Defined in 1 files as a function:
Referenced in 1 files:
Smatch caller information:
mm/userfaultfd.c userfaultfd_continue() -> wake_userfault()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | ctx | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->map_changing_lock.first_waiter->handoff_set | 0-1 |
| PARAM_VALUE | 0 | ctx->map_changing_lock.first_waiter->type | 0-1 |
| PARAM_VALUE | 0 | ctx->mm | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->context.ldt | 0 |
| PARAM_VALUE | 0 | ctx->mm->exe_file | 0 |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->process_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->process_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->rcu.func | 1-u64max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->request_key_auth->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->request_key_auth->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->session_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->session_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->thread_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->thread_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->ucounts->ns->work.entry.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->user_ns->work.entry.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_task_work.func | 5179756662909861888 |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_task_work.next | 0-7661163036167163903,7661163036167163905-u64max |
| PARAM_VALUE | 0 | ctx->mm->ioctx_table | 0 |
| PARAM_VALUE | 0 | ctx->mm->lru_gen.list.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->lru_gen.list.prev->next | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->mm_cid.pcpu | 0 |
| PARAM_VALUE | 0 | ctx->mm->mm_id | 0 |
| PARAM_VALUE | 0 | ctx->mm->mm_mt.ma_lock.rlock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | ctx->mm->mm_mt.ma_root | 0 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->handoff_set | 0-1 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->list.next | 2212933610777083904,2624917664208203776 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->list.prev | 2212933610777083904,2624917664208203776 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->type | 0-1 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.osq.tail.counter | 0-s32max |
| PARAM_VALUE | 0 | ctx->mm->notifier_subscriptions | 0 |
| PARAM_VALUE | 0 | ctx->mm->sc_stat.pcpu_sched | 0 |
| PARAM_VALUE | 0 | ctx->mm->task_size | 1-u64max |
| PARAM_VALUE | 0 | ctx->mmap_changing.counter | 0 |
| PARAM_VALUE | 0 | *ctx->mm->exe_file->f_cred->user->uidhash_node.next->pprev | 1-u64max |
| PARAM_VALUE | 1 | range | 5674392698514534400 |
| PARAM_VALUE | 1 | range->len | 0,4096-9223372036854775807 |
| PARAM_VALUE | 1 | range->start | 0-18446744073709551614 |
| BUF_SIZE | 0 | ctx | s32min-(-2),1-s32max |
| BUF_SIZE | 0 | ctx | s32min-(-2),1-s32max |
| CAPPED_DATA | 0 | ctx->mm->task_size | 1 |
| DATA_SOURCE | 0 | ctx | $0 |
| NOCHECK_CALL | |||
| USER_DATA | 1 | range->start | 0-18446744073709551614[c] |
| NO_OVERFLOW_SIMPLE | 1 | range->start |
mm/userfaultfd.c userfaultfd_copy() -> wake_userfault()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | ctx | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->map_changing_lock.first_waiter->handoff_set | 0-1 |
| PARAM_VALUE | 0 | ctx->map_changing_lock.first_waiter->type | 0-1 |
| PARAM_VALUE | 0 | ctx->mm | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->context.ldt | 0 |
| PARAM_VALUE | 0 | ctx->mm->exe_file | 0 |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->process_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->process_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->rcu.func | 1-u64max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->request_key_auth->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->request_key_auth->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->session_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->session_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->thread_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->thread_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->ucounts->ns->work.entry.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->user_ns->work.entry.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_task_work.func | 5179756662909861888 |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_task_work.next | 0-7661163036167163903,7661163036167163905-u64max |
| PARAM_VALUE | 0 | ctx->mm->ioctx_table | 0 |
| PARAM_VALUE | 0 | ctx->mm->lru_gen.list.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->lru_gen.list.prev->next | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->mm_cid.pcpu | 0 |
