Defined in 1 files as a function:
Referenced in 1 files:
Smatch caller information:
net/vmw_vsock/vsock_bpf.c vsock_bpf_recvmsg() -> __vsock_recvmsg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sk | 4096-ptr_max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 0 | sk->sk_user_data | 1 |
| DATA_SOURCE | 0 | sk | $0 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| DATA_SOURCE | 3 | flags | $3 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_controllen | 0-u64max |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 0-u64max |
| USER_DATA | 3 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_backlog.len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->truesize | |
| UNITS | 0 | sk | unit_byte |
| UNITS | 2 | len | unit_byte |
net/vmw_vsock/vsock_bpf.c vsock_bpf_recvmsg() -> __vsock_recvmsg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sk | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->__sk_common.skc_net.net->ipv4.fib_main->tb_data->kv->key | 0-4294967295 |
| PARAM_VALUE | 0 | sk->__sk_common.skc_net.net->loopback_dev->refcnt_tracker.list.next->next | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->__sk_common.skc_net.net->mctp.bind_lock.first_waiter->list.prev->prev | 5159360019465732096 |
| PARAM_VALUE | 0 | sk->__sk_common.skc_node.next->pprev | 1-u64max |
| PARAM_VALUE | 0 | sk->__sk_common.skc_prot->owner->refcnt.counter | 0-s32max |
| PARAM_VALUE | 0 | sk->listener->__sk_common.skc_net.net->notrefcnt_tracker.dead | 1 |
| PARAM_VALUE | 0 | sk->listener->__sk_common.skc_net.net->refcnt_tracker.dead | 1 |
| PARAM_VALUE | 0 | sk->listener->sk_bpf_storage->owner_refcnt.refs.counter | s32min-s32max |
| PARAM_VALUE | 0 | sk->listener->sk_callback_lock.raw_lock.cnts.counter | 0-s32max |
| PARAM_VALUE | 0 | sk->listener->sk_lock.owned | 1 |
| PARAM_VALUE | 0 | sk->listener->sk_rcu.next | 0 |
| PARAM_VALUE | 0 | sk->listener->sk_reuseport_cb | 0 |
| PARAM_VALUE | 0 | sk->listener->sk_user_data | 0 |
| PARAM_VALUE | 0 | sk->peer_shutdown | 0-4294967295 |
| PARAM_VALUE | 0 | sk->sk_backlog.head->extensions->refcnt.refs.counter | 1 |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->__sk_common.skc_net.net->notrefcnt_tracker.dead | 1 |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->__sk_common.skc_net.net->refcnt_tracker.dead | 1 |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->__sk_common.skc_prot | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->__sk_common.skc_state | 0-9,11-255 |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->sk_callback_lock.owner | (-1) |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->sk_callback_lock.owner_cpu | u32max |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->sk_callback_lock.raw_lock.cnts.counter | 0-s32max |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->sk_filter->rcu.func | 1-u64max |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->sk_owner->refcnt.counter | 0-s32max |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->sk_prot_creator->owner->refcnt.counter | 0-s32max |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->sk_rcu.func | 1-u64max |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->sk_reuseport_cb->rcu.func | 1-u64max |
| PARAM_VALUE | 0 | sk->sk_callback_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | sk->sk_data_ready | 1-u64max |
| PARAM_VALUE | 0 | sk->sk_dst_cache->callback_head.flags | 0-4294967295 |
| PARAM_VALUE | 0 | sk->sk_dst_cache->callback_head.is_hard | 0-1 |
| PARAM_VALUE | 0 | sk->sk_dst_cache->callback_head.is_lazy | 0-1 |
| PARAM_VALUE | 0 | sk->sk_dst_cache->callback_head.is_queued | 0-1 |
