Defined in 1 files as a function:
Referenced in 39 files:
- drivers/net/ovpn/tcp.c, line 194
- drivers/net/ppp/pppoe.c, line 939
- net/atm/common.c, line 540
- net/bluetooth/af_bluetooth.c
- net/bluetooth/hci_sock.c, line 1588
- net/core/datagram.c, line 902
- net/core/sock.c, line 3978
- net/ieee802154/socket.c
- net/ipv4/ip_sockglue.c, line 545
- net/ipv4/ping.c, line 870
- net/ipv4/raw.c, line 776
- net/ipv4/tcp.c
- net/ipv4/udp.c, line 2073
- net/ipv6/datagram.c
- net/ipv6/raw.c
- net/ipv6/udp.c, line 511
- net/iucv/af_iucv.c, line 1274
- net/kcm/kcmsock.c, line 1012
- net/key/af_key.c, line 3755
- net/l2tp/l2tp_ip.c, line 561
- net/l2tp/l2tp_ip6.c, line 706
- net/l2tp/l2tp_ppp.c, line 189
- net/llc/af_llc.c, line 871
- net/mctp/af_mctp.c, line 316
- net/mptcp/protocol.c, line 2103
- net/netlink/af_netlink.c, line 1957
- net/nfc/llcp_sock.c, line 876
- net/nfc/rawsock.c, line 272
- net/packet/af_packet.c, line 3501
- net/phonet/datagram.c, line 135
- net/phonet/pep.c, line 1346
- net/qrtr/af_qrtr.c, line 1057
- net/sctp/socket.c, line 2139
- net/tipc/socket.c
- net/tls/tls_sw.c
- net/unix/af_unix.c
- net/vmw_vsock/vmci_transport.c, line 1778
- net/x25/af_x25.c, line 1354
- net/xfrm/espintcp.c, line 160
Smatch caller information:
net/ipv6/datagram.c ipv6_recv_error() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 0 | from->next | 0 |
| PARAM_VALUE | 0 | from->prev | 0 |
| PARAM_VALUE | 1 | offset | 0 |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r sock_dequeue_err_skb |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | s32min-2147483646[c] |
| UNITS | 3 | size | unit_byte |
net/ipv6/datagram.c ipv6_recv_rxpmtu() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | s32min-2147483646[c] |
| UNITS | 3 | size | unit_byte |
net/phonet/datagram.c pn_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
net/key/af_key.c pfkey_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/kcm/kcmsock.c kcm_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| DATA_SOURCE | 3 | size | $2 [m] |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 1 | offset | unit_byte |
| UNITS | 3 | size | unit_byte |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/ipv4/ping.c ping_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
net/qrtr/af_qrtr.c qrtr_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/nfc/rawsock.c rawsock_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/core/datagram.c skb_copy_and_csum_datagram_msg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 0 | from->csum_complete_sw | 1 |
| PARAM_VALUE | 0 | from->dev->rtnl_link_ops->priv_size | 0,8,32,48,56,88,112,120,144,160,224,240,256,296,616,624,728,736,744,1056,1128,1336,1616,2176,2240,2272,2560,3296,3720,9688-u64max |
| PARAM_VALUE | 0 | *from->dev->name | 0-255 |
| PARAM_VALUE | 1 | offset | 0-s32max |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| PARAM_VALUE | 3 | size | s32min-(-1),1-s32max |
| BUF_SIZE | 0 | from | (-1)-s32max |
| BUF_SIZE | 0 | from | (-1)-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| DATA_SOURCE | 0 | from | $0 |
| DATA_SOURCE | 1 | offset | $1 |
| DATA_SOURCE | 2 | msg | $2 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| UNITS | 1 | offset | unit_byte |
| UNITS | 3 | size | unit_byte |
net/packet/af_packet.c packet_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/ipv6/udp.c udpv6_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 0 | from->sk->ns_tracker->alloc_stack_handle | 0-4294967295 |
| PARAM_VALUE | 0 | from->sk->ns_tracker->dead | 0-1 |
| PARAM_VALUE | 0 | from->sk->ns_tracker->free_stack_handle | 0-4294967295 |
| PARAM_VALUE | 1 | offset | 0-s32max |
| BUF_SIZE | 0 | from | (-1),240 |
| BUF_SIZE | 0 | from | (-1),240 |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r __skb_recv_udp |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 1 | offset | unit_byte |
| UNITS | 3 | size | unit_byte |
net/phonet/pep.c pep_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| PARAM_VALUE | 2 | msg->msg_flags | 0,32-u32max |
| BUF_SIZE | 0 | from | (-1)-s32max |
| BUF_SIZE | 0 | from | (-1)-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 0 | from->len | 1 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 2 | msg | $1 |
| DATA_SOURCE | 3 | size | $2 [m] |
| PARAM_COMPARE | 3 | size | <= $0->len |
