Defined in 1 files as a function:
Referenced in 1 files:
-
kernel/bpf/verifier.c
- line 2192
- line 3099
- line 3700
- line 6117
- line 6168
- line 6201
- line 6224
- line 6230
- line 6271
- line 6282
- line 6291
- line 6295
- line 6323
- line 6326
- line 9435
- line 10462
- line 10679
- line 12995
- line 13170
- line 13182
- line 13461
- line 13463
- line 13464
- line 14816
- line 14994
- line 15021
- line 15056
- line 15067
- line 16370
- line 18484
- line 18510
Smatch caller information:
kernel/bpf/verifier.c __check_reg_arg() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state->frame | 4096-ptr_max |
| PARAM_VALUE | 0 | env->insn_aux_data->btf_var.reg_type | 0,16,529,4112 |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,5704186734949433344 |
| PARAM_VALUE | 1 | regs | 4096-ptr_max |
| PARAM_VALUE | 2 | regno | 0-9,11-u32max |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | $1 |
| DATA_SOURCE | 2 | regno | $2 |
| STR_LEN | 0 | env | (-1),2-3,11 |
| STR_LEN | 0 | env | (-1),2-3,11 |
| NOCHECK_CALL | |||
| NO_OVERFLOW_SIMPLE | 0 | env->cur_state->jmp_history_cnt |
kernel/bpf/verifier.c adjust_reg_min_max_vals() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->allow_ptr_leaks | 1 |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state->frame | 4096-ptr_max |
| PARAM_VALUE | 0 | env->prog->insnsi | 4096-ptr_max |
| PARAM_VALUE | 1 | regs | 4096-ptr_max |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| NOCHECK_CALL |
kernel/bpf/verifier.c check_alu_op() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->prog->insnsi | 4096-ptr_max |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | r cur_regs |
| NOCHECK_CALL |
kernel/bpf/verifier.c check_alu_op() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->prog->insnsi | 4096-ptr_max |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | r cur_regs |
| NOCHECK_CALL |
kernel/bpf/verifier.c check_alu_op() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->prog->insnsi | 4096-ptr_max |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | r cur_regs |
| NOCHECK_CALL |
kernel/bpf/verifier.c check_alu_op() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->prog->insnsi | 4096-ptr_max |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | r cur_regs |
| NOCHECK_CALL |
kernel/bpf/verifier.c check_func_call() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state->active_locks | 0 |
| PARAM_VALUE | 0 | env->cur_state->frame | 4096-ptr_max |
| PARAM_VALUE | 0 | env->prog | 4096-ptr_max |
| PARAM_VALUE | 0 | env->prog->aux | 4096-ptr_max |
| PARAM_VALUE | 0 | env->prog->aux->func_info | 4096-ptr_max |
| PARAM_VALUE | 0 | env->prog->insnsi | 4096-ptr_max |
| PARAM_VALUE | 0 | env->prog->len | 1-u32max |
| PARAM_VALUE | 0 | env->subprog_cnt | 1-u32max |
| PARAM_VALUE | 0 | env->subprog_info | 4096-ptr_max |
| PARAM_VALUE | 0 | *env->log->kbuf | 0-255 |
| PARAM_VALUE | 0 | *env->tmp_arg_name | 0-255 |
| PARAM_VALUE | 0 | *env->tmp_str_buf | 0-255 |
| PARAM_VALUE | 2 | regno | 0 |
| BUF_SIZE | 1 | regs | 880 |
| CAPPED_DATA | 0 | env->prog->aux->btf->start_id | 1 |
| DATA_SOURCE | 0 | env | $0 |
| NOCHECK_CALL | |||
| NO_OVERFLOW_SIMPLE | 0 | env->log.kbuf |
kernel/bpf/verifier.c check_helper_call() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,5704186734949433344 |
| PARAM_VALUE | 0 | env->ops->get_func_proto | 1-u64max |
| PARAM_VALUE | 0 | env->prog | 4096-ptr_max |
| PARAM_VALUE | 0 | *env->log.kbuf | 0-255 |
| PARAM_VALUE | 0 | *env->tmp_arg_name | 0-255 |
| PARAM_VALUE | 0 | *env->tmp_str_buf | 0-255 |
| PARAM_VALUE | 1 | regs | 4096-ptr_max |
