Defined in 2 files as a function:
- arch/arm64/kvm/hyp/exception.c, line 297 (as a function)
- arch/x86/kvm/x86.c, line 7514 (as a function)
Referenced in 2 files:
Smatch caller information:
arch/x86/kvm/x86.c kvm_check_and_inject_events() -> kvm_inject_exception()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | vcpu | 4096-ptr_max |
| PARAM_VALUE | 0 | vcpu->____srcu_idx | 0-1 |
| PARAM_VALUE | 0 | vcpu->arch.apf.halted | 0 |
| PARAM_VALUE | 0 | vcpu->arch.apic->lapic_timer.timer.node.node.node.__rb_parent_color | 1 |
| PARAM_VALUE | 0 | vcpu->arch.apic->lapic_timer.timer_advance_ns | 0-5000 |
| PARAM_VALUE | 0 | vcpu->arch.apic->lapic_timer.timer_mode | 0,131072-393216 |
| PARAM_VALUE | 0 | vcpu->arch.apic->lapic_timer.timer_mode_mask | 131072,393216 |
| PARAM_VALUE | 0 | vcpu->arch.apic->vcpu->kvm->arch.apic_map->xapic_flat_map->lapic_timer.timer_mode | 0-4294967295 |
| PARAM_VALUE | 0 | vcpu->arch.apic->vcpu->kvm->arch.apicv_update_lock.first_waiter->handoff_set | 0-1 |
| PARAM_VALUE | 0 | vcpu->arch.apic->vcpu->kvm->arch.apicv_update_lock.first_waiter->type | 0-1 |
| PARAM_VALUE | 0 | vcpu->arch.at_instruction_boundary | 0 |
| PARAM_VALUE | 0 | vcpu->arch.complete_userspace_io | 0 |
| PARAM_VALUE | 0 | vcpu->arch.exception.injected | 1 |
| PARAM_VALUE | 0 | vcpu->arch.exception_from_userspace | 0 |
| PARAM_VALUE | 0 | vcpu->arch.guest_fpu.fpstate | 4096-ptr_max |
| PARAM_VALUE | 0 | vcpu->arch.mp_state | 0 |
| PARAM_VALUE | 0 | vcpu->arch.nested_run_pending | 0,2-255 |
| PARAM_VALUE | 0 | vcpu->arch.tsc_offset_adjustment | 0 |
| PARAM_VALUE | 0 | vcpu->cpu | 0 |
| PARAM_VALUE | 0 | vcpu->kvm | 4096-ptr_max |
| PARAM_VALUE | 0 | vcpu->kvm->arch.apicv_update_lock.first_waiter->handoff_set | 0-1 |
| PARAM_VALUE | 0 | vcpu->kvm->arch.apicv_update_lock.first_waiter->type | 0-1 |
| PARAM_VALUE | 0 | vcpu->kvm->arch.irqchip_mode | 0,2-u32max |
| PARAM_VALUE | 0 | vcpu->kvm->arch.kvmclock_update_rs.lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | vcpu->kvm->arch.kvmclock_update_rs.lock.owner | (-1) |
| PARAM_VALUE | 0 | vcpu->kvm->arch.kvmclock_update_rs.lock.owner_cpu | u32max |
| PARAM_VALUE | 0 | vcpu->kvm->srcu.srcu_ctrp | 4096-ptr_max |
| PARAM_VALUE | 0 | vcpu->mutex.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | vcpu->mutex.first_waiter->list.prev->next | 5159360019465732096 |
| PARAM_VALUE | 0 | vcpu->mutex.first_waiter->list.prev->prev | 5159360019465732096 |
| PARAM_VALUE | 0 | vcpu->mutex.osq.tail.counter | 0-s32max |
| PARAM_VALUE | 0 | vcpu->mutex.wait_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | vcpu->mutex.wait_lock.owner | (-1) |
| PARAM_VALUE | 0 | vcpu->mutex.wait_lock.owner_cpu | u32max |
| PARAM_VALUE | 0 | vcpu->preempt_notifier.link->pprev | 4096-ptr_max |
| PARAM_VALUE | 0 | vcpu->preempt_notifier.link.pprev | 4096-ptr_max |
| PARAM_VALUE | 0 | vcpu->requests | 0-1 |
| PARAM_VALUE | 0 | vcpu->run | 4096-ptr_max |
| PARAM_VALUE | 0 | vcpu->run->debug.arch.exception | 1,3 |
| PARAM_VALUE | 0 | vcpu->run->emulation_failure.flags | 0-1 |
