<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="/source/rss.xsl.xml"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
    <title>Changes in verifier_btf_flex_array.c</title>
    <description></description>
    <language>en</language>
    <copyright>Copyright 2015</copyright>
    <generator>Java</generator><item>
        <title>5fc5768c7ca92895ccd1de94dc521e5a55ae7896 - Merge tag &apos;bpf-fixes&apos; of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf</title>
        <link>http://kernelsources.org:8080/source/history/linux/tools/testing/selftests/bpf/progs/verifier_btf_flex_array.c#5fc5768c7ca92895ccd1de94dc521e5a55ae7896</link>
        <description>Merge tag &apos;bpf-fixes&apos; of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpfPull bpf fixes from Alexei Starovoitov: - Fix bpf_skb_change_tail() to drop the checksum offload instead of   rejecting the trim of CHECKSUM_PARTIAL skbs (Daniel Borkmann) - Add KF_PERFMON kfunc flag and require CAP_PERFMON for kfuncs that   read arbitrary memory and for untrusted read-only memory reads   (Daniel Borkmann) - Clear scalar delta on narrowing stack spill (Daniel Borkmann) - Set up the frame pointer for the exception callback in arm64 JIT, and   zero-fill other CPUs when BPF_F_CPU update creates a per-cpu hash   element (Donggeun Yoo) - Various fixes (Emil Tsalapatis):     - Fix bounds check underflow for skb-backed dynptrs     - Fix rx_queue_mapping context access code generation in bpf_sock     - Reject packet pointer arguments to subprogs that may mutate the       packet     - Reject ALU instructions that see arena and non-arena operands on       different code paths - Fix copied_seq double-counting on sockmap self-redirect   (Geliang Tang) - Fix divide-by-zero in btf_struct_walk() on a flexible array of   zero-sized elements, fix out-of-bounds read of rtt_min in sock_ops   (Jiayuan Chen) - Fix bpf_sock_destroy() out-of-bounds read of sk_protocol on TIME_WAIT   and request socks, and sleeping under RCU when destroying a listener   with pending children (Jiayuan Chen) - Fix JEQ/JNE with immediate operand in MIPS32 JIT and missing zero   extension of BSWAP 16/32 in MIPS64 JIT (Johan Almbladh) - Avoid soft lockup in htab lookup[_and_delete] batch operations on   large maps (Jose Fernandez) - Various fixes (Kumar Kartikeya Dwivedi):     - Verify global subprogs in each sleepability context they are       called from     - Make post-verification instruction rewrites killable     - Preserve packet pointer displacement in regsafe()     - Apply CO-RE relocations before subprogram validation, restrict       CO-RE poisoning to relocatable instructions, and reject truncated       ldimm64 CO-RE relocations in libbpf     - Assign lock identity to callback map values     - Compare stack frames in regs_exact()     - Bound ownership depth through local kptrs and graph roots - Fix u32 overflow in map batch operations when the map size exceeds   4GB (Masoud Aghasi) - Fix UAF in bpf memalloc due to concurrent consumption of ttrace lists   in alloc_bulk() (Pu Lehui) - Allow gotox as the terminal instruction of a program or a subprogram   (Siddharth Chintamaneni) - Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL, skip unsettled links   in link iterator, and reject dev-bound-only programs on other devices   (Weiming Shi) - Reject non-negative stack offsets in stack_slot_obj_get_spi()   (Xu Yunxiang) - Check params size before reading reserved fields in   bpf_crypto_ctx_create() (Yuqi Xu) - Reject max_entries &gt; INT_MAX in sock_map_alloc() (Zhao Gongyi) - Use a 32-bit compare in xsk_map_gen_lookup() (Zhiling Zou) - Use kvfree() in xdp_test_run_teardown() (Zhixing Chen)* tag &apos;bpf-fixes&apos; of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf: (58 commits)  selftests/bpf: Test per-cpu initialization of a BPF_F_CPU created element  bpf: Zero-fill other CPUs when BPF_F_CPU creates a per-cpu hash element  bpf: Fix BSWAP 32 and 16 on MIPS64  bpf: Fix immediate JMP JEQ/JNE on MIPS32  bpf: Reject dev-bound-only programs on other devices  bpf, sockmap: Reject max_entries &gt; INT_MAX in sock_map_alloc  selftests/bpf: Test for mixed arena/nonarena code paths  bpf: Prevent variable arena/non-arena register contents  selftests/bpf: Test rejection of pkt args to mutating subprogs  bpf: Reject pkt arguments in mutating subprogs  selftests/bpf: Add selftests for rx_queue_mapping context access  bpf: Fix bpf_sock context code generation  selftests/bpf: Test dynptr slices past end of skb  bpf: Fix bounds check for skb-backed dynptrs  selftests/bpf: Reject iterator destruction through fp+0  bpf: Reject non-negative offsets in stack_slot_obj_get_spi()  bpf: Check params size before reading reserved fields  selftests/bpf: Check local object ownership depth  bpf: Bound ownership depth through local kptrs and graph roots  selftests/bpf: Cover frame changes in bounded loops  ...

            List of files:
            /linux/tools/testing/selftests/bpf/progs/verifier_btf_flex_array.c</description>
        <pubDate>Thu, 24 Sep 2026 17:25:26 +0200</pubDate>
        <dc:creator>Linus Torvalds &lt;torvalds@linux-foundation.org&gt;</dc:creator>
    </item>
<item>
        <title>f77d21245710690f3fb02d19d8dd4dc17ee58c2c - selftests/bpf: Test BTF walk into a flexible array of zero-sized elements</title>
        <link>http://kernelsources.org:8080/source/history/linux/tools/testing/selftests/bpf/progs/verifier_btf_flex_array.c#f77d21245710690f3fb02d19d8dd4dc17ee58c2c</link>
        <description>selftests/bpf: Test BTF walk into a flexible array of zero-sized elementsThe program stashes a bpf_obj_new() object whose type ends with a flexiblearray of empty structs, then reads it back as an untrusted kptr. Withoutthe previous patch this divides by zero in btf_struct_walk() instead ofbeing rejected.  # ./test_progs -t verifier_btf_flex_array  ...  #602     verifier_btf_flex_array:OK  Summary: 1/1 PASSED, 0 SKIPPED, 0/0 FAILEDSigned-off-by: Jiayuan Chen &lt;jiayuan.chen@linux.dev&gt;Link: https://lore.kernel.org/r/20260910122316.186384-2-jiayuan.chen@linux.devSigned-off-by: Alexei Starovoitov &lt;ast@kernel.org&gt;

            List of files:
            /linux/tools/testing/selftests/bpf/progs/verifier_btf_flex_array.c</description>
        <pubDate>Thu, 10 Sep 2026 14:22:56 +0200</pubDate>
        <dc:creator>Jiayuan Chen &lt;jiayuan.chen@linux.dev&gt;</dc:creator>
    </item>
</channel>
</rss>