| PARAM_VALUE | 2 | regno | 0 |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | r cur_regs |
| NOCHECK_CALL |
kernel/bpf/verifier.c check_helper_call() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state->curframe | 1-2147483646 |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,5704186734949433344 |
| PARAM_VALUE | 0 | env->ops->get_func_proto | 1-u64max |
| PARAM_VALUE | 0 | env->prog | 4096-ptr_max |
| PARAM_VALUE | 0 | *env->log.kbuf | 0-255 |
| PARAM_VALUE | 0 | *env->tmp_arg_name | 0-255 |
| PARAM_VALUE | 0 | *env->tmp_str_buf | 0-255 |
| PARAM_VALUE | 1 | regs | 4096-ptr_max |
| PARAM_VALUE | 2 | regno | 0 |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | r cur_regs |
| NOCHECK_CALL |
kernel/bpf/verifier.c check_kfunc_call() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state->curframe | 0-2147483646 |
| PARAM_VALUE | 0 | env->head | 4096-ptr_max |
| PARAM_VALUE | 0 | env->insn_aux_data | 4096-ptr_max |
| PARAM_VALUE | 0 | env->log->tmp_str_buf | 0-255 |
| PARAM_VALUE | 0 | env->prog | 4096-ptr_max |
| PARAM_VALUE | 0 | env->prog->aux | 4096-ptr_max |
| PARAM_VALUE | 0 | env->prog->aux->kfunc_tab | 4096-ptr_max |
| PARAM_VALUE | 0 | env->stack_size | s32min-8192 |
| PARAM_VALUE | 1 | regs | 4096-ptr_max |
| PARAM_VALUE | 2 | regno | 0 |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| CAPPED_DATA | 0 | env->cur_state->curframe | 1 |
| DATA_SOURCE | 0 | env | $0 |
| NOCHECK_CALL |
kernel/bpf/verifier.c check_kfunc_call() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->insn_aux_data | 4096-ptr_max |
| PARAM_VALUE | 0 | env->log->tmp_str_buf | 0-255 |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,4096-ptr_max |
| PARAM_VALUE | 0 | env->prog | 4096-ptr_max |
| PARAM_VALUE | 0 | env->prog->aux | 4096-ptr_max |
| PARAM_VALUE | 0 | env->prog->aux->kfunc_tab | 4096-ptr_max |
| PARAM_VALUE | 1 | regs | 4096-ptr_max |
| PARAM_VALUE | 2 | regno | 0 |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | r cur_regs |
| NOCHECK_CALL |
kernel/bpf/verifier.c check_kfunc_call() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->insn_aux_data | 4096-ptr_max |
| PARAM_VALUE | 0 | env->log->tmp_str_buf | 0-255 |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,4096-ptr_max |
| PARAM_VALUE | 0 | env->prog | 4096-ptr_max |
| PARAM_VALUE | 0 | env->prog->aux | 4096-ptr_max |
| PARAM_VALUE | 0 | env->prog->aux->kfunc_tab | 4096-ptr_max |
| PARAM_VALUE | 1 | regs | 4096-ptr_max |
| PARAM_VALUE | 2 | regno | 0 |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | r cur_regs |
| NOCHECK_CALL |
kernel/bpf/verifier.c check_ld_abs() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state->active_irq_id | 0 |
| PARAM_VALUE | 0 | env->cur_state->active_locks | 0 |
| PARAM_VALUE | 0 | env->cur_state->active_preempt_locks | 0 |
| PARAM_VALUE | 0 | env->cur_state->active_rcu_locks | 0 |
| PARAM_VALUE | 0 | env->ops | 4096-ptr_max |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 5704186734949433344 |
| PARAM_VALUE | 0 | env->prog | 4096-ptr_max |
| PARAM_VALUE | 1 | regs | 4096-ptr_max |
| PARAM_VALUE | 2 | regno | 0 |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | r cur_regs |
| NOCHECK_CALL |
kernel/bpf/verifier.c check_mem_access() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->insn_aux_data->btf_var.reg_type | 0,16,529,4112 |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,5704186734949433344 |
| PARAM_VALUE | 2 | regno | 0-s32max |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | r cur_regs |
| DATA_SOURCE | 2 | regno | $7 |
| STR_LEN | 0 | env | (-1),3,11 |
| STR_LEN | 0 | env | (-1),3,11 |
