sDDF net

SkillSecurity

Network I/O in agentOS is sDDF-shaped: driver owns the NIC (or QEMU virtio-net as a stand-in), netvirt muxes, clients hold queue caps.

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the sDDF net skill

About this skill

An operating system designed from the core up for agents and agentic security requirements. Built on seL4 microkernel with capability-based security and agent-native vibe-coding.

What this skill tells your AI

The instructions your AI receives, as published by jordanhubbard/agentos in skills/sddf-net/SKILL.md and read by ahel’s review.

Network I/O in agentOS is sDDF-shaped: driver owns the NIC (or QEMU virtio-net as a stand-in), net_virt muxes, clients hold queue caps.

Invariants

  • NIC MMIO/IRQ belong to the driver PD only.
  • Clients (VMM virtio backends, native stacks) use free/active queue pairs.
  • Buffers are offsets into a data region, not raw pointers across PDs.
  • Guests do not DMA to the host NIC. The VMM emulates virtio-net.

Forbidden

  • MSG_NET_SEND of a full frame through IPC registers as the data path.
  • Mapping QEMU virtio-net MMIO into a guest.
  • Per-guest NICs that split QEMU buses instead of sharing net_virt.

Helper

Run make test-guest-net for target evidence or make test-host for the queue-layout and pump pre-filter.

Signals

GitHub stars
43
Forks
7
Last commit
Sep 2026
Advanced
Item type
skill
Key
sddf-net
Source
github.com/jordanhubbard/agentos