Commit c3fd8e5fd100 for kernel

commit c3fd8e5fd100f122bad503bdc0e9277219533253
Author: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Date:   Sat Sep 5 03:47:33 2026 +0200

    bpf: Reject non-scalar bpf_loop iteration counts

    bpf_loop() declares its nr_loops argument as ARG_ANYTHING. Privileged
    programs may pass pointer values to such arguments, so check_func_arg()
    lets a pointer-valued R1 reach the helper-specific checks.

    Since commit bb124da69c47 ("bpf: keep track of max number of bpf_loop
    callback iterations"), the verifier marks R1 precise and reads its upper
    bound to limit callback simulation. Precision backtracking only accepts
    scalar registers, so passing a pointer instead triggers the "backtracking
    misuse" verifier warning. Kernels with panic_on_warn enabled subsequently
    panic.

    Introduce ARG_SCALAR for helper arguments that only accept scalar values
    and use it for bpf_loop() nr_loops. Generic helper argument validation then
    rejects pointers before loop inlining and precision processing.

    Fixes: bb124da69c47 ("bpf: keep track of max number of bpf_loop callback iterations")
    Reported-by: syzbot+7b47f87674e9a1569110@syzkaller.appspotmail.com
    Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
    Link: https://patch.msgid.link/20260905014735.1452988-2-memxor@gmail.com
    Closes: https://lore.kernel.org/bpf/6a9ad24c.b5d4176b.238c3e.0001.GAE@google.com/
    Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>

diff --git a/include/linux/bpf.h b/include/linux/bpf.h
index b7dbf3d9b5c0..e57af902560c 100644
--- a/include/linux/bpf.h
+++ b/include/linux/bpf.h
@@ -894,6 +894,7 @@ enum bpf_arg_type {

 	ARG_PTR_TO_CTX,		/* pointer to context */
 	ARG_ANYTHING,		/* any (initialized) argument is ok */
+	ARG_SCALAR,		/* scalar argument */
 	ARG_PTR_TO_SPIN_LOCK,	/* pointer to bpf_spin_lock */
 	ARG_PTR_TO_SOCK_COMMON,	/* pointer to sock_common */
 	ARG_PTR_TO_SOCKET,	/* pointer to bpf_sock (fullsock) */
diff --git a/kernel/bpf/bpf_iter.c b/kernel/bpf/bpf_iter.c
index 14a5fdfa0421..b40eb404adab 100644
--- a/kernel/bpf/bpf_iter.c
+++ b/kernel/bpf/bpf_iter.c
@@ -754,7 +754,7 @@ const struct bpf_func_proto bpf_loop_proto = {
 	.func		= bpf_loop,
 	.gpl_only	= false,
 	.ret_type	= RET_INTEGER,
-	.arg1_type	= ARG_ANYTHING,
+	.arg1_type	= ARG_SCALAR,
 	.arg2_type	= ARG_PTR_TO_FUNC,
 	.arg3_type	= ARG_PTR_TO_STACK_OR_NULL,
 	.arg4_type	= ARG_ANYTHING,
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index 1c3039f3fc32..4638a2f85d0f 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -8211,6 +8211,7 @@ static const struct bpf_reg_types *compatible_reg_types[__BPF_ARG_TYPE_MAX] = {
 	[ARG_MEM_SIZE]			= &scalar_types,
 	[ARG_MEM_SIZE_OR_ZERO]		= &scalar_types,
 	[ARG_CONST_ALLOC_SIZE_OR_ZERO]	= &scalar_types,
+	[ARG_SCALAR]			= &scalar_types,
 	[ARG_CONST_MAP_PTR]		= &const_map_ptr_types,
 	[ARG_PTR_TO_CTX]		= &context_types,
 	[ARG_PTR_TO_SOCK_COMMON]	= &sock_types,