eBPF/XDP: The Verifier Passing Does Not Mean Your Network Program Is Safe
The verifier proves classes of memory and control-flow safety. It does not prove that returning the wrong XDP action, updating the wrong map, or attaching at the wrong hook will preserve network connectivity.