| PARAM_VALUE | 0 | sk->sk_dst_cache->callback_head.is_soft | 0-1 |
| PARAM_VALUE | 0 | sk->sk_dst_cache->ops->pcpuc_entries.lock.owner | (-1) |
| PARAM_VALUE | 0 | sk->sk_dst_cache->ops->pcpuc_entries.lock.owner_cpu | u32max |
| PARAM_VALUE | 0 | sk->sk_dst_cache->ops->pcpuc_entries.lock.raw_lock.val.counter | 0-s32max |
| PARAM_VALUE | 0 | sk->sk_error_queue.next->prev | 2011684551238094848 |
| PARAM_VALUE | 0 | sk->sk_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | sk->sk_lock.owned | 0 |
| PARAM_VALUE | 0 | sk->sk_lock.slock.rlock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | sk->sk_lock.wq.head.prev->next | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->sk_lock.wq.head.prev->next->next | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->sk_memcg->high_work.entry.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->sk_memcg->tcpmem_pressure | 0-1 |
| PARAM_VALUE | 0 | sk->sk_reuseport_cb->rcu.func | 1-u64max |
| PARAM_VALUE | 0 | sk->sk_reuseport_cb->rcu.next | 0 |
| PARAM_VALUE | 0 | sk->sk_rx_dst->u.dst.__pad | s16min-s16max |
| PARAM_VALUE | 0 | sk->sk_rx_dst->u.dst.__rcuref.refcnt.counter | s32min-s32max |
| PARAM_VALUE | 0 | sk->sk_rx_dst->u.dst.__use | s32min-s32max |
| PARAM_VALUE | 0 | sk->sk_rx_dst->u.dst.dst_trace_seq.counter | s32min-s32max |
| PARAM_VALUE | 0 | sk->sk_rx_dst->u.dst.error | s16min-s16max |
| PARAM_VALUE | 0 | sk->sk_rx_dst->u.dst.header_len | 0-u16max |
| PARAM_VALUE | 0 | sk->sk_rx_dst->u.dst.obsolete | s16min-s16max |
| PARAM_VALUE | 0 | sk->sk_rx_dst->u.dst.tclassid | 0-4294967295 |
| PARAM_VALUE | 0 | sk->sk_rx_dst->u.dst.trailer_len | 0-u16max |
| PARAM_VALUE | 0 | sk->sk_user_data | 0 |
| PARAM_VALUE | 0 | sk->skc_family | 0-u16max |
| PARAM_VALUE | 0 | sk->tcp_retransmit_timer.entry->pprev | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->trans->chan->inbound.pkt_buffer->flags | 0-u16max |
| PARAM_VALUE | 0 | sk->trans->chan->inbound.pkt_buffer->len8 | 0-u16max |
| PARAM_VALUE | 0 | sk->trans->chan->inbound.pkt_buffer->offset8 | 2-u16max |
| PARAM_VALUE | 0 | sk->trans->chan->inbound.pkt_buffer->type | 0-u16max |
| PARAM_VALUE | 0 | sk->trans->recv_data_len | 0-4088 |
| PARAM_VALUE | 0 | sk->trans->recv_data_off | 0 |
| PARAM_VALUE | 0 | sk->trans->recv_desc | 0 |
| PARAM_VALUE | 0 | sk->trans->recv_desc->flags | 0-u16max |
| PARAM_VALUE | 0 | sk->trans->recv_desc->len8 | 0-u16max |
| PARAM_VALUE | 0 | sk->trans->recv_desc->offset8 | 2-u16max |
| PARAM_VALUE | 0 | sk->trans->recv_desc->type | 0-u16max |
| PARAM_VALUE | 0 | sk->trans->rx_lock.rlock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | sk->trans->vsk->peer_shutdown | 0,2-4294967295 |
| PARAM_VALUE | 0 | sk->transport | 313939572454838272,4304869436517031936,5599459859400630272,7768179779944185856,8703969711714045952 |
| PARAM_VALUE | 0 | *sk->sk_backlog.head->dev->name | 0-255 |
| PARAM_VALUE | 0 | *sk->sk_user_data->dev->pcpu_refcnt | s32min-s32max |
| PARAM_VALUE | 0 | *sk->sk_user_data->door_bell.wait.lock.owner | (-4611686018427387904)-4611686018427387903 |
| PARAM_VALUE | 0 | *sk->sk_user_data->private->o_auth.authorizer->session_key.key | (-4611686018427387904)-4611686018427387903 |
| PARAM_VALUE | 0 | *sk->sk_user_data->private->s_auth.authorizer->session_key.key | (-4611686018427387904)-4611686018427387903 |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 0 | sk | 1 |
| DATA_SOURCE | 0 | sk | $0 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| DATA_SOURCE | 3 | flags | $3 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_controllen | 0-u64max |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 0-u64max |
