Defined in 1 files as a prototype:
Defined in 1 files as a function:
Referenced in 3 files:
Smatch caller information:
mm/userfaultfd.c mrwprotect_range() -> change_protection()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | tlb | 6288812456027070464 |
| PARAM_VALUE | 0 | tlb->active | 4096-ptr_max |
| PARAM_VALUE | 0 | tlb->batch | 0 |
| PARAM_VALUE | 0 | tlb->fullmm | 0 |
| PARAM_VALUE | 0 | tlb->local.max | 8 |
| PARAM_VALUE | 0 | tlb->local.nr | 0 |
| PARAM_VALUE | 0 | tlb->mm | 4096-ptr_max |
| PARAM_VALUE | 1 | vma | 4096-ptr_max |
| PARAM_VALUE | 1 | vma->vm_file->f_mapping->i_mmap_rwsem.first_waiter->handoff_set | 0-1 |
| PARAM_VALUE | 1 | vma->vm_file->f_mapping->i_mmap_rwsem.first_waiter->type | 0-1 |
| PARAM_VALUE | 4 | cp_flags | 16,32-33 |
| CAPPED_DATA | 2 | start | 1 |
| CAPPED_DATA | 2 | start | 1 |
| CAPPED_DATA | 3 | end | 1 |
| CAPPED_DATA | 3 | end | 1 |
| DATA_SOURCE | 1 | vma | r vma_find |
| FUZZY_MAX | 4 | cp_flags | 32 |
| BIT_INFO | 4 | cp_flags | 0x0,0x31 |
| NOCHECK_CALL | |||
| USER_DATA | 0 | tlb->start | 0-u64max[c] |
| USER_DATA | 2 | start | 0-18446744073709551614[c] |
| NO_OVERFLOW_SIMPLE | 2 | start | |
| UNITS | 2 | start | unit_byte |
| UNITS | 3 | end | unit_byte |
| LOCK2 | &dst_mm->mmap_lock | ||
| LOCK2 | _T->lock | ||
| TYPE_LOCK | (struct mm_struct)->mmap_lock |
mm/userfaultfd.c uffd_wp_range() -> change_protection()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | tlb | 5518561256286212096 |
| PARAM_VALUE | 0 | tlb->active | 4096-ptr_max |
| PARAM_VALUE | 0 | tlb->batch | 0 |
| PARAM_VALUE | 0 | tlb->cleared_pmds | 0 |
| PARAM_VALUE | 0 | tlb->cleared_ptes | 0 |
| PARAM_VALUE | 0 | tlb->cleared_puds | 0 |
| PARAM_VALUE | 0 | tlb->end | 0,u64max |
| PARAM_VALUE | 0 | tlb->fullmm | 0 |
| PARAM_VALUE | 0 | tlb->local.max | 8 |
| PARAM_VALUE | 0 | tlb->local.nr | 0 |
| PARAM_VALUE | 0 | tlb->mm | 4096-ptr_max |
| PARAM_VALUE | 0 | tlb->vma_pfn | 0 |
| PARAM_VALUE | 1 | vma | 4096-ptr_max |
| PARAM_VALUE | 1 | vma->flags.__vma_flags | 4096-ptr_max |
| PARAM_VALUE | 1 | vma->vm_file->f_mapping->i_mmap_rwsem.first_waiter->handoff_set | 0-1 |
| PARAM_VALUE | 1 | vma->vm_file->f_mapping->i_mmap_rwsem.first_waiter->type | 0-1 |
| PARAM_VALUE | 1 | vma->vm_mm | 4096-ptr_max |
| PARAM_VALUE | 4 | cp_flags | 4,8-9 |
| CAPPED_DATA | 1 | vma->vm_start | 1 |
| DATA_SOURCE | 1 | vma | $0 |
| DATA_SOURCE | 2 | start | $1 |
| FUZZY_MAX | 4 | cp_flags | 8 |
| BIT_INFO | 4 | cp_flags | 0x0,0xd |
| NOSPEC | 2 | start | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 2 | start | 0-u64max[c] |