| PARAM_VALUE | 0 | ctx->mm->mm_id | 0 |
| PARAM_VALUE | 0 | ctx->mm->mm_mt.ma_lock.rlock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | ctx->mm->mm_mt.ma_root | 0 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->handoff_set | 0-1 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->list.next | 2212933610777083904,2624917664208203776 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->list.prev | 2212933610777083904,2624917664208203776 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->type | 0-1 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.osq.tail.counter | 0-s32max |
| PARAM_VALUE | 0 | ctx->mm->notifier_subscriptions | 0 |
| PARAM_VALUE | 0 | ctx->mm->sc_stat.pcpu_sched | 0 |
| PARAM_VALUE | 0 | ctx->mm->task_size | 1-u64max |
| PARAM_VALUE | 0 | ctx->mmap_changing.counter | 0 |
| PARAM_VALUE | 0 | *ctx->mm->exe_file->f_cred->user->uidhash_node.next->pprev | 1-u64max |
| PARAM_VALUE | 1 | range | 5926806938084950016 |
| PARAM_VALUE | 1 | range->len | 0,4096-9223372036854775807 |
| PARAM_VALUE | 1 | range->start | 0-18446744073709551614 |
| BUF_SIZE | 0 | ctx | s32min-(-2),1-s32max |
| BUF_SIZE | 0 | ctx | s32min-(-2),1-s32max |
| CAPPED_DATA | 0 | ctx->mm->task_size | 1 |
| DATA_SOURCE | 0 | ctx | $0 |
| NOCHECK_CALL | |||
| USER_DATA | 1 | range->start | 0-18446744073709551614[c] |
| NO_OVERFLOW_SIMPLE | 1 | range->start |
mm/userfaultfd.c userfaultfd_move() -> wake_userfault()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | ctx | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->map_changing_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | ctx->map_changing_lock.first_waiter->handoff_set | 1 |
| PARAM_VALUE | 0 | ctx->map_changing_lock.first_waiter->list.next | 2212933610777083904 |
| PARAM_VALUE | 0 | ctx->map_changing_lock.first_waiter->list.prev | 2212933610777083904 |
| PARAM_VALUE | 0 | ctx->map_changing_lock.first_waiter->type | 0-1 |
| PARAM_VALUE | 0 | ctx->mm | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->context.ldt | 0 |
| PARAM_VALUE | 0 | ctx->mm->exe_file | 0 |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->process_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->process_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->rcu.func | 1-u64max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->request_key_auth->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->request_key_auth->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->session_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->session_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->thread_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->thread_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->ucounts->ns->work.entry.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->user_ns->work.entry.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_task_work.func | 5179756662909861888 |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_task_work.next | 0-7661163036167163903,7661163036167163905-u64max |
| PARAM_VALUE | 0 | ctx->mm->ioctx_table | 0 |
| PARAM_VALUE | 0 | ctx->mm->lru_gen.list.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->lru_gen.list.prev->next | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->mm_cid.pcpu | 0 |
| PARAM_VALUE | 0 | ctx->mm->mm_id | 0 |
| PARAM_VALUE | 0 | ctx->mm->mm_mt.ma_lock.rlock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | ctx->mm->mm_mt.ma_root | 0 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->handoff_set | 0-1 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->list.next | 2212933610777083904,2624917664208203776 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->list.prev | 2212933610777083904,2624917664208203776 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->type | 0-1 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.osq.tail.counter | 0-s32max |
| PARAM_VALUE | 0 | ctx->mm->notifier_subscriptions | 0 |
| PARAM_VALUE | 0 | ctx->mm->page_table_lock.rlock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | ctx->mm->sc_stat.pcpu_sched | 0 |
| PARAM_VALUE | 0 | ctx->mm->task_size | 1-u64max |
| PARAM_VALUE | 0 | ctx->mmap_changing.counter | 0 |
| PARAM_VALUE | 0 | *ctx->mm->exe_file->f_cred->user->uidhash_node.next->pprev | 1-u64max |
| PARAM_VALUE | 1 | range | 2938025146406608896 |
| PARAM_VALUE | 1 | range->len | 0-9223372036854775807 |
| PARAM_VALUE | 1 | range->start | 0-18446744073709551614 |
| BUF_SIZE | 0 | ctx | s32min-(-2),1-s32max |
| BUF_SIZE | 0 | ctx | s32min-(-2),1-s32max |
| CAPPED_DATA | 0 | ctx | 1 |
