← Back to Labs
Linux eBPF & XDP Packet Processing Pipeline
Step through the high-performance XDP driver datapath. Observe pre-allocation packet drops, in-kernel verifier bounds validation, and BPF map hash lookups.
XDP Hook Mode
Native (Driver Hook)
Frames Ingested
0
Line-Rate Drops
0
Passed to Host Stack
0
sk_buff Allocs Saved
0
Hardware to Kernel Pipeline Stages
1. Physical Ingress
NIC RX Ring
DMA directly into host memory page pool.
2. XDP Execution
eBPF Bytecode
Bounds verified (Safe)
3. BPF Map Table
Blacklist Map
2 blocked IP subnets loaded.
4. Action Outcome
Driver Verdict
XDP_DROP (recycle) or XDP_PASS (alloc skb).
Recent Inspected Packets (Raw Driver Ring Buffer)
No packets currently traversing the queue. Inject test frames below.
KERNEL LOGIn-Kernel Verifier: PASS
eBPF XDP filter loaded into driver ring. Ready for packet inspection.
Notice: In Native mode, XDP_DROP recycles the RX buffer directly with 0 memory allocation. Disabling the bounds guard demonstrates why the kernel verifier rejects unverified pointers.