Documented in 1 files:
Defined in 1 files as a prototype:
Defined in 1 files as a function:
Referenced in 3 files:
Smatch caller information:
crypto/algif_aead.c _aead_recvmsg() -> af_alg_get_rsgl()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sk | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->sk_lock.owned | 1 |
| PARAM_VALUE | 0 | sk->sk_lock.wq.head.prev | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 3 | areq | 4096-ptr_max |
| PARAM_VALUE | 3 | areq->areqlen | 728-4000000 |
| PARAM_VALUE | 3 | areq->first_rsgl.sgl.sgl | 0 |
| PARAM_VALUE | 3 | areq->first_rsgl.sgl.sgt.sgl | 0 |
| PARAM_VALUE | 3 | areq->rsgl_list.next | 4096-ptr_max |
| PARAM_VALUE | 3 | areq->rsgl_list.next->next | 4096-ptr_max |
| PARAM_VALUE | 3 | areq->rsgl_list.prev | 4096-ptr_max |
| PARAM_VALUE | 3 | areq->rsgl_list.prev->next | 4096-ptr_max |
| PARAM_VALUE | 3 | areq->rsgl_list.prev->prev | 4096-ptr_max |
| PARAM_VALUE | 3 | areq->sk | 4096-ptr_max |
| PARAM_VALUE | 3 | areq->sk->sk_lock.owned | 1 |
| PARAM_VALUE | 3 | areq->sk->sk_lock.wq.head.prev | 4096-ptr_max |
| PARAM_VALUE | 5 | outlen | 5201315072727977984 |
| PARAM_VALUE | 5 | *outlen | 0 |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,128 |
| BUF_SIZE | 3 | areq | 0-s32max |
| BUF_SIZE | 3 | areq | 0-s32max |
| CAPPED_DATA | 0 | sk | 1 |
| CAPPED_DATA | 0 | sk->__sk_common.skc_net.net | 1 |
| CAPPED_DATA | 3 | areq->areqlen | 1 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | flags | $3 |
| DATA_SOURCE | 3 | areq | r af_alg_alloc_areq |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_controllen | 0-u64max |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_backlog.len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_prot_creator->twsk_prot->twsk_slab->sheaf_capacity | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->data_len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->data_len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->data_len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->data_len | |
| NO_OVERFLOW_SIMPLE | 3 | areq->sk->sk_backlog.len | |
| UNITS | 0 | sk | unit_byte |
| UNITS | 4 | maxsize | unit_byte |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex |
crypto/algif_skcipher.c _skcipher_recvmsg() -> af_alg_get_rsgl()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | sk | 4096-ptr_max |
| PARAM_VALUE | 0 | sk->sk_lock.owned | 1 |
| PARAM_VALUE | 0 | sk->sk_lock.wq.head.prev | 4096-ptr_max |
| PARAM_VALUE | 1 | msg | 4096-ptr_max |
| PARAM_VALUE | 3 | areq | 4096-ptr_max |
| PARAM_VALUE | 3 | areq->areqlen | 728-4000000 |
| PARAM_VALUE | 3 | areq->first_rsgl.sgl.sgl | 0 |
| PARAM_VALUE | 3 | areq->first_rsgl.sgl.sgt.sgl | 0 |
| PARAM_VALUE | 3 | areq->rsgl_list.next | 4096-ptr_max |
| PARAM_VALUE | 3 | areq->rsgl_list.next->next | 4096-ptr_max |
| PARAM_VALUE | 3 | areq->rsgl_list.prev | 4096-ptr_max |
| PARAM_VALUE | 3 | areq->rsgl_list.prev->next | 4096-ptr_max |
| PARAM_VALUE | 3 | areq->rsgl_list.prev->prev | 4096-ptr_max |
| PARAM_VALUE | 3 | areq->sk | 4096-ptr_max |
| PARAM_VALUE | 3 | areq->sk->sk_lock.owned | 1 |
| PARAM_VALUE | 3 | areq->sk->sk_lock.wq.head.prev | 4096-ptr_max |
| PARAM_VALUE | 5 | outlen | 6489376506898075648 |
| PARAM_VALUE | 5 | *outlen | 0 |
| BUF_SIZE | 1 | msg->msg_control | (-1)-0,16-17,24 |
| BUF_SIZE | 1 | msg->msg_name | (-1)-0,12,128 |
| BUF_SIZE | 3 | areq | 0-s32max |
| BUF_SIZE | 3 | areq | 0-s32max |
| CAPPED_DATA | 0 | sk | 1 |
| CAPPED_DATA | 0 | sk->__sk_common.skc_net.net | 1 |
| CAPPED_DATA | 3 | areq->areqlen | 1 |
| DATA_SOURCE | 1 | msg | $1 |
| DATA_SOURCE | 2 | flags | $3 |
| DATA_SOURCE | 3 | areq | r af_alg_alloc_areq |
| NOSPEC | 1 | msg->msg_iter.count | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 1 | msg->msg_control | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_control_user | 4096-ptr_max[c][u] |
| USER_DATA | 1 | msg->msg_controllen | 0-u64max |
| USER_DATA | 1 | msg->msg_flags | 0-u32max[c] |
| USER_DATA | 1 | msg->msg_iter.count | 0-u64max |
| USER_DATA | 1 | msg->msg_iter.iov_offset | 0-u64max[c] |
| USER_DATA | 1 | *msg->msg_name | s64min-s64max |
| USER_DATA | 2 | flags | s32min-s32max |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_backlog.len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_prot_creator->twsk_prot->twsk_slab->sheaf_capacity | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->data_len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_receive_queue.prev->next->data_len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->data_len | |
| NO_OVERFLOW_SIMPLE | 0 | sk->sk_write_queue.next->prev->data_len | |
| NO_OVERFLOW_SIMPLE | 3 | areq->sk->sk_backlog.len | |
| UNITS | 0 | sk | unit_byte |
| UNITS | 4 | maxsize | unit_byte |
| LOCK2 | sk | ||
| HALF_LOCKED2 | &vq->mutex |