| NO_OVERFLOW_SIMPLE | 1 | vma->vm_end | |
| NO_OVERFLOW_SIMPLE | 1 | vma->vm_pgoff | |
| NO_OVERFLOW_SIMPLE | 1 | vma->vm_start | |
| UNITS | 2 | start | unit_byte |
| UNITS | 3 | end | unit_byte |
| HALF_LOCKED2 | &ctx->map_changing_lock | ||
| HALF_LOCKED2 | &dst_mm->mmap_lock |
mm/userfaultfd.c userfaultfd_clear_vma() -> change_protection()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | tlb | 697157037476265984 |
| PARAM_VALUE | 0 | tlb->active | 4096-ptr_max |
| PARAM_VALUE | 0 | tlb->batch | 0 |
| PARAM_VALUE | 0 | tlb->cleared_pmds | 0 |
| PARAM_VALUE | 0 | tlb->cleared_ptes | 0 |
| PARAM_VALUE | 0 | tlb->cleared_puds | 0 |
| PARAM_VALUE | 0 | tlb->end | 0,u64max |
| PARAM_VALUE | 0 | tlb->fullmm | 0 |
| PARAM_VALUE | 0 | tlb->local.max | 8 |
| PARAM_VALUE | 0 | tlb->local.nr | 0 |
| PARAM_VALUE | 0 | tlb->mm | 4096-ptr_max |
| PARAM_VALUE | 0 | tlb->vma_pfn | 0 |
| PARAM_VALUE | 1 | vma | 4096-ptr_max |
| PARAM_VALUE | 1 | vma->vm_file->f_mapping->i_mmap_rwsem.first_waiter->handoff_set | 0-1 |
| PARAM_VALUE | 1 | vma->vm_file->f_mapping->i_mmap_rwsem.first_waiter->type | 0-1 |
| PARAM_VALUE | 1 | vma->vm_mm | 4096-ptr_max |
| PARAM_VALUE | 1 | vma->vm_userfaultfd_ctx.ctx | 1-u64max |
| PARAM_VALUE | 4 | cp_flags | 0-1,8-9,32-33,40-41 |
| CAPPED_DATA | 1 | vma->vm_userfaultfd_ctx.ctx | 1 |
| DATA_SOURCE | 1 | vma | $2 |
| DATA_SOURCE | 2 | start | $3 |
| DATA_SOURCE | 3 | end | $4 |
| FUZZY_MAX | 4 | cp_flags | 0 |
| BIT_INFO | 4 | cp_flags | 0x0,0x29 |
| NOSPEC | 2 | start | |
| NOSPEC | 2 | start | |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NOCHECK_CALL | |||
| USER_DATA | 2 | start | 0-18446744073709551614[c] |
| NO_OVERFLOW_SIMPLE | 1 | vma->vm_start | |
| NO_OVERFLOW_SIMPLE | 2 | start | |
| UNITS | 2 | start | unit_byte |
| UNITS | 3 | end | unit_byte |
| LOCK2 | &mm->mmap_lock | ||
| TYPE_LOCK | (struct mm_struct)->mmap_lock |
mm/mprotect.c mprotect_fixup() -> change_protection()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | tlb | 1328374472486391808,3520855664362516480 |
| PARAM_VALUE | 0 | tlb->active | 4096-ptr_max |
| PARAM_VALUE | 0 | tlb->batch | 0 |
| PARAM_VALUE | 0 | tlb->fullmm | 0 |
| PARAM_VALUE | 0 | tlb->local.max | 8 |
| PARAM_VALUE | 0 | tlb->local.nr | 0 |
| PARAM_VALUE | 0 | tlb->mm | 4096-ptr_max |
| PARAM_VALUE | 1 | vma | 4096-ptr_max |
| PARAM_VALUE | 1 | vma->flags.__vma_flags | 4096-ptr_max |
| PARAM_VALUE | 1 | vma->vm_file->f_inode->i_sb->s_cop->inode_info_offs | 1632,1720,2632,2648 |
| PARAM_VALUE | 1 | vma->vm_file->f_mapping->i_mmap_rwsem.first_waiter->handoff_set | 0-1 |
