Defined in 1 files as a function:

Referenced in 1 files:

Smatch caller information:

net/bluetooth/l2cap_core.c l2cap_ertm_send() -> __next_seq()

Type Parameter Key Value
PARAM_VALUE 0 chan 4096-ptr_max
BUF_SIZE 0 chan->data (-1)-s32max
CAPPED_DATA 0 chan 1
CAPPED_DATA 0 chan->unacked_frames 1
DATA_SOURCE 0 chan $0
PARAM_COMPARE 0 chan->remote_tx_win > $0->unacked_frames
RX_PATH
TASK_NOT_RUNNING
NO_OVERFLOW_SIMPLE 0 chan->conn->hchan->data_q.prev->len
NO_OVERFLOW_SIMPLE 0 chan->conn->hchan->data_q.prev->next->len
NO_OVERFLOW_SIMPLE 0 chan->sdu->data_len
NO_OVERFLOW_SIMPLE 0 chan->sdu->end
NO_OVERFLOW_SIMPLE 0 chan->sdu->len
NO_OVERFLOW_SIMPLE 0 chan->sdu_last_frag->end
NO_OVERFLOW_SIMPLE 0 chan->sdu_last_frag->len
NO_OVERFLOW_SIMPLE 0 chan->sdu_last_frag->next->end
NO_OVERFLOW_SIMPLE 0 chan->sdu_last_frag->next->len
NO_OVERFLOW_SIMPLE 0 chan->sdu_last_frag->next->tail
NO_OVERFLOW_SIMPLE 0 chan->sdu_last_frag->tail
USER_PTR 0 chan->tx_send_head->data
HALF_LOCKED2 &conn->lock
HALF_LOCKED2 0 &chan->lock

net/bluetooth/l2cap_core.c l2cap_process_reqseq() -> __next_seq()

Type Parameter Key Value
PARAM_VALUE 0 chan 4096-ptr_max
BUF_SIZE 0 chan->data (-1)-s32max
DATA_SOURCE 0 chan $0
RX_PATH
TASK_NOT_RUNNING
NO_OVERFLOW_SIMPLE 0 chan->sdu->data_len
NO_OVERFLOW_SIMPLE 0 chan->sdu->len
NO_OVERFLOW_SIMPLE 0 chan->sdu_last_frag->len
NO_OVERFLOW_SIMPLE 0 chan->sdu_last_frag->next->len
NO_OVERFLOW_SIMPLE 0 chan->sdu_last_frag->next->tail
NO_OVERFLOW_SIMPLE 0 chan->sdu_last_frag->tail
USER_PTR 0 chan->tx_send_head->data
HALF_LOCKED2 &conn->lock
HALF_LOCKED2 0 &chan->lock

net/bluetooth/l2cap_core.c l2cap_rx_queued_iframes() -> __next_seq()

Type Parameter Key Value
PARAM_VALUE 0 chan 4096-ptr_max
CAPPED_DATA 0 chan 1
CAPPED_DATA 0 chan->buffer_seq 1
CAPPED_DATA 1 seq 1
DATA_SOURCE 0 chan $0
RX_PATH
NO_OVERFLOW_SIMPLE 0 chan->conn->hchan->data_q.prev->len
NO_OVERFLOW_SIMPLE 0 chan->conn->hchan->data_q.prev->next->len
NO_OVERFLOW_SIMPLE 0 chan->sdu->end
NO_OVERFLOW_SIMPLE 0 chan->sdu_last_frag->end
LOCK2 &conn->lock
LOCK2 0 &chan->lock
HALF_LOCKED2 &pool->lock
TYPE_LOCK (struct l2cap_chan)->lock
TYPE_LOCK (struct l2cap_conn)->lock

net/bluetooth/l2cap_core.c l2cap_rx_state_recv() -> __next_seq()

Type Parameter Key Value
PARAM_VALUE 0 chan 4096-ptr_max
CAPPED_DATA 0 chan 1
DATA_SOURCE 0 chan $0
RX_PATH
NO_OVERFLOW_SIMPLE 0 chan->conn->hchan->data_q.prev->len
NO_OVERFLOW_SIMPLE 0 chan->conn->hchan->data_q.prev->next->len
USER_PTR 0 chan->tx_send_head->data
LOCK2 &conn->lock
LOCK2 0 &chan->lock
HALF_LOCKED2 &pool->lock
TYPE_LOCK (struct l2cap_chan)->lock
TYPE_LOCK (struct l2cap_conn)->lock

net/bluetooth/l2cap_core.c l2cap_rx_state_srej_sent() -> __next_seq()

