Defined in 1 files as a function:
Referenced in 1 files:
Smatch caller information:
net/bluetooth/l2cap_core.c l2cap_ertm_send() -> __next_seq()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | chan | 4096-ptr_max |
| BUF_SIZE | 0 | chan->data | (-1)-s32max |
| CAPPED_DATA | 0 | chan | 1 |
| CAPPED_DATA | 0 | chan->unacked_frames | 1 |
| DATA_SOURCE | 0 | chan | $0 |
| PARAM_COMPARE | 0 | chan->remote_tx_win | > $0->unacked_frames |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NO_OVERFLOW_SIMPLE | 0 | chan->conn->hchan->data_q.prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | chan->conn->hchan->data_q.prev->next->len | |
| NO_OVERFLOW_SIMPLE | 0 | chan->sdu->data_len | |
| NO_OVERFLOW_SIMPLE | 0 | chan->sdu->end | |
| NO_OVERFLOW_SIMPLE | 0 | chan->sdu->len | |
| NO_OVERFLOW_SIMPLE | 0 | chan->sdu_last_frag->end | |
| NO_OVERFLOW_SIMPLE | 0 | chan->sdu_last_frag->len | |
| NO_OVERFLOW_SIMPLE | 0 | chan->sdu_last_frag->next->end | |
| NO_OVERFLOW_SIMPLE | 0 | chan->sdu_last_frag->next->len | |
| NO_OVERFLOW_SIMPLE | 0 | chan->sdu_last_frag->next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | chan->sdu_last_frag->tail | |
| USER_PTR | 0 | chan->tx_send_head->data | |
| HALF_LOCKED2 | &conn->lock | ||
| HALF_LOCKED2 | 0 | &chan->lock |
net/bluetooth/l2cap_core.c l2cap_process_reqseq() -> __next_seq()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | chan | 4096-ptr_max |
| BUF_SIZE | 0 | chan->data | (-1)-s32max |
| DATA_SOURCE | 0 | chan | $0 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NO_OVERFLOW_SIMPLE | 0 | chan->sdu->data_len | |
| NO_OVERFLOW_SIMPLE | 0 | chan->sdu->len | |
| NO_OVERFLOW_SIMPLE | 0 | chan->sdu_last_frag->len | |
| NO_OVERFLOW_SIMPLE | 0 | chan->sdu_last_frag->next->len | |
| NO_OVERFLOW_SIMPLE | 0 | chan->sdu_last_frag->next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | chan->sdu_last_frag->tail | |
| USER_PTR | 0 | chan->tx_send_head->data | |
| HALF_LOCKED2 | &conn->lock | ||
| HALF_LOCKED2 | 0 | &chan->lock |
net/bluetooth/l2cap_core.c l2cap_rx_queued_iframes() -> __next_seq()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | chan | 4096-ptr_max |
| CAPPED_DATA | 0 | chan | 1 |
| CAPPED_DATA | 0 | chan->buffer_seq | 1 |
| CAPPED_DATA | 1 | seq | 1 |
| DATA_SOURCE | 0 | chan | $0 |
| RX_PATH | |||
| NO_OVERFLOW_SIMPLE | 0 | chan->conn->hchan->data_q.prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | chan->conn->hchan->data_q.prev->next->len | |
| NO_OVERFLOW_SIMPLE | 0 | chan->sdu->end | |
| NO_OVERFLOW_SIMPLE | 0 | chan->sdu_last_frag->end | |
| LOCK2 | &conn->lock | ||
| LOCK2 | 0 | &chan->lock | |
| HALF_LOCKED2 | &pool->lock | ||
| TYPE_LOCK | (struct l2cap_chan)->lock | ||
| TYPE_LOCK | (struct l2cap_conn)->lock |
net/bluetooth/l2cap_core.c l2cap_rx_state_recv() -> __next_seq()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | chan | 4096-ptr_max |
| CAPPED_DATA | 0 | chan | 1 |
| DATA_SOURCE | 0 | chan | $0 |
| RX_PATH | |||
| NO_OVERFLOW_SIMPLE | 0 | chan->conn->hchan->data_q.prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | chan->conn->hchan->data_q.prev->next->len | |
| USER_PTR | 0 | chan->tx_send_head->data | |
| LOCK2 | &conn->lock | ||
| LOCK2 | 0 | &chan->lock | |
| HALF_LOCKED2 | &pool->lock | ||
| TYPE_LOCK | (struct l2cap_chan)->lock | ||
| TYPE_LOCK | (struct l2cap_conn)->lock |
net/bluetooth/l2cap_core.c l2cap_rx_state_srej_sent() -> __next_seq()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | chan | 4096-ptr_max |
| CAPPED_DATA | 0 | chan | 1 |
