Defined in 1 files as a prototype:
Defined in 1 files as a function:
Referenced in 6 files:
- drivers/acpi/acpi_ipmi.c, line 434
- drivers/char/ipmi/ipmi_devintf.c
- drivers/char/ipmi/ipmi_msghandler.c
- drivers/char/ipmi/ipmi_watchdog.c, line 887
- drivers/hwmon/ibmaem.c
- drivers/hwmon/ibmpex.c
Smatch caller information:
drivers/char/ipmi/ipmi_watchdog.c ipmi_wdog_msg_handler() -> ipmi_free_recv_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | msg | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->msg.data | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->user | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->user->destroyed.refs.counter | s32min-(-1),1-s32max |
| DATA_SOURCE | 0 | msg | $0 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NOCHECK_CALL | |||
| LOCK2 | &intf->user_msgs_mutex | ||
| TYPE_LOCK | (struct ipmi_smi)->user_msgs_mutex |
drivers/char/ipmi/ipmi_devintf.c handle_recv() -> ipmi_free_recv_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | msg | 4096-ptr_max |
| CAPPED_DATA | 0 | msg->msg.data_len | 1 |
| NOCHECK_CALL | |||
| USER_DATA | 0 | msg->msg.data_len | 0-65534[c] |
drivers/char/ipmi/ipmi_devintf.c ipmi_release() -> ipmi_free_recv_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | msg | 4096-ptr_max |
| CAPPED_DATA | 0 | &msg->link | 1 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NOCHECK_CALL |
drivers/hwmon/ibmaem.c aem_msg_handler() -> ipmi_free_recv_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | msg | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->user | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->user->destroyed.refs.counter | s32min-(-1),1-s32max |
| DATA_SOURCE | 0 | msg | $0 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NOCHECK_CALL | |||
| LOCK2 | &intf->user_msgs_mutex | ||
| TYPE_LOCK | (struct ipmi_smi)->user_msgs_mutex |
drivers/hwmon/ibmaem.c aem_msg_handler() -> ipmi_free_recv_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | msg | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->user | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->user->destroyed.refs.counter | s32min-(-1),1-s32max |
| CAPPED_DATA | 0 | msg->msgid | 1 |
| DATA_SOURCE | 0 | msg | $0 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NOCHECK_CALL | |||
| LOCK2 | &intf->user_msgs_mutex | ||
| TYPE_LOCK | (struct ipmi_smi)->user_msgs_mutex |
drivers/acpi/acpi_ipmi.c ipmi_msg_handler() -> ipmi_free_recv_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | msg | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->user | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->user->destroyed.refs.counter | s32min-(-1),1-s32max |
| CAPPED_DATA | 0 | msg->user | 1 |
| DATA_SOURCE | 0 | msg | $0 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NOCHECK_CALL | |||
| LOCK2 | &intf->user_msgs_mutex | ||
| TYPE_LOCK | (struct ipmi_smi)->user_msgs_mutex |
drivers/hwmon/ibmpex.c ibmpex_msg_handler() -> ipmi_free_recv_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | msg | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->user | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->user->destroyed.refs.counter | s32min-(-1),1-s32max |
| DATA_SOURCE | 0 | msg | $0 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NOCHECK_CALL | |||
| LOCK2 | &intf->user_msgs_mutex | ||
| TYPE_LOCK | (struct ipmi_smi)->user_msgs_mutex |
drivers/hwmon/ibmpex.c ibmpex_msg_handler() -> ipmi_free_recv_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | msg | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->user | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->user->destroyed.refs.counter | s32min-(-1),1-s32max |
| CAPPED_DATA | 0 | msg->msgid | 1 |
| DATA_SOURCE | 0 | msg | $0 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NOCHECK_CALL | |||
| LOCK2 | &intf->user_msgs_mutex | ||
| TYPE_LOCK | (struct ipmi_smi)->user_msgs_mutex |
drivers/char/ipmi/ipmi_msghandler.c _ipmi_destroy_user() -> ipmi_free_recv_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | msg | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->user | 4096-ptr_max |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NOCHECK_CALL | |||
| LOCK2 | &intf->seq_lock | ||
| LOCK2 | &intf->users_mutex | ||
| TYPE_LOCK | (struct ipmi_smi)->seq_lock | ||
