Defined in 1 files as a prototype:
Defined in 1 files as a function:
Referenced in 1 files:
Smatch caller information:
net/bluetooth/rfcomm/core.c __rfcomm_dlc_accept() -> (struct rfcomm_dlc)->state_change()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | dlc | 4096-ptr_max |
| PARAM_VALUE | 0 | dlc->lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | dlc->lock.first_waiter | 0,4096-ptr_max |
| PARAM_VALUE | 0 | dlc->lock.first_waiter->list.prev->next | 5159360019465732096 |
| PARAM_VALUE | 0 | dlc->lock.first_waiter->task->blocked_on | 0 |
| PARAM_VALUE | 0 | dlc->lock.osq.tail.counter | 0-s32max |
| PARAM_VALUE | 0 | dlc->lock.wait_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | dlc->lock.wait_lock.owner | (-1) |
| PARAM_VALUE | 0 | dlc->lock.wait_lock.owner_cpu | u32max |
| PARAM_VALUE | 0 | dlc->session->sock | 4096-ptr_max |
| PARAM_VALUE | 0 | dlc->session->sock->sk | 4096-ptr_max |
| PARAM_VALUE | 0 | dlc->session->sock->sk->__sk_common.skc_bind_node.pprev | 4096-ptr_max |
| PARAM_VALUE | 0 | dlc->session->sock->sk->__sk_common.skc_net.net->ipv4.ping_port_rover | 1-u16max |
| PARAM_VALUE | 0 | dlc->session->sock->sk->__sk_common.skc_node.pprev | 1-u64max |
| PARAM_VALUE | 0 | dlc->session->sock->sk->chan | 4096-ptr_max |
| PARAM_VALUE | 0 | dlc->session->sock->sk->ns_tracker->alloc_stack_handle | 0-4294967295 |
| PARAM_VALUE | 0 | dlc->session->sock->sk->ns_tracker->dead | 0-1 |
| PARAM_VALUE | 0 | dlc->session->sock->sk->ns_tracker->free_stack_handle | 0-4294967295 |
| PARAM_VALUE | 0 | dlc->session->sock->sk->sk_backlog.head | 0 |
| PARAM_VALUE | 0 | dlc->session->sock->sk->sk_backlog.head->extensions->refcnt.refs.counter | 1 |
| PARAM_VALUE | 0 | dlc->session->sock->sk->sk_backlog_rcv | 0-1770402027252219903,1770402027252219905-3047833183539765247,3047833183539765249-u64max |
| PARAM_VALUE | 0 | dlc->session->sock->sk->sk_bpf_storage->owner_refcnt.refs.counter | s32min-s32max |
| PARAM_VALUE | 0 | dlc->session->sock->sk->sk_filter->refcnt.refs.counter | s32min-s32max |
| PARAM_VALUE | 0 | dlc->session->sock->sk->sk_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | dlc->session->sock->sk->sk_lock.wq.head.prev->next->next | 4096-ptr_max |
| PARAM_VALUE | 0 | dlc->session->sock->sk->sk_reuseport_cb | 4096-ptr_max |
| PARAM_VALUE | 0 | dlc->session->sock->sk->sk_reuseport_cb->bind_inany | 0-1 |
| PARAM_VALUE | 0 | dlc->session->sock->sk->sk_reuseport_cb->has_conns | 0-1 |
| PARAM_VALUE | 0 | dlc->session->sock->sk->sk_reuseport_cb->incoming_cpu | 0-u16max |
| PARAM_VALUE | 0 | dlc->session->sock->sk->sk_reuseport_cb->max_socks | 0-u16max |
| PARAM_VALUE | 0 | dlc->session->sock->sk->sk_reuseport_cb->num_closed_socks | 0-u16max |
| PARAM_VALUE | 0 | dlc->session->sock->sk->sk_reuseport_cb->num_socks | 0-u16max |
| PARAM_VALUE | 0 | dlc->session->sock->sk->sk_reuseport_cb->rcu.next | 0 |
| PARAM_VALUE | 0 | dlc->session->sock->sk->sk_reuseport_cb->reuseport_id | 0-4294967295 |
| PARAM_VALUE | 0 | dlc->session->sock->sk->sk_reuseport_cb->synq_overflow_ts | 0-4294967295 |
| PARAM_VALUE | 0 | dlc->session->sock->sk->sk_user_data->work.flags | 0-4294967295 |
