Defined in 1 files as a function:
Referenced in 26 files:
- arch/s390/kvm/guestdbg.c, line 216
- drivers/accel/qaic/qaic_data.c
- drivers/comedi/comedi_fops.c
- drivers/fpga/dfl.c, line 2001
- drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c
- drivers/gpu/drm/amd/amdgpu/amdgpu_userq_fence.c
- drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
- drivers/gpu/drm/drm_lease.c, line 512
- drivers/gpu/drm/vmwgfx/vmwgfx_surface.c, line 763
- drivers/i2c/i2c-dev.c, line 462
- drivers/infiniband/hw/hfi1/user_exp_rcv.c, line 483
- drivers/infiniband/hw/hfi1/user_sdma.c, line 495
- drivers/input/misc/cs40l50-vibra.c, line 335
- drivers/media/dvb-core/dvb_frontend.c
- drivers/net/ppp/ppp_generic.c, line 589
- drivers/s390/crypto/pkey_api.c, line 89
- drivers/tty/vt/keyboard.c
- drivers/vfio/pci/vfio_pci_dmabuf.c, line 254
- drivers/video/fbdev/via/viafbdev.c, line 577
- drivers/xen/privcmd.c, line 1271
- fs/nilfs2/ioctl.c, line 871
- kernel/kexec.c, line 257
- kernel/watch_queue.c, line 342
- sound/core/pcm_native.c, line 3359
- sound/isa/wavefront/wavefront_fx.c, line 194
- sound/usb/fcp.c, line 654
Smatch caller information:
drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c amdgpu_cs_pass1() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 2 | size | 8 |
| USER_DATA | 1 | n | 0-u32max[u] |
| UNITS | 2 | size | unit_byte |
drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c amdgpu_cs_wait_fences_ioctl() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 1-u32max |
| PARAM_VALUE | 2 | size | 24 |
| USER_DATA | 1 | n | 1-u32max[u] |
| UNITS | 2 | size | unit_byte |
drivers/tty/vt/keyboard.c vt_do_kdskbdiacr() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 1-255 |
| PARAM_VALUE | 2 | size | 3 |
| BUF_SIZE | 0 | src | 768 |
| USER_DATA | 1 | n | 1-255 |
| UNITS | 2 | size | unit_byte |
drivers/tty/vt/keyboard.c vt_do_kdskbdiacruc() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 1-255 |
| PARAM_VALUE | 2 | size | 12 |
| BUF_SIZE | 0 | src | 3072 |
| USER_DATA | 1 | n | 1-255 |
| UNITS | 2 | size | unit_byte |
drivers/infiniband/hw/hfi1/user_sdma.c hfi1_user_sdma_process_request() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 1-1024 |
| PARAM_VALUE | 2 | size | 4 |
| FUZZY_MAX | 1 | n | 1024 |
| HARD_MAX | 1 | n | 1024 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| UNITS | 0 | src | unit_byte |
| UNITS | 2 | size | unit_byte |
| LOCK2 | &fd->pq_srcu | ||
| HALF_LOCKED2 | &pool->lock | ||
| TYPE_LOCK | (struct hfi1_filedata)->pq_srcu |
drivers/net/ppp/ppp_generic.c get_filter() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 1-u16max |
| PARAM_VALUE | 2 | size | 8 |
| USER_DATA | 1 | n | 1-u16max |
| UNITS | 2 | size | unit_byte |
| LOCK2 | global &ppp_mutex |
kernel/watch_queue.c watch_queue_set_filter() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 1-16 |
| PARAM_VALUE | 2 | size | 44 |
| FUZZY_MAX | 1 | n | 16 |
| HARD_MAX | 1 | n | 16 |