| PARAM_VALUE | 0 | vcpu->run->emulation_failure.insn_size | 1-255 |
| PARAM_VALUE | 0 | vcpu->run->emulation_failure.ndata | 6,8,10,12 |
| PARAM_VALUE | 0 | vcpu->run->emulation_failure.suberror | 1 |
| PARAM_VALUE | 0 | vcpu->run->exit_reason | 0,10,39 |
| PARAM_VALUE | 0 | vcpu->run->flags | 0 |
| PARAM_VALUE | 0 | vcpu->run->hypercall.ret | 0-s32max,18446744071562067968-u64max |
| PARAM_VALUE | 0 | vcpu->run->hyperv.type | 0-3 |
| PARAM_VALUE | 0 | vcpu->run->internal.ndata | 0,2,4-5 |
| PARAM_VALUE | 0 | vcpu->run->internal.suberror | 1-4 |
| PARAM_VALUE | 0 | vcpu->run->memory_fault.flags | 0,8 |
| PARAM_VALUE | 0 | vcpu->run->memory_fault.gpa | 0,4096-18446744073709547520 |
| PARAM_VALUE | 0 | vcpu->run->memory_fault.size | 4096 |
| PARAM_VALUE | 0 | vcpu->run->mmio.is_write | 0-1 |
| PARAM_VALUE | 0 | vcpu->run->mmio.len | 0-8 |
| PARAM_VALUE | 0 | vcpu->run->request_interrupt_window | 1-255 |
| PARAM_VALUE | 0 | vcpu->run->system_event.ndata | 0-1,16 |
| PARAM_VALUE | 0 | vcpu->run->system_event.type | 2-3,6-7 |
| PARAM_VALUE | 0 | vcpu->wants_to_run | 1 |
| PARAM_VALUE | 0 | *vcpu->arch.apic->vcpu->kvm->arch.vioapic->irq_eoi | 0-4294967295 |
| BUF_SIZE | 0 | vcpu | s32min-(-2),1-s32max |
| BUF_SIZE | 0 | vcpu | s32min-(-2),1-s32max |
| CAPPED_DATA | 0 | vcpu->kvm | 1 |
| CAPPED_DATA | 0 | vcpu->kvm->mm | 1 |
| CAPPED_DATA | 0 | vcpu->kvm->srcu.srcu_ctrp | 1 |
| DATA_SOURCE | 0 | vcpu | $0 |
| FUZZY_MAX | 0 | vcpu->run->exit_reason | 0 |
| NOCHECK_CALL | |||
| HOST_DATA | 0 | vcpu->arch.host_debugctl | 0-u64max[c] |
| USER_DATA | 0 | vcpu->arch.apic->lapic_timer.expired_tscdeadline | 0-u64max |
| USER_DATA | 0 | vcpu->arch.apic->lapic_timer.tscdeadline | 0-u64max |
| USER_DATA | 0 | vcpu->arch.apic->sipi_vector | 1-255[c] |
| USER_DATA | 0 | vcpu->arch.cr8 | 0-14 |
| USER_DATA | 0 | vcpu->arch.exception.payload | 0-u64max |
| USER_DATA | 0 | vcpu->arch.l1_tsc_offset | 0-u64max |
| USER_DATA | 0 | vcpu->arch.tsc_offset | 0-u64max |
| USER_DATA | 0 | vcpu->arch.xen.runstate2_cache.gpa | 0-18446744073709551614[c] |
| USER_DATA | 0 | vcpu->arch.xen.runstate2_cache.pfn | 0-4503599627370494[c] |
| USER_DATA | 0 | vcpu->arch.xen.runstate2_cache.uhva | 0-u64max[c] |
| USER_DATA | 0 | vcpu->arch.xen.runstate_cache.gpa | 0-18446744073709551614[c] |
| USER_DATA | 0 | vcpu->arch.xen.runstate_cache.pfn | 0-4503599627370494[c] |
| USER_DATA | 0 | vcpu->arch.xen.runstate_cache.uhva | 0-u64max[c] |
| USER_DATA | 0 | vcpu->run->memory_fault.gpa | 0,4096-18446744073709547520[c] |
| USER_DATA | 0 | *vcpu->arch.emulate_ctxt->fetch.end | 0-255 |
| USER_DATA | 0 | *vcpu->arch.sev_pio_data | s64min-s64max |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_external_spt_cache.capacity | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_external_spt_cache.kmem_cache->object_size | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_external_spt_cache.kmem_cache->sheaf_capacity | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_external_spt_cache.nobjs | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_page_header_cache.capacity | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_page_header_cache.kmem_cache->object_size | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_page_header_cache.nobjs | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_pte_list_desc_cache.capacity | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_pte_list_desc_cache.kmem_cache->object_size | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_pte_list_desc_cache.kmem_cache->sheaf_capacity | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_pte_list_desc_cache.nobjs | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_shadow_page_cache.capacity | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_shadow_page_cache.kmem_cache->object_size | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_shadow_page_cache.nobjs | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_shadowed_info_cache.capacity | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_shadowed_info_cache.kmem_cache->object_size | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_shadowed_info_cache.nobjs | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.pio.count | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.pio.size | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->run->io.count | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->run->io.size | |
| USER_PTR | 0 | vcpu->arch.emulate_ctxt->fetch.end | |
| USER_PTR | 0 | vcpu->arch.pdptrs | |
| LOCK2 | 0 | &vcpu->kvm->srcu | |
| LOCK2 | 0 | &vcpu->mutex | |
| TYPE_LOCK | (struct kvm)->srcu | ||
| TYPE_LOCK | (struct kvm_vcpu)->mutex |
arch/x86/kvm/x86.c kvm_check_and_inject_events() -> kvm_inject_exception()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | vcpu | 4096-ptr_max |
| PARAM_VALUE | 0 | vcpu->____srcu_idx | 0-1 |
| PARAM_VALUE | 0 | vcpu->arch.apf.halted | 0 |
| PARAM_VALUE | 0 | vcpu->arch.apic->lapic_timer.timer.node.node.node.__rb_parent_color | 1 |
| PARAM_VALUE | 0 | vcpu->arch.apic->lapic_timer.timer_advance_ns | 0-5000 |
| PARAM_VALUE | 0 | vcpu->arch.apic->lapic_timer.timer_mode | 0,131072-393216 |
| PARAM_VALUE | 0 | vcpu->arch.apic->lapic_timer.timer_mode_mask | 131072,393216 |
| PARAM_VALUE | 0 | vcpu->arch.apic->vcpu->kvm->arch.apic_map->xapic_flat_map->lapic_timer.timer_mode | 0-4294967295 |
| PARAM_VALUE | 0 | vcpu->arch.apic->vcpu->kvm->arch.apicv_update_lock.first_waiter->handoff_set | 0-1 |
| PARAM_VALUE | 0 | vcpu->arch.apic->vcpu->kvm->arch.apicv_update_lock.first_waiter->type | 0-1 |
| PARAM_VALUE | 0 | vcpu->arch.at_instruction_boundary | 0 |
| PARAM_VALUE | 0 | vcpu->arch.complete_userspace_io | 0 |
| PARAM_VALUE | 0 | vcpu->arch.exception_from_userspace | 0 |
| PARAM_VALUE | 0 | vcpu->arch.exception_vmexit.pending | 0 |
| PARAM_VALUE | 0 | vcpu->arch.guest_fpu.fpstate | 4096-ptr_max |
| PARAM_VALUE | 0 | vcpu->arch.mp_state | 0 |
| PARAM_VALUE | 0 | vcpu->arch.nested_run_pending | 0,2-255 |
| PARAM_VALUE | 0 | vcpu->arch.tsc_offset_adjustment | 0 |
| PARAM_VALUE | 0 | vcpu->cpu | 0 |