| PARAM_VALUE | 0 | dlc->session->sock->sk->sobject | 0-u16max |
| PARAM_VALUE | 0 | dlc->state | 1 |
| PARAM_VALUE | 0 | dlc->tx_queue.next->prev | 2011684551238094848 |
| PARAM_VALUE | 0 | dlc->tx_queue.prev->next | 2011684551238094848 |
| PARAM_VALUE | 0 | *dlc->session->sock->sk->sk_backlog.head->dev->name | 0-255 |
| PARAM_VALUE | 1 | err | 0 |
| CAPPED_DATA | 0 | dlc | 1 |
| CAPPED_DATA | 0 | &dlc->lock | 1 |
| DATA_SOURCE | 0 | dlc | $0 |
| CONTAINER | 0 | -432+0 | $(-1) |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NOCHECK_CALL | |||
| LOCK2 | global &rfcomm_mutex | ||
| LOCK2 | 0 | &dlc->lock | |
| TYPE_LOCK | (struct rfcomm_dlc)->lock |
net/bluetooth/rfcomm/core.c __rfcomm_dlc_close() -> (struct rfcomm_dlc)->state_change()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | dlc | 4096-ptr_max |
| PARAM_VALUE | 0 | dlc->lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | dlc->lock.first_waiter | 0,4096-ptr_max |
| PARAM_VALUE | 0 | dlc->lock.first_waiter->list.prev->next | 5159360019465732096 |
| PARAM_VALUE | 0 | dlc->lock.first_waiter->task->blocked_on | 0 |
| PARAM_VALUE | 0 | dlc->lock.osq.tail.counter | 0-s32max |
| PARAM_VALUE | 0 | dlc->lock.wait_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | dlc->lock.wait_lock.owner | (-1) |
| PARAM_VALUE | 0 | dlc->lock.wait_lock.owner_cpu | u32max |
| PARAM_VALUE | 0 | dlc->session->state | 3 |
| PARAM_VALUE | 0 | dlc->state | 9 |
| PARAM_VALUE | 0 | dlc->tx_queue.next->prev | 2011684551238094848 |
| PARAM_VALUE | 0 | dlc->tx_queue.prev->next | 2011684551238094848 |
| CAPPED_DATA | 0 | dlc | 1 |
| CAPPED_DATA | 0 | &dlc->lock | 1 |
| DATA_SOURCE | 0 | dlc | $0 |
| DATA_SOURCE | 1 | err | $1 |
| CONTAINER | 0 | -432+0 | $(-1) |
| RX_PATH | |||
| TASK_NOT_RUNNING | |||
| NOCHECK_CALL | |||
| LOCK2 | global &rfcomm_mutex | ||
| LOCK2 | 0 | &dlc->lock | |
| TYPE_LOCK | (struct rfcomm_dlc)->lock |
net/bluetooth/rfcomm/core.c rfcomm_check_accept() -> (struct rfcomm_dlc)->state_change()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | dlc | 4096-ptr_max |
| PARAM_VALUE | 0 | dlc->defer_setup | 1-u32max |
| PARAM_VALUE | 0 | dlc->dlci | 1-63 |
| PARAM_VALUE | 0 | dlc->lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | dlc->lock.first_waiter | 0,4096-ptr_max |
| PARAM_VALUE | 0 | dlc->lock.first_waiter->list.prev->next | 5159360019465732096 |
| PARAM_VALUE | 0 | dlc->lock.first_waiter->task->blocked_on | 0 |
| PARAM_VALUE | 0 | dlc->lock.osq.tail.counter | 0-s32max |
| PARAM_VALUE | 0 | dlc->lock.wait_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | dlc->lock.wait_lock.owner | (-1) |
| PARAM_VALUE | 0 | dlc->lock.wait_lock.owner_cpu | u32max |
| PARAM_VALUE | 0 | dlc->session | 4096-ptr_max |
| PARAM_VALUE | 0 | dlc->session->sock | 4096-ptr_max |
| PARAM_VALUE | 0 | dlc->session->sock->sk | 4096-ptr_max |
| PARAM_VALUE | 0 | dlc->session->sock->sk->chan | 4096-ptr_max |
| PARAM_VALUE | 0 | dlc->session->sock->sk->chan->conn | 4096-ptr_max |
| PARAM_VALUE | 0 | dlc->session->sock->sk->chan->conn->hcon | 4096-ptr_max |