| USER_DATA | 1 | n | 1-16 |
| UNITS | 2 | size | unit_byte |
drivers/fpga/dfl.c dfl_feature_ioctl_set_irq() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 1-u32max |
| PARAM_VALUE | 2 | size | 4 |
| USER_DATA | 1 | n | 1-u32max |
| NO_OVERFLOW_SIMPLE | 1 | n | |
| UNITS | 0 | src | unit_byte |
| UNITS | 2 | size | unit_byte |
fs/nilfs2/ioctl.c nilfs_ioctl_clean_segments() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 0-u32max |
| PARAM_VALUE | 2 | size | 8 |
| CAPABLE | 0 | 21 | |
| UNITS | 1 | n | unit_array_size |
| UNITS | 2 | size | unit_byte |
drivers/infiniband/hw/hfi1/user_exp_rcv.c hfi1_user_exp_rcv_clear() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 2 | size | 4 |
| CAPPED_DATA | 1 | n | 1 |
| USER_DATA | 1 | n | 0-s32max[c] |
| UNITS | 1 | n | unit_array_size |
| UNITS | 2 | size | unit_byte |
drivers/input/misc/cs40l50-vibra.c cs40l50_add() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 2-u32max |
| PARAM_VALUE | 2 | size | 2 |
| FUZZY_MAX | 1 | n | 2 |
| USER_DATA | 1 | n | 2-u32max |
| UNITS | 2 | size | unit_byte |
| LOCK2 | &evdev->mutex | ||
| LOCK2 | _T->lock | ||
| TYPE_LOCK | (struct evdev)->mutex |
drivers/video/fbdev/via/viafbdev.c viafb_ioctl() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 256 |
| PARAM_VALUE | 2 | size | 4 |
| DATA_SOURCE | 0 | src | $2 |
| UNITS | 2 | size | unit_byte |
| LOCK2 | &info->lock | ||
| TYPE_LOCK | (struct fb_info)->lock |
drivers/i2c/i2c-dev.c i2cdev_ioctl() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | src | 1-u64max |
| PARAM_VALUE | 1 | n | 1-42 |
| PARAM_VALUE | 2 | size | 16 |
| FUZZY_MAX | 1 | n | 42 |
| HARD_MAX | 1 | n | 42 |
| USER_DATA | 1 | n | 1-42 |
| UNITS | 2 | size | unit_byte |
drivers/gpu/drm/drm_lease.c drm_mode_create_lease_ioctl() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 1-u32max |
| PARAM_VALUE | 2 | size | 4 |
| USER_DATA | 1 | n | 1-u32max[u] |
| UNITS | 2 | size | unit_byte |
drivers/gpu/drm/vmwgfx/vmwgfx_surface.c vmw_surface_define_ioctl() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 1-144 |
| PARAM_VALUE | 2 | size | 16 |
| UNITS | 1 | n | unit_array_size |
| UNITS | 2 | size | unit_byte |
sound/core/pcm_native.c snd_pcm_xfern_frames_ioctl() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 0-128 |
| PARAM_VALUE | 2 | size | 8 |
| FUZZY_MAX | 1 | n | 128 |
| HARD_MAX | 1 | n | 128 |
| UNITS | 1 | n | unit_byte |
| UNITS | 2 | size | unit_byte |
drivers/gpu/drm/amd/amdgpu/../amdkfd/kfd_chardev.c criu_restore_devices() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | src | 1-u64max |
| PARAM_VALUE | 1 | n | 1-s32max |
| PARAM_VALUE | 2 | size | 16 |
| CAPPED_DATA | 1 | n | 1 |
| UNITS | 1 | n | unit_array_size |
| UNITS | 2 | size | unit_byte |
| LOCK2 | &p->mutex | ||
| TYPE_LOCK | (struct kfd_process)->mutex |
drivers/gpu/drm/amd/amdgpu/../amdkfd/kfd_chardev.c kfd_ioctl_map_memory_to_gpu() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 1-u32max |
