AFXDP skill for high-performance XDP sockets. An agent skill from mohitmishra786/low-level-dev-skills.

MITAuto-check passed

Install Af Xdp

skills CLI
$ npx skills add mohitmishra786/low-level-dev-skills --skill af-xdp -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitmishra786/low-level-dev-skills af-xdp --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitmishra786/low-level-dev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/async-io/af-xdp .claude/skills/af-xdp && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
af-xdp
GitHub stars
252
Token cost
~1.8k tokens
SKILL.md length
371 words
Files
1
Skills in repo
138
Repo updated
First seen
Licence
MIT

At a glance

AFXDP skill for high-performance XDP sockets. An agent skill from mohitmishra786/low-level-dev-skills.

  • Works in 9 steps: Architecture overview → UMEM and XSK socket creation → Populate fill ring → …
  • Creating AFXDP sockets
  • SKILL.md covers Purpose, When to Use, Workflow and Common Problems, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Af Xdp is an agent skill from mohitmishra786/low-level-dev-skills. AFXDP skill for high-performance XDP sockets. Use when creating AFXDP sockets, configuring UMEM and XSK rings, XDPREDIRECT programs, copy vs zero-copy mode, or comparing with DPDK. Activates on queries about AFXDP, xskumem, XDPREDIRECT, libbpf xsk, or zero-copy XDP.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: A curated suite of AI agent skills for systems and low-level programming with C/C++, Rust, and Zig toolchains, covering compilers, debuggers, profilers, build systems…. The licence is MIT.

When your agent uses it

  • Creating AFXDP sockets
  • Configuring UMEM and XSK rings
  • XDPREDIRECT programs
  • Copy vs zero-copy mode

Example prompts

  • “/af-xdp”

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Architecture overview
  2. UMEM and XSK socket creation
  3. Populate fill ring
  4. XDP redirect program
  5. RX processing loop
  6. Copy vs zero-copy
  7. libbpf xsk.h helpers
  8. Performance vs DPDK
  9. Production patterns

What it can do on your machine

Read from SKILL.md and the folder at commit bdc5847. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are c and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Af Xdp loads about 1.8k tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 371 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitmishra786/low-level-dev-skills at commit bdc5847, republished under its MIT licence (© mohitmishra786). 371 words, ~1,831 tokens.

Download SKILL.mdSave it as .claude/skills/af-xdp/SKILL.md (or your agent's skills folder).
name
af-xdp
description
AF_XDP skill for high-performance XDP sockets. Use when creating AF_XDP sockets, configuring UMEM and XSK rings, XDP_REDIRECT programs, copy vs zero-copy mode, or comparing with DPDK. Activates on queries about AF_XDP, xsk_umem, XDP_REDIRECT, libbpf xsk, or zero-copy XDP.

AF_XDP

Purpose

Guide agents through AF_XDP sockets for high-performance packet I/O: socket creation, UMEM setup, fill/completion/RX/TX rings, XDP programs with XDP_REDIRECT to XSK, copy vs zero-copy modes, libbpf helpers, performance comparison with DPDK, and production use cases.

When to Use

  • Building a userspace packet processor with lower overhead than raw sockets
  • Redirecting XDP-filtered traffic to userspace without DPDK complexity
  • Implementing a custom load balancer or IDS dataplane
  • Comparing zero-copy vs copy mode on your NIC/driver
  • Integrating with existing libbpf/XDP infrastructure
  • Need kernel cooperation (firewall rules) plus userspace processing

Workflow

1. Architecture overview
NIC → XDP program (BPF) → XDP_REDIRECT → AF_XDP socket → userspace
                ↓
           XDP_DROP/PASS/TX

Components:

  • UMEM — shared memory region for frames
  • Fill ring — userspace provides empty frame addresses to kernel
  • Completion ring — kernel returns completed TX frames
  • RX ring — kernel delivers received packets
  • TX ring — userspace submits packets for transmission
2. UMEM and XSK socket creation
c
#include <bpf/xsk.h>
#include <bpf/libbpf.h>
#include <xdp/xsk.h>