| NOCHECK_CALL | |||
| NO_OVERFLOW_SIMPLE | 0 | env->cur_state->jmp_history_cnt |
kernel/bpf/verifier.c check_mem_access() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->insn_aux_data->btf_var.reg_type | 0,16,529,4112 |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,5704186734949433344 |
| PARAM_VALUE | 2 | regno | 0-s32max |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | r cur_regs |
| DATA_SOURCE | 2 | regno | $7 |
| STR_LEN | 0 | env | (-1),3,11 |
| STR_LEN | 0 | env | (-1),3,11 |
| NOCHECK_CALL | |||
| NO_OVERFLOW_SIMPLE | 0 | env->cur_state->jmp_history_cnt |
kernel/bpf/verifier.c check_mem_access() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->insn_aux_data->btf_var.reg_type | 0,16,529,4112 |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,4096-ptr_max |
| PARAM_VALUE | 0 | *env->tmp_str_buf | 0-255 |
| PARAM_VALUE | 2 | regno | 0-s32max |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | r cur_regs |
| DATA_SOURCE | 2 | regno | $7 |
| STR_LEN | 0 | env | (-1),3,11 |
| STR_LEN | 0 | env | (-1),3,11 |
| NOCHECK_CALL | |||
| NO_OVERFLOW_SIMPLE | 0 | env->cur_state->jmp_history_cnt |
kernel/bpf/verifier.c check_mem_access() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->insn_aux_data->btf_var.reg_type | 0,16,529,4112 |
| PARAM_VALUE | 0 | env->ops | 4096-ptr_max |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,5704186734949433344 |
| PARAM_VALUE | 0 | env->ops->is_valid_access | 1-u64max |
| PARAM_VALUE | 0 | env->prog | 4096-ptr_max |
| PARAM_VALUE | 0 | env->prog->aux->attach_func_proto->type | 1-u32max |
| PARAM_VALUE | 0 | env->prog->aux->max_ctx_offset | 1-u32max |
| PARAM_VALUE | 0 | env->prog->expected_attach_type | 27 |
| PARAM_VALUE | 0 | env->prog->type | 29 |
| PARAM_VALUE | 2 | regno | 0-s32max |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | r cur_regs |
| DATA_SOURCE | 2 | regno | $7 |
| STR_LEN | 0 | env | (-1),3,11 |
| STR_LEN | 0 | env | (-1),3,11 |
| NOCHECK_CALL | |||
| NO_OVERFLOW_SIMPLE | 0 | env->cur_state->jmp_history_cnt |
kernel/bpf/verifier.c check_mem_access() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->insn_aux_data->btf_var.reg_type | 0,16,529,4112 |
| PARAM_VALUE | 0 | env->ops | 4096-ptr_max |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,5704186734949433344 |
| PARAM_VALUE | 0 | env->ops->is_valid_access | 1-u64max |
| PARAM_VALUE | 0 | env->prog | 4096-ptr_max |
| PARAM_VALUE | 0 | env->prog->aux->max_ctx_offset | 1-u32max |
| PARAM_VALUE | 2 | regno | 0-s32max |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | r cur_regs |
| DATA_SOURCE | 2 | regno | $7 |
| STR_LEN | 0 | env | (-1),3,11 |
| STR_LEN | 0 | env | (-1),3,11 |
| NOCHECK_CALL | |||
| NO_OVERFLOW_SIMPLE | 0 | env->cur_state->jmp_history_cnt |
kernel/bpf/verifier.c check_mem_access() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->insn_aux_data->btf_var.reg_type | 0,16,529,4112 |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,5704186734949433344 |
| PARAM_VALUE | 2 | regno | 0-s32max |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | r cur_regs |
| DATA_SOURCE | 2 | regno | $7 |
| STR_LEN | 0 | env | (-1),3,11 |
| STR_LEN | 0 | env | (-1),3,11 |
| NOCHECK_CALL | |||
| NO_OVERFLOW_SIMPLE | 0 | env->cur_state->jmp_history_cnt |
kernel/bpf/verifier.c check_mem_access() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->insn_aux_data->btf_var.reg_type | 0,16,529,4112 |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,5704186734949433344 |
| PARAM_VALUE | 2 | regno | 0-s32max |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | r cur_regs |
