# Snabb: a LuaJIT packet toolkit that ships as one binary

> Snabb is a userspace packet networking toolkit written in Lua on top of LuaJIT, built around kernel bypass and distributed as a single stand-alone executable. It is aimed at engineers who need to move packets at 10G and 100G rates without writing C drivers from scratch.

**snabbco/snabb** — Snabb: Simple and fast packet networking

- Repository: https://github.com/snabbco/snabb
- Stars: 3,033 · Forks: 298
- Language: Lua
- License: Apache-2.0
- Published: 2026-09-24 · Updated: 2026-09-24 · Language: en
- Canonical page: https://hysenlabs.com/projects/snabbco-snabb

## The problem Snabb solves for packet-heavy Linux hosts

A standard Linux host moves packets through the kernel. That path is general and safe, but every packet crosses a boundary the application does not control, and the cost shows up as per-packet overhead you cannot tune from userspace. Snabb takes the opposite position: the README states that Ethernet I/O runs with no kernel overhead, described there as kernel bypass mode. The application talks to the NIC directly.

The audience follows from that choice. Snabb NFV is documented as targeting people who want to process up to 100 Gbps or 50 Mpps of Virtio-net traffic per server, and the README says it was originally developed to support Deutsche Telekom's TeraStream network. Snabb lwAFTR is aimed at ISPs running an IPv6-only internal network that still need to give subscribers IPv4 access through lightweight 4-over-6. These are not general-purpose server workloads. They are packet paths where the kernel is the bottleneck.

The README also frames the project as a community of programmers and network engineers, and the toolkit framing is literal: Snabb is a set of building blocks for constructing network elements, not a finished appliance. If you want a product with a support contract, this is the wrong starting point.

## Lua, LuaJIT and a single snabb binary

Snabb is written in Lua and compiled by LuaJIT, which the README describes as a just-in-time compiler competitive with C. The build does not produce a Lua script you run with an interpreter. It produces a stand-alone executable called snabb, and the README says this single binary includes multiple applications and runs on any modern Linux/x86-64 distribution. The README's own analogy is busybox for networking.

That packaging decision has visible consequences. The Makefile copies ljsyscall sources into src/syscall and ljndpi sources into src/ndpi before descending into src, so the syscall layer and the nDPI bindings are vendored into the build tree rather than resolved from the system. The binary that comes out is self-contained, which is why the README can say it can be copied between machines. The trade-off is that the build is not a thin wrapper around system libraries; it rebuilds LuaJIT from lib/luajit and stages its own Lua dependencies. The Dockerfile reflects the same shape, using a two-stage build on alpine:3.7 where the final image carries only libgcc and the compiled snabb at /usr/local/bin/snabb.

The applications listed in the README are snabbnfv for QEMU/KVM Virtio-net performance, lwAFTR for lw4o6, VPWS for Layer-2 VPN, packetblaster for generating load by replaying a pcap trace or synthesizing packets on Intel 82599 10-Gigabit interfaces, and snsh, a Lua shell giving direct access to all APIs from script files or interactively.

## Building Snabb and replaying a pcap with packetblaster

The README states that setting up a development environment takes around one minute and gives this sequence. The build compiles LuaJIT and the C sources, then links the stand-alone binary.

```bash
$ git clone https://github.com/SnabbCo/snabb
$ cd snabb
$ make -j
$ sudo src/snabb --help
```

The result you should see is a src/snabb executable that responds to --help with the list of included programs. The README notes the binary is stand-alone and can be copied between machines.

To install it system-wide and use it as a load generator, the README gives these two commands. The second one replays a capture file onto a specific PCI device address, here 01:00.0.

```bash
$ cp src/snabb /usr/local/bin/
$ sudo snabb packetblaster replay capture.pcap 01:00.0
```

packetblaster is described as efficient enough that only a small percentage of one core per CPU is required even for hundreds of Gbps of traffic, which is why the README suggests it can run on a small server or directly on the device under test. The PCI address is the interface you are transmitting on, and the README's example uses an Intel 82599 10-Gigabit interface.

There is also a container path. The README documents make docker, which builds what it calls a tiny snabb container of 8MB.

```bash
$ make docker
$ docker run -ti --rm snabb --help
```

The Dockerfile shows the runtime image is alpine:3.7 with libgcc, the binary at /usr/local/bin/snabb, a volume at /u and an entrypoint of /usr/local/bin/snabb. The Makefile's docker target also symlinks src/scripts/dock.sh to src/snabb, so the README's claim that you can simply call src/snabb under Linux is a wrapper around docker run.

## Where Snabb is the wrong tool

Kernel bypass means the kernel is not there to help. The README states plainly that Ethernet I/O runs with no kernel overhead, and every consequence of that is on you. There is no mention in the README of a fallback path, of running Snabb against a kernel network interface, or of a supported way to share a NIC between Snabb and the rest of the system. If you need the host's normal networking stack and Snabb on the same port, the README does not describe how.

Platform coverage is narrow by design. The README says the binary runs on any modern Linux/x86-64 distribution and links to src/doc/porting.md for porting. There is no macOS or Windows build described, and the Dockerfile is Alpine-based, which is a Linux container. If your deployment target is not Linux on x86-64, this is not the toolkit for you.