#define NUM_FRAMES     4096
#define FRAME_SIZE     XSK_UMEM__DEFAULT_FRAME_SIZE
#define RX_BATCH_SIZE  64

struct xsk_umem_info {
    struct xsk_ring_prod fill;
    struct xsk_ring_cons comp;
    struct xsk_umem *umem;
    void *buffer;
};

struct xsk_socket_info {
    struct xsk_ring_cons rx;
    struct xsk_ring_prod tx;
    struct xsk_socket *xsk;
};

int xsk_setup(struct xsk_umem_info *umem_info,
              struct xsk_socket_info *xsk_info,
              int ifindex, int queue_id, int xsk_flags)
{
    umem_info->buffer = mmap(NULL, NUM_FRAMES * FRAME_SIZE,
        PROT_READ | PROT_WRITE, MAP_PRIVATE | MAP_ANONYMOUS, -1, 0);

    struct xsk_umem_config umem_cfg = {
        .fill_size = XSK_RING_PROD__DEFAULT_NUM_DESCS,
        .comp_size = XSK_RING_CONS__DEFAULT_NUM_DESCS,
        .frame_size = FRAME_SIZE,
        .frame_headroom = XSK_UMEM__DEFAULT_FRAME_HEADROOM,
        .flags = 0,
    };

    int ret = xsk_umem__create(&umem_info->umem, umem_info->buffer,
        NUM_FRAMES * FRAME_SIZE, &umem_info->fill, &umem_info->comp,
        &umem_cfg);
    if (ret)
        return ret;

    struct xsk_socket_config xsk_cfg = {
        .rx_size = XSK_RING_CONS__DEFAULT_NUM_DESCS,
        .tx_size = XSK_RING_PROD__DEFAULT_NUM_DESCS,
        .libbpf_flags = XSK_LIBBPF_FLAGS__INHIBIT_PROG_LOAD,
        .xdp_flags = XDP_FLAGS_UPDATE_IF_NOEXIST,
        .bind_flags = xsk_flags,  // XDP_ZEROCOPY or XDP_COPY
    };

    return xsk_socket__create(&xsk_info->xsk, "eth0", queue_id,
        umem_info->umem, &xsk_info->rx, &xsk_info->tx, &xsk_cfg);
}
3. Populate fill ring
c
void populate_fill_ring(struct xsk_umem_info *umem) {
    uint32_t idx;
    uint32_t ret = xsk_ring_prod__reserve(&umem->fill, RX_BATCH_SIZE, &idx);
    for (uint32_t i = 0; i < ret; i++)
        *xsk_ring_prod__fill_addr(&umem->fill, idx + i) = i * FRAME_SIZE;
    xsk_ring_prod__submit(&umem->fill, ret);
}

Must keep fill ring stocked — kernel drops packets if no buffers available.

4. XDP redirect program
c
// xdp_redirect.c
#include <linux/bpf.h>
#include <bpf/bpf_helpers.h>

struct {
    __uint(type, BPF_MAP_TYPE_XSKMAP);
    __uint(max_entries, 64);
    __type(key, int);
    __type(value, int);
} xsks_map SEC(".maps");

SEC("xdp")
int xdp_redirect_prog(struct xdp_md *ctx)
{
    int index = ctx->rx_queue_index;
    return bpf_redirect_map(&xsks_map, index, 0);
}
bash
# Load and attach
bpftool prog load xdp_redirect.o /sys/fs/bpf/xdp_redirect
ip link set dev eth0 xdp obj xdp_redirect.o sec xdp

# Pin xsks_map and update with socket fd
5. RX processing loop
c
while (running) {
    uint32_t idx_rx = 0, rcvd;
    rcvd = xsk_ring_cons__peek(&xsk_info->rx, RX_BATCH_SIZE, &idx_rx);
    if (!rcvd)
        continue;

    for (uint32_t i = 0; i < rcvd; i++) {
        const struct xdp_desc *desc = xsk_ring_cons__rx_desc(&xsk_info->rx, idx_rx + i);
        uint64_t addr = desc->addr;
        uint32_t len = desc->len;
        uint8_t *pkt = (uint8_t *)xsk_umem__get_data(umem_info->buffer, addr);
        process_packet(pkt, len);
    }
    xsk_ring_cons__release(&xsk_info->rx, rcvd);

    // Return frames to fill ring
    refill_fill_ring(umem_info, rcvd);
}
6. Copy vs zero-copy
ModeFlagRequirements
CopyXDP_COPY (default)Any driver; kernel copies to UMEM
Zero-copyXDP_ZEROCOPYDriver support (i40e, ixgbe, mlx5, etc.)
bash
# Check driver ZC support
ethtool -i eth0
# Kernel log on bind:
dmesg | grep xsk
# "Zero-copy enabled" or "Copy mode"

Zero-copy: NIC DMAs directly into UMEM frames — lowest latency. Copy mode: safer, universal.

