Defined in 1 files as a function:
Referenced in 1 files:
Smatch caller information:
net/rxrpc/recvmsg.c rxrpc_kernel_recv_data() -> rxrpc_recvmsg_data()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | call->user_mutex.dep_map->name | 0-255 |
| PARAM_VALUE | 1 | call->user_mutex.first_waiter | 0,4096-ptr_max |
| PARAM_VALUE | 1 | call->user_mutex.first_waiter->list.prev->next | 5159360019465732096 |
| PARAM_VALUE | 1 | call->user_mutex.osq.tail.counter | 0-s32max |
| PARAM_VALUE | 1 | call->user_mutex.wait_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 1 | call->user_mutex.wait_lock.owner | (-1) |
| PARAM_VALUE | 1 | call->user_mutex.wait_lock.owner_cpu | u32max |
| PARAM_VALUE | 2 | msg | 0 |
| PARAM_VALUE | 5 | flags | 0 |
| PARAM_VALUE | 6 | _offset | 2166422318627311616 |
| PARAM_VALUE | 6 | *_offset | 0 |
| BUF_SIZE | 3 | iter | (-1),40 |
| BUF_SIZE | 3 | iter | (-1),40 |
| CAPPED_DATA | 1 | &call->user_mutex | 1 |
| DATA_SOURCE | 0 | sock | $0 |
| DATA_SOURCE | 1 | call | $1 |
| DATA_SOURCE | 3 | iter | $2 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | call->tx_pending->alloc_size | 0-1418[c] |
| USER_DATA | 1 | call->tx_pending->cksum | 1-u16max[c] |
| USER_DATA | 1 | call->tx_pending->len | 0-u16max[c][u] |
| USER_DATA | 1 | call->tx_pending->offset | 0-u16max[c][u] |
| USER_DATA | 1 | call->tx_pending->pkt_len | 0-u16max[c] |
| USER_DATA | 1 | call->tx_pending->space | 0-u16max |
| USER_DATA | 4 | len | 0-17179869180,18446744073709486082-u64max |
| NO_OVERFLOW_SIMPLE | 1 | call->rx_dec_buffer | |
| NO_OVERFLOW_SIMPLE | 1 | call->rx_dec_len | |
| LOCK2 | 1 | &call->user_mutex | |
| HALF_LOCKED2 | &rx->sk | ||
| TYPE_LOCK | (struct rxrpc_call)->user_mutex |
net/rxrpc/recvmsg.c rxrpc_recvmsg() -> rxrpc_recvmsg_data()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sock | 4096-ptr_max |
| PARAM_VALUE | 1 | call | 4096-ptr_max |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| PARAM_VALUE | 3 | iter | 4096-ptr_max |
| PARAM_VALUE | 6 | _offset | 5929212022464839680 |
| PARAM_VALUE | 6 | *_offset | 0 |
| BUF_SIZE | 0 | sock | s32min-(-1),1-s32max |
| BUF_SIZE | 0 | sock | s32min-(-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 1 | &call->user_mutex | 1 |
| DATA_SOURCE | 0 | sock | $0 |
| DATA_SOURCE | 2 | msg | $1 |
| DATA_SOURCE | 4 | len | $2 |
| DATA_SOURCE | 5 | flags | $3 |
| BIT_INFO | 5 | flags | 0x0,0x7fffffde |
| NOSPEC | 2 | msg->msg_iter.count | |
| NOSPEC | 3 | iter->count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | iter->count | 0-u64max |
| USER_DATA | 3 | iter->iov_offset | 0-u64max[c] |
| USER_DATA | 4 | len | 0-u64max |
| USER_DATA | 5 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sock->sk->sk_backlog.len | |
| NO_OVERFLOW_SIMPLE | 0 | sock->sk->sk_receive_queue.prev->next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sock->sk->sk_receive_queue.prev->next->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sock->sk->sk_receive_queue.prev->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sock->sk->sk_receive_queue.prev->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sock->sk->sk_write_queue.next->prev->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sock->sk->sk_write_queue.next->prev->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sock->sk->sk_write_queue.next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sock->sk->sk_write_queue.next->truesize | |
| LOCK2 | 1 | &call->user_mutex | |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk | ||
| TYPE_LOCK | (struct rxrpc_call)->user_mutex |