Defined in 1 files as a prototype:
Defined in 1 files as a function:
Referenced in 7 files:
- net/ipv4/ip_output.c
- net/ipv4/raw.c, line 486
- net/ipv4/udp.c
- net/ipv6/ip6_output.c
- net/ipv6/raw.c, line 739
- net/ipv6/udp.c
- net/l2tp/l2tp_ip6.c, line 655
Smatch caller information:
net/ipv4/raw.c raw_getfrag() -> ip_generic_getfrag()
| Type | Parameter | Key | Value |
|---|---|---|---|
| DATA_SOURCE | 1 | to | $1 [m] |
| DATA_SOURCE | 2 | offset | $2 [m] |
| DATA_SOURCE | 3 | len | $3 [m] |
| DATA_SOURCE | 4 | odd | $4 [m] |
| DATA_SOURCE | 5 | skb | $5 |
net/ipv6/raw.c raw6_getfrag() -> ip_generic_getfrag()
| Type | Parameter | Key | Value |
|---|---|---|---|
| DATA_SOURCE | 1 | to | $1 [m] |
| DATA_SOURCE | 2 | offset | $2 [m] |
| DATA_SOURCE | 3 | len | $3 [m] |
| DATA_SOURCE | 4 | odd | $4 [m] |
| DATA_SOURCE | 5 | skb | $5 |
net/ipv6/ip6_output.c __ip6_append_data() -> ip_generic_getfrag()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | to | 4096-ptr_max |
| PARAM_VALUE | 2 | offset | 0-s32max |
| PARAM_VALUE | 3 | len | 1-s32max |
| PARAM_VALUE | 5 | skb | 4096-ptr_max |
| PARAM_VALUE | 5 | skb->data | 4096-ptr_max |
| PARAM_VALUE | 5 | skb->data_len | 0 |
| PARAM_VALUE | 5 | skb->ip_summed | 0,3 |
| PARAM_VALUE | 5 | skb->protocol | 34525 |
| BUF_SIZE | 0 | from | (-1),16,24 |
| BUF_SIZE | 0 | from | (-1),16,24 |
| BUF_SIZE | 5 | skb | 0-s32max |
| BUF_SIZE | 5 | skb | 0-s32max |
| DATA_SOURCE | 0 | from | $5 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 0 | from->msg_iter.count | s64min-s64max |
| USER_DATA | 0 | from->msg_iter.iov_offset | s64min-s64max[c] |
| USER_DATA | 2 | offset | 1-s32max[c][u] |
| UNITS | 1 | to | unit_byte |
| UNITS | 3 | len | unit_byte |
| UNITS | 4 | odd | unit_byte |
net/ipv4/ip_output.c __ip_append_data() -> ip_generic_getfrag()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 3 | len | 1-s32max |
| PARAM_VALUE | 5 | skb | 4096-ptr_max |
| PARAM_VALUE | 5 | skb->data | 4096-ptr_max |
| PARAM_VALUE | 5 | skb->data_len | 0 |
| PARAM_VALUE | 5 | skb->ip_summed | 0,3 |
| BUF_SIZE | 0 | from | s32min-(-1),1-s32max |
| BUF_SIZE | 0 | from | s32min-(-1),1-s32max |
| BUF_SIZE | 5 | skb | 0-s32max |
| BUF_SIZE | 5 | skb | 0-s32max |
| DATA_SOURCE | 0 | from | $6 |
| FUZZY_MAX | 3 | len | 1 |
| FUZZY_MAX | 5 | skb->ip_summed | 3 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 0 | from->msg_iter.count | s64min-s64max |
| USER_DATA | 0 | from->msg_iter.iov_offset | s64min-s64max[c] |
| USER_DATA | 2 | offset | 1-s32max[c][u] |
| UNITS | 0 | from | unit_byte |
| UNITS | 1 | to | unit_byte |
| UNITS | 3 | len | unit_byte |
| UNITS | 4 | odd | unit_byte |
net/ipv4/ip_output.c __ip_append_data() -> ip_generic_getfrag()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | to | 4096-ptr_max |
| PARAM_VALUE | 3 | len | 1-s32max |
| PARAM_VALUE | 5 | skb | 4096-ptr_max |
| PARAM_VALUE | 5 | skb->data_len | 0 |
| BUF_SIZE | 0 | from | s32min-(-1),1-s32max |
| BUF_SIZE | 0 | from | s32min-(-1),1-s32max |
| BUF_SIZE | 5 | skb | (-1)-s32max |
| BUF_SIZE | 5 | skb | (-1)-s32max |
| CAPPED_DATA | 3 | len | 1 |
| DATA_SOURCE | 0 | from | $6 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 0 | from->msg_iter.count | s64min-s64max |
| USER_DATA | 0 | from->msg_iter.iov_offset | s64min-s64max[c] |
| USER_DATA | 2 | offset | 1-s32max[c][u] |
| USER_DATA | 3 | len | 1-65543[c] |
| UNITS | 0 | from | unit_byte |
| UNITS | 3 | len | unit_byte |
| UNITS | 4 | odd | unit_byte |
