Inspect Generic Netlink Families with genl
You will use genl to see which generic netlink families the kernel has registered, inspect one family by name or numeric ID, and watch controller notifications without changing network configuration. The examples use genl from iproute2 6.1.0, installed here as package version 6.1.0-1ubuntu6.4.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about ten minutes. You need a shell with iproute2 installed. The commands in this guide are read-only, so they normally need no elevated privileges. The monitor example deliberately runs until you stop it.
1. Confirm the installed command
Check the binary and its version before relying on output in a script:
$ command -v genl
/usr/sbin/genl
$ genl -V
genl utility, iproute2-6.1.0
The version matters here. The installed program's ctrl help output also advertises a policy command, although the local 2015 manpage documents the older set of operations. Treat the installed help and observed output as the contract for this machine, and check again after an iproute2 upgrade.
Checkpoint
If genl -V fails, stop and fix the iproute2 installation or your PATH before diagnosing generic netlink.
2. Read the controller help
Ask the ctrl object what it supports:
$ genl ctrl help
Usage: ctrl <CMD>
CMD := get <PARMS> | list | monitor | policy <PARMS>
PARMS := name <name> | id <id>
On this installation, the useful read-only operations are list, get, and monitor. The help text also lists policy, but the supplied manpage does not describe its output or arguments beyond the syntax shown above. Do not build an automated workflow around undocumented fields without testing it against the exact iproute2 build you deploy.
3. List registered generic netlink families
Run the list operation:
$ genl ctrl list
The output is one block per registered user of the generic netlink controller. A typical block begins like this on the guide machine:
Name: nlctrl
ID: 0x10 Version: 0x2 header size: 0 max attribs: 0
commands supported:
#1: ID-0x3
#2: ID-0xa
multicast groups:
#1: ID-0x10 name: notify
Further blocks include families such as ethtool, devlink and nl80211, depending on the kernel and loaded drivers. The list is not a fixed inventory: a different kernel, hardware set or module set can add or remove families.
Read the fields as discovery data. The family ID is the numeric address used by netlink, Version is the family's reported version, and the command and multicast-group sections describe interfaces exposed by that family. They do not tell you that every command is safe for an unprivileged caller. In particular, the installed output marks some commands as requiring administrator permission.
Checkpoint
Save a list for comparison without changing the system:
$ genl ctrl list > /tmp/genl-families.txt
$ grep -A3 '^Name: ' /tmp/genl-families.txt
The temporary file is only a snapshot. It becomes stale when the kernel or its modules change.
4. Query one family by name
Once the list gives you an exact name, query that family directly. nlctrl is available on this machine and is a useful controller-level test:
$ genl ctrl get name nlctrl
Name: nlctrl
ID: 0x10 Version: 0x2 header size: 0 max attribs: 0
commands supported:
#1: ID-0x3
#2: ID-0xa
multicast groups:
#1: ID-0x10 name: notify
Use a family name copied from your own list, not one guessed from a package name. A missing or misspelled family produces an error instead of a useful block.
This query is still observation. It does not enable the family, load a kernel module, alter a network device or subscribe the shell to notifications.
5. Query the same family by numeric ID
The ID in the list is hexadecimal in the display. The installed command accepts that value in the id form:
$ genl ctrl get id 0x10
Name: nlctrl
ID: 0x10 Version: 0x2 header size: 0 max attribs: 0
commands supported:
#1: ID-0x3
#2: ID-0xa
Use the ID only for the current kernel view. Numeric family IDs can differ between boots or hosts, so scripts that need a stable selection should resolve an exact family name and then verify the returned Name and Version.
Checkpoint
Compare the returned name with the name you requested. If a script receives an unexpected family, treat that as a discovery error and stop rather than sending follow-up requests based on the wrong ID.
6. Watch generic netlink notifications
Start a monitor when you need to see controller notifications:
$ genl ctrl monitor
The command waits for events and may print nothing until a relevant notification arrives. It is a foreground listener, not a one-shot query. Stop it with Ctrl-C when the observation window is over. There is no persistent configuration to undo.
For a bounded diagnostic capture, let the shell terminate it after a chosen interval:
$ timeout 30s genl ctrl monitor
$ printf 'monitor status: %s\n' "$?"
A status of 124 from GNU timeout means the 30-second limit expired. That is expected for a quiet observation window, not evidence that genl found an error. A status of 0 means the monitor ended normally, usually because it received a termination signal or the session was closed. Do not use sudo automatically: elevate only if your host's policy denies the read, and remember that privilege does not make a missing family exist.
7. Use output options carefully
The global options -s, -d and -r request statistics, details or raw output. They change presentation, not the family being queried:
$ genl -d ctrl get name nlctrl
$ genl -r ctrl get name nlctrl
Raw output is useful when another tool consumes the result, but it is less suitable for a human checklist. Do not parse decorative spacing or assume that command numbers map to the same operations across family versions. The family-specific interface remains the authority for what a command means.
Common traps
- Confusing generic netlink with ordinary IP configuration:
genlis a frontend for inspecting generic netlink controller data. It is not a replacement foripcommands that configure links, addresses or routes. - Assuming the list is stable: driver loading and kernel changes affect the registered families. Capture and compare snapshots only when you also record the host and kernel context.
- Leaving a monitor running: it is intentionally long-lived. Use
Ctrl-Cortimeout, especially in a terminal shared with another diagnostic task. - Trusting an old manpage blindly: this installed binary exposes
policyin its help even though the local manpage synopsis is narrower. Checkgenl ctrl helpon the target host.
Done means
genl -Vreports the expected iproute2 build.genl ctrl listshows the families registered by the current kernel.- You can query a selected family by both its exact name and its current ID.
- Any monitor session has been stopped or bounded with
timeout. - No network configuration or persistent system state was changed.