7. libbpf xsk.h helpers
bash
# Modern libbpf includes xsk API
pkg-config --libs libbpf
# -lbpf -lxdp (if separate libxdp installed)

Key functions:

  • xsk_umem__create / xsk_umem__delete
  • xsk_socket__create / xsk_socket__delete
  • xsk_umem__get_data — pointer from frame address
  • xsk_socket__fd — for epoll/poll integration
Show full SKILL.md (157 more words)Show less
8. Performance vs DPDK
FactorAF_XDPDPDK
Setup complexityModerateHigh (hugepages, EAL)
Kernel integrationXDP filter in kernelFull bypass
Typical throughputNear-DPDK with ZCHighest
NIC bindingStays on kernel drivervfio/uio binding
Use case fitFilter + selective userspaceFull dataplane takeover
9. Production patterns
Common deployments
├── CDN edge cache — XDP_DROP junk, redirect cacheable to XSK
├── DDoS mitigation — XDP_DROP attack patterns
├── Load balancer — XDP_TX hairpin or redirect to backend XSK
└── Observability — mirror subset to XSK for analysis
bash
# Multi-queue: one XSK per RX queue, pinned to CPU
taskset -c 2 ./xsk_app --queue 2

Common Problems

SymptomCauseFix
No packets in RX ringXDP program not redirectingVerify xsks_map entry for queue index
EBUSY on socket createXDP already attachedip link set dev eth0 xdp off first
Zero-copy fallback to copyDriver lacks ZCCheck dmesg; use supported NIC
Packet dropsFill ring emptyAggressive refill; increase NUM_FRAMES
TX not workingCompletion ring not polledProcess comp ring to recycle frames
Permission deniedCAP_NET_RAW neededRun with appropriate capabilities
  • skills/observability/ebpf — XDP/BPF program development
  • skills/async-io/dpdk — full kernel bypass alternative
  • skills/async-io/io-uring — async I/O for non-packet workloads
  • skills/observability/ebpf-rust — Aya for XDP in Rust
  • skills/profilers/linux-perf — profile XDP program CPU usage
  • skills/allocators/numa-programming — NUMA-local UMEM allocation

© mohitmishra786, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/async-io/af-xdp of mohitmishra786/low-level-dev-skills.

Open the folder on GitHubat commit bdc5847

Compare with similar skills

Af Xdp next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Af Xdp compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Af Xdp this skillmohitmishra786/low-level-dev-skills252—~1.8kAutomated safety check: PassMIT
cmux Socket Policymanaflow-ai/cmux28k1 repos~631Automated safety check: PassCustom licence
Doca Socket RelayNVIDIA/skills3.6k—~4kAutomated safety check: PassApache-2.0
Socket BridgeCai-aa/CAE-Agent-Hub1k—~745Automated safety check: PassMIT
Socket Event Listenerr0adkll/Campfire141—~2.5kAutomated safety check: PassGPL-3.0
TreeSheets Agent Socketaardappel/treesheets3.2k—~5.7kAutomated safety check: NotesZlib

Similar skills

  • cmux Socket Policy

    manaflow-ai/cmux

    Sets threading and focus rules for adding or changing cmux socket and CLI commands, so telemetry stays off the main thread and automation never steals app focus.

    28k GitHub starsUsed in 1 repo~631 tokens
    DevelopmentAuto-check passed
  • Doca Socket Relay

    NVIDIA/skills

    Official

    A skill your agent uses when the operator is driving the DOCA Socket Relay to bridge a socket-oriented host application onto a BlueField DPU peer without rewriting it — picking the deployment shape…

    3.6k GitHub stars~4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Socket Bridge

    Cai-aa/CAE-Agent-Hub

    Connect to Abaqus CAE via socket bridge for curing simulation.

    1k GitHub stars~745 tokensUpdated 10 days ago
    Auto-check passed
  • Socket Event Listener

    r0adkll/Campfire

    Enforce the Campfire pattern for feature modules to react to Audiobookshelf socket events.