Type Parameter Key Value
PARAM_VALUE 0 chan 4096-ptr_max
CAPPED_DATA 0 chan 1
DATA_SOURCE 0 chan $0
RX_PATH
NO_OVERFLOW_SIMPLE 0 chan->conn->hchan->data_q.prev->len
NO_OVERFLOW_SIMPLE 0 chan->conn->hchan->data_q.prev->next->len
LOCK2 &conn->lock
LOCK2 &pool->lock
LOCK2 0 &chan->lock
TYPE_LOCK (struct l2cap_chan)->lock
TYPE_LOCK (struct l2cap_conn)->lock

net/bluetooth/l2cap_core.c l2cap_send_srej() -> __next_seq()

Type Parameter Key Value
PARAM_VALUE 0 chan 4096-ptr_max
CAPPED_DATA 0 chan 1
DATA_SOURCE 0 chan $0
RX_PATH
NO_OVERFLOW_SIMPLE 0 chan->conn->hchan->data_q.prev->len
NO_OVERFLOW_SIMPLE 0 chan->conn->hchan->data_q.prev->next->len
USER_PTR 0 chan->tx_send_head->data
LOCK2 &conn->lock
LOCK2 0 &chan->lock
HALF_LOCKED2 &pool->lock
TYPE_LOCK (struct l2cap_chan)->lock
TYPE_LOCK (struct l2cap_conn)->lock

net/bluetooth/l2cap_core.c l2cap_send_srej() -> __next_seq()

Type Parameter Key Value
PARAM_VALUE 0 chan 4096-ptr_max
CAPPED_DATA 0 chan 1
CAPPED_DATA 1 seq 1
DATA_SOURCE 0 chan $0
DATA_SOURCE 1 seq $1
RX_PATH
NO_OVERFLOW_SIMPLE 0 chan->conn->hchan->data_q.prev->len
NO_OVERFLOW_SIMPLE 0 chan->conn->hchan->data_q.prev->next->len
USER_PTR 0 chan->tx_send_head->data
LOCK2 &conn->lock
LOCK2 0 &chan->lock
HALF_LOCKED2 &pool->lock
TYPE_LOCK (struct l2cap_chan)->lock
TYPE_LOCK (struct l2cap_conn)->lock

net/bluetooth/l2cap_core.c l2cap_stream_rx() -> __next_seq()

Type Parameter Key Value
PARAM_VALUE 0 chan 4096-ptr_max
CAPPED_DATA 0 chan 1
DATA_SOURCE 0 chan $0
RX_PATH
NO_OVERFLOW_SIMPLE 0 chan->conn->hchan->data_q.prev->len
NO_OVERFLOW_SIMPLE 0 chan->conn->hchan->data_q.prev->next->len
LOCK2 &conn->lock
LOCK2 &pool->lock
TYPE_LOCK (struct l2cap_conn)->lock

net/bluetooth/l2cap_core.c l2cap_stream_rx() -> __next_seq()

Type Parameter Key Value
PARAM_VALUE 0 chan 4096-ptr_max
CAPPED_DATA 0 chan 1
DATA_SOURCE 0 chan $0
RX_PATH
NO_OVERFLOW_SIMPLE 0 chan->conn->hchan->data_q.prev->len
NO_OVERFLOW_SIMPLE 0 chan->conn->hchan->data_q.prev->next->len
LOCK2 &conn->lock
LOCK2 &pool->lock
TYPE_LOCK (struct l2cap_conn)->lock

net/bluetooth/l2cap_core.c l2cap_stream_rx() -> __next_seq()

Type Parameter Key Value
PARAM_VALUE 0 chan 4096-ptr_max
CAPPED_DATA 0 chan 1
DATA_SOURCE 0 chan $0
RX_PATH
NO_OVERFLOW_SIMPLE 0 chan->conn->hchan->data_q.prev->len
NO_OVERFLOW_SIMPLE 0 chan->conn->hchan->data_q.prev->next->len
NO_OVERFLOW_SIMPLE 0 chan->sdu->end
NO_OVERFLOW_SIMPLE 0 chan->sdu_last_frag->end
LOCK2 &conn->lock
LOCK2 &pool->lock
TYPE_LOCK (struct l2cap_conn)->lock

net/bluetooth/l2cap_core.c l2cap_streaming_send() -> __next_seq()

Type Parameter Key Value
PARAM_VALUE 0 chan 4096-ptr_max
BUF_SIZE 0 chan->data (-1)-s32max
CAPPED_DATA 0 &chan->tx_q 1
DATA_SOURCE 0 chan $0
PARAM_COMPARE 0 &chan->tx_q != $0->tx_q.next
RX_PATH
TASK_NOT_RUNNING
HALF_LOCKED2 0 &chan->lock