| PARAM_VALUE | 2 | size | 4 |
| USER_DATA | 1 | n | 1-u32max[u] |
| UNITS | 2 | size | unit_byte |
drivers/gpu/drm/amd/amdgpu/../amdkfd/kfd_chardev.c kfd_ioctl_unmap_memory_from_gpu() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 1-u32max |
| PARAM_VALUE | 2 | size | 4 |
| USER_DATA | 1 | n | 1-u32max[u] |
| UNITS | 2 | size | unit_byte |
drivers/xen/privcmd.c alloc_ioreq() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 1-4096 |
| PARAM_VALUE | 2 | size | 4 |
| USER_DATA | 1 | n | 1-4096 |
| UNITS | 2 | size | unit_byte |
| LOCK2 | global &ioreq_lock |
sound/isa/wavefront/wavefront_fx.c snd_wavefront_fx_ioctl() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 2-256 |
| PARAM_VALUE | 2 | size | 2 |
| USER_DATA | 1 | n | 2-256 |
| UNITS | 2 | size | unit_byte |
drivers/vfio/pci/vfio_pci_dmabuf.c vfio_pci_core_feature_dma_buf() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | src | 4096-ptr_max |
| PARAM_VALUE | 1 | n | 1-u32max |
| PARAM_VALUE | 2 | size | 16 |
| USER_DATA | 1 | n | 1-u32max |
| UNITS | 1 | n | unit_array_size |
| UNITS | 2 | size | unit_byte |
drivers/gpu/drm/amd/amdgpu/amdgpu_userq_fence.c amdgpu_userq_signal_ioctl() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 0-u16max |
| PARAM_VALUE | 2 | size | 4 |
| USER_DATA | 1 | n | 0-u16max[u] |
| UNITS | 2 | size | unit_byte |
drivers/gpu/drm/amd/amdgpu/amdgpu_userq_fence.c amdgpu_userq_wait_ioctl() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 0-u16max |
| PARAM_VALUE | 2 | size | 4 |
| USER_DATA | 1 | n | 0-u16max[u] |
| UNITS | 2 | size | unit_byte |
drivers/gpu/drm/amd/amdgpu/amdgpu_userq_fence.c amdgpu_userq_wait_ioctl() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 0-u16max |
| PARAM_VALUE | 2 | size | 4 |
| USER_DATA | 1 | n | 0-u16max[u] |
| UNITS | 2 | size | unit_byte |
drivers/gpu/drm/amd/amdgpu/amdgpu_userq_fence.c amdgpu_userq_wait_ioctl() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 0-u16max |
| PARAM_VALUE | 2 | size | 8 |
| USER_DATA | 1 | n | 0-u16max[u] |
| UNITS | 2 | size | unit_byte |
drivers/accel/qaic/qaic_data.c __qaic_execute_bo_ioctl() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 1-u32max |
| PARAM_VALUE | 2 | size | 8,16 |
| FUZZY_MAX | 2 | size | 16 |
| BIT_INFO | 2 | size | 0x0,0x18 |
| BIT_INFO | 2 | size | 0x0,0x18 |
| HARD_MAX | 2 | size | 16 |
| USER_DATA | 1 | n | 1-u32max[u] |
| UNITS | 2 | size | unit_byte |
drivers/accel/qaic/qaic_data.c qaic_perf_stats_bo_ioctl() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 2 | size | 24 |
| USER_DATA | 1 | n | 0-u16max[u] |
| UNITS | 2 | size | unit_byte |
| LOCK2 | &qdev->dev_lock | ||
| LOCK2 | &usr->qddev_lock | ||
| TYPE_LOCK | (struct qaic_device)->dev_lock | ||
| TYPE_LOCK | (struct qaic_user)->qddev_lock |
sound/usb/fcp.c fcp_ioctl_set_meter_map() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 1-128 |
| PARAM_VALUE | 2 | size | 2 |