net/ipv6/ip6_output.c __ip6_append_data() -> __f1()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | from | 4096-ptr_max |
| PARAM_VALUE | 1 | to | 4096-ptr_max |
| PARAM_VALUE | 2 | offset | 0-s32max |
| PARAM_VALUE | 3 | len | 1-s32max |
| PARAM_VALUE | 5 | skb | 4096-ptr_max |
| PARAM_VALUE | 5 | skb->data | 4096-ptr_max |
| PARAM_VALUE | 5 | skb->data_len | 0 |
| PARAM_VALUE | 5 | skb->ip_summed | 0,3 |
| PARAM_VALUE | 5 | skb->protocol | 34525 |
| BUF_SIZE | 0 | from | (-1),16,24 |
| BUF_SIZE | 0 | from | (-1),16,24 |
| BUF_SIZE | 5 | skb | 0-s32max |
| BUF_SIZE | 5 | skb | 0-s32max |
| DATA_SOURCE | 0 | from | $5 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 0 | from->msg_iter.count | s64min-s64max |
| USER_DATA | 0 | from->msg_iter.iov_offset | s64min-s64max[c] |
| USER_DATA | 2 | offset | 1-s32max[c][u] |
| UNITS | 1 | to | unit_byte |
| UNITS | 3 | len | unit_byte |
| UNITS | 4 | odd | unit_byte |
net/ipv4/ip_output.c __ip_append_data() -> __f1()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 3 | len | 1-s32max |
| PARAM_VALUE | 5 | skb | 4096-ptr_max |
| PARAM_VALUE | 5 | skb->data | 4096-ptr_max |
| PARAM_VALUE | 5 | skb->data_len | 0 |
| PARAM_VALUE | 5 | skb->ip_summed | 0,3 |
| BUF_SIZE | 0 | from | s32min-(-1),1-s32max |
| BUF_SIZE | 0 | from | s32min-(-1),1-s32max |
| BUF_SIZE | 5 | skb | 0-s32max |
| BUF_SIZE | 5 | skb | 0-s32max |
| DATA_SOURCE | 0 | from | $6 |
| FUZZY_MAX | 3 | len | 1 |
| FUZZY_MAX | 5 | skb->ip_summed | 3 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 0 | from->msg_iter.count | s64min-s64max |
| USER_DATA | 0 | from->msg_iter.iov_offset | s64min-s64max[c] |
| USER_DATA | 2 | offset | 1-s32max[c][u] |
| UNITS | 0 | from | unit_byte |
| UNITS | 1 | to | unit_byte |
| UNITS | 3 | len | unit_byte |
| UNITS | 4 | odd | unit_byte |
net/ipv4/ip_output.c __ip_append_data() -> __f1()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | to | 4096-ptr_max |
| PARAM_VALUE | 3 | len | 1-s32max |
| PARAM_VALUE | 5 | skb | 4096-ptr_max |
| PARAM_VALUE | 5 | skb->data_len | 0 |
| BUF_SIZE | 0 | from | s32min-(-1),1-s32max |
| BUF_SIZE | 0 | from | s32min-(-1),1-s32max |
| BUF_SIZE | 5 | skb | (-1)-s32max |
| BUF_SIZE | 5 | skb | (-1)-s32max |
| CAPPED_DATA | 3 | len | 1 |
| DATA_SOURCE | 0 | from | $6 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 0 | from->msg_iter.count | s64min-s64max |
| USER_DATA | 0 | from->msg_iter.iov_offset | s64min-s64max[c] |
| USER_DATA | 2 | offset | 1-s32max[c][u] |
| USER_DATA | 3 | len | 1-65543[c] |
| UNITS | 0 | from | unit_byte |
| UNITS | 3 | len | unit_byte |
| UNITS | 4 | odd | unit_byte |
net/ipv4/ip_output.c __ip_append_data() -> __f1()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 1 | to | 4096-ptr_max |
| PARAM_VALUE | 3 | len | 1-s32max |
| PARAM_VALUE | 5 | skb | 4096-ptr_max |
| PARAM_VALUE | 5 | skb->data_len | 0 |
| BUF_SIZE | 0 | from | s32min-(-1),1-s32max |
| BUF_SIZE | 0 | from | s32min-(-1),1-s32max |
| BUF_SIZE | 5 | skb | (-1)-s32max |
| BUF_SIZE | 5 | skb | (-1)-s32max |
| CAPPED_DATA | 3 | len | 1 |
| DATA_SOURCE | 0 | from | $6 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| USER_DATA | 0 | from->msg_iter.count | s64min-s64max |
| USER_DATA | 0 | from->msg_iter.iov_offset | s64min-s64max[c] |
| USER_DATA | 2 | offset | 1-s32max[c][u] |
| USER_DATA | 3 | len | 1-65543[c] |
| UNITS | 0 | from | unit_byte |
| UNITS | 3 | len | unit_byte |
| UNITS | 4 | odd | unit_byte |