the host, joined by a veth pair
7Connecting two network namespaces (ns1, ns2) - with a veth pairLevel 4: two namespaces joined directly by a veth pair
8Connecting two network namespaces (ns1, ns2) - with two veth pairs and a standard Linux bridgeLevel 4: two namespaces on a standard Linux bridge
9Connecting two network namespaces (ns1, ns2) - with two veth pairs and a distributed OVS switch (openvswitch)Level 4: two namespaces on an Open vSwitch switch, with veth pairs
10Connecting two network namespaces (ns1, ns2) - with two ports on a distributed OVS switch (openvswitch)Level 4: two namespaces on Open vSwitch internal ports
11IPC namespaceLevel 5: System V IPC objects and POSIX message queues of a process's own
12USER namespaceLevel 5: UID and GID maps, root without privilege, and the namespace every unprivileged one builds on
13CGROUP namespaceLevel 5: a private view of the cgroup hierarchy, and how it differs from a limit
14TIME namespaceLevel 5: a process with its own monotonic and boot-time clocks
15From namespaces to a sandboxLevel 5: capabilities, seccomp and Landlock, pasta, bwrap, and what still leaks in

What you will be able to do

Set up once

One Linux machine, physical or virtual, where you are root. Use one you can afford to break: the labs create network devices and change addresses. The connection labs with Open vSwitch need the openvswitch package. Level 5 needs no root; articles 12 and 15 use podman, and article 15 also bwrap (bubblewrap) and pasta (passt).

Inspiration and current practice

Articles 1 to 10 do everything as root, the way it was done in 2016. Today the starting point is the user namespace, which needs no root and which the other namespaces build on. Each of those articles therefore ends with a section Current practice, which says what has changed and shows the unprivileged way where there is one, and articles 12 and 15 cover the user namespace and what a sandbox needs on top of it.

Those sections and the new articles build on one talk:

It puts namespaces beside the other pieces of process isolation in Linux, capabilities, seccomp and Landlock, walks through unshare, user namespaces, pasta and bubblewrap at the keyboard, and shows why namespaces alone are not a sandbox: environment variables, open file descriptors and the network all pass through unless something stops them.

Final check

Create two network namespaces, connect them, and make one ping the other. Then explain, for each command you typed, which namespace it ran in. A container runtime does the same steps for you.