| DATA_SOURCE | 2 | regno | $7 |
| STR_LEN | 0 | env | (-1),3,11 |
| STR_LEN | 0 | env | (-1),3,11 |
| NOCHECK_CALL | |||
| NO_OVERFLOW_SIMPLE | 0 | env->cur_state->jmp_history_cnt |
kernel/bpf/verifier.c check_mem_access() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->insn_aux_data->btf_var.reg_type | 0,16,529,4112 |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,5704186734949433344 |
| PARAM_VALUE | 2 | regno | 0-s32max |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | r cur_regs |
| DATA_SOURCE | 2 | regno | $7 |
| STR_LEN | 0 | env | (-1),3,11 |
| STR_LEN | 0 | env | (-1),3,11 |
| NOCHECK_CALL | |||
| NO_OVERFLOW_SIMPLE | 0 | env->cur_state->jmp_history_cnt |
kernel/bpf/verifier.c check_mem_access() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->insn_aux_data->btf_var.reg_type | 0,16,529,4112 |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,5704186734949433344 |
| PARAM_VALUE | 2 | regno | 0-s32max |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | r cur_regs |
| DATA_SOURCE | 2 | regno | $7 |
| STR_LEN | 0 | env | (-1),3,11 |
| STR_LEN | 0 | env | (-1),3,11 |
| NOCHECK_CALL | |||
| NO_OVERFLOW_SIMPLE | 0 | env->cur_state->jmp_history_cnt |
kernel/bpf/verifier.c check_mem_access() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->insn_aux_data->btf_var.reg_type | 0,16,529,4112 |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,5704186734949433344 |
| PARAM_VALUE | 0 | env->prog | 4096-ptr_max |
| PARAM_VALUE | 2 | regno | 0-s32max |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | r cur_regs |
| DATA_SOURCE | 2 | regno | $7 |
| STR_LEN | 0 | env | (-1),3,11 |
| STR_LEN | 0 | env | (-1),3,11 |
| NOCHECK_CALL | |||
| NO_OVERFLOW_SIMPLE | 0 | env->cur_state->jmp_history_cnt |
kernel/bpf/verifier.c check_mem_access() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->insn_aux_data->btf_var.reg_type | 0,16,529,4112 |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,5704186734949433344 |
| PARAM_VALUE | 2 | regno | 0-s32max |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | r cur_regs |
| DATA_SOURCE | 2 | regno | $7 |
| STR_LEN | 0 | env | (-1),3,11 |
| STR_LEN | 0 | env | (-1),3,11 |
| NOCHECK_CALL | |||
| NO_OVERFLOW_SIMPLE | 0 | env->cur_state->jmp_history_cnt |
kernel/bpf/verifier.c do_check_common() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state->branches | 1 |
| PARAM_VALUE | 0 | env->cur_state->curframe | 0 |
| PARAM_VALUE | 0 | env->cur_state->speculative | 0 |
| PARAM_VALUE | 0 | env->prev_linfo | 0 |
| PARAM_VALUE | 0 | env->prog | 4096-ptr_max |
| PARAM_VALUE | 0 | env->prog->aux | 4096-ptr_max |
| PARAM_VALUE | 0 | env->scratched_regs | u32max |
| PARAM_VALUE | 0 | env->scratched_stack_slots | u64max |
| PARAM_VALUE | 0 | env->subprog_info | 4096-ptr_max |
| PARAM_VALUE | 1 | regs | 4096-ptr_max |
| PARAM_VALUE | 2 | regno | 1-5 |
| BUF_SIZE | 0 | env->cur_state | 232 |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| CAPPED_DATA | 2 | regno | 1 |
| DATA_SOURCE | 0 | env | $0 |
| NOCHECK_CALL |
kernel/bpf/verifier.c do_check_common() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state->branches | 1 |
| PARAM_VALUE | 0 | env->cur_state->curframe | 0 |
| PARAM_VALUE | 0 | env->cur_state->speculative | 0 |
| PARAM_VALUE | 0 | env->prev_linfo | 0 |
| PARAM_VALUE | 0 | env->prog | 4096-ptr_max |
| PARAM_VALUE | 0 | env->prog->aux | 4096-ptr_max |
| PARAM_VALUE | 0 | env->scratched_regs | u32max |
| PARAM_VALUE | 0 | env->scratched_stack_slots | u64max |
| PARAM_VALUE | 0 | env->subprog_info | 4096-ptr_max |
| PARAM_VALUE | 1 | regs | 4096-ptr_max |