    141 GitHub stars~2.5k tokensUpdated today
    MobileAuto-check passed
  • TreeSheets Agent Socket

    aardappel/treesheets

    Runs Lobster scripts against the document open in a running TreeSheets instance through its local agent socket, and returns the results or errors.

    3.2k GitHub stars~5.7k tokensUpdated yesterday
    Productivity & AutomationAuto-check: notes
  • Acarshub Socket Namespace

    sdr-enthusiasts/docker-acarshub

    Use ONLY when working in the docker-acarshub repository AND touching socket.io code -- emit / on / connect calls on either the React frontend or the Fastify backend.

    117 GitHub stars~710 tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed

More from mohitmishra786/low-level-dev-skills

All 138 skills in this repo
  • ARM and AArch64 Assembly

    mohitmishra786/low-level-dev-skills

    Guides reading and writing AArch64 and ARM Thumb assembly: compiler output, inline asm, registers, the AAPCS calling convention and NEON or SVE basics.

    252 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • RISC-V Assembly Guide

    mohitmishra786/low-level-dev-skills

    Reference for RISC-V assembly on RV32 and RV64: register names and calling convention, extension naming, GCC and Clang inline asm, and QEMU with GDB debugging.

    252 GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check passed
  • x86-64 Assembly Reference

    mohitmishra786/low-level-dev-skills

    Explains x86-64 registers, the System V AMD64 calling convention, and how to read compiler-generated or inline assembly.

    252 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Bazel for C and C++

    mohitmishra786/low-level-dev-skills

    Guides your agent through Bazel for C/C++ projects: BUILD files, Bzlmod dependencies, toolchain registration, remote execution, dependency queries and sandbox debugging.

    252 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Binary Hardening

    mohitmishra786/low-level-dev-skills

    Binary hardening skill for security-hardened C/C++ builds. An agent skill from mohitmishra786/low-level-dev-skills.

    252 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed
  • Binutils

    mohitmishra786/low-level-dev-skills

    GNU binutils skill for binary manipulation and analysis. An agent skill from mohitmishra786/low-level-dev-skills.

    252 GitHub stars~1.2k tokensUpdated 3 mo ago
    Auto-check passed

Questions about Af Xdp

What does Af Xdp do?

AFXDP skill for high-performance XDP sockets. An agent skill from mohitmishra786/low-level-dev-skills. Af Xdp is an agent skill from mohitmishra786/low-level-dev-skills. AFXDP skill for high-performance XDP sockets.

When should I use Af Xdp?

Af Xdp fits situations like: creating AFXDP sockets; configuring UMEM and XSK rings; XDPREDIRECT programs; copy vs zero-copy mode.

How do I install Af Xdp in Claude Code?

Run `npx skills add mohitmishra786/low-level-dev-skills --skill af-xdp -a claude-code`. Or copy the skill folder (skills/async-io/af-xdp in mohitmishra786/low-level-dev-skills) into .claude/skills/af-xdp in your project. Claude Code loads it when a task matches its description.

How do I install Af Xdp in Codex?

Run `npx skills add mohitmishra786/low-level-dev-skills --skill af-xdp -a codex`. Or copy the skill folder (skills/async-io/af-xdp in mohitmishra786/low-level-dev-skills) into .agents/skills/af-xdp in your project. Codex loads it when a task matches its description.

Can I use Af Xdp in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitmishra786/low-level-dev-skills --skill af-xdp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/af-xdp, .gemini/skills/af-xdp, .github/skills/af-xdp and .opencode/skills/af-xdp in your project.

What does Af Xdp need to run?

SKILL.md names no scripts, command-line tools or credentials: Af Xdp is instructions for the agent only.

Does Af Xdp access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Af Xdp safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Af Xdp use?

Af Xdp is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Af Xdp use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Af Xdp?

Skills that share tags, products or a category with Af Xdp: cmux Socket Policy (manaflow-ai/cmux, 28k stars), Doca Socket Relay (NVIDIA/skills, 3.6k stars), Socket Bridge (Cai-aa/CAE-Agent-Hub, 1k stars) and Socket Event Listener (r0adkll/Campfire, 141 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Af Xdp?

mohitmishra786 (a GitHub user) maintains it in mohitmishra786/low-level-dev-skills, which has 252 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on June 27, 2026.

Source: mohitmishra786/low-level-dev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.