| BIT_INFO | 2 | msg->msg_flags | 0x80,0xffffffff |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0,32-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
net/ipv4/raw.c raw_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
net/tipc/socket.c tipc_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 0 | from->cb | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | s32min-655354 |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| PARAM_VALUE | 2 | msg->msg_name | 0,4096-ptr_max |
| PARAM_VALUE | 2 | msg->msg_name->sock.addr.id.node | 0-4294967295 |
| PARAM_VALUE | 2 | msg->msg_name->sock.addr.id.ref | 0-4294967295 |
| PARAM_VALUE | 2 | msg->msg_name->sock.addr.name.domain | 0 |
| PARAM_VALUE | 2 | msg->msg_name->sock.addrtype | 3 |
| PARAM_VALUE | 2 | msg->msg_name->sock.family | 30 |
| PARAM_VALUE | 2 | msg->msg_name->sock.scope | 0 |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_peek |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | offset | s32min-655354[c] |
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | msg->msg_name->member.addr.name.name.type | 0-4294967295 |
| USER_DATA | 2 | msg->msg_name->sock.addr.id.node | 0-4294967295 |
| USER_DATA | 2 | msg->msg_name->sock.addr.id.ref | 0-4294967295 |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | s32min-s32max[c] |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/tipc/socket.c tipc_recvstream() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 0 | from->cb | 4096-ptr_max |
| PARAM_VALUE | 0 | from->data | 4096-ptr_max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_peek |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | offset | s32min-s32max[c] |
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | msg->msg_name->member.addr.name.name.type | 0-4294967295 |
| USER_DATA | 2 | msg->msg_name->sock.addr.id.node | 0-4294967295 |
| USER_DATA | 2 | msg->msg_name->sock.addr.id.ref | 0-4294967295 |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 2-s32max[c] |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/ipv4/tcp.c tcp_copy_straggler_data() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 0 | from->cb | 4096-ptr_max |
| PARAM_VALUE | 0 | from->sk->ns_tracker->alloc_stack_handle | 0-4294967295 |
| PARAM_VALUE | 0 | from->sk->ns_tracker->dead | 0-1 |
| PARAM_VALUE | 0 | from->sk->ns_tracker->free_stack_handle | 0-4294967295 |
| PARAM_VALUE | 2 | msg | 3252789435301113856 |
| PARAM_VALUE | 2 | msg->msg_inq | 0 |
| PARAM_VALUE | 2 | msg->msg_name | 0 |
| PARAM_VALUE | 2 | msg->msg_ubuf | 0 |
| PARAM_VALUE | 3 | size | s32min-(-1),1-s32max |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | $1 |
| DATA_SOURCE | 3 | size | $2 |
| NOSPEC | 3 | size | |
| NOSPEC | 3 | size | |
| RX_PATH | |||
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 0 | from | unit_byte |
| UNITS | 3 | size | unit_byte |
| HALF_LOCKED2 | sk |
net/ipv4/tcp.c tcp_peek_sndq() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| DATA_SOURCE | 2 | msg | $1 |
| UNITS | 3 | size | unit_byte |
net/ipv4/tcp.c tcp_peek_sndq() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| DATA_SOURCE | 2 | msg | $1 |
| UNITS | 0 | from | unit_byte |
| UNITS | 3 | size | unit_byte |
net/llc/af_llc.c llc_ui_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_peek |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | offset | 0-s32max[c][u] |
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 1 | offset | unit_byte |
| UNITS | 3 | size | unit_byte |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/l2tp/l2tp_ip.c l2tp_ip_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
net/sctp/socket.c sctp_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r sctp_skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
| LOCK2 | sk |
net/l2tp/l2tp_ip6.c l2tp_ip6_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
net/bluetooth/hci_sock.c hci_sock_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/unix/af_unix.c __unix_dgram_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 0 | from->sk->ns_tracker->alloc_stack_handle | 0-4294967295 |
| PARAM_VALUE | 0 | from->sk->ns_tracker->dead | 0-1 |
| PARAM_VALUE | 0 | from->sk->ns_tracker->free_stack_handle | 0-4294967295 |
| PARAM_VALUE | 1 | offset | 0-s32max |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| BUF_SIZE | 0 | from | (-1),240 |