| PARAM_VALUE | 1 | vma->vm_file->f_mapping->i_mmap_rwsem.first_waiter->type | 0-1 |
| PARAM_VALUE | 1 | vma->vm_mm | 4096-ptr_max |
| PARAM_VALUE | 4 | cp_flags | 0-1 |
| CAPPED_DATA | 1 | vma | 1 |
| DATA_SOURCE | 0 | tlb | $1 |
| DATA_SOURCE | 1 | vma | r vma_modify_flags |
| DATA_SOURCE | 2 | start | $4 |
| DATA_SOURCE | 3 | end | $5 |
| FUZZY_MAX | 4 | cp_flags | 0 |
| NOSPEC | 2 | start | |
| NOSPEC | 2 | start | |
| NOSPEC | 3 | end | |
| NOSPEC | 3 | end | |
| NOCHECK_CALL | |||
| USER_DATA | 1 | vma->vm_pgoff | 0-4503599627370495[c] |
| USER_DATA | 1 | vma->vm_start | 1-u64max[c] |
| USER_DATA | 2 | start | 0-u64max |
| USER_DATA | 3 | end | 1-s32max[c] |
| NO_OVERFLOW_SIMPLE | 1 | vma->vm_end | |
| NO_OVERFLOW_SIMPLE | 1 | vma->vm_start | |
| NO_OVERFLOW_SIMPLE | 3 | end | |
| UNITS | 2 | start | unit_byte |
| UNITS | 3 | end | unit_byte |
| HALF_LOCKED2 | &mm->mmap_lock | ||
| HALF_LOCKED2 | &tsk->signal->exec_update_lock |
mm/mempolicy.c change_prot_numa() -> change_protection()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | tlb | 8385517359223296000 |
| PARAM_VALUE | 0 | tlb->active | 4096-ptr_max |
| PARAM_VALUE | 0 | tlb->batch | 0 |
| PARAM_VALUE | 0 | tlb->cleared_pmds | 0 |
| PARAM_VALUE | 0 | tlb->cleared_ptes | 0 |
| PARAM_VALUE | 0 | tlb->cleared_puds | 0 |
| PARAM_VALUE | 0 | tlb->end | 0,u64max |
| PARAM_VALUE | 0 | tlb->fullmm | 0 |
| PARAM_VALUE | 0 | tlb->local.max | 8 |
| PARAM_VALUE | 0 | tlb->local.nr | 0 |
| PARAM_VALUE | 0 | tlb->mm | 4096-ptr_max |
| PARAM_VALUE | 0 | tlb->vma_pfn | 0 |
| PARAM_VALUE | 1 | vma | 4096-ptr_max |
| PARAM_VALUE | 1 | vma->flags.__vma_flags | 4096-ptr_max |
| PARAM_VALUE | 1 | vma->numab_state | 4096-ptr_max |
| PARAM_VALUE | 1 | vma->vm_file | 0,4096-ptr_max |
| PARAM_VALUE | 1 | vma->vm_file->f_mapping->i_mmap_rwsem.first_waiter->handoff_set | 0-1 |
| PARAM_VALUE | 1 | vma->vm_file->f_mapping->i_mmap_rwsem.first_waiter->type | 0-1 |
| PARAM_VALUE | 1 | vma->vm_flags | 1-u64max |
| PARAM_VALUE | 1 | vma->vm_mm | 4096-ptr_max |
| PARAM_VALUE | 1 | vma->vm_ops | 0,4096-ptr_max |
| PARAM_VALUE | 4 | cp_flags | 2 |
| CAPPED_DATA | 3 | end | 1 |
| CAPPED_DATA | 3 | end | 1 |
| DATA_SOURCE | 1 | vma | $0 |
| DATA_SOURCE | 2 | start | $1 |
| DATA_SOURCE | 3 | end | $2 |
| BIT_INFO | 1 | vma->vm_flags | 0x0,0xffffffffefffffff |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| UNITS | 2 | start | unit_byte |
| UNITS | 3 | end | unit_byte |
| LOCK2 | &mm->mmap_lock | ||
| HALF_LOCKED2 | bh | ||
| HALF_LOCKED2 | rcu | ||
| TYPE_LOCK | (struct mm_struct)->mmap_lock |