| CAPPED_DATA | 0 | ctx->mm | 1 |
| DATA_SOURCE | 0 | ctx | $0 |
| NOCHECK_CALL | |||
| USER_DATA | 1 | range->start | 0-18446744073709551614[c] |
| NO_OVERFLOW_SIMPLE | 1 | range->start | |
| UNITS | 0 | ctx | unit_byte |
mm/userfaultfd.c userfaultfd_poison() -> wake_userfault()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | ctx | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->map_changing_lock.first_waiter->handoff_set | 0-1 |
| PARAM_VALUE | 0 | ctx->map_changing_lock.first_waiter->type | 0-1 |
| PARAM_VALUE | 0 | ctx->mm | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->context.ldt | 0 |
| PARAM_VALUE | 0 | ctx->mm->exe_file | 0 |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->process_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->process_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->rcu.func | 1-u64max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->request_key_auth->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->request_key_auth->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->session_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->session_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->thread_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->thread_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->ucounts->ns->work.entry.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->user_ns->work.entry.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_task_work.func | 5179756662909861888 |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_task_work.next | 0-7661163036167163903,7661163036167163905-u64max |
| PARAM_VALUE | 0 | ctx->mm->ioctx_table | 0 |
| PARAM_VALUE | 0 | ctx->mm->lru_gen.list.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->lru_gen.list.prev->next | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->mm_cid.pcpu | 0 |
| PARAM_VALUE | 0 | ctx->mm->mm_id | 0 |
| PARAM_VALUE | 0 | ctx->mm->mm_mt.ma_lock.rlock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | ctx->mm->mm_mt.ma_root | 0 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->handoff_set | 0-1 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->list.next | 2212933610777083904,2624917664208203776 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->list.prev | 2212933610777083904,2624917664208203776 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->type | 0-1 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.osq.tail.counter | 0-s32max |
| PARAM_VALUE | 0 | ctx->mm->notifier_subscriptions | 0 |
| PARAM_VALUE | 0 | ctx->mm->sc_stat.pcpu_sched | 0 |
| PARAM_VALUE | 0 | ctx->mm->task_size | 1-u64max |
| PARAM_VALUE | 0 | ctx->mmap_changing.counter | 0 |
| PARAM_VALUE | 0 | *ctx->mm->exe_file->f_cred->user->uidhash_node.next->pprev | 1-u64max |
| PARAM_VALUE | 1 | range | 5808395638298644480 |
| PARAM_VALUE | 1 | range->len | 0,4096-9223372036854775807 |
| PARAM_VALUE | 1 | range->start | 0-18446744073709551614 |
| BUF_SIZE | 0 | ctx | s32min-(-2),1-s32max |
| BUF_SIZE | 0 | ctx | s32min-(-2),1-s32max |
| CAPPED_DATA | 0 | ctx->mm->task_size | 1 |
| DATA_SOURCE | 0 | ctx | $0 |
| NOCHECK_CALL | |||
| USER_DATA | 1 | range->start | 0-18446744073709551614[c] |
| NO_OVERFLOW_SIMPLE | 1 | range->start |
mm/userfaultfd.c userfaultfd_rwprotect() -> wake_userfault()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | ctx | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->context.ldt | 0 |
| PARAM_VALUE | 0 | ctx->mm->exe_file | 0 |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->process_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->process_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->rcu.func | 1-u64max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->request_key_auth->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->request_key_auth->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->session_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->session_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->thread_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->thread_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->ucounts->ns->work.entry.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->user_ns->work.entry.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_task_work.func | 5179756662909861888 |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_task_work.next | 0-7661163036167163903,7661163036167163905-u64max |
| PARAM_VALUE | 0 | ctx->mm->ioctx_table | 0 |
| PARAM_VALUE | 0 | ctx->mm->lru_gen.list.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->lru_gen.list.prev->next | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->mm_cid.pcpu | 0 |
