Defined in 1 files as a prototype:
Defined in 1 files as a function:
Referenced in 6 files:
- io_uring/zcrx.c, line 1788
- net/ipv4/af_inet.c, line 894
- net/ipv4/tcp_bpf.c
- net/ipv4/tcp_ipv4.c, line 3364
- net/ipv6/af_inet6.c, line 656
- net/ipv6/tcp_ipv6.c, line 2292
Smatch caller information:
net/ipv4/af_inet.c inet_recvmsg() -> tcp_recvmsg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sk->__sk_common.skc_prot | 4096-ptr_max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,128 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| DATA_SOURCE | 3 | flags | $3 |
| NOSPEC | 1 | msg->msg_iter.count | |
| PREEMPT_ADD | |||
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_controllen | 0-u64max |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 0-u64max |
| USER_DATA | 3 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_backlog.len | |
| UNITS | 0 | sk | unit_byte |
| UNITS | 2 | len | unit_byte |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/ipv4/tcp_bpf.c tcp_bpf_recvmsg() -> tcp_recvmsg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sk | 4096-ptr_max |
| PARAM_VALUE | 2 | len | 1-u64max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 0 | sk->sk_user_data | 1 |
| DATA_SOURCE | 0 | sk | $0 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| DATA_SOURCE | 3 | flags | $3 |
| BIT_INFO | 3 | flags | 0x0,0xffffdfff |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_controllen | 0-u64max |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 1-u64max |
| USER_DATA | 3 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_backlog.len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->truesize | |
| UNITS | 0 | sk | unit_byte |
| UNITS | 2 | len | unit_byte |
net/ipv4/tcp_bpf.c tcp_bpf_recvmsg() -> tcp_recvmsg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sk | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->sk_callback_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | sk->sk_callback_lock.owner | (-1) |
| PARAM_VALUE | 0 | sk->sk_callback_lock.owner_cpu | u32max |
| PARAM_VALUE | 0 | sk->sk_callback_lock.raw_lock.cnts.counter | 0-s32max |
| PARAM_VALUE | 0 | sk->sk_callback_lock.raw_lock.wlocked | 0 |
| PARAM_VALUE | 0 | sk->sk_data_ready | 1-u64max |
| PARAM_VALUE | 0 | sk->sk_user_data | 0 |
| PARAM_VALUE | 2 | len | 1-u64max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 0 | &sk->sk_receive_queue | 1 |
| DATA_SOURCE | 0 | sk | $0 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| DATA_SOURCE | 3 | flags | $3 |
| PARAM_COMPARE | 0 | &sk->sk_receive_queue | != $0->sk_receive_queue.next |
| BIT_INFO | 3 | flags | 0x0,0xffffdfff |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_controllen | 0-u64max |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 1-u64max |
| USER_DATA | 3 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_backlog.len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->truesize | |
| UNITS | 0 | sk | unit_byte |
| UNITS | 2 | len | unit_byte |
net/ipv4/tcp_bpf.c tcp_bpf_recvmsg() -> tcp_recvmsg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sk | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->sk_callback_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | sk->sk_data_ready | 1-u64max |
| PARAM_VALUE | 0 | sk->sk_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | sk->sk_lock.owned | 0 |
| PARAM_VALUE | 0 | sk->sk_lock.slock.rlock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | sk->sk_lock.wq.head.prev->next | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->sk_lock.wq.head.prev->next->next | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->sk_user_data | 0 |
| PARAM_VALUE | 0 | *sk->sk_backlog.head->dev->name | 0-255 |
| PARAM_VALUE | 1 | msg->msg_iter.__iov | 4096-u64max |
| PARAM_VALUE | 1 | msg->msg_iter.bvec | 4096-u64max |
| PARAM_VALUE | 1 | msg->msg_iter.folioq | 1-u64max |
| PARAM_VALUE | 1 | msg->msg_iter.kvec | 4096-u64max |
| PARAM_VALUE | 2 | len | 1-u64max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 0 | sk | 1 |
| CAPPED_DATA | 0 | &sk->sk_receive_queue | 1 |
| DATA_SOURCE | 0 | sk | $0 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| DATA_SOURCE | 3 | flags | $3 |
| BIT_INFO | 3 | flags | 0x0,0xffffdfff |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_controllen | 0-u64max |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 1-u64max |
| USER_DATA | 3 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_backlog.len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->truesize | |
| UNITS | 0 | sk | unit_byte |
| UNITS | 2 | len | unit_byte |
net/ipv4/tcp_bpf.c tcp_bpf_recvmsg_parser() -> tcp_recvmsg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sk | 4096-ptr_max |
| PARAM_VALUE | 2 | len | 1-u64max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 0 | sk->sk_user_data | 1 |
| DATA_SOURCE | 0 | sk | $0 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| DATA_SOURCE | 3 | flags | $3 |
| BIT_INFO | 3 | flags | 0x0,0xffffdfff |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_controllen | 0-u64max |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 1-u64max |
| USER_DATA | 3 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_backlog.len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->truesize | |
| UNITS | 0 | sk | unit_byte |
| UNITS | 2 | len | unit_byte |
net/ipv6/af_inet6.c inet6_recvmsg() -> tcp_recvmsg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sk->__sk_common.skc_prot | 4096-ptr_max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,128 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| DATA_SOURCE | 3 | flags | $3 |
| NOSPEC | 1 | msg->msg_iter.count | |
| PREEMPT_ADD | |||
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_controllen | 0-u64max |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 0-u64max |
| USER_DATA | 3 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_backlog.len | |
| UNITS | 0 | sk | unit_byte |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/ipv4/udp_bpf.c sk_udp_recvmsg() -> (struct proto)->recvmsg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sk | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->__sk_common.skc_family | 10 |
| PARAM_VALUE | 2 | len | 1-u64max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 0 | sk | 1 |