| FUZZY_MAX | 1 | n | 128 |
| HARD_MAX | 1 | n | 128 |
| USER_DATA | 1 | n | 1-128 |
| UNITS | 1 | n | unit_array_size |
| UNITS | 2 | size | unit_byte |
| LOCK2 | _T->lock |
drivers/media/dvb-core/dvb_frontend.c dvb_frontend_handle_compat_ioctl() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | src | 0-u32max |
| PARAM_VALUE | 1 | n | 1-64 |
| PARAM_VALUE | 2 | size | 72 |
| FUZZY_MAX | 1 | n | 64 |
| HARD_MAX | 1 | n | 64 |
| USER_DATA | 1 | n | 1-64 |
| UNITS | 2 | size | unit_byte |
| LOCK2 | &fepriv->sem | ||
| TYPE_LOCK | (struct dvb_frontend_private)->sem |
drivers/media/dvb-core/dvb_frontend.c dvb_frontend_handle_compat_ioctl() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | src | 0-u32max |
| PARAM_VALUE | 1 | n | 1-64 |
| PARAM_VALUE | 2 | size | 72 |
| FUZZY_MAX | 1 | n | 64 |
| HARD_MAX | 1 | n | 64 |
| USER_DATA | 1 | n | 1-64 |
| UNITS | 2 | size | unit_byte |
| LOCK2 | &fepriv->sem | ||
| TYPE_LOCK | (struct dvb_frontend_private)->sem |
drivers/media/dvb-core/dvb_frontend.c dvb_frontend_handle_ioctl() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 1-64 |
| PARAM_VALUE | 2 | size | 76 |
| FUZZY_MAX | 1 | n | 64 |
| HARD_MAX | 1 | n | 64 |
| USER_DATA | 1 | n | 1-64[u] |
| UNITS | 2 | size | unit_byte |
| LOCK2 | &fepriv->sem | ||
| TYPE_LOCK | (struct dvb_frontend_private)->sem |
drivers/media/dvb-core/dvb_frontend.c dvb_get_property() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 1-64 |
| PARAM_VALUE | 2 | size | 76 |
| FUZZY_MAX | 1 | n | 64 |
| HARD_MAX | 1 | n | 64 |
| USER_DATA | 1 | n | 1-64[u] |
| UNITS | 2 | size | unit_byte |
| LOCK2 | &fepriv->sem | ||
| TYPE_LOCK | (struct dvb_frontend_private)->sem |
kernel/kexec.c __do_sys_kexec_load() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 0-16 |
| PARAM_VALUE | 2 | size | 32 |
| DATA_SOURCE | 0 | src | $2 |
| DATA_SOURCE | 1 | n | $1 |
| HARD_MAX | 1 | n | 16 |
| USER_DATA | 1 | n | 0-16 |
| UNITS | 2 | size | unit_byte |
kernel/kexec.c __do_sys_kexec_load() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 0-16 |
| PARAM_VALUE | 2 | size | 32 |
| DATA_SOURCE | 0 | src | $2 |
| DATA_SOURCE | 1 | n | $1 |
| HARD_MAX | 1 | n | 16 |
| USER_DATA | 1 | n | 0-16 |
| UNITS | 2 | size | unit_byte |
drivers/comedi/comedi_fops.c __comedi_get_user_chanlist() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 2 | size | 4 |
| BUF_SIZE | 0 | src | 1-s32max |
| CAPPED_DATA | 1 | n | 1 |
| DATA_SOURCE | 0 | src | $2 |
| USER_DATA | 1 | n | 0-u32max[c] |
| UNITS | 2 | size | unit_byte |
| LOCK2 | &dev->mutex | ||
| TYPE_LOCK | (struct comedi_device)->mutex |
drivers/comedi/comedi_fops.c comedi_unlocked_ioctl() -> memdup_array_user()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | n | 0-65536 |
| PARAM_VALUE | 2 | size | 40 |
| HARD_MAX | 1 | n | 65536 |
| USER_DATA | 1 | n | 0-65536 |
| UNITS | 2 | size | unit_byte |
| LOCK2 | &dev->mutex | ||
| TYPE_LOCK | (struct comedi_device)->mutex |