Defined in 1 files as a struct:

Defined in 3 files as a member:

Defined in 1 files as a function:

Referenced in 90 files:

Smatch caller information:

kernel/bpf/verifier.c check_atomic_load() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
DATA_SOURCE 0 env $0

kernel/bpf/verifier.c check_atomic_rmw() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
DATA_SOURCE 0 env $0

kernel/bpf/verifier.c check_atomic_store() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
DATA_SOURCE 0 env $0
NO_OVERFLOW_SIMPLE 0 env->cur_state->jmp_history_cnt

kernel/bpf/verifier.c check_func_arg() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
PARAM_VALUE 1 regno 1-5
DATA_SOURCE 0 env $0

kernel/bpf/verifier.c check_func_arg() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
PARAM_VALUE 1 regno 0-4
CAPPED_DATA 0 env->cur_state->acquired_refs 1
DATA_SOURCE 0 env $0

kernel/bpf/verifier.c check_func_arg() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
PARAM_VALUE 1 regno 0-4
CAPPED_DATA 0 env->cur_state->acquired_refs 1
DATA_SOURCE 0 env $0

kernel/bpf/verifier.c check_global_subprog_return_code() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
PARAM_VALUE 0 env->cur_state->frame 4096-ptr_max
PARAM_VALUE 1 regno 0
CAPPED_DATA 0 env->prog->aux->btf->start_id 1
CAPPED_DATA 0 env->prog->len 1
DATA_SOURCE 0 env $0

kernel/bpf/verifier.c check_indirect_jump() -> reg_state()

Type Parameter Key Value
DATA_SOURCE 0 env $0

kernel/bpf/verifier.c check_map_kptr_access() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
DATA_SOURCE 0 env $0
DATA_SOURCE 1 regno $1
STR_LEN 0 env (-1),3,11
STR_LEN 0 env (-1),3,11
NO_OVERFLOW_SIMPLE 0 env->cur_state->jmp_history_cnt

kernel/bpf/verifier.c check_reference_leak() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
PARAM_VALUE 1 regno 0
DATA_SOURCE 0 env $0
STR_LEN 0 env 9,16
STR_LEN 0 env 9,16
NO_OVERFLOW_SIMPLE 0 env->cur_state->jmp_history_cnt

kernel/bpf/verifier.c check_return_code() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
PARAM_VALUE 1 regno 0-1
DATA_SOURCE 0 env $0
DATA_SOURCE 1 regno $1
STR_LEN 0 env 2
STR_LEN 0 env 2
HARD_MAX 1 regno 1

kernel/bpf/verifier.c indirect_jump_min_max_index() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
DATA_SOURCE 0 env $0
DATA_SOURCE 1 regno $1

kernel/bpf/verifier.c is_arena_reg() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
DATA_SOURCE 0 env $0
DATA_SOURCE 1 regno $1

kernel/bpf/verifier.c is_ctx_reg() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
DATA_SOURCE 0 env $0
DATA_SOURCE 1 regno $1

kernel/bpf/verifier.c is_flow_key_reg() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
DATA_SOURCE 0 env $0
DATA_SOURCE 1 regno $1

kernel/bpf/verifier.c is_load_acq_unsafe() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
DATA_SOURCE 0 env $0
DATA_SOURCE 1 regno $1

kernel/bpf/verifier.c is_pkt_reg() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
DATA_SOURCE 0 env $0
DATA_SOURCE 1 regno $1

kernel/bpf/verifier.c is_pointer_value() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
DATA_SOURCE 0 env $0
DATA_SOURCE 1 regno $1
STR_LEN 0 env (-1),2-3,11
STR_LEN 0 env (-1),2-3,11
NO_OVERFLOW_SIMPLE 0 env->cur_state->jmp_history_cnt

kernel/bpf/verifier.c is_sk_reg() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
DATA_SOURCE 0 env $0
DATA_SOURCE 1 regno $1

kernel/bpf/verifier.c loop_flag_is_zero() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
PARAM_VALUE 1 regno 4
DATA_SOURCE 0 env $0
NO_OVERFLOW_SIMPLE 0 env->cur_state->jmp_history_cnt

kernel/bpf/verifier.c mark_uptr_ld_reg() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
DATA_SOURCE 0 env $0
DATA_SOURCE 1 regno $1
STR_LEN 0 env (-1),11
STR_LEN 0 env (-1),11
NO_OVERFLOW_SIMPLE 0 env->cur_state->jmp_history_cnt

kernel/bpf/verifier.c process_kptr_func() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
PARAM_VALUE 1 regno 1-5
CAPPED_DATA 0 env->cur_state->acquired_refs 1
DATA_SOURCE 0 env $0
DATA_SOURCE 1 regno $1
NO_OVERFLOW_SIMPLE 0 env->cur_state->jmp_history_cnt

kernel/bpf/verifier.c record_func_key() -> reg_state()

Type Parameter Key Value
PARAM_VALUE 0 env 4096-ptr_max
PARAM_VALUE 0 env->cur_state 4096-ptr_max
PARAM_VALUE 1 regno 3
DATA_SOURCE 0 env $0