Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

NetworkManager Dispatcher runs administrator-provided scripts when NetworkManager reports particular events. The action name is the second script argument: pre-up and pre-down are transition hooks, while up and down report completed activation or deactivation. These events explain why a script was queued; they do not guarantee the interface is still in that state when the script runs.

What a NetworkManager Dispatcher event means

Dispatcher is a D-Bus-activated service that runs administrator-provided scripts in response to NetworkManager events. Scripts receive the interface name as their first argument and the event action as their second. The action describes a NetworkManager transition or change, not necessarily the device’s state at the later moment the script executes.

The event definitions and timing below follow the NetworkManager Dispatcher reference manual.

Which events run before or after a connection changes?

Action Meaning and timing
pre-up The interface is connected but not fully activated. Applicable scripts run late in activation, and NetworkManager waits for them before reporting the interface fully activated.
up The interface has been activated.
pre-down The interface is about to be deactivated but has not yet disconnected. NetworkManager waits for applicable scripts before disconnecting it. This clean-transition event is not emitted for forced losses such as lost carrier or a fading Wi-Fi signal.
down The interface has been deactivated.
vpn-pre-up A VPN is connected but not fully activated. This uses the pre-up hook location, and NetworkManager waits for applicable scripts before reporting the VPN fully activated.
vpn-up A VPN connection has been activated.
vpn-pre-down The VPN is about to be deactivated but remains connected. This uses the pre-down hook location, and NetworkManager waits for applicable scripts before disconnecting it. Unexpected VPN termination or general connectivity loss does not produce this clean pre-down event.
vpn-down A VPN connection has been deactivated.

The practical distinction is whether work should happen during a clean transition or after it completes. For example, a script that must run before an orderly disconnect belongs on a pre-down hook; it must not assume that hook will run when connectivity vanishes unexpectedly.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What do the other dispatcher actions indicate?

Action Meaning and special detail
hostname The system hostname was updated. The interface argument is none, and no environment variable is set for this action.
dhcp4-change The DHCPv4 lease changed, such as through renewal or rebinding.
dhcp6-change The DHCPv6 lease changed.
connectivity-change NetworkManager’s connectivity state changed, for example when connectivity is lost or becomes available. The interface argument is empty.
reapply The connection was reapplied on the device.
dns-change DNS configuration changed, even if NetworkManager is configured not to manage resolv.conf. In that case, active connection DNS settings may be available in /run/NetworkManager/resolv.conf. The interface argument is empty.
device-add A special action for a generic connection whose generic.device-handler property names a handler script. Only one script runs, from dispatcher.d/device, and extra interface and connection information is supplied.

How Dispatcher chooses and invokes scripts

Script locations, ordering, and security

Dispatcher searches /etc/NetworkManager/dispatcher.d and /usr/lib/NetworkManager/dispatcher.d, along with applicable subdirectories. Applicable scripts run in alphabetical order. If identically named scripts exist in both locations, the /etc script takes precedence over the /usr/lib script.

An ordinary script must be a regular executable file owned by root, not writable by group or others, and not setuid. These requirements help prevent untrusted users from changing code that NetworkManager runs with administrative authority.

Arguments and environment

Ordinary invocations receive two arguments: the interface name first and the action second. For device events, the interface is the kernel interface suitable for IP configuration; depending on the case, it can correspond to VPN_IP_IFACE, DEVICE_IP_IFACE, or DEVICE_IFACE. The interface argument is none for hostname, and empty for connectivity-change and dns-change.

Scripts can also use environment values such as NM_DISPATCHER_ACTION, CONNECTION_UUID, CONNECTION_ID, CONNECTION_DBUS_PATH, CONNECTION_FILENAME, CONNECTION_EXTERNAL, DEVICE_IFACE, and DEVICE_IP_IFACE. Applicable IP configuration variables are exported as well; VPN invocations can include VPN-prefixed interface and address values. Connection user settings are exposed as CONNECTION_USER_ variables after their keys are encoded. The exact available environment depends on the action; consult the manual’s action-specific environment documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How long scripts run, and why events can be stale

Dispatcher runs scripts one at a time and asynchronously from NetworkManager’s main process. A script that takes too long can be killed. If a task might take an arbitrary amount of time, the manual advises starting a child process and returning promptly. A script symlinked into /etc/NetworkManager/dispatcher.d/no-wait.d/ runs immediately in parallel, without waiting for preceding scripts to finish.

Queued events are not cancelled just because a newer event makes them obsolete. An up action, for example, may execute after the interface has already gone down. Treat the action as the reason for invocation, not proof of current state; inspect the current device or connection state before taking consequential action.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Does a Dispatcher event mean the network is ready?

No. A pre-up hook runs late in profile activation, but neither that timing nor an up event proves that an application can reach a remote endpoint. The NetworkManager wait-online manual describes pre-up scripts as running late during profile activation; it does not make Dispatcher an application-readiness check or guarantee that every startup dependency is ready.

For a script that depends on a specific service or host, check that dependency directly and handle failure or retry as appropriate. Use Dispatcher for NetworkManager’s connection and configuration events, not as a substitute for verifying the thing your application needs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.