Driver coverage is the sharper constraint. The README's packetblaster section names Intel 82599 10-Gigabit interfaces specifically, and the Intel driver source is at src/apps/intel/intel10g.lua. Nothing in the README claims broad NIC support. Before designing around Snabb, check that your hardware appears in the driver tree; a NIC without a Snabb driver is a hard stop.

Finally, VPWS is a special case. The README says it is being developed by Alexander Gall at SWITCH and that his Github vpn branch is the master line of development. That means the VPWS code you want may not be on the default branch of this repository at all.

## Snabb compared with DPDK-based packet frameworks

The obvious alternative category is DPDK-based frameworks, where the packet path is written in C or C++ against a C library and the application is compiled ahead of time. The difference in approach is not just language. A DPDK application is a compiled C program with its own build system, linking a library that manages hugepages, memory pools and device queues. Snabb compiles LuaJIT and ships a single binary that contains its applications, and the README's framing of Snabb as a busybox for networking is a direct statement of that contrast: many small programs in one executable rather than one program per binary.

That changes the development loop. The README points to snsh as a tool for interactively experimenting with Snabb, giving direct access to all APIs through a Lua shell, usable from script files or interactively. A compiled DPDK application does not offer that. The cost is that you are working in Lua and depending on LuaJIT's code generation to reach the performance the README claims. Whether that trade is acceptable depends on whether your team would rather debug a Lua data plane or a C one.

A second alternative is simply staying in the kernel, with AF_PACKET or a kernel-bypass-free fast path. That keeps the host's networking stack intact and removes the driver-coverage problem, at the cost of the per-packet overhead Snabb was built to avoid. The README does not present Snabb as a general replacement for kernel networking, and the applications it describes (100 Gbps Virtio-net, lwAFTR, packetblaster) are all cases where that overhead matters.

## Maintenance, releases and the Apache-2.0 licence

The repository is not archived and the last push was on 2026-07-30, which is recent. That said, the release tags tell a different story about cadence. The most recent release listed is v2024.08, tagged Snabb 2024.08 "Garmin" on 2024-08-30, preceded by v2024.06 "Faye" on 2024-06-25 and v2023.10 "Enigma" on 2023-11-16. Between the 2024.08 release and the last push there is a long stretch of commits without a tagged release visible here, so anyone pinning to a release should check what master contains beyond the last tag.

The build has a real upgrade cost. Because the Makefile rebuilds LuaJIT from lib/luajit and copies ljsyscall and ljndpi sources into src at build time, a Snabb upgrade can change the compiler and the syscall bindings under you, not just the application code. The clean target removes src/syscall.lua and src/syscall, so the staged copies are regenerated rather than tracked. If you vendor Snabb into a build pipeline, budget for rebuilding the whole tree rather than swapping a binary.

Snabb is licensed Apache-2.0, and the repository carries a COPYING file at the top level alongside LICENSE-style metadata. Apache-2.0 is a permissive licence with an explicit patent grant and requires that notices be preserved. It does not impose copyleft on your own code. Note that the build pulls in LuaJIT, ljsyscall and ljndpi from submodules listed in .gitmodules, and those carry their own licences; anyone redistributing a built snabb binary should review those separately. This is a description of the licence, not legal advice.

## Conclusion

Snabb fits operators and network engineers who need a programmable packet path at 10G or 100G on Linux x86-64 and are comfortable reading Lua. It is a poor fit if you need portability beyond Linux, a Windows or macOS build, or a vendor-supported product with a formal release cadence. Before committing, verify that your NIC is covered by the drivers under src/apps/intel, confirm the build succeeds on your distribution with make -j, and check whether the application you want (snabbnfv, lwAFTR, VPWS, packetblaster, snsh) is one of the first-generation programs the README actually describes. The VPWS application is the notable exception: the README points to a separate branch, not master.

## FAQ

### What is Snabb?

Snabb is a packet networking toolkit written in Lua and compiled with LuaJIT, described in its README as simple and fast. It builds into a single stand-alone executable called snabb that includes multiple applications and runs on Linux/x86-64.

### How do I install Snabb?

The README gives a four-command sequence: clone the repository, change into it, run make -j, then run sudo src/snabb --help. The resulting binary is stand-alone and the README says it can be copied between machines.

### Can I run Snabb in Docker?

Yes. The README documents make docker, which builds what it calls a tiny snabb container of 8MB, after which you can run docker run -ti --rm snabb --help. The Dockerfile uses a two-stage alpine:3.7 build and places the binary at /usr/local/bin/snabb.

### What programs does Snabb include?

The README lists snabbnfv for QEMU/KVM Virtio-net performance, lwAFTR for lightweight 4-over-6, VPWS for Layer-2 VPN, packetblaster for generating load from pcap traces or synthesized packets, and snsh, a Lua shell for interacting with the APIs.

### Which network interfaces does Snabb support?

The README names Intel 82599 10-Gigabit interfaces in its packetblaster example and links to the Intel driver source at src/apps/intel/intel10g.lua. It does not claim broad NIC support, so hardware should be checked against the driver tree before designing around Snabb.

## Sources

- [Issues](https://github.com/snabbco/snabb/issues)
- [License: Apache-2.0](https://github.com/snabbco/snabb/blob/master/LICENSE)
- [README](https://github.com/snabbco/snabb/blob/master/README.md)
- [Releases](https://github.com/snabbco/snabb/releases)
- [snabbco/snabb on GitHub](https://github.com/snabbco/snabb)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/snabbco-snabb