| DATA_SOURCE | 0 | sk | $0 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| DATA_SOURCE | 3 | flags | $3 |
| BIT_INFO | 3 | flags | 0x0,0xffffdfff |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_controllen | 0-u64max |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 1-u64max |
| USER_DATA | 3 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_backlog.len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_prot_creator->twsk_prot->twsk_slab->sheaf_capacity | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->data_len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->data_len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->data_len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->data_len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->truesize |
net/ipv4/udp_bpf.c sk_udp_recvmsg() -> (struct proto)->recvmsg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sk | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->__sk_common.skc_family | 0-9,11-u16max |
| PARAM_VALUE | 2 | len | 1-u64max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 0 | sk | 1 |
| DATA_SOURCE | 0 | sk | $0 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| DATA_SOURCE | 3 | flags | $3 |
| BIT_INFO | 3 | flags | 0x0,0xffffdfff |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_controllen | 0-u64max |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 1-u64max |
| USER_DATA | 3 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_backlog.len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_prot_creator->twsk_prot->twsk_slab->sheaf_capacity | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->data_len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->data_len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->data_len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->data_len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->truesize |
net/unix/af_unix.c unix_dgram_recvmsg() -> (struct proto)->recvmsg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sk->__sk_common.skc_prot | 4096-5685900286491869183,5685900286491869185-ptr_max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,128 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| DATA_SOURCE | 3 | flags | $3 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_controllen | 0-u64max |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 0-u64max |
| USER_DATA | 3 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_backlog.len | |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/unix/af_unix.c unix_stream_recvmsg() -> (struct proto)->recvmsg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sk->__sk_common.skc_prot | 4096-8773621801401122815,8773621801401122817-ptr_max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,128 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| DATA_SOURCE | 3 | flags | $3 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_controllen | 0-u64max |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 0-u64max |
| USER_DATA | 3 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_backlog.len | |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/vmw_vsock/af_vsock.c vsock_connectible_recvmsg() -> (struct proto)->recvmsg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sk->__sk_common.skc_prot | 4096-4318459831623020543,4318459831623020545-ptr_max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,128 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| DATA_SOURCE | 3 | flags | $3 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_controllen | 0-u64max |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 0-u64max |
| USER_DATA | 3 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_backlog.len | |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/vmw_vsock/af_vsock.c vsock_dgram_recvmsg() -> (struct proto)->recvmsg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sk->__sk_common.skc_prot | 4096-4318459831623020543,4318459831623020545-ptr_max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,128 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| DATA_SOURCE | 3 | flags | $3 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_controllen | 0-u64max |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 0-u64max |
| USER_DATA | 3 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_backlog.len | |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/core/sock.c sock_common_recvmsg() -> (struct proto)->recvmsg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sk | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->__sk_common.skc_prot | 4096-ptr_max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,128 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| DATA_SOURCE | 3 | flags | $3 |
| CONTAINER | 0 | -112-40-0+0 | $(-1) |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_controllen | 0-u64max |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 0-u64max |
| USER_DATA | 3 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_backlog.len | |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/ipv6/af_inet6.c inet6_recvmsg() -> inet6_recvmsg ptr __f1()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sk->__sk_common.skc_prot | 4096-ptr_max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,128 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| DATA_SOURCE | 3 | flags | $3 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_controllen | 0-u64max |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 0-u64max |
| USER_DATA | 3 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_backlog.len | |
| UNITS | 0 | sk | unit_byte |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |
net/ipv4/af_inet.c inet_recvmsg() -> inet_recvmsg ptr __f1()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sk->__sk_common.skc_prot | 4096-ptr_max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,128 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| DATA_SOURCE | 3 | flags | $3 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_controllen | 0-u64max |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 0-u64max |
| USER_DATA | 3 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_backlog.len | |
| UNITS | 0 | sk | unit_byte |
| UNITS | 2 | len | unit_byte |
| HALF_LOCKED2 | &vq->mutex | ||
| HALF_LOCKED2 | sk |