| PARAM_VALUE | 0 | dlc->session->sock->sk->chan->conn->hcon->l2cap_data->smp->lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | dlc->session->sock->sk->chan->conn->hcon->l2cap_data->smp->lock.osq.tail.counter | s32min-s32max |
| PARAM_VALUE | 0 | dlc->session->sock->sk->chan->conn->hcon->pending_sec_level | 0-255 |
| PARAM_VALUE | 0 | dlc->state | 6 |
| PARAM_VALUE | 0 | dlc->timer.entry->pprev | 4096-ptr_max |
| PARAM_VALUE | 0 | dlc->timer.entry.pprev | 0,4096-ptr_max |
| PARAM_VALUE | 1 | err | 0 |
| CAPPED_DATA | 0 | dlc->dlci | 1 |
| CAPPED_DATA | 0 | &dlc->lock | 1 |
| DATA_SOURCE | 0 | dlc | $0 |
| CONTAINER | 0 | -432+0 | $(-1) |
| NOSPEC | 0 | dlc->dlci | |
| NOCHECK_CALL | |||
| USER_DATA | 0 | dlc->addr | 0-255[c] |
| USER_DATA | 0 | dlc->dlci | 1-63[c] |
| LOCK2 | global &rfcomm_mutex | ||
| LOCK2 | 0 | &dlc->lock | |
| TYPE_LOCK | (struct rfcomm_dlc)->lock |
net/bluetooth/rfcomm/core.c rfcomm_process_dlcs() -> (struct rfcomm_dlc)->state_change()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | dlc | 4096-ptr_max |
| PARAM_VALUE | 0 | dlc->defer_setup | 1-u32max |
| PARAM_VALUE | 0 | dlc->lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | dlc->lock.first_waiter | 0,4096-ptr_max |
| PARAM_VALUE | 0 | dlc->lock.first_waiter->list.prev->next | 5159360019465732096 |
| PARAM_VALUE | 0 | dlc->lock.osq.tail.counter | 0-s32max |
| PARAM_VALUE | 0 | dlc->lock.wait_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | dlc->lock.wait_lock.owner | (-1) |
| PARAM_VALUE | 0 | dlc->lock.wait_lock.owner_cpu | u32max |
| PARAM_VALUE | 0 | dlc->out | 0 |
| PARAM_VALUE | 0 | dlc->state | 6 |
| PARAM_VALUE | 0 | dlc->timer.entry->pprev | 4096-ptr_max |
| PARAM_VALUE | 0 | dlc->timer.entry.pprev | 0,4096-ptr_max |
| PARAM_VALUE | 1 | err | 0 |
| CAPPED_DATA | 0 | dlc | 1 |
| CAPPED_DATA | 0 | &dlc->list | 1 |
| CAPPED_DATA | 0 | &dlc->lock | 1 |
| CONTAINER | 0 | -432+0 | $(-1) |
| NOCHECK_CALL | |||
| LOCK2 | global &rfcomm_mutex | ||
| LOCK2 | 0 | &dlc->lock | |
| TYPE_LOCK | (struct rfcomm_dlc)->lock |
net/bluetooth/rfcomm/core.c rfcomm_recv_ua() -> (struct rfcomm_dlc)->state_change()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | dlc | 4096-ptr_max |
| PARAM_VALUE | 0 | dlc->lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | dlc->lock.first_waiter | 0,4096-ptr_max |
| PARAM_VALUE | 0 | dlc->lock.first_waiter->list.prev->next | 5159360019465732096 |
| PARAM_VALUE | 0 | dlc->lock.first_waiter->task->blocked_on | 0 |
| PARAM_VALUE | 0 | dlc->lock.osq.tail.counter | 0-s32max |
| PARAM_VALUE | 0 | dlc->lock.wait_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | dlc->lock.wait_lock.owner | (-1) |
| PARAM_VALUE | 0 | dlc->lock.wait_lock.owner_cpu | u32max |
| PARAM_VALUE | 0 | dlc->state | 1 |
| PARAM_VALUE | 0 | dlc->tx_queue.next->prev | 2011684551238094848 |
| PARAM_VALUE | 0 | dlc->tx_queue.prev->next | 2011684551238094848 |
| PARAM_VALUE | 1 | err | 0 |
| CAPPED_DATA | 0 | dlc | 1 |
| CAPPED_DATA | 0 | &dlc->lock | 1 |
| DATA_SOURCE | 0 | dlc | r rfcomm_dlc_get |
| CONTAINER | 0 | -432+0 | $(-1) |
| NOCHECK_CALL | |||
| LOCK2 | global &rfcomm_mutex | ||
| LOCK2 | 0 | &dlc->lock | |
| TYPE_LOCK | (struct rfcomm_dlc)->lock |