bpf: mark a NULL kfunc argument precise

check_kfunc_arg() allows bpf_register_is_null() for nullable arguments
w/o marking the underlying scalar register precise. Hence a checkpoint
created on such a path would prune against arbitrary scalar value.

Fixes: 3bda08b636 ("bpf: Allow NULL buffers in bpf_dynptr_slice(_rw)")
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
Link: https://lore.kernel.org/r/20260904-register-is-null-precise-fixes-v1-5-0f5a360ff15d@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
This commit is contained in:
Eduard Zingerman
2026-09-04 17:05:56 -07:00
committed by Alexei Starovoitov
parent 100f4cc0d5
commit 506ada8962

View File

@@ -12733,8 +12733,12 @@ static int check_kfunc_args(struct bpf_verifier_env *env, struct bpf_call_arg_me
if (reg_is_referenced(env, reg))
update_ref_obj(&meta->ref_obj, reg);
if (bpf_register_is_null(reg) && type_may_be_null(kf_arg_type))
if (bpf_register_is_null(reg) && type_may_be_null(kf_arg_type)) {
ret = mark_arg_precision(env, argno);
if (ret)
return ret;
continue;
}
if (is_kfunc_arg_map(btf, &args[i])) {
ref_id = *reg2btf_ids[CONST_PTR_TO_MAP];