| PARAM_VALUE | 0 | ctx->mm->mm_id | 0 |
| PARAM_VALUE | 0 | ctx->mm->mm_mt.ma_lock.rlock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | ctx->mm->mm_mt.ma_root | 0 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->handoff_set | 1 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->list.next | 2212933610777083904,2624917664208203776 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->list.prev | 2212933610777083904,2624917664208203776 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->type | 0-1 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.osq.tail.counter | 0-s32max |
| PARAM_VALUE | 0 | ctx->mm->notifier_subscriptions | 0 |
| PARAM_VALUE | 0 | ctx->mm->sc_stat.pcpu_sched | 0 |
| PARAM_VALUE | 0 | ctx->mm->task_size | 1-u64max |
| PARAM_VALUE | 0 | ctx->mmap_changing.counter | 0 |
| PARAM_VALUE | 0 | *ctx->mm->exe_file->f_cred->user->uidhash_node.next->pprev | 1-u64max |
| PARAM_VALUE | 1 | range | 6539811957199052800 |
| PARAM_VALUE | 1 | range->len | 1-u64max |
| PARAM_VALUE | 1 | range->start | 0-18446744073709551614 |
| BUF_SIZE | 0 | ctx | s32min-(-2),1-s32max |
| BUF_SIZE | 0 | ctx | s32min-(-2),1-s32max |
| CAPPED_DATA | 0 | ctx->mm->task_size | 1 |
| DATA_SOURCE | 0 | ctx | $0 |
| NOSPEC | 1 | range->len | |
| NOSPEC | 1 | range->start | |
| NOCHECK_CALL | |||
| USER_DATA | 1 | range->len | 1-u64max[c] |
| USER_DATA | 1 | range->start | 0-18446744073709551614[c] |
| NO_OVERFLOW_SIMPLE | 1 | range->len | |
| NO_OVERFLOW_SIMPLE | 1 | range->start |
mm/userfaultfd.c userfaultfd_unregister() -> wake_userfault()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | ctx | 1-u64max |
| PARAM_VALUE | 1 | range | 4419322055644729344 |
| NOSPEC | 1 | range->start | |
| NOCHECK_CALL | |||
| USER_DATA | 1 | range->start | 0-18446744073709551614[c] |
| NO_OVERFLOW_SIMPLE | 1 | range->start | |
| UNITS | 0 | ctx | unit_byte |
| LOCK2 | &mm->mmap_lock | ||
| TYPE_LOCK | (struct mm_struct)->mmap_lock |
mm/userfaultfd.c userfaultfd_wake() -> wake_userfault()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | ctx | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->task_size | 1-u64max |
| PARAM_VALUE | 1 | range | 1745586174167207936 |
| PARAM_VALUE | 1 | range->len | 1-u64max |
| PARAM_VALUE | 1 | range->start | 0-18446744073709551614 |
| BUF_SIZE | 0 | ctx | s32min-(-2),1-s32max |
| BUF_SIZE | 0 | ctx | s32min-(-2),1-s32max |
| CAPPED_DATA | 0 | ctx->mm->task_size | 1 |
| DATA_SOURCE | 0 | ctx | $0 |
| NOCHECK_CALL | |||
| USER_DATA | 1 | range->len | 1-u64max[c] |
| USER_DATA | 1 | range->start | 0-18446744073709551614[c] |
| NO_OVERFLOW_SIMPLE | 1 | range->len | |
| NO_OVERFLOW_SIMPLE | 1 | range->start |
mm/userfaultfd.c userfaultfd_writeprotect() -> wake_userfault()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | ctx | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->map_changing_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | ctx->map_changing_lock.first_waiter->handoff_set | 1 |
| PARAM_VALUE | 0 | ctx->map_changing_lock.first_waiter->list.next | 2212933610777083904 |
| PARAM_VALUE | 0 | ctx->map_changing_lock.first_waiter->list.prev | 2212933610777083904 |
| PARAM_VALUE | 0 | ctx->map_changing_lock.first_waiter->type | 0-1 |
| PARAM_VALUE | 0 | ctx->mm | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->context.ldt | 0 |
| PARAM_VALUE | 0 | ctx->mm->exe_file | 0 |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->process_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->process_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->rcu.func | 1-u64max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->request_key_auth->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->request_key_auth->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->session_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->session_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->thread_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->thread_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->ucounts->ns->work.entry.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->user_ns->work.entry.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_task_work.func | 5179756662909861888 |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_task_work.next | 0-7661163036167163903,7661163036167163905-u64max |
| PARAM_VALUE | 0 | ctx->mm->ioctx_table | 0 |
| PARAM_VALUE | 0 | ctx->mm->lru_gen.list.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->lru_gen.list.prev->next | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->mm_cid.pcpu | 0 |
| PARAM_VALUE | 0 | ctx->mm->mm_id | 0 |
