Commit e726fc6b9afe for kernel

commit e726fc6b9afe6b3a446a31d0f0767b7b9cb5085e
Author: Eduard Zingerman <eddyz87@gmail.com>
Date:   Fri Sep 4 17:05:58 2026 -0700

    bpf: mark a NULL BTF_ID argument of a global subprogram precise

    btf_check_func_arg_match() accepts a NULL register for an
    ARG_PTR_TO_BTF_ID argument tagged __arg_nullable and skips
    check_reg_type() and check_func_arg_reg_off() without marking the
    register precise. Hence a checkpoint created on such a path would
    prune against arbitrary scalar value.

    Fixes: e2b3c4ff5d18 ("bpf: add __arg_trusted global func arg tag")
    Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
    Link: https://lore.kernel.org/r/20260904-register-is-null-precise-fixes-v1-7-0f5a360ff15d@gmail.com
    Signed-off-by: Alexei Starovoitov <ast@kernel.org>

diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index 2117c39ac332..1b9fcbe4621a 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -9774,8 +9774,12 @@ static int btf_check_func_arg_match(struct bpf_verifier_env *env, int subprog,
 			struct bpf_call_arg_meta meta;
 			int err;

-			if (bpf_register_is_null(reg) && type_may_be_null(arg->arg_type))
+			if (bpf_register_is_null(reg) && type_may_be_null(arg->arg_type)) {
+				err = mark_arg_precision(env, argno);
+				if (err)
+					return err;
 				continue;
+			}

 			memset(&meta, 0, sizeof(meta)); /* leave func_id as zero */
 			err = check_reg_type(env, reg, argno, arg->arg_type, &arg->btf_id, &meta,