| USER_DATA | 3 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_backlog.len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->truesize | |
| UNITS | 0 | sk | unit_byte |
| UNITS | 2 | len | unit_byte |
net/vmw_vsock/vsock_bpf.c vsock_bpf_recvmsg() -> __vsock_recvmsg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sk | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->__sk_common.skc_net.net->ipv4.fib_main->tb_data->kv->key | 0-4294967295 |
| PARAM_VALUE | 0 | sk->__sk_common.skc_net.net->loopback_dev->refcnt_tracker.list.next->next | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->__sk_common.skc_net.net->mctp.bind_lock.first_waiter->list.prev->prev | 5159360019465732096 |
| PARAM_VALUE | 0 | sk->__sk_common.skc_node.next->pprev | 1-u64max |
| PARAM_VALUE | 0 | sk->__sk_common.skc_prot->owner->refcnt.counter | 0-s32max |
| PARAM_VALUE | 0 | sk->listener->__sk_common.skc_net.net->notrefcnt_tracker.dead | 1 |
| PARAM_VALUE | 0 | sk->listener->__sk_common.skc_net.net->refcnt_tracker.dead | 1 |
| PARAM_VALUE | 0 | sk->listener->sk_bpf_storage->owner_refcnt.refs.counter | s32min-s32max |
| PARAM_VALUE | 0 | sk->listener->sk_callback_lock.raw_lock.cnts.counter | 0-s32max |
| PARAM_VALUE | 0 | sk->listener->sk_lock.owned | 1 |
| PARAM_VALUE | 0 | sk->listener->sk_rcu.next | 0 |
| PARAM_VALUE | 0 | sk->listener->sk_reuseport_cb | 0 |
| PARAM_VALUE | 0 | sk->listener->sk_user_data | 0 |
| PARAM_VALUE | 0 | sk->peer_shutdown | 0-4294967295 |
| PARAM_VALUE | 0 | sk->sk_backlog.head->extensions->refcnt.refs.counter | 1 |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->__sk_common.skc_net.net->notrefcnt_tracker.dead | 1 |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->__sk_common.skc_net.net->refcnt_tracker.dead | 1 |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->__sk_common.skc_prot | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->__sk_common.skc_state | 0-9,11-255 |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->sk_callback_lock.owner | (-1) |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->sk_callback_lock.owner_cpu | u32max |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->sk_callback_lock.raw_lock.cnts.counter | 0-s32max |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->sk_filter->rcu.func | 1-u64max |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->sk_owner->refcnt.counter | 0-s32max |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->sk_prot_creator->owner->refcnt.counter | 0-s32max |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->sk_rcu.func | 1-u64max |
| PARAM_VALUE | 0 | sk->sk_backlog.head->sk->sk_reuseport_cb->rcu.func | 1-u64max |
| PARAM_VALUE | 0 | sk->sk_callback_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | sk->sk_data_ready | 1-u64max |
| PARAM_VALUE | 0 | sk->sk_dst_cache->callback_head.flags | 0-4294967295 |
| PARAM_VALUE | 0 | sk->sk_dst_cache->callback_head.is_hard | 0-1 |
| PARAM_VALUE | 0 | sk->sk_dst_cache->callback_head.is_lazy | 0-1 |
| PARAM_VALUE | 0 | sk->sk_dst_cache->callback_head.is_queued | 0-1 |
| PARAM_VALUE | 0 | sk->sk_dst_cache->callback_head.is_soft | 0-1 |
| PARAM_VALUE | 0 | sk->sk_dst_cache->ops->pcpuc_entries.lock.owner | (-1) |
| PARAM_VALUE | 0 | sk->sk_dst_cache->ops->pcpuc_entries.lock.owner_cpu | u32max |
| PARAM_VALUE | 0 | sk->sk_dst_cache->ops->pcpuc_entries.lock.raw_lock.val.counter | 0-s32max |
| PARAM_VALUE | 0 | sk->sk_error_queue.next->prev | 2011684551238094848 |
| PARAM_VALUE | 0 | sk->sk_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | sk->sk_lock.owned | 0 |
