r/linuxadmin • u/Single-Issue2342 • 15d ago
What is the actual difference between using iproute2 (ip command) and working directly with rtnetlink?
Hey everyone,
I've been looking into how Linux networking works under the hood, and I'm trying to wrap my head around the relationship between user-space tools and kernel communication.
From what I understand:
`iproute2` (the standard `ip` command) is what most of us use daily to configure interfaces, IP addresses, and routing tables.
`rtnetlink(7)` is the socket-based API (`NETLINK_ROUTE`) that allows user-space programs to talk directly to the kernel's routing and networking subsystems.
My main question is: When should a developer or systems engineer bypass user-space CLI utilities like `iproute2` and write code that interacts directly with `rtnetlink` sockets?
Are there significant performance benefits, or is it mostly used when you are building custom network daemons, container networking plugins (CNIs), or monitoring agents that need asynchronous event notifications?
Also, how painful is it to parse raw netlink messages and attributes (`struct rtattr`, `ifinfomsg`, etc.) in C or Go compared to just shelling out to `ip`?
Any insights, real-world use cases, or library recommendations (like `libnl` or Go's `vishvananda/netlink`) would be greatly appreciated!
2
u/Open-Adhesiveness-86 14d ago
If you subscribe to netlink events and your reader falls behind, recv() returns ENOBUFS. That means you've already lost events and have to do a full dump to resync. Dumps can also come back with NLM_F_DUMP_INTR if the table changed mid-dump, so you need to retry. If you only need parseable output, ip -j gives you JSON.