| PARAM_VALUE | 0 | ctx->mm->mm_mt.ma_lock.rlock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | ctx->mm->mm_mt.ma_root | 0 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->handoff_set | 1 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->list.next | 2212933610777083904,2624917664208203776 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->list.prev | 2212933610777083904,2624917664208203776 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->type | 0-1 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.osq.tail.counter | 0-s32max |
| PARAM_VALUE | 0 | ctx->mm->notifier_subscriptions | 0 |
| PARAM_VALUE | 0 | ctx->mm->sc_stat.pcpu_sched | 0 |
| PARAM_VALUE | 0 | ctx->mm->task_size | 1-u64max |
| PARAM_VALUE | 0 | ctx->mmap_changing.counter | 0 |
| PARAM_VALUE | 0 | *ctx->mm->exe_file->f_cred->user->uidhash_node.next->pprev | 1-u64max |
| PARAM_VALUE | 1 | range | 6630017992706576384 |
| PARAM_VALUE | 1 | range->len | 1-u64max |
| PARAM_VALUE | 1 | range->start | 0-18446744073709551614 |
| BUF_SIZE | 0 | ctx | s32min-(-2),1-s32max |
| BUF_SIZE | 0 | ctx | s32min-(-2),1-s32max |
| CAPPED_DATA | 0 | ctx->mm->task_size | 1 |
| DATA_SOURCE | 0 | ctx | $0 |
| NOSPEC | 1 | range->len | |
| NOSPEC | 1 | range->start | |
| NOCHECK_CALL | |||
| USER_DATA | 1 | range->len | 1-u64max[c] |
| USER_DATA | 1 | range->start | 0-18446744073709551614[c] |
| NO_OVERFLOW_SIMPLE | 1 | range->len | |
| NO_OVERFLOW_SIMPLE | 1 | range->start |
mm/userfaultfd.c userfaultfd_zeropage() -> wake_userfault()
| Type | Parameter | Key | Value |
|---|---|---|---|
| PARAM_VALUE | 0 | ctx | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->map_changing_lock.first_waiter->handoff_set | 0-1 |
| PARAM_VALUE | 0 | ctx->map_changing_lock.first_waiter->type | 0-1 |
| PARAM_VALUE | 0 | ctx->mm | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->context.ldt | 0 |
| PARAM_VALUE | 0 | ctx->mm->exe_file | 0 |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->process_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->process_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->rcu.func | 1-u64max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->request_key_auth->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->request_key_auth->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->session_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->session_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->thread_keyring->user->qnbytes | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->thread_keyring->user->qnkeys | s32min-s32max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->ucounts->ns->work.entry.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_cred->user_ns->work.entry.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_task_work.func | 5179756662909861888 |
| PARAM_VALUE | 0 | ctx->mm->exe_file->f_task_work.next | 0-7661163036167163903,7661163036167163905-u64max |
| PARAM_VALUE | 0 | ctx->mm->ioctx_table | 0 |
| PARAM_VALUE | 0 | ctx->mm->lru_gen.list.next->prev | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->lru_gen.list.prev->next | 4096-ptr_max |
| PARAM_VALUE | 0 | ctx->mm->mm_cid.pcpu | 0 |
| PARAM_VALUE | 0 | ctx->mm->mm_id | 0 |
| PARAM_VALUE | 0 | ctx->mm->mm_mt.ma_lock.rlock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | ctx->mm->mm_mt.ma_root | 0 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.dep_map->name | 0-255 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->handoff_set | 0-1 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->list.next | 2212933610777083904,2624917664208203776 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->list.prev | 2212933610777083904,2624917664208203776 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.first_waiter->type | 0-1 |
| PARAM_VALUE | 0 | ctx->mm->mmap_lock.osq.tail.counter | 0-s32max |
| PARAM_VALUE | 0 | ctx->mm->notifier_subscriptions | 0 |
| PARAM_VALUE | 0 | ctx->mm->sc_stat.pcpu_sched | 0 |
| PARAM_VALUE | 0 | ctx->mm->task_size | 1-u64max |
| PARAM_VALUE | 0 | ctx->mmap_changing.counter | 0 |
| PARAM_VALUE | 0 | *ctx->mm->exe_file->f_cred->user->uidhash_node.next->pprev | 1-u64max |
| PARAM_VALUE | 1 | range | 4686075703099240448 |
| PARAM_VALUE | 1 | range->len | 0,4096-9223372036854775807 |
| PARAM_VALUE | 1 | range->start | 0-18446744073709551614 |
| BUF_SIZE | 0 | ctx | s32min-(-2),1-s32max |
| BUF_SIZE | 0 | ctx | s32min-(-2),1-s32max |
| CAPPED_DATA | 0 | ctx->mm->task_size | 1 |
| DATA_SOURCE | 0 | ctx | $0 |
| NOCHECK_CALL | |||
| USER_DATA | 1 | range->start | 0-18446744073709551614[c] |
| NO_OVERFLOW_SIMPLE | 1 | range->start |