| PARAM_VALUE | 0 | sk->sk_lock.slock.rlock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | sk->sk_lock.wq.head.prev->next | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->sk_lock.wq.head.prev->next->next | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->sk_memcg->high_work.entry.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->sk_memcg->tcpmem_pressure | 0-1 |
| PARAM_VALUE | 0 | sk->sk_reuseport_cb->rcu.func | 1-u64max |
| PARAM_VALUE | 0 | sk->sk_reuseport_cb->rcu.next | 0 |
| PARAM_VALUE | 0 | sk->sk_rx_dst->u.dst.__pad | s16min-s16max |
| PARAM_VALUE | 0 | sk->sk_rx_dst->u.dst.__rcuref.refcnt.counter | s32min-s32max |
| PARAM_VALUE | 0 | sk->sk_rx_dst->u.dst.__use | s32min-s32max |
| PARAM_VALUE | 0 | sk->sk_rx_dst->u.dst.dst_trace_seq.counter | s32min-s32max |
| PARAM_VALUE | 0 | sk->sk_rx_dst->u.dst.error | s16min-s16max |
| PARAM_VALUE | 0 | sk->sk_rx_dst->u.dst.header_len | 0-u16max |
| PARAM_VALUE | 0 | sk->sk_rx_dst->u.dst.obsolete | s16min-s16max |
| PARAM_VALUE | 0 | sk->sk_rx_dst->u.dst.tclassid | 0-4294967295 |
| PARAM_VALUE | 0 | sk->sk_rx_dst->u.dst.trailer_len | 0-u16max |
| PARAM_VALUE | 0 | sk->sk_user_data | 0 |
| PARAM_VALUE | 0 | sk->skc_family | 0-u16max |
| PARAM_VALUE | 0 | sk->tcp_retransmit_timer.entry->pprev | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->trans->chan->inbound.pkt_buffer->flags | 0-u16max |
| PARAM_VALUE | 0 | sk->trans->chan->inbound.pkt_buffer->len8 | 0-u16max |
| PARAM_VALUE | 0 | sk->trans->chan->inbound.pkt_buffer->offset8 | 2-u16max |
| PARAM_VALUE | 0 | sk->trans->chan->inbound.pkt_buffer->type | 0-u16max |
| PARAM_VALUE | 0 | sk->trans->recv_data_len | 0-16384 |
| PARAM_VALUE | 0 | sk->trans->recv_data_off | 0 |
| PARAM_VALUE | 0 | sk->trans->recv_desc | 0 |
| PARAM_VALUE | 0 | sk->trans->recv_desc->flags | 0-u16max |
| PARAM_VALUE | 0 | sk->trans->recv_desc->len8 | 0-u16max |
| PARAM_VALUE | 0 | sk->trans->recv_desc->offset8 | 2-u16max |
| PARAM_VALUE | 0 | sk->trans->recv_desc->type | 0-u16max |
| PARAM_VALUE | 0 | sk->trans->rx_lock.rlock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | sk->trans->vsk->peer_shutdown | 0,2-4294967295 |
| PARAM_VALUE | 0 | sk->transport | 313939572454838272,4304869436517031936,5599459859400630272,7768179779944185856,8703969711714045952 |
| PARAM_VALUE | 0 | *sk->sk_backlog.head->dev->name | 0-255 |
| PARAM_VALUE | 0 | *sk->sk_user_data->dev->pcpu_refcnt | s32min-s32max |
| PARAM_VALUE | 0 | *sk->sk_user_data->door_bell.wait.lock.owner | (-4611686018427387904)-4611686018427387903 |
| PARAM_VALUE | 0 | *sk->sk_user_data->private->o_auth.authorizer->session_key.key | (-4611686018427387904)-4611686018427387903 |
| PARAM_VALUE | 0 | *sk->sk_user_data->private->s_auth.authorizer->session_key.key | (-4611686018427387904)-4611686018427387903 |
| PARAM_VALUE | 1 | msg->msg_iter.__iov | 4096-u64max |
| PARAM_VALUE | 1 | msg->msg_iter.bvec | 4096-u64max |
| PARAM_VALUE | 1 | msg->msg_iter.folioq | 1-u64max |
| PARAM_VALUE | 1 | msg->msg_iter.kvec | 4096-u64max |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,128 |
| CAPPED_DATA | 0 | sk | 1 |
| DATA_SOURCE | 0 | sk | $0 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | len | $2 |
| DATA_SOURCE | 3 | flags | $3 |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_controllen | 0-u64max |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | len | 0-u64max |
| USER_DATA | 3 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_backlog.len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->end | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->truesize | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->tail | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->truesize | |
| UNITS | 0 | sk | unit_byte |
| UNITS | 2 | len | unit_byte |