| BUF_SIZE | 0 | from | (-1),240 |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r __skb_try_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| DATA_SOURCE | 3 | size | $2 [m] |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 1 | offset | unit_byte |
| UNITS | 3 | size | unit_byte |
| LOCK2 | &u->iolock | ||
| TYPE_LOCK | (struct unix_sock)->iolock |
net/unix/af_unix.c unix_stream_read_actor() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 1-u64max |
| PARAM_VALUE | 0 | from->dev->rtnl_link_ops->priv_size | 0,8,32,40,48,56,88,112,120,144,160,224,240,256,296,616,624,728,736,744,1056,1128,1336,1616,2176,2240,2272,2560,3296,3552,3720,9688-u64max |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | $0 |
| DATA_SOURCE | 3 | size | $2 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 1 | offset | unit_byte |
| LOCK2 | &u->iolock | ||
| TYPE_LOCK | (struct unix_sock)->iolock |
net/tls/tls_sw.c process_rx_list() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 1-ptr_max |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 1 | offset | unit_byte |
| UNITS | 3 | size | unit_byte |
| LOCK2 | sk |
net/tls/tls_sw.c tls_decrypt_device() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 2 | msg | 0,4096-ptr_max |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| DATA_SOURCE | 0 | from | r tls_strp_msg |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| UNITS | 1 | offset | unit_byte |
| UNITS | 3 | size | unit_byte |
| USER_PTR | 0 | from->data | |
| HALF_LOCKED2 | sk |
net/tls/tls_sw.c tls_sw_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from->extensions | 4096-ptr_max |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| UNITS | 1 | offset | unit_byte |
| UNITS | 3 | size | unit_byte |
net/ipv4/ip_sockglue.c ip_recv_error() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 0 | from->next | 0 |
| PARAM_VALUE | 0 | from->prev | 0 |
| PARAM_VALUE | 1 | offset | 0 |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r sock_dequeue_err_skb |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | s32min-2147483646[c] |
| UNITS | 3 | size | unit_byte |
net/mptcp/protocol.c __mptcp_recvmsg_mskq() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 0 | from->cb | 4096-ptr_max |
| PARAM_VALUE | 3 | size | 0-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 2-2147483644[c] |
| UNITS | 0 | from | unit_byte |
| UNITS | 1 | offset | unit_byte |
| UNITS | 3 | size | unit_byte |
| LOCK2 | sk |
net/xfrm/espintcp.c espintcp_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 0 | from->sk->ns_tracker->alloc_stack_handle | 0-4294967295 |
| PARAM_VALUE | 0 | from->sk->ns_tracker->dead | 0-1 |
| PARAM_VALUE | 0 | from->sk->ns_tracker->free_stack_handle | 0-4294967295 |
| PARAM_VALUE | 1 | offset | 0 |
| BUF_SIZE | 0 | from | (-1)-s32max |
| BUF_SIZE | 0 | from | (-1)-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 0 | from->len | 1 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r __skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| PARAM_COMPARE | 3 | size | <= $0->len |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 0-s32max[c] |
| UNITS | 3 | size | unit_byte |
net/ipv4/udp.c udp_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 0 | from->sk->ns_tracker->alloc_stack_handle | 0-4294967295 |
| PARAM_VALUE | 0 | from->sk->ns_tracker->dead | 0-1 |
| PARAM_VALUE | 0 | from->sk->ns_tracker->free_stack_handle | 0-4294967295 |
| PARAM_VALUE | 1 | offset | 0-s32max |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| BUF_SIZE | 0 | from | (-1),240 |
| BUF_SIZE | 0 | from | (-1),240 |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r __skb_recv_udp |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 1 | offset | unit_byte |
| UNITS | 3 | size | unit_byte |
drivers/net/ppp/pppoe.c pppoe_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| DATA_SOURCE | 3 | size | $2 [m] |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/core/sock.c sock_recv_errqueue() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 0 | from->next | 0 |
| PARAM_VALUE | 0 | from->prev | 0 |
| PARAM_VALUE | 1 | offset | 0 |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r sock_dequeue_err_skb |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | s32min-2147483646[c] |
| UNITS | 3 | size | unit_byte |
net/l2tp/l2tp_ppp.c pppol2tp_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 0 | from->len | 1 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| DATA_SOURCE | 3 | size | $2 [m] |