| PARAM_VALUE | 2 | regno | 1-5 |
| BUF_SIZE | 0 | env->cur_state | 232 |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| CAPPED_DATA | 2 | regno | 1 |
| DATA_SOURCE | 0 | env | $0 |
| NOCHECK_CALL |
kernel/bpf/verifier.c mark_btf_ld_reg() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->allow_ptr_leaks | 1 |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->log->kbuf | 0-255 |
| PARAM_VALUE | 0 | env->ops->btf_struct_access | 0,109229580818747392,1844169638972944384,1972137615492878336,2503603943122952192,5286233595241070592 |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,4096-ptr_max |
| PARAM_VALUE | 2 | regno | 0-s32max |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 1 | regs | $1 |
| DATA_SOURCE | 2 | regno | $2 |
| STR_LEN | 0 | env | (-1),11 |
| STR_LEN | 0 | env | (-1),11 |
| NOCHECK_CALL | |||
| NO_OVERFLOW_SIMPLE | 0 | env->cur_state->jmp_history_cnt |
kernel/bpf/verifier.c mark_reg_stack_read() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state->frame | 4096-ptr_max |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,5704186734949433344 |
| PARAM_VALUE | 0 | env->prog->insnsi | 4096-ptr_max |
| PARAM_VALUE | 2 | regno | 0-s32max |
| BUF_SIZE | 1 | regs | 880 |
| DATA_SOURCE | 0 | env | $0 |
| DATA_SOURCE | 2 | regno | $4 |
| STR_LEN | 0 | env | (-1),11 |
| STR_LEN | 0 | env | (-1),11 |
| NOCHECK_CALL | |||
| NO_OVERFLOW_SIMPLE | 0 | env->cur_state->jmp_history_cnt |
kernel/bpf/verifier.c sanitize_speculative_path() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->bypass_spec_v1 | 0 |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state->curframe | 0-2147483646 |
| PARAM_VALUE | 0 | env->cur_state->frame | 4096-ptr_max |
| PARAM_VALUE | 0 | env->head | 4096-ptr_max |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,5704186734949433344 |
| PARAM_VALUE | 0 | env->stack_size | s32min-8192 |
| PARAM_VALUE | 0 | *env->log.kbuf | 0-255 |
| PARAM_VALUE | 0 | *env->tmp_str_buf | 0-255 |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| CAPPED_DATA | 0 | env->cur_state->curframe | 1 |
| DATA_SOURCE | 0 | env | $0 |
| NOCHECK_CALL |
kernel/bpf/verifier.c sanitize_speculative_path() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->bypass_spec_v1 | 0 |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state->curframe | 0-2147483646 |
| PARAM_VALUE | 0 | env->cur_state->frame | 4096-ptr_max |
| PARAM_VALUE | 0 | env->head | 4096-ptr_max |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,5704186734949433344 |
| PARAM_VALUE | 0 | env->stack_size | s32min-8192 |
| PARAM_VALUE | 0 | *env->log.kbuf | 0-255 |
| PARAM_VALUE | 0 | *env->tmp_str_buf | 0-255 |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| CAPPED_DATA | 0 | env->cur_state->curframe | 1 |
| DATA_SOURCE | 0 | env | $0 |
| NOCHECK_CALL |
kernel/bpf/verifier.c sanitize_speculative_path() -> mark_reg_unknown()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | env | 4096-ptr_max |
| PARAM_VALUE | 0 | env->bypass_spec_v1 | 0 |
| PARAM_VALUE | 0 | env->cur_state | 4096-ptr_max |
| PARAM_VALUE | 0 | env->cur_state->curframe | 0-2147483646 |
| PARAM_VALUE | 0 | env->cur_state->frame | 4096-ptr_max |
| PARAM_VALUE | 0 | env->head | 4096-ptr_max |
| PARAM_VALUE | 0 | env->ops->gen_ld_abs | 0,5704186734949433344 |
| PARAM_VALUE | 0 | env->stack_size | s32min-8192 |
| PARAM_VALUE | 0 | *env->log.kbuf | 0-255 |
| PARAM_VALUE | 0 | *env->tmp_str_buf | 0-255 |
| BUF_SIZE | 1 | regs | 880 |
| BUF_SIZE | 1 | regs | 880 |
| CAPPED_DATA | 0 | env->cur_state->curframe | 1 |
| DATA_SOURCE | 0 | env | $0 |
| NOCHECK_CALL |