| DATA_SOURCE | 0 | chan | $0 |
| RX_PATH | |||
| NO_OVERFLOW_SIMPLE | 0 | chan->conn->hchan->data_q.prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | chan->conn->hchan->data_q.prev->next->len | |
| LOCK2 | &conn->lock | ||
| LOCK2 | &pool->lock | ||
| LOCK2 | 0 | &chan->lock | |
| TYPE_LOCK | (struct l2cap_chan)->lock | ||
| TYPE_LOCK | (struct l2cap_conn)->lock |
net/bluetooth/l2cap_core.c l2cap_send_srej() -> __next_seq()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | chan | 4096-ptr_max |
| CAPPED_DATA | 0 | chan | 1 |
| DATA_SOURCE | 0 | chan | $0 |
| RX_PATH | |||
| NO_OVERFLOW_SIMPLE | 0 | chan->conn->hchan->data_q.prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | chan->conn->hchan->data_q.prev->next->len | |
| USER_PTR | 0 | chan->tx_send_head->data | |
| LOCK2 | &conn->lock | ||
| LOCK2 | 0 | &chan->lock | |
| HALF_LOCKED2 | &pool->lock | ||
| TYPE_LOCK | (struct l2cap_chan)->lock | ||
| TYPE_LOCK | (struct l2cap_conn)->lock |
net/bluetooth/l2cap_core.c l2cap_send_srej() -> __next_seq()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | chan | 4096-ptr_max |
| CAPPED_DATA | 0 | chan | 1 |
| CAPPED_DATA | 1 | seq | 1 |
| DATA_SOURCE | 0 | chan | $0 |
| DATA_SOURCE | 1 | seq | $1 |
| RX_PATH | |||
| NO_OVERFLOW_SIMPLE | 0 | chan->conn->hchan->data_q.prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | chan->conn->hchan->data_q.prev->next->len | |
| USER_PTR | 0 | chan->tx_send_head->data | |
| LOCK2 | &conn->lock | ||
| LOCK2 | 0 | &chan->lock | |
| HALF_LOCKED2 | &pool->lock | ||
| TYPE_LOCK | (struct l2cap_chan)->lock | ||
| TYPE_LOCK | (struct l2cap_conn)->lock |
net/bluetooth/l2cap_core.c l2cap_stream_rx() -> __next_seq()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | chan | 4096-ptr_max |
| CAPPED_DATA | 0 | chan | 1 |
| DATA_SOURCE | 0 | chan | $0 |
| RX_PATH | |||
| NO_OVERFLOW_SIMPLE | 0 | chan->conn->hchan->data_q.prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | chan->conn->hchan->data_q.prev->next->len | |
| LOCK2 | &conn->lock | ||
| LOCK2 | &pool->lock | ||
| TYPE_LOCK | (struct l2cap_conn)->lock |
net/bluetooth/l2cap_core.c l2cap_stream_rx() -> __next_seq()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | chan | 4096-ptr_max |
| CAPPED_DATA | 0 | chan | 1 |
| DATA_SOURCE | 0 | chan | $0 |
| RX_PATH | |||
| NO_OVERFLOW_SIMPLE | 0 | chan->conn->hchan->data_q.prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | chan->conn->hchan->data_q.prev->next->len | |
| LOCK2 | &conn->lock | ||
| LOCK2 | &pool->lock | ||
| TYPE_LOCK | (struct l2cap_conn)->lock |
net/bluetooth/l2cap_core.c l2cap_stream_rx() -> __next_seq()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | chan | 4096-ptr_max |
| CAPPED_DATA | 0 | chan | 1 |
| DATA_SOURCE | 0 | chan | $0 |
| RX_PATH | |||
| NO_OVERFLOW_SIMPLE | 0 | chan->conn->hchan->data_q.prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | chan->conn->hchan->data_q.prev->next->len | |
| NO_OVERFLOW_SIMPLE | 0 | chan->sdu->end | |
| NO_OVERFLOW_SIMPLE | 0 | chan->sdu_last_frag->end | |
| LOCK2 | &conn->lock | ||
| LOCK2 | &pool->lock | ||
| TYPE_LOCK | (struct l2cap_conn)->lock |
net/bluetooth/l2cap_core.c l2cap_streaming_send() -> __next_seq()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | chan | 4096-ptr_max |
| BUF_SIZE | 0 | chan->data | (-1)-s32max |
| CAPPED_DATA | 0 | &chan->tx_q | 1 |
| DATA_SOURCE | 0 | chan | $0 |
| PARAM_COMPARE | 0 | &chan->tx_q | != $0->tx_q.next |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| HALF_LOCKED2 | 0 | &chan->lock |