| PARAM_COMPARE | 3 | size | <= $0->len |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/ieee802154/socket.c dgram_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
net/ieee802154/socket.c raw_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
net/bluetooth/af_bluetooth.c bt_sock_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
| HALF_LOCKED2 | &vq->mutex |
net/bluetooth/af_bluetooth.c bt_sock_stream_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 0 | from->next | 0 |
| PARAM_VALUE | 0 | from->prev | 0 |
| PARAM_VALUE | 1 | offset | 0 |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_dequeue |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex |
net/mctp/af_mctp.c mctp_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 0 | from->data | 4096-ptr_max |
| PARAM_VALUE | 0 | from->len | 1-u32max |
| PARAM_VALUE | 1 | offset | 1 |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| DATA_SOURCE | 3 | size | $2 [m] |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/ipv6/raw.c rawv6_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
net/ipv6/raw.c rawv6_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 0 | from->csum_complete_sw | 1 |
| PARAM_VALUE | 0 | from->ip_summed | 0,2-3 |
| PARAM_VALUE | 0 | *from->dev->name | 0-255 |
| PARAM_VALUE | 1 | offset | 0 |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| PARAM_VALUE | 2 | msg->msg_flags | 32-u32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| BIT_INFO | 2 | msg->msg_flags | 0x20,0xffffffff |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 32-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
drivers/net/ovpn/tcp.c ovpn_tcp_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 0 | from->sk->ns_tracker->alloc_stack_handle | 0-4294967295 |
| PARAM_VALUE | 0 | from->sk->ns_tracker->dead | 0-1 |
| PARAM_VALUE | 0 | from->sk->ns_tracker->free_stack_handle | 0-4294967295 |
| PARAM_VALUE | 1 | offset | 0 |
| BUF_SIZE | 0 | from | (-1)-s32max |
| BUF_SIZE | 0 | from | (-1)-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 0 | from->len | 1 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r __skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| PARAM_COMPARE | 3 | size | <= $0->len |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 0-s32max[c] |
| UNITS | 3 | size | unit_byte |
net/nfc/llcp_sock.c llcp_sock_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/vmw_vsock/vmci_transport.c vmci_transport_dgram_dequeue() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 0 | from->data | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 24 |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 1 | offset | unit_byte |
| UNITS | 3 | size | unit_byte |
net/atm/common.c vcc_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 0 | from | r skb_recv_datagram |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/x25/af_x25.c x25_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| PARAM_VALUE | 2 | msg | 4096-ptr_max |
| PARAM_VALUE | 2 | msg->msg_flags | 0,128-u32max |
| BUF_SIZE | 0 | from | (-1)-s32max |
| BUF_SIZE | 0 | from | (-1)-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 2 | msg | $1 |
| BIT_INFO | 2 | msg->msg_flags | 0x80,0xffffffff |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0,128-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 3 | size | unit_byte |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/netlink/af_netlink.c netlink_recvmsg() -> skb_copy_datagram_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | offset | 0 |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 0 | from | (-1),1-s32max |
| BUF_SIZE | 2 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 2 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 3 | size | 1 |
| DATA_SOURCE | 2 | msg | $1 |
| NOSPEC | 2 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 2 | msg->msg_controllen | 0-u64max |
| USER_DATA | 2 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 2 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 2 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 2 | *msg->msg_name | s64min-s64max |
| USER_DATA | 3 | size | 1-s32max[c] |
| UNITS | 0 | from | unit_byte |
| UNITS | 3 | size | unit_byte |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |