Skip to content
vast-cow's blog
Go back

Capturing DHCP-Assigned Network Parameters Using a Temporary macvlan in a Linux Network Namespace

Edit page

This article explains a simple workflow for safely obtaining network configuration information—such as a MAC address, newly assigned IPv4/IPv6 addresses, and default gateways—by creating a temporary macvlan interface, moving it into a Linux network namespace, running DHCP, recording results into a reusable env.sh file, and then cleaning up all temporary objects.

Overview

The goal is to:

  1. Create a macvlan interface on top of a physical interface (e.g., eth0).

  2. Move that macvlan interface into a dedicated network namespace (e.g., netns1).

  3. Run dhclient inside the namespace to obtain addresses:

    • IPv4 via DHCP (dhclient)
    • IPv6 via DHCPv6 if available (dhclient -6), while still allowing IPv6 Router Advertisements (SLAAC) to populate addresses where DHCPv6 is not used.
  4. Compare the interface’s address state before and after DHCP, and record only the newly added IPv4/IPv6 address (the first added address).

  5. Collect the final default route gateway (“via”) for IPv4 and IPv6 (without before/after comparison).

  6. Save values into env.sh in a format that later scripts can source.

  7. Delete the temporary macvlan and namespace to leave the system unchanged.

Why Use a Network Namespace?

A network namespace provides an isolated networking context. Running DHCP inside the namespace prevents your host’s primary networking from being modified and makes it easy to discard all state afterward. This is particularly helpful when you only need to “probe” a network and capture the resulting configuration for later use.

Why Use ip -j and jq?

The ip command supports JSON output (-j), which is much easier and safer to parse than human-readable output. With jq, you can reliably extract:

This approach avoids brittle text parsing and is more robust across distributions and iproute2 versions.

What Gets Written to env.sh?

The script writes shell-exportable variables, including:

Because these are standard export assignments, later scripts can simply do:

source ./env.sh

and immediately reuse the captured parameters.

Cleanup and Safety

A key design point is that the macvlan interface and namespace are temporary. The script uses a cleanup routine (typically via trap) to ensure the following objects are removed even if an error occurs:

This ensures the host returns to its original state after the run.

Practical Notes

Conclusion

By combining macvlan, network namespaces, DHCP, and JSON parsing with jq, you can safely obtain network configuration data without permanently altering the host’s networking. Saving results in env.sh provides a clean handoff to other scripts and automation, while the final cleanup step keeps the system tidy and repeatable.


Edit page
Share this post:

Comments


Previous Post
Building a “Software HSM” Workflow with SoftHSM2, OpenSC, and Python (Private Key Never Exported)
Next Post
Designing a Secure Directory Layout for Services That Start as Root and Then Drop Privileges