| PARAM_VALUE | 0 | vcpu->kvm | 4096-ptr_max |
| PARAM_VALUE | 0 | vcpu->kvm->arch.apicv_update_lock.first_waiter->handoff_set | 0-1 |
| PARAM_VALUE | 0 | vcpu->kvm->arch.apicv_update_lock.first_waiter->type | 0-1 |
| PARAM_VALUE | 0 | vcpu->kvm->arch.irqchip_mode | 0,2-u32max |
| PARAM_VALUE | 0 | vcpu->kvm->arch.kvmclock_update_rs.lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | vcpu->kvm->arch.kvmclock_update_rs.lock.owner | (-1) |
| PARAM_VALUE | 0 | vcpu->kvm->arch.kvmclock_update_rs.lock.owner_cpu | u32max |
| PARAM_VALUE | 0 | vcpu->kvm->srcu.srcu_ctrp | 4096-ptr_max |
| PARAM_VALUE | 0 | vcpu->mutex.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | vcpu->mutex.first_waiter->list.prev->next | 5159360019465732096 |
| PARAM_VALUE | 0 | vcpu->mutex.first_waiter->list.prev->prev | 5159360019465732096 |
| PARAM_VALUE | 0 | vcpu->mutex.osq.tail.counter | 0-s32max |
| PARAM_VALUE | 0 | vcpu->mutex.wait_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | vcpu->mutex.wait_lock.owner | (-1) |
| PARAM_VALUE | 0 | vcpu->mutex.wait_lock.owner_cpu | u32max |
| PARAM_VALUE | 0 | vcpu->preempt_notifier.link->pprev | 4096-ptr_max |
| PARAM_VALUE | 0 | vcpu->preempt_notifier.link.pprev | 4096-ptr_max |
| PARAM_VALUE | 0 | vcpu->requests | 0-1 |
| PARAM_VALUE | 0 | vcpu->run | 4096-ptr_max |
| PARAM_VALUE | 0 | vcpu->run->debug.arch.exception | 1,3 |
| PARAM_VALUE | 0 | vcpu->run->emulation_failure.flags | 0-1 |
| PARAM_VALUE | 0 | vcpu->run->emulation_failure.insn_size | 1-255 |
| PARAM_VALUE | 0 | vcpu->run->emulation_failure.ndata | 6,8,10,12 |
| PARAM_VALUE | 0 | vcpu->run->emulation_failure.suberror | 1 |
| PARAM_VALUE | 0 | vcpu->run->exit_reason | 0,10,39 |
| PARAM_VALUE | 0 | vcpu->run->flags | 0 |
| PARAM_VALUE | 0 | vcpu->run->hypercall.ret | 0-s32max,18446744071562067968-u64max |
| PARAM_VALUE | 0 | vcpu->run->hyperv.type | 0-3 |
| PARAM_VALUE | 0 | vcpu->run->internal.ndata | 0,2,4-5 |
| PARAM_VALUE | 0 | vcpu->run->internal.suberror | 1-4 |
| PARAM_VALUE | 0 | vcpu->run->memory_fault.flags | 0,8 |
| PARAM_VALUE | 0 | vcpu->run->memory_fault.gpa | 0,4096-18446744073709547520 |
| PARAM_VALUE | 0 | vcpu->run->memory_fault.size | 4096 |
| PARAM_VALUE | 0 | vcpu->run->mmio.is_write | 0-1 |
| PARAM_VALUE | 0 | vcpu->run->mmio.len | 0-8 |
| PARAM_VALUE | 0 | vcpu->run->request_interrupt_window | 1-255 |
| PARAM_VALUE | 0 | vcpu->run->system_event.ndata | 0-1,16 |
| PARAM_VALUE | 0 | vcpu->run->system_event.type | 2-3,6-7 |
| PARAM_VALUE | 0 | vcpu->wants_to_run | 1 |
| PARAM_VALUE | 0 | *vcpu->arch.apic->vcpu->kvm->arch.vioapic->irq_eoi | 0-4294967295 |
| BUF_SIZE | 0 | vcpu | s32min-(-2),1-s32max |
| BUF_SIZE | 0 | vcpu | s32min-(-2),1-s32max |
| CAPPED_DATA | 0 | vcpu->kvm | 1 |
| CAPPED_DATA | 0 | vcpu->kvm->mm | 1 |
| CAPPED_DATA | 0 | vcpu->kvm->srcu.srcu_ctrp | 1 |
| DATA_SOURCE | 0 | vcpu | $0 |
| FUZZY_MAX | 0 | vcpu->run->exit_reason | 0 |
| NOCHECK_CALL | |||
| HOST_DATA | 0 | vcpu->arch.host_debugctl | 0-u64max[c] |
| USER_DATA | 0 | vcpu->arch.apic->lapic_timer.expired_tscdeadline | 0-u64max |