| TYPE_LOCK | (struct ipmi_smi)->users_mutex |
drivers/char/ipmi/ipmi_msghandler.c _ipmi_destroy_user() -> ipmi_free_recv_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | msg | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->user | 4096-ptr_max |
| CAPPED_DATA | 0 | msg->user | 1 |
| CAPPED_DATA | 0 | &msg->link | 1 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NOCHECK_CALL | |||
| LOCK2 | &intf->user_msgs_mutex | ||
| LOCK2 | &intf->users_mutex | ||
| TYPE_LOCK | (struct ipmi_smi)->user_msgs_mutex | ||
| TYPE_LOCK | (struct ipmi_smi)->users_mutex |
drivers/char/ipmi/ipmi_msghandler.c deliver_response() -> ipmi_free_recv_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | msg | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->user | 0 |
| BUF_SIZE | 0 | msg->msg.data | (-1),272 |
| DATA_SOURCE | 0 | msg | $1 |
| PREEMPT_ADD | |||
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NOCHECK_CALL | |||
| USER_DATA | 0 | msg->user->gets_events | 1 |
drivers/char/ipmi/ipmi_msghandler.c deliver_response() -> ipmi_free_recv_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | msg | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->user | 1-u64max |
| BUF_SIZE | 0 | msg | (-1),384 |
| BUF_SIZE | 0 | msg | (-1),384 |
| BUF_SIZE | 0 | msg->msg.data | (-1),272 |
| DATA_SOURCE | 0 | msg | $1 |
| PREEMPT_ADD | |||
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NOCHECK_CALL | |||
| USER_DATA | 0 | msg->user->gets_events | 1 |
drivers/char/ipmi/ipmi_msghandler.c free_recv_msg_list() -> ipmi_free_recv_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | msg | 4096-ptr_max |
| CAPPED_DATA | 0 | &msg->link | 1 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NOCHECK_CALL |
drivers/char/ipmi/ipmi_msghandler.c handle_read_event_rsp() -> ipmi_free_recv_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | msg | 4096-ptr_max |
| PREEMPT_ADD | |||
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NOCHECK_CALL | |||
| LOCK2 | &intf->events_mutex | ||
| TYPE_LOCK | (struct ipmi_smi)->events_mutex |
drivers/char/ipmi/ipmi_msghandler.c i_ipmi_request() -> ipmi_free_recv_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | msg | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->done | 2945873742805610496 |
| PARAM_VALUE | 0 | msg->user | 0,4096-ptr_max |
| PARAM_VALUE | 0 | msg->user_msg_data | 0,4096-ptr_max |
| BUF_SIZE | 0 | msg | 384 |
| BUF_SIZE | 0 | msg->user_msg_data | s32min-(-1),1-s32max |
| DATA_SOURCE | 0 | msg | r ipmi_alloc_recv_msg |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NOCHECK_CALL | |||
| HALF_LOCKED2 | &bmc->dyn_mutex | ||
| HALF_LOCKED2 | &intf->bmc_reg_mutex |
drivers/char/ipmi/ipmi_msghandler.c i_ipmi_request() -> ipmi_free_recv_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | msg | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->done | 2945873742805610496 |
| PARAM_VALUE | 0 | msg->msg.data_len | 0-283 |
| PARAM_VALUE | 0 | msg->user | 0,4096-ptr_max |
| PARAM_VALUE | 0 | msg->user_msg_data | 0,4096-ptr_max |
| BUF_SIZE | 0 | msg | 384 |
| BUF_SIZE | 0 | msg->user_msg_data | s32min-(-1),1-s32max |
| DATA_SOURCE | 0 | msg | r ipmi_alloc_recv_msg |
| STR_LEN | 0 | msg->msg.data | (-1),3 |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NOCHECK_CALL | |||
| USER_DATA | 0 | msg->msg.cmd | 0-255 |
| USER_DATA | 0 | msg->msg.data_len | 0-272 |
| USER_DATA | 0 | msg->msg.netfn | 0-255 |
| USER_DATA | 0 | msg->msgid | s64min-s64max |
| USER_PTR | 0 | msg->msg.data | |
| HALF_LOCKED2 | &bmc->dyn_mutex | ||
| HALF_LOCKED2 | &intf->bmc_reg_mutex |
drivers/char/ipmi/ipmi_msghandler.c intf_free() -> ipmi_free_recv_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | msg | 1-u64max |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NOCHECK_CALL |
drivers/char/ipmi/ipmi_msghandler.c smi_work() -> ipmi_free_recv_msg()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | msg | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->user | 4096-ptr_max |
| PARAM_VALUE | 0 | msg->user->destroyed.refs.counter | 0 |
| CAPPED_DATA | 0 | &msg->link | 1 |
| PREEMPT_ADD | |||
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NOCHECK_CALL | |||
| LOCK2 | &intf->user_msgs_mutex | ||
| TYPE_LOCK | (struct ipmi_smi)->user_msgs_mutex |