Defined in 1 files as a function:

Referenced in 1 files:

Smatch caller information:

net/bluetooth/l2cap_core.c __valid_reqseq() -> __seq_offset()

Type Parameter Key Value
PARAM_VALUE 0 chan 4096-ptr_max
DATA_SOURCE 0 chan $0
RX_PATH
LOCK2 &conn->lock
LOCK2 &pool->lock
LOCK2 0 &chan->lock
TYPE_LOCK (struct l2cap_chan)->lock
TYPE_LOCK (struct l2cap_conn)->lock

net/bluetooth/l2cap_core.c __valid_reqseq() -> __seq_offset()

Type Parameter Key Value
PARAM_VALUE 0 chan 4096-ptr_max
CAPPED_DATA 0 chan->expected_ack_seq 1
DATA_SOURCE 0 chan $0
DATA_SOURCE 2 seq2 $1
RX_PATH
LOCK2 &conn->lock
LOCK2 &pool->lock
LOCK2 0 &chan->lock
TYPE_LOCK (struct l2cap_chan)->lock
TYPE_LOCK (struct l2cap_conn)->lock

net/bluetooth/l2cap_core.c l2cap_ack_timeout() -> __seq_offset()

Type Parameter Key Value
PARAM_VALUE 0 chan 4096-ptr_max
LOCK2 0 &chan->lock
HALF_LOCKED2 &pool->lock
TYPE_LOCK (struct l2cap_chan)->lock

net/bluetooth/l2cap_core.c l2cap_classify_txseq() -> __seq_offset()

Type Parameter Key Value
PARAM_VALUE 0 chan 4096-ptr_max
CAPPED_DATA 0 chan 1
DATA_SOURCE 0 chan $0
DATA_SOURCE 1 seq1 $1
RX_PATH
LOCK2 &conn->lock
LOCK2 0 &chan->lock
HALF_LOCKED2 &pool->lock
TYPE_LOCK (struct l2cap_chan)->lock
TYPE_LOCK (struct l2cap_conn)->lock

net/bluetooth/l2cap_core.c l2cap_classify_txseq() -> __seq_offset()

Type Parameter Key Value
PARAM_VALUE 0 chan 4096-ptr_max
CAPPED_DATA 0 chan 1
CAPPED_DATA 0 chan->expected_tx_seq 1
CAPPED_DATA 1 seq1 1
DATA_SOURCE 0 chan $0
DATA_SOURCE 1 seq1 $1
PARAM_COMPARE 0 chan->expected_tx_seq == $1
PARAM_COMPARE 1 seq1 == $0->expected_tx_seq
RX_PATH
USER_PTR 0 chan->tx_send_head->data
LOCK2 &conn->lock
LOCK2 0 &chan->lock
HALF_LOCKED2 &pool->lock
TYPE_LOCK (struct l2cap_chan)->lock
TYPE_LOCK (struct l2cap_conn)->lock

net/bluetooth/l2cap_core.c l2cap_classify_txseq() -> __seq_offset()

Type Parameter Key Value
PARAM_VALUE 0 chan 4096-ptr_max
CAPPED_DATA 0 chan 1
DATA_SOURCE 0 chan $0
DATA_SOURCE 1 seq1 $1
PARAM_COMPARE 0 chan->expected_tx_seq != $1
PARAM_COMPARE 1 seq1 != $0->expected_tx_seq
RX_PATH
USER_PTR 0 chan->tx_send_head->data
LOCK2 &conn->lock
LOCK2 0 &chan->lock
HALF_LOCKED2 &pool->lock
TYPE_LOCK (struct l2cap_chan)->lock
TYPE_LOCK (struct l2cap_conn)->lock

net/bluetooth/l2cap_core.c l2cap_classify_txseq() -> __seq_offset()

Type Parameter Key Value
PARAM_VALUE 0 chan 4096-ptr_max
CAPPED_DATA 0 chan 1
DATA_SOURCE 0 chan $0
RX_PATH
USER_PTR 0 chan->tx_send_head->data
LOCK2 &conn->lock
LOCK2 0 &chan->lock
HALF_LOCKED2 &pool->lock
TYPE_LOCK (struct l2cap_chan)->lock
TYPE_LOCK (struct l2cap_conn)->lock

net/bluetooth/l2cap_core.c l2cap_classify_txseq() -> __seq_offset()

Type Parameter Key Value
PARAM_VALUE 0 chan 4096-ptr_max
CAPPED_DATA 0 chan 1
DATA_SOURCE 0 chan $0
DATA_SOURCE 1 seq1 $1
PARAM_COMPARE 0 chan->expected_tx_seq != $1
PARAM_COMPARE 1 seq1 != $0->expected_tx_seq
RX_PATH
USER_PTR 0 chan->tx_send_head->data
LOCK2 &conn->lock
LOCK2 0 &chan->lock
HALF_LOCKED2 &pool->lock
TYPE_LOCK (struct l2cap_chan)->lock
TYPE_LOCK (struct l2cap_conn)->lock

net/bluetooth/l2cap_core.c l2cap_send_ack() -> __seq_offset()

Type Parameter Key Value
PARAM_VALUE 0 chan 4096-ptr_max
BUF_SIZE 0 chan->data (-1)-s32max
CAPPED_DATA 0 chan 1
DATA_SOURCE 0 chan $0
RX_PATH
TASK_NOT_RUNNING
NO_OVERFLOW_SIMPLE 0 chan->conn->hchan->data_q.prev->len
NO_OVERFLOW_SIMPLE 0 chan->conn->hchan->data_q.prev->next->len
NO_OVERFLOW_SIMPLE 0 chan->sdu->data_len
NO_OVERFLOW_SIMPLE 0 chan->sdu->end
NO_OVERFLOW_SIMPLE 0 chan->sdu->len
NO_OVERFLOW_SIMPLE 0 chan->sdu_last_frag->end
NO_OVERFLOW_SIMPLE 0 chan->sdu_last_frag->len
NO_OVERFLOW_SIMPLE 0 chan->sdu_last_frag->next->end
NO_OVERFLOW_SIMPLE 0 chan->sdu_last_frag->next->len
NO_OVERFLOW_SIMPLE 0 chan->sdu_last_frag->next->tail
NO_OVERFLOW_SIMPLE 0 chan->sdu_last_frag->tail
USER_PTR 0 chan->tx_send_head->data
HALF_LOCKED2 &conn->lock
HALF_LOCKED2 0 &chan->lock