| USER_DATA | 0 | vcpu->arch.apic->lapic_timer.tscdeadline | 0-u64max |
| USER_DATA | 0 | vcpu->arch.apic->sipi_vector | 1-255[c] |
| USER_DATA | 0 | vcpu->arch.cr8 | 0-14 |
| USER_DATA | 0 | vcpu->arch.exception.payload | 0-u64max |
| USER_DATA | 0 | vcpu->arch.l1_tsc_offset | 0-u64max |
| USER_DATA | 0 | vcpu->arch.tsc_offset | 0-u64max |
| USER_DATA | 0 | vcpu->arch.xen.runstate2_cache.gpa | 0-18446744073709551614[c] |
| USER_DATA | 0 | vcpu->arch.xen.runstate2_cache.pfn | 0-4503599627370494[c] |
| USER_DATA | 0 | vcpu->arch.xen.runstate2_cache.uhva | 0-u64max[c] |
| USER_DATA | 0 | vcpu->arch.xen.runstate_cache.gpa | 0-18446744073709551614[c] |
| USER_DATA | 0 | vcpu->arch.xen.runstate_cache.pfn | 0-4503599627370494[c] |
| USER_DATA | 0 | vcpu->arch.xen.runstate_cache.uhva | 0-u64max[c] |
| USER_DATA | 0 | vcpu->run->memory_fault.gpa | 0,4096-18446744073709547520[c] |
| USER_DATA | 0 | *vcpu->arch.emulate_ctxt->fetch.end | 0-255 |
| USER_DATA | 0 | *vcpu->arch.sev_pio_data | s64min-s64max |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_external_spt_cache.capacity | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_external_spt_cache.kmem_cache->object_size | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_external_spt_cache.kmem_cache->sheaf_capacity | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_external_spt_cache.nobjs | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_page_header_cache.capacity | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_page_header_cache.kmem_cache->object_size | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_page_header_cache.nobjs | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_pte_list_desc_cache.capacity | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_pte_list_desc_cache.kmem_cache->object_size | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_pte_list_desc_cache.kmem_cache->sheaf_capacity | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_pte_list_desc_cache.nobjs | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_shadow_page_cache.capacity | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_shadow_page_cache.kmem_cache->object_size | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_shadow_page_cache.nobjs | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_shadowed_info_cache.capacity | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_shadowed_info_cache.kmem_cache->object_size | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.mmu_shadowed_info_cache.nobjs | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.pio.count | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->arch.pio.size | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->run->io.count | |
| NO_OVERFLOW_SIMPLE | 0 | vcpu->run->io.size | |
| USER_PTR | 0 | vcpu->arch.emulate_ctxt->fetch.end | |
| USER_PTR | 0 | vcpu->arch.pdptrs | |
| LOCK2 | 0 | &vcpu->kvm->srcu | |
| LOCK2 | 0 | &vcpu->mutex | |
| TYPE_LOCK | (struct kvm)->srcu | ||
| TYPE_LOCK